State Privacy Laws: Which States Have One and Where to Read It

Title card for the Vaquill AI guide: State Privacy Laws: Which States Have One and Where to Read It

Short answer: Many states now have comprehensive state privacy laws, and the list keeps changing. A comprehensive privacy law is a statute (a law passed by a legislature) that gives people rights over their personal data and puts duties on businesses across most industries. The table below covers every state I could confirm from the state's own code, with the citation to read. This post is general information and is not legal advice.

TL;DR

  • "Comprehensive" here means rights to see, correct, delete and opt out of the sale of personal data, plus duties for businesses that handle it. A health privacy law or a breach notice law does not count.
  • Whether a law covers you depends on thresholds, such as how many residents' data you handle.
  • Start dates, cure periods and thresholds are changing in several states during 2026 and 2027.
  • California is the only row with an express right for consumers to sue, and only after certain data breaches.
  • Do not rely on any list for a count. Use the check at the end of this post.

What I counted as a comprehensive law

The test: a statute must give consumers rights over their personal data and impose duties on the businesses that control it, across industries. A sector law covers one field, such as banking or health care. A breach law only says what to do after data is stolen. Neither is in the table.

I found candidates by running a topic search across every state's statutes through Vaquill AI's API. Then I read each law's coverage, enforcement and start-date text in the state's own code or session law. A session law is the act as the legislature passed it, before it is folded into the code.

State privacy laws in one table

How to use the table: find your states, check the "covers a business that" column against your numbers, then read the enforcement columns. Five terms matter.

  • A consumer is a person whose data is collected. Each law defines the term for itself.
  • A controller is the business that decides why and how personal data is used.
  • A cure period is a window to fix a violation after a warning, before any penalty.
  • A private suit is a lawsuit that a consumer files on their own.
  • Sensitive data is a list each statute sets out, with things like health details.

I checked every row on October 5, 2026. Where a column is silent, the text I read is silent. Later amendments can change a row, and each law has exemptions the table does not show, so treat it as a starting point.

State and where to read itEffective dateCovers a business thatWho enforces itCure period and private suits
Alabama: Ala. Code § 8-44-1 and following (Alabama Personal Data Protection Act)May 1, 2027Handles data of over 25,000 consumers, or gets over 25% of its total sales income (gross revenue) from selling personal dataAttorney General. Penalty up to $15,000 per violation45 days to fix after written notice. The text does not mention private suits
California: Cal. Civ. Code § 1798.100 and following (California Consumer Privacy Act)Jan. 1, 2020. Voter-approved changes Jan. 1, 2023Does business in California and meets one test: over $25 million in revenue (adjusted), or buys, sells or shares data of 100,000 or more consumers or households, or gets 50% or more of revenue from selling or sharing dataPrivacy Protection Agency and Attorney GeneralThe enforcement sections I read set no cure period, and the agency may allow time to fix. Consumers may sue only after certain data breaches, with 30 days' written notice first
Colorado: C.R.S. § 6-1-1301 and following (Colorado Privacy Act)July 1, 2023Handles data of 100,000 consumers a year, or 25,000 while getting revenue or a discount from selling data. Rules for fingerprints and face scans apply at any sizeAttorney General and district attorneys60-day cure for the child-protection sections only, ending Dec. 31, 2026. No private suit
Connecticut: Conn. Gen. Stat. § 42-515 and following (chapter titled Data Privacy and Security)July 1, 2023. Wider coverage from July 1, 2026 (Public Act 25-113)Since July 1, 2026: handled data of 35,000 consumers in the prior year, or handles any sensitive data, or offers personal data for saleAttorney General onlyRequired 60-day cure ended Dec. 31, 2024. The Attorney General may now choose to offer one. No private suit
Delaware: 6 Del. C. § 12D-101 and following (Delaware Personal Data Privacy Act)Jan. 1, 2025Handles data of 35,000 consumers, or 10,000 with over 20% of revenue from selling data. From Jan. 1, 2027 (House Bill 380): 10,000, or 5,000 with over 20% of revenue from sales, plus third parties that acquire data from a controllerDepartment of JusticeRequired 60-day cure in 2025 only. Optional since 2026. No private suit
Florida: Fla. Stat. § 501.701 and following (Florida Digital Bill of Rights)July 1, 2024Mostly "controllers" with over $1 billion in global revenue that also run a large ad business, a smart speaker service, or an app store with 250,000 or more apps. A separate rule bars any for-profit business from selling sensitive data without consentDepartment of Legal Affairs. Penalty up to $50,000 per violationThe department may grant a 45-day cure. The text says it creates no private suit
Indiana: Ind. Code art. 24-15Jan. 1, 2026Handles data of 100,000 Indiana consumers, or 25,000 with over 50% of revenue from selling dataAttorney General only. Penalty up to $7,500 per violation30-day cure. No private suit
Iowa: Iowa Code ch. 715DJan. 1, 2025Handles data of 100,000 consumers, or 25,000 with over 50% of revenue from selling dataAttorney General only. Penalty up to $7,500 per violation90-day cure. No private suit
Kentucky: KRS 367.3611 to 367.3629Jan. 1, 2026. A 2026 act adds rules from July 1, 2027Handles data of 100,000 consumers, or 25,000 with over 50% of revenue from selling dataAttorney General only. Up to $7,500 per continued violation30-day cure. No private suit
Maryland: Md. Code, Com. Law § 14-4701 and followingOct. 1, 2025Handles data of 35,000 consumers, or 10,000 with over 20% of revenue from selling dataEnforced under Title 13 of the same article, Maryland's general law against unfair or misleading business conductState may give at least 60 days to cure, for violations through April 1, 2027. The consumer-suit section of Title 13 is excluded, and the text says other remedies are not blocked
Minnesota: Minn. Stat. §§ 325M.10 to 325M.21 (Minnesota Consumer Data Privacy Act)July 31, 2025 (colleges under the Office of Higher Education: July 31, 2029)Handles data of 100,000 consumers, or 25,000 with over 25% of revenue from selling data. Small businesses still need consent to sell sensitive dataAttorney General. Penalty up to $7,500 per violationThe 30-day cure ended Jan. 31, 2026. No private suit
Montana: Mont. Code Ann. §§ 30-14-2801 to 30-14-2820 (Consumer Data Privacy Act)Oct. 1, 2024Handles data of 25,000 consumers, or 15,000 with over 25% of revenue from selling dataAttorney General onlyNo cure period in the enforcement section. No private suit
Nebraska: Neb. Rev. Stat. §§ 87-1101 to 87-1130 (Data Privacy Act)Jan. 1, 2025Sells or processes personal data and is not a small business under the federal Small Business ActAttorney General. Penalty up to $7,500 per violation30-day cure. No private suit
New Hampshire: N.H. Rev. Stat. ch. 507-HJan. 1, 2025Handled data of 35,000 consumers in a year, or 10,000 with over 25% of revenue from selling dataAttorney General only60-day cure required in 2025, optional since. No private suit
New Jersey: N.J. Stat. § 56:8-166.4 and following (P.L. 2023, c. 266)365th day after enactment (enacted Jan. 16, 2024, so Jan. 15, 2025)Handles data of 100,000 consumers, or 25,000 while getting revenue or a discount from selling dataOnly the Attorney General may enforce it30-day cure for the first 18 months only. No private suit
Oregon: ORS 646A.570 to 646A.589July 1, 2024 (charities with 501(c)(3) federal tax-exempt status: July 1, 2025)Handles data of 100,000 consumers, or 25,000 with 25% or more of revenue from selling data. Vehicle makers and affiliates handling vehicle-use data at any sizeAttorney General only. Penalty up to $7,500 per violationA 2025 cure window has ended and the current text has none. No private suit
Rhode Island: R.I. Gen. Laws § 6-48.1-1 and following (Data Transparency and Privacy Protection Act)Jan. 1, 2026For-profit businesses that handled data of 35,000 customers, or 10,000 with over 20% of revenue from selling dataAttorney General has sole enforcementNo cure period in the enforcement section. No private suit
Tennessee: Tenn. Code Ann. § 47-18-3301 and following (Tennessee Information Protection Act)July 1, 2025Has over $25 million in revenue and handles data of 175,000 consumers, or 25,000 with over 50% of revenue from selling dataAttorney General. Penalty up to $7,500 per violation. For a willful or knowing violation, a court may triple the damages60-day cure. No private suit, class actions included
Texas: Tex. Bus. & Com. Code ch. 541July 1, 2024. Browser and device opt-out rule: Jan. 1, 2025Sells or processes personal data and is not a small business under the U.S. Small Business Administration's definitionAttorney General. Penalty up to $7,500 per violation30-day cure. No private suit
Utah: Utah Code title 13, ch. 61Dec. 31, 2023Has $25 million or more in revenue and handles data of 100,000 consumers, or 25,000 with over 50% of revenue from selling dataAttorney General. Actual damages to the consumer plus up to $7,500 per violation30-day cure. No private suit
Virginia: Va. Code § 59.1-575 and followingJan. 1, 2023Handles data of 100,000 consumers, or 25,000 with over 50% of revenue from selling dataAttorney General only. Penalty up to $7,500 per violation30-day cure. No private suit

Connecticut's row comes from Public Act 25-113, because the state's online code page I read had not yet folded in the July 2026 changes. Delaware's 2027 change is House Bill 380, signed September 2, 2026, and you can read it on the Delaware legislature's site. The summary printed on that page was written when the bill was introduced and cites a different threshold, so use the signed version's numbers. Kentucky's is 2026 Ky. Acts ch. 118. Start dates come from each session law. Coverage and enforcement come from the codified text, except Connecticut's coverage, which comes from the public act.

Laws that are not in the table yet

The table holds laws I could read in the state code. Oklahoma, Louisiana and Vermont have each passed a comprehensive law that starts later. I read the acts on their legislatures' sites, such as Oklahoma's bill page. Oklahoma's Senate Bill 546 and Louisiana's Act 502 start January 1, 2027. Vermont's Act 145 starts January 1, 2028. I left them out because I could not read their codified text, which is the version that sits in the state's code.

What they have in common

These laws follow a shared pattern. New Hampshire's section on consumer rights is typical. It lets a consumer confirm whether a business holds their data, correct it, delete it, get a copy, and opt out of targeted ads, the sale of the data, or automated decisions with serious effects. Many of the laws also require a privacy notice and a written risk review, called a data protection assessment, for riskier uses. Most set special rules for sensitive data, which is a list the statute sets out.

Here is a real operative passage. Virginia's coverage section, Va. Code § 59.1-576(A), reads:

This chapter applies to persons that conduct business in the Commonwealth or produce products or services that are targeted to residents of the Commonwealth and that (i) during a calendar year, control or process personal data of at least 100,000 consumers or (ii) control or process personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal data.

You can read it at the Virginia code site.

Where they differ, and what matters most if you sell nationwide

Who is covered. Virginia needs 100,000 consumers. Maryland needs 35,000. Delaware moves to 10,000 in 2027. Texas and Nebraska ask whether you are a small business instead of counting people. Florida puts its main duties on companies with over $1 billion in global revenue. Connecticut now covers any business that handles sensitive data or offers data for sale.

Start dates and moving rules. Alabama starts in 2027. Delaware and Kentucky change in 2027. Connecticut changed in July 2026. A table from last spring may be wrong.

Cure periods. A cure period lets you fix a problem after a warning. Virginia, Texas, Indiana and Utah keep one in their text with no end date. Minnesota's and Oregon's have ended. Rhode Island and Montana show none in their enforcement sections. If you plan to rely on a cure period, read the enforcement section for that state itself.

Who can sue. Every law in the table sends enforcement to a state office. California's text lets consumers sue, and only after certain data breaches. Maryland's text keeps other remedies open, so ask counsel what that means there. Alabama's text says nothing either way.

Who counts as a consumer. Virginia says a consumer acts "only in an individual or household context" and excludes people acting "in a commercial or employment context." California defines a consumer as "a natural person who is a California resident." That difference decides whether employee and business-contact data is in scope.

Here are thresholds in practice. A company with data on 40,000 Maryland residents is covered in Maryland. A company with data on 12,000 Delaware residents is not covered today, unless it earns over 20% of revenue from selling data, but will be from January 1, 2027.

The safest national approach is to meet the strictest version of each rule you are subject to. A lawyer can tell you which rules apply to you.

Common mistakes

  • Counting states. A number goes stale in weeks. Check the states where your customers live.
  • Reading a summary instead of the statute. Law-firm charts help you find the section. They lag behind amendments.
  • Using the old threshold. Connecticut and Delaware changed theirs. Your headcount of users may now cross the line.
  • Assuming a nonprofit or a bank is out. Many laws exempt them in whole or in part, and the exemptions differ. Read the exemption section.

How to check whether your state has one

  1. Open the state legislature's official website and find the searchable code. Do not start from a blog.
  2. Search the code for the words "controller" and "personal data." Add "consumer" and "opt out" if you get too many hits.
  3. Open the hit and look for a section on coverage, one on consumer rights and one on enforcement. A law with all three is the kind this post means.
  4. Read the coverage section and note the numbers. Read the enforcement section for the enforcer, penalties, any cure period and any private suit.
  5. Find the start date in the session law or the history note under the section.
  6. Look for newer acts. Search the legislature's site for this year's enacted bills on "data privacy," and check the attorney general's site.
  7. Write down the date you checked. Our guides on running a 50-state survey and citing a statute walk through the method. For the layers of law you will meet, see types of primary law. For why a source can lag, see legal data freshness.

This guide is part of US Law Data: The Complete Guide, a map of where US law comes from and how to use it.

FAQ

Which states have privacy laws?

Many do, and more are passing them. The table lists the ones I could confirm from state code. The section after it names three more that start in 2027 and 2028. For your states, use the check above.

Does my small business have to follow a state privacy law?

It depends on the state. Most laws apply only above a size test, such as the number of residents whose data you handle. Texas and Nebraska use a small business test instead. Some states also apply a few rules to small businesses, such as consent before selling sensitive data. Read the coverage section.

Is there a federal privacy law that covers everything?

The state laws I read point to federal laws for single fields, such as HIPAA, the federal health privacy law, and COPPA, the federal children's online privacy law. This post covers state statutes only.

Can a consumer sue under these laws?

Rarely. Every law in the table puts enforcement in a state office. California's text lets consumers sue after certain data breaches. Maryland's text keeps other remedies open, and Alabama's is silent. Ask counsel before relying on any of these points.

What is a state privacy law tracker, and can I trust one?

A tracker is a list someone keeps up to date. Use it to find the section, then read that section on the state's own site. It is only as current as its last edit.

If you need official statute text behind a workflow like this one, see Vaquill AI's legal API.

Connect our US primary law database.
Every US statute, regulation, constitution, and executive order via REST, MCP or SQL. 5M+ sections, section-level citations, and links to the official source. Plus a free open dataset.
Updated October 5, 202616 min read

New legal AI guides, weekly.

Priyansh Khodiyar

Priyansh Khodiyar

Co-Founder & CTO

Priyansh leads engineering and AI at Vaquill AI: the pipelines that pull statutes, regulations and court rules from every US jurisdiction's official publisher, and the REST API, MCP server and open dataset that serve them.