The laws, and what they mean in practice
Privacy, AI and cybersecurity laws that shape digital trust work, from the GDPR to every US state privacy law. Each entry says who it applies to, who enforces it and when, in plain words, with the sources. Free for everyone.
Regulatory Watch follows new rules, enforcement and court decisions as they happen.
US states 40
CCPA/CPRA
The most detailed US state privacy law and the only one with a dedicated privacy regulator. It covers employee and business-to-business data, requires opt-outs from selling and sharing, and has its own regulations on automated decision-making.
Since 1 Jan 2020 · Guide in progress In force · VirginiaVCDPA
The template for most later state laws: consumer rights, opt-outs from targeted advertising, sale and profiling, opt-in consent for sensitive data, and data protection assessments.
Since 1 Jan 2023 · Guide in progress In force · ColoradoCPA
Virginia-style law with detailed Attorney General rules, including requirements to honor universal opt-out signals.
Since 1 Jul 2023 · Guide in progress In force · ConnecticutCTDPA
Virginia-style law, amended to broaden coverage and strengthen rules on sensitive data and minors.
Since 1 Jul 2023 · Guide in progress In force · UtahUCPA
One of the more business-friendly state laws, with narrower rights and higher thresholds.
Since 31 Dec 2023 In force · TexasTDPSA
No revenue or volume threshold: it reaches almost every business that is not a small business, which makes it one of the broadest state laws in practice.
Since 1 Jul 2024 · Guide in progress In force · OregonOCPA
Virginia-style law that also gives consumers the right to learn the specific third parties their data was disclosed to.
Since 1 Jul 2024 · Guide in progress In force · MontanaMCDPA
Virginia-style law with relatively low thresholds, reflecting the state's population.
Since 1 Oct 2024 In force · FloridaFDBR
Narrow in who it covers, but strict for the largest technology companies it targets.
Since 1 Jul 2024 · Guide in progress In force · IowaICDPA
A narrower Virginia-style law with fewer consumer rights.
Since 1 Jan 2025 In force · DelawareDPDPA
Virginia-style law with low thresholds and coverage of many nonprofits.
Since 1 Jan 2025 In force · New HampshireNHDPA
Virginia-style law with thresholds scaled to a small state.
Since 1 Jan 2025 In force · New JerseyNJDPA
Virginia-style law with broad sensitive-data definitions and rulemaking by the Division of Consumer Affairs.
Since 15 Jan 2025 · Guide in progress In force · NebraskaNDPA
Texas-style law without a volume threshold, applying to most businesses that are not small businesses.
Since 1 Jan 2025 In force · TennesseeTIPA
High thresholds, and an affirmative defense for businesses that follow the NIST Privacy Framework.
Since 1 Jul 2025 In force · MinnesotaMCDPA
Adds rights other states lack, including the right to question the result of a profiling decision and to see the list of third parties that received data.
Since 31 Jul 2025 · Guide in progress In force · MarylandMODPA
The strictest state law on data minimization: collection must be reasonably necessary for the service, and selling sensitive data is prohibited.
Since 1 Oct 2025 · Guide in progress In force · IndianaICDPA
Virginia-style law, in force from 2026.
Since 1 Jan 2026 In force · KentuckyKCDPA
Virginia-style law, in force from 2026.
Since 1 Jan 2026 In force · Rhode IslandRIDTPPA
Virginia-style law with unusual website disclosure duties and no cure period.
Since 1 Jan 2026 Enacted, not yet in force · OklahomaOCDPA
Enacted in 2026 and not yet in force. Largely Virginia-style, with its own thresholds and cure period.
From 1 Jan 2027 Enacted, not yet in force · LouisianaLDPA
Enacted in 2026 and not yet in force. Largely Virginia-style, with its own thresholds and cure period.
From 1 Jan 2027 Enacted, not yet in force · AlabamaAPDPA
Enacted in 2026 and not yet in force. Largely Virginia-style, with its own thresholds and cure period.
From 1 May 2027 Enacted, not yet in force · VermontVDPOSA
Enacted in 2026 and not yet in force. Largely Virginia-style, with its own thresholds and cure period.
From 1 Jan 2028 In force · IllinoisBIPA
Written notice and consent before collecting biometrics, a public retention schedule, and a private right of action that has produced some of the largest privacy settlements in the US.
Since 3 Oct 2008 · Guide in progress In force · TexasCUBI
Notice and consent before capturing biometric identifiers, limits on sale and disclosure, and destruction within a set period. Enforced by the Attorney General, which has obtained large settlements.
Since 1 Sep 2009 In force · WashingtonRCW 19.375
Notice and consent or an opt-out mechanism before enrolling biometric identifiers for a commercial purpose.
Since 23 Jul 2017 In force · WashingtonMHMDA
A broad definition of consumer health data, separate consent to collect and to share, a signed authorization to sell, geofencing limits near health facilities, and a private right of action.
Since 31 Mar 2024 · Guide in progress In force · NevadaSB 370
Similar in approach to Washington's law, without a private right of action.
Since 31 Mar 2024 In force · CaliforniaDelete Act
Lets a California resident ask every registered data broker to delete their data with one request, which brokers must check and process on a fixed schedule.
Since 1 Jan 2024 In force · VermontVermont data broker law
The first state data broker registry, with security program and disclosure requirements.
Since 1 Jan 2019 In force · TexasTexas data broker law
Registration, website notices and a security program for data brokers.
Since 1 Sep 2023 In force · OregonOregon data broker registry
Annual registration for data brokers.
Since 1 Jan 2024 Challenged in court · CaliforniaCA AADC
Would require child-protective defaults and assessments for services likely to be used by children. Its enforceability is being decided in court.
See details Enacted, not yet in force · New YorkSAFE for Kids Act
Limits addictive algorithmic feeds and overnight notifications for minors without parental consent.
See details In force · New YorkSHIELD Act
Broadened New York's breach notification law and requires reasonable administrative, technical and physical safeguards.
Since 21 Mar 2020 In force · Massachusetts201 CMR 17.00
One of the first prescriptive state security rules: a written information security program, encryption and vendor oversight.
Since 1 Mar 2010 In force · New YorkNYDFS Part 500
A detailed cybersecurity program regulation with annual certification, CISO reporting, incident notice within 72 hours and personal liability exposure for certifying executives.
Since 1 Mar 2017 · Guide in progress Enforcement stayed · ColoradoColorado AI Act
The first broad US state law on algorithmic discrimination, modeled partly on risk-based approaches like the EU AI Act.
See details In forceState breach laws
Every state requires notice to affected residents after a breach of personal information. Deadlines, regulator notices and what counts as personal information differ, so a multi-state breach means applying several laws at once.
See detailsThis library explains laws for practitioners. It is not legal advice, and laws change: check the sources on each page and take advice from counsel before acting.