When we work as information professionals in specialized areas, it is important to understand laws dealing with privacy, records regulation, and cybersecurity standards. Then, of course, once the laws are known, it is necessary to know how to comply.
Diving into all applicable laws and compliance procedures is a bigger topic than I have room for in this blog post, but I want to highlight a few and remind us all of the importance of knowing the laws that govern your area.
Law Libraries
Within law libraries, it is not only laws that govern the work of information professionals, but also the established responsibilities of the profession.
- Attorney-client privilege and the work product doctrine shape what can be disclosed, cataloged, or shared externally, even in research requests that seem routine.
- ABA Model Rule 1.6 (and state equivalents) impose a duty of confidentiality on client information.
- State bar cybersecurity guidance increasingly addresses cloud storage, vendor due diligence, and data breach response, all of which touch library systems and databases.
Government Libraries
Government libraries carry their own set of responsibilities, and information professionals in this space need to be just as familiar with disclosure requirements as they are with confidentiality ones.
- Freedom of Information Act (FOIA) at the federal level, and state-level open records or “sunshine” laws, govern what must be disclosed on request and what can be withheld.
- Federal Records Act and NARA regulations dictate retention schedules and disposition requirements for government records, including many special collections.
- Controlled Unclassified Information (CUI) rules apply to government libraries and contractors handling sensitive-but-unclassified material, requiring specific marking, storage, and access controls.
- State public records and retention laws vary widely, so a multi-state agency or a librarian supporting distributed offices needs to track requirements jurisdiction by jurisdiction.
Corporate Libraries
Corporate libraries add another layer, since information professionals here are often protecting proprietary and financial information alongside patron data.
- Gramm-Leach-Bliley Act (GLBA) governs financial institutions’ handling of nonpublic personal information, relevant for librarians supporting banking, insurance, or financial services divisions.
- Trade secret law, under the federal Defend Trade Secrets Act and state Uniform Trade Secrets Act adoptions, protects proprietary research and competitive intelligence, but only if reasonable safeguards are documented and maintained.
- PCI DSS isn’t a law but a contractual security standard that applies if your library systems process any payment card data (e.g., paid database subscriptions billed through internal systems).
Laws for All Libraries
Regardless of the type of special library you work in, there are a couple of areas every information professional should have on their radar.
- State data breach notification laws. Every state now has one, and they differ in what counts as a reportable breach and how quickly notification must occur.
- State comprehensive privacy laws. Approximately 20 states currently have comprehensive privacy laws. I encourage you to know your state’s laws and, if your organization operates across state lines, all applicable privacy laws.
This is not meant to be a comprehensive list, but rather to provide important information for you. I encourage you to dig into the laws yourself and ensure you are up to date and compliant. The regulatory landscape that special librarians navigate is often more complex than in most other library settings.
As you consider the complexity, note that this is one reason the role is indispensable. Understanding which laws govern your collection isn’t just a compliance exercise. It is a core professional expertise that protects your users and your organization.
References
- American Bar Association. (2020). Model rules of professional conduct: Rule 1.6 Confidentiality of information.
- Controlled Unclassified Information, 32 C.F.R. § 2002 (2016).
- Defend Trade Secrets Act of 2016, Pub. L. No. 114-153, 130 Stat. 376 (codified at 18 U.S.C. § 1836 et seq.).
- Federal Records Act of 1950, 44 U.S.C. §§ 2101–3107 (2018).
- Freedom of Information Act, 5 U.S.C. § 552 (2018).
- Gramm-Leach-Bliley Act, Pub. L. No. 106-102, 113 Stat. 1338 (1999) (codified at 15 U.S.C. §§ 6801–6809).
- International Association of Privacy Professionals. (2025). US state data breach notification chart.
- International Association of Privacy Professionals. (2026). US state privacy legislation tracker.
- PCI Security Standards Council. (2022). Payment Card Industry data security standard: Requirements and testing procedures (Version 4.0).
- Uniform Trade Secrets Act (Unif. Law Comm’n 1985).
0 Comments