---------------------------
Title: U.S. State Privacy Laws: Compliance Thresholds, Requirements, Rights, and Enforcement
URL: https://www.cookiebot.com/us/us-data-privacy-laws/
---------------------------

# U.S. State Privacy Laws: Compliance Thresholds, Requirements, Rights, and Enforcement

This guide covers the landscape of U.S. state privacy laws. Which states have laws to date, what they typically require, and how thresholds, penalties, and opt-out signal obligations differ among them.

## At a Glance

- More than twenty U.S. states now have their own comprehensive privacy law, with no federal law to unify them.
- Nearly all follow the same core pattern: opt-out consent, a privacy notice, and rights to know, access, correct, delete, and port personal data.
- Compliance thresholds vary widely, and several recent laws drop the revenue floor entirely, so traffic volume alone can trigger obligations.
- Most states offer a right to cure a violation before facing penalties, but several of these grace periods sunset in 2026.
- A growing number of states require recognition of Global Privacy Control or other opt-out signals, though the requirement isn't universal and some versions of it are set to expire.
- California is the only state with its own dedicated privacy agency (CalPrivacy) and a private right of action for data breaches.

There's no single federal privacy law in the U.S. Instead, more than twenty states have passed their own, and that number keeps growing. If your website reaches visitors across state lines, which most do, you're likely already subject to more than one.

The good news is that despite different names and thresholds, these laws share a common backbone. Once you understand the pattern, extending compliance to a new state is a matter of degree, not starting from scratch.

## Which U.S. States Have Privacy Laws?

California was first, passing the [California Consumer Privacy Act (CCPA)](https://www.cookiebot.com/us/what-is-ccpa/) in 2018. Progress elsewhere was slow until 2023, when momentum picked up sharply and six more states passed laws that year, and the pace has continued since, with four more states passing laws in the first half of 2026.

StateRegulationEffective DateCompliance ThresholdsCure PeriodGPC / UOOM RequiredAlabama[Alabama Personal Data Protection Act (APDPA)](https://www.cookiebot.com/us/alabama-personal-data-protection-act-apdpa/)May 1, 2027One of:

- 25,000+ consumers
- 25%+ revenue from sales45 days, no sunsetNoCalifornia[California Consumer Privacy Act (CCPA)](https://www.cookiebot.com/us/what-is-ccpa/) / [California Privacy Rights Act (CPRA)](https://www.cookiebot.com/us/what-is-ccpa/)January 1, 2020 / January 1, 2023One of:

- $26.6M+ revenue (adjusted for inflation, next adjustment 2027)
- 100,000+ residents' data
- 50%+ revenue from data salesExpiredYesColorado[Colorado Privacy Act (CPA)](https://www.cookiebot.com/us/cpa-colorado-privacy-act/)July 1, 2023One of:

- 100,000+ consumers
- 25,000+ with 50%+ revenue from salesExpiredYes Connecticut[Connecticut Data Privacy Act (CTDPA)](https://www.cookiebot.com/us/ctdpa-connecticut-data-privacy-act/)July 1, 2023One of:

- 100,000+ consumers,
- 25,000+ with a data-sale discountExpiredYesDelaware[Delaware Personal Data Privacy Act (DPDPA)](https://www.cookiebot.com/us/delaware-personal-data-privacy-act-dpdpa/)January 1, 2025One of:

- 35,000+ residents
- 10,000+ with 20%+ revenue from salesExpiredYesFlorida*[Florida Digital Bill of Rights (FDBR)](https://www.cookiebot.com/us/florida-digital-bill-of-rights-fdbr/)July 1, 2024$1B+ global revenue and specific business models (ad sales, smart speakers, app stores)- 45 days, at AG discretion
- None for violations involving a known childNoIndiana`Indiana Consumer Data Protection Act (INCDPA)`July 1, 2026One of:

- 100,000+ consumers
- 25,000+ with 50%+ revenue from sales30 days, no sunsetNoIowa[Iowa Consumer Data Protection Act (ICDPA)](https://www.cookiebot.com/us/iowa-consumer-data-protection-act-icdpa/)January 1, 2025One of:

- 100,000+ consumers
- 25,000+ with 50%+ revenue from sales90 days, no sunsetNoKentuckyKentucky Consumer Data Protection Act (KCDPA)January 1, 2026One of:

- 100,000+ consumers
- 25,000+ with 50%+ revenue from sales30 days, no sunsetNoLouisiana[Louisiana Data Privacy Act (LDPA)](https://www.cookiebot.com/us/louisiana-data-privacy-act-ldpa/)January 1, 2027One of:

- $25M+ revenue
- 75,000+ consumers/households/devices
- 50%+ revenue from sales30 days, available only January 1–July 31, 2027YesMarylandMaryland Online Data Privacy Act (MODPA)October 1, 2025One of:

- 35,000+ consumers
- 10,000+ with 20%+ revenue from sales60 days, expires April 1, 2027YesMinnesota`Minnesota Consumer Data Privacy Act (MCDPA)`July 31, 2025One of:

- 100,000+ consumers,
- 25,000+ with 50%+ revenue from salesExpiredYesMontana[Montana Consumer Data Privacy Act (MTCDPA)](https://www.cookiebot.com/us/montana-consumer-data-privacy-act-mtcdpa/)October 24, 2024One of:

- 35,000+ residents
- 10,000+ with 20%+ revenue from salesExpiredYesNebraska[Nebraska Data Privacy Act (NDPA)](https://www.cookiebot.com/us/nebraska-data-privacy-act-ndpa/)January 1, 2025No revenue floor: applies to any business not defined as small30 days, no sunsetYesNevada*`Nevada Privacy of Information Collected on the Internet from Consumers Act, as amended by SB-260 (NPICICA)`July 1, 2017, amended October 1, 2021Any business operating a website with 20,000+ annual Nevada visitors30 days, no sunsetNoNew HampshireNew Hampshire Privacy Act (NHPA)January 1, 2025One of:

- 100,000+ consumers
- 25,000+ with 25%+ revenue from salesExpiredYesNew JerseyNew Jersey Data Privacy Act (NJDPA)January 15, 2025One of:

- 100,000+ consumers
- 25,000+ with revenue, and a discount tied to data salesExpiredYesOklahoma[Oklahoma Consumer Data Privacy Act (OCDPA)](https://www.cookiebot.com/us/oklahoma-consumer-data-privacy-act-ocdpa/)January 1, 2027One of:

- 100,000+ consumers
- 25,000+ with 50%+ revenue from sales30 days, no sunsetNoOregon`Oregon Consumer Privacy Act (OCPA)`July 1, 2024One of:

- 100,000+ consumers
- 25,000+ with 25%+ revenue from salesExpiredYesRhode IslandRhode Island Data Transparency and Privacy Protection Act (RI-DTPPA)January 1, 202610,000+ consumers with 20%+ revenue from salesExpiredNoTennessee`Tennessee Information Protection Act (TIPA)`July 1, 2025One of:

- $25M+ revenue and 25,000+ consumers with 50%+ revenue from sales
- 175,000+ residents60 days, no sunsetNoTexas[Texas Data Privacy and Security Act (TDPSA)](https://www.cookiebot.com/us/texas-data-privacy-and-security-act-tdpsa/)July 1, 2024No revenue floor: applies to any business not defined as small30 days, no sunsetYesVermont[Vermont Data Privacy and Online Surveillance Act (VDPOSA)](https://www.cookiebot.com/us/vermont-data-privacy-and-online-surveillance-act-vdposa/)January 1, 2028One of:

- 35,000+ consumers
- 3,000+ with sensitive data or data sales60 days, available January 1, 2028–June 30, 2029YesVirginia[Virginia Consumer Data Protection Act (VCDPA)](https://www.cookiebot.com/us/virginia-vcdpa/)January 1, 2023One of:

- 100,000+ consumers
- 25,000+ consumers with 50%+ revenue from sales30 days, no sunsetNoUtah[Utah Consumer Privacy Act (UCPA)](https://www.cookiebot.com/us/utah-consumer-privacy-act-ucpa/)December 31, 2023One of:

- $25M+ revenue, and 100,000+ consumers
- 25,000+ with 50%+ revenue from sales30 days, no sunsetNo

*Florida and Nevada are generally excluded from the "comprehensive" privacy law count. Florida's law applies only to a narrow set of large businesses meeting specific criteria (ad sales, smart speakers, app stores), rather than any business over a general threshold. Nevada's law predates the current wave, covers a narrower set of "covered information," and gives consumers only an opt-out right, without the fuller rights bundle (access, correction, portability) the newer state laws provide.

## What Do These Laws Actually Require?

Strip away the state-specific language, and nearly every one of these laws asks for the same handful of things. Where the laws diverge is in the details, including specific thresholds, cure periods, and whether Global Privacy Control has to be honored. California remains the outlier on two counts: it's the only state with its own dedicated enforcement agency ([CalPrivacy](https://www.cookiebot.com/en/escalating-cppa-enforcement/)), and the only one that gives consumers a private right of action for data breaches.

## Standard Requirements

- **Privacy notice** — Disclose what data you collect, why, and who you share it with.
- **opt-out mechanism** — Typically a link, for the sale of personal data, targeted advertising, or profiling.
- **Consumer rights** — To know, access, correct, delete, and (in most states) port their data.
- **Prior consent** — Before collecting sensitive data or data belonging to a known child.
- **Non-discrimination** — You can't penalize a consumer for exercising these rights.

## Compliance Thresholds: Do These Laws Apply to You?

Most laws use some version of the same formula. Either you process a set number of residents' data — 100,000 is fairly common, though several recent laws use lower numbers or drop the threshold altogether — or you process a smaller number but derive meaningful revenue from selling it. A shrinking number of states — Utah and Tennessee among them — still include a revenue floor on top of that; newer laws increasingly skip it.

The practical implication is that a small business with a highly-trafficked website can trigger a state privacy law without meeting any revenue bar at all, purely on volume.

## Penalties and Cure Periods

Fines range from roughly USD 5,000 to USD 20,000 per violation depending on the state, with a handful of states (Alabama, Florida, Indiana, and others) linking penalties to their existing deceptive trade practices statutes rather than setting a privacy-specific number.

Most states offer a "right to cure," which is typically 30 to 60 days to fix a violation once notified, before penalties apply. However, that right typically sunsets within 12 to 18 months of the law coming into effect, after which the right to cure can be offered at the Attorney General's discretion.

Do you know what your website is collecting?
Scan your website for free and find all the cookies and tracking technologies in use. Get your customized report and privacy compliance risk level in minutes.

[Start Scan](https://www.cookiebot.com/us/cookie-checker/)

## Global Privacy Control: Do You Need to Honor It?

[Global Privacy Control (GPC)](https://www.cookiebot.com/en/global-privacy-control/) or other Universal Opt-Out Mechanisms (UOOM) lets a visitor set their opt-out preference once, in their browser, and have it recognized automatically across every site they visit afterward, so no repeat clicking required. A growing number of states require businesses to recognize an opt-out signal — either GPC specifically or a UOOM more generally — including California, Colorado, Connecticut, Delaware, and Montana, with more joining.

## A Related but Separate Risk: CIPA Litigation in California

None of the laws above cover a risk that's landed many California-facing businesses in court anyway, that of the [California Invasion of Privacy Act (CIPA)](https://www.cookiebot.com/us/cipa-california-invasion-of-privacy-act/). CIPA is a 1967 wiretapping statute, not a modern comprehensive privacy law, and it works on different legal grounds entirely. Plaintiffs argue that common website tools like tracking pixels, chat widgets, and session replay software "intercept" communications without the consent CIPA requires, with statutory damages up to USD 5,000 per violation.

It's worth mentioning because being compliant with the CCPA or any other state privacy law does nothing to shield you from a CIPA claim, as they rest on separate legal foundations. One is a consumer-rights framework, the other is decades-old wiretapping law being applied to modern web technology, and courts have reached inconsistent conclusions on whether it even applies.

A reform bill in California, SB 690, has been narrowed sharply from its original scope and would — if passed before its August 31, 2026 deadline — shift enforcement of pen-register and trap-and-trace claims to the California Attorney General alone. It leaves the more commonly litigated wiretapping and eavesdropping provisions untouched, so even in the best case for businesses, CIPA exposure doesn't disappear.

Additionally, similar statutes in other states, and the [Video Privacy Protection Act (VPPA)](https://usercentrics.com/us/knowledge-hub/video-privacy-protection-act-vppa/) and [Electronic Communications Privacy Act (ECPA)](https://www.cookiebot.com/us/electronic-communications-privacy-act-ecpa/), both of which are federal, are being used along with CIPA in claims, or in separate ones. SB 690 does nothing about any of them.

A consent management platform like [Cookiebot™ CMP](https://www.cookiebot.com/us/cookie-consent-solution/) can help reduce this exposure by capturing consent before tracking scripts fire, but it isn't a guarantee against a CIPA claim. The safest move is a technical audit of what fires before consent, paired with legal counsel familiar with the current litigation landscape.

## Managing Compliance Across Multiple States

Handling one state's privacy law manually is workable. Handling twenty is not, particularly once you factor in that thresholds, GPC requirements, and cure periods are all still shifting year to year. The complexity grows further if your business expands internationally.

[Cookiebot™ CMP](https://www.cookiebot.com/us/cookie-consent-solution/) handles this by detecting a visitor's location and serving the right notice and opt-out mechanism automatically, recognizing GPC and other opt-out signals without manual configuration, and keeping records of consent and opt-out choices for when a regulator comes asking. See how straightforward it can be to manage all this from one place.

One state, multiple, or global business operations?
Cookiebot™ has you covered. Flexible and scalable to support privacy compliance for your growing business See how easy it is to configure different regulations, with customized banners, automated updates, and more. Try it free for 14 days.

[Start Free Trial](https://admin.cookiebot.com/signup?lang=en)

## Summary

This guide covers the landscape of U.S. state privacy laws. Which states have laws to date, what they typically require, and how thresholds, penalties, and opt-out signal obligations differ among them.

---

## Footer

### Products
- [Cookiebot™ Consent Solution](https://www.cookiebot.com/us/cookie-consent-solution/)
- [Audience Survey](https://www.cookiebot.com/us/audience-survey-add-on/)
- [Usercentrics for Wix](https://www.cookiebot.com/us/cookiebot-for-wix-by-usercentrics-app/)
- [Usercentrics Cookiebot WordPress Plugin](https://www.cookiebot.com/us/new-wp-cookie-plugin/)
- [Cookiebot CMP for Shopify](https://www.cookiebot.com/us/cookiebot-cmp-for-shopify/)
- [Cookie checker](https://www.cookiebot.com/us/cookie-checker/)
- [Usercentrics products](https://usercentrics.com/us/)
- [Pricing](https://www.cookiebot.com/us/pricing/)

### Regulations
- [DMA (EU)](https://www.cookiebot.com/us/digital-markets-act-dma/)
- [GDPR (EU)](https://www.cookiebot.com/us/gdpr/)
- [CCPA (California)](https://www.cookiebot.com/us/what-is-ccpa/)
- [VCDPA (Virginia)](https://www.cookiebot.com/us/virginia-vcdpa/)
- [LGPD (Brazil)](https://www.cookiebot.com/us/lgpd/)
- [TCF v2.3 (IAB)](https://www.cookiebot.com/us/tcf/)
- [Google Consent Mode (EU)](https://www.cookiebot.com/us/cookiebot-cmp-google-consent-mode/)
- [Microsoft UET Consent Mode](https://www.cookiebot.com/us/microsoft-consent-mode-cmp/)
- [View all regulations](/us/regulations-and-frameworks/#united-states-state&united-states-federal)

### Partners
- [Become an affiliate](https://www.cookiebot.com/us/affiliates/)
- [Affiliate Login](https://app.impact.com/login.user)
- [Become a partner](https://www.cookiebot.com/us/resellers/)
- [Find a partner](https://www.cookiebot.com/us/cookiebot-reseller/)

### Resources
- [Blog](https://www.cookiebot.com/us/blog/)
- [Customer stories](https://www.cookiebot.com/us/customer-stories/)
- [Customer directory](https://www.cookiebot.com/us/cookiebot-customer-directory/)
- [Digital Markets Act Hub](https://www.cookiebot.com/us/digital-markets-act-dma-resources/)
- [Google Consent Mode Hub](https://www.cookiebot.com/us/google-consent-mode-resources/)
- [Google Consent Mode V2 certification](https://courses.usercentrics.com/course/google-consent-mode-v2)
- [Google Consent Audit Fixes](https://www.cookiebot.com/us/google-consent-audit-fixes/)
- [Cookie Banner Cost Calculator](https://www.cookiebot.com/us/cookie-banner-pricing-calculator/)

### Company
- [About us](https://www.cookiebot.com/us/about/)
- [Careers](https://usercentrics.com/career/)
- [Support](https://support.cookiebot.com/hc/en-us/)
- [Developer documentation](https://www.cookiebot.com/us/developer/)

©2026 Cookiebot. All rights reserved. Cookiebot is a trademark of     Usercentrics     A/S. Usercentrics A/S is registered in Denmark. Company reg. no.: 34624607. Do Not Sell or Share My Personal InformationData Subject RequestsManage Your Preferences

[Privacy Policy](https://www.cookiebot.com/us/privacy-policy/) · [Terms of Service](/en/terms-of-service/) · [Cookie Declaration](https://www.cookiebot.com/us/cookie-declaration/) · [Data Processing Agreement](/us/data-processing-agreement/) · [Legal Notice](https://www.cookiebot.com/us/legal-notice/) · [Accessibility Statement](/en/accessibility-statement-wcag-compliance/)