July 27, 2026 · 4 min read

Privacy Laws Help, But They Do Not Hide Your Connection

Privacy laws are useful. I am glad they exist. But they are easy to misunderstand.

A law can give you the right to ask a company what data it has about you. It can let you request deletion. It can make a business put a “do not sell or share my personal information” link on a page. That is real progress.

But none of that makes the coffee shop WiFi private. None of it stops your internet provider from being the first company your traffic touches. And none of it turns Incognito mode into a force field.

What privacy laws actually do

In the U.S., privacy law is still a patchwork. There is no single federal law that works like a simple “online privacy bill of rights” for everyone. Instead, you get a mix of federal rules for specific industries, FTC enforcement against unfair or deceptive practices, and state privacy laws.

California started the big state privacy wave with the CCPA and CPRA. Since then, more states have passed their own consumer privacy laws. By 2026, trackers like IAPP and Bloomberg Law count around 20 states with comprehensive privacy laws in effect or on the books.

The common rights are pretty practical:

That matters. If a data broker, app, retailer, or ad-tech company is building a profile on you, these rights can help you push back.

What privacy laws do not do

Here is the part people miss: legal rights are not the same thing as network privacy.

When you connect to WiFi at a library, airport, hotel, or apartment building, your traffic still has to move through that network. HTTPS protects the contents of most websites, which is good. But the network can still learn things from domains, DNS requests, timing, traffic volume, and the IP addresses you connect to.

Your ISP also sits in a powerful spot. Even when it cannot read the inside of an encrypted page, it can often see where connections are going and when. The FTC has warned before that internet providers can collect large amounts of personal data and that users often have limited practical choices.

A privacy law might say a company needs to disclose what it collects or let you opt out of certain uses. It does not encrypt your packets on public WiFi. It does not stop a hotel network from seeing that your laptop is talking to a work service. It does not hide your home IP address from the sites you visit.

Where a VPN fits

A VPN solves a narrower problem, but it solves it directly.

It puts an encrypted tunnel between your device and the VPN server. The local network sees encrypted traffic going to one VPN endpoint. Your ISP sees the VPN connection, not the full list of sites and services inside the tunnel. Websites see the VPN server IP instead of your home or coffee shop IP.

That does not replace privacy laws. It also does not make you anonymous. If you log into Instagram, Instagram still knows it is you. If you hand your email to a store, the VPN cannot delete that record later.

Think of it this way: privacy laws help with what companies do after they collect data. A VPN helps reduce what the network can see in the first place.

You want both habits. Use privacy rights when a company already has your data. Use a VPN when you do not want every network between you and the internet getting an easy look at your traffic.

If you want the simple version, 99¢ VPN gives you WireGuard protection for one device at $11.88/year. It is not a legal department. It is just a cheap, practical lock for your connection.


Written by the person who runs 99¢ VPN. Not legal advice. Just the plain-English version of where privacy laws stop and connection privacy starts.