Three Layers of State Privacy Law
State privacy law comes in three forms, and a single state can have all three.
Comprehensive consumer privacy laws govern personal data across industries rather than regulating one sector. They define who counts as a controller, usually by the number of state residents whose data a business handles, and they give residents rights over that data. Twenty-two of the 24 grant the same seven rights: access, correction, deletion, portability, and opt-outs from sale, from targeted advertising and from profiling used for decisions with legal or similarly significant effects. Every one of the 24 is enforced by the state attorney general or an office within it. California is the only state whose comprehensive law carries a private right of action, and it is narrow: it reaches breaches of defined categories of unencrypted and unredacted personal information resulting from a failure to maintain reasonable security, and nothing else. The State Privacy Law Comparison sets all 24 side by side on thresholds, rights, sensitive data, cure periods and penalties.
Sectoral statutes regulate one kind of information or one activity. Illinois’s Biometric Information Privacy Act (740 ILCS 14) requires written notice and a written release before a private entity collects a biometric identifier, and it is the only state biometric statute with a broad private right of action, at $1,000 per negligent and $5,000 per intentional or reckless violation. Texas and Washington also regulate biometric identifiers but reserve enforcement to the state, as the biometric privacy guide describes. Washington’s My Health My Data Act and Nevada’s NRS 603A.430 regulate consumer health data held by companies HIPAA does not reach (consumer health data guide). California, Vermont, Texas and Oregon run data broker registries (data broker guide).
Breach notification laws exist in every state, and no two set the same combination of deadline, regulator and threshold. Of the 48 states charted in the breach notification guide, 21 set a fixed outer limit for notifying individuals (five at 30 days, eleven at 45 and five at 60) and 27 use a reasonableness standard with no stated number. Maryland and Massachusetts require notice to the regulator before individuals are notified, reversing the order every other state uses.
The 24 Comprehensive Laws, by Effective Date
California stood alone for three years before a second state joined it. Four statutes then took effect in 2023, four in 2024, eight in 2025 and three in the first half of 2026. The figures below are as of August 2026, from the state pages and the comparison guide.
| State | Statute | Citation | Effective |
|---|---|---|---|
| California | California Consumer Privacy Act, as amended by the CPRA (CCPA/CPRA) | Cal. Civ. Code § 1798.100 et seq. | January 1, 2020 |
| Virginia | Virginia Consumer Data Protection Act (VCDPA) | Va. Code § 59.1-575 et seq. (tit. 59.1, ch. 53) | January 1, 2023 |
| Colorado | Colorado Privacy Act (CPA) | C.R.S. § 6-1-1301 et seq. (art. 1, pt. 13) | July 1, 2023 |
| Connecticut | Connecticut Data Privacy Act (CTDPA) | Conn. Gen. Stat. § 42-515 et seq. | July 1, 2023 |
| Utah | Utah Consumer Privacy Act (UCPA) | Utah Code § 13-61-101 et seq. | December 31, 2023 |
| Florida | Florida Digital Bill of Rights (FDBR) | Fla. Stat. §§ 501.701–501.722 | July 1, 2024 |
| Oregon | Oregon Consumer Privacy Act (OCPA) | Or. Rev. Stat. §§ 646A.570 to 646A.589 | July 1, 2024 |
| Texas | Texas Data Privacy and Security Act (TDPSA) | Tex. Bus. & Com. Code ch. 541 | July 1, 2024 |
| Montana | Montana Consumer Data Privacy Act (MCDPA) | Mont. Code Ann. §§ 30-14-2801 to 30-14-2820 | October 1, 2024 |
| Delaware | Delaware Personal Data Privacy Act (DPDPA) | Del. Code tit. 6, ch. 12D | January 1, 2025 |
| Iowa | Iowa Consumer Data Protection Act (ICDPA) | Iowa Code ch. 715D | January 1, 2025 |
| Nebraska | Nebraska Data Privacy Act (NDPA) | Neb. Rev. Stat. §§ 87-1101 to 87-1130 | January 1, 2025 |
| New Hampshire | New Hampshire Data Privacy Act (NHPA) | N.H. Rev. Stat. Ann. ch. 507-H | January 1, 2025 |
| New Jersey | New Jersey Data Privacy Act (NJDPA) | P.L.2023, c.266 (N.J.S.A. 56:8-166.4 et seq.) | January 15, 2025 |
| Tennessee | Tennessee Information Protection Act (TIPA) | Tenn. Code Ann. § 47-18-3201 et seq. | July 1, 2025 |
| Minnesota | Minnesota Consumer Data Privacy Act (MCDPA) | Minn. Stat. §§ 325M.10 to 325M.21 | July 31, 2025 |
| Maryland | Maryland Online Data Privacy Act (MODPA) | Md. Code, Com. Law § 14-4701 et seq. | October 1, 2025 |
| Indiana | Indiana Consumer Data Protection Act (INCDPA) | Ind. Code art. 24-15 | January 1, 2026 |
| Kentucky | Kentucky Consumer Data Protection Act (KCDPA) | Ky. Rev. Stat. §§ 367.3611 to 367.3629 | January 1, 2026 |
| Rhode Island | Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) | R.I. Gen. Laws ch. 6-48.1 | January 1, 2026 |
| Louisiana | Louisiana Data Privacy Act (LDPA) | Act 502 of 2026 (SB 386), La. R.S. 51:1780.1–1780.5 | January 1, 2027 (not yet in effect) |
| Oklahoma | Oklahoma Consumer Data Privacy Act (OKCDPA) | SB 546 (2026), codified at 75A O.S. §§ 300 et seq. | January 1, 2027 (not yet in effect) |
| Alabama | Alabama Personal Data Protection Act (Alabama PDPA) | HB 351, 2026 Regular Session | May 1, 2027 (not yet in effect) |
| Vermont | Vermont Data Privacy and Online Surveillance Act (VDPOSA) | Act 145 of 2026 (S.71), 9 V.S.A. §§ 2415a–2415k | January 1, 2028 (not yet in effect) |
States Without a Comprehensive Law
Twenty-six states have no comprehensive consumer privacy law: Alaska, Arizona, Arkansas, Georgia, Hawaii, Idaho, Illinois, Kansas, Maine, Massachusetts, Michigan, Mississippi, Missouri, Nevada, New Mexico, New York, North Carolina, North Dakota, Ohio, Pennsylvania, South Carolina, South Dakota, Washington, West Virginia, Wisconsin and Wyoming. Illinois is on this list despite BIPA, because BIPA governs biometric identifiers only. Washington is on it despite the My Health My Data Act for the same reason. The pages for these states describe their sectoral statutes, their breach notification law and whatever enforcement record could be found for them.
What Each State Page Contains
- The state’s comprehensive law, where it has one: its citation, effective date, who it covers and the rights it gives residents.
- Sector-specific statutes, such as biometric, health data, data broker, student data and employee privacy laws, each with its citation.
- The breach notification statute: what triggers it, the deadline for notifying individuals and when the attorney general or another regulator is notified.
- The enforcement record, where one could be found in a primary source: actions the attorney general or a court has taken under the state’s privacy laws, linked to the release or docket.
- Pending legislation where there is any, the federal laws that apply in every state, and a set of frequently asked questions.
- A numbered list of sources at the foot of the page, and the date the page was last checked.
Guides That Cover Several States
- State Privacy Law Comparison: All 24 Comprehensive Statutes Side by Side
- State Data Breach Notification Requirements, Compared Across 48 States
- Biometric Privacy Statutes Outside Illinois, and Who Gets to Enforce Them
- Health Data Laws That Reach the Companies HIPAA Never Touched
- Data Broker Registration: The Four State Registries and What They Require
- Employee Privacy Under State Law, in the Order the Statutes Arrived
Reporting, not legal advice. The state pages describe what each statute says, using publicly available primary sources linked on each page. They do not assess how any law applies to a particular person or business. How we report.