Byte Technology
Byte Privacy 11 min read

What US Privacy Law Actually Protects — and What It Leaves Open

The US has no general federal privacy law. What protects you depends on who holds the data and what kind it is, so the useful question is which layer applies.

Byte Editorial

People ask whether the law protects their personal data, and they expect a yes or no. The honest answer in the United States is that the question is malformed. There is no general federal privacy law, so “does the law protect me” has no single answer — only answers that depend on who is holding the data and what kind it is.

That is not a dodge. It is the actual structure of American privacy protection, and once you can see the structure, you can predict which rights you have in a given situation instead of guessing. The rest of this article maps that structure: three layers, each covering a different slice of the problem, and the specific gaps between them.

Layer one: the Constitution constrains the government, not companies

The most common misunderstanding is that the Fourth Amendment is a general privacy shield. It is not. The Fourth Amendment limits what the government — police and agencies — may do. It says nothing about what a private company may collect, keep, or sell.

This matters because the line between the two has been moving, and the movement shows how the doctrine works. Under the “third-party doctrine,” the Supreme Court long held that a person has no reasonable expectation of privacy in information voluntarily handed to a third party — bank records in United States v. Miller (1976), dialed phone numbers in Smith v. Maryland (1979). The theory was that you take the risk of disclosure when you reveal your affairs to someone else.

In 2018 the Court narrowed that doctrine in Carpenter v. United States. The question was whether police needed a warrant to obtain historical cell site location information — the record of which towers your phone connected to, which can reconstruct where you have been. The government argued that the third-party doctrine applied: you gave the data to your carrier, so you had no expectation of privacy in it. The Court disagreed, 5–4.

Two parts of the reasoning are worth carrying around. First, the Court said that cell phone location data is not really “shared” in the ordinary sense, because carrying a phone is “indispensable to participation in modern society” and a phone logs a cell-site record “by dint of its operation” — you do not meaningfully choose to hand it over. Second, the Court described the resulting capability as “near perfect surveillance,” an “intimate window into a person’s life” revealing not just movements but through them a person’s “familial, political, professional, religious, and sexual associations.”

The holding is narrower than it sounds. It covers historical cell site location information. It did not abolish the third-party doctrine, and the Court was explicit that it had not decided how the doctrine applies to other technologies. Banking records, for instance, remain governed by the older rule. So the practical takeaway is not “the Fourth Amendment now protects my data.” It is: the Fourth Amendment sometimes requires a warrant for government access to certain kinds of digital records, and the boundary is being litigated case by case. And none of it touches what a company may collect from you in the first place.

Layer two: sector laws that protect by category, not by person

If the Constitution is the wrong tool for private collection, the plausible candidate is a statute. And there are statutes — but they are built around specific industries and specific kinds of data, not around you as a person. Four of them do most of the work.

LawWho it coversWhat it protectsWhat it does not reach
HIPAAHealth plans, healthcare clearinghouses, and providers that transmit standard electronic health transactions — plus their business associatesProtected health information held by those entitiesA wellness app, a wearable, or a health website that does not act for a covered entity. The data can be about your health and still sit outside HIPAA.
GLBA“Financial institutions,” a broad and non-intuitive category under the Gramm-Leach-Bliley Act — it reaches businesses significantly engaged in financial activities, including lenders, debt collectors, and tax preparersNonpublic personal information, with notice and opt-out dutiesBusinesses that are not engaged in financial activities as the rule defines them. The category is wider than most people expect, but it still turns on what the business does, not on whether it handles money.
COPPASites and services directed to children under 13, general-audience sites with “actual knowledge” of collecting from a child under 13, and third-party services running on kids’ sitesPersonal information from children under 13, including persistent identifiers such as IP addressesAdults entirely. It also does not require a general-audience site to go find out users’ ages — but asking for information that establishes a visitor is under 13 brings the obligation into play.
FCRAConsumer reporting agencies and the users of consumer reportsThe accuracy, privacy, and permitted uses of consumer report informationData about you that is not a consumer report. Your browsing history is not a credit file.

The pattern is the point. Each of these laws answers the question “what kind of entity are you, and what kind of data is this?” — not “are you a person with a right to privacy?” A health app and a hospital can hold the same fact about you, and only one of them is covered by HIPAA. A bank and a landlord can both know your income, and the legal obligations diverge.

This is why privacy policies so often contain a line about whether HIPAA applies. It is not boilerplate. It is a statement about which of these regimes, if any, governs the data the company is holding.

Layer three: one general law that works indirectly

The gap between the sector laws is filled — partially — by a statute that was never written as a privacy law. Section 5 of the FTC Act declares unlawful “unfair or deceptive acts or practices in or affecting commerce.” The Federal Trade Commission has used that general authority to become the closest thing the United States has to a national privacy regulator.

Two theories do the work. A practice is deceptive if it is a material representation or omission likely to mislead a consumer acting reasonably. A practice is unfair if it causes or is likely to cause substantial injury that consumers cannot reasonably avoid and that is not outweighed by benefits to consumers or competition.

Apply those to privacy and you get the FTC’s most settled principle: a company is bound by the promises it makes. Gather, use, or disclose personal information in a way that contradicts your posted privacy policy, and the FTC treats that as deceptive. Fail to protect data as your policy says you will, and that is a broken promise too. Over years of cases this has produced what scholars call a kind of common law of privacy — not a statute, but a body of consent decrees showing what the agency considers out of bounds.

Read that carefully, though, because the limits are as important as the power.

The FTC’s authority is derivative. It attaches to a broken promise or an injury that meets the unfairness test. Where there is no promise and no provable injury within the test, the same conduct can be lawful. A company that never claimed to protect your data may be able to sell it.

Section 5 does not allow civil penalties for a first-time privacy violation. The Commission has said so directly, and it has asked Congress for the authority. Its principal remedy is prospective: an order requiring the company to change its practices, delete data, and submit to outside assessments.

It does not reach everyone. Nonprofits and common carriers — in some circumstances, telecommunications services among them — fall outside FTC jurisdiction. And the FTC does not have jurisdiction over banks, credit unions, or savings and loan institutions; those are supervised by other agencies.

After AMG Capital Management v. FTC (2021), one common route to monetary relief in these cases narrowed. The Supreme Court unanimously held that Section 13(b) of the FTC Act — the provision the Commission had used for decades to seek restitution and disgorgement directly in court — does not authorize equitable monetary relief. The FTC can still seek consumer redress in some situations, through the older and more procedurally burdened section 19 path after a cease-and-desist order, but it lost the direct route it had come to rely on. The case was decided on statutory interpretation, so Congress can restore the authority; it has not.

The FTC itself makes the summary argument: Section 5 is “an imperfect tool” for privacy, which is why the Commission has repeatedly asked Congress to pass privacy and data security legislation enforceable by the FTC with civil penalty authority and jurisdiction over nonprofits and common carriers. That legislation has not passed.

The newest layer: state law, which is where the real rights now live

Because Washington has not acted, the states have — and this is the layer that has changed fastest. As of early 2026, roughly 20 states have a comprehensive consumer privacy law in effect. Indiana, Kentucky, and Rhode Island joined on January 1, 2026; Oklahoma has been signed and takes effect in 2027.

The laws follow a shared model, set first by Virginia in 2023. If you are a resident of one of these states and the business meets the law’s threshold, you generally have the right to:

  • Access the personal data a business holds about you
  • Delete it and correct it
  • Opt out of its sale and of targeted advertising
  • Appeal a business’s refusal to honor a request

But three cautions, and they are the reason this section cannot simply say “move to California.”

The thresholds matter more than the rights. Every one of these laws exempts small businesses, and the thresholds vary widely — some states count consumers processed, some require revenue, some require both. A business can be large by your standards and still fall below the line.

Coverage is by residency, and the numbers are moving. The count above is a snapshot. State legislatures add laws and amend effective dates every session, so any specific number in any article — including this one — should be checked against a current tracker before you act on it.

There is no federal backstop if your state has not acted. If you live in a state without a comprehensive law, the rights in that list may simply not exist for you as a matter of statute. What remains is the FTC layer — real, but narrower and dependent on a broken promise or a provable unfair practice.

Where the gaps actually are

Stepping back, the gaps are easier to see as a list than as an abstraction.

Data brokers are the clearest example. A business that buys and sells personal information may not be a consumer reporting agency under FCRA, may not be a financial institution under GLBA, and may not be a covered entity under HIPAA. It may have made promises it keeps. What constrains it, if anything, is state law in states that have acted — and federal enforcement against specific deceptive or unfair conduct, case by case.

Health data outside the clinic. A period tracker, a fitness app, a symptom checker: all can hold information that would be protected in a doctor’s office and fall outside HIPAA in an app, because the app is not acting for a covered entity.

Anything you post or carry. The Fourth Amendment analysis in Carpenter was about government access to records held by a carrier. It does not regulate what a platform does with what you upload, beyond the platform’s own terms and the Section 5 limit on breaking them.

Adults on general-audience services. COPPA is real and enforced, but its protections run to children under 13. There is no federal equivalent for adults.

What to do with this

The structure suggests a few practical habits.

Stop asking “is this legal?” and ask “which layer applies?” When you hand data to a company, identify what kind of entity it is and what kind of data it is. Health data at a hospital and health data in an app are the same fact under two different regimes.

Read the promises, because they are enforceable. The privacy policy is not decoration. Under the FTC’s most settled principle, a company that contradicts its own policy is engaged in a deceptive practice. The policy tells you what the company has committed to — and that commitment is the thing the law will hold it to.

Use the state rights if you have them, and know their shape. Access, delete, correct, opt out of sale and targeted ads, and appeal. Check whether your state has a law in effect and whether the business meets its threshold before assuming the right applies.

Do not rely on paid services that promise to enforce your privacy. The tools that work are the ones the law or the agency provides directly: your state attorney general or consumer protection office for state law, and ReportFraud.ftc.gov for a deceptive or unfair practice. Neither costs anything.

Treat the Fourth Amendment as a limit on government, not a shield against companies. It can require a warrant for certain government access to digital records. It does not tell a business what it may collect.

The bottom line

The United States protects privacy in slices. The Constitution limits the government; sector laws protect specific data in specific industries; Section 5 gives the FTC a general but indirect authority that attaches to broken promises and provable injuries; and state law, in about 20 states, is where actual consumer rights to access, delete, and opt out now live. There is no single law that protects you as a person, and a business handling data you consider sensitive may sit in a gap between all four layers.

The useful move is not to memorize the statutes. It is to internalize the question that replaces “does the law protect me”: Who holds this data, what kind is it, and what did they promise? Those three answers tell you which layer you are standing in.

Byte is the technology site of the Omni Mundi Compendium network. The specific tools that stop someone from opening accounts in your name are in Credit Freeze, Fraud Alert, or Credit Lock, and what to do in the days after a breach notice is in You Got a Data Breach Notice.

This article is general information about US privacy law, not legal advice. Whether a particular business is covered by any of these regimes depends on facts — its role, its data, and its jurisdiction — and comprehensive state privacy laws vary by state and change with each legislative session. The count of states with a law in effect is a snapshot, not a standing figure. It is AI-written and independently AI-reviewed before publication; the review standard and this article’s findings are recorded in the network’s editorial review log.

Frequently asked questions

Is there a single federal law that protects my personal data?
No. The United States has no comprehensive federal consumer privacy statute. Protection comes from a patchwork: sector-specific laws that reach certain industries (health, financial, children's data), a general but indirect authority the FTC uses against deceptive or unfair practices, and a growing set of state laws. What protects you depends on who is holding the data and what kind it is.
Does the Fourth Amendment stop companies from collecting my data?
No. The Fourth Amendment constrains government action — police and agencies — not private companies. It says nothing about what a business may collect. The closest thing to a limit on businesses is the FTC's power to act against practices it finds deceptive or unfair, which is a commercial standard, not a constitutional privacy right.
If a company says it will protect my data and then sells it anyway, is that illegal?
It can be. The FTC's most settled privacy principle is that a company is bound by its own promises. Gathering, using, or disclosing personal information in a way that contradicts a posted privacy policy is treated as a deceptive practice under Section 5 of the FTC Act. That is a real limit — but note what it depends on: the company having made the promise. Where there is no promise and no specific statute, the same conduct may be lawful.
Why do so many privacy policies say data is not covered by HIPAA?
Because HIPAA applies to specific roles, not to health information as a topic. It covers health plans, clearinghouses, and providers that transmit standard electronic health transactions, plus their business associates. A wellness app, a wearable, or a health website that does not act for one of those entities is generally outside HIPAA, even though the data concerns your health. Other laws or the company's own policy may still reach it, but HIPAA does not.
Do I have a right to see and delete the data a company holds about me?
It depends on where you live and where the company does business. As of early 2026, about 20 states have a comprehensive consumer privacy law in effect, and those laws generally give residents rights to access, delete, and correct personal data, plus a right to opt out of its sale and of targeted advertising. There is no federal equivalent. If your state has not passed one — or the company falls below the law's thresholds — that right may not exist.

Sources

  1. Federal Trade Commission — "Privacy and Data Security" program materials and the FTC Report to Congress on Privacy and Data Security (September 2021): the position that Section 5 of the FTC Act is the Commission's primary authority in the privacy space, the definitions of "deceptive" and "unfair" practices, and the limits — no civil penalties for first-time violations and no jurisdiction over nonprofits and common carriers
  2. Congressional Research Service, "AMG Capital Management v. FTC: Supreme Court Holds FTC Cannot Obtain Monetary Relief in Section 13(b) Suits" (LSB10596, April 30, 2021) — the unanimous April 22, 2021 holding that Section 13(b) of the FTC Act (15 U.S.C. § 53(b)) does not authorize the Commission to seek equitable monetary relief such as restitution or disgorgement, the earlier role of Section 13(b) as the FTC's primary mechanism for monetary relief in first-time violations, and the remaining route to consumer redress through Section 19 (15 U.S.C. § 57b) after a final cease-and-desist order
  3. Federal Trade Commission, "How To Comply with the Privacy of Consumer Financial Information Rule of the Gramm-Leach-Bliley Act" and the FTC's Privacy Rule at 16 C.F.R. Part 313 — the GLBA privacy regime, the notice and opt-out duties, and the point that the law "covers a broad range of financial institutions, including many companies not traditionally considered to be financial institutions because they engage in certain 'financial activities'"
  4. 15 U.S.C. § 45 (Federal Trade Commission Act) — declaration of unlawful "unfair or deceptive acts or practices in or affecting commerce," and § 45(n)'s three-part test for unfairness: substantial injury not reasonably avoidable by consumers and not outweighed by countervailing benefits
  5. Congressional Research Service, "Data Protection Law: An Overview" (R45631) — the sectoral structure of US data protection law, the FTC's use of enforcement rather than trade regulation rules, and the observation that FTC consent decrees function as a kind of common law of privacy binding companies to their stated promises
  6. Congressional Research Service, "The Privacy Act of 1974: Overview and Issues for Congress" (R47863) — the scope of the Privacy Act at 5 U.S.C. § 552a, its application to federal agency records in a "system of records," the twelve conditions of disclosure, and the ten statutory exemptions
  7. 5 U.S.C. § 552a (Privacy Act of 1974) — the Act's application to records maintained by federal agencies, individual rights of access and amendment, and the limitation that it does not reach records held by state governments or private companies
  8. Congressional Research Service, "Carpenter v. United States" legal sidebar (LSB10157) — the June 22, 2018 holding that government acquisition of historical cell site location information is a Fourth Amendment search requiring a warrant, the treatment of the third-party doctrine, and the Court's description of the ruling as narrow
  9. Carpenter v. United States, 585 U.S. ___ (2018) — the majority's reasoning that the third-party doctrine does not extend to historical cell site location information and that carrying a cell phone is "indispensable to participation in modern society"
  10. Congressional Research Service, "Data Protection Law: An Overview" — discussion of the Stored Communications Act as Title II of the Electronic Communications Privacy Act of 1986, the 180-day distinction for stored communications, and the courts' divergence from the statute under the Fourth Amendment
  11. U.S. Department of Justice, "Overview of the Privacy Act of 1974" — the definition of "agency" as limited to executive-branch departments, military departments, government corporations, and independent regulatory agencies
  12. U.S. Department of Health and Human Services — "Health Information Privacy" (the HIPAA portal): the HIPAA Rules as administered by HHS, individual rights under the Rules, the process for filing a health information privacy complaint with the Office for Civil Rights, and OCR's role in protecting the privacy and security of health information. The portal's own framing — information organized "for individuals" and "for professionals" — reflects that HIPAA obligations attach to defined roles rather than to health information as a topic
  13. Centers for Disease Control and Prevention (CDC), Public Health Law Program — "Health Insurance Portability and Accountability Act of 1996 (HIPAA)": the definition of covered entities as health plans, healthcare clearinghouses, and healthcare providers that transmit health information in connection with standard electronic transactions, and the business associate construct
  14. Federal Trade Commission, "Children's Online Privacy Protection Rule: Not Just for Kids' Sites" and "How to Comply With The Children's Online Privacy Protection Rule" — the coverage rule: sites directed to children under 13, general-audience sites with "actual knowledge" of collecting from a child under 13, and third-party services operating on kids' sites; the definition of "actual knowledge"; and the categories of personal information COPPA covers, including persistent identifiers
  15. Federal Trade Commission, FTC Report to Congress on Privacy and Data Security (September 2021) — the list of statutes the FTC enforces beyond Section 5, including the Gramm-Leach-Bliley Act (financial information), the Children's Online Privacy Protection Act, the Fair Credit Reporting Act, and the CAN-SPAM Act
  16. IAPP US State Privacy Legislation Tracker, cross-checked against state enacted bill text (as of January 2026) — approximately 20 states with a comprehensive consumer privacy law in effect, following the access/delete/correct and opt-out model, with Indiana, Kentucky, and Rhode Island taking effect January 1, 2026. The count changes as legislatures act; verify the current roster before relying on it
#privacy law#FTC Act#sectoral privacy#state privacy laws#HIPAA#COPPA#GLBA#Fourth Amendment#data broker