The legal framework
The United States has no general privacy statute. Federal law is sectoral — HIPAA for health data, the Fair Credit Reporting Act for credit files, COPPA for children under 13 — while the Federal Trade Commission polices unfair and deceptive practices. Since California's CCPA, later strengthened as the CPRA, a large number of states have enacted comprehensive privacy laws with broadly similar rights.
Key points
| Federal | Sectoral: HIPAA, FCRA, GLBA, COPPA; FTC Act for unfair or deceptive practices |
|---|---|
| State laws | California, Virginia, Colorado, Connecticut, Utah and many others, with access, deletion and opt-out rights |
| Sale of data | Most state laws give a right to opt out of sale and of targeted advertising |
| Sensitive data | State laws generally require consent or an opt-out for health, precise location and sexual orientation data |
| Health apps | Often outside HIPAA; the FTC has used the Health Breach Notification Rule against them |
| Children | COPPA applies under 13; several states have added teen protections |
| Private right of action | Rare — California allows it for certain data breaches |
| No federal statute | Protection is sectoral and supplemented by state laws |
| State rights | Access, deletion, correction and opt-out of sale in a growing number of states |
| Global privacy control | Some states require businesses to honour browser opt-out signals |
In practice
- Write to the organisation first, citing the relevant statutory right; keep proof of the date.
- Set out clearly what you want: a copy of your data, deletion, or an end to marketing.
- If there is no adequate reply within the statutory period, complain to the regulator — it is free.
- For dating, health and fertility apps, ask specifically about third-party sharing and overseas transfers.
- Check whether your state has a comprehensive privacy law before assuming you have rights.
- Use the opt-out links that state laws require businesses to publish.
Cost and coverage
Requests are free; state attorneys general and the FTC handle enforcement, though individuals rarely obtain personal remedies.
Recent changes
Data brokers and location data have become the main enforcement focus, particularly after concerns about reproductive health and location tracking.
Where to go
- State attorney general privacy units, which take complaints.
- Federal Trade Commission complaint assistant.
- Consumer Reports' Permission Slip and similar tools for sending deletion requests.
Worth knowing
A period-tracking or dating app is usually not covered by HIPAA. Assume health data in consumer apps is regulated only by state privacy law and the FTC — and read the sharing settings accordingly. Most state laws give enforcement to the attorney general, not to you. Illinois biometric law is the notable exception where individuals can sue.
Official sources and links
- USA.gov — official guide to government services
- Congress.gov — federal legislation
