HomeAnalyticsGuidesData Protection Compliance in United States: Legal Framework and Obligations

Data Protection Compliance in United States: Legal Framework and Obligations

A European technology company launches a US-facing subscription product. Within weeks, it begins collecting personal data from residents across multiple US states. Its legal team assumes that existing GDPR compliance procedures are sufficient. That assumption is wrong – and the cost of discovering the error through enforcement can run well into six figures.

Data protection compliance in the United States requires businesses to map applicable federal sector-specific legislation and state-level privacy statutes. Appoint appropriate internal or external data governance contacts. Additionally, implement documented consent mechanisms, data transfer safeguards, and vendor agreements. There is no single federal data protection authority in the US; obligations arise from a patchwork of laws that vary by sector, data type, and the states where consumers reside. A compliance programme must be built layer by layer, with each layer corresponding to a distinct legal obligation.

This guide walks through the procedural requirements step by step. It covers the legislative sources of obligation, the documentation and contractual checklist, common errors made by foreign businesses entering the US market, cost expectations, and a decision framework for different operating scenarios.

Understanding the US data protection legislative environment

The United States does not have a single omnibus data protection law. Instead, obligations arise from a combination of federal sector-specific legislation, state privacy statutes, and regulatory guidance from agencies such as the Federal Trade Commission (FTC) – the primary federal consumer protection body in this space.

At the federal level, distinct bodies of law govern specific categories of data. Health information is regulated under federal health privacy legislation. Financial data held by banks and financial institutions falls under federal financial privacy rules. Children's online data is subject to its own federal statutory regime. Educational records attract separate federal protections. Each of these regimes defines its own data controller and data processor obligations, with different notice, consent, and security requirements.

State law adds a second, increasingly significant layer. California's privacy legislation is the most developed in the country. It grants consumers rights to know, delete, and opt out of the sale of their personal data. Several other states – including Virginia, Colorado, Connecticut, Texas, and Oregon – have enacted broadly comparable statutes. These laws apply to businesses that meet specified thresholds: typically, a minimum number of consumers whose data the business processes, or a minimum revenue share derived from data-related activities.

A Delaware LLC (limited liability company incorporated in Delaware) or any other US-registered entity is not automatically exempt from state privacy statutes of other states. If the business collects data from residents of California or Virginia, for example, the statutes of those states apply – regardless of the state of incorporation.

Foreign companies without a US physical presence are equally at risk. State privacy laws generally apply to companies that target or collect data from state residents, regardless of where the company is headquartered. A foreign business with a US-facing website and US consumer data should not assume that its offshore structure provides a shield.

The Securities and Exchange Commission (SEC) has also introduced cybersecurity disclosure rules affecting publicly listed companies. These rules require timely disclosure of material cybersecurity incidents and annual reporting on cybersecurity governance. For businesses that are listed or planning to list in the US, SEC obligations add a distinct compliance dimension beyond standard data protection requirements.

Practitioners advising international clients consistently note that the most common source of early non-compliance is the failure to map all applicable legal regimes before building internal policies. A business operating in healthcare and financial services, for example, may face obligations under four or five distinct bodies of federal and state law simultaneously. Mapping must precede drafting.

Step-by-step compliance procedure and timeline

Building a defensible data protection compliance programme in the United States involves five sequential phases. Each phase has defined deliverables, responsible parties, and a realistic timeframe.

Phase 1: Data inventory and classification (weeks 1–4)

The starting point is a comprehensive data inventory. The business must identify every category of personal data it collects, the source of collection, the purpose of processing, the systems where data is stored, and the third parties with whom data is shared. This exercise produces a data map – the foundational document on which every subsequent compliance decision rests.

During this phase, the business also classifies data by sensitivity. Standard personal identifiers require one level of protection. Financial data, health data, biometric data, and children's data attract heightened obligations under specific federal and state rules. Misclassifying sensitive data at this stage leads to systematic under-protection – a risk that surfaces during audits or breach investigations.

Phase 2: Legal obligation mapping (weeks 3–6, overlapping with Phase 1)

With the data inventory in hand, legal counsel identifies which federal and state statutes apply. The analysis considers: the categories of data collected. the states of residence of consumers whose data is processed. the sectors in which the business operates. and whether the business meets the thresholds specified in each applicable state statute.

This phase produces a compliance matrix – a document that cross-references each data category against each applicable law and summarises the specific obligations triggered. For foreign businesses, this phase also identifies whether any international data transfer obligations arise. A company transferring data from the US to the EU, for example. Must consider whether GDPR compliance rules govern the receiving end of the transfer. and must document that the data transfer is lawful under both systems.

Phase 3: Policy and contract drafting (weeks 5–10)

The compliance matrix drives the drafting phase. The business must produce or update the following core documents.

  • A privacy notice or privacy policy, posted on the business's website and updated to reflect the specific rights available to consumers in each applicable state
  • Internal data governance policies, including data retention schedules, security incident response procedures, and access control protocols
  • Vendor and service provider agreements that include data processing terms – ensuring that third parties who access personal data are contractually bound to appropriate standards
  • A consent mechanism design, where applicable – particularly for the sale or sharing of personal data under California-style statutes
  • Employee training materials, adapted to the roles that involve personal data handling

The vendor contract review is frequently underestimated. A business may have dozens or hundreds of third-party service providers with access to personal data. Each relationship requires a written agreement that specifies the permissible uses of the data, the security standards the vendor must maintain, and the obligations upon a breach. Preparing these agreements for an existing vendor base can take several weeks if done thoroughly.

For clients operating in both the US and the EU, it is worth noting that the consent mechanism requirements differ. GDPR compliance under EU data protection law sets a high bar for valid consent – freely given, specific, informed, and unambiguous. US state laws generally permit opt-out mechanisms for the sale of data rather than requiring opt-in consent. A business with consumers on both sides of the Atlantic must design consent flows that satisfy both standards simultaneously. The EU standard is usually the more demanding one, but the US standard includes specific opt-out infrastructure – such as a "Do Not Sell My Personal Information" link – that has no direct EU equivalent.

Phase 4: Technical and organisational measures (weeks 8–14)

Documented policies are necessary but not sufficient. The business must also implement the technical measures that give effect to those policies. This includes encryption of personal data in transit and at rest, access controls that restrict data to authorised personnel, logging and audit trails, and a tested incident response plan.

The incident response plan deserves particular attention. US state breach notification laws impose mandatory notification timelines – typically ranging from 30 to 90 days following discovery of a breach, depending on the state. Some states require notification to affected consumers; others additionally require notification to state regulators. Failure to notify within the required window is itself an independent violation, separate from the underlying breach.

For businesses that process children's data, the technical and organisational requirements are more demanding. Federal children's data legislation requires verifiable parental consent before collecting personal information from children below a specified age. Implementing a defensible age verification and parental consent mechanism is both a technical and a legal challenge.

Phase 5: Ongoing monitoring and review (from month 3 onwards)

US privacy law is changing rapidly. Several states have enacted new statutes or amended existing ones in recent years. Businesses must build a review cycle into their compliance programme – at minimum annually, and more frequently when new legislation takes effect in a state where the business has consumers.

For international businesses, this phase also includes monitoring the status of cross-border data transfer mechanisms. The legal basis for transferring personal data from the EU to the US, for example, is subject to regulatory and judicial developments that can alter the permissible transfer mechanisms at relatively short notice. A compliance programme that was current 18 months ago may no longer reflect the operative legal position.

To receive an expert assessment of your data protection compliance obligations in the United States, contact us at info@ferrazwhitmore.com.

Documentary checklist and common errors by foreign clients

Foreign businesses entering the US market make a predictable set of compliance errors. Understanding these patterns in advance substantially reduces the cost of remediation.

The most common error is assuming that compliance with home-country data protection law – most often GDPR compliance under EU legislation – satisfies US requirements. It does not. GDPR compliance is a European obligation. It does not address the sector-specific federal laws applicable in the US, nor the state-level privacy statutes. A business that has invested heavily in its EU data protection programme must treat the US as a separate compliance project.

A second frequent error involves data transfer planning. A business that collects data from US consumers and processes or stores it outside the United States may face obligations under both US and foreign data protection legislation. The direction of transfer matters: data flowing from the US to the EU attracts GDPR considerations on the EU side. data flowing from the EU to the US requires a valid transfer mechanism under EU law. Both directions require documentation. Many foreign businesses focus only on one direction and leave the reverse transfer undocumented.

Third, businesses regularly underestimate the scope of vendor contract obligations. Under California-style privacy legislation, a business that discloses personal data to a service provider without a written agreement that meets specific statutory requirements may be treated as having "sold" that data. triggering consumer rights and potentially enforcement action. The written agreement must contain specific provisions prescribed by the applicable statute. A generic confidentiality clause does not suffice.

Fourth, privacy notices are frequently drafted at too high a level of generality. State privacy laws require notices to be specific about the categories of data collected, the purposes of processing, and the rights available to consumers in each applicable state. A generic notice that does not address state-specific rights will not satisfy California or Virginia requirements, for example.

Fifth, businesses without a US physical presence sometimes overlook the need to designate an agent for service of process or a point of contact for consumer rights requests. When a consumer submits a data access or deletion request, the business must respond within a defined period – typically 45 days under California legislation, with a possible extension. Absent a clear internal process, these requests go unanswered, which constitutes a separate violation.

The core documentary checklist for a baseline US data protection compliance programme includes:

  • Completed data inventory and data map, signed off by legal and IT
  • Compliance matrix identifying applicable federal and state statutes
  • Published privacy notice meeting all applicable state disclosure requirements
  • Consent mechanism or opt-out infrastructure, as required by applicable law
  • Data processing agreements with all third-party service providers
  • Internal data governance and retention policy
  • Security incident response plan with defined notification timelines by state
  • Employee training records
  • Annual review log documenting changes in applicable law and corresponding programme updates

For businesses subject to SEC cybersecurity rules, the checklist expands to include board-level cybersecurity governance documentation and incident disclosure procedures aligned with SEC reporting timelines.

Disputes arising from data protection obligations – whether between businesses and regulators, or between businesses and their vendors – may be referred to JAMS or AAA arbitration (American Arbitration Association) under contractual dispute resolution clauses. Some disputes proceed before a US District Court when regulatory enforcement is involved. Understanding the dispute resolution pathway relevant to your contracts and regulatory exposure is part of sound compliance planning. Clients with cross-border operations should also review our analysis of AI and technology law obligations in the United States, which increasingly intersects with data protection requirements.

For a tailored strategy on data protection compliance in the United States, reach out to info@ferrazwhitmore.com.

Cost ranges and decision framework for different business scenarios

The cost of building a US data protection compliance programme varies significantly depending on the size of the business, the complexity of its data processing activities. The number of applicable state laws. Additionally, whether compliance is built from scratch or adapted from an existing programme.

For a small business processing data from residents of one or two states, with a limited vendor base and no sensitive data categories. A baseline programme can be completed with legal fees in the low-to-mid thousands of US dollars. This assumes that internal staff are available to assist with data mapping and that no bespoke technical infrastructure is required.

For a mid-size business with consumers across multiple states, processing several categories of data, and operating through a network of third-party service providers, legal and consulting costs are likely to run considerably higher. Adding sector-specific federal compliance – health data, financial data, or children's data – increases costs further, as each regime requires specialised analysis and documentation.

For a large or multinational business with a complex data ecosystem and SEC obligations, a comprehensive compliance programme is a multi-month project involving legal counsel, technology consultants, and internal governance resources. The cost of getting this right is substantially lower than the cost of enforcement. FTC enforcement actions and state attorney general investigations can result in financial penalties, mandatory compliance programmes, and reputational damage that significantly exceeds any reasonable compliance investment.

The decision framework below helps identify the appropriate compliance pathway for different business scenarios.

Scenario A: Foreign business with US-facing digital product, no US office

This business should begin with a jurisdictional assessment to identify which state privacy laws apply based on the states of residence of its US consumers. If it meets the threshold for California, Virginia, or other states with enacted statutes, it must build state-compliant privacy notices, opt-out mechanisms, and consumer rights response procedures. It should also assess whether any federal sector-specific law applies to its data categories. A data protection authority (DPA) contact or designated privacy officer – even if informal – is advisable.

Scenario B: Foreign business acquiring a US company or establishing a Delaware LLC

Post-acquisition or formation, the business inherits any existing compliance obligations of the US entity. A data protection due diligence review should be part of any acquisition process. A Delaware LLC does not carry any inherent data protection obligations by reason of its state of incorporation alone – obligations arise from the data it processes and the consumers it serves. The acquiring business must integrate the US entity's compliance programme with its global data governance structure, resolving any conflicts between US and non-US requirements – particularly around international data transfer mechanisms.

Scenario C: Business subject to both GDPR and US state privacy law

This is the most complex scenario. The business must maintain two compliance programmes that are coherent but not identical. The consent mechanism must satisfy the higher EU standard where EU residents are involved, while also providing the US-specific opt-out infrastructure. Vendor agreements must comply with both GDPR data processing agreement requirements and US statutory requirements. Data transfer documentation must address both outbound transfers from the EU to the US and any reverse transfers. Practitioners in this area consistently recommend maintaining a unified data governance structure with jurisdiction-specific annexes, rather than running entirely separate programmes. The alternative – disconnected policies for different markets – creates internal inconsistencies that surface in audits and investigations. For businesses with operations in multiple jurisdictions across the Americas, our guide to data protection compliance in Brazil provides a useful comparative perspective on civil-law data protection regimes.

Scenario D: Business subject to SEC cybersecurity disclosure obligations

In addition to the steps above, this business must document its board-level cybersecurity oversight processes. Maintain an incident assessment and escalation procedure that feeds into SEC reporting timelines. Additionally, ensure that material incidents are disclosed in compliance with SEC rules. The interplay between SEC disclosure obligations and state breach notification requirements requires careful coordination. the timelines and notification recipients differ. Additionally. A business that focuses only on one set of obligations may inadvertently fail the other.

The full scope of US data protection obligations for technology-driven businesses – including those developing or deploying AI systems – is covered in our dedicated resource on data protection law services in the United States.

Self-assessment checklist before initiating a compliance programme

Before engaging counsel and beginning the compliance build, the following questions help establish scope and priority.

This compliance programme is applicable if your business:

  • Collects, processes, or stores personal data about US residents, regardless of where your business is located
  • Meets the consumer volume or revenue thresholds specified in applicable state privacy statutes
  • Operates in a sector covered by federal sector-specific data legislation (health, financial services, education, children's products)
  • Is listed or planning to list on a US exchange, triggering SEC cybersecurity obligations
  • Transfers personal data between the United States and one or more other countries

Before initiating, verify the following:

  • You have identified all US states from which you collect consumer data and checked whether you meet the applicable statutory thresholds
  • You have confirmed whether any federal sector-specific law applies to your data categories
  • You have identified all third-party service providers with access to personal data and assessed whether written data processing agreements are in place
  • You have assessed the direction and legal basis for any cross-border data transfers – both from the US and into the US
  • You have allocated internal responsibility for privacy governance, including a designated point of contact for consumer rights requests

Trigger indicators for escalating to specialist legal counsel:

If your data inventory reveals sensitive data categories – health, financial, biometric, or children's data – the complexity of the applicable federal and state obligations warrants specialist advice from the outset. If you are acquiring a US business, specialist counsel should be engaged before completion to conduct data protection due diligence. If you have received a consumer complaint, a regulatory inquiry, or a notice of investigation from a state attorney general or the FTC, you should engage counsel immediately. The window for a voluntary and co-operative response to early regulatory contact is narrow – and a delayed or inadequate response typically worsens the outcome.

Frequently asked questions

Q: How long does it take to build a baseline data protection compliance programme in the United States?

A: A baseline programme for a mid-size business typically takes between three and six months to implement fully. The first month focuses on data mapping and gap analysis. Policy drafting, vendor contract review, and staff training occupy the following two to four months. Ongoing monitoring then continues indefinitely.

Q: Does a foreign company with no US office still need to comply with US data protection laws?

A: Yes, in many cases. Several US state privacy laws apply to companies that collect data about state residents, regardless of where the company is incorporated or physically located. A foreign business that targets US consumers, operates a US-facing website, or holds data on US residents should conduct a jurisdictional assessment before concluding that no US obligations apply. Engaging a lawyer with United States data protection experience is strongly recommended at this stage.

Q: Is GDPR compliance sufficient for operating in the United States?

A: No. GDPR compliance addresses obligations under EU data protection law, but it does not satisfy US requirements. US privacy law is fragmented across federal sector-specific rules and state-level statutes. A company compliant with GDPR will still need to map its US consumer data, assess applicable state laws, and implement US-specific contractual, technical, and organisational measures. Working with a law firm with United States data protection expertise helps avoid the assumption that EU compliance transfers automatically to the US context.

About Ferraz & Whitmore

Ferraz & Whitmore is an international law firm based in Lisbon, advising business clients across 46 jurisdictions on data protection compliance, cross-border transactions, and regulatory matters. Our data protection practice covers both the US patchwork of federal and state legislation and EU-side obligations under GDPR, enabling us to advise clients who operate across both systems simultaneously. The firm's attorneys have advised on data governance, consent mechanism design, vendor contract programmes, and breach response matters across common law and civil law systems. Our Lisbon base provides direct access to EU regulatory developments, while our common law expertise supports enforcement and dispute resolution strategies in US federal courts and before arbitral bodies including JAMS and AAA arbitration panels. As an international law firm working across the United States and European markets, we support in-house legal teams and international entrepreneurs who need results-oriented counsel that bridges two distinct legal traditions. To discuss your data protection compliance situation in the United States, contact us at info@ferrazwhitmore.com.

Disclaimer: This publication is provided for informational purposes only and does not constitute legal advice. The information herein should not be relied upon as a substitute for professional legal counsel tailored to your specific circumstances. Ferraz & Whitmore assumes no liability for actions taken or not taken based on the contents of this material. For advice regarding your particular situation, please contact info@ferrazwhitmore.com.