US State Privacy Laws

Every US state privacy law in one table, with the obligations that decide what your site has to do.

27
Laws tracked, across 25 states
23
In force today
4
Passed, not yet in force
12
Require honoring a browser opt-out signal today (14 including upcoming)

Last reviewed August 9, 2026. Each row links to a full breakdown of that law, and the figures above are counted from those records rather than maintained by hand.

Compare every US state privacy law

There is no federal US privacy law, so the rules that apply to your site depend on where your visitors live. The table below is ordered by the date each law took effect, so the newest obligations are at the bottom. Blanks mean the law does not state a figure, not that the answer is zero.

LawStateEffectiveConsent modelHonors browser opt-outCure periodConsumers can sue
CIPACaliforniaJan 1, 1967Opt-inNoNot specifiedYes
CCPACaliforniaJan 1, 2020Opt-outNo30 daysYes
CPRACaliforniaJan 1, 2023Opt-outYesNot specifiedYes
VCDPAVirginiaJan 1, 2023Opt-outNo30 daysNo
CPAColoradoJul 1, 2023Opt-outYesNot specifiedNo
CTDPAConnecticutJul 1, 2023Opt-outYesNot specifiedNo
UCPAUtahDec 31, 2023Opt-outNo30 daysNo
MHMDAWashingtonMar 31, 2024Opt-inNoNot specifiedYes
FDBRFloridaJul 1, 2024Opt-outNo45 daysNo
OCPAOregonJul 1, 2024Opt-outYes30 daysNo
TDPSATexasJul 1, 2024Opt-outYes30 daysNo
Montana MCDPAMontanaOct 1, 2024Opt-outYesNot specifiedNo
DPDPADelawareJan 1, 2025Opt-outYes60 daysNo
ICDPAIowaJan 1, 2025Opt-outNo90 daysNo
NDPANebraskaJan 1, 2025Opt-outYes30 daysNo
NHPANew HampshireJan 1, 2025Opt-outYesNot specifiedNo
NJDPANew JerseyJan 15, 2025Opt-outYes30 daysNo
TIPATennesseeJul 1, 2025Opt-outNo60 daysNo
Minnesota MCDPAMinnesotaJul 31, 2025Opt-outYes30 daysNo
MODPAMarylandOct 1, 2025Opt-outYesNot specifiedNo
INCDPAIndianaJan 1, 2026Opt-outNo30 daysNo
RIDTPPARhode IslandJan 1, 2026Opt-outNoNot specifiedNo
KCDPAKentuckyJan 1, 2026Opt-outNo30 daysNo
LDPALouisianaJan 1, 2027UpcomingOpt-outYes30 daysNo
OKCDPAOklahomaJan 1, 2027UpcomingOpt-outNo30 daysNo
APDPAAlabamaMay 1, 2027UpcomingOpt-outNoNot specifiedNo
VDPOSAVermontJan 1, 2028UpcomingOpt-outYesNot specifiedNo

How many US states have a privacy law?

27 privacy laws across 25 states are tracked here, of which 23 are in force today and 4 have passed but have not taken effect yet. California accounts for more than one because its rules were built in layers, and each layer still carries obligations of its own.

Which states make you honor a browser opt-out signal?

12 laws in force today require you to respect a preference the visitor's browser sends automatically, usually Global Privacy Control, and 14 do once the upcoming ones land. This is the obligation most sites miss, because it is invisible: there is no banner click to catch it, and the signal arrives before anyone interacts with your page. Our Global Privacy Control guide covers how the signal is detected and applied.

Do these laws require a cookie banner?

Mostly not in the European sense. 25 of these laws run on an opt-out model, so tracking may generally start before the visitor chooses, provided you offer a clear way to opt out and honor it. 24 of them still require opt-in consent before you handle sensitive categories of data, which is where a banner usually re-enters the picture.

Can consumers sue you directly?

Under 4 of these laws they can. Everywhere else, enforcement runs through the state attorney general or a dedicated privacy agency. The terms differ law by law, including what triggers the right and what damages are available, so the individual law pages carry the specifics rather than this summary.

Which law takes effect next?

Louisiana Data Privacy Act (SB 386 / Act 502) is the next to take effect, on Jan 1, 2027. Because obligations attach to where your visitors live rather than where your business is, a new state law can apply to you without anything about your site changing.

CCPA
California, United States
Flag of US
Opt-outState

The CCPA was the first comprehensive consumer privacy law in the United States, giving California residents the right to know what personal information businesses collect and to opt out of its sale. It established the opt-out consent model that most subsequent US state privacy laws adopted.

CPRA
California, United States
Flag of US
Opt-outState

The CPRA is the most comprehensive US state privacy law with a dedicated enforcement agency (CPPA). Cross-context behavioral advertising via cookies constitutes sharing personal information, triggering opt-out obligations. GPC signals must be honored as valid opt-out requests.

CIPA
California, United States
Flag of US
Opt-inState

CIPA is a 1967 California chapter covering wiretapping, eavesdropping, and other privacy invasions, not a website-specific law. Since 2022, courts have applied two of its sections to website chat, analytics, and ad tools, and any visitor can sue directly for at least $5,000 per violation, no revenue threshold.

CPA
Colorado, United States
Flag of US
Opt-outState

Colorado's CPA features the highest per-violation penalties among US state privacy laws at $20,000. Must honor GPC signals since July 2024. Participated in a joint GPC enforcement sweep with California and Connecticut in September 2025. The cure period was eliminated in January 2025.

MODPA
Maryland, United States
Flag of US
Opt-outState

The most restrictive US state privacy law. Sensitive data may only be processed when strictly necessary to deliver a requested service, and sale of sensitive data is completely prohibited even with consent. Under-18 sale and targeted advertising are prohibited regardless of consent. Strictest data minimization in the US.

TDPSA
Texas, United States
Flag of US
Opt-outState

The TDPSA is the broadest US state privacy law: no revenue thresholds and no minimum consumer data volume thresholds. Applies to any non-small-business processing personal data of Texas residents. Must honor GPC signals since January 2025. This breadth means far more businesses are captured than under any other state law.

VCDPA
Virginia, United States
Flag of US
Opt-outState

Virginia was the second US state to enact a comprehensive privacy law and became the template for most subsequent state laws. Follows an opt-out model with opt-in for sensitive data. A permanent 30-day cure period distinguishes it from newer laws that sunset cure periods.

MHMDA
Washington, United States
Flag of US
Opt-inState

Washington's sector-specific health data privacy law has the broadest health data definition among US laws. Requires opt-in consent for ALL consumer health data collection, sharing, and sale. Uniquely prohibits geofencing within 2,000 feet of healthcare facilities. Provides a private right of action.

CTDPA
Connecticut, United States
Flag of US
Opt-outState

Connecticut's CTDPA features a unique consent revocation mechanism for sensitive data and some of the strongest children's data protections. The cure period was eliminated January 2025. The 2025 amendments prohibit sale of children's data or use for targeted advertising even with consent.

Montana MCDPA
Montana, United States
Flag of US
Opt-outState

Montana has the lowest applicability thresholds among US state privacy laws (25,000/15,000 consumers after SB 297). The October 2025 amendments eliminated the cure period, added GPC signal honoring, and introduced a unique duty of reasonable care for minors. Sale of 13-17 data is prohibited.

NJDPA
New Jersey, United States
Flag of US
Opt-outState

New Jersey's NJDPA features a unique 15-day opt-out processing requirement (shortest among US states) and explicitly requires that universal opt-out mechanisms must NOT default to opt-in. Covers opt-out of profiling for decisions with legal or similarly significant effects, broader than most states.

DPDPA
Delaware, United States
Flag of US
Opt-outState

Delaware features lower applicability thresholds and the broadest children's age protection among US states: under 18 for sale and targeted advertising. The cure period sunsets December 2025. Must honor universal opt-out mechanisms. The AG can also seek restitution and disgorgement.

LDPA
Louisiana, United States
Flag of US
Opt-outState

Louisiana's comprehensive consumer privacy law (LDPA, Act 502) takes effect January 2027. It is an opt-out model: visitors get access/deletion/portability rights and can opt out of targeted advertising, sale, and profiling, and the law requires recognition of a universal opt-out signal (GPC).

OCPA
Oregon, United States
Flag of US
Opt-outState

Oregon is the first US state to extend comprehensive privacy law coverage to nonprofit organizations. Features the broadest sensitive data definition among US states, uniquely including transgender/nonbinary status and crime victim status. The cure period sunsets January 2026 when GPC signal honoring becomes mandatory.

Minnesota MCDPA
Minnesota, United States
Flag of US
Opt-outState

Minnesota introduces several first-of-their-kind requirements: mandatory Chief Privacy Officer designation, required data inventory maintenance, and the right to challenge profiling decisions. The sensitive data definition is expanded to include SSN, government IDs, financial accounts, and passwords.

NHPA
New Hampshire, United States
Flag of US
Opt-outState

New Hampshire's privacy law includes both civil penalties ($10,000) and criminal penalties for intentional noncompliance ($100,000), which is unusual among US state privacy laws. The discretionary cure period uses a multi-factor assessment. Children aged 13-16 are protected from sale and targeted advertising.

FDBR
Florida, United States
Flag of US
Opt-outState

Florida's FDBR has the narrowest applicability among US states, targeting only very large technology companies with a $1 billion revenue threshold. However, it has the highest base penalty ($50,000) and treble damages for violations involving children ($150,000). Smart speaker surveillance restrictions apply.

VDPOSA
Vermont, United States
Flag of US
Opt-outState

Vermont's comprehensive consumer privacy law (VDPOSA), modeled on the amended Connecticut CTDPA, takes effect January 2028. It is an opt-out model with universal opt-out (GPC) recognition, profiling opt-out, broad sensitive/health data coverage (opt-in to sell health data), and low applicability thresholds.

TIPA
Tennessee, United States
Flag of US
Opt-outState

Tennessee's TIPA has the highest consumer threshold among US state laws (175,000) and a first-of-its-kind NIST safe harbor provision. Controllers maintaining a written privacy program conforming to the NIST framework can assert an affirmative defense. Treble damages apply for willful violations.

RIDTPPA
Rhode Island, United States
Flag of US
Opt-outState

Rhode Island's RIDTPPA has no cure period and applies broadly by also covering commercial websites and ISPs with Rhode Island customers, even without meeting numerical thresholds. Under-18 data is classified as sensitive. Additional per-disclosure penalties apply for intentional unauthorized disclosure.

OKCDPA
Oklahoma, United States
Flag of US
Opt-outState

Oklahoma's comprehensive consumer privacy law (OKCDPA) takes effect January 2027. It is a Virginia-style opt-out model with opt-out of sale, targeted advertising, and profiling, and opt-in consent for sensitive data. It does not mandate universal opt-out (GPC) signal recognition.

UCPA
Utah, United States
Flag of US
Opt-outState

The most business-friendly US state privacy law, requiring both a revenue threshold ($25M+) and data volume threshold, the highest dual threshold among US states. Does not include a right to correct data or opt out of profiling.

APDPA
Alabama, United States
Flag of US
Opt-outState

Alabama's comprehensive consumer privacy law (APDPA) takes effect May 2027. It is a Virginia-style opt-out model with opt-in consent for sensitive data. Universal opt-out (GPC) signal recognition is not required at launch (becomes required in 2028).

NDPA
Nebraska, United States
Flag of US
Opt-outState

Nebraska's NDPA has no revenue or data processing minimums, making it applicable to businesses of all sizes except SBA-defined small businesses. Defines precise geolocation uniquely as within a 1,750-foot (533.4m) radius. Must honor GPC/UOOM signals.

ICDPA
Iowa, United States
Flag of US
Opt-outState

Iowa's privacy law has the longest cure period among US states at 90 days and is unique in requiring only notice and opt-out for sensitive data rather than opt-in consent. It does not grant the right to correct data or opt out of profiling or targeted advertising.

INCDPA
Indiana, United States
Flag of US
Opt-outState

Indiana's INCDPA closely follows the Virginia VCDPA template with a permanent 30-day cure period and data protection assessments for high-risk processing. Features a narrower health data definition compared to some other states. Takes effect January 1, 2026.

KCDPA
Kentucky, United States
Flag of US
Opt-outState

Kentucky's KCDPA closely follows the Virginia VCDPA template with a permanent 30-day cure period. Does not require honoring GPC/UOOM signals. Data protection impact assessments apply to processing from June 2026. HB 473 (March 2025) refined healthcare and DPIA provisions.