One year after GDPR, US state data privacy legislation still lags
One year after the EU GDPR was implemented, the progress of data privacy legislation in US states has been slow, with fewer than 20 states proposing related bills, most of which have not reached the governor's signing stage. The CCPA, pushed by California Senator Hertzberg, has become a benchmark, but federal legislation is hopeless, and the tension between corporate lobbying and consumer protection demands continues to intensify.

The European Union's General Data Protection Regulation (GDPR) has been in effect for over a year, and while U.S. states have successively initiated similar legislative processes, progress has been slow. Entering its second year, there are no signs that relevant regulatory provisions can be fully implemented.
States are beginning theirdata privacy legislative journeys, althoughCalifornia has blazed a trail, few have followed. Currently, fewer than 20 states have data privacy bills in progress, many of which have died in committee and never reached the governor's desk.
"GDPR hasn't dominated the debate, but it has influenced the attitudes of businesses that realize they must address privacy issues," California Democratic Senator Robert Hertzberg told CIO Dive. Hertzberg helped pass theCalifornia Consumer Privacy Act(CCPA) last year.
Businesses have created an imbalance between themselves and consumers. Extreme cases of data collection and use without consent include Google's search engine and Facebook's social platform, which are driven by consumers providing data in exchange for services.
This often feels more like a "bait-and-switch" than a genuine business transaction.
Hertzberg said exchanging personal identifiable information for free services "is no longer a fair exchange." "I'm a fairly moderate person, but it's reached the point where we need to intervene."
Lawmakers recognize they must act because the core of data privacy lies in consumer protection. However, there are significant disagreements over how far data privacy legislation should go, to the point that lawmakers are "on the brink of doing nothing," Texas Republican Representative Giovanni Capriglione told CIO. Capriglione championed the Texas Privacy Protection Act (TPPA), which has not yet passed.
Currently, Hertzberg and Capriglione have low expectations for federal data privacy law, putting pressure on states to act on their own.
"I see no reason to wait for the federal government," Capriglione said.
Which states have entered the fray
The U.S. lags far behind the EU in crafting comprehensive federal data privacy law, and state-level progress has been slow.
Lawmakers always "hesitate without perfect legislation," Mitchell Noordyke, Westin Fellow at the International Association of Privacy Professionals (IAPP), told CIO Dive.
Noordyke noted that the path to passing a bill is "getting enough parties within a state satisfied with legislation that is 'just good' rather than 'perfect'."
Currently, 14 states have privacy bills that have passed, are pending, or have failed, varying by preference and party stance.
Proposed state data privacy legislation
| State | Bill |
|---|---|
| California | California Consumer Protection Act |
| Connecticut | RB 1108 |
| Hawaii | SB 418 |
| Illinois | HB 3358 |
| Maryland | SB 613 |
| Massachusetts | SD 341/S 120 |
| Nevada | SB 220 |
| New Jersey | S2834 |
| New Mexico | Consumer Information Privacy Act |
| New York | 2019 Right to Know Act |
| North Dakota | HB 1485 |
| Rhode Island | Consumer Privacy Protection Act |
| Texas | Texas Consumer Privacy Act |
| Texas Privacy Protection Act | |
| Washington | Washington Privacy Act |
Source: International Association of Privacy Professionals
Texas has two bills—one similar to GDPR, the other similar to CCPA—which was not intentional. Noordyke said it will be worth watching which bill's language performs better in committee.
The GDPR-like Texas Privacy Protection Act (TPPA) was introduced in March and, unlike the other Texas bill, does not regulate "personal information" but rather "personally identifiable information," defined as "categories of information related to an identified or identifiable person."
After several rounds of legislative process, the TPPA was amended to focus more on data breach notification requirements and "effectively became a committee, which will be a temporary effort to move forward by bringing in a batch of industry reviews," Capriglione said.
Texas is an emerging tech hub, contributing nearly$142 billion。
For a long time, the idea of data privacy and technology regulation made people "think of Silicon Valley, or the Boston area and Washington, D.C.," Capriglione said, "but if you're from Texas, you see that we are a growing high-tech leader."
Despite Capriglione's nonpartisan stance on data privacy, the prospects for both bills remain uncertain.
Noordyke said that in every state with pending bills, the likelihood of a data privacy bill becoming law is below 50%. Both Texas bills "are nearly dead at this point."
According to Noordyke, Washington's bill "looked almost certain to pass," even "passed smoothly through the Senate," but ultimately failed. Illinois has actively pushed privacy and security legislation for over a decade, "so they at least have a record of getting legislation done."
An effective law must benefit consumers, businesses, and individuals alike to attract support from both political sides. Most proposed data privacy bills have not yet satisfied all parties.
Businesses are lobbying for federal law rather than complying with a patchwork of state laws. But as more regulations emerge, and as data increasingly becomes a liability, it becomes easier for businesses to establish GDPR- or CCPA-style privacy standards.
Lawmakers agree that despite rising interest, federal privacy law is unlikely in the short term. The Federal Trade Commission (FTC) is seekinggreater enforcement authority, while the nation still awaits federal privacy law.
The political climate is forcing data privacy to become more of a state-level issue. "I'd be shocked if the federal government passed two consecutive budgets," Capriglione said.
What businesses want
Data privacy laws ultimately come down to consumers wanting their data not to be stolen, traded, sold, or leaked without consent. Critics argue that data privacy laws like CCPA aretoo burdensome for businesses, calling for limits on the scope of the law. "Lawmakers will be sensitive to anything that could harm (businesses)," Noordyke said, and the same applies to consumers and companies.
Washington state is home to tech giants Amazon and Microsoft. Disrupting these companies' business practices could directly impact the state's economy.Amazon's Seattle headquartersprovides over 40,000 jobs and approximately $3.7 billion in capital investment to the city.
While privacy is a top concern for government officials, they are also sensitive to how data privacy laws might affect small businesses' ability to compete or bear the financial burden that laws inevitably bring. Large businesses can absorb the financial requirements of the law, but this couldstifle their innovation capabilities。
Some view data protection as a civil rights issue. "This isn't a political issue at all, but more of a human rights issue," Capriglione said.
Washington state'snow-defunct proposed legislationhad included lenient provisions on facial recognition technology. The American Civil Liberties Union (ACLU) and other human rights organizations expressed concerns about the technology's biases and uses.
The ACLU claimed Washington's bill was not a true consumer protection law. "The first problem is that it was written by the tech companies themselves," Shankar Narayan, director of the ACLU's Technology and Liberty Project, said in aKiro Radio interview.
In Narayan's view, the bill was full of loopholes that would allow businesses to override consumers' data consent rights.
Microsoft was a supporter of the bill. "We believe this is the only way to avoid losing all standards and racing to the bottom," Microsoft President Brad Smith said in March at the University of Washington, asreported by GeekWire。
In Microsoft's view, Washington's proposed privacy bill was best suited as a model for the federal government.
The traditional tech company recently praised CCPA as a "good starting point," but federal law should go further, Microsoft Corporate Vice President and Deputy General Counsel Julie Brillwrote in a blog post on Monday. "One way to achieve this is to require assessments that weigh the benefits of data processing against the potential privacy risks to the individuals whose data is processed."
Essentially, Brill believes tech companies should bear the burden of data privacy responsibility rather than leaving consumers to navigate opt-out mechanisms on their own.
However, data privacy laws have far less impact on Microsoft's profits than on companies that call themselves tech companies. Ultimately, Microsoft sells technology products and services, not platforms driven by personalized advertising.
"At Microsoft, we believe our customers' data belongs to our customers, employees, and customers themselves, so we will never use customer data for any Microsoft commercial purpose," Shelley Bransten, Microsoft's Corporate Vice President of Global Retail and Consumer Goods, said last year inan email to CIO Dive。
Nevertheless, Microsoft remains in the tech sector, alongside companies like Google, Amazon, and Facebook, all of which are protecting their own interests in data privacy legislation.