States set most US privacy law in practice, and this hub tracks that patchwork as it grows.
State Comprehensive Privacy Laws
September 21, 2026
Substitute Senate Bill 1295 became Public Act 25-113 on June 24, 2025. Its Data Privacy Act sections took effect together on July 1, 2026: a lower threshold, two no-threshold triggers, more sensitive data, profiling rights, impact assessments and a ban on selling teenagers' data. Public Act 26-64 amends several of the same sections again from October 1, 2026.
Read more →
State Comprehensive Privacy Laws
September 21, 2026
Chapter 121 of the Laws of 2024 added article 39-FF, sections 899-ee to 899-mm, to New York's General Business Law. It has applied since June 20, 2025 to operators whose users are known minors or whose services are primarily directed to minors. The Attorney General issued an advance notice in 2024 and implementation guidance in May 2025, but has not published proposed rules.
Read more →
Data Security Rules
September 14, 2026
The NAIC adopted its Insurance Data Security Model Law in late 2017 as a template for state legislatures. It asks insurance licensees to run a written information security program, oversee vendors, investigate cybersecurity events and notify the insurance commissioner within 72 hours. This walks through the model's text and compares it with eight enacted state versions.
Read more →
State Comprehensive Privacy Laws
September 14, 2026
The Maryland Online Data Privacy Act has applied since October 1, 2025, but not at the section numbers its bill record gives, or in the form its chapter law's plain text suggests. This post sets out the statute as the General Assembly now publishes it, the Attorney General's reading of its minimization rule, and the immigration-enforcement amendments effective July 1, 2026.
Read more →
Data Security Rules
September 14, 2026
The SHIELD Act of 2019 did two things: it widened New York's breach notification statute, General Business Law section 899-aa, and it added section 899-bb, a standalone duty to maintain reasonable data security. This sets out the security requirement as enacted, the routes to deemed compliance, and the three later chapters that changed section 899-aa without touching section 899-bb.
Read more →
Dark Patterns
September 14, 2026
California, Colorado and Connecticut define a dark pattern in nearly the same words, and each treats agreement obtained through one as no consent at all. What differs is the material around that sentence: an example-driven regulation in California, design and withdrawal rules in Colorado, and in Connecticut a statute that points to the FTC.
Read more →
State Comprehensive Privacy Laws
September 14, 2026
Vermont enacted its Age-Appropriate Design Code as Act 63 of 2025, signed June 12, 2025. The substantive duties begin on January 1, 2027, but the Attorney General's rulemaking powers took effect in July 2025 and proposed rules are open for comment until October 2, 2026. This post covers its definitions and duties and compares them with the California provisions the Ninth Circuit has ruled on.
Read more →
Automated Decision-Making
September 7, 2026
Colorado's 2024 artificial intelligence statute was delayed once, then repealed and reenacted before it ever took effect. Senate Bill 26-189, signed May 14, 2026, replaced part 17 of article 1 of title 6 with a framework keyed to automated decision-making technology. Consequential decision survived as the trigger; the algorithmic discrimination duty did not.
Read more →
CPPA
September 7, 2026
Proposition 24 established the California Privacy Protection Agency in December 2020, but the power to write CCPA regulations did not move to it on that date. The transfer was conditional, it completed in April 2022, and the Attorney General's own regulatory authority was never extinguished. This traces the grant, the condition, the board that exercises it, and what the agency has adopted.
Read more →
Workplace Monitoring
September 7, 2026
Three states condition workplace electronic monitoring on notice rather than on consent, and each builds the requirement differently. Connecticut makes a posted notice the legal notice. New York requires a notice on hiring and a posting. Delaware offers a choice between a daily electronic notice and a one-time acknowledged one.
Read more →
Facial Recognition
September 7, 2026
Three states regulate what happens to an applicant's face during hiring, through four statutes that each define permission differently. Maryland asks for a signed waiver with four listed contents. Illinois asks for notice, an explanation and consent, and separately for a written release. Texas asks only that the individual be informed and consent before capture.
Read more →
Employee Privacy
September 7, 2026
New Jersey's tracking device statute, N.J.S.A. 34:6B-22, was approved on January 18, 2022 and took effect ninety days later. It reached that form after four reprints that moved it from a fourth-degree crime to a civil penalty, from written consent to written notice, and from any tracking device to one designed for the sole purpose of tracking.
Read more →
Data Brokers
September 7, 2026
Registration statutes are usually compared by what they demand of a filer. They can also be compared by what they hand back to the public, and on that axis the four state registries are not alike. One publishes every answer as a downloadable file; the other three publish a search box. This reports what is readable off each, and what California's file disclosed.
Read more →
Data Brokers
September 1, 2026
California's Delete Act took an existing registry and attached machinery to it: one consumer request that reaches every registered broker, a 45-day processing cycle, a triennial third-party audit and a $200-a-day fine for not signing up. This reports what SB 362 and the 2025 amendment require, and the dates the statute and the DROP regulations set.
Read more →
CCPA / CPRA
September 1, 2026
California is the only state whose comprehensive privacy law has produced a substantial public enforcement record, and it has two enforcers producing it. This charts the twelve publicly documented CCPA actions, the penalty in each, the document each rests on, and the allegations that recur across almost all of them.
Read more →
CCPA / CPRA
September 1, 2026
The California Privacy Protection Agency's rulemaking package on automated decisionmaking technology, risk assessments and cybersecurity audits took effect January 1, 2026, and the obligations it creates switch on across four separate years. This reports what the approved text defines, whom each article reaches by its own terms, and the dates written into it.
Read more →
BIPA
August 31, 2026
Two 2023 decisions of the Illinois Supreme Court set the outer bounds of exposure under the Biometric Information Privacy Act, and the legislature answered one of them in 2024. The reasoning in each is more revealing than the result: both courts reached conclusions the statutory text compelled while acknowledging the consequences.
Read more →
BIPA
August 31, 2026
Section 10 of the Illinois Biometric Information Privacy Act carves health care information out of the definition of a biometric identifier. In Mosby v. Ingalls Memorial Hospital, the Illinois Supreme Court held that the carve-out is two clauses joined by "or" and that only the first is limited to patients. The second turns on purpose, whatever the source.
Read more →
BIPA
August 31, 2026
The Illinois Workers' Compensation Act makes its own remedies exclusive for injuries covered by it, and Illinois employers argued that a fingerprint timeclock claim was such an injury. In McDonald v. Symphony Bronzeville Park, the Illinois Supreme Court answered the certified question in the negative, on grounds that turn on what kind of injury the compensation scheme was built to price.
Read more →
Biometric Privacy
August 31, 2026
Texas has regulated the commercial capture of biometric identifiers since 2009, and for more than a decade nobody enforced the statute. The record now consists of two Attorney General actions, against Meta and against Google, and the settlement documents are more informative than the headline figures.
Read more →
Biometric Privacy
August 24, 2026
Illinois is not the only state with a biometric privacy statute — it is the only one where a private plaintiff can bring the claim. Texas, Washington and Colorado each regulate the capture and retention of biometric identifiers, and each reserves enforcement to a state official. This guide reads the three statutes against each other and traces what that enforcement design produces in practice.
Read more →
Breach Notification
August 24, 2026
Every state has a breach notification statute, and no two set the same combination of deadline, regulator and threshold. This guide charts the individual-notice deadline and the regulator notice rule for the 48 states whose statutes are documented against a primary source in the research behind this site.
Read more →
Consumer Health Data
August 24, 2026
HIPAA attaches to a category of organisation. A newer class of state statute attaches to a category of information instead, defined by what it reveals about a person's health rather than by who holds it. This guide compares how Nevada, Maryland and Washington draw that line, and where the federal Health Breach Notification Rule sits alongside them.
Read more →
Data Brokers
August 24, 2026
Data broker registration is the one privacy obligation that starts with a public filing rather than a consumer request. Four states — California, Vermont, Texas and Oregon — operate registries, and each defines the regulated entity differently enough that a company can be a broker in one and not the next. This guide reads the four statutes against each other.
Read more →
Employee Privacy
August 24, 2026
There is no single employee privacy statute in any state. What exists is a stack of laws written decades apart, each aimed at whatever the anxiety of its moment was — a paper file, a tape recorder, a Facebook password, a fingerprint scanner. Read in the order they arrived, the stack explains its own gaps. This guide takes them chronologically rather than by state.
Read more →
State Comprehensive Privacy Laws
August 24, 2026
Twenty-four states have enacted a comprehensive consumer privacy statute. Twenty are in force as of August 2026 and four take effect between 2027 and 2028. This guide charts every one against the same questions, with each cell drawn from the statute cited in its row.
Read more →
Pixel Tracking
August 24, 2026
Plaintiffs suing over analytics pixels, session recording and web chat rarely plead a privacy statute. They plead eavesdropping laws written for telephone wires in 1967 and 1968, which carry per-violation damages and no requirement to prove loss. This guide sets out the statutory elements those claims turn on, the party-consent question that decides most of them, and the newer pen-register theory.
Read more →
CCPA / CPRA
August 12, 2026
The CCPA gives California residents seven rights over their personal information, each with its own mechanics, exceptions and deadlines. This guide sets out what each right requires of a covered business, how verification works, when a request can be refused, and what the statute permits by way of charging for data.
Read more →
CCPA / CPRA
August 12, 2026
The California Consumer Privacy Act does not apply to every company that touches Californian data. It applies to for-profit entities that do business in California and meet one of three thresholds. This explains what each threshold counts, how the definitions of business, service provider and third party divide responsibility, and which categories of data fall outside the statute.
Read more →
BIPA
August 12, 2026
Illinois BIPA is the only major US biometric statute that lets individuals sue directly, which is why a single-state law drives nationwide settlement exposure. This guide sets out what the statute requires, what the Illinois Supreme Court has held about accrual and injury, and where the obligations sit relative to biometric rules in other states.
Read more →
Consumer Health Data
August 12, 2026
Most health data collected by apps, wearables and websites falls outside HIPAA, which reaches only covered entities and their business associates. Washington's My Health My Data Act was the first US statute written specifically to close that gap, and it is enforceable by individuals rather than only by the state.
Read more →