Not legal advice. This guide is for general informational purposes only. Regulations change frequently. Always consult a qualified attorney for guidance specific to your situation.

Regulation Guide

State Data Privacy Laws: What Your Business Needs to Know in 2026

The United States now has one of the world's most fragmented data privacy regulatory environments. With more than 20 state-level comprehensive privacy laws in effect, and more advancing through legislatures every year, businesses operating across state lines face a growing compliance challenge. This guide explains what you need to know.

The US Privacy Law Landscape in 2026

Unlike the European Union's unified GDPR, the United States has taken a state-by-state approach to consumer data privacy. California led the way with the California Consumer Privacy Act (CCPA) in 2020, subsequently strengthened by Proposition 24 into the California Privacy Rights Act (CPRA) in 2023. Since then, the pace of state enactment has accelerated sharply.

As of early 2026, comprehensive consumer privacy laws are in effect in California, Colorado, Virginia, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Indiana, Tennessee, New Hampshire, New Jersey, and Nebraska, among others. Several additional states have bills moving through their legislatures. The result is a patchwork of overlapping requirements that differ on applicability thresholds, consumer rights, cure periods, and enforcement mechanisms.

No comprehensive federal privacy law has been enacted, though the American Privacy Rights Act (APRA) has been introduced in Congress. Until federal legislation preempts state law, each state's requirements apply independently.

Key Requirements Common Across State Privacy Laws

Despite their differences, most state comprehensive privacy laws share a core set of requirements:

Consumer Rights

  • Right to know - Consumers can request what personal data a business holds about them.
  • Right to correct - Consumers can ask businesses to correct inaccurate data.
  • Right to delete - Consumers can request deletion of their personal data, subject to legal exceptions.
  • Right to portability - Consumers can request a machine-readable copy of their data.
  • Right to opt out of sale - Consumers can opt out of the sale of their personal data to third parties.
  • Right to opt out of targeted advertising - Most states include this alongside opt-out of sale rights.
  • Right to opt out of profiling - Several states extend opt-out rights to automated profiling that produces significant legal or similarly significant effects.

Business Obligations

  • Privacy notice - A clear, accessible privacy policy disclosing data categories collected, purposes, and consumer rights.
  • Data processing agreements - Written contracts with processors (vendors, SaaS providers) that handle personal data on your behalf.
  • Data minimization - Collect only data that is adequate and relevant for the disclosed purpose.
  • Purpose limitation - Do not use data for purposes incompatible with what was disclosed at collection.
  • Sensitive data handling - Additional consent or opt-in requirements for sensitive categories: health, biometric, precise geolocation, children's data, financial information, and others.
  • Data protection assessments (DPAs) - Required in Colorado, Connecticut, Virginia, and several others for high-risk processing activities such as targeted advertising or data sales.
  • Universal opt-out mechanism (UOOM) - California, Colorado, Oregon, New Jersey, and several other states require businesses to honor browser-level opt-out signals such as the Global Privacy Control (GPC).

Which States Are Strictest

California, CCPA/CPRA

California remains the gold standard of US privacy regulation. The CPRA created the California Privacy Protection Agency (CPPA), a dedicated enforcement body with independent rulemaking authority. California is the only state with a private right of action for data breaches - consumers can sue directly without waiting for state enforcement. Penalties reach $7,500 per intentional violation, and there is no cure period for most violations as of 2023. California's applicability thresholds are also the lowest: businesses with over $25 million annual revenue, data on 100,000+ consumers, or 50%+ of revenue from data sales must comply.

California also mandates honoring the Global Privacy Control signal and requires opt-in consent for sensitive personal information, a higher bar than most states.

Colorado, CPA

The Colorado Privacy Act applies to controllers processing data of 100,000+ Colorado consumers annually, or 25,000+ consumers where revenue derives from data sales. Colorado mandates data protection assessments for high-risk processing, requires opt-in consent for sensitive data, and requires honoring universal opt-out mechanisms. Civil penalties reach $20,000 per violation. Colorado provides a 60-day cure period for alleged violations.

Virginia, VCDPA

The Virginia Consumer Data Protection Act closely mirrors Colorado's framework with a 100,000-consumer threshold and $7,500 per-violation civil penalties after a 30-day cure period. Virginia does not require businesses to honor universal opt-out signals like the Global Privacy Control, which distinguishes it from California and Colorado. Enforcement is exclusively by the state attorney general, there is no private right of action.

Texas, Oregon, and New Jersey

Texas's Data Privacy and Security Act (TDPSA) notably has no revenue threshold - it applies to any business processing data of Texas residents that is not a small business under the SBA definition, making it potentially the broadest in scope. Oregon and New Jersey mandate honoring the Global Privacy Control and have rights packages similar to Colorado.

Compliance Checklist for Multi-State Businesses

  1. Map your data flows - Document what personal data you collect, why, how it is stored, who it is shared with, and for how long.
  2. Determine which state laws apply - Run applicability thresholds for each state where you have customers: resident volume, revenue from data sales, total revenue.
  3. Audit and update your privacy notice - Ensure it discloses required categories, rights, opt-out mechanisms, and retention periods. Update it whenever processing practices change.
  4. Build a consumer rights request (DSAR) process - Implement a submission mechanism (webform or email), verify requestor identity, and meet the response deadline (typically 45 days, extendable to 90 days).
  5. Implement opt-out signal recognition - If operating in California, Colorado, Oregon, New Jersey, or Montana, configure your site to honor the Global Privacy Control browser signal.
  6. Audit vendor contracts - Ensure all processors handling personal data on your behalf have signed data processing agreements with the required contractual provisions.
  7. Conduct data protection assessments - For high-risk activities (targeted advertising, selling data, profiling, sensitive data processing), complete assessments before beginning processing.
  8. Review sensitive data handling - Identify whether you process sensitive categories and implement opt-in consent where required by California, Colorado, and other states.
  9. Train your team - Privacy compliance is an operational practice, not just a legal document. Staff handling personal data should understand the basics of consumer rights and internal procedures.
  10. Schedule periodic reviews - Laws are amended, new states enact legislation, and your data practices evolve. Review your compliance program at least annually.

Where to Go Next on PlainRegWatch

PlainRegWatch tracks data privacy regulations across all 50 states. Browse current status, effective dates, and law summaries:

Frequently Asked Questions

How many US states have data privacy laws in 2026?

More than 20 states have enacted comprehensive consumer data privacy laws. The number has grown rapidly since California's CCPA took effect in 2020. Several additional states have bills advancing through legislatures.

Does my business need to comply with every state privacy law?

Only for states where you process personal data about residents above the law's applicability thresholds, typically 100,000 residents annually or a revenue threshold tied to data sales. Small businesses often fall below thresholds in most states, but should verify carefully, especially for California and Texas.

Is California the strictest state for data privacy?

Yes. California's CPRA is the most comprehensive, the only US state law with a dedicated enforcement agency, a private right of action for data breaches, and opt-in consent for sensitive personal information. Colorado and Virginia are close runners-up in substantive obligations.

What are the penalties for violating state data privacy laws?

Penalties range from $7,500 per violation (California) to $20,000 per violation (Colorado, Virginia). Many states offer a cure period of 30–60 days before formal enforcement begins. California eliminated its cure period for most violations in 2023.

Is there a federal US data privacy law?

As of 2026, no. The American Privacy Rights Act has been proposed but not enacted. Sector-specific laws like HIPAA (health) and COPPA (children under 13) remain in place. Until federal legislation passes, businesses must comply with each applicable state law independently.

Every figure on PlainRegWatch is rendered directly from state source data, no number is typed in by an editor. This page draws directly on federal and state source data, no figure is typed in by an editor. See our editorial standards & corrections policy, the methodology behind these numbers, or report a data error.