CampusDownWiki CampusDown (Korean) ↗
English

Privacy Rights in the U.S.

⚖️ Law By CampusDown Wiki Editorial Team Last updated
Quick answer: in the U.S., privacy rights come from three layers: the Constitution, which mainly limits the government; sector-specific federal laws for health, education, children and communications; and state laws such as California's CCPA. There's still no single comprehensive federal privacy law, unlike Korea's Personal Information Protection Act or the EU's GDPR.
Contents
  1. 1. What privacy rights do Americans have?
  2. 2. The Fourth Amendment in the digital age
  3. 3. Federal privacy laws: a sector-by-sector approach
  4. 4. State privacy laws and the CCPA
  5. 5. Privacy and private lawsuits
  6. 6. Korea vs. the U.S.: comprehensive vs. patchwork
  7. 7. References and official sources
Advertisement

What privacy rights do Americans have?

Americans often assume they have a broad "right to privacy," but legally it's a patchwork. The Constitution protects against certain government intrusions; Congress has passed privacy laws for specific sectors; and states have added their own, increasingly comprehensive, consumer privacy statutes. The constitutional idea of privacy as personal autonomy, from contraception to marriage, is covered on the right to privacy page. This page focuses on information and digital privacy.

📌 At a glance
Against the government
Fourth Amendment protection from unreasonable searches
Against companies
Sector laws, state laws, FTC enforcement
Comprehensive federal law
None yet
Leading state law
California Consumer Privacy Act (CCPA), amended by the CPRA

The key distinction is who is collecting your data. The Constitution generally restrains only the government. A private company tracking your browsing is governed by statutes and contracts, not the Fourth Amendment. Understanding that split explains most of American privacy law.

The Fourth Amendment in the digital age

The Fourth Amendment protects "the right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures." In Katz v. United States (1967), the Supreme Court held that it protects people, not places, and adopted the test of a "reasonable expectation of privacy." Under the third-party doctrine, though, information voluntarily shared with others, like bank records or numbers dialed, generally lost that protection (United States v. Miller, 1976; Smith v. Maryland, 1979).

Digital technology has pushed the Court to adjust. In Riley v. California (2014), it unanimously held that police generally need a warrant to search a cell phone seized during an arrest, because phones hold "the privacies of life." In Carpenter v. United States (2018), it held that obtaining seven days or more of historical cell-site location records is a search requiring a warrant, declining to extend the third-party doctrine to such detailed tracking. These cases shape how police gather evidence in criminal procedure.

📁 Case file
Katz v. United States (1967)
Reasonable expectation of privacy test; wiretapping a phone booth is a search
Riley v. California (2014)
Warrant generally required to search a cell phone after arrest
Carpenter v. United States (2018)
Warrant required for historical cell-site location data

The Fourth Amendment was written for letters and locked drawers. The Court now has to decide what "papers and effects" mean when your whole life fits in a phone.

Advertisement

Federal privacy laws: a sector-by-sector approach

Instead of one general law, Congress has regulated specific kinds of information:

  • HIPAA (1996): health information held by health plans, providers and their business associates.
  • FERPA (1974): student education records at schools receiving federal funds.
  • COPPA (1998): online collection of personal information from children under 13, requiring verifiable parental consent (15 U.S.C. § 6501 and following).
  • ECPA (1986): interception of communications and access to stored communications.
  • Gramm-Leach-Bliley Act (1999) and Fair Credit Reporting Act (1970): financial and credit information.
  • Video Privacy Protection Act (1988): video rental and viewing records, passed after a Supreme Court nominee's rental history was published.

Outside these sectors, the Federal Trade Commission acts as the main privacy regulator under Section 5 of the FTC Act (15 U.S.C. § 45), which bans unfair or deceptive practices. When a company breaks its own privacy promises or fails to secure data, the FTC can bring enforcement actions and impose orders lasting decades.

State privacy laws and the CCPA

States have filled many gaps. The California Consumer Privacy Act (2018), expanded by the California Privacy Rights Act approved by voters in 2020, gives residents rights to know what personal information businesses collect, to delete it, to correct it, and to opt out of its sale or sharing, and created a dedicated state privacy agency. Since then, many other states, including Virginia, Colorado, Connecticut and Texas, have passed comprehensive consumer privacy laws, though their details differ.

Some state laws target specific risks. Illinois's Biometric Information Privacy Act (2008) requires consent before collecting fingerprints or face geometry and lets individuals sue, which has produced large settlements. State data breach notification laws, now in every state, require companies to tell people when their data is compromised.

Privacy and private lawsuits

Individuals can also sue under common-law privacy torts: intrusion upon seclusion, public disclosure of private facts, false light, and appropriation of name or likeness. These torts, described by William Prosser in 1960 and rooted in Warren and Brandeis's 1890 article "The Right to Privacy," protect against serious invasions by private parties, though courts apply them cautiously when speech about public matters is involved.

Data breach and tracking cases face a hurdle: standing. In TransUnion LLC v. Ramirez (2021), the Supreme Court held that plaintiffs need a concrete injury to sue in federal court, so people whose inaccurate credit files were never shared with third parties couldn't recover damages, even though a statute was violated. Questions about who owns content created from personal data also overlap with copyright basics.

Korea vs. the U.S.: comprehensive vs. patchwork

Korea took the opposite path. Its Personal Information Protection Act (개인정보 보호법, 2011) applies across the public and private sectors. It generally requires consent or another legal basis for collecting personal information, limits use to stated purposes, gives individuals rights of access, correction, deletion and suspension of processing, and is enforced by the independent Personal Information Protection Commission, reorganized as a central administrative agency in 2020. Korea's Constitutional Court has also recognized a constitutional right to informational self-determination.

United StatesKorea
StructureSector laws plus state lawsOne comprehensive statute
Main regulatorFTC (plus sector agencies, states)Personal Information Protection Commission
Default for companiesAllowed unless a law restrictsLegal basis such as consent required
Constitutional basisFourth Amendment against governmentRight to informational self-determination

Both systems share roots in the Bill of Rights tradition of limiting state power, but they diverge on how much the law should restrain private data collection.

In Korea, a company usually needs a reason to use your data; in the U.S., it usually needs a reason not to. That reversed default explains most of the practical differences between the two systems.

Is there a federal privacy law in the U.S.?
Not a comprehensive one. There are sector-specific laws such as HIPAA, FERPA, COPPA and ECPA, plus FTC enforcement.
Does the Fourth Amendment protect my data from companies?
No. It limits the government. Companies are governed by statutes, contracts and state laws.
What rights does the CCPA give?
California residents can learn what personal information businesses collect, delete and correct it, and opt out of its sale or sharing.
How is Korea's privacy law different?
Korea has one comprehensive law covering public and private sectors, with an independent commission enforcing it.
Think about it. Should the U.S. adopt a single comprehensive privacy law like Korea's, or does the sector approach allow more innovation? Who benefits from each design?
Advertisement

References and official sources

  1. Fourth Amendment. Cornell LII
  2. 15 U.S.C. § 6501, Children's Online Privacy Protection. Cornell LII
  3. 15 U.S.C. § 45, Unfair methods of competition and deceptive acts. Cornell LII
  4. Riley v. California, 573 U.S. 373 (2014). Justia
  5. Carpenter v. United States, 585 U.S. 296 (2018). Justia
  6. 개인정보 보호법. 국가법령정보센터

Reports and materials that use this theory (Korean)

There are no materials dedicated to this theory yet, but you can search related reports in the CampusDown library (Korean).

Find more reports · Search '미국의 프라이버시권' on CampusDown →

You may also like

This article was last updated on October 10, 2026. It is based on widely recognized original works and textbooks; when citing it in a paper, please check the original sources listed in the references.

Advertisement