State Comprehensive Privacy Laws

State Privacy Law Comparison: All 24 Comprehensive Statutes Side by Side

Correction, September 14, 2026. This guide originally described Maryland's sensitive-data rule as "strictly necessary, plus consent" and cited the Act as § 14-4601 et seq. Md. Code, Com. Law § 14-4707(a)(1) permits collecting or processing sensitive data only where strictly necessary, with no consent route, and the Act is codified at §§ 14-4701 to 14-4714.

Correction, September 21, 2026. This guide originally said Connecticut's cure period expired on December 31, 2024. Under Conn. Gen. Stat. § 42-525(c), the mandatory 60-day cure ended on that date, and from January 1, 2025 the Attorney General may offer a cure at its discretion, weighing seven factors.

Key Takeaways

  • Twenty-four states have enacted comprehensive privacy statutes; twenty are in effect and four — Oklahoma, Louisiana, Alabama and Vermont — take effect between January 2027 and January 2028.
  • Twenty-two of the twenty-four grant the same seven consumer rights. Iowa is the outlier at four, and Utah grants six.
  • California remains the only one of the twenty-four with a private right of action, and it reaches only breaches caused by a failure to maintain reasonable security.
  • Texas and Nebraska state no numeric threshold at all, keying applicability to the federal Small Business Administration definition instead.
  • Cure periods are diverging rather than converging: nine are permanent, four have lapsed or been repealed, and five are now discretionary.

How Many States Have a Comprehensive Privacy Law

Twenty-four states have enacted a comprehensive consumer privacy statute — a law governing personal data across sectors rather than regulating one industry or one data type. As of August 2026, twenty are in force. Four have been signed but have not reached their effective dates: Oklahoma and Louisiana on January 1, 2027, Alabama on May 1, 2027, and Vermont on January 1, 2028.

The count is worth stating precisely because it is often reported loosely. Statutes regulating a single category — biometric identifiers in Illinois, genetic data in New Mexico, consumer health data in Nevada — are not comprehensive laws and are not counted here, even though they can impose sharper duties within their scope. What follows compares only the cross-sector statutes, and compares each on the terms it states for itself.

Every figure in the tables below is taken from the statute cited in that row. The source list at the foot of this guide links a primary document for each of the twenty-four laws.

The Chronology, and What Each Statute Is Called

Ordering by effective date rather than alphabetically shows the shape of the thing. California stood alone for three years before any second state joined it. Then the pace changed sharply: four statutes took effect in 2023, four more in 2024, eight in 2025, and three in the first half of 2026. Twelve of the twenty-four became enforceable within a twenty-four-month window.

StateStatuteShort nameEffectiveStatus
CaliforniaCalifornia Consumer Privacy Act, as amended by the CPRACCPA/CPRAJanuary 1, 2020; CPRA amendments operative January 1, 2023In effect
VirginiaVirginia Consumer Data Protection ActVCDPAJanuary 1, 2023In effect
ColoradoColorado Privacy ActCPAJuly 1, 2023In effect
ConnecticutConnecticut Data Privacy ActCTDPAJuly 1, 2023In effect
UtahUtah Consumer Privacy ActUCPADecember 31, 2023In effect
TexasTexas Data Privacy and Security ActTDPSAJuly 1, 2024In effect
FloridaFlorida Digital Bill of RightsFDBRJuly 1, 2024In effect
OregonOregon Consumer Privacy ActOCPAJuly 1, 2024In effect
MontanaMontana Consumer Data Privacy ActMCDPAOctober 1, 2024In effect
DelawareDelaware Personal Data Privacy ActDPDPAJanuary 1, 2025In effect
IowaIowa Consumer Data Protection ActICDPAJanuary 1, 2025In effect
NebraskaNebraska Data Privacy ActNDPAJanuary 1, 2025In effect
New HampshireNew Hampshire Data Privacy ActNHPAJanuary 1, 2025In effect
New JerseyNew Jersey Data Privacy ActNJDPAJanuary 15, 2025In effect
TennesseeTennessee Information Protection ActTIPAJuly 1, 2025In effect
MinnesotaMinnesota Consumer Data Privacy ActMCDPAJuly 31, 2025In effect
MarylandMaryland Online Data Privacy ActMODPAOctober 1, 2025In effect
IndianaIndiana Consumer Data Protection ActINCDPAJanuary 1, 2026In effect
KentuckyKentucky Consumer Data Protection ActKCDPAJanuary 1, 2026In effect
Rhode IslandRhode Island Data Transparency and Privacy Protection ActRIDTPPAJanuary 1, 2026In effect
OklahomaOklahoma Consumer Data Privacy ActOKCDPAJanuary 1, 2027Enacted, not yet effective
LouisianaLouisiana Data Privacy ActLDPAJanuary 1, 2027Enacted, not yet effective
AlabamaAlabama Personal Data Protection ActAlabama PDPAMay 1, 2027Enacted, not yet effective
VermontVermont Data Privacy and Online Surveillance ActVDPOSAJanuary 1, 2028Enacted, not yet effective

The short names matter for searching case law and enforcement records, and two of them collide: Montana and Minnesota both abbreviate to MCDPA. Colorado is the CPA, an abbreviation also used in secondary writing for the California Privacy Rights Act, though the operative California text is the CCPA as amended rather than a freestanding act.

Applicability Thresholds Compared

The threshold is the first question each statute answers and the one on which they differ most. Three patterns recur. The most common pairs a consumer-count trigger with a lower count coupled to a revenue-share-from-selling-data trigger — Virginia's 100,000 consumers, or 25,000 consumers plus more than 50% of gross revenue from the sale of personal data, is the template most later states followed. A second pattern adds an absolute revenue floor, as Utah and Tennessee do at $25 million. A third dispenses with numbers entirely, which Texas and Nebraska do.

Among the twenty-two statutes that use a consumer count at all, the primary trigger spans a factor of seven. Montana and Alabama sit lowest at 25,000 residents. Connecticut, Delaware, New Hampshire, Maryland, Rhode Island and Vermont sit at 35,000. Louisiana sits at 75,000. Eleven states — California, Virginia, Colorado, Utah, Oregon, Iowa, New Jersey, Minnesota, Indiana, Kentucky and Oklahoma — set it at 100,000, making that the modal figure. Tennessee sits highest at 175,000. Florida sits outside the pattern altogether, reaching only companies above $1 billion in global gross annual revenue that also satisfy one of three business-model tests.

StateCitationApplicability threshold
CaliforniaCal. Civ. Code § 1798.100 et seq.Is a for-profit business doing business in California that determines the purposes and means of processing, and meets any one of three alternatives:
Gross annual revenue over $25 million in the preceding calendar year, or
Buys, sells or shares the personal information of 100,000 or more California consumers or households, or
Derives 50% or more of annual revenue from selling or sharing personal information
VirginiaVa. Code § 59.1-575 et seq. (tit. 59.1, ch. 53)Controls or processes the personal data of at least 100,000 Virginia consumers during a calendar year, or
Controls or processes the personal data of at least 25,000 consumers and derives over 50% of gross revenue from the sale of personal data
ColoradoC.R.S. § 6-1-1301 et seq. (art. 1, pt. 13)Controls or processes the personal data of at least 100,000 Colorado consumers during a calendar year, or
Derives revenue or receives a discount on goods or services from selling personal data and controls or processes the data of at least 25,000 consumers
For biometric identifiers or biometric data, any amount — the ordinary numeric thresholds do not gate § 6-1-1314
ConnecticutConn. Gen. Stat. § 42-515 et seq.Conducts business in Connecticut or produces products or services targeted to Connecticut residents, and
Controlled or processed the personal data of at least 35,000 consumers, excluding data processed solely to complete payment transactions, or
Controlled or processed consumers’ sensitive data, excluding data processed solely to complete payment transactions, or
Offered consumers’ personal data for sale in trade or commerce — with all consumer health data controllers covered regardless of size
UtahUtah Code § 13-61-101 et seq.Conducts business in Utah or targets Utah residents, and
Has annual revenue of $25,000,000 or more, and
Controls or processes the personal data of 100,000+ consumers in a calendar year, or derives over 50% of gross revenue from the sale of personal data while processing the data of 25,000+ consumers
TexasTex. Bus. & Com. Code ch. 541Conducts business in Texas or produces products or services consumed by Texas residents, and
Processes or engages in the sale of personal data, and
Is not a small business as defined by the U.S. Small Business Administration (no revenue or consumer-count minimum)
FloridaFla. Stat. §§ 501.701–501.722Organized or operated for the profit or financial benefit of its shareholders or owners, and
Makes in excess of $1 billion in global gross annual revenues, and
Derives 50%+ of global gross annual revenue from online advertising, or operates a smart speaker and voice-command service with an integrated virtual assistant, or operates an app store or digital distribution platform offering 250,000+ applications
OregonOr. Rev. Stat. §§ 646A.570 to 646A.589Conducts business in Oregon or provides products or services to Oregon residents, and during a calendar year controls or processes
The personal data of 100,000 or more consumers, other than data processed solely to complete a payment transaction, or
The personal data of 25,000 or more consumers while deriving 25% or more of annual gross revenue from selling personal data — with motor vehicle manufacturers covered regardless of these numbers
MontanaMont. Code Ann. §§ 30-14-2801 to 30-14-2820Conducts business in Montana or produces products or services targeted to Montana residents, and
Controls or processes the personal data of not less than 25,000 consumers, excluding data processed solely to complete a payment transaction, or
Controls or processes the personal data of not less than 15,000 consumers while deriving more than 25% of gross revenue from the sale of personal data
DelawareDel. Code tit. 6, ch. 12DConducts business in Delaware or produces products or services targeted to Delaware residents, and during the preceding calendar year
Controlled or processed the personal data of not less than 35,000 consumers, excluding data controlled or processed solely to complete a payment transaction, or
Controlled or processed the personal data of not less than 10,000 consumers and derived more than 20% of gross revenue from the sale of personal data
IowaIowa Code ch. 715DControls or processes the personal data of at least 100,000 Iowa consumers during a calendar year, or
Controls or processes the personal data of at least 25,000 consumers and derives over 50% of gross revenue from the sale of personal data
NebraskaNeb. Rev. Stat. §§ 87-1101 to 87-1130Conducts business in Nebraska or produces products or services consumed by Nebraska residents, and
Processes or engages in the sale of personal data, and
Is not a small business as determined under the federal Small Business Administration definition — though § 87-1118 still bars a small business from selling sensitive data without consent
New HampshireN.H. Rev. Stat. Ann. ch. 507-HConducts business in New Hampshire or produces products or services targeted to New Hampshire residents, and
During a one-year period controlled or processed the personal data of not less than 35,000 unique consumers, excluding data processed solely to complete a payment transaction, or
Controlled or processed the personal data of not less than 10,000 unique consumers while deriving more than 25% of gross revenue from the sale of personal data
New JerseyP.L.2023, c.266 (N.J.S.A. 56:8-166.4 et seq.)Conducts business in New Jersey or produces products or services targeted to New Jersey residents, and
During a calendar year controls or processes the personal data of at least 100,000 consumers, excluding data processed solely to complete a payment transaction, or
Controls or processes the personal data of at least 25,000 consumers and derives revenue, or receives a discount on the price of any goods or services, from the sale of personal data
TennesseeTenn. Code Ann. § 47-18-3201 et seq.Exceeds $25,000,000 in revenue, and
Controls or processes the personal information of at least 25,000 consumers and derives more than 50% of gross revenue from the sale of personal information, or
During a calendar year, controls or processes the personal information of at least 175,000 consumers
MinnesotaMinn. Stat. §§ 325M.10 to 325M.21Conducts business in Minnesota or produces products or services targeted to Minnesota residents, and
During a calendar year controls or processes the personal data of 100,000 consumers or more, excluding data processed solely to complete a payment transaction, or
Derives over 25% of gross revenue from the sale of personal data and processes or controls the personal data of 25,000 consumers or more
MarylandMd. Code, Com. Law § 14-4701 et seq.Conducts business in Maryland or targets Maryland residents, and during the preceding calendar year controlled or processed the personal data of at least 35,000 consumers, excluding data processed solely to complete a payment transaction, or
Controlled or processed the personal data of at least 10,000 consumers and derived more than 20% of gross revenue from the sale of personal data
IndianaInd. Code art. 24-15Conducts business in Indiana or produces products or services targeted to Indiana residents, and
During a calendar year controls or processes the personal data of at least 100,000 Indiana consumers, or
Controls or processes the personal data of at least 25,000 Indiana consumers and derives more than 50% of gross revenue from the sale of personal data
KentuckyKy. Rev. Stat. §§ 367.3611 to 367.3629Conducts business in the Commonwealth or produces products or services targeted to Kentucky residents, and
During a calendar year controls or processes the personal data of at least 100,000 consumers, or
Controls or processes the personal data of at least 25,000 consumers while deriving over 50% of gross revenue from the sale of personal data
Rhode IslandR.I. Gen. Laws ch. 6-48.1Any commercial website or internet service provider doing business in Rhode Island or with Rhode Island customers must designate a controller and make the § 6-48.1-3 disclosures — no threshold applies, and
The § 6-48.1-4 processing obligations apply to for-profit entities that during the preceding calendar year controlled or processed the personal data of not less than 35,000 customers, excluding data processed solely to complete a payment transaction, or
Controlled or processed the personal data of not less than 10,000 customers and derived more than 20% of gross revenue from the sale of personal data
OklahomaSB 546 (2026), codified at 75A O.S. §§ 300 et seq.Conducts business in Oklahoma or produces a product or service targeted to Oklahoma residents, and
During a calendar year controls or processes the personal data of at least 100,000 consumers, or
Controls or processes the personal data of at least 25,000 consumers and derives over 50% of gross revenue from the sale of personal data
LouisianaAct 502 of 2026 (SB 386), La. R.S. 51:1780.1–1780.5Conducts business in the state, and
Has annual gross revenues in excess of $25 million, or
Annually buys, receives for commercial purposes, sells or shares for commercial purposes the personal information of 75,000 or more consumers, households or devices, or
Derives 50% or more of annual revenues from selling consumers’ personal information
AlabamaHB 351, 2026 Regular SessionConducts business in Alabama or produces products or services targeted to Alabama residents, and
Controls or processes the personal data of more than 25,000 consumers, excluding data processed solely to complete a payment transaction, or
Derives more than 25% of gross revenue from the sale of personal data, regardless of the number of consumers whose data the person controls or processes
VermontAct 145 of 2026 (S.71), 9 V.S.A. §§ 2415a–2415kConducts business in Vermont or produces products or services targeted to Vermont residents, and
During the preceding calendar year controlled or processed the personal data of not fewer than 35,000 consumers, excluding data processed solely to complete a payment transaction, or
Controlled or processed the sensitive data of not fewer than 3,000 consumers, or
Offered for sale in trade or commerce the personal data of not fewer than 3,000 consumers

The Statutes With No Numeric Threshold

Texas and Nebraska share a drafting approach that makes them the widest-reaching state privacy laws in the country measured by the number of businesses inside them. Neither states a consumer-count or revenue minimum. Each instead reaches any person that conducts business in the state or produces products or services consumed by its residents, that processes or engages in the sale of personal data, and that is not a small business as defined by the United States Small Business Administration.

Both then keep one duty on the small businesses the applicability test otherwise excludes. Texas section 541.107 and Nebraska section 87-1118 each bar a small business from engaging in the sale of sensitive data without prior consumer consent. The effect is that a company well below the thresholds excluding it in California or Virginia is inside the Texas and Nebraska statutes, and a company small enough to fall outside them is still reached on the sensitive-data question.

Rhode Island arrives at a comparable place by a different route. The section 6-48.1-3 disclosure duties apply to any commercial website or internet service provider doing business in the state or with Rhode Island customers, with no threshold at all; only the section 6-48.1-4 processing obligations are gated by the 35,000-customer count.

Consumer Rights Compared

Rights are where the statutes converge rather than diverge. Twenty-two of the twenty-four grant the same seven: access, correction, deletion, portability, and opt-outs from sale, from targeted advertising, and from profiling in furtherance of decisions producing legal or similarly significant effects.

Two states depart from the template. Iowa grants four — access, deletion, portability and an opt-out of sale — with no right of correction and no opt-out of targeted advertising or profiling, which makes it the narrowest comprehensive statute in the country on this axis. Utah grants six, omitting only the profiling opt-out.

StateAccessCorrectDeletePortabilityOpt out of saleOpt out of targeted adsOpt out of profiling
CaliforniaYesYesYesYesYesYesYes
VirginiaYesYesYesYesYesYesYes
ColoradoYesYesYesYesYesYesYes
ConnecticutYesYesYesYesYesYesYes
UtahYesYesYesYesYesYes
TexasYesYesYesYesYesYesYes
FloridaYesYesYesYesYesYesYes
OregonYesYesYesYesYesYesYes
MontanaYesYesYesYesYesYesYes
DelawareYesYesYesYesYesYesYes
IowaYesYesYesYes
NebraskaYesYesYesYesYesYesYes
New HampshireYesYesYesYesYesYesYes
New JerseyYesYesYesYesYesYesYes
TennesseeYesYesYesYesYesYesYes
MinnesotaYesYesYesYesYesYesYes
MarylandYesYesYesYesYesYesYes
IndianaYesYesYesYesYesYesYes
KentuckyYesYesYesYesYesYesYes
Rhode IslandYesYesYesYesYesYesYes
OklahomaYesYesYesYesYesYesYes
LouisianaYesYesYesYesYesYesYes
AlabamaYesYesYesYesYesYesYes
VermontYesYesYesYesYesYesYes

The uniformity of this table is the most consequential single fact in the comparison. A rights-request process built to the seven-right template meets the terms of twenty-two statutes at once, and the divergence that remains sits in the mechanics — response windows, verification standards, appeal rights — rather than in which rights exist at all.

Sensitive Data, and the One Private Right of Action

Opt-in consent before processing sensitive data is the dominant rule: twenty of the twenty-four require it. Four depart. Utah and Iowa require notice and an opportunity to opt out rather than prior consent. California uses a different mechanism again, a right to limit the use and disclosure of sensitive personal information to what is necessary to provide the service. Maryland is the strictest of the twenty-four: collection and processing of sensitive data are confined to what is strictly necessary to provide the requested product or service, and the sale of sensitive data is prohibited outright rather than gated by consent.

On private enforcement the picture is simpler. California is the only state of the twenty-four whose comprehensive statute carries a private right of action, and it is narrow — reaching a breach of defined categories of unencrypted and unredacted personal information resulting from a failure to maintain reasonable security, and nothing else. An ignored access request or a missing opt-out link is a regulator's matter in all twenty-four.

StateSensitive data treatmentPrivate right of action
Californiaright to limit use and disclosureYes (breach only)
Virginiaopt-inNo
Coloradoopt-inNo
Connecticutopt-inNo
Utahopt-out (notice and opportunity to opt out)No
Texasopt-inNo
Floridaopt-inNo
Oregonopt-inNo
Montanaopt-inNo
Delawareopt-inNo
Iowanotice and opportunity to opt outNo
Nebraskaopt-inNo
New Hampshireopt-inNo
New Jerseyopt-inNo
Tennesseeopt-inNo
Minnesotaopt-inNo
Marylandstrictly necessary only, no consent route; sale prohibited outrightNo
Indianaopt-inNo
Kentuckyopt-inNo
Rhode Islandopt-inNo
Oklahomaopt-inNo
Louisianaopt-inNo
Alabamaopt-inNo
Vermontopt-inNo

Cure Periods and Their Sunset Dates

The right to cure — a window in which a controller can fix a violation before enforcement proceeds — is the fastest-moving variable in the comparison, and the one most likely to be out of date in a chart compiled a year ago. Four distinct treatments now exist across the twenty-four statutes.

Nine provide a permanent cure period with no sunset: Texas and Utah at 30 days, Iowa at 90, Tennessee at 60, and Nebraska, Indiana, Kentucky, Oklahoma and Alabama on their own terms. Four have lapsed or been repealed: Colorado was repealed for the Act generally on January 1, 2025, Montana removed its provision outright effective October 1, 2025, Oregon lapsed on January 1, 2026, and Minnesota expired on January 31, 2026. Five are discretionary rather than mandatory: Florida and Maryland by their own terms, and Connecticut, Delaware and New Hampshire, which converted from mandatory to discretionary against statutory factors. Connecticut's mandatory 60-day cure ran through December 31, 2024, and from January 1, 2025 its section 42-525(c) lets the Attorney General weigh seven factors in deciding whether to offer one; Delaware and New Hampshire converted on January 1, 2026 against seven and six factors respectively. New Jersey's window closed by its own terms in mid-2026. Rhode Island provides none at all, and California's fixed window was removed by the CPRA, leaving time to cure discretionary there. Louisiana's and Vermont's are time-limited windows that open when the statutes do and close again on stated dates.

StateRight to cure as the statute now stands
CaliforniaNone — the fixed cure window was removed by the CPRA; time to cure is discretionary
Virginia30 days
Colorado60 days, repealed January 1, 2025 for the Act generally; a separate 60-day cure for the minors’ sections runs until December 31, 2026
Connecticut60 days, mandatory through December 31, 2024; discretionary from January 1, 2025 against seven factors (§ 42-525(c))
Utah30 days (permanent)
Texas30 days (permanent right to cure)
Florida45 days, discretionary; unavailable for known-child violations
Oregon30 days, lapsed January 1, 2026 except for certain public broadcast stations; that carve-out was repealed July 1, 2026
MontanaNone — removed from § 30-14-2817 by Ch. 567, L. 2025, effective October 1, 2025
Delaware60 days, mandatory to December 31, 2025; discretionary from January 1, 2026 against seven statutory factors
Iowa90 days (permanent)
Nebraska30 days, with no sunset, but the cure must be documented (Neb. Rev. Stat. § 87-1122)
New Hampshire60 days, mandatory to December 31, 2025; discretionary from January 1, 2026 against six statutory factors
New Jersey30 days, available until the first day of the 18th month following the effective date
Tennessee60 days (permanent)
Minnesota30 days after a warning letter; the paragraph expired January 31, 2026
MarylandAt least 60 days, discretionary, for violations occurring on or before April 1, 2027
Indiana30 days, with no sunset date (Ind. Code § 24-15-10-3)
Kentucky30 days, with no sunset date (Ky. Rev. Stat. § 367.3627(2))
Rhode IslandNone — the chapter provides no right to cure
Oklahoma30 days’ written notice before suit, with no expiry date
Louisiana30 days’ written notice before an investigation, available January 1 through July 31, 2027 only
Alabama45 days after a notice of violation, with no expiry date
Vermont60 days after a notice of violation, available January 1, 2028 through June 30, 2029

The direction of travel is one-way. No state in the group has added a cure period or extended one after the fact; the movement has been from mandatory to discretionary, and from discretionary to none.

Enforcement Authority and Penalty Exposure

Every one of the twenty-four statutes is enforced by the state attorney general or an office within it. Two add to that. Colorado shares authority with district attorneys, and California is the only state with a dedicated regulator — the California Privacy Protection Agency, the first administrative body in the United States created solely to enforce a consumer privacy law, which exercises rulemaking and enforcement powers alongside the Attorney General rather than instead of them.

Stated penalties range from $5,000 per violation in Connecticut to $50,000 in Florida, trebled in three defined circumstances. The most common figure by a wide margin is $7,500. Several states set no privacy-specific figure at all and route violations through an existing consumer protection statute: New Jersey through the Consumer Fraud Act, Louisiana through the Unfair Trade Practices and Consumer Protection Law, Vermont through the Consumer Protection Act, and Maryland through its unfair, abusive or deceptive trade practice provisions.

StateEnforcerPenalty as stated in the statute
CaliforniaCalifornia Privacy Protection Agency and the Attorney GeneralUp to $7,500 per intentional violation
VirginiaVirginia Attorney GeneralUp to $7,500 per violation under Va. Code § 59.1-584, plus reasonable investigation expenses and attorney fees
ColoradoColorado Attorney General and district attorneysUp to $20,000 per violation under C.R.S. § 6-1-112(1)(a), counted separately per consumer or transaction, rising to $50,000 where the violation was committed against an elderly person
ConnecticutConnecticut Attorney General, Privacy SectionUp to $5,000 per violation under the Connecticut Unfair Trade Practices Act
UtahUtah Attorney General, on referral from the Division of Consumer ProtectionActual damages to the consumer plus up to $7,500 per violation under Utah Code § 13-61-402(3)(d)
TexasTexas Attorney GeneralUp to $7,500 per violation under Tex. Bus. & Com. Code § 541.155
FloridaFlorida Department of Legal AffairsUp to $50,000 per violation, treble in three defined circumstances
OregonOregon Attorney General, Department of Justice Privacy UnitUp to $7,500 for each violation under Or. Rev. Stat. § 646A.589(4)(a)
MontanaMontana Attorney GeneralUp to $7,500 for each violation under Mont. Code Ann. § 30-14-2820(2)
DelawareDelaware Department of JusticeThe Department of Justice states civil penalties of up to $10,000 per violation; 29 Del. C. § 2522(b) sets that figure for a wilful violation in court and § 2523 sets $5,000 administratively
IowaIowa Attorney GeneralUp to $7,500 per violation under Iowa Code § 715D.8(3), paid into the consumer education and litigation fund established under § 714.16C
NebraskaNebraska Attorney GeneralUp to $7,500 for each violation under Neb. Rev. Stat. § 87-1124(1)
New HampshireNew Hampshire Attorney GeneralCivil penalties of up to $10,000 for each violation under RSA 358-A:4, III(b), which a violation of RSA 507-H becomes by operation of § 507-H:11, V
New JerseyNew Jersey Attorney General (Division of Consumer Affairs)Enforced as an unlawful practice under the Consumer Fraud Act, which sets civil penalties of up to $10,000 per violation for a first offense and up to $20,000 for every subsequent offense under N.J.S.A. 56:8-13
TennesseeTennessee Attorney General and ReporterUp to $7,500 per violation under Tenn. Code Ann. § 47-18-3212(d)(1), plus discretionary treble damages for a wilful or knowing violation
MinnesotaMinnesota Attorney GeneralInjunction and a civil penalty of not more than $7,500 for each violation under Minn. Stat. § 325M.20(c)
MarylandMaryland Division of Consumer Protection, Office of the Attorney GeneralA violation is an unfair, abusive or deceptive trade practice under title 13, carrying up to $10,000 per violation and up to $25,000 for a repeated violation under Md. Code, Com. Law § 13-410
IndianaIndiana Attorney GeneralUp to $7,500 per violation under Ind. Code § 24-15-10-2(a)
KentuckyKentucky Attorney General, Office of Data PrivacyUp to $7,500 for each continued violation under Ky. Rev. Stat. § 367.3627(3)
Rhode IslandRhode Island Attorney General$100 to $500 for each intentional disclosure under § 6-48.1-8(a)(2); other violations are deceptive trade practices carrying up to $10,000 per violation under § 6-13.1-8
OklahomaOklahoma Attorney GeneralUp to $7,500 per violation, plus court-awarded attorney fees and investigation expenses
LouisianaLouisiana Attorney GeneralEnforced as an unfair and deceptive trade practice under the Unfair Trade Practices and Consumer Protection Law, R.S. 51:1401 et seq.
AlabamaAlabama Attorney GeneralUp to $15,000 per violation, assessed by a court after a failure to correct within 45 days
VermontVermont Attorney GeneralEnforced as a violation of the Vermont Consumer Protection Act, 9 V.S.A. chapter 63

Per-violation counting is what makes these figures consequential rather than nominal. Colorado states the point explicitly: penalties are counted separately per consumer or per transaction, which turns a $20,000 maximum into an aggregate that scales with the size of the affected population.

Universal Opt-Out Preference Signals

Recognition of a browser-transmitted opt-out signal, such as Global Privacy Control, is a genuine point of divergence, and it is the one axis on which this chart does not claim completeness. Of the twenty-four state records behind this comparison, eight document the treatment of opt-out preference signals against a primary source: Colorado, Connecticut, Delaware, New Hampshire, New Jersey, Indiana, Kentucky and Rhode Island. California's obligation to honour such a signal is stated on its own statute page.

The remaining states were not researched on this specific question, and no claim is made here about what their statutes provide. That gap is recorded rather than filled by inference, because the mechanism differs enough between states — some requiring recognition outright, some allowing it as one of two permitted methods — that a generalisation drawn from the eight would not reliably describe the rest.

Where the Laws Genuinely Diverge

Read across the six tables, the divergence concentrates in four places rather than being spread evenly. Thresholds differ by a factor of seven among the states that use consumer counts, and differ in kind beyond that, with Texas and Nebraska using no number at all and Florida using a revenue floor plus a business-model test. Cure periods differ in whether they exist at all, and are moving. Penalty figures differ by a factor of ten, and the counting rule beneath them differs further. Sensitive data treatment splits four ways.

Against that, consumer rights are close to uniform, the enforcer is the attorney general almost everywhere, and private enforcement is absent everywhere but California. The practical consequence is that the questions of whether a statute applies and what happens when it is broken vary far more between states than the question of what the statute grants a consumer.

What This Chart Does Not Cover

Six axes are compared here. Several others are not, and their absence is deliberate rather than an oversight. Data protection assessment requirements, controller-processor contract terms, response deadlines and appeal mechanics, children's and minors' provisions, and the exemptions for entities and data regulated under HIPAA, the Gramm-Leach-Bliley Act and the Fair Credit Reporting Act all differ between these statutes and are not charted above.

The exemption structures in particular resist tabulation: some states exempt covered entities wholesale while others exempt only the regulated data, and the difference determines whether a healthcare or financial services business is outside the statute or merely outside part of it. Each state page linked from the sources below sets out that state's exemptions against its own text.

Frequently Asked Questions

How many states have comprehensive privacy laws in 2026?
Twenty-four states have enacted one. Twenty are in force as of August 2026. Oklahoma and Louisiana take effect on January 1, 2027, Alabama on May 1, 2027, and Vermont on January 1, 2028.
Which state privacy law has the lowest applicability threshold?
Texas and Nebraska state no numeric threshold at all — any business that is not a small business under the federal Small Business Administration definition is covered. Among statutes that do use numbers, Montana is the lowest at 25,000 residents.
Do all state privacy laws grant the same consumer rights?
Twenty-two of the twenty-four grant the same seven rights. Iowa grants four, with no right of correction and no opt-out of targeted advertising or profiling. Utah grants six, omitting the profiling opt-out.
Which states still allow a right to cure before enforcement?
Nine provide a permanent cure period, five provide a discretionary one (Florida, Maryland, Connecticut, Delaware and New Hampshire), and four have lapsed or been repealed: Colorado, Oregon, Minnesota and Montana. Rhode Island and California provide none.
Can consumers sue directly under state privacy laws?
Only in California, and only for a breach of defined categories of unencrypted and unredacted personal information resulting from a failure to maintain reasonable security. Every other violation in every one of the twenty-four states is enforced by a regulator.

Sources

Everything above is reported from these documents. Follow them to verify.

  1. California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq. statute
  2. California Privacy Protection Agency — CCPA regulations regulation
  3. Va. Code § 59.1-576 — Scope; exemptions statute
  4. Colorado Revised Statutes 2024, Title 6 — Consumer and Commercial Affairs (§§ 6-1-112, 6-1-716, 6-1-1301 to 6-1-1314) statute
  5. Connecticut Attorney General — The Connecticut Data Privacy Act (FAQs and universal opt-out resources) agency guidance
  6. Utah S.B. 227 (2022) — Consumer Privacy Act, enrolled copy statute
  7. House Bill 4 (88th Legislature, 2023) — Texas Data Privacy and Security Act, enrolled text statute
  8. Fla. Stat. § 501.171 — Security of confidential personal information statute
  9. Or. Rev. Stat. ch. 646A — Trade Regulation (OCPA at 646A.570 to 646A.589; breach at 646A.600 to 646A.628; data brokers at 646A.593) statute
  10. Mont. Code Ann. § 30-14-2803 — Applicability statute
  11. Del. Code tit. 6, ch. 12D — Delaware Personal Data Privacy Act statute
  12. Iowa Code ch. 715D — Consumer Data Protections statute
  13. Neb. Rev. Stat. § 87-1101 — Data Privacy Act, how cited statute
  14. N.H. Rev. Stat. Ann. ch. 507-H — Expectation of Privacy statute
  15. P.L.2023, c.266 (S332 6R) — New Jersey Data Privacy Act, as enacted statute
  16. Tennessee Public Chapter No. 408 (2023) — Tennessee Information Protection Act statute
  17. Minn. Stat. ch. 325M — Consumer Digital and Data Privacy (full chapter text) statute
  18. Maryland Senate Bill 541 (2024) — Maryland Online Data Privacy Act, enrolled text statute
  19. Ind. Code art. 24-15 — Consumer Data Protection statute
  20. Ky. Rev. Stat. § 367.3611 — Definitions (effective until July 1, 2027) statute
  21. R.I. Gen. Laws ch. 6-48.1 — Data Transparency and Privacy Protection Act (index) statute
  22. Oklahoma Statutes Title 15 — Consumer Protection Act, §§ 751–765 statute
  23. La. R.S. 51:3074 — Disclosure upon breach in the security of personal information statute
  24. Ala. Code § 8-38-2 — Data breach notification; definitions statute
  25. 9 V.S.A. § 2435 — Security Breach Notice Act statute

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.