State Privacy Law Comparison: All 24 Comprehensive Statutes Side by Side
Correction, September 14, 2026. This guide originally described Maryland's sensitive-data rule as "strictly necessary, plus consent" and cited the Act as § 14-4601 et seq. Md. Code, Com. Law § 14-4707(a)(1) permits collecting or processing sensitive data only where strictly necessary, with no consent route, and the Act is codified at §§ 14-4701 to 14-4714.
Correction, September 21, 2026. This guide originally said Connecticut's cure period expired on December 31, 2024. Under Conn. Gen. Stat. § 42-525(c), the mandatory 60-day cure ended on that date, and from January 1, 2025 the Attorney General may offer a cure at its discretion, weighing seven factors.
Key Takeaways
- Twenty-four states have enacted comprehensive privacy statutes; twenty are in effect and four — Oklahoma, Louisiana, Alabama and Vermont — take effect between January 2027 and January 2028.
- Twenty-two of the twenty-four grant the same seven consumer rights. Iowa is the outlier at four, and Utah grants six.
- California remains the only one of the twenty-four with a private right of action, and it reaches only breaches caused by a failure to maintain reasonable security.
- Texas and Nebraska state no numeric threshold at all, keying applicability to the federal Small Business Administration definition instead.
- Cure periods are diverging rather than converging: nine are permanent, four have lapsed or been repealed, and five are now discretionary.
How Many States Have a Comprehensive Privacy Law
Twenty-four states have enacted a comprehensive consumer privacy statute — a law governing personal data across sectors rather than regulating one industry or one data type. As of August 2026, twenty are in force. Four have been signed but have not reached their effective dates: Oklahoma and Louisiana on January 1, 2027, Alabama on May 1, 2027, and Vermont on January 1, 2028.
The count is worth stating precisely because it is often reported loosely. Statutes regulating a single category — biometric identifiers in Illinois, genetic data in New Mexico, consumer health data in Nevada — are not comprehensive laws and are not counted here, even though they can impose sharper duties within their scope. What follows compares only the cross-sector statutes, and compares each on the terms it states for itself.
Every figure in the tables below is taken from the statute cited in that row. The source list at the foot of this guide links a primary document for each of the twenty-four laws.
The Chronology, and What Each Statute Is Called
Ordering by effective date rather than alphabetically shows the shape of the thing. California stood alone for three years before any second state joined it. Then the pace changed sharply: four statutes took effect in 2023, four more in 2024, eight in 2025, and three in the first half of 2026. Twelve of the twenty-four became enforceable within a twenty-four-month window.
| State | Statute | Short name | Effective | Status |
|---|---|---|---|---|
| California | California Consumer Privacy Act, as amended by the CPRA | CCPA/CPRA | January 1, 2020; CPRA amendments operative January 1, 2023 | In effect |
| Virginia | Virginia Consumer Data Protection Act | VCDPA | January 1, 2023 | In effect |
| Colorado | Colorado Privacy Act | CPA | July 1, 2023 | In effect |
| Connecticut | Connecticut Data Privacy Act | CTDPA | July 1, 2023 | In effect |
| Utah | Utah Consumer Privacy Act | UCPA | December 31, 2023 | In effect |
| Texas | Texas Data Privacy and Security Act | TDPSA | July 1, 2024 | In effect |
| Florida | Florida Digital Bill of Rights | FDBR | July 1, 2024 | In effect |
| Oregon | Oregon Consumer Privacy Act | OCPA | July 1, 2024 | In effect |
| Montana | Montana Consumer Data Privacy Act | MCDPA | October 1, 2024 | In effect |
| Delaware | Delaware Personal Data Privacy Act | DPDPA | January 1, 2025 | In effect |
| Iowa | Iowa Consumer Data Protection Act | ICDPA | January 1, 2025 | In effect |
| Nebraska | Nebraska Data Privacy Act | NDPA | January 1, 2025 | In effect |
| New Hampshire | New Hampshire Data Privacy Act | NHPA | January 1, 2025 | In effect |
| New Jersey | New Jersey Data Privacy Act | NJDPA | January 15, 2025 | In effect |
| Tennessee | Tennessee Information Protection Act | TIPA | July 1, 2025 | In effect |
| Minnesota | Minnesota Consumer Data Privacy Act | MCDPA | July 31, 2025 | In effect |
| Maryland | Maryland Online Data Privacy Act | MODPA | October 1, 2025 | In effect |
| Indiana | Indiana Consumer Data Protection Act | INCDPA | January 1, 2026 | In effect |
| Kentucky | Kentucky Consumer Data Protection Act | KCDPA | January 1, 2026 | In effect |
| Rhode Island | Rhode Island Data Transparency and Privacy Protection Act | RIDTPPA | January 1, 2026 | In effect |
| Oklahoma | Oklahoma Consumer Data Privacy Act | OKCDPA | January 1, 2027 | Enacted, not yet effective |
| Louisiana | Louisiana Data Privacy Act | LDPA | January 1, 2027 | Enacted, not yet effective |
| Alabama | Alabama Personal Data Protection Act | Alabama PDPA | May 1, 2027 | Enacted, not yet effective |
| Vermont | Vermont Data Privacy and Online Surveillance Act | VDPOSA | January 1, 2028 | Enacted, not yet effective |
The short names matter for searching case law and enforcement records, and two of them collide: Montana and Minnesota both abbreviate to MCDPA. Colorado is the CPA, an abbreviation also used in secondary writing for the California Privacy Rights Act, though the operative California text is the CCPA as amended rather than a freestanding act.
Applicability Thresholds Compared
The threshold is the first question each statute answers and the one on which they differ most. Three patterns recur. The most common pairs a consumer-count trigger with a lower count coupled to a revenue-share-from-selling-data trigger — Virginia's 100,000 consumers, or 25,000 consumers plus more than 50% of gross revenue from the sale of personal data, is the template most later states followed. A second pattern adds an absolute revenue floor, as Utah and Tennessee do at $25 million. A third dispenses with numbers entirely, which Texas and Nebraska do.
Among the twenty-two statutes that use a consumer count at all, the primary trigger spans a factor of seven. Montana and Alabama sit lowest at 25,000 residents. Connecticut, Delaware, New Hampshire, Maryland, Rhode Island and Vermont sit at 35,000. Louisiana sits at 75,000. Eleven states — California, Virginia, Colorado, Utah, Oregon, Iowa, New Jersey, Minnesota, Indiana, Kentucky and Oklahoma — set it at 100,000, making that the modal figure. Tennessee sits highest at 175,000. Florida sits outside the pattern altogether, reaching only companies above $1 billion in global gross annual revenue that also satisfy one of three business-model tests.
| State | Citation | Applicability threshold |
|---|---|---|
| California | Cal. Civ. Code § 1798.100 et seq. | Is a for-profit business doing business in California that determines the purposes and means of processing, and meets any one of three alternatives: Gross annual revenue over $25 million in the preceding calendar year, or Buys, sells or shares the personal information of 100,000 or more California consumers or households, or Derives 50% or more of annual revenue from selling or sharing personal information |
| Virginia | Va. Code § 59.1-575 et seq. (tit. 59.1, ch. 53) | Controls or processes the personal data of at least 100,000 Virginia consumers during a calendar year, or Controls or processes the personal data of at least 25,000 consumers and derives over 50% of gross revenue from the sale of personal data |
| Colorado | C.R.S. § 6-1-1301 et seq. (art. 1, pt. 13) | Controls or processes the personal data of at least 100,000 Colorado consumers during a calendar year, or Derives revenue or receives a discount on goods or services from selling personal data and controls or processes the data of at least 25,000 consumers For biometric identifiers or biometric data, any amount — the ordinary numeric thresholds do not gate § 6-1-1314 |
| Connecticut | Conn. Gen. Stat. § 42-515 et seq. | Conducts business in Connecticut or produces products or services targeted to Connecticut residents, and Controlled or processed the personal data of at least 35,000 consumers, excluding data processed solely to complete payment transactions, or Controlled or processed consumers’ sensitive data, excluding data processed solely to complete payment transactions, or Offered consumers’ personal data for sale in trade or commerce — with all consumer health data controllers covered regardless of size |
| Utah | Utah Code § 13-61-101 et seq. | Conducts business in Utah or targets Utah residents, and Has annual revenue of $25,000,000 or more, and Controls or processes the personal data of 100,000+ consumers in a calendar year, or derives over 50% of gross revenue from the sale of personal data while processing the data of 25,000+ consumers |
| Texas | Tex. Bus. & Com. Code ch. 541 | Conducts business in Texas or produces products or services consumed by Texas residents, and Processes or engages in the sale of personal data, and Is not a small business as defined by the U.S. Small Business Administration (no revenue or consumer-count minimum) |
| Florida | Fla. Stat. §§ 501.701–501.722 | Organized or operated for the profit or financial benefit of its shareholders or owners, and Makes in excess of $1 billion in global gross annual revenues, and Derives 50%+ of global gross annual revenue from online advertising, or operates a smart speaker and voice-command service with an integrated virtual assistant, or operates an app store or digital distribution platform offering 250,000+ applications |
| Oregon | Or. Rev. Stat. §§ 646A.570 to 646A.589 | Conducts business in Oregon or provides products or services to Oregon residents, and during a calendar year controls or processes The personal data of 100,000 or more consumers, other than data processed solely to complete a payment transaction, or The personal data of 25,000 or more consumers while deriving 25% or more of annual gross revenue from selling personal data — with motor vehicle manufacturers covered regardless of these numbers |
| Montana | Mont. Code Ann. §§ 30-14-2801 to 30-14-2820 | Conducts business in Montana or produces products or services targeted to Montana residents, and Controls or processes the personal data of not less than 25,000 consumers, excluding data processed solely to complete a payment transaction, or Controls or processes the personal data of not less than 15,000 consumers while deriving more than 25% of gross revenue from the sale of personal data |
| Delaware | Del. Code tit. 6, ch. 12D | Conducts business in Delaware or produces products or services targeted to Delaware residents, and during the preceding calendar year Controlled or processed the personal data of not less than 35,000 consumers, excluding data controlled or processed solely to complete a payment transaction, or Controlled or processed the personal data of not less than 10,000 consumers and derived more than 20% of gross revenue from the sale of personal data |
| Iowa | Iowa Code ch. 715D | Controls or processes the personal data of at least 100,000 Iowa consumers during a calendar year, or Controls or processes the personal data of at least 25,000 consumers and derives over 50% of gross revenue from the sale of personal data |
| Nebraska | Neb. Rev. Stat. §§ 87-1101 to 87-1130 | Conducts business in Nebraska or produces products or services consumed by Nebraska residents, and Processes or engages in the sale of personal data, and Is not a small business as determined under the federal Small Business Administration definition — though § 87-1118 still bars a small business from selling sensitive data without consent |
| New Hampshire | N.H. Rev. Stat. Ann. ch. 507-H | Conducts business in New Hampshire or produces products or services targeted to New Hampshire residents, and During a one-year period controlled or processed the personal data of not less than 35,000 unique consumers, excluding data processed solely to complete a payment transaction, or Controlled or processed the personal data of not less than 10,000 unique consumers while deriving more than 25% of gross revenue from the sale of personal data |
| New Jersey | P.L.2023, c.266 (N.J.S.A. 56:8-166.4 et seq.) | Conducts business in New Jersey or produces products or services targeted to New Jersey residents, and During a calendar year controls or processes the personal data of at least 100,000 consumers, excluding data processed solely to complete a payment transaction, or Controls or processes the personal data of at least 25,000 consumers and derives revenue, or receives a discount on the price of any goods or services, from the sale of personal data |
| Tennessee | Tenn. Code Ann. § 47-18-3201 et seq. | Exceeds $25,000,000 in revenue, and Controls or processes the personal information of at least 25,000 consumers and derives more than 50% of gross revenue from the sale of personal information, or During a calendar year, controls or processes the personal information of at least 175,000 consumers |
| Minnesota | Minn. Stat. §§ 325M.10 to 325M.21 | Conducts business in Minnesota or produces products or services targeted to Minnesota residents, and During a calendar year controls or processes the personal data of 100,000 consumers or more, excluding data processed solely to complete a payment transaction, or Derives over 25% of gross revenue from the sale of personal data and processes or controls the personal data of 25,000 consumers or more |
| Maryland | Md. Code, Com. Law § 14-4701 et seq. | Conducts business in Maryland or targets Maryland residents, and during the preceding calendar year controlled or processed the personal data of at least 35,000 consumers, excluding data processed solely to complete a payment transaction, or Controlled or processed the personal data of at least 10,000 consumers and derived more than 20% of gross revenue from the sale of personal data |
| Indiana | Ind. Code art. 24-15 | Conducts business in Indiana or produces products or services targeted to Indiana residents, and During a calendar year controls or processes the personal data of at least 100,000 Indiana consumers, or Controls or processes the personal data of at least 25,000 Indiana consumers and derives more than 50% of gross revenue from the sale of personal data |
| Kentucky | Ky. Rev. Stat. §§ 367.3611 to 367.3629 | Conducts business in the Commonwealth or produces products or services targeted to Kentucky residents, and During a calendar year controls or processes the personal data of at least 100,000 consumers, or Controls or processes the personal data of at least 25,000 consumers while deriving over 50% of gross revenue from the sale of personal data |
| Rhode Island | R.I. Gen. Laws ch. 6-48.1 | Any commercial website or internet service provider doing business in Rhode Island or with Rhode Island customers must designate a controller and make the § 6-48.1-3 disclosures — no threshold applies, and The § 6-48.1-4 processing obligations apply to for-profit entities that during the preceding calendar year controlled or processed the personal data of not less than 35,000 customers, excluding data processed solely to complete a payment transaction, or Controlled or processed the personal data of not less than 10,000 customers and derived more than 20% of gross revenue from the sale of personal data |
| Oklahoma | SB 546 (2026), codified at 75A O.S. §§ 300 et seq. | Conducts business in Oklahoma or produces a product or service targeted to Oklahoma residents, and During a calendar year controls or processes the personal data of at least 100,000 consumers, or Controls or processes the personal data of at least 25,000 consumers and derives over 50% of gross revenue from the sale of personal data |
| Louisiana | Act 502 of 2026 (SB 386), La. R.S. 51:1780.1–1780.5 | Conducts business in the state, and Has annual gross revenues in excess of $25 million, or Annually buys, receives for commercial purposes, sells or shares for commercial purposes the personal information of 75,000 or more consumers, households or devices, or Derives 50% or more of annual revenues from selling consumers’ personal information |
| Alabama | HB 351, 2026 Regular Session | Conducts business in Alabama or produces products or services targeted to Alabama residents, and Controls or processes the personal data of more than 25,000 consumers, excluding data processed solely to complete a payment transaction, or Derives more than 25% of gross revenue from the sale of personal data, regardless of the number of consumers whose data the person controls or processes |
| Vermont | Act 145 of 2026 (S.71), 9 V.S.A. §§ 2415a–2415k | Conducts business in Vermont or produces products or services targeted to Vermont residents, and During the preceding calendar year controlled or processed the personal data of not fewer than 35,000 consumers, excluding data processed solely to complete a payment transaction, or Controlled or processed the sensitive data of not fewer than 3,000 consumers, or Offered for sale in trade or commerce the personal data of not fewer than 3,000 consumers |
The Statutes With No Numeric Threshold
Texas and Nebraska share a drafting approach that makes them the widest-reaching state privacy laws in the country measured by the number of businesses inside them. Neither states a consumer-count or revenue minimum. Each instead reaches any person that conducts business in the state or produces products or services consumed by its residents, that processes or engages in the sale of personal data, and that is not a small business as defined by the United States Small Business Administration.
Both then keep one duty on the small businesses the applicability test otherwise excludes. Texas section 541.107 and Nebraska section 87-1118 each bar a small business from engaging in the sale of sensitive data without prior consumer consent. The effect is that a company well below the thresholds excluding it in California or Virginia is inside the Texas and Nebraska statutes, and a company small enough to fall outside them is still reached on the sensitive-data question.
Rhode Island arrives at a comparable place by a different route. The section 6-48.1-3 disclosure duties apply to any commercial website or internet service provider doing business in the state or with Rhode Island customers, with no threshold at all; only the section 6-48.1-4 processing obligations are gated by the 35,000-customer count.
Consumer Rights Compared
Rights are where the statutes converge rather than diverge. Twenty-two of the twenty-four grant the same seven: access, correction, deletion, portability, and opt-outs from sale, from targeted advertising, and from profiling in furtherance of decisions producing legal or similarly significant effects.
Two states depart from the template. Iowa grants four — access, deletion, portability and an opt-out of sale — with no right of correction and no opt-out of targeted advertising or profiling, which makes it the narrowest comprehensive statute in the country on this axis. Utah grants six, omitting only the profiling opt-out.
| State | Access | Correct | Delete | Portability | Opt out of sale | Opt out of targeted ads | Opt out of profiling |
|---|---|---|---|---|---|---|---|
| California | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Virginia | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Colorado | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Connecticut | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Utah | Yes | Yes | Yes | Yes | Yes | Yes | — |
| Texas | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Florida | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Oregon | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Montana | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Delaware | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Iowa | Yes | — | Yes | Yes | Yes | — | — |
| Nebraska | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| New Hampshire | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| New Jersey | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Tennessee | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Minnesota | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Maryland | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Indiana | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Kentucky | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Rhode Island | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Oklahoma | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Louisiana | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Alabama | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Vermont | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
The uniformity of this table is the most consequential single fact in the comparison. A rights-request process built to the seven-right template meets the terms of twenty-two statutes at once, and the divergence that remains sits in the mechanics — response windows, verification standards, appeal rights — rather than in which rights exist at all.
Sensitive Data, and the One Private Right of Action
Opt-in consent before processing sensitive data is the dominant rule: twenty of the twenty-four require it. Four depart. Utah and Iowa require notice and an opportunity to opt out rather than prior consent. California uses a different mechanism again, a right to limit the use and disclosure of sensitive personal information to what is necessary to provide the service. Maryland is the strictest of the twenty-four: collection and processing of sensitive data are confined to what is strictly necessary to provide the requested product or service, and the sale of sensitive data is prohibited outright rather than gated by consent.
On private enforcement the picture is simpler. California is the only state of the twenty-four whose comprehensive statute carries a private right of action, and it is narrow — reaching a breach of defined categories of unencrypted and unredacted personal information resulting from a failure to maintain reasonable security, and nothing else. An ignored access request or a missing opt-out link is a regulator's matter in all twenty-four.
| State | Sensitive data treatment | Private right of action |
|---|---|---|
| California | right to limit use and disclosure | Yes (breach only) |
| Virginia | opt-in | No |
| Colorado | opt-in | No |
| Connecticut | opt-in | No |
| Utah | opt-out (notice and opportunity to opt out) | No |
| Texas | opt-in | No |
| Florida | opt-in | No |
| Oregon | opt-in | No |
| Montana | opt-in | No |
| Delaware | opt-in | No |
| Iowa | notice and opportunity to opt out | No |
| Nebraska | opt-in | No |
| New Hampshire | opt-in | No |
| New Jersey | opt-in | No |
| Tennessee | opt-in | No |
| Minnesota | opt-in | No |
| Maryland | strictly necessary only, no consent route; sale prohibited outright | No |
| Indiana | opt-in | No |
| Kentucky | opt-in | No |
| Rhode Island | opt-in | No |
| Oklahoma | opt-in | No |
| Louisiana | opt-in | No |
| Alabama | opt-in | No |
| Vermont | opt-in | No |
Cure Periods and Their Sunset Dates
The right to cure — a window in which a controller can fix a violation before enforcement proceeds — is the fastest-moving variable in the comparison, and the one most likely to be out of date in a chart compiled a year ago. Four distinct treatments now exist across the twenty-four statutes.
Nine provide a permanent cure period with no sunset: Texas and Utah at 30 days, Iowa at 90, Tennessee at 60, and Nebraska, Indiana, Kentucky, Oklahoma and Alabama on their own terms. Four have lapsed or been repealed: Colorado was repealed for the Act generally on January 1, 2025, Montana removed its provision outright effective October 1, 2025, Oregon lapsed on January 1, 2026, and Minnesota expired on January 31, 2026. Five are discretionary rather than mandatory: Florida and Maryland by their own terms, and Connecticut, Delaware and New Hampshire, which converted from mandatory to discretionary against statutory factors. Connecticut's mandatory 60-day cure ran through December 31, 2024, and from January 1, 2025 its section 42-525(c) lets the Attorney General weigh seven factors in deciding whether to offer one; Delaware and New Hampshire converted on January 1, 2026 against seven and six factors respectively. New Jersey's window closed by its own terms in mid-2026. Rhode Island provides none at all, and California's fixed window was removed by the CPRA, leaving time to cure discretionary there. Louisiana's and Vermont's are time-limited windows that open when the statutes do and close again on stated dates.
| State | Right to cure as the statute now stands |
|---|---|
| California | None — the fixed cure window was removed by the CPRA; time to cure is discretionary |
| Virginia | 30 days |
| Colorado | 60 days, repealed January 1, 2025 for the Act generally; a separate 60-day cure for the minors’ sections runs until December 31, 2026 |
| Connecticut | 60 days, mandatory through December 31, 2024; discretionary from January 1, 2025 against seven factors (§ 42-525(c)) |
| Utah | 30 days (permanent) |
| Texas | 30 days (permanent right to cure) |
| Florida | 45 days, discretionary; unavailable for known-child violations |
| Oregon | 30 days, lapsed January 1, 2026 except for certain public broadcast stations; that carve-out was repealed July 1, 2026 |
| Montana | None — removed from § 30-14-2817 by Ch. 567, L. 2025, effective October 1, 2025 |
| Delaware | 60 days, mandatory to December 31, 2025; discretionary from January 1, 2026 against seven statutory factors |
| Iowa | 90 days (permanent) |
| Nebraska | 30 days, with no sunset, but the cure must be documented (Neb. Rev. Stat. § 87-1122) |
| New Hampshire | 60 days, mandatory to December 31, 2025; discretionary from January 1, 2026 against six statutory factors |
| New Jersey | 30 days, available until the first day of the 18th month following the effective date |
| Tennessee | 60 days (permanent) |
| Minnesota | 30 days after a warning letter; the paragraph expired January 31, 2026 |
| Maryland | At least 60 days, discretionary, for violations occurring on or before April 1, 2027 |
| Indiana | 30 days, with no sunset date (Ind. Code § 24-15-10-3) |
| Kentucky | 30 days, with no sunset date (Ky. Rev. Stat. § 367.3627(2)) |
| Rhode Island | None — the chapter provides no right to cure |
| Oklahoma | 30 days’ written notice before suit, with no expiry date |
| Louisiana | 30 days’ written notice before an investigation, available January 1 through July 31, 2027 only |
| Alabama | 45 days after a notice of violation, with no expiry date |
| Vermont | 60 days after a notice of violation, available January 1, 2028 through June 30, 2029 |
The direction of travel is one-way. No state in the group has added a cure period or extended one after the fact; the movement has been from mandatory to discretionary, and from discretionary to none.
Enforcement Authority and Penalty Exposure
Every one of the twenty-four statutes is enforced by the state attorney general or an office within it. Two add to that. Colorado shares authority with district attorneys, and California is the only state with a dedicated regulator — the California Privacy Protection Agency, the first administrative body in the United States created solely to enforce a consumer privacy law, which exercises rulemaking and enforcement powers alongside the Attorney General rather than instead of them.
Stated penalties range from $5,000 per violation in Connecticut to $50,000 in Florida, trebled in three defined circumstances. The most common figure by a wide margin is $7,500. Several states set no privacy-specific figure at all and route violations through an existing consumer protection statute: New Jersey through the Consumer Fraud Act, Louisiana through the Unfair Trade Practices and Consumer Protection Law, Vermont through the Consumer Protection Act, and Maryland through its unfair, abusive or deceptive trade practice provisions.
| State | Enforcer | Penalty as stated in the statute |
|---|---|---|
| California | California Privacy Protection Agency and the Attorney General | Up to $7,500 per intentional violation |
| Virginia | Virginia Attorney General | Up to $7,500 per violation under Va. Code § 59.1-584, plus reasonable investigation expenses and attorney fees |
| Colorado | Colorado Attorney General and district attorneys | Up to $20,000 per violation under C.R.S. § 6-1-112(1)(a), counted separately per consumer or transaction, rising to $50,000 where the violation was committed against an elderly person |
| Connecticut | Connecticut Attorney General, Privacy Section | Up to $5,000 per violation under the Connecticut Unfair Trade Practices Act |
| Utah | Utah Attorney General, on referral from the Division of Consumer Protection | Actual damages to the consumer plus up to $7,500 per violation under Utah Code § 13-61-402(3)(d) |
| Texas | Texas Attorney General | Up to $7,500 per violation under Tex. Bus. & Com. Code § 541.155 |
| Florida | Florida Department of Legal Affairs | Up to $50,000 per violation, treble in three defined circumstances |
| Oregon | Oregon Attorney General, Department of Justice Privacy Unit | Up to $7,500 for each violation under Or. Rev. Stat. § 646A.589(4)(a) |
| Montana | Montana Attorney General | Up to $7,500 for each violation under Mont. Code Ann. § 30-14-2820(2) |
| Delaware | Delaware Department of Justice | The Department of Justice states civil penalties of up to $10,000 per violation; 29 Del. C. § 2522(b) sets that figure for a wilful violation in court and § 2523 sets $5,000 administratively |
| Iowa | Iowa Attorney General | Up to $7,500 per violation under Iowa Code § 715D.8(3), paid into the consumer education and litigation fund established under § 714.16C |
| Nebraska | Nebraska Attorney General | Up to $7,500 for each violation under Neb. Rev. Stat. § 87-1124(1) |
| New Hampshire | New Hampshire Attorney General | Civil penalties of up to $10,000 for each violation under RSA 358-A:4, III(b), which a violation of RSA 507-H becomes by operation of § 507-H:11, V |
| New Jersey | New Jersey Attorney General (Division of Consumer Affairs) | Enforced as an unlawful practice under the Consumer Fraud Act, which sets civil penalties of up to $10,000 per violation for a first offense and up to $20,000 for every subsequent offense under N.J.S.A. 56:8-13 |
| Tennessee | Tennessee Attorney General and Reporter | Up to $7,500 per violation under Tenn. Code Ann. § 47-18-3212(d)(1), plus discretionary treble damages for a wilful or knowing violation |
| Minnesota | Minnesota Attorney General | Injunction and a civil penalty of not more than $7,500 for each violation under Minn. Stat. § 325M.20(c) |
| Maryland | Maryland Division of Consumer Protection, Office of the Attorney General | A violation is an unfair, abusive or deceptive trade practice under title 13, carrying up to $10,000 per violation and up to $25,000 for a repeated violation under Md. Code, Com. Law § 13-410 |
| Indiana | Indiana Attorney General | Up to $7,500 per violation under Ind. Code § 24-15-10-2(a) |
| Kentucky | Kentucky Attorney General, Office of Data Privacy | Up to $7,500 for each continued violation under Ky. Rev. Stat. § 367.3627(3) |
| Rhode Island | Rhode Island Attorney General | $100 to $500 for each intentional disclosure under § 6-48.1-8(a)(2); other violations are deceptive trade practices carrying up to $10,000 per violation under § 6-13.1-8 |
| Oklahoma | Oklahoma Attorney General | Up to $7,500 per violation, plus court-awarded attorney fees and investigation expenses |
| Louisiana | Louisiana Attorney General | Enforced as an unfair and deceptive trade practice under the Unfair Trade Practices and Consumer Protection Law, R.S. 51:1401 et seq. |
| Alabama | Alabama Attorney General | Up to $15,000 per violation, assessed by a court after a failure to correct within 45 days |
| Vermont | Vermont Attorney General | Enforced as a violation of the Vermont Consumer Protection Act, 9 V.S.A. chapter 63 |
Per-violation counting is what makes these figures consequential rather than nominal. Colorado states the point explicitly: penalties are counted separately per consumer or per transaction, which turns a $20,000 maximum into an aggregate that scales with the size of the affected population.
Universal Opt-Out Preference Signals
Recognition of a browser-transmitted opt-out signal, such as Global Privacy Control, is a genuine point of divergence, and it is the one axis on which this chart does not claim completeness. Of the twenty-four state records behind this comparison, eight document the treatment of opt-out preference signals against a primary source: Colorado, Connecticut, Delaware, New Hampshire, New Jersey, Indiana, Kentucky and Rhode Island. California's obligation to honour such a signal is stated on its own statute page.
The remaining states were not researched on this specific question, and no claim is made here about what their statutes provide. That gap is recorded rather than filled by inference, because the mechanism differs enough between states — some requiring recognition outright, some allowing it as one of two permitted methods — that a generalisation drawn from the eight would not reliably describe the rest.
Where the Laws Genuinely Diverge
Read across the six tables, the divergence concentrates in four places rather than being spread evenly. Thresholds differ by a factor of seven among the states that use consumer counts, and differ in kind beyond that, with Texas and Nebraska using no number at all and Florida using a revenue floor plus a business-model test. Cure periods differ in whether they exist at all, and are moving. Penalty figures differ by a factor of ten, and the counting rule beneath them differs further. Sensitive data treatment splits four ways.
Against that, consumer rights are close to uniform, the enforcer is the attorney general almost everywhere, and private enforcement is absent everywhere but California. The practical consequence is that the questions of whether a statute applies and what happens when it is broken vary far more between states than the question of what the statute grants a consumer.
What This Chart Does Not Cover
Six axes are compared here. Several others are not, and their absence is deliberate rather than an oversight. Data protection assessment requirements, controller-processor contract terms, response deadlines and appeal mechanics, children's and minors' provisions, and the exemptions for entities and data regulated under HIPAA, the Gramm-Leach-Bliley Act and the Fair Credit Reporting Act all differ between these statutes and are not charted above.
The exemption structures in particular resist tabulation: some states exempt covered entities wholesale while others exempt only the regulated data, and the difference determines whether a healthcare or financial services business is outside the statute or merely outside part of it. Each state page linked from the sources below sets out that state's exemptions against its own text.
Frequently Asked Questions
How many states have comprehensive privacy laws in 2026?
Which state privacy law has the lowest applicability threshold?
Do all state privacy laws grant the same consumer rights?
Which states still allow a right to cure before enforcement?
Can consumers sue directly under state privacy laws?
Sources
Everything above is reported from these documents. Follow them to verify.
- California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq. statute
- California Privacy Protection Agency — CCPA regulations regulation
- Va. Code § 59.1-576 — Scope; exemptions statute
- Colorado Revised Statutes 2024, Title 6 — Consumer and Commercial Affairs (§§ 6-1-112, 6-1-716, 6-1-1301 to 6-1-1314) statute
- Connecticut Attorney General — The Connecticut Data Privacy Act (FAQs and universal opt-out resources) agency guidance
- Utah S.B. 227 (2022) — Consumer Privacy Act, enrolled copy statute
- House Bill 4 (88th Legislature, 2023) — Texas Data Privacy and Security Act, enrolled text statute
- Fla. Stat. § 501.171 — Security of confidential personal information statute
- Or. Rev. Stat. ch. 646A — Trade Regulation (OCPA at 646A.570 to 646A.589; breach at 646A.600 to 646A.628; data brokers at 646A.593) statute
- Mont. Code Ann. § 30-14-2803 — Applicability statute
- Del. Code tit. 6, ch. 12D — Delaware Personal Data Privacy Act statute
- Iowa Code ch. 715D — Consumer Data Protections statute
- Neb. Rev. Stat. § 87-1101 — Data Privacy Act, how cited statute
- N.H. Rev. Stat. Ann. ch. 507-H — Expectation of Privacy statute
- P.L.2023, c.266 (S332 6R) — New Jersey Data Privacy Act, as enacted statute
- Tennessee Public Chapter No. 408 (2023) — Tennessee Information Protection Act statute
- Minn. Stat. ch. 325M — Consumer Digital and Data Privacy (full chapter text) statute
- Maryland Senate Bill 541 (2024) — Maryland Online Data Privacy Act, enrolled text statute
- Ind. Code art. 24-15 — Consumer Data Protection statute
- Ky. Rev. Stat. § 367.3611 — Definitions (effective until July 1, 2027) statute
- R.I. Gen. Laws ch. 6-48.1 — Data Transparency and Privacy Protection Act (index) statute
- Oklahoma Statutes Title 15 — Consumer Protection Act, §§ 751–765 statute
- La. R.S. 51:3074 — Disclosure upon breach in the security of personal information statute
- Ala. Code § 8-38-2 — Data breach notification; definitions statute
- 9 V.S.A. § 2435 — Security Breach Notice Act statute
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.