Data Privacy Laws in the US: A Complete 2026 Guide
Your privacy team probably isn't asking, “What is US privacy law?” They're asking why the company got one deletion request from California, one access request from Connecticut, one opt-out signal routed through ad tech, and a leadership question about AI training data, all before lunch.
That's the problem with data privacy laws in the US. The issue isn't awareness. It's operational mismatch. Legal teams summarize statutes. Product teams ship flows. Regulators now test whether those flows honor the rights and limits the statutes require.
If you run compliance for a national enterprise, stop treating US privacy as a reading project. Treat it as a routing problem. You need to know which law applies, when it applies, where exemptions end, and which controls produce evidence fast.
Table of Contents
The US Privacy Patchwork and Why It Matters Now - What your team should map first
Why the US Has No Single Federal Privacy Law - The sectoral model became the default
Federal Sectoral Privacy Laws You Must Comply With - Health, financial, and children's data - Credit, marketing, and communications rules - The residual federal backstop
State Comprehensive Privacy Laws and the 19-State Map - Where enterprises should focus first - Build your state matrix around the fields that change outcomes
Core Obligations Across US Privacy Laws - Start with notice and choice - Rights handling, minimization, and security
How US Privacy Enforcement Is Changing in 2025 and 2026 - Where 2025 to 2026 enforcement is actually focused - The decision points compliance teams should track - What good evidence looks like now
Engineering Privacy Controls Using the NIST Framework - Controls that actually matter - Don't oversell voluntary guidance
How Federal and State Laws Interact in Practice - Four interaction patterns that matter - The federal backstop still matters
Rethinking Compliance Beyond the Privacy Policy - What to test instead
A 30 60 90 Day Compliance Roadmap for 2026 - Days 1 to 30 - Days 31 to 60 - Days 61 to 90
Frequently Asked Questions for Compliance Teams - Which cure periods actually differ in practice - Are nonprofits exempt - What about B2B and employee data - Does honoring Global Privacy Control solve all opt-out duties - How do GLBA exemptions interact with state consumer rights - What counts as sensitive personal information - Can one DPIA satisfy HIPAA, state law, and NIST
The US Privacy Patchwork and Why It Matters Now
At 9:00 a.m., your team receives a California deletion request. By 10:00 a.m., ad tech is passing a browser opt-out signal that Colorado and California regulators expect you to honor. Before noon, procurement asks whether your AI training workflow pulls consumer data from a broker. That is the U.S. privacy problem in practice.
A national company does not face one privacy regime. It faces a decision map. You need to know which state laws you trigger, which exemptions apply, whether a cure period exists, and which behaviors regulators are testing now. The answer usually turns on resident location, revenue and processing thresholds, the role you play with the data, and whether the product uses targeted advertising, profiling, sale or sharing, sensitive data, or brokered data.
The older structure still shapes that map. The United States built privacy law through federal sector statutes, state consumer privacy laws, narrower state rules, and FTC unfair or deceptive practices enforcement, rather than one general code (history of US privacy law).

What your team should map first
Start with legal triggers that change operational duties.
Resident scope: Map where the people are, not where the company sits. State consumer privacy laws generally key off the resident, and employee and B2B treatment can differ by statute.
Thresholds and role: Check whether the law applies because of revenue, volume of personal data processed, or the percentage of revenue tied to selling data. Then confirm whether you act as a controller, processor, business, service provider, or contractor under the relevant law.
Data and use cases: Separate account data, support data, adtech and analytics data, precise geolocation, sensitive data, employee data, and AI training inputs. Different categories trigger different notice, consent, and assessment duties.
Enforcement posture: Do not treat every state the same. Cure periods differ. Some are gone, some are discretionary, and some are limited. Regulators in 2025 and 2026 are concentrating on dark patterns, Global Privacy Control recognition, profiling and automated decision-making, children's data, and data broker obligations.
State law is now the main source of new privacy obligations for consumer-facing enterprises. The practical question is not whether the patchwork exists. The practical question is which parts of it attach to your business this quarter, and which product defaults will create enforcement risk first.
Practical rule: Start with applicability, rights-routing, and product controls. Update the privacy policy after those decisions are made.
Why the US Has No Single Federal Privacy Law
A national retailer can meet HIPAA in one business line, GLBA in another, and still face state consumer privacy duties across its website, loyalty program, and adtech stack. That split is not temporary. It is how U.S. privacy law was built.
The United States never adopted a single baseline consumer privacy code because Congress regulated privacy problem by problem, industry by industry, and agency by agency. The result is a system that treats privacy as several separate compliance questions. Public records. Credit reporting. Health data. Financial data. Children's data. General consumer data. Each category developed under different statutes, regulators, and political coalitions.
The federal starting point was narrow. The Privacy Act of 1974 governs federal agency record systems and limits disclosure of covered records without consent unless a statutory exception applies (DOJ Privacy Act overview). It established rules for the government's own files. It did not create a general privacy law for private companies.

The sectoral model became the default
Congress kept adding privacy rules through targeted statutes. FCRA governs the consumer reporting system. HIPAA governs protected health information in the hands of covered entities and business associates. GLBA covers defined financial institutions and their customer information. COPPA regulates online collection of personal information from children under 13. The dates matter less than the pattern. Washington passed narrow laws for specific risks and left the rest to a mix of state law and FTC enforcement.
That history explains today's decision map. Start by asking which regulated role your company plays, which data set is involved, and whether the use case falls inside a sectoral statute. If the answer is yes, federal law applies directly. If the answer is no, state consumer privacy law usually becomes the main operating rule, with the FTC acting as the backstop for deceptive claims, unfair data practices, broken consent flows, and dark patterns.
Do not wait for Congress to simplify this. Plan for continued fragmentation, more state divergence, and sharper enforcement around AI, Global Privacy Control recognition, profiling, children's data, and data broker activity. If your team needs a visual reference for how privacy and security controls often intersect across jurisdictions, use this privacy and data security program reference image.
The right operating assumption is simple: federal law covers specific lanes, state law governs the open road, and the FTC will challenge any gap between what your product does and what your notices promise.
Federal Sectoral Privacy Laws You Must Comply With
Federal privacy law in the US is narrow by design. It attaches to data type, industry, or communications channel. If you map those three elements correctly, most federal applicability questions become manageable.
Health, financial, and children's data
HIPAA applies to covered entities and business associates handling protected health information. If you aren't one of those entities, HIPAA usually doesn't save you from state privacy law. If you are, it governs PHI and related disclosures, safeguards, and breach handling.
GLBA applies to financial institutions and related handling of covered financial information. It's not a blanket exemption for every data set a financial company touches. Marketing analytics, general website telemetry, and recruiting data can still create separate exposure.
COPPA applies to operators of child-directed online services and to services with actual knowledge they collect personal information from children under 13. The key operational issue is verifiable parental consent and disciplined product design around child data collection.
Credit, marketing, and communications rules
FCRA applies to consumer reporting agencies, users of consumer reports, and furnishers in the credit ecosystem. If your product helps determine eligibility for credit, employment, housing, or similar decisions, FCRA questions arrive quickly.
TCPA sits on the outreach layer. If your teams run telemarketing, autodialed outreach, or prerecorded messaging, this statute belongs in your privacy and marketing governance process, not in a separate telecom silo.
CAN-SPAM governs commercial email practices. ECPA governs access to and interception or storage issues involving electronic communications. These laws don't look like modern omnibus privacy statutes, but they remain active compliance constraints.
The residual federal backstop
The FTC's unfair-and-deceptive-practices authority is the default federal hook when no sectoral statute fully fits. If your notice says one thing and your SDKs, ad-tech vendors, or AI tooling do another, that mismatch can become the case.
Federal Sectoral Privacy Laws at a Glance | Data Type Covered | Regulated Entity | Enforcement Authority |
|---|---|---|---|
HIPAA | Protected health information | Covered entities and business associates | HHS OCR |
GLBA | Financial information covered by GLBA | Financial institutions and covered service providers | Federal regulators and FTC, depending on entity |
COPPA | Personal information from children under 13 | Operators of child-directed services or services with actual knowledge | FTC |
FCRA | Consumer report data | Consumer reporting agencies, users, furnishers | FTC, CFPB, other regulators |
TCPA | Telemarketing and certain communications data | Businesses using covered calling or messaging practices | FCC, private litigants |
CAN-SPAM | Commercial email data and practices | Senders of commercial email | FTC and other authorities |
ECPA | Stored or intercepted electronic communications | Service providers and others handling covered communications | DOJ and other authorities |
Here's the blunt version. If your company says, “We're not in healthcare or banking, so federal privacy law doesn't matter,” your team is probably missing COPPA, FCRA, communications rules, and FTC deception risk.
State Comprehensive Privacy Laws and the 19-State Map
Your product team wants one national consent flow. Your ad-tech stack honors Global Privacy Control in some contexts, ignores it in others, and your data broker intake process still relies on contract language from last year. That is how companies walk into preventable state enforcement.
Treat the 19-state map as a decision map. Start with three questions. Which states pull you into scope based on revenue, consumer volume, or business model. Which states change the product build because they regulate targeted advertising, profiling, sensitive data, or universal opt-out signals differently. Which states still give you time to cure, and which expect you to get it right on the first pass.
Several newer state laws became enforceable during 2025, and more take effect in 2026. Use an effective-date tracker that your legal and product teams can maintain, such as the IAPP US state privacy legislation tracker: IAPP state privacy tracker. The point is not to memorize dates. The point is to know which launches, ad flows, and vendor transfers need state-specific logic now.
Where enterprises should focus first
California drives the build. It has the broadest operational effect because of "sale" and "sharing," detailed notice expectations, sensitive-data use limits, a dedicated regulator, and active scrutiny of dark patterns and opt-out mechanics.
Colorado and Connecticut matter because regulators there have been explicit about universal opt-out signals. If your cookie banner works but your backend ignores a valid browser signal, you still have a problem. Texas matters because scope works differently from the revenue-threshold model many teams expect, and the attorney general has shown interest in privacy representations that do not match actual processing. Maryland deserves early attention because it is less permissive on data practices than many Virginia-style laws and will force harder decisions on minimization, sensitive data, and youth-facing design.
Virginia and Utah still matter, but mainly as baseline states. They are useful for pattern recognition. They should not set your ceiling.
If your privacy intake cannot separate California "sharing," Colorado universal opt-out signal handling, Maryland data-use limits, and Texas scope analysis, your program is not ready for 2026.
Build your state matrix around the fields that change outcomes
Do not build a 50-state spreadsheet full of summaries. Build a working matrix with the fields that change legal exposure and engineering work:
Scope trigger
Effective or enforceable date
Cure period, including whether it sunsets
Private right of action
Universal opt-out signal treatment
Sensitive data and profiling rules
Data broker exposure and registration risk, where applicable
That last point matters more in 2025 and 2026 than many teams admit. Enforcement attention is clustering around four areas: AI-enabled profiling, dark patterns, Global Privacy Control and other universal opt-out signals, and data broker activity. A state law may look familiar on paper and still require a different implementation priority because regulators are looking at a different failure point.
Comparison of US State Privacy Laws | Trigger Threshold | Effective Date | Cure Period | Private Right of Action |
|---|---|---|---|---|
California / CCPA-CPRA | Varies by statutory scope and business activity | In effect | No general cure right stated here | Limited and context-specific, not a broad general right |
Virginia / VCDPA | Commonly uses data volume or sale-revenue threshold structure | In effect | Cure period exists under the statute | No general private right of action |
Colorado / CPA | Commonly uses data volume or sale-revenue threshold structure | In effect | No permanent cure model like early-state laws | No general private right of action |
Connecticut / CTDPA | Commonly uses data volume or sale-revenue threshold structure | In effect | Temporary cure period existed and expired | No general private right of action |
Utah / UCPA | Uses revenue plus data-volume criteria | In effect | State-specific cure approach | No general private right of action |
Texas / TDPSA | Scope differs materially from revenue-threshold states | In effect | Cure treatment remains important | No general private right of action |
Tennessee / TIPA | Applies under a narrower threshold model | Enforceable in 2025 | Cure period exists | No general private right of action |
Iowa / ICDPA | Uses threshold model with a narrower rights set | Enforceable in 2025 | Cure period exists | No general private right of action |
Minnesota / MCDPA | Uses threshold model with broader obligations than some peers | Enforceable in 2025 | State-specific | No general private right of action |
Nebraska / NDPA | Scope tracks a broader business-activity model | Enforceable in 2025 | Cure period exists | No general private right of action |
New Hampshire / NHPA | Uses lower thresholds than many larger states | Enforceable in 2025 | Cure period exists, with sunset features | No general private right of action |
New Jersey / NJDPA | Threshold model with distinctive sale treatment | Enforceable in 2025 | State-specific | No general private right of action |
Maryland / MODPA | Lower thresholds and stricter substantive limits | Enforceable in 2025 | State-specific | No general private right of action |
Delaware / DPDPA | Lower-threshold model | Enforceable in 2025 | Cure period existed with a sunset structure | No general private right of action |
Indiana / INCDPA | Threshold model similar to Virginia-style statutes | Effective in 2026 | Cure period exists | No general private right of action |
Kentucky / KCDPA | Threshold model similar to Virginia-style statutes | Effective in 2026 | State-specific | No general private right of action |
Rhode Island / RIDTPPA | Lower-threshold model | Effective in 2026 | No cure period | No general private right of action |
If you need a tactical implementation resource for California-specific operational work, this checklist on CCPA compliance steps for North Texas firms is a practical companion for distributed teams that support California residents but operate elsewhere.
My recommendation is simple. Set your design baseline with California, Colorado, Connecticut, Texas, and Maryland. Then run threshold analysis for the rest of the active states, with special attention to Tennessee, Nebraska, New Hampshire, Delaware, and Rhode Island because cure assumptions and scope logic diverge faster there. That approach matches where enforcement and operational risk are headed, not where last year's slide deck said they were.
Core Obligations Across US Privacy Laws
Most US privacy programs fail because they treat obligations as legal categories instead of build steps. Don't do that. Build in sequence.

Start with notice and choice
Your privacy notice has to match your actual collection, use, disclosure, retention logic, and sensitive-data handling. If marketing, product, and legal wrote different versions of the truth, the regulator will find the gap before your internal audit does.
Then distinguish opt-out rights from opt-in obligations. Sale, sharing, targeted advertising, and some profiling uses often sit in opt-out territory. Sensitive data and children's data often demand a higher bar.
For teams harmonizing US and international retention governance, this guide to retention schedules for GDPR is useful because it forces the right operational question: what are we keeping, for what purpose, and for how long?
Rights handling, minimization, and security
Many state laws converge around access, deletion, correction, portability, and deadline-based response handling. Your intake process needs identity verification rules, exception handling, and routing to the systems that hold the data.
The next obligation is the one teams neglect most. Data minimization and purpose limitation. Don't collect because a field might become useful later. Don't retain because storage is cheap. If your engineers need a framing document for integrating privacy controls into broader security architecture, this data privacy and cybersecurity reference is a sensible starting point.
A short explainer can help align legal and technical teams on the implementation side:
Notice: Publish collection and use disclosures that match system behavior.
Choice: Wire opt-out and consent signals into products, not just banners.
Rights: Route access, deletion, correction, and portability requests into the systems of record.
Minimization: Reduce collection fields, retention periods, and internal access.
Security: Apply reasonable safeguards and prepare breach response evidence.
How US Privacy Enforcement Is Changing in 2025 and 2026
Your company sells nationwide, runs targeted ads, uses an AI feature, and accepts traffic from California, Texas, Colorado, and a handful of other states. The question for 2025 and 2026 is no longer whether you have a privacy policy. The question is which state can act first, whether that state still offers a cure period, and whether your product behavior matches your disclosures.
Enforcement is getting more operational and more state-specific. Treat the U.S. patchwork as a decision map. If you trigger California, expect scrutiny on Global Privacy Control, dark patterns, data broker obligations, and sensitive data use. If you trigger Texas, assume an aggressive attorney general and less patience for paper compliance. If you trigger multiple state laws, your risk turns on the strictest rule that applies to the same workflow, not the weakest one.
Where 2025 to 2026 enforcement is actually focused
The priority areas are clear:
AI and automated processing: Regulators want to know what data went into the model, what notices users saw, whether sensitive or minors' data was involved, and whether outputs create unfair or undisclosed downstream uses.
Dark patterns: Choice screens, cookie banners, account settings, and cancellation flows are being examined for friction, asymmetry, and misleading language.
Global Privacy Control: If a browser-level opt-out signal is valid under the applicable state law, your systems need to receive it, honor it, and propagate it to ad-tech and downstream processors.
Data brokers: Registration, deletion workflows, and suppression handling are moving from back-office disclosure work to active enforcement risk.
A recent enforcement analysis describes the shift plainly. Regulators are focusing on user choice integrity, GPC handling, protections for children and teens, and data broker governance, with California and Texas setting the pace and more states expected to become active in 2026 (2025 enforcement trends analysis).
The decision points compliance teams should track
Do not manage enforcement risk as a generic U.S. program. Map it by trigger and remedy.
First, identify which state laws you trigger by revenue, consumer volume, and data-sale or targeted-advertising activity. Then track cure periods state by state. Some laws gave businesses time to fix issues. Others narrowed that option or made cure discretionary. That difference matters when legal is deciding whether to launch a feature with unresolved consent or opt-out gaps.
Second, separate voluntary guidance from enforceable law. Regulator blog posts, FAQs, and technical explainers can signal priorities. They are not all binding. Statutes, regulations, and attorney general actions are what create direct exposure.
What good evidence looks like now
Policy text is weak evidence. Product behavior is strong evidence.
Expect regulators to ask for screenshots of choice flows, event logs showing when a GPC signal was received, vendor configuration showing suppression of targeted advertising, records proving a broker deletion request reached downstream systems, and documentation tying AI training inputs to disclosed purposes. If your consent tool says "opted out" while tags still fire and vendors still receive the event, the violation is in the system design, not the wording of the notice.
That is the shift. Enforcement in 2025 and 2026 is aimed at broken control paths, not missing adjectives in the privacy policy.
Engineering Privacy Controls Using the NIST Framework
NIST gives engineering teams a usable blueprint, but not a legal shield. Treat it as a control architecture, not immunity.
NIST's Privacy Framework says organizations should collect only what is necessary for an identified purpose, define retention periods, and implement scheduled deletion and logging aligned to those purposes. NIST also states clearly that the framework is voluntary and has no force of law (NIST Privacy Framework).
Controls that actually matter
Translate that guidance into product requirements:
Collection limits at ingress: block unnecessary fields in web forms, SDKs, APIs, and mobile events.
Retention clocks by purpose: tie each data category to a retention rule that engineering can enforce.
Deletion jobs: support both scheduled purge and request-based deletion.
Pseudonymization: separate analytics use from direct identity where possible.
Audit logging: preserve evidence showing when data was collected, why, where it flowed, and when it was deleted.
NIST Privacy Framework Functions Mapped to Engineering Controls | Engineering Control | Evidence Produced |
|---|---|---|
Data minimization related controls | Field-level collection rules | Schema definitions, intake configs, change tickets |
Purpose governance related controls | Purpose tags in data inventory | Records of processing, control matrices |
Retention and deletion related controls | Scheduled deletion jobs and retention logic | Deletion logs, retention policies, execution reports |
Access governance related controls | Role-based access and approvals | Access logs, review records |
Response and monitoring related controls | Audit trails and incident workflows | Event logs, incident records, validation outputs |
Don't oversell voluntary guidance
If your team needs a technical governance pattern for operationalizing these controls across services and integrations, this API governance best practices reference fits well with NIST-style implementation work.
One option for enterprises that need outside help on this buildout is Freeform Company. It has published work on data mapping, baseline assessments against GDPR, CCPA, sector requirements, contractual duties, and internal standards, which is the right operating scope for organizations trying to turn legal obligations into system controls. Freeform's role in marketing AI goes back to 2013, which matters because teams now need advisors who understand both compliance architecture and AI-enabled data operations. In practice, that matters for speed and economics too: industry comparisons published in 2026 report that AI marketing agencies can be about 30–60% cheaper on production-heavy work (Automaton comparison), can launch campaigns in 1–2 weeks instead of the 3–6 weeks traditional agencies commonly need (Etradewind comparison), and can test 10–50 times more creative variations while reducing marketing overhead by 30–60% (Hovi comparison).
How Federal and State Laws Interact in Practice
Most difficult privacy questions aren't about a single statute. They're about overlap. Your team needs interaction rules.

Four interaction patterns that matter
HIPAA plus state law. HIPAA governs PHI for covered entities and business associates. But the same organization can still face state-law duties for non-PHI datasets, including marketing, tracking, and nonclinical support data.
COPPA plus state law. COPPA remains the federal baseline for under-13 data. State laws may add separate duties around broader consumer rights or youth-oriented design, but they don't erase COPPA's consent structure.
GLBA plus state law. GLBA may exempt or narrow some state consumer-rights exposure for covered financial data. It does not automatically remove all state privacy risk for every other business process run by that institution.
State stacking. If your company triggers multiple state statutes, it often makes operational sense to implement the strictest workable standard across shared systems, then document justified exceptions.
The expensive mistake is assuming one exemption follows the data everywhere it goes. It usually doesn't.
The federal backstop still matters
When sectoral law doesn't fully apply and state law doesn't neatly address the conduct, the FTC remains the residual federal backstop. That's why product claims, ad-tech architecture, and user-choice integrity matter far beyond any single state statute.
Rethinking Compliance Beyond the Privacy Policy
A privacy policy is a disclosure artifact. It is not proof of compliant processing.
If your opt-out path is buried, your SDK sends data before consent logic resolves, your AI workflow ingests personal data beyond the disclosed purpose, or your vendors operate without usable contractual restrictions, the policy becomes evidence against you. Regulators read policies against technical behavior.
What to test instead
Walk your top user journeys and inspect the actual system actions.
Account creation: What fields are collected, which are optional, and where do they flow next?
Marketing interaction: Which vendors receive data, under what settings, and can those settings be suppressed consistently?
AI enablement: Which datasets feed model development, evaluation, or prompt logging, and what disclosures support that use?
Rights exercise: Can the user do what the policy promises?
For teams that need a disciplined method to identify disconnects between paper controls and operational reality, this guide from CloudCops GmbH is a helpful model for compliance gap analysis.
A mature privacy signoff isn't “the policy is live.” It's “we tested the journey, validated the data path, and confirmed the right can be exercised in the product.”
A 30 60 90 Day Compliance Roadmap for 2026
You don't need a grand transformation plan first. You need ninety days of disciplined execution.

Days 1 to 30
Run the jurisdiction map. Identify which states you trigger, which datasets are in scope, where exemptions plausibly apply, and where they clearly do not. Refresh your records of processing and inventory all third-party recipients.
Days 31 to 60
Build the rights and preference plumbing. Validate request intake, verification, routing, and deadline tracking. Test universal opt-out handling and make sure preference signals propagate into analytics, advertising, and downstream vendor paths.
Recommended sequence: Map applicability first, then rights workflows, then AI and ad-tech defensibility. Teams that reverse that order waste time.
Days 61 to 90
Pressure-test high-risk uses. Review targeted advertising, profiling, sensitive-data handling, AI training inputs, and broker-like data sharing. Update vendor terms where restrictions don't match the states you trigger. Run a tabletop on a regulator request for deletion evidence, preference honoring, or training-data provenance.
Exit criteria should be concrete: an updated inventory, an applicability matrix, functioning rights workflows, tested suppression paths, and decision logs for the high-risk processing your executives care about most.
Quick Reference Catalog of US Privacy Statutes
You need a fast lookup tool, not another lecture. Use this table for first-pass issue spotting, then escalate edge cases to counsel.
US Privacy Statutes at a Glance | Scope | Trigger / Threshold | Core Rights | Cure Period | Enforcer |
|---|---|---|---|---|---|
Privacy Act of 1974 | Federal agency record systems | Federal records handling | Disclosure restrictions and fair information practices | Statutory framework specific | Federal agencies, courts |
HIPAA | PHI and covered healthcare ecosystem | Covered entity or business associate status | Health privacy and access rights within HIPAA framework | Sector-specific | HHS OCR |
GLBA | Covered financial information | GLBA-regulated institution status | Privacy notices and safeguard obligations | Sector-specific | Federal regulators, FTC |
COPPA | Under-13 online data | Child-directed service or actual knowledge | Parental consent framework | Sector-specific | FTC |
FCRA | Consumer report ecosystem | Use or furnishing of covered report data | Access, dispute, accuracy related rights | Sector-specific | FTC, CFPB, others |
CAN-SPAM | Commercial email | Covered commercial email practices | Commercial email rule set | Sector-specific | FTC and others |
CCPA-CPRA | California consumer data | California statutory applicability | Access, deletion, correction, opt-out and related rights | Varies by issue | CPPA, California AG |
VCDPA | Virginia consumers | Threshold-based | Core consumer rights and opt-outs | State-specific | Virginia AG |
CPA | Colorado consumers | Threshold-based | State-specific | Colorado AG | |
CTDPA | Connecticut consumers | Threshold-based | Core consumer rights and opt-outs | Expired temporary cure structure | Connecticut AG |
UCPA | Utah consumers | Revenue plus threshold-based | Narrower core rights set | State-specific | Utah AG |
TDPSA | Texas consumers | Business-activity model | Core consumer rights and opt-outs | Cure structure exists | Texas AG |
MODPA | Maryland consumers | Lower-threshold model | Strong sensitive-data restrictions and consumer rights | State-specific | Maryland AG |
MCDPA | Minnesota consumers | Threshold-based | Core consumer rights and assessments | State-specific | Minnesota AG |
OCPA | Oregon consumers | Threshold-based | Core consumer rights and opt-outs | State-specific | Oregon AG |
RIDTPPA | Rhode Island consumers | Lower-threshold model | Core consumer rights | No cure period | Rhode Island AG |
ICDPA | Iowa consumers | Threshold-based | Narrower core rights set | Cure period exists | Iowa AG |
INCDPA | Indiana consumers | Threshold-based | Core rights and assessments | Cure period exists | Indiana AG |
KCDPA | Kentucky consumers | Threshold-based | Core rights | State-specific | Kentucky AG |
TIPA | Tennessee consumers | Threshold-based | Core rights and business-friendly defenses | Cure period exists | Tennessee AG |
NHPA | New Hampshire consumers | Lower-population-adjusted threshold model | Core rights and opt-outs | Cure period with sunset dynamic | New Hampshire AG |
NJDPA | New Jersey consumers | Threshold-based | Core rights and broader sale framing | State-specific | New Jersey AG |
Frequently Asked Questions for Compliance Teams
Which cure periods actually differ in practice
They differ enough to break a one-size-fits-all remediation plan. Some states keep a cure mechanism, some sunset it, and some are less forgiving. Don't let your incident playbook assume you'll always get time to fix first.
Are nonprofits exempt
Sometimes yes, sometimes no, depending on the statute. Don't generalize from one state to another. Check both the entity exemption and the data exemption. A nonprofit health or education affiliate can still create separate legal questions.
What about B2B and employee data
California changed the market's assumptions here. Teams that still treat B2B and workforce data as automatically out of scope are often relying on expired thinking. Confirm treatment by statute and dataset.
Does honoring Global Privacy Control solve all opt-out duties
No. It helps, and in some jurisdictions it is a critical signal, but it doesn't erase your need for functioning sale, sharing, and targeted advertising controls across systems and vendors.
How do GLBA exemptions interact with state consumer rights
Treat GLBA as a scoped carve-out, not a universal shield. Covered financial data may be treated differently, but adjacent marketing and operational datasets often remain exposed.
What counts as sensitive personal information
That depends on the statute, and the differences matter. Biometric data, precise geolocation, health-related inferences, government identifiers, and children's data often trigger special handling. Maryland deserves special attention because it takes a stricter posture on sensitive data processing.
Can one DPIA satisfy HIPAA, state law, and NIST
One assessment can support all three if it is written well. But don't assume one template automatically satisfies each legal requirement. Use a common fact base, then map the output to each regime's specific expectations. Where the requirement is interpretive rather than binding, document that judgment clearly and get counsel involved for edge cases.
Freeform Company helps enterprises turn privacy obligations into operating controls, with practical support on data mapping, compliance assessments, AI-enabled workflows, and program design that can stand up to regulator scrutiny. If your team needs a faster path from legal analysis to technical implementation, visit Freeform Company.
