The laws, and what they mean in practice

Privacy, AI and cybersecurity laws that shape digital trust work, from the GDPR to every US state privacy law. Each entry says who it applies to, who enforces it and when, in plain words, with the sources. Free for everyone.

Regulatory Watch follows new rules, enforcement and court decisions as they happen.

Coming into force

US states

Every state with a comprehensive privacy law, plus the states with notable biometric, health data, data broker, children's or security laws. Twenty-four states have enacted comprehensive privacy laws; four take effect in 2027 and 2028.

Comprehensive law in force Enacted, not yet in force Sector laws only

European Union 12

In force

GDPR

The global reference point for privacy law: lawful bases, principles, rights, accountability, breach notice within 72 hours, transfer rules and fines up to 4 percent of worldwide turnover.

Since 25 May 2018 · Guide in progress
In force

EU AI Act

Risk-based AI regulation with obligations assigned by role: prohibited practices, high-risk requirements, transparency duties and rules for general-purpose models.

Since 1 Aug 2024 · Guide in progress
In force

ePrivacy Directive

The source of EU cookie consent and electronic marketing rules, alongside the GDPR.

See details · Guide in progress
In force

NIS2

Cybersecurity risk management, management accountability and staged incident reporting starting with an early warning within 24 hours.

See details · Guide in progress
In force

DORA

ICT risk management, incident reporting, resilience testing and a register of ICT third-party arrangements for the financial sector.

Since 17 Jan 2025
In force

Data Act

Rights for users to access and share data from connected products, and rules making it easier to switch cloud providers.

Since 12 Sep 2025
In force

DSA

Content moderation, transparency, a ban on ads targeted using sensitive data or at minors based on profiling, and risk assessments for very large platforms.

Since 17 Feb 2024
In force

DMA

Limits on how gatekeepers combine personal data across services without consent, among other conduct rules.

Since 2 May 2023
In force

CRA

Security requirements across the life of hardware and software products, with vulnerability handling and reporting duties.

Since 10 Dec 2024
In force

DGA

Rules for neutral data intermediaries and for re-using protected public sector data.

Since 24 Sep 2023
In force

EHDS

Patients' access to and control of electronic health data across the EU, and a framework for secondary use of health data.

Since 26 Mar 2025
In force

EU-US DPF

An adequacy decision letting personal data flow to self-certified US companies without standard contractual clauses.

Since 10 Jul 2023

United Kingdom 1

US federal 12

In force

HIPAA

Governs protected health information held by the health care system and its vendors: permitted uses and disclosures, patient rights, security safeguards for electronic records, and breach notice.

Since 14 Apr 2003 · Guide in progress
In force

FTC Act Section 5

The main federal privacy enforcement tool: unfair or deceptive practices, including privacy promises not kept and unreasonable security.

Since 26 Sep 1914 · Guide in progress
In force

GLBA

Privacy notices and opt-outs for sharing customer financial information, and an information security program with specific safeguards under the Safeguards Rule.

Since 12 Nov 1999 · Guide in progress
In force

COPPA

Verifiable parental consent before collecting personal information from children under 13, with notice, access and deletion rights for parents.

Since 21 Apr 2000 · Guide in progress
In force

CAN-SPAM

Honest headers and subject lines, a postal address, and an opt-out honored within ten business days. No consent is required to send.

Since 1 Jan 2004 · Guide in progress
In force

TCPA

Consent rules for automated and prerecorded calls and texts, the National Do Not Call Registry, and statutory damages per call.

Since 20 Dec 1991 · Guide in progress
In force

FCRA

Accuracy, permissible purpose and dispute rights for consumer reports, including background checks for employment.

Since 25 Apr 1971
In force

FERPA

Parent and eligible student rights over education records, and limits on disclosing them.

Since 21 Aug 1974
In force

VPPA

Limits disclosure of what video a person watched; now a frequent basis for lawsuits over tracking pixels on video pages.

Since 5 Nov 1988
In force

GINA

Prohibits use of genetic information in employment and health insurance decisions.

Since 21 May 2008
In force

SEC cyber disclosure

Disclosure of material cybersecurity incidents within four business days of determining materiality, and annual disclosure of risk management and governance.

Since 5 Sep 2023
In force

FTC HBNR

Breach notice for health apps and similar services outside HIPAA, where unauthorized sharing counts as a breach.

Since 24 Sep 2009

US states 40

In force · California

CCPA/CPRA

The most detailed US state privacy law and the only one with a dedicated privacy regulator. It covers employee and business-to-business data, requires opt-outs from selling and sharing, and has its own regulations on automated decision-making.

Since 1 Jan 2020 · Guide in progress
In force · Virginia

VCDPA

The template for most later state laws: consumer rights, opt-outs from targeted advertising, sale and profiling, opt-in consent for sensitive data, and data protection assessments.

Since 1 Jan 2023 · Guide in progress
In force · Colorado

CPA

Virginia-style law with detailed Attorney General rules, including requirements to honor universal opt-out signals.

Since 1 Jul 2023 · Guide in progress
In force · Connecticut

CTDPA

Virginia-style law, amended to broaden coverage and strengthen rules on sensitive data and minors.

Since 1 Jul 2023 · Guide in progress
In force · Utah

UCPA

One of the more business-friendly state laws, with narrower rights and higher thresholds.

Since 31 Dec 2023
In force · Texas

TDPSA

No revenue or volume threshold: it reaches almost every business that is not a small business, which makes it one of the broadest state laws in practice.

Since 1 Jul 2024 · Guide in progress
In force · Oregon

OCPA

Virginia-style law that also gives consumers the right to learn the specific third parties their data was disclosed to.

Since 1 Jul 2024 · Guide in progress
In force · Montana

MCDPA

Virginia-style law with relatively low thresholds, reflecting the state's population.

Since 1 Oct 2024
In force · Florida

FDBR

Narrow in who it covers, but strict for the largest technology companies it targets.

Since 1 Jul 2024 · Guide in progress
In force · Iowa

ICDPA

A narrower Virginia-style law with fewer consumer rights.

Since 1 Jan 2025
In force · Delaware

DPDPA

Virginia-style law with low thresholds and coverage of many nonprofits.

Since 1 Jan 2025
In force · New Hampshire

NHDPA

Virginia-style law with thresholds scaled to a small state.

Since 1 Jan 2025
In force · New Jersey

NJDPA

Virginia-style law with broad sensitive-data definitions and rulemaking by the Division of Consumer Affairs.

Since 15 Jan 2025 · Guide in progress
In force · Nebraska

NDPA

Texas-style law without a volume threshold, applying to most businesses that are not small businesses.

Since 1 Jan 2025
In force · Tennessee

TIPA

High thresholds, and an affirmative defense for businesses that follow the NIST Privacy Framework.

Since 1 Jul 2025
In force · Minnesota

MCDPA

Adds rights other states lack, including the right to question the result of a profiling decision and to see the list of third parties that received data.

Since 31 Jul 2025 · Guide in progress
In force · Maryland

MODPA

The strictest state law on data minimization: collection must be reasonably necessary for the service, and selling sensitive data is prohibited.

Since 1 Oct 2025 · Guide in progress
In force · Indiana

ICDPA

Virginia-style law, in force from 2026.

Since 1 Jan 2026
In force · Kentucky

KCDPA

Virginia-style law, in force from 2026.

Since 1 Jan 2026
In force · Rhode Island

RIDTPPA

Virginia-style law with unusual website disclosure duties and no cure period.

Since 1 Jan 2026
Enacted, not yet in force · Oklahoma

OCDPA

Enacted in 2026 and not yet in force. Largely Virginia-style, with its own thresholds and cure period.

From 1 Jan 2027
Enacted, not yet in force · Louisiana

LDPA

Enacted in 2026 and not yet in force. Largely Virginia-style, with its own thresholds and cure period.

From 1 Jan 2027
Enacted, not yet in force · Alabama

APDPA

Enacted in 2026 and not yet in force. Largely Virginia-style, with its own thresholds and cure period.

From 1 May 2027
Enacted, not yet in force · Vermont

VDPOSA

Enacted in 2026 and not yet in force. Largely Virginia-style, with its own thresholds and cure period.

From 1 Jan 2028
In force · Illinois

BIPA

Written notice and consent before collecting biometrics, a public retention schedule, and a private right of action that has produced some of the largest privacy settlements in the US.

Since 3 Oct 2008 · Guide in progress
In force · Texas

CUBI

Notice and consent before capturing biometric identifiers, limits on sale and disclosure, and destruction within a set period. Enforced by the Attorney General, which has obtained large settlements.

Since 1 Sep 2009
In force · Washington

RCW 19.375

Notice and consent or an opt-out mechanism before enrolling biometric identifiers for a commercial purpose.

Since 23 Jul 2017
In force · Washington

MHMDA

A broad definition of consumer health data, separate consent to collect and to share, a signed authorization to sell, geofencing limits near health facilities, and a private right of action.

Since 31 Mar 2024 · Guide in progress
In force · Nevada

SB 370

Similar in approach to Washington's law, without a private right of action.

Since 31 Mar 2024
In force · California

Delete Act

Lets a California resident ask every registered data broker to delete their data with one request, which brokers must check and process on a fixed schedule.

Since 1 Jan 2024
In force · Vermont

Vermont data broker law

The first state data broker registry, with security program and disclosure requirements.

Since 1 Jan 2019
In force · Texas

Texas data broker law

Registration, website notices and a security program for data brokers.

Since 1 Sep 2023
In force · Oregon

Oregon data broker registry

Annual registration for data brokers.

Since 1 Jan 2024
Challenged in court · California

CA AADC

Would require child-protective defaults and assessments for services likely to be used by children. Its enforceability is being decided in court.

See details
Enacted, not yet in force · New York

SAFE for Kids Act

Limits addictive algorithmic feeds and overnight notifications for minors without parental consent.

See details
In force · New York

SHIELD Act

Broadened New York's breach notification law and requires reasonable administrative, technical and physical safeguards.

Since 21 Mar 2020
In force · Massachusetts

201 CMR 17.00

One of the first prescriptive state security rules: a written information security program, encryption and vendor oversight.

Since 1 Mar 2010
In force · New York

NYDFS Part 500

A detailed cybersecurity program regulation with annual certification, CISO reporting, incident notice within 72 hours and personal liability exposure for certifying executives.

Since 1 Mar 2017 · Guide in progress
Enforcement stayed · Colorado

Colorado AI Act

The first broad US state law on algorithmic discrimination, modeled partly on risk-based approaches like the EU AI Act.

See details
In force

State breach laws

Every state requires notice to affected residents after a breach of personal information. Deadlines, regulator notices and what counts as personal information differ, so a multi-state breach means applying several laws at once.

See details

Rest of world 10

This library explains laws for practitioners. It is not legal advice, and laws change: check the sources on each page and take advice from counsel before acting.