Which privacy laws matter by industry, and what does that mean for an introduction?
There is no single US privacy law. Rules are sectoral: health, financial services, communications and state consumer-privacy statutes each cover different data and different businesses. For a referral partner the practical point is narrow. Before you introduce a company, know which regime is likely to attach to the records it holds, because that decides whether the data can be considered at all. The company and SourceX run the formal rights review; you only need to spot the flags early.
This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.
Quick reference: industry, rule, scope and what it means for you
| Industry | Rule | What it covers | Introduction implication to confirm |
|---|---|---|---|
| Healthcare and health administration | HIPAA de-identification standard (45 CFR 164.514) | Protected health information held by covered entities and their business associates | Health data generally needs to be de-identified under the standard, or otherwise authorized, before it is licensed; non-PHI administrative records are a different matter |
| Financial services, lending, tax prep, collections | Gramm-Leach-Bliley Act and the FTC Safeguards Rule | Customer information held by financial institutions, including many non-bank businesses | Sharing customer information faces notice and opt-out limits, and a security program is required; customer-level records are a red flag |
| Any for-profit business meeting the thresholds, with California residents' data | California Consumer Privacy Act | Personal information of California consumers, with rights to know, delete and opt out of sale or sharing | Records with consumer personal information may trigger notice and contract duties; ask whether the data is business records or consumer data |
| Companies in bankruptcy that promised customers privacy | Bankruptcy Code section 363 | Sale of estate property, including personally identifiable information, when a privacy policy restricts transfer | Customer data can be sold in bankruptcy, but a privacy policy constrains it; involve the trustee or assignee early |
| Contact centers and any firm recording calls | Federal Wiretap Act | Interception of wire, oral and electronic communications, with a one-party consent exception | Federal law allows one-party consent, but some states require all parties; recordings need a notice and consent trail |
Treat the table as a map for questions, not a verdict. Thresholds change, state laws differ, and a company may sit under more than one regime.
How the rules apply in common partner situations
| Situation | What to check | Typical outcome to confirm |
|---|---|---|
| A healthcare billing or admin company | Is the material operational (scheduling, vendor, HR) or PHI? | Operational records may be considered; PHI needs de-identification or authorization |
| A lender or tax firm | Do the records identify customers? | Customer-identifiable files are usually out; internal process records may be in |
| A retailer or consumer brand | Is the data mostly consumer personal information? | Mainly consumer data with no licensing basis is a red flag |
| A call center | Were callers told about recording and did the right parties consent? | Without a clear notice and consent trail, recordings are likely excluded |
| A company a court or trustee controls | Who has authority over the assets? | Approval from that party comes before any conversation about records |
| A business with 50+ full-time employees at peak and mostly internal documents | Rights and sponsor in place? | Likely a candidate for the standard screen |
What good disclosure looks like
You do not give legal advice and you do not describe confidential records. Three habits keep you safe.
- Name the regime only as a question: "Does your data include health or customer financial information?"
- Tell the sponsor that rights review, de-identification and redaction rules are agreed with the company before any work begins, and that nothing is delivered without a signed agreement and the company's authorization.
- Send the company to its own counsel for legal questions; SourceX handles the licensing process, not legal advice.
If you are a licensed professional, your own rules on referral fees and disclosure also apply. Check them separately before you register.
Questions to ask your counsel
- Does my own license or employer restrict accepting referral fees tied to client companies?
- Which state privacy laws could attach to the sectors in my book?
- What should I say, and not say, when a prospect asks whether their data is "allowed"?
- How should I document that I only made an introduction?
Where the standard screen still applies
Privacy law is one of several filters. The same company must also clear size, history, data breadth and rights. The company fit checker gives a preliminary, non-binding screen with no contact details required, and the who qualifies page lists the baseline. For concrete sector examples, see HVAC and mechanical contractors, franchise consultants and attorneys and government contracting advisors. The page on poor-fit industries and the guide to buy-and-build sectors show where privacy rules most often narrow the list, and how partners find companies covers sourcing.
Next step
Pick one company in your network, ask the two regime questions, and run the screen. If it looks workable, register as a partner and make the introduction. This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting.