Satisfying The Cookies Monster: An Evaluatory Approach of the EU and U.S. Legal Data Privacy Frameworks
Head Researchers: Olivia Clyne and Sidney Dwyer
Researchers: Emma Jansen, Simon Ratz, Eleanor Christie
Editors: Edwin Brattselius Thunfors and Grace Risucci
Editor-in-Chief: Edwin Bratteselius Thunfors
Executive Summary
Given the crucial role of data in the global economy and the dangers that unregulated data pose, every country must attempt to develop policies that safeguard the rights of its citizens. Therefore, this research paper will conduct a case study examining the legal frameworks employed by the United States and the European Union to defend data privacy. Rather than applying universal regulations to protect data security, the United States has established several sector-specific policies, such as the Privacy Act (1974), the Health Insurance Portability and Accountability Act (HIPAA) of 1996, and the 2000 Children’s Online Privacy Protection Act (COPPA). Apart from these laws, the Federal Government has left concerns regarding data security to the discretion of each state, which has spurred a patchwork-style framework of state laws. Conversely, the European Union developed one standardized policy, known as the General Data Protection Regulation (GDPR), to secure data security across all member states.
To better assess the efficacy of each approach, we classified states into three different groups based on the strength of the privacy law in question: (1) comprehensive, (2) narrow, and (3) other. We conducted a statistical analysis to better understand the relationship between privacy laws in the U.S. and the per-capita income, the median income, educational attainment, and political party of the state, amongst other factors. Based on these findings and the information we acquired from conducting the case study, we determined that the universal approach taken by the EU was ultimately much more effective than the sector and state-specific design of the U.S. legal framework. To conclude the paper, we utilized this data to recommend several policies that the U.S. could implement to improve the data security of its citizens.
