Most legal specialisms grow slowly. This one was created almost entirely by legislation inside a decade, and the pace of that legislation is still the single best explanation for why the jobs exist. If you want to understand the market for privacy and cybersecurity lawyers in the United States, start with the statute book rather than with the job listings.
What actually changed
Four things, each of which added a distinct layer of legal work.
The state patchwork. The United States has no single comprehensive federal privacy law, so states have legislated one by one. By 2026 roughly twenty states have comprehensive consumer privacy statutes on the books, according to the International Association of Privacy Professionals and its state privacy legislation tracker, with the Indiana, Kentucky, and Rhode Island laws taking effect on 1 January 2026. Each has its own definitions, thresholds, consumer rights, and enforcement approach. A company operating nationally must reconcile all of them, which is a permanent legal workload rather than a project.
A dedicated regulator. California went further than the rest by creating the California Privacy Protection Agency, the first American state agency devoted specifically to privacy, with its own rulemaking and enforcement powers alongside the Attorney General. A specialist regulator produces rules, investigations, and enforcement actions, and each of those produces legal work.
Securities disclosure of cyber incidents. The Securities and Exchange Commission's cybersecurity rules require public companies to disclose material cybersecurity incidents on Item 1.05 of Form 8-K, generally within four business days of determining that an incident is material, with a narrow national security delay available where the Attorney General so determines and notifies the Commission. This turned incident response from a technical exercise into a securities disclosure question with a clock on it, which is why in-house teams now want lawyers who understand both.
Sectoral and international overlay. On top of all of the above sit the older federal sectoral rules covering health, financial, education, and children's data, plus the European Union's General Data Protection Regulation, whose extraterritorial reach means American companies with European users are inside its scope. Then artificial intelligence governance arrived, drawing on the same skill set.
Every one of these developments produced a compliance obligation that must be met continuously rather than once. That is the structural reason privacy roles keep appearing even in years when general legal hiring is flat.
The roles this created
| Role | What it does | Law degree |
|---|---|---|
| Privacy counsel | Advises on the statutory patchwork, drafts policies and data agreements, handles regulator contact | Yes |
| Product counsel | Sits with engineering and product teams, advising on features before they ship | Yes |
| Cybersecurity or incident response counsel | Breach analysis, notification decisions, disclosure obligations, privilege management | Yes |
| Data protection officer | A statutory role under European rules, independent oversight of processing | Often, not always |
| Privacy programme manager or analyst | Assessments, records of processing, vendor reviews, training, rights requests | No |
| AI governance lead | Model inventories, risk assessments, policy design for AI deployment | No |
Note the bottom half of that table. Roughly half of this field does not require a law degree, which makes privacy one of the more accessible legal adjacent specialisms for people entering from compliance, security, audit, or programme management backgrounds.
What it pays, and why the data is awkward
There is no Bureau of Labor Statistics occupation code for privacy counsel, so anyone quoting a precise national salary figure for the role is quoting a private survey rather than official data. What the BLS does publish sets useful bounds.
Lawyers across all industries had a median annual wage of about USD 159,670 in May 2025, with the 10th percentile near USD 78,360 and the 90th percentile near USD 351,600. Compliance officers, which is the closest published code for the non lawyer privacy roles, numbered about 417,070 with a median near USD 80,730 and a 90th percentile around USD 133,720.
The honest reading is that lawyer side privacy roles sit within the in-house counsel range for the relevant company and market, and non lawyer privacy roles sit within the compliance range, with the specialist premium showing up towards the top of each distribution rather than as a separate scale. Treat any single quoted number with suspicion, and price your own market by company size, sector, and city.
The credentials that carry weight
Privacy is unusual among legal specialisms in having a widely recognised certification ecosystem, run by the International Association of Privacy Professionals. The main credentials are the Certified Information Privacy Professional, offered in regional concentrations including a United States version, the Certified Information Privacy Manager for programme management, and the Certified Information Privacy Technologist for the engineering facing side. The association also offers an Artificial Intelligence Governance Professional credential, and its exam content was updated for testing from 2 February 2026 to reflect changes in the field. Several of these credentials are accredited under the ISO and IEC 17024 standard by the ANSI National Accreditation Board.
For a qualified lawyer, a certification is a signal rather than a licence: it tells a hiring manager you have systematic knowledge rather than incidental exposure. For a non lawyer, it is closer to essential, because it is the standard way to demonstrate competence without a legal qualification.
How people actually get in
Four routes account for most entrants.
From regulatory or litigation practice. Lawyers who have handled consumer protection, advertising, or data breach litigation move across naturally, because the underlying enforcement framework is familiar.
From transactional practice. Data processing agreements, vendor terms, and cross border transfer mechanics are contract work at heart, so commercial lawyers convert well.
From compliance. Anyone who has built a compliance programme knows how to run assessments, evidence controls, and train a business. The subject matter is new but the machinery is not, a pattern also visible in AML and financial crime compliance careers and trade compliance careers.
From security or engineering. The scarcest and most valuable profile in this field is someone who can talk to engineers about how data actually flows and then translate that into a legal position. If you have that background, the privacy technologist route is open to you.
The common failure is applying with generic interest. "I am interested in privacy law" is not a differentiator in 2026. Naming a specific statute you have worked with, a specific assessment you have run, or a specific incident process you have supported is.
Where the jobs are
In-house teams at technology, healthcare, financial services, retail, and advertising companies are the largest employers, and privacy is one of the specialisms where in-house roles appear at more junior levels than the usual in-house pattern would suggest. Law firms run privacy and cybersecurity practices, often paired with incident response. Consultancies and audit firms hire heavily for the programme side, and regulators themselves, including state attorney general offices, hire lawyers to enforce these statutes. For the corporate route see in-house counsel careers, and for a comparable specialised regulatory track see regulatory affairs specialist careers.
Frequently asked questions
Do I need a law degree to work in privacy?
Not for all of it. Privacy counsel, product counsel, and incident response counsel roles require a law degree. Privacy programme management, assessments, rights request handling, and AI governance roles frequently do not, and are commonly filled from compliance, audit, and security backgrounds.
How many US states have comprehensive privacy laws?
Roughly twenty as of 2026 according to the International Association of Privacy Professionals, with the Indiana, Kentucky, and Rhode Island statutes taking effect on 1 January 2026. There is still no single comprehensive federal privacy law, which is what makes the patchwork a permanent workload.
What does privacy counsel pay?
There is no separate BLS occupation code, so official figures do not exist for the role. The BLS lawyer median was about USD 159,670 in May 2025 with a 90th percentile near USD 351,600, and compliance officers, the closest code for non lawyer privacy roles, had a median near USD 80,730. Position yourself within those ranges by sector and city rather than trusting a single quoted figure.
Is the CIPP certification worth it?
For non lawyers it is close to a standard requirement. For lawyers it is a credible signal of systematic knowledge, particularly when moving into privacy from another practice area. Several IAPP credentials are accredited under the ISO and IEC 17024 standard.
What are the SEC cybersecurity disclosure rules?
They require public companies to disclose material cybersecurity incidents on Item 1.05 of Form 8-K, generally within four business days of determining materiality, with a narrow delay available on national security grounds determined by the Attorney General. They are the reason incident response now involves securities lawyers.
Is AI governance a separate career or part of privacy?
In most organisations it currently sits with the privacy team, because the assessment machinery, the data mapping, and the regulator facing skills are the same. Dedicated credentials now exist, which suggests it is separating into its own specialism over time.
The bottom line
Privacy and cybersecurity is the clearest example in American law of legislation creating a profession. The workload is structural rather than cyclical, roughly half the roles are open to non lawyers, and the certification path is unusually well defined. Pick your entry route honestly, get the credential that matches it, and replace generic interest with one concrete thing you have actually done.
Ready to look ahead? Compare adjacent specialisms in AML compliance analyst careers and e-discovery analyst careers, see the corporate route in in-house counsel careers, and browse current roles on our US legal jobs board.
This article is a general 2026 guide, not legal or career advice. Privacy legislation, regulator powers, disclosure rules, and certification syllabuses change frequently, and the number of state laws in force moves year to year. Wage figures are Bureau of Labor Statistics Occupational Employment and Wage Statistics estimates for May 2025 for adjacent occupation codes, since no code exists for privacy counsel. Always verify current law with the relevant regulator, certification details with the IAPP (iapp.org), and pay data with the BLS (bls.gov).
