Tag: Data Privacy Law

  • Data Privacy Compliance for SaaS Companies Selling Across State Lines

    Data Privacy Compliance for SaaS Companies Selling Across State Lines

    If your SaaS company sells to customers in more than one state, and most do by design, you are likely already subject to more than one state’s privacy law, whether or not your company is headquartered in that state. What began with California’s Consumer Privacy Act (“CCPA”) has grown into a patchwork of approximately twenty (20) comprehensive state privacy laws, with more states adopting similar frameworks each year. This year alone Indiana, Kentucky, and Rhode Island joined the list. For SaaS companies, “we’re not based there” is no longer a reliable answer to “do we have to comply there.”

    Why Your Home State Doesn’t Determine Your Obligations

    Most state privacy laws apply based on where your customers or users are located, and how much of their personal data you process, not where your company is incorporated or headquartered. A SaaS company based in Oklahoma serving customers in California, Colorado, Virginia, Connecticut, and a dozen other states can find itself subject to all of those states’ requirements simultaneously. It’s a bit of a compliance nightmare right now with little hope for a unified federal data privacy law coming to tame the masses. As for current state laws, applicability thresholds vary (some laws apply based on revenue, others based on the number of residents’ records processed), so the analysis has to be done state by state.

    The Common Threads Across State Laws

    Despite the patchwork, most comprehensive state privacy laws share a core set of requirements: consumers get rights to access, correct, delete, and in some cases port their personal data; consumers can opt out of the sale of personal data and certain targeted advertising; companies must maintain reasonable data security safeguards; and companies must have data processing agreements in place with vendors and subprocessors who touch personal data on their behalf. If your SaaS product already has a privacy policy and a standard Data Processing Agreement (“DPA”) in its commercial contract stack, you have a foundation. The question is whether that foundation actually reflects the specific obligations that apply to your current customer footprint.

    Where SaaS Companies Typically Get Tripped Up

    Three recurring gaps show up again and again: DPAs that were drafted years ago and never updated to reflect current state law requirements or the company’s current subprocessor list; privacy policies that describe data practices in the abstract but don’t actually match what the product does today; and no internal process for tracking which states trigger new obligations as the customer base grows, so compliance becomes reactive instead of built in.

    A Practical Starting Point

    Before assuming you need a state-by-state legal opinion for every jurisdiction, most SaaS companies benefit from three concrete steps: mapping what personal data the product actually collects and where it flows, including subprocessors; reviewing the current DPA and privacy policy against that map; and building a lightweight internal process to flag new state obligations as the customer base expands. From there, targeted legal review can focus on the states and data types that create the most real exposure, rather than trying to solve every jurisdiction at once.
    Multi-state privacy compliance is manageable when it’s built into how a SaaS company already reviews and negotiates its commercial contracts, rather than treated as a separate project. If your DPA or privacy policy hasn’t been reviewed against your current customer footprint, that’s a good place to start the conversation.

    This post is provided for general informational purposes only and does not constitute legal advice. Reading this post does not create an attorney-client relationship. Contact ME to discuss your company’s specific circumstances.

  • The Importance of Data Privacy to Businesses

    The Importance of Data Privacy to Businesses

    In today’s interconnected world, data privacy has emerged as a cornerstone of trust and responsibility. At its core, data privacy refers to the proper handling, processing, and protection of personal information, such as names, contact details, financial records, or behavioral data, ensuring it is collected, stored, and used in ways that respect individuals’ rights and expectations. For business executives, this concept is not just a technical concern but a strategic priority that can define a company’s reputation, compliance posture, and bottom line.

    Why should data privacy matter to leaders? First, customers and clients increasingly demand transparency and control over their information. A breach of trust, whether through a cyberattack or careless data practices, can erode loyalty and drive stakeholders away. In an era where consumer awareness is at an all-time high, businesses that prioritize privacy signal integrity and reliability, fostering stronger relationships.

    Second, the regulatory landscape continues to tighten. Governments worldwide are enforcing stringent laws, imposing hefty fines, and holding companies accountable for mishandling data. Executives who overlook these obligations risk not only financial penalties but also legal scrutiny that can disrupt operations and tarnish their brand.

    Finally, data privacy is a competitive advantage. As organizations leverage advanced technologies like AI and big data analytics, those that embed privacy into their strategies can innovate responsibly, avoiding the pitfalls of overreach. With digital transformation accelerating, executives who champion privacy will position their companies as leaders in an ethical, customer-centric marketplace.

    In short, data privacy is no longer optional, it’s a business imperative. For executives, understanding and prioritizing it ensures resilience, trust, and long-term success in a data-driven world.

  • The Data Privacy Hodge-Podge

    The Data Privacy Hodge-Podge

    On February 12, 2025 the U.S. House of Representatives Committee on Energy and Commerce announced the formation of a working group to explore creation of a framework for a comprehensive national data privacy bill. It seems Congress is catching a little heat from some business industry groups growing evermore concerned about the proliferation of state-specific data privacy laws. Will Congress put on their big boy/girl shorts and work together to pass a federal data privacy law that will preempt state data privacy laws and unify data privacy law across the nation? Looking back at my magic 8-ball again…”all signs point to probably NOT.” Congress has tried repeatedly over the last few years to hold hands and agree on some sort of privacy legislation, but failed to even get a bill to a full vote of their respective chambers. Most recently, just last June, a data privacy bill in the House Energy and Commerce Committee was scheduled for a markup session but was cancelled due to disagreement over its provisions. I’ll also note this year’s would-be data privacy law is being assigned to a working group of nine Republicans and ZERO Democrats; not exactly a bipartisan hug-it-out to get this done for the people kind of a start.

    In the absence of any ability of the U.S. Congress to get their collective brains dreaming in the same direction to pass a cohesive national data privacy law that doesn’t leave companies pulling their hair out attempting to be aware of and comply with various state’s data privacy laws, the problem is growing more unmanageable. As of this post 19 states have passed some version of a comprehensive data privacy law in an effort to protect their citizens personal data (6 of the 19 states’ laws don’t go into effect until later this year or 2026). In addition, there are 12 more states that currently have data privacy laws either introduced or already in committee in this 2025 legislative session. So, by the beginning of 2026 businesses will be struggling to navigate 31 or more distinct state data privacy laws. How does that sound, business leaders?

    Setting aside the 19 remaining states that, for whatever reason, do not yet have data privacy laws currently in process, this state-by-state solution is becoming a very large administrative burden on business. Before long we’ll all be telling jokes about the company’s army of data privacy specialists instead of its heard of accountants. Speaking of data privacy jokes, a little something from the Dad-Files, “Why doesn’t Cookie Monster have good internet privacy? Because he always accepts the cookies!” All my IT nerds out there are spitting Mountain Dew all over their monitors.

    The take away? Although our federal legislators continue to talk about, getting around to, proposing, to do something about a nationwide data privacy law. I’m not holding my breath. And in the meantime the states are cranking out new state-specific data privacy laws by the bushel. So, if you are a business that deals with personal data for employees, contractors, customers, vendors, or any other human being who possesses personally identifiable information, you need to enlist the assistance of a data privacy attorney or other privacy professional to ensure your business is compliant with all data privacy laws applicable to it. Data privacy is not going away, and its only getting bigger and less likely to not apply to you.

    Don’t think data privacy applies to you? Here is a fun fact for you. All data privacy laws define the processing of personal data. They might use a different word for “processing,” but it’s the same concept. I’ve participated in countless meetings with executives who assure me, neh, outright lecture me that the business is not processing personal data. All I do in response is read aloud the General Data Protection Regulation (“GDPR”) (fyi, GDPR is the mother and 500 lb. gorilla in the room of data privacy laws) definition of “processing.”

    “Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
    ~GDPR, Art. 4(2).

    It is correct to say that there are many reasons why a particular data privacy law may not apply to your business. But one thing that almost all data privacy laws have in common is a very broad definition of what constitutes processing (or selling or sharing, or whatever a specific jurisdiction may call it). So, if you store, transmit, delete or view personal data, you likely qualify as having processed it.

    Do yourself a favor, work with a data privacy attorney or other privacy professional to understand how your company’s data handling practices fit in with any and all applicable data privacy laws. If the professional you counsel with tells you data privacy doesn’t apply to you, then you can keep all the cookies too.

    Conduct yourself accordingly!