DIGITAL PRIVACY REGULATIONSThe Worldwide Register of Data Privacy Law
Tracking 197 jurisdictions
Language: English
Americas · In force · Opt-out

🇺🇸 United States Data Privacy Laws

The United States is the world's great opt-out exception. With no federal comprehensive law, advertisers can generally target adults using personal data without prior consent, subject to a growing patchwork of state opt-out rights. That summary holds for global media planning, and its exceptions are where US enforcement now lives.

Updated September 28, 2026 · digitalprivacyregs.com
Status
In force
Consent model
Opt-out
Primary law
No federal comprehensive law; 24 state comprehensive laws (20 in effect) + sectoral statutes (COPPA, HIPAA, GLBA, FCRA, TCPA, CAN-SPAM)
Year
2020
Authority
FTC (Section 5) + state Attorneys General + California Privacy Protection Agency
Marketing consent
Targeted advertising and data sales run on opt-out for adults and non-sensitive data. Opt-in is required for sensitive data in most state laws, for children's data, and for calls and texts under the TCPA.
Transfers
No general restrictions on data leaving the US; the EU-US Data Privacy Framework governs inbound EU data.
Penalties
State AG actions typically $7,500 per violation ($2,500-$7,500 under CCPA); FTC consent decrees; TCPA statutory damages of $500-$1,500 per call or text.

The framework

Start with the structure. Congress has never passed a comprehensive consumer privacy law; the American Privacy Rights Act stalled in 2024 like every predecessor. What exists federally is sectoral: HIPAA for covered health entities, GLBA for financial institutions, FCRA for consumer reports, COPPA for children under 13, the TCPA for calls and texts, CAN-SPAM for email, and FTC Act Section 5 for unfair or deceptive practices, which the FTC has stretched into data broker, sensitive-location and dark-pattern enforcement.

The states filled the vacuum. Since the CCPA took effect in 2020, twenty-four states have enacted comprehensive laws and twenty are in effect as of 2026, with Indiana, Kentucky and Rhode Island the newest arrivals on 1 January 2026. Nearly all follow the Virginia model: notice duties, access and deletion rights, opt-outs for sale, targeted advertising and profiling, opt-in consent for sensitive data, AG enforcement around $7,500 per violation, and no private right of action outside California's breach provision. Cure periods are sunsetting: Delaware's ended 31 December 2025, Montana's on 1 April 2026, and Rhode Island launched with none. The 2026 wave lands on a published schedule: Louisiana and Oklahoma on 1 January 2027, Alabama on 1 May 2027, Vermont on 1 January 2028.

California remains the outlier that behaves like a regulator-first jurisdiction. The CCPA/CPRA adds a dedicated agency (the CPPA), Global Privacy Control enforcement, and a regulation package that took effect 1 January 2026, with the automated decision-making rights themselves (pre-use notice, access, opt-out) operative 1 January 2027 and cybersecurity audit certifications phasing in from April 2028. The Delete Act's DROP platform went live 1 August 2026 alongside expanded broker registration, and enforcement has escalated fast, from the CPPA's $1.35M Tractor Supply order in 2025 to a $12.75M joint settlement with General Motors in May 2026 over driving and location data sold to brokers without consent. The 2026 session then sent Sacramento's biggest package yet to the governor. On 27 September he vetoed AB 1542, which would have banned selling or sharing sensitive personal information outright, calling a categorical ban a step too far when consumers already hold a right to limit its use, and signed SB 923, which expands deletion to data gathered about you from third parties, and AB 883 on data broker deletion, both effective 1 January 2027. SB 690, which would end the private pen-register lawsuits that made website tracking a CIPA class-action industry, and AB 2561, which would stop operating systems and apps from overriding users' privacy settings, awaited his decision with a 30 September deadline.

In practice, opt-out means that for a US adult and non-sensitive data, a brand can collect, model and target without asking first; it must honor opt-outs (including the GPC browser signal in a growing set of states), post disclosures, and skip discrimination against opted-out users. The opt-in exceptions are real: sensitive categories (health, precise geolocation, race, religion, sexual orientation, biometrics) need consent in most states; Washington's My Health My Data Act reaches consumer health inferences with a private right of action; Maryland bans the sale of sensitive data outright and imposes data minimization by default; and anything touching known minors is shifting to opt-in with several states restricting targeted advertising to teens entirely.

The US is far from opt-out everywhere. Calls and texts under the TCPA require prior express written consent for marketing, at $500 to $1,500 per violation in statutory damages, which is why SMS compliance is a litigation industry. Email is opt-out under CAN-SPAM, the loosest major email law on earth. Knowing which channel runs on which rule is the whole game.

Key instruments

California CCPA/CPRA

2018/2020 · In force; 2025 regulations effective 1 Jan 2026, ADMT rights operative 1 Jan 2027, cyber audit certifications from Apr 2028

The strictest state regime: opt-out of sale/share, sensitive data limitation rights, GPC honoring, CPPA rulemaking and enforcement, Delete Act broker deletion (DROP) with the 1 Aug 2026 processing deadline.

Official source →

Virginia CDPA and its 18 descendants

2021-2026 · In force across 20 states

The template most states copied: consumer rights, opt-outs for sale/targeted advertising/profiling, opt-in for sensitive data, AG enforcement, 30-day cure periods that are progressively expiring.

TCPA (Telephone Consumer Protection Act)

1991 · In force

Prior express written consent for marketing calls and texts using autodialers or prerecorded voice; statutory damages of $500-$1,500 per violation with no cap; the reason US SMS marketing is opt-in.

Official source →

CAN-SPAM Act

2003 · In force

Opt-out email regime: no prior consent required, but honest headers, identification, postal address and a working unsubscribe honored within 10 business days.

Official source →

COPPA

1998 · In force; amended FTC rule phasing in through 2025-2026

Verifiable parental consent before collecting personal information from children under 13; the amended rule tightens ad-related uses and third-party disclosures.

Official source →

Marketing and advertising

Targeted advertising and data sales run on opt-out for adults and non-sensitive data. Opt-in is required for sensitive data in most state laws, for children's data, and for calls and texts under the TCPA. Most channel decisions here follow from that consent rule.

For a media planner the operational rules are: honor opt-outs and the GPC signal in state-law states, treat sensitive-category and health-adjacent targeting as opt-in territory (and check Washington MHMD before touching wellness data), keep SMS programs on documented prior express written consent, run email under CAN-SPAM hygiene, and keep anyone under 18 out of targeted advertising entirely. Do that and the US remains the most permissive major ad market in the world.

Cross-border transfers

No general restrictions on data leaving the US; the EU-US Data Privacy Framework governs inbound EU data.

Enforcement and penalties

State AG actions typically $7,500 per violation ($2,500-$7,500 under CCPA); FTC consent decrees; TCPA statutory damages of $500-$1,500 per call or text.

Primary sources

Cite this page: "United States Data Privacy Laws." Digital Privacy Regulations, September 28, 2026, https://digitalprivacyregs.com/united-states.html. Accessed [date].