US State Privacy Laws Tracker (2026): Every Law, Deadline, and Amendment
In short
As of 1 October 2026, 24 US states have enacted comprehensive consumer privacy laws if you count Florida's narrower law, and 23 if you follow IAPP and FPF and exclude it; 20 laws are in effect (19 without Florida). Oklahoma and Louisiana take effect on 1 January 2027, Alabama on 1 May 2027 and Vermont on 1 January 2028, and FPF counts more than half of the 23 states with laws as having already amended them.
As of 1 October 2026, 24 US states have enacted comprehensive consumer privacy laws, and 20 of them are in effect. Both figures shrink by one if you exclude Florida, which is how IAPP and the Future of Privacy Forum (FPF) count: 23 enacted, 19 in effect. Four laws are signed but not yet operative: Oklahoma's and Louisiana's take effect on 1 January 2027, Alabama's on 1 May 2027 and Vermont's on 1 January 2028. If those numbers disagree with the last tracker you read, check its date. In 2026 alone, Oklahoma (signed 20 March), Alabama (17 April), Louisiana (29 May) and Vermont (16 June) all became law within 88 days, so a chart saved before 20 March is four states short.
Law firms are careful, but they count differently and rarely say how. DLA Piper and Hunton both called Alabama the 21st state, which is a Florida-excluded count. Under the rule this tracker uses, Alabama is the 22nd. This tracker states its counting rule up front, then merges four layers that usually get tracked separately (statutes, amendments that changed them, deadlines that regulators created through rulemaking, and the cure-period sunsets that decide when enforcement bites) into two comparison tables and one dated calendar, with a visible changelog at the bottom. We wrote it for the counsel who maintains this exact table by hand today; it is one of the living trackers in our trackers and templates hub.
The counting rule this tracker uses. "Comprehensive" means a generally applicable consumer privacy statute that grants individual rights and puts obligations on controllers and processors. Enacted: 24. In effect: 20. That counts Florida's Digital Bill of Rights, which qualifies structurally but applies to sensitive-data sales by any for-profit business and to its other duties only above $1 billion in global revenue plus specific business models, which is why IAPP and FPF exclude it and land on 23 and 19. Sectoral laws, data-broker laws and children's codes never enter the headline count, though some appear in the calendar. On the Florida-excluded basis the 2026 signings were Oklahoma (20th), Alabama (21st), Louisiana (22nd) and Vermont (23rd). Never trust an ordinal ("the Nth state") from a source that does not state its rule.
The comparison tables cover every enacted state privacy law as of 1 October 2026
One row per enacted law, ordered by effective date. The "Amended since passage" column is where the compliance risk lives in 2025 and 2026. A dagger (†) marks a cell that rests on secondary summaries (FPF, IAPP, law-firm posts) because the state's own legislature or attorney general site blocked our fetchers or returned no text. The Indiana, Kentucky, New Hampshire, New Jersey and Rhode Island rows are wholly in that category, and several Utah cells are too. Confirm daggered cells against the statute before you rely on them.
In effect: 20 laws
| State and law | In effect since | Amended since passage | Applicability threshold | Cure period | Universal opt-out | Sensitive data and assessments | Enforcement (latest dated public actions we verified) |
|---|---|---|---|---|---|---|---|
| California: CCPA/CPRA (AB 375, 2018; Prop 24, 2020) | 1 Jan 2020 (CPRA amendments operative 1 Jan 2023) | CPPA regulations on audits, risk assessments and ADMT (effective 1 Jan 2026); Delete Act broker deletions from 1 Aug 2026; SB 923 (signed 27 Sep 2026, effective 1 Jan 2027); AB 566 browser signals (Jan 2027) | Revenue over $26,625,000 (CPI-adjusted from $25M on 1 Jan 2025), or 100,000 consumers or households, or 50% of revenue from selling or sharing | None required for the AG since 1 Jan 2023 | Yes (GPC) | Right to limit use (opt-out model); risk assessments under the CPPA regulations | AG: GM $12.75M, 8 May 2026; Disney $2.75M, 11 Feb 2026. CPPA: Tractor Supply $1.35M, 30 Sep 2025; PlayOn Sports $1.10M and Ford $375,703 (March 2026); LocateSmarter $116,490, 11 Aug 2026, the first action under both the CCPA and the Delete Act |
| Virginia: VCDPA (SB 1392 and HB 2307, 2021) | 1 Jan 2023 | HB 707 (2024): known-child data. SB 854 (2025): under-16 social media limit, preliminarily enjoined for NetChoice members since 27 Feb 2026. SB 338 (approved 13 Apr 2026): no sale of precise geolocation data from 1 Jul 2026 | 100,000 consumers, or 25,000 plus over 50% of revenue from sale | 30 days, permanent | No | Opt-in consent; assessments required | AG, up to $7,500 per violation; no public VCDPA action found |
| Colorado: CPA (SB 21-190) | 1 Jul 2023 | HB 24-1058 (neural data, Aug 2024); HB 24-1130 (biometrics, 1 Jul 2025); SB 24-041 (minors, 1 Oct 2025); SB 25-276 (sale of sensitive data needs consent, May 2025). Separate ADMT law SB 26-189, signed 14 May 2026, repeals and re-enacts the 2024 AI Act | 100,000 consumers, or 25,000 plus any revenue or discount from sale | 60 days, sunset 1 Jan 2025 | Yes, since 1 Jul 2024 (GPC) | Opt-in consent; assessments required; AG rulemaking (amendments proposed 29 Jul 2025, adoption not verified) | AG and district attorneys; no public CPA settlement found |
| Connecticut: CTDPA (SB 6, 2022) | 1 Jul 2023 | PA 25-113 (SB 1295, effective 1 Jul 2026): threshold cut, minimization, minors 13 to 17. PA 26-64 (SB 4, signed 27 May 2026, effective 1 Oct 2026): no sale of precise geolocation, narrower "publicly available information", data broker registry | From 1 Jul 2026: 35,000 consumers, or any volume if processing sensitive data or offering personal data for sale | 60 days through 31 Dec 2024; discretionary since | Yes, since 1 Jan 2025 | Opt-in consent; assessments required, including profiling assessments for activities created on or after 1 Aug 2026 | AG, up to $5,000 per violation: TicketNetwork $85,000, 8 Jul 2025 |
| Utah: UCPA (SB 227, 2022) | 31 Dec 2023 | HB 418 (2025): right to correct from 1 Jul 2026 plus the Digital Choice Act (social media data portability). HB 357 (2026): motor-vehicle manufacturers covered from 1 Jan 2027 | Revenue of $25M or more AND (100,000 consumers, or 25,000 plus over 50% of revenue from sale) | 30 days† | No† | Notice and opt-out†; no assessments† | Attorney general and Division of Consumer Protection†; no action found |
| Florida: FDBR (SB 262, ch. 2023-201) | 1 Jul 2024 | None found | Over $1B global revenue AND (50% or more of revenue from online ads, or the smart-speaker or app-store criteria). Consent to sell sensitive data applies to any for-profit business | 45 days, discretionary | No | Opt-in consent; assessments†; rules mandated by statute (adoption not verified) | Department of Legal Affairs, up to $50,000 per violation: Roku sued 14 Oct 2025 and resolved 26 Jun 2026 with no fine; Netflix sued 9 Sep 2026 |
| Oregon: OCPA (SB 619) | 1 Jul 2024 (nonprofits 1 Jul 2025) | HB 2008 (operative 1 Jan 2026): no sale of precise geolocation or of data of consumers under 16; no targeted ads or profiling for under 16. Separately, motor-vehicle manufacturers covered regardless of thresholds since September 2025 | 100,000 consumers, or 25,000 plus 25% or more of revenue from sale | 30 days, sunset 1 Jan 2026 (ended) | Yes, since 1 Jan 2026 | Opt-in consent; assessments required | AG, up to $7,500 per violation; no public lawsuit or settlement found |
| Texas: TDPSA (HB 4) | 1 Jul 2024 | HB 149 (1 Jan 2026): minor processor-duty change | No numeric floor: applies unless an SBA-defined small business, which still needs consent to sell sensitive data | 30 days, permanent | Yes, since 1 Jan 2025 | Opt-in consent; assessments required | AG, up to $7,500 per violation: Allstate and Arity suit, 13 Jan 2025, the first TDPSA lawsuit |
| Montana: MCDPA (SB 384, 2023) | 1 Oct 2024 | SB 297 (signed 8 May 2025, effective 1 Oct 2025): thresholds cut, cure eliminated, minors' duty of care | 25,000 consumers, or 15,000 plus over 25% of revenue from sale; minors' provisions have no consumer-count threshold | Eliminated 1 Oct 2025 | Yes, since 1 Jan 2025 | Opt-in consent; assessments required | AG, up to $7,500 per violation; no public action found (AG site not retrievable) |
| Iowa: ICDPA (SF 262, 2023) | 1 Jan 2025 | None found in the Code as of Dec 2025; outcome of 2026 bills not verified | 100,000 consumers, or 25,000 plus over 50% of revenue from sale | 90 days, permanent | No | Notice and opt-out; no assessments | AG, up to $7,500 per violation; none found |
| Delaware: DPDPA (HB 154, 2023) | 1 Jan 2025 | HB 380 (signed 2 Sep 2026, effective 1 Jan 2027): thresholds lowered, third parties covered, sensitive data expanded, minimization tightened | 35,000 consumers, or 10,000 plus over 20% of revenue from sale; from 1 Jan 2027, 10,000 or 5,000 plus over 20% | 60 days through 31 Dec 2025; discretionary since | Yes, since 1 Jan 2026 | Opt-in consent; assessments required | Department of Justice; no public action found |
| Nebraska: NDPA (LB 1074, 2024) | 1 Jan 2025 | None found (statute captured to Mar 2025; 2026 not checked). Age-Appropriate Design Code (LB 504) reported effective 1 Jan 2026† | No numeric floor: applies unless an SBA-defined small business, which still needs consent to sell sensitive data | 30 days, permanent | Yes, since 1 Jan 2025 (authorized-agent technology clause) | Opt-in consent; assessments required | AG, up to $7,500 per violation; none found |
| New Hampshire: NHDPA (SB 255, 2024) † | 1 Jan 2025† | 2024 amendment (HB 1220) noted by FPF, text not reviewed†. HB 1460 (signed 19 Jun 2026, effective 1 Jan 2027): no sale of a child's personal data, with or without consent | 35,000 consumers, or 10,000 plus over 25% of revenue from sale† | 60 days, expiration reported as 31 Dec 2025† | Yes, since 1 Jan 2025† | Opt-in consent; assessments; two narrow secretary-of-state rulemaking provisions† | AG; none found |
| New Jersey: NJDPA (S332, 2024) † | 15 Jan 2025† | Data broker law (signed and effective 30 Jun 2026): no sale of sensitive data by any controller, regardless of volume; data broker and "data collector" registration | 100,000 consumers, or 25,000 plus revenue from sale† | 30 days for 18 months after the effective date, ending about 15 Jul 2026† | Yes, required from mid-2025† | Opt-in consent; assessments; rules proposed 2 Jun 2025, final status not verified† | Attorney general (Division of Consumer Affairs); none found |
| Tennessee: TIPA (HB 1181 and SB 73, PC 408, 2023) | 1 Jul 2025 | None found for 2025; 2026 not checked | Revenue over $25M AND (175,000 consumers, or 25,000 plus over 50% of revenue from sale) | 60 days, permanent; NIST privacy framework affirmative defense | No | Opt-in consent; assessments required | AG, up to $7,500 per violation, trebled if willful; none found |
| Minnesota: MNCDPA (HF 4757, Minn. Stat. 325M.10 to 325M.21) | 31 Jul 2025 (postsecondary institutions 31 Jul 2029) | None to the MNCDPA | 100,000 consumers, or 25,000 plus over 25% of revenue from sale | 30 days, sunset 31 Jan 2026 (ended) | Yes, since 31 Jul 2025 | Opt-in consent; assessments required; right to question profiling results | AG, up to $7,500 per violation; none found |
| Maryland: MODPA (SB 541, Ch. 455, 2024) | 1 Oct 2025; the exceptions section does not reach processing before 1 Apr 2026 | None found (FPF lists none for 2025; 2026 not checked) | 35,000 consumers, or 10,000 plus over 20% of revenue from sale | Discretionary for violations on or before 1 Apr 2027, at least 60 days when granted | Signal recognition is one of two permitted opt-out methods, by 1 Oct 2025 | Sensitive data only where strictly necessary and never sold, with no consent route; assessments required | AG; none found |
| Indiana: INCDPA (SB 5, 2023) † | 1 Jan 2026† | None found | 100,000 consumers, or 25,000 plus a share of revenue from sale (share not verified)† | Mandatory, no sunset (days not verified)† | No† | Opt-in consent; assessments† | AG; none found |
| Kentucky: KCDPA (HB 15, 2024) † | 1 Jan 2026† | HB 473 (signed 15 Mar 2025): exempts HIPAA-covered providers' data and limited data sets; MultiState reports it also clarified when profiling assessments apply†. HB 692 (signed 13 Apr 2026, effective 1 Jul 2027): certain smart TV data becomes sensitive data | 100,000 consumers, or 25,000 plus a share of revenue from sale (share not verified)† | Mandatory, no sunset† | No† | Opt-in consent; assessments† | AG; none found |
| Rhode Island: RIDTPPA (H 7787 and S 2500, 2024) † | 1 Jan 2026; became law without the governor's signature in June 2024† | None found | 35,000 consumers, or 10,000 plus 20% or more of revenue from sale† | None† | No† | Opt-in consent; assessments†; the privacy-notice duty reaches only commercial websites and internet service providers† | AG; none found |
Signed, not yet in effect: 4 laws
| State and law | Signed and effective | Applicability threshold | Cure period | Universal opt-out | Sensitive data and assessments | Enforcement |
|---|---|---|---|---|---|---|
| Oklahoma: OKCDPA (SB 546) | Signed 20 Mar 2026; effective 1 Jan 2027 (the House moved it from 1 Jul 2026 before passage) | 100,000 consumers, or 25,000 plus over 50% of revenue from sale | 30 days, no sunset found | No | Opt-in consent; assessments required | AG exclusive, up to $7,500 per violation |
| Louisiana: LDPA (SB 386, Act 502) | Signed 29 May 2026; effective 1 Jan 2027 | Any one of: revenue over $25M; 75,000 or more consumers, households or devices; 50% or more of revenue from selling personal information | Mandatory 30 days from 1 Jan to 31 Jul 2027, then none required | No (authorized-agent technology only, per FPF) | Consent for sensitive data and assessments, per FPF | AG exclusive |
| Alabama: APDPA (HB 351, Act 2026-552) | Signed 17 Apr 2026; effective 1 May 2027 | More than 25,000 consumers, or more than 25% of revenue from sale regardless of consumer count | 45 days, no sunset | No (requirement removed before passage) | Opt-in consent; no assessments | AG (no express exclusivity clause); up to $15,000 per violation after a failure to cure |
| Vermont: VDPOSA (S.71, Act 145) | Signed 16 Jun 2026; effective 1 Jan 2028 | 35,000 consumers, or sensitive data of 3,000 consumers, or personal data of 3,000 consumers offered for sale | 60 days where the AG finds a cure possible, 1 Jan 2028 to 30 Jun 2029 | Yes, opt-out preference signal duty from 1 Jan 2028 | Assessments and rights to contest certain profiling decisions, per FPF | AG only |
Reading notes. Thresholds are annual figures unless marked. "None found" in an enforcement cell means no public dated action turned up, which is not the same as no risk: several attorneys general run cure-notice sweeps that never become press releases, and Connecticut's had issued over two dozen cure notices across four sweeps by July 2025. The rows show what the statutes say; confirm your own applicability with counsel.
Amendments are now the main event: more than half of the states with laws have already changed them
FPF wrote on 3 September 2026: "More than half of the 23 states with comprehensive privacy laws have now amended their laws." If your tracker only logs enactments, it is already wrong many times over.
Delaware is the newest and the largest. Governor Meyer signed HB 380 on 2 September 2026, effective 1 January 2027. It cuts the applicability thresholds from 35,000 consumers (or 10,000 with over 20% of revenue from sales) to 10,000 (or 5,000 with over 20%), adds "third parties who acquire personal data from a controller" as covered persons, expands sensitive data, tightens minimization to "reasonably necessary and proportional" and adds assessments for profiling. A Delaware applicability call made in August is out of date on 1 January (FPF summary).
Connecticut has now amended its law twice in two years. Public Act 25-113 (SB 1295), signed 24 June 2025 and effective 1 July 2026, dropped the threshold from 100,000 to 35,000 consumers and removed it entirely for anyone processing sensitive data or offering personal data for sale, which, given how broadly "sale" reads, put most ad-supported businesses that touch Connecticut residents back into scope. It also imposed "reasonably necessary and proportionate" minimization and banned targeted advertising to, and the sale of the data of, consumers aged 13 to 17, with no consent exception. Public Act 26-64 (SB 4), signed 27 May 2026 and effective 1 October 2026, adds a ban on selling precise geolocation data, narrows "publicly available information" and creates a data broker registry with a 1 January 2027 registration date, per the Attorney General's advisory.
Montana went the same direction earlier. SB 297, signed 8 May 2025 and effective 1 October 2025, cut the thresholds to 25,000 consumers (15,000 with over 25% of revenue from sales), extended the minors' provisions to businesses with no consumer-count threshold, and eliminated a cure period that had been scheduled to end on 1 April 2026. A Montana assessment dated mid-2025 is now wrong.
Virginia added a known-child data rule (HB 707, effective 1 January 2025), an under-16 social media time limit (SB 854, effective 1 January 2026 and enjoined for NetChoice members since 27 February 2026) and a ban on selling precise geolocation data (SB 338, approved 13 April 2026 and effective 1 July 2026). Colorado added neural data, biometrics, minors' protections and a consent rule for the sale of sensitive data across four bills in two sessions. Kentucky amended its law in March 2025 (HB 473), nine months before it took effect, exempting data collected by HIPAA-covered providers, so a program scoped from the 2024 enrolled bill was stale on day one.
Three more 2026 amendments belong in any register. New Jersey's data broker law, which took effect when it was signed on 30 June 2026, bans the sale of sensitive data by any controller, whatever its volume. New Hampshire's HB 1460 bans the sale of a child's personal data, with or without consent, from 1 January 2027. And Kentucky's HB 692 adds certain smart TV data to the definition of sensitive data from 1 July 2027.
In my view, for a company that mapped the first fifteen states in 2023 and 2024, amendment-watching is now higher value than new-state-watching. A new state gives you runway: the four 2026 laws gave about seven months (Louisiana) to eighteen (Vermont) between signature and effective date. The amendments above gave anywhere from no runway at all (New Jersey's took effect the day it was signed) to almost fifteen months (Kentucky's HB 692), and they change obligations you have already operationalized, which is what static charts miss.
California's regulators keep creating deadlines that never passed through a statehouse
Static trackers also drop a second layer, the deadlines set by rulemaking. The California Privacy Protection Agency (CPPA, which now uses the name CalPrivacy) announced on 23 September 2025 that the Office of Administrative Law had approved its regulations on cybersecurity audits, risk assessments and automated decisionmaking technology (ADMT), effective 1 January 2026. "Effective" and "enforceable now" differ, and compressing them is the most common error in coverage of these rules. The phasing in the regulation text: ADMT compliance for significant decisions by 1 January 2027; risk assessments conducted in 2026 and 2027 submitted to the CPPA, as an attestation plus a summary, by 1 April 2028; and cybersecurity audit certifications due on 1 April 2028 for businesses over $100 million in revenue, 1 April 2029 for $50 to $100 million and 1 April 2030 below that.
The Delete Act (SB 362) runs on its own clock. Data brokers had to register with the CPPA between 1 and 31 January 2026 (a $6,000 annual fee plus a processing fee). From 1 August 2026 every registered broker must access the DROP deletion platform at least every 45 days and process the requests waiting in it, and the penalty is a daily meter: $200 for each day a broker fails to register and $200 for each deletion request for each day it fails to delete. Unlike a one-time fine, that penalty compounds while nobody is watching. Two more California changes arrive in January 2027. SB 923, signed 27 September 2026, extends the right to delete to information a business obtained from third parties, allows suppression lists and requires online-only businesses to offer a webform. And AB 566, the Opt Me Out Act signed 8 October 2025, requires browsers to offer opt-out preference signals. The CCPA's revenue threshold, $26,625,000 since 1 January 2025, is due for another CPI adjustment in 2027, because the CPPA adjusts its monetary thresholds every odd-numbered year.
Enforcement actions are no longer hypothetical, and California has two enforcers; conflating them is a recurring error. The Attorney General announced the $2.75 million Disney settlement on 11 February 2026, then, with four county district attorneys, a $12.75 million General Motors settlement on 8 May 2026, the largest CCPA penalty to date and the Attorney General's first data-minimization case, over sales of driving data. The CPPA's Board has issued its own fines, including Tractor Supply ($1.35 million, 30 September 2025, the largest in the agency's history at that time), PlayOn Sports ($1.10 million, March 2026, the first case involving students and schools) and Ford ($375,703, March 2026, for unnecessary friction in the opt-out process), alongside a run of Delete Act actions against data brokers. The Disney theory should worry every multi-service consumer business: the AG said Disney failed to carry opt-out requests across all devices and streaming services tied to an account, and that for consumers who opted out through Global Privacy Control it limited the request to the specific device in use, even when they were logged in.
Cure periods are disappearing, and they never guaranteed safety anyway
When enforcement actually bites is governed by two mechanisms that comparison charts under-specify: cure-period sunsets and universal opt-out commencement dates.
The cure map as of 1 October 2026. Eliminated: Montana, on 1 October 2025, so the AG can sue on day one. Ended: Colorado and Connecticut on 1 January 2025 (Connecticut's mandatory period ran through 31 December 2024), Delaware's mandatory period on 31 December 2025, Oregon's on 1 January 2026, Minnesota's on 31 January 2026, and, if the reported dates hold, New Jersey's around 15 July 2026 and New Hampshire's on 31 December 2025†. California has required no cure from the AG since 1 January 2023, and Rhode Island's law has none†. Discretionary: Florida (45 days), Delaware since 2026 and Maryland through 1 April 2027. Permanent: Virginia, Texas, Nebraska and Oklahoma (30 days), Tennessee (60 days), Iowa (90 days) and Alabama (45 days), with Utah, Indiana and Kentucky reported to have one†. Sunsetting by design: Louisiana's mandatory 30 days ends on 31 July 2027, and Vermont's 60 days runs from 1 January 2028 to 30 June 2029. The states diverge in enforcement philosophy, which is one reason a posture keyed to the strictest state is becoming the only maintainable strategy.
But treat the cure column as risk-shaping, not immunity. Connecticut's TicketNetwork settlement, $85,000 plus compliance reporting and announced on 8 July 2025, began with a cure notice sent on 9 November 2023. The company had 60 days, until 8 January 2024, and "did not resolve these deficiencies well beyond the cure period," the Attorney General said. A cure notice starts a documented record that makes the eventual settlement write itself.
On universal opt-out mechanisms, FPF counts twelve states whose laws require controllers to recognize opt-out preference signals, and all twelve requirements are now in force: California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon and Texas. The commencement dates differ, and secondary sources get them wrong: Colorado on 1 July 2024, Connecticut, Texas and Montana on 1 January 2025 (Connecticut's SB 1295 is a separate 2026 change), Nebraska on 1 January 2025 through an authorized-agent technology clause, Minnesota on 31 July 2025, Oregon and Delaware on 1 January 2026, and Maryland by 1 October 2025 as one of two permitted opt-out methods, not as a stand-alone mandate. New Hampshire and New Jersey are counted on FPF's word†. The 2026 laws point in different directions: Oklahoma, Louisiana and Alabama have no such duty (Alabama removed its requirement before passage), while Vermont adds one from 1 January 2028. The CPPA and the California, Colorado and Connecticut attorneys general jointly swept for Global Privacy Control compliance in September 2025, and eleven state attorneys general plus CalPrivacy now coordinate through the Consortium of Privacy Regulators, which Vermont joined on 4 August 2026.
The compliance calendar lists the key dated obligations from January 2026 through 2030
Statutes, amendments, regulator deadlines, cure sunsets and enforcement markers in one chronological view, verified against the linked sources as of 1 October 2026. Rows marked ✓ have passed and stay because they define the state of play. A dagger marks a date resting on secondary sources.
| Date | Jurisdiction | What happens | Who must act | Source |
|---|---|---|---|---|
| ✓ 1 Jan 2026 | IN†, KY†, RI† | Indiana, Kentucky and Rhode Island laws take effect | Controllers meeting each state's thresholds | MultiState |
| ✓ 1 Jan 2026 | California | CCPA regulations on audits, risk assessments and ADMT take effect; obligations phase to 2030 | CCPA-covered businesses | CPPA |
| ✓ 1 Jan 2026 | Oregon, Delaware | Universal opt-out recognition begins; Oregon HB 2008 bans sale of precise geolocation and under-16 data | Controllers selling data or targeting ads | Oregon DOJ |
| ✓ 31 Jan 2026 | Minnesota | MNCDPA cure period sunsets | Everyone in Minnesota scope | Minn. Stat. 325M |
| ✓ 11 Feb 2026 | California | Enforcement marker: $2.75M Disney settlement; opt-out and GPC requests did not reach all devices and services | Anyone running opt-out plumbing | CA AG |
| ✓ 20 Mar 2026 | Oklahoma | SB 546 signed | Watch for 1 Jan 2027 | Hunton |
| ✓ 17 Apr 2026 | Alabama | HB 351 signed | Watch for 1 May 2027 | Alabama Legislature |
| ✓ 8 May 2026 | California | Enforcement marker: $12.75M General Motors settlement, the largest CCPA penalty to date | Businesses selling or sharing driving or location data | CalPrivacy |
| ✓ 27 May 2026 | Connecticut | PA 26-64 (SB 4) signed | Watch for 1 Oct 2026 | CT AG |
| ✓ 29 May and 16 Jun 2026 | Louisiana, Vermont | Louisiana SB 386 and Vermont S.71 signed | Watch for 1 Jan 2027 and 1 Jan 2028 | FPF |
| ✓ 30 Jun 2026 | New Jersey | Data broker law signed and in effect: no sale of sensitive data by any controller; data broker and "data collector" registration | NJDPA controllers; data brokers | FPF |
| ✓ 1 Jul 2026 | Connecticut | SB 1295 changes take effect: 35,000 threshold, none for sensitive data or sale, minimization, minors 13 to 17 | Re-run Connecticut applicability | PA 25-113 |
| ✓ 1 Jul 2026 | Utah, Virginia | Utah right to correct; Virginia ban on selling precise geolocation data (SB 338) | UCPA and VCDPA controllers | Utah HB 418; Va. Code |
| ✓ about 15 Jul 2026 | New Jersey† | NJDPA cure period sunsets (18 months after the effective date) | Everyone in New Jersey scope | FPF |
| ✓ 1 Aug 2026 | California | DROP deletions go live: brokers access it at least every 45 days and process requests; $200 per request per day exposure | Registered data brokers | CPPA |
| ✓ 1 Aug 2026 | Connecticut | Profiling assessments required for activities created on or after this date | Controllers profiling Connecticut residents | PA 25-113 |
| ✓ 2 Sep 2026 | Delaware | HB 380 signed | Re-run Delaware applicability before 1 Jan 2027 | FPF |
| ✓ 27 Sep 2026 | California | SB 923 signed | CCPA-covered businesses | CalPrivacy |
| ✓ 1 Oct 2026 | Connecticut | PA 26-64 takes effect: no sale of precise geolocation, narrower "publicly available information" | CTDPA controllers | PA 26-64 |
| 1 Jan 2027 | Oklahoma, Louisiana | Both laws take effect; Louisiana's mandatory 30-day cure runs to 31 Jul 2027 | Controllers in scope | Hunton; Louisiana Act 502 |
| 1 Jan 2027 | Delaware, Connecticut | Delaware HB 380 changes take effect; Connecticut data broker registration due | Delaware controllers; data brokers | Delaware HB 380 |
| 1 Jan 2027 | California | ADMT compliance for significant decisions; SB 923; AB 566 browser signals; next CPI adjustment of the CCPA thresholds | Businesses using ADMT; all CCPA businesses | CPPA |
| 1 Jan 2027 | Utah, Colorado | HB 357 covers motor-vehicle manufacturers; Colorado's SB 26-189 AI act duties begin | Vehicle makers; AI developers and deployers | Utah HB 357; Colorado SB 26-189 |
| 1 Jan 2027 | New Hampshire | HB 1460 takes effect: no sale of a child's personal data, with or without consent | NHDPA controllers | Hunton |
| 1 Apr 2027 | Maryland | Discretionary cure period ends for violations on or before this date | MODPA controllers | Chapter 455 |
| 1 May 2027 | Alabama | APDPA takes effect (45-day cure; up to $15,000 per violation after a failure to cure) | Controllers in Alabama scope | Alabama Legislature |
| 1 Jul 2027 | Kentucky | HB 692 takes effect: certain smart TV data becomes sensitive data | KCDPA controllers | Hunton |
| 1 Jan 2028 | Vermont | VDPOSA takes effect, with an opt-out preference signal duty; 60-day cure, where the AG finds one possible, to 30 Jun 2029 | Controllers in Vermont scope | Vermont Act 145 |
| 1 Apr 2028 | California | First risk-assessment attestations due to the CPPA; first cybersecurity audit certifications (over $100M revenue); $50 to $100M tier 1 Apr 2029, smaller 1 Apr 2030 | CCPA-covered businesses | CPPA |
Forward-watch notes. Federally, the SECURE Data Act (H.R. 8413) was referred to the House Energy and Commerce and Judiciary Committees on 21 April 2026, and FPF reads its preemption language as capable of displacing state comprehensive laws; on 3 June 2026 CalPrivacy said it had joined a coalition of 18 attorneys general and state agencies opposing it. On the state side, DLA Piper's 10 March 2026 update listed 13 comprehensive bills in eight states in progress as of 2 March, including five in Illinois; Alabama has since enacted its bill, and Vermont enacted a law through a different bill, S.71. Pending bills stay out of the tables until a governor signs (or, Rhode Island-style, declines to). And IAPP's US State Privacy Legislation Tracker, updated 8 September 2026, remains the best bill-status resource; it tracks legislative motion, not compliance deadlines.
Run this as a maintained register, not a bookmarked chart
Keeping these tables true means watching 24 statutes, amendments at more than half of the states that have one, three rulemaking bodies (IAPP names Colorado, California and New Jersey as the states that give rulemaking authority to an agency), the enforcement programs of at least a dozen attorneys general plus CalPrivacy, thirteen opt-out signal regimes counting Vermont's, cure-period sunsets that keep arriving, and the bills that could add rows mid-session. Any chart dated before 20 March 2026 is at least four states short, and the four signed within 88 days. Trust pages that show their work: this page's regulatory change log is at the bottom, with every row sourced.
If you maintain this register by hand, three practices carry most of the value: log the amendment layer separately from the enactment layer (Kentucky and Delaware prove that enactment-only logs go stale, before a law starts and after it does); record both signed and effective dates (Maryland's 1 October 2025 and 1 April 2026 split is the cautionary example); and source every row to the statute or regulator page, never to coverage of it. Our regulatory change tracker spreadsheet implements those columns, and the regulatory change management policy template turns the cadence (who reviews, how often, who signs) into something an auditor can test. Other tracking methods are compared in how compliance teams track regulatory changes.
And yes, the disclosure, because this page is a working demonstration of my company's category: this is the job RegWatch automates. A Watchlist per jurisdiction, scheduled monitoring of the primary Sources (the CPPA announcements page, legislature bill feeds, attorney general press rooms), each hit landing as a Finding with its source URL, dates and verbatim excerpt, triaged into an Alert with a written "Why this matters," and converted into an Obligation with an owner and a deadline. But the register logic above is tool-agnostic: a counsel with a disciplined spreadsheet and a Friday review block will beat a team with expensive software and no changelog.
The amendment layer (laws changing before and after they take effect, regulators out-legislating legislatures) has made every undated chart quietly dangerous, so ask any privacy-law tracker for its counting rule and its changelog.
The changelog records every revision to this tracker
| Date | Change | Source |
|---|---|---|
| 2026-09-30 | First edition. All rows, the amendment layer and the calendar verified against the linked statutes, bills and regulator pages as of this date, including the four 2026 signings (Oklahoma, Alabama, Louisiana, Vermont), Delaware HB 380 (2 Sep 2026), Connecticut PA 26-64 (27 May 2026), California SB 923 (27 Sep 2026) and the General Motors settlement (8 May 2026). Cells marked † rest on secondary sources and are queued for statute-level confirmation. | Inline citations |
| 2026-10-01 | Re-verified against the statutes, FPF, Hunton and regulator pages as of 1 October 2026. Counts and statuses unchanged: no state has enacted a comprehensive law since Vermont. Added three 2026 amendments (New Jersey's data broker law of 30 Jun 2026, New Hampshire HB 1460, Kentucky HB 692) and CalPrivacy's LocateSmarter action (11 Aug 2026). Connecticut PA 26-64 marked in effect from 1 Oct 2026. Corrected: Vermont's cure period applies where the AG finds a cure possible; Alabama's law has no express AG-exclusivity clause; the General Motors settlement was brought by the Attorney General with four district attorneys; Oregon's motor-vehicle coverage dates from September 2025, separate from HB 2008. | Inline citations |
This article is general information, not legal advice.
Questions
How many US states have privacy laws in 2026?
As of 1 October 2026, 24 states have enacted comprehensive consumer privacy laws if you count Florida's narrower law, and 23 if you follow IAPP and FPF. Twenty laws are in effect (19 without Florida). Oklahoma and Louisiana take effect on 1 January 2027, Alabama on 1 May 2027 and Vermont on 1 January 2028. Counts differ because Florida reaches only very large companies and because trackers rarely state a counting rule.
Which state privacy laws take effect in 2026?
Indiana, Kentucky and Rhode Island took effect on 1 January 2026. The heavier 2026 work came from amendments and regulators: Connecticut's SB 1295 changes, Utah's right to correct and Virginia's ban on selling precise geolocation data on 1 July, California's data broker deletion platform on 1 August, and Connecticut's 2026 amendment, Public Act 26-64, took effect on 1 October 2026.
Is there a federal privacy law in the United States?
No. As of 1 October 2026 Congress has enacted no comprehensive consumer privacy law: HIPAA, GLBA, COPPA and FTC Act Section 5 cover sectors and unfair practices, not general consumer data rights. The SECURE Data Act (H.R. 8413), introduced in April 2026, was referred to committee on 21 April, and FPF reads its broad preemption language as capable of displacing state comprehensive privacy laws.
Do all state privacy laws give businesses a cure period?
No, and the trend is against them. Montana eliminated its cure period on 1 October 2025, Oregon's ended on 1 January 2026 and Minnesota's on 31 January 2026, and Delaware's mandatory period ended on 31 December 2025. A cure notice does not make a company safe: Connecticut's Attorney General fined TicketNetwork $85,000 in July 2025 for deficiencies the company did not resolve well beyond its 60-day cure period.
Which states require honoring Global Privacy Control signals?
By FPF's count, twelve states' laws require controllers to recognize universal opt-out signals, and all twelve requirements are now in force: California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon and Texas. Vermont adds a duty from 2028. California's $2.75 million Disney settlement in February 2026 turned on opt-outs that reached only one device or service.
Terms in this guide
Sources
- FPF: Louisiana becomes the 22nd state to enact a comprehensive privacy law (3 June 2026) accessed 30 Sep 2026
- FPF: Vermont becomes the 23rd state (17 June 2026) accessed 30 Sep 2026
- FPF: Delaware updates its privacy law with HB 380 (3 September 2026) accessed 30 Sep 2026
- FPF: Anatomy of a State Comprehensive Privacy Law (December 2025) accessed 30 Sep 2026
- FPF: New Hampshire, SB 255 (March 2024) accessed 30 Sep 2026
- FPF: New Jersey, S332 (January 2024) accessed 30 Sep 2026
- FPF: Rhode Island, H 7787 and S 2500 (June 2024) accessed 30 Sep 2026
- FPF: contextualizing the proposed SECURE Data Act (23 April 2026) accessed 30 Sep 2026
- Congress.gov: H.R. 8413, SECURE Data Act accessed 30 Sep 2026
- CalPrivacy: agency opposes the federal SECURE Data Act (3 June 2026) accessed 30 Sep 2026
- IAPP: US State Privacy Laws overview (report updated 27 October 2025) accessed 30 Sep 2026
- IAPP: State comprehensive privacy law chart (November 2025) accessed 30 Sep 2026
- IAPP: US State Privacy Legislation Tracker (page updated 8 September 2026) accessed 30 Sep 2026
- MultiState: privacy laws taking effect in 2026 (4 February 2026) accessed 30 Sep 2026
- DLA Piper: US privacy laws legislative update (10 March 2026) accessed 30 Sep 2026
- DLA Piper: Alabama becomes the 21st state (10 April 2026) accessed 30 Sep 2026
- Hunton: Alabama becomes the 21st state (21 April 2026) accessed 30 Sep 2026
- Hunton: Oklahoma enacts a comprehensive consumer privacy law (25 March 2026) accessed 30 Sep 2026
- Hunton: Kentucky amends its consumer privacy law, HB 473 (20 March 2025) accessed 30 Sep 2026
- Hunton: Kentucky classifies smart TV data as sensitive, HB 692 (22 April 2026) accessed 1 Oct 2026
- Hunton: New Hampshire amends the NHDPA to prohibit the sale of children's personal data, HB 1460 (14 July 2026) accessed 1 Oct 2026
- FPF: New Jersey's data broker and data collector registration law (10 July 2026) accessed 1 Oct 2026
- CalPrivacy: first action against a data broker under both the CCPA and the Delete Act, LocateSmarter (11 August 2026) accessed 1 Oct 2026
- CalPrivacy: Vermont joins the Consortium of Privacy Regulators (4 August 2026) accessed 30 Sep 2026
- CPPA: California finalizes regulations on audits, risk assessments and ADMT (23 September 2025) accessed 30 Sep 2026
- CPPA: CCPA regulation text (cybersecurity audits, risk assessments, ADMT) accessed 30 Sep 2026
- CPPA: updated monetary thresholds in the CCPA (2025) accessed 30 Sep 2026
- CPPA: information for data brokers and DROP accessed 30 Sep 2026
- California Civil Code section 1798.99.82 (Delete Act penalties) accessed 30 Sep 2026
- California Civil Code section 1798.99.86 (accessible deletion mechanism) accessed 30 Sep 2026
- CPPA: Governor signs the Opt Me Out Act, AB 566 (8 October 2025) accessed 30 Sep 2026
- CalPrivacy: Governor signs SB 923, Expanding Privacy Rights Act (27 September 2026) accessed 30 Sep 2026
- CPPA and state attorneys general: joint Global Privacy Control sweep (9 September 2025) accessed 30 Sep 2026
- California Attorney General: privacy enforcement actions accessed 30 Sep 2026
- California Attorney General: Disney settlement, $2.75 million (11 February 2026) accessed 30 Sep 2026
- CalPrivacy: General Motors settlement, $12.75 million (8 May 2026) accessed 30 Sep 2026
- CPPA: Tractor Supply fine, $1.35 million (30 September 2025) accessed 30 Sep 2026
- CalPrivacy: PlayOn Sports fine, $1.10 million (3 March 2026) accessed 30 Sep 2026
- CalPrivacy: Ford fine, $375,703 (5 March 2026) accessed 30 Sep 2026
- Code of Virginia section 59.1-576 (VCDPA scope) accessed 30 Sep 2026
- Code of Virginia section 59.1-578 (controller duties, including SB 338) accessed 30 Sep 2026
- Code of Virginia section 59.1-584 (enforcement and cure) accessed 30 Sep 2026
- NetChoice v. Jones (E.D. Va.): preliminary injunction against SB 854 (27 February 2026) accessed 30 Sep 2026
- Colorado Attorney General: Colorado Privacy Act accessed 30 Sep 2026
- Colorado Attorney General: universal opt-out mechanism accessed 30 Sep 2026
- Colorado SB 24-041 (minors) accessed 30 Sep 2026
- Colorado HB 24-1130 (biometrics) accessed 30 Sep 2026
- Colorado HB 24-1058 (neural data) accessed 30 Sep 2026
- Colorado SB 25-276 (sale of sensitive data) accessed 30 Sep 2026
- Colorado SB 26-189 (automated decision-making technology) accessed 30 Sep 2026
- Connecticut Attorney General: Connecticut Data Privacy Act FAQ accessed 30 Sep 2026
- Connecticut Public Act 25-113 (SB 1295) accessed 30 Sep 2026
- Connecticut Public Act 26-64 (SB 4) accessed 30 Sep 2026
- Connecticut Attorney General: rights and requirements under new and updated privacy laws (16 September 2026) accessed 30 Sep 2026
- Connecticut Attorney General: TicketNetwork settlement, $85,000 (8 July 2025) accessed 30 Sep 2026
- Utah HB 418 (2025), Data Sharing Amendments, enrolled accessed 30 Sep 2026
- Utah HB 357 (2026), enrolled accessed 30 Sep 2026
- Utah SB 227 (2022), Consumer Privacy Act accessed 30 Sep 2026
- Florida Statutes section 501.702 (definitions and scope) accessed 30 Sep 2026
- Florida Statutes section 501.715 (sale of sensitive data) accessed 30 Sep 2026
- Florida Statutes section 501.72 (enforcement and cure) accessed 30 Sep 2026
- Florida Attorney General: Roku resolution (26 June 2026) accessed 30 Sep 2026
- Florida Attorney General: action against Netflix (9 September 2026) accessed 30 Sep 2026
- Florida Attorney General: Digital Bill of Rights annual report (2026) accessed 30 Sep 2026
- Oregon Department of Justice: privacy law FAQs for businesses accessed 30 Sep 2026
- Oregon Department of Justice: universal opt-out tool (28 January 2026) accessed 30 Sep 2026
- Oregon HB 2008 (2025), enrolled (Internet Archive copy of the legislature's PDF) accessed 30 Sep 2026
- Texas HB 4 (2023), Data Privacy and Security Act, enrolled accessed 30 Sep 2026
- Texas Attorney General: Allstate and Arity lawsuit (13 January 2025) accessed 30 Sep 2026
- Montana Code Annotated, Title 30, chapter 14, part 28 accessed 30 Sep 2026
- FPF: amendments to the Montana Consumer Data Privacy Act (SB 297) accessed 30 Sep 2026
- Iowa Acts 2023, chapter 17 (SF 262) accessed 30 Sep 2026
- Iowa Code chapter 715D accessed 30 Sep 2026
- Delaware Code, Title 6, chapter 12D accessed 30 Sep 2026
- Delaware HB 380 (153rd General Assembly) accessed 30 Sep 2026
- Nebraska Data Privacy Act, sections 87-1101 to 87-1130 accessed 30 Sep 2026
- Tennessee Public Chapter 408 (2023), Information Protection Act accessed 30 Sep 2026
- Minnesota Statutes chapter 325M (Consumer Data Privacy Act) accessed 30 Sep 2026
- Maryland Chapter 455 (2024), SB 541, Online Data Privacy Act accessed 30 Sep 2026
- Oklahoma SB 546, enrolled text accessed 30 Sep 2026
- Alabama HB 351 (Act 2026-552), enrolled text accessed 30 Sep 2026
- Louisiana Act 502 (SB 386), Internet Archive copy of the enrolled act accessed 30 Sep 2026
- Vermont Act 145 (S.71), as enacted accessed 30 Sep 2026
