Generate your Privacy Policy for free, Get started now →

State privacy laws

100,000 Consumers: Utah, Iowa, Indiana Privacy Scope

100,000 Consumers: Utah, Iowa, Indiana Privacy Scope

Utah, Iowa, and Indiana all trigger privacy-law coverage at 100,000 processed consumers a year, but Utah's Consumer Privacy Act is the only one of the three that also requires $25 million or more in annual revenue, per the enrolled Utah Senate Bill and Iowa's codified statute. See the full threshold, cure-period, and penalty comparison for all three laws.

Read article
$7,500 Per Violation: Virginia CDPA Enforcement 2026

$7,500 Per Violation: Virginia CDPA Enforcement 2026

Virginia's Consumer Data Protection Act caps civil penalties at $7,500 per violation and covers any business controlling data on 100,000 or more Virginia consumers, per Code of Virginia section 59.1-584. See how VCDPA's cure period, threshold, and 2026 scope expansions compare to the three other states that followed Virginia into effect in 2023.

Read article
Universal Opt-Out Mechanisms 2026: 12-State Adoption

Universal Opt-Out Mechanisms 2026: 12-State Adoption

At least 12 US states require businesses to honor a universal opt-out signal such as Global Privacy Control as of August 2026, per compiled state Attorney General guidance. See which states mandate it, when each requirement took effect, and what enforcement looks like so far.

Read article
35,000 Consumers: Oregon and Delaware Privacy Scope

35,000 Consumers: Oregon and Delaware Privacy Scope

Delaware's Personal Data Privacy Act applies once a business processes the data of 35,000 Delaware consumers a year, well below Oregon's 100,000-consumer bar under the Oregon Consumer Privacy Act. See both laws' thresholds, penalty caps, cure periods, and 2026 enforcement posture side by side.

Read article
State Privacy Law Exemptions: 13 of 20 Exempt Nonprofits

State Privacy Law Exemptions: 13 of 20 Exempt Nonprofits

13 of the 20 US state comprehensive privacy laws in effect or enacted as of January 2026 fully exempt nonprofit organizations, per Foley & Lardner's state privacy law comparison chart. See which states exempt GLBA, HIPAA and B2B data too, and where California is the outlier.

Read article
New Jersey Data Privacy Act: Key Figures

New Jersey Data Privacy Act: Key Figures

New Jersey can fine a business up to $20,000 per violation of its Data Privacy Act, and the law's mandatory cure period expired July 1, 2026, according to the New Jersey Division of Consumer Affairs' official NJDPA guidance. See the applicability thresholds, penalty structure, and first-year enforcement data.

Read article
Colorado Privacy Act: Key Figures and Deadlines

Colorado Privacy Act: Key Figures and Deadlines

Colorado can fine a business up to $20,000 per violation under the Colorado Privacy Act, with no aggregate cap on the total, per Colorado Revised Statutes 6-1-112. See the full 2023-2027 deadline timeline, applicability thresholds, and how Colorado's penalty structure compares to Virginia, Connecticut, and California.

Read article
$5,000 Per Violation: Connecticut CTDPA Enforcement 2026

$5,000 Per Violation: Connecticut CTDPA Enforcement 2026

Connecticut's CTDPA caps civil penalties at $5,000 per willful violation under CUTPA, and the Attorney General's office logged 1,830 data breach notifications in 2025, per the OAG's own 2025 CTDPA Enforcement Report. See the law's first dedicated settlement, the full tally of privacy-related payments to the state, and how its scope expands in 2026.

Read article
45% of US Websites Honor State Privacy Law Opt-Outs

45% of US Websites Honor State Privacy Law Opt-Outs

Only 45% of the 11,708 US websites Wesleyan University researchers tracked actually honored Global Privacy Control opt-out signals as of April 2024, per research presented at USENIX Security 2025. See measured compliance rates by industry, self-reported confidence versus tested behavior, and a real enforcement fine.

Read article
20 of 50 US States Have Privacy Laws in 2026 [Tracker]

20 of 50 US States Have Privacy Laws in 2026 [Tracker]

20 of the 50 US states, 40 percent, have a comprehensive consumer privacy law in effect as of 2026, per the IAPP's US State Privacy Legislation Tracker. Four more are enacted but not yet effective, and 26 states still have no comprehensive privacy law at all.

Read article
Just 3 States Require a Biometric Privacy Policy [2026]

Just 3 States Require a Biometric Privacy Policy [2026]

Only 3 of the 50 US states, Illinois, Texas, and Washington, have a dedicated biometric privacy statute in 2026, and just one of them requires the retention policy itself to be written down and made public. See how all 20 comprehensive state privacy laws now treat biometric data, per RecordingLaw's 2026 fifty-state comparison.

Read article