April 22, 2025

Ten Principles for a U.S. Privacy Law

Earlier this year, the U.S. Congress signaled its intent to take a fresh look at the potential elements of a U.S. federal privacy law. CIPL submitted a detailed comment to the House Committee on Energy and Commerce Data Privacy Working Group on April 7th in response. Following this, we created this summary of our views on the path forward for U.S. Federal privacy legislation. This paper is an update to our 2019 paper on this same topic.

In summary, CIPL believes that the following principles will help ensure that a new federal privacy law enables responsible data use for innovation in the digital economy and advances U.S. leadership and competitiveness:

  1. Organizational Accountability
  2. Risk-Based Approach
  3. Contextual Transparency
  4. Individual Protections
  5. Controller and Processor Distinction
  6. Global Interoperability
  7. Supportive of Innovation
  8. Oversight and Smart Regulation
  9. Effective and Proportionate Enforcement
  10. Comprehensive and Harmonized Law

Ten Principles a U.S. Privacy Law

Download Now