Regional regulatory context
Vendor risk and data privacy in United States
The US has a sectoral privacy framework rather than a comprehensive federal privacy law. HIPAA governs health data, GLBA governs financial institutions, COPPA governs children's data, and a growing set of state laws (CCPA/CPRA, Virginia, Colorado, Connecticut) fill the gap.
Applicable regulations
- HIPAA
- GLBA
- CCPA/CPRA
- COPPA
- FedRAMP
Hosting considerations
US hosting is standard for most commercial vendors. Federal government workloads require FedRAMP authorization. State-level data residency requirements are emerging for government contracts in several states.
Common questions
Is there a US equivalent of GDPR?
Not at the federal level. The American Data Privacy and Protection Act (ADPPA) has been debated but not enacted. State laws — CCPA in California, CPA in Colorado, VCDPA in Virginia — provide partial coverage and vary significantly in scope and enforcement.
Which of your vendors operate in US?
TrustVendor tracks vendor hosting regions, subprocessor geographies, and applicable adequacy decisions.
Book a demo