Skip to main content

Nixon Peabody LLP

  • People
  • Capabilities
  • Insights
  • About
Trending Topics
    • People
    • Capabilities
    • Insights
    • About
    • Locations
    • Events
    • Careers
    • Alumni
    Practices

    View All

    • Affordable Housing
    • Community Development Finance
    • Corporate & Finance
    • Cybersecurity & Privacy
    • Entertainment & Media
    • Environmental
    • Franchising & Distribution
    • Government Investigations & White Collar Defense
    • Healthcare
    • Intellectual Property
    • International Services
    • Labor, Employment, and Benefits
    • Litigation
    • Private Wealth & Advisory
    • Project Finance
    • Public Finance
    • Real Estate
    • Regulatory & Government Relations
    Industries

    View All

    • Aviation
    • Cannabis
    • Consumer
    • Energy
    • Financial Services
    • Healthcare
    • Higher Education
    • Infrastructure
    • Manufacturing
    • Nonprofit Organizations
    • Real Estate
    • Sports & Stadiums
    • Technology
    Value-Added Services

    View All

    • Alternative Fee Arrangements

      Developing innovative pricing structures and alternative fee agreement models that deliver additional value for our clients.

    • Continuing Education

      Advancing professional knowledge and offering credits for attorneys, staff and other professionals.

    • Crisis Advisory

      Helping clients respond correctly when a crisis occurs.

    • DEI Strategic Services

      Providing our clients with legal, strategic, and practical advice to make transformational changes in their organizations.

    • eDiscovery

      Leveraging law and technology to deliver sound solutions.

    • Environmental, Social, and Governance (ESG)

      We help clients create positive return on investments in people, products, and the planet.

    • Global Services

      Delivering seamless service through partnerships across the globe.

    • Innovation

      Leveraging leading-edge technology to guide change and create seamless, collaborative experiences for clients and attorneys.

    • IPED

      Industry-leading conferences focused on affordable housing, tax credits, and more.

    • Legal Project Management

      Providing actionable information to support strategic decision-making.

    • Legally Green

      Teaming with clients to advance sustainable projects, mitigate the effects of climate change, and protect our planet.

    • Nixon Peabody Trust Company

      Offering a range of investment management and fiduciary services.

    • NP Capital Connector

      Bringing together companies and investors for tomorrow’s new deals.

    • NP Second Opinion

      Offering fresh insights on cases that are delayed, over budget, or off-target from the desired resolution.

    • NP Trial

      Courtroom-ready lawyers who can resolve disputes early on clients’ terms or prevail at trial before a judge or jury.

    • Social Impact

      Creating positive impact in our communities through increasing equity, access, and opportunity.

    • Women in Dealmaking

      We provide strategic counsel on complex corporate transactions and unite dynamic women in the dealmaking arena.

    1. Home
    2. Insights
    3. Articles
    4. What is the right to privacy?

      Articles

    Article

    What is the right to privacy?

    Sep 15, 2023

    LinkedInX (Twitter)EmailCopy URL

    Discover the intricacies of privacy rights and unveil the significance of the right to privacy in the digital age.

    Legislatures and courts have long struggled not only to define privacy but to determine and balance enumerated and implied privacy rights for individuals and organizations. The right to privacy is especially important in the digital age, as increasing volumes of personally identifiable information are collected, stored, and transmitted electronically.

    What are privacy laws?

    Privacy laws govern the regulation, collection, storage, and use of personally identifiable information. They are intended to:

    • Ensure that individuals and organizations have control over their data (and who is granted access to it);
    • Prevent crime, such as fraud and identity theft; and
    • Ensure optimal digital functionality.

    Privacy laws protect data such as social security and driver’s license numbers, educational or employment records, medical history, financial information, date and place of birth, IP addresses, and internet history.

    U.S. data privacy law

    Data privacy laws in the U.S. have garnered increased support from both lawmakers and the public in recent years. In addition to established privacy laws that protect healthcare data and consumer privacy, new laws and proposals for increased regulation targeting biometric data collection, use, storage, and transmission are on the rise.

    Federal privacy laws

    While there is no comprehensive federal data privacy law, certain federal laws protect specific segments of personal data:

    • The Health Insurance Portability and Accountability Act of 1996 (HIPAA) governs how healthcare providers and healthcare businesses are allowed to store, use, and share patients’ personally identifiable information with anyone other than the patient or the patient’s authorized representatives without explicit consent.
    • The Telephone Consumer Protection Act of 1991 (TCPA) places restrictions on certain marketing phone calls, faxes, and text messages, as well as limits on the use of autodialers and pre-recorded voice messages. Telephone-based collection activities are also regulated by the TCPA.
    • The Privacy Act of 1974 (the Privacy Act) protects individuals against unwarranted invasions of their personally identifiable information and was designed to balance the government’s need to maintain data on individuals with individuals’ right to be protected from invasions of privacy.

    Congress has introduced comprehensive privacy bills; none has been signed into law.

    SAFE DATA Act

    There is currently no comprehensive federal privacy law in the U.S., but this may change as more institutions and industries recognize the importance of data privacy and cybersecurity. The latest federal privacy bill introduced by lawmakers is the Setting an American Framework to Ensure Data Access, Transparency, and Accountability (SAFE DATA) Act, which is designed to:

    • Give Americans more choice and control over their data;
    • Require businesses to be more transparent and accountable for their data practices; and
    • Bolster the Federal Trade Commission’s authority to respond to potentially harmful changes in technology and hold businesses accountable for unlawful use of consumer data.

    The SAFE DATA Act would limit how businesses can handle sensitive consumer data and require them to implement heightened cybersecurity measures. If passed, compliance could be initially burdensome. At the same time, fulfilling these measures could also help businesses minimize exposure in consumer privacy actions.

    Internet privacy laws

    In the U.S., no single law governs online privacy, but key laws regulating online data include:

    • The Federal Trade Commission Act, Section 5, prohibits unfair or deceptive acts in the marketplace. Section 5 gives the FTC the authority to address various privacy and consumer safety issues.
    • The Children's Online Privacy Protection Act (COPPA) navigates the online collection of personal information from children under 13 years of age and dictates certain marketing restrictions and parental consent standards. COPPA applies to websites, including social media sites and apps, and carries a significant penalty for noncompliance—up to $50,120 per violation.
    • Section 230 is a section of the Telecommunications Act of 1996 that prevents online businesses—and, recently, social media companies—from being held liable for content generated by its users. Section 230 also protects the identities of users posting content anonymously.
    • The Video Privacy Protection Act (VPPA). Originally intended to protect consumers’ videotape rental histories, VPPA actions by the plaintiffs’ bar are on the rise in the context of businesses’ use of online tracking technologies, such as cookies and Pixel code.

    In addition to these laws, several states have introduced and/or passed legislation banning certain social media platforms—for both children under 18 and adult users. We anticipate legal challenges to these bans.

    Data privacy laws by state

    The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act, is the most comprehensive state privacy law. It protects both consumer and employee data and governs how businesses and employers must handle the collection, storage, usage, and sharing of personal data.

    New York’s Stop Hacks and Improve Electronic Data Security Act (SHIELD Act) imposes strict data security and breach notification protocols on any person or business that owns or licenses computerized data that includes private information of New York residents, regardless of whether that person or business conducts business in New York.

    The Illinois Biometric Information Privacy Act (BIPA) regulates how private entities may collect, use, and store biometric information. BIPA is the only law in the U.S. that grants a private right of action to individuals harmed by BIPA violations, which has led to an explosion of consumer- and employee-led BIPA class actions.

    Several additional states are enacting privacy laws similar to those above pertaining to residents’ data, including consumer data. With most states considering at least one privacy bill, privacy legislation is expected to increase dramatically in the next decade.

    Privacy laws and law firms: How Nixon Peabody attorneys can help you

    Empowering our clients to understand and follow the patchwork of related federal and state rules that govern privacy is the core of our Cybersecurity & Data Privacy practice. We understand that the lack of federal oversight and the varying state regulations can cause confusion for businesses that have to comply with conflicting regulations, including small businesses that may not have the resources needed to comply.

    We advise businesses of all sizes and across industries on navigating the privacy laws that govern them now or that may govern them in the future to ensure that their data management policies and procedures are compliant in all areas where the patchwork of data privacy laws may impact operations.

    Practices

    Cybersecurity & PrivacyBiometric Information Privacy Act (BIPA)TCPA & Consumer PrivacyHealth Information - Privacy, Security & Data Sharing

    Insights And Happenings

    • Video

      Cybersecurity in the EU beyond the GDPR

      Cybersecurity & Privacy
      Dec 29, 2023
    • Video

      Intimate privacy in the digital age

      Cybersecurity & Privacy
      Dec 5, 2023
    • Video

      Data Protection Laws in Mexico

      Cybersecurity & Privacy
      Nov 6, 2023
    The foregoing has been prepared for the general information of clients and friends of the firm. It is not meant to provide legal advice with respect to any specific matter and should not be acted upon without professional counsel. If you have any questions or require any further information regarding these or other related matters, please contact your regular Nixon Peabody LLP representative. This material may be considered advertising under certain rules of professional conduct.

    Subscribe to stay informed of the latest legal news, alerts, and business trends.Subscribe

    • People
    • Capabilities
    • Insights
    • About
    • Locations
    • Events
    • Careers
    • Alumni
    • Cookie Preferences
    • Privacy Policy
    • Terms of Use
    • Accessibility Statement
    • Statement of Client Rights
    • Purchase Order Terms & Conditions
    • Nixon Peabody International LLC
    • PAL
    © 2025 Nixon Peabody. All rights reserved