🥝GuideKiwi
Free Guide

Free Guide to Understanding Data Protection Laws

What Data Protection Laws Are and Why They Matter Data protection laws are rules that control how organizations collect, store, use, and share personal infor...

What Data Protection Laws Are and Why They Matter

Data protection laws are rules that control how organizations collect, store, use, and share personal information about people. These laws exist in countries around the world, and they have grown more important as businesses and governments collect more data about us every day. Personal data includes information like your name, address, phone number, email, social security number, financial information, health records, and even your online activity.

In the United States, data protection is handled differently than in many other countries. The U.S. does not have one single national data protection law. Instead, there are separate laws for different industries and types of data. For example, the Health Insurance Portability and Accountability Act (HIPAA) protects health information, the Gramm-Leach-Bliley Act (GLBA) protects financial information, and the Children's Online Privacy Protection Act (COPPA) protects information about children under 13. California, Virginia, Colorado, Connecticut, and Utah have passed their own state-level data protection laws that give residents more control over their personal information. This patchwork approach means that the rules depend on where you live and what type of information is being collected.

In Europe, the situation is different. The General Data Protection Regulation (GDPR), which took effect in 2018, is a comprehensive law that applies across all European Union countries. It gives people strong rights over their data and requires organizations to follow strict rules about how they handle it. Other countries like Canada, Brazil, Australia, and Japan have also passed their own data protection laws.

Understanding these laws matters for several reasons. First, if you live in a place with data protection laws, you have legal rights regarding your personal information. Knowing what those rights are can help you protect yourself. Second, businesses need to understand these laws to stay compliant—failure to follow data protection rules can result in large fines and damage to a company's reputation. According to the International Association of Privacy Professionals (IAPP), organizations spent an estimated $15.4 billion on data protection and privacy in 2023. Third, as data collection grows, these laws are becoming stricter and more common worldwide.

Practical Takeaway: Data protection laws vary significantly by location and industry. Before trying to understand your rights or obligations, identify which laws apply to your situation based on where you live and what type of data is involved.

How Organizations Collect and Use Your Data

Every time you use the internet, make a purchase, visit a doctor, or interact with a business, data about you is being collected. Understanding how this happens is the first step to understanding why data protection laws exist. Organizations collect data both directly and indirectly. Direct collection happens when you intentionally provide information—for example, filling out a form with your name and email address, creating an online account, or providing your payment information. Indirect collection happens when companies track your behavior without you actively providing information, such as collecting data about which websites you visit, what you buy, how long you spend on a page, or your location.

Companies use collected data for many reasons. Marketing is one of the most common uses. If you buy something online, that retailer may track your purchase history to recommend similar products in the future. Advertisers may collect data about your browsing habits to show you targeted ads. According to a 2023 Pew Research Center survey, 81% of Americans said the risks of data collection by companies outweigh the benefits. Data is also used for customer service, fraud prevention, product development, and credit decisions. Insurance companies use data to assess risk and set rates. Banks use data to detect suspicious activity. Employers use data during the hiring process. Healthcare providers use data to treat patients and conduct medical research.

The scope of data collection has grown dramatically. In 2024, the global datasphere—the amount of data created, captured, and copied—reached approximately 147 zettabytes, according to industry estimates. One zettabyte equals one trillion gigabytes. Mobile devices, smart home technology, social media platforms, and internet-connected devices (called the Internet of Things or IoT) have all increased the amount of data being collected about individuals. Many people don't realize how much data is collected because it happens invisibly in the background.

Data can also be sold or shared between organizations. A data broker is a company that collects personal information and sells it to other companies. Sometimes this happens without people knowing about it. For example, a data broker might purchase home address information from public records, combine it with phone numbers and email addresses purchased from other sources, and then sell this compiled profile to marketers. The Federal Trade Commission (FTC) published a report in 2024 showing that major data brokers handle billions of data points on American consumers.

Practical Takeaway: Data collection is ongoing and often invisible. Be aware of what information you're sharing directly (through forms and accounts) and what information companies may be collecting indirectly (through tracking your behavior and online activity).

Your Rights Under Data Protection Laws

Data protection laws give people specific rights regarding their personal information. These rights vary depending on which law applies to you, but common rights include the right to know, the right to access, the right to correct, the right to delete, and the right to control how your data is used. Understanding these rights is important because they give you power over your personal information.

The right to know means organizations must tell you that they're collecting your data and explain how they'll use it. This is typically done through a privacy policy—a legal document that describes what data a company collects, why they collect it, how they use it, and who they share it with. Under GDPR in Europe, companies must get your consent before collecting certain types of data, and they must clearly explain why they need it. The right to access means you can ask an organization to give you a copy of all the personal data they have about you. Under GDPR, companies must respond to access requests within 30 days. Under California's Consumer Privacy Act (CCPA), companies have 45 days to respond. The right to correct means if data about you is wrong, you can ask the organization to fix it. For example, if your address is listed incorrectly, you can request a correction.

The right to delete, also called the right to be forgotten, allows you to ask organizations to remove your personal data. However, this right is not absolute. Organizations can often refuse to delete data if they have a legal reason to keep it, such as for tax purposes or to complete a transaction you started. The right to control how your data is used means you can object to certain uses of your data. For example, you might be able to opt out of targeted advertising or refuse to allow your data to be used for automated decision-making. Under GDPR, individuals have the right to know if an automated system is being used to make decisions about them, and they can ask for human review of those decisions.

Some laws also give people rights related to data breaches. A data breach occurs when unauthorized people access data they shouldn't be able to access. Most laws require companies to notify people if a breach happens and their data was exposed. Under federal law in the U.S., companies generally must notify people within 60 days of discovering a breach. California law requires notification without unreasonable delay. In 2023, the Average Cost of a Data Breach Study found that the average cost of a data breach to organizations was $4.45 million, and breaches exposed an average of 25,899 records per incident.

Practical Takeaway: You likely have rights over your personal data, but these rights depend on where you live and the type of data involved. Look up the specific laws that apply to you, and don't hesitate to contact organizations directly to exercise your rights—they are required to respond to reasonable requests.

How Data Protection Rules Work in Different Industries

Different industries handle data protection differently because various laws apply to different sectors. Healthcare is one of the most heavily regulated industries. HIPAA, passed in 1996, applies to healthcare providers, health insurance companies, and healthcare clearinghouses. Under HIPAA, covered entities must protect patient privacy and keep medical records secure. Patients have the right to view their medical records, get copies of them, and request corrections. Healthcare data is considered especially sensitive because it involves personal health information that could be used to discriminate against or harm people. A HIPAA violation can result in fines ranging from $100 to $50,000 per violation, with annual maximums reaching into the millions of dollars.

The financial services industry is regulated by the Gramm-Leach-Bliley Act (GLBA), passed in 1999

🥝

More guides on the way

Browse our full collection of free guides on topics that matter.

Browse All Guides →