Skip to content

U.S. State Privacy Laws: 2026 Tracker and Compliance Guide

Mate Prgin 8/11/26, 1:09 AM

Table of Contents

As of August 2026, 20 U.S. states have comprehensive consumer privacy laws in effect. Indiana, Kentucky, and Rhode Island joined on January 1, 2026, and Oklahoma and Alabama arrive in 2027. There is still no U.S federal data privacy law.

Each state law sets its own rules for who's covered, which rights consumers get, and when you need consent. Twelve U.S. states now require sites to honor Global Privacy Control (GPC) opt-out signals.

This tracker covers every U.S. state law, who it applies to, and what it means for your website.

First, the bad news: if you sell to customers in multiple states, you're subject to a messy patchwork of regulations that grows every year. No single law covers you entirely; you inherit whichever state laws your customers live under, each with its own thresholds and quirks.

The good news: these laws share most of their DNA. Get the common baseline right, handle the handful of stricter outliers, and multi-state compliance stops being a quarterly project.

Below you'll find every law with its key facts, then the practical part most legal trackers skip: what these laws require from your website.

 

map-geographic@3x

 

At a glance: every state privacy law in 2026

According to MultiState's legislative tracking, 20 comprehensive U.S. state privacy laws are in effect as of August 2026, with two more signed and set to take effect in 2027.

The 2026 tracker: every comprehensive state privacy law
State Law In effect GPC required
California CCPA / CPRA Jan 2020 / Jan 2023 Yes
Virginia VCDPA Jan 2023 No
Colorado CPA Jul 2023 Yes
Connecticut CTDPA Jul 2023 Yes
Utah UCPA Dec 2023 No
Texas TDPSA Jul 2024 Yes
Oregon OCPA Jul 2024 Yes (Jan 2026)
Florida FDBR Jul 2024 No
Montana MCDPA Oct 2024 Yes
Delaware DPDPA Jan 2025 Yes (Jan 2026)
Iowa ICDPA Jan 2025 No
Nebraska NDPA Jan 2025 Yes
New Hampshire NHDPA Jan 2025 Yes
New Jersey NJDPA Jan 2025 Yes
Tennessee TIPA Jul 2025 No
Minnesota MCDPA Jul 2025 Yes
Maryland MODPA Oct 2025 Yes
Indiana INCDPA Jan 2026 No
Kentucky KCDPA Jan 2026 No
Rhode Island RIDTPPA Jan 2026 No
Oklahoma OCDPA Jan 2027 (signed) No
Alabama APDPA May 2027 (signed) Yes

Three more states regulate privacy without a comprehensive law, and two of them carry more litigation risk than the rest:

Targeted state laws to know: Illinois, New York, Washington
State Law In effect The short version
Illinois BIPA 2008 Biometric data; private right of action; most-litigated privacy statute in the U.S.
New York SHIELD Act 2020 Data security and breach notification duties for anyone holding NY residents' data
Washington My Health My Data Act 2024 Consumer health data; broad private right of action

Is there a federal U.S. privacy law?

No. The American Data Privacy and Protection Act (ADPPA) and its successor, the American Privacy Rights Act, both stalled in Congress, and newer proposals like the SECURE Data Act haven't moved past committee either, with preemption of stronger state laws still the sticking point. What exists federally is sectoral: HIPAA for health data held by covered entities, GLBA for financial institutions, COPPA for children's data, and FTC enforcement against unfair or deceptive data practices.

According to the FTC's business guidance, the agency treats broken privacy promises as deceptive practices, which means your own privacy policy is enforceable against you even in states with no privacy law at all.

Until Congress acts, your obligations come from the state laws below.

 

California Consumer Privacy Act (CCPA / CPRA)

California started the wave of strict U.S. privacy legislation and remains the most demanding of the lot. 

The CCPA (2020), amended by the CPRA (2023), created the country's only dedicated privacy regulator (the CPPA) and the only private right of action in a comprehensive law for data breaches, with damages ranging from $100 to $750 per consumer per incident.

It also runs a rulemaking machine that keeps adding requirements: data broker registration, AI and automated decision-making rules, and risk assessments through 2026. 

If you comply with California and nothing else, you're most of the way to the national baseline.

California's CCPA / CPRA at a glance
Feature CCPA / CPRA
In effect CCPA Jan 1, 2020; CPRA amendments Jan 1, 2023
Applies to you if You had $25M+ gross revenue in the preceding year; OR buy, sell, or share personal information of 100K+ CA consumers or households; OR earn 50%+ of revenue from selling or sharing personal information
Fines $2,500 per negligent violation; $7,500 per intentional violation; breach suits at $100 to $750 per consumer per incident
Cure period None
Recognizes GPC Yes
Privacy impact assessments Required for profiling, sensitive data, large-scale processing, and other processing that risks harm to consumers
Sensitive data Race or ethnicity, religion, health, sex life, sexual orientation, citizenship or immigration status, genetic and biometric data, precise geolocation, union membership, neural data, personal data of minors under 16
Consumer rights Know/confirm, access, correct, delete, portability, opt out of sale or sharing, limit use of sensitive data, opt out of automated decision-making and profiling

 

Virginia Consumer Data Protection Act (VCDPA)

Virginia wrote the template that most states copied: opt-out rights for ordinary data, opt-in consent for sensitive data, a 100,000-consumer threshold, and attorney general-only enforcement. It's also one of the more forgiving laws to operate under: its 30-day cure period never expires.

Virginia's VCDPA at a glance
Feature VCDPA
In effect Jan 1, 2023
Applies to you if You do business in or target Virginia and control/process personal data of 100K+ consumers; OR 25K+ consumers with 50%+ of revenue from selling personal data
Fines Up to $7,500 per violation
Cure period 30 days, no sunset
Recognizes GPC No
Privacy impact assessments Required for targeted advertising, data sales, profiling, sensitive data, and any processing presenting a risk of harm
Sensitive data Race or ethnicity, religion, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation (within a 1,750-foot radius)
Consumer rights Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data

Colorado Privacy Act (CPA)

Colorado follows the Virginia model but with sharper teeth: fines run to $20,000 per violation (capped at $500,000), while most state laws cap fines at $7,500. Its cure period sunset in January 2025, and GPC enforcement has been live since July 2024. Colorado's AG also keeps updating guidance, so requirements move more than in most standard-model states.

Colorado's CPA at a glance
Feature CPA
In effect Jul 1, 2023
Applies to you if You collect personal data of 100K+ CO residents; OR 25K+ residents with any revenue or discount derived from selling that data
Fines $20,000 per violation, capped at $500,000
Cure period None (sunset Jan 2025)
Recognizes GPC Yes (since Jul 2024)
Privacy impact assessments Required for high-risk processing: targeted advertising, data sales, sensitive data, profiling
Sensitive data Race or ethnicity, religion, health condition or diagnosis, sex life, sexual orientation, citizenship status, genetic and biometric data, data of a known child, neural data
Consumer rights Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, object to automated decision-making

 

Connecticut Data Privacy Act (CTDPA)

Connecticut runs the standard model with the broadest sensitive-data definition outside Maryland, and 2026 made it stricter. Amendments effective July 1 dropped the threshold from 100,000 to 35,000 consumers and added two triggers with no threshold at all: if you sell personal data or process sensitive data, you're covered at any volume.

Connecticut's CTDPA at a glance
Feature CTDPA
In effect Jul 1, 2023 (amendments Jul 1, 2026)
Applies to you if You do business in or target Connecticut and control/process personal data of 35K+ consumers; OR sell personal data at any volume; OR process sensitive data at any volume (payment-only processing excluded)
Fines $5,000 per willful violation (via CUTPA), plus AG orders, disgorgement, and restitution
Cure period None (sunset Dec 2024)
Recognizes GPC Yes
Privacy impact assessments Required for heightened-risk activities: targeted advertising, data sales, profiling, sensitive data
Sensitive data Race or ethnicity, religion, health condition or diagnosis, consumer health data, sex life, sexual orientation, transgender or nonbinary status, citizenship status, genetic and biometric data, data of a known child, precise geolocation, crime-victim status, disability, financial account or card numbers with access credentials, government-issued IDs, neural data
Consumer rights Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, object to automated decision-making, question the result of profiling

 

Utah Consumer Privacy Act (UCPA)

Utah is the most business-friendly law on this list. It only applies if you clear $25 million in revenue AND a consumer-count threshold, sensitive data needs only notice and an opt-out (not opt-in consent), there's no GPC requirement, no impact assessments, and the 30-day cure period never expires.

If you're already handling California, consider yourself covered on the Utah front.

Utah's UCPA at a glance
Feature UCPA
In effect Dec 31, 2023
Applies to you if You have $25M+ annual revenue AND control/process personal data of 100K+ UT residents, OR 25K+ residents with 50%+ of revenue from selling personal data
Fines Up to $7,500 per violation plus actual damages
Cure period 30 days, no sunset
Recognizes GPC No
Privacy impact assessments Not required
Sensitive data Race or ethnicity, religion, health condition and medical history, sexual orientation, citizenship or immigration status, genetic and biometric data, precise geolocation
Consumer rights Know/confirm, access, correct (added by HB 418), delete, portability, opt out of sale and targeted advertising, notice and opt-out for sensitive data

 

Texas Data Privacy and Security Act (TDPSA)


Texas skipped the consumer-count threshold entirely: if you do business in Texas and you're not an SBA-defined small business, you're covered, with no revenue floor.

Even exempt small businesses need consent before selling sensitive data. Texas's AG has run dedicated privacy sweeps since 2024, enforcement most states haven't attempted.

Texas's TDPSA at a glance
Feature TDPSA
In effect Jul 1, 2024
Applies to you if You do business in Texas or serve Texas residents, process or sell personal data, and aren't an SBA-defined small business. No revenue or volume thresholds
Fines Up to $7,500 per violation, plus injunctive relief
Cure period 30 days, no sunset
Recognizes GPC Yes (since Jan 2025)
Privacy impact assessments Required for targeted advertising, data sales, profiling, sensitive data, and other heightened-risk processing
Sensitive data Race or ethnicity, religion, health diagnosis, sexuality, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation
Consumer rights Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, object to automated decision-making

Oregon Consumer Privacy Act (OCPA)

Oregon follows the standard model with one right no other state started with: consumers can request the specific third parties that received their data, not just the categories. Its GPC requirement kicked in January 2026, the same month its cure period expired. A 2026 amendment also banned the sale of data from users known to be under 16, and the law uniquely covers motor vehicle manufacturers that process vehicle data, regardless of thresholds.

Oregon's OCPA at a glance
Feature OCPA
In effect Jul 1, 2024
Applies to you if You control/process personal data of 100K+ OR residents; OR 25K+ residents with 25%+ of revenue from selling personal data; OR you're a vehicle manufacturer processing data from vehicle use
Fines Up to $7,500 per violation
Cure period None (sunset Jan 2026)
Recognizes GPC Yes (since Jan 1, 2026)
Privacy impact assessments Required for targeted advertising, data sales, profiling, sensitive data, and other heightened-risk processing
Sensitive data Race, ethnicity, or national origin, religion, health condition or diagnosis, sexual orientation, transgender or nonbinary status, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation, crime-victim status
Consumer rights Know/confirm, access, list of specific third parties who received your data, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, object to automated decision-making

Florida Digital Bill of Rights (FDBR)

Florida is the asterisk in every state count. The FDBR's full controller obligations only apply to for-profit companies with over $1 billion in global revenue that also meet one of three tech-platform criteria: 50%+ of revenue from online ads, an app store with 250,000+ apps, or a consumer smart-speaker service. That's why most trackers count '19 plus Florida. '

Two parts do reach smaller companies: rules on selling sensitive data and children's data protections. 

Florida's FDBR at a glance
Feature FDBR
In effect Jul 1, 2024
Applies to you if Full obligations: for-profit, doing business in Florida, $1B+ global revenue, AND one of: 50%+ of revenue from online ads; an app store with 250K+ apps; or a consumer smart-speaker and voice assistant service (in-car systems excluded). Sensitive-data sale rules: ANY for-profit entity doing business in Florida
Fines Up to $50,000 per violation; up to $150,000 (tripled) when a known child's data is involved
Cure period 45 days (discretionary; not available for children's-data violations)
Recognizes GPC No (statute is silent on universal opt-out signals)
Privacy impact assessments Required for targeted advertising, data sales, risky profiling, sensitive data, and other heightened-risk processing
Sensitive data Race or ethnicity, religion, health diagnosis, sexual orientation, citizenship or immigration status, genetic and biometric data, precise geolocation, and all personal data of a known child under 18
Consumer rights Know/confirm, access, correct, delete, portability, opt out of sale, targeted advertising, and significant profiling, opt out of sensitive-data collection, opt out of voice and facial recognition collection on smart devices (unique to Florida), search-engine ranking transparency (unique to Florida)

Montana Consumer Data Privacy Act (MCDPA)

Montana fit the standard model to a small population, and 2025 amendments cut the thresholds deeper: 25,000 residents, down from 50,000, or just 15,000 if a quarter of your revenue comes from data sales. Its cure period sunset in April 2026.

Duty-of-care rules for minors reach every business serving Montanans, regardless of size.

Montana's MCDPA at a glance
Feature MCDPA (Montana)
In effect Oct 1, 2024
Applies to you if You control/process personal data of 25K+ MT residents; OR 15K+ residents with 25%+ of revenue from selling personal data. Minor duty-of-care rules apply regardless of thresholds
Fines Up to $7,500 per violation
Cure period None (60-day period sunset Apr 2026)
Recognizes GPC Yes
Privacy impact assessments Required for targeted advertising, data sales, profiling, sensitive data, and other heightened-risk processing
Sensitive data Race or ethnicity, religion, health condition or diagnosis, sex life, sexual orientation, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation
Consumer rights Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, object to automated decision-making

 

Delaware Personal Data Privacy Act (DPDPA)

Delaware runs the standard model at one of the lowest thresholds in the country: 35,000 consumers, or just 10,000 if a fifth of your revenue comes from data sales. Its GPC requirement and cure-period sunset both landed January 2026.

Enforcement discretion rests with the state Department of Justice, and, as in Oregon, consumers can demand the specific third parties that obtained their data.

Delaware's DPDPA at a glance
Feature DPDPA
In effect Jan 1, 2025
Applies to you if You do business in or target Delaware and control/process personal data of 35K+ consumers (payment-only processing excluded); OR 10K+ consumers with 20%+ of revenue from selling personal data
Fines Up to $10,000 per violation, at DOJ discretion
Cure period None (60-day period sunset Jan 2026)
Recognizes GPC Yes (since Jan 1, 2026)
Privacy impact assessments Required for targeted advertising, data sales, sensitive data, and profiling that risks deceptive treatment, injury, or intrusion on solitude
Sensitive data Race, ethnicity, or national origin, religion, health condition or diagnosis, sex life, sexual orientation, transgender or nonbinary status, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation
Consumer rights Know/confirm, access, list of specific third parties who received your data, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, object to automated decision-making

 

Iowa Consumer Data Protection Act (ICDPA)

Iowa sits with Utah at the lenient end: sensitive data requires only notice and an opt-out, there's no GPC duty, no impact assessments, no correction right, and the 90-day cure period is the longest anywhere.

Treat it as covered by your Virginia-model baseline.

Iowa's ICDPA at a glance
Feature ICDPA
In effect Jan 1, 2025
Applies to you if You control/process personal data of 100K+ IA consumers; OR 25K+ consumers with 50%+ of revenue from selling personal data
Fines $7,500 per violation
Cure period 90 days
Recognizes GPC No
Privacy impact assessments Not addressed by the law
Sensitive data Race, ethnicity, or national origin, religion, health diagnosis, sexual orientation, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation
Consumer rights Know/confirm, access, delete, portability, opt out of sale and targeted advertising, opt out or limit sensitive data processing. No correction right

 

Nebraska Data Privacy Act (NDPA)

Nebraska copied the Texas playbook: no consumer-count or revenue threshold, an SBA small-business carve-out, and GPC recognition from day one. If you do business in Nebraska at any real scale, assume you're covered.

The 30-day cure period doesn't sunset.

Nebraska's NDPA at a glance
Feature NDPA
In effect Jan 1, 2025
Applies to you if You do business in Nebraska or serve Nebraska residents, process or sell personal data, and aren't an SBA-defined small business. No thresholds
Fines $7,500 per violation
Cure period 30 days, no sunset
Recognizes GPC Yes
Privacy impact assessments Required for targeted advertising, data sales, sensitive data, and profiling that risks deceptive treatment, injury, or intrusion on solitude
Sensitive data Race or ethnicity, religion, health diagnosis, sexual orientation, citizenship or immigration status, genetic and biometric data processed to identify a person, data of a known child, precise geolocation
Consumer rights Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling with significant effects

 

New Hampshire Data Privacy Act (NHDPA)

New Hampshire pairs low thresholds (35,000 consumers) with the same enforcement route Connecticut and New Jersey use: privacy violations count as deceptive trade practices, with penalties up to $10,000 per violation. The cure period sunset in January 2026.

New Hampshire's NHDPA at a glance
Feature NHDPA
In effect Jan 1, 2025
Applies to you if You do business in or target New Hampshire and control/process personal data of 35K+ unique consumers (payment-only processing excluded); OR 10K+ consumers with 25%+ of revenue from selling personal data
Fines Up to $10,000 per violation, via the deceptive trade practices law
Cure period None (sunset Jan 2026)
Recognizes GPC Yes
Privacy impact assessments Required for any processing with heightened risk of harm: targeted advertising, data sales, certain profiling, sensitive data
Sensitive data Race or ethnicity, religion, health condition or diagnosis, sex life, sexual orientation, citizenship or immigration status, genetic and biometric data processed to identify a person, data of a known child, precise geolocation
Consumer rights Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling with legal or similarly significant effects

 

New Jersey Data Privacy Act (NJDPA)

New Jersey extends the standard model in two ways that trip up companies compliant elsewhere.

Financial information counts as sensitive data; a broader trigger than any other state's (Connecticut's stops at account and card numbers with access credentials). And penalties escalate: violations route through the Consumer Fraud Act at up to $10,000 for a first offense and $20,000 after that.

Its cure period sunset on July 15, 2026, so as of writing there's no grace window.

New Jersey's NJDPA at a glance
Feature NJDPA
In effect Jan 15, 2025
Applies to you if You control/process personal data of 100K+ NJ consumers (payment-only processing excluded); OR 25K+ consumers with revenue or price discounts derived from selling personal data
Fines Up to $10,000 first violation, up to $20,000 for subsequent violations (via Consumer Fraud Act)
Cure period None (sunset Jul 15, 2026)
Recognizes GPC Yes
Privacy impact assessments Required for targeted advertising, data sales, sensitive data, and profiling with reasonably foreseeable risk of deceptive treatment, disparate impact, injury, or intrusion
Sensitive data Race or ethnicity, religion, health condition, treatment, or diagnosis, sex life, sexual orientation, transgender or nonbinary status, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation, financial information
Consumer rights Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, opt out of automated decision-making

 

Tennessee Information Protection Act (TIPA)

Tennessee is the only state with a built-in affirmative defense: a written privacy program that reasonably conforms to the NIST Privacy Framework (or a comparable standard) shields you from liability.

Two conditions: the program stays updated within two years of framework revisions, and consumers still get every right the law grants them.

Tennessee's TIPA at a glance
Feature TIPA
In effect Jul 1, 2025
Applies to you if You have $25M+ annual revenue AND control/process personal information of 175K+ TN consumers; OR 25K+ consumers with 50%+ of revenue from selling personal information
Fines Up to $7,500 per violation, trebled if willful
Cure period 60 days
Recognizes GPC No
Privacy impact assessments Required for targeted advertising, data sales, sensitive data, profiling, and other heightened-risk processing
Sensitive data Race, ethnicity, or national origin, religion, health condition or diagnosis, sexual orientation, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation
Consumer rights Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, object to automated decision-making

 

Minnesota Consumer Data Privacy Act (MCDPA)

Minnesota adds a right no other state has: consumers can question the result of profiling and get an explanation of why an automated decision came out the way it did. It also requires a documented privacy program the AG can inspect, plus a third-party disclosure list on request. The cure period sunset January 31, 2026.

Minnesota's MCDPA at a glance
Feature MCDPA (Minnesota)
In effect Jul 31, 2025
Applies to you if You target Minnesotans and control/process personal data of 100K+ consumers; OR 25K+ consumers with 25%+ of revenue from selling personal data
Fines $7,500 per violation
Cure period None (sunset Jan 31, 2026)
Recognizes GPC Yes
Privacy impact assessments Required for targeted advertising, data sales, sensitive data, heightened-risk processing, and profiling that risks unfair treatment or injury; AG may review assessments
Sensitive data Race or ethnicity, religion, health diagnosis, sexual orientation, citizenship or immigration status, genetic and biometric data, data of a known child, specific geolocation
Consumer rights Know/confirm, access, list of third parties, correct, delete, portability, opt out of sale and targeted advertising, question the result of profiling, non-discrimination, appeal

 

Maryland Online Data Privacy Act (MODPA)

Maryland is the strictest law since California, and stricter in one way: it bans the sale of sensitive data outright, consent or not, and imposes the country's toughest data-minimization standard (collect only what's reasonably necessary for the specific product the consumer asked for). Impact assessments must be run per algorithm.

Maryland imposes a data-minimization standard none of the Virginia-model laws attempt: collect only what's reasonably necessary for the specific product the consumer asked for.

Maryland's MODPA at a glance
Feature MODPA
In effect Oct 1, 2025
Applies to you if You do business in or target Maryland and control/process personal data of 35K+ consumers (payment-only processing excluded); OR 10K+ consumers with 20%+ of revenue from selling personal data
Fines Up to $10,000 per violation; up to $25,000 per repeat of the same violation
Cure period Discretionary, up to 60 days (sunsets Apr 2027)
Recognizes GPC Yes
Privacy impact assessments Required for targeted advertising, data sales, sensitive data, and processing risking deceptive treatment, disparate impact, or injury. Must be conducted for each algorithm used
Sensitive data Race, ethnicity, or national origin, religion, consumer health data, sex life, sexual orientation, transgender or nonbinary status, citizenship or immigration status, genetic data, biometric data, data of a known child, precise geolocation. Sale of sensitive data is banned entirely
Consumer rights Know/confirm, access, correct, delete, portability, list of third parties (or categories) who received your data, opt out of sale, opt out of targeted advertising and profiling with significant effects

 

Indiana Consumer Data Protection Act (INCDPA)

Indiana went live January 1, 2026 as a faithful copy of the Virginia model: same thresholds, same opt-in rule for sensitive data, same AG-only enforcement, same permanent 30-day cure period. That makes it one of the gentler laws in the 2026 wave.

Indiana's INCDPA at a glance
Feature INCDPA
In effect Jan 1, 2026
Applies to you if You operate in or target Indiana and control/process personal information of 100K+ residents; OR 25K+ residents with 50%+ of revenue from selling that data
Fines $7,500 per violation
Cure period 30 days, no sunset
Recognizes GPC No
Privacy impact assessments Required for targeted advertising, data sales, sensitive data, risky profiling, and other heightened-risk processing
Sensitive data Race, ethnicity, or national origin, religion, health diagnosis made by a healthcare provider, sexual orientation, citizenship or immigration status, genetic and biometric data, data of a known child, precise geolocation
Consumer rights Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, object to automated decision-making

 

Kentucky Consumer Data Protection Act (KCDPA)

Kentucky also launched January 1, 2026 on the Virginia template, with pre-effective-date amendments (HB 473, March 2025) that widened healthcare exemptions: data held by HIPAA-covered providers and HIPAA limited data sets sit outside the law entirely. The same amendments narrowed the impact-assessment trigger for profiling to risks of unlawful disparate impact.

Kentucky's KCDPA at a glance
Feature KCDPA
In effect Jan 1, 2026 (PIA requirement from Jun 1, 2026)
Applies to you if You do business in or target Kentucky and control/process data of 100K+ consumers; OR 25K+ consumers with 50%+ of revenue from selling personal data
Fines $7,500 per violation
Cure period 30 days, no sunset
Recognizes GPC No
Privacy impact assessments Required (from Jun 1, 2026) for targeted advertising, data sales, risky profiling, sensitive data, and heightened-risk processing
Sensitive data Race or ethnicity, religion, health diagnosis, sexual orientation, citizenship or immigration status, genetic and biometric data processed to identify a person, data of a known child, precise geolocation
Consumer rights Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling, opt-in for sensitive data, object to automated decision-making

 

Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)

Rhode Island is small-state, sharp-edges: a 35,000-consumer threshold, no cure period at all, penalties to $10,000 per violation, plus $100 to $500 per intentional disclosure of personal information. It launched January 1, 2026 with the least forgiving enforcement posture of the new wave.

Rhode Island's RIDTPPA at a glance
Feature RIDTPPA
In effect Jan 1, 2026
Applies to you if You're a for-profit entity doing business in or targeting Rhode Island and control/process personal data of 35K+ residents; OR 10K+ residents with 20%+ of revenue from selling that data
Fines $10,000 per violation, plus $100 to $500 per intentional disclosure
Cure period None
Recognizes GPC No
Privacy impact assessments Required before targeted advertising, data sales, risky profiling, and sensitive data processing
Sensitive data Race or ethnicity, religion, health condition or diagnosis, sex life, sexual orientation, citizenship or immigration status, genetic and biometric data processed to identify a person, data of a known child, precise geolocation
Consumer rights Know/confirm, access, correct, delete, portability, opt out of sale, opt out of targeted advertising and profiling with legal or similarly significant effects

 

Illinois Biometric Information Privacy Act (BIPA)

Illinois has no comprehensive privacy law, yet it still produces more privacy litigation than any state in the table above. BIPA (2008) requires written consent before collecting biometric identifiers, and it hands consumers a private right of action with statutory damages. That combination built an entire class-action industry: fingerprint time clocks, face-tagging features, and voiceprint tools have all produced eight- and nine-figure settlements.

An August 2024 amendment (SB 2979) reined in the worst of it: repeated scans of the same data by the same method now count as one violation, not thousands. But BIPA remains the highest-severity privacy statute in the country for any company touching biometrics.

Illinois's BIPA at a glance
Feature BIPA
In effect Oct 2008
Applies to you if You're a private entity collecting, storing, or using biometric identifiers of Illinois residents. No thresholds of any kind
Fines $1,000 per negligent violation; $5,000 per intentional or reckless violation, recoverable by private plaintiffs
Cure period None
Recognizes GPC Not applicable (consent-based, not opt-out-based)
Privacy impact assessments Not required; written retention policy required
Sensitive data Biometric identifiers: fingerprints, voiceprints, retina or iris scans, face geometry, hand scans
Consumer rights Informed written consent before collection, disclosure of retention schedule, deletion within statutory timelines, private right of action for violations

 

New York SHIELD Act

New York also lacks a comprehensive consumer privacy law, but the SHIELD Act (2020) reaches almost everyone anyway. Any business holding the private information of New York residents must maintain reasonable data security safeguards and report breaches, regardless of where the business sits.

It grants no consumer rights and needs no consent banner; it's a security-and-breach law, enforced by the Attorney General with no private right of action.

Treat it as the floor for your security program, and watch this space: New York's comprehensive privacy bills keep advancing each session without passing.

New York's SHIELD Act at a glance
Feature SHIELD Act
In effect Mar 2020 (security requirements)
Applies to you if You own or license computerized private information of any New York resident, wherever your business is located. Reduced obligations for small businesses
Fines Up to $5,000 per violation for failing reasonable safeguards; breach-notification failures at $20 per failed notice (up to $5,000 each if knowing or reckless), capped at $250,000 total
Cure period None
Recognizes GPC Not applicable
Privacy impact assessments Not required; a documented data security program is
Sensitive data "Private information": SSNs, driver's license numbers, financial account and card data with credentials, biometric data, username or email plus password
Consumer rights Breach notification. No access, deletion, or opt-out rights

 

Washington My Health My Data Act (MHMDA)

Washington regulates one category, consumer health data, and does it more aggressively than any comprehensive law.

MHMDA (2024) requires opt-in consent to collect or share health data, a separate signed authorization to sell it, and a ban on geofencing around health facilities. The teeth: a broad private right of action through Washington's Consumer Protection Act, covering any violation, not just breaches.

'Health data' is defined loosely enough to reach period trackers, fitness apps, wellness e-commerce, and ad pixels on symptom pages.

Washington's MHMDA at a glance
Feature MHMDA
In effect Mar 31, 2024 (Jun 30, 2024 for small businesses)
Applies to you if You do business in Washington or target its residents and collect, share, or sell consumer health data. No revenue or volume thresholds
Fines Enforced as per se Consumer Protection Act violations: AG penalties up to $7,500 per violation, plus a $5,000 enhancement for violations impacting vulnerable communities; private suits recover actual damages with discretionary treble damages capped at $25,000, plus attorney's fees
Cure period None
Recognizes GPC Not applicable (opt-in consent model)
Privacy impact assessments Not required; consumer health data privacy policy required
Sensitive data Consumer health data broadly: conditions, treatments, reproductive health, gender-affirming care, biometrics used for health inference, precise location near health services
Consumer rights Access, deletion, withdrawal of consent, list of third parties with contact details, private right of action

 

Signed and arriving in 2027: Oklahoma and Alabama

Two more comprehensive laws are already signed. Oklahoma's OCDPA takes effect January 1, 2027 on the Virginia model.

Alabama's Personal Data Protection Act (APDPA) follows May 1, 2027, with a $15,000-per-violation penalty, double the $7,500 most Virginia-model states carry. It also has an unusual second threshold: anyone earning more than 25% of revenue from data sales is covered, no matter how few consumers are involved.

Unlike Oklahoma, Alabama requires controllers to honor opt-out preference signals, so plan on GPC support there from day one.

Coming in 2027: Oklahoma and Alabama
Feature OCDPA (Oklahoma) APDPA (Alabama)
In effect Jan 1, 2027 May 1, 2027
Applies to you if 100K+ consumers, or 25K+ with 50%+ revenue from data sales 25K+ consumers (payment-only processing excluded), or 25%+ of gross revenue from data sales at any volume
Fines $7,500 per violation Up to $15,000 per violation
Cure period 30 days, mandatory before AG action 45 days after AG notice of violation; correcting bars the action
Recognizes GPC No Yes (opt-out preference signals must be honored)
Privacy impact assessments Required for targeted advertising, data sales, risky profiling, sensitive data Not required
Sensitive data Standard list plus precise geolocation defined as a 1,750-foot radius Standard list plus precise geolocation
Consumer rights Access, correct, delete, portability, opt out of targeted advertising, sale, and significant profiling, appeal Access, correct, delete, portability, opt out of targeted advertising, sale, and significant automated decisions

 

What do U.S. state privacy laws require from your website?

This is where the actual work starts. Across all of these laws, the obligations that touch your website come down to four things.

Consent management

Every comprehensive law requires you to let consumers opt out of the sale or sharing of personal data, and most require opt-in consent before processing sensitive data. In practice, that means a consent banner or preference center that actually blocks trackers until the right consent state is in place, not one that just decorates the page.

This is the core job of Enzuzo's consent management platform: detect where a visitor is, apply that state's rules, and keep a record of what they chose.

Geo-aware behavior

Opt-in and opt-out obligations differ by state, so one-size-fits-all banner behavior either over-asks (hurting your opt-in rates in states that don't require it) or under-asks (creating exposure in states that do).

The teams we talk to increasingly run region-specific consent rules: stricter defaults for California, lighter treatment where the law allows it. 

Consent records

Several laws require you to be able to demonstrate consent. If a regulator or a plaintiff's firm asks when a visitor consented and to what, "our banner was live that month" is not an answer. Timestamped consent logs are.

Data subject rights requests

Access, correction, deletion, and portability requests, generally with a 45-day response deadline. If you're fielding these by email and spreadsheet today, that works at low volume and breaks the first time a deletion request touches six systems. Our guide to data subject access requests covers how to set this up properly.

 

website-requirements@3x

 

What is Global Privacy Control, and which states enforce it?

Global Privacy Control (GPC) is a browser signal that broadcasts a consumer's opt-out preference automatically. Instead of clicking "do not sell my data" on every site, the browser says it for them, and the law treats that signal as a valid opt-out you must honor.

Twelve states now require it: California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas. [verify: Virginia may make it 13; sources conflict on whether VCDPA amendments added a universal opt-out duty.] That list more than doubled in two years, and every serious draft bill now includes a universal opt-out clause. Treat GPC support as the direction of travel, not an edge case.

One question we hear consistently from teams that already honor GPC: are we allowed to skip a cookie banner? The answer is that it depends: we don't recommend skipping it entirely, since it depends on the states you operate in and whether you process sensitive data that requires opt-in consent.

It's a genuinely good question to put to your counsel, because the answer changes your banner strategy, not just your legal posture.

 

What happens if you're not compliant?

Enforcement runs through state attorneys general, with civil penalties typically between $2,500 and $20,000 per violation depending on the state. California adds two things nobody else has among the comprehensive laws: a dedicated regulator (the CPPA) and a private right of action for data breaches, at $100 to $750 per consumer per incident. Illinois BIPA and Washington MHMDA go further, allowing consumers to sue directly for violations, which is why those statutes generate more lawsuits than others.

The AG letter is not the risk most mid-market companies actually meet first, though. The demand letter is. Plaintiff firms now run automated scans for tracking technologies that fire before consent is obtained, then mail settlement demands under wiretapping laws such as CIPA

at-a-glance@3x

Our California Invasion of Privacy Act explainer covers that exposure in detail.

The practical takeaway: enforcement risk scales with how visibly your site mishandles consent, not with how big you are.

 

How to operationalize U.S. state compliance (without a team)

If you're selling across the continental U.S, you don't need a 50-state legal memo. You need a defensible baseline:

1.  Know your states. Check your analytics against the "applies to you if" rows above. You're probably covered in more states than you think, and that's fine; the point is knowing which rules are yours.
2.  Run one consent standard, geo-adjusted. Meet the strictest rules that apply to you (usually California plus the GPC states), relax where the law genuinely allows it, and let your CMP handle the geography.
3.  Honor GPC. Twelve states require it and the list only grows.
4.  Keep consent records. Logs, timestamps, versions. This is what turns 'we have a banner' into 'we can show what each visitor chose, and when.
5.  Have a DSAR intake that isn't an inbox. A form, a deadline tracker, and a deletion checklist cover most of it at mid-market scale.

Enzuzo's consent management platform handles the first four out of the box, and teams typically go live in one to three days.

If you'd rather see it against your own site than read about it, book a call with a U.S. privacy law expert.

 

FAQs

What are some United States data protection laws I should know about?  

Twenty states have comprehensive consumer privacy laws as of 2026, led by California's CCPA/CPRA. Federally, sectoral laws apply: HIPAA (health), GLBA (financial), COPPA (children). If you sell nationally, the practical short list is California, Texas, Colorado, Connecticut, Illinois BIPA if you touch biometrics, and whichever states hold most of your customers.

Is there a federal data privacy law in the U.S.?

No. Proposed federal bills (ADPPA, APRA) have not passed. The FTC enforces against deceptive data practices, but consumer privacy rights currently exist only at the state level.

Which states have data privacy laws in 2026?  

California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island. Indiana, Kentucky, and Rhode Island took effect January 1, 2026. Oklahoma and Alabama have signed laws arriving in 2027, and Illinois, New York, and Washington regulate privacy through targeted statutes.

Can you get sued for a data breach?  

Yes. California's CCPA gives consumers a private right of action for breaches ($100 to $750 per consumer per incident), Illinois BIPA and Washington MHMDA allow direct consumer suits for violations, and breach class actions are common nationwide under other theories. See our [data privacy lawsuits roundup](/blog/data-privacy-lawsuits) for real settlement figures.

If our site honours Global Privacy Control, do we still need a cookie banner?  

Usually yes. GPC covers the opt-out signal, but opt-in requirements for sensitive data, consent records, and non-GPC visitors still need a consent mechanism. The exact answer depends on your states and data types; it's worth a specific conversation with counsel.

We don't sell to EU customers. Do U.S. state laws still require consent management?  

Yes, if you meet any state's threshold. GDPR is irrelevant to this question; 20 U.S. states impose their own consent and opt-out duties, and 12 require honoring GPC signals regardless of where your company is based.

Which states require opt-in consent instead of opt-out?  

For ordinary personal data, none; the U.S. model is opt-out. For sensitive data (health, biometrics, precise location, children's data), nearly every state requires opt-in consent. Utah and Iowa are the main exceptions (notice plus opt-out), and California uses a right-to-limit model instead. Illinois and Washington require opt-in consent for biometric and health data specifically.

Do small businesses face the same privacy-law risk as national brands?  

Increasingly, yes. Thresholds have dropped to 35,000 consumers in several states, Texas and Nebraska have no threshold at all, and demand-letter firms scan small-business sites the same way they scan enterprise ones. What matters is whether your site fires trackers before consent is obtained; scanners check small sites as readily as large ones.

Mate Prgin

Mate Prgin

Mate is the CEO & Founder of Enzuzo. He has an executive MBA from Ivey Business School and is a subject matter expert in data privacy and compliance.