Blog: US Privacy Laws

Page 2

Jurisdictional Conflicts: What Happens When GDPR and CCPA Apply at the Same Time?

If you collect or use individuals' personal information through your website, app, or service, you likely already know that it's essential to comply with applicable privacy laws. But what happens when you are subject to both the European Union's (EU) General Data Protection Regulation (GDPR) and the California Consumer Privacy...

Can You Host EU Data in the U.S. Under the Data Privacy Framework (DPF) and Still Be Sued Under GDPR?

The EU-U.S. Data Privacy Framework (DPF) was adopted in July of 2023. It effectively replaced the now-invalidated Privacy Shield and helped give some clarity to U.S. companies who receive personal data from individuals located in the EU. However, many legal experts and privacy advocates have cautioned that DPF certification is not...

When Does CPRA Apply to B2B Communications?

If your business collects or uses personal information belonging to California residents-including as part of B2B communications-it's important to understand the circumstances in which you may be required to comply with the California Privacy Rights Act (CPRA). This article explains what CPRA and B2B communications are, whether CPRA applies to...

Serving U.S. Customers from the EU? Key GDPR Considerations Explained

The General Data Protection Regulation (GDPR) is an EU law that works to protect the privacy rights of EU residents. Businesses that collect or process personal data from people within the EU must comply with the GDPR. But what about if your company is located in the EU and your customers...

Does the GDPR Apply to Employee Data for U.S. Companies with EU Contractors?

The General Data Protection Regulation (GDPR) imposes strict obligations on companies around the world when it comes to how they can process the personal data of EU residents. U.S.-based companies that work with EU-based freelancers, contractors, or remote hires often aren't sure whether or not the GDPR applies to the handling...

How U.S. Companies Can Inadvertently Trigger LGPD Enforcement in Brazil

Brazil's Lei Geral de Proteção de Dados (LGPD) has strict compliance requirements for companies that handle the personal data of Brazilian residents. U.S.-based companies - namely eCommerce and SaaS companies - may be required to comply with the LGPD if they have customers or users located in Brazil. This article will...