Amid the ever-present threats posed by hackers, scammers and other bad actors, more and more states have adopted legislation aimed at bolstering efforts to protect individuals’ personal information, creating a patchwork of approaches across the United States.

Background

As of November 2023, more than 40 states have introduced proactive cybersecurity legislation, and at least 20 states adopted proactive privacy and/or cybersecurity laws. In addition, there are also federal laws, state constitutional rights, and industry mandates (e.g., for payment card processors) and common law that require companies to proactively adopt “reasonable” measures to protect personal information against “foreseeable” risks that could compromise the integrity, availability and confidentiality of personal data.