{"id":6684,"date":"2021-09-03T10:35:10","date_gmt":"2021-09-03T10:35:10","guid":{"rendered":"https:\/\/emoneyadvisor.com\/?post_type=thought_leadership&#038;p=6684"},"modified":"2021-09-03T20:40:54","modified_gmt":"2021-09-03T20:40:54","slug":"united-states-privacy-laws-a-legal-evolution","status":"publish","type":"thought_leadership","link":"https:\/\/emoneyadvisor.com\/blog\/united-states-privacy-laws-a-legal-evolution\/","title":{"rendered":"United States Privacy Laws: A Legal Evolution"},"content":{"rendered":"<p>Your name. Your date of birth. Your IP addresses. The video your neighbor took of you winning the hot dog eating contest last Labor Day.<\/p>\n<p>Just kidding about that last one. Kind of.<\/p>\n<p>As technology evolves, more data becomes available, and more potential harm results from data breaches that expose personal information. Privacy legislation is the response to that harm, and it has evolved dramatically over the last few years. Here is a snapshot of that progression.<\/p>\n<h1>Global Shift Toward Privacy<\/h1>\n<p>In 1999 the United States federal government implemented the Gramm-Leach-Bliely Act (GLBA) with the intention of modernizing the financial industry in everything from security policies to privacy. The GLBA&#8217;s primary privacy outcome was that certain financial institutions became required to tell their customers about their information-sharing practices and provide an &#8220;opt-out&#8221; of sharing customer information with third parties.<\/p>\n<p>Regulations didn&#8217;t become privacy-specific until three years ago when the EU General Data Protection Regulation (GDPR) took effect to protect individuals inside the EU. The GDPR is known as the most important change in data privacy regulations in 20 years because it impacted businesses across the world by basing its applicability on the relationship between the business and EU consumers. But, because the law is centered around EU consumers, it does not apply to many U.S. companies that don&#8217;t do business in or market to the EU.<\/p>\n<p>Despite the GDPR&#8217;s inapplicability to some U.S. companies, many correctly saw the consumer rights and operational business requirements contained within the GDPR as indicators of United States privacy trends to come.<\/p>\n<h1>California Knows How to Privacy<\/h1>\n<p>On\u00a0January 1, 2020,\u00a0the\u00a0<a href=\"https:\/\/oag.ca.gov\/privacy\/ccpa\">California Consumer Privacy Act (\u201c<b>CCPA<\/b>&#8220;) became<\/a>\u00a0the first impactful US privacy regulation to resemble the GDPR most closely by giving much broader privacy rights to California consumers (including prospects and employees). If a consumer lives in California and asks a business to reveal, potentially delete, provide an extract of, and\/or stop selling an individual&#8217;s data, businesses must comply if the request isn&#8217;t covered by an exemption.<\/p>\n<p>According to the law CA individuals can also sue a business if they are harmed by a company&#8217;s security or data breach if they can prove that the business failed to maintain reasonable security practices and procedures. In California and in many other states consumers already had the right to bring suit under data breach law. However, the CCPA&#8217;s private right of action provision makes it easier by providing for statutory damages and eliminating the need to prove actual damages in court.<\/p>\n<h1>CPRA<\/h1>\n<p>While U.S.-based businesses scrambled to prepare for the CCPA, California wasn&#8217;t done yet. The state took privacy to the next level through the\u00a0<a href=\"https:\/\/iapp.org\/resources\/article\/the-california-privacy-rights-act-of-2020\/\">California Privacy Rights Act of 2020 (\u201c<b>CPRA<\/b>&#8220;)<\/a>, a ballot initiative that becomes operative Jan. 1, 2023, with a yearlong \u201clook back&#8221; requiring businesses to include data starting Jan.1, 2022. It expands the scope of the CCPA by giving consumers additional rights (rectification, restriction against automated decision making), and adds additional business obligations such as requiring risk assessments and prohibiting discrimination. More notably, the CPRA funds a California agency that will make privacy rules, enforce them, and provide residents with related education and guidance (as opposed to the current regime where the state Attorney General is charged with interpreting and enforcing the law).<\/p>\n<h1>Virginia Is\u00a0for Lawyers and Rocky Mountain PII<\/h1>\n<p>The same day that businesses must comply with the CPRA,\u00a0<a href=\"https:\/\/www.natlawreview.com\/article\/virginia-becomes-2nd-state-to-adopt-comprehensive-consumer-data-privacy-law\">Virginia&#8217;s Consumer Data Protection Act (\u201c<b>VCDPA<\/b>&#8220;)<\/a>\u00a0becomes effective, followed by the\u00a0<a href=\"https:\/\/www.natlawreview.com\/article\/and-now-there-are-three-colorado-privacy-act\">Colorado Privacy Act (\u201c<b>CPA<\/b>&#8220;)<\/a>\u00a0in July of 2023. Both Virginia and Colorado laws create similar consumer rights as California, although Virginia doesn&#8217;t go quite as far, aligning more closely with the CCPA than the CPRA (of course, with distinctions). In addition, federal law exemptions for GLBA and Health Insurance Portability and Accountability Act of 1996 (\u201c<b>HIPAA<\/b>&#8220;) that are set to expire in California continue in perpetuity in Virginia making the law not applicable to certain businesses. In Colorado, the GLBA exemption also continues in perpetuity, but the HIPAA exemption is absent, and the scope of impacted businesses is broader.<\/p>\n<p>Subtleties aside, if a financial institution is prepared for the CCPA and CPRA ,it is largely ready for (or exempt from) Virginia and Colorado regulations aside from any state specific disclosure requirements and other technicalities.<\/p>\n<h1>Preparing for New Privacy Laws<\/h1>\n<p>While the practical implications of managing state laws are manageable so far, it is becoming onerous. There are five additional state privacy bills containing equally nuanced language and implications. Luckily, the driver of federal legislation is often conflicting state legislation. Privacy laws are no different. Federal proposals were rolled out by both Republicans and Democrats in 2019 but were stalled until recently when Republicans submitted a largely reintroduced bill this summer. If and when a federal law is passed, it will likely supersede less restrictive state legislation. But the proposals from both parties so far have not been as comprehensive as states like California with more restrictive legislation.<\/p>\n<p>In the meantime, businesses must be prepared to comply with each state&#8217;s law unless they are covered by an exemption. Companies should seek counsel on specific use cases and applicability and be forward-thinking in their privacy approach.<\/p>\n<p>Follow the foundational tenets that the state privacy laws intend and implement them into internal policies and procedures. That way, as more state laws evolve, you will already be prepared to comply. Then take a deep breath and keep taking things one state at a time.<\/p>\n<p>DISCLAIMER: The eMoney Advisor Blog is meant as an educational and informative resource for financial professionals and individuals alike. It is not meant to be, and should not be taken as financial, legal, tax or other professional advice. Those seeking professional advice may do so by consulting with a professional advisor. eMoney Advisor will not be liable for any actions you may take based on the content of this blog.<\/p>\n","protected":false},"author":43,"featured_media":6685,"template":"","thought_leadership_cat":[93,91],"class_list":["post-6684","thought_leadership","type-thought_leadership","status-publish","has-post-thumbnail","hentry","thought_leadership_cat-industry-news-and-trends","thought_leadership_cat-practice-management"],"acf":{"left_sidebar_ads":false,"right_sidebar_ads":false},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v19.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>The Evolution of U.S. Privacy Laws for Financial Services<\/title>\n<meta name=\"description\" content=\"Privacy laws are rapidly evolving. Learn how to adopt the latest best practices to stay ahead of game-changing privacy legislation.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/emoneyadvisor.com\/blog\/united-states-privacy-laws-a-legal-evolution\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The Evolution of U.S. Privacy Laws for Financial Services\" \/>\n<meta property=\"og:description\" content=\"Privacy laws are rapidly evolving. Learn how to adopt the latest best practices to stay ahead of game-changing privacy legislation.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/emoneyadvisor.com\/blog\/united-states-privacy-laws-a-legal-evolution\/\" \/>\n<meta property=\"og:site_name\" content=\"eMoney Advisor\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/eMoneyAdvisor\/\" \/>\n<meta property=\"article:modified_time\" content=\"2021-09-03T20:40:54+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/emoneyadvisor.com\/blog\/wp-content\/uploads\/2021\/08\/privacy-laws-in-the-U.S..png\" \/>\n\t<meta property=\"og:image:width\" content=\"573\" \/>\n\t<meta property=\"og:image:height\" content=\"360\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@eMoneyAdvisor\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/emoneyadvisor.com\/blog\/#organization\",\"name\":\"eMoney Advisor\",\"url\":\"https:\/\/emoneyadvisor.com\/blog\/\",\"sameAs\":[\"https:\/\/www.instagram.com\/emoney.advisor\/\",\"https:\/\/www.linkedin.com\/company\/emoney-advisor\",\"https:\/\/www.youtube.com\/user\/eMoneyAdvisor\",\"https:\/\/www.facebook.com\/eMoneyAdvisor\/\",\"https:\/\/twitter.com\/eMoneyAdvisor\"],\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/emoneyadvisor.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/emoneyadvisor.com\/blog\/wp-content\/uploads\/2020\/05\/emoney-logo.jpg\",\"contentUrl\":\"https:\/\/emoneyadvisor.com\/blog\/wp-content\/uploads\/2020\/05\/emoney-logo.jpg\",\"width\":2500,\"height\":808,\"caption\":\"eMoney Advisor\"},\"image\":{\"@id\":\"https:\/\/emoneyadvisor.com\/blog\/#\/schema\/logo\/image\/\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/emoneyadvisor.com\/blog\/#website\",\"url\":\"https:\/\/emoneyadvisor.com\/blog\/\",\"name\":\"eMoney Advisor\",\"description\":\"Heart of Advice Blog\",\"publisher\":{\"@id\":\"https:\/\/emoneyadvisor.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/emoneyadvisor.com\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/emoneyadvisor.com\/blog\/united-states-privacy-laws-a-legal-evolution\/#primaryimage\",\"url\":\"https:\/\/emoneyadvisor.com\/blog\/wp-content\/uploads\/2021\/08\/privacy-laws-in-the-U.S..png\",\"contentUrl\":\"https:\/\/emoneyadvisor.com\/blog\/wp-content\/uploads\/2021\/08\/privacy-laws-in-the-U.S..png\",\"width\":573,\"height\":360,\"caption\":\"United States Privacy Laws\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/emoneyadvisor.com\/blog\/united-states-privacy-laws-a-legal-evolution\/#webpage\",\"url\":\"https:\/\/emoneyadvisor.com\/blog\/united-states-privacy-laws-a-legal-evolution\/\",\"name\":\"The Evolution of U.S. Privacy Laws for Financial Services\",\"isPartOf\":{\"@id\":\"https:\/\/emoneyadvisor.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/emoneyadvisor.com\/blog\/united-states-privacy-laws-a-legal-evolution\/#primaryimage\"},\"datePublished\":\"2021-09-03T10:35:10+00:00\",\"dateModified\":\"2021-09-03T20:40:54+00:00\",\"description\":\"Privacy laws are rapidly evolving. Learn how to adopt the latest best practices to stay ahead of game-changing privacy legislation.\",\"breadcrumb\":{\"@id\":\"https:\/\/emoneyadvisor.com\/blog\/united-states-privacy-laws-a-legal-evolution\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/emoneyadvisor.com\/blog\/united-states-privacy-laws-a-legal-evolution\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/emoneyadvisor.com\/blog\/united-states-privacy-laws-a-legal-evolution\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Thought Leadership\",\"item\":\"https:\/\/emoneyadvisor.com\/blog\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"United States Privacy Laws: A Legal Evolution\"}]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The Evolution of U.S. Privacy Laws for Financial Services","description":"Privacy laws are rapidly evolving. Learn how to adopt the latest best practices to stay ahead of game-changing privacy legislation.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/emoneyadvisor.com\/blog\/united-states-privacy-laws-a-legal-evolution\/","og_locale":"en_US","og_type":"article","og_title":"The Evolution of U.S. Privacy Laws for Financial Services","og_description":"Privacy laws are rapidly evolving. Learn how to adopt the latest best practices to stay ahead of game-changing privacy legislation.","og_url":"https:\/\/emoneyadvisor.com\/blog\/united-states-privacy-laws-a-legal-evolution\/","og_site_name":"eMoney Advisor","article_publisher":"https:\/\/www.facebook.com\/eMoneyAdvisor\/","article_modified_time":"2021-09-03T20:40:54+00:00","og_image":[{"width":573,"height":360,"url":"https:\/\/emoneyadvisor.com\/blog\/wp-content\/uploads\/2021\/08\/privacy-laws-in-the-U.S..png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_site":"@eMoneyAdvisor","twitter_misc":{"Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/emoneyadvisor.com\/blog\/#organization","name":"eMoney Advisor","url":"https:\/\/emoneyadvisor.com\/blog\/","sameAs":["https:\/\/www.instagram.com\/emoney.advisor\/","https:\/\/www.linkedin.com\/company\/emoney-advisor","https:\/\/www.youtube.com\/user\/eMoneyAdvisor","https:\/\/www.facebook.com\/eMoneyAdvisor\/","https:\/\/twitter.com\/eMoneyAdvisor"],"logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/emoneyadvisor.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/emoneyadvisor.com\/blog\/wp-content\/uploads\/2020\/05\/emoney-logo.jpg","contentUrl":"https:\/\/emoneyadvisor.com\/blog\/wp-content\/uploads\/2020\/05\/emoney-logo.jpg","width":2500,"height":808,"caption":"eMoney Advisor"},"image":{"@id":"https:\/\/emoneyadvisor.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"WebSite","@id":"https:\/\/emoneyadvisor.com\/blog\/#website","url":"https:\/\/emoneyadvisor.com\/blog\/","name":"eMoney Advisor","description":"Heart of Advice Blog","publisher":{"@id":"https:\/\/emoneyadvisor.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/emoneyadvisor.com\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/emoneyadvisor.com\/blog\/united-states-privacy-laws-a-legal-evolution\/#primaryimage","url":"https:\/\/emoneyadvisor.com\/blog\/wp-content\/uploads\/2021\/08\/privacy-laws-in-the-U.S..png","contentUrl":"https:\/\/emoneyadvisor.com\/blog\/wp-content\/uploads\/2021\/08\/privacy-laws-in-the-U.S..png","width":573,"height":360,"caption":"United States Privacy Laws"},{"@type":"WebPage","@id":"https:\/\/emoneyadvisor.com\/blog\/united-states-privacy-laws-a-legal-evolution\/#webpage","url":"https:\/\/emoneyadvisor.com\/blog\/united-states-privacy-laws-a-legal-evolution\/","name":"The Evolution of U.S. Privacy Laws for Financial Services","isPartOf":{"@id":"https:\/\/emoneyadvisor.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/emoneyadvisor.com\/blog\/united-states-privacy-laws-a-legal-evolution\/#primaryimage"},"datePublished":"2021-09-03T10:35:10+00:00","dateModified":"2021-09-03T20:40:54+00:00","description":"Privacy laws are rapidly evolving. Learn how to adopt the latest best practices to stay ahead of game-changing privacy legislation.","breadcrumb":{"@id":"https:\/\/emoneyadvisor.com\/blog\/united-states-privacy-laws-a-legal-evolution\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/emoneyadvisor.com\/blog\/united-states-privacy-laws-a-legal-evolution\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/emoneyadvisor.com\/blog\/united-states-privacy-laws-a-legal-evolution\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Thought Leadership","item":"https:\/\/emoneyadvisor.com\/blog\/blog\/"},{"@type":"ListItem","position":2,"name":"United States Privacy Laws: A Legal Evolution"}]}]}},"_links":{"self":[{"href":"https:\/\/emoneyadvisor.com\/blog\/wp-json\/wp\/v2\/thought_leadership\/6684","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/emoneyadvisor.com\/blog\/wp-json\/wp\/v2\/thought_leadership"}],"about":[{"href":"https:\/\/emoneyadvisor.com\/blog\/wp-json\/wp\/v2\/types\/thought_leadership"}],"author":[{"embeddable":true,"href":"https:\/\/emoneyadvisor.com\/blog\/wp-json\/wp\/v2\/users\/43"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/emoneyadvisor.com\/blog\/wp-json\/wp\/v2\/media\/6685"}],"wp:attachment":[{"href":"https:\/\/emoneyadvisor.com\/blog\/wp-json\/wp\/v2\/media?parent=6684"}],"wp:term":[{"taxonomy":"thought_leadership_cat","embeddable":true,"href":"https:\/\/emoneyadvisor.com\/blog\/wp-json\/wp\/v2\/thought_leadership_cat?post=6684"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}