U.S. State Privacy Laws: 2026 Tracker and Compliance Guide
Table of Contents
As of August 2026, 20 U.S. states have comprehensive consumer privacy laws in effect. Indiana, Kentucky, and Rhode Island joined on January 1, 2026, and Oklahoma and Alabama arrive in 2027. There is still no U.S federal data privacy law.
Each state law sets its own rules for who's covered, which rights consumers get, and when you need consent. Twelve U.S. states now require sites to honor Global Privacy Control (GPC) opt-out signals.
This tracker covers every U.S. state law, who it applies to, and what it means for your website.
First, the bad news: if you sell to customers in multiple states, you're subject to a messy patchwork of regulations that grows every year. No single law covers you entirely; you inherit whichever state laws your customers live under, each with its own thresholds and quirks.
The good news: these laws share most of their DNA. Get the common baseline right, handle the handful of stricter outliers, and multi-state compliance stops being a quarterly project.
Below you'll find every law with its key facts, then the practical part most legal trackers skip: what these laws require from your website.

At a glance: every state privacy law in 2026
According to MultiState's legislative tracking, 20 comprehensive U.S. state privacy laws are in effect as of August 2026, with two more signed and set to take effect in 2027.
| State | Law | In effect | GPC required |
|---|---|---|---|
| California | CCPA / CPRA | Jan 2020 / Jan 2023 | Yes |
| Virginia | VCDPA | Jan 2023 | No |
| Colorado | CPA | Jul 2023 | Yes |
| Connecticut | CTDPA | Jul 2023 | Yes |
| Utah | UCPA | Dec 2023 | No |
| Texas | TDPSA | Jul 2024 | Yes |
| Oregon | OCPA | Jul 2024 | Yes (Jan 2026) |
| Florida | FDBR | Jul 2024 | No |
| Montana | MCDPA | Oct 2024 | Yes |
| Delaware | DPDPA | Jan 2025 | Yes (Jan 2026) |
| Iowa | ICDPA | Jan 2025 | No |
| Nebraska | NDPA | Jan 2025 | Yes |
| New Hampshire | NHDPA | Jan 2025 | Yes |
| New Jersey | NJDPA | Jan 2025 | Yes |
| Tennessee | TIPA | Jul 2025 | No |
| Minnesota | MCDPA | Jul 2025 | Yes |
| Maryland | MODPA | Oct 2025 | Yes |
| Indiana | INCDPA | Jan 2026 | No |
| Kentucky | KCDPA | Jan 2026 | No |
| Rhode Island | RIDTPPA | Jan 2026 | No |
| Oklahoma | OCDPA | Jan 2027 (signed) | No |
| Alabama | APDPA | May 2027 (signed) | Yes |
Three more states regulate privacy without a comprehensive law, and two of them carry more litigation risk than the rest:
| State | Law | In effect | The short version |
|---|---|---|---|
| Illinois | BIPA | 2008 | Biometric data; private right of action; most-litigated privacy statute in the U.S. |
| New York | SHIELD Act | 2020 | Data security and breach notification duties for anyone holding NY residents' data |
| Washington | My Health My Data Act | 2024 | Consumer health data; broad private right of action |
Is there a federal U.S. privacy law?
No. The American Data Privacy and Protection Act (ADPPA) and its successor, the American Privacy Rights Act, both stalled in Congress, and newer proposals like the SECURE Data Act haven't moved past committee either, with preemption of stronger state laws still the sticking point. What exists federally is sectoral: HIPAA for health data held by covered entities, GLBA for financial institutions, COPPA for children's data, and FTC enforcement against unfair or deceptive data practices.
According to the FTC's business guidance, the agency treats broken privacy promises as deceptive practices, which means your own privacy policy is enforceable against you even in states with no privacy law at all.
Until Congress acts, your obligations come from the state laws below.
California Consumer Privacy Act (CCPA / CPRA)
California started the wave of strict U.S. privacy legislation and remains the most demanding of the lot.
The CCPA (2020), amended by the CPRA (2023), created the country's only dedicated privacy regulator (the CPPA) and the only private right of action in a comprehensive law for data breaches, with damages ranging from $100 to $750 per consumer per incident.
It also runs a rulemaking machine that keeps adding requirements: data broker registration, AI and automated decision-making rules, and risk assessments through 2026.
If you comply with California and nothing else, you're most of the way to the national baseline.
| Feature | CCPA / CPRA |
|---|---|
| In effect | CCPA Jan 1, 2020; CPRA amendments Jan 1, 2023 |
| Applies to you if | You had $25M+ gross revenue in the preceding year; OR buy, sell, or share personal information of 100K+ CA consumers or households; OR earn 50%+ of revenue from selling or sharing personal information |
| Fines | $2,500 per negligent violation; $7,500 per intentional violation; breach suits at $100 to $750 per consumer per incident |
| Cure period | None |
| Recognizes GPC | Yes |
| Privacy impact assessments | Required for profiling, sensitive data, large-scale processing, and other processing that risks harm to consumers |
| Sensitive data | Race or ethnicity, religion, health, sex life, sexual orientation, citizenship or immigration status, genetic and biometric data, precise geolocation, union membership, neural data, personal data of minors under 16 |
| Consumer rights | Know/confirm, access, correct, delete, portability, opt out of sale or sharing, limit use of sensitive data, opt out of automated decision-making and profiling |
Virginia Consumer Data Protection Act (VCDPA)
Virginia wrote the template that most states copied: opt-out rights for ordinary data, opt-in consent for sensitive data, a 100,000-consumer threshold, and attorney general-only enforcement. It's also one of the more forgiving laws to operate under: its 30-day cure period never expires.
| Feature | VCDPA |
|---|---|
| In effect | Jan 1, 2023 |
| Applies to you if | You do business in or target Virginia and control/process personal data of 100K+ consumers; OR 25K+ consumers with 50%+ of revenue from selling personal data |
| Fines | Up to $7,500 per violation |
| Cure period | 30 days, no sunset |
| Recognizes GPC | No |
| Privacy impact assessments | Required for targeted advertising, data sales, profiling, sensitive data, and any processing presenting a risk of harm |
| Sensitive data | Race or ethnicity, religion, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation (within a 1,750-foot radius) |
| Consumer rights | Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data |
Colorado Privacy Act (CPA)
Colorado follows the Virginia model but with sharper teeth: fines run to $20,000 per violation (capped at $500,000), while most state laws cap fines at $7,500. Its cure period sunset in January 2025, and GPC enforcement has been live since July 2024. Colorado's AG also keeps updating guidance, so requirements move more than in most standard-model states.
| Feature | CPA |
|---|---|
| In effect | Jul 1, 2023 |
| Applies to you if | You collect personal data of 100K+ CO residents; OR 25K+ residents with any revenue or discount derived from selling that data |
| Fines | $20,000 per violation, capped at $500,000 |
| Cure period | None (sunset Jan 2025) |
| Recognizes GPC | Yes (since Jul 2024) |
| Privacy impact assessments | Required for high-risk processing: targeted advertising, data sales, sensitive data, profiling |
| Sensitive data | Race or ethnicity, religion, health condition or diagnosis, sex life, sexual orientation, citizenship status, genetic and biometric data, data of a known child, neural data |
| Consumer rights | Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, object to automated decision-making |
Connecticut Data Privacy Act (CTDPA)
Connecticut runs the standard model with the broadest sensitive-data definition outside Maryland, and 2026 made it stricter. Amendments effective July 1 dropped the threshold from 100,000 to 35,000 consumers and added two triggers with no threshold at all: if you sell personal data or process sensitive data, you're covered at any volume.
| Feature | CTDPA |
|---|---|
| In effect | Jul 1, 2023 (amendments Jul 1, 2026) |
| Applies to you if | You do business in or target Connecticut and control/process personal data of 35K+ consumers; OR sell personal data at any volume; OR process sensitive data at any volume (payment-only processing excluded) |
| Fines | $5,000 per willful violation (via CUTPA), plus AG orders, disgorgement, and restitution |
| Cure period | None (sunset Dec 2024) |
| Recognizes GPC | Yes |
| Privacy impact assessments | Required for heightened-risk activities: targeted advertising, data sales, profiling, sensitive data |
| Sensitive data | Race or ethnicity, religion, health condition or diagnosis, consumer health data, sex life, sexual orientation, transgender or nonbinary status, citizenship status, genetic and biometric data, data of a known child, precise geolocation, crime-victim status, disability, financial account or card numbers with access credentials, government-issued IDs, neural data |
| Consumer rights | Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, object to automated decision-making, question the result of profiling |
Utah Consumer Privacy Act (UCPA)
Utah is the most business-friendly law on this list. It only applies if you clear $25 million in revenue AND a consumer-count threshold, sensitive data needs only notice and an opt-out (not opt-in consent), there's no GPC requirement, no impact assessments, and the 30-day cure period never expires.
If you're already handling California, consider yourself covered on the Utah front.
| Feature | UCPA |
|---|---|
| In effect | Dec 31, 2023 |
| Applies to you if | You have $25M+ annual revenue AND control/process personal data of 100K+ UT residents, OR 25K+ residents with 50%+ of revenue from selling personal data |
| Fines | Up to $7,500 per violation plus actual damages |
| Cure period | 30 days, no sunset |
| Recognizes GPC | No |
| Privacy impact assessments | Not required |
| Sensitive data | Race or ethnicity, religion, health condition and medical history, sexual orientation, citizenship or immigration status, genetic and biometric data, precise geolocation |
| Consumer rights | Know/confirm, access, correct (added by HB 418), delete, portability, opt out of sale and targeted advertising, notice and opt-out for sensitive data |
Texas Data Privacy and Security Act (TDPSA)
Texas skipped the consumer-count threshold entirely: if you do business in Texas and you're not an SBA-defined small business, you're covered, with no revenue floor.
Even exempt small businesses need consent before selling sensitive data. Texas's AG has run dedicated privacy sweeps since 2024, enforcement most states haven't attempted.
| Feature | TDPSA |
|---|---|
| In effect | Jul 1, 2024 |
| Applies to you if | You do business in Texas or serve Texas residents, process or sell personal data, and aren't an SBA-defined small business. No revenue or volume thresholds |
| Fines | Up to $7,500 per violation, plus injunctive relief |
| Cure period | 30 days, no sunset |
| Recognizes GPC | Yes (since Jan 2025) |
| Privacy impact assessments | Required for targeted advertising, data sales, profiling, sensitive data, and other heightened-risk processing |
| Sensitive data | Race or ethnicity, religion, health diagnosis, sexuality, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation |
| Consumer rights | Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, object to automated decision-making |
Oregon Consumer Privacy Act (OCPA)
Oregon follows the standard model with one right no other state started with: consumers can request the specific third parties that received their data, not just the categories. Its GPC requirement kicked in January 2026, the same month its cure period expired. A 2026 amendment also banned the sale of data from users known to be under 16, and the law uniquely covers motor vehicle manufacturers that process vehicle data, regardless of thresholds.
| Feature | OCPA |
|---|---|
| In effect | Jul 1, 2024 |
| Applies to you if | You control/process personal data of 100K+ OR residents; OR 25K+ residents with 25%+ of revenue from selling personal data; OR you're a vehicle manufacturer processing data from vehicle use |
| Fines | Up to $7,500 per violation |
| Cure period | None (sunset Jan 2026) |
| Recognizes GPC | Yes (since Jan 1, 2026) |
| Privacy impact assessments | Required for targeted advertising, data sales, profiling, sensitive data, and other heightened-risk processing |
| Sensitive data | Race, ethnicity, or national origin, religion, health condition or diagnosis, sexual orientation, transgender or nonbinary status, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation, crime-victim status |
| Consumer rights | Know/confirm, access, list of specific third parties who received your data, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, object to automated decision-making |
Florida Digital Bill of Rights (FDBR)
Florida is the asterisk in every state count. The FDBR's full controller obligations only apply to for-profit companies with over $1 billion in global revenue that also meet one of three tech-platform criteria: 50%+ of revenue from online ads, an app store with 250,000+ apps, or a consumer smart-speaker service. That's why most trackers count '19 plus Florida. '
Two parts do reach smaller companies: rules on selling sensitive data and children's data protections.
| Feature | FDBR |
|---|---|
| In effect | Jul 1, 2024 |
| Applies to you if | Full obligations: for-profit, doing business in Florida, $1B+ global revenue, AND one of: 50%+ of revenue from online ads; an app store with 250K+ apps; or a consumer smart-speaker and voice assistant service (in-car systems excluded). Sensitive-data sale rules: ANY for-profit entity doing business in Florida |
| Fines | Up to $50,000 per violation; up to $150,000 (tripled) when a known child's data is involved |
| Cure period | 45 days (discretionary; not available for children's-data violations) |
| Recognizes GPC | No (statute is silent on universal opt-out signals) |
| Privacy impact assessments | Required for targeted advertising, data sales, risky profiling, sensitive data, and other heightened-risk processing |
| Sensitive data | Race or ethnicity, religion, health diagnosis, sexual orientation, citizenship or immigration status, genetic and biometric data, precise geolocation, and all personal data of a known child under 18 |
| Consumer rights | Know/confirm, access, correct, delete, portability, opt out of sale, targeted advertising, and significant profiling, opt out of sensitive-data collection, opt out of voice and facial recognition collection on smart devices (unique to Florida), search-engine ranking transparency (unique to Florida) |
Montana Consumer Data Privacy Act (MCDPA)
Montana fit the standard model to a small population, and 2025 amendments cut the thresholds deeper: 25,000 residents, down from 50,000, or just 15,000 if a quarter of your revenue comes from data sales. Its cure period sunset in April 2026.
Duty-of-care rules for minors reach every business serving Montanans, regardless of size.
| Feature | MCDPA (Montana) |
|---|---|
| In effect | Oct 1, 2024 |
| Applies to you if | You control/process personal data of 25K+ MT residents; OR 15K+ residents with 25%+ of revenue from selling personal data. Minor duty-of-care rules apply regardless of thresholds |
| Fines | Up to $7,500 per violation |
| Cure period | None (60-day period sunset Apr 2026) |
| Recognizes GPC | Yes |
| Privacy impact assessments | Required for targeted advertising, data sales, profiling, sensitive data, and other heightened-risk processing |
| Sensitive data | Race or ethnicity, religion, health condition or diagnosis, sex life, sexual orientation, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation |
| Consumer rights | Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, object to automated decision-making |
Delaware Personal Data Privacy Act (DPDPA)
Delaware runs the standard model at one of the lowest thresholds in the country: 35,000 consumers, or just 10,000 if a fifth of your revenue comes from data sales. Its GPC requirement and cure-period sunset both landed January 2026.
Enforcement discretion rests with the state Department of Justice, and, as in Oregon, consumers can demand the specific third parties that obtained their data.
| Feature | DPDPA |
|---|---|
| In effect | Jan 1, 2025 |
| Applies to you if | You do business in or target Delaware and control/process personal data of 35K+ consumers (payment-only processing excluded); OR 10K+ consumers with 20%+ of revenue from selling personal data |
| Fines | Up to $10,000 per violation, at DOJ discretion |
| Cure period | None (60-day period sunset Jan 2026) |
| Recognizes GPC | Yes (since Jan 1, 2026) |
| Privacy impact assessments | Required for targeted advertising, data sales, sensitive data, and profiling that risks deceptive treatment, injury, or intrusion on solitude |
| Sensitive data | Race, ethnicity, or national origin, religion, health condition or diagnosis, sex life, sexual orientation, transgender or nonbinary status, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation |
| Consumer rights | Know/confirm, access, list of specific third parties who received your data, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, object to automated decision-making |
Iowa Consumer Data Protection Act (ICDPA)
Iowa sits with Utah at the lenient end: sensitive data requires only notice and an opt-out, there's no GPC duty, no impact assessments, no correction right, and the 90-day cure period is the longest anywhere.
Treat it as covered by your Virginia-model baseline.
| Feature | ICDPA |
|---|---|
| In effect | Jan 1, 2025 |
| Applies to you if | You control/process personal data of 100K+ IA consumers; OR 25K+ consumers with 50%+ of revenue from selling personal data |
| Fines | $7,500 per violation |
| Cure period | 90 days |
| Recognizes GPC | No |
| Privacy impact assessments | Not addressed by the law |
| Sensitive data | Race, ethnicity, or national origin, religion, health diagnosis, sexual orientation, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation |
| Consumer rights | Know/confirm, access, delete, portability, opt out of sale and targeted advertising, opt out or limit sensitive data processing. No correction right |
Nebraska Data Privacy Act (NDPA)
Nebraska copied the Texas playbook: no consumer-count or revenue threshold, an SBA small-business carve-out, and GPC recognition from day one. If you do business in Nebraska at any real scale, assume you're covered.
The 30-day cure period doesn't sunset.
| Feature | NDPA |
|---|---|
| In effect | Jan 1, 2025 |
| Applies to you if | You do business in Nebraska or serve Nebraska residents, process or sell personal data, and aren't an SBA-defined small business. No thresholds |
| Fines | $7,500 per violation |
| Cure period | 30 days, no sunset |
| Recognizes GPC | Yes |
| Privacy impact assessments | Required for targeted advertising, data sales, sensitive data, and profiling that risks deceptive treatment, injury, or intrusion on solitude |
| Sensitive data | Race or ethnicity, religion, health diagnosis, sexual orientation, citizenship or immigration status, genetic and biometric data processed to identify a person, data of a known child, precise geolocation |
| Consumer rights | Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling with significant effects |
New Hampshire Data Privacy Act (NHDPA)
New Hampshire pairs low thresholds (35,000 consumers) with the same enforcement route Connecticut and New Jersey use: privacy violations count as deceptive trade practices, with penalties up to $10,000 per violation. The cure period sunset in January 2026.
| Feature | NHDPA |
|---|---|
| In effect | Jan 1, 2025 |
| Applies to you if | You do business in or target New Hampshire and control/process personal data of 35K+ unique consumers (payment-only processing excluded); OR 10K+ consumers with 25%+ of revenue from selling personal data |
| Fines | Up to $10,000 per violation, via the deceptive trade practices law |
| Cure period | None (sunset Jan 2026) |
| Recognizes GPC | Yes |
| Privacy impact assessments | Required for any processing with heightened risk of harm: targeted advertising, data sales, certain profiling, sensitive data |
| Sensitive data | Race or ethnicity, religion, health condition or diagnosis, sex life, sexual orientation, citizenship or immigration status, genetic and biometric data processed to identify a person, data of a known child, precise geolocation |
| Consumer rights | Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling with legal or similarly significant effects |
New Jersey Data Privacy Act (NJDPA)
New Jersey extends the standard model in two ways that trip up companies compliant elsewhere.
Financial information counts as sensitive data; a broader trigger than any other state's (Connecticut's stops at account and card numbers with access credentials). And penalties escalate: violations route through the Consumer Fraud Act at up to $10,000 for a first offense and $20,000 after that.
Its cure period sunset on July 15, 2026, so as of writing there's no grace window.
| Feature | NJDPA |
|---|---|
| In effect | Jan 15, 2025 |
| Applies to you if | You control/process personal data of 100K+ NJ consumers (payment-only processing excluded); OR 25K+ consumers with revenue or price discounts derived from selling personal data |
| Fines | Up to $10,000 first violation, up to $20,000 for subsequent violations (via Consumer Fraud Act) |
| Cure period | None (sunset Jul 15, 2026) |
| Recognizes GPC | Yes |
| Privacy impact assessments | Required for targeted advertising, data sales, sensitive data, and profiling with reasonably foreseeable risk of deceptive treatment, disparate impact, injury, or intrusion |
| Sensitive data | Race or ethnicity, religion, health condition, treatment, or diagnosis, sex life, sexual orientation, transgender or nonbinary status, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation, financial information |
| Consumer rights | Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, opt out of automated decision-making |
Tennessee Information Protection Act (TIPA)
Tennessee is the only state with a built-in affirmative defense: a written privacy program that reasonably conforms to the NIST Privacy Framework (or a comparable standard) shields you from liability.
Two conditions: the program stays updated within two years of framework revisions, and consumers still get every right the law grants them.
| Feature | TIPA |
|---|---|
| In effect | Jul 1, 2025 |
| Applies to you if | You have $25M+ annual revenue AND control/process personal information of 175K+ TN consumers; OR 25K+ consumers with 50%+ of revenue from selling personal information |
| Fines | Up to $7,500 per violation, trebled if willful |
| Cure period | 60 days |
| Recognizes GPC | No |
| Privacy impact assessments | Required for targeted advertising, data sales, sensitive data, profiling, and other heightened-risk processing |
| Sensitive data | Race, ethnicity, or national origin, religion, health condition or diagnosis, sexual orientation, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation |
| Consumer rights | Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, object to automated decision-making |
Minnesota Consumer Data Privacy Act (MCDPA)
Minnesota adds a right no other state has: consumers can question the result of profiling and get an explanation of why an automated decision came out the way it did. It also requires a documented privacy program the AG can inspect, plus a third-party disclosure list on request. The cure period sunset January 31, 2026.
| Feature | MCDPA (Minnesota) |
|---|---|
| In effect | Jul 31, 2025 |
| Applies to you if | You target Minnesotans and control/process personal data of 100K+ consumers; OR 25K+ consumers with 25%+ of revenue from selling personal data |
| Fines | $7,500 per violation |
| Cure period | None (sunset Jan 31, 2026) |
| Recognizes GPC | Yes |
| Privacy impact assessments | Required for targeted advertising, data sales, sensitive data, heightened-risk processing, and profiling that risks unfair treatment or injury; AG may review assessments |
| Sensitive data | Race or ethnicity, religion, health diagnosis, sexual orientation, citizenship or immigration status, genetic and biometric data, data of a known child, specific geolocation |
| Consumer rights | Know/confirm, access, list of third parties, correct, delete, portability, opt out of sale and targeted advertising, question the result of profiling, non-discrimination, appeal |
Maryland Online Data Privacy Act (MODPA)
Maryland is the strictest law since California, and stricter in one way: it bans the sale of sensitive data outright, consent or not, and imposes the country's toughest data-minimization standard (collect only what's reasonably necessary for the specific product the consumer asked for). Impact assessments must be run per algorithm.
Maryland imposes a data-minimization standard none of the Virginia-model laws attempt: collect only what's reasonably necessary for the specific product the consumer asked for.
| Feature | MODPA |
|---|---|
| In effect | Oct 1, 2025 |
| Applies to you if | You do business in or target Maryland and control/process personal data of 35K+ consumers (payment-only processing excluded); OR 10K+ consumers with 20%+ of revenue from selling personal data |
| Fines | Up to $10,000 per violation; up to $25,000 per repeat of the same violation |
| Cure period | Discretionary, up to 60 days (sunsets Apr 2027) |
| Recognizes GPC | Yes |
| Privacy impact assessments | Required for targeted advertising, data sales, sensitive data, and processing risking deceptive treatment, disparate impact, or injury. Must be conducted for each algorithm used |
| Sensitive data | Race, ethnicity, or national origin, religion, consumer health data, sex life, sexual orientation, transgender or nonbinary status, citizenship or immigration status, genetic data, biometric data, data of a known child, precise geolocation. Sale of sensitive data is banned entirely |
| Consumer rights | Know/confirm, access, correct, delete, portability, list of third parties (or categories) who received your data, opt out of sale, opt out of targeted advertising and profiling with significant effects |
Indiana Consumer Data Protection Act (INCDPA)
Indiana went live January 1, 2026 as a faithful copy of the Virginia model: same thresholds, same opt-in rule for sensitive data, same AG-only enforcement, same permanent 30-day cure period. That makes it one of the gentler laws in the 2026 wave.
| Feature | INCDPA |
|---|---|
| In effect | Jan 1, 2026 |
| Applies to you if | You operate in or target Indiana and control/process personal information of 100K+ residents; OR 25K+ residents with 50%+ of revenue from selling that data |
| Fines | $7,500 per violation |
| Cure period | 30 days, no sunset |
| Recognizes GPC | No |
| Privacy impact assessments | Required for targeted advertising, data sales, sensitive data, risky profiling, and other heightened-risk processing |
| Sensitive data | Race, ethnicity, or national origin, religion, health diagnosis made by a healthcare provider, sexual orientation, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation |
| Consumer rights | Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, object to automated decision-making |
Kentucky Consumer Data Protection Act (KCDPA)
Kentucky also launched January 1, 2026 on the Virginia template, with pre-effective-date amendments (HB 473, March 2025) that widened healthcare exemptions: data held by HIPAA-covered providers and HIPAA limited data sets sit outside the law entirely. The same amendments narrowed the impact-assessment trigger for profiling to risks of unlawful disparate impact.
| Feature | KCDPA |
|---|---|
| In effect | Jan 1, 2026 (PIA requirement from Jun 1, 2026) |
| Applies to you if | You do business in or target Kentucky and control/process data of 100K+ consumers; OR 25K+ consumers with 50%+ of revenue from selling personal data |
| Fines | $7,500 per violation |
| Cure period | 30 days, no sunset |
| Recognizes GPC | No |
| Privacy impact assessments | Required (from Jun 1, 2026) for targeted advertising, data sales, risky profiling, sensitive data, and heightened-risk processing |
| Sensitive data | Race or ethnicity, religion, health diagnosis, sexual orientation, citizenship or immigration status, genetic and biometric data processed to identify a person, data of a known child, precise geolocation |
| Consumer rights | Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, object to automated decision-making |
Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
Rhode Island is small-state, sharp-edges: a 35,000-consumer threshold, no cure period at all, penalties to $10,000 per violation, plus $100 to $500 per intentional disclosure of personal information. It launched January 1, 2026 with the least forgiving enforcement posture of the new wave.
| Feature | RIDTPPA |
|---|---|
| In effect | Jan 1, 2026 |
| Applies to you if | You're a for-profit entity doing business in or targeting Rhode Island and control/process personal data of 35K+ residents; OR 10K+ residents with 20%+ of revenue from selling that data |
| Fines | $10,000 per violation, plus $100 to $500 per intentional disclosure |
| Cure period | None |
| Recognizes GPC | No |
| Privacy impact assessments | Required before targeted advertising, data sales, risky profiling, and sensitive data processing |
| Sensitive data | Race or ethnicity, religion, health condition or diagnosis, sex life, sexual orientation, citizenship or immigration status, genetic and biometric data processed to identify a person, data of a known child, precise geolocation |
| Consumer rights | Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling with legal or similarly significant effects |
Illinois Biometric Information Privacy Act (BIPA)
Illinois has no comprehensive privacy law, yet it still produces more privacy litigation than any state in the table above. BIPA (2008) requires written consent before collecting biometric identifiers, and it hands consumers a private right of action with statutory damages. That combination built an entire class-action industry: fingerprint time clocks, face-tagging features, and voiceprint tools have all produced eight- and nine-figure settlements.
An August 2024 amendment (SB 2979) reined in the worst of it: repeated scans of the same data by the same method now count as one violation, not thousands. But BIPA remains the highest-severity privacy statute in the country for any company touching biometrics.
| Feature | BIPA |
|---|---|
| In effect | Oct 2008 |
| Applies to you if | You're a private entity collecting, storing, or using biometric identifiers of Illinois residents. No thresholds of any kind |
| Fines | $1,000 per negligent violation; $5,000 per intentional or reckless violation, recoverable by private plaintiffs |
| Cure period | None |
| Recognizes GPC | Not applicable (consent-based, not opt-out-based) |
| Privacy impact assessments | Not required; written retention policy required |
| Sensitive data | Biometric identifiers: fingerprints, voiceprints, retina or iris scans, face geometry, hand scans |
| Consumer rights | Informed written consent before collection, disclosure of retention schedule, deletion within statutory timelines, private right of action for violations |
New York SHIELD Act
New York also lacks a comprehensive consumer privacy law, but the SHIELD Act (2020) reaches almost everyone anyway. Any business holding the private information of New York residents must maintain reasonable data security safeguards and report breaches, regardless of where the business sits.
It grants no consumer rights and needs no consent banner; it's a security-and-breach law, enforced by the Attorney General with no private right of action.
Treat it as the floor for your security program, and watch this space: New York's comprehensive privacy bills keep advancing each session without passing.
| Feature | SHIELD Act |
|---|---|
| In effect | Mar 2020 (security requirements) |
| Applies to you if | You own or license computerized private information of any New York resident, wherever your business is located. Reduced obligations for small businesses |
| Fines | Up to $5,000 per violation for failing reasonable safeguards; breach-notification failures at $20 per failed notice (up to $5,000 each if knowing or reckless), capped at $250,000 total |
| Cure period | None |
| Recognizes GPC | Not applicable |
| Privacy impact assessments | Not required; a documented data security program is |
| Sensitive data | "Private information": SSNs, driver's license numbers, financial account and card data with credentials, biometric data, username or email plus password |
| Consumer rights | Breach notification. No access, deletion, or opt-out rights |
Washington My Health My Data Act (MHMDA)
Washington regulates one category, consumer health data, and does it more aggressively than any comprehensive law.
MHMDA (2024) requires opt-in consent to collect or share health data, a separate signed authorization to sell it, and a ban on geofencing around health facilities. The teeth: a broad private right of action through Washington's Consumer Protection Act, covering any violation, not just breaches.
'Health data' is defined loosely enough to reach period trackers, fitness apps, wellness e-commerce, and ad pixels on symptom pages.
| Feature | MHMDA |
|---|---|
| In effect | Mar 31, 2024 (Jun 30, 2024 for small businesses) |
| Applies to you if | You do business in Washington or target its residents and collect, share, or sell consumer health data. No revenue or volume thresholds |
| Fines | Enforced as per se Consumer Protection Act violations: AG penalties up to $7,500 per violation, plus a $5,000 enhancement for violations impacting vulnerable communities; private suits recover actual damages with discretionary treble damages capped at $25,000, plus attorney's fees |
| Cure period | None |
| Recognizes GPC | Not applicable (opt-in consent model) |
| Privacy impact assessments | Not required; consumer health data privacy policy required |
| Sensitive data | Consumer health data broadly: conditions, treatments, reproductive health, gender-affirming care, biometrics used for health inference, precise location near health services |
| Consumer rights | Access, deletion, withdrawal of consent, list of third parties with contact details, private right of action |
Signed and arriving in 2027: Oklahoma and Alabama
Two more comprehensive laws are already signed. Oklahoma's OCDPA takes effect January 1, 2027 on the Virginia model.
Alabama's Personal Data Protection Act (APDPA) follows May 1, 2027, with a $15,000-per-violation penalty, double the $7,500 most Virginia-model states carry. It also has an unusual second threshold: anyone earning more than 25% of revenue from data sales is covered, no matter how few consumers are involved.
Unlike Oklahoma, Alabama requires controllers to honor opt-out preference signals, so plan on GPC support there from day one.
| Feature | OCDPA (Oklahoma) | APDPA (Alabama) |
|---|---|---|
| In effect | Jan 1, 2027 | May 1, 2027 |
| Applies to you if | 100K+ consumers, or 25K+ with 50%+ revenue from data sales | 25K+ consumers (payment-only processing excluded), or 25%+ of gross revenue from data sales at any volume |
| Fines | $7,500 per violation | Up to $15,000 per violation |
| Cure period | 30 days, mandatory before AG action | 45 days after AG notice of violation; correcting bars the action |
| Recognizes GPC | No | Yes (opt-out preference signals must be honored) |
| Privacy impact assessments | Required for targeted advertising, data sales, risky profiling, sensitive data | Not required |
| Sensitive data | Standard list plus precise geolocation defined as a 1,750-foot radius | Standard list plus precise geolocation |
| Consumer rights | Access, correct, delete, portability, opt out of targeted advertising, sale, and significant profiling, appeal | Access, correct, delete, portability, opt out of targeted advertising, sale, and significant automated decisions |
What do U.S. state privacy laws require from your website?
This is where the actual work starts. Across all of these laws, the obligations that touch your website come down to four things.
Consent management
Every comprehensive law requires you to let consumers opt out of the sale or sharing of personal data, and most require opt-in consent before processing sensitive data. In practice, that means a consent banner or preference center that actually blocks trackers until the right consent state is in place, not one that just decorates the page.
This is the core job of Enzuzo's consent management platform: detect where a visitor is, apply that state's rules, and keep a record of what they chose.
Geo-aware behavior
Opt-in and opt-out obligations differ by state, so one-size-fits-all banner behavior either over-asks (hurting your opt-in rates in states that don't require it) or under-asks (creating exposure in states that do).
The teams we talk to increasingly run region-specific consent rules: stricter defaults for California, lighter treatment where the law allows it.
Consent records
Several laws require you to be able to demonstrate consent. If a regulator or a plaintiff's firm asks when a visitor consented and to what, "our banner was live that month" is not an answer. Timestamped consent logs are.
Data subject rights requests
Access, correction, deletion, and portability requests, generally with a 45-day response deadline. If you're fielding these by email and spreadsheet today, that works at low volume and breaks the first time a deletion request touches six systems. Our guide to data subject access requests covers how to set this up properly.

What is Global Privacy Control, and which states enforce it?
Global Privacy Control (GPC) is a browser signal that broadcasts a consumer's opt-out preference automatically. Instead of clicking "do not sell my data" on every site, the browser says it for them, and the law treats that signal as a valid opt-out you must honor.
Twelve states now require it: California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas. [verify: Virginia may make it 13; sources conflict on whether VCDPA amendments added a universal opt-out duty.] That list more than doubled in two years, and every serious draft bill now includes a universal opt-out clause. Treat GPC support as the direction of travel, not an edge case.
One question we hear consistently from teams that already honor GPC: are we allowed to skip a cookie banner? The answer is that it depends: we don't recommend skipping it entirely, since it depends on the states you operate in and whether you process sensitive data that requires opt-in consent.
It's a genuinely good question to put to your counsel, because the answer changes your banner strategy, not just your legal posture.
What happens if you're not compliant?
Enforcement runs through state attorneys general, with civil penalties typically between $2,500 and $20,000 per violation depending on the state. California adds two things nobody else has among the comprehensive laws: a dedicated regulator (the CPPA) and a private right of action for data breaches, at $100 to $750 per consumer per incident. Illinois BIPA and Washington MHMDA go further, allowing consumers to sue directly for violations, which is why those statutes generate more lawsuits than others.
The AG letter is not the risk most mid-market companies actually meet first, though. The demand letter is. Plaintiff firms now run automated scans for tracking technologies that fire before consent is obtained, then mail settlement demands under wiretapping laws such as CIPA.

Our California Invasion of Privacy Act explainer covers that exposure in detail.
The practical takeaway: enforcement risk scales with how visibly your site mishandles consent, not with how big you are.
How to operationalize U.S. state compliance (without a team)
If you're selling across the continental U.S, you don't need a 50-state legal memo. You need a defensible baseline:
1. Know your states. Check your analytics against the "applies to you if" rows above. You're probably covered in more states than you think, and that's fine; the point is knowing which rules are yours.
2. Run one consent standard, geo-adjusted. Meet the strictest rules that apply to you (usually California plus the GPC states), relax where the law genuinely allows it, and let your CMP handle the geography.
3. Honor GPC. Twelve states require it and the list only grows.
4. Keep consent records. Logs, timestamps, versions. This is what turns 'we have a banner' into 'we can show what each visitor chose, and when.
5. Have a DSAR intake that isn't an inbox. A form, a deadline tracker, and a deletion checklist cover most of it at mid-market scale.
Enzuzo's consent management platform handles the first four out of the box, and teams typically go live in one to three days.
If you'd rather see it against your own site than read about it, book a call with a U.S. privacy law expert.
FAQs
What are some United States data protection laws I should know about?
Twenty states have comprehensive consumer privacy laws as of 2026, led by California's CCPA/CPRA. Federally, sectoral laws apply: HIPAA (health), GLBA (financial), COPPA (children). If you sell nationally, the practical short list is California, Texas, Colorado, Connecticut, Illinois BIPA if you touch biometrics, and whichever states hold most of your customers.
Is there a federal data privacy law in the U.S.?
No. Proposed federal bills (ADPPA, APRA) have not passed. The FTC enforces against deceptive data practices, but consumer privacy rights currently exist only at the state level.
Which states have data privacy laws in 2026?
California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island. Indiana, Kentucky, and Rhode Island took effect January 1, 2026. Oklahoma and Alabama have signed laws arriving in 2027, and Illinois, New York, and Washington regulate privacy through targeted statutes.
Can you get sued for a data breach?
Yes. California's CCPA gives consumers a private right of action for breaches ($100 to $750 per consumer per incident), Illinois BIPA and Washington MHMDA allow direct consumer suits for violations, and breach class actions are common nationwide under other theories. See our [data privacy lawsuits roundup](/blog/data-privacy-lawsuits) for real settlement figures.
If our site honours Global Privacy Control, do we still need a cookie banner?
Usually yes. GPC covers the opt-out signal, but opt-in requirements for sensitive data, consent records, and non-GPC visitors still need a consent mechanism. The exact answer depends on your states and data types; it's worth a specific conversation with counsel.
We don't sell to EU customers. Do U.S. state laws still require consent management?
Yes, if you meet any state's threshold. GDPR is irrelevant to this question; 20 U.S. states impose their own consent and opt-out duties, and 12 require honoring GPC signals regardless of where your company is based.
Which states require opt-in consent instead of opt-out?
For ordinary personal data, none; the U.S. model is opt-out. For sensitive data (health, biometrics, precise location, children's data), nearly every state requires opt-in consent. Utah and Iowa are the main exceptions (notice plus opt-out), and California uses a right-to-limit model instead. Illinois and Washington require opt-in consent for biometric and health data specifically.
Do small businesses face the same privacy-law risk as national brands?
Increasingly, yes. Thresholds have dropped to 35,000 consumers in several states, Texas and Nebraska have no threshold at all, and demand-letter firms scan small-business sites the same way they scan enterprise ones. What matters is whether your site fires trackers before consent is obtained; scanners check small sites as readily as large ones.
Mate Prgin
Mate is the CEO & Founder of Enzuzo. He has an executive MBA from Ivey Business School and is a subject matter expert in data privacy and compliance.