The laws, and what they mean in practice

Privacy, AI and cybersecurity laws that shape digital trust work, from the GDPR to every US state privacy law. Each entry says who it applies to, who enforces it and when, in plain words, with the sources. Free for everyone.

Regulatory Watch follows new rules, enforcement and court decisions as they happen.

US states 40

In force · California

CCPA/CPRA

The most detailed US state privacy law and the only one with a dedicated privacy regulator. It covers employee and business-to-business data, requires opt-outs from selling and sharing, and has its own regulations on automated decision-making.

Since 1 Jan 2020 · Guide in progress
In force · Virginia

VCDPA

The template for most later state laws: consumer rights, opt-outs from targeted advertising, sale and profiling, opt-in consent for sensitive data, and data protection assessments.

Since 1 Jan 2023 · Guide in progress
In force · Colorado

CPA

Virginia-style law with detailed Attorney General rules, including requirements to honor universal opt-out signals.

Since 1 Jul 2023 · Guide in progress
In force · Connecticut

CTDPA

Virginia-style law, amended to broaden coverage and strengthen rules on sensitive data and minors.

Since 1 Jul 2023 · Guide in progress
In force · Utah

UCPA

One of the more business-friendly state laws, with narrower rights and higher thresholds.

Since 31 Dec 2023
In force · Texas

TDPSA

No revenue or volume threshold: it reaches almost every business that is not a small business, which makes it one of the broadest state laws in practice.

Since 1 Jul 2024 · Guide in progress
In force · Oregon

OCPA

Virginia-style law that also gives consumers the right to learn the specific third parties their data was disclosed to.

Since 1 Jul 2024 · Guide in progress
In force · Montana

MCDPA

Virginia-style law with relatively low thresholds, reflecting the state's population.

Since 1 Oct 2024
In force · Florida

FDBR

Narrow in who it covers, but strict for the largest technology companies it targets.

Since 1 Jul 2024 · Guide in progress
In force · Iowa

ICDPA

A narrower Virginia-style law with fewer consumer rights.

Since 1 Jan 2025
In force · Delaware

DPDPA

Virginia-style law with low thresholds and coverage of many nonprofits.

Since 1 Jan 2025
In force · New Hampshire

NHDPA

Virginia-style law with thresholds scaled to a small state.

Since 1 Jan 2025
In force · New Jersey

NJDPA

Virginia-style law with broad sensitive-data definitions and rulemaking by the Division of Consumer Affairs.

Since 15 Jan 2025 · Guide in progress
In force · Nebraska

NDPA

Texas-style law without a volume threshold, applying to most businesses that are not small businesses.

Since 1 Jan 2025
In force · Tennessee

TIPA

High thresholds, and an affirmative defense for businesses that follow the NIST Privacy Framework.

Since 1 Jul 2025
In force · Minnesota

MCDPA

Adds rights other states lack, including the right to question the result of a profiling decision and to see the list of third parties that received data.

Since 31 Jul 2025 · Guide in progress
In force · Maryland

MODPA

The strictest state law on data minimization: collection must be reasonably necessary for the service, and selling sensitive data is prohibited.

Since 1 Oct 2025 · Guide in progress
In force · Indiana

ICDPA

Virginia-style law, in force from 2026.

Since 1 Jan 2026
In force · Kentucky

KCDPA

Virginia-style law, in force from 2026.

Since 1 Jan 2026
In force · Rhode Island

RIDTPPA

Virginia-style law with unusual website disclosure duties and no cure period.

Since 1 Jan 2026
Enacted, not yet in force · Oklahoma

OCDPA

Enacted in 2026 and not yet in force. Largely Virginia-style, with its own thresholds and cure period.

From 1 Jan 2027
Enacted, not yet in force · Louisiana

LDPA

Enacted in 2026 and not yet in force. Largely Virginia-style, with its own thresholds and cure period.

From 1 Jan 2027
Enacted, not yet in force · Alabama

APDPA

Enacted in 2026 and not yet in force. Largely Virginia-style, with its own thresholds and cure period.

From 1 May 2027
Enacted, not yet in force · Vermont

VDPOSA

Enacted in 2026 and not yet in force. Largely Virginia-style, with its own thresholds and cure period.

From 1 Jan 2028
In force · Illinois

BIPA

Written notice and consent before collecting biometrics, a public retention schedule, and a private right of action that has produced some of the largest privacy settlements in the US.

Since 3 Oct 2008 · Guide in progress
In force · Texas

CUBI

Notice and consent before capturing biometric identifiers, limits on sale and disclosure, and destruction within a set period. Enforced by the Attorney General, which has obtained large settlements.

Since 1 Sep 2009
In force · Washington

RCW 19.375

Notice and consent or an opt-out mechanism before enrolling biometric identifiers for a commercial purpose.

Since 23 Jul 2017
In force · Washington

MHMDA

A broad definition of consumer health data, separate consent to collect and to share, a signed authorization to sell, geofencing limits near health facilities, and a private right of action.

Since 31 Mar 2024 · Guide in progress
In force · Nevada

SB 370

Similar in approach to Washington's law, without a private right of action.

Since 31 Mar 2024
In force · California

Delete Act

Lets a California resident ask every registered data broker to delete their data with one request, which brokers must check and process on a fixed schedule.

Since 1 Jan 2024
In force · Vermont

Vermont data broker law

The first state data broker registry, with security program and disclosure requirements.

Since 1 Jan 2019
In force · Texas

Texas data broker law

Registration, website notices and a security program for data brokers.

Since 1 Sep 2023
In force · Oregon

Oregon data broker registry

Annual registration for data brokers.

Since 1 Jan 2024
Challenged in court · California

CA AADC

Would require child-protective defaults and assessments for services likely to be used by children. Its enforceability is being decided in court.

See details
Enacted, not yet in force · New York

SAFE for Kids Act

Limits addictive algorithmic feeds and overnight notifications for minors without parental consent.

See details
In force · New York

SHIELD Act

Broadened New York's breach notification law and requires reasonable administrative, technical and physical safeguards.

Since 21 Mar 2020
In force · Massachusetts

201 CMR 17.00

One of the first prescriptive state security rules: a written information security program, encryption and vendor oversight.

Since 1 Mar 2010
In force · New York

NYDFS Part 500

A detailed cybersecurity program regulation with annual certification, CISO reporting, incident notice within 72 hours and personal liability exposure for certifying executives.

Since 1 Mar 2017 · Guide in progress
Enforcement stayed · Colorado

Colorado AI Act

The first broad US state law on algorithmic discrimination, modeled partly on risk-based approaches like the EU AI Act.

See details
In force

State breach laws

Every state requires notice to affected residents after a breach of personal information. Deadlines, regulator notices and what counts as personal information differ, so a multi-state breach means applying several laws at once.

See details

This library explains laws for practitioners. It is not legal advice, and laws change: check the sources on each page and take advice from counsel before acting.