A common assumption among app developers outside the United States is that US data privacy law does not reach them until they open a US office or sign a US customer. It does not work that way. What triggers obligations is the data and the users, not the address on the incorporation certificate.
This matters most for apps that touch health, fitness, wellness or anything adjacent. The regimes that reach hardest into that category are the ones with no revenue threshold at all.
There is no single US data privacy law
The United States has no general federal privacy statute. What it has instead is a patchwork: sector-specific federal laws, a growing set of state comprehensive privacy laws, and the Federal Trade Commission’s authority over unfair and deceptive practices, which functions in practice as a national privacy enforcer.
For an app developer, the practical consequence is that you cannot answer the question “are we compliant?” once. You answer it per state, per data category, and per claim you make in your own privacy policy.
State comprehensive laws
California’s regime, now consolidated under the California Consumer Privacy Act as amended by the CPRA, is the one most people know. It applies to businesses meeting a revenue or data-volume threshold that handle personal information of California residents. A number of other states have since enacted comparable laws with their own thresholds, definitions and cure periods.
The important point for a smaller developer is that thresholds cut both ways. Falling under a threshold is not the same as being exempt from everything, because the laws below do not have thresholds.
Health data laws that reach further than HIPAA
Most consumer health apps are not covered by HIPAA. Developers frequently read that as good news and stop there. It is not the end of the analysis.
Washington’s My Health My Data Act regulates consumer health data broadly defined, applies to entities that do business in Washington or target Washington consumers regardless of size, and carries a private right of action. Nevada enacted a similar statute. Because the definition of consumer health data in these laws extends well past clinical records into inferences about physical and mental health, an app that never touches a diagnosis can still fall inside them.
A private right of action changes the risk profile. It means exposure does not depend on an agency deciding your app is worth its time.
Children and teens
If your app is directed to children under 13, or you have actual knowledge that you collect personal information from them, the Children’s Online Privacy Protection Act applies and requires verifiable parental consent. Several states have added their own requirements covering minors past that age. Age-gating that exists only in the terms of service does not resolve this.
What your own policy says
The FTC’s most-used tool against app developers is not a privacy statute. It is Section 5 of the FTC Act, applied to the gap between what a company said it did with data and what it actually did. A privacy policy drafted for a different market, or copied from a template, becomes the standard you are held to. That is a self-inflicted risk and among the cheapest to fix.
Your vendors are your exposure too
Analytics providers, advertising SDKs, crash reporting, session replay, chat widgets and payment processors all receive data from your app, and the platform’s standard terms are written for the platform.
Litigation over advertising and analytics pixels on health-related sites and apps has been a steady source of claims in recent years, often brought under older wiretapping and video privacy statutes rather than modern privacy laws. The mechanism is usually the same: a tag installed for marketing reasons transmitted more than anyone internally realized.
Two practical steps close most of that gap. Inventory what every SDK in your build actually transmits, and read the vendor terms for what the vendor is permitted to do with the data for its own purposes, which is usually the clause that matters.
What enforcement has looked like
Recent resolutions give a sense of scale:
- DoorDash settled with California for $375,000 over claims it sold customer data in violation of state privacy law.
- Google settled with California for $93 million over location privacy practices.
- Equifax settled with federal and state agencies for up to $600 million following its 2017 breach.
- Uber settled for $148 million over its handling of a 2016 breach.
The figures at the top of that list are what large companies pay. The figure that ends a smaller company is smaller, and it is usually the cost of defending a class claim rather than the settlement itself.
Where to start
If you are launching in the US or already have US users, four questions will tell you most of what you need to know.
- What data does the app actually collect and transmit, including everything the SDKs send? Not what the specification says. What the build does.
- Does any of it constitute consumer health data under the broad state definitions, whether or not you consider your app a health app?
- Does the privacy policy accurately describe all of it, and does it describe practices you can evidence?
- What do your vendor agreements permit those vendors to do with the data independently?
Getting this right before launch is materially cheaper than retrofitting it. Consent architecture, data minimization and deletion mechanics are design decisions, and reversing them after the fact usually means reworking the product rather than the paperwork.
Talk to us
We advise non-US technology companies on US privacy obligations, vendor terms and compliance for digital health products. If you are working through any of the above, book a discovery call.
The information provided on this website is for general informational purposes only and should not be considered legal advice. No attorney-client relationship is created by accessing or using this website. Please consult with a qualified attorney before making any legal decisions. Global Link Law is not liable for any reliance on the information provided. Prior results do not guarantee a similar outcome.