US State Privacy Laws: Every State, Dates, Rules and Thresholds

As of October 2026, 19 states have a broad comprehensive consumer privacy law in effect, 20 if you count Florida’s narrow one, and four more (Oklahoma, Louisiana, Alabama and Vermont) are signed and take effect in 2027 or 2028. There is still no federal equivalent, so US state privacy laws are the rules: they give residents the right to access, correct, delete and port their data and to opt out of its sale, targeted advertising and profiling, and they require covered businesses to publish a privacy notice, limit what they collect, assess risky processing and, in a growing number of states, honor browser opt-out signals.
This guide lists every law with its effective date and who it covers, compares the rights and duties, explains where the usual trackers disagree, and then does what legal trackers skip: it shows what these laws change on a real website, from ad pixels to conversion tracking, with a worked threshold check you can repeat with your own numbers.
Dates, thresholds and penalties below were cross-checked across several legal trackers on October 7, 2026, and California’s against the Attorney General’s own page. Laws get amended every session. Confirm the statute, or ask counsel, before you rely on a detail.
How Many States Have Privacy Laws?
The honest answer is “it depends on what you count,” and that is why sources give different numbers:
- 19 broad comprehensive laws are in effect today (California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Nebraska, Iowa, Delaware, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island).
- 20 if you add Florida’s Digital Bill of Rights. It is often left out because it only reaches companies with over $1 billion in global revenue that meet further conditions, such as running an app store or smart speaker service.
- 24 enacted laws when you add the four signed but not yet in force: Oklahoma, Louisiana, Alabama and Vermont.
- Hundreds of state privacy statutes if you count narrower laws: breach notification (every state has one), biometrics, health data, children’s data, Social Security numbers, wiretapping and more.
“Comprehensive” means a law that applies across industries and gives a full set of consumer rights, not one about a single sector or data type. Nevada is the classic edge case: its 2005 online privacy law requires a website privacy notice and was the first to give consumers a right to opt out of the sale of their data, but it lacks the access, correction and deletion rights of the newer laws, so most trackers do not count it.
US State Privacy Laws by State
The map shows status at a glance. Blue states have a broad law in force, orange states have signed one that is not yet effective, and Florida is marked separately because of its narrow scope.

The full list, with the official name of each law, the date it first took effect and whether it requires you to honor a universal opt-out signal such as Global Privacy Control (GPC):
| State | Law | Effective | Must honor GPC |
|---|---|---|---|
| California | California Consumer Privacy Act, amended by the California Privacy Rights Act | Jan 1, 2020 (CPRA changes Jan 1, 2023) | Yes |
| Virginia | Consumer Data Protection Act | Jan 1, 2023 | No |
| Colorado | Colorado Privacy Act | Jul 1, 2023 | Yes |
| Connecticut | Connecticut Data Privacy Act | Jul 1, 2023 | Yes |
| Utah | Utah Consumer Privacy Act | Dec 31, 2023 | No |
| Texas | Texas Data Privacy and Security Act | Jul 1, 2024 | Yes |
| Florida | Florida Digital Bill of Rights (narrow scope) | Jul 1, 2024 | No |
| Oregon | Oregon Consumer Privacy Act | Jul 1, 2024 | Yes (since Jan 1, 2026) |
| Montana | Montana Consumer Data Privacy Act | Oct 1, 2024 | Yes |
| Nebraska | Nebraska Data Privacy Act | Jan 1, 2025 | Yes |
| Iowa | Iowa Consumer Data Protection Act | Jan 1, 2025 | No |
| Delaware | Delaware Personal Data Privacy Act | Jan 1, 2025 | Yes (since Jan 1, 2026) |
| New Hampshire | New Hampshire Privacy Act | Jan 1, 2025 | Yes |
| New Jersey | New Jersey Data Privacy Act | Jan 15, 2025 | Yes |
| Tennessee | Tennessee Information Protection Act | Jul 1, 2025 | No |
| Minnesota | Minnesota Consumer Data Privacy Act | Jul 31, 2025 | Yes |
| Maryland | Maryland Online Data Privacy Act | Oct 1, 2025 | Yes |
| Indiana | Indiana Consumer Data Protection Act | Jan 1, 2026 | No |
| Kentucky | Kentucky Consumer Data Protection Act | Jan 1, 2026 | No |
| Rhode Island | Data Transparency and Privacy Protection Act | Jan 1, 2026 | No |
| Oklahoma | Oklahoma Consumer Data Privacy Act | Jan 1, 2027 | No |
| Louisiana | Louisiana Data Privacy Act | Jan 1, 2027 | Yes (affirmative, non-default signal) |
| Alabama | Alabama Personal Data Protection Act | May 1, 2027 | Referenced, not a full duty |
| Vermont | Data Privacy and Online Surveillance Act | Jan 1, 2028 (disputed, see below) | Yes |
Twelve of the laws already in force require businesses to treat a browser opt-out signal as a valid request. That column matters more for marketers than any other, and the tracking section below explains why.
Laws Taking Effect in 2026, 2027 and 2028
The pace picked up after 2023. One law took effect in 2020 (California), none in 2021 or 2022, four in 2023, four in 2024 (including Florida), eight in 2025 and three in 2026. Three more start in 2027 and one in 2028.

What changed in 2026
- Indiana, Kentucky and Rhode Island took effect on January 1, 2026. Rhode Island stands out: no cure period, and its privacy notice rules apply to commercial websites regardless of the usual thresholds.
- Opt-out signals became mandatory in Oregon and Delaware on January 1, 2026.
- California’s new regulations on risk assessments, cybersecurity audits and automated decision-making technology took effect on January 1, 2026, with phased deadlines: ADMT rules apply from January 1, 2027, risk assessment attestations are due April 1, 2028, and audit certifications are due between April 1, 2028 and April 1, 2030 depending on revenue.
- California’s DROP platform went live in January 2026, letting residents send one deletion request to every registered data broker.
- Cure periods ran out in several states, including Delaware, Minnesota, New Hampshire, Oregon and New Jersey. Regulators there can now go straight to penalties.
What is coming
- Oklahoma (January 1, 2027): closely modeled on Virginia, 30-day cure period with no sunset, no duty to honor opt-out signals.
- Louisiana (January 1, 2027): Texas-style rights with a California-style threshold, so a company with more than $25 million in revenue can be covered regardless of how much Louisiana data it holds.
- Delaware amendments (January 1, 2027): lower thresholds, a broader sensitive data definition and new profiling duties.
- Alabama (May 1, 2027): low threshold, $15,000 maximum penalty per violation, and no data protection assessment requirement.
- Vermont (January 1, 2028): Connecticut-based, with low thresholds, neural data protections, a consumer health data section that applies at any size, and a right to learn which specific third parties bought your data.
Bills are also active in large states without a law, including New York, Pennsylvania, Massachusetts, Michigan, Illinois, Georgia and North Carolina. A federal law that would replace the patchwork has been proposed several times, most recently the American Privacy Rights Act of 2024, and has not passed.
Consumer Rights Under State Privacy Laws
The rights are close to identical across states. The differences sit in the edges: who can ask for a list of recipients, whether profiling is covered, and how long you have to answer.
| Right | Where it applies | Notable gaps |
|---|---|---|
| Confirm and access | All 24 | None |
| Correct inaccurate data | Nearly all | Iowa has no right to correct |
| Delete | All 24 | None |
| Data portability (a usable copy) | All 24 | None |
| Opt out of sale | All 24 | Indiana, Iowa, Kentucky, New Jersey, Utah and Virginia define “sale” as money only; most others include “other valuable consideration” |
| Opt out of targeted advertising | All 24 | Covers ads based on activity across other sites, not ads based only on activity on your own site |
| Opt out of profiling for significant decisions | Most | Iowa and Utah do not include it; Connecticut, Minnesota and Vermont add a right to question the result |
| List of specific third parties | Connecticut, Oregon, Delaware, Minnesota, Vermont | Maryland gives a list of categories instead |
| Appeal a refused request | Most | California, Utah and Alabama have no appeal right |
| No discrimination for using rights | All 24 | Loyalty programs allowed with proper notice |
Deadlines. Most states give 45 calendar days to answer, usually extendable once. Iowa allows 90 days. California requires opt-out and limit-use requests to be handled within 15 business days, and Rhode Island gives 15 days for consent revocations. Every state lets you verify the identity of the person asking before you hand over or delete data.
Business Obligations
If a law applies to you, expect these duties almost everywhere:
- Privacy notice. What categories of personal data you collect, why, who receives it, how consumers use their rights, and how to appeal. Several states add their own required statements.
- Data minimization and purpose limitation. Collect what is reasonably necessary for the purposes you disclosed and do not reuse it for unrelated purposes without consent. Maryland goes further: data must be strictly necessary for the product or service the consumer asked for, and sensitive data cannot be sold at all.
- Data protection assessments. Required before targeted advertising, selling data, processing sensitive data or risky profiling in nearly every state. Utah, Iowa and Alabama do not require them.
- Reasonable security for the data you hold.
- Processor contracts. Vendors that handle personal data for you need a written contract with specific terms. Without one, a transfer can be treated as a sale.
- Financial incentive notices. California and Colorado require detailed notices for loyalty programs and discounts tied to data.
Sensitive Data: Opt-In or Opt-Out
Sensitive data is where US state laws stop being opt-out laws. Most require opt-in consent before you process it. The exceptions: Utah and Iowa only require notice and an opt-out, California gives a right to limit its use, and Maryland allows it only when strictly necessary.
The core categories are the same everywhere: racial or ethnic origin, religious beliefs, health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data used to identify someone, data about a known child (under 13 in most states), and precise geolocation, typically within a 1,750-foot radius. Newer laws add neural data, transgender or nonbinary status, crime victim status, financial account numbers and government ID numbers. If your forms ask about health conditions, or your app collects precise location, check this list before anything else.
Who Has to Comply: Thresholds by State
Most laws apply to businesses that operate in the state or target its residents and cross a volume threshold, counted per year. California uses revenue instead; Texas and Nebraska use size.
| State | Covered if (per year) |
|---|---|
| California | Over $25M gross revenue, or buys, sells or shares data of 100,000+ residents or households, or 50%+ of revenue from selling data |
| Virginia, Indiana, Iowa, Kentucky, Oklahoma | 100,000+ consumers, or 25,000+ and over 50% of revenue from selling data |
| Colorado, New Jersey | 100,000+ consumers, or 25,000+ and any revenue or discount from selling data |
| Minnesota, Oregon | 100,000+ consumers, or 25,000+ and 25%+ of revenue from selling data |
| Utah | $25M+ revenue and 100,000+ consumers (or 25,000+ and over 50% from sales) |
| Tennessee | Over $25M revenue and 175,000+ consumers (or 25,000+ and over 50% from sales) |
| Connecticut | 35,000+ consumers, or any sale of personal data, or any sensitive data |
| Maryland, Rhode Island | 35,000+ consumers, or 10,000+ and over 20% of revenue from sales |
| New Hampshire | 35,000+ consumers, or 10,000+ and over 25% of revenue from sales |
| Delaware | 35,000+ consumers, or 10,000+ and over 20% from sales; from Jan 1, 2027: 10,000+, or 5,000+ and over 20% |
| Montana | 25,000+ consumers, or 15,000+ and over 25% of revenue from sales |
| Alabama | More than 25,000 consumers, or over 25% of revenue from sales |
| Vermont | 35,000+ consumers, or sensitive data of 3,000+, or sells data of 3,000+ |
| Louisiana | Over $25M revenue, or 75,000+ consumers, households or devices, or 50%+ of revenue from sales |
| Texas, Nebraska | Any business in the state that processes or sells personal data and is not a small business under SBA standards |
| Florida | Over $1B global revenue plus further conditions (ad revenue share, app store or smart speaker) |
Counts usually exclude data processed only to complete a payment. “Consumer” means a resident acting in a personal capacity in every state except California, which also covers employees, job applicants and B2B contacts. Exemptions vary: most states exempt financial institutions under GLBA entirely, while some exempt HIPAA-covered entities and others only the HIPAA data itself. Oregon also covers nonprofits.
Worked Example: Does a State Law Apply to Your Site?
Threshold lists are hard to apply until you put numbers in them. The key point most guides skip: these laws define personal data as information linked or reasonably linkable to a person, and a cookie ID or IP address tied to a device can qualify. If your analytics or ad tags collect those, your website visitors can count toward the thresholds, not just your customers.
| State | Your number | Threshold | Covered? |
|---|---|---|---|
| Virginia | 41,000 | 100,000, or 25,000 and over 50% of revenue from sales | No |
| Montana | 4,000 | 25,000, or 15,000 and over 25% from sales | No |
| California | $8M revenue; pixel shares data of 62,000 | $25M revenue, or sharing data of 100,000 | No, but close: at 100,000 residents the pixel alone triggers it |
| Connecticut | 12,000 | 35,000, or any sale of personal data | Depends on whether the pixel counts as a sale (broad definition) |
| Texas, Nebraska | Any | Not a small business | No while it stays a small business |
Two lessons from this one store. First, growth changes the answer without any new decision: 38,000 more California visitors whose data the pixel shares and the CCPA applies. Second, the ad pixel, not the analytics, is what pulls the business toward coverage in Connecticut and California, because both laws have prongs triggered by selling or sharing rather than by volume. Drop the pixel, or stop it from receiving visitor data, and those two prongs no longer apply; analytics run by a processor for your own measurement does not trigger them.
What These Laws Mean for Your Website Tracking
For a marketer, US state privacy laws come down to three tracking questions: is this tag a sale or targeted advertising, does it stop when a visitor opts out, and does the privacy notice describe it.
Which tags are affected
- Ad platform pixels and retargeting tags send visitor data to a company that uses it to target ads across other sites. That is the textbook case of “sharing” in California and of targeted advertising elsewhere, and in states with a broad sale definition it can be a sale.
- Session replay, chat widgets and some pixels are also the target of wiretapping lawsuits under the California Invasion of Privacy Act, a separate risk from the comprehensive laws.
- First-party analytics run by a vendor acting as your processor, used only to measure your own site, is generally neither a sale nor targeted advertising. It still needs to be disclosed in your notice, and it still collects personal data if it stores IP addresses or identifiers.
Global Privacy Control in practice
Global Privacy Control is a signal sent by browsers and extensions such as Brave, DuckDuckGo, Firefox and Privacy Badger. The California Attorney General’s CCPA page says covered businesses must honor it as a valid request to stop selling or sharing that visitor’s personal information, and that businesses that sell must also offer a clear “Do Not Sell or Share My Personal Information” link. The other states that require opt-out signals work the same way. In practice, your site reads the signal and switches off the tags that sell or share, while your own measurement keeps running.

What honoring opt-outs does to your conversion numbers
Every opted-out visitor who converts disappears from the ad platform’s reports, so platform-reported conversions and smart bidding see less than what happened. The arithmetic, with illustrative numbers:
| Visits | Conversions | Value at $120 each | |
|---|---|---|---|
| Everything that happened | 10,000 | 200 | $24,000 |
| Ad platform (10% of converters opted out) | 9,000 | 180 | $21,600 |
| First-party measurement on your site | 10,000 | 200 | $24,000 |
The 20 missing conversions and $2,400 did not vanish; the ad platform just cannot see them. Two consequences follow. Compare channels and landing pages on your first-party numbers, not on what each ad platform reports. And expect the gap to grow as more states require GPC and more browsers send it by default, so measure it now while you can set a baseline. Organic search and AI assistant traffic are the easiest to undercount here, since no ad platform reports them at all; our SEO conversion tracking guide shows how to tie those visits to conversions and revenue by landing page.
A cookieless, first-party setup keeps the measurement side simple under these laws. SEOConversion is built that way: no cookies, no PII, honors GPC and Do Not Track, and can run without a cookie banner in most of the US. See how cookieless tracking works and, for visitors outside the US, what cookie banners require.
Enforcement, Fines and Cure Periods
State attorneys general enforce every law except California’s, which is enforced by both the Attorney General and a dedicated agency, the California Privacy Protection Agency. None of the comprehensive laws lets consumers sue, with one exception: California allows private lawsuits after a data breach caused by poor security.
| State | Maximum civil penalty | Cure period |
|---|---|---|
| California | $2,500 per violation, $7,500 if intentional (before inflation adjustments) | None |
| Colorado | $20,000 per violation | Ended Jan 1, 2025 |
| Connecticut | $5,000 per violation | Ended Dec 31, 2024; now at the AG’s discretion |
| Virginia, Utah, Texas, Nebraska, Indiana, Kentucky, Oklahoma | $7,500 per violation | 30 days, no end date |
| Iowa | $7,500 per violation | 90 days |
| Tennessee | $7,500 per violation, tripled if willful | 60 days |
| New Jersey | $10,000 first violation, $20,000 after | Ended Jul 15, 2026 |
| Maryland | $10,000 per violation, $25,000 if repeated | Discretionary until Apr 1, 2027 |
| Delaware, New Hampshire, Rhode Island, Vermont | $10,000 per violation | DE and NH ended; RI never had one; VT 60 days until Jun 30, 2029 |
| Oregon, Montana, Minnesota | $7,500 per violation | Ended |
| Alabama | $15,000 per violation | 45 days |
| Louisiana | $5,000 per violation, plus up to $5,000 more for elderly or disabled victims | 30 days until Jul 31, 2027 |
Tennessee also offers an affirmative defense to companies whose privacy program follows the NIST Privacy Framework. Regulators’ recent focus, across states, has been honoring opt-out signals, opt-outs of selling and sharing, and the online tracking tools discussed above.
Federal Privacy Laws and Other State Laws
The comprehensive state laws sit on top of a federal system that regulates by sector. The main federal laws:
- HIPAA: health data held by providers, insurers and their business associates.
- GLBA: financial institutions.
- COPPA: online data from children under 13; the FTC finalized the first update to its rule since 2013 in January 2025.
- FCRA: credit reports and background checks.
- VPPA, TCPA, CAN-SPAM: video viewing records, calls and texts, and commercial email.
- FTC Act Section 5: the FTC acts against unfair or deceptive practices, including privacy policies that do not match reality.
- Privacy Act of 1974: records held by federal agencies, not private businesses.
States also have narrower laws that apply regardless of the comprehensive law thresholds: data breach notification in all 50 states, biometric laws (Illinois’ BIPA, the most litigated, plus Texas and Washington), consumer health data laws (Washington’s My Health My Data Act, Nevada, Connecticut), children’s codes in California and Maryland, and California’s Delete Act for data brokers. A small business under every comprehensive threshold can still be caught by these.
Which State Has the Strongest Privacy Law?
“Best” depends on which protection you value most. Judged on specific criteria:
| Criterion | Strongest | Why |
|---|---|---|
| Breadth of who is protected | California | Only law covering employees, job applicants and B2B contacts |
| Enforcement | California | Dedicated agency plus a private right of action for breaches |
| Limits on collection | Maryland | Strictly necessary standard; ban on selling sensitive data |
| Reach to small businesses | Vermont (2028), Texas, Nebraska | Very low or no numeric thresholds |
| Penalty per violation | Colorado | Up to $20,000 |
| Weakest overall | Utah, Iowa | High thresholds, no assessments, no profiling opt-out |
Where the Sources Disagree
Read three trackers and you will find three different answers on a few points. Here is what is going on.
- The count. Some say 19 states, some 20, some 23 or 24. The difference is whether they include Florida and whether they count laws signed but not yet effective. Our numbers: 19 broad laws in force, 20 with Florida, 24 enacted.
- Vermont’s effective date. One law library guide lists July 1, 2026, while two other trackers give January 1, 2028 and report that the governor signed the final version on June 16, 2026, after vetoing a stricter bill in 2024. A law signed in mid-June 2026 taking effect two weeks later would be unusual, so January 1, 2028 is the more likely date. Check the act before planning around it.
- Cure periods. Trackers updated at different times show cure periods that have since expired, for example in New Jersey (July 15, 2026) and Minnesota (January 31, 2026). Assume no cure period unless the statute gives one with no end date.
Compliance Checklist: 7 Steps for a Website
- Count residents per state. Pull a year of visitors, customers and leads by state from analytics and your CRM. Note whether you collect IP addresses or cookie IDs.
- Compare to each threshold. Use the thresholds table, then check the prongs that apply at any volume: selling data (Connecticut), sensitive data (Connecticut, Vermont) and size-based laws (Texas, Nebraska).
- List what leaves your site. Every tag, pixel and vendor that receives personal data, and whether it is a processor under contract or a third party using the data for itself.
- Honor opt-outs and GPC. If you sell or share, add the opt-out link and make ad pixels stop for visitors who opt out or send GPC. Test it in a browser that sends the signal.
- Update the privacy notice. Categories, purposes, recipients, rights, how to exercise them and how to appeal.
- Set up request handling. An intake form or email, identity verification, a 45-day clock and an appeal path.
- Assess high-risk processing. Document a data protection assessment before targeted advertising, selling data, sensitive data or significant profiling.
FAQ
Which states will have privacy laws in 2026?
Three comprehensive laws took effect on January 1, 2026: Indiana, Kentucky and Rhode Island. They join the 16 broad laws already in force, for 19 in total, plus Florida’s narrow law. Oklahoma and Louisiana follow on January 1, 2027, Alabama on May 1, 2027 and Vermont on January 1, 2028.
Which states have passed privacy laws?
Twenty-four states have passed a comprehensive consumer privacy law: Alabama, California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Louisiana, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oklahoma, Oregon, Rhode Island, Tennessee, Texas, Utah, Vermont and Virginia. Every state also has narrower privacy laws, such as data breach notification rules.
What US state has the best privacy laws?
California has the broadest law: it covers employee and B2B data, has a dedicated privacy agency and gives consumers a private right of action after certain data breaches. Maryland has the strictest data minimization rule and bans the sale of sensitive data. Vermont’s law, once in force, will cover many smaller businesses because of its low thresholds.
What are the main privacy laws in the United States?
At the federal level, sector laws: HIPAA for health data, GLBA for financial institutions, COPPA for children under 13, FCRA for credit reports, and the FTC Act against unfair or deceptive practices. At the state level, the comprehensive laws led by the CCPA, plus biometric laws like Illinois’ BIPA, health data laws like Washington’s My Health My Data Act, and breach notification laws in every state.
How many US state privacy laws are there?
It depends on what you count. Twenty-four states have enacted a comprehensive consumer privacy law, 19 broad ones are in effect as of October 2026, and Florida’s narrow law makes 20. Counting sector laws on biometrics, health data, children and breach notification, there are hundreds of state privacy statutes.
What are the 7 types of privacy?
The best known list comes from Rachel Finn, David Wright and Michael Friedewald (2013): privacy of the person, of behavior and action, of communication, of data and image, of thoughts and feelings, of location and space, and of association. It is an academic framework, not a legal one. US state laws mainly protect the fourth type, data, with extra rules for location and health.
Keep measuring conversions while you honor opt-outs.
SEOConversion is a cookieless, PII-free, first-party tracker that honors GPC and DNT and reports conversions and revenue from organic and AI search by landing page.
Start free