Skip to the content
Global Data RulesData governance rules, country by country

United States

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Depends on your industryWork: HighEnforcement: Active

In general the United States lets data go anywhere. There is no national privacy law and no permit is needed to move data abroad. Two things bite hard. Six countries are effectively off limits for large amounts of sensitive data, with prison sentences attached. And anything connected to government work must physically stay on American soil.

Eight questions about the United States

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do the United States' rules apply to my company?

Yes. American rules reach a foreign company with no office in the country. California's privacy law applies to any for-profit business that 'does business in California' and crosses one of three thresholds, and physical presence is not one of them. The children's rule covers foreign websites aimed at American children. No state and no federal law requires you to appoint a local representative — a real difference from Europe.

High confidenceState or provincial ruleNational rules

Can I store my users' data outside the United States?

It depends entirely on your industry, so the single national answer is misleading. For ordinary consumer or employee data, yes — send it anywhere, no paperwork. But six sectors have hard walls. Government contracting, police data, federal tax data and defence work require the data to physically stay in the United States. Telecom licences restrict which foreign staff may even look at records. And for anyone, sending large volumes of sensitive data to six named countries is now a crime.

High confidenceDepends on your industryBlocklist

What do I need in place before data leaves the United States?

For ordinary data, nothing. No standard contract, no government approval, no destination approval list. The model is a blocklist and it is now populated: six countries are named. Before you move large volumes of sensitive data, your only real job is to work out whether a country of concern, or a company or person they control, could end up with access — including through a vendor, an investor or an employee.

High confidenceBlocklistNothing requiredSecurity review needed

Who enforces the rules in the United States, and what can they do?

Nobody, and everybody. There is no national privacy regulator. Instead the consumer protection regulator, the health department, the securities regulator, the communications regulator, the Justice Department, all fifty state attorneys general and one dedicated state privacy agency each enforce a slice. Almost all of them are visibly working right now. The one exception is the new national data transfer programme: it is staffed and issuing guidance but has published no enforcement action yet.

High confidenceActive

How long do I have to keep the data?

There is a strong floor and a weak but growing ceiling. Investment firms must keep some books for six years and most others for three, with the first two years easy to reach. Health providers keep their paperwork for six years. In the other direction, state privacy laws now force you to publish how long you keep each type of data and to stop keeping it longer than you said, and since April 2026 children's data may no longer be kept indefinitely. Where a keep-it rule and a delete-it rule collide, the keep-it rule wins: every state law carves out data you are required by law to retain.

High confidenceKeep data for a minimum periodDelete data after a periodLet people delete their data

What happens if there is a breach?

Count the clocks — there are at least seven, and they disagree. New York financial firms: 72 hours to the state regulator, and only 24 hours to report paying a ransom. Telecom carriers: seven working days to the police agencies and the communications regulator, and you may not warn customers until seven working days after that. Investment and finance firms: 30 days to affected customers. Health organisations: 60 days. Texas and many other states: 30 days to the state attorney general. Listed companies: four working days to disclose a material incident. The overlap, not any single deadline, is what people fail.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in the United States?

Five that cost people their weekend. One: the national data transfer programme carries prison — up to twenty years for a deliberate breach. Two: Illinois lets individuals sue over fingerprints and face scans with fixed damages per person, no proof of harm needed, and that is where the largest privacy payouts happen. Three: the children's rule uses under 13, but several state laws use under 18, so a single age gate will not do. Four: government work means American soil, and police data allows only the United States, its territories, tribal lands and Canada. Five: a rule can be printed in the law book and still be unenforceable, because a court has blocked it.

High confidenceCriminal liabilityClaims by individualsGet a parent's consent for childrenKeep the data in the countryUnenforceable

What is changing soon in the United States?

Four things in the next twelve months. The national critical infrastructure reporting rule should be finalised in late 2026, which will switch on a 72-hour incident clock and a 24-hour ransom-payment clock for a very wide range of businesses. California's rules on automated decision-making bite on 1 January 2027. The open banking rule is being rewritten after a court blocked it. And a federal privacy bill is moving in Congress, but it is only a bill and binds nobody.

High confidenceProposedPassed, not yet fully in force

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    4 rules here

  2. Layer 2

    State or provincial rule

    Made by a state or province. Only binds you for people in that state.

    2 rules here

  3. Layer 3

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    8 rules here

  4. Layer 4

    Contract-imposed rule

    Binds you because you signed something, typically a government contract.

    1 rule here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules4 rules

Preventing Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons (the Data Security Program)

Directly binding regulation · 28 CFR Part 202, made under Executive Order 14117

In forceYes, with paperwork

The closest thing the United States has to a cross-border transfer law. Large amounts of Americans' sensitive data may not be sold or made accessible to China, Cuba, Iran, North Korea, Russia or Venezuela, or to people they control. Vendor, staffing and investment deals with those countries are allowed only with strict security controls, annual audits and reporting. Penalties include prison.

In force since 8 April 2025But only enforceable from 6 October 2025

Enforced by United States Department of Justice, National Security Division

Transfer model: Blocklist · Accepted routes: Security review needed, Nothing required

High confidence

Protecting Americans' Data from Foreign Adversaries Act of 2024

Act of parliament · Public Law 118-50, Division I

In forceYes, with paperwork

A short, blunt statute that bans data brokers from giving Americans' sensitive data to North Korea, China, Russia or Iran, or to entities they control. Unlike the Justice Department programme it has no volume threshold and no way to comply through security controls — the transfer is simply forbidden. The consumer protection regulator sent warning letters to thirteen data brokers in February 2026.

In force since 23 June 2024

Enforced by Federal Trade Commission

Transfer model: Blocklist

High confidence

Children's Online Privacy Protection Rule, as amended

Directly binding regulation · 16 CFR Part 312

In forceYes — store it anywhere

The federal children's rule applies to any website or app anywhere in the world aimed at American under-13s. The 2025 amendments became fully enforceable on 22 April 2026 and added three things people miss: a written retention policy with no indefinite retention, separate consent before sharing a child's data with advertisers, and disclosure of who those third parties are. Several state laws set the age at 16 or 18 instead.

In force since 23 June 2025But only enforceable from 22 April 2026

Enforced by Federal Trade Commission

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

State or provincial rule2 rules

Cybersecurity Requirements for Financial Services Companies

Directly binding regulation · 23 NYCRR Part 500, as amended 1 November 2023 · Finance

In forceYes — store it anywhere

New York's rule reaches every bank, insurer, mortgage servicer and cryptocurrency business licensed in the state, wherever they are based. It has the shortest routine clocks in American financial regulation: 72 hours to report an incident and 24 hours to report paying a ransom. The final phase, including multi-factor authentication for everyone, took effect on 1 November 2025.

In force since 1 December 2023But only enforceable from 1 November 2025

Enforced by New York State Department of Financial Services

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

California Consumer Privacy Act, as amended by the California Privacy Rights Act, plus around twenty comparable state statutes

Act of parliament · California Civil Code 1798.100 et seq.; California Code of Regulations title 11, division 6

Partly in forceYes — store it anywhere

The layer that actually binds most businesses. Around twenty states now have a comprehensive privacy law, and none of them restricts where the data is stored. What they do require is notice, access, correction, deletion, portability, an opt-out of targeted advertising honoured through an automatic browser signal, and a published retention schedule. California adds risk assessments from 2026, automated decision-making rights from 2027 and cybersecurity audits from 2028.

In force since 1 January 2020But only enforceable from 1 July 2023

Enforced by California Privacy Protection Agency

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence

Industry rules8 rules

Criminal Justice Information Services (CJIS) Security Policy

Government policy document · CJISSECPOL version 6.1 · Government

In forceNo — it stays put

The hardest routine data-location wall in the United States. Police and criminal justice information may only be stored in cloud environments inside the United States, its territories, tribal lands or Canada. Encrypting it does not help — the restriction applies regardless of encryption status. Any vendor to a police force, court or background-check programme inherits this.

In force since 25 June 2026

Enforced by Federal Bureau of Investigation, Criminal Justice Information Services Division

Transfer model: Not allowed

High confidence

Publication 1075, Tax Information Security Guidelines for Federal, State and Local Agencies

Regulator guideline · Made binding through Internal Revenue Code section 6103 safeguard agreements · Government

In forceNo — it stays put

Any organisation that receives federal tax information — state revenue departments, benefits agencies, child support programmes and their contractors — must keep that data, and all access to it, inside the United States and its territories. This is a control condition on receiving the data, not a general privacy rule, so it flows down to every subcontractor.

In force since 1 June 2022

Enforced by Internal Revenue Service

Transfer model: Not allowed

High confidence

International Traffic in Arms Regulations, activities that are not exports

Directly binding regulation · 22 CFR 120.54 · Defence

In forceYes, with paperwork

Defence technical data can legally sit on a foreign server, but only under tight conditions: strong end-to-end encryption, no storage in an embargoed country, and only authorised people able to read it. Handing an encryption key to a foreign national breaks the exemption and turns routine cloud storage into an unlicensed arms export.

In force since 25 March 2020

Enforced by Directorate of Defense Trade Controls

Transfer model: Blocklist · Accepted routes: Nothing required, Government sign-off needed

High confidence

Contract-imposed rule1 rule

Defense Federal Acquisition Regulation Supplement clause 252.239-7010, Cloud Computing Services

Directly binding regulation · DFARS 252.239-7010 (JAN 2023) · Defence

In forceNo — it stays put

If you host anything for the United States military, the data stays on American soil. This is a contract clause rather than a privacy law, which is exactly why it is missed: it binds through the supply chain, applies to subcontractors, and can only be waived by a written authorisation from the contracting officer.

In force since 1 January 2023

Enforced by United States Department of Defense

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Who you would hear from

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact number of states with a comprehensive consumer privacy law in force on 18 August 2026 (we say 'around twenty')

    No single government source publishes a definitive national count; trackers disagree because some count laws that are enacted but not yet commenced. Each individual state law we cite is on a government domain, but the aggregate figure rests on secondary trackers, so the state-layer rule is marked medium confidence.

  • The 2026 inflation-adjusted California revenue threshold and the 2026 adjusted maximum penalties per violation

    The California attorney general's page still states the unadjusted $25 million figure. We could not open the regulator's 2025 adjustment announcement with the current figures, so we describe the threshold as 'about $25 million, adjusted each year'.

  • The court order blocking the open banking rule (12 CFR Part 1033)

    Reported consistently by banking press and law firms as an injunction issued by a federal court in Kentucky in late 2025, but we could not locate the order on a court's own domain. The government backlinks for that rule are the regulator's reconsideration page and the published rule text, not the injunction itself. Confidence lowered to medium.

  • That Team Telecom security agreements uniformly require United States records to be stored inside the United States

    We verified the foreign-personnel vetting obligation verbatim from the communications regulator's own consent decree. The storage-location clause is standard in the published agreement templates but the agreements themselves are negotiated case by case and often not public, so we describe this sector as mirror-like rather than closed.

  • The exact compliance dates for the amended Regulation S-P (3 December 2025 for larger entities, 3 June 2026 for smaller entities)

    The regulator's fact sheet states 18 and 24 months from Federal Register publication rather than the calendar dates. We computed them from the 3 June 2024 publication date; treat the earlier date as the safe assumption.

  • Whether any enforcement action has been taken under the Data Security Program between the last update of the Justice Department's public actions page and 18 August 2026

    We can evidence the absence of published actions from the department's own page, but cannot prove a negative for unpublished or sealed matters.

  • State insurance data security laws based on the industry model law

    The model law is published by a private association of state regulators rather than a government body, and adoption varies state by state. We cover the insurance sector through the New York rule, which is on a government domain and reaches insurers licensed in New York wherever they are based.

  • That no federal or state rule requires health data or education data to remain in the United States

    No such rule found, checked 18 August 2026. Individual state Medicaid and student data contracts frequently impose United States residency by contract rather than by law, and we did not survey those.

60-day cadence. Three dormant switches justify it: the Attorney General can add a country to the countries-of-concern list or designate any person a covered person overnight with no consultation; the critical infrastructure reporting rule could be finalised at any time and would add a 72-hour clock across sixteen sectors; and state legislatures add two to four comprehensive privacy laws per year with short lead times. The court-blocked rules (reproductive health privacy, open banking, the California children's design code) can also move on a single ruling.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.