Congress never passed a comprehensive privacy law, so the states built one twenty-four times. As of September 2026, twenty state laws are in effect, three of them (Indiana, Kentucky, Rhode Island) new on January 1, and four more arrive on a published schedule: Louisiana and Oklahoma on January 1, 2027, Alabama on May 1, 2027, and Vermont on January 1, 2028. Nearly all copy Virginia: opt-out rights for sale, targeted advertising and profiling; opt-in consent for sensitive data; attorney general enforcement around $7,500 per violation; no private lawsuits outside California.
Several 2026 developments matter more than the new states. California's regulation package took effect January 1, with the automated decision-making rights themselves operative January 1, 2027, and the Delete Act's DROP deletion mechanism went live for data brokers August 1. Enforcement escalated in step, and the $12.75M joint settlement with General Motors in May over driving and location data sold to brokers is now the largest under the CCPA. Sacramento closed its session by sending its biggest privacy package yet to the governor. On September 27 he vetoed AB 1542, the flat ban on selling or sharing sensitive personal information, calling a categorical ban a step too far, and signed SB 923, which extends deletion to data obtained from third parties, and AB 883 on data broker deletion, both effective January 1, 2027. SB 690, the CIPA reform that would end private pen-register tracking suits, was still awaiting his decision at the September 30 deadline. Connecticut's July 1 amendments pulled in any business that processes sensitive data or sells personal data, and its SB 4 bans selling precise geolocation data from October 1. The minors' wave is cresting too. Arkansas's ACTOPPA extended COPPA-style rules to teens on July 1 (Arkansas has no comprehensive consumer law), Virginia banned selling precise geolocation, and California replaced its court-blocked Age-Appropriate Design Code with the signed AB 2246. And the cure periods keep dying: Delaware's expired December 31, 2025, Montana's on April 1, 2026, and Rhode Island launched with none.
In effect (20 states)
| State | Statute | Effective | What stands out |
|---|---|---|---|
| California | CCPA/CPRA | Jan 1, 2020 (CPRA Jan 1, 2023) | The outlier: CPPA agency, GPC enforcement, 2025 regulations effective Jan 1, 2026 (ADMT rights operative Jan 1, 2027; cyber audit certifications from Apr 2028), Delete Act DROP broker deletion live since Aug 1, 2026, limited private right of action for breaches. |
| Virginia | VCDPA | Jan 1, 2023 | The template law most states copied. Opt-in for sensitive data, opt-out for sale/targeting/profiling, AG enforcement, 30-day cure; a ban on selling precise geolocation data took effect Jul 1, 2026. |
| Colorado | CPA | Jul 1, 2023 | Universal opt-out mechanism honoring required; rulemaking authority used actively; 2025 amendments added biometric and minors' provisions. |
| Connecticut | CTDPA | Jul 1, 2023 | The Jul 1, 2026 amendments lowered the threshold to 35,000 residents, pull in any business that processes sensitive data or sells personal data, and add profiling impact assessments. SB 4, signed May 27, 2026, bans selling precise geolocation data from Oct 1, 2026; companion bills restrict surveillance pricing and add data broker registration from Jan 1, 2027. |
| Utah | UCPA | Dec 31, 2023 | The most business-friendly of the wave: narrower rights, opt-out only, amendments effective Jul 1, 2026. |
| Texas | TDPSA | Jul 1, 2024 | Applies to nearly all non-small businesses regardless of revenue thresholds; the Texas AG runs an aggressive dedicated enforcement team. |
| Oregon | OCPA | Jul 1, 2024 | Includes a right to a list of specific third parties that received your data, a disclosure most laws lack. |
| Montana | MTCDPA | Oct 1, 2024 | Low thresholds for a small state; cure period sunsets Apr 1, 2026; 2025 amendments tightened minors' duties. |
| Florida | FDBR | Jul 1, 2024 | Narrower than it looks: the core duties bind only companies with $1B+ revenue meeting tech-platform criteria, though some provisions reach further. |
| Iowa | ICDPA | Jan 1, 2025 | Utah-style, lighter-touch: no profiling opt-out, opt-out (not opt-in) for sensitive data via notice. |
| Delaware | DPDPA | Jan 1, 2025 | Low thresholds (35K consumers); cure period expired Dec 31, 2025, so enforcement can now proceed straight to penalties. |
| Nebraska | NDPA | Jan 1, 2025 | Texas-style applicability: covers most non-small businesses without revenue thresholds. |
| New Hampshire | NHDPA | Jan 1, 2025 | Virginia-model with 35K-consumer threshold. |
| New Jersey | NJDPA | Jan 15, 2025 | Includes financial data in sensitive categories; universal opt-out honoring required; cure discretion ends mid-2026. |
| Tennessee | TIPA | Jul 1, 2025 | Unique NIST-privacy-framework affirmative defense for documented programs. |
| Minnesota | MCDPA | Jul 31, 2025 | Adds a right to question profiling results and data inventory duties unusual among state laws. |
| Maryland | MODPA | Oct 1, 2025 | The strictest since California: data minimization by default, sale of sensitive data banned outright, targeted advertising to under-18s prohibited. |
| Indiana | INCDPA | Jan 1, 2026 | Virginia-model; 30-day cure period is permanent. |
| Kentucky | KCDPA | Jan 1, 2026 | Virginia-model; AG enforcement with permanent cure period. |
| Rhode Island | RIDTPPA | Jan 1, 2026 | One of the lowest thresholds in the country (35K consumers) and no cure period at all; disclosure duties are unusually specific. |
Enacted, effective date ahead (4 states)
| State | Statute | Effective | What stands out |
|---|---|---|---|
| Alabama | Alabama Consumer Privacy Act | May 1, 2027 | Part of the 2026 legislative wave; Virginia-model structure. |
| Louisiana | Louisiana Consumer Privacy Act | Jan 1, 2027 | Part of the 2026 wave; adds specific notice before selling sensitive or biometric data and authentication duties for consumer requests. |
| Oklahoma | Oklahoma Consumer Privacy Act | Jan 1, 2027 | Part of the 2026 wave; Virginia-model. |
| Vermont | Vermont Data Privacy Act | Jan 1, 2028 | Part of the 2026 wave; earlier Vermont attempts died over private-right-of-action fights, and the enacted version arrives narrower. |
What still binds everyone federally
The sectoral layer applies nationwide regardless of state: COPPA for children under 13 (with the amended FTC rule phasing in), HIPAA for covered health entities, GLBA for financial institutions, FCRA for consumer reports, the TCPA's opt-in rule for marketing calls and texts, CAN-SPAM's opt-out rule for email, and FTC Act Section 5, which the Commission uses against data brokers, sensitive-location sellers and dark patterns. Washington's My Health My Data Act deserves its own line. It reaches consumer health inferences far beyond HIPAA and carries a private right of action, which makes wellness-adjacent targeting the riskiest single category in US marketing.
The consequences for planning sit on the United States page and the consent map.