United States
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in the United States — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can send most data out of the United States. There is no national privacy law. You need no permit to move data abroad. Two things change that. You cannot send large amounts of sensitive data to six countries, and breaking that rule can mean prison. And anything connected to government work must stay on American soil.
Data governance in the United States
The eight things that decide how you handle data about people in the United States. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. American rules apply even if you have no office in the country. California's privacy law covers any for-profit business that 'does business in California' and meets one of three tests. Having an office there is not one of those tests. The children's rule covers foreign websites aimed at American children. You do not have to appoint a local representative. No state law and no national law asks for one. That is a real difference from Europe.
California Consumer Privacy Act tests. You are covered if your gross annual revenue is over $25 million. That figure is adjusted upward for inflation each year. You are also covered if you buy, sell or share the personal information of 100,000 or more California residents or households. Or if 50% or more of your annual revenue comes from selling California residents' personal information. Most other state privacy laws only count people. The common test is 100,000 residents, or 25,000 residents where more than 25% of revenue comes from selling data. Those states set no revenue floor at all. So a mid-sized foreign business can be caught in one state and not another. The Federal Trade Commission Act reaches conduct that affects United States commerce, wherever the company sits. The Justice Department's Data Security Program is written around 'U.S. persons'. It also binds foreign recipients through the deals it bans.
Sources
- Official sourceCalifornia Attorney GeneralCalifornia Consumer Privacy Act — who must comply
oag.ca.gov
“Have a gross annual revenue of over $25 million”
Link checked 18 August 2026
- Official sourceFederal Trade CommissionChildren's Online Privacy Protection Rule
ftc.gov
Link checked 18 August 2026
Where the data is allowed to live
It depends on your industry. For ordinary customer or staff data, you can send it anywhere with no paperwork. Six industries are different. Government contracting, police data, federal tax data and defence work all require the data to stay in the United States. Telecom licences limit which foreign staff may even look at records. And for any business, sending large amounts of sensitive data to six named countries is now a crime.
Industry by industry. OPEN (we found no rule about where the data must sit, checked 18 August 2026). Health under the federal health privacy law. Banking and payments under federal banking law. Insurance under state insurance data security laws. Education under the federal student records law. Online shopping, social media and online gaming. Map and location data on its own. Bank supervisors expect you to manage the legal risk of a foreign-based service provider. They also expect you to hand records to examiners. They do not say where the servers must sit. CONDITIONAL: every industry, because of the Justice Department's Data Security Program. You may not sell large amounts of sensitive data about Americans to China (including Hong Kong and Macau), Cuba, Iran, North Korea, Russia or Venezuela. You may not give them access to it either. The same goes for people and companies those countries control. Sensitive data here means genomic, biometric, precise location, health, financial and identifier data above set volume limits. Vendor, employment and investment arrangements with those countries are allowed only with strict security controls, audits and reporting. Defence technical data may sit on a foreign server only under three conditions. It must be encrypted end to end to a strong standard. It must not be stored in an embargoed country. And only authorised people may be able to read it. CLOSED: federal tax information handled for the tax authority. Criminal justice information under the police data policy, which allows only the United States, its territories, tribal lands and Canada. Department of Defense cloud contracts. Government data must stay in the United States or its outlying areas. A contracting officer can say otherwise in writing. MIRROR-LIKE: telecom carriers with foreign investment. Their agreements with the security agencies say United States records must be kept where American authorities can reach them. The agreements also require government vetting before foreign staff are given access.
Sources
- Official sourceUnited States Department of JusticeData Security Program — National Security Division
justice.gov
“establishes what are effectively export controls that prohibit or restrict countries of concern ... from engaging in certain categories of transactions with U.S. persons that can give them access to U.S. Government-related data or Americans' bulk genomic, geolocation, biometric, health, financial, or other sensitive personal data.”
Link checked 18 August 2026
- Official sourceElectronic Code of Federal RegulationsCountries of concern, 28 CFR 202.601
ecfr.gov
Link checked 18 August 2026
- Official sourceInternal Revenue ServicePublication 1075 — Tax Information Security Guidelines, offshore operations
irs.gov
“restrict the accessing, processing, storage, and transmission of FTI to the United States and its territories”
Link checked 18 August 2026
- Official sourceFederal Bureau of Investigation, Criminal Justice Information Services DivisionCJIS Security Policy version 6.1, 25 June 2026 — storage of criminal justice information
le.fbi.gov
“The storage of CJI, regardless of encryption status, shall only be permitted in cloud environments ... which reside within the physical boundaries of APB-member country (i.e., United States, U.S. territories, Indian Tribes, and Canada)”
Link checked 18 August 2026
- Official sourceAcquisition.govDefense Federal Acquisition Regulation Supplement clause 252.239-7010, Cloud Computing Services
acquisition.gov
“The Contractor shall maintain within the United States or outlying areas all Government data that is not physically located on DoD premises”
Link checked 18 August 2026
- Official sourceBoard of Governors of the Federal Reserve SystemInteragency Guidance on Third-Party Relationships: Risk Management (SR 23-4)
federalreserve.gov
“third parties whose servicing operations are located in a foreign country and subject to the law and jurisdiction of that country”
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
For ordinary data, nothing. No standard contract, no government approval, no list of approved destination countries. You can send data anywhere except to banned countries, and six are now named. Before you move large amounts of sensitive data, do one thing. Work out whether one of those six countries, or a company or person they control, could end up with access. That includes access through a vendor, an investor or an employee.
- Ways to send data out:
- Nothing required · Security review needed
The Justice Department programme splits deals into three groups. Prohibited: selling data to one of the six countries, or to a covered person. Also prohibited: any transfer of large amounts of human genomic data, or of the biospecimens behind it. Restricted: vendor, employment and investment agreements. These are allowed only with a defined security programme, annual independent audits and record-keeping. Exempt: ordinary administration inside your own corporate group, official United States government business, financial services activity, regulatory approvals, and personal communications. Volume limits decide when the rules apply. They start at more than 100 people for genomic data, and 1,000 people for biometric data. For precise location, 1,000 devices. For health or financial data, 10,000 people. For basic identifiers, 100,000 people. You count over any rolling twelve months. Separately, a 2024 law bans data brokers from selling sensitive data to North Korea, China, Russia or Iran at all. The consumer protection regulator enforces it. There is no volume limit, and the security-controls route does not apply here.
Sources
- Official sourceElectronic Code of Federal RegulationsBulk thresholds, 28 CFR 202.205
ecfr.gov
“more than 100 U.S. persons ... more than 1,000 U.S. persons ... more than 1,000 U.S. devices ... more than 10,000 U.S. persons ... more than 100,000 U.S. persons”
Link checked 18 August 2026
- Official sourceFederal Trade CommissionProtecting Americans' Data from Foreign Adversaries Act of 2024
ftc.gov
Link checked 18 August 2026
- Official sourceElectronic Code of Federal Regulations22 CFR 120.54 — activities that are not exports, including encrypted technical data
ecfr.gov
Link checked 18 August 2026
What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.
The regulator, and whether it actually acts
There is no national privacy regulator. Many bodies each enforce a slice instead. They are the consumer protection regulator, the health department, the securities regulator and the communications regulator. Add the Justice Department, all fifty state attorneys general, and one dedicated state privacy agency. Almost all of them are visibly working right now. The one exception is the new national data transfer programme. It is staffed and issuing guidance, but has published no enforcement action yet.
Evidence gathered on 18 August 2026. The Federal Trade Commission finalised an order against a car maker and its connected-car arm in January 2026 over selling driver location data. It sued two dating apps in March 2026 over sharing personal data. It finalised an order against an education technology company over student data in June 2026. In February 2026 it sent warning letters to thirteen data brokers about selling sensitive data to foreign adversaries. California's privacy agency has issued a run of fines. They include $1.35 million against a rural retailer in September 2025 and $632,500 against a car maker. It opened a fresh round of data broker cases in January 2026. The Texas attorney general sued a group of Chinese-linked companies in May 2025. It also warned over a hundred firms about the state data broker law. The communications regulator issued its first ever penalty for breaching a national security agreement in January 2026. The health department continues to settle security cases. The Justice Department's data security unit is the outlier. As of 18 August 2026 it lists no public enforcement action, licence or advisory opinion under the programme. It is staffed and publishing guidance, but has taken no action.
Sources
- Official sourceFederal Trade CommissionFTC reminds data brokers of their obligations to comply with PADFAA, 9 February 2026
ftc.gov
“The FTC is committed to enforcing PADFAA and ensuring companies are complying with its requirements.”
Link checked 18 August 2026
- Official sourceCalifornia Privacy Protection AgencyCalifornia Privacy Protection Agency — enforcement announcements 2025 and 2026
cppa.ca.gov
Link checked 18 August 2026
- Official sourceUnited States Department of JusticeNational Security Division — public actions (no Data Security Program enforcement action listed)
justice.gov
Link checked 18 August 2026
- Official sourceFederal Communications CommissionFCC order and consent decree DA 26-25, 8 January 2026 — first penalty for breaching a national security agreement
docs.fcc.gov
Link checked 18 August 2026
- Official sourceOffice of the Attorney General of TexasTexas attorney general takes legal action against Chinese companies, 6 May 2025
texasattorneygeneral.gov
Link checked 18 August 2026
How long you must keep it — and when to delete it
You must keep some records for years, and you must not keep others too long. Investment firms must keep some books for six years and most others for three. The first two years must be easy to reach. Health providers keep their paperwork for six years. In the other direction, state privacy laws now make you publish how long you keep each type of data. You must not keep it longer than you said. Since April 2026 you may no longer keep children's data forever. Where a keep-it rule and a delete-it rule clash, the keep-it rule wins. Every state law says so.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Let people delete their data
Minimums. Broker-dealer records: six years for the core books, with two years in an easily accessible place. Three years for most operational records. Formation documents for the life of the business. Customer account records run six years past account closure. Health privacy paperwork: six years. Tax records: the tax authority's normal periods, commonly three to seven years depending on the item. Investment advisers and funds have parallel rules. Maximums. The California rules require a retention schedule and require you to publish how long you keep data. The amended children's rule requires a written retention policy. It bans keeping children's data forever and requires deletion once the original purpose is met. State consumer privacy laws give people a right to have data deleted, unless the law requires you to keep it. No state deletion right overrides a federal duty to keep records. The state laws say so directly rather than leaving it to interpretation.
Sources
- Official sourceElectronic Code of Federal RegulationsSEC Rule 17a-4 — records to be preserved by brokers and dealers
ecfr.gov
Link checked 18 August 2026
- Official sourceFederal RegisterChildren's Online Privacy Protection Rule, final amendments — retention and deletion requirements
federalregister.gov
Link checked 18 August 2026
- Official sourceCalifornia Privacy Protection AgencyCalifornia Consumer Privacy Act regulations — retention, risk assessments and cybersecurity audits
cppa.ca.gov
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Count the deadlines. There are at least seven and they do not agree. New York financial firms: 72 hours to the state regulator, and only 24 hours to report paying a ransom. Telecom carriers: seven working days to the police agencies and the communications regulator. You may not warn customers until seven working days after that. Investment and finance firms: 30 days to affected customers. Health organisations: 60 days. Texas and many other states: 30 days to the state attorney general. Listed companies: four working days to tell investors, once they decide an incident is important. The overlap is what people fail, not any single deadline.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Deadlines verified 18 August 2026. New York Department of Financial Services rule Part 500: tell the regulator within 72 hours of deciding a cybersecurity incident happened. Report extortion payments within 24 hours. Communications regulator rule: tell the Federal Bureau of Investigation, the Secret Service and the Commission as soon as you can. The deadline is seven business days after you reasonably decide there was a breach. Then wait seven business days before telling customers, unless law enforcement extends the hold. The Sixth Circuit court upheld these rules, so they are live and not merely on the books. Amended Regulation S-P: tell affected people as soon as you can, and no later than 30 days after you learn of unauthorised access. Larger firms had to comply from December 2025 and smaller ones from June 2026. Consumer protection regulator's Safeguards Rule: report security events affecting 500 or more consumers within 30 days. Health privacy rule: tell individuals and the health department within 60 days. If more than 500 residents of one state are affected, tell the media too, within 60 days. Smaller breaches are reported once a year, within 60 days of the year end. Texas: 30 days to the attorney general where 250 or more Texans are affected. Securities disclosure rule: file Form 8-K within four business days of deciding an incident is material. The national critical infrastructure reporting law adds a 72-hour incident deadline and a 24-hour ransom-payment deadline. It is not yet switched on. See question eight.
Sources
- Official sourceUnited States Department of Health and Human Services, Office for Civil RightsBreach Notification Rule — 60-day deadlines
hhs.gov
“without unreasonable delay and in no case later than 60 days following the discovery of a breach”
Link checked 18 August 2026
- Official sourceElectronic Code of Federal Regulations47 CFR 64.2011 — notification of customer proprietary network information security breaches
ecfr.gov
“As soon as practicable, and in no event later than seven (7) business days, after reasonable determination of the breach”
Link checked 18 August 2026
- Official sourceNew York State Department of Financial ServicesNew York Department of Financial Services cybersecurity regulation Part 500
dfs.ny.gov
“as promptly as possible but in no event later than 72 hours after determining that a Cybersecurity Incident has occurred”
Link checked 18 August 2026
- Official sourceUnited States Securities and Exchange CommissionFact sheet — final rules, enhancements to Regulation S-P
sec.gov
“not later than 30 days, after becoming aware that unauthorized access to or use of customer information has occurred”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General of TexasData breach reporting to the Texas attorney general
texasattorneygeneral.gov
“affects 250 or more Texans to report that breach to the Office of the Texas Attorney General as soon as practicably possible and no later than 30 days after the discovery of the breach”
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five traps cost people their weekend. One: the national data transfer programme can mean prison, up to twenty years for a deliberate breach. Two: Illinois lets people sue over fingerprints and face scans. Damages are fixed per person and you do not have to prove harm. The largest privacy payouts happen there. Three: the children's rule uses under 13, but several state laws use under 18. One age gate will not do. Four: government work means the data stays on American soil. Police data may only go to the United States, its territories, tribal lands and Canada. Five: a rule can be printed in the law book and still not apply, because a court has blocked it.
- What you have to do here:
- Get a parent's consent for children · Keep the data in the country
- What it costs if you get it wrong:
- Criminal liability · Claims by individuals
Trap one. The data transfer programme runs on emergency economic powers. Civil penalties go up to the greater of $368,136 or twice the value of the deal. Criminal penalties go up to $1,000,000 and up to twenty years in prison for a person acting wilfully. This is not an administrative privacy fine. Trap two. The Illinois biometric law lets people sue you directly. Damages are set at $1,000 for negligent breaches and $5,000 for reckless or intentional ones. A 2024 change (Public Act 103-0769) limits each person to one claim per collection method, rather than one per scan. That cut the possible exposure enormously, but did not remove it. Washington's health data law also lets people sue. Trap three. The federal children's rule covers under 13. State design-code and social-media laws reach under 18 or under 16. The amended federal rule became fully enforceable on 22 April 2026. It now requires a written data retention policy, separate consent for targeted advertising, and a list of the third parties that receive children's data. Trap four. Criminal justice information may only be stored in the United States, its territories, tribal lands or Canada. The metadata derived from it is protected the same way and may not be used for advertising. Federal tax information must stay in the United States and its territories. Department of Defense cloud contracts require government data to stay in the United States or outlying areas. Trap five. Two live examples. A court struck down most of the 2024 health rule on reproductive health privacy nationwide in 2025, so it no longer applies. Some notice changes survived, with a compliance date of 16 February 2026. And most of California's children's design code has been blocked since 2022. In March 2026 the appeal court kept the block on the data-use and dark-pattern parts and lifted it on the rest. So parts of that law apply and parts do not.
Sources
- Official sourceElectronic Code of Federal Regulations28 CFR Part 202 subpart M — penalties
ecfr.gov
“fined not more than $1,000,000, or if a natural person, may be imprisoned for not more than 20 years, or both”
Link checked 18 August 2026
- Official sourceIllinois General AssemblyIllinois Public Act 103-0769 — amendment to the Biometric Information Privacy Act
ilga.gov
Link checked 18 August 2026
- Official sourceUnited States Court of Appeals for the Ninth CircuitNetChoice, LLC v. Bonta, No. 25-2366, 12 March 2026
cdn.ca9.uscourts.gov
“we AFFIRM the district court's preliminary injunction insofar as it enjoined enforcement of California Civil Code 1798.99.31(b)(1)-(4) and 1798.99.31(b)(7), and VACATE the remainder of the preliminary injunction.”
Link checked 18 August 2026
- Official sourceUnited States Department of Health and Human ServicesReproductive health privacy rule — status after Purl v. HHS
hhs.gov
“The court vacated only the provisions that were deemed unlawful, namely 164.520(b)(1)(ii)(F), (G), and (H).”
Link checked 18 August 2026
- Official sourceFederal Bureau of InvestigationCJIS Security Policy version 6.1 — metadata and storage restrictions
le.fbi.gov
“Metadata derived from unencrypted CJI shall be protected in the same manner as CJI and shall not be used for any advertising or other commercial purposes by any cloud service provider or other associated entity.”
Link checked 18 August 2026
What's changing next
Four things are due in the next twelve months. The national critical infrastructure reporting rule should be finished in late 2026. It will start a 72-hour incident deadline and a 24-hour ransom-payment deadline for a very wide range of businesses. California's rules on automated decision-making start on 1 January 2027. The open banking rule is being rewritten after a court blocked it. And a national privacy bill is moving in Congress. It is only a bill and binds nobody.
Dated items. The critical infrastructure reporting rule: the agency's own page still says you do not have to report until the final rule takes effect. That date has slipped repeatedly through 2025 and 2026. Automated decision-making: businesses using it for significant decisions must comply from 1 January 2027. Risk assessments began on 1 January 2026, with first submissions due by 1 April 2028. Cybersecurity audit submissions start 1 April 2028 for businesses with revenue over $100 million. Businesses between $50 million and $100 million start in 2029, and those below $50 million in 2030. Open banking: the finance regulator reopened the rulemaking in August 2025. A federal court has blocked enforcement of the existing version, whose first compliance date was 1 April 2026. Health security rule: a proposal to tighten it was published in January 2025 and has not been finalised. Federal bills, including the SECURE Data Act introduced in April 2026, are still only proposals. Powers already held that could change things overnight. First and largest: the Attorney General can add a country to the list of countries of concern. The Attorney General can also name any person as a covered person. No consultation and no notice period are needed. Second: the communications regulator's list of untrusted suppliers can be expanded. A rulemaking opened in April 2026 to strip listed companies of blanket permission to provide domestic services. Third: export control decisions can move technical data into a restricted category without new legislation. Fourth: state attorneys general in Texas and California have shown they will open sweeps against whole categories of company at a few days' notice.
Sources
- Official sourceCybersecurity and Infrastructure Security AgencyCyber Incident Reporting for Critical Infrastructure Act of 2022 — status
cisa.gov
“Organizations are not required to submit cyber incident or ransomware payment reports under CIRCIA until the yet-to-be-determined effective date of the Final Rule.”
Link checked 18 August 2026
- Official sourceCalifornia Privacy Protection AgencyCalifornia finalises regulations on automated decision-making, risk assessments and cybersecurity audits
cppa.ca.gov
“Businesses that use ADMT to make significant decisions must comply with the ADMT requirements beginning January 1, 2027.”
Link checked 18 August 2026
- Official sourceConsumer Financial Protection BureauPersonal Financial Data Rights Reconsideration
consumerfinance.gov
Link checked 18 August 2026
- Official sourceCongress.gov, Library of CongressConsumer Data Privacy and Security Act of 2026 (S.4211) — a bill, no legal effect
congress.gov
Link checked 18 August 2026
- Official sourceFederal RegisterProposed rule to strengthen the health security rule, 6 January 2025 — not finalised
federalregister.gov
Link checked 18 August 2026
What to do: Diarise 1 January 2027 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries6 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Government data must stay in the country
Official name: Criminal Justice Information Services (CJIS) Security Policy · CJISSECPOL version 6.1 · Government policy document
This is the strictest everyday rule in the United States about where data must sit. Police and criminal justice information may only be stored in cloud services inside the United States, its territories, tribal lands or Canada. Encrypting it does not help. The rule applies whether or not the data is encrypted. Any supplier to a police force, court or background-check programme inherits this.
Enforced by Federal Bureau of Investigation, Criminal Justice Information Services Division
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryYou may store it only in the United States, its territories, Indian tribal lands and Canada. It must be under the legal authority of a member agency. Encryption does not lift the restriction.
- Written vendor contractCloud providers may not use metadata taken from unencrypted criminal justice information for advertising or any other commercial purpose.
- Secure the dataOutside physically secure locations, stored data must be encrypted. Use FIPS 140-3, a United States government encryption standard, with at least a 256-bit symmetric key. FIPS 197 with at least 256 bits also works.
What it costs if you get it wrong
- Order to stopSanctions up to termination of access to the national criminal justice systems
Sources
- Official sourceFederal Bureau of Investigation, Criminal Justice Information Services DivisionCJIS Security Policy version 6.1, 25 June 2026
le.fbi.gov
“The storage of CJI, regardless of encryption status, shall only be permitted in cloud environments (e.g., government or third-party/commercial datacenters, etc.) which reside within the physical boundaries of APB-member country (i.e., United States, U.S. territories, Indian Tribes, and Canada) and are under legal authority of an APB-member agency”
Link checked 18 August 2026
Government data must stay in the country (Government)
Official name: Publication 1075, Tax Information Security Guidelines for Federal, State and Local Agencies · Made binding through Internal Revenue Code section 6103 safeguard agreements · Regulator guideline
If you receive federal tax information, it must stay inside the United States and its territories. So must all access to it. This covers state revenue departments, benefits agencies, child support programmes and their contractors. It is a condition of receiving the data, not a general privacy rule. So it passes down to every subcontractor.
Enforced by Internal Revenue Service
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryYou may only access, use, store and send federal tax information inside the United States and its territories.
- Independent auditSafeguard reporting and on-site reviews by the tax authority.
What it costs if you get it wrong
- Criminal liabilityUnauthorised disclosure or inspection of federal tax information is a criminal offence under the tax code
- Order to stopSuspension of the agency's access to federal tax information
Sources
- Official sourceInternal Revenue ServicePublication 1075 — offshore operations, control SA-9(5)
irs.gov
“Control Enhancement to restrict the accessing, processing, storage, and transmission of FTI to the United States and its territories.”
Link checked 18 August 2026
- Official sourceInternal Revenue ServiceEncryption requirements of Publication 1075
irs.gov
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: International Traffic in Arms Regulations, activities that are not exports · 22 CFR 120.54 · Directly binding regulation
Defence technical data can legally sit on a foreign server, but only under tight conditions. It must be encrypted end to end and strongly. It must not be stored in an embargoed country. Only authorised people may be able to read it. Handing an encryption key to a foreign national breaks the exemption. Routine cloud storage then counts as an unlicensed arms export.
Enforced by Directorate of Defense Trade Controls
How this country controls where data goes: Any country except banned ones · Accepted routes: Nothing required, Government sign-off needed
What you have to do
- Secure the dataEnd-to-end encryption, or a validated cryptographic module, or comparable strength of at least 128 bits. You must not give keys to a foreign person or a foreign government.
- Put a transfer safeguard in placeYou must not deliberately send or store the data in an embargoed country. The recipient must be the originator, a United States person inside the United States, or someone otherwise authorised.
What it costs if you get it wrong
- Criminal liabilityUnauthorised export of defence technical data
- Fixed maximum fineCivil penalties per violation under the arms export control statute
Sources
- Official sourceElectronic Code of Federal Regulations22 CFR 120.54 — activities that are not exports, reexports, retransfers or temporary imports
ecfr.gov
“not intentionally sent to a person in or stored in a country proscribed in 126.1 of this subchapter”
Link checked 18 August 2026
Telecoms rules
Official name: National security agreement / letter of assurance conditioning a section 214 authorisation, reviewed by the Committee for the Assessment of Foreign Participation in the United States Telecommunications Services Sector · Executive Order 13913; enforced in FCC DA 26-25, File No. EB-TCD-00038619 · Licence condition
Telecom carriers with foreign owners sign a security agreement as the price of their licence. It controls where United States records sit. It also controls which foreign staff may touch them. In January 2026 the communications regulator issued its first ever penalty under one of these agreements. It fined a satellite communications provider that gave 186 foreign employees access without government vetting first.
Enforced by Federal Communications Commission
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryUnited States records and domestic communications infrastructure must stay within reach of American authorities. Foreign staff need government vetting before they get access.
- Do not hand data to foreign authorities on demandCarriers must tell the Justice Department at least 30 days before giving a foreign employee access to United States records or domestic communications infrastructure.
- Register or notifyThis applies to carriers with reportable foreign ownership that hold an international section 214 authorisation or an earth station licence.
What it costs if you get it wrong
- Fixed maximum fine: $175,000 in the first case — about $175 thousandFailure to submit foreign employees for vetting before granting access
- Loss of your licenceBreach of a national security agreement can cost the operating authorisation
Sources
- Official sourceFederal Communications Commission, Enforcement BureauOrder and consent decree, DA 26-25, 8 January 2026
docs.fcc.gov
“notify [DOJ] of all its Foreign person employees that it intends to allow Access to U.S. Records, [Domestic Communications], or [Domestic Communications Infrastructure]”
Link checked 18 August 2026
Breach reporting rules
Official name: Notification of customer proprietary network information security breaches · 47 CFR 64.2011 · Directly binding regulation
Telecom and internet-calling providers must report a breach of call and connection records within seven working days. They report to two federal police agencies and the communications regulator. Then they tell customers, but not until another seven working days have passed. There is no minimum number of affected customers. The Sixth Circuit court upheld these rules, so they are live rather than merely printed.
Enforced by Federal Communications Commission
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report breaches to the regulator — within 168 hoursSeven business days to tell the Federal Bureau of Investigation, the Secret Service and the Commission, after you reasonably decide a breach happened.
- Tell affected peopleTell customers after law enforcement, and no sooner than seven business days after the law enforcement notice, unless the agencies agree otherwise.
What it costs if you get it wrong
- Fixed maximum fineForfeiture penalties for breach of the communications rules
Sources
- Official sourceElectronic Code of Federal Regulations47 CFR 64.2011
ecfr.gov
“As soon as practicable, and in no event later than seven (7) business days, after reasonable determination of the breach”
Link checked 18 August 2026
- Official sourceFederal RegisterData Breach Reporting Requirements, final rule
federalregister.gov
Link checked 18 August 2026
General data protection law
Official name: Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information, as amended · 17 CFR Part 248; Release 34-100155 · Directly binding regulation
Investment firms, brokers and funds must tell affected customers within 30 days of learning their information was accessed without permission. They must keep written proof that they complied. The clock started for larger firms in December 2025 and for smaller ones in June 2026. As of August 2026 it applies to everyone covered.
Enforced by United States Securities and Exchange Commission
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Tell affected people — within 720 hours, from 3 December 202530 days from learning of unauthorised access or use. Larger firms from December 2025, smaller firms from June 2026.
- Written vendor contractFirms must oversee their service providers and make sure those providers report a breach in time for the firm to meet its own 30-day deadline.
- Keep records of how you use dataWritten records showing you followed the safeguards and disposal rules.
- Keep data for a minimum period — 6 yearsBroker-dealer books and records: six years for core records, with two years easy to reach. Three years for most others.
What it costs if you get it wrong
- Fixed maximum fineSecurities law civil penalties and censure
Sources
- Official sourceUnited States Securities and Exchange CommissionFact sheet — final rules, enhancements to Regulation S-P
sec.gov
“not later than 30 days, after becoming aware that unauthorized access to or use of customer information has occurred”
Link checked 18 August 2026
- Official sourceUnited States Securities and Exchange CommissionSEC adopts rule amendments to Regulation S-P
sec.gov
Link checked 18 August 2026
- Official sourceElectronic Code of Federal RegulationsSEC Rule 17a-4 — record retention periods
ecfr.gov
Link checked 18 August 2026
Applies to every company4 rules
These bind you whatever business you are in, once the country's rules reach you.
Government data rules
Official name: Preventing Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons (the Data Security Program) · 28 CFR Part 202, made under Executive Order 14117 · Directly binding regulation
This is the closest thing the United States has to a law on sending data abroad. You may not sell large amounts of Americans' sensitive data to China, Cuba, Iran, North Korea, Russia or Venezuela. You may not give them access to it either. The same goes for people they control. Vendor, staffing and investment deals with those countries are allowed only with strict security controls, annual audits and reporting. Penalties include prison.
Enforced by United States Department of Justice, National Security Division
How this country controls where data goes: Any country except banned ones · Accepted routes: Security review needed, Nothing required
What you have to do
- Put a transfer safeguard in placeVendor, employment and investment agreements with one of the six countries, or a covered person, are restricted. You need a defined security programme built on the national cyber agency's security requirements.
- Independent audit — from 6 October 2025Annual independent audit for these restricted deals.
- Keep records of how you use data — 10 years, from 6 October 2025Annual reports, and reports of any banned deal you turned down.
- Keep the data in the countryThis does not say data must stay in the United States. But large amounts of human genomic data, and the biospecimens behind it, may not go to one of the six countries at all.
What it costs if you get it wrong
- Fixed maximum fine: $368,136 or twice the transaction value, whichever is greater — about $368 thousandCivil penalty for any violation
- Criminal liability: $1,000,000 fine and up to 20 years' imprisonment — about $1 millionWilful violation
Sources
- Official sourceUnited States Department of Justice, National Security DivisionData Security Program
justice.gov
“due diligence and audits for restricted transactions (subpart J), annual reports (202.1103), and reports on rejected prohibited transactions (202.1104)”
Link checked 18 August 2026
- Official sourceElectronic Code of Federal Regulations28 CFR Part 202 — Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons
ecfr.gov
Link checked 18 August 2026
- Official sourceUnited States Department of JusticeJustice Department implements critical national security program, 11 April 2025
justice.gov
“NSD will not prioritize civil enforcement actions against any person for violations of the Data Security Program that occur from April 8 through July 8, 2025, so long as the person is engaging in good faith efforts to comply.”
Link checked 18 August 2026
Rules for sending data abroad
Official name: Protecting Americans' Data from Foreign Adversaries Act of 2024 · Public Law 118-50, Division I · Act of parliament
A short, blunt law bans data brokers from giving Americans' sensitive data to North Korea, China, Russia or Iran, or to companies they control. Unlike the Justice Department programme, it has no volume limit. There is no way to comply through security controls. The transfer is simply forbidden. The consumer protection regulator sent warning letters to thirteen data brokers in February 2026.
Enforced by Federal Trade Commission
How this country controls where data goes: Any country except banned ones
What you have to do
- Put a transfer safeguard in placeApplies to data brokers only. The definition of data broker is broad and there is no volume limit.
What it costs if you get it wrong
- Fixed maximum fine: $53,088 per violation — about $53 thousandSelling, releasing, disclosing or providing access to Americans' sensitive data to a foreign adversary
Sources
- Official sourceFederal Trade CommissionProtecting Americans' Data from Foreign Adversaries Act of 2024
ftc.gov
Link checked 18 August 2026
- Official sourceFederal Trade CommissionFTC reminds data brokers of their obligations to comply with PADFAA, 9 February 2026
ftc.gov
Link checked 18 August 2026
- Official sourceCongress.gov, Library of CongressH.R.7520 — Protecting Americans' Data from Foreign Adversaries Act of 2024, text
congress.gov
Link checked 18 August 2026
Children's data rules
Official name: Children's Online Privacy Protection Rule, as amended · 16 CFR Part 312 · Directly binding regulation
The federal children's rule applies to any website or app anywhere in the world aimed at American under-13s. The 2025 changes became fully enforceable on 22 April 2026. They added three things people miss. You need a written retention policy and may not keep children's data forever. You need separate consent before sharing a child's data with advertisers. And you must say who those third parties are. Several state laws set the age at 16 or 18 instead.
Enforced by Federal Trade Commission
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Get a parent's consent for children — applies at: under 13, from 22 April 2026You now need separate, extra consent before giving a child's data to third parties for advertising.
- Delete data after a period — from 22 April 2026You need a written retention policy. You may not keep children's data forever, and must delete it once you have met the purpose you collected it for.
- Tell people what you do — from 22 April 2026You must say which third parties receive children's data, by name or by category.
- Secure the data — from 22 April 2026A written security programme for children's data.
What it costs if you get it wrong
- Fixed maximum fine: Civil penalties per violation under the Federal Trade Commission Act, adjusted annuallyEach affected child can count as a separate violation
Sources
- Official sourceFederal RegisterChildren's Online Privacy Protection Rule, final amendments, 22 April 2025
federalregister.gov
Link checked 18 August 2026
- Official sourceFederal Trade CommissionChildren's Online Privacy Protection Rule
ftc.gov
Link checked 18 August 2026
- Official sourceElectronic Code of Federal Regulations16 CFR Part 312
ecfr.gov
Link checked 18 August 2026
Payment data rules
Official name: Cyber Incident Reporting for Critical Infrastructure Act of 2022 · 6 U.S.C. 681b; implementing rule at 6 CFR Part 226 not yet final · Act of parliament
This is the biggest incident-reporting duty in American law, and it is not switched on. The law passed in 2022, but the rule that implements it has slipped repeatedly. The agency's own page still says nobody has to report until the final rule takes effect. When it lands it will add a 72-hour incident deadline and a 24-hour ransom-payment deadline across sixteen critical infrastructure industries.
Enforced by Cybersecurity and Infrastructure Security Agency
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — within 72 hoursNot yet enforceable. 72 hours for a substantial cyber incident and 24 hours for a ransom payment, once the final rule takes effect.
What it costs if you get it wrong
- Fixed maximum fineSubpoena, referral to the Justice Department and contractor suspension, once in force
Sources
- Official sourceCybersecurity and Infrastructure Security AgencyCyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)
cisa.gov
“Organizations are not required to submit cyber incident or ransomware payment reports under CIRCIA until the yet-to-be-determined effective date of the Final Rule.”
Link checked 18 August 2026
Applies only in certain states2 rules
Made by a state or province. It only binds you for the people living there.
Cyber security rules
Official name: Cybersecurity Requirements for Financial Services Companies · 23 NYCRR Part 500, as amended 1 November 2023 · Directly binding regulation
New York's rule covers every bank, insurer, mortgage servicer and cryptocurrency business licensed in the state, wherever they are based. It has the shortest routine deadlines in American financial regulation. You have 72 hours to report an incident and 24 hours to report paying a ransom. The final phase took effect on 1 November 2025 and includes multi-factor authentication for everyone.
Enforced by New York State Department of Financial Services
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — within 72 hours72 hours from deciding a cybersecurity incident happened.
- Report breaches to the regulator — within 24 hours24 hours to report making an extortion payment, plus a written explanation within 30 days.
- Appoint a data protection officerYou need a chief information security officer who reports to the board in writing at least once a year.
- Secure the data — from 1 November 2025Final phase: multi-factor authentication for everyone who accesses information systems, and a full list of assets.
- Independent auditAn annual certificate of compliance, signed by the chief executive and the security officer. If you are not compliant, you sign a written acknowledgement with a plan to fix it.
What it costs if you get it wrong
- Fixed maximum finePer-violation penalties under New York banking, insurance and financial services law
- Loss of your licenceLoss of a New York licence
Sources
- Official sourceNew York State Department of Financial ServicesCybersecurity Resource Center — Part 500
dfs.ny.gov
“as promptly as possible but in no event later than 72 hours after determining that a Cybersecurity Incident has occurred”
Link checked 18 August 2026
Cyber security rules (2023)
Official name: California Consumer Privacy Act, as amended by the California Privacy Rights Act, plus around twenty comparable state statutes · California Civil Code 1798.100 et seq.; California Code of Regulations title 11, division 6 · Act of parliament
This is the layer that binds most businesses. Around twenty states now have a broad privacy law, and none of them says where data must be stored. They require notice, access, correction, deletion and portability. They also require an opt-out of targeted advertising that you honour through an automatic browser signal, plus a published retention schedule. California adds risk assessments from 2026, automated decision-making rights from 2027 and cybersecurity audits from 2028.
Enforced by California Privacy Protection Agency
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people objectPeople can opt out of sale, sharing and targeted advertising, including through an automatic browser signal.
- Delete data after a periodYou must publish how long you keep each category and must not keep it longer than disclosed.
- Written vendor contract
- Assess high-risk projects — from 1 January 2026Risk assessments from 1 January 2026. First statement to the regulator by 1 April 2028.
- Limit automated decisions — from 1 January 2027Automated decision-making rights start on 1 January 2027.
- Independent audit — from 1 April 2028Cybersecurity audits are phased by revenue: 2028 above $100 million, 2029 between $50 million and $100 million, 2030 below $50 million.
- Register or notifyData brokers must register and honour a single statewide deletion request platform.
What it costs if you get it wrong
- Fixed maximum fine: $2,500 per violation, $7,500 per intentional violation or violation involving a minor, adjusted for inflation — about $8 thousandEach affected consumer counts as a separate violation
- Claims by individualsStatutory damages for a data breach caused by unreasonable security
Sources
- Official sourceCalifornia Attorney GeneralCalifornia Consumer Privacy Act
oag.ca.gov
Link checked 18 August 2026
- Official sourceCalifornia Privacy Protection AgencyCalifornia finalises regulations to strengthen consumer privacy protections, 23 September 2025
cppa.ca.gov
“The regulations go into effect January 1, 2026.”
Link checked 18 August 2026
- Official sourceCalifornia Privacy Protection AgencyCalifornia Consumer Privacy Act statute text effective 1 January 2026
cppa.ca.gov
Link checked 18 August 2026
- Official sourceOffice of the Attorney General of TexasTexas Data Privacy and Security Act
texasattorneygeneral.gov
Link checked 18 August 2026
Applies only if you signed a contract1 rule
Usually a government or enterprise contract that adds rules of its own.
Defence data must stay in the country
Official name: Defense Federal Acquisition Regulation Supplement clause 252.239-7010, Cloud Computing Services · DFARS 252.239-7010 (JAN 2023) · Directly binding regulation
If you host anything for the United States military, the data stays on American soil. This comes from a contract clause, not a privacy law. That is exactly why people miss it. It passes down the supply chain and applies to subcontractors. Only a written authorisation from the contracting officer can waive it.
Enforced by United States Department of Defense
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryAll government data not physically on defence premises must stay in the United States or its outlying areas. The contracting officer can allow otherwise in writing.
- Report cyber incidents — within 72 hoursCyber incidents affecting the cloud service must be reported to the defence cyber crime centre.
- Hold a security certificateThe cloud service needs a temporary approval under the defence cloud security requirements guide.
What it costs if you get it wrong
- Loss of your licenceLoss of contract and potential suspension or debarment from federal contracting
Sources
- Official sourceAcquisition.govDFARS 252.239-7010 Cloud Computing Services
acquisition.gov
“The Contractor shall maintain within the United States or outlying areas all Government data that is not physically located on DoD premises”
Link checked 18 August 2026
On the books, but not enforceable2 rules
These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.
Health data rules
Official name: HIPAA Privacy Rule to Support Reproductive Health Care Privacy · 45 CFR 164.502(a)(5)(iii), 164.509 and 164.520(b)(1)(ii)(F)-(H) · Directly binding regulation
This rule is still printed but mostly cannot be enforced. A federal court in Texas struck down the 2024 reproductive health privacy rule nationwide in June 2025. That included the attestation requirement many organisations had already built. The health department confirms the rule was struck down. Only some changes to the privacy notice survive, with a compliance date of 16 February 2026.
Enforced by United States Department of Health and Human Services, Office for Civil Rights
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Tell people what you do — from 16 February 2026The privacy notice changes that survived the ruling still had to be in place by 16 February 2026.
What it costs if you get it wrong
- Fixed maximum fineHealth privacy penalties still apply to the surviving provisions
Sources
- Official sourceUnited States Department of Health and Human Services, Office for Civil RightsReproductive health care privacy — status after Purl v. HHS
hhs.gov
“The court vacated only the provisions that were deemed unlawful, namely 164.520(b)(1)(ii)(F), (G), and (H). The remaining modifications to the NPP requirements are undisturbed and remain in effect.”
Link checked 18 August 2026
Banking rules
Official name: Personal Financial Data Rights (Required Rulemaking on Personal Financial Data Rights) · 12 CFR Part 1033 · Directly binding regulation
This is the American open banking rule. Its text still shows a first compliance date of 1 April 2026 for the largest banks. But a federal court in Kentucky stopped the regulator from enforcing it, and the regulator reopened the rulemaking in August 2025. Treat the printed dates as unreliable and expect a different rule. Reading the code of regulations alone would wrongly suggest this binds you today.
Enforced by Consumer Financial Protection Bureau
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Let people take their data elsewhere — applies at: Banks with at least $250bn of assets and non-banks with at least $10bn of receipts first; smaller tiers to 2030, from 1 April 2026Compliance dates are printed in the rule, but a federal court has blocked enforcement while the regulator rewrites it.
- Written vendor contractConditions on third-party access, and limits on how authorised recipients may use the data.
What it costs if you get it wrong
- Fixed maximum fineConsumer financial law penalties, currently not being applied
Sources
- Official sourceConsumer Financial Protection BureauPersonal Financial Data Rights Reconsideration — advance notice of proposed rulemaking, 22 August 2025
consumerfinance.gov
Link checked 18 August 2026
- Official sourceConsumer Financial Protection Bureau12 CFR 1033.121 — compliance dates as currently published
consumerfinance.gov
Link checked 18 August 2026
- Secondary sourceCozen O'ConnorSection 1033 compliance date: open banking rule enjoined and under reconsideration
cozen.com
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact number of states with a comprehensive consumer privacy law in force on 18 August 2026 (we say 'around twenty')
No government source publishes a definitive national count of state privacy laws. Trackers disagree, because some count laws that are passed but not yet in force. Each state law we cite is on a government website. The total figure comes from private trackers. That is why we mark the state-layer rule medium confidence.
The 2026 inflation-adjusted California revenue threshold and the 2026 adjusted maximum penalties per violation
The California attorney general's page still shows the $25 million figure without the inflation adjustment. We could not confirm the regulator's 2025 adjusted figure. So we describe the threshold as about $25 million, adjusted each year.
The court order blocking the open banking rule (12 CFR Part 1033)
Banking press and law firms consistently report an injunction from a federal court in Kentucky in late 2025. We could not confirm the order on a court's own website. Our government links for that rule are the regulator's reconsideration page and the published rule text, not the injunction itself. That is why we mark it medium confidence.
That Team Telecom security agreements uniformly require United States records to be stored inside the United States
We confirmed the foreign-staff vetting duty word for word from the communications regulator's own consent decree. The storage-location clause is standard in the published agreement templates. But each agreement is negotiated case by case and is often not public. So we call this industry mirror-like rather than closed.
The exact compliance dates for the amended Regulation S-P (3 December 2025 for larger entities, 3 June 2026 for smaller entities)
The regulator's fact sheet gives 18 and 24 months from Federal Register publication, not calendar dates. We worked the dates out from the 3 June 2024 publication date. Treat the earlier date as the safe assumption.
Whether any enforcement action has been taken under the Data Security Program between the last update of the Justice Department's public actions page and 18 August 2026
We can show there are no published actions, using the department's own page. We cannot rule out unpublished or sealed cases.
State insurance data security laws based on the industry model law
The model law is published by a private association of state regulators, not a government body. Adoption varies from state to state. We cover insurance through the New York rule instead. That rule is on a government website and covers insurers licensed in New York wherever they are based.
That no federal or state rule requires health data or education data to remain in the United States
We found no rule requiring this. Individual state Medicaid and student data contracts often require data to stay in the United States by contract rather than by law. We did not survey those contracts. If you work in this industry, check before you rely on this.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.