Regional regulatory context

Vendor risk and data privacy in United States

The US has a sectoral privacy framework rather than a comprehensive federal privacy law. HIPAA governs health data, GLBA governs financial institutions, COPPA governs children's data, and a growing set of state laws (CCPA/CPRA, Virginia, Colorado, Connecticut) fill the gap.

Applicable regulations

  • HIPAA
  • GLBA
  • CCPA/CPRA
  • COPPA
  • FedRAMP

Hosting considerations

US hosting is standard for most commercial vendors. Federal government workloads require FedRAMP authorization. State-level data residency requirements are emerging for government contracts in several states.

Common questions

Is there a US equivalent of GDPR?
Not at the federal level. The American Data Privacy and Protection Act (ADPPA) has been debated but not enacted. State laws — CCPA in California, CPA in Colorado, VCDPA in Virginia — provide partial coverage and vary significantly in scope and enforcement.

Which of your vendors operate in US?

TrustVendor tracks vendor hosting regions, subprocessor geographies, and applicable adequacy decisions.

Book a demo