What privacy rights do Americans have?
Americans often assume they have a broad "right to privacy," but legally it's a patchwork. The Constitution protects against certain government intrusions; Congress has passed privacy laws for specific sectors; and states have added their own, increasingly comprehensive, consumer privacy statutes. The constitutional idea of privacy as personal autonomy, from contraception to marriage, is covered on the right to privacy page. This page focuses on information and digital privacy.
- Against the government
- Fourth Amendment protection from unreasonable searches
- Against companies
- Sector laws, state laws, FTC enforcement
- Comprehensive federal law
- None yet
- Leading state law
- California Consumer Privacy Act (CCPA), amended by the CPRA
The key distinction is who is collecting your data. The Constitution generally restrains only the government. A private company tracking your browsing is governed by statutes and contracts, not the Fourth Amendment. Understanding that split explains most of American privacy law.
The Fourth Amendment in the digital age
The Fourth Amendment protects "the right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures." In Katz v. United States (1967), the Supreme Court held that it protects people, not places, and adopted the test of a "reasonable expectation of privacy." Under the third-party doctrine, though, information voluntarily shared with others, like bank records or numbers dialed, generally lost that protection (United States v. Miller, 1976; Smith v. Maryland, 1979).
Digital technology has pushed the Court to adjust. In Riley v. California (2014), it unanimously held that police generally need a warrant to search a cell phone seized during an arrest, because phones hold "the privacies of life." In Carpenter v. United States (2018), it held that obtaining seven days or more of historical cell-site location records is a search requiring a warrant, declining to extend the third-party doctrine to such detailed tracking. These cases shape how police gather evidence in criminal procedure.
- Katz v. United States (1967)
- Reasonable expectation of privacy test; wiretapping a phone booth is a search
- Riley v. California (2014)
- Warrant generally required to search a cell phone after arrest
- Carpenter v. United States (2018)
- Warrant required for historical cell-site location data
The Fourth Amendment was written for letters and locked drawers. The Court now has to decide what "papers and effects" mean when your whole life fits in a phone.
Federal privacy laws: a sector-by-sector approach
Instead of one general law, Congress has regulated specific kinds of information:
- HIPAA (1996): health information held by health plans, providers and their business associates.
- FERPA (1974): student education records at schools receiving federal funds.
- COPPA (1998): online collection of personal information from children under 13, requiring verifiable parental consent (15 U.S.C. § 6501 and following).
- ECPA (1986): interception of communications and access to stored communications.
- Gramm-Leach-Bliley Act (1999) and Fair Credit Reporting Act (1970): financial and credit information.
- Video Privacy Protection Act (1988): video rental and viewing records, passed after a Supreme Court nominee's rental history was published.
Outside these sectors, the Federal Trade Commission acts as the main privacy regulator under Section 5 of the FTC Act (15 U.S.C. § 45), which bans unfair or deceptive practices. When a company breaks its own privacy promises or fails to secure data, the FTC can bring enforcement actions and impose orders lasting decades.
State privacy laws and the CCPA
States have filled many gaps. The California Consumer Privacy Act (2018), expanded by the California Privacy Rights Act approved by voters in 2020, gives residents rights to know what personal information businesses collect, to delete it, to correct it, and to opt out of its sale or sharing, and created a dedicated state privacy agency. Since then, many other states, including Virginia, Colorado, Connecticut and Texas, have passed comprehensive consumer privacy laws, though their details differ.
Some state laws target specific risks. Illinois's Biometric Information Privacy Act (2008) requires consent before collecting fingerprints or face geometry and lets individuals sue, which has produced large settlements. State data breach notification laws, now in every state, require companies to tell people when their data is compromised.
Privacy and private lawsuits
Individuals can also sue under common-law privacy torts: intrusion upon seclusion, public disclosure of private facts, false light, and appropriation of name or likeness. These torts, described by William Prosser in 1960 and rooted in Warren and Brandeis's 1890 article "The Right to Privacy," protect against serious invasions by private parties, though courts apply them cautiously when speech about public matters is involved.
Data breach and tracking cases face a hurdle: standing. In TransUnion LLC v. Ramirez (2021), the Supreme Court held that plaintiffs need a concrete injury to sue in federal court, so people whose inaccurate credit files were never shared with third parties couldn't recover damages, even though a statute was violated. Questions about who owns content created from personal data also overlap with copyright basics.
Korea vs. the U.S.: comprehensive vs. patchwork
Korea took the opposite path. Its Personal Information Protection Act (개인정보 보호법, 2011) applies across the public and private sectors. It generally requires consent or another legal basis for collecting personal information, limits use to stated purposes, gives individuals rights of access, correction, deletion and suspension of processing, and is enforced by the independent Personal Information Protection Commission, reorganized as a central administrative agency in 2020. Korea's Constitutional Court has also recognized a constitutional right to informational self-determination.
| United States | Korea | |
|---|---|---|
| Structure | Sector laws plus state laws | One comprehensive statute |
| Main regulator | FTC (plus sector agencies, states) | Personal Information Protection Commission |
| Default for companies | Allowed unless a law restricts | Legal basis such as consent required |
| Constitutional basis | Fourth Amendment against government | Right to informational self-determination |
Both systems share roots in the Bill of Rights tradition of limiting state power, but they diverge on how much the law should restrain private data collection.
In Korea, a company usually needs a reason to use your data; in the U.S., it usually needs a reason not to. That reversed default explains most of the practical differences between the two systems.
- Is there a federal privacy law in the U.S.?
- Not a comprehensive one. There are sector-specific laws such as HIPAA, FERPA, COPPA and ECPA, plus FTC enforcement.
- Does the Fourth Amendment protect my data from companies?
- No. It limits the government. Companies are governed by statutes, contracts and state laws.
- What rights does the CCPA give?
- California residents can learn what personal information businesses collect, delete and correct it, and opt out of its sale or sharing.
- How is Korea's privacy law different?
- Korea has one comprehensive law covering public and private sectors, with an independent commission enforcing it.
References and official sources
- Fourth Amendment. Cornell LII
- 15 U.S.C. § 6501, Children's Online Privacy Protection. Cornell LII
- 15 U.S.C. § 45, Unfair methods of competition and deceptive acts. Cornell LII
- Riley v. California, 573 U.S. 373 (2014). Justia
- Carpenter v. United States, 585 U.S. 296 (2018). Justia
- 개인정보 보호법. 국가법령정보센터