Country:美国(特拉华) · Data Privacy
United States (Delaware) · Data Privacy
The U.S. has no comprehensive federal privacy law (only sector laws such as HIPAA, GLBA, COPPA). At the state level, California's CCPA/CPRA is the strictest, followed by others (Virginia, Colorado, etc.). Cross-border transfers rely on SCC / Privacy Shield mechanisms. Delaware's own privacy law is weak; actual compliance depends on the operating state.
Key points
- Federal: no unified privacy law; FTC enforces under unfair/deceptive authority
- California CCPA/CPRA: applies to businesses meeting California revenue/user thresholds, grants access/deletion/opt-out-of-sale rights
- State laws diverge: VA, CO, CT, UT etc. each have their own rights acts
- Cross-border: EU–U.S. data requires SCC or EU-US Data Privacy Framework (Privacy Shield successor)
- Violations: state attorney general penalties + private right of action (California)
- China data outbound obligations (pkulaw verified 2026-07): transferring data to/back to China requires one of three routes — security assessment (CAC Order No. 11), standard contract (Order No. 13), or certification (CAC–SAMR Order No. 20, 2025-10-14); the 2024–2025 stance has eased — Provisions on Promoting and Regulating Cross-Border Data Flows (Order No. 16) and the Network Data Security Management Regulation (State Council Order No. 790) are in effect, with some scenarios exempt from filing.
Procedure
- Map users' states and data processing activities
- Benchmark against CCPA/CPRA to draft privacy policy and opt-out mechanism
- Sign cross-border transfer SCC / certify under Privacy Shield
- Establish data subject request (DSAR) process
Hard requirements
- Privacy policy; opt-out; cross-border mechanism (by operating state)
Costs
Compliance build; multi-state difference management⏱ ⏱ Timeline:Compliance framework before launch⚠ Common risks
- Multi-state law conflicts and compliance cost
- CCPA private right of action → litigation risk
- Conflict with PIPL (see data topic)
Handbook
📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)
Applies to:Chinese-capital enterprises operating via U.S. (Delaware etc.) entities, processing U.S. users/consumers/employees personal data, or transferring data to the U.S.; actual compliance focus depends on the operating state (e.g., California CCPA/CPRA).
Prerequisites
- Clarify the U.S. states reached and user scale
- Determine whether the business threshold of state laws like CCPA/CPRA is met
- Reserve budget for multi-state difference management and compliance
| Step | Action | Owner | Timeline | Cost | Official form / system | Notes & penalties |
|---|---|---|---|---|---|---|
| 1 | Map users' states and processing activities Map user distribution and data processing types (sale/sharing/sensitive info) by state; determine which state privacy laws apply. | Legal / compliance | 2–3 weeks | Internal cost | State applicability matrix, data inventory | California strictest, benchmark CCPA/CPRA first Penalty:Violation under applicable law → state penalty |
| 2 | Benchmark CCPA/CPRA to draft privacy policy and opt-out Publish a privacy policy, provide opt-out mechanisms such as Do Not Sell/Share and Limit Sensitive Data Use, and deploy compliance signals on the site (e.g., GPC). | Legal / product | 2–4 weeks | Internal / development cost | Privacy policy, opt-out links, GPC support | Must cover the broad definition of sale/share Penalty:CCPA/CPRA up to $2,500 per violation (non-intentional) / $7,500 (intentional or involving minors) |
| 3 | Establish DSAR process Establish a process to receive, verify and respond to access, deletion, correction, disclosure requests (CCPA generally 45 days, extendable). | Privacy team / support | Ongoing | Internal cost | DSAR process, identity verification | Must not discriminate against users for exercising rights Penalty:Violation → state attorney general suit |
| 4 | Cross-border transfer mechanism (SCC / Data Privacy Framework) For EU–U.S. transfers, sign Standard Contractual Clauses (SCC) or rely on the EU-US Data Privacy Framework (Privacy Shield successor); transfers back to China require a PIPL outbound mechanism. | Legal | 2–4 weeks | Internal / legal fee | SCC, DPF certification, PIPL outbound documents | The U.S. has no unified federal cross-border restriction, but EU-side must be satisfied Penalty:No lawful cross-border mechanism → EU-side penalty (see EU country) |
| 5 | Establish breach notification and security Establish a security incident response per each state's breach notification law (most states require notice within a reasonable time); implement reasonable security measures. | Security / legal | Ongoing | Internal cost | Incident response plan, state notice templates | State deadlines vary; apply the strictest Penalty:Failure to notify → state penalty and class action |
| 6 | Address private right of action and litigation risk For jurisdictions with private right of action like California, build a defense against breach/privacy-class litigation (legal fees, remediation evidence retention). | Legal | Ongoing | Legal fees | Litigation response plan | CCPA private right of action $100–$750 per consumer per breach Penalty:Class action damages and legal fees |
| 7 | Ongoing compliance and policy updates Track new state legislation (VA/CO/CT/UT etc.), annual review and training. | Compliance | Annual | Internal cost | Annual compliance review | Manage multiple states in parallel Penalty:Continued non-compliance accumulates risk |
✅ Self-check list
⚠ Common pitfalls
Assume no federal law means no compliance needed影响:State laws (esp. California) enforce frequently规避:Benchmark state by state by operating state
Ignore CCPA private right of action影响:Class action high damages规避:Build breach defense and remediation evidence
Misunderstand sharing as only monetary transactions影响:No opt-out provided → penalty规避:Configure opt-out per the broad definition
Transfers back to China ignore PIPL outbound影响:China-side violation规避:Simultaneously complete one of the three outbound routes
Mix up state law differences影响:Some states missed compliance规避:Establish a state-by-state list management
DSAR without identity verification影响:Fraudulent claims / wrongful disclosure规避:Deploy reliable verification process
📅 Ongoing post-incorporation obligations
- Ongoing DSAR response and opt-out maintenance
- State breach notification plan drills
- Track state legislation updates and review
- Employee privacy compliance training
- PIPL outbound mechanism to China remains effective
🔗 Official portals
📎 Source:https://oag.ca.gov/privacy ; https://www.ftc.gov ; https://www.cac.gov.cn
Want to turn this into an actionable compliance workflow?
CompliGo · Outbound Compliance Automation
You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.
CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.