Laws

This section is a reference library of the laws, regulations, and regulatory frameworks that Rob Melton Law advises on. Each entry explains what the law requires, who it covers, and what businesses need to do to comply. The library is organized by subject area and updated as new laws take effect and existing ones are amended. If you are trying to understand a specific legal framework, assess whether a particular law applies to your business, or find substantive guidance on a compliance question, start here.


Privacy & Data Protection

Privacy law has become one of the most complex compliance challenges for US businesses. A patchwork of US federal laws, US state privacy statutes, and international data protection regimes now governs how companies collect, process, share, and retain personal information — with different rules applying depending on the nature of the data, the jurisdiction, and the type of company involved. The resources below cover the major frameworks.

US Federal Privacy Laws

HIPAA (Health Insurance Portability and Accountability Act) governs the privacy and security of protected health information held by covered entities and their business associates. It is one of the most extensively litigated and enforced federal privacy laws in the US. Key topics include the Privacy Rule, the Security Rule, breach notification obligations, business associate agreements, and the minimum necessary standard. See: HIPAA Minimum Necessary Rule · Do You Need a BAA With Every Vendor? · BAA Negotiation Guide

COPPA (Children’s Online Privacy Protection Act) restricts the online collection of personal information from children under age 13 and requires verifiable parental consent before collecting, using, or disclosing that information. It applies to operators of commercial websites and online services directed to children and to general-audience platforms with actual knowledge that they are collecting personal information from children.

FERPA (Family Educational Rights and Privacy Act) protects the privacy of student education records and applies to educational agencies and institutions that receive funding from the US Department of Education. Technology companies that provide services to schools and universities — including SaaS platforms, cloud storage, and learning management systems — must comply with FERPA’s requirements governing the access and disclosure of student records.

FCRA (Fair Credit Reporting Act) governs the collection, accuracy, and use of consumer credit information by consumer reporting agencies and the employers and lenders who use consumer reports. It imposes specific obligations on employers conducting background checks, including disclosure and authorization requirements and adverse action procedures.

TCPA (Telephone Consumer Protection Act) restricts telemarketing calls, auto-dialed calls, prerecorded messages, and text messages. It also governs the National Do Not Call Registry. TCPA class action litigation is one of the most active areas of consumer protection enforcement in the US, with statutory damages of $500–$1,500 per violation making large-scale non-compliance extraordinarily expensive.

CAN-SPAM Act establishes requirements for commercial email messages, including mandatory opt-out mechanisms, accurate header information, and physical address disclosure. It applies to any business sending commercial email, regardless of size.

Illinois Biometric Information Privacy Act (BIPA) requires companies to obtain informed written consent before collecting biometric identifiers — including fingerprints, retina scans, facial geometry, and voiceprints — and mandates specific data retention and destruction schedules. BIPA is the most heavily litigated state biometric privacy law in the country and has generated class action settlements in the hundreds of millions of dollars.

Video Privacy Protection Act (VPPA), enacted in 1988, prohibits the disclosure of personally identifiable information relating to video content rentals or purchases without written consent. In recent years, plaintiffs have used the VPPA to pursue class actions against websites that embed video content and use tracking technologies that share viewing data with third parties, significantly expanding the law’s practical reach.

US State Privacy Laws

California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA) is the most comprehensive US state privacy law and the framework against which all other state laws are measured. The CCPA as amended by the CPRA gives California consumers the rights to know, delete, correct, and opt out of the sale or sharing of their personal information, and imposes significant obligations on businesses that meet the law’s revenue, data volume, or data sale thresholds. The California Privacy Protection Agency actively enforces the law. Rob has published an extensive series on CCPA compliance. See: Intro to the CCPA for Service Providers · CCPA Data Subject Rights · CCPA Contract Requirements · CCPA Use and Retention Rules · CCPA Enforcement Guide · “Do Not Sell or Share” CCPA Compliance

More than twenty additional US states have now enacted comprehensive privacy laws, including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), and Washington state. These laws share a common architecture with the CCPA but differ in important details — including applicability thresholds, consumer rights, and enforcement mechanisms. Businesses that are compliant with CCPA are typically well-positioned for multi-state compliance but must review the specific requirements of each state where they have meaningful consumer data exposure.

Washington My Health My Data Act (MHMDA) is among the most expansive health privacy laws enacted by any US state. Unlike HIPAA, it is not limited to covered entities and business associates — it applies to any company that collects or processes the health data of Washington residents, covering a much broader range of consumer health information including menstrual tracking, location data near healthcare facilities, and other data inferences about health conditions. See: Overview of the Washington My Health My Data Act

International Privacy Laws

GDPR (General Data Protection Regulation) is the EU’s comprehensive data protection law, in force since May 2018. It applies to any organization that processes the personal data of EU residents, regardless of where the organization is located — giving it global reach for any US business with EU customers, employees, or users. The GDPR imposes obligations across the full data life cycle: lawful basis for processing, transparency and notice, data subject rights, data minimization, security, breach notification, data transfer restrictions, and accountability documentation including records of processing activities. Penalties can reach €20 million or four percent of global annual turnover, whichever is higher. See: GDPR vs. CCPA Comparison · How to Negotiate a DPA · Data Protection Audit Rights · Data Mapping for Privacy Compliance

The following guides cover the privacy laws of major jurisdictions that US businesses commonly encounter. Each guide explains what the law requires, who it covers, and how it compares to the GDPR and CCPA frameworks US compliance teams are most familiar with.

  • Australia’s Privacy Act 1988 — Federal privacy framework applying to businesses above a revenue threshold, covering Australian Privacy Principles and cross-border data transfer rules
  • Brazil’s LGPD — Brazil’s General Data Protection Law, a GDPR-influenced framework with important differences in enforcement and data subject rights
  • China’s Data Privacy Laws — China’s interlocking data protection regime: the Personal Information Protection Law (PIPL), Data Security Law (DSL), and Cybersecurity Law (CSL)
  • India’s Digital Personal Data Protection Act (DPDPA) — India’s first comprehensive data protection law, with phased implementation and significant implications for US businesses processing Indian consumer data
  • Japan’s Act on the Protection of Personal Information (APPI) — Japan’s amended privacy law, with strengthened consent requirements and cross-border transfer restrictions
  • South Africa’s POPIA — South Africa’s Protection of Personal Information Act, with its distinct territorial trigger and Information Regulator enforcement regime
  • Canada’s PIPEDA — Canada’s federal private sector privacy law and provincial laws in Quebec, Alberta, and BC (guide coming soon)
  • UK GDPR — The UK’s post-Brexit data protection framework and how it diverges from the EU GDPR (guide coming soon)
  • Switzerland’s revised Federal Act on Data Protection (FADP) — Switzerland’s modernized privacy law aligning with GDPR standards (guide coming soon)
  • Saudi Arabia’s Personal Data Protection Law (PDPL) — Saudi Arabia’s evolving privacy framework for companies processing Saudi resident data (guide coming soon)
  • Philippines Data Privacy Act — The Philippines’ comprehensive data protection framework for US businesses with Philippine operations (guide coming soon)
  • Quebec Law 25 — Quebec’s privacy modernization law and its implications for US businesses with Quebec users or employees (guide coming soon)

Artificial Intelligence & Emerging Technology

EU AI Act is the world’s first comprehensive, binding legal framework for artificial intelligence. It entered into force on August 1, 2024, and applies to US businesses that develop, deploy, or import AI systems for use in the EU. The law classifies AI systems by risk level — from unacceptable risk (prohibited) to high risk (requiring conformity assessments, technical documentation, and human oversight) to limited and minimal risk — and imposes distinct compliance obligations at each tier. It also imposes specific obligations on providers of general-purpose AI models (such as large language models). See: What US Businesses Need to Know About the EU AI Act

US State AI Laws are proliferating rapidly. California has enacted a suite of AI-related statutes addressing deepfakes, AI-generated content disclosure, automated decision-making in employment, and healthcare AI. Colorado’s Artificial Intelligence Act regulates high-risk AI systems used in consequential decisions. Utah’s AI Policy Act imposes transparency requirements. Texas, Illinois, and other states are actively considering or have enacted AI legislation. Compliance with US state AI law requires ongoing monitoring as the landscape continues to develop.

Agentic AI — autonomous AI systems that take real-world actions, orchestrate other AI agents, and make decisions without continuous human oversight — presents a distinct set of legal and compliance challenges that do not map neatly onto existing regulatory frameworks. Rob has published extensively on the governance, data protection, and liability implications of agentic AI deployment. See: AI Governance and Compliance Safeguards for Agentic AI · Five Challenges of Agentic AI for Compliance Teams · OWASP Top 10 for Agentic AI · Securing AI Agents · Fulfilling the Right to Delete in Agentic AI · How GDPR Applies to AI Model Training

Take It Down Act is a 2025 federal law requiring online platforms to remove non-consensual intimate imagery — including AI-generated deepfakes — upon receiving a valid takedown request. It creates new content moderation obligations for covered platforms. See: Take It Down Act Overview


Cybersecurity & Incident Response

State Security Breach Notification Laws require businesses to notify affected individuals, and in many cases regulators, when a security breach exposes personal information. All fifty US states, the District of Columbia, and several US territories have enacted breach notification laws, and the requirements — including the definition of personal information covered, the notification timeline, and the required content of notices — vary significantly across jurisdictions. See: Security Incident Notification Laws Guide

NYDFS Cybersecurity Regulation (Part 500) is New York’s mandatory cybersecurity framework for financial services companies licensed in New York, including insurers, banks, and mortgage companies. It requires covered entities to maintain a written cybersecurity program, conduct annual penetration testing, implement multi-factor authentication, and report material cybersecurity events to the NYDFS within 72 hours.

EU Digital Operational Resilience Act (DORA) imposes mandatory cybersecurity and operational resilience requirements on financial entities operating in the EU and, critically, on the ICT service providers — including cloud providers, data analytics firms, and software vendors — that provide services to those financial entities. US technology companies with EU financial sector customers need to understand whether DORA’s ICT third-party provider requirements apply to them.

For guidance on building the legal and operational infrastructure to respond to a security incident, see: Developing an Effective Incident Response Plan · Planning a Tabletop Exercise · Reviewing Cyber Insurance · Preparing With External Vendors


Healthcare Privacy & Compliance Laws

HIPAA is the foundational federal healthcare privacy and security law in the US. The Privacy Rule establishes national standards for the protection of protected health information (PHI) and governs how covered entities and their business associates may use and disclose it. The Security Rule requires covered entities and business associates to implement administrative, physical, and technical safeguards to protect electronic PHI. The Breach Notification Rule requires covered entities to notify affected individuals, the HHS Office for Civil Rights, and in some cases the media when unsecured PHI is compromised. See: HIPAA Minimum Necessary Rule · BAA Requirements

Anti-Kickback Statute and Stark Law are the principal federal laws governing financial relationships in the healthcare industry. The Anti-Kickback Statute prohibits the payment or receipt of remuneration to induce or reward referrals of items or services covered by federal healthcare programs. The Stark Law (Physician Self-Referral Law) prohibits physicians from referring Medicare patients for designated health services to entities in which the physician has a financial relationship, unless an exception applies. Both laws are among the most frequently used bases for False Claims Act enforcement actions.

42 CFR Part 2 provides heightened confidentiality protections for records relating to the diagnosis, treatment, or referral for treatment of substance use disorders. Part 2 is significantly more restrictive than HIPAA in many respects and is frequently relevant to behavioral health organizations, integrated health systems, and health IT companies that handle substance use disorder treatment records.


Anti-Corruption, Sanctions & Export Controls

Foreign Corrupt Practices Act (FCPA) is the principal US anti-bribery law governing payments to foreign government officials. It applies to US issuers, US domestic concerns, and foreign companies and individuals acting in furtherance of a corrupt payment within US territory. Its accounting provisions apply to all issuers of US securities, regardless of where the potentially corrupt conduct occurred. The DOJ and SEC jointly enforce the FCPA, and penalties in large cases have reached hundreds of millions of dollars. See: The DOJ’s New Corporate Enforcement and Voluntary Self-Disclosure Policy

OFAC Sanctions Programs administered by the Office of Foreign Assets Control of the US Treasury Department prohibit transactions with sanctioned countries, entities, and individuals. US persons — including US companies and their non-US subsidiaries in some circumstances — are prohibited from engaging in transactions with SDN-listed parties and from conducting business in or with comprehensively embargoed jurisdictions. Sanctions compliance requires ongoing screening of customers, vendors, and counterparties against government-maintained lists.

Export Administration Regulations (EAR), administered by the Bureau of Industry and Security (BIS) at the Department of Commerce, govern the export and re-export of commercial and dual-use goods, software, and technology. Companies exporting controlled items — including software, encryption technology, semiconductors, and AI systems — must classify their products under the Commerce Control List, determine whether a license is required, and screen end users against denied party lists. See: Voluntary Self-Disclosure Under the EAR

ITAR (International Traffic in Arms Regulations), administered by the State Department’s Directorate of Defense Trade Controls, govern the export of defense articles and services on the US Munitions List. ITAR registration is mandatory for companies that manufacture, export, or import USML items, and most transactions involving controlled defense items require an export license. ITAR compliance is particularly demanding and the penalties for violations are severe.


ESG & Climate Disclosure

California Climate Disclosure Laws (SB 253 and SB 261): California’s Climate Corporate Data Accountability Act (SB 253) requires companies with over $1 billion in annual revenues doing business in California to publicly disclose their Scope 1, Scope 2, and Scope 3 greenhouse gas emissions on an annual basis — with the first Scope 1 and Scope 2 deadline on August 10, 2026. SB 261, which requires biennial climate-related financial risk reports from companies with over $500 million in revenues, is currently enjoined by the Ninth Circuit pending appeal. Both laws apply to public and private companies alike.

SEC Climate Disclosure Rules: The SEC adopted comprehensive climate disclosure rules for public companies in March 2024, requiring disclosure of climate-related risks, governance, strategy, GHG emissions, and climate-related financial statement impacts. The rules were challenged in court, stayed, and abandoned by the SEC in March 2025 under the new Trump administration. They have never taken effect — but the underlying materiality obligations under existing securities law continue to require public companies to disclose material climate-related risks.

EU Corporate Sustainability Reporting Directive (CSRD) requires large companies with significant EU operations or revenues to report on a comprehensive range of ESG matters under the European Sustainability Reporting Standards. US companies with EU-listed securities or net EU turnover exceeding €150 million and a qualifying EU subsidiary or branch will be subject to CSRD reporting on a phased schedule. The CSRD’s climate-related reporting requirements are more detailed and demanding than either the SEC’s (now-abandoned) rules or California’s laws.


Financial Services & Digital Assets

GLBA (Gramm-Leach-Bliley Act) requires financial institutions to protect the security and confidentiality of nonpublic personal information about their customers. The FTC’s Safeguards Rule, updated in 2023, significantly strengthened the GLBA security program requirements for non-bank financial institutions including mortgage brokers, auto dealers, and FinTech companies, requiring written information security programs, penetration testing, and encryption of customer data in transit and at rest.

Cryptocurrency & Digital Asset Laws: The regulatory framework for digital assets in the US has undergone a significant transformation. The SEC and CFTC released landmark joint guidance in March 2026 establishing the most comprehensive interpretive framework for crypto assets since The DAO Report in 2017. The GENIUS Act, enacted July 2025, established the first federal regulatory framework for payment stablecoins. See: Cryptocurrency Laws Overview · GENIUS Act: US Stablecoin Regulation


Corporate Governance

Corporate Governance & Directors and Officers (D&O): The legal framework governing the duties, obligations, and liability of directors and officers of US corporations. Core topics include fiduciary duties, the business judgment rule, the Caremark oversight standard, director independence, D&O insurance, indemnification, and shareholder litigation. See: Corporate Governance & D&O Overview


More Resources

The guides in this section are supplemented by the articles and analyses published in the Insights section of the site, which covers current regulatory developments, enforcement trends, and practical compliance guidance across all of the practice areas listed here. If you are looking for information on a specific law or compliance question that is not yet covered in this library, or if you would like to discuss how a particular legal framework applies to your business, contact Rob for a free consultation.


In This Section