See what matters to your business

US privacy law atlas. Every law that reaches you

A working reference to US privacy law for privacy and compliance teams at any business operating in the US, wherever it's headquartered: every comprehensive state law, the federal sectoral regimes, and the specialty state laws that carry real obligations and enforcement.

Scope in seven questions

Answer what you know about your business and the atlas narrows to the laws that reach you, with the obligations each one generates.

Every law explained

Comprehensive state statutes, the federal sectoral regimes, and the specialty laws beside them, each with its thresholds, rights, cure period, and enforcer.

Traced to the source

Obligations cite the section they come from, and the enforcement record quotes regulators and courts verbatim.

24

State comprehensive laws enacted

20

Laws in effect today

4

Upcoming laws

13

Federal regimes

13

Specialty categories

Scope your obligations

Answer what you know about your business and the atlas narrows to the laws that reach you, listing the obligations they generate, each traced to the statute or regulation it comes from.

Where do your consumers live?

Select every state where you have consumers, employees, or web traffic.

Your entries are not stored or shared. The scope engine runs entirely in your browser.

Cross-cutting mechanics

What enforcement is actually about

Before the state-by-state detail: the mechanics regulators and courts have already made concrete. Statutory, regulatory, and case language is quoted verbatim, with each claim linked to its official source.

View Enforcement Analysis

"Sale" reaches far beyond cash for data

Source

Cal. Civ. Code § 1798.140 (California Legislative Information)

Under Cal. Civ. Code § 1798.140(ad), "sell" covers disclosing or making personal information available to a third party "for monetary or other valuable consideration." Section 1798.140(ah) separately defines "share" as the same range of disclosures made for cross-context behavioral advertising, regardless of whether any money changes hands. Most ad tech relationships trigger the "share" definition well before they would satisfy the narrower "sale" test.

The definitions cover both online data (pixels, cookies, ad-tech identifiers) and offline data (account records, email and phone identifiers moved by file transfer or API).

Beyond consumer rights and consent

Rights fulfilment is the visible half of a privacy programme. These are the standing duties that apply whether or not a single consumer ever contacts you, and they are where assessments and enforcement increasingly land.

Data minimization

Collect only what the stated purpose actually requires. This is a standing limit on collection, not a disclosure duty, and consent does not lift it.

“A controller shall limit the collection of personal data to what is adequate, relevant and reasonably necessary in relation to the purposes for which such data is processed, as disclosed to the consumer.”

Connecticut Data Privacy Act § 6(a)(1)

California measures the same idea by proportionality: collection, use, retention and sharing must each be “reasonably necessary and proportionate” to the disclosed purpose, and that test applies to consented purposes too. Colorado uses “adequate, relevant, and limited to what is reasonably necessary.” Maryland is the strict outlier: collection is limited to what is reasonably necessary to provide the specific product the consumer requested, and consent cannot widen it.

Purpose limitation and secondary use

Processing for a purpose you did not disclose requires fresh consent. This is the obligation most often broken quietly, when a dataset collected for one reason is reused for another.

“A controller shall not process personal data for purposes that are neither reasonably necessary to nor compatible with the disclosed purposes for which such personal data is processed, as disclosed to the consumer, unless the controller obtains the consumer’s consent.”

Virginia Consumer Data Protection Act § 59.1-578(a)(2)

Colorado and Connecticut carry near-identical language. California frames it around the consumer's reasonable expectations at the time of collection rather than the disclosed purpose, which is a different test that can reach further.

Retention

No state requires a retention schedule. Every state requires you to be able to justify how long you keep data, which in practice means you need one.

“Reasonably necessary and proportionate to achieve the purpose(s) for which the information was collected.”

California, 11 CCR § 7002

California sets three factors for the proportionality analysis: the minimum data necessary to achieve the purpose, the possible negative impacts on consumers, and the safeguards that address those impacts. Virginia and Connecticut require retention to “take into account the nature and purpose or purposes of such collection, use, or retention.”

Security

A substantive safeguards duty, scaled to the data. In California it now carries an audit obligation on top.

“A controller shall establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data. Such data security practices shall be appropriate to the volume and nature of the personal data at issue.”

Virginia Consumer Data Protection Act § 59.1-578(a)(3)

California adds an annual cybersecurity audit where processing presents significant risk to consumers' security, with the threshold turning on revenue derived from selling or sharing personal information or on gross revenue. Colorado requires measures appropriate to the volume, scope and nature of the data and to the nature of the business.

Risk and data protection assessments

Documented before the processing starts, not after. This is the obligation practitioners miss most often in the Virginia-model states.

A controller must conduct and document an assessment for targeted advertising, the sale of personal data, processing of sensitive data, and profiling that presents a reasonably foreseeable risk of unfair or deceptive treatment, unlawful disparate impact, financial, physical or reputational injury, intrusion upon solitude, or other substantial injury.

Virginia Consumer Data Protection Act § 59.1-580

California runs a separate and heavier track: a risk assessment before selling or sharing personal information, before processing sensitive personal information, and, under a separate paragraph of the same section, access and opt-out rights around automated decision-making technology and profiling. A certification and an abridged assessment go to the agency within 24 months and annually after that, and the agency may demand the full version. Virginia and most Virginia-model states produce the assessment only on the Attorney General's request.

Dark patterns

A design rule with a direct consequence: if the interface subverted the choice, you did not get consent, and everything downstream of that consent is unsupported.

“A user interface designed or manipulated with the substantial effect of subverting or impairing user autonomy, decision-making, or choice. Agreement obtained through dark patterns does not constitute consent.”

Colorado Privacy Act §§ 6-1-1303(5)(c), 6-1-1303(9)

California carries the same definition and the same consequence. This is the provision that connects design review to legal exposure, and it is why the opt-out friction cases in the enforcement record are about interface choices rather than missing features.

Processor and service provider contracts

The contract terms are prescribed. A processor relationship that lacks them is not a processor relationship, whatever the agreement is titled.

Required terms include: delete or return all personal data at the controller’s direction at the end of services unless retention is legally required; make available all information necessary to demonstrate compliance; and allow and cooperate with reasonable assessments, or arrange a qualified independent assessor.

Virginia Consumer Data Protection Act § 59.1-579(b)

California prescribes different terms for service providers and contractors, including a prohibition on selling or sharing the personal information and an obligation to identify the specific business purposes, with disclosure limited to those purposes. A service provider or contractor cannot contract to provide cross-context behavioral advertising. New Jersey makes controller-versus-processor status a fact-based determination regardless of what the contract says.

Training

An explicit statutory duty in California, and a practical necessity everywhere the law gives consumers a response deadline.

All individuals responsible for handling consumer inquiries about the business’s information practices or its CCPA compliance must be informed of the requirements and of how to direct consumers to exercise their rights.

California, 11 CCR

A business that buys, receives, sells or shares the personal information of 10,000,000 or more consumers in a calendar year must establish, document and comply with a training policy. Other states impose no training requirement in terms, but the response clocks make untrained front-line staff a compliance risk regardless.

Showing duty 1 of 8

Rights fulfilment

The mechanics around the request

Intake, verification, agents, appeals and minors. These decide whether a request is handled lawfully once it arrives, and they are where a workflow built to one state's rules quietly breaks in another.

How consumers must be able to ask, and which rule applies

The number of intake channels is set by statute, and California runs two different rules depending on which right is being exercised.

California's rule for know, delete and correct requests is two or more designated methods including, at a minimum, a toll-free telephone number. The toll-free number is the default, not a special case: the only escape is a business that is exclusively online and has a direct relationship with the consumer it collected from, which may provide an email address alone. Both conditions must hold, so a hybrid retailer with any offline presence still owes the toll-free line, and an exclusively-online data broker with no direct consumer relationship does too.

Opt-outs run on a different rule entirely. Section 1798.130 does not govern them. Two or more methods for opt-out requests comes from 11 CCR § 7026(a), with no toll-free minimum and no online-only carve-out, and the compliance clock there is 15 business days rather than 45. Texas requires two or more methods; most other states require at least one clear and conspicuous method reflecting how consumers normally interact with you.

Timeframes for request fulfilment

The deadline for each right, in every state with a comprehensive law.

Statutory response deadlines for each consumer right, by state
StateAcknowledgeKnow / accessCorrectDeleteOpt out: saleOpt out: share / TAOpt out: profilingExtensionAppeal window
CACalifornia10 days45 days45 days45 days15 business days15 business daysSubject to rulemaking45 additional daysUnspecified
VAVirginiano separate deadline set45 days45 days45 days45 days45 days45 days45 additional days60 days
COColoradono separate deadline set45 days45 days45 days45 days45 days45 days45 additional days45 days
CTConnecticutno separate deadline set45 days45 days45 days45 days45 days45 days45 additional days60 days
UTUtahno separate deadline set45 daysno separate deadline set45 days45 days45 daysno separate deadline set45 daysno separate deadline set
OROregonno separate deadline set45 days45 days45 days15 days15 days15 days45 additional days45 days
TXTexasno separate deadline set45 days45 days45 days45 days45 days45 days45 additional days60 days
MTMontanano separate deadline set45 days45 days45 days45 days45 days45 days45 additional days60 days
IAIowano separate deadline set90 days90 days90 days90 days90 daysno separate deadline set45 additional days60 days
DEDelawareno separate deadline set45 days45 days45 days45 days45 days45 days45 additional days60 days
NENebraskano separate deadline set45 days45 days45 days45 days45 days45 days45 additional days60 days
NHNew Hampshireno separate deadline set45 days45 days45 days45 days15 days for revoking consent45 days15 days for revoking consent45 days15 days for revoking consent45 additional days60 days
NJNew Jerseyno separate deadline set45 days45 days45 days45 days15 days for revoking consent45 days15 days for revoking consent45 days15 days for revoking consent45 additional days45 days
TNTennesseeno separate deadline set45 days45 days45 days45 days45 days45 days45 additional days60 days
MNMinnesotano separate deadline set45 days45 days45 days45 days15 days for revoking consent45 days15 days for revoking consent45 days15 days for revoking consent45 additional days45 + 60 days
MDMarylandno separate deadline set45 days45 days45 days45 days30 days for revoking consent45 days30 days for revoking consent45 days30 days for revoking consent45 additional days60 days
INIndianano separate deadline set45 days45 days45 days45 days45 days45 days45 additional days60 days
KYKentuckyno separate deadline set45 days45 days45 days45 days45 days45 days45 additional days60 days
RIRhode Islandno separate deadline set45 days45 days45 days45 days15 days for revoking consent45 days15 days for revoking consent45 days15 days for revoking consent45 additional days60 days
OKOklahomano separate deadline set45 days45 days45 days45 days45 days45 days45 days60 days
LALouisianano separate deadline setno separate deadline setno separate deadline setno separate deadline setno separate deadline setno separate deadline setno separate deadline setno separate deadline set60 days
ALAlabamano separate deadline setno separate deadline setno separate deadline setno separate deadline setno separate deadline setno separate deadline setno separate deadline setno separate deadline setno separate deadline set
VTVermontno separate deadline setno separate deadline setno separate deadline setno separate deadline setno separate deadline setno separate deadline setno separate deadline setno separate deadline set60 days

One 45-day clock, extendable once

Most states run a single 45-day deadline across all rights, and the divergences from it are where programmes fail. California allows one 45-day extension, conditioned on notifying the consumer inside the first 45 days. Deciding whether a request is verifiable does not stop the clock, and an extension taken silently is a missed deadline.

The California opt-out clock is the outlier

Fifteen business days for sale and share, against 45 calendar days for everything else, and the two run under different provisions: § 1798.130 for know, delete and correct, 11 CCR § 7026 for opt-outs. Oregon also runs 15, and Iowa 90 across the board. A programme running one queue at one service level misses it structurally.

Revocation and appeals run their own clocks

Maryland, Minnesota, New Jersey, New Hampshire and Rhode Island set a shorter clock for revoking consent than for anything else. Appeal windows usually run longer than response windows, 60 days against 45 in most states; Colorado, New Jersey and Oregon run 45, and California specifies none.

US privacy laws tracker

This tracker is US only. For GDPR and the rest of the directory, see the regulatory compliance hub.

Showing 50 of 50.

State comprehensive privacy laws

Comprehensive means the law reaches consumer data across sectors rather than one industry. Thresholds count residents of that state whose personal data a business controls or processes in a year, unless an entry says otherwise.

Alabama Personal Data Protection Act (APDPA)

Ala. HB 351 (2026)
UpcomingMay 1, 2027 · Signed Apr 16, 2026
Applies to
25,000+ Alabama residents (excluding payment-only data), or 25%+ of gross revenue from personal data sales regardless of volume.
Rights & obligations
Confirm processing, correct, delete, portability, opt out of targeted advertising, sale, and solely-automated significant decisions.
Sensitive data
Opt-in consent (racial/ethnic origin, religious beliefs, health, biometric and genetic data used for identification, geolocation, children's data).
Universal opt-out signals
No opt-out preference signal requirement
Cure period
45-day cure period, permanent.
Enforcement
AG exclusive; up to $15,000 per violation. No rulemaking authority.
Private right of action
None.
Amendments, rules & related
No data protection assessment requirement, a notable omission versus the VA model.

Practitioner note. Business-friendly, but the automated-decisions opt-out phrasing ("solely automated significant decisions") tracks the GDPR Article 22 shape more than most US laws, worth a read if you run automated underwriting or screening.

California Consumer Privacy Act (CCPA), as amended by the CPRA

Cal. Civ. Code § 1798.100 et seq.
In effectJan 1, 2020 · CPRA amendments effective Jan 1, 2023
Applies to
For-profit businesses doing business in California with: $25M+ annual revenue (CPI-adjusted); or buying/selling/sharing personal information of 100,000+ consumers or households; or 50%+ of revenue from selling/sharing personal information. Uniquely covers employee and B2B data.
Rights & obligations
Know/access, delete, correct, portability, opt out of sale and sharing, limit use of sensitive personal information, non-discrimination.
Sensitive data
Right to limit use and disclosure of sensitive personal information (opt-out model, unlike the opt-in consent model in most other states).
Universal opt-out signals
Opt-out preference signals (e.g. Global Privacy Control) must be honored
Cure period
No mandatory cure period (the original 30-day cure right was removed by the CPRA; cure is discretionary).
Enforcement
California AG and the California Privacy Protection Agency, the only dedicated state privacy regulator. Base figures of $2,500 per violation and $7,500 if intentional or involving minors. All statutory dollar figures, including the $25M revenue threshold and the breach damages below, are adjusted for inflation every odd-numbered year under § 1798.199.95(d), so the operative amounts now exceed the base figures quoted here.
Private right of action
Limited: private right of action for data breaches only ($100-$750 statutory damages per consumer per incident).
Amendments, rules & related
CPPA regulations approved Sept 23, 2025 (OAL) covering ADMT, risk assessments, cybersecurity audits, and CCPA updates; most requirements effective Jan 1, 2026. Phased deadlines: ADMT compliance by Jan 1, 2027; risk-assessment attestations/summaries to the CPPA by Apr 1, 2028; cybersecurity audit certifications by Apr 1, 2028 ($100M+ revenue), Apr 1, 2029 ($50-100M), Apr 1, 2030 (under $50M). Delete Act: see the data-broker entry below.

Practitioner note. The center of gravity: an active dedicated regulator, an accelerating enforcement record (see themes above), and the only state with employee/B2B coverage. If you comply properly with California plus the strictest state provisions elsewhere (Maryland minimization, Connecticut sensitive-data rules), most of the map follows.

Colorado Privacy Act (CPA)

Colo. Rev. Stat. § 6-1-1301 et seq.
In effectJul 1, 2023
Applies to
Three separate paths under § 6-1-1304(1). (1) 100,000+ Colorado consumers, or 25,000+ plus any revenue or discount from the sale of personal data. (2) Controlling or processing any amount of biometric identifiers or biometric data, with no numeric threshold (added by HB 24-1130). (3) §§ 6-1-1305.5, 6-1-1308.5 and 6-1-1309.5 to 6-1-1313 apply to any controller doing business in or targeting Colorado, with no threshold at all. No revenue floor; nonprofits are covered.
Rights & obligations
Access, correct, delete, portability, opt out of targeted advertising, sale, and significant-effects profiling; right to appeal.
Sensitive data
Opt-in consent required; AG rules add detail on consent and dark patterns.
Universal opt-out signals
Universal opt-out mechanisms mandatory since Jul 1, 2024 (Colorado maintains a public list of recognized signals, including GPC)
Cure period
The general 60-day cure at § 6-1-1311(1)(d)(I) was repealed 1 Jan 2025. A separate 60-day cure notice under § 6-1-1311(1)(d)(II) is currently live: it applies before any action to enforce §§ 6-1-1305.5, 6-1-1308.5 or 6-1-1309.5, took effect 1 Oct 2025, and is repealed 31 Dec 2026.
Enforcement
AG and district attorneys; penalties under the Colorado Consumer Protection Act of up to $20,000 per violation.
Private right of action
None.
Amendments, rules & related
2024 amendments extended the CPA: biometric-identifier provisions effective Jul 1, 2025 apply to any entity processing biometrics in Colorado regardless of the CPA's volume thresholds (consent, retention schedules, employee-context rules); separate minors' provisions (duty of care, consent for certain uses) effective Oct 1, 2025.

Practitioner note. First state to make universal opt-out signals mandatory, and the biometric amendment quietly created a BIPA-adjacent obligation, without a private right of action, that reaches employers no other CPA provision touches.

Connecticut Data Privacy Act (CTDPA)

Conn. Gen. Stat. § 42-515 et seq.
In effectJul 1, 2023 · Major SB 1295 amendments effective Jul 1, 2026
Applies to
As amended effective Jul 1, 2026: controllers processing personal data of 35,000+ Connecticut consumers (down from 100,000, excluding payment-only data); OR any sensitive data (no volume threshold); OR any personal data offered for sale (no volume threshold).
Rights & obligations
VA-model rights plus, from Jul 1, 2026: profiling rights (question automated decisions, learn the reasoning, review underlying data, request correction/re-evaluation in some cases), a right to the names of third parties to whom data was sold, and inferences included in access rights.
Sensitive data
Opt-in consent; categories expanded in 2026 to include government IDs (SSN, driver's license, passport) and financial account details. Sale of sensitive data requires explicit consent, and processing requires both consent and a reasonably-necessary determination.
Universal opt-out signals
Universal opt-out signals mandatory since Jan 1, 2025
Cure period
60-day cure period sunset Dec 31, 2024, discretionary since.
Enforcement
AG exclusive, via the Connecticut Unfair Trade Practices Act.
Private right of action
None.
Amendments, rules & related
SB 1295 (2025, effective Jul 1, 2026) also requires privacy notices to disclose whether personal data is used or sold for LLM training, bans targeted advertising and sale for known 13-17-year-olds regardless of consent, and adds profiling impact assessments effective Aug 1, 2026. Separately, SB 4 (signed May 27, 2026, effective Oct 1, 2026) adds annual data broker registration, a deletion mechanism by Jul 1, 2028, and facial-recognition restrictions.

Practitioner note. Connecticut has become the fastest-moving state legislature in privacy. The any-sensitive-data and any-sale applicability prongs mean businesses far below the old headcount thresholds are now in scope, re-run scoping analyses that predate July 2026.

Delaware Personal Data Privacy Act (DPDPA)

6 Del. C. ch. 12D
In effectJan 1, 2025
Applies to
35,000+ Delaware consumers, or 10,000+ with 20%+ revenue from personal data sales. Most nonprofits covered.
Rights & obligations
CT-model rights plus the Oregon-style right to a list of specific third parties to which data was disclosed.
Sensitive data
Opt-in consent; definition includes status as transgender or nonbinary.
Universal opt-out signals
Universal opt-out signals mandatory since Jan 1, 2026
Cure period
60-day cure period sunset Dec 31, 2025, discretionary since.
Enforcement
Delaware Department of Justice.
Private right of action
None.
Amendments, rules & related
Heightened minors protections (restrictions on targeted advertising and sale for known minors). HB 380 (passed June 2026, awaiting signature at last check) would update applicability thresholds, narrow the GLBA exemption, require binding contracts for data sales/sharing, and heighten profiling protections effective Jan 1, 2027.

Practitioner note. Low thresholds plus nonprofit coverage pull in organizations that assumed they were below every state's line. Watch HB 380, the GLBA-exemption narrowing would be unusual among state laws.

Florida Digital Bill of Rights (FDBR)

Fla. SB 262 (2023)
In effectJul 1, 2024
Applies to
Core obligations: for-profit entities with $1B+ global revenue that also derive 50%+ of ad revenue online, operate an app store with 250,000+ apps, or run a consumer smart-speaker/voice service, a handful of large platforms. Some provisions (including consent for selling sensitive data) reach more broadly; scope analysis is provision-by-provision.
Rights & obligations
CCPA/VA-style rights against covered controllers, including deletion, correction, portability, and opt-outs of sale, targeted advertising, and profiling.
Sensitive data
Consent required for sale of sensitive data (with statutory notice wording), applying beyond the $1B core threshold.
Universal opt-out signals
No universal opt-out signal mandate
Cure period
45-day discretionary cure.
Enforcement
Florida Department of Legal Affairs; up to $50,000 per violation. Trebled under § 501.72(1) for three categories, not only minors: a violation involving a known child, failure to delete or correct after an authenticated request, and continuing to sell or share after the consumer opts out.
Private right of action
None.
Amendments, rules & related
Because of the narrow core applicability, several public trackers exclude Florida from the comprehensive-law count, hence 23 vs. 24 discrepancies.

Practitioner note. Most businesses are outside the core scope but should still check the sensitive-data-sale and minors provisions, which do not carry the $1B threshold.

Indiana Consumer Data Protection Act

Ind. SB 5 (2023)
In effectJan 1, 2026
Applies to
100,000+ Indiana consumers, or 25,000+ with 50%+ revenue from personal data sales.
Rights & obligations
VA-model rights; correction limited to data the consumer provided; appeal.
Sensitive data
Opt-in consent.
Universal opt-out signals
No universal opt-out signal requirement
Cure period
30-day cure period, permanent.
Enforcement
AG exclusive; up to $7,500 per violation.
Private right of action
None.
Amendments, rules & related
Enacted 2023 with the longest runway of any state law (2.5 years).

Practitioner note. A near-verbatim Virginia clone; existing VA-model programs extend here with a threshold and notice refresh.

Iowa Consumer Data Protection Act (ICDPA)

Iowa Code ch. 715D
In effectJan 1, 2025
Applies to
100,000+ Iowa consumers, or 25,000+ with 50%+ revenue from personal data sales.
Rights & obligations
Access, delete, portability, opt out of sale. No correction right; no express profiling opt-out; targeted advertising handled through notice-and-opt-out disclosure rather than a standalone right.
Sensitive data
Notice and opportunity to opt out (not opt-in consent).
Universal opt-out signals
No universal opt-out signal requirement
Cure period
90-day cure period, the longest of any state law in this atlas; permanent.
Enforcement
AG exclusive; up to $7,500 per violation.
Private right of action
None.
Amendments, rules & related
No data protection assessment requirement.

Practitioner note. The lightest post-Utah law. As with Utah: satisfy the stricter states and Iowa follows; never scope a program to Iowa.

Kentucky Consumer Data Protection Act

Ky. HB 15 (2024)
In effectJan 1, 2026
Applies to
100,000+ Kentucky consumers, or 25,000+ with 50%+ revenue from personal data sales.
Rights & obligations
VA-model rights; appeal.
Sensitive data
Opt-in consent.
Universal opt-out signals
No universal opt-out signal requirement
Cure period
30-day cure period, permanent.
Enforcement
AG exclusive; up to $7,500 per violation.
Private right of action
None.
Amendments, rules & related
Amended before taking effect (HB 473, 2025): modified healthcare-related exemptions and data protection assessment triggers, effective with the law on Jan 1, 2026.

Practitioner note. Another Virginia clone, but scoped assessments were tweaked pre-launch, so use the amended text, not 2024 summaries.

Louisiana Data Privacy Act (LDPA)

La. LDPA (2026)
UpcomingJan 1, 2027 · Signed May 29, 2026
Applies to
Entities doing business in Louisiana meeting any one of: $25M+ annual gross revenue; 75,000+ consumers, households, or devices; or 50%+ of revenue from personal information sales.
Rights & obligations
Access/confirmation, correction, deletion, portability, opt-outs of targeted advertising, sale, and significant-effects profiling.
Sensitive data
Opt-in consent (including citizenship status and precise geolocation).
Universal opt-out signals
Connecticut-model statute, universal opt-out treatment not confirmed in this pass
Cure period
30-day cure period, sunsets after Jul 31, 2027.
Enforcement
AG exclusive; civil penalties up to $5,000. No rulemaking authority.
Private right of action
None.
Amendments, rules & related
Uses the broader Connecticut-style "sale" definition (monetary or other valuable consideration), a wider net than the VA-model states around it.

Practitioner note. The device-count prong (75,000 consumers, households, or devices) can trip high-traffic consumer businesses that would pass a pure headcount test.

Maryland Online Data Privacy Act (MODPA)

Maryland Online Data Privacy Act (2024)
In effectOct 1, 2025 · No effect on processing occurring before Apr 1, 2026
Applies to
35,000+ Maryland consumers, or 10,000+ with 20%+ revenue from personal data sales.
Rights & obligations
CT-model rights plus the third-party disclosure list.
Sensitive data
Sale of sensitive data is prohibited outright, with no consent path (New Jersey's 2026 amendment followed suit), and processing sensitive data is allowed only when strictly necessary to provide a requested product or service. HB 711 (effective Jul 1, 2026) expanded the sensitive-data definition to include inferred characteristics and restricted sale of personal data to immigration-enforcement entities.
Universal opt-out signals
Universal opt-out signals must be honored
Cure period
Discretionary. Under § 14-4714 the Consumer Protection Division may issue a cure notice where it determines a cure is possible, allowing at least 60 days. It applies only to violations occurring on or before 1 April 2027, so it is still live today.
Enforcement
AG / Division of Consumer Protection; penalties under the Maryland Consumer Protection Act.
Private right of action
None (MODPA itself creates none).
Amendments, rules & related
Data minimization is MODPA's signature: collection is limited to what is reasonably necessary and proportionate to the specific product or service the consumer requested, consent does not expand it. Targeted advertising and sale are banned outright for consumers the controller knew or should have known are under 18.

Practitioner note. Maryland breaks the consent-fixes-everything model: minimization and the sensitive-data sale ban are duties you cannot paper over with a consent flow. For data-hungry businesses this is the state that forces an actual collection-practices review.

Minnesota Consumer Data Privacy Act (MCDPA)

Minnesota Consumer Data Privacy Act (2024)
In effectJul 31, 2025
Applies to
100,000+ Minnesota consumers, or 25,000+ with 25%+ revenue from personal data sales. SBA small businesses are exempt but need consent to sell sensitive data.
Rights & obligations
VA-model rights plus distinctive profiling rights: a consumer subject to significant-effects profiling may question the result, learn why the decision was reached, and review the personal data used. Also a right to a list of specific third parties to which personal data was disclosed.
Sensitive data
Opt-in consent.
Universal opt-out signals
Universal opt-out signals must be honored
Cure period
30-day cure period sunset Jan 31, 2026, none since.
Enforcement
AG exclusive; up to $7,500 per violation.
Private right of action
None.
Amendments, rules & related
Two obligations no other state imposes in this form: controllers must maintain a data inventory, and must document a privacy program with a designated responsible individual (small-company scale expectations, but written down).

Practitioner note. The data-inventory requirement turns data mapping from best practice into a statutory obligation, an audit-ready inventory is now a compliance artifact in Minnesota, not just an enabler.

Montana Consumer Data Privacy Act (MTCDPA)

Mont. SB 384 (2023), amended by SB 297 (2025)
In effectOct 1, 2024 · SB 297 amendments effective Oct 1, 2025
Applies to
As amended by SB 297, effective 1 Oct 2025: 25,000+ Montana consumers, or 15,000+ with more than 25% of gross revenue from the sale of personal data. The original SB 384 thresholds were 50,000, or 25,000 with 25%+ revenue from sale.
Rights & obligations
VA/CT-model rights: access, correct, delete, portability, opt out of targeted advertising, sale, and significant-effects profiling; appeal.
Sensitive data
Opt-in consent.
Universal opt-out signals
Universal opt-out signals mandatory since Jan 1, 2025
Cure period
SB 297 eliminated the 60-day cure period effective Oct 1, 2025, none since.
Enforcement
AG exclusive; up to $7,500 per violation under § 30-14-2820(2).
Private right of action
None.
Amendments, rules & related
SB 297 also added heightened protections for minors (duty of care, restrictions on targeted advertising to known minors). Montana separately enacted a genetic information privacy law and strong judicial privacy protections.

Practitioner note. Montana is the small-state template for a second wave: thresholds calibrated to population, then tightened by amendment two years in. Track the amended thresholds if you deprioritized Montana at launch.

Nebraska Data Privacy Act (NDPA)

Neb. LB 1074 (2024)
In effectJan 1, 2025
Applies to
Texas model: any entity conducting business in Nebraska or targeting Nebraska residents that processes or sells personal data and is not an SBA-defined small business. Small businesses still need consent to sell sensitive data.
Rights & obligations
VA-model rights including opt-outs of targeted advertising, sale, and significant-effects profiling; appeal.
Sensitive data
Opt-in consent.
Universal opt-out signals
Universal opt-out signals must be honored
Cure period
30-day cure period, permanent.
Enforcement
AG exclusive; up to $7,500 per violation.
Private right of action
None.
Amendments, rules & related
Nebraska also enacted an Age-Appropriate Design Code (LB 504), effective Jan 1, 2026, imposing duties on covered online services likely to be accessed by minors.

Practitioner note. Same trap as Texas: no headcount safe harbor. A 200-person company with no Nebraska office but Nebraska customers is in scope.

New Hampshire Privacy Act

N.H. RSA ch. 507-H (SB 255, 2024)
In effectJan 1, 2025
Applies to
35,000+ New Hampshire consumers, or 10,000+ with 25%+ revenue from personal data sales.
Rights & obligations
CT-model rights: access, correct, delete, portability, opt out of targeted advertising, sale, and significant-effects profiling; appeal.
Sensitive data
Opt-in consent.
Universal opt-out signals
Universal opt-out signals mandatory since Jan 1, 2025
Cure period
Mandatory 60-day cure from 1 Jan to 31 Dec 2025 under RSA 507-H:11, II; discretionary since, against the factors in RSA 507-H:11, III.
Enforcement
AG exclusive.
Private right of action
None.
Amendments, rules & related
HB 1460 (signed Jun 19, 2026, effective Jan 1, 2027) prohibits the sale of personal data of children under 13.

Practitioner note. A faithful Connecticut clone with small-state thresholds. Programs already built for CT need only the threshold re-check here.

New Jersey Data Privacy Act (NJDPA)

P.L. 2023, c. 266 (C.56:8-166.4 et seq.)
In effectJan 15, 2025
Applies to
100,000+ New Jersey consumers (excluding payment-only data), or 25,000+ plus any revenue or discount from the sale of personal data.
Rights & obligations
Access, correct, delete, portability, opt out of targeted advertising, sale, and significant-effects profiling; appeal. § 3(c)(1) prohibits requiring a new account to exercise a right; § 4(f) requires a conspicuous appeal process.
Sensitive data
Opt-in consent (§ 9(a)(4)); definition includes financial information. A5328 (signed Jun 30, 2026) goes further and prohibits the sale of sensitive personal data outright.
Universal opt-out signals
§ 8(b)(1): controllers processing for targeted advertising or sale must honor a user-selected universal opt-out mechanism; § 8(b)(2)(c) sets a consumer-friendly usability standard
Cure period
A cure window ran until the first day of the 18th month after the effective date, so it lapsed on 1 July 2026. While live it read as mandatory notice: § 14(b) says the Division shall issue notice where a cure is deemed possible.
Enforcement
AG / Division of Consumer Affairs, with rulemaking authority; penalties via the New Jersey Consumer Fraud Act.
Private right of action
None.
Amendments, rules & related
Three consent regimes by age: parental consent under 13; opt-in consent for known 13-16-year-olds for targeted advertising, sale, or profiling (§ 9(a)(7)); standard opt-out at 17+. § 7(b) imposes the forward-looking "remains deleted" suppression standard for data sourced from third parties. A5328 (2026) also adds data broker registration with a public database.

Practitioner note. The remains-deleted standard is operationally demanding: deletion is not a one-time database operation but a continuing check of future ingestion against a suppression record. The 2026 flat ban on selling sensitive data (with Maryland's) signals where sensitive-data monetization is heading.

Oklahoma Consumer Privacy Act

Okla. SB 546 (2026)
UpcomingJan 1, 2027 · Signed March 2026
Applies to
100,000+ Oklahoma consumers, or 25,000+ with 50%+ revenue from personal data sales.
Rights & obligations
VA-model: access rights, opt-outs of targeted advertising and sale.
Sensitive data
Opt-in style protections per the VA framework.
Universal opt-out signals
No universal opt-out mechanism recognition
Cure period
30-day cure period, permanent.
Enforcement
AG exclusive.
Private right of action
None.
Amendments, rules & related
Data protection assessments required. Omits universal opt-out recognition and enhanced children's provisions, gaps that leave some trackers hesitant to call it fully comprehensive. Seven years in the making (debated since 2019).

Practitioner note. A late, conservative Virginia-model entry. Existing multi-state programs absorb it with minimal change.

Oregon Consumer Privacy Act (OCPA)

ORS 646A.570 et seq.
In effectJul 1, 2024 · Applied to nonprofits from Jul 1, 2025
Applies to
100,000+ Oregon consumers, or 25,000+ with 25%+ of revenue from personal data sales. Nonprofits covered (delayed one year).
Rights & obligations
VA-model rights plus a distinctive one: the right to obtain a list of the specific third parties to which the controller disclosed personal data.
Sensitive data
Opt-in consent; among the broadest definitions, includes status as transgender or nonbinary, status as a victim of crime, and national origin.
Universal opt-out signals
Universal opt-out signals mandatory since Jan 1, 2026
Cure period
30-day cure period sunset Jan 1, 2026, none since.
Enforcement
AG exclusive; up to $7,500 per violation.
Private right of action
None.
Amendments, rules & related
Amendments effective Jan 1, 2026: sale of precise geolocation data prohibited, and sale of personal data of consumers the controller has actual knowledge are under 16 prohibited (HB 2008). Oregon also runs a data broker registration law.

Practitioner note. The third-party-list right changes DSR operations: you need disclosure records at the level of named recipients, not category labels. The 2026 geolocation-sale ban is an outright prohibition, not an opt-out, location-data monetization needs a Texas-style scoping review here.

Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)

R.I. H 7787 / S 2500 (2024)
In effectJan 1, 2026
Applies to
35,000+ Rhode Island consumers, or 10,000+ with 20%+ revenue from personal data sales.
Rights & obligations
VA-model rights: access, correct, delete, portability, opt-outs of targeted advertising, sale, and significant-effects profiling.
Sensitive data
Opt-in consent.
Universal opt-out signals
No universal opt-out signal requirement
Cure period
No cure period.
Enforcement
AG exclusive; penalties include $100-$500 per intentional disclosure violation plus up to $10,000 per violation under the state deceptive trade practices act.
Private right of action
None.
Amendments, rules & related
Distinctive drafting quirk: the privacy notice must identify the third parties to which the controller has sold or may sell personal data, read by many practitioners as requiring named entities, not categories, in the public notice itself.

Practitioner note. The named-third-parties notice requirement is the sleeper obligation: it forces the disclosure-recipient inventory that Oregon and Minnesota only require on request into your public-facing privacy policy.

Tennessee Information Protection Act (TIPA)

Tenn. Code Ann. § 47-18-3201 et seq.
In effectJul 1, 2025
Applies to
$25M+ annual revenue AND either 175,000+ Tennessee consumers or 25,000+ with 50%+ revenue from personal data sales. The 175,000 figure is the highest headcount threshold among the state laws in this atlas.
Rights & obligations
VA-model rights; appeal.
Sensitive data
Opt-in consent.
Universal opt-out signals
No universal opt-out signal requirement
Cure period
60-day cure period, permanent.
Enforcement
AG exclusive; up to $7,500 per violation. § 47-18-3212(d)(2) allows a court to treble damages at its discretion on a finding of a willful or knowing violation, which is not the same as automatic trebling of the penalty.
Private right of action
None.
Amendments, rules & related
Unique feature: an affirmative defense for controllers that maintain a written privacy program reasonably conforming to the NIST Privacy Framework.

Practitioner note. The NIST safe harbor makes documented privacy-program governance directly outcome-relevant in Tennessee, the one state where a framework mapping exercise has explicit litigation value.

Texas Data Privacy and Security Act (TDPSA)

Tex. Bus. & Com. Code ch. 541
In effectJul 1, 2024
Applies to
No numeric thresholds: applies to any entity conducting business in Texas or targeting Texas residents that processes or sells personal data and is not a small business under the SBA definition. Small businesses still need consent to sell sensitive data.
Rights & obligations
VA-model: access, correct, delete, portability, opt out of targeted advertising, sale, and significant-effects profiling; appeal.
Sensitive data
Opt-in consent; prescriptive notice text required for businesses selling sensitive or biometric data (verbatim statutory wording in the privacy notice).
Universal opt-out signals
Universal opt-out signals mandatory since Jan 1, 2025
Cure period
30-day cure period, permanent.
Enforcement
AG exclusive; up to $7,500 per violation. Texas stood up a dedicated privacy enforcement team and enforces actively, including under its separate biometric statute (see CUBI below).
Private right of action
None.
Amendments, rules & related
Data protection assessments required. Texas also operates a data broker registration law and enacted an AI governance statute (HB 149, effective Jan 1, 2026).

Practitioner note. The SBA small-business test replaces headcount thresholds entirely, scope turns on what your company is, not how many Texans you process. Almost every non-small business touching Texas residents is in.

Utah Consumer Privacy Act (UCPA)

Utah Code § 13-61-101 et seq.
In effectDec 31, 2023
Applies to
$25M+ annual revenue AND either 100,000+ Utah consumers or 25,000+ with 50%+ revenue from personal data sales, the double threshold keeps most mid-market companies out of scope.
Rights & obligations
Access, delete, portability, opt out of targeted advertising and sale. No correction right; no profiling opt-out.
Sensitive data
Notice and opportunity to opt out (not opt-in consent), the lightest sensitive-data standard among state laws.
Universal opt-out signals
No universal opt-out signal requirement
Cure period
30-day cure period, permanent.
Enforcement
AG via the Division of Consumer Protection; up to $7,500 per violation.
Private right of action
None.
Amendments, rules & related
No data protection assessment requirement.

Practitioner note. The business-friendliest of the early laws. If a program satisfies Virginia and Colorado it will satisfy Utah; do not build to Utah as a baseline.

Vermont Data Privacy and Online Surveillance Act (VDPOSA)

Vt. S.71 (2026)
UpcomingJan 1, 2028 · Signed Jun 16, 2026
Applies to
35,000+ Vermont consumers; or sensitive data of 3,000+; or personal data of 3,000+ offered for sale. Consumer health data provisions apply with no threshold.
Rights & obligations
Confirm processing, access, correct, delete, opt out of targeted advertising, sale, and significant-effects profiling; appeal.
Sensitive data
Prior consent required, with use limited to necessary purposes.
Universal opt-out signals
Universal opt-out treatment not confirmed in this pass
Cure period
60-day cure window from Jan 1, 2028 through Jun 30, 2029.
Enforcement
AG exclusive, under the Vermont Consumer Protection Act.
Private right of action
None identified in this pass (a prior 2024 Vermont bill died over a private right of action, confirm the enacted text).
Amendments, rules & related
Data minimization: collection limited to what is reasonably necessary and proportionate. Sale and targeted advertising involving known 13-17-year-olds prohibited. Vermont separately enacted an Age-Appropriate Design Code (2025, effective Jan 1, 2027) and has long run the country's oldest data broker registration law.

Practitioner note. The sensitive-data (3,000) and offered-for-sale (3,000) prongs are the lowest applicability triggers of any state law in this atlas; small data-heavy businesses that ignore every other state's thresholds can be captured here.

Virginia Consumer Data Protection Act (VCDPA)

Va. Code § 59.1-575 et seq.
In effectJan 1, 2023
Applies to
Controllers/processors of personal data of 100,000+ Virginia consumers, or 25,000+ if 50%+ of gross revenue comes from the sale of personal data. Consumers acting in an employment or commercial (B2B) context are excluded.
Rights & obligations
Access, correct, delete, portability, opt out of targeted advertising, sale, and profiling producing legal or similarly significant effects; right to appeal.
Sensitive data
Opt-in consent required before processing sensitive data.
Universal opt-out signals
No universal opt-out signal requirement
Cure period
30-day cure period, permanent.
Enforcement
AG exclusive; up to $7,500 per violation.
Private right of action
None.
Amendments, rules & related
The template: most later state laws are drafted from the VCDPA model. Amended after passage (including minors-related provisions), check current text for post-2024 changes.

Practitioner note. Data protection assessments are required for targeted advertising, sale, sensitive data, and risky profiling, the assessment obligation practitioners most often miss in VA-model states.

Federal privacy laws

Federal law is sectoral rather than comprehensive, dividing by industry, data type, and communication channel, with the FTC acting as the de facto national enforcer through its unfairness and deception authority.

CAN-SPAM Act, commercial email

15 U.S.C. § 7701 et seq.
In effectJan 1, 2004 · enacted Dec 16, 2003
Applies to
Senders of commercial email.
Rights & obligations
No deceptive headers/subject lines; clear identification as advertising; valid physical postal address; conspicuous opt-out honored within 10 business days; no opt-out fees or hurdles.
Enforcement
FTC primarily; FCC for mobile service messages; state AGs and ISPs have limited actions.
Private right of action
None for consumers.
Amendments, rules & related
Preemption under § 7707(b) is partial only: it supersedes state laws that expressly regulate commercial email, except to the extent they prohibit falsity or deception, and does not preempt laws that are not email-specific or that address fraud or computer crime. Opt-out-based, unlike Canada’s CASL or the EU consent model.

Practitioner note. Treat suppression-list integrity as a rights-fulfillment problem: the 10-business-day clock and the no-hurdles rule are where marketing-automation configurations quietly fail.

COPPA, Children's Online Privacy Protection Act

15 U.S.C. §§ 6501-6506; 16 C.F.R. Part 312
In effect1998 · Amended Rule: compliance April 22, 2026
Applies to
Operators of websites and online services directed to children under 13, or with actual knowledge they collect personal information from under-13 users.
Rights & obligations
Verifiable parental consent before collection; notice; parental access and deletion rights; data minimization and retention limits.
Enforcement
FTC and state AGs; civil penalties per violation, inflation-adjusted.
Private right of action
None.
Amendments, rules & related
The amended COPPA Rule took effect June 23, 2025 with full compliance required by April 22, 2026: separate verifiable parental consent for disclosures to third parties (including targeted advertising), expanded personal-information definition (biometrics), written retention policies, and limits on indefinite retention.

Practitioner note. The amended Rule's separate-consent-for-third-party-disclosure requirement effectively ends third-party targeted advertising in child-directed contexts absent explicit parental opt-in, and the state minors' laws layer 13-17 protections on top of COPPA's under-13 floor.

DOJ Bulk Sensitive Data Rule (EO 14117)

28 C.F.R. Part 202
In effectApr 8, 2025
Applies to
US persons engaging in covered data transactions, data brokerage, vendor, employment, and investment agreements, involving bulk US sensitive personal data or government-related data accessible to countries of concern (China incl. Hong Kong and Macau, Russia, Iran, North Korea, Cuba, Venezuela) or covered persons.
Rights & obligations
Prohibits data-brokerage transactions with covered persons outright; restricts other covered transactions unless CISA-level security requirements are met. Bulk thresholds vary by data type (e.g., precise geolocation, biometrics, genomic, health, financial data, and combinations).
Enforcement
DOJ National Security Division under IEEPA. Civil penalties at § 202.1301 run through 50 U.S.C. § 1705: up to the greater of $368,136 or twice the transaction value, with willful violations exposed to $1M and 20 years. The due-diligence, audit and reporting obligations are now in force, not phasing in: compliance programmes were due 6 Oct 2025, with audits and annual reports covering conduct on or after that date.
Private right of action
None.
Amendments, rules & related
Not a privacy statute in the consumer-rights sense, a national-security data-transfer control regime. It lands on the privacy team anyway: the compliance inputs are data mapping, vendor inventories, and cross-border flow analysis.

Practitioner note. Global companies with China-based engineering, analytics, or support functions need a covered-transaction analysis even when no data is "sold" to anyone. This is the closest thing the US has to a data-localization rule.

DPPA, Driver's Privacy Protection Act

18 U.S.C. §§ 2721-2725
In effectSep 13, 1997 · enacted 1994, effective three years later
Applies to
State DMVs and downstream recipients of motor-vehicle-record data.
Rights & obligations
Disclosure only for enumerated permissible uses; resale/re-disclosure restrictions and record-keeping for resellers.
Enforcement
Criminal fines and civil actions. § 2723(b) also lets the Attorney General impose a civil penalty of up to $5,000 a day on a state DMV with a policy or practice of substantial noncompliance.
Private right of action
Yes, but narrower than often stated. § 2724(b)(1) says a court may award actual damages but not less than $2,500 liquidated. The award is discretionary, runs to the individual the information pertains to, and the text sets no per-violation multiplier.
Amendments, rules & related
Recurring litigation against data brokers and marketers who acquire DMV-sourced data outside a permissible use.

Practitioner note. If a vendor's people-data product includes vehicle or license attributes, DPPA permissible-use diligence belongs in procurement review.

ECPA, Wiretap Act & Stored Communications Act

18 U.S.C. §§ 2510-2523, 2701-2713
In effect1968 / 1986 · Wiretap Act 1968; ECPA added the SCA in 1986
Applies to
Interception of communications in transit (Wiretap Act) and access to stored communications (SCA). Federal law requires one-party consent to interception; a dozen-plus states require all-party consent, the hook for the state session-replay/pixel litigation.
Rights & obligations
Consent or another statutory exception before interception or unauthorized access.
Enforcement
Criminal enforcement plus civil actions.
Private right of action
Yes: statutory damages under both acts.
Amendments, rules & related
Session replay, chatbots, and pixel tracking are litigated under the state all-party-consent analogs (California CIPA foremost, see the specialty entry) with ECPA as backdrop.

Practitioner note. The federal one-party rule is why plaintiffs pick state statutes: build your tracking-disclosure posture to the all-party-consent states and the federal claim follows.

FCRA, Fair Credit Reporting Act

15 U.S.C. § 1681 et seq.
In effect1970
Applies to
Consumer reporting agencies, furnishers of data to them, and users of consumer reports (credit, employment, tenant, insurance screening).
Rights & obligations
Permissible-purpose limits on obtaining reports; accuracy and dispute obligations; adverse-action notices; access to one's own file.
Enforcement
CFPB and FTC; state enforcement.
Private right of action
Yes: statutory damages ($100-$1,000 per willful violation), actual damages, punitive damages, and fee-shifting; a major class-action regime.
Amendments, rules & related
The boundary question of the decade: when does a data broker or people-search product become a consumer reporting agency? Screening-adjacent data products keep drawing FCRA suits and regulatory attention.

Practitioner note. If any data product you build or buy influences eligibility decisions, credit, housing, employment, insurance, assume FCRA analysis is needed before any state privacy law analysis.

FERPA, education records

20 U.S.C. § 1232g
In effect1974
Applies to
Educational agencies and institutions receiving federal education funds; reaches their edtech vendors through the school-official exception's contractual conditions.
Rights & obligations
Parental/eligible-student rights of access, amendment, and consent before disclosure of education records, subject to enumerated exceptions.
Enforcement
US Department of Education (funding conditions); no fines regime comparable to the FTC's.
Private right of action
None.
Amendments, rules & related
State student-privacy laws (California's SOPIPA and its many clones) impose the operative restrictions on edtech vendors directly, no targeted advertising, no profile-building, no sale.

Practitioner note. Edtech vendors: FERPA flows down through contracts, but the state student-privacy statutes are the enforceable floor on your own conduct.

FTC Act § 5, Unfair or Deceptive Acts or Practices

15 U.S.C. § 45
In effect1914
Applies to
Nearly every company in US commerce (banks, common carriers, and certain others excepted). No privacy-specific trigger: the FTC polices broken privacy promises, deceptive data practices, inadequate security, and dark patterns as unfair or deceptive conduct.
Rights & obligations
Not a rights statute. Obligations arise from your own representations (privacy policies, consent flows) and from FTC rules the agency administers, including the COPPA Rule, GLBA Safeguards Rule, and the Health Breach Notification Rule for non-HIPAA health apps.
Enforcement
FTC. A first § 5 violation generally brings a complaint and a consent agreement or cease-and-desist order rather than a fine. Civil penalties attach only to violations of a final order under § 45(l) or knowing violations of a trade rule under § 45(m), currently $53,088 per violation under 16 C.F.R. § 1.98.
Private right of action
None.
Amendments, rules & related
The FTC is the de facto national privacy regulator in the absence of a comprehensive federal statute. Decades of consent decrees function as common law for what adequate notice, choice, and security look like.

Practitioner note. Whatever the states require, your public privacy statements are independently enforceable here. Say-do gaps, policy says one thing, stack does another, are the classic § 5 case.

Gramm-Leach-Bliley Act (GLBA), financial data

15 U.S.C. §§ 6801-6809
In effect1999
Applies to
Financial institutions, defined broadly, banks, lenders, but also mortgage brokers, auto dealers extending credit, tax preparers, higher-ed institutions handling federal student aid, and many fintechs.
Rights & obligations
Privacy Rule: initial/annual privacy notices and opt-out before sharing nonpublic personal information with nonaffiliated third parties. Safeguards Rule: a written information security program with designated qualified individual, risk assessment, encryption, MFA; non-bank institutions must report breaches affecting 500+ consumers to the FTC (since May 2024).
Enforcement
Under 15 U.S.C. § 6805(a): the CFPB, the federal banking agencies, the NCUA, the SEC for brokers, dealers, investment companies and advisers, state insurance authorities, and the FTC for any institution not covered by the others.
Private right of action
None.
Amendments, rules & related
GLBA data is exempt (entity-level or data-level, varying by state) from most state comprehensive privacy laws, but the exemption's shape differs state to state, and Delaware's pending amendment would narrow its entity-level exemption.

Practitioner note. The state-law GLBA exemption is entity-level in some states and data-level in others: a fintech can be fully exempt in Virginia and substantially covered in California for the same processing. Map it per state rather than assuming.

HIPAA / HITECH, health information

45 C.F.R. Parts 160, 164
In effect1996 · Privacy Rule compliance 2003
Applies to
Covered entities (health plans, healthcare clearinghouses, providers that bill electronically) and their business associates. It does not cover most consumer health data, wellness apps, wearables, ad-tech health inferences, which is exactly the gap the state consumer-health laws (Washington MHMD, Nevada, New York's pending act) now fill.
Rights & obligations
Individual rights of access and amendment; Privacy Rule use/disclosure limits; Security Rule administrative, physical, and technical safeguards; Breach Notification Rule (HHS, individuals, media for 500+ record breaches).
Enforcement
HHS Office for Civil Rights. Tiered civil monetary penalties at 45 C.F.R. § 160.404, inflation-adjusted at 45 C.F.R. § 102.3 to $145 to $73,011 per violation with a $2,190,294 calendar-year cap per identical-violation category. State AGs may also enforce under 42 U.S.C. § 1320d-5(d), up to $100 per violation.
Private right of action
None (state negligence suits often borrow HIPAA as the standard of care).
Amendments, rules & related
The 2024 Reproductive Health Privacy Rule was largely vacated nationwide by a federal district court in June 2025, treat pre-2025 summaries of it as outdated. A major Security Rule update was proposed in late 2024; rulemaking status should be confirmed before relying.

Practitioner note. For privacy teams outside healthcare, HIPAA matters mostly as a boundary: data that falls outside it lands in the state consumer-health-data regimes, several of which carry private rights of action.

PADFAA, Protecting Americans' Data from Foreign Adversaries Act

Pub. L. 118-50, div. I (2024)
In effectJun 23, 2024
Applies to
Data brokers (defined by function, not registration) selling, licensing, or otherwise making available personally identifiable sensitive data of US individuals to foreign adversary countries (China, Russia, Iran, North Korea) or entities controlled by them.
Rights & obligations
A flat prohibition, no consent path.
Enforcement
FTC. § 2(b)(1) treats a violation as a violation of a trade regulation rule under FTC Act § 18(a)(1)(B), which is what supports civil penalties, rather than as a standalone § 5 violation.
Private right of action
None.
Amendments, rules & related
"Sensitive data" here is broad: precise geolocation, health, biometric and genetic data, financial data, log-in credentials, private communications, and data about minors, among more.

Practitioner note. The definition of data broker turns on selling data you did not collect from a first-party relationship, companies that never think of themselves as brokers (app publishers monetizing SDK data) can qualify.

TCPA, Telephone Consumer Protection Act

47 U.S.C. § 227
In effect1991
Applies to
Anyone placing calls or texts: autodialed or prerecorded/artificial-voice calls and texts to mobile numbers, telemarketing consent rules, and Do-Not-Call obligations.
Rights & obligations
Prior express (written, for marketing) consent; identification requirements; opt-out honoring; DNC list scrubbing.
Enforcement
FCC and state AGs.
Private right of action
Yes. § 227(b)(3)(B) sets $500 per call or text; the court may in its discretion increase the award to up to three times that amount for a willful or knowing violation, so $1,500 is a ceiling rather than an automatic figure. No aggregate cap in the statute.
Amendments, rules & related
The FCC's one-to-one consent rule for lead generators was struck down in early 2025 before taking effect; revocation-of-consent rules (any reasonable means, honored within a set period) took effect in 2025. Litigation volume continues regardless of rule churn.

Practitioner note. SMS programs are the current exposure center: consent capture at point of collection, quiet hours, and revocation handling need the same rigor as any privacy-rights workflow, the per-message damages math is what makes this board-visible.

VPPA, Video Privacy Protection Act

18 U.S.C. § 2710
In effect1988
Applies to
"Video tape service providers", read by plaintiffs to cover any site or app delivering video content that discloses a consumer's identity plus viewing information to a third party (most commonly via ad pixels).
Rights & obligations
No disclosure of personally identifiable viewing information without separate, informed, opt-in consent meeting statutory formalities.
Enforcement
Private litigation is the enforcement mechanism in practice.
Private right of action
Yes: $2,500 liquidated damages per person, plus punitive damages and fees; the engine of the pixel class-action wave.
Amendments, rules & related
Any company with significant video content, media, entertainment, streaming, healthcare, retail with product video, has active VPPA exposure from standard marketing-stack practices. A distinct regime from CIPA; the two must not be blurred.

Practitioner note. The practical test: does a pixel on a video page transmit both an identifier and the video title/URL? That pairing is the complaint template.

Specialty and adjacent state laws

Single-subject laws: biometric, consumer-health, data-broker, wiretapping, breach-notification, genetic, and minors'. Several carry a private right of action and drive more litigation than the comprehensive statutes.

California AB 45, family planning location data and health geofencing

Cal. Civ. Code §§ 1798.99.90-1798.99.93 (Stats. 2025, Ch. 134)
In effectJan 1, 2026 · chaptered Sep 26, 2025
Applies to
Two conduct-specific prohibitions binding any person, not only businesses meeting a threshold. § 1798.99.91 bars collecting, using, disclosing, selling, sharing or retaining the personal information of a natural person physically at or within a precise geolocation of a family planning center, defined as a radius of 1,850 feet or less, except as necessary to provide goods or services the person requested. § 1798.99.92 bars geofencing an entity that provides in-person health care services in California in order to track a person, collect personal information, notify them, or advertise to them, and bars selling or sharing personal information to a third party for those uses.
Rights & obligations
Not a rights statute. These are outright prohibitions with no consent path.
Sensitive data
Carve-out from § 1798.99.91 for providers subject to the Confidentiality of Medical Information Act and for HIPAA covered entities and business associates.
Universal opt-out signals
Not applicable, this is a prohibition rather than an opt-out regime
Cure period
None.
Enforcement
For the § 1798.99.92 geofencing ban, the Attorney General only: injunctive relief plus a civil penalty of $25,000 per violation, deposited in the California Reproductive Justice and Freedom Fund. The CPPA has no role under AB 45.
Private right of action
Yes, but only under § 1798.99.91(c): an aggrieved person or entity, including a family planning center itself, may sue within three years of discovery for injunctive and monetary relief, recovering treble actual damages plus expenses, costs and attorney’s fees. There is no private right of action under the § 1798.99.92 geofencing ban.
Amendments, rules & related
Part of a large 2025 California class of privacy and AI bills, alongside SB 361’s expanded data broker disclosures. California keeps regulating by accretion: the CCPA is the floor, not the whole story.

Practitioner note. This is narrower and sharper than a general health and location regime. It does not restrict location-data monetization at large; it draws a hard perimeter around family planning centers and in-person health care providers, and puts treble damages behind the first of the two bans. If you buy location segments or run geofenced campaigns, the question is not whether you handle health data but whether any audience could have been built from proximity to a covered facility.

California's adjacent stack, CalOPPA, Shine the Light, CMIA, SOPIPA

Bus. & Prof. Code § 22575; Civ. Code §§ 1798.83, 56 et seq.
In effect1981-2016 · CMIA 1981; CalOPPA 2004; SOPIPA 2016
Applies to
CalOPPA: any commercial website or app collecting Californians' PII (a conspicuous privacy policy with required contents, including Do-Not-Track response disclosure). Shine the Light: businesses sharing personal information with third parties for those parties' direct marketing. CMIA: providers of health care, a definition amended to reach many health apps. SOPIPA: edtech services.
Rights & obligations
CalOPPA: the posted-policy obligation that makes every other say-do gap actionable. Shine the Light: annual disclosure of third-party marketing shares on request. CMIA: authorization before disclosure of medical information, with statutory damages. SOPIPA: no targeted ads, profiling, or sale by edtech operators.
Enforcement
AG (CalOPPA via UCL); CMIA carries private statutory damages.
Private right of action
Two of them, not one. CMIA: § 56.36(b)(1) gives nominal damages of $1,000 with no need to show actual harm, and § 56.35 adds compensatory and punitive damages up to $3,000 plus fees. Shine the Light also carries an express action: Civ. Code § 1798.84(b)-(c) lets an injured customer sue for damages and a civil penalty up to $500 per violation, or up to $3,000 where the violation is willful, intentional or reckless, subject to a 90-day cure defence for non-willful violations. CalOPPA and SOPIPA state no remedy in their own text.
Amendments, rules & related
These predate the CCPA and still apply alongside it, CalOPPA is why a non-compliant privacy policy is independently actionable even where a CCPA claim would not lie.

Practitioner note. Health apps repeatedly miss CMIA: if your app offers health services to Californians, authorization requirements and damages exposure apply regardless of your HIPAA status.

CIPA & state wiretap law, the session-replay and pixel litigation wave

Cal. Penal Code § 631 et seq. and state analogs
In effectLitigation wave: 2022-present
Applies to
Any website or app using tracking pixels, session replay, chat transcripts, or analytics that transmit visitor interactions to third parties, argued by plaintiff's firms to be "wiretapping" under all-party-consent statutes (California CIPA foremost; Pennsylvania, Massachusetts, Florida and others have analogs used similarly).
Rights & obligations
Not a rights statute: a consent statute ported from telephony. The theory: interception without all-party consent.
Enforcement
Private demand letters and class actions at industrial scale.
Private right of action
Yes. Cal. Penal Code § 637.2(a) sets the greater of $5,000 per violation or treble actual damages, and § 637.2(c) removes any requirement to show actual damages first. That combination is the engine behind the demand-letter volume.
Amendments, rules & related
Demand letters typically seek roughly $50,000 in settlement plus roughly $30,000 in fees, an ~$80,000 problem per instance, with targeted companies seeing two to six per year. The defense arms race has moved from no-disclosure, to disclosure (defeated by the contemporaneous-consent argument, you cannot consent to something already underway), to the current edge: a time gap between disclosure and tag firing, with a documented record of what fired when.

Practitioner note. Two calibrations that matter: (1) this is private litigation risk, not a CCPA obligation, the CCPA never required a tracking banner; (2) going fully opt-in does not close the gap, because "strictly necessary" vendors that are third parties keep the theory alive. A timestamped evidentiary record of disclosure-then-firing is the strongest settlement-posture lever.

Data broker registration & the California Delete Act

Cal. SB 362 (2023); Civ. Code § 1798.99.80 et seq.
In effectRegistries live; DROP duties from 2026
Applies to
Data brokers, businesses that knowingly collect and sell personal information about consumers with whom they have no direct relationship. § 1798.99.80(c) carves out FCRA, GLBA, insurance-information and HIPAA-adjacent activity. Registration regimes: California (CPPA), Vermont (the original, 2018), Texas and Oregon. Connecticut joins via Public Act 26-64, with sections effective 1 Oct 2026 but the operative duty, no selling or licensing brokered personal data without an active registration, beginning 1 Jan 2027, administered by the Department of Consumer Protection at $2,500 initial and renewal, with an accessible deletion mechanism due 1 July 2028.
Rights & obligations
California's Delete Act adds the one-stop DROP mechanism: the consumer-facing deletion portal opened Jan 1, 2026, and brokers must access and process DROP deletion requests beginning Aug 1, 2026 and at least every 45 days thereafter, deletion of all held data absent an exemption, on a recurring basis.
Enforcement
California: CPPA administrative action. § 1798.99.82(c) sets $200 per day for failure to register plus fees owed, and § 1798.99.82(d)(1) $200 per deletion request per day for failure to delete, with a five-year limitation at § 1798.99.89. Connecticut’s regime sits with the Department of Consumer Protection rather than the Attorney General.
Private right of action
None.
Amendments, rules & related
California SB 361 (2025) expanded registration disclosures, including whether data is shared with foreign actors or used for AI training, effective 1 Jan 2026. § 1798.99.86(e)(1) adds independent third-party audits from 1 Jan 2028, every three years. Expect more states to copy the model.

Practitioner note. The August 2026 DROP processing duty just took effect: any company meeting California's broker definition now owes recurring, portal-driven deletion, an operational pipeline, not a policy statement. Broker status analysis (you sell data about people you have no relationship with) catches ad-tech intermediaries, list vendors, and identity-graph products that never self-identify as brokers.

Employee monitoring notice laws

N.Y. Civ. Rights Law § 52-c*2; Conn. Gen. Stat. § 31-48d; 19 Del. C. § 705
In effectCT 1998; DE 2001; NY 2022
Applies to
Employers monitoring employee email, internet usage, or telephone communications in New York (private employers, written notice at hiring plus acknowledgment), Connecticut (posted notice), and Delaware (notice with acknowledgment or daily notice).
Rights & obligations
Notice only: these are transparency statutes, not consent statutes.
Enforcement
New York: AG enforcement with escalating civil penalties of up to $500 for a first violation, $1,000 for a second and $3,000 for a third and subsequent. Delaware: a civil penalty of $100 per violation. Connecticut’s regime could not be verified.
Private right of action
New York: none in the text. Delaware: contested. 19 Del. C. § 705(c) allows a civil penalty claim to be filed in any court of competent jurisdiction without reserving it to the State, and § 705(d) says the section is not an exclusive remedy. Do not assert that Delaware has no private right of action.
Amendments, rules & related
California reaches employee monitoring differently: employees are CCPA consumers, so monitoring data is subject to access and deletion rights, and CIPA all-party consent covers call recording.

Practitioner note. Remote work made this multistate by default: the employee's state, not headquarters, drives coverage. Fold monitoring notices into onboarding paperwork for NY/CT/DE hires and treat California employee data as CCPA data.

Genetic privacy laws, Illinois GIPA and DTC genetic-testing statutes

410 ILCS 513; ~15 state DTC statutes
In effect1998 (IL); 2021+ (DTC wave)
Applies to
Illinois GIPA: employers and insurers using genetic information (family medical history included). The DTC wave (California, Arizona, Utah, and a dozen-plus others): direct-to-consumer genetic testing companies.
Rights & obligations
GIPA: no soliciting or using genetic information in employment or insurance contexts. DTC statutes: express consent for collection, use, and each new category of use; consent before transfer; deletion and sample-destruction rights.
Enforcement
State AGs for DTC statutes.
Private right of action
Yes. Illinois GIPA § 40 follows the BIPA model: $2,500 liquidated for a negligent violation and $15,000 for an intentional or reckless one, or actual damages, whichever is greater, plus fees, costs, expert fees and injunctive relief, running to any person aggrieved. A litigation wave began in 2023 targeting employer physicals that asked about family medical history.
Amendments, rules & related
Genetic data is also a named sensitive category in nearly every comprehensive state law and in the DOJ bulk-data rule.

Practitioner note. GIPA is following the BIPA arc, same plaintiff's bar, same statutory-damages engine, employment-context focus. HR intake forms and occupational-health vendors are the exposure to audit.

Illinois Biometric Information Privacy Act (BIPA)

740 ILCS 14 (2008)
In effect2008
Applies to
Private entities collecting, capturing, or otherwise obtaining biometric identifiers or information (fingerprints, voiceprints, face geometry, retina/iris scans) from Illinois residents, employees included.
Rights & obligations
Written notice of purpose and retention, a written release before collection, a public retention-and-destruction schedule, no sale, and disclosure limits.
Enforcement
Private litigation drives it entirely.
Private right of action
Yes. § 20(a) sets liquidated damages of $1,000 for a negligent violation and $5,000 for an intentional or reckless one, or actual damages, whichever is greater, plus attorney’s fees, expert fees and injunctive relief.
Amendments, rules & related
2024 amendment: a single recovery per person per collection method (overriding the per-scan accrual reading of Cothron), and electronic signatures expressly satisfy the written-release requirement. Thousands of class actions since 2015, including a landmark $650M settlement.

Practitioner note. Timekeeping, access control, voice authentication, and camera analytics vendors are the usual exposure paths. If you touch Illinois employees or users with anything biometric-shaped, BIPA diligence comes before feature launch.

Minors' privacy and online-safety laws, the state wave

NE LB 504; VT AADC; MD Kids Code; TX SCOPE; FL HB 3; NY CDPA; more
In effectRolling: 2024-2027
Applies to
Online services likely to be accessed by minors (age-appropriate-design-code model) or social platforms specifically (access-restriction model). Layered on top of COPPA's under-13 floor and the 13-17 protections inside the comprehensive laws (CT, MD, NJ, DE, OR, MT, VT).
Rights & obligations
Duty-of-care and default-privacy-settings obligations (AADC model); parental-consent and age-verification requirements (access model); bans on targeted advertising to minors and on sale of minors' data across a growing set of states.
Enforcement
State AGs.
Private right of action
Generally none.
Amendments, rules & related
Anchors verified against primary text: Nebraska LB 504, the Age-Appropriate Online Design Code Act, approved 30 May 2025 and operative 1 Jan 2026, AG-only enforcement up to $50,000 per violation with no penalty action before 1 July 2026. Vermont Act 63, signed 12 June 2025, codified at 9 V.S.A. § 2449a, AG-only, effective 1 Jan 2027 rather than on enactment. Not verified against primary text: the New Hampshire under-13 sale ban, because the 2026 amendment is not yet incorporated into the published RSA, and the Connecticut 13-17 ban, because the Connecticut code site was unreachable. Several laws in this family, including the California design code, parts of Texas SCOPE and Florida HB 3, have been enjoined in whole or in part on First Amendment grounds; the litigation map changes quarterly.

Practitioner note. Two compliance postures are emerging: age-gate everything (access model) or design-to-default-safety (AADC model). Most multistate operators are converging on knowledge-based minor flags plus no-targeted-ads-under-18 as the portable baseline, it satisfies the comprehensive-law provisions regardless of how the First Amendment litigation resolves.

New York Health Information Privacy Act (pending)

NY S9269 (2025-26 session)
PendingIf signed: 6 months after signing
Applies to
Entities processing "regulated health information" of New York residents (and of individuals physically in New York), defined to reach location data indicating health services, reproductive and sexual health information, and health inferences drawn by algorithms.
Rights & obligations
Written consent or a strictly-necessary purpose before processing; access and deletion within 30 days; an outright prohibition on selling regulated health information.
Enforcement
NY AG; penalties up to $15,000 per violation.
Private right of action
Not identified in bill summaries reviewed.
Amendments, rules & related
Passed the Senate Jun 3, 2026 and Assembly Jun 4, 2026; delivered to the Governor and awaiting signature at last check. An earlier version passed in January 2025 was vetoed; this is the revised attempt. New York also runs the SHIELD Act (breach/security) and a Child Data Protection Act.

Practitioner note. If signed, this becomes the third major consumer-health regime (after Washington and Nevada) and the first in a top-three-population state without HIPAA's boundaries. Watch the signature; the six-month runway is short.

State AI acts (adjacent), Colorado, Texas, Utah

Colo. SB 26-189 (C.R.S. § 6-1-1701 et seq., as reenacted); Tex. HB 149; Utah SB 149
UpcomingCO Jan 1, 2027; TX Jan 1, 2026; UT May 1, 2024
Applies to
Colorado, as reenacted. SB 26-189, signed 14 May 2026, repealed and reenacted part 17 as Automated Decision-Making Technology in Consequential Decisions, taking effect 1 January 2027 and applying to consequential decisions made on or after that date. Duties run to developers and deployers of automated decision-making technology used in consequential decisions. Texas TRAIGA (HB 149): prohibited-purpose rules and government-use guardrails, effective 1 Jan 2026. Utah SB 149: disclosure duties around generative AI.
Rights & obligations
Colorado, as reenacted: developer technical documentation to deployers, consumer notice at the point of interaction, a plain-language explanation within 30 days of an adverse consequential decision, and a right to request human review. Utah: § 13-2-12(3) requires disclosure that the person is interacting with generative AI if asked or prompted, for general consumer transactions; the affirmative, unprompted disclosure duty applies to regulated occupations.
Universal opt-out signals
Not applicable
Cure period
Colorado: 60-day notice and cure before 1 Jan 2030.
Enforcement
Colorado: AG enforcement through the Colorado Consumer Protection Act as a deceptive trade practice, with rules due by 1 Jan 2027. Texas: AG, with civil penalties.
Private right of action
Colorado: the act expressly creates no new private right of action. Not separately verified for Texas or Utah.
Amendments, rules & related
The chain matters. SB 24-205 as originally enacted imposed duties from 1 Feb 2026; SB 25B-004 pushed that to 30 Jun 2026; SB 26-189 then repealed and reenacted the whole part. The high-risk AI system framing, the anti-algorithmic-discrimination duties and the impact assessments of the original act were all dropped. What remains is a transparency and human-review statute; on discrimination it only allocates fault between developers and deployers in actions under existing law.

Practitioner note. Anyone working from a 2024 or 2025 summary of the Colorado AI Act is reading about a statute that no longer exists. Privacy teams still inherit this work, because the compliance inputs are the same data inventories, notices and explanation workflows, but the obligation is now disclosure and human review rather than impact assessment. Treat it as an extension of the profiling and ADMT workstream.

State data breach notification laws, all 50 states

50 states + DC and territories
In effect2002-2018 (CA first, AL/SD last)
Applies to
Any entity holding defined personal information of a state's residents; triggered by unauthorized acquisition or access. Definitions of covered PI, harm thresholds, and timing vary by state.
Rights & obligations
Notice to affected individuals, with deadlines ranging from "most expedient time possible" to fixed 30, 45 and 60-day windows; California moved to a hard 30-day clock on 1 Jan 2026. AG or regulator notification above per-state thresholds; credit-monitoring offers in some states; substitute-notice rules.
Enforcement
State AGs; a handful of states allow private suits, and breach litigation proceeds under negligence and contract theories everywhere.
Private right of action
Varies; litigation exposure is universal regardless.
Amendments, rules & related
Sectoral overlays stack on top: HIPAA breach rules, GLBA/FTC Safeguards notification, NYDFS Part 500 for financial services, SEC 8-K material-incident disclosure for public companies.

Practitioner note. The operational answer is a single incident-response playbook keyed to the strictest common denominators (shortest deadline, broadest PI definition) rather than 54 separate analyses at 2 a.m.

Texas CUBI & Washington HB 1493, biometric laws

Tex. Bus. & Com. Code § 503.001; RCW 19.375
In effect2009 / 2017
Applies to
Texas: capture of biometric identifiers for a commercial purpose. Washington: enrollment of biometric identifiers in a database for a commercial purpose.
Rights & obligations
Notice and consent before capture/enrollment; sale and disclosure restrictions; retention limits (Texas: destroy within a year of the purpose ending, with exceptions).
Enforcement
AG-only in both states. Texas § 503.001(d) sets a civil penalty of up to $25,000 per violation; RCW 19.375.030(2) says the chapter may be enforced solely by the attorney general.
Private right of action
None.
Amendments, rules & related
Texas CUBI went from dormant to defining. The Texas AG announced a $1.4 billion settlement with Meta on 30 July 2024, described in the announcement as the first suit brought and first settlement obtained under CUBI, an order of magnitude above anything under the comprehensive laws. A $1.375 billion Google settlement in principle followed in May 2025, though that one bundles geolocation and incognito claims and is not a pure CUBI figure. Texas HB 149 added AI training and development carve-outs at § 503.001(e)(2)-(3) and (f), effective 1 Jan 2026.

Practitioner note. AG-only does not mean low-risk; Texas has shown CUBI exposure can dwarf comprehensive-law penalties. Colorado's 2025 biometric amendments (see the Colorado entry) add a third enforcement-only regime with employer-specific rules.

Washington My Health My Data Act (MHMD)

RCW 19.373 (2023)
In effectMar 31, 2024 · Small businesses: Jun 30, 2024
Applies to
Any legal entity that conducts business in Washington or targets Washington consumers and collects consumer health data, defined expansively to include inferences, biometrics, and data that identifies past, present, or future physical or mental health status. Covers non-residents whose data is collected in Washington. No size thresholds for the core prohibitions.
Rights & obligations
Consent before collecting or sharing consumer health data beyond what is necessary for a requested service; a separate, signed valid authorization before any sale; access and deletion rights (deletion propagates to affiliates and processors); geofencing ban around in-person healthcare facilities.
Enforcement
Washington AG, plus consumers directly.
Private right of action
Yes: via the Washington Consumer Protection Act. Expansive definitions plus a private right of action: the combination that made BIPA a litigation engine.
Amendments, rules & related
Nevada enacted a parallel consumer health data law (SB 370, also effective Mar 31, 2024) with AG-only enforcement; Connecticut folded similar consumer-health protections into the CTDPA.

Practitioner note. "Health data" here includes what ad-tech infers: wellness-app events, symptom searches on your properties, purchases that imply a condition. Retail, fitness, and food businesses have discovered they hold MHMD-covered data. Litigation against major platforms and retailers began in 2025, check current posture.

Frequently asked questions

Next step

The gap this atlas keeps pointing at

Ketch is permissioning infrastructure built around that split: collection control, the browser-side tag and cookie blocking that stops future collection, and downstream processing control, server-to-server, purpose-scoped instructions that change how a downstream system may process data it already holds for a specific person.

Get Started Free

Get started in less than 5 min