U.S. State Privacy Laws: 2026 Tracker and Compliance Guide
Mate Prgin
As of August 2026, 20 U.S. states have comprehensive consumer privacy laws in effect. Indiana, Kentucky, and Rhode Island joined on January 1, 2026, and Oklahoma and Alabama arrive in 2027. There is still no U.S federal data privacy law.
Each state law sets its own rules for who's covered, which rights consumers get, and when you need consent. Twelve U.S. states now require sites to honor Global Privacy Control (GPC) opt-out signals.
This tracker covers every U.S. state law, who it applies to, and what it means for your website.
First, the bad news: if you sell to customers in multiple states, you're subject to a messy patchwork of regulations that grows every year. No single law covers you entirely; you inherit whichever state laws your customers live under, each with its own thresholds and quirks.
The good news: these laws share most of their DNA. Get the common baseline right, handle the handful of stricter outliers, and multi-state compliance stops being a quarterly project.
Below you'll find every law with its key facts, then the practical part most legal trackers skip: what these laws require from your website.

At a glance: every state privacy law in 2026
According to MultiState's legislative tracking, 20 comprehensive U.S. state privacy laws are in effect as of August 2026, with two more signed and set to take effect in 2027.
| State | Law | In effect | GPC required |
|---|---|---|---|
| California | CCPA / CPRA | Jan 2020 / Jan 2023 | Yes |
| Virginia | VCDPA | Jan 2023 | No |
| Colorado | CPA | Jul 2023 | Yes |
| Connecticut | CTDPA | Jul 2023 | Yes |
| Utah | UCPA | Dec 2023 | No |
| Texas | TDPSA | Jul 2024 | Yes |
| Oregon | OCPA | Jul 2024 | Yes (Jan 2026) |
| Florida | FDBR | Jul 2024 | No |
| Montana | MCDPA | Oct 2024 | Yes |
| Delaware | DPDPA | Jan 2025 | Yes (Jan 2026) |
| Iowa | ICDPA | Jan 2025 | No |
| Nebraska | NDPA | Jan 2025 | Yes |
| New Hampshire | NHDPA | Jan 2025 | Yes |
| New Jersey | NJDPA | Jan 2025 | Yes |
| Tennessee | TIPA | Jul 2025 | No |
| Minnesota | MCDPA | Jul 2025 | Yes |
| Maryland | MODPA | Oct 2025 | Yes |
| Indiana | INCDPA | Jan 2026 | No |
| Kentucky | KCDPA | Jan 2026 | No |
| Rhode Island | RIDTPPA | Jan 2026 | No |
| Oklahoma | OCDPA | Jan 2027 (signed) | No |
| Alabama | APDPA | May 2027 (signed) | Yes |
Three more states regulate privacy without a comprehensive law, and two of them carry more litigation risk than the rest:
| State | Law | In effect | The short version |
|---|---|---|---|
| Illinois | BIPA | 2008 | Biometric data; private right of action with preset damages per violation |
| New York | SHIELD Act | 2020 | Data security and breach notification duties for anyone holding NY residents' data |
| Washington | My Health My Data Act | 2023 | Consumer health data; broad private right of action |
Is there a federal U.S. privacy law?
No. The American Data Privacy and Protection Act (ADPPA) and its successor, the American Privacy Rights Act, both stalled in Congress, and newer proposals like the SECURE Data Act haven't moved past committee either, with preemption of stronger state laws still the sticking point. What exists federally is sectoral: HIPAA for health data held by covered entities, GLBA for financial institutions, COPPA for children's data, and FTC enforcement against unfair or deceptive data practices.
According to the FTC's business guidance, the agency treats broken privacy promises as deceptive practices, which means your own privacy policy is enforceable against you even in states with no privacy law at all.
Until Congress acts, your obligations come from the state laws below.
California Consumer Privacy Act (CCPA / CPRA)
The California Consumer Privacy Act (CCPA) is California's comprehensive privacy law, in effect since 2020. A comprehensive law covers personal data across industries, where a sector law such as BIPA covers one kind of data. The California Privacy Rights Act (CPRA) amended the CCPA rather than creating a second law. Its changes took effect in 2023, so both names refer to one statute.
California's law covers employee and business-to-business data, which Virginia's excludes. It also has a dedicated regulator, the California Privacy Protection Agency, which writes detailed regulations and enforces the law alongside the attorney general.
If you sell or share personal information, your site needs a Do Not Sell or Share link. California's regulations also allow a single alternative opt-out link instead. Sharing includes third-party ad cookies and pixels used for cross-site advertising, even when no money changes hands.
California requires you to treat a Global Privacy Control (GPC) signal as a valid opt-out request. GPC is an opt-out a visitor's browser sends on their behalf. Since January 2026, you have to show visitors whether you honored their signal. A cookie banner on its own doesn't count as an opt-out method.
California gives consumers a right to limit how you use their sensitive data instead of requiring opt-in consent up front. Virginia, Colorado, and Connecticut require opt-in, so a California-only consent setup won't cover them. California does require opt-in before you sell or share personal information of a consumer you know is under 16. A parent gives it for under-13s.
California's largest CCPA penalty so far is the $12.75 million General Motors agreed to pay in May 2026 for selling drivers' location and driving data. Other recent fines, including Todd Snyder's and Ford's, targeted opt-out processes that demanded verification or extra personal details before honoring a request.
| Feature | CCPA / CPRA |
|---|---|
| In effect | CCPA Jan 1, 2020; CPRA amendments Jan 1, 2023 |
| Applies to you if | You're a for-profit business doing business in California and meet any one of three tests: more than $26,625,000 in annual gross revenue in the prior year (inflation-adjusted Jan 1, 2025); buying, selling, or sharing personal information of 100,000+ California consumers or households a year; or earning 50% or more of revenue from selling or sharing personal information. Nonprofits aren't covered. |
| Sensitive data | Government ID numbers, account logins with credentials, precise geolocation (1,850 feet), racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, union membership, contents of mail, email, and texts, genetic and neural data, biometric data used to identify someone, health data, and sex life or sexual orientation. Consumers can limit its use (an opt-out right, not opt-in). |
| Opt-out signals (GPC) | Yes. Required, first enforced against Sephora in 2022. Since Jan 1, 2026 you must display whether you honored the signal. |
| Consumer rights | Know, access (in a portable format), delete, correct, opt out of sale or sharing, limit use of sensitive data, and no retaliation. Responses within 45 days. |
| Risk assessments | Required before selling or sharing personal information, processing sensitive data, or using automated decision-making for significant decisions (2026 regulations). |
| Who enforces | The California Privacy Protection Agency (administrative fines) and the attorney general (civil penalties). Consumers can sue only over data breaches. |
| Fines | Up to $2,663 per violation, or $7,988 per intentional violation or violation involving a known under-16 (inflation-adjusted Jan 1, 2025). Breach suits: $107 to $799 per consumer per incident, or actual damages. |
| Cure period | None for regulator actions since Jan 1, 2023, though the agency may allow one. Breach suits keep a 30-day notice-and-cure before statutory damages. |
| Recent changes | Regulations effective Jan 1, 2026 added risk assessments, cybersecurity audits, and automated decision-making rules. Neural data became sensitive data on Jan 1, 2025. |
| Coming up | Jan 1, 2027: automated decision-making rules apply, browsers must offer an opt-out signal, and dollar amounts adjust for inflation. Dec 31, 2027: risk assessments due for processing that began before 2026. Apr 1, 2028: first risk-assessment attestations and cybersecurity audit reports. |
California's required notices and enforcement record get fuller treatment in the CCPA guide.
Virginia Consumer Data Protection Act (VCDPA)
Virginia's comprehensive privacy law, the Virginia Consumer Data Protection Act (VCDPA), took effect on January 1, 2023. It gives residents opt-out rights for ordinary personal data, requires opt-in consent for sensitive data, and leaves enforcement to the attorney general alone. Many later state privacy laws copy Virginia's structure, so it's the usual baseline for comparing them.
Virginia still gives you a chance to fix a violation after the attorney general's notice (a cure period), and that right never expires. The mandatory cure periods in Colorado and Connecticut have ended. Virginia also doesn't require you to honor Global Privacy Control signals. Its definition of a sale covers only exchanges for money, where Colorado and Connecticut also count trades for anything of value.
Give Virginia residents a way to opt out of targeted advertising and sales. Get opt-in consent before you process sensitive data such as a health diagnosis, precise location, or a known child's data. Since July 1, 2026, Virginia has banned selling precise geolocation data, even with consent.
Since January 1, 2025, Virginia has required parental consent before you sell a known child's data. The same goes for using it for targeted ads or for profiling that shapes significant decisions about them. Parents give that consent through COPPA, the federal children's privacy law.
A federal court preliminarily blocked Virginia's one-hour daily limit for under-16s on each social media service in NetChoice v. Jones in February 2026. The limit, which applied unless a parent agreed otherwise, took effect that January, and Virginia has appealed.
| Feature | VCDPA |
|---|---|
| In effect | Jan 1, 2023 |
| Applies to you if | You do business in Virginia or target Virginia residents and process personal data of 100,000+ Virginia consumers in a calendar year, or 25,000+ consumers while earning more than 50% of gross revenue from selling personal data. No revenue threshold, and employee and B2B data don't count. Nonprofits, colleges, and HIPAA- and GLBA-covered entities are exempt. |
| Sensitive data | Racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data used to identify someone, a known child's data, and precise geolocation (1,750 feet). Opt-in consent required. |
| Opt-out signals (GPC) | No. Not required. |
| Consumer rights | Confirm and access, correct, delete, portability, opt out of targeted ads, sale, and profiling for significant decisions, and appeal a refusal. Responses within 45 days. |
| Risk assessments | Required for targeted advertising, sale, sensitive data, risky profiling, other heightened-risk processing, and services directed to known children. They stay confidential, but the attorney general can demand them. |
| Who enforces | The attorney general only. Consumers can't sue, and there's been no public enforcement action as of Sep 2026. |
| Fines | Up to $7,500 per violation, plus investigation costs and attorney fees |
| Cure period | 30 days after the attorney general's notice. Mandatory, and it never expires. |
| Recent changes | Jan 1, 2025: known-child rules. Jan 1, 2026: social media limits for under-16s (blocked Feb 27, 2026; appeal pending). Jul 1, 2026: ban on selling precise geolocation data. |
| Coming up | A Fourth Circuit ruling on the social media injunction (date unknown). |
Read our VCDPA guide for the exemptions and a side-by-side with California.
Colorado Privacy Act (CPA)
The Colorado Privacy Act (CPA), in effect since July 1, 2023, is a comprehensive privacy law built on Virginia's structure but with a wider reach. Colorado covers nonprofits, which Virginia exempts. Its 25,000-consumer threshold applies when a business gets any revenue or discount from selling data, where Virginia's requires more than half of gross revenue. Colorado also requires businesses to honor Global Privacy Control signals.
If you sell data or run targeted ads, treat a GPC signal from a Colorado visitor as an opt-out of both. Once someone opts out, the attorney general's CPA rules bar you from using screen-dominating banners, repeated prompts, or cookie walls (overlays that block the site until the visitor accepts) to win them back. Accept and reject choices have to be equally easy to find.
Get opt-in consent before you process or sell sensitive data in Colorado. Inferred traits count too, such as browsing data that suggests someone's sexual orientation. If a person hasn't interacted with you in 24 months, ask for that consent again.
Colorado's biometric and minors' rules apply at any business size, even below the CPA's thresholds. If you process biometric data, you need a public retention policy, plus notice and consent before collection, and you can't sell biometric identifiers.
If you know, or willfully ignore, that a user is under 18, get consent before targeted ads or selling their data. The same applies to design features that keep them online longer.
Colorado joined California and Connecticut in a joint sweep, announced in September 2025, that sent letters to businesses whose sites didn't appear to honor GPC. Colorado hasn't announced a CPA penalty.
| Feature | CPA |
|---|---|
| In effect | Jul 1, 2023 |
| Applies to you if | You do business in Colorado or target Colorado residents and process personal data of 100,000+ Colorado consumers in a calendar year, or 25,000+ consumers while getting any revenue or discount from selling personal data. No revenue threshold. Any business that processes biometric data (biometric rules) or knows or willfully disregards that it's dealing with minors (minors' rules) is covered at any size. Nonprofits are covered, and HIPAA-covered entities are exempt only for HIPAA-protected data. |
| Sensitive data | Racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, sex life or sexual orientation, citizenship status, genetic or biometric data used to identify someone, a known child's data, biological and neural data, and precise geolocation (1,850 feet). Inferences that reveal these count too. Opt-in consent to process or sell. |
| Opt-out signals (GPC) | Yes. Required since Jul 1, 2024, and GPC is the only signal on the attorney general's approved list. |
| Consumer rights | Opt out of targeted ads, sale, and profiling for significant decisions; confirm and access, correct, delete, portability (twice a year), and appeal. Responses within 45 days. |
| Risk assessments | Required before targeted advertising, sale, sensitive data, and risky profiling, and for online services with a heightened risk of harm to minors (at any size). Produce them to the attorney general within 30 days of a request. |
| Who enforces | The attorney general and district attorneys. Consumers can't sue. |
| Fines | Up to $20,000 per violation, counted separately for each consumer or transaction, and up to $50,000 per violation against an elderly person. No overall cap since HB 19-1289 removed it in 2019. |
| Cure period | The general cure ended Jan 1, 2025. A 60-day cure still covers the minors' rules until Dec 31, 2026. |
| Recent changes | Aug 7, 2024: biological and neural data added. May 23, 2025 (SB 25-276): precise geolocation became sensitive data, and selling sensitive data needs consent. Jul 1, 2025: biometric rules at any size. Oct 1, 2025: minors' rules at any size. Aug 12, 2026: a CPA advisory council created. |
| Coming up | Dec 31, 2026: the 60-day cure for the minors' rules ends. Jan 1, 2027: Colorado's separate automated decision-making law (SB 26-189) takes effect. |
Colorado's attorney general also issues opinion letters on request: written answers a business can rely on in good faith. The Colorado guide explains how they work.
Connecticut Data Privacy Act (CTDPA)
Since July 1, 2023, the Connecticut Data Privacy Act (CTDPA) has been Connecticut's comprehensive privacy law. Amendments in Public Act 25-113 took effect July 1, 2026. They extended it to any business that sells personal data or processes sensitive data, whatever its size, and lowered the consumer count for everyone else. Virginia, by contrast, doesn't cover a business below its consumer thresholds, however much it earns from selling data.
Connecticut requires a clear opt-out link on your site and support for opt-out preference signals such as Global Privacy Control. You need the person's opt-in consent before processing their sensitive data. For known minors aged 13 to 17, Connecticut bans targeted ads and data sales, even with consent.
Connecticut's attorney general expects any banner with an accept-all button to give reject all the same prominence (2025 enforcement report). In the attorney general's view, a GPC signal should opt someone out across all their personal data, not only cookie data. Connecticut's first CTDPA settlement, $85,000 from TicketNetwork in July 2025, followed findings that its privacy notice was largely unreadable and its rights tools didn't work.
| Feature | CTDPA |
|---|---|
| In effect | Jul 1, 2023; major amendments Jul 1, 2026 |
| Applies to you if | You do business in or target Connecticut and processed personal data of 35,000+ Connecticut consumers in the prior calendar year (payment-only processing excluded); OR you process sensitive data at any volume; OR you sell personal data at any volume. Employee and B2B data don't count. Nonprofits, colleges, HIPAA-covered entities, insurers, and qualifying banks and credit unions are exempt, except from the consumer health data rules, which apply to everyone (including a ban on geofencing within 1,750 feet of mental, reproductive, or sexual health facilities to track visitors or send them health-related messages). |
| Sensitive data | Racial or ethnic origin, religious beliefs, mental or physical health condition, diagnosis, disability, or treatment, sex life, sexual orientation, nonbinary or transgender status, citizenship or immigration status, consumer health data, genetic or biometric data, a child's data (actual knowledge or wilful disregard of age), crime-victim status, precise geolocation (1,750 feet), neural data, financial account logins, and government ID numbers. Opt-in consent to process, and consent to sell. |
| Opt-out signals (GPC) | Yes. Required since Jan 1, 2025. |
| Consumer rights | Confirm and access (including inferences), correct, delete, portability, opt out of targeted ads, sale, and profiling for significant automated decisions, question a profiling-based decision, get a list of the third parties your data was sold to, and appeal. Responses within 45 days. |
| Risk assessments | Required for targeted advertising, sale, sensitive data, and risky profiling. A separate impact assessment covers significant-decision profiling for processing from Aug 1, 2026. The attorney general can demand either. |
| Who enforces | The attorney general only, under the Connecticut Unfair Trade Practices Act. Consumers can't sue. |
| Fines | Up to $5,000 per willful violation, plus court orders to repay consumers, give up profits from the violation, or stop the practice |
| Cure period | No mandatory cure since Dec 31, 2024. The attorney general can still offer one. |
| Recent changes | Jul 1, 2026: 35,000 threshold, plus coverage for any business that sells personal data or processes sensitive data; ad and sale ban for known 13-to-17-year-olds; new rights; privacy notices must say whether data trains large language models; impact assessments for profiling used in significant decisions. |
| Coming up | Oct 1, 2026 (Public Act 26-64): ban on selling precise geolocation data, and the deletion right expands to public data compiled into profiles. Jan 1, 2027: data brokers must register with the state. |
The CTDPA guide breaks down the 2026 amendments and the attorney general's enforcement priorities.
Utah Consumer Privacy Act (UCPA)
Utah's comprehensive privacy law is the Utah Consumer Privacy Act (UCPA), in effect since December 31, 2023. Utah uses Virginia's consumer thresholds and adds a $25 million annual revenue test on top. A business has to meet both to be covered.
Utah skips several duties Virginia imposes: opt-in consent for sensitive data, data protection assessments, a profiling opt-out, and an appeal process for refused requests. The deletion right covers only data the consumer gave you, a limit Utah's attorney general says no other state's law has (2025 report).
If Utah's law covers you, offer opt-outs for targeted advertising and sales, and explain in your privacy notice how to use them. Before you process sensitive data, give clear notice and a chance to opt out; opt-in consent isn't required.
Utah's attorney general flags privacy policies that give rights to California residents but not to Utahns as apparent violations. If your notices and rights process were built for California, extend them to Utah residents.
In June 2025, Utah sued Snap under the UCPA and other laws. The state claims Snapchat didn't disclose that it shared My AI chat data with OpenAI and didn't offer an opt-out before collecting sensitive data.
| Feature | UCPA |
|---|---|
| In effect | Dec 31, 2023 |
| Applies to you if | You do business in Utah or target Utah residents, have $25 million or more in annual revenue, AND process personal data of 100,000+ Utah consumers in a calendar year, or 25,000+ consumers while earning more than 50% of gross revenue from selling personal data. Nonprofits, colleges, and HIPAA- and GLBA-covered entities are exempt. |
| Sensitive data | Racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, medical history, mental or physical health condition, treatment, or diagnosis, genetic or biometric data used to identify someone, and specific geolocation (1,750 feet). Notice and a chance to opt out before processing; no opt-in consent. A known child's data is handled under COPPA. |
| Opt-out signals (GPC) | No. Not required. |
| Consumer rights | Confirm and access, delete and port the data you provided, correct (since Jul 1, 2026), and opt out of targeted ads and sale. Responses within 45 days. No appeal right. |
| Risk assessments | Not required |
| Who enforces | The Division of Consumer Protection investigates and refers cases, and only the attorney general can sue. |
| Fines | Up to $7,500 per violation, plus actual damages to consumers |
| Cure period | 30 days after the attorney general's notice, with no sunset |
| Recent changes | Jul 1, 2026: right to correct inaccurate data (HB 418). |
| Coming up | Jan 1, 2027 (HB 357): the UCPA covers motor vehicle manufacturers at any size, with in-vehicle privacy controls for model year 2030 and later vehicles. |
If you're near the revenue line, the Utah guide shows how the two thresholds work together.
Texas Data Privacy and Security Act (TDPSA)
Texas skipped the consumer-count threshold entirely: if you do business in Texas and you're not an SBA-defined small business, you're covered, with no revenue floor.
Even exempt small businesses need consent before selling sensitive data. Texas's AG has run dedicated privacy sweeps since 2024, enforcement most states haven't attempted.
| Feature | TDPSA |
|---|---|
| In effect | Jul 1, 2024 |
| Applies to you if | You do business in Texas or serve Texas residents, process or sell personal data, and aren't an SBA-defined small business. No revenue or volume thresholds |
| Fines | Up to $7,500 per violation, plus injunctive relief |
| Cure period | 30 days, no sunset |
| Recognizes GPC | Yes (since Jan 2025) |
| Privacy impact assessments | Required for targeted advertising, data sales, profiling, sensitive data, and other heightened-risk processing |
| Sensitive data | Race or ethnicity, religion, health diagnosis, sexuality, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation |
| Consumer rights | Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, object to automated decision-making |
Oregon Consumer Privacy Act (OCPA)
Oregon follows the standard model with one right no other state started with: consumers can request the specific third parties that received their data, not just the categories. Its GPC requirement kicked in January 2026, the same month its cure period expired. A 2026 amendment also banned the sale of data from users known to be under 16, and the law uniquely covers motor vehicle manufacturers that process vehicle data, regardless of thresholds.
| Feature | OCPA |
|---|---|
| In effect | Jul 1, 2024 |
| Applies to you if | You control/process personal data of 100K+ OR residents; OR 25K+ residents with 25%+ of revenue from selling personal data; OR you're a vehicle manufacturer processing data from vehicle use |
| Fines | Up to $7,500 per violation |
| Cure period | None (sunset Jan 2026) |
| Recognizes GPC | Yes (since Jan 1, 2026) |
| Privacy impact assessments | Required for targeted advertising, data sales, profiling, sensitive data, and other heightened-risk processing |
| Sensitive data | Race, ethnicity, or national origin, religion, health condition or diagnosis, sexual orientation, transgender or nonbinary status, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation, crime-victim status |
| Consumer rights | Know/confirm, access, list of specific third parties who received your data, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, object to automated decision-making |
Florida Digital Bill of Rights (FDBR)
Florida is the asterisk in every state count. The FDBR's full controller obligations only apply to for-profit companies with over $1 billion in global revenue that also meet one of three tech-platform criteria: 50%+ of revenue from online ads, an app store with 250,000+ apps, or a consumer smart-speaker service. That's why most trackers count '19 plus Florida. '
Two parts do reach smaller companies: rules on selling sensitive data and children's data protections.
| Feature | FDBR |
|---|---|
| In effect | Jul 1, 2024 |
| Applies to you if | Full obligations: for-profit, doing business in Florida, $1B+ global revenue, AND one of: 50%+ of revenue from online ads; an app store with 250K+ apps; or a consumer smart-speaker and voice assistant service (in-car systems excluded). Sensitive-data sale rules: ANY for-profit entity doing business in Florida |
| Fines | Up to $50,000 per violation; up to $150,000 (tripled) when a known child's data is involved |
| Cure period | 45 days (discretionary; not available for children's-data violations) |
| Recognizes GPC | No (statute is silent on universal opt-out signals) |
| Privacy impact assessments | Required for targeted advertising, data sales, risky profiling, sensitive data, and other heightened-risk processing |
| Sensitive data | Race or ethnicity, religion, health diagnosis, sexual orientation, citizenship or immigration status, genetic and biometric data, precise geolocation, and all personal data of a known child under 18 |
| Consumer rights | Know/confirm, access, correct, delete, portability, opt out of sale, targeted advertising, and significant profiling, opt out of sensitive-data collection, opt out of voice and facial recognition collection on smart devices (unique to Florida), search-engine ranking transparency (unique to Florida) |
Montana Consumer Data Privacy Act (MCDPA)
Montana fit the standard model to a small population, and 2025 amendments cut the thresholds deeper: 25,000 residents, down from 50,000, or just 15,000 if a quarter of your revenue comes from data sales. Its cure period sunset in April 2026.
Duty-of-care rules for minors reach every business serving Montanans, regardless of size.
| Feature | MCDPA (Montana) |
|---|---|
| In effect | Oct 1, 2024 |
| Applies to you if | You control/process personal data of 25K+ MT residents; OR 15K+ residents with 25%+ of revenue from selling personal data. Minor duty-of-care rules apply regardless of thresholds |
| Fines | Up to $7,500 per violation |
| Cure period | None (60-day period sunset Apr 2026) |
| Recognizes GPC | Yes |
| Privacy impact assessments | Required for targeted advertising, data sales, profiling, sensitive data, and other heightened-risk processing |
| Sensitive data | Race or ethnicity, religion, health condition or diagnosis, sex life, sexual orientation, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation |
| Consumer rights | Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, object to automated decision-making |
Delaware Personal Data Privacy Act (DPDPA)
Delaware runs the standard model at one of the lowest thresholds in the country: 35,000 consumers, or just 10,000 if a fifth of your revenue comes from data sales. Its GPC requirement and cure-period sunset both landed January 2026.
Enforcement discretion rests with the state Department of Justice, and, as in Oregon, consumers can demand the specific third parties that obtained their data.
| Feature | DPDPA |
|---|---|
| In effect | Jan 1, 2025 |
| Applies to you if | You do business in or target Delaware and control/process personal data of 35K+ consumers (payment-only processing excluded); OR 10K+ consumers with 20%+ of revenue from selling personal data |
| Fines | Up to $10,000 per violation, at DOJ discretion |
| Cure period | None (60-day period sunset Jan 2026) |
| Recognizes GPC | Yes (since Jan 1, 2026) |
| Privacy impact assessments | Required for targeted advertising, data sales, sensitive data, and profiling that risks deceptive treatment, injury, or intrusion on solitude |
| Sensitive data | Race, ethnicity, or national origin, religion, health condition or diagnosis, sex life, sexual orientation, transgender or nonbinary status, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation |
| Consumer rights | Know/confirm, access, list of specific third parties who received your data, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, object to automated decision-making |
Iowa Consumer Data Protection Act (ICDPA)
Iowa sits with Utah at the lenient end: sensitive data requires only notice and an opt-out, there's no GPC duty, no impact assessments, no correction right, and the 90-day cure period is the longest anywhere.
Treat it as covered by your Virginia-model baseline.
| Feature | ICDPA |
|---|---|
| In effect | Jan 1, 2025 |
| Applies to you if | You control/process personal data of 100K+ IA consumers; OR 25K+ consumers with 50%+ of revenue from selling personal data |
| Fines | $7,500 per violation |
| Cure period | 90 days |
| Recognizes GPC | No |
| Privacy impact assessments | Not addressed by the law |
| Sensitive data | Race, ethnicity, or national origin, religion, health diagnosis, sexual orientation, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation |
| Consumer rights | Know/confirm, access, delete, portability, opt out of sale and targeted advertising, opt out or limit sensitive data processing. No correction right |
Nebraska Data Privacy Act (NDPA)
Nebraska copied the Texas playbook: no consumer-count or revenue threshold, an SBA small-business carve-out, and GPC recognition from day one. If you do business in Nebraska at any real scale, assume you're covered.
The 30-day cure period doesn't sunset.
| Feature | NDPA |
|---|---|
| In effect | Jan 1, 2025 |
| Applies to you if | You do business in Nebraska or serve Nebraska residents, process or sell personal data, and aren't an SBA-defined small business. No thresholds |
| Fines | $7,500 per violation |
| Cure period | 30 days, no sunset |
| Recognizes GPC | Yes |
| Privacy impact assessments | Required for targeted advertising, data sales, sensitive data, and profiling that risks deceptive treatment, injury, or intrusion on solitude |
| Sensitive data | Race or ethnicity, religion, health diagnosis, sexual orientation, citizenship or immigration status, genetic and biometric data processed to identify a person, data of a known child, precise geolocation |
| Consumer rights | Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling with significant effects |
New Hampshire Data Privacy Act (NHDPA)
New Hampshire pairs low thresholds (35,000 consumers) with the same enforcement route Connecticut and New Jersey use: privacy violations count as deceptive trade practices, with penalties up to $10,000 per violation. The cure period sunset in January 2026.
| Feature | NHDPA |
|---|---|
| In effect | Jan 1, 2025 |
| Applies to you if | You do business in or target New Hampshire and control/process personal data of 35K+ unique consumers (payment-only processing excluded); OR 10K+ consumers with 25%+ of revenue from selling personal data |
| Fines | Up to $10,000 per violation, via the deceptive trade practices law |
| Cure period | None (sunset Jan 2026) |
| Recognizes GPC | Yes |
| Privacy impact assessments | Required for any processing with heightened risk of harm: targeted advertising, data sales, certain profiling, sensitive data |
| Sensitive data | Race or ethnicity, religion, health condition or diagnosis, sex life, sexual orientation, citizenship or immigration status, genetic and biometric data processed to identify a person, data of a known child, precise geolocation |
| Consumer rights | Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling with legal or similarly significant effects |
New Jersey Data Privacy Act (NJDPA)
New Jersey extends the standard model in two ways that trip up companies compliant elsewhere.
Financial information counts as sensitive data; a broader trigger than any other state's (Connecticut's stops at account and card numbers with access credentials). And penalties escalate: violations route through the Consumer Fraud Act at up to $10,000 for a first offense and $20,000 after that.
Its cure period sunset on July 15, 2026, so as of writing there's no grace window.
| Feature | NJDPA |
|---|---|
| In effect | Jan 15, 2025 |
| Applies to you if | You control/process personal data of 100K+ NJ consumers (payment-only processing excluded); OR 25K+ consumers with revenue or price discounts derived from selling personal data |
| Fines | Up to $10,000 first violation, up to $20,000 for subsequent violations (via Consumer Fraud Act) |
| Cure period | None (sunset Jul 15, 2026) |
| Recognizes GPC | Yes |
| Privacy impact assessments | Required for targeted advertising, data sales, sensitive data, and profiling with reasonably foreseeable risk of deceptive treatment, disparate impact, injury, or intrusion |
| Sensitive data | Race or ethnicity, religion, health condition, treatment, or diagnosis, sex life, sexual orientation, transgender or nonbinary status, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation, financial information |
| Consumer rights | Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, opt out of automated decision-making |
Tennessee Information Protection Act (TIPA)
Tennessee is the only state with a built-in affirmative defense: a written privacy program that reasonably conforms to the NIST Privacy Framework (or a comparable standard) shields you from liability.
Two conditions: the program stays updated within two years of framework revisions, and consumers still get every right the law grants them.
| Feature | TIPA |
|---|---|
| In effect | Jul 1, 2025 |
| Applies to you if | You have $25M+ annual revenue AND control/process personal information of 175K+ TN consumers; OR 25K+ consumers with 50%+ of revenue from selling personal information |
| Fines | Up to $7,500 per violation, trebled if willful |
| Cure period | 60 days |
| Recognizes GPC | No |
| Privacy impact assessments | Required for targeted advertising, data sales, sensitive data, profiling, and other heightened-risk processing |
| Sensitive data | Race, ethnicity, or national origin, religion, health condition or diagnosis, sexual orientation, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation |
| Consumer rights | Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, object to automated decision-making |
Minnesota Consumer Data Privacy Act (MCDPA)
Minnesota adds a right no other state has: consumers can question the result of profiling and get an explanation of why an automated decision came out the way it did. It also requires a documented privacy program the AG can inspect, plus a third-party disclosure list on request. The cure period sunset January 31, 2026.
| Feature | MCDPA (Minnesota) |
|---|---|
| In effect | Jul 31, 2025 |
| Applies to you if | You target Minnesotans and control/process personal data of 100K+ consumers; OR 25K+ consumers with 25%+ of revenue from selling personal data |
| Fines | $7,500 per violation |
| Cure period | None (sunset Jan 31, 2026) |
| Recognizes GPC | Yes |
| Privacy impact assessments | Required for targeted advertising, data sales, sensitive data, heightened-risk processing, and profiling that risks unfair treatment or injury; AG may review assessments |
| Sensitive data | Race or ethnicity, religion, health diagnosis, sexual orientation, citizenship or immigration status, genetic and biometric data, data of a known child, specific geolocation |
| Consumer rights | Know/confirm, access, list of third parties, correct, delete, portability, opt out of sale and targeted advertising, question the result of profiling, non-discrimination, appeal |
Maryland Online Data Privacy Act (MODPA)
The Maryland Online Data Privacy Act (MODPA) is Maryland's comprehensive privacy law, in effect since October 1, 2025. Unlike Virginia and Connecticut, which limit data collection to the purposes you've disclosed to consumers, Maryland limits it to what's reasonably necessary for the specific product or service the consumer asked for.
Maryland lets you collect or process sensitive data only when it's strictly necessary for something the consumer requested. It bans selling sensitive data, even with consent. Connecticut lets you process and sell most sensitive data with the person's opt-in consent. If you know or should know a consumer is under 18, you can't target them with ads or sell their data.
Maryland consumers must be able to opt out of targeted advertising, sales, and significant decisions about them made by automated profiling alone. You don't have to verify identity before honoring an opt-out, and you can't require an account to use one.
Don't draw a geofence, a virtual boundary around a location, within 1,750 feet of a mental, reproductive, or sexual health facility. Maryland's ban covers using one to track people, collect their data, or message them about their health.
Since July 1, 2026, Maryland's HB 711 amendment counts anything you infer about someone's sensitive traits as sensitive data. The strictly-necessary rule and the sale ban now cover those inferences too.
| Feature | MODPA |
|---|---|
| In effect | Oct 1, 2025; HB 711 amendments Jul 1, 2026 |
| Applies to you if | You do business in Maryland or target Maryland residents and, in the prior calendar year, processed personal data of 35,000+ Maryland consumers (payment-only processing excluded), or 10,000+ consumers while earning more than 20% of gross revenue from selling personal data. Nonprofits, colleges, and HIPAA-covered entities aren't exempt as organizations; only HIPAA-protected health data is. |
| Sensitive data | Racial or ethnic origin, religious beliefs, consumer health data, sex life, sexual orientation, transgender or nonbinary status, national origin, citizenship or immigration status, genetic or biometric data, a child's data (under 13), precise geolocation of a person, device, or vehicle (1,750 feet), and, since Jul 1, 2026, inferences that indicate any of these. Only when strictly necessary, and never for sale. |
| Opt-out signals (GPC) | Yes. The statute lists opt-out preference signals as one way consumers can opt out, and a business that honors signals other states approve is treated as meeting Maryland's signal requirement. |
| Consumer rights | Confirm and access, correct, delete, portability, get a list of the categories of third parties your data went to, and opt out of targeted ads, sale, and solely automated profiling with significant effects. Responses within 45 days; appeals answered within 60. |
| Risk assessments | Required on a regular basis for targeted advertising, sale, sensitive data, and risky profiling, including one for each algorithm used. The attorney general's Consumer Protection Division can demand them. |
| Who enforces | The attorney general's Consumer Protection Division. Consumers can't sue under MODPA, and there's been no public enforcement action as of Sep 2026. |
| Fines | Up to $10,000 per violation; up to $25,000 for each repeat of the same violation |
| Cure period | Discretionary. If the attorney general offers one, you get at least 60 days. Ends for violations after Apr 1, 2027. |
| Recent changes | HB 711 (Jul 1, 2026): inferred sensitive data, device and vehicle location added to precise geolocation, and a ban on knowingly selling data to government units that took part in civil immigration enforcement in the prior six months. |
| Coming up | Apr 1, 2027: the discretionary cure ends. |
Before you set up opt-outs for Maryland, check how the collection limit applies to your data in the Maryland guide.
Indiana Consumer Data Protection Act (INCDPA)
Indiana went live January 1, 2026 as a faithful copy of the Virginia model: same thresholds, same opt-in rule for sensitive data, same AG-only enforcement, same permanent 30-day cure period. That makes it one of the gentler laws in the 2026 wave.
| Feature | INCDPA |
|---|---|
| In effect | Jan 1, 2026 |
| Applies to you if | You operate in or target Indiana and control/process personal information of 100K+ residents; OR 25K+ residents with 50%+ of revenue from selling that data |
| Fines | $7,500 per violation |
| Cure period | 30 days, no sunset |
| Recognizes GPC | No |
| Privacy impact assessments | Required for targeted advertising, data sales, sensitive data, risky profiling, and other heightened-risk processing |
| Sensitive data | Race, ethnicity, or national origin, religion, health diagnosis made by a healthcare provider, sexual orientation, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation |
| Consumer rights | Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, object to automated decision-making |
Kentucky Consumer Data Protection Act (KCDPA)
Kentucky also launched January 1, 2026 on the Virginia template, with pre-effective-date amendments (HB 473, March 2025) that widened healthcare exemptions: data held by HIPAA-covered providers and HIPAA limited data sets sit outside the law entirely. The same amendments narrowed the impact-assessment trigger for profiling to risks of unlawful disparate impact.
| Feature | KCDPA |
|---|---|
| In effect | Jan 1, 2026 (PIA requirement from Jun 1, 2026) |
| Applies to you if | You do business in or target Kentucky and control/process data of 100K+ consumers; OR 25K+ consumers with 50%+ of revenue from selling personal data |
| Fines | $7,500 per violation |
| Cure period | 30 days, no sunset |
| Recognizes GPC | No |
| Privacy impact assessments | Required (from Jun 1, 2026) for targeted advertising, data sales, risky profiling, sensitive data, and heightened-risk processing |
| Sensitive data | Race or ethnicity, religion, health diagnosis, sexual orientation, citizenship or immigration status, genetic and biometric data processed to identify a person, data of a known child, precise geolocation |
| Consumer rights | Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, object to automated decision-making |
Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
Rhode Island is small-state, sharp-edges: a 35,000-consumer threshold, no cure period at all, penalties to $10,000 per violation, plus $100 to $500 per intentional disclosure of personal information. It launched January 1, 2026 with the least forgiving enforcement posture of the new wave.
| Feature | RIDTPPA |
|---|---|
| In effect | Jan 1, 2026 |
| Applies to you if | You're a for-profit entity doing business in or targeting Rhode Island and control/process personal data of 35K+ residents; OR 10K+ residents with 20%+ of revenue from selling that data |
| Fines | $10,000 per violation, plus $100 to $500 per intentional disclosure |
| Cure period | None |
| Recognizes GPC | No |
| Privacy impact assessments | Required before targeted advertising, data sales, risky profiling, and sensitive data processing |
| Sensitive data | Race or ethnicity, religion, health condition or diagnosis, sex life, sexual orientation, citizenship or immigration status, genetic and biometric data processed to identify a person, data of a known child, precise geolocation |
| Consumer rights | Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling with legal or similarly significant effects |
Illinois Biometric Information Privacy Act (BIPA)
Illinois's Biometric Information Privacy Act (BIPA) is a 2008 law that protects biometric data. It requires any private company to get a signed release (written consent) before collecting someone's biometric identifiers, such as a fingerprint or face scan. Unlike comprehensive state privacy laws, which state officials mainly enforce, BIPA is enforced by the people it protects: anyone whose biometric data is mishandled can sue.
BIPA reaches your website or app when a feature scans faces or voices, such as photo tagging, filters, virtual try-on, selfie ID checks, or voice login. Cookies and tracking pixels fall outside BIPA. Before that feature runs on someone, tell them in writing what you collect, why, and how long you'll keep it, then get their signed release. An electronic signature has counted since August 2024.
Even with consent, you need a public retention policy. The policy has to commit you to destroying the data once its purpose is met. The outside limit is three years after the person's last interaction. You also can't sell or otherwise profit from biometric data at all.
BIPA's largest settlements have come from face scanning: Facebook paid $650 million in 2021 to settle claims over its photo tag suggestions.
Public Act 103-0769, a 2024 amendment, treats repeated collection of the same identifier from the same person by the same method as one violation. Before, each scan could count separately. In April 2026 the federal appeals court covering Illinois (the Seventh Circuit) applied that limit to cases already pending in Clay v. Union Pacific, though the Illinois Supreme Court hasn't ruled on the question.
| Feature | BIPA |
|---|---|
| In effect | Oct 3, 2008 |
| Covers | Biometric identifiers (fingerprints, voiceprints, retina or iris scans, scans of hand or face geometry) and information based on them. Photos, signatures, and DNA aren't on the list. |
| Applies to you if | You're a private entity (any company or individual) that collects, buys, receives, or holds biometric data. No thresholds, and the statute has no residency test. Government bodies, Illinois courts, and financial institutions covered by the Gramm-Leach-Bliley Act are excluded. |
| Consent required | Written notice of what you collect, why, and for how long, plus a signed written release before collection. You also need consent before you disclose it, unless a listed exception applies (a requested financial transaction, a legal requirement, or a warrant or subpoena). |
| Consumer rights | None in the statute. BIPA sets business duties instead: notice and release, a public retention policy, a destruction schedule, and no selling. |
| Who can sue | Anyone aggrieved by a violation, employees included. There's no attorney general role. |
| Damages | $1,000 per negligent violation or $5,000 per intentional or reckless violation (or actual damages if higher), plus attorneys' fees. Courts have discretion over the total. Claims can be filed within five years (Tims v. Black Horse Carriers, 2023). |
| Cure period | None |
| Recent changes | Public Act 103-0769 (Aug 2, 2024): repeated collection, or repeated disclosure to the same recipient, of the same identifier by the same method counts as one violation, and e-signatures count as a written release. The Seventh Circuit applied it to pending federal cases (Apr 1, 2026). |
| Coming up | No enacted changes scheduled. Bills to make the 2024 amendment explicitly retroactive, add a security exception, and cover neural data are stalled in committee. |
Every major BIPA settlement, with amounts and dates, is in our full BIPA guide.
New York SHIELD Act
New York also lacks a comprehensive consumer privacy law, but the SHIELD Act (2020) reaches almost everyone anyway. Any business holding the private information of New York residents must maintain reasonable data security safeguards and report breaches, regardless of where the business sits.
It grants no consumer rights and needs no consent banner; it's a security-and-breach law, enforced by the Attorney General with no private right of action.
Treat it as the floor for your security program, and watch this space: New York's comprehensive privacy bills keep advancing each session without passing.
| Feature | SHIELD Act |
|---|---|
| In effect | Mar 2020 (security requirements) |
| Applies to you if | You own or license computerized private information of any New York resident, wherever your business is located. Reduced obligations for small businesses |
| Fines | Up to $5,000 per violation for failing reasonable safeguards; breach-notification failures at $20 per failed notice (up to $5,000 each if knowing or reckless), capped at $250,000 total |
| Cure period | None |
| Recognizes GPC | Not applicable |
| Privacy impact assessments | Not required; a documented data security program is |
| Sensitive data | "Private information": SSNs, driver's license numbers, financial account and card data with credentials, biometric data, username or email plus password |
| Consumer rights | Breach notification. No access, deletion, or opt-out rights |
Washington My Health My Data Act (MHMDA)
Washington's My Health My Data Act (MHMDA), passed in 2023, protects consumer health data that HIPAA, the federal health privacy law, doesn't cover. It reaches health inferences drawn from data such as purchases or location. People injured by an MHMDA violation can sue, because the act makes each violation a violation of Washington's Consumer Protection Act. Most state privacy laws leave enforcement to state officials.
MHMDA applies to businesses and nonprofits of any size, and it counts cookie IDs and IP addresses as personal information.
If your site or app handles anything that could count as health data, publish a separate consumer health data privacy policy. Link it from every page that collects personal information.
Get consent before you collect that data, and a second, separate consent before you share it. Neither is needed when the use is necessary for something the person asked for. Selling it takes a signed authorization with nine required elements. Accepting general terms of use, closing a pop-up, or clicking through a misleading design doesn't count as consent under MHMDA.
Early private MHMDA lawsuits have targeted tracking technology. The first was an SDK case against Amazon over location data its ad software collected inside third-party apps. Another was a pixel case against a Seattle cannabis retailer. No court has yet ruled on whether a pixel collects consumer health data.
| Feature | MHMDA |
|---|---|
| In effect | Jul 23, 2023 (the act and its geofencing ban); Mar 31, 2024 for most obligations; Jun 30, 2024 for small businesses |
| Covers | Consumer health data: health conditions, treatment, reproductive and gender-affirming care, biometric and genetic data, precise location that could show someone seeking care, and health information inferred from non-health data |
| Applies to you if | You do business in Washington or target Washington consumers, and you decide how consumer health data is collected or used. No size threshold, and nonprofits are covered. The sale and geofencing rules apply to any person. |
| Consent required | Consent to collect and a separate consent to share, unless either is needed to provide what the consumer asked for. A signed authorization to sell. No geofencing within 2,000 feet of an in-person health care facility to track visitors, collect their health data, or send them health-related ads. |
| Consumer rights | Confirm and access your data (including a list of every third party that received it), delete it (backups included), and withdraw consent. Businesses respond within 45 days and must offer an appeal. |
| Who can sue | Anyone injured in their business or property, through the Consumer Protection Act. The attorney general can also enforce. |
| Damages | Private suits: actual damages, which a court can raise up to three times (the increase capped at $25,000), plus attorneys' fees. Attorney general: civil penalties up to $7,500 per violation, with a $5,000 enhanced penalty for practices that target people by characteristics such as age, race, or disability. |
| Cure period | None |
| Recent changes | None. The act hasn't been amended since it passed in 2023. |
| Coming up | No amendment pending. The attorney general's next review of Consumer Protection Act penalty amounts is due Dec 1, 2027. |
Our MHMDA guide walks through the consent rules, the sale authorization, and how website tracking gets pulled in.
Signed and arriving in 2027: Oklahoma and Alabama
Two more comprehensive laws are already signed. Oklahoma's OCDPA takes effect January 1, 2027 on the Virginia model.
Alabama's Personal Data Protection Act (APDPA) follows May 1, 2027, with a $15,000-per-violation penalty, double the $7,500 most Virginia-model states carry. It also has an unusual second threshold: anyone earning more than 25% of revenue from data sales is covered, no matter how few consumers are involved.
Unlike Oklahoma, Alabama requires controllers to honor opt-out preference signals, so plan on GPC support there from day one.
| Feature | OCDPA (Oklahoma) | APDPA (Alabama) |
|---|---|---|
| In effect | Jan 1, 2027 | May 1, 2027 |
| Applies to you if | 100K+ consumers, or 25K+ with 50%+ revenue from data sales | 25K+ consumers (payment-only processing excluded), or 25%+ of gross revenue from data sales at any volume |
| Fines | $7,500 per violation | Up to $15,000 per violation |
| Cure period | 30 days, mandatory before AG action | 45 days after AG notice of violation; correcting bars the action |
| Recognizes GPC | No | Yes (opt-out preference signals must be honored) |
| Privacy impact assessments | Required for targeted advertising, data sales, risky profiling, sensitive data | Not required |
| Sensitive data | Standard list plus precise geolocation defined as a 1,750-foot radius | Standard list plus precise geolocation |
| Consumer rights | Access, correct, delete, portability, opt out of targeted advertising, sale, and significant profiling, appeal | Access, correct, delete, portability, opt out of targeted advertising, sale, and significant automated decisions |
What do U.S. state privacy laws require from your website?
This is where the actual work starts. Across all of these laws, the obligations that touch your website come down to four things.
Consent management
Every comprehensive law requires you to let consumers opt out of the sale or sharing of personal data, and most require opt-in consent before processing sensitive data. In practice, that means a consent banner or preference center that actually blocks trackers until the right consent state is in place, not one that just decorates the page.
This is the core job of Enzuzo's consent management platform: detect where a visitor is, apply that state's rules, and keep a record of what they chose.
Geo-aware behavior
Opt-in and opt-out obligations differ by state, so one-size-fits-all banner behavior either over-asks (hurting your opt-in rates in states that don't require it) or under-asks (creating exposure in states that do).
The teams we talk to increasingly run region-specific consent rules: stricter defaults for California, lighter treatment where the law allows it.
Consent records
Several laws require you to be able to demonstrate consent. If a regulator or a plaintiff's firm asks when a visitor consented and to what, "our banner was live that month" is not an answer. Timestamped consent logs are.
Data subject rights requests
Access, correction, deletion, and portability requests, generally with a 45-day response deadline. If you're fielding these by email and spreadsheet today, that works at low volume and breaks the first time a deletion request touches six systems. Our guide to data subject access requests covers how to set this up properly.

What is Global Privacy Control, and which states enforce it?
Global Privacy Control (GPC) is a browser signal that broadcasts a consumer's opt-out preference automatically. Instead of clicking "do not sell my data" on every site, the browser says it for them, and the law treats that signal as a valid opt-out you must honor.
Twelve states now require it: California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas. That list more than doubled in two years, and every serious draft bill now includes a universal opt-out clause. Treat GPC support as the direction of travel, not an edge case.
One question we hear consistently from teams that already honor GPC: are we allowed to skip a cookie banner? The answer is that it depends: we don't recommend skipping it entirely, since it depends on the states you operate in and whether you process sensitive data that requires opt-in consent.
It's a genuinely good question to put to your counsel, because the answer changes your banner strategy, not just your legal posture.
What happens if you're not compliant?
Enforcement runs mainly through state attorneys general, and civil penalties are set per violation: up to $7,500 in Virginia, $10,000 in Maryland, and $20,000 in Colorado, for example. California adds a dedicated regulator, the California Privacy Protection Agency, and a private right of action for data breaches, at $107 to $799 per consumer per incident. Illinois BIPA and Washington MHMDA go further, allowing consumers to sue directly for violations, which is why those statutes generate more lawsuits than others.
The AG letter is not the risk most mid-market companies actually meet first, though. The demand letter is. Plaintiff firms now run automated scans for tracking technologies that fire before consent is obtained, then mail settlement demands under wiretapping laws such as CIPA.

Our California Invasion of Privacy Act explainer covers that exposure in detail.
The practical takeaway: enforcement risk scales with how visibly your site mishandles consent, not with how big you are.
How to operationalize U.S. state compliance (without a team)
If you're selling across the continental U.S, you don't need a 50-state legal memo. You need a defensible baseline:
1. Know your states. Check your analytics against the "applies to you if" rows above. You're probably covered in more states than you think, and that's fine; the point is knowing which rules are yours.
2. Run one consent standard, geo-adjusted. Meet the strictest rules that apply to you (usually California plus the GPC states), relax where the law genuinely allows it, and let your CMP handle the geography.
3. Honor GPC. Twelve states require it and the list only grows.
4. Keep consent records. Logs, timestamps, versions. This is what turns 'we have a banner' into 'we can show what each visitor chose, and when.
5. Have a DSAR intake that isn't an inbox. A form, a deadline tracker, and a deletion checklist cover most of it at mid-market scale.
Enzuzo's consent management platform handles the first four out of the box, and teams typically go live in one to three days.
If you'd rather see it against your own site than read about it, book a call with a U.S. privacy law expert.
FAQs
What are some United States data protection laws I should know about?
Twenty states have comprehensive consumer privacy laws as of 2026, led by California's CCPA/CPRA. Federally, sectoral laws apply: HIPAA (health), GLBA (financial), COPPA (children). If you sell nationally, the practical short list is California, Texas, Colorado, Connecticut, Illinois BIPA if you touch biometrics, and whichever states hold most of your customers.
Is there a federal data privacy law in the U.S.?
No. Proposed federal bills (ADPPA, APRA) have not passed. The FTC enforces against deceptive data practices, but consumer privacy rights currently exist only at the state level.
Which states have data privacy laws in 2026?
California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island. Indiana, Kentucky, and Rhode Island took effect January 1, 2026. Oklahoma and Alabama have signed laws arriving in 2027, and Illinois, New York, and Washington regulate privacy through targeted statutes.
Can you get sued for a data breach?
Yes. California's CCPA gives consumers a private right of action for breaches ($107 to $799 per consumer per incident), Illinois BIPA and Washington MHMDA allow direct consumer suits for violations, and breach class actions are common nationwide under other theories. See our data privacy lawsuits roundup for real settlement figures.
If our site honours Global Privacy Control, do we still need a cookie banner?
Usually yes. GPC covers the opt-out signal, but opt-in requirements for sensitive data, consent records, and non-GPC visitors still need a consent mechanism. The exact answer depends on your states and data types; it's worth a specific conversation with counsel.
We don't sell to EU customers. Do U.S. state laws still require consent management?
Yes, if you meet any state's threshold. GDPR is irrelevant to this question; 20 U.S. states impose their own consent and opt-out duties, and 12 require honoring GPC signals regardless of where your company is based.
Which states require opt-in consent instead of opt-out?
For ordinary personal data, none; the U.S. model is opt-out. For sensitive data (health, biometrics, precise location, children's data), nearly every state requires opt-in consent. Utah and Iowa are the main exceptions (notice plus opt-out), and California uses a right-to-limit model instead. Illinois and Washington require opt-in consent for biometric and health data specifically.
Do small businesses face the same privacy-law risk as national brands?
Increasingly, yes. Thresholds have dropped to 35,000 consumers in several states, Texas and Nebraska have no threshold at all, and demand-letter firms scan small-business sites the same way they scan enterprise ones. What matters is whether your site fires trackers before consent is obtained; scanners check small sites as readily as large ones.
Mate Prgin
Mate is the CEO & Founder of Enzuzo. He has an executive MBA from Ivey Business School and is a subject matter expert in data privacy and compliance.
More related blogs
Your next read
Start managing consent
the easy way.
Free forever plan available. No credit card required.