Legislators and privacy experts detail how the tech industry has sought to water down state privacy regulation in the US; 13 US states now have privacy laws
Suzanne Smalley / The Record :
Context & Ripple Effects
Congressional deadlock had already pushed privacy policymaking toward the states, while industry groups were reported to favor state laws weaker than California's. Earlier federal lobbying also sought a framework that would override California's privacy rules.
This report places 13 enacted state laws in that continuing contest: advocates have treated statehouses as the practical route for stronger protections after federal efforts stalled, while companies seek to shape the scope of those rules.
First-order effects
- State legislators drafting or revising privacy statutes face organized pressure over the strength and enforceability of their rules.
- Companies operating across the affected states must track a larger, potentially uneven set of privacy obligations rather than relying on a single federal standard.
Second-order effects
- The growing state patchwork gives industry groups a renewed incentive to pursue federal preemption or state-to-state harmonization, echoing the earlier push for federal control over state privacy frameworks.
- Privacy advocates can use enacted state laws as legislative baselines in remaining states, even as lobbying determines how closely new statutes resemble stronger models.
Third-order effects
- If state-by-state lawmaking continues, U.S. privacy governance is likely to be shaped by competition between stronger state standards, business-friendly compromises, and a possible federal override.
- The central policy question shifts from whether privacy rules exist to who sets their floor—individual states or Congress—and whether that floor constrains data collection and use.
The trend: U.S. digital privacy policy is evolving through a contested state-led patchwork as federal legislation remains unresolved.