Explaining the GDPR to an American
U.S. consumer privacy law, in large part, relies on notice and consent, which is, in turn, enforced by the unfair and deceptive trade principles laid out in the Federal Trade Commission Act and state consumer protection laws.
“For the most part, being explicit in a privacy statement about how consumer data is used, shared, and kept secure, and then living up to those promises while not acting in a way that would surprise or be unfair to a consumer, sums up the basic of U.S. consumer privacy law (nuance notwithstanding),” writes IAPP Research Director and DPO Rita Heimes, CIPP/E, CIPP/US, CIPM.
Source: DPO Confessional: Explaining the GDPR to an American