The laws, and what they mean in practice
Privacy, AI and cybersecurity laws that shape digital trust work, from the GDPR to every US state privacy law. Each entry says who it applies to, who enforces it and when, in plain words, with the sources. Free for everyone.
Regulatory Watch follows new rules, enforcement and court decisions as they happen.
Coming into force
US states
Every state with a comprehensive privacy law, plus the states with notable biometric, health data, data broker, children's or security laws. Twenty-four states have enacted comprehensive privacy laws; four take effect in 2027 and 2028.
Comprehensive law in force Enacted, not yet in force Sector laws only
European Union 12
GDPR
The global reference point for privacy law: lawful bases, principles, rights, accountability, breach notice within 72 hours, transfer rules and fines up to 4 percent of worldwide turnover.
Since 25 May 2018 · Guide in progress In forceEU AI Act
Risk-based AI regulation with obligations assigned by role: prohibited practices, high-risk requirements, transparency duties and rules for general-purpose models.
Since 1 Aug 2024 · Guide in progress In forceePrivacy Directive
The source of EU cookie consent and electronic marketing rules, alongside the GDPR.
See details · Guide in progress In forceNIS2
Cybersecurity risk management, management accountability and staged incident reporting starting with an early warning within 24 hours.
See details · Guide in progress In forceDORA
ICT risk management, incident reporting, resilience testing and a register of ICT third-party arrangements for the financial sector.
Since 17 Jan 2025 In forceData Act
Rights for users to access and share data from connected products, and rules making it easier to switch cloud providers.
Since 12 Sep 2025 In forceDSA
Content moderation, transparency, a ban on ads targeted using sensitive data or at minors based on profiling, and risk assessments for very large platforms.
Since 17 Feb 2024 In forceDMA
Limits on how gatekeepers combine personal data across services without consent, among other conduct rules.
Since 2 May 2023 In forceCRA
Security requirements across the life of hardware and software products, with vulnerability handling and reporting duties.
Since 10 Dec 2024 In forceDGA
Rules for neutral data intermediaries and for re-using protected public sector data.
Since 24 Sep 2023 In forceEHDS
Patients' access to and control of electronic health data across the EU, and a framework for secondary use of health data.
Since 26 Mar 2025 In forceEU-US DPF
An adequacy decision letting personal data flow to self-certified US companies without standard contractual clauses.
Since 10 Jul 2023United Kingdom 1
US federal 12
HIPAA
Governs protected health information held by the health care system and its vendors: permitted uses and disclosures, patient rights, security safeguards for electronic records, and breach notice.
Since 14 Apr 2003 · Guide in progress In forceFTC Act Section 5
The main federal privacy enforcement tool: unfair or deceptive practices, including privacy promises not kept and unreasonable security.
Since 26 Sep 1914 · Guide in progress In forceGLBA
Privacy notices and opt-outs for sharing customer financial information, and an information security program with specific safeguards under the Safeguards Rule.
Since 12 Nov 1999 · Guide in progress In forceCOPPA
Verifiable parental consent before collecting personal information from children under 13, with notice, access and deletion rights for parents.
Since 21 Apr 2000 · Guide in progress In forceCAN-SPAM
Honest headers and subject lines, a postal address, and an opt-out honored within ten business days. No consent is required to send.
Since 1 Jan 2004 · Guide in progress In forceTCPA
Consent rules for automated and prerecorded calls and texts, the National Do Not Call Registry, and statutory damages per call.
Since 20 Dec 1991 · Guide in progress In forceFCRA
Accuracy, permissible purpose and dispute rights for consumer reports, including background checks for employment.
Since 25 Apr 1971 In forceFERPA
Parent and eligible student rights over education records, and limits on disclosing them.
Since 21 Aug 1974 In forceVPPA
Limits disclosure of what video a person watched; now a frequent basis for lawsuits over tracking pixels on video pages.
Since 5 Nov 1988 In forceGINA
Prohibits use of genetic information in employment and health insurance decisions.
Since 21 May 2008 In forceSEC cyber disclosure
Disclosure of material cybersecurity incidents within four business days of determining materiality, and annual disclosure of risk management and governance.
Since 5 Sep 2023 In forceFTC HBNR
Breach notice for health apps and similar services outside HIPAA, where unauthorized sharing counts as a breach.
Since 24 Sep 2009US states 40
CCPA/CPRA
The most detailed US state privacy law and the only one with a dedicated privacy regulator. It covers employee and business-to-business data, requires opt-outs from selling and sharing, and has its own regulations on automated decision-making.
Since 1 Jan 2020 · Guide in progress In force · VirginiaVCDPA
The template for most later state laws: consumer rights, opt-outs from targeted advertising, sale and profiling, opt-in consent for sensitive data, and data protection assessments.
Since 1 Jan 2023 · Guide in progress In force · ColoradoCPA
Virginia-style law with detailed Attorney General rules, including requirements to honor universal opt-out signals.
Since 1 Jul 2023 · Guide in progress In force · ConnecticutCTDPA
Virginia-style law, amended to broaden coverage and strengthen rules on sensitive data and minors.
Since 1 Jul 2023 · Guide in progress In force · UtahUCPA
One of the more business-friendly state laws, with narrower rights and higher thresholds.
Since 31 Dec 2023 In force · TexasTDPSA
No revenue or volume threshold: it reaches almost every business that is not a small business, which makes it one of the broadest state laws in practice.
Since 1 Jul 2024 · Guide in progress In force · OregonOCPA
Virginia-style law that also gives consumers the right to learn the specific third parties their data was disclosed to.
Since 1 Jul 2024 · Guide in progress In force · MontanaMCDPA
Virginia-style law with relatively low thresholds, reflecting the state's population.
Since 1 Oct 2024 In force · FloridaFDBR
Narrow in who it covers, but strict for the largest technology companies it targets.
Since 1 Jul 2024 · Guide in progress In force · IowaICDPA
A narrower Virginia-style law with fewer consumer rights.
Since 1 Jan 2025 In force · DelawareDPDPA
Virginia-style law with low thresholds and coverage of many nonprofits.
Since 1 Jan 2025 In force · New HampshireNHDPA
Virginia-style law with thresholds scaled to a small state.
Since 1 Jan 2025 In force · New JerseyNJDPA
Virginia-style law with broad sensitive-data definitions and rulemaking by the Division of Consumer Affairs.
Since 15 Jan 2025 · Guide in progress In force · NebraskaNDPA
Texas-style law without a volume threshold, applying to most businesses that are not small businesses.
Since 1 Jan 2025 In force · TennesseeTIPA
High thresholds, and an affirmative defense for businesses that follow the NIST Privacy Framework.
Since 1 Jul 2025 In force · MinnesotaMCDPA
Adds rights other states lack, including the right to question the result of a profiling decision and to see the list of third parties that received data.
Since 31 Jul 2025 · Guide in progress In force · MarylandMODPA
The strictest state law on data minimization: collection must be reasonably necessary for the service, and selling sensitive data is prohibited.
Since 1 Oct 2025 · Guide in progress In force · IndianaICDPA
Virginia-style law, in force from 2026.
Since 1 Jan 2026 In force · KentuckyKCDPA
Virginia-style law, in force from 2026.
Since 1 Jan 2026 In force · Rhode IslandRIDTPPA
Virginia-style law with unusual website disclosure duties and no cure period.
Since 1 Jan 2026 Enacted, not yet in force · OklahomaOCDPA
Enacted in 2026 and not yet in force. Largely Virginia-style, with its own thresholds and cure period.
From 1 Jan 2027 Enacted, not yet in force · LouisianaLDPA
Enacted in 2026 and not yet in force. Largely Virginia-style, with its own thresholds and cure period.
From 1 Jan 2027 Enacted, not yet in force · AlabamaAPDPA
Enacted in 2026 and not yet in force. Largely Virginia-style, with its own thresholds and cure period.
From 1 May 2027 Enacted, not yet in force · VermontVDPOSA
Enacted in 2026 and not yet in force. Largely Virginia-style, with its own thresholds and cure period.
From 1 Jan 2028 In force · IllinoisBIPA
Written notice and consent before collecting biometrics, a public retention schedule, and a private right of action that has produced some of the largest privacy settlements in the US.
Since 3 Oct 2008 · Guide in progress In force · TexasCUBI
Notice and consent before capturing biometric identifiers, limits on sale and disclosure, and destruction within a set period. Enforced by the Attorney General, which has obtained large settlements.
Since 1 Sep 2009 In force · WashingtonRCW 19.375
Notice and consent or an opt-out mechanism before enrolling biometric identifiers for a commercial purpose.
Since 23 Jul 2017 In force · WashingtonMHMDA
A broad definition of consumer health data, separate consent to collect and to share, a signed authorization to sell, geofencing limits near health facilities, and a private right of action.
Since 31 Mar 2024 · Guide in progress In force · NevadaSB 370
Similar in approach to Washington's law, without a private right of action.
Since 31 Mar 2024 In force · CaliforniaDelete Act
Lets a California resident ask every registered data broker to delete their data with one request, which brokers must check and process on a fixed schedule.
Since 1 Jan 2024 In force · VermontVermont data broker law
The first state data broker registry, with security program and disclosure requirements.
Since 1 Jan 2019 In force · TexasTexas data broker law
Registration, website notices and a security program for data brokers.
Since 1 Sep 2023 In force · OregonOregon data broker registry
Annual registration for data brokers.
Since 1 Jan 2024 Challenged in court · CaliforniaCA AADC
Would require child-protective defaults and assessments for services likely to be used by children. Its enforceability is being decided in court.
See details Enacted, not yet in force · New YorkSAFE for Kids Act
Limits addictive algorithmic feeds and overnight notifications for minors without parental consent.
See details In force · New YorkSHIELD Act
Broadened New York's breach notification law and requires reasonable administrative, technical and physical safeguards.
Since 21 Mar 2020 In force · Massachusetts201 CMR 17.00
One of the first prescriptive state security rules: a written information security program, encryption and vendor oversight.
Since 1 Mar 2010 In force · New YorkNYDFS Part 500
A detailed cybersecurity program regulation with annual certification, CISO reporting, incident notice within 72 hours and personal liability exposure for certifying executives.
Since 1 Mar 2017 · Guide in progress Enforcement stayed · ColoradoColorado AI Act
The first broad US state law on algorithmic discrimination, modeled partly on risk-based approaches like the EU AI Act.
See details In forceState breach laws
Every state requires notice to affected residents after a breach of personal information. Deadlines, regulator notices and what counts as personal information differ, so a multi-state breach means applying several laws at once.
See detailsRest of world 10
PIPEDA
Canada's federal private-sector privacy law, built on ten fair information principles.
Since 1 Jan 2001 In force · QCLaw 25
The strictest privacy law in Canada, with privacy impact assessments for transfers and GDPR-level fines.
Since 22 Sep 2022 In forceLGPD
Brazil's GDPR-inspired law, with ten legal bases and a national authority.
Since 18 Sep 2020 In forcePIPL
China's comprehensive privacy law, with strict rules on consent and cross-border transfers.
Since 1 Nov 2021 In forceAPPI
Japan's privacy law, recognized by the EU as adequate.
Since 1 Apr 2005 In forcePDPA (SG)
Consent-based privacy law with mandatory breach notification since 2021.
Since 2 Jul 2014 In forcePOPIA
South Africa's comprehensive privacy law, based on eight conditions for lawful processing.
Since 1 Jul 2021 In forcenFADP
Switzerland's revised law, closely aligned with the GDPR, with fines aimed at responsible individuals.
Since 1 Sep 2023 In forcePrivacy Act (AU)
Australia's privacy law, built on the thirteen Australian Privacy Principles, now in a period of reform.
Since 1 Jan 1989 Enacted, not yet in forceDPDP Act
India's comprehensive privacy law, consent-centered, with duties for significant data fiduciaries.
See detailsThis library explains laws for practitioners. It is not legal advice, and laws change: check the sources on each page and take advice from counsel before acting.