Policy Issue

Protecting Consumer Privacy

A person swiping their credit card.

Retailers prioritize protecting consumer privacy to build trust and long-term relationships in a competitive marketplace that stretches from Main Street stores to websites and mobile apps. Beyond offering merchandise at competitive prices, retailers must responsibly gather and use customer data to understand the products and services customers want in order to better serve them and win their sustained business. NRF supports a customer-centric approach to data privacy under state and federal laws.

NRF joined a broad coalition of business associations in supporting the introduction of the SECURE Data Act, federal legislation that would establish a national privacy framework, based on the consensus of state data privacy laws already in place, extending important protections to all consumers.  Read the business community statement.

Data's role in retail

Customer data — ranging from shipping addresses to buying preferences — enables retailers to offer consumers the level of personalized services they demand, improving the convenience and value of their shopping experience. Consumers today are savvy shoppers who are more sensitive to how their personal information is handled, expecting it to be kept confidential and used only for its intended purposes.

Retailers go to great lengths to adopt policies and practices that put customers first and invest billions of dollars in technology to responsibly collect, process and protect this information. However, overreaching regulations could interfere with popular services like loyalty programs, expedited services and promotions. New laws and regulations must avoid frustrating consumers by restricting their shopping experiences in stores and online, particularly at their favorite retail stores.

Federal privacy legislation

Since California’s Consumer Privacy Act passed in 2018, state privacy laws have been enacted in nearly 40% of states making it difficult for retailers to comply with a patchwork of laws. NRF supports federal privacy legislation that would apply to all entities handling consumer information, including financial institutions, big tech companies and retailers, to simplify compliance and avoid the challenges of differing state laws.

NRF's Principles for Federal Privacy Legislation:

  • National privacy law: One uniform law requiring all businesses to protect consumers nationwide.

  • Transparency: Clear communication with consumers on data collection and use.

  • Preserving customer benefits: Protect voluntary services like loyalty programs.

  • Responsibility: Businesses must be accountable for their own data practices — not violations by a partner, franchise or contractor.

  • No exemptions: All businesses and every industry handling data must have equivalent privacy responsibilities.

  • Enforcement: Government agencies should enforce consistent privacy standards.

  • Notice-and-cure: Businesses should have reasonable opportunities to address non-compliance.

Main Street Privacy Coalition

NRF leads the Main Street Privacy Coalition, a group of 20 trade associations representing over 1 million businesses. Together, the coalition advocates for a uniform, consumer-focused privacy law at the federal level.

Learn more about the coalition’s principles for federal privacy legislation.

State privacy legislation

NRF supports the work of our state retail association partners who advocate on behalf of the retail industry on data privacy legislation in the state legislatures. For more information on current bills being actively considered, please see NRF’s state legislative activity tracker.  

Learn more about state privacy legislation.

European privacy regulations

The General Data Protection Regulation, enacted in 2018, is a European Union privacy law that affects global retailers operating in Europe or targeting European consumers online. It governs data collection and processing, with significant implications for U.S.-based retailers. Since 2016, the EU has worked to establish data privacy frameworks to protect the transatlantic transfer of personal data between EU member states and the U.S. After years of collaboration with the global retail community, NRF welcomed the creation of the EU-U.S. Data Privacy Framework, adopted in 2023, to ensure safe transatlantic data transfers and enable U.S. companies to continue operating in Europe.

Learn more about European privacy rules.

Protecting Consumer Privacy
Retail’s 6 most important policy priorities for 2026
California Retail Law Summit tackles evolving regulations
Related Content