The First File The First File
  • News & Cases
  • Federal Law
    • Taxes
    • Federal Courts & Procedure
      • Appeals
      • Civil Procedure
      • Criminal Procedure
      • Evidence
    • Constitution & Rights
    • Consumer Protection
    • Bankruptcy
    • Agencies & Administrative Law
    • Federal Employment Law
    • Health & Federal Benefits
  • State Law
    • Criminal Law & Procedure
    • Employment & Work
      • Unemployment Insurance
      • Wages & Pay
        • Minimum Wage & Local Rules
      • Workers’ Compensation
      • Workplace Rights
    • Family & Relationships
      • Divorce
      • Guardianship
      • Probate & Estates
    • Housing & Real Estate
      • Landlord–Tenant
      • Foreclosure
      • HOAs & Condominiums
      • Deeds & Property Records
    • Personal Injury & Torts
      • Auto Accidents
      • Negligence
    • Business & Contracts
      • Business Entities
      • Contracts
    • Money, Debt & Consumer
      • Consumer Protection
      • Debt Collection & Judgments
Reading: Data privacy and security rules for lawyers, businesses, and consumers under federal and state law
Share
FIRST FILEFIRST FILE
Font ResizerAa
Search
  • Federal Law
    • Constitution & Rights
    • Consumer Protection
    • Practice Areas
  • State Law
    • Criminal Law & Procedure
    • Employment & Work
    • Family & Relationships
    • Housing & Real Estate
    • Personal Injury & Torts
    • Money, Debt & Consumer
    • Business & Contracts
  • Legal Terms Glossary
Follow US
Copyright © 2014-2025 Ruby Theme Ltd. All Rights Reserved.
Home » Blog » Data privacy and security rules for lawyers, businesses, and consumers under federal and state law
Archives

Data privacy and security rules for lawyers, businesses, and consumers under federal and state law

By Lucas S.
Last updated: August 11, 2026
13 Min Read
SHARE

This material is general public information for educational purposes only. It should not be used as legal, financial, or tax advice, and no attorney-client relationship is created by reading it. Federal, state, and local rules may vary and may change over time. A qualified professional can review specific circumstances.

Key Facts
  1. Federal level: The FTC Act declares unfair methods of competition and unfair or deceptive acts or practices unlawful and empowers the FTC to prevent them under 15 U.S.C. § 45.
  2. Federal level: GLBA requires each financial institution to respect customer privacy and protect the security and confidentiality of customers’ nonpublic personal information under 15 U.S.C. § 6801.
  3. Federal level: The GLBA Safeguards Rule requires an information security program based on a risk assessment and includes encryption in transit and at rest where applicable under 16 CFR Part 314.
  4. Federal level: The GLBA Safeguards Rule requires FTC notification no later than 30 days after discovery for notification events involving at least 500 consumers under 16 CFR Part 314.
  5. Federal level: HIPAA breach notification defines “breach” and presumes a breach unless the covered entity demonstrates low probability using a risk assessment under 45 CFR Part 164 Subpart D.
  6. Federal level: HIPAA requires individual notice after a breach of unsecured protected health information without unreasonable delay and no later than 60 calendar days after discovery under 45 CFR Part 164 Subpart D.
  7. Federal level: HIPAA requires media notification for breaches involving more than 500 residents of a State or jurisdiction under 45 CFR Part 164 Subpart D.
  8. State level: California requires disclosure of a security breach to California residents within 30 calendar days of discovery or notification, with allowed law-enforcement delays under California Civil Code § 1798.82.
  9. State level: New York’s SHIELD Act requires reasonable safeguards for private information, including disposal, and states that it does not create a private right of action under New York General Business Law § 899-bb.
  10. National overview: Federal damages claims generally require Article III standing based on concrete harm, and speculative future harms must be certainly impending under TransUnion LLC v. Ramirez and Clapper v. Amnesty International USA.

Last reviewed: May 2026. Legal rules, forms, deadlines, and procedures can change by jurisdiction, agency, and court system.

Contents
  • The federal enforcement baseline often starts with the FTC Act
  • How the FTC describes practical security planning for business
  • Financial sector example GLBA and the Safeguards Rule
    • GLBA sets a continuing privacy and security obligation for covered financial institutions
    • The Safeguards Rule translates that policy into program, risk, and encryption requirements
    • A federal breach notification deadline example GLBA’s 500 consumer threshold and 30 day timing
  • A compact comparison of breach notification timing examples
  • Health sector example HIPAA breach notification focuses on a “breach” definition and a low probability exception
  • State examples California’s breach notice statute and New York’s reasonable safeguards requirement
    • California 30 day resident disclosure plus allowed law enforcement delays
    • New York reasonable safeguards and no private right of action
  • Court system angle standing limits can affect data breach and privacy damages cases
  • Putting the pieces together how professionals often frame compliance
  • Sources

Data privacy and security obligations often feel like they “move” because they come from multiple sources at once. In the U.S., controlling rules can differ based on who holds the data, what kind of information it involves, and where affected individuals live.

A helpful way to understand the patchwork is to separate three questions: (1) which federal statute or regulation governs the data-holder relationship, (2) whether a state breach-security law also applies, and (3) how federal courts handle damages claims when standing is disputed.

The federal enforcement baseline often starts with the FTC Act

Federal law gives the FTC a broad enforcement pathway for unfair methods of competition and unfair or deceptive acts or practices. The statutory text declares these conduct types unlawful and empowers the FTC to prevent them under 15 U.S.C. § 45.

How the FTC describes practical security planning for business

The FTC’s business guidance frames a data security plan around five principles—TAKE STOCK, SCALE DOWN, LOCK IT, PITCH IT, and PLAN AHEAD—and it describes that statutes like GLBA and the FTC Act may require reasonable security for sensitive information in applicable contexts. That guidance appears in Protecting Personal Information: A Guide for Business.

Financial sector example GLBA and the Safeguards Rule

GLBA sets a continuing privacy and security obligation for covered financial institutions

GLBA includes an express policy that each financial institution has an affirmative and continuing obligation to protect the security and confidentiality of customers’ nonpublic personal information. That obligation appears in 15 U.S.C. § 6801.

The Safeguards Rule translates that policy into program, risk, and encryption requirements

For FTC-jurisdiction financial institutions, the GLBA Safeguards Rule requires a comprehensive information security program tailored to the institution and based on a risk assessment. The rule also requires protecting customer information by encryption in transit and at rest as described in 16 CFR Part 314.

A federal breach notification deadline example GLBA’s 500 consumer threshold and 30 day timing

Federal rules can also include explicit notice timing. Under the GLBA Safeguards Rule, when a notification event involves the information of at least 500 consumers, an institution must notify the FTC “no later than 30 days after discovery” as stated in 16 CFR Part 314. The rule also includes effective-date language stating that § 314.4(j) is effective as of May 13, 2024 under the same eCFR Part 314 text.

A compact comparison of breach notification timing examples

Framework (example scope) Notice trigger concept supported by the rule Timing language supported by the rule
GLBA Safeguards Rule (FTC-jurisdiction financial institutions) Notification event involving information of at least 500 consumers Notify the FTC no later than 30 days after discovery
HIPAA Breach Notification Rule (covered entities and business associates) Breach of unsecured protected health information Individual notice in no case later than 60 calendar days after discovery
California Civil Code § 1798.82 (California residents) Unauthorized breach of the security of the system involving computerized personal information Disclosure to California residents within 30 calendar days of discovery or notification

Health sector example HIPAA breach notification focuses on a “breach” definition and a low probability exception

HIPAA’s breach-notification rule uses both a definition of “breach” and a risk-assessment concept that affects how breach presumption works. The regulation defines a breach as acquisition, access, use, or disclosure of protected health information in a manner not permitted that compromises security or privacy, and it presumes a breach unless the covered entity or business associate demonstrates low probability based on a risk assessment of specified factors under 45 CFR Part 164 Subpart D.

HIPAA’s notification duties also include specific timing and communication modes, including individual notice “without unreasonable delay and in no case later than 60 calendar days after discovery.” The same eCFR Part 164 Subpart D text also includes a media-notification requirement for breaches involving more than 500 residents of a state or jurisdiction under the HIPAA rule.

The U.S. Department of Health and Human Services provides an official summary page that tracks the regulation’s breach definition and risk-assessment concept for HIPAA breach notification, as described on HHS’s Breach Notification Rule page.

State examples California’s breach notice statute and New York’s reasonable safeguards requirement

California 30 day resident disclosure plus allowed law enforcement delays

California’s data breach notice statute applies to an entity that owns or licenses computerized data including personal information, and it includes a timing rule that requires disclosure to California residents within 30 calendar days of discovery or notification under California Civil Code § 1798.82. The statute also allows delaying notification to accommodate legitimate law-enforcement needs, including when a law enforcement agency determines that notification will impede a criminal investigation, while requiring prompt notice after the agency determines it will not compromise the investigation.

California’s statute also defines “breach of the security of the system” in terms of unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information, and it includes an exclusion for certain good-faith employee or agent acquisition if no further unauthorized disclosure occurs under the same Civil Code section. State breach laws can also change on effective dates, and the California legislative text for § 1798.82 includes an amendment note indicating an effective date of January 1, 2026.

New York reasonable safeguards and no private right of action

New York’s SHIELD Act requires covered persons or businesses that own or license computerized data including private information of New York residents to develop, implement, and maintain reasonable safeguards to protect security, confidentiality, and integrity, including disposal of data under New York General Business Law § 899-bb. The same statute states that it does not create a private right of action under § 899-bb(2)(e).

Court system angle standing limits can affect data breach and privacy damages cases

Even when a statute or regulation creates an obligation, federal damages claims in court generally require plaintiffs to satisfy Article III standing. In TransUnion LLC v. Ramirez, the Supreme Court held that only plaintiffs concretely harmed by a defendant’s statutory violation have Article III standing to seek damages against a private defendant in federal court.

Standing doctrine also limits speculative “future” injury theories. In Clapper v. Amnesty International USA, the Supreme Court described threatened injury as needing to be “certainly impending” and rejected the idea that plaintiffs can manufacture standing by incurring costs based on hypothetical future harm.

Putting the pieces together how professionals often frame compliance

Because the rules come from multiple federal and state sources, many organizations treat “data privacy and security” as a mapping problem rather than a single checklist. This article’s examples illustrate how controlling duties can depend on the data-holder category and statutory trigger—such as GLBA Safeguards Rule encryption and notice timing for certain 500-consumer events, HIPAA’s breach definition and low-probability risk assessment concept, and California’s 30-day disclosure timing for resident breach notices.

Lawyers often connect these themes to other privacy, confidentiality, and technology concerns. For related discussion in this site’s archive, see technology raises significant privacy concerns and for a consumer-facing framing of personal information harms, see invasion of the personal information snatchers. For confidentiality concepts that often matter when attorneys handle sensitive information, this site also covers questions about the attorney-client privilege.

The key legal takeaway is that the most binding requirements come from the statute or regulation that actually applies, while federal court procedure can still narrow what plaintiffs can recover through damages by requiring concrete harm under Article III.

Sources

  • 15 U.S.C. § 45
  • 15 U.S.C. § 6801
  • 16 CFR Part 314
  • 45 CFR Part 164 Subpart D
  • HHS’s Breach Notification Rule page
  • California Civil Code § 1798.82
  • New York General Business Law § 899-bb
  • Protecting Personal Information: A Guide for Business
  • TransUnion LLC v. Ramirez
  • Clapper v. Amnesty International USA

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Copy Link Print
ByLucas S.
Follow:
I am an independent writer and researcher with a deep interest in law, public affairs, and how the U.S. legal system operates in the real world. Regarding the key facts about my work, my role consists of providing plain-English legal explanations and covering various lawsuits and legal disputes. My approach involves preparing articles using the primary sources listed on each page. I am not an attorney or a lawyer and I do not provide legal advice. The primary areas where I focus my research include explaining complex legal topics in plain English, translating official legal materials into accessible explanations, and following current lawsuits and court cases. You should consult a qualified professional for advice regarding your own situation.
Previous Article Researcher reviewing a federal court docket on a laptop beside unmarked legal files Federal Warrant Search: What Public Records Can Show
Next Article Young adult organizing blank application records beside a laptop and calendar DACA Requirements and Current Eligibility Rules
Most Popular
An unpaved road curves through a sunlit high-desert landscape toward two distant red-rock buttes.
Patagonia coalition asks court to revive Bears Ears challenge after Trump reduction
September 3, 2026
A broad daylight street view of a modern courthouse with palm trees, entrance steps, traffic lights and a few distant pedestrians.
Duane Davis Convicted in Tupac Shakur Murder Case: What the Verdict Decides
September 3, 2026
The White House stands beside fenced construction sites, cranes and partially built concrete structures in daylight.
Supreme Court Lets White House Ballroom Work Continue Without Deciding Its Legality
September 3, 2026
Pedestrians walk near the entrance of a modern federal courthouse complex in daylight.
Music Publishers Sue Anthropic Over Alleged Use of Thousands of Compositions
September 3, 2026
Pedestrians pass a large stone courthouse with tall windows and mature trees along an urban street.
FTC and 22 States Sue Amazon Over Sponsored Ads Pricing
September 1, 2026

You Might Also Like

ABA meeting highlights from February 2013 in Dallas

10 Min Read

What the missing 2013 AM 101 archive item appears to mean

13 Min Read

Human trafficking law explains federal criminal and civil tools for victims

10 Min Read

Missouri death penalty reforms explained through ABA assessment and review law

11 Min Read

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles instantly!
The First File The First File

Our goal is to provide simple explanations of federal and state laws without the confusing jargon

Latest News

  • Federal Law
  • State Law
  • Legal Terms Glossary

Resouce

  • Business Contact Page
  • Corrections Policy
  • Editoral Policy
  • About
  • Sitemap

Legal Notice

The information on this website is for educational purposes only and does not constitute legal advice.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?