United States
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
In general the United States lets data go anywhere. There is no national privacy law and no permit is needed to move data abroad. Two things bite hard. Six countries are effectively off limits for large amounts of sensitive data, with prison sentences attached. And anything connected to government work must physically stay on American soil.
Eight questions about the United States
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do the United States' rules apply to my company?
Yes. American rules reach a foreign company with no office in the country. California's privacy law applies to any for-profit business that 'does business in California' and crosses one of three thresholds, and physical presence is not one of them. The children's rule covers foreign websites aimed at American children. No state and no federal law requires you to appoint a local representative — a real difference from Europe.
California Consumer Privacy Act thresholds: gross annual revenue over $25 million (a figure adjusted upward for inflation each year), or buying/selling/sharing the personal information of 100,000 or more California residents or households, or deriving 50% or more of annual revenue from selling California residents' personal information. Most other state privacy laws use a volume test only (commonly 100,000 residents, or 25,000 residents where more than 25% of revenue comes from selling data) and have no revenue floor at all, so a mid-sized foreign business can be caught in one state and not another. The Federal Trade Commission Act reaches conduct affecting United States commerce regardless of where the company sits. The Justice Department's Data Security Program is drafted around 'U.S. persons' but also binds foreign recipients through the transactions it prohibits.
Sources
- Official sourceCalifornia Attorney GeneralCalifornia Consumer Privacy Act — who must comply
oag.ca.gov
“Have a gross annual revenue of over $25 million”
Link checked 18 August 2026
- Official sourceFederal Trade CommissionChildren's Online Privacy Protection Rule
ftc.gov
Link checked 18 August 2026
Can I store my users' data outside the United States?
It depends entirely on your industry, so the single national answer is misleading. For ordinary consumer or employee data, yes — send it anywhere, no paperwork. But six sectors have hard walls. Government contracting, police data, federal tax data and defence work require the data to physically stay in the United States. Telecom licences restrict which foreign staff may even look at records. And for anyone, sending large volumes of sensitive data to six named countries is now a crime.
Sector-by-sector ratings. OPEN (no location rule found, checked 18 August 2026): health under the federal health privacy law; banking and payments under federal banking law; insurance under state insurance data security laws; education under the federal student records law; e-commerce; social media; online gaming; mapping and location data as such. Bank supervisors expect you to manage the legal risk of a foreign-based service provider and to be able to hand records to examiners, but they do not tell you where the servers must sit. CONDITIONAL: everything, because of the Justice Department's Data Security Program. Bulk sensitive data about Americans — genomic, biometric, precise location, health, financial and identifier data above set volume thresholds — may not be sold or made accessible to China (including Hong Kong and Macau), Cuba, Iran, North Korea, Russia or Venezuela, or to people and companies they control. Vendor, employment and investment arrangements with those countries are allowed only with strict security controls, audits and reporting. Defence technical data may sit on a foreign server only if it is end-to-end encrypted to a strong standard, is not stored in an embargoed country, and is only readable by authorised people. CLOSED: federal tax information handled for the tax authority; criminal justice information under the police data policy, which allows only the United States, its territories, tribal lands and Canada; Department of Defense cloud contracts, where government data must be maintained in the United States or its outlying areas unless a contracting officer says otherwise in writing. MIRROR-LIKE: telecom carriers holding foreign investment. Their agreements with the security agencies require United States records to be kept where American authorities can reach them and require prior government vetting before foreign staff are given access.
Sources
- Official sourceUnited States Department of JusticeData Security Program — National Security Division
justice.gov
“establishes what are effectively export controls that prohibit or restrict countries of concern ... from engaging in certain categories of transactions with U.S. persons that can give them access to U.S. Government-related data or Americans' bulk genomic, geolocation, biometric, health, financial, or other sensitive personal data.”
Link checked 18 August 2026
- Official sourceElectronic Code of Federal RegulationsCountries of concern, 28 CFR 202.601
ecfr.gov
Link checked 18 August 2026
- Official sourceInternal Revenue ServicePublication 1075 — Tax Information Security Guidelines, offshore operations
irs.gov
“restrict the accessing, processing, storage, and transmission of FTI to the United States and its territories”
Link checked 18 August 2026
- Official sourceFederal Bureau of Investigation, Criminal Justice Information Services DivisionCJIS Security Policy version 6.1, 25 June 2026 — storage of criminal justice information
le.fbi.gov
“The storage of CJI, regardless of encryption status, shall only be permitted in cloud environments ... which reside within the physical boundaries of APB-member country (i.e., United States, U.S. territories, Indian Tribes, and Canada)”
Link checked 18 August 2026
- Official sourceAcquisition.govDefense Federal Acquisition Regulation Supplement clause 252.239-7010, Cloud Computing Services
acquisition.gov
“The Contractor shall maintain within the United States or outlying areas all Government data that is not physically located on DoD premises”
Link checked 18 August 2026
- Official sourceBoard of Governors of the Federal Reserve SystemInteragency Guidance on Third-Party Relationships: Risk Management (SR 23-4)
federalreserve.gov
“third parties whose servicing operations are located in a foreign country and subject to the law and jurisdiction of that country”
Link checked 18 August 2026
What do I need in place before data leaves the United States?
For ordinary data, nothing. No standard contract, no government approval, no destination approval list. The model is a blocklist and it is now populated: six countries are named. Before you move large volumes of sensitive data, your only real job is to work out whether a country of concern, or a company or person they control, could end up with access — including through a vendor, an investor or an employee.
The Justice Department programme splits transactions into three buckets. Prohibited: data brokerage with a country of concern or a covered person, and any transfer of bulk human genomic data or the biospecimens behind it. Restricted: vendor, employment and investment agreements, which are permitted only with a defined security programme, annual independent audits and record-keeping. Exempt: ordinary corporate group administration, official business of the United States government, financial services activity, regulatory approvals, and personal communications. Volume thresholds trigger the rules: more than 100 people for genomic data, 1,000 for biometric data, 1,000 devices for precise location, 10,000 people for health or financial data, and 100,000 people for basic identifiers, measured over any rolling twelve months. Separately, data brokers may not sell sensitive data to North Korea, China, Russia or Iran at all under a 2024 statute enforced by the consumer protection regulator, with no volume threshold and no exemption for restricted transactions.
Sources
- Official sourceElectronic Code of Federal RegulationsBulk thresholds, 28 CFR 202.205
ecfr.gov
“more than 100 U.S. persons ... more than 1,000 U.S. persons ... more than 1,000 U.S. devices ... more than 10,000 U.S. persons ... more than 100,000 U.S. persons”
Link checked 18 August 2026
- Official sourceFederal Trade CommissionProtecting Americans' Data from Foreign Adversaries Act of 2024
ftc.gov
Link checked 18 August 2026
- Official sourceElectronic Code of Federal Regulations22 CFR 120.54 — activities that are not exports, including encrypted technical data
ecfr.gov
Link checked 18 August 2026
Who enforces the rules in the United States, and what can they do?
Nobody, and everybody. There is no national privacy regulator. Instead the consumer protection regulator, the health department, the securities regulator, the communications regulator, the Justice Department, all fifty state attorneys general and one dedicated state privacy agency each enforce a slice. Almost all of them are visibly working right now. The one exception is the new national data transfer programme: it is staffed and issuing guidance but has published no enforcement action yet.
Observable evidence gathered on 18 August 2026. The Federal Trade Commission finalised an order against a car maker and its connected-car arm over selling driver location data in January 2026, sued two dating apps in March 2026 over sharing personal data, and finalised an order against an education technology company over student data in June 2026; in February 2026 it sent warning letters to thirteen data brokers about selling sensitive data to foreign adversaries. California's privacy agency has issued a run of fines including $1.35 million against a rural retailer in September 2025 and $632,500 against a car maker, and opened a fresh round of data broker cases in January 2026. The Texas attorney general sued a group of Chinese-linked companies in May 2025 and warned over a hundred firms about the state data broker law. The communications regulator issued its first ever penalty for breaching a national security agreement in January 2026. The health department continues to settle security cases. Against that, the Justice Department's data security unit lists no public enforcement action, licence or advisory opinion under the programme as of 18 August 2026 — it is staffed and publishing guidance, but has not yet bitten.
Sources
- Official sourceFederal Trade CommissionFTC reminds data brokers of their obligations to comply with PADFAA, 9 February 2026
ftc.gov
“The FTC is committed to enforcing PADFAA and ensuring companies are complying with its requirements.”
Link checked 18 August 2026
- Official sourceCalifornia Privacy Protection AgencyCalifornia Privacy Protection Agency — enforcement announcements 2025 and 2026
cppa.ca.gov
Link checked 18 August 2026
- Official sourceUnited States Department of JusticeNational Security Division — public actions (no Data Security Program enforcement action listed)
justice.gov
Link checked 18 August 2026
- Official sourceFederal Communications CommissionFCC order and consent decree DA 26-25, 8 January 2026 — first penalty for breaching a national security agreement
docs.fcc.gov
Link checked 18 August 2026
- Official sourceOffice of the Attorney General of TexasTexas attorney general takes legal action against Chinese companies, 6 May 2025
texasattorneygeneral.gov
Link checked 18 August 2026
How long do I have to keep the data?
There is a strong floor and a weak but growing ceiling. Investment firms must keep some books for six years and most others for three, with the first two years easy to reach. Health providers keep their paperwork for six years. In the other direction, state privacy laws now force you to publish how long you keep each type of data and to stop keeping it longer than you said, and since April 2026 children's data may no longer be kept indefinitely. Where a keep-it rule and a delete-it rule collide, the keep-it rule wins: every state law carves out data you are required by law to retain.
Floors. Broker-dealer records: six years for the core books with two years in an easily accessible place, three years for most operational records, and for the life of the business for formation documents; customer account records run six years past account closure. Health privacy documentation: six years. Tax records: the tax authority's normal periods, commonly three to seven years depending on the item. Investment advisers and funds have parallel rules. Ceilings. The California regulations require a retention schedule and disclosure of retention periods; the amended children's rule requires a written retention policy, bans indefinite retention, and requires deletion once the original purpose is met; state consumer privacy laws give a deletion right subject to a legal-obligation exception. Note that no state deletion right overrides a federal retention duty — the statutes say so explicitly rather than leaving it to interpretation.
Sources
- Official sourceElectronic Code of Federal RegulationsSEC Rule 17a-4 — records to be preserved by brokers and dealers
ecfr.gov
Link checked 18 August 2026
- Official sourceFederal RegisterChildren's Online Privacy Protection Rule, final amendments — retention and deletion requirements
federalregister.gov
Link checked 18 August 2026
- Official sourceCalifornia Privacy Protection AgencyCalifornia Consumer Privacy Act regulations — retention, risk assessments and cybersecurity audits
cppa.ca.gov
Link checked 18 August 2026
What happens if there is a breach?
Count the clocks — there are at least seven, and they disagree. New York financial firms: 72 hours to the state regulator, and only 24 hours to report paying a ransom. Telecom carriers: seven working days to the police agencies and the communications regulator, and you may not warn customers until seven working days after that. Investment and finance firms: 30 days to affected customers. Health organisations: 60 days. Texas and many other states: 30 days to the state attorney general. Listed companies: four working days to disclose a material incident. The overlap, not any single deadline, is what people fail.
Deadlines verified 18 August 2026. New York Department of Financial Services rule Part 500: notify within 72 hours of determining a cybersecurity incident occurred; extortion payments reported within 24 hours. Communications regulator rule at 47 CFR 64.2011: notify the Federal Bureau of Investigation, the Secret Service and the Commission as soon as practicable and no later than seven business days after a reasonable determination of a breach, then wait seven business days before notifying customers unless law enforcement extends the hold; the Sixth Circuit upheld these rules, so they are live and not merely on the books. Amended Regulation S-P: notify affected individuals as soon as practicable and no later than 30 days after becoming aware of unauthorised access, with compliance from December 2025 for larger firms and June 2026 for smaller ones. Consumer protection regulator's Safeguards Rule: report security events affecting 500 or more consumers within 30 days. Health privacy rule: individuals, the health department and, above 500 residents of one state, the media within 60 days; smaller breaches reported annually within 60 days of year end. Texas: 30 days to the attorney general where 250 or more Texans are affected. Securities disclosure rule: Form 8-K within four business days of deciding an incident is material. The national critical infrastructure reporting law adds 72-hour incident and 24-hour ransom-payment duties but is not yet switched on — see question eight.
Sources
- Official sourceUnited States Department of Health and Human Services, Office for Civil RightsBreach Notification Rule — 60-day deadlines
hhs.gov
“without unreasonable delay and in no case later than 60 days following the discovery of a breach”
Link checked 18 August 2026
- Official sourceElectronic Code of Federal Regulations47 CFR 64.2011 — notification of customer proprietary network information security breaches
ecfr.gov
“As soon as practicable, and in no event later than seven (7) business days, after reasonable determination of the breach”
Link checked 18 August 2026
- Official sourceNew York State Department of Financial ServicesNew York Department of Financial Services cybersecurity regulation Part 500
dfs.ny.gov
“as promptly as possible but in no event later than 72 hours after determining that a Cybersecurity Incident has occurred”
Link checked 18 August 2026
- Official sourceUnited States Securities and Exchange CommissionFact sheet — final rules, enhancements to Regulation S-P
sec.gov
“not later than 30 days, after becoming aware that unauthorized access to or use of customer information has occurred”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General of TexasData breach reporting to the Texas attorney general
texasattorneygeneral.gov
“affects 250 or more Texans to report that breach to the Office of the Texas Attorney General as soon as practicably possible and no later than 30 days after the discovery of the breach”
Link checked 18 August 2026
What trips people up in the United States?
Five that cost people their weekend. One: the national data transfer programme carries prison — up to twenty years for a deliberate breach. Two: Illinois lets individuals sue over fingerprints and face scans with fixed damages per person, no proof of harm needed, and that is where the largest privacy payouts happen. Three: the children's rule uses under 13, but several state laws use under 18, so a single age gate will not do. Four: government work means American soil, and police data allows only the United States, its territories, tribal lands and Canada. Five: a rule can be printed in the law book and still be unenforceable, because a court has blocked it.
Trap one. The data transfer programme runs on emergency economic powers, so penalties are civil up to the greater of $368,136 or twice the value of the transaction, and criminal up to $1,000,000 with up to twenty years' imprisonment for a natural person acting wilfully. This is not an administrative privacy fine. Trap two. The Illinois biometric statute gives a private right of action with liquidated damages of $1,000 for negligent and $5,000 for reckless or intentional violations. A 2024 amendment (Public Act 103-0769) limits recovery to a single claim per person per method of collection rather than per scan, which cut the theoretical exposure enormously but did not remove it. Washington's health data statute also carries a private right of action. Trap three. The federal children's rule covers under 13. State design-code and social-media laws reach under 18 or under 16. The amended federal rule became fully enforceable on 22 April 2026 and now requires a written data retention policy, separate consent for targeted advertising, and disclosure of the third parties that receive children's data. Trap four. Criminal justice information may only be stored in the United States, its territories, tribal lands or Canada, and the metadata derived from it is protected the same way and may not be used for advertising. Federal tax information must stay in the United States and its territories. Department of Defense cloud contracts require government data to be maintained in the United States or outlying areas. Trap five. Two live examples. Most of the 2024 health rule on reproductive health privacy was struck down nationwide in 2025 and no longer applies, although some notice changes survived with a compliance date of 16 February 2026. And most of California's children's design code has been enjoined since 2022; in March 2026 the appeal court kept the injunction over the data-use and dark-pattern provisions and lifted it over the rest, so parts of that law are enforceable and parts are not.
Sources
- Official sourceElectronic Code of Federal Regulations28 CFR Part 202 subpart M — penalties
ecfr.gov
“fined not more than $1,000,000, or if a natural person, may be imprisoned for not more than 20 years, or both”
Link checked 18 August 2026
- Official sourceIllinois General AssemblyIllinois Public Act 103-0769 — amendment to the Biometric Information Privacy Act
ilga.gov
Link checked 18 August 2026
- Official sourceUnited States Court of Appeals for the Ninth CircuitNetChoice, LLC v. Bonta, No. 25-2366, 12 March 2026
cdn.ca9.uscourts.gov
“we AFFIRM the district court's preliminary injunction insofar as it enjoined enforcement of California Civil Code 1798.99.31(b)(1)-(4) and 1798.99.31(b)(7), and VACATE the remainder of the preliminary injunction.”
Link checked 18 August 2026
- Official sourceUnited States Department of Health and Human ServicesReproductive health privacy rule — status after Purl v. HHS
hhs.gov
“The court vacated only the provisions that were deemed unlawful, namely 164.520(b)(1)(ii)(F), (G), and (H).”
Link checked 18 August 2026
- Official sourceFederal Bureau of InvestigationCJIS Security Policy version 6.1 — metadata and storage restrictions
le.fbi.gov
“Metadata derived from unencrypted CJI shall be protected in the same manner as CJI and shall not be used for any advertising or other commercial purposes by any cloud service provider or other associated entity.”
Link checked 18 August 2026
What is changing soon in the United States?
Four things in the next twelve months. The national critical infrastructure reporting rule should be finalised in late 2026, which will switch on a 72-hour incident clock and a 24-hour ransom-payment clock for a very wide range of businesses. California's rules on automated decision-making bite on 1 January 2027. The open banking rule is being rewritten after a court blocked it. And a federal privacy bill is moving in Congress, but it is only a bill and binds nobody.
Dated items. The critical infrastructure reporting rule: the agency's own page still says organisations are not required to report until the effective date of the final rule, which has slipped repeatedly through 2025 and 2026. Automated decision-making: businesses using such technology for significant decisions must comply from 1 January 2027; risk assessments began on 1 January 2026 with first submissions due by 1 April 2028; cybersecurity audit submissions start 1 April 2028 for businesses over $100 million of revenue, 2029 between $50 million and $100 million, and 2030 below $50 million. Open banking: the finance regulator reopened the rulemaking in August 2025 and a federal court has blocked enforcement of the existing version, whose first compliance date was 1 April 2026. Health security rule: a proposal to tighten the health security rule was published in January 2025 and has not been finalised. Federal bills, including the SECURE Data Act introduced in April 2026, remain proposals. Dormant switches — powers already held that can change the picture overnight. First and largest: the Attorney General can add a country to the countries-of-concern list by determination, and can designate any person as a covered person, with no consultation and no notice period. Second: the communications regulator's Covered List of untrusted suppliers can be expanded, and a rulemaking opened in April 2026 to strip listed entities of blanket authority to provide domestic services. Third: export control designations can move technical data into a restricted category without legislation. Fourth: state attorneys general in Texas and California have shown they will open sweeps against whole categories of company on days' notice.
Sources
- Official sourceCybersecurity and Infrastructure Security AgencyCyber Incident Reporting for Critical Infrastructure Act of 2022 — status
cisa.gov
“Organizations are not required to submit cyber incident or ransomware payment reports under CIRCIA until the yet-to-be-determined effective date of the Final Rule.”
Link checked 18 August 2026
- Official sourceCalifornia Privacy Protection AgencyCalifornia finalises regulations on automated decision-making, risk assessments and cybersecurity audits
cppa.ca.gov
“Businesses that use ADMT to make significant decisions must comply with the ADMT requirements beginning January 1, 2027.”
Link checked 18 August 2026
- Official sourceConsumer Financial Protection BureauPersonal Financial Data Rights Reconsideration
consumerfinance.gov
Link checked 18 August 2026
- Official sourceCongress.gov, Library of CongressConsumer Data Privacy and Security Act of 2026 (S.4211) — a bill, no legal effect
congress.gov
Link checked 18 August 2026
- Official sourceFederal RegisterProposed rule to strengthen the health security rule, 6 January 2025 — not finalised
federalregister.gov
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
4 rules here
Layer 2
State or provincial rule
Made by a state or province. Only binds you for people in that state.
2 rules here
Layer 3
Industry rules
Made by an industry regulator. These usually beat the general position.
8 rules here
Layer 4
Contract-imposed rule
Binds you because you signed something, typically a government contract.
1 rule here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules4 rules
Preventing Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons (the Data Security Program)
Directly binding regulation · 28 CFR Part 202, made under Executive Order 14117
The closest thing the United States has to a cross-border transfer law. Large amounts of Americans' sensitive data may not be sold or made accessible to China, Cuba, Iran, North Korea, Russia or Venezuela, or to people they control. Vendor, staffing and investment deals with those countries are allowed only with strict security controls, annual audits and reporting. Penalties include prison.
Enforced by United States Department of Justice, National Security Division
Transfer model: Blocklist · Accepted routes: Security review needed, Nothing required
What it makes you do
- Put a transfer safeguard in placeRestricted transactions — vendor, employment and investment agreements with a country of concern or covered person — require a defined security programme built on the national cyber agency's security requirements.
- Independent audit — from 6 October 2025Annual independent audit for restricted transactions.
- Keep records of processing — 10 years, from 6 October 2025Annual reports, and reports of rejected prohibited transactions.
- Keep the data in the countryNot a general localisation duty. Bulk human genomic data and the biospecimens behind it may not go to a country of concern at all.
What it costs if you get it wrong
- Fixed maximum fine: $368,136 or twice the transaction value, whichever is greater — about $368 thousandCivil penalty for any violation
- Criminal liability: $1,000,000 fine and up to 20 years' imprisonment — about $1 millionWilful violation
Sources
- Official sourceUnited States Department of Justice, National Security DivisionData Security Program
justice.gov
“due diligence and audits for restricted transactions (subpart J), annual reports (202.1103), and reports on rejected prohibited transactions (202.1104)”
Link checked 18 August 2026
- Official sourceElectronic Code of Federal Regulations28 CFR Part 202 — Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons
ecfr.gov
Link checked 18 August 2026
- Official sourceUnited States Department of JusticeJustice Department implements critical national security program, 11 April 2025
justice.gov
“NSD will not prioritize civil enforcement actions against any person for violations of the Data Security Program that occur from April 8 through July 8, 2025, so long as the person is engaging in good faith efforts to comply.”
Link checked 18 August 2026
Protecting Americans' Data from Foreign Adversaries Act of 2024
Act of parliament · Public Law 118-50, Division I
A short, blunt statute that bans data brokers from giving Americans' sensitive data to North Korea, China, Russia or Iran, or to entities they control. Unlike the Justice Department programme it has no volume threshold and no way to comply through security controls — the transfer is simply forbidden. The consumer protection regulator sent warning letters to thirteen data brokers in February 2026.
Enforced by Federal Trade Commission
Transfer model: Blocklist
What it makes you do
- Put a transfer safeguard in placeApplies to data brokers only, but the definition of data broker is broad and there is no volume threshold.
What it costs if you get it wrong
- Fixed maximum fine: $53,088 per violation — about $53 thousandSelling, releasing, disclosing or providing access to Americans' sensitive data to a foreign adversary
Sources
- Official sourceFederal Trade CommissionProtecting Americans' Data from Foreign Adversaries Act of 2024
ftc.gov
Link checked 18 August 2026
- Official sourceFederal Trade CommissionFTC reminds data brokers of their obligations to comply with PADFAA, 9 February 2026
ftc.gov
Link checked 18 August 2026
- Official sourceCongress.gov, Library of CongressH.R.7520 — Protecting Americans' Data from Foreign Adversaries Act of 2024, text
congress.gov
Link checked 18 August 2026
Children's Online Privacy Protection Rule, as amended
Directly binding regulation · 16 CFR Part 312
The federal children's rule applies to any website or app anywhere in the world aimed at American under-13s. The 2025 amendments became fully enforceable on 22 April 2026 and added three things people miss: a written retention policy with no indefinite retention, separate consent before sharing a child's data with advertisers, and disclosure of who those third parties are. Several state laws set the age at 16 or 18 instead.
Enforced by Federal Trade Commission
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Get a parent's consent for children — applies at: under 13, from 22 April 2026Separate, additional consent is now needed before disclosing a child's data to third parties for advertising.
- Delete data after a period — from 22 April 2026A written retention policy is required; children's data may not be kept indefinitely and must be deleted once the collection purpose is met.
- Tell people what you do — from 22 April 2026The identities or categories of third parties receiving children's data must be disclosed.
- Secure the data — from 22 April 2026A written children's data security programme.
What it costs if you get it wrong
- Fixed maximum fine: Civil penalties per violation under the Federal Trade Commission Act, adjusted annuallyEach affected child can count as a separate violation
Sources
- Official sourceFederal RegisterChildren's Online Privacy Protection Rule, final amendments, 22 April 2025
federalregister.gov
Link checked 18 August 2026
- Official sourceFederal Trade CommissionChildren's Online Privacy Protection Rule
ftc.gov
Link checked 18 August 2026
- Official sourceElectronic Code of Federal Regulations16 CFR Part 312
ecfr.gov
Link checked 18 August 2026
Cyber Incident Reporting for Critical Infrastructure Act of 2022
Act of parliament · 6 U.S.C. 681b; implementing rule at 6 CFR Part 226 not yet final
The biggest incident-reporting duty in American law, and it is not switched on. The statute passed in 2022 but the implementing rule has slipped repeatedly and the agency's own page still says nobody has to report until the final rule takes effect. When it lands it will add a 72-hour incident clock and a 24-hour ransom-payment clock across sixteen critical infrastructure sectors.
Enforced by Cybersecurity and Infrastructure Security Agency
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — within 72 hoursNot yet enforceable. 72 hours for a substantial cyber incident and 24 hours for a ransom payment, once the final rule takes effect.
What it costs if you get it wrong
- Fixed maximum fineSubpoena, referral to the Justice Department and contractor suspension, once in force
Sources
- Official sourceCybersecurity and Infrastructure Security AgencyCyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)
cisa.gov
“Organizations are not required to submit cyber incident or ransomware payment reports under CIRCIA until the yet-to-be-determined effective date of the Final Rule.”
Link checked 18 August 2026
State or provincial rule2 rules
Cybersecurity Requirements for Financial Services Companies
Directly binding regulation · 23 NYCRR Part 500, as amended 1 November 2023 · Finance
New York's rule reaches every bank, insurer, mortgage servicer and cryptocurrency business licensed in the state, wherever they are based. It has the shortest routine clocks in American financial regulation: 72 hours to report an incident and 24 hours to report paying a ransom. The final phase, including multi-factor authentication for everyone, took effect on 1 November 2025.
Enforced by New York State Department of Financial Services
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — within 72 hours72 hours from determining a cybersecurity incident occurred.
- Report breaches to the regulator — within 24 hours24 hours to report making an extortion payment, plus a written explanation within 30 days.
- Appoint a data protection officerA chief information security officer who reports to the board in writing at least annually.
- Secure the data — from 1 November 2025Final phase: multi-factor authentication for all individuals accessing information systems, and a full asset inventory.
- Independent auditAnnual certification of compliance, or written acknowledgement of non-compliance with a remediation plan, signed by the chief executive and the security officer.
What it costs if you get it wrong
- Fixed maximum finePer-violation penalties under New York banking, insurance and financial services law
- Loss of your licenceLoss of a New York licence
Sources
- Official sourceNew York State Department of Financial ServicesCybersecurity Resource Center — Part 500
dfs.ny.gov
“as promptly as possible but in no event later than 72 hours after determining that a Cybersecurity Incident has occurred”
Link checked 18 August 2026
California Consumer Privacy Act, as amended by the California Privacy Rights Act, plus around twenty comparable state statutes
Act of parliament · California Civil Code 1798.100 et seq.; California Code of Regulations title 11, division 6
The layer that actually binds most businesses. Around twenty states now have a comprehensive privacy law, and none of them restricts where the data is stored. What they do require is notice, access, correction, deletion, portability, an opt-out of targeted advertising honoured through an automatic browser signal, and a published retention schedule. California adds risk assessments from 2026, automated decision-making rights from 2027 and cybersecurity audits from 2028.
Enforced by California Privacy Protection Agency
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people objectOpt out of sale, sharing and targeted advertising, including through an automatic browser signal.
- Delete data after a periodYou must publish how long you keep each category and must not keep it longer than disclosed.
- Written vendor contract
- Assess high-risk projects — from 1 January 2026Risk assessments from 1 January 2026; first attestation to the regulator by 1 April 2028.
- Limit automated decisions — from 1 January 2027Automated decision-making rights bite on 1 January 2027.
- Independent audit — from 1 April 2028Cybersecurity audits phased by revenue: 2028 above $100m, 2029 between $50m and $100m, 2030 below $50m.
- Register or notifyData brokers must register and honour a single statewide deletion request platform.
What it costs if you get it wrong
- Fixed maximum fine: $2,500 per violation, $7,500 per intentional violation or violation involving a minor, adjusted for inflation — about $8 thousandEach affected consumer counts as a separate violation
- Claims by individualsStatutory damages for a data breach caused by unreasonable security
Sources
- Official sourceCalifornia Attorney GeneralCalifornia Consumer Privacy Act
oag.ca.gov
Link checked 18 August 2026
- Official sourceCalifornia Privacy Protection AgencyCalifornia finalises regulations to strengthen consumer privacy protections, 23 September 2025
cppa.ca.gov
“The regulations go into effect January 1, 2026.”
Link checked 18 August 2026
- Official sourceCalifornia Privacy Protection AgencyCalifornia Consumer Privacy Act statute text effective 1 January 2026
cppa.ca.gov
Link checked 18 August 2026
- Official sourceOffice of the Attorney General of TexasTexas Data Privacy and Security Act
texasattorneygeneral.gov
Link checked 18 August 2026
Industry rules8 rules
Criminal Justice Information Services (CJIS) Security Policy
Government policy document · CJISSECPOL version 6.1 · Government
The hardest routine data-location wall in the United States. Police and criminal justice information may only be stored in cloud environments inside the United States, its territories, tribal lands or Canada. Encrypting it does not help — the restriction applies regardless of encryption status. Any vendor to a police force, court or background-check programme inherits this.
Enforced by Federal Bureau of Investigation, Criminal Justice Information Services Division
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryStorage permitted only within the United States, its territories, Indian tribal lands and Canada, and only under the legal authority of a member agency. Encryption does not lift the restriction.
- Written vendor contractCloud providers may not use metadata derived from unencrypted criminal justice information for advertising or any other commercial purpose.
- Secure the dataEncryption at rest to FIPS 140-3 with at least a 256-bit symmetric key, or FIPS 197 with at least 256 bits, outside physically secure locations.
What it costs if you get it wrong
- Order to stopSanctions up to termination of access to the national criminal justice systems
Sources
- Official sourceFederal Bureau of Investigation, Criminal Justice Information Services DivisionCJIS Security Policy version 6.1, 25 June 2026
le.fbi.gov
“The storage of CJI, regardless of encryption status, shall only be permitted in cloud environments (e.g., government or third-party/commercial datacenters, etc.) which reside within the physical boundaries of APB-member country (i.e., United States, U.S. territories, Indian Tribes, and Canada) and are under legal authority of an APB-member agency”
Link checked 18 August 2026
Publication 1075, Tax Information Security Guidelines for Federal, State and Local Agencies
Regulator guideline · Made binding through Internal Revenue Code section 6103 safeguard agreements · Government
Any organisation that receives federal tax information — state revenue departments, benefits agencies, child support programmes and their contractors — must keep that data, and all access to it, inside the United States and its territories. This is a control condition on receiving the data, not a general privacy rule, so it flows down to every subcontractor.
Enforced by Internal Revenue Service
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryAccess, processing, storage and transmission of federal tax information restricted to the United States and its territories.
- Independent auditSafeguard reporting and on-site reviews by the tax authority.
What it costs if you get it wrong
- Criminal liabilityUnauthorised disclosure or inspection of federal tax information is a criminal offence under the tax code
- Order to stopSuspension of the agency's access to federal tax information
Sources
- Official sourceInternal Revenue ServicePublication 1075 — offshore operations, control SA-9(5)
irs.gov
“Control Enhancement to restrict the accessing, processing, storage, and transmission of FTI to the United States and its territories.”
Link checked 18 August 2026
- Official sourceInternal Revenue ServiceEncryption requirements of Publication 1075
irs.gov
Link checked 18 August 2026
International Traffic in Arms Regulations, activities that are not exports
Directly binding regulation · 22 CFR 120.54 · Defence
Defence technical data can legally sit on a foreign server, but only under tight conditions: strong end-to-end encryption, no storage in an embargoed country, and only authorised people able to read it. Handing an encryption key to a foreign national breaks the exemption and turns routine cloud storage into an unlicensed arms export.
Enforced by Directorate of Defense Trade Controls
Transfer model: Blocklist · Accepted routes: Nothing required, Government sign-off needed
What it makes you do
- Secure the dataEnd-to-end encryption, or a validated cryptographic module, or comparable strength of at least 128 bits. Keys must not be given to a foreign person or a foreign government.
- Put a transfer safeguard in placeData must not be intentionally sent to or stored in an embargoed country, and the recipient must be the originator, a US person in the United States, or someone otherwise authorised.
What it costs if you get it wrong
- Criminal liabilityUnauthorised export of defence technical data
- Fixed maximum fineCivil penalties per violation under the arms export control statute
Sources
- Official sourceElectronic Code of Federal Regulations22 CFR 120.54 — activities that are not exports, reexports, retransfers or temporary imports
ecfr.gov
“not intentionally sent to a person in or stored in a country proscribed in 126.1 of this subchapter”
Link checked 18 August 2026
National security agreement / letter of assurance conditioning a section 214 authorisation, reviewed by the Committee for the Assessment of Foreign Participation in the United States Telecommunications Services Sector
Licence condition · Executive Order 13913; enforced in FCC DA 26-25, File No. EB-TCD-00038619 · Telecoms
Telecom carriers with foreign owners sign a security agreement as the price of their licence. It controls where United States records sit and, critically, which foreign staff may touch them. In January 2026 the communications regulator issued its first ever penalty under one of these agreements, against a satellite communications provider that gave 186 foreign employees access without prior government vetting.
Enforced by Federal Communications Commission
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryUnited States records and domestic communications infrastructure must remain within reach of American authorities; access by foreign-person employees requires prior government vetting.
- Do not hand data to foreign authorities on demandCarriers must notify the Justice Department at least 30 days before granting a foreign-person employee access to United States records or domestic communications infrastructure.
- Register or notifyApplies to carriers with reportable foreign ownership holding an international section 214 authorisation or an earth station licence.
What it costs if you get it wrong
- Fixed maximum fine: $175,000 in the first case — about $175 thousandFailure to submit foreign employees for vetting before granting access
- Loss of your licenceBreach of a national security agreement can cost the operating authorisation
Sources
- Official sourceFederal Communications Commission, Enforcement BureauOrder and consent decree, DA 26-25, 8 January 2026
docs.fcc.gov
“notify [DOJ] of all its Foreign person employees that it intends to allow Access to U.S. Records, [Domestic Communications], or [Domestic Communications Infrastructure]”
Link checked 18 August 2026
Notification of customer proprietary network information security breaches
Directly binding regulation · 47 CFR 64.2011 · Telecoms
Telecom and voice-over-internet providers must report a breach of call and connection records to two federal police agencies and the communications regulator within seven working days, then tell customers — but not before another seven working days have passed. There is no minimum number of affected customers. The Sixth Circuit upheld these rules, so they are live rather than merely printed.
Enforced by Federal Communications Commission
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report breaches to the regulator — within 168 hoursSeven business days to the Federal Bureau of Investigation, the Secret Service and the Commission after a reasonable determination that a breach occurred.
- Tell affected peopleCustomers notified after law enforcement, and not sooner than seven business days after the law enforcement notice unless the agencies agree otherwise.
What it costs if you get it wrong
- Fixed maximum fineForfeiture penalties for breach of the communications rules
Sources
- Official sourceElectronic Code of Federal Regulations47 CFR 64.2011
ecfr.gov
“As soon as practicable, and in no event later than seven (7) business days, after reasonable determination of the breach”
Link checked 18 August 2026
- Official sourceFederal RegisterData Breach Reporting Requirements, final rule
federalregister.gov
Link checked 18 August 2026
HIPAA Privacy Rule to Support Reproductive Health Care Privacy
Directly binding regulation · 45 CFR 164.502(a)(5)(iii), 164.509 and 164.520(b)(1)(ii)(F)-(H) · Health and social care
A textbook case of a rule that is still printed but mostly unenforceable. A federal court in Texas struck down the 2024 reproductive health privacy rule nationwide in June 2025, including the attestation requirement that many organisations had already built. The health department confirms the vacatur; only some notice-of-privacy-practices changes survive, with a compliance date of 16 February 2026.
Enforced by United States Department of Health and Human Services, Office for Civil Rights
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Tell people what you do — from 16 February 2026The notice-of-privacy-practices changes that survived the ruling still had to be implemented by 16 February 2026.
What it costs if you get it wrong
- Fixed maximum fineHealth privacy penalties still apply to the surviving provisions
Sources
- Official sourceUnited States Department of Health and Human Services, Office for Civil RightsReproductive health care privacy — status after Purl v. HHS
hhs.gov
“The court vacated only the provisions that were deemed unlawful, namely 164.520(b)(1)(ii)(F), (G), and (H). The remaining modifications to the NPP requirements are undisturbed and remain in effect.”
Link checked 18 August 2026
Personal Financial Data Rights (Required Rulemaking on Personal Financial Data Rights)
Directly binding regulation · 12 CFR Part 1033 · Banking
The American open banking rule. Its text still shows a first compliance date of 1 April 2026 for the largest banks, but a federal court in Kentucky blocked the regulator from enforcing it and the regulator reopened the rulemaking in August 2025. Treat the printed dates as unreliable and expect a different rule. A naive reading of the code of regulations would wrongly report this as binding today.
Enforced by Consumer Financial Protection Bureau
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Let people take their data elsewhere — applies at: Banks with at least $250bn of assets and non-banks with at least $10bn of receipts first; smaller tiers to 2030, from 1 April 2026Compliance dates are printed in the rule but a federal court has blocked enforcement while the regulator rewrites it.
- Written vendor contractThird-party access conditions and data-use limits for authorised recipients.
What it costs if you get it wrong
- Fixed maximum fineConsumer financial law penalties, currently not being applied
Sources
- Official sourceConsumer Financial Protection BureauPersonal Financial Data Rights Reconsideration — advance notice of proposed rulemaking, 22 August 2025
consumerfinance.gov
Link checked 18 August 2026
- Official sourceConsumer Financial Protection Bureau12 CFR 1033.121 — compliance dates as currently published
consumerfinance.gov
Link checked 18 August 2026
- Secondary sourceCozen O'ConnorSection 1033 compliance date: open banking rule enjoined and under reconsideration
cozen.com
Link checked 18 August 2026
Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information, as amended
Directly binding regulation · 17 CFR Part 248; Release 34-100155 · Securities
Investment firms, brokers and funds must tell affected customers within 30 days of learning that their information was accessed without authorisation, and must keep written proof of compliance. The clock started for larger firms in December 2025 and for smaller ones in June 2026, so as of August 2026 it applies to everyone covered.
Enforced by United States Securities and Exchange Commission
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Tell affected people — within 720 hours, from 3 December 202530 days from becoming aware of unauthorised access or use. Larger firms from December 2025, smaller firms from June 2026.
- Written vendor contractFirms must oversee service providers and ensure they give notice of a breach so the firm can meet its own 30-day clock.
- Keep records of processingWritten records documenting compliance with the safeguards and disposal rules.
- Keep data for a minimum period — 6 yearsBroker-dealer books and records: six years for core records with two years easily accessible; three years for most others.
What it costs if you get it wrong
- Fixed maximum fineSecurities law civil penalties and censure
Sources
- Official sourceUnited States Securities and Exchange CommissionFact sheet — final rules, enhancements to Regulation S-P
sec.gov
“not later than 30 days, after becoming aware that unauthorized access to or use of customer information has occurred”
Link checked 18 August 2026
- Official sourceUnited States Securities and Exchange CommissionSEC adopts rule amendments to Regulation S-P
sec.gov
Link checked 18 August 2026
- Official sourceElectronic Code of Federal RegulationsSEC Rule 17a-4 — record retention periods
ecfr.gov
Link checked 18 August 2026
Contract-imposed rule1 rule
Defense Federal Acquisition Regulation Supplement clause 252.239-7010, Cloud Computing Services
Directly binding regulation · DFARS 252.239-7010 (JAN 2023) · Defence
If you host anything for the United States military, the data stays on American soil. This is a contract clause rather than a privacy law, which is exactly why it is missed: it binds through the supply chain, applies to subcontractors, and can only be waived by a written authorisation from the contracting officer.
Enforced by United States Department of Defense
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryAll government data not physically on defence premises must be maintained in the United States or its outlying areas, unless the contracting officer authorises otherwise in writing.
- Report cyber incidents — within 72 hoursCyber incidents affecting the cloud service must be reported to the defence cyber crime centre.
- Hold a security certificateProvisional authorisation under the defence cloud security requirements guide.
What it costs if you get it wrong
- Loss of your licenceLoss of contract and potential suspension or debarment from federal contracting
Sources
- Official sourceAcquisition.govDFARS 252.239-7010 Cloud Computing Services
acquisition.gov
“The Contractor shall maintain within the United States or outlying areas all Government data that is not physically located on DoD premises”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The exact number of states with a comprehensive consumer privacy law in force on 18 August 2026 (we say 'around twenty')
No single government source publishes a definitive national count; trackers disagree because some count laws that are enacted but not yet commenced. Each individual state law we cite is on a government domain, but the aggregate figure rests on secondary trackers, so the state-layer rule is marked medium confidence.
The 2026 inflation-adjusted California revenue threshold and the 2026 adjusted maximum penalties per violation
The California attorney general's page still states the unadjusted $25 million figure. We could not open the regulator's 2025 adjustment announcement with the current figures, so we describe the threshold as 'about $25 million, adjusted each year'.
The court order blocking the open banking rule (12 CFR Part 1033)
Reported consistently by banking press and law firms as an injunction issued by a federal court in Kentucky in late 2025, but we could not locate the order on a court's own domain. The government backlinks for that rule are the regulator's reconsideration page and the published rule text, not the injunction itself. Confidence lowered to medium.
That Team Telecom security agreements uniformly require United States records to be stored inside the United States
We verified the foreign-personnel vetting obligation verbatim from the communications regulator's own consent decree. The storage-location clause is standard in the published agreement templates but the agreements themselves are negotiated case by case and often not public, so we describe this sector as mirror-like rather than closed.
The exact compliance dates for the amended Regulation S-P (3 December 2025 for larger entities, 3 June 2026 for smaller entities)
The regulator's fact sheet states 18 and 24 months from Federal Register publication rather than the calendar dates. We computed them from the 3 June 2024 publication date; treat the earlier date as the safe assumption.
Whether any enforcement action has been taken under the Data Security Program between the last update of the Justice Department's public actions page and 18 August 2026
We can evidence the absence of published actions from the department's own page, but cannot prove a negative for unpublished or sealed matters.
State insurance data security laws based on the industry model law
The model law is published by a private association of state regulators rather than a government body, and adoption varies state by state. We cover the insurance sector through the New York rule, which is on a government domain and reaches insurers licensed in New York wherever they are based.
That no federal or state rule requires health data or education data to remain in the United States
No such rule found, checked 18 August 2026. Individual state Medicaid and student data contracts frequently impose United States residency by contract rather than by law, and we did not survey those.
60-day cadence. Three dormant switches justify it: the Attorney General can add a country to the countries-of-concern list or designate any person a covered person overnight with no consultation; the critical infrastructure reporting rule could be finalised at any time and would add a 72-hour clock across sixteen sectors; and state legislatures add two to four comprehensive privacy laws per year with short lead times. The court-blocked rules (reproductive health privacy, open banking, the California children's design code) can also move on a single ruling.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Compare with
- United States versus Bulgaria
- United States versus Canada
- United States versus China
- United States versus France
- United States versus Germany
- United States versus Greece
- United States versus Hungary
- United States versus India
- United States versus Italy
- United States versus Japan
- United States versus Slovakia
- United States versus United Kingdom