EnglishEspañol

US State Privacy Laws Comparison Chart & Tracker (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 20, 2026. · 11 primary sources cited on this page. How we verify our legal content

US State Privacy Laws Comparison Chart & Tracker (2026)

Frequently Asked Questions

How many US states have comprehensive data privacy laws?

As of August 2026, 24 states have enacted comprehensive consumer data privacy laws: California, Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Tennessee, Montana, Oregon, Texas, Florida, Delaware, New Hampshire, New Jersey, Kentucky, Nebraska, Minnesota, Maryland, Rhode Island, Oklahoma (effective Jan. 1, 2027), Alabama (effective May 1, 2027), Louisiana (effective Jan. 1, 2027), and Vermont (effective Jan. 1, 2028). Additional states have active legislation in progress.

Which state has the strictest data privacy law?

California's CCPA/CPRA is generally considered the most protective overall, with a dedicated enforcement agency, an inflation-adjusted revenue threshold of $26,625,000 (raised from the statutory $25 million on January 1, 2025), and the only private right of action among state privacy laws. However, Maryland's MODPA is stricter in certain respects, prohibiting the sale of sensitive data entirely and imposing data minimization requirements that go beyond California's approach.

Do businesses need to comply with every state privacy law separately?

Businesses that process personal data of residents in multiple states must comply with each applicable state law. In practice, many businesses adopt a baseline privacy program that meets the requirements of the strictest applicable laws (typically California) and then add state-specific provisions where laws diverge, such as Oregon's nonprofit coverage or Maryland's data minimization requirement.

Can consumers sue businesses under state privacy laws?

Only California provides a private right of action, and it is limited to data breaches involving certain categories of unencrypted personal information. Under all other state privacy laws, enforcement is handled exclusively by the state Attorney General (or designated agency). Consumers in those states cannot file individual lawsuits for privacy violations under the comprehensive privacy statute.

Will a federal privacy law replace state privacy laws?

As of August 2026, there is no comprehensive federal data privacy law, though bills like the American Data Privacy and Protection Act have been introduced. Whether a federal law would preempt state laws depends on its specific preemption provisions. California and other states with strong privacy protections have historically opposed preemption, making this a significant political obstacle to federal legislation.

Updates

Corrected the consumer rights table to show that Florida, Indiana, Kentucky and Tennessee all grant consumers the right to correct inaccurate personal data, updated California's applicability threshold to the inflation-adjusted $26,625,000 in effect since January 1, 2025, and added Florida to the sensitive data comparison.

Governing law re-checked for recent changes

Updated the enacted-state count from 20 to 24 to include Oklahoma, Alabama, Louisiana, and Vermont (each noted as enacted-but-not-yet-effective with its effective date), corrected Connecticut's applicability threshold to the current 35,000-consumer/any-sensitive-data/any-sale test, replaced a dead Minnesota bill-text citation, and added Oklahoma, Alabama, Louisiana, and Vermont rows to all four detailed comparison tables (applicability thresholds, consumer rights, sensitive data rules, enforcement and penalties) and the effective-dates timeline, which had been left showing only the original 20 states despite the page's own '24 states' framing. Also refreshed three remaining 'as of March 2026' references to August 2026.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. California Consumer Privacy Act (CCPA)(leginfo.legislature.ca.gov).gov
  2. Virginia Consumer Data Protection Act (VCDPA)(law.lis.virginia.gov).gov
  3. Colorado Privacy Act (CPA)(leg.colorado.gov).gov
  4. Texas Data Privacy and Security Act (TDPSA)(capitol.texas.gov).gov
  5. Oregon Consumer Privacy Act (OCPA)(olis.oregonlegislature.gov).gov
  6. Maryland Online Data Privacy Act (MODPA)(mgaleg.maryland.gov).gov
  7. California Privacy Protection Agency (CPPA)(cppa.ca.gov).gov
  8. Connecticut Data Privacy Act (CTDPA)(cga.ct.gov).gov
  9. Minnesota Consumer Data Privacy Act(revisor.mn.gov).gov
  10. Connecticut Public Act 26-64 (SB 4)(cga.ct.gov).gov
  11. Fla. Stat. 501.705 - Florida Digital Bill of Rights, consumer rights(leg.state.fl.us)
  12. Fla. Stat. 501.702 - Florida Digital Bill of Rights, definitions including sensitive data(leg.state.fl.us)
  13. Fla. Stat. 501.71 - Florida Digital Bill of Rights, controller duties and sensitive data consent(leg.state.fl.us)
  14. Tennessee Public Chapter 408 (2023) - Tennessee Information Protection Act, as enacted(publications.tnsosfiles.com)
  15. California Privacy Protection Agency - 2025 inflation-adjusted CCPA monetary thresholds(cppa.ca.gov)
  16. Cal. Civ. Code 1798.140(d)(1)(A) - CCPA definition of business and revenue threshold(leginfo.legislature.ca.gov)
  17. Ind. Code 24-15-3-1 - Indiana Consumer Data Protection Act, consumer rights(iga.in.gov)
  18. KRS 367.3615 - Kentucky Consumer Data Protection Act, consumer rights request(apps.legislature.ky.gov)
  19. Delaware General Assembly, House Bill 380 (153rd General Assembly), signed September 2, 2026, chaptered as 85 Del. Laws ch. 463, effective January 1, 2027(legis.delaware.gov).gov
Share: