All Blog Posts

U.S. State Privacy Laws: Compliance Thresholds, Requirements, Rights, and Enforcement

Close
Read time
7 mins
Updated
Aug 18, 2026
Share
  • More than twenty U.S. states now have their own comprehensive privacy law, with no federal law to unify them.
  • Nearly all follow the same core pattern: opt-out consent, a privacy notice, and rights to know, access, correct, delete, and port personal data.
  • Compliance thresholds vary widely, and several recent laws drop the revenue floor entirely, so traffic volume alone can trigger obligations.
  • Most states offer a right to cure a violation before facing penalties, but several of these grace periods sunset in 2026.
  • A growing number of states require recognition of Global Privacy Control or other opt-out signals, though the requirement isn't universal and some versions of it are set to expire.
  • California is the only state with its own dedicated privacy agency (CalPrivacy) and a private right of action for data breaches.

There's no single federal privacy law in the U.S. Instead, more than twenty states have passed their own, and that number keeps growing. If your website reaches visitors across state lines, which most do, you're likely already subject to more than one.

The good news is that despite different names and thresholds, these laws share a common backbone. Once you understand the pattern, extending compliance to a new state is a matter of degree, not starting from scratch.

Which U.S. States Have Privacy Laws?

California was first, passing the California Consumer Privacy Act (CCPA) in 2018. Progress elsewhere was slow until 2023, when momentum picked up sharply and six more states passed laws that year, and the pace has continued since, with four more states passing laws in the first half of 2026.

StateRegulationEffective DateCompliance ThresholdsCure PeriodGPC / UOOM Required
AlabamaAlabama Personal Data Protection Act (APDPA)May 1, 2027One of:

- 25,000+ consumers
- 25%+ revenue from sales
45 days, no sunsetNo
CaliforniaCalifornia Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA)January 1, 2020 / January 1, 2023One of:

- $26.6M+ revenue (adjusted for inflation, next adjustment 2027)
- 100,000+ residents' data
- 50%+ revenue from data sales
ExpiredYes
ColoradoColorado Privacy Act (CPA)July 1, 2023One of:

- 100,000+ consumers
- 25,000+ with 50%+ revenue from sales
ExpiredYes
ConnecticutConnecticut Data Privacy Act (CTDPA)July 1, 2023One of:

- 100,000+ consumers,
- 25,000+ with a data-sale discount
ExpiredYes
DelawareDelaware Personal Data Privacy Act (DPDPA)January 1, 2025One of:

- 35,000+ residents
- 10,000+ with 20%+ revenue from sales
ExpiredYes
Florida*Florida Digital Bill of Rights (FDBR)July 1, 2024$1B+ global revenue and specific business models (ad sales, smart speakers, app stores)- 45 days, at AG discretion
- None for violations involving a known child
No
IndianaIndiana Consumer Data Protection Act (INCDPA)July 1, 2026One of:

- 100,000+ consumers
- 25,000+ with 50%+ revenue from sales
30 days, no sunsetNo
IowaIowa Consumer Data Protection Act (ICDPA)January 1, 2025One of:

- 100,000+ consumers
- 25,000+ with 50%+ revenue from sales
90 days, no sunsetNo
KentuckyKentucky Consumer Data Protection Act (KCDPA)January 1, 2026One of:

- 100,000+ consumers
- 25,000+ with 50%+ revenue from sales
30 days, no sunsetNo
LouisianaLouisiana Data Privacy Act (LDPA)January 1, 2027One of:

- $25M+ revenue
- 75,000+ consumers/households/devices
- 50%+ revenue from sales
30 days, available only January 1–July 31, 2027Yes
MarylandMaryland Online Data Privacy Act (MODPA)October 1, 2025One of:

- 35,000+ consumers
- 10,000+ with 20%+ revenue from sales
60 days, expires April 1, 2027Yes
MinnesotaMinnesota Consumer Data Privacy Act (MCDPA)July 31, 2025One of:

- 100,000+ consumers,
- 25,000+ with 50%+ revenue from sales
ExpiredYes
MontanaMontana Consumer Data Privacy Act (MTCDPA)October 24, 2024One of:

- 35,000+ residents
- 10,000+ with 20%+ revenue from sales
ExpiredYes
NebraskaNebraska Data Privacy Act (NDPA)January 1, 2025No revenue floor: applies to any business not defined as small30 days, no sunsetYes
Nevada*Nevada Privacy of Information Collected on the Internet from Consumers Act, as amended by SB-260 (NPICICA)July 1, 2017, amended October 1, 2021Any business operating a website with 20,000+ annual Nevada visitors30 days, no sunsetNo
New HampshireNew Hampshire Privacy Act (NHPA)January 1, 2025One of:

- 100,000+ consumers
- 25,000+ with 25%+ revenue from sales
ExpiredYes
New JerseyNew Jersey Data Privacy Act (NJDPA)January 15, 2025One of:

- 100,000+ consumers
- 25,000+ with revenue, and a discount tied to data sales
ExpiredYes
OklahomaOklahoma Consumer Data Privacy Act (OCDPA)January 1, 2027One of:

- 100,000+ consumers
- 25,000+ with 50%+ revenue from sales
30 days, no sunsetNo
OregonOregon Consumer Privacy Act (OCPA)July 1, 2024One of:

- 100,000+ consumers
- 25,000+ with 25%+ revenue from sales
ExpiredYes
Rhode IslandRhode Island Data Transparency and Privacy Protection Act (RI-DTPPA)January 1, 202610,000+ consumers with 20%+ revenue from salesExpiredNo
TennesseeTennessee Information Protection Act (TIPA)July 1, 2025One of:

- $25M+ revenue and 25,000+ consumers with 50%+ revenue from sales
- 175,000+ residents
60 days, no sunsetNo
TexasTexas Data Privacy and Security Act (TDPSA)July 1, 2024No revenue floor: applies to any business not defined as small30 days, no sunsetYes
VermontVermont Data Privacy and Online Surveillance Act (VDPOSA)January 1, 2028One of:

- 35,000+ consumers
- 3,000+ with sensitive data or data sales
60 days, available January 1, 2028–June 30, 2029Yes
VirginiaVirginia Consumer Data Protection Act (VCDPA)January 1, 2023One of:

- 100,000+ consumers
- 25,000+ consumers with 50%+ revenue from sales
30 days, no sunsetNo
UtahUtah Consumer Privacy Act (UCPA)December 31, 2023One of:

- $25M+ revenue, and 100,000+ consumers
- 25,000+ with 50%+ revenue from sales
30 days, no sunsetNo

*Florida and Nevada are generally excluded from the "comprehensive" privacy law count. Florida's law applies only to a narrow set of large businesses meeting specific criteria (ad sales, smart speakers, app stores), rather than any business over a general threshold. Nevada's law predates the current wave, covers a narrower set of "covered information," and gives consumers only an opt-out right, without the fuller rights bundle (access, correction, portability) the newer state laws provide.

What Do These Laws Actually Require?

Strip away the state-specific language, and nearly every one of these laws asks for the same handful of things. Where the laws diverge is in the details, including specific thresholds, cure periods, and whether Global Privacy Control has to be honored. California remains the outlier on two counts: it's the only state with its own dedicated enforcement agency (CalPrivacy), and the only one that gives consumers a private right of action for data breaches.

Standard Requirements

Standard Requirements
Privacy notice

Disclose what data you collect, why, and who you share it with.

opt-out mechanism

Typically a link, for the sale of personal data, targeted advertising, or profiling.

Consumer rights

To know, access, correct, delete, and (in most states) port their data.

Prior consent

Before collecting sensitive data or data belonging to a known child.

Non-discrimination

You can't penalize a consumer for exercising these rights.

Compliance Thresholds: Do These Laws Apply to You?

Most laws use some version of the same formula. Either you process a set number of residents' data — 100,000 is fairly common, though several recent laws use lower numbers or drop the threshold altogether — or you process a smaller number but derive meaningful revenue from selling it. A shrinking number of states — Utah and Tennessee among them — still include a revenue floor on top of that; newer laws increasingly skip it.

The practical implication is that a small business with a highly-trafficked website can trigger a state privacy law without meeting any revenue bar at all, purely on volume.

Penalties and Cure Periods

Fines range from roughly USD 5,000 to USD 20,000 per violation depending on the state, with a handful of states (Alabama, Florida, Indiana, and others) linking penalties to their existing deceptive trade practices statutes rather than setting a privacy-specific number.

Most states offer a "right to cure," which is typically 30 to 60 days to fix a violation once notified, before penalties apply. However, that right typically sunsets within 12 to 18 months of the law coming into effect, after which the right to cure can be offered at the Attorney General's discretion.

Do you know what your website is collecting?

Scan your website for free and find all the cookies and tracking technologies in use. Get your customized report and privacy compliance risk level in minutes.

Global Privacy Control: Do You Need to Honor It?

Global Privacy Control (GPC) or other Universal Opt-Out Mechanisms (UOOM) lets a visitor set their opt-out preference once, in their browser, and have it recognized automatically across every site they visit afterward, so no repeat clicking required. A growing number of states require businesses to recognize an opt-out signal — either GPC specifically or a UOOM more generally — including California, Colorado, Connecticut, Delaware, and Montana, with more joining.

A Related but Separate Risk: CIPA Litigation in California

None of the laws above cover a risk that's landed many California-facing businesses in court anyway, that of the California Invasion of Privacy Act (CIPA). CIPA is a 1967 wiretapping statute, not a modern comprehensive privacy law, and it works on different legal grounds entirely. Plaintiffs argue that common website tools like tracking pixels, chat widgets, and session replay software "intercept" communications without the consent CIPA requires, with statutory damages up to USD 5,000 per violation.

It's worth mentioning because being compliant with the CCPA or any other state privacy law does nothing to shield you from a CIPA claim, as they rest on separate legal foundations. One is a consumer-rights framework, the other is decades-old wiretapping law being applied to modern web technology, and courts have reached inconsistent conclusions on whether it even applies.

A reform bill in California, SB 690, has been narrowed sharply from its original scope and would — if passed before its August 31, 2026 deadline — shift enforcement of pen-register and trap-and-trace claims to the California Attorney General alone. It leaves the more commonly litigated wiretapping and eavesdropping provisions untouched, so even in the best case for businesses, CIPA exposure doesn't disappear.

Additionally, similar statutes in other states, and the Video Privacy Protection Act (VPPA) and Electronic Communications Privacy Act (ECPA), both of which are federal, are being used along with CIPA in claims, or in separate ones. SB 690 does nothing about any of them.

A consent management platform like Cookiebot™ CMP can help reduce this exposure by capturing consent before tracking scripts fire, but it isn't a guarantee against a CIPA claim. The safest move is a technical audit of what fires before consent, paired with legal counsel familiar with the current litigation landscape.

Managing Compliance Across Multiple States

Handling one state's privacy law manually is workable. Handling twenty is not, particularly once you factor in that thresholds, GPC requirements, and cure periods are all still shifting year to year. The complexity grows further if your business expands internationally.

Cookiebot™ CMP handles this by detecting a visitor's location and serving the right notice and opt-out mechanism automatically, recognizing GPC and other opt-out signals without manual configuration, and keeping records of consent and opt-out choices for when a regulator comes asking. See how straightforward it can be to manage all this from one place.

One state, multiple, or global business operations?

Cookiebot™ has you covered. Flexible and scalable to support privacy compliance for your growing business See how easy it is to configure different regulations, with customized banners, automated updates, and more. Try it free for 14 days.

Frequently asked questions

No. There's no single federal privacy law covering the U.S. as a whole. Instead, more than twenty states have passed their own, each with different thresholds, rights, and enforcement mechanisms, which is why a business operating nationally can find itself subject to a dozen or more separate laws at once.

There has been federal privacy legislation on several occasions, including the SECURE Data Act in 2026, but nothing has been enacted yet.

As of mid-2026, 24 states have enacted comprehensive privacy laws, ranging from California's 2018 CCPA to Vermont's, which won't take effect until 2028. Florida and Nevada also have privacy statutes, but both are generally excluded from the "comprehensive" count due to narrower scope. See the full table above for effective dates and requirements state by state.

 

It can. The EU's GDPR applies to any organization that processes the personal data of people in the EU, regardless of where the business itself is located, so a U.S. company with EU customers, subscribers, or site visitors may need to meet GDPR requirements even without a physical presence in Europe. GDPR and U.S. state privacy laws are separate frameworks with different consent models, so meeting one doesn't automatically satisfy the other.

Virginia's VCDPA follows the standard opt-out model most other states use, with no private right of action and enforcement resting solely with the Attorney General. California's CCPA/CPRA goes further on several fronts: it has its own dedicated enforcement agency (CalPrivacy), a private right of action for data breaches, and additional consumer rights around automated decision-making that Virginia's law doesn't include.

Due to these differences, the U.S. state privacy laws are sometimes divided up as using either the Virginia or California model.

Yes, if you have visitors from a state that requires it. GPC/UOOM obligations are tied to where your visitors are located, not where your business is headquartered, and over a dozen states currently require recognizing the signal. A consent management platform that detects visitor location and applies the right rules automatically removes the need to track this state by state.

It depends on the state and the timing. Several states still offer a right to cure, typically 30 to 60 days to fix a violation once notified, but many of these have already sunset in 2026, shifting enforcement to the Attorney General's discretion with no automatic grace period. Check the current status for each state you operate in before assuming you have time to fix an issue before facing a penalty.

No, and this is a common point of confusion. CIPA is a 1967 California wiretapping statute, not a modern comprehensive privacy law, and meeting CCPA or any other state law's requirements does nothing to shield a business from a CIPA claim. The two rest on entirely separate legal foundations. It's strongly recommended to consult qualified legal counsel about complying with CIPA or if your business has received a demand letter.

It depends on where your website's visitors are located, not where your business is headquartered. Most laws apply once you cross a threshold, commonly 100,000 residents' data processed annually, or a smaller number combined with meaningful revenue from data sales, so a small business with high traffic can be covered without meeting any revenue bar at all. It's important to know where your website visitors and customers are located, and what the thresholds in each jurisdiction are.

Or you could implement a privacy compliance template covering all of the United States, or default to an even stricter model, like that used for the GDPR in Europe. It's also recommended to consult qualified legal counsel about your business's specific privacy compliance requirements and implementation.

Generally, yes. A CMP that detects a visitor's location can serve the right notice and opt-out mechanism automatically for each applicable state, recognize GPC and other opt-out signals without manual configuration per state, and keep consent records for when a regulator requests them, which is considerably more practical than managing twenty-plus sets of state-specific rules by hand. This flexibility and scalability becomes even more important as businesses grow internationally.