How to Request Your Personal Data: US Privacy Rights by State
Independently fact-checked against primary sources (last audited September 12, 2026). · 37 primary sources cited on this page. How we verify our legal content

A U.S. personal-data request starts with two questions: who holds the records, and which law covers that holder? State consumer privacy laws govern some private businesses. Health, credit, school, and government records use different federal or state routes. Residence alone does not establish a right or make an organization subject to a statute.
Compare all 50 states and D.C. · Explore the cited laws
Information last verified from the cited sources on September 11, 2026. This article has not yet been reviewed by a licensed lawyer.
Jurisdiction scope: This guide covers selected federal record-access routes and all 50 states plus the District of Columbia as of September 11, 2026. It does not establish eligibility, catalog every exemption, or classify the 25 unresolved jurisdictions as lacking access rights.
Which US Data-Access Law Applies?
The correct law usually follows the holder and the reason the record exists. A private retailer's customer profile, a hospital chart, a credit file, a school record, and a federal agency file do not share one U.S. request procedure. Start with the organization's identity and privacy notice, then match the data to a positively identified statute.

A comprehensive state privacy law may provide confirmation, access, correction, deletion, or portability when it covers both the individual and the controller. “Controller” generally means the entity that determines why and how personal data is processed, but each statute supplies its own definition and thresholds. A resident may fall outside a consumer definition when acting in an employment or business context. An organization may be excluded because of its size, sector, nonprofit status, government role, or another statutory rule.
Data exemptions matter too. A law may exclude an entity, only data regulated by another law, or processing in a specified context. Financial, health, insurance, education, employment, and government records often require a different route. The fact that a business has a request form does not prove that every listed right applies to every submission.
This guide uses four labels. “Operative” means the reviewed comprehensive framework has taken effect. “Future” means it was enacted but its relevant rights are not yet operative. “Targeted” identifies a narrower right that should not be compared as access to all personal data. “Unclassified” means this review does not make a comprehensive-law classification, without implying that no other access right exists.
Health, Credit, School, and Government Records Use Different Routes
Federal sector laws answer different questions and should remain separate from the state consumer table.
| Record and holder | Possible route | Core boundary in the cited source |
|---|---|---|
| Protected health information held by a covered entity | 45 C.F.R. § 164.524 and HHS guidance | Access concerns a designated record set and remains subject to exclusions |
| File held by a consumer reporting agency | 15 U.S.C. § 1681g | The requester must make a request and provide proper identification |
| Education records at a covered school | 34 C.F.R. § 99.10 | Parents and eligible students generally receive inspection within no more than 45 days |
| Federal agency records | FOIA, 5 U.S.C. § 552 | Concerns agency records and is subject to exemptions and agency procedures |
| Records about oneself in a federal system of records | Privacy Act, 5 U.S.C. § 552a | Applies through the Act's system-of-records structure and exemptions |

HIPAA generally requires a covered entity to act on a covered access request within 30 calendar days and permits one written 30-day extension in the circumstances described by the rule. FCRA requires a consumer reporting agency, upon request and proper identification, to disclose the information in the consumer's file subject to the statute. FERPA uses its own requester definitions and outside 45-day inspection period.
FOIA concerns federal agency records, while the Privacy Act can supply a route to records about an individual in a federal system of records. State and local agencies follow their own public-records and privacy statutes. A request for government records such as 911 calls therefore raises a different question from a consumer request to a private controller.
Where a Comprehensive State Consumer Access Right Applies
As of September 11, 2026, this guide identifies 20 operative comprehensive state frameworks: California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia. This is a status count, not a promise that every resident or business falls within those laws.

Alabama, Louisiana, Oklahoma, and Vermont enacted future frameworks. Alabama's relevant provisions take effect May 1, 2027. Louisiana and Oklahoma take effect January 1, 2027. Vermont's relevant consumer privacy subchapter takes effect January 1, 2028, according to Act 145. A request filed before an effective date cannot rely on a future right as though it were already operative.
Nevada and Washington stay in a separate targeted category. The recovered official Nevada text confirms an opt-out for certain covered sales by online operators, with its own response structure, rather than the general confirmation-and-access right compared here. Washington's My Health My Data Act covers consumer health data and does not create access to every category of personal data.
Common coverage questions include the consumer's role, the controller's revenue or data-volume threshold, whether the entity conducts business in or targets the state, and whether an exemption applies. Government bodies, financial institutions or data, HIPAA-regulated entities or information, insurers, nonprofits, higher education, and employment-context data receive different treatment across statutes. The controlling text must answer each element.
Florida shows why labels need detail. Fla. Stat. § 501.702(9) covers a qualifying for-profit entity that exceeds $1 billion in global annual gross revenue and satisfies at least one of three branches: at least 50 percent of global gross annual revenue from online-ad sales; operation of the specified smart-speaker or voice-assistant service; or operation of an app store or digital distribution platform offering at least 250,000 applications. The definition also reaches entities within the statute's control relationship. Calling Florida broadly applicable would omit those gates.
How to Submit a Verifiable Consumer Access Request
Use the method identified in the covered organization's privacy notice or official instructions. This is a practical checklist drawn from common request provisions, not a universal statutory formula.
- Identify the account, transaction, device, service, or other relationship connected to the data.
- Name the positively identified access or confirmation right and describe the data sought clearly enough to locate it.
- Request the copy or portable format the governing law makes available.
- Provide only reasonably requested authentication information through a secure channel. Avoid sending unnecessary identity documents through ordinary email.
- Save the submitted request, date, delivery receipt, confirmation number, authentication exchanges, extension notice, and response.

Authorized-agent and parental requests follow statute-specific rules. A controller may explain that it cannot authenticate the requester or connect the person to the requested data. That response is not necessarily a final denial. The next step may be completion of a secure verification method.
Combining unrelated theories can obscure the request. A hospital records request, credit-file disclosure, school inspection, government public-record request, and consumer privacy request may need separate recipients and proof. If the organization cites an exemption or declines action, ask for the written reason and any appeal instructions required by the applicable law.
Response Deadlines, Extensions, Copies, and Fees
There is no single national deadline for personal-data access. Many operative comprehensive laws use 45 days for the initial response and allow one additional 45-day period when reasonably necessary, commonly with notice and reasons during the original period. The statute still determines when the period begins, whether it uses calendar days, and what counts as a completed response.

Iowa uses a 90-day initial period under Iowa Code § 715D.3. Florida uses 45 days initially and permits one additional 15-day extension when reasonably necessary with timely notice under Fla. Stat. § 501.706. California's right-to-know system has its own acknowledgment, verification, frequency, lookback, and disclosure rules in the current statute and regulations.
An acknowledgment is not the completed response. An extension notice is not necessarily a denial. Some laws permit a fee or refusal for requests that are manifestly unfounded, excessive, technically infeasible, or repetitive, but the wording and burden vary. Free-request frequency and delivery format also differ.
Calendar the date the controller received the request and preserve any confirmation. If the organization asks for additional authentication, retain that exchange and the date supplied. The chronology determines whether an appeal or regulator complaint route has matured.
What to Do After a Denial or No Response
Read the stated reason before choosing the next route. A controller may cite failed authentication, an entity or data exemption, excessive requests, lack of control over the data, or another statutory ground. A curable identification problem can be addressed through the secure channel without assuming that the controller has finally denied the right.
Where the governing law provides an internal appeal, follow the identified method and preserve proof of delivery. Florida requires a conspicuously available appeal process similar to the original request method. Under Fla. Stat. § 501.707, the controller must provide a written result and reasons within 60 days after receiving the appeal. The Florida source also directs the controller to provide the statutory contact route when the appeal is denied.
Vermont's future law provides another 60-day appeal result under enacted § 2415d(d), but that consumer privacy subchapter does not take effect until January 1, 2028. Current Connecticut text confirms a 60-day appeal result, while recovered official New Jersey text confirms 45 days. These examples do not create a universal appeal deadline.

If an appeal remains denied, use only the regulator, attorney-general, complaint, or court route the applicable law supports. Enforcement authority, cure provisions, and private remedies vary. The privacy complaint guide explains how to organize the record, while the data deletion guide addresses a separate consumer right.
Consumer Data-Access Rights in All 50 States and DC
Each section links to a state privacy guide. The operative and future rows identify only the access process and timing supported by the cited authority. They do not establish eligibility or present a complete exemption inventory. Targeted rows remain separate, and unclassified rows make no no-law claim.
| State or D.C. | Framework and effective date | Rights, timing and limits |
|---|---|---|
Alabama | Future comprehensive framework, effective 2027-05-01. | Alabama Personal Data Protection Act, Act 2026-552, Ala. Code § 8-44-5. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Alabama privacy guide. |
Alaska | Unclassified in this comparison. | This article makes no absence-of-law claim. Use the Alaska privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right. |
Arizona | Unclassified in this comparison. | This article makes no absence-of-law claim. Use the Arizona privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right. |
Arkansas | Unclassified in this comparison. | This article makes no absence-of-law claim. Use the Arkansas privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right. |
California | Operative comprehensive framework, since 2020-01-01; current statute edition effective 2026-01-01. | California Consumer Privacy Act as amended, Cal. Civ. Code §§ 1798.100, 1798.110, 1798.115; implementing regulations. Response: 45 days; possible extension: 45 days. Coverage and exemptions still control. See the California privacy guide. |
Colorado | Operative comprehensive framework, since 2023-07-01. | Colorado Privacy Act, Colo. Rev. Stat. § 6-1-1306; 4 CCR 904-3. Response: 45 days; possible extension: 45 days; appeal result: 45 days. Coverage and exemptions still control. See the Colorado privacy guide. |
Connecticut | Operative comprehensive framework, since 2023-07-01. | Connecticut Data Privacy Act, Conn. Gen. Stat. § 42-518. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Connecticut privacy guide. |
Delaware | Operative comprehensive framework, since 2025-01-01. | Delaware Personal Data Privacy Act, 6 Del. C. § 12D-104. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Delaware privacy guide. |
District of Columbia | Unclassified in this comparison. | This article makes no absence-of-law claim. Use the District of Columbia privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right. |
Florida | Operative comprehensive framework, since 2024-07-01. | Florida Digital Bill of Rights, Fla. Stat. §§ 501.705-.707. Response: 45 days; possible extension: 15 days; appeal result: 60 days. Coverage and exemptions still control. See the Florida privacy guide. |
Georgia | Unclassified in this comparison. | This article makes no absence-of-law claim. Use the Georgia privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right. |
Hawaii | Unclassified in this comparison. | This article makes no absence-of-law claim. Use the Hawaii privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right. |
Idaho | Unclassified in this comparison. | This article makes no absence-of-law claim. Use the Idaho privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right. |
Illinois | Unclassified in this comparison. | This article makes no absence-of-law claim. Use the Illinois privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right. |
Indiana | Operative comprehensive framework, since 2026-01-01. | Indiana Consumer Data Protection Act, Ind. Code § 24-15-3-1. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Indiana privacy guide. |
Iowa | Operative comprehensive framework, since 2025-01-01. | Iowa Consumer Data Protection Act, Iowa Code § 715D.3. Response: 90 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Iowa privacy guide. |
Kansas | Unclassified in this comparison. | This article makes no absence-of-law claim. Use the Kansas privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right. |
Kentucky | Operative comprehensive framework, since 2026-01-01. | Kentucky Consumer Data Protection Act, KRS 367.3615. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Kentucky privacy guide. |
Louisiana | Future comprehensive framework, effective 2027-01-01. | Louisiana Data Privacy Act, Act 502 (SB 386), La. R.S. 51:1780.3. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Louisiana privacy guide. |
Maine | Unclassified in this comparison. | This article makes no absence-of-law claim. Use the Maine privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right. |
Maryland | Operative comprehensive framework, since 2025-10-01. | Maryland Online Data Privacy Act, Md. Code, Commercial Law § 14-4605. Response: 45 days; possible extension: 45 days; appeal result: 45 days. Coverage and exemptions still control. See the Maryland privacy guide. |
Massachusetts | Unclassified in this comparison. | This article makes no absence-of-law claim. Use the Massachusetts privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right. |
Michigan | Unclassified in this comparison. | This article makes no absence-of-law claim. Use the Michigan privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right. |
Minnesota | Operative comprehensive framework, since 2025-07-31. | Minnesota Consumer Data Privacy Act, Minn. Stat. § 325M.13. Response: 45 days; possible extension: 45 days; appeal result: 45 days. Coverage and exemptions still control. See the Minnesota privacy guide. |
Mississippi | Unclassified in this comparison. | This article makes no absence-of-law claim. Use the Mississippi privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right. |
Missouri | Unclassified in this comparison. | This article makes no absence-of-law claim. Use the Missouri privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right. |
Montana | Operative comprehensive framework, since 2023-10-01. | Montana Consumer Data Privacy Act, Mont. Code Ann. § 30-14-2808. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Montana privacy guide. |
Nebraska | Operative comprehensive framework, since 2025-01-01. | Nebraska Data Privacy Act, Neb. Rev. Stat. § 87-1107. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Nebraska privacy guide. |
Nevada | Targeted right. | NRS 603A provides a verified opt-out for covered sales by online operators, not the general access right compared here. See NRS 603A.340 creates a verified opt-out of covered sales, not the general access/confirmation right compared here and the Nevada privacy guide. |
New Hampshire | Operative comprehensive framework, since 2025-01-01. | New Hampshire Data Privacy Act, RSA 507-H:4. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the New Hampshire privacy guide. |
New Jersey | Operative comprehensive framework, since 2025-01-15. | New Jersey Data Privacy Act, N.J. Stat. §§ 56:8-166.7 and 56:8-166.10. Response: 45 days; possible extension: 45 days; appeal result: 45 days. Coverage and exemptions still control. See the New Jersey privacy guide. |
New Mexico | Unclassified in this comparison. | This article makes no absence-of-law claim. Use the New Mexico privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right. |
New York | Unclassified in this comparison. | This article makes no absence-of-law claim. Use the New York privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right. |
North Carolina | Unclassified in this comparison. | This article makes no absence-of-law claim. Use the North Carolina privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right. |
North Dakota | Unclassified in this comparison. | This article makes no absence-of-law claim. Use the North Dakota privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right. |
Ohio | Unclassified in this comparison. | This article makes no absence-of-law claim. Use the Ohio privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right. |
Oklahoma | Future comprehensive framework, effective 2027-01-01. | Oklahoma consumer data privacy law, SB 546, Enrolled sections 2-4, to be codified at 75A O.S. §§ 301-303. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Oklahoma privacy guide. |
Oregon | Operative comprehensive framework, since 2024-07-01. | Oregon Consumer Privacy Act, ORS 646A.574 and 646A.578. Response: 45 days; possible extension: 45 days; appeal result: 45 days. Coverage and exemptions still control. See the Oregon privacy guide. |
Pennsylvania | Unclassified in this comparison. | This article makes no absence-of-law claim. Use the Pennsylvania privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right. |
Rhode Island | Operative comprehensive framework, since 2026-01-01. | Rhode Island Data Transparency and Privacy Protection Act, R.I. Gen. Laws §§ 6-48.1-5 and 6-48.1-6. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Rhode Island privacy guide. |
South Carolina | Unclassified in this comparison. | This article makes no absence-of-law claim. Use the South Carolina privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right. |
South Dakota | Unclassified in this comparison. | This article makes no absence-of-law claim. Use the South Dakota privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right. |
Tennessee | Operative comprehensive framework, since 2025-07-01. | Tennessee Information Protection Act, Tenn. Code Ann. § 47-18-3303. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Tennessee privacy guide. |
Texas | Operative comprehensive framework, since 2024-07-01. | Texas Data Privacy and Security Act, Tex. Bus. & Com. Code § 541.051. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Texas privacy guide. |
Utah | Operative comprehensive framework, since 2023-12-31. | Utah Consumer Privacy Act, Utah Code § 13-61-201. Response: 45 days; possible extension: 45 days. Coverage and exemptions still control. See the Utah privacy guide. |
Vermont | Future comprehensive framework, effective 2028-01-01. | Vermont Data Privacy and Online Surveillance Act, Act 145 (S.71), 9 V.S.A. chapter 61A, enacted § 2415d consumer rights. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Vermont privacy guide. |
Virginia | Operative comprehensive framework, since 2023-01-01. | Virginia Consumer Data Protection Act, Va. Code § 59.1-577. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Virginia privacy guide. |
Washington | Targeted right. | Chapter 19.373 RCW provides access concerning covered consumer health data, not all personal data. See RCW 19.373.040 for consumer health data and the Washington privacy guide. |
West Virginia | Unclassified in this comparison. | This article makes no absence-of-law claim. Use the West Virginia privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right. |
Wisconsin | Unclassified in this comparison. | This article makes no absence-of-law claim. Use the Wisconsin privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right. |
Wyoming | Unclassified in this comparison. | This article makes no absence-of-law claim. Use the Wyoming privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right. |
For the broader landscape, see US data privacy laws by state and the guide to opting out of data brokers.
Disclaimer: This guide provides general information about consumer data-access routes as of September 11, 2026. Coverage depends on the requester, residence, organization, data, collection context, statutory thresholds, exemptions, and request date. It is not legal advice. Check the current official statute and the organization's privacy notice before relying on a deadline or remedy. Consult a lawyer licensed in the relevant jurisdiction for advice about a specific request, denial, deadline, or remedy.
About the author: The RecordingLaw Editorial Team researches privacy and recording laws from official statutes and regulator materials.
Last updated: September 11, 2026.
Frequently Asked Questions
Is a data subject access request valid in the United States?
It can be when a state comprehensive law or a federal sector law covers the requester, holder, and data. The United States does not use one universal request right or procedure.
How long does a company have to answer?
Many state frameworks use 45 days and may allow an extension, but Iowa uses 90 days initially and Florida permits a 15-day extension after its initial 45 days. The applicable statute controls.
Can a company verify my identity?
State request processes generally contemplate authentication. Use the secure method provided and supply only information reasonably needed to connect you to the data.
Does every state provide a general consumer access right?
This comparison identifies 20 operative comprehensive frameworks, four future laws, and two targeted regimes. It leaves 25 jurisdictions unclassified and makes no claim that other access rights are absent.
Updates
Independently fact-checked against the cited primary sources
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Code of Federal Regulations Title 45
§ 164.524Access of individuals to protected health information.In forcecited in 25 of our articles
(a) Standard: Access to protected health information —(1) Right of access. Except as otherwise provided in paragraph (a)(2) or (a)(3) of this section, an individual has a right of access to inspect and obtain a copy of protected health information about the individual in a designated record set, for as long as the protected health information is maintained in the designated record set, except for: (i) Psychotherapy notes; and (ii) Information compiled in reasonable anticipation of, or for use in, a civil, criminal, or administrative action or proceeding. (2) Unreviewable grounds for denial. A covered entity may deny an individual access without providing the individual an opportunity for review, in the following circumstances. (i) The protected health information is excepted from the right of access by paragraph (a)(1) of this section.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Cited in 88 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Webb v. Smart Document Solutions, LLC (2007) held the reduced, cost-based fee in section 164.524(c)(4) applies only when the individual himself requests his records, not a law firm acting as his agent. Ciox Health, LLC v. Hargan (2020) vacated 2016 guidance that extended that patient rate to third-party directives.
Opinions citing this section in our collection:
- Webb v. Smart Document Solutions, LLC (Court of Appeals for the Ninth Circuit 2007, 499 F.3d 1078)✓A law firm ordered its client's hospital records and was billed a copying company's higher third-party rate; the Ninth Circuit held Section 164.524(c)(4)'s cost-based fee limit applies only when the individual or a personal representative asks, not an attorney acting as agent.
- Evenson v. Hartford Life & Annuity Insurance (District Court, M.D. Florida 2007, 244 F.R.D. 666)✓A therapist refused a subpoena for her psychotherapy notes, citing Section 164.524(a)(1)'s exclusion of those notes from a patient's right of access; the court held that exclusion governs only individual access, not discovery, and ordered the notes produced.
- Ciox Health, LLC v. Hargan (District Court, District of Columbia 2020)“…fee that can be charged for such production. See generally 45 C.F.R. § 164.524. For requests brought by an individual…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: How Long Do Hospitals Keep Medical Records? (2026), How to Find Old Medical Records Online, Medical Records Retention Laws by State (2026 Guide)
United States Code Title 15
§ 1681gDisclosures to consumersIn forcecited in 4 of our articles
(a) Information on file; sources; report recipients Every consumer reporting agency shall, upon request, and subject to section 1681h(a)(1) of this title, clearly and accurately disclose to the consumer: (1) All information in the consumer’s file at the time of the request, except that— (A) if the consumer to whom the file relates requests that the first 5 digits of the social security number (or similar identification number) of the consumer not be included in the disclosure and the consumer reporting agency has received appropriate proof of the identity of the requester, the consumer reporting agency shall so truncate such number in such disclosure; and (B) nothing in this paragraph shall be construed to require a consumer reporting agency to disclose to a consumer any information concerning credit scores or any other risk scores or predictors relating to the consumer.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 271 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Sandra Cortez v. Trans Union (Court of Appeals for the Third Circuit 2010, 617 F.3d 688)“…rify information.”).25 C. Trans Union’s Liability Under 15 U.S.C. § 1681g 15 U.S.C. § 1681g(a) states in…”
- Renie Guimond v. Trans Union Credit Information Company (Court of Appeals for the Ninth Circuit 1995, 45 F.3d 1329)“…and willfully 1) violated 15 U.S.C. § 1681e(b); 2) violated 15 U.S.C. § 1681g(a)(2); 3) violated 15 U.S.C. § 1681i(c)…”
- John Shaw v. Experian Information Solutions (Court of Appeals for the Ninth Circuit 2018, 891 F.3d 749)“…U.S.C. § 1681i; and (3) a file disclosure claim pursuant to 15 U.S.C. § 1681g. They requested damages pursuant to 15 U…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: FTC Fines Amazon $2.25 Million for Denying Identity-Theft Victims Their Fraud Records Under the FCRA, 15 U.S.C. § 1681 (FCRA): Credit Report Rights Explained
Code of Federal Regulations Title 34
§ 99.10What rights exist for a parent or eligible student to inspect and review education records?In forcecited in 2 of our articles
(a) Except as limited under § 99.12, a parent or eligible student must be given the opportunity to inspect and review the student's education records. This provision applies to— (1) Any educational agency or institution; and (2) Any State educational agency (SEA) and its components. (i) For the purposes of subpart B of this part, an SEA and its components constitute an educational agency or institution. (ii) An SEA and its components are subject to subpart B of this part if the SEA maintains education records on students who are or have been in attendance at any school of an educational agency or institution subject to the Act and this part. (b) The educational agency or institution, or SEA or its component, shall comply with a request for access to records within a reasonable period of time, but not more than 45 days after it has received the request. (c) The educational agency or institution, or SEA or its component shall respond to reasonable requests for explanations and interpretations of the records.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
United States Code Title 5
§ 552Public information; agency rules, opinions, orders, records, and proceedingsIn forcecited in 38 of our articles
Each agency shall make available to the public information as follows: Each agency shall separately state and currently publish in the Federal Register for the guidance of the public— descriptions of its central and field organization and the established places at which, the employees (and in the case of a uniformed service, the members) from whom, and the methods whereby, the public may obtain information, make submittals or requests, or obtain decisions; statements of the general course and method by which its functions are channeled and determined, including the nature and requirements of all formal and informal procedures available; rules of procedure, descriptions of forms available or the places at which forms may be obtained, and instructions as to the scope and contents of all papers, reports, or examinations; substantive rules of general applicability adopted as authorized by law, and statements of general policy or interpretations of general applicability formulated and adopted by the agency; and each amendment, revision, or repeal of the foregoing.
Official text (excerpt) · last checked 2026-09-02 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 11,434 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):United States Department of Justice v. Reporters Committee for Freedom of the Press (1989) held categorically that releasing a private citizen's FBI rap sheet to a third party is an unwarranted privacy invasion under Exemption 7(C). Consumer Product Safety Commission v. GTE Sylvania, Inc. (1980) applied Exemption 3, 552(b)(3).
Opinions citing this section in our collection:
- Alyeska Pipeline Service Co. v. Wilderness Society (Supreme Court of the United States 1975, 421 U.S. 240)“…Pub. L. 93-502, § 1 (b) (2), 88 Stat. 1561 (amending 5 U. S. C. § 552 (a)); Packers and Stockyards Act, 42…”
- Consumer Product Safety Commission v. GTE Sylvania, Inc. (Supreme Court of the United States 1980, 447 U.S. 102)✓Consumer groups filed FOIA requests for accident reports manufacturers had given the CPSC as confidential; the Court held that the Consumer Product Safety Act's section 6(b)(1) applies to FOIA requests and that its standards fall within Exemption 3, 5 U.S.C. § 552(b)(3).
- Taylor v. Sturgell (Supreme Court of the United States 2008, 553 U.S. 880)✓An aircraft enthusiast made a FOIA request for FAA records after a friend's identical suit failed; the Court disapproved preclusion by 'virtual representation' and read § 552(a)(3)(A) as directing agencies to release records to the requesting person, not the public at large.
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Public Records Laws by State: FOIA Guide for All 50 States (2026), How to File a FOIA Request (Step by Step, 2026), Virginia Freedom of Information Act: Who Can Request and How (2026)
§ 552aRecords maintained on individualsIn forcecited in 4 of our articles
For purposes of this section— the term “agency” means agency as defined in section 552(e) 1 See References in Text note below. of this title; the term “individual” means a citizen of the United States or an alien lawfully admitted for permanent residence; the term “maintain” includes maintain, collect, use, or disseminate; the term “record” means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, his education, financial transactions, medical history, and criminal or employment history and that contains his name, or the identifying number, symbol, or other identifying particular assigned to the individual, such as a finger or voice print or a photograph; the term “system of records” means a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual; the term “statistical record” means a record in a system of records maintained for statistical research or reporting purposes only and not used in whole or in part in making any determination about…
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 3,701 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Siegert v. Gilley (Supreme Court of the United States 1991, 500 U.S. 226)“…n that Bartel had violated the federal Privacy Act of 1974, 5 U. S. C. § 552a, during his previous tenure with the FA…”
- United States Department of Justice v. Reporters Committee for Freedom of the Press (Supreme Court of the United States 1989, 489 U.S. 749)“…terized information is the Privacy Act of 1974, codified at 5 U. S. C. § 552a (1982 ed. and Supp. V). The Privacy Act…”
- Department of the Air Force v. Rose (Supreme Court of the United States 1976, 425 U.S. 352)“…ngress’ recent manifest concern in the Privacy Act of 1974, 5 U. S. C. § 552a (1970 ed.; Supp. Y), for “governmental…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: District of Columbia AI Meeting Recording Laws (2026), 5 U.S.C. § 552 (FOIA) Explained: Requests, Fees, Appeals
Revised Code of Washington
§ 19.373.040Consumer rights and requests—Refusal—Appeal.In forcecited in 4 of our articles
(1)(a) Except as provided in subsection (2) of this section, beginning March 31, 2024, a consumer has the right to confirm whether a regulated entity or a small business is collecting, sharing, or selling consumer health data concerning the consumer and to access such data, including a list of all third parties and affiliates with whom the regulated entity or the small business has shared or sold the consumer health data and an active email address or other online mechanism that the consumer may use to contact these third parties. (b) A consumer has the right to withdraw consent from the regulated entity's or the small business's collection and sharing of consumer health data concerning the consumer. (c) A consumer has the right to have consumer health data concerning the consumer deleted and may exercise that right by informing the regulated entity or the small business of the consumer's request for deletion.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at app.leg.wa.gov
Also relied on in: MHMDA Business Compliance (Washington), MHMDA Consumer Rights (Washington)
California Civil Code
§ 1798.100In forcecited in 13 of our articles
General Duties of Businesses that Collect Personal Information (a) A business that controls the collection of a consumer’s personal information shall, at or before the point of collection, inform consumers of the following: (1) The categories of personal information to be collected and the purposes for which the categories of personal information are collected or used and whether that information is sold or shared. A business shall not collect additional categories of personal information or use personal information collected for additional purposes that are incompatible with the disclosed purpose for which the personal information was collected without providing the consumer with notice consistent with this section. (2) If the business collects sensitive personal information, the categories of sensitive personal information to be collected and the purposes for which the categories of sensitive personal information are collected or used, and whether that information is sold or shared.
Official text (excerpt) · last checked 2026-08-31 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 36 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Untitled California Attorney General Opinion (California Attorney General Reports 2022)“…ROUND The California Consumer Privacy Act of 2018 (Civil Code, §§ 1798.100 et seq.) is the first law of its kind i…”
- Troester v. Starbucks Corporation (California Supreme Court 2018, 235 Cal. Rptr. 3d 820)“…he consumer law context. (See Consumer Privacy Act of 2018, Civ. Code, § 1798.100 et seq. (added by Stats. 2018, ch. 55,…”
- Hajny v. Volkswagen Group of America CA1/1 (California Court of Appeal 2024)“…ions of the California Consumer Privacy Act of 2018 (CCPA), Civil Code section 1798.100 et seq. Shortly after Wynne filed…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: California Sues 23andMe's Successor Over Genetic Data Breach (2026), Employee Data Privacy: Employer Obligations by State (2026), Privacy Policy Requirements: What You Must Include (2026)
§ 1798.110In forcecited in 2 of our articles
Consumers’ Right to Know What Personal Information is Being Collected. Right to Access Personal Information (a) A consumer shall have the right to request that a business that collects personal information about the consumer disclose to the consumer the following: (1) The categories of personal information it has collected about that consumer. (2) The categories of sources from which the personal information is collected. (3) The business or commercial purpose for collecting, selling, or sharing personal information. (4) The categories of third parties to whom the business discloses personal information. (5) The specific pieces of personal information it has collected about that consumer.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
§ 1798.115In forcecited in 2 of our articles
Consumers’ Right to Know What Personal Information is Sold or Shared and to Whom (a) A consumer shall have the right to request that a business that sells or shares the consumer’s personal information, or that discloses it for a business purpose, disclose to that consumer: (1) The categories of personal information that the business collected about the consumer. (2) The categories of personal information that the business sold or shared about the consumer and the categories of third parties to whom the personal information was sold or shared, by category or categories of personal information for each category of third parties to whom the personal information was sold or shared. (3) The categories of personal information that the business disclosed about the consumer for a business purpose and the categories of persons to whom it was disclosed for a business purpose.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Colorado Revised Statutes, Title 6: Consumer and Commercial Affairs
§ 6-1-1306Consumer personal data rightsIn forcecited in 5 of our articles
(1) Consumers may exercise the following rights by submitting a request using the methods specified by the controller in the privacy notice required under section 6-1-1308 (1)(a). The method must take into account the ways in which consumers normally interact with the controller, the need for secure and reliable communication relating to the request, and the ability of the controller to authenticate the identity of the consumer making the request. Controllers shall not require a consumer to create a new account in order to exercise consumer rights pursuant to this section but may require a consumer to use an existing account. A consumer may submit a request at any time to a controller specifying which of the following rights the consumer wishes to exercise: (a) Right to opt out. (I) A consumer has the right to opt out of the processing of personal data concerning the consumer for purposes of: (A) Targeted advertising; (B) The sale of personal data; or (C) Profiling in furtherance of decisions that produce legal or similarly significant effects concerning a consumer.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at olls.info
Also relied on in: Colorado Privacy Act Consumer Rights & How to Use Them, Colorado Data Privacy Laws: CPA Consumer Rights Guide (2026), What Is the Colorado Privacy Act (CPA)?
Connecticut General Statutes, Title 42 (Business, Selling, Trading and Collection Practices), Chapter 743jj
§ 42-518Consumers' rights. Compliance by Controllers. Appeals.In forcecited in 5 of our articles
(a) A consumer shall have the right to: (1) Confirm whether or not a controller is processing the consumer's personal data and access such personal data, unless such confirmation or access would require the controller to reveal a trade secret; (2) correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; (3) delete personal data provided by, or obtained about, the consumer; (4) obtain a copy of the consumer's personal data processed by the controller, in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means, provided such controller shall not be required to reveal any trade secret; and (5) opt out of the processing of the personal data for purposes of (A) targeted advertising, (B) the sale of personal data, except as provided in subsection (b) of section 42-520, or (C) profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the consumer.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at cga.ct.gov
Also relied on in: CTDPA Consumer Rights: Exercise Your Connecticut Privacy Rights, What Is the CTDPA? Connecticut Data Privacy Act Explained, Connecticut Data Privacy Laws: CTDPA Consumer Rights Guide (2026)
Delaware Code, Title 6 (Commerce and Trade), Chapter 012d (Delaware Personal Data Privacy Act)
§ 12D-104Consumer personal data rights.In forcecited in 5 of our articles
(a) A consumer has the right to do all of the following: (1) Confirm whether a controller is processing the consumer’s personal data and access such personal data, unless such confirmation or access would require the controller to reveal a trade secret. (2) Correct inaccuracies in the consumer’s personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer’s personal data. (3) Delete personal data provided by, or obtained about, the consumer. (4) Obtain a copy of the consumer’s personal data processed by the controller, in a portable and, to the extent technically feasible, readily-usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means, provided such controller shall not be required to reveal any trade secret. (5) Obtain a list of the categories of third parties to which the controller has disclosed the consumer’s personal data. (6) Opt out of the processing of the personal data for purposes of any of the following: a. Targeted advertising. b. The sale of personal data, except as provided in § 12D-106(b) of this title.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at delcode.delaware.gov
Also relied on in: Delaware Data Privacy Laws: DPDPA Consumer Rights Guide (2026), DPDPA Consumer Rights: Delaware Data Privacy, What Is the DPDPA? Delaware Data Privacy Act
Florida Statutes
§ 501.702Definitions.In forcecited in 6 of our articles
As used in this part, the term:(1) “Affiliate” means a legal entity that controls, is controlled by, or is under common control with another legal entity or that shares common branding with another legal entity. For purposes of this subsection, the term “control” or “controlled” means any of the following:(a) The ownership of, or power to vote, more than 50 percent of the outstanding shares of any class of voting security of a company. (b) The control in any manner over the election of a majority of the directors or of individuals exercising similar functions. (c) The power to exercise controlling influence over the management of a company. (2) “Aggregate consumer information” means information that relates to a group or category of consumers from which the identity of an individual consumer has been removed and is not reasonably capable of being directly or indirectly associated or linked with any consumer, household, or device. The term does not include information about a group or category of consumers used to facilitate targeted advertising or the display of ads online. The term does not include personal information that has been deidentified.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leg.state.fl.us
Also relied on in: Florida Biometric Privacy Laws: Collection, Consent & Penalties (2026), FDBR Compliance Checklist: Florida Data Privacy, FDBR Consumer Rights: Florida Data Privacy Rights
§ 501.706Controller response to consumer requests.In forcecited in 4 of our articles
(1) Except as otherwise provided by this part, a controller shall comply with a request submitted by a consumer to exercise the consumer’s rights pursuant to s. 501.705, as provided in this section. (2) A controller shall respond to the consumer request without undue delay, which may not be later than 45 days after the date of receipt of the request. The controller may extend the response period once by an additional 15 days when reasonably necessary, taking into account the complexity and number of the consumer’s requests, so long as the controller informs the consumer of the extension within the initial 45-day response period, together with the reason for the extension. (3) If a controller cannot take action regarding the consumer’s request, the controller must inform the consumer without undue delay, which may not be later than 45 days after the date of receipt of the request, of the justification for the inability to take action on the request and provide instructions on how to appeal the decision in accordance with s. 501.707. A controller is not required to comply with a consumer request submitted under s. 501.705 if the controller cannot authenticate the request.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leg.state.fl.us
§ 501.707Appeal.In forcecited in 3 of our articles
(1) A controller shall establish a process for a consumer to appeal the controller’s refusal to take action on a request within a reasonable period of time after the consumer’s receipt of the decision under s. 501.706(3). (2) The appeal process must be conspicuously available and similar to the process for initiating action to exercise consumer rights by submitting a request under s. 501.705. (3) A controller shall inform the consumer in writing of any action taken or not taken in response to an appeal under this section within 60 days after the date of receipt of the appeal, including a written explanation of the reason or reasons for the decision.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leg.state.fl.us
Indiana Code, TITLE 24. TRADE REGULATION
§ 24-15-3-1Personal data; consumer rights; consumer's request to controller; compliance by controller; consumer's right to appealIn forcecited in 6 of our articles
Sec. 1. (a) A consumer may invoke one (1) or more rights set forth in subsection (b) by submitting to a controller a request specifying the rights the consumer wishes to invoke. A known child's parent or legal guardian may invoke on behalf of the child one (1) or more rights set forth in subsection (b) with respect to the processing of personal data belonging to the known child by submitting to a controller a request specifying the rights the consumer wishes to invoke on behalf of the child. Except as provided in IC 24-15-7-1(c) and IC 24-15-7-2, and subject to any limitations or conditions set forth in subsections (b) and (c), a controller shall comply with an authenticated consumer request to exercise a right set forth in subsection (b). (b) A consumer has the following rights: (1) To confirm whether or not a controller is processing the consumer's personal data and, subject to the limitations set forth in subdivision (4), to access such personal data.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at iga.in.gov
Also relied on in: INCDPA Compliance Checklist for Indiana Businesses, What Is the INCDPA? Indiana's Data Privacy Law, Indiana Data Privacy Laws: ICDPA Consumer Rights Guide (2026)
Kentucky Revised Statutes, Chapter 367: CONSUMER PROTECTION
§ 367.3615Consumer rights request -- Controller compliance -- Requirements -- Appeal processIn forcecited in 7 of our articles
(1) A consumer may invoke the consumer rights authorized pursuant to this section at any time by submitting a request to a controller, via the means specified by the controller pursuant to KRS 367.3617, specifying the consumer rights the consumer wishes to invoke. A child's parent or legal guardian may invoke such consumer rights on behalf of the child regarding processing personal data belonging to the child. (2) A controller shall comply with an authenticated consumer request to exercise the right to: (a) Confirm whether or not a controller is processing the consumer's personal data and to access the personal data, unless the confirmation and access would require the controller to reveal a trade secret; (b) Correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of processing the data; (c) Delete personal data provided by or obtained about the consumer; (d) Obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent technically practicable, readily usable format that allows the consumer to transmit the data to another controller…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at apps.legislature.ky.gov
Also relied on in: Kentucky Data Privacy Laws: Consumer Rights Guide (2026), Kentucky Biometric Privacy Laws: Collection, Consent & Penalties (2026), KCDPA Compliance Checklist: Kentucky Privacy Law
Minnesota Statutes, Chapter 325M: CONSUMER DIGITAL AND DATA PRIVACY
§ 325M.13RESPONSIBILITY ACCORDING TO ROLEIn forcecited in 2 of our articles
(a) Controllers and processors are responsible for meeting the respective obligations established under sections 325M.10 to 325M.21. (b) Processors are responsible under sections 325M.10 to 325M.21 for adhering to the instructions of the controller and assisting the controller to meet the controller's obligations under sections 325M.10 to 325M.21. Assistance under this paragraph shall include the following: (1) taking into account the nature of the processing, the processor shall assist the controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the controller's obligation to respond to consumer requests to exercise their rights pursuant to section 325M.14; and (2) taking into account the nature of processing and the information available to the processor, the processor shall assist the controller in meeting the controller's obligations in relation to the security of processing the personal data and in relation to the notification of a breach of the security of the system pursuant to section 325E.61, and shall provide information to the controller necessary to enable the controller to conduct and document any data…
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at revisor.mn.gov
Montana Code Annotated, Title 30
§ 30-14-2808Consumer Personal Data -- Opt-Out -- Compliance -- AppealsIn forcecited in 6 of our articles
30-14-2808. Consumer personal data -- opt-out -- compliance -- appeals. (1) A consumer must have the right to: (a) confirm whether a controller is processing the consumer's personal data and access the consumer's personal data, unless such confirmation or access would require the controller to reveal a trade secret; (b) correct inaccuracies in the consumer's personal data, considering the nature of the personal data and the purposes of the processing of the consumer's personal data; (c) delete personal data about the consumer; (d) obtain a copy of the consumer's personal data previously provided by the consumer to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the personal data to another controller without hindrance when the processing is carried out by automated means, provided the controller is not required to reveal any trade secret; and (e) opt out of the processing of the consumer's personal data for the purposes of: (i) targeted advertising; (ii) the sale of the consumer's personal data, except as provided in 30-14-2812(2); or (iii) profiling in furtherance of automated decisions that…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at mca.legmt.gov
Also relied on in: MCDPA Consumer Rights: Montana Privacy Rights (2026), What Is the MCDPA? Montana Data Privacy Law (2026), Montana Data Privacy Laws: MCDPA Consumer Rights Guide (2026)
Nebraska Revised Statutes, Chapter 87: TRADE PRACTICES
§ 87-1107Consumer rights; request to exerciseIn forcecited in 5 of our articles
(1) A consumer may at any time submit a request to a controller specifying the consumer rights the consumer wishes to exercise. With respect to the processing of personal data belonging to a known child, a parent or legal guardian of the child may exercise the consumer rights on behalf of the known child. (2) A controller shall comply with an authenticated consumer request to exercise the right to: (a) Confirm whether a controller is processing the consumer's personal data and to access the personal data; (b) Correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; (c) Delete personal data provided by or obtained about the consumer; (d) If the data is available in a digital format and the processing is completed by automated means, obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance; or (e) Opt out of the processing of the personal data for purposes…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at nebraskalegislature.gov
Also relied on in: Nebraska Data Privacy Laws: Consumer Rights Guide (2026), NDPA Consumer Rights: Nebraska Data Privacy (2026), Nebraska Biometric Privacy Laws: Collection, Consent & Penalties (2026)
New Hampshire Revised Statutes Annotated, TITLE LII ACTIONS, PROCESS, AND SERVICE OF PROCESS, CHAPTER 507-H EXPECTATION OF PRIVACY
§ 507-H:4Consumer Expectation of Privacy.In forcecited in 6 of our articles
I. A consumer shall have the right to: (a) Confirm whether or not a controller is processing the consumer's personal data and access such personal data, unless such confirmation or access would require the controller to reveal a trade secret; (b) Correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; (c) Delete personal data provided by, or obtained about, the consumer; (d) Obtain a copy of the consumer's personal data processed by the controller, in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means, provided such controller shall not be required to reveal any trade secret; and (e) Opt-out of the processing of the personal data for purposes of targeted advertising, the sale of personal data, except as provided in RSA 507-H:6, or profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the consumer. II.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at gc.nh.gov
Also relied on in: New Hampshire Biometric Privacy Laws: Collection, Consent & Penalties (2026), NHDPA Consumer Rights: New Hampshire Data Privacy, New Hampshire Data Privacy Laws: Consumer Rights Guide (2026)
New Jersey Statutes (Unannotated)
§ 56:8-166.10Consumer rights, personal data.In forcecited in 5 of our articles
7. a. A consumer shall have the right to: (1) confirm whether a controller processes the consumer's personal data and accesses such personal data, provided that nothing in this paragraph shall require a controller to provide the data to the consumer in a manner that would reveal the controller's trade secrets; (2) correct inaccuracies in the consumer's personal data, taking into account the nature of the information and the purposes of the processing of the information; (3) delete personal data concerning the consumer; (4) obtain a copy of the consumer's personal data held by the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another entity without hindrance, provided that nothing in this paragraph shall require a controller to provide the data to the consumer in a manner that would reveal the controller's trade secrets; and (5) opt out of the processing of personal data for the purposes of (a) targeted advertising; (b) the sale of personal data; or (c) profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer. b.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at lis.njleg.state.nj.us
Also relied on in: NJDPA Consumer Rights: New Jersey Privacy Law, New Jersey Data Privacy Laws: NJDPA Consumer Rights Guide (2026), What Is the NJDPA? New Jersey Data Privacy Act
§ 56:8-166.7Personal data; controller, verified request, consumer, response period.In forcecited in 4 of our articles
4. a. A controller that receives a verified request from a consumer shall provide a response to the consumer within 45 days of the controller's receipt of the request. The controller may extend the response period by 45 additional days where reasonably necessary, considering the complexity and number of the consumer's requests, provided that the controller informs the consumer of any such extension within the initial 45-day response period and the reason for the extension and shall provide the information for all disclosures of personal data that occurred in the prior 12 months. b. This section shall not apply to personal data collected prior to the effective date of P.L.2023, c.266 (C.56:8-166.4 et seq.) unless the controller continues to process such information thereafter. c. If a controller declines to take action regarding the consumer's request, the controller shall inform the consumer without undue delay, but not later than 45 days after receipt of the request, of the justification for declining to take action and instructions for how to appeal the decision.
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at lis.njleg.state.nj.us
Also relied on in: NJDPA Compliance Checklist: New Jersey Privacy
Oregon Revised Statutes, Chapter 646A: Trade Regulation
§ 646A.574Consumer requests for personal data; requirement to correct inaccuracies; requirement to delete personal data; conditions under which consumer may opt out of personal data processing; format for providing copy of personal data to consumerIn forcecited in 5 of our articles
(1) Subject to ORS 646A.576, a consumer may: (a) Obtain from a controller: (A) Confirmation as to whether the controller is processing or has processed the consumer’s personal data and the categories of personal data the controller is processing or has processed; (B) At the controller’s option, a list of specific third parties, other than natural persons, to which the controller has disclosed: (i) The consumer’s personal data; or (ii) Any personal data; and (C) A copy of all of the consumer’s personal data that the controller has processed or is processing; (b) Require a controller to correct inaccuracies in personal data about the consumer, taking into account the nature of the personal data and the controller’s purpose for processing the personal data; (c) Require a controller to delete personal data about the consumer, including personal data the consumer provided to the controller, personal data the controller obtained from another source and derived data; or (d) Opt out from a controller’s processing of personal data of the consumer that the controller processes for any of the following purposes: (A) Targeted advertising; (B) Selling…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at oregonlegislature.gov
Also relied on in: OCPA Compliance Checklist for Oregon Businesses, OCPA Consumer Rights: Oregon Data Privacy Act, What Is the OCPA? Oregon Consumer Privacy Act
§ 646A.578Duties of controller; prohibitions; privacy notice to consumerIn forcecited in 7 of our articles
(1) A controller shall: (a) Specify in the privacy notice described in subsection (4) of this section the express purposes for which the controller is collecting and processing personal data; (b) Limit the controller’s collection of personal data to only the personal data that is adequate, relevant and reasonably necessary to serve the purposes the controller specified in paragraph (a) of this subsection; (c) Establish, implement and maintain for personal data the same safeguards described in ORS 646A.622 that are required for protecting personal information, as defined in ORS 646A.602, such that the controller’s safeguards protect the confidentiality, integrity and accessibility of the personal data to the extent appropriate for the volume and nature of the personal data; and (d) Provide an effective means by which a consumer may revoke consent a consumer gave under ORS 646A.570 to 646A.589 to the controller’s processing of the consumer’s personal data. The means must be at least as easy as the means by which the consumer provided consent.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at oregonlegislature.gov
Also relied on in: Oregon Data Privacy Laws: OCPA Consumer Rights Guide (2026), Oregon Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Rhode Island General Laws, Title 6: Commercial Law
§ 6-48.1-5Customer rights. [Effective January 1, 2026.]In forcecited in 7 of our articles
(a) This section shall apply to for-profit entities that conduct business in the state or for-profit entities that produce products or services that are targeted to residents of the state and that during the preceding calendar year did any of the following: (1) Controlled or processed the personal data of not less than thirty-five thousand (35,000) customers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction. (2) Controlled or processed the personal data of not less than ten thousand (10,000) customers and derived more than twenty percent (20%) of their gross revenue from the sale of personal data. (b) No controller shall discriminate against a customer for exercising their customer rights. (c) No controller shall deny goods or services, charge different prices or rates for goods or services, or provide a different level of quality of goods or services to the customer if the customer opts out to use of their data. However, if a customer opts out of data collection, the covered entity is not required to provide a service that requires this data collection.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at webserver.rilegislature.gov
Also relied on in: Rhode Island Data Privacy Laws: RIDTPPA Consumer Rights Guide (2026), Rhode Island Biometric Privacy Laws: Collection, Consent & Penalties (2026), RIDTPPA Compliance Checklist for Rhode Island
§ 6-48.1-6Exercising customer rights. [Effective January 1, 2026.]In forcecited in 6 of our articles
(a) This section shall apply to for-profit entities that conduct business in the state or for-profit entities that produce products or services that are targeted to residents of the state and that during the preceding calendar year did any of the following: (1) Controlled or processed the personal data of not less than thirty-five thousand (35,000) customers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction. (2) Controlled or processed the personal data of not less than ten thousand (10,000) customers and derived more than twenty percent (20%) of their gross revenue from the sale of personal data. (b) A controller shall comply with a request by a customer to exercise the customer rights authorized as follows: (1) A controller shall respond to the customer without undue delay, but not later than forty-five (45) days after receipt of the request.
Official text (excerpt) · last checked 2026-07-30 · Read the full text in our law library · Verify at webserver.rilegislature.gov
Also relied on in: What Is the RIDTPPA? Rhode Island Data Privacy Act, RIDTPPA Consumer Rights in Rhode Island Explained
Texas Business & Commerce Code
§ 541.051CONSUMER'S PERSONAL DATA RIGHTS; REQUEST TO EXERCISE RIGHTSIn forcecited in 5 of our articles
(a) A consumer is entitled to exercise the consumer rights authorized by this section at any time by submitting a request to a controller specifying the consumer rights the consumer wishes to exercise. With respect to the processing of personal data belonging to a known child, a parent or legal guardian of the child may exercise the consumer rights on behalf of the child. (b) A controller shall comply with an authenticated consumer request to exercise the right to: (1) confirm whether a controller is processing the consumer's personal data and to access the personal data; (2) correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; (3) delete personal data provided by or obtained about the consumer; (4) if the data is available in a digital format, obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance; or (5) opt out of the processing of the personal…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at statutes.capitol.texas.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- State of Texas v. Arity 875, LLC (Texas Court of Appeals, 15th District 2025)“…10 Tex. Bus. & Com. Code § 541.051(b)(5) .................................…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: TDPSA Consumer Rights: Your Texas Data Privacy Rights, What Is the TDPSA? Texas Data Privacy and Security Act, Texas Data Privacy Laws: TDPSA & Consumer Rights Guide (2026)
Utah Code, Title 13: Commerce and Trade
§ 13-61-201Consumer rights -- Access -- Deletion -- Portability -- Opt out of certain processing.In forcecited in 6 of our articles
(1) A consumer has the right to: (a) confirm whether a controller is processing the consumer's personal data; and (b) access the consumer's personal data. (2) A consumer has the right to delete the consumer's personal data that the consumer provided to the controller. (3) A consumer has the right to obtain a copy of the consumer's personal data, that the consumer previously provided to the controller, in a format that: (a) to the extent technically feasible, is portable; (b) to the extent practicable, is readily usable; and (c) allows the consumer to transmit the data to another controller without impediment, where the processing is carried out by automated means. (4) A consumer has the right to request that a controller correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data. (5) A consumer has the right to opt out of the processing of the consumer's personal data for purposes of: (a) targeted advertising; or (b) the sale of personal data. (6) Nothing in this section requires a person to cause a breach of security system as defined in Section 13-44-102.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at le.utah.gov
Also relied on in: UCPA Compliance Checklist for Businesses (Utah 2026), UCPA Consumer Rights: Access, Delete & Opt Out (Utah), Utah Data Privacy Laws: UCPA Consumer Rights Guide (2026)
Code of Virginia, Title 59.1: Trade and Commerce
§ 59.1-577Personal data rights; consumersIn forcecited in 9 of our articles
A. A consumer may invoke the consumer rights authorized pursuant to this subsection at any time by submitting a request to a controller specifying the consumer rights the consumer wishes to invoke. A known child's parent or legal guardian may invoke such consumer rights on behalf of the child regarding processing personal data belonging to the known child. A controller shall comply with an authenticated consumer request to exercise the right: 1. To confirm whether or not a controller is processing the consumer's personal data and to access such personal data; 2. To correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; 3. To delete personal data provided by or obtained about the consumer; 4. To obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means; and 5.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at law.lis.virginia.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- Eweka (District Court, E.D. Virginia 2025)“…e the VCDPA protects consumer’s private personal data, see Va Code Ann. § 59.1-577, it explicitly gives Virginia’s Attorne…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: How to Submit a Data Deletion Request (2026), Virginia Data Privacy Laws: VCDPA Consumer Rights Guide (2026), Virginia Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- 45 C.F.R. § 164.524(www.hhs.gov).gov
- 15 U.S.C. § 1681g(uscode.house.gov).gov
- 34 C.F.R. § 99.10(www.ecfr.gov).gov
- 5 U.S.C. §§ 552, 552a(www.justice.gov).gov
- Ala. Act 2026-552; La. Act 502 (2026); Okla. SB 546 (2026); Vt. Act 145 (2026)(alison.legislature.state.al.us).gov
- Ala. Act 2026-552; La. Act 502 (2026); Okla. SB 546 (2026); Vt. Act 145 (2026)(www.legis.la.gov).gov
- Ala. Act 2026-552; La. Act 502 (2026); Okla. SB 546 (2026); Vt. Act 145 (2026)(www.oklegislature.gov).gov
- Ala. Act 2026-552; La. Act 502 (2026); Okla. SB 546 (2026); Vt. Act 145 (2026)(legislature.vermont.gov).gov
- NRS Chapter 603A; chapter 19.373 RCW(www.leg.state.nv.us).gov
- NRS Chapter 603A; chapter 19.373 RCW(app.leg.wa.gov).gov
- Iowa Code § 715D.3; Fla. Stat. §§ 501.706-.707(www.legis.iowa.gov).gov
- Iowa Code § 715D.3; Fla. Stat. §§ 501.706-.707(www.leg.state.fl.us).gov
- Iowa Code § 715D.3; Fla. Stat. §§ 501.706-.707(www.leg.state.fl.us).gov
- Maine LD 1822 official status(legislature.maine.gov).gov
- Alabama Personal Data Protection Act, Act 2026-552: Ala. Code § 8-44-5(alison.legislature.state.al.us).gov
- California Consumer Privacy Act as amended: Cal. Civ. Code §§ 1798.100, 1798.110, 1798.115; implementing regulations(cppa.ca.gov).gov
- Colorado Privacy Act: Colo. Rev. Stat. § 6-1-1306; 4 CCR 904-3(coag.gov).gov
- Connecticut Data Privacy Act: Conn. Gen. Stat. § 42-518(www.cga.ct.gov).gov
- Delaware Personal Data Privacy Act: 6 Del. C. § 12D-104(delcode.delaware.gov).gov
- Florida Digital Bill of Rights: Fla. Stat. §§ 501.705-.707(www.leg.state.fl.us).gov
- Indiana Consumer Data Protection Act: Ind. Code § 24-15-3-1(iga.in.gov).gov
- Kentucky Consumer Data Protection Act: KRS 367.3615(apps.legislature.ky.gov).gov
- Louisiana Data Privacy Act, Act 502 (SB 386): La. R.S. 51:1780.3(www.legis.la.gov).gov
- Maryland Online Data Privacy Act: Md. Code, Commercial Law § 14-4605(mgaleg.maryland.gov).gov
- Minnesota Consumer Data Privacy Act: Minn. Stat. § 325M.13(www.revisor.mn.gov).gov
- Montana Consumer Data Privacy Act: Mont. Code Ann. § 30-14-2808(archive.legmt.gov).gov
- Nebraska Data Privacy Act: Neb. Rev. Stat. § 87-1107(nebraskalegislature.gov).gov
- New Hampshire Data Privacy Act: RSA 507-H:4(gc.nh.gov).gov
- New Jersey Data Privacy Act: N.J. Stat. §§ 56:8-166.7 and 56:8-166.10(pub.njleg.state.nj.us).gov
- Oklahoma consumer data privacy law, SB 546: Enrolled sections 2-4, to be codified at 75A O.S. §§ 301-303(www.oklegislature.gov).gov
- Oregon Consumer Privacy Act: ORS 646A.574 and 646A.578(www.oregonlegislature.gov).gov
- Rhode Island Data Transparency and Privacy Protection Act: R.I. Gen. Laws §§ 6-48.1-5 and 6-48.1-6(webserver.rilegislature.gov).gov
- Tennessee Information Protection Act: Tenn. Code Ann. § 47-18-3303(www.tn.gov).gov
- Texas Data Privacy and Security Act: Tex. Bus. & Com. Code § 541.051(statutes.capitol.texas.gov).gov
- Utah Consumer Privacy Act: Utah Code § 13-61-201(le.utah.gov).gov
- Vermont Data Privacy and Online Surveillance Act, Act 145 (S.71): 9 V.S.A. chapter 61A, enacted § 2415d consumer rights(legislature.vermont.gov).gov
- Virginia Consumer Data Protection Act: Va. Code § 59.1-577(law.lis.virginia.gov).gov