For years, companies collected enormous amounts of information about customers with relatively few restrictions outside certain industries.
That is beginning to change.
Across the United States, a growing number of states have adopted comprehensive consumer privacy laws that give people more control over how businesses collect, use, sell and share their personal information.
The result is a major shift in the relationship between consumers and the companies that track them.
For businesses, personal data is no longer something that can simply be collected because technology makes it possible.
Increasingly, companies have to explain why they want it, how they plan to use it and, in some cases, give consumers a meaningful way to say no.
Personal Data Is Much Broader Than Most People Realize
When people hear the phrase “personal data,” they may think of obvious information such as a name, address or Social Security number.
Modern privacy laws can reach much further.
Personal information may include browsing activity, purchasing history, precise location information, device identifiers, online behavior and other data that can be linked to an individual or household.
That matters because companies can build surprisingly detailed profiles without ever asking a customer a deeply personal question.
A retailer may know what products someone repeatedly views.
An app may know where a person travels.
An advertising network may infer interests based on websites visited across the internet.
A business may combine information from several sources to create a much more complete picture of a consumer than any individual piece of data would reveal.
Privacy laws increasingly focus on what happens to that information after it is collected.
Consumers Are Gaining More Control
Many state privacy laws give consumers specific rights involving their information.
The exact rules vary from one state to another, but common rights include the ability to ask what information a company has collected, request corrections, request deletion in certain circumstances and obtain copies of personal data.
Some laws also allow people to opt out of certain uses of their information.
That can include the sale of personal data or its use for targeted advertising.
The shift is significant.
For years, the burden was largely on consumers to avoid being tracked.
The emerging legal approach increasingly places obligations on companies to provide choices and respond when consumers exercise their rights.
Targeted Advertising Is Under Greater Scrutiny
Advertising is one of the biggest reasons companies collect information about online behavior.
A person searches for running shoes, visits several retail websites and begins seeing athletic footwear advertisements elsewhere online.
That experience is familiar because digital advertising systems can use information about browsing behavior to decide which ads someone is likely to respond to.
New privacy laws are forcing companies to examine those practices more carefully.
In some states, consumers can opt out of certain forms of targeted advertising or the sale of personal data used to support it.
Newer privacy tools can also allow a browser or device to communicate a user’s preference automatically rather than requiring that person to adjust privacy settings on every individual website.
That could eventually make privacy choices much easier for ordinary users.
Companies May Need to Collect Less Information
Another important change is the growing emphasis on data minimization.
The idea is straightforward.
Companies should not necessarily collect every piece of information they can simply because storage is inexpensive and the data may become useful someday.
Instead, businesses may need to consider whether particular information is reasonably necessary for the service they are providing.
That represents a major change in thinking.
For much of the digital era, the business incentive was to collect as much information as possible.
Data could be analyzed later, combined with other information or used for advertising.
Privacy regulation is increasingly pushing companies toward the opposite question:
Do we actually need this information at all?
Sensitive Data Can Receive Extra Protection
Not all information is treated equally.
Some privacy laws impose additional requirements when businesses handle sensitive categories of data.
Depending on the state, that may include precise geolocation, biometric information, certain health-related information and other highly personal data.
Companies may need stronger consent or additional safeguards before using certain sensitive information.
The reason is easy to understand.
If a shopping preference is exposed, the consequences may be limited.
If biometric, health or precise location information is mishandled, the consequences can be much more serious.
Lawmakers are increasingly recognizing that distinction.
Data Brokers Are Receiving More Attention
Many consumers understand that companies they directly interact with collect information about them.
Less visible are data brokers.
These businesses collect, organize and sell information about people, often without having a direct relationship with the individuals whose data they possess.
That information can come from public records, online activity, purchases and other commercial sources.
Data broker regulation has become a growing focus of state privacy legislation.
The concern is that consumers may have little idea which companies possess information about them or how that information is being used.
Some states have moved toward greater registration, disclosure and consumer control over these businesses.
Children’s Privacy Is Becoming Its Own Legal Battleground
Privacy protections involving children and teenagers are developing particularly quickly.
Lawmakers in multiple states have considered or adopted measures dealing with children’s online privacy, social media platforms and the collection of information about younger users.
The debate goes beyond whether companies should simply ask for parental permission.
It increasingly involves questions about targeted advertising, recommendation systems, age verification, default privacy settings and whether companies should collect certain information from younger users at all.
That makes youth privacy one of the fastest-moving areas of technology law.
Businesses Face a Patchwork Instead of One National Rule
One of the biggest challenges for companies is that the United States still relies heavily on a patchwork of state privacy laws rather than one single comprehensive standard covering every business nationwide.
Those laws often share major concepts, but the details can differ.
One state may define a covered business differently from another.
Consumer-request procedures may vary.
Sensitive-data requirements can differ.
Enforcement rules may not be identical.
That means a company operating nationwide may have to comply with several different privacy frameworks at once.
For large businesses, that can require entirely new compliance systems.
For smaller companies, it can create a complicated legal landscape that changes depending on where customers live.
Enforcement Is Becoming More Important
Passing privacy laws is only the first step.
The next question is whether regulators actually enforce them.
That stage is becoming increasingly significant as more laws take effect.
State regulators and attorneys general are paying closer attention to consumer data practices, and companies may face consequences if their privacy policies do not match what they actually do.
That changes the calculation for businesses.
Privacy policies can no longer be treated purely as paperwork placed at the bottom of a website.
Companies may need systems capable of locating consumer information, responding to deletion requests, honoring opt-outs and documenting how personal data is handled.
Privacy Is Becoming Part of Product Design
One of the most important long-term changes may happen before a customer ever clicks a privacy setting.
Companies are increasingly being pushed to consider privacy while designing products and services.
What information will the product collect?
How long will it be stored?
Who will have access?
Can the product operate without collecting certain data?
Can users easily understand their choices?
Those questions were once more likely to appear after a product had already been built.
Increasingly, they are becoming part of the design process itself.
The Era of Unlimited Data Collection Is Starting to Change
Personal information remains enormously valuable.
Companies use it to prevent fraud, improve products, personalize services, measure advertising and understand customers.
Privacy laws are not eliminating those uses.
They are changing the assumptions behind them.
The emerging principle is that information about consumers is not simply another unlimited corporate resource.
People may have rights involving what is collected, why it is used and whether it can be sold or shared.
Exactly where those boundaries should be drawn will continue to be debated.
But the direction is becoming increasingly clear.
For much of the internet’s history, technology moved faster than privacy law.
Now the law is beginning to catch up.
