US State Privacy Laws Comparison Chart & Tracker (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 20, 2026. · 11 primary sources cited on this page. How we verify our legal content
As of August 2026, 24 US states have enacted comprehensive consumer data privacy laws, with California's CCPA/CPRA leading the way. All 24 laws grant residents rights to access, delete, and opt out of data sales, though applicability thresholds, sensitive data rules, and enforcement penalties vary significantly by state. Four of the 24 (Oklahoma, Alabama, Louisiana, and Vermont) were enacted in 2026 and are not yet effective.
The US has no single federal comprehensive data privacy law. Instead, a growing patchwork of state legislation governs how businesses collect, use, and share consumers' personal data. Each state law differs in scope, consumer rights, enforcement mechanisms, and business obligations.
This guide provides a side-by-side comparison of every US state that has enacted a comprehensive consumer data privacy law as of August 2026, covering applicability thresholds, consumer rights, sensitive data rules, enforcement provisions, and key distinguishing features.
Overview of Enacted State Privacy Laws
The following states have enacted comprehensive consumer data privacy statutes (listed in order of enactment/signing):
- California - CCPA (2018) / CPRA (2020, effective 2023)
- Virginia - VCDPA (2021, effective Jan 2023)
- Colorado - CPA (2021, effective Jul 2023)
- Connecticut - CTDPA (2022, effective Jul 2023)
- Utah - UCPA (2022, effective Dec 2023)
- Iowa - ICDPA (2023, effective Jan 2025)
- Indiana - ICDPA (2023, effective Jan 2026)
- Tennessee - TIPA (2023, effective Jul 2025)
- Montana - MCDPA (2023, effective Oct 2024)
- Oregon - OCPA (2023, effective Jul 2024)
- Texas - TDPSA (2023, effective Jul 2024)
- Florida - FDBR (2023, effective Jul 2024)
- Delaware - DPDPA (2023, effective Jan 2025)
- New Hampshire - (2024, effective Jan 2025)
- New Jersey - NJDPA (2024, effective Jan 2025)
- Kentucky - KCDPA (2024, effective Jan 2026)
- Nebraska - NDPA (2024, effective Jan 2025)
- Minnesota - MCDPA (2024, effective Jul 2025)
- Maryland - MODPA (2024, effective Oct 2025)
- Rhode Island - RIDTPPA (2024, effective Jan 2026)
- Oklahoma - OKCDPA (2026, effective Jan 2027)
- Alabama - ALDPA (2026, effective May 2027)
- Louisiana - Act 502 (2026, effective Jan 2027)
- Vermont - Act 145 (2026, effective Jan 2028)
Several additional states have active privacy legislation in progress, and this list may expand through 2026 and 2027 legislative sessions.
Applicability Thresholds
One of the most important practical questions for any business: does this law apply to me? The thresholds vary significantly.
| State | Revenue Threshold | Data Processing Threshold | Additional Conditions |
|---|---|---|---|
| California | $26,625,000 gross revenue (inflation-adjusted from the statutory $25M) | 100,000+ consumers/households OR 50%+ revenue from selling/sharing PI | Any one of the three triggers; the CPPA readjusts the revenue figure each odd-numbered year |
| Virginia | None | 100,000+ consumers OR 25,000+ consumers if deriving revenue from data sales | Calendar year |
| Colorado | None | 100,000+ consumers OR 25,000+ consumers + revenue from data sales | Calendar year |
| Connecticut | None | 35,000+ consumers, OR any sensitive-data processing (any volume), OR any sale of personal data (any volume) | Effective July 1, 2026 (Public Act 25-113); no revenue-percentage trigger; excludes Connecticut government entities |
| Utah | $25M gross revenue | 100,000+ consumers OR 25,000+ consumers + 50%+ revenue from data sales | Both revenue AND data threshold required |
| Iowa | None | 100,000+ consumers OR 25,000+ consumers + 50%+ revenue from data sales | Calendar year |
| Indiana | None | 100,000+ consumers OR 25,000+ consumers + 50%+ revenue from data sales | Calendar year |
| Tennessee | $25M revenue | 175,000+ consumers OR 25,000+ consumers + 50%+ revenue from data sales | Revenue AND data threshold |
| Montana | None | 50,000+ consumers OR 25,000+ consumers + revenue from data sales | Lower consumer threshold |
| Oregon | None | 100,000+ consumers OR 25,000+ consumers + revenue from data sales | Includes nonprofit organizations |
| Texas | None | No data volume threshold | Applies to all entities doing business in Texas that process PI (excluding small businesses per SBA definition) |
| Florida | $1B gross revenue | N/A | Also requires: significant operations in FL, 50%+ revenue from ad sales, or operating a platform with 100M+ monthly active users |
| Delaware | None | 35,000+ consumers OR 10,000+ consumers + revenue from data sales | Lower thresholds; HB 380 (signed Sept. 2, 2026) drops these to 10,000 and 5,000 consumers and adds a trigger for third parties who acquire personal data from a controller, effective Jan. 1, 2027 |
| New Hampshire | None | 35,000+ consumers OR 10,000+ consumers + revenue from data sales | Lower thresholds |
| New Jersey | None | 100,000+ consumers OR 25,000+ consumers + revenue from data sales | Calendar year |
| Kentucky | None | 100,000+ consumers OR 25,000+ consumers + revenue from data sales | Calendar year |
| Nebraska | None | No data volume threshold | Applies to all entities that process PI of Nebraska residents (excluding small businesses) |
| Minnesota | None | 100,000+ consumers OR 25,000+ consumers + revenue from data sales | Calendar year |
| Maryland | None | 35,000+ consumers OR 10,000+ consumers + revenue from data sales | Lower thresholds |
| Rhode Island | None | 35,000+ consumers OR 10,000+ consumers + revenue from data sales | Lower thresholds |
| Oklahoma | None | 100,000+ consumers OR 25,000+ consumers + 50%+ revenue from data sales | Effective Jan. 1, 2027; calendar year |
| Alabama | None | 25,000+ consumers OR 25%+ gross revenue from data sales | Effective May 1, 2027; no consumer minimum on the revenue-based trigger |
| Louisiana | $25M gross revenue | 75,000+ consumers/households/devices OR 50%+ revenue from selling personal data | Effective Jan. 1, 2027; any one of the three triggers, CCPA-style rather than the Virginia-style volume model |
| Vermont | None | 35,000+ consumers OR 3,000+ consumers' sensitive data OR 3,000+ consumers' data sold | Effective Jan. 1, 2028 |
Notable outliers: Florida's $1 billion revenue threshold limits the law to major corporations and large tech platforms. Texas and Nebraska apply broadly to all businesses processing personal data (with small business exemptions). Montana's 50,000-consumer threshold was the lowest among the original 20 states using that model, until Alabama's 2026 law set an even lower 25,000-consumer floor (with no consumer minimum at all under its 25%-of-revenue alternative test). Delaware goes lower still on January 1, 2027, when HB 380 drops its primary threshold to 10,000 consumers. Louisiana breaks from the Virginia-style volume model entirely, adopting California's CCPA approach: a $25 million revenue threshold, a 75,000-consumer/household/device threshold, or a 50%-of-revenue-from-data-sales threshold.
Consumer Rights Comparison
All enacted state privacy laws provide a core set of consumer rights, but the specific rights and their scope vary.
| Right | CA | VA | CO | CT | UT | IA | IN | TN | MT | OR | TX | FL | DE | NH | NJ | KY | NE | MN | MD | RI | OK | AL | LA | VT |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Access | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Delete | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Portability | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Opt out of sale | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Opt out of targeted ads | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Opt out of profiling | Yes | Yes | Yes | Yes | No | No | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Correct | Yes | Yes | Yes | Yes | No | No | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Appeal | No | Yes | Yes | Yes | No | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | Yes | Yes |
California stands alone in providing the right to know what specific pieces of personal information a business has collected (not just categories) and the right to limit the use of sensitive personal information. Oregon is notable for granting consumers the right to obtain a list of specific third parties to whom their data has been disclosed.
Florida adds two rights the Virginia-model states do not: the right to opt out of the collection of sensitive data, including precise geolocation data, or the processing of sensitive data (Fla. Stat. 501.705(2)(f)), and the right to opt out of the collection of personal data through a voice recognition or facial recognition feature (s. 501.705(2)(g)). Section 501.705(3) goes further, barring a controller from using a device's voice, facial, video, audio, thermal, or olfactory collection features for surveillance when the consumer is not actively using them, unless the consumer expressly authorizes it.
Minnesota's law is distinctive in providing consumers the right to question the results of profiling and to be informed about the types of profiling a controller engages in. Maryland's MODPA takes a restrictive approach by requiring businesses to limit data collection to what is reasonably necessary for the purpose disclosed to the consumer, a data minimization standard stronger than most other state laws.
Sensitive Data Treatment
How each state handles sensitive personal data reveals important differences in privacy philosophy.
| State | Sensitive Data Consent Model | Categories of Sensitive Data |
|---|---|---|
| California | Right to limit use (opt-out) | SSN, financial, precise geolocation, race, religion, health, sex life, biometrics, communications content, genetic data |
| Virginia | Opt-in consent required | Race, religion, health, sex life, citizenship/immigration, genetic, biometric, children's data, precise geolocation |
| Colorado | Opt-in consent required | Same as Virginia |
| Connecticut | Opt-in consent required | Same as Virginia |
| Utah | Opt-in consent required | Race, religion, health, sex life, citizenship, biometric, genetic, geolocation, children's data |
| Iowa | Opt-in consent required | Race, religion, health, sex life, citizenship, biometric, genetic, geolocation, children's data |
| Oregon | Opt-in consent required | Broad definition including race, religion, health, sex life, citizenship, biometric, genetic, transgender/nonbinary status, precise geolocation, children's data |
| Texas | Opt-in consent required | Race, religion, health, sex life, citizenship, biometric, genetic, precise geolocation, children's data |
| Montana | Opt-in consent required | Standard categories similar to Virginia |
| Florida | Opt-in consent required, plus a standalone right to opt out of collection or processing | Race/ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship/immigration status, genetic/biometric data (for unique identification), known child's data, precise geolocation |
| Delaware | Opt-in consent required | Standard categories plus immigration status; HB 380 adds national origin, neural data, financial account numbers and log-in credentials, and government-issued ID numbers effective Jan. 1, 2027 |
| Minnesota | Opt-in consent required | Broad definition; includes precise location, children's data, gender identity |
| Maryland | Opt-in consent required; sale/sharing prohibited | Standard categories; prohibits sale of sensitive data entirely |
| Nebraska | Opt-in consent required | Standard categories similar to Virginia |
| Oklahoma | Opt-in consent required | Race/ethnic origin, religious beliefs, mental/physical health diagnosis, sexual orientation, citizenship/immigration status, genetic/biometric data (for unique identification), children's data, precise geolocation |
| Alabama | Opt-in consent required | Race/ethnic origin, religious beliefs, health condition/diagnosis, sex life, sexual orientation, citizenship/immigration status, genetic/biometric data (for unique identification), children's data, precise geolocation |
| Louisiana | Opt-in consent required | Race/ethnic origin, religious beliefs, health diagnosis, sexuality, citizenship/immigration status, genetic/biometric data (for unique identification), children's data, precise geolocation |
| Vermont | Opt-in consent required | Broadest among enacted states: race/ethnicity, religion, sex life, sexual orientation, transgender/nonbinary status, citizenship/immigration status, health condition/diagnosis, consumer health data, genetic/biometric data, children's data, precise geolocation, neural data, financial account credentials, and government-issued ID numbers |
Oregon and Vermont are notable for explicitly including transgender and nonbinary status as sensitive data. Vermont's definition is the broadest among enacted state laws, also treating neural data, financial account login credentials, and government-issued ID numbers as sensitive. Maryland's MODPA goes further than any other state by prohibiting the sale of sensitive personal data entirely, not just requiring opt-in consent. Florida layers a standalone opt-out on top of the opt-in model: s. 501.71(2)(d) already bars processing sensitive data without consent, yet s. 501.705(2)(f) separately lets a consumer opt out of that collection or processing.
Most state laws treat children's data as sensitive personal information. The age threshold is typically 13 (aligning with COPPA), though Connecticut applies heightened protections for data about consumers aged 13-15 in the context of targeted advertising.
Enforcement and Penalties
| State | Enforcement Authority | Maximum Penalty | Private Right of Action | Cure Period |
|---|---|---|---|---|
| California | AG + CPPA | $7,500/intentional violation | Yes (data breaches only) | 30 days (AG only; CPPA: none) |
| Virginia | AG | $7,500/violation | No | 30 days |
| Colorado | AG | $20,000/violation | No | 60 days (sunset Jan 2025) |
| Connecticut | AG | $5,000/violation (CUTPA) | No | 60 days (sunset Dec 2024) |
| Utah | AG | $7,500/violation | No | 30 days |
| Iowa | AG | $7,500/violation | No | 90 days |
| Indiana | AG | $7,500/violation | No | 30 days |
| Tennessee | AG | $7,500/violation | No | 60 days |
| Montana | AG | $7,500/violation | No | 60 days |
| Oregon | AG | $7,500/violation | No | 30 days (sunset Jan 2026) |
| Texas | AG | $7,500/violation | No | 30 days |
| Florida | AG (Dept. of Legal Affairs) | $50,000/violation | No | 45 days |
| Delaware | AG (DOJ) | $10,000/violation | No | 60 days (sunset Dec 2025) |
| New Hampshire | AG | $10,000/violation | No | 60 days |
| New Jersey | AG (DCA) | $10,000/first; $20,000/subsequent | No | 30 days (sunset Jul 2026) |
| Kentucky | AG | $7,500/violation | No | 30 days |
| Nebraska | AG | $7,500/violation | No | 30 days |
| Minnesota | AG | $7,500/violation | No | 30 days |
| Maryland | AG (DCP) | $10,000/violation; $25,000/subsequent | No | 60 days (sunset Apr 2027) |
| Rhode Island | AG | $10,000/violation | No | 30 days |
| Oklahoma | AG | $7,500/violation | No | 30 days |
| Alabama | AG | $15,000/violation | No | 45 days |
| Louisiana | AG | Enforced under the Louisiana Unfair Trade Practices Law; Act 502 sets no separate per-violation dollar cap of its own | No | 30 days (available only Jan. 1-Jul. 31, 2027) |
| Vermont | AG | Enforced under the Vermont Consumer Protection Act, 9 V.S.A. ch. 63; Act 145 sets no separate per-violation dollar cap of its own | No | 60 days (temporary, Jan. 1, 2028-Jun. 30, 2029 only) |
California remains the only state with a private right of action (limited to data breaches involving unencrypted personal information), with statutory damages of $100-$750 per consumer per incident. No other state comprehensive privacy law currently includes a private right of action.
Florida's $50,000 per-violation maximum is the highest among state privacy laws, though the law's narrow applicability (limited to businesses with over $1 billion in revenue) means it affects relatively few companies.
The trend toward eliminating or sunsetting cure periods reflects a maturation of the enforcement landscape. Early laws like Virginia and Utah have permanent cure periods, while newer laws like Colorado, Connecticut, Oregon, and Delaware included cure periods that expire, shifting from a collaborative to a punitive enforcement model over time.
Effective Dates Timeline
| Year | State Laws Taking Effect |
|---|---|
| 2020 | California CCPA |
| 2023 | California CPRA amendments, Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA |
| 2024 | Montana MCDPA, Oregon OCPA, Texas TDPSA, Florida FDBR |
| 2025 | Iowa ICDPA, Delaware DPDPA, New Hampshire, New Jersey NJDPA, Nebraska NDPA, Tennessee TIPA, Minnesota MCDPA, Maryland MODPA |
| 2026 | Indiana ICDPA, Kentucky KCDPA, Rhode Island RIDTPPA |
| 2027 | Oklahoma OKCDPA (Jan. 1), Louisiana Act 502 (Jan. 1), Delaware DPDPA amendments under HB 380 (Jan. 1), Alabama ALDPA (May 1) |
| 2028 | Vermont Act 145 (Jan. 1) |
Amendments taking effect next: Connecticut's Public Act 26-64 (SB 4, signed May 2026) amends the CTDPA with a data broker registration regime, an accessible deletion mechanism, and a prohibition on selling precise geolocation data, with core provisions effective October 1, 2026. Delaware's House Bill 380 (signed September 2, 2026, 85 Del. Laws ch. 463) amends the DPDPA effective January 1, 2027, lowering the applicability thresholds to 10,000 consumers and to 5,000 consumers under the data-sales revenue prong, extending the law to third parties who acquire personal data from a controller, and expanding the sensitive data definition.
Watching (verified August 20, 2026): Massachusetts's Consumer Data Privacy Act passed the House 146-0 on June 4, 2026 but remains in conference committee. It is not yet law, and no other state has enacted a comprehensive privacy law since Vermont in June 2026.
Key Distinctions by State
Several states have provisions that set them apart from the majority model:
California (CCPA/CPRA): Only state with a dedicated privacy enforcement agency (CPPA). Only state with a private right of action. Only state whose revenue threshold is indexed to inflation ($26,625,000 since January 1, 2025, up from the statutory $25M). Broadest definition of "sale" (any exchange for valuable consideration). Right to limit use of sensitive personal information rather than opt-in consent model.
Oregon (OCPA): Only state that applies to nonprofit organizations. Includes transgender/nonbinary status as sensitive data. Grants consumers the right to obtain a list of specific third parties receiving their data.
Texas (TDPSA): No data-processing volume threshold, applying to all businesses processing personal data (excluding SBA-defined small businesses). Combined with no revenue threshold, this gives Texas one of the broadest applicability scopes.
Maryland (MODPA): Prohibits the sale of sensitive personal data entirely. Imposes a data minimization standard requiring collection to be "reasonably necessary" for the disclosed purpose. Among the most protective state privacy laws enacted.
Minnesota (MCDPA): Grants profiling-related rights including the right to question profiling results. Requires privacy impact assessments. Includes a data minimization requirement.
Florida (FDBR): Narrowest applicability ($1B revenue threshold). Targets large technology companies and digital platforms. Includes specific provisions for children's online protections.
Montana (MCDPA): A 50,000-consumer threshold, among the lowest in the volume-based model and reflecting Montana's smaller population, though Alabama's 2026 law sets a lower 25,000-consumer trigger once it takes effect in 2027.
How These Laws Interact with Federal Law
No comprehensive federal privacy law exists as of August 2026, though the American Data Privacy and Protection Act (ADPPA) has been introduced in multiple Congressional sessions. The relationship between state and federal privacy law involves several layers:
- HIPAA preempts state laws for covered health data but only applies to healthcare providers, insurers, and their business associates. State privacy laws cover health data held by other businesses (health apps, fitness trackers, etc.).
- GLBA preempts state laws for financial institutions regarding customer financial information, though state laws may impose additional requirements.
- COPPA provides a federal floor for children's data (under 13), but state laws can provide additional protections.
- FCRA governs consumer reporting agencies and is not preempted by state privacy laws.
Most state privacy laws explicitly exclude data that is already regulated by these federal frameworks, avoiding direct conflict.
For detailed analysis of individual state laws, see our state-by-state guides:
- California (CCPA/CPRA)
- Virginia (VCDPA)
- Colorado (CPA)
- Connecticut (CTDPA)
- Texas (TDPSA)
- Oregon (OCPA)
- Maryland (MODPA)
- Minnesota
For a comparison of these laws against international frameworks, see our GDPR vs CCPA analysis.
This information reflects the law as of August 2026, last reviewed September 5, 2026 to add Delaware's enacted HB 380 amendments. State privacy legislation is an active area, with new bills introduced in multiple states each legislative session. Consult an attorney for advice specific to your situation.
Frequently Asked Questions
How many US states have comprehensive data privacy laws?
As of August 2026, 24 states have enacted comprehensive consumer data privacy laws: California, Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Tennessee, Montana, Oregon, Texas, Florida, Delaware, New Hampshire, New Jersey, Kentucky, Nebraska, Minnesota, Maryland, Rhode Island, Oklahoma (effective Jan. 1, 2027), Alabama (effective May 1, 2027), Louisiana (effective Jan. 1, 2027), and Vermont (effective Jan. 1, 2028). Additional states have active legislation in progress.
Which state has the strictest data privacy law?
California's CCPA/CPRA is generally considered the most protective overall, with a dedicated enforcement agency, an inflation-adjusted revenue threshold of $26,625,000 (raised from the statutory $25 million on January 1, 2025), and the only private right of action among state privacy laws. However, Maryland's MODPA is stricter in certain respects, prohibiting the sale of sensitive data entirely and imposing data minimization requirements that go beyond California's approach.
Do businesses need to comply with every state privacy law separately?
Businesses that process personal data of residents in multiple states must comply with each applicable state law. In practice, many businesses adopt a baseline privacy program that meets the requirements of the strictest applicable laws (typically California) and then add state-specific provisions where laws diverge, such as Oregon's nonprofit coverage or Maryland's data minimization requirement.
Can consumers sue businesses under state privacy laws?
Only California provides a private right of action, and it is limited to data breaches involving certain categories of unencrypted personal information. Under all other state privacy laws, enforcement is handled exclusively by the state Attorney General (or designated agency). Consumers in those states cannot file individual lawsuits for privacy violations under the comprehensive privacy statute.
Will a federal privacy law replace state privacy laws?
As of August 2026, there is no comprehensive federal data privacy law, though bills like the American Data Privacy and Protection Act have been introduced. Whether a federal law would preempt state laws depends on its specific preemption provisions. California and other states with strong privacy protections have historically opposed preemption, making this a significant political obstacle to federal legislation.
Updates
Corrected the consumer rights table to show that Florida, Indiana, Kentucky and Tennessee all grant consumers the right to correct inaccurate personal data, updated California's applicability threshold to the inflation-adjusted $26,625,000 in effect since January 1, 2025, and added Florida to the sensitive data comparison.
Governing law re-checked for recent changes
Updated the enacted-state count from 20 to 24 to include Oklahoma, Alabama, Louisiana, and Vermont (each noted as enacted-but-not-yet-effective with its effective date), corrected Connecticut's applicability threshold to the current 35,000-consumer/any-sensitive-data/any-sale test, replaced a dead Minnesota bill-text citation, and added Oklahoma, Alabama, Louisiana, and Vermont rows to all four detailed comparison tables (applicability thresholds, consumer rights, sensitive data rules, enforcement and penalties) and the effective-dates timeline, which had been left showing only the original 20 states despite the page's own '24 states' framing. Also refreshed three remaining 'as of March 2026' references to August 2026.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
Sources and References
- California Consumer Privacy Act (CCPA)(leginfo.legislature.ca.gov).gov
- Virginia Consumer Data Protection Act (VCDPA)(law.lis.virginia.gov).gov
- Colorado Privacy Act (CPA)(leg.colorado.gov).gov
- Texas Data Privacy and Security Act (TDPSA)(capitol.texas.gov).gov
- Oregon Consumer Privacy Act (OCPA)(olis.oregonlegislature.gov).gov
- Maryland Online Data Privacy Act (MODPA)(mgaleg.maryland.gov).gov
- California Privacy Protection Agency (CPPA)(cppa.ca.gov).gov
- Connecticut Data Privacy Act (CTDPA)(cga.ct.gov).gov
- Minnesota Consumer Data Privacy Act(revisor.mn.gov).gov
- Connecticut Public Act 26-64 (SB 4)(cga.ct.gov).gov
- Fla. Stat. 501.705 - Florida Digital Bill of Rights, consumer rights(leg.state.fl.us)
- Fla. Stat. 501.702 - Florida Digital Bill of Rights, definitions including sensitive data(leg.state.fl.us)
- Fla. Stat. 501.71 - Florida Digital Bill of Rights, controller duties and sensitive data consent(leg.state.fl.us)
- Tennessee Public Chapter 408 (2023) - Tennessee Information Protection Act, as enacted(publications.tnsosfiles.com)
- California Privacy Protection Agency - 2025 inflation-adjusted CCPA monetary thresholds(cppa.ca.gov)
- Cal. Civ. Code 1798.140(d)(1)(A) - CCPA definition of business and revenue threshold(leginfo.legislature.ca.gov)
- Ind. Code 24-15-3-1 - Indiana Consumer Data Protection Act, consumer rights(iga.in.gov)
- KRS 367.3615 - Kentucky Consumer Data Protection Act, consumer rights request(apps.legislature.ky.gov)
- Delaware General Assembly, House Bill 380 (153rd General Assembly), signed September 2, 2026, chaptered as 85 Del. Laws ch. 463, effective January 1, 2027(legis.delaware.gov).gov