Skip to the content
Global Data RulesData governance rules, country by country

United States

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in the United States — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Active

You can send most data out of the United States. There is no national privacy law. You need no permit to move data abroad. Two things change that. You cannot send large amounts of sensitive data to six countries, and breaking that rule can mean prison. And anything connected to government work must stay on American soil.

Data governance in the United States

The eight things that decide how you handle data about people in the United States. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. American rules apply even if you have no office in the country. California's privacy law covers any for-profit business that 'does business in California' and meets one of three tests. Having an office there is not one of those tests. The children's rule covers foreign websites aimed at American children. You do not have to appoint a local representative. No state law and no national law asks for one. That is a real difference from Europe.

Where the data is allowed to live

It depends on your industry. For ordinary customer or staff data, you can send it anywhere with no paperwork. Six industries are different. Government contracting, police data, federal tax data and defence work all require the data to stay in the United States. Telecom licences limit which foreign staff may even look at records. And for any business, sending large amounts of sensitive data to six named countries is now a crime.

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

For ordinary data, nothing. No standard contract, no government approval, no list of approved destination countries. You can send data anywhere except to banned countries, and six are now named. Before you move large amounts of sensitive data, do one thing. Work out whether one of those six countries, or a company or person they control, could end up with access. That includes access through a vendor, an investor or an employee.

Ways to send data out:
Nothing required · Security review needed

What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.

The regulator, and whether it actually acts

There is no national privacy regulator. Many bodies each enforce a slice instead. They are the consumer protection regulator, the health department, the securities regulator and the communications regulator. Add the Justice Department, all fifty state attorneys general, and one dedicated state privacy agency. Almost all of them are visibly working right now. The one exception is the new national data transfer programme. It is staffed and issuing guidance, but has published no enforcement action yet.

How long you must keep it — and when to delete it

You must keep some records for years, and you must not keep others too long. Investment firms must keep some books for six years and most others for three. The first two years must be easy to reach. Health providers keep their paperwork for six years. In the other direction, state privacy laws now make you publish how long you keep each type of data. You must not keep it longer than you said. Since April 2026 you may no longer keep children's data forever. Where a keep-it rule and a delete-it rule clash, the keep-it rule wins. Every state law says so.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Let people delete their data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Count the deadlines. There are at least seven and they do not agree. New York financial firms: 72 hours to the state regulator, and only 24 hours to report paying a ransom. Telecom carriers: seven working days to the police agencies and the communications regulator. You may not warn customers until seven working days after that. Investment and finance firms: 30 days to affected customers. Health organisations: 60 days. Texas and many other states: 30 days to the state attorney general. Listed companies: four working days to tell investors, once they decide an incident is important. The overlap is what people fail, not any single deadline.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five traps cost people their weekend. One: the national data transfer programme can mean prison, up to twenty years for a deliberate breach. Two: Illinois lets people sue over fingerprints and face scans. Damages are fixed per person and you do not have to prove harm. The largest privacy payouts happen there. Three: the children's rule uses under 13, but several state laws use under 18. One age gate will not do. Four: government work means the data stays on American soil. Police data may only go to the United States, its territories, tribal lands and Canada. Five: a rule can be printed in the law book and still not apply, because a court has blocked it.

What you have to do here:
Get a parent's consent for children · Keep the data in the country
What it costs if you get it wrong:
Criminal liability · Claims by individuals

What's changing next

Four things are due in the next twelve months. The national critical infrastructure reporting rule should be finished in late 2026. It will start a 72-hour incident deadline and a 24-hour ransom-payment deadline for a very wide range of businesses. California's rules on automated decision-making start on 1 January 2027. The open banking rule is being rewritten after a court blocked it. And a national privacy bill is moving in Congress. It is only a bill and binds nobody.

What to do: Diarise 1 January 2027 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries6 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Government data must stay in the country

Official name: Criminal Justice Information Services (CJIS) Security Policy · CJISSECPOL version 6.1 · Government policy document

In forceNo — it stays put

This is the strictest everyday rule in the United States about where data must sit. Police and criminal justice information may only be stored in cloud services inside the United States, its territories, tribal lands or Canada. Encrypting it does not help. The rule applies whether or not the data is encrypted. Any supplier to a police force, court or background-check programme inherits this.

In force since 25 June 2026

Enforced by Federal Bureau of Investigation, Criminal Justice Information Services Division

How this country controls where data goes: Not allowed

Government

Government data must stay in the country (Government)

Official name: Publication 1075, Tax Information Security Guidelines for Federal, State and Local Agencies · Made binding through Internal Revenue Code section 6103 safeguard agreements · Regulator guideline

In forceNo — it stays put

If you receive federal tax information, it must stay inside the United States and its territories. So must all access to it. This covers state revenue departments, benefits agencies, child support programmes and their contractors. It is a condition of receiving the data, not a general privacy rule. So it passes down to every subcontractor.

In force since 1 June 2022

Enforced by Internal Revenue Service

How this country controls where data goes: Not allowed

Defence

Cloud and outsourcing rules

Official name: International Traffic in Arms Regulations, activities that are not exports · 22 CFR 120.54 · Directly binding regulation

In forceYes, with paperwork

Defence technical data can legally sit on a foreign server, but only under tight conditions. It must be encrypted end to end and strongly. It must not be stored in an embargoed country. Only authorised people may be able to read it. Handing an encryption key to a foreign national breaks the exemption. Routine cloud storage then counts as an unlicensed arms export.

In force since 25 March 2020

Enforced by Directorate of Defense Trade Controls

How this country controls where data goes: Any country except banned ones · Accepted routes: Nothing required, Government sign-off needed

Applies to every company4 rules

These bind you whatever business you are in, once the country's rules reach you.

Government data rules

Official name: Preventing Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons (the Data Security Program) · 28 CFR Part 202, made under Executive Order 14117 · Directly binding regulation

In forceYes, with paperwork

This is the closest thing the United States has to a law on sending data abroad. You may not sell large amounts of Americans' sensitive data to China, Cuba, Iran, North Korea, Russia or Venezuela. You may not give them access to it either. The same goes for people they control. Vendor, staffing and investment deals with those countries are allowed only with strict security controls, annual audits and reporting. Penalties include prison.

In force since 8 April 2025Enforced from 6 October 2025

Enforced by United States Department of Justice, National Security Division

How this country controls where data goes: Any country except banned ones · Accepted routes: Security review needed, Nothing required

Rules for sending data abroad

Official name: Protecting Americans' Data from Foreign Adversaries Act of 2024 · Public Law 118-50, Division I · Act of parliament

In forceYes, with paperwork

A short, blunt law bans data brokers from giving Americans' sensitive data to North Korea, China, Russia or Iran, or to companies they control. Unlike the Justice Department programme, it has no volume limit. There is no way to comply through security controls. The transfer is simply forbidden. The consumer protection regulator sent warning letters to thirteen data brokers in February 2026.

In force since 23 June 2024

Enforced by Federal Trade Commission

How this country controls where data goes: Any country except banned ones

Children's data rules

Official name: Children's Online Privacy Protection Rule, as amended · 16 CFR Part 312 · Directly binding regulation

In forceYes — store it anywhere

The federal children's rule applies to any website or app anywhere in the world aimed at American under-13s. The 2025 changes became fully enforceable on 22 April 2026. They added three things people miss. You need a written retention policy and may not keep children's data forever. You need separate consent before sharing a child's data with advertisers. And you must say who those third parties are. Several state laws set the age at 16 or 18 instead.

In force since 23 June 2025Enforced from 22 April 2026

Enforced by Federal Trade Commission

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies only in certain states2 rules

Made by a state or province. It only binds you for the people living there.

Finance

Cyber security rules

Official name: Cybersecurity Requirements for Financial Services Companies · 23 NYCRR Part 500, as amended 1 November 2023 · Directly binding regulation

In forceYes — store it anywhere

New York's rule covers every bank, insurer, mortgage servicer and cryptocurrency business licensed in the state, wherever they are based. It has the shortest routine deadlines in American financial regulation. You have 72 hours to report an incident and 24 hours to report paying a ransom. The final phase took effect on 1 November 2025 and includes multi-factor authentication for everyone.

In force since 1 December 2023Enforced from 1 November 2025

Enforced by New York State Department of Financial Services

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Cyber security rules (2023)

Official name: California Consumer Privacy Act, as amended by the California Privacy Rights Act, plus around twenty comparable state statutes · California Civil Code 1798.100 et seq.; California Code of Regulations title 11, division 6 · Act of parliament

Partly in forceYes — store it anywhere

This is the layer that binds most businesses. Around twenty states now have a broad privacy law, and none of them says where data must be stored. They require notice, access, correction, deletion and portability. They also require an opt-out of targeted advertising that you honour through an automatic browser signal, plus a published retention schedule. California adds risk assessments from 2026, automated decision-making rights from 2027 and cybersecurity audits from 2028.

In force since 1 January 2020Enforced from 1 July 2023

Enforced by California Privacy Protection Agency

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.

Applies only if you signed a contract1 rule

Usually a government or enterprise contract that adds rules of its own.

Defence

Defence data must stay in the country

Official name: Defense Federal Acquisition Regulation Supplement clause 252.239-7010, Cloud Computing Services · DFARS 252.239-7010 (JAN 2023) · Directly binding regulation

In forceNo — it stays put

If you host anything for the United States military, the data stays on American soil. This comes from a contract clause, not a privacy law. That is exactly why people miss it. It passes down the supply chain and applies to subcontractors. Only a written authorisation from the contracting officer can waive it.

In force since 1 January 2023

Enforced by United States Department of Defense

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

On the books, but not enforceable2 rules

These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.

Health and social care

Health data rules

Official name: HIPAA Privacy Rule to Support Reproductive Health Care Privacy · 45 CFR 164.502(a)(5)(iii), 164.509 and 164.520(b)(1)(ii)(F)-(H) · Directly binding regulation

UnenforceableYes — store it anywhere

This rule is still printed but mostly cannot be enforced. A federal court in Texas struck down the 2024 reproductive health privacy rule nationwide in June 2025. That included the attestation requirement many organisations had already built. The health department confirms the rule was struck down. Only some changes to the privacy notice survive, with a compliance date of 16 February 2026.

In force since 25 June 2024

Enforced by United States Department of Health and Human Services, Office for Civil Rights

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Banking

Banking rules

Official name: Personal Financial Data Rights (Required Rulemaking on Personal Financial Data Rights) · 12 CFR Part 1033 · Directly binding regulation

UnenforceableYes — store it anywhere

This is the American open banking rule. Its text still shows a first compliance date of 1 April 2026 for the largest banks. But a federal court in Kentucky stopped the regulator from enforcing it, and the regulator reopened the rulemaking in August 2025. Treat the printed dates as unreliable and expect a different rule. Reading the code of regulations alone would wrongly suggest this binds you today.

In force since 17 January 2025Enforced from 1 April 2026

Enforced by Consumer Financial Protection Bureau

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.

Who you would hear from

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact number of states with a comprehensive consumer privacy law in force on 18 August 2026 (we say 'around twenty')

    No government source publishes a definitive national count of state privacy laws. Trackers disagree, because some count laws that are passed but not yet in force. Each state law we cite is on a government website. The total figure comes from private trackers. That is why we mark the state-layer rule medium confidence.

  • The 2026 inflation-adjusted California revenue threshold and the 2026 adjusted maximum penalties per violation

    The California attorney general's page still shows the $25 million figure without the inflation adjustment. We could not confirm the regulator's 2025 adjusted figure. So we describe the threshold as about $25 million, adjusted each year.

  • The court order blocking the open banking rule (12 CFR Part 1033)

    Banking press and law firms consistently report an injunction from a federal court in Kentucky in late 2025. We could not confirm the order on a court's own website. Our government links for that rule are the regulator's reconsideration page and the published rule text, not the injunction itself. That is why we mark it medium confidence.

  • That Team Telecom security agreements uniformly require United States records to be stored inside the United States

    We confirmed the foreign-staff vetting duty word for word from the communications regulator's own consent decree. The storage-location clause is standard in the published agreement templates. But each agreement is negotiated case by case and is often not public. So we call this industry mirror-like rather than closed.

  • The exact compliance dates for the amended Regulation S-P (3 December 2025 for larger entities, 3 June 2026 for smaller entities)

    The regulator's fact sheet gives 18 and 24 months from Federal Register publication, not calendar dates. We worked the dates out from the 3 June 2024 publication date. Treat the earlier date as the safe assumption.

  • Whether any enforcement action has been taken under the Data Security Program between the last update of the Justice Department's public actions page and 18 August 2026

    We can show there are no published actions, using the department's own page. We cannot rule out unpublished or sealed cases.

  • State insurance data security laws based on the industry model law

    The model law is published by a private association of state regulators, not a government body. Adoption varies from state to state. We cover insurance through the New York rule instead. That rule is on a government website and covers insurers licensed in New York wherever they are based.

  • That no federal or state rule requires health data or education data to remain in the United States

    We found no rule requiring this. Individual state Medicaid and student data contracts often require data to stay in the United States by contract rather than by law. We did not survey those contracts. If you work in this industry, check before you rely on this.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.