Privacy Laws Help. A VPN Still Protects the Connection.
Online privacy law is getting better, slowly. More US states now have consumer privacy laws. California has the CCPA and its data broker deletion tools. Europe has the GDPR. The FTC can go after companies that lie about privacy or use unfair data practices.
That is good. It gives people more leverage than they had ten years ago. But it is easy to misunderstand what those laws actually do.
A privacy law can help you ask a company what it knows about you. It can give you a way to delete some data. It can let you opt out of certain sales, targeted ads, or profiling. What it usually does not do is make the network you are using private while you are using it.
What privacy laws actually give you
Most modern privacy laws are about rights after data is collected. Depending on where you live, you may be able to:
- Ask for a copy of your personal data. This is usually called access.
- Correct inaccurate data. Useful when a company has the wrong details about you.
- Request deletion. There are exceptions, but the right matters.
- Opt out of data sales or targeted advertising. This is the one most people think of first.
- Limit sensitive data use. Some states treat location, health, biometric, or children’s data more carefully.
In 2026, the state privacy map is more crowded than ever. Indiana, Kentucky, and Rhode Island joined the list of states with comprehensive privacy laws in effect. California’s data broker deletion system also became a bigger part of the picture.
The trend is clear: regulators are paying more attention to data brokers, targeted ads, sensitive data, and companies that say one thing in a privacy policy but do another behind the scenes.
What those laws do not hide
Here is the part that matters for everyday browsing: legal rights are not the same thing as encryption.
If you connect to airport WiFi, hotel WiFi, public library WiFi, or your regular home internet, the network still handles your traffic. HTTPS protects the contents of most modern web pages, which is great. But the network can still often see useful metadata: domains, timing, traffic volume, device behavior, and which services your apps are talking to.
Your ISP is also still your first hop to the internet. Even when it cannot read the exact page you are viewing, it may still learn from DNS requests, IP addresses, connection timing, and traffic patterns. The FTC’s own ISP privacy work has pointed out that internet providers can sit in a powerful position because they carry so much of your traffic.
Where a VPN fits
A VPN is not a replacement for privacy law. It does not make bad companies delete old profiles. It does not stop every tracker. It does not make you anonymous.
What it does is simpler: it encrypts the connection between your device and the VPN server. The coffee shop, hotel, airport, library, or ISP sees encrypted traffic going to one VPN server instead of a detailed map of every service your device is contacting.
That is why the privacy law versus VPN debate is the wrong framing. You want both. Laws give you rights over data companies already collected. A VPN reduces what some networks can collect from the connection in the first place.
If you want a simple version, use privacy rights when companies already have your data. Use a VPN when you do not want every network between you and the internet learning as much in the first place.
And you do not need a $12/month bundle to do that. If all you want is basic WireGuard protection for one device, 99¢ VPN is $11.88/year. It is the boring lock on the connection, which is usually the point.
Written by the person who runs 99¢ VPN. Not legal advice. Just a plain-English privacy guide for people who want less tracking without reading every statute.