• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
CommentaryData Security

States Are Getting Tough on Data Security—but That Might Be a Problem

By
Greg Arnette
Greg Arnette
Down Arrow Button Icon
By
Greg Arnette
Greg Arnette
Down Arrow Button Icon
May 2, 2018, 3:10 PM ET

The Facebook-Cambridge Analytica scandal is the latest of many incidents in recent years that have left consumers jittery about the security of their online personal information. It also is yet another event that shines a bright light on the need for more regulation protecting data.

But while data security becomes an ever more pressing issue for businesses and users, the Trump administration’s anti-regulation fervor has translated into little to no new federal action enforcing it.

What happens when an unstoppable force meets an immovable object? In this case, states are stepping in with their own cybersecurity measures. More than 240 bills were introduced in 42 states last year covering a range of security issues, from improving government practices to restricting public disclosure of confidential information, according to the National Conference of State Legislatures.

Interestingly, the willingness of the states to wade into cybersecurity regulation is both a positive development and a potentially problematic one.

First, let’s explore the good.

Some states are breaking new ground as they force companies to be more accountable for maintaining the security of personal information.

For example, a regulation called 23 NYCRR Part 500 that went into effect in New York in March 2017 established detailed security rules for financial services companies, which of course hold some of the most sensitive customer data.

In California, tough legislation has been introduced that would require any company selling an Internet-connected device to equip it with features that protect it from unauthorized access and to obtain consumer consent before it collects or transmits information.

In Illinois, lawmakers considered a bill requiring public utilities operating in the state to report annually on the vulnerability of the state’s water supply system to cyberattacks.

Such measures show that the states are serving as catalysts for better cybersecurity, with ideas that can be replicated in other states and, hopefully one day, nationally. The situation is analogous to health care policy in the years before Obamacare, when, in the absence of a federal consensus, Massachusetts pioneered its own law aimed at reforming health insurance (which later became a model for the Affordable Care Act).

Some of these state measures seem more in step with efforts in other countries to protect personal data—such as the European Union’s General Data Protection Regulation (GDPR), which goes into effect May 25—than with the U.S. administration’s anti-regulation fervor.

But there’s a fly in the ointment in states’ individual action on cybersecurity—the prospect of a patchwork of different laws governing something, the Internet, that knows no geographical borders.

For example, 48 states mandate that private or government organizations notify individuals of security breaches of information involving personally identifiable information. (The remaining two—South Dakota and Alabama—are working on similar rules.) But the laws can be inconsistent and confusing to comply with across the various states.

“For businesses doing business in multiple states, the different and confounding state laws make responding to a data breach in an appropriate, timely and in a compliant fashion very difficult,” asserted Stephen Embry in an American Bar Association blog post. “This is compounded by the aftermath of a breach being filled with the uncertainty, concern, and even panic that any emergency brings. Add to that the multiple competing interests in such a situation and the opportunity for a wrong decision with significant consequences is magnified many times over.”

Some worry about even more serious, constitutional issues.

A nationwide assortment of state cybersecurity regulations “raises the issue of whether such regulations violate the U.S. Constitution’s ‘dormant’ Commerce Clause, which restricts states’ ability to discriminate against or unduly burden interstate commerce,” write Matthew A. Schwartz and Corey Omer for the Clearing House, a banking and payments trade group.

All this said, with scant new regulatory activity on the horizon at the federal level, siloed statutes at the state level are a whole lot better than nothing. Let’s just hope that the innovation taking place at the state level eventually finds its way into the uniform, national set of policies that we really need.

Greg Arnette is the director of data protection platform strategy at Barracuda, a Thoma Bravo company. Previously, he was founder and CTO of Sonian, a cloud archiving company that was acquired by Barracuda in November 2017.

About the Author
By Greg Arnette
See full bioRight Arrow Button Icon

Latest in Commentary

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Commentary

hollywood
CommentaryMarketing
I spent 20 years learning to navigate an industry. Then I built a campaign for the man who’s dismantling it
By Matti YahavApril 29, 2026
6 hours ago
aging
HealthLongevity
We’re the CEOs of Peloton and the Hospital for Special Surgery. Living longer isn’t enough, we need to live better, too
By Bryan T. Kelly and Peter SternApril 29, 2026
7 hours ago
gen z
Commentarydisruption
AI won’t kill your job — it will kill the path to your first one
By Jeffrey Sonnenfeld, Stephen Henriques, Johan Griesel, Andrew Alam-Nist and Peter YuApril 29, 2026
8 hours ago
greer
CommentaryTariffs
No, tariffs are not strengthening the economy
By Alex DuranteApril 29, 2026
9 hours ago
AI is changing who gets to be an expert. Are your colleagues ready to become ‘directors of intelligence’?
AIProductivity
AI is changing who gets to be an expert. Are your colleagues ready to become ‘directors of intelligence’?
By Bruce BroussardApril 29, 2026
10 hours ago
gen z
CommentaryEducation
Gen Z has the wrong idea about college. Your career doesn’t start after you graduate 
By Ashley BigdaApril 29, 2026
11 hours ago

Most Popular

Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
Success
Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
By Preston ForeApril 27, 2026
2 days ago
‘The cost of compute is far beyond the costs of the employees’: Nvidia executive says right now AI is more expensive than paying human workers
AI
‘The cost of compute is far beyond the costs of the employees’: Nvidia executive says right now AI is more expensive than paying human workers
By Sasha RogelbergApril 28, 2026
2 days ago
‘Take the money and run’: Johns Hopkins economist Steve Hanke on why the UAE quit OPEC
Energy
‘Take the money and run’: Johns Hopkins economist Steve Hanke on why the UAE quit OPEC
By Shawn TullyApril 29, 2026
13 hours ago
Current price of gold as of April 28, 2026
Personal Finance
Current price of gold as of April 28, 2026
By Danny BakstApril 28, 2026
1 day ago
The U.S. military may have already used up half of its most expensive missiles, and it could take up to 4 years to rebuild its stockpiles
Politics
The U.S. military may have already used up half of its most expensive missiles, and it could take up to 4 years to rebuild its stockpiles
By Sasha RogelbergApril 24, 2026
5 days ago
Current price of silver as of Tuesday, April 28, 2026
Personal Finance
Current price of silver as of Tuesday, April 28, 2026
By Joseph HostetlerApril 28, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.