Planning for 2023: New State Data Privacy Laws Coming Online
On May 10, 2022, Connecticut Governor Ned Lamont signed the Connecticut Data Privacy Act, making Connecticut the fifth state in the nation to pass a comprehensive data privacy law after California, Colorado, Utah, and Virginia. Together, these laws represent a monumental shift in the regulatory landscape for businesses and impose significant and meaningful legal obligations on companies nationwide – regardless of where the company is located.
Businesses as diverse as grocery store chains, delivery services, and marketing companies, among countless others that collect personal information from consumers, will have a legal obligation to adopt and implement a slate of data privacy requirements affecting all manner of how the business collects, uses, and discloses consumer data. While specific dates vary, these laws generally come into effect in 2023.
Following the lead of the European Union (which passed its groundbreaking data privacy law – the GDPR – in 2018), these state consumer data privacy laws seek to fill a gap in American data privacy regulation. As many readers of this article know, data privacy law in the United States has been primarily sector-based, with different data privacy laws applying to different sectors of the economy. For example,?HIPAA?for health care, FERPA for education, GLBA for finance, and so forth. While this approach has allowed laws to be tailored to specific contexts, it has also resulted in many businesses being exempt from meaningful data privacy regulation. Recognizing these gaps, these state consumer data privacy laws seek to establish a comprehensive framework for the control and processing of personal data by many businesses currently exempt from other regulatory schemes. While the state laws vary somewhat, they share a few common principles:
By this point, you may be thinking “But my business is located in Wisconsin – do I really need to worry about the laws of these other states?” The answer to that question is an emphatic “yes.” While, again, the details vary, these state consumer data privacy laws may apply to businesses located in the five states (California, Colorado, Connecticut, Utah, and Virginia) and to any business, no matter where it is located, if that business targets products or services to residents of such states, as long as certain other thresholds are met. This means that, for example, a hardware store chain located in New York that opens locations in Connecticut may need to comply with?Connecticut’s new data privacy law?when its Connecticut resident consumers use the hardware store’s mobile app. Similarly, an online market research company based in North Carolina may need to comply with the laws of all five states if it collects the personal data of residents of those five states.
领英推荐
In light of the broad application of these new data privacy laws, it is important for businesses to begin analyzing their compliance obligations now in order to give themselves sufficient time to develop and implement any necessary compliance programs. Businesses should consider at least the following: (a) if and how the business collects personal data from consumers; (b) whether the business makes available its goods and services to residents of California, Colorado, Connecticut, Utah, or Virginia and whether the business markets such goods and services to the residents of those states; and (c) whether the state data privacy laws apply to the business or whether any legal exemptions apply to the business in one or more states.
A business that is subject to one or more of these data privacy laws must then begin the process of complying prior to the applicable effective date. A roadmap for compliance would include the following steps:
The above list can be daunting, even for the most sophisticated of businesses. To be compliant on-time, businesses should start the process of evaluating these laws now. Non-compliance with these data privacy laws may result in government enforcement actions, fines and penalties, reputational damage in the marketplace, and loss of business partners that desire to work with only compliant entities. The good news though is that with a proper plan and sufficient resources in place, every business can be ready to comply with these laws and satisfy its legal obligations.
William Roberts is a data privacy and cybersecurity attorney with the law firm of?Day Pitney LLP?and is based out of the firm’s Hartford, Connecticut office.