State Privacy Laws 2026: Three Took Effect in January, Four More Were Signed, and 27 States Still Have None

On January 1, 2026, three states switched on new comprehensive privacy laws at once: the Kentucky Consumer Data Protection Act (KCDPA), the Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) and the Indiana Consumer Data Protection Act (ICDPA). That was the biggest single-day change to the state privacy laws 2026 map, and it brought the count of states with a law in force to twenty. Then the 2026 sessions added four more on paper (Oklahoma, Alabama, Louisiana and Vermont), none of them in effect before 2027. "Comprehensive privacy law" isn't a single standard, though. These laws differ from one another in ways that change what you can do and who has to listen, and if you live in Kentucky, Rhode Island or Indiana, the fine print matters more than the headline. If you live somewhere else, the full state list further down answers the question most people came here with.

State privacy laws 2026: what rights you actually get

All three January laws hand residents the same baseline: the right to confirm whether a company is processing your personal data, to access it, to correct it, to delete it, and to get a portable copy. All three also give you opt-out rights. You can tell a company to stop using your data for targeted advertising, to stop selling it and, with some variation by state, to stop running it through automated profiling. Rhode Island adds a clock: once you revoke consent, the company has 15 days to stop processing.

Rhode Island goes a step further on transparency. Most opt-out laws give you a switch to flip: you object, the company is supposed to stop. RIDTPPA's disclosure section, R.I. Gen. Laws § 6-48.1-3, also requires a business to "identify all third parties to whom the controller has sold or may sell" your personal information. That turns "you can opt out of sale" into "you can find out who's buying you." Kentucky and Indiana have no equivalent. They require data-processing agreements with third parties, which you never see.

The thresholds are not the same, and that matters

None of these laws applies to every company that touches your data. Each sets a size threshold, and the three states drew the line in different places.

The Kentucky Consumer Data Protection Act and the Indiana Consumer Data Protection Act apply to a business that operates in the state and either processes personal data on at least 100,000 residents a year, or processes data on at least 25,000 residents while earning more than 50% of its gross revenue from selling personal data, per Koley Jessen's comparison of the three statutes. That second bracket is aimed at data brokers, companies whose product is you rather than companies that collect your data as a side effect of something else.

Rhode Island set a lower bar: 35,000 consumers, or 10,000 consumers if more than 20% of gross revenue comes from selling personal data. A mid-size broker that clears 20% of revenue from data sales and touches 10,000 Rhode Islanders is covered by RIDTPPA. The same company might sit under Kentucky's or Indiana's threshold entirely. Whether a specific broker legally has to honour your request depends on your state and on that company's size and revenue mix, not just on whether your state has a law.

Sensitive data needs your yes, not just your non-objection

All three states single out sensitive data and require opt-in consent before a company can process it. The category covers racial or ethnic origin, religious beliefs, mental or physical health conditions, sexual orientation, citizenship or immigration status, genetic and biometric data, precise geolocation, and data collected from a known child.

The distinction sounds procedural, but it flips the default. For ordinary personal data a company can start using your information and you have to notice and object. For sensitive data the company has to get your affirmative yes first. That is the strongest lever these laws hand you, because it puts the burden of asking on the business.

Enforcement: the part that decides whether any of this bites

This is where the three laws differ most.

The attorney general enforces in all three states, and none of the three creates a private right of action. If a company blows off your deletion request or keeps selling your data after you opt out, you cannot sue it under these statutes. Only the AG can act. Your practical recourse is a complaint to the AG's office and the hope that it is worth their time. Kentucky at least built the front door: the AG's Office of Data Privacy takes complaints through an online form once a company has denied your appeal or ignored your request.

Kentucky and Indiana give businesses a 30-day right to cure: if you or the AG catch a violation, the company gets a 30-day warning window to fix it before any penalty attaches. Rhode Island included no cure period, so a violation can be penalised immediately. When penalties land they are up to $7,500 per violation in Indiana and Kentucky and up to $10,000 per violation in Rhode Island, where the act deems each violation a deceptive trade practice and the penalty lives in that law rather than the privacy statute. Per-violation fines enforced entirely through an AG's office, with a grace period in two of the three states and no direct legal path for the consumer in any of them, are a much weaker deterrent than a law individuals can enforce themselves, which is one of the two disputes that have killed every federal bill.

State privacy laws 2026: the four signed this year, and when they start

The 2026 sessions were the busiest since the Virginia template started spreading in 2021. As of September 14, 2026:

  • Oklahoma went first. Governor Stitt signed SB 546 on March 20, 2026, and it takes effect January 1, 2027.
  • Alabama's HB 351 was signed on April 17, 2026, making it the 21st state. Effective May 1, 2027.
  • Louisiana's SB 386, the Louisiana Data Privacy Act, was signed by Governor Landry on May 29, 2026. It starts January 1, 2027, and unlike the other three it borrows California's thresholds rather than Virginia's: $25 million in revenue, or 75,000 consumers, or half of revenue from selling personal information.
  • Vermont signed S.71 on June 16, 2026, the same day Governor Scott signed H.211, which overhauls the state's separate data broker registry law with a $900 registration fee, a $20,000 surety bond and a deletion-on-request duty from January 1, 2027. The comprehensive act itself waits until January 1, 2028.

That makes 23 states with a comprehensive privacy law enacted, counting the way the law firms count: Oklahoma was the 20th, Alabama the 21st, Louisiana the 22nd and Vermont the 23rd. You will also see 24, from trackers that include Florida's 2023 law, which MultiState describes as having "a narrower scope than other state privacy laws." Twenty are in force today on MultiState's count, which includes Florida, so 19 if you leave it out.

Two more changes this year don't add a state but do change what a state gives you. Connecticut amended its existing law, adding a data broker registry and an eventual one-stop deletion tool on a timeline that stretches to 2028. And on September 2, 2026, Delaware's governor signed HB 380 and HB 381, which from January 1, 2027 drop the state's applicability threshold to 10,000 consumers, the lowest in the country, and bar the sale of sensitive data unless it is strictly necessary for the product you asked for. Massachusetts is the one to watch next: its Consumer Data Privacy Act passed the Senate 40-0 in September 2025 and the House 146-0 on June 4, 2026, but the two versions differ and the bill has sat in a conference committee since June 17. Nothing has been signed.

State by state: the one thing that sets each of the newest laws apart

The table flattens 23 statutes into seven columns. These are the details that don't fit in a cell but change what a resident can do.

Indiana

The plainest Virginia copy of the three January laws, with a cure period that never expires: the attorney general must give a company 30 days' written notice before suing, every time, under IC 24-15-10-3. The act also says its assessment duties are "not retroactive to any processing activities created or generated before January 1, 2026," so a broker's existing files were never reviewed under it.

Kentucky

Kentucky built the complaint desk before the law switched on. The attorney general's Office of Data Privacy publishes a phone number and a named contact next to its complaint form. No other state in the 2026 cohort does.

Rhode Island

The shortest of the three and the oddest. It has no cure period, and its violations section routes penalties through the state's deceptive trade practices act rather than setting its own, apart from one specific fine: $100 to $500 per disclosure for a company that hands your data to "a shell company or any entity that has been formed or established solely, or in part, for the purposes of circumventing" the law. Section 6-48.1-6 gives you the standard 45-day response clock and a 60-day appeal.

Oklahoma

A near line-for-line Virginia copy, with a 30-day cure that never sunsets, a $7,500 cap, and no duty to honor opt-out signals. Until January 1, 2027 a broker can decline an Oklahoman's deletion request and be within the law.

Alabama

Alabama's second threshold has no head count: a company earning more than 25% of its revenue from selling personal data is covered however small it is, per HB 351. The penalty cap is $15,000 per violation, twice the Virginia-model figure, and a company gets 45 days after you revoke consent to stop processing. There is no appeal right.

Louisiana

California's thresholds with Texas's opt-out mechanics. Act 502 lets you designate "a technology, including a link to a website, an internet browser setting or extension, or a global setting on an electronic device" as your agent to opt out. Its 30-day cure runs for seven months only, and the act reaches only companies that do business in the state, not every company that markets to Louisianans.

Vermont

The strictest of the four and the last to start. It pulls in any company that sells personal data on 3,000 residents, requires the privacy notice to say whether the company uses your data "for the purpose of training large language models," and makes a controller list "all third parties to which such controller has sold personal data" on request, per Act 145. The act's own findings say the attorney general "will bear the burden of enforcing the Act," because Vermont, like every other state, declined to let residents sue.

How to exercise your rights under a state privacy law

The mechanics are close to identical across the 19 states in force because they all descend from the same two drafts. This walk-through cites Virginia's § 59.1-577, the template most of the others copied, with exceptions noted.

  1. Find the request route in the privacy notice. Every one of these laws requires the notice to describe the "secure and reliable means" for submitting a request, in Montana's wording. On people-search sites the link is usually in the footer under "Do Not Sell" or "Privacy Center," and when we screenshot these flows the form is often two clicks deeper, behind a search for your own listing.
  2. Say which right you're using and which state you live in. Residency is what triggers the law.
  3. Expect verification for deletion and access. A company can ask for "additional information reasonably necessary to authenticate" you. Opt-outs are different: Montana's statute says a controller "may not be required to authenticate an opt-out request," so a demand for ID before an opt-out is a stalling tactic.
  4. Start a 45-day clock. The company must respond "without undue delay, but in all cases within 45 days," extendable once by 45 more if it tells you why inside the first window. Iowa's clock is 90 days. The response is free up to twice a year.
  5. If the answer is no, appeal. A refusal must come with "instructions for how to appeal," and the company then has 60 days to answer the appeal in writing with reasons.
  6. If the appeal fails, go to the attorney general. The denial must include a way to reach the AG. Kentucky, Oregon and Montana run online complaint forms, and Nebraska's § 87-1120 requires one. Attach the request, the refusal and the appeal decision, with dates.
  7. Know what comes back. The AG may or may not act, and any penalty goes to the state, "into the state treasury" in Virginia's words. The value of the complaint is the record it creates.

Which states have privacy laws in 2026: the US state privacy law list

If you just want to know which states have privacy laws, here is the list as of September 14, 2026.

In force now, 19 states: California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia. Florida's narrower 2023 law makes it 20 on most trackers.

Signed but not yet in force, 4 states: Oklahoma and Louisiana (January 1, 2027), Alabama (May 1, 2027) and Vermont (January 1, 2028).

No comprehensive privacy law, 27 states: Alaska, Arizona, Arkansas, Florida (see above), Georgia, Hawaii, Idaho, Illinois, Kansas, Maine, Massachusetts (in conference), Michigan, Mississippi, Missouri, Nevada, New Mexico, New York, North Carolina, North Dakota, Ohio, Pennsylvania, South Carolina, South Dakota, Washington, West Virginia, Wisconsin and Wyoming.

State privacy law comparison: all 23 enacted laws in one table, plus Florida

Trackers disagree on the count for two reasons, and both show up here. Some include Florida, whose 2023 law reaches only companies with more than $1 billion in global revenue, and some count laws that are signed but not yet binding. Every row comes from the statute text or the state attorney general's page, apart from Alabama's signal column, which relies on a law firm's reading of the enrolled bill. Thresholds read as the number of residents whose data a company handles in a year, or a smaller number plus the share of revenue it earns from selling data. The last column says whether a business has to treat a browser signal such as Global Privacy Control as a valid opt-out.

State Law In force since Threshold Cure period Enforced by Honors opt-out signals
California CCPA Jan 1, 2020 $25M revenue, or 100,000 residents or households, or 50% of revenue from selling or sharing data None. § 1798.155: $2,500 to $7,500 per violation AG and CPPA. Consumers can sue over a breach only, up to $750 Yes
Virginia VCDPA Jan 1, 2023 100,000, or 25,000 + over 50% 30 days, permanent AG No
Colorado CPA July 1, 2023 100,000, or 25,000 + any revenue or discount from sales 60 days, ended Jan 1, 2025 AG and district attorneys Yes, since July 1, 2024
Connecticut CTDPA July 1, 2023 35,000, or any sensitive data, or any data sale 60 days, ended Dec 31, 2024 AG Yes, since Jan 1, 2025
Utah UCPA Dec 31, 2023 $25M revenue and 100,000, or 25,000 + over 50% 30 days, permanent Consumer Protection division, then AG No
Texas TDPSA July 1, 2024 Any business above the SBA's small-business line. No head count 30 days, permanent AG Yes, since Jan 1, 2025, as a technology acting as your agent
Oregon OCPA July 1, 2024 100,000, or 25,000 + 25% 30 days, ended Jan 1, 2026 DOJ Yes, since Jan 1, 2026
Montana MCDPA Oct 1, 2024 25,000, or 15,000 + over 25% None AG Yes, since Jan 1, 2025
Iowa Ch. 715D Jan 1, 2025 100,000, or 25,000 + over 50% 90 days, permanent AG No
Delaware DPDPA Jan 1, 2025 35,000, or 10,000 + over 20% (10,000 flat from Jan 1, 2027) 60 days, ended Dec 31, 2025 DOJ Yes, since Jan 1, 2026
Nebraska NDPA Jan 1, 2025 Any non-small business, Texas model 30 days, permanent AG Yes, Texas-style
New Hampshire RSA 507-H Jan 1, 2025 35,000, or 10,000 + over 25% 60 days, ended Dec 31, 2025 AG Yes, since Jan 1, 2025
New Jersey P.L. 2023, c. 266 Jan 15, 2025 100,000, or 25,000 + any revenue or discount from sales 30 days, ends 18 months after effect Division of Consumer Affairs Yes, from July 2025
Tennessee TIPA July 1, 2025 $25M revenue and 175,000, or 25,000 + over 50% 60 days, permanent AG No
Minnesota MCDPA July 31, 2025 100,000, or 25,000 + over 25% 30 days, ended Jan 31, 2026 AG Yes
Maryland MODPA Oct 1, 2025 35,000, or 10,000 + over 20% 60 days, for violations through April 1, 2027 Consumer Protection division Yes
Indiana ICDPA Jan 1, 2026 100,000, or 25,000 + over 50% 30 days, permanent AG No
Kentucky KCDPA Jan 1, 2026 100,000, or 25,000 + over 50% 30 days, permanent AG No
Rhode Island RIDTPPA Jan 1, 2026 35,000, or 10,000 + over 20% None AG No
Oklahoma SB 546 Jan 1, 2027 100,000, or 25,000 + over 50% 30 days, permanent AG No
Alabama HB 351 May 1, 2027 Over 25,000, or over 25% from data sales at any size 45 days, permanent AG Not required
Louisiana Act 502 Jan 1, 2027 $25M revenue, or 75,000 consumers, households or devices, or 50% from data sales 30 days, Jan 1 to July 31, 2027 AG Yes, Texas-style
Vermont Act 145 Jan 1, 2028 35,000, or sensitive data on 3,000, or sells data on 3,000 60 days, Jan 1, 2028 to June 30, 2029 AG Yes
Florida (not counted) FDBR July 1, 2024 $1B global revenue plus an ad business, a smart speaker or a 250,000-app store 45 days, discretionary Dept. of Legal Affairs No

Two things the table shows that the headline count hides. The right to sue exists in one state, California, and there only for a breach. And the cure period, the warning window a company gets before any penalty, has already expired in seven of the 19 states in force, is permanent in eight, still runs in one (Maryland, to April 2027), and never existed in three. If you're comparing states by how much their law bites, that column and the last one tell you more than the effective date does.

Does my state have a privacy law? Washington, New York and the other 27

Twenty-seven states have no comprehensive consumer privacy law enacted at all (26 if you count Florida), and 30 have none in force: no statutory right to make a data broker delete your information, no mandated opt-out mechanism, and no attorney general with a legal duty to act on your behalf.

Two big ones surprise people. Washington state privacy law is a health-data law, the My Health My Data Act, which covers health information that HIPAA doesn't reach and comes with a right to sue. It is not a general privacy law, and Washington's comprehensive bill has stalled in the legislature three sessions running. New York state privacy laws are a similar story: the SHIELD Act covers breach notification and security, the New York Privacy Act has never passed both chambers, and the Health Information Privacy Act that did pass was vetoed in December 2025 and reintroduced in 2026. Illinois has BIPA for biometrics and nothing broader.

In those states a data broker's decision to remove your listing is a courtesy. Most people-search sites honour opt-outs anyway, because it is less hassle than refusing and because they also serve customers in covered states. Some don't, and they say so. In the BBB complaints we read for our FastBackgroundCheck guide, the site's automated denials tell requesters they live "in a state that does not have a comprehensive consumer privacy law that applies to our data," and one complainant said the company "refused because they are not required by Michigan law." Appeals citing a safety concern, and BBB complaints, got those listings removed. The law didn't. On the other side of the line, having a right to delete changes what you can ask for: PeopleConnect's Privacy Center offers a deletion route in addition to its standard suppression tool, but only where a state law gives you the right, and suppression alone leaves the underlying record in place. That 19-versus-31 split is the difference between a right you can enforce and a favour you can ask for.

What you can still use in a state with no privacy law

Four tools work in all 50 states.

  • The Fair Credit Reporting Act covers any company that sells reports for employment, tenant or insurance screening. The CFPB's list of consumer reporting companies includes employment and tenant screeners, and each owes you a free copy of your file and a free investigation of anything you dispute. A background-check site that sells to employers is on the hook here even if it ignores privacy-law requests.
  • CAN-SPAM makes every commercial emailer honor an unsubscribe within 10 business days, at up to $53,088 per email that breaks the rule.
  • The people-search sites' own opt-out forms, which most run voluntarily. Our opt-out guides walk through each with screenshots.
  • California's DROP, if you live in California now. The Delete Act platform verifies residency before it accepts a profile, so a past California address alone does not qualify you. If you do qualify, the ZIP codes and phone numbers you submit can be from anywhere you have lived, and the registered brokers must match against all of them.

Frequently asked questions

Does Texas have a privacy law?

Yes. The Texas Data Privacy and Security Act has been in force since July 1, 2024 and has no head count: it covers any company doing business in Texas that is not a small business under the SBA's definition, per HB 4. Since January 1, 2025 a browser setting can act as your agent to opt out. The attorney general enforces, with a permanent 30-day cure period and no right to sue.

Does Virginia have a privacy law?

Virginia's Consumer Data Protection Act took effect on January 1, 2023 and is the template Indiana, Kentucky, Oklahoma and most others copied. It covers companies handling data on 100,000 Virginians, or 25,000 if selling data is over half their revenue, under § 59.1-576, with a permanent 30-day cure period and no duty to honor browser opt-out signals.

Do small businesses have to follow state privacy laws?

Usually no. Most states start at 100,000 residents' data, or 25,000 plus a data-sales revenue share, and Utah and Tennessee add a $25 million revenue floor. The exceptions matter for data brokers: Texas and Nebraska cover every non-small business, Alabama will cover any company earning over 25% of revenue from selling data, and Connecticut now covers anyone who sells personal data at all, per the attorney general's summary.

Can I sue a company under my state's privacy law?

In 22 of the 23 states, no. Each statute says it does not create a private right of action, and enforcement belongs to the attorney general. California is the exception, and only partly: the attorney general's guidance says you can sue a business "only if there is a data breach," for up to $750 per incident, after giving it 30 days' notice.

Does my browser's Global Privacy Control opt me out automatically?

Only where the law says a business has to listen. Twelve of the 19 states in force require it. Virginia, Utah, Iowa, Tennessee, Indiana, Kentucky and Rhode Island do not. Colorado's attorney general publishes the list of recognised signals. GPC also covers only sale and targeted advertising, so it never deletes anything.

Where Delist My Data fits

We're still pre-launch and building this out. The point of Delist My Data is to do the removal work site by site, regardless of which of these laws covers you, because data brokers move faster than state legislatures do. If that's useful to you, join the waitlist for founding-member access.

Sources

Sources

Find out which brokers are publishing your details.

No spam. One email when Delist My Data opens for your area.