
Short answer: Many states now have comprehensive state privacy laws, and the list keeps changing. A comprehensive privacy law is a statute (a law passed by a legislature) that gives people rights over their personal data and puts duties on businesses across most industries. The table below covers every state I could confirm from the state's own code, with the citation to read. This post is general information and is not legal advice.
TL;DR
- "Comprehensive" here means rights to see, correct, delete and opt out of the sale of personal data, plus duties for businesses that handle it. A health privacy law or a breach notice law does not count.
- Whether a law covers you depends on thresholds, such as how many residents' data you handle.
- Start dates, cure periods and thresholds are changing in several states during 2026 and 2027.
- California is the only row with an express right for consumers to sue, and only after certain data breaches.
- Do not rely on any list for a count. Use the check at the end of this post.
What I counted as a comprehensive law
The test: a statute must give consumers rights over their personal data and impose duties on the businesses that control it, across industries. A sector law covers one field, such as banking or health care. A breach law only says what to do after data is stolen. Neither is in the table.
I found candidates by running a topic search across every state's statutes through Vaquill AI's API. Then I read each law's coverage, enforcement and start-date text in the state's own code or session law. A session law is the act as the legislature passed it, before it is folded into the code.
State privacy laws in one table
How to use the table: find your states, check the "covers a business that" column against your numbers, then read the enforcement columns. Five terms matter.
- A consumer is a person whose data is collected. Each law defines the term for itself.
- A controller is the business that decides why and how personal data is used.
- A cure period is a window to fix a violation after a warning, before any penalty.
- A private suit is a lawsuit that a consumer files on their own.
- Sensitive data is a list each statute sets out, with things like health details.
I checked every row on October 5, 2026. Where a column is silent, the text I read is silent. Later amendments can change a row, and each law has exemptions the table does not show, so treat it as a starting point.
| State and where to read it | Effective date | Covers a business that | Who enforces it | Cure period and private suits |
|---|---|---|---|---|
| Alabama: Ala. Code § 8-44-1 and following (Alabama Personal Data Protection Act) | May 1, 2027 | Handles data of over 25,000 consumers, or gets over 25% of its total sales income (gross revenue) from selling personal data | Attorney General. Penalty up to $15,000 per violation | 45 days to fix after written notice. The text does not mention private suits |
| California: Cal. Civ. Code § 1798.100 and following (California Consumer Privacy Act) | Jan. 1, 2020. Voter-approved changes Jan. 1, 2023 | Does business in California and meets one test: over $25 million in revenue (adjusted), or buys, sells or shares data of 100,000 or more consumers or households, or gets 50% or more of revenue from selling or sharing data | Privacy Protection Agency and Attorney General | The enforcement sections I read set no cure period, and the agency may allow time to fix. Consumers may sue only after certain data breaches, with 30 days' written notice first |
| Colorado: C.R.S. § 6-1-1301 and following (Colorado Privacy Act) | July 1, 2023 | Handles data of 100,000 consumers a year, or 25,000 while getting revenue or a discount from selling data. Rules for fingerprints and face scans apply at any size | Attorney General and district attorneys | 60-day cure for the child-protection sections only, ending Dec. 31, 2026. No private suit |
| Connecticut: Conn. Gen. Stat. § 42-515 and following (chapter titled Data Privacy and Security) | July 1, 2023. Wider coverage from July 1, 2026 (Public Act 25-113) | Since July 1, 2026: handled data of 35,000 consumers in the prior year, or handles any sensitive data, or offers personal data for sale | Attorney General only | Required 60-day cure ended Dec. 31, 2024. The Attorney General may now choose to offer one. No private suit |
| Delaware: 6 Del. C. § 12D-101 and following (Delaware Personal Data Privacy Act) | Jan. 1, 2025 | Handles data of 35,000 consumers, or 10,000 with over 20% of revenue from selling data. From Jan. 1, 2027 (House Bill 380): 10,000, or 5,000 with over 20% of revenue from sales, plus third parties that acquire data from a controller | Department of Justice | Required 60-day cure in 2025 only. Optional since 2026. No private suit |
| Florida: Fla. Stat. § 501.701 and following (Florida Digital Bill of Rights) | July 1, 2024 | Mostly "controllers" with over $1 billion in global revenue that also run a large ad business, a smart speaker service, or an app store with 250,000 or more apps. A separate rule bars any for-profit business from selling sensitive data without consent | Department of Legal Affairs. Penalty up to $50,000 per violation | The department may grant a 45-day cure. The text says it creates no private suit |
| Indiana: Ind. Code art. 24-15 | Jan. 1, 2026 | Handles data of 100,000 Indiana consumers, or 25,000 with over 50% of revenue from selling data | Attorney General only. Penalty up to $7,500 per violation | 30-day cure. No private suit |
| Iowa: Iowa Code ch. 715D | Jan. 1, 2025 | Handles data of 100,000 consumers, or 25,000 with over 50% of revenue from selling data | Attorney General only. Penalty up to $7,500 per violation | 90-day cure. No private suit |
| Kentucky: KRS 367.3611 to 367.3629 | Jan. 1, 2026. A 2026 act adds rules from July 1, 2027 | Handles data of 100,000 consumers, or 25,000 with over 50% of revenue from selling data | Attorney General only. Up to $7,500 per continued violation | 30-day cure. No private suit |
| Maryland: Md. Code, Com. Law § 14-4701 and following | Oct. 1, 2025 | Handles data of 35,000 consumers, or 10,000 with over 20% of revenue from selling data | Enforced under Title 13 of the same article, Maryland's general law against unfair or misleading business conduct | State may give at least 60 days to cure, for violations through April 1, 2027. The consumer-suit section of Title 13 is excluded, and the text says other remedies are not blocked |
| Minnesota: Minn. Stat. §§ 325M.10 to 325M.21 (Minnesota Consumer Data Privacy Act) | July 31, 2025 (colleges under the Office of Higher Education: July 31, 2029) | Handles data of 100,000 consumers, or 25,000 with over 25% of revenue from selling data. Small businesses still need consent to sell sensitive data | Attorney General. Penalty up to $7,500 per violation | The 30-day cure ended Jan. 31, 2026. No private suit |
| Montana: Mont. Code Ann. §§ 30-14-2801 to 30-14-2820 (Consumer Data Privacy Act) | Oct. 1, 2024 | Handles data of 25,000 consumers, or 15,000 with over 25% of revenue from selling data | Attorney General only | No cure period in the enforcement section. No private suit |
| Nebraska: Neb. Rev. Stat. §§ 87-1101 to 87-1130 (Data Privacy Act) | Jan. 1, 2025 | Sells or processes personal data and is not a small business under the federal Small Business Act | Attorney General. Penalty up to $7,500 per violation | 30-day cure. No private suit |
| New Hampshire: N.H. Rev. Stat. ch. 507-H | Jan. 1, 2025 | Handled data of 35,000 consumers in a year, or 10,000 with over 25% of revenue from selling data | Attorney General only | 60-day cure required in 2025, optional since. No private suit |
| New Jersey: N.J. Stat. § 56:8-166.4 and following (P.L. 2023, c. 266) | 365th day after enactment (enacted Jan. 16, 2024, so Jan. 15, 2025) | Handles data of 100,000 consumers, or 25,000 while getting revenue or a discount from selling data | Only the Attorney General may enforce it | 30-day cure for the first 18 months only. No private suit |
| Oregon: ORS 646A.570 to 646A.589 | July 1, 2024 (charities with 501(c)(3) federal tax-exempt status: July 1, 2025) | Handles data of 100,000 consumers, or 25,000 with 25% or more of revenue from selling data. Vehicle makers and affiliates handling vehicle-use data at any size | Attorney General only. Penalty up to $7,500 per violation | A 2025 cure window has ended and the current text has none. No private suit |
| Rhode Island: R.I. Gen. Laws § 6-48.1-1 and following (Data Transparency and Privacy Protection Act) | Jan. 1, 2026 | For-profit businesses that handled data of 35,000 customers, or 10,000 with over 20% of revenue from selling data | Attorney General has sole enforcement | No cure period in the enforcement section. No private suit |
| Tennessee: Tenn. Code Ann. § 47-18-3301 and following (Tennessee Information Protection Act) | July 1, 2025 | Has over $25 million in revenue and handles data of 175,000 consumers, or 25,000 with over 50% of revenue from selling data | Attorney General. Penalty up to $7,500 per violation. For a willful or knowing violation, a court may triple the damages | 60-day cure. No private suit, class actions included |
| Texas: Tex. Bus. & Com. Code ch. 541 | July 1, 2024. Browser and device opt-out rule: Jan. 1, 2025 | Sells or processes personal data and is not a small business under the U.S. Small Business Administration's definition | Attorney General. Penalty up to $7,500 per violation | 30-day cure. No private suit |
| Utah: Utah Code title 13, ch. 61 | Dec. 31, 2023 | Has $25 million or more in revenue and handles data of 100,000 consumers, or 25,000 with over 50% of revenue from selling data | Attorney General. Actual damages to the consumer plus up to $7,500 per violation | 30-day cure. No private suit |
| Virginia: Va. Code § 59.1-575 and following | Jan. 1, 2023 | Handles data of 100,000 consumers, or 25,000 with over 50% of revenue from selling data | Attorney General only. Penalty up to $7,500 per violation | 30-day cure. No private suit |
Connecticut's row comes from Public Act 25-113, because the state's online code page I read had not yet folded in the July 2026 changes. Delaware's 2027 change is House Bill 380, signed September 2, 2026, and you can read it on the Delaware legislature's site. The summary printed on that page was written when the bill was introduced and cites a different threshold, so use the signed version's numbers. Kentucky's is 2026 Ky. Acts ch. 118. Start dates come from each session law. Coverage and enforcement come from the codified text, except Connecticut's coverage, which comes from the public act.
Laws that are not in the table yet
The table holds laws I could read in the state code. Oklahoma, Louisiana and Vermont have each passed a comprehensive law that starts later. I read the acts on their legislatures' sites, such as Oklahoma's bill page. Oklahoma's Senate Bill 546 and Louisiana's Act 502 start January 1, 2027. Vermont's Act 145 starts January 1, 2028. I left them out because I could not read their codified text, which is the version that sits in the state's code.
What they have in common
These laws follow a shared pattern. New Hampshire's section on consumer rights is typical. It lets a consumer confirm whether a business holds their data, correct it, delete it, get a copy, and opt out of targeted ads, the sale of the data, or automated decisions with serious effects. Many of the laws also require a privacy notice and a written risk review, called a data protection assessment, for riskier uses. Most set special rules for sensitive data, which is a list the statute sets out.
Here is a real operative passage. Virginia's coverage section, Va. Code § 59.1-576(A), reads:
This chapter applies to persons that conduct business in the Commonwealth or produce products or services that are targeted to residents of the Commonwealth and that (i) during a calendar year, control or process personal data of at least 100,000 consumers or (ii) control or process personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal data.
You can read it at the Virginia code site.
Where they differ, and what matters most if you sell nationwide
Who is covered. Virginia needs 100,000 consumers. Maryland needs 35,000. Delaware moves to 10,000 in 2027. Texas and Nebraska ask whether you are a small business instead of counting people. Florida puts its main duties on companies with over $1 billion in global revenue. Connecticut now covers any business that handles sensitive data or offers data for sale.
Start dates and moving rules. Alabama starts in 2027. Delaware and Kentucky change in 2027. Connecticut changed in July 2026. A table from last spring may be wrong.
Cure periods. A cure period lets you fix a problem after a warning. Virginia, Texas, Indiana and Utah keep one in their text with no end date. Minnesota's and Oregon's have ended. Rhode Island and Montana show none in their enforcement sections. If you plan to rely on a cure period, read the enforcement section for that state itself.
Who can sue. Every law in the table sends enforcement to a state office. California's text lets consumers sue, and only after certain data breaches. Maryland's text keeps other remedies open, so ask counsel what that means there. Alabama's text says nothing either way.
Who counts as a consumer. Virginia says a consumer acts "only in an individual or household context" and excludes people acting "in a commercial or employment context." California defines a consumer as "a natural person who is a California resident." That difference decides whether employee and business-contact data is in scope.
Here are thresholds in practice. A company with data on 40,000 Maryland residents is covered in Maryland. A company with data on 12,000 Delaware residents is not covered today, unless it earns over 20% of revenue from selling data, but will be from January 1, 2027.
The safest national approach is to meet the strictest version of each rule you are subject to. A lawyer can tell you which rules apply to you.
Common mistakes
- Counting states. A number goes stale in weeks. Check the states where your customers live.
- Reading a summary instead of the statute. Law-firm charts help you find the section. They lag behind amendments.
- Using the old threshold. Connecticut and Delaware changed theirs. Your headcount of users may now cross the line.
- Assuming a nonprofit or a bank is out. Many laws exempt them in whole or in part, and the exemptions differ. Read the exemption section.
How to check whether your state has one
- Open the state legislature's official website and find the searchable code. Do not start from a blog.
- Search the code for the words "controller" and "personal data." Add "consumer" and "opt out" if you get too many hits.
- Open the hit and look for a section on coverage, one on consumer rights and one on enforcement. A law with all three is the kind this post means.
- Read the coverage section and note the numbers. Read the enforcement section for the enforcer, penalties, any cure period and any private suit.
- Find the start date in the session law or the history note under the section.
- Look for newer acts. Search the legislature's site for this year's enacted bills on "data privacy," and check the attorney general's site.
- Write down the date you checked. Our guides on running a 50-state survey and citing a statute walk through the method. For the layers of law you will meet, see types of primary law. For why a source can lag, see legal data freshness.
This guide is part of US Law Data: The Complete Guide, a map of where US law comes from and how to use it.
FAQ
Which states have privacy laws?
Many do, and more are passing them. The table lists the ones I could confirm from state code. The section after it names three more that start in 2027 and 2028. For your states, use the check above.
Does my small business have to follow a state privacy law?
It depends on the state. Most laws apply only above a size test, such as the number of residents whose data you handle. Texas and Nebraska use a small business test instead. Some states also apply a few rules to small businesses, such as consent before selling sensitive data. Read the coverage section.
Is there a federal privacy law that covers everything?
The state laws I read point to federal laws for single fields, such as HIPAA, the federal health privacy law, and COPPA, the federal children's online privacy law. This post covers state statutes only.
Can a consumer sue under these laws?
Rarely. Every law in the table puts enforcement in a state office. California's text lets consumers sue after certain data breaches. Maryland's text keeps other remedies open, and Alabama's is silent. Ask counsel before relying on any of these points.
What is a state privacy law tracker, and can I trust one?
A tracker is a list someone keeps up to date. Use it to find the section, then read that section on the state's own site. It is only as current as its last edit.
If you need official statute text behind a workflow like this one, see Vaquill AI's legal API.
New legal AI guides, weekly.
Further Reading
State Consumer Protection Laws (UDAP Statutes) Explained: 12 States Side by Side
Read postDeepfake Laws by State: What Is Actually on the Books (14 States)
Read postState Data Breach Notification Laws: Where Each One Lives and What It Requires (10 States)
Read postHow to Run a 50-State Survey: A Step-by-Step Guide
Read postUSC vs CFR: What the Abbreviations Mean and How They Differ
Read postWhat Does Codified Mean in Law? A Plain Guide With Real Examples
Read post
Co-Founder & CTO
Priyansh leads engineering and AI at Vaquill AI: the pipelines that pull statutes, regulations and court rules from every US jurisdiction's official publisher, and the REST API, MCP server and open dataset that serve them.