States set most US privacy law in practice, and this hub tracks that patchwork as it grows.

State Comprehensive Privacy Laws

Public Act 25-113 Rewrote the Connecticut Data Privacy Act on July 1, 2026, and a 2026 Act Rewrites Part of It Again in October

September 21, 2026

Substitute Senate Bill 1295 became Public Act 25-113 on June 24, 2025. Its Data Privacy Act sections took effect together on July 1, 2026: a lower threshold, two no-threshold triggers, more sensitive data, profiling rights, impact assessments and a ban on selling teenagers' data. Public Act 26-64 amends several of the same sections again from October 1, 2026.

Read more →
State Comprehensive Privacy Laws

New York's Child Data Protection Act: Nine Sections, a Consent Form With Four Conditions, and Rules Still Unproposed

September 21, 2026

Chapter 121 of the Laws of 2024 added article 39-FF, sections 899-ee to 899-mm, to New York's General Business Law. It has applied since June 20, 2025 to operators whose users are known minors or whose services are primarily directed to minors. The Attorney General issued an advance notice in 2024 and implementation guidance in May 2025, but has not published proposed rules.

Read more →
Data Security Rules

The NAIC Insurance Data Security Model Law: What Model #668 Requires and How Eight States Rewrote It

September 14, 2026

The NAIC adopted its Insurance Data Security Model Law in late 2017 as a template for state legislatures. It asks insurance licensees to run a written information security program, oversee vendors, investigate cybersecurity events and notify the insurance commissioner within 72 hours. This walks through the model's text and compares it with eight enacted state versions.

Read more →
State Comprehensive Privacy Laws

The Maryland Online Data Privacy Act as Enacted: New Section Numbers, No Consent Route and a 2026 Rewrite

September 14, 2026

The Maryland Online Data Privacy Act has applied since October 1, 2025, but not at the section numbers its bill record gives, or in the form its chapter law's plain text suggests. This post sets out the statute as the General Assembly now publishes it, the Attorney General's reading of its minimization rule, and the immigration-enforcement amendments effective July 1, 2026.

Read more →
Data Security Rules

New York's SHIELD Act: The Section 899-bb Security Requirement and the Breach Law Changes Since 2019

September 14, 2026

The SHIELD Act of 2019 did two things: it widened New York's breach notification statute, General Business Law section 899-aa, and it added section 899-bb, a standalone duty to maintain reasonable data security. This sets out the security requirement as enacted, the routes to deemed compliance, and the three later chapters that changed section 899-aa without touching section 899-bb.

Read more →
State Comprehensive Privacy Laws

Vermont's Age-Appropriate Design Code: What Act 63 Requires of Online Services From January 1, 2027

September 14, 2026

Vermont enacted its Age-Appropriate Design Code as Act 63 of 2025, signed June 12, 2025. The substantive duties begin on January 1, 2027, but the Attorney General's rulemaking powers took effect in July 2025 and proposed rules are open for comment until October 2, 2026. This post covers its definitions and duties and compares them with the California provisions the Ninth Circuit has ruled on.

Read more →
Automated Decision-Making

Colorado's AI Act and the Consequential Decision: What the Reenacted Part 17 Says

September 7, 2026

Colorado's 2024 artificial intelligence statute was delayed once, then repealed and reenacted before it ever took effect. Senate Bill 26-189, signed May 14, 2026, replaced part 17 of article 1 of title 6 with a framework keyed to automated decision-making technology. Consequential decision survived as the trigger; the algorithmic discrimination duty did not.

Read more →
CPPA

Where the CPPA's Rulemaking Authority Comes From, and What It Covers

September 7, 2026

Proposition 24 established the California Privacy Protection Agency in December 2020, but the power to write CCPA regulations did not move to it on that date. The transfer was conditional, it completed in April 2022, and the Attorney General's own regulatory authority was never extinguished. This traces the grant, the condition, the board that exercises it, and what the agency has adopted.

Read more →
Workplace Monitoring

Three Ways to Tell an Employee They Are Being Monitored

September 7, 2026

Three states condition workplace electronic monitoring on notice rather than on consent, and each builds the requirement differently. Connecticut makes a posted notice the legal notice. New York requires a notice on hiring and a posting. Delaware offers a choice between a daily electronic notice and a one-time acknowledged one.

Read more →
Facial Recognition

Consent to Face Analysis in a Job Interview: Four Statutes, Four Different Asks

September 7, 2026

Three states regulate what happens to an applicant's face during hiring, through four statutes that each define permission differently. Maryland asks for a signed waiver with four listed contents. Illinois asks for notice, an explanation and consent, and separately for a written release. Texas asks only that the individual be informed and consent before capture.

Read more →
Employee Privacy

New Jersey's Vehicle Tracking Notice Law, and the Four Reprints That Made It

September 7, 2026

New Jersey's tracking device statute, N.J.S.A. 34:6B-22, was approved on January 18, 2022 and took effect ninety days later. It reached that form after four reprints that moved it from a fourth-degree crime to a civil penalty, from written consent to written notice, and from any tracking device to one designed for the sole purpose of tracking.

Read more →
Data Brokers

State Data Broker Registries Compared: What Each One Actually Publishes

September 7, 2026

Registration statutes are usually compared by what they demand of a filer. They can also be compared by what they hand back to the public, and on that axis the four state registries are not alike. One publishes every answer as a downloadable file; the other three publish a search box. This reports what is readable off each, and what California's file disclosed.

Read more →
CCPA / CPRA

California's ADMT, Risk Assessment and Cybersecurity Audit Regulations: What the Final Text Says

September 1, 2026

The California Privacy Protection Agency's rulemaking package on automated decisionmaking technology, risk assessments and cybersecurity audits took effect January 1, 2026, and the obligations it creates switch on across four separate years. This reports what the approved text defines, whom each article reaches by its own terms, and the dates written into it.

Read more →
BIPA

How Illinois Decided When a BIPA Claim Accrues, and How Long It Lasts

August 31, 2026

Two 2023 decisions of the Illinois Supreme Court set the outer bounds of exposure under the Biometric Information Privacy Act, and the legislature answered one of them in 2024. The reasoning in each is more revealing than the result: both courts reached conclusions the statutory text compelled while acknowledging the consequences.

Read more →
BIPA

BIPA's Health Care Exemption After Mosby v. Ingalls Memorial

August 31, 2026

Section 10 of the Illinois Biometric Information Privacy Act carves health care information out of the definition of a biometric identifier. In Mosby v. Ingalls Memorial Hospital, the Illinois Supreme Court held that the carve-out is two clauses joined by "or" and that only the first is limited to patients. The second turns on purpose, whatever the source.

Read more →
BIPA

Why Workers' Compensation Exclusivity Does Not Bar a BIPA Claim

August 31, 2026

The Illinois Workers' Compensation Act makes its own remedies exclusive for injuries covered by it, and Illinois employers argued that a fingerprint timeclock claim was such an injury. In McDonald v. Symphony Bronzeville Park, the Illinois Supreme Court answered the certified question in the negative, on grounds that turn on what kind of injury the compensation scheme was built to price.

Read more →
Biometric Privacy

Two Cases: The Whole Enforcement Record Under Texas's Biometric Statute

August 31, 2026

Texas has regulated the commercial capture of biometric identifiers since 2009, and for more than a decade nobody enforced the statute. The record now consists of two Attorney General actions, against Meta and against Google, and the settlement documents are more informative than the headline figures.

Read more →
Biometric Privacy

Biometric Privacy Statutes Outside Illinois, and Who Gets to Enforce Them

August 24, 2026

Illinois is not the only state with a biometric privacy statute — it is the only one where a private plaintiff can bring the claim. Texas, Washington and Colorado each regulate the capture and retention of biometric identifiers, and each reserves enforcement to a state official. This guide reads the three statutes against each other and traces what that enforcement design produces in practice.

Read more →
Breach Notification

State Data Breach Notification Requirements, Compared Across 48 States

August 24, 2026

Every state has a breach notification statute, and no two set the same combination of deadline, regulator and threshold. This guide charts the individual-notice deadline and the regulator notice rule for the 48 states whose statutes are documented against a primary source in the research behind this site.

Read more →
Consumer Health Data

Health Data Laws That Reach the Companies HIPAA Never Touched

August 24, 2026

HIPAA attaches to a category of organisation. A newer class of state statute attaches to a category of information instead, defined by what it reveals about a person's health rather than by who holds it. This guide compares how Nevada, Maryland and Washington draw that line, and where the federal Health Breach Notification Rule sits alongside them.

Read more →
Data Brokers

Data Broker Registration: The Four State Registries and What They Require

August 24, 2026

Data broker registration is the one privacy obligation that starts with a public filing rather than a consumer request. Four states — California, Vermont, Texas and Oregon — operate registries, and each defines the regulated entity differently enough that a company can be a broker in one and not the next. This guide reads the four statutes against each other.

Read more →
Employee Privacy

Employee Privacy Under State Law, in the Order the Statutes Arrived

August 24, 2026

There is no single employee privacy statute in any state. What exists is a stack of laws written decades apart, each aimed at whatever the anxiety of its moment was — a paper file, a tape recorder, a Facebook password, a fingerprint scanner. Read in the order they arrived, the stack explains its own gaps. This guide takes them chronologically rather than by state.

Read more →
Pixel Tracking

Wiretapping Claims Against Website Tracking: How the Theories Work

August 24, 2026

Plaintiffs suing over analytics pixels, session recording and web chat rarely plead a privacy statute. They plead eavesdropping laws written for telephone wires in 1967 and 1968, which carry per-violation damages and no requirement to prove loss. This guide sets out the statutory elements those claims turn on, the party-consent question that decides most of them, and the newer pen-register theory.

Read more →
CCPA / CPRA

Consumer Rights Under the CCPA: What California Residents Can Require

August 12, 2026

The CCPA gives California residents seven rights over their personal information, each with its own mechanics, exceptions and deadlines. This guide sets out what each right requires of a covered business, how verification works, when a request can be refused, and what the statute permits by way of charging for data.

Read more →
CCPA / CPRA

Who Has to Comply With the CCPA? The Applicability Thresholds Explained

August 12, 2026

The California Consumer Privacy Act does not apply to every company that touches Californian data. It applies to for-profit entities that do business in California and meet one of three thresholds. This explains what each threshold counts, how the definitions of business, service provider and third party divide responsibility, and which categories of data fall outside the statute.

Read more →
BIPA

Illinois BIPA: What the Biometric Information Privacy Act Requires

August 12, 2026

Illinois BIPA is the only major US biometric statute that lets individuals sue directly, which is why a single-state law drives nationwide settlement exposure. This guide sets out what the statute requires, what the Illinois Supreme Court has held about accrual and injury, and where the obligations sit relative to biometric rules in other states.

Read more →
Consumer Health Data

Washington's My Health My Data Act Covers Health Data HIPAA Does Not

August 12, 2026

Most health data collected by apps, wearables and websites falls outside HIPAA, which reaches only covered entities and their business associates. Washington's My Health My Data Act was the first US statute written specifically to close that gap, and it is enforceable by individuals rather than only by the state.

Read more →