US state privacy laws

Every US state privacy law,
with the dates that matter.

The United States has no general federal privacy law, so states have filled the gap. This tracker lists every comprehensive state privacy law in force or enacted as of October 2026, who each one applies to, and which require you to honour Global Privacy Control. A summary for planning, not legal advice.

19 in force4 enacted in 202612 require opt-out signalsChecked 6 October 2026

Last updated Published by TryTrustableNot legal advice

Short answer

As of October 2026, 19 US states have a comprehensive consumer privacy law in force: California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Hampshire, Nebraska, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island. Four more were enacted in 2026 and take effect later: Oklahoma and Louisiana on 1 January 2027, Alabama on 1 May 2027 and Vermont on 1 January 2028. Florida has a narrower law aimed at very large companies. Twelve of the laws in force require businesses to honour browser opt-out signals such as Global Privacy Control.

01

Which US states have comprehensive privacy laws?

A comprehensive privacy law covers personal data across industries, rather than one sector such as health or children. The table below lists all of them. Counts you see elsewhere range from 19 to 24 depending on whether Florida is included and whether laws not yet in force are counted.

StateLawIn force fromApplies to (per year, state residents)Opt-out signals (GPC)
CaliforniaCCPA, as amended by the CPRA1 Jan 2020 (CPRA: 1 Jan 2023)Revenue over $26,625,000; or buys, sells or shares data of 100,000+ consumers or households; or 50%+ of revenue from selling or sharingYes
VirginiaConsumer Data Protection Act1 Jan 2023100,000+ consumers; or 25,000+ and over 50% of revenue from saleNo
ColoradoColorado Privacy Act1 Jul 2023100,000+ consumers; or 25,000+ and any revenue or discount from saleYes, from 1 Jul 2024
ConnecticutData Privacy Act1 Jul 2023From 1 Jul 2026: 35,000+ consumers; or any sensitive data; or offers personal data for saleYes, from 1 Jan 2025
UtahConsumer Privacy Act31 Dec 2023Revenue of $25M+ and either 100,000+ consumers, or 25,000+ and over 50% of revenue from saleNo
TexasData Privacy and Security Act1 Jul 2024No volume test: anyone doing business in Texas that processes or sells personal data and is not a small business by SBA standards (small businesses still need consent to sell sensitive data)Yes, from 1 Jan 2025
OregonConsumer Privacy Act1 Jul 2024 (nonprofits 1 Jul 2025)100,000+ consumers; or 25,000+ and 25%+ of revenue from saleYes, from 1 Jan 2026
MontanaConsumer Data Privacy Act1 Oct 2024From 1 Oct 2025: 25,000+ consumers; or 15,000+ and 25%+ of revenue from saleYes, from 1 Jan 2025
IowaConsumer Data Protection Act1 Jan 2025100,000+ consumers; or 25,000+ and over 50% of revenue from saleNo
DelawarePersonal Data Privacy Act1 Jan 202535,000+ consumers; or 10,000+ and over 20% of revenue from saleYes, from 1 Jan 2026
New HampshireSB 255 (consumer data privacy)1 Jan 202535,000+ consumers; or 10,000+ and over 25% of revenue from saleYes
NebraskaData Privacy Act1 Jan 2025No volume test; SBA small businesses exempt (as in Texas)Yes
New JerseyData Privacy Act15 Jan 2025100,000+ consumers; or 25,000+ and any revenue or discount from saleYes, from 15 Jul 2025
TennesseeInformation Protection Act1 Jul 2025Revenue over $25M and either 175,000+ consumers, or 25,000+ and over 50% of revenue from saleNo
MinnesotaConsumer Data Privacy Act31 Jul 2025100,000+ consumers; or 25,000+ and over 25% of revenue from saleYes
MarylandOnline Data Privacy Act1 Oct 2025 (processing from 1 Apr 2026)35,000+ consumers; or 10,000+ and over 20% of revenue from saleYes
IndianaConsumer Data Protection Act1 Jan 2026100,000+ consumers; or 25,000+ and over 50% of revenue from saleNo
KentuckyConsumer Data Protection Act1 Jan 2026100,000+ consumers; or 25,000+ and over 50% of revenue from saleNo
Rhode IslandData Transparency and Privacy Protection Act1 Jan 202635,000+ consumers; or 10,000+ and over 20% of revenue from saleNo
OklahomaSB 546 (signed 20 Mar 2026)1 Jan 2027100,000+ consumers; or 25,000+ and over 50% of revenue from saleNo
LouisianaLouisiana Data Privacy Act, SB 386 (signed 29 May 2026)1 Jan 2027Revenue over $25M; or 75,000+ consumers, households or devices; or 50%+ of revenue from sellingUnclear: commentators read the text differently
AlabamaPersonal Data Protection Act, HB 351 (signed Apr 2026)1 May 2027More than 25,000 consumers; or more than 25% of revenue from sale; employers under 500 staff exempt unless they sell dataNo standalone duty
VermontData Privacy and Online Surveillance Act, S.71 (signed 16 Jun 2026)1 Jan 202835,000+ consumers; or sensitive data of 3,000+; or sells data of 3,000+Yes

Most counts exclude data processed only to complete a payment. Florida's Digital Bill of Rights (1 Jul 2024) reaches only businesses with over $1 billion in revenue that meet further tests. A summary, not legal advice: check each statute before relying on a threshold.

02

What the state laws have in common

Apart from California, the laws follow a shared model first used in Virginia. If you build for that model once, most states become a matter of thresholds and dates.

  • Rights: access, correction, deletion, portability, and opt-out of sale, targeted advertising and profiling for significant decisions. Most give 45 days to respond, extendable once.
  • Sensitive data: opt-in consent before processing health, biometric, precise location, children's and similar data in almost every state (California, Utah and Iowa use notice and opt-out instead).
  • Notice: a privacy notice listing categories, purposes, recipients and how to use the rights, plus an appeal process if a request is refused.
  • Data protection assessments for targeted advertising, sale, sensitive data and risky profiling. A DPIA built for GDPR usually covers the substance.
  • Processor contracts with instructions, confidentiality, deletion and audit terms.
  • Enforcement by the state Attorney General only (California also has its privacy agency), with no private right of action and, in many states, a cure period before action.
03

Where they differ

  • Thresholds. From no volume test at all (Texas, Nebraska) to 175,000 consumers plus $25 million in revenue (Tennessee). The trend is downward: Connecticut and Montana both lowered theirs.
  • Opt-out signals. Twelve states require you to honour them; the rest do not. See below.
  • Data minimisation. Maryland limits the collection of sensitive data to what is strictly necessary for the product a consumer asked for, and bans its sale outright. Vermont, from 2028, adds its own minimisation rule.
  • Cure periods. Some have expired, some sunset, some (Alabama) do not end.
  • Exemptions. Most exempt data or entities covered by HIPAA and the Gramm-Leach-Bliley Act; some exempt nonprofits and universities, others do not.
04

Which states require Global Privacy Control?

Twelve states require businesses to treat a browser opt-out preference signal, which in practice means Global Privacy Control, as a valid request to opt out of sale and targeted advertising: California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon and Texas. Vermont joins in 2028. Louisiana's new law is read differently by different commentators, so plan to honour the signal there too. Because you cannot tell reliably which state a browser is in, most businesses honour GPC for every US visitor.

05

Upcoming dates in 2026 to 2028

DateWhat starts
1 Jan 2026Indiana, Kentucky and Rhode Island in force; Oregon and Delaware opt-out signals; California's new regulations (risk assessments, audits, signal status display)
1 Apr 2026Maryland's law applies to processing activities
1 Jul 2026Connecticut's lower thresholds and wider scope
1 Jan 2027Oklahoma and Louisiana in force; California ADMT rules; California browsers must offer an opt-out signal
1 May 2027Alabama in force
1 Jan 2028Vermont in force
06

How to comply with many state laws at once

  1. Count residents per state and test each threshold yearly. The low thresholds (25,000 in Montana and Alabama, 35,000 in Connecticut, Delaware, Maryland, New Hampshire, Rhode Island and Vermont) catch mid-sized companies.
  2. Pick the strictest common denominator: one rights process, one appeal route, opt-in for sensitive data, and GPC honoured nationally.
  3. Write one privacy notice with state-specific sections where the laws demand them. The privacy policy generator is a starting point.
  4. Run data protection assessments for advertising, sale and sensitive data, and keep them ready for an Attorney General's request.
  5. Update processor contracts once, to the strictest terms. See vendor risk management.
  6. Track the calendar. New laws and amendments arrive every legislative session.
07

How TryTrustable helps with US state privacy

The consent platform applies a US opt-out regime per visitor, reads Global Privacy Control from the browser and records the opt-out, with the reason, in a tamper-evident ledger. A privacy-request link on the banner feeds a request queue with deadlines set by request type. US state privacy requirements are modelled in the shared control library alongside GDPR and SOC 2, so one control and one piece of evidence count everywhere they apply. See consent management and framework coverage. Deciding which laws apply to you remains a legal judgement.

Questions

The things people ask us

How many US states have privacy laws in 2026?

Nineteen states have a comprehensive privacy law in force as of October 2026. Four more (Oklahoma, Louisiana, Alabama and Vermont) were enacted in 2026 and take effect in 2027 or 2028. Florida has a narrower law for very large companies.

Is there a federal privacy law in the US?

No general one. Federal laws cover specific sectors and groups, such as HIPAA for health data, GLBA for financial institutions and COPPA for children under 13. Consumer privacy in general is left to the states.

Do state privacy laws apply to companies outside the state?

Yes. Each law applies to businesses that do business in the state or target its residents and meet its threshold, wherever the business is based.

What is the Colorado Privacy Act threshold?

Controlling or processing the personal data of 100,000 or more Colorado consumers a year, or 25,000 or more while earning revenue or a discount from selling personal data. It has required honouring universal opt-out signals since 1 July 2024.

Does the Texas Data Privacy and Security Act have a revenue threshold?

No. It applies to anyone doing business in Texas who processes or sells personal data, unless they are a small business as defined by the US Small Business Administration. Even small businesses need consent before selling sensitive data.

Which state privacy laws take effect in 2027?

Oklahoma and Louisiana on 1 January 2027 and Alabama on 1 May 2027. Vermont follows on 1 January 2028.

Do state privacy laws apply to employee data?

Of the laws in force, only California's. The others exclude people acting in an employment or commercial (B2B) context.

Book a walkthrough

One consent setup for every US state.

Thirty minutes: we scan your site with Global Privacy Control on, show which states' rules you trigger, and walk through the opt-out ledger and request queue.