Skip to main content

Summit 2027 early-bird pricing ends soon — register before it closes.Learn more

Brief

State Data Privacy Brief

What a state-by-state patchwork of consumer and member data privacy laws requires of an association that holds member records across chapters.

Moira Kavanagh-Pratt

General Counsel, Society of Rural Hospital Administrators

4 min read
Line-icon cover art in cream on a dark navy background: a locked filing cabinet beside an open laptop

A growing number of states have adopted their own consumer data privacy laws, each with its own thresholds, exemptions, and member-notification requirements, and an association with member organizations and staff across state lines has to track obligations that don't line up neatly from state to state. This brief, written by Moira Kavanagh-Pratt, general counsel at the Society of Rural Hospital Administrators and an instructor in NANA's Learning catalog, explains what an association's own member and donor data has in common with the consumer data these laws cover, and where it doesn't.

It walks through the practical questions an association's data-privacy review needs to answer: which states' laws reach a nonprofit's member records at all, since several exempt nonprofits outright or only partially; what breach notification actually requires when member data spans several states; and how remote staff working from a state other than headquarters can independently trigger obligations under that state's law.

Associations reviewing their own privacy policy will find a practical framework here for sorting which state laws apply to their own membership and staff footprint, rather than assuming blanket coverage or blanket exemption.

Published by NANA's research team as part of the brief series.

Related resources