• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Commentarydata privacy

California’s New Data Privacy Law Could Begin a Regulatory Disaster

By
Danny Allan
Danny Allan
Down Arrow Button Icon
By
Danny Allan
Danny Allan
Down Arrow Button Icon
October 23, 2018, 2:12 PM ET
The Facebook login screen is seen is seen on an iPhone in this photo illustration on May 25, 2018.
The Facebook log in screen is seen is seen on an iPhone 8 plus in this photo illustration on May 25, 2018. (Photo by Jaap Arriens/NurPhoto via Getty Images)Jaap Arriens—NurPhoto via Getty Images

When the European Union adopted the General Data Protection Regulation (GDPR) in 2016, many in the technology industry saw it as just the first of many such data privacy laws to come.

They were right. And, as a result, we may be on the brink of a convoluted regulatory disaster.

In June, California became the first U.S. state to pass its own data privacy law, the California Consumer Privacy Act. When it goes into effect on Jan. 1, 2020, the act will provide the state’s 40 million residents with rights similar to those granted to European citizens through the GDPR.

The hastily approved act gives all California residents the right to see what personal information is being collected by businesses and to request that this data be deleted. They will also be able to discover whether organizations are selling their information to third parties, such as advertisers, and to request those organizations stop doing so. It will be the most comprehensive data privacy law in the country.

That said, while the GDPR was criticized for being too ambiguous, it looks downright hyper-specific in comparison to the California law. For example, thanks to some loose categorization of businesses to which the act applies, it has the potential to include not just organizations that sell individuals’ data for financial gain, but also websites that collect IP addresses from millions of unique visitors per day.

In 2017 alone, over 1.9 billion files were leaked through security breaches. After the California Consumer Privacy Act comes into force, organizations mishandling data could be fined up to $7,500 for each violation. The financial impact to businesses could be enormous—and that doesn’t even take into account the soft costs associated with loss of customer and employee confidence and damage to brand reputation.

Data privacy regulation in America is about to become seriously confusing. Since the GDPR came into effect, only some states have expanded their data protection regulations to include breach notification requirements. And state laws governing data breaches vary significantly: Texas imposes civil fines of up to $50,000 per violation, while Georgia imposes no penalty at all.

It’s likely that other states will soon pass their own data privacy legislation. Just over half the public (51%) thinks technology companies should be regulated more than they are now, according to a June 2018 report from the Pew Research Center. As security breaches and privacy concerns continue to make headlines, public awareness of and demand for stronger data protection practices are likely to increase.

If each state takes on a local approach to data privacy, America will become a patchwork quilt of regulation, making it an extremely challenging place to do business.

Imagine having to ensure that datasets with personal information on millions of people comply not just with the GDPR, but also with 50 different and sometimes contradictory policies? As people move from one state to another, presumably the rules regulating their data would also change. How can organizations possibly keep track?

This is the stuff CIO nightmares are made of.

What we need is common set of rules for everyone, ideally similar to the GDPR’s, which U.S. organizations doing business in the EU are already following. This would minimize the regulatory burden while also providing U.S. citizens with substantial control over their personal information.

A discussion draft of a new proposed House law, the Data Acquisition and Technology Accountability and Security Act, would create federal standards for breach notification that would preempt state laws. However, the bill is too focused on notifying customers of data theft, failing to provide them with the more comprehensive rights they need to adequately control their personal data. It will need to be strengthened significantly to meet the privacy demands of U.S. citizens.

In any case, Washington needs to act soon. Otherwise, the U.S. may end up with a regulatory scheme that makes GDPR compliance look like a walk in the park.

Danny Allan is the vice president of product strategy at Veeam.

About the Author
By Danny Allan
See full bioRight Arrow Button Icon

Latest in Commentary

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Commentary

Duncan Tait, CEO of Inchcape
Europecar manufacturing
“Competition is good for the industry”. Inchcape CEO’s case for optimism in automotive’s next chapter
By Duncan TaitApril 30, 2026
28 minutes ago
agentic
CommentaryAI agents
Why your data infrastructure — not your AI model — will determine whether Agentic AI scales
By Jeffrey Sonnenfeld, Stephen Henriques, Catherine Dai and Zander JeinthanuttkanontApril 30, 2026
3 hours ago
hoskins
Commentaryoffices
Gensler Co-Chair: Hot-desking was supposed to save money. It may be costing you your culture
By Diane HoskinsApril 30, 2026
5 hours ago
tillis
CommentaryCongress
Thom Tillis: Free markets built American prosperity. Government intervention puts it at risk
By Thom Tillis and John StanfordApril 30, 2026
6 hours ago
iran
CommentaryIran
The Strait of Hormuz is a data problem, not just a military one
By Erik Bethel and Ami DanielApril 30, 2026
7 hours ago
hollywood
CommentaryMarketing
I spent 20 years learning to navigate an industry. Then I built a campaign for the man who’s dismantling it
By Matti YahavApril 29, 2026
1 day ago

Most Popular

Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
Success
Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
By Preston ForeApril 27, 2026
3 days ago
Jamie Dimon gets candid about national debt: ‘There will be a bond crisis, and then we’ll have to deal with it’
Economy
Jamie Dimon gets candid about national debt: ‘There will be a bond crisis, and then we’ll have to deal with it’
By Eleanor PringleApril 29, 2026
1 day ago
‘They left me no choice’: Powell isn’t going anywhere—blocking Trump from another Fed appointee
Banking
‘They left me no choice’: Powell isn’t going anywhere—blocking Trump from another Fed appointee
By Eva RoytburgApril 29, 2026
20 hours ago
‘The cost of compute is far beyond the costs of the employees’: Nvidia executive says right now AI is more expensive than paying human workers
AI
‘The cost of compute is far beyond the costs of the employees’: Nvidia executive says right now AI is more expensive than paying human workers
By Sasha RogelbergApril 28, 2026
2 days ago
‘Take the money and run’: Johns Hopkins economist Steve Hanke on why the UAE quit OPEC
Energy
‘Take the money and run’: Johns Hopkins economist Steve Hanke on why the UAE quit OPEC
By Shawn TullyApril 29, 2026
1 day ago
Google Cloud revenue is now 18% of Alphabet's business. Is this the beginning of the end of Google's search identity?
Big Tech
Google Cloud revenue is now 18% of Alphabet's business. Is this the beginning of the end of Google's search identity?
By Alexei OreskovicApril 29, 2026
13 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.