Applicability
The applicability of new state data privacy laws is largely consistent with existing state data privacy laws, with some variations based on factors such as the volume of data processed or the company’s revenue from selling data, or whether the business or the data it holds is exempt from the legislation.
- Application threshold – Unlike most state privacy laws, Nebraska’s privacy law applies to all companies operating in the state, regardless of the amount of personal data they processed or their revenue from selling data. In contrast, Tennessee’s privacy law is more restrictive and applies only to businesses with revenue exceeding US$25 million.
- Exemptions – Unlike most state privacy laws, the privacy laws in Delaware, Minnesota and New Jersey (like Colorado’s) do not generally exempt nonprofit organizations. Delaware, Maryland and New Jersey also follow the approach of California and Oregon by including institutions of higher education within the scope of their privacy laws. A unique aspect of New Jersey’s privacy law is that it does not include the Family Educational Rights and Privacy Act (FERPA) exemption. New state privacy laws continue to differ in how they handle exemptions under the Gramm-Leach-Bliley Act (GLBA) and the Health Insurance Portability and Accountability Act (HIPAA), depending on whether the exemptions apply to entities or specific types of data. As a recall, an entity-level exemption removes an entire organization from the law’s scope, while a data-level exemption only excludes specific types of data held by the entity, which may still be subject to the law. Delaware, Maryland, Nebraska and New Jersey privacy laws include an entity-level exemption under the GLBA, while Minnesota provides only a data-level GLBA exemption. In contrast, Iowa, New Hampshire and Tennessee offer both entity-level and data-level GLBA exemptions. Regarding HIPAA, most new state privacy laws provide only data-level exemptions. However, Iowa, Nebraska and Tennessee’s privacy laws provide both entity-level and data-level HIPAA exemptions. Finally, privacy laws in both Nebraska and Minnesota (similar to Texas’s) exempt small businesses as defined by the US Small Business Administration.
I appreciate the focus on helping regional banks specifically. Often, the advice out there is geared towards larger institutions and doesn’t address the specific constraints and opportunities that regional banks face. I think exploring strategies like M&A to achieve operational scale and offset regulatory compliance costs is critical for these banks1. Also, as mentioned in another article, developing or expanding niche capabilities to open up new opportunities could be a game-changer.
Comments are closed.