• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
CommentaryData Security

States Are Getting Tough on Data Security—but That Might Be a Problem

By
Greg Arnette
Greg Arnette
Down Arrow Button Icon
By
Greg Arnette
Greg Arnette
Down Arrow Button Icon
May 2, 2018, 3:10 PM ET

The Facebook-Cambridge Analytica scandal is the latest of many incidents in recent years that have left consumers jittery about the security of their online personal information. It also is yet another event that shines a bright light on the need for more regulation protecting data.

But while data security becomes an ever more pressing issue for businesses and users, the Trump administration’s anti-regulation fervor has translated into little to no new federal action enforcing it.

What happens when an unstoppable force meets an immovable object? In this case, states are stepping in with their own cybersecurity measures. More than 240 bills were introduced in 42 states last year covering a range of security issues, from improving government practices to restricting public disclosure of confidential information, according to the National Conference of State Legislatures.

Interestingly, the willingness of the states to wade into cybersecurity regulation is both a positive development and a potentially problematic one.

First, let’s explore the good.

Some states are breaking new ground as they force companies to be more accountable for maintaining the security of personal information.

For example, a regulation called 23 NYCRR Part 500 that went into effect in New York in March 2017 established detailed security rules for financial services companies, which of course hold some of the most sensitive customer data.

In California, tough legislation has been introduced that would require any company selling an Internet-connected device to equip it with features that protect it from unauthorized access and to obtain consumer consent before it collects or transmits information.

In Illinois, lawmakers considered a bill requiring public utilities operating in the state to report annually on the vulnerability of the state’s water supply system to cyberattacks.

Such measures show that the states are serving as catalysts for better cybersecurity, with ideas that can be replicated in other states and, hopefully one day, nationally. The situation is analogous to health care policy in the years before Obamacare, when, in the absence of a federal consensus, Massachusetts pioneered its own law aimed at reforming health insurance (which later became a model for the Affordable Care Act).

Some of these state measures seem more in step with efforts in other countries to protect personal data—such as the European Union’s General Data Protection Regulation (GDPR), which goes into effect May 25—than with the U.S. administration’s anti-regulation fervor.

But there’s a fly in the ointment in states’ individual action on cybersecurity—the prospect of a patchwork of different laws governing something, the Internet, that knows no geographical borders.

For example, 48 states mandate that private or government organizations notify individuals of security breaches of information involving personally identifiable information. (The remaining two—South Dakota and Alabama—are working on similar rules.) But the laws can be inconsistent and confusing to comply with across the various states.

“For businesses doing business in multiple states, the different and confounding state laws make responding to a data breach in an appropriate, timely and in a compliant fashion very difficult,” asserted Stephen Embry in an American Bar Association blog post. “This is compounded by the aftermath of a breach being filled with the uncertainty, concern, and even panic that any emergency brings. Add to that the multiple competing interests in such a situation and the opportunity for a wrong decision with significant consequences is magnified many times over.”

Some worry about even more serious, constitutional issues.

A nationwide assortment of state cybersecurity regulations “raises the issue of whether such regulations violate the U.S. Constitution’s ‘dormant’ Commerce Clause, which restricts states’ ability to discriminate against or unduly burden interstate commerce,” write Matthew A. Schwartz and Corey Omer for the Clearing House, a banking and payments trade group.

All this said, with scant new regulatory activity on the horizon at the federal level, siloed statutes at the state level are a whole lot better than nothing. Let’s just hope that the innovation taking place at the state level eventually finds its way into the uniform, national set of policies that we really need.

Greg Arnette is the director of data protection platform strategy at Barracuda, a Thoma Bravo company. Previously, he was founder and CTO of Sonian, a cloud archiving company that was acquired by Barracuda in November 2017.

About the Author
By Greg Arnette
See full bioRight Arrow Button Icon

Latest in Commentary

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Commentary

golf
Commentarybooks
How playing golf alone can make you better at your job
By Gary BelskyMay 8, 2026
15 hours ago
naomi
Commentarymental health
Naomi Osaka: the things I didn’t do to succeed
By Naomi OsakaMay 8, 2026
17 hours ago
amanda
Commentarybatteries
Why energy storage is moving beyond the capex debate
By Amanda SimonianMay 7, 2026
2 days ago
trump
CommentaryMedicare
Auto-enrollment in Medicare Advantage isn’t a nudge. It’s a trap
By Brian KeyserMay 7, 2026
2 days ago
nyse
CommentaryAI agents
Your trusted advocate or your rebellious Frankenstein: how you deploy agentic AI determines which one you get
By Jeffrey Sonnenfeld, Stephen Henriques, Yevheniia Podurets and Jasmine GarryMay 7, 2026
2 days ago
moore
CommentaryAntitrust
I litigated the JetBlue-Spirit merger. A few thoughts on the future of antitrust in the airline industry
By James "Jimmy" MooreMay 7, 2026
2 days ago

Most Popular

California farmers must destroy 420,000 peach trees after Del Monte closes its canneries and cancels more than $550 million in long-term contracts
North America
California farmers must destroy 420,000 peach trees after Del Monte closes its canneries and cancels more than $550 million in long-term contracts
By Sasha RogelbergMay 7, 2026
1 day ago
'Blue dot fever' plagues musicians like Post Malone, Meghan Trainor, and Zayn as a growing list of artists cancel tours due to lagging ticket sales
Arts & Entertainment
'Blue dot fever' plagues musicians like Post Malone, Meghan Trainor, and Zayn as a growing list of artists cancel tours due to lagging ticket sales
By Dave Lozo and Morning BrewMay 7, 2026
1 day ago
A Michigan farm town voted down plans for a giant OpenAI-Oracle data center. Weeks later, construction began
Magazine
A Michigan farm town voted down plans for a giant OpenAI-Oracle data center. Weeks later, construction began
By Sharon GoldmanMay 6, 2026
3 days ago
U.S. Treasury will have to borrow $2 trillion this year just to continue functioning—more than $166 billion every month
Economy
U.S. Treasury will have to borrow $2 trillion this year just to continue functioning—more than $166 billion every month
By Eleanor PringleMay 7, 2026
2 days ago
Airbnb CEO Brian Chesky warns two types of people won’t survive the AI era: ‘pure people managers’ and workers who resist change
Success
Airbnb CEO Brian Chesky warns two types of people won’t survive the AI era: ‘pure people managers’ and workers who resist change
By Emma BurleighMay 7, 2026
1 day ago
Current price of oil as of May 8, 2026
Personal Finance
Current price of oil as of May 8, 2026
By Joseph HostetlerMay 8, 2026
14 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.