The Actual Privacy Laws Protecting You Online
People talk about online privacy like there is one big law standing between you and every creepy data broker on the internet.
There is not.
In the US, online privacy is more like a messy junk drawer. A little FTC enforcement here. A state privacy law there. A few rules for kids, health data, credit reports, and financial accounts. If you live in Europe, GDPR gives you a much stronger baseline. If you live in the US, what you get depends a lot on where you live and what kind of data is involved.
That does not mean you have no protection. It just means the protection is patchy.
The FTC is the privacy cop, but mostly after the fact
The Federal Trade Commission is one of the main US agencies that goes after companies for bad privacy and security behavior. The FTC can act when a company lies about what it collects, hides important data practices, breaks its own privacy promises, or uses unfair or deceptive practices.
That matters. If an app says, "we do not sell your data," then quietly shares it anyway, the FTC can step in. If a company claims it uses strong security and then leaves customer data exposed, that can become an enforcement problem.
But the FTC is not the same thing as a universal privacy shield. It usually reacts after something goes wrong. It does not stop every tracker, every sketchy data broker, or every app from collecting more than it needs.
State privacy laws are getting stronger
The bigger change in the US is happening state by state. California started the modern wave with the CCPA and CPRA. Other states followed with their own consumer privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Delaware, Iowa, Montana, Tennessee, Indiana, Kentucky, Rhode Island, and more.
By 2026, privacy trackers count about 20 US states with comprehensive consumer privacy laws in effect. The details vary, but many give people rights like:
- Ask what personal data a company has about you.
- Request deletion of certain personal data.
- Correct inaccurate information.
- Opt out of some targeted advertising or data sales.
- Appeal when a company denies your request.
That is real progress. It also creates a weird privacy map. Your rights may be stronger in California than in a state without a comprehensive privacy law. A company may offer the same privacy controls to everyone because it is easier, or it may only expose certain rights where legally required.
GDPR is the stronger model
The European Union's GDPR is still the privacy law people point to because it starts from a different assumption: personal data deserves protection by default. It gives people rights to access, correct, delete, restrict, and object to certain uses of their data. It also requires companies to have a legal basis for processing personal information.
GDPR can apply beyond Europe when a company handles data about people in the EU. That is why you see cookie banners and privacy controls on sites run by companies that are not based in Europe.
Still, GDPR does not make you invisible. It gives you rights against companies. It does not stop your internet provider, hotel WiFi, airport network, or local hotspot from seeing basic connection patterns when your traffic passes through them.
Where a VPN fits in
Privacy law is about what companies are allowed to do with data. A VPN is about reducing what your network can see in the first place.
Those are different tools. You still need laws, regulators, and privacy rights. But when you turn on a VPN, your internet provider or public WiFi network sees encrypted traffic to a VPN server instead of a readable list of sites and services your device is contacting.
That is not magic. It does not erase your accounts, block every tracker, or make you anonymous. It just moves one big trust point away from the local network you happen to be using.
If you want a simple way to reduce what your ISP or public WiFi can see, 99¢ VPN is $11.88/year for one device using WireGuard. Cheap, boring, and enough for the basic privacy layer most people actually need.
The bottom line: privacy laws help after data is collected. A VPN helps before some of that network data is exposed. Neither one solves everything. Together, they make you less easy to track.
Written by the person who runs 99¢ VPN. Not legal advice. Just a practical guide to what privacy laws do, what they do not do, and where a VPN fits.