United States map, representing the patchwork of different state privacy laws in effect in 2026

US State Privacy Laws 2026: Does Your State Protect You?

Quick Answer: There is still no comprehensive federal privacy law in the United States, so whether you have meaningful legal rights over your personal data depends almost entirely on which state you live in. As of 2026, 20 states have comprehensive privacy laws in effect — California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and Washington — with Indiana, Kentucky, and Rhode Island joining the list on January 1, 2026. California’s law remains the strongest and the only one offering residents a limited private right of action. If you live in one of the roughly 30 states without a comprehensive privacy law, you generally have no state-level right to access, correct, or delete the personal data companies hold on you.

Why There’s No Federal Privacy Law

Unlike the European Union’s GDPR, the United States has never passed a comprehensive federal data privacy law covering the private sector broadly. The most recent serious attempt, the American Privacy Rights Act (APRA), stalled in Congress in 2024 and hasn’t been revived with meaningful momentum since. In the resulting vacuum, states have moved individually — starting with California’s Consumer Privacy Act (CCPA) in 2020, followed by Virginia’s Consumer Data Protection Act in 2021 and Colorado’s Consumer Privacy Act in 2022 — creating the patchwork of state-by-state protection that defines the US privacy landscape in 2026.

That patchwork means your actual privacy rights as a consumer can change meaningfully just by crossing a state line, in a way that’s genuinely unusual compared to most other areas of consumer protection law. It’s a dynamic that shows up elsewhere in tech regulation too — our coverage of the FTC’s vacated click-to-cancel rule covers a similar pattern, where the absence of durable federal action has pushed meaningful consumer protection down to the state level.

The pace of state-level action has also been accelerating rather than slowing. Between 2023 and 2026 alone, nineteen additional states enacted comprehensive privacy legislation on top of California’s original framework — a remarkably fast expansion for state-by-state legislation, driven partly by advocacy groups pushing model legislation across multiple statehouses simultaneously, and partly by states watching neighboring states adopt similar frameworks and following suit to avoid becoming outliers.

Which States Have Privacy Laws in 2026

State Law Effective Date
California CCPA / CPRA 2020 (CPRA: 2023)
Virginia Consumer Data Protection Act 2023
Colorado Colorado Privacy Act 2023
Connecticut Connecticut Data Privacy Act 2023
Utah Utah Consumer Privacy Act 2023
Iowa, Delaware, Nebraska, New Hampshire, New Jersey State-specific acts 2024-2025
Texas, Oregon, Montana, Tennessee State-specific acts 2024
Maryland, Minnesota State-specific acts 2025
Indiana, Kentucky, Rhode Island State-specific acts January 1, 2026
Washington My Health My Data Act (health-specific) 2023

Two more states have laws enacted but not yet active as of this writing: Oklahoma’s law takes effect in January 2027, and Alabama’s Personal Data Protection Act — making Alabama the 21st state to enact a comprehensive framework — follows in May 2027. The list keeps growing; checking the IAPP US State Privacy Legislation Tracker is the most reliable way to confirm the current, up-to-date count, since new laws and amendments continue moving through state legislatures regularly.

United States map, representing the patchwork of different state privacy laws in effect in 2026

What These Laws Actually Give You

Despite differing in scope and strength, most state privacy laws share a common core of consumer rights, largely because eighteen of the twenty follow a model that originated with Virginia’s law. Typical rights include:

  • Right to access — request confirmation of what personal data a company holds about you.
  • Right to correct — fix inaccurate personal information a company has on file.
  • Right to delete — request deletion of your personal data, with some exceptions (legal recordkeeping requirements, for instance).
  • Right to opt out — of the sale of your personal data and, in most states, of targeted advertising and certain automated profiling.
  • Right to data portability — receive a copy of your data in a portable, commonly used format.

Companies typically have 30 to 45 days to respond to a request, depending on the state, and most laws let a business deny a request it considers “manifestly unfounded or excessive” — a standard broad enough that companies retain real discretion in practice. Verification requirements for these requests vary considerably too: some states accept simple email confirmation, while others require more rigorous identity verification, including notarization or government ID in certain circumstances.

California: The Strongest Law

California’s CCPA, expanded by the California Privacy Rights Act (CPRA), remains the most comprehensive and detailed privacy framework of any state, and the only one that gives residents even a limited private right of action — meaning Californians can, in specific circumstances (primarily certain data breaches), sue a company directly rather than relying solely on the state Attorney General to enforce the law. Every other state’s law is enforced exclusively through the state Attorney General’s office, which means individual residents in those states generally can’t bring their own lawsuit over a privacy violation, only file a complaint and hope for regulatory action.

California also expanded its data broker registration requirements in August 2026, mandating more detailed disclosures from data brokers and streamlining the deletion request process — part of a broader pattern where California continues to add incremental strengthening to an already-comprehensive framework, while most other states largely hold steady once their initial law takes effect.

Maryland: The Second-Strongest

Maryland’s law is frequently cited by privacy analysts as the second-strongest in the country, largely because of two specific provisions few other states match: it bans the sale of sensitive data outright, rather than merely requiring an opt-out mechanism the way most other states do, and it limits data collection to what’s “reasonably necessary” for the service being provided — a data-minimization standard that mirrors the EU’s GDPR more closely than any other US state law. For residents specifically concerned about sensitive categories of data (health information, precise location, biometric data), Maryland’s framework offers real, structural protection rather than just an opt-out button buried in a privacy settings menu.

Utah: The Weakest

Utah’s Consumer Privacy Act is generally regarded as the lightest-touch law among the 20 currently in effect. It offers the core rights — access, deletion, opt-out — but with narrower obligations on businesses, fewer data-minimization requirements, and less aggressive enforcement mechanisms than states like California or Maryland. For a business, Utah’s law is often the easiest to comply with among all 20; for a consumer, it provides real but comparatively modest protection relative to what residents of stronger-law states have available to them.

Person holding a smartphone with a VPN privacy service enabled, representing exercising data privacy rights under state privacy laws in 2026

Global Privacy Control: The One Setting Worth Turning On

Global Privacy Control (GPC) is a browser- or device-level signal that automatically tells every website you visit that you’re opting out of the sale and sharing of your personal data and targeted advertising — a single setting that, in states that legally require companies to honor it, effectively exercises your opt-out rights across every site you visit without submitting a separate request to each one individually. A growing number of state laws — including Colorado, Connecticut, Texas, Oregon, Montana, Delaware, and New Jersey — legally require covered businesses to detect and honor GPC signals specifically.

GPC is built directly into privacy-focused browsers like Brave and Firefox (with an extension), and can be enabled through browser extensions on Chrome and other mainstream browsers as well. It’s a genuinely low-effort way to exercise real legal rights automatically, at least for residents of states that mandate compliance with it — worth turning on regardless of which state you live in, since it costs nothing and simply has no legal effect in states without a GPC requirement.

Setting it up takes only a few minutes: Brave has GPC enabled by default with no configuration needed, Firefox users can enable it through Settings under Privacy & Security, and Chrome, Edge, and Safari users need a dedicated extension since none of those browsers currently build the signal in natively. Once enabled, the signal applies automatically to every site visited in that browser going forward — there’s no per-site action required, and no way to accidentally miss a site the way a manual state-by-state opt-out request could.

Special Protections for Children’s Data

Several states have specifically strengthened protections for minors’ data over the past two years, layering additional requirements on top of the general consumer rights described above. Connecticut and Arkansas, for instance, have both added age-appropriate design code requirements and tighter restrictions specifically on the sale and use of minors’ personal data. These provisions typically require companies to apply stricter default privacy settings for accounts they know or reasonably should know belong to a minor, and in some cases prohibit targeted advertising to minors entirely regardless of consent.

This state-level push on children’s privacy connects to a broader wave of regulatory and legal attention on the same issue nationally — Meta’s $16.7 billion settlement over child-targeted platform design and TikTok’s $400 million COPPA settlement both reflect the same underlying concern driving these state-level age-appropriate design requirements: that platforms have historically had strong commercial incentives to collect and monetize children’s data with insufficient guardrails, and that neither company self-regulation nor existing federal law (COPPA, largely unchanged since 1998) has kept pace with how platforms actually operate today.

How Multi-State Compliance Actually Works for Businesses

For a business operating across the country, the honest reality of complying with 20 different, mostly-similar-but-not-identical privacy laws is that most opt for a unified approach rather than building 20 separate compliance systems. The most common practical strategy: adopt the requirements of the strictest applicable state (usually California or Maryland) as a company-wide baseline, then layer on state-specific exceptions only where genuinely necessary. That approach is generally cheaper and less error-prone than maintaining a patchwork of state-specific systems internally, and it has the side effect of giving residents of weaker-law states — Utah, for instance — many of the practical protections of a stronger state’s law, even though they have no legal entitlement to them.

That said, this isn’t universal — smaller businesses, or those operating in a genuinely narrow single-state footprint, sometimes do build state-specific compliance rather than adopting a strictest-common-denominator approach, particularly if the cost of extending stronger protections company-wide outweighs the administrative cost of state-by-state compliance. There’s no reliable way to know from the outside which approach a specific company has taken without checking its actual privacy policy, which is generally the most direct way to confirm what rights you actually have with a given company regardless of what your state’s law technically requires.

What Counts as “Comprehensive”

It’s worth distinguishing comprehensive state privacy laws from narrower, sector-specific ones. HIPAA governs health data specifically, at the federal level, regardless of state. Washington’s My Health My Data Act is a state law but focused specifically on health-related data rather than personal data broadly. Florida’s law is sometimes counted among the 20 “comprehensive” state laws and sometimes excluded, since its scope and applicability thresholds are considerably narrower than states like California or Virginia — which is part of why different sources report slightly different total counts (19, 20, or 21 depending on methodology and timing).

None of these narrower or sector-specific laws function as a substitute for a comprehensive consumer privacy law — they cover a specific category of data or a specific industry, rather than giving residents broad rights over all the personal data companies collect about them across every context.

What If Your State Has No Privacy Law?

Roughly 30 states still have no comprehensive privacy law in effect as of 2026, meaning residents there have no state-created legal right to access, correct, or delete the personal data companies hold on them. That doesn’t mean zero protection exists — federal sector-specific laws (HIPAA for health data, the Fair Credit Reporting Act for credit data, COPPA for children’s data) still apply regardless of state, and companies operating nationally often extend privacy-law compliance to all users rather than building state-specific systems, simply because it’s operationally simpler than maintaining separate rules for 20 different jurisdictions.

Practically, if you live in a state without a comprehensive privacy law, a few tools remain available regardless: enabling Global Privacy Control (which some companies honor voluntarily even where not legally required), directly emailing a company’s privacy team to request data deletion (many will comply as a courtesy even without a legal mandate), and checking whether a specific company you’re concerned about is headquartered in or does substantial business in a state with a strong law, since some companies apply that state’s stricter standard to all users company-wide rather than segmenting by residency.

How to Actually Exercise Your Rights

  • Check your state’s specific law first. Rights, response windows, and verification requirements vary meaningfully, so knowing your state’s specific framework before submitting a request saves time.
  • Use a company’s dedicated privacy request page. Most larger companies now maintain a specific privacy rights portal separate from general customer support, required under most state laws.
  • Enable Global Privacy Control. A one-time browser setting that automatically exercises opt-out rights across every site you visit, in states that legally require compliance.
  • Keep records of your requests. Screenshots and confirmation emails matter if a company fails to respond within the legally required window and you need to escalate to your state Attorney General.
  • Escalate to your state Attorney General if ignored. Since most states enforce these laws exclusively through the AG’s office, filing a complaint there is generally the only enforcement path available to an individual resident outside California.

Frequently Asked Questions

Does my state have a data privacy law?

As of 2026, 20 states have comprehensive privacy laws: California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and Washington. If your state isn’t on this list, you generally don’t have state-created privacy rights, though federal sector-specific laws may still apply.

Is there a federal privacy law in the US?

No. The United States has no comprehensive federal privacy law covering the private sector broadly. The most recent serious attempt, the American Privacy Rights Act, stalled in Congress in 2024.

Which state has the strongest privacy law?

California’s CCPA/CPRA is widely considered the strongest, and the only state law offering residents a limited private right of action. Maryland is generally regarded as the second-strongest, with strict data minimization requirements and an outright ban on selling sensitive data.

What is Global Privacy Control?

Global Privacy Control (GPC) is a browser or device signal that automatically communicates an opt-out of data sale and targeted advertising to every website you visit. Several states, including Colorado, Connecticut, Texas, Oregon, Montana, Delaware, and New Jersey, legally require covered businesses to honor it.

Can I sue a company for violating my state’s privacy law?

In most states, no — enforcement is handled exclusively by the state Attorney General. California is the exception, offering residents a limited private right of action, primarily for certain data breaches.

What states are getting new privacy laws next?

Oklahoma’s comprehensive privacy law takes effect in January 2027, and Alabama’s Personal Data Protection Act follows in May 2027, which will bring the total number of states with comprehensive privacy laws past 20.

Do state privacy laws protect children more strictly?

Yes, several states have added specific provisions for minors’ data. Connecticut and Arkansas, for example, have added age-appropriate design code requirements and tighter restrictions on selling or using children’s personal data, on top of the general consumer rights that apply to all residents.

Key Takeaways

  • There is still no comprehensive federal privacy law in the US — your rights depend almost entirely on which state you live in.
  • 20 states have comprehensive privacy laws in effect as of 2026, with Indiana, Kentucky, and Rhode Island joining on January 1, 2026.
  • California remains the strongest law and the only one with a private right of action; Maryland ranks second-strongest, and Utah is generally viewed as the lightest.
  • Global Privacy Control is a free, one-time browser setting that automatically exercises opt-out rights in states that legally require compliance.
  • Residents of roughly 30 states without a comprehensive privacy law have no state-created right to access, correct, or delete their personal data, though federal sector-specific laws may still apply.

Leave a Comment

Your email address will not be published. Required fields are marked *