Ruston Miles is the founder and chief strategy and development officer of Bluefin, the Atlanta-based payments and data security software provider. He is based in Broken Arrow, Oklahoma.
Your privacy rights should not depend on your ZIP code. Right now, they do.
In the absence of a federal consumer privacy framework, both consumers and businesses are paying the price.
Consumers receive different privacy protections depending on where they live, while organizations operating nationally must navigate an increasingly fragmented web of requirements governing how payment data is collected, shared, stored, and used.

So far, more than 20 states have enacted comprehensive consumer privacy laws, with additional legislation under consideration across the country. Those laws represent meaningful progress, giving consumers greater visibility into and control over their personal information.
But they come with a cost.
Payments don’t operate state by state. Merchants, payment processors, financial institutions, and technology providers routinely support customers from coast to coast. As state privacy laws continue to diverge, organizations must layer increasingly complex compliance obligations onto a payments system designed to operate nationally.
Here's the uncomfortable truth: compliance is not the same as protection. A merchant can satisfy every requirement in every state privacy law on the books and still be one breach away from exposing millions of card numbers.
Meanwhile, the practices that actually reduce risk, such as data minimization, tokenization, and encryption, are the same in every jurisdiction. No state line changes what makes payment data safe. Yet organizations are spending their security budgets proving compliance rather than eliminating risk.
A national privacy framework should establish consistent consumer rights while taking an outcome-based approach to payment security. Instead of measuring compliance by the number of requirements organizations satisfy, it should encourage demonstrable reductions in consumer risk.
There's already precedent for this: many state breach notification laws include safe harbors for data that was encrypted at the time of compromise. Those laws recognize that the consequences of a breach are fundamentally different when the exposed data has been devalued and rendered unreadable or unusable. A federal framework should extend that logic to payment data broadly.
This means creating regulatory incentives for organizations to devalue sensitive payment data, making it far less useful to attackers even if it is compromised. It’s an approach that better aligns regulation with its ultimate goal: protecting consumers.
The stakes will only grow as artificial intelligence becomes embedded throughout the payments ecosystem. Privacy law has focused on how data is collected, shared, and stored; AI expands the question to how data is analyzed, combined, and acted upon.
A state-by-state patchwork was already a poor fit for a national payments system. It has no chance of keeping pace with AI.
The payments industry has already built national networks capable of moving money securely across state lines. Now we need a national framework in which privacy protections travel with the data.