Exemptions: Federal Privacy Laws

State privacy laws include a number of exemptions for situations where there are already existing data privacy laws in place. The purpose of these exemptions is to avoid interfering with those regulatory schemes and placing undue burdens on businesses. The most significant exemptions are tied to several federal laws, including the Health Insurance Portability and Accountability Act (HIPAA), the Gramm-Leach-Bliley Act (GLBA), and the Fair Credit Reporting Act (FCRA), among others.

Critically, these are not blanket exemptions, but are tied to specific types of data collection and usage. A business that is regulated by the GLBA, for example, may still have obligations under state privacy laws. Also, a business that excludes vendors based on these exemptions should ensure that all data processed by that vendor falls under the exemption.

Health Insurance Portability and Accountability Act

HIPAA is a federal health-care law that regulates, among other things, the disclosure and security of protected health information (PHI). U.S. state privacy laws do not apply to PHI collected by a covered entity or business associate (similar to a CCPA service provider) that is governed by the privacy, security, and breach notification rules of HIPAA.

Examples:

  • Healthcare data provided to a healthcare provider.

Gramm-Leach-Bliley Act

The GLBA imposes privacy rules on financial institutions regarding the collection and sharing of consumers’ nonpublic personal information (NPI). NPI is “personally identifiable financial information” collected in connection with providing financial products or services. Under the GLBA’s Privacy Rule, financial institutions must disclose how NPI is collected and shared, as well as provide consumers with the opportunity to opt out of sharing their NPI with third parties.

Again, this is is not an entity-level exemption. If financial institutions are collecting personal information that is not subject to the GLBA, that personal information may be subject to state privacy laws. For example, if a financial institution also provides non-financial products, personal information collected while providing those products could be covered by state privacy laws.

Examples:

  • Personal data provider to banks, financial management firms, and some insurance companies, to the extent it's related to a financial product.

Fair Credit Reporting Act

The FCRA governs how personal information can be used by consumer reporting agencies such as credit bureaus and background-screening companies. It also gives consumers certain rights regarding the accuracy and privacy of their information.

The exemption only applies to the extent that the personal information is subject to the FCRA and is used as authorized by that law.

Examples:

  • Providing personal data to a credit bureau in connection with requesting a credit check on the consumer.
  • Providing information on a job applicant to a background-checking service, provided that service is regulated by the FCRA.

Other Federal Laws

State privacy laws offer exemptions for data covered by other federal privacy laws that are less likely to apply to most businesses

  • Family Educational Rights and Privacy Act: FERPA restricts the disclosure of education-related personal information, such as grades and enrollment, without the permission of the student or their parent.
  • Driver's Privacy Protection Act: The DPPA prohibits public agencies such as departments of motor vehicles and other authorized recipients from disclosing personal information related to records such as driver's licenses and motor vehicle registration.
  • Farm Credit Act: The FCA is meant to facilitate financial lending to farmers and ranchers in rural areas. Personal information collected in relation to the FCA is subject to privacy regulations.