Expert legal support
Address any regulatory question — from GDPR to local frameworks.
Regulatory compliance hub
Ketch's comprehensive resources on GDPR, CCPA and all major regulations in the US and worldwide.
Learn why Ketch is built for privacy and legal teams with
Jack Carvel
Data Protection Officer at Ketch

Statute/bill legislative status:
| Regulations | Status | Unique features | Penalties | Effective | Details |
|---|---|---|---|---|---|
| CCPA/CPRA California Consumer Privacy Act | Effective | Gives Californians strong privacy rights (access to personal data, deletion, and the right to opt out of data sales)—rights that were groundbreaking when introduced. Defines "sale" broadly to include sharing personal information for any valuable consideration, not just monetary transactions. | Up to $7,500 per intentional violation. | January 1, 2020 | Learn More |
| CPA Colorado Privacy Act | Effective | Requires businesses to provide a user-friendly global opt-out mechanism for data sales and targeted advertising, a first among U.S. state privacy laws. | Up to $20,000 per violation | July 1, 2023 | Learn More |
| VCDPA Virginia Consumer Data Protection Act | Effective | Adopts a GDPR-like model, clearly distinguishing between "controllers" and "processors," setting specific obligations for each, requires opt-in consent for processing sensitive data such as race, health, and precise geolocation, offering stronger protections in these areas compared to many U.S. state privacy laws. | Up to $7,500 per violation. | January 1, 2023 | Learn More |
| INCDPA Indiana Consumer Data Protection Act | Effective | Targets large-scale data processors with significant revenue or data volume with robust data protection and breach notification rules. | Up to $7,500 per violation. | January 1, 2026 | Learn More |
| KCDPA Kentucky Consumer Data Protection Act | Effective | Provides comprehensive data rights and requires agreements outlining processors’ data-handling obligations. | Up to $7,500 per violation. | January 1, 2026 | Learn More |
| RIDTPPA Rhode Island Data Transparency and Privacy Protection Act | Effective | Demands clear privacy disclosures for consumers and allows consumers to opt out of data sales and targeted advertising. | Up to $10,000 per violation. | January 1, 2026 | Learn More |
| MODPA Maryland Online Data Privacy Act | Effective | Covers various types of online data collection and use and strengthens privacy rules for minors under 16. | Up to $10,000 per violation. | October 1, 2025 | Learn More |
| MNCDPA Minnesota Consumer Data Privacy Act | Effective | Requires opt-in consent for processing sensitive personal data and imposes strong data security obligations on businesses. | Up to $7,500 per violation. | July 31, 2025 | Learn More |
| TIPA Tennessee Information Protection Act | Effective | Allows consumers to opt out of targeted advertising and data sales and strengthens breach notification requirements. | Up to $7,500 per violation. | July 1, 2025 | Learn More |
| NJDPA New Jersey Data Privacy Act | Effective | Requires businesses to process opt-out requests within 15 days, faster than most state privacy laws and applies to nonprofits and educational institutions. | Up to $10,000 per violation. | January 15, 2025 | Learn More |
| DPDPA Delaware Personal Data Privacy Act | Effective | Applies to certain nonprofit organizations, and requires parental consent for processing personal data of consumers under 18. | Up to $10,000 per violation. | January 1, 2025 | Learn More |
| ICDPA Iowa Consumer Data Protection Act | Effective | Requires businesses to provide clear notice and an opt-out option and limits consumer rights to correct inaccuracies. | Up to $7,500 per violation. | January 1, 2025 | Learn More |
| NDPA Nebraska Data Privacy Act | Effective | Covers businesses of all sizes, including those not classified under the federal Small Business Act. | Up to $7,500 per violation. | January 1, 2025 | Learn More |
| NHPA New Hampshire Privacy Act | Effective | Requires businesses to honor universal opt-out signals, including the Global Privacy Control (GPC), and mandates clear, accessible privacy notices. | Up to $5,000 per violation. | January 1, 2025 | Learn More |
| MCDPA Montana Consumer Data Protection Act | Effective | Mandates assessments for processing activities that pose significant consumer risks. Grants access, correction, deletion, and data portability rights. | Up to $7,500 per violation. | October 1, 2024 | Learn More |
| OCPA Oregon Consumer Privacy Act | Effective | Applies to certain nonprofit organizations, expanding its scope beyond for-profit entities. | Up to $7,500 per violation. | July 1, 2024 | Learn More |
| TDPSA Texas Data Privacy And Security Act | Effective | Exempts "small businesses" as defined by the U.S. Small Business Administration. | Up to $7,500 per violation. | July 1, 2024 | Learn More |
| UCPA Utah Consumer Privacy Act | Effective | Higher applicability thresholds than most U.S. state privacy laws, applying only to businesses generating $25 million+ in revenue and processing data of 100,000+ consumers. | Up to $7,500 per violation. | December 31, 2023 | Learn More |
| CTDPA Connecticut Data Privacy Act | Effective | Strong opt-out rights with extended grace period | Up to $5,000 per violation. | July 1, 2023 | Learn More |
| APDPA Alabama Personal Data Protection Act | Signed | Lowest people-based threshold (25,000) of any state law + highest penalty cap + no DPA required + permanent cure period | Up to $15,000 per violation | May 1, 2027 | |
| LDPA Louisiana Data Privacy Act | Signed | CCPA-style thresholds + GPC signal required + cure period expires after 7 months | Up to $5,000 per violation | January 1, 2027 | |
| OKCDPA Oklahoma Consumer Data Privacy Act | Signed | Business-friendly Virginia/Texas hybrid with permanent cure period and nonprofit exemption | Up to $7,500 per violation | January 1, 2027 | |
| Michigan Personal Data Privacy Act | Introduced | — | — | — | |
| North Carolina | Introduced | — | — | — | |
| PCDPA Pennsylvania Consumer Data Privacy Act | Introduced | — | — | — | |
| WDPA Wisconsin | Introduced | — | — | — | |
| Ohio Ohio Personal Privacy Act X | Inactive | — | — | — | |
| Wyoming | Inactive | — | — | — |
| Regulations | Status | Unique features | Penalties | Effective | Details |
|---|---|---|---|---|---|
| GDPR (European Union) General Data Protection Regulation | Effective | Applies to businesses worldwide if they process EU residents' data. | Up to €20 million | May 25, 2018 | Learn More |
| EU AI Act EU Artificial Intelligence Act | Effective | First comprehensive, binding AI regulation from a major regulator. Risk-tiered obligations plus Article 10 data-governance rules for high-risk training data, with extraterritorial reach like GDPR. | Up to €35 million or 7% of worldwide annual turnover. | August 1, 2024 | Learn More |
| Law 25 (Canada) Quebec residents | Effective | In addition to explicit consent requirement, organizations must appoint a privacy officer. | Up to CAD $25 million or 4% of global annual revenue | September 22, 2023 | |
| LGPD (Brazil) General Personal Data Protection Law | Effective | Covers all personal data processing, including offline data, overseed by National privacy authority (ANPD). | Up to R$50 million per violation. | August 1, 2021 | |
| DPA (United Kingdom) The Data Protection Act | Effective | Implements GDPR-like provisions with UK-specific adjustments post-Brexit. | Up to £17.5 million or 4% of global annual revenue. | May 25, 2018 | |
| PIPEDA (Canada) Personal Information Protection and Electronic Documents Act | Effective | Requires businesses to ensure adequate data protection when transferring data internationally. | Up to CAD $100,000 per violation. | April 13, 2000 |
Regulatory guidance on-demand
Comprehensive expert legal support and GDPR representative services to help you meet privacy regulatory obligations with confidence.
Address any regulatory question — from GDPR to local frameworks.
Expertise across all major privacy and AI laws.
Recommendations matched to your unique needs.
One platform, every regulation
Most privacy software tools make data privacy law compliance a costly game of add-on modules for each new law. We think that’s a ridiculous expectation in today’s changing regulatory landscape.
We’ve developed privacy primitives like processing purpose, legal bases, and rights to customize and reassemble for each jurisdiction—build your own, or start from pre-configured templates.

Summer 2026 Leader
Rated 4.6/5 on G2
Top rated consent management platform based on 170+ reviews on G2.
See Reviews on G2Continue reading
Next step
Start free for the CMP path, or book a demo to map every regulation across the full platform.
Get started in less than 5 min