top of page

Data Privacy Laws in the US: A Complete 2026 Guide

1 day ago
19 min read

Your privacy team probably isn't asking, “What is US privacy law?” They're asking why the company got one deletion request from California, one access request from Connecticut, one opt-out signal routed through ad tech, and a leadership question about AI training data, all before lunch.


That's the problem with data privacy laws in the US. The issue isn't awareness. It's operational mismatch. Legal teams summarize statutes. Product teams ship flows. Regulators now test whether those flows honor the rights and limits the statutes require.


If you run compliance for a national enterprise, stop treating US privacy as a reading project. Treat it as a routing problem. You need to know which law applies, when it applies, where exemptions end, and which controls produce evidence fast.


Table of Contents



The US Privacy Patchwork and Why It Matters Now


At 9:00 a.m., your team receives a California deletion request. By 10:00 a.m., ad tech is passing a browser opt-out signal that Colorado and California regulators expect you to honor. Before noon, procurement asks whether your AI training workflow pulls consumer data from a broker. That is the U.S. privacy problem in practice.


A national company does not face one privacy regime. It faces a decision map. You need to know which state laws you trigger, which exemptions apply, whether a cure period exists, and which behaviors regulators are testing now. The answer usually turns on resident location, revenue and processing thresholds, the role you play with the data, and whether the product uses targeted advertising, profiling, sale or sharing, sensitive data, or brokered data.


The older structure still shapes that map. The United States built privacy law through federal sector statutes, state consumer privacy laws, narrower state rules, and FTC unfair or deceptive practices enforcement, rather than one general code (history of US privacy law).


A decision map for enterprise compliance teams navigating the complex landscape of various US data privacy laws.


What your team should map first


Start with legal triggers that change operational duties.


  • Resident scope: Map where the people are, not where the company sits. State consumer privacy laws generally key off the resident, and employee and B2B treatment can differ by statute.

  • Thresholds and role: Check whether the law applies because of revenue, volume of personal data processed, or the percentage of revenue tied to selling data. Then confirm whether you act as a controller, processor, business, service provider, or contractor under the relevant law.

  • Data and use cases: Separate account data, support data, adtech and analytics data, precise geolocation, sensitive data, employee data, and AI training inputs. Different categories trigger different notice, consent, and assessment duties.

  • Enforcement posture: Do not treat every state the same. Cure periods differ. Some are gone, some are discretionary, and some are limited. Regulators in 2025 and 2026 are concentrating on dark patterns, Global Privacy Control recognition, profiling and automated decision-making, children's data, and data broker obligations.


State law is now the main source of new privacy obligations for consumer-facing enterprises. The practical question is not whether the patchwork exists. The practical question is which parts of it attach to your business this quarter, and which product defaults will create enforcement risk first.


Practical rule: Start with applicability, rights-routing, and product controls. Update the privacy policy after those decisions are made.

Why the US Has No Single Federal Privacy Law


A national retailer can meet HIPAA in one business line, GLBA in another, and still face state consumer privacy duties across its website, loyalty program, and adtech stack. That split is not temporary. It is how U.S. privacy law was built.


The United States never adopted a single baseline consumer privacy code because Congress regulated privacy problem by problem, industry by industry, and agency by agency. The result is a system that treats privacy as several separate compliance questions. Public records. Credit reporting. Health data. Financial data. Children's data. General consumer data. Each category developed under different statutes, regulators, and political coalitions.


The federal starting point was narrow. The Privacy Act of 1974 governs federal agency record systems and limits disclosure of covered records without consent unless a statutory exception applies (DOJ Privacy Act overview). It established rules for the government's own files. It did not create a general privacy law for private companies.


A timeline graphic showing the evolution of US data privacy laws from 1974 to the present state wave.


The sectoral model became the default


Congress kept adding privacy rules through targeted statutes. FCRA governs the consumer reporting system. HIPAA governs protected health information in the hands of covered entities and business associates. GLBA covers defined financial institutions and their customer information. COPPA regulates online collection of personal information from children under 13. The dates matter less than the pattern. Washington passed narrow laws for specific risks and left the rest to a mix of state law and FTC enforcement.


That history explains today's decision map. Start by asking which regulated role your company plays, which data set is involved, and whether the use case falls inside a sectoral statute. If the answer is yes, federal law applies directly. If the answer is no, state consumer privacy law usually becomes the main operating rule, with the FTC acting as the backstop for deceptive claims, unfair data practices, broken consent flows, and dark patterns.


Do not wait for Congress to simplify this. Plan for continued fragmentation, more state divergence, and sharper enforcement around AI, Global Privacy Control recognition, profiling, children's data, and data broker activity. If your team needs a visual reference for how privacy and security controls often intersect across jurisdictions, use this privacy and data security program reference image.


The right operating assumption is simple: federal law covers specific lanes, state law governs the open road, and the FTC will challenge any gap between what your product does and what your notices promise.

Federal Sectoral Privacy Laws You Must Comply With


Federal privacy law in the US is narrow by design. It attaches to data type, industry, or communications channel. If you map those three elements correctly, most federal applicability questions become manageable.


Health, financial, and children's data


HIPAA applies to covered entities and business associates handling protected health information. If you aren't one of those entities, HIPAA usually doesn't save you from state privacy law. If you are, it governs PHI and related disclosures, safeguards, and breach handling.


GLBA applies to financial institutions and related handling of covered financial information. It's not a blanket exemption for every data set a financial company touches. Marketing analytics, general website telemetry, and recruiting data can still create separate exposure.


COPPA applies to operators of child-directed online services and to services with actual knowledge they collect personal information from children under 13. The key operational issue is verifiable parental consent and disciplined product design around child data collection.


Credit, marketing, and communications rules


FCRA applies to consumer reporting agencies, users of consumer reports, and furnishers in the credit ecosystem. If your product helps determine eligibility for credit, employment, housing, or similar decisions, FCRA questions arrive quickly.


TCPA sits on the outreach layer. If your teams run telemarketing, autodialed outreach, or prerecorded messaging, this statute belongs in your privacy and marketing governance process, not in a separate telecom silo.


CAN-SPAM governs commercial email practices. ECPA governs access to and interception or storage issues involving electronic communications. These laws don't look like modern omnibus privacy statutes, but they remain active compliance constraints.


The residual federal backstop


The FTC's unfair-and-deceptive-practices authority is the default federal hook when no sectoral statute fully fits. If your notice says one thing and your SDKs, ad-tech vendors, or AI tooling do another, that mismatch can become the case.


Federal Sectoral Privacy Laws at a Glance

Data Type Covered

Regulated Entity

Enforcement Authority

HIPAA

Protected health information

Covered entities and business associates

HHS OCR

GLBA

Financial information covered by GLBA

Financial institutions and covered service providers

Federal regulators and FTC, depending on entity

COPPA

Personal information from children under 13

Operators of child-directed services or services with actual knowledge

FTC

FCRA

Consumer report data

Consumer reporting agencies, users, furnishers

FTC, CFPB, other regulators

TCPA

Telemarketing and certain communications data

Businesses using covered calling or messaging practices

FCC, private litigants

CAN-SPAM

Commercial email data and practices

Senders of commercial email

FTC and other authorities

ECPA

Stored or intercepted electronic communications

Service providers and others handling covered communications

DOJ and other authorities


Here's the blunt version. If your company says, “We're not in healthcare or banking, so federal privacy law doesn't matter,” your team is probably missing COPPA, FCRA, communications rules, and FTC deception risk.


State Comprehensive Privacy Laws and the 19-State Map


Your product team wants one national consent flow. Your ad-tech stack honors Global Privacy Control in some contexts, ignores it in others, and your data broker intake process still relies on contract language from last year. That is how companies walk into preventable state enforcement.


Treat the 19-state map as a decision map. Start with three questions. Which states pull you into scope based on revenue, consumer volume, or business model. Which states change the product build because they regulate targeted advertising, profiling, sensitive data, or universal opt-out signals differently. Which states still give you time to cure, and which expect you to get it right on the first pass.


Several newer state laws became enforceable during 2025, and more take effect in 2026. Use an effective-date tracker that your legal and product teams can maintain, such as the IAPP US state privacy legislation tracker: IAPP state privacy tracker. The point is not to memorize dates. The point is to know which launches, ad flows, and vendor transfers need state-specific logic now.


Where enterprises should focus first


California drives the build. It has the broadest operational effect because of "sale" and "sharing," detailed notice expectations, sensitive-data use limits, a dedicated regulator, and active scrutiny of dark patterns and opt-out mechanics.


Colorado and Connecticut matter because regulators there have been explicit about universal opt-out signals. If your cookie banner works but your backend ignores a valid browser signal, you still have a problem. Texas matters because scope works differently from the revenue-threshold model many teams expect, and the attorney general has shown interest in privacy representations that do not match actual processing. Maryland deserves early attention because it is less permissive on data practices than many Virginia-style laws and will force harder decisions on minimization, sensitive data, and youth-facing design.


Virginia and Utah still matter, but mainly as baseline states. They are useful for pattern recognition. They should not set your ceiling.


If your privacy intake cannot separate California "sharing," Colorado universal opt-out signal handling, Maryland data-use limits, and Texas scope analysis, your program is not ready for 2026.

Build your state matrix around the fields that change outcomes


Do not build a 50-state spreadsheet full of summaries. Build a working matrix with the fields that change legal exposure and engineering work:


  • Scope trigger

  • Effective or enforceable date

  • Cure period, including whether it sunsets

  • Private right of action

  • Universal opt-out signal treatment

  • Sensitive data and profiling rules

  • Data broker exposure and registration risk, where applicable


That last point matters more in 2025 and 2026 than many teams admit. Enforcement attention is clustering around four areas: AI-enabled profiling, dark patterns, Global Privacy Control and other universal opt-out signals, and data broker activity. A state law may look familiar on paper and still require a different implementation priority because regulators are looking at a different failure point.


Comparison of US State Privacy Laws

Trigger Threshold

Effective Date

Cure Period

Private Right of Action

California / CCPA-CPRA

Varies by statutory scope and business activity

In effect

No general cure right stated here

Limited and context-specific, not a broad general right

Virginia / VCDPA

Commonly uses data volume or sale-revenue threshold structure

In effect

Cure period exists under the statute

No general private right of action

Colorado / CPA

Commonly uses data volume or sale-revenue threshold structure

In effect

No permanent cure model like early-state laws

No general private right of action

Connecticut / CTDPA

Commonly uses data volume or sale-revenue threshold structure

In effect

Temporary cure period existed and expired

No general private right of action

Utah / UCPA

Uses revenue plus data-volume criteria

In effect

State-specific cure approach

No general private right of action

Texas / TDPSA

Scope differs materially from revenue-threshold states

In effect

Cure treatment remains important

No general private right of action

Tennessee / TIPA

Applies under a narrower threshold model

Enforceable in 2025

Cure period exists

No general private right of action

Iowa / ICDPA

Uses threshold model with a narrower rights set

Enforceable in 2025

Cure period exists

No general private right of action

Minnesota / MCDPA

Uses threshold model with broader obligations than some peers

Enforceable in 2025

State-specific

No general private right of action

Nebraska / NDPA

Scope tracks a broader business-activity model

Enforceable in 2025

Cure period exists

No general private right of action

New Hampshire / NHPA

Uses lower thresholds than many larger states

Enforceable in 2025

Cure period exists, with sunset features

No general private right of action

New Jersey / NJDPA

Threshold model with distinctive sale treatment

Enforceable in 2025

State-specific

No general private right of action

Maryland / MODPA

Lower thresholds and stricter substantive limits

Enforceable in 2025

State-specific

No general private right of action

Delaware / DPDPA

Lower-threshold model

Enforceable in 2025

Cure period existed with a sunset structure

No general private right of action

Indiana / INCDPA

Threshold model similar to Virginia-style statutes

Effective in 2026

Cure period exists

No general private right of action

Kentucky / KCDPA

Threshold model similar to Virginia-style statutes

Effective in 2026

State-specific

No general private right of action

Rhode Island / RIDTPPA

Lower-threshold model

Effective in 2026

No cure period

No general private right of action


If you need a tactical implementation resource for California-specific operational work, this checklist on CCPA compliance steps for North Texas firms is a practical companion for distributed teams that support California residents but operate elsewhere.


My recommendation is simple. Set your design baseline with California, Colorado, Connecticut, Texas, and Maryland. Then run threshold analysis for the rest of the active states, with special attention to Tennessee, Nebraska, New Hampshire, Delaware, and Rhode Island because cure assumptions and scope logic diverge faster there. That approach matches where enforcement and operational risk are headed, not where last year's slide deck said they were.


Core Obligations Across US Privacy Laws


Most US privacy programs fail because they treat obligations as legal categories instead of build steps. Don't do that. Build in sequence.


An infographic detailing five essential steps for mapping an organization's program to US data privacy laws.


Start with notice and choice


Your privacy notice has to match your actual collection, use, disclosure, retention logic, and sensitive-data handling. If marketing, product, and legal wrote different versions of the truth, the regulator will find the gap before your internal audit does.


Then distinguish opt-out rights from opt-in obligations. Sale, sharing, targeted advertising, and some profiling uses often sit in opt-out territory. Sensitive data and children's data often demand a higher bar.


For teams harmonizing US and international retention governance, this guide to retention schedules for GDPR is useful because it forces the right operational question: what are we keeping, for what purpose, and for how long?


Rights handling, minimization, and security


Many state laws converge around access, deletion, correction, portability, and deadline-based response handling. Your intake process needs identity verification rules, exception handling, and routing to the systems that hold the data.


The next obligation is the one teams neglect most. Data minimization and purpose limitation. Don't collect because a field might become useful later. Don't retain because storage is cheap. If your engineers need a framing document for integrating privacy controls into broader security architecture, this data privacy and cybersecurity reference is a sensible starting point.


A short explainer can help align legal and technical teams on the implementation side:



  • Notice: Publish collection and use disclosures that match system behavior.

  • Choice: Wire opt-out and consent signals into products, not just banners.

  • Rights: Route access, deletion, correction, and portability requests into the systems of record.

  • Minimization: Reduce collection fields, retention periods, and internal access.

  • Security: Apply reasonable safeguards and prepare breach response evidence.


How US Privacy Enforcement Is Changing in 2025 and 2026


Your company sells nationwide, runs targeted ads, uses an AI feature, and accepts traffic from California, Texas, Colorado, and a handful of other states. The question for 2025 and 2026 is no longer whether you have a privacy policy. The question is which state can act first, whether that state still offers a cure period, and whether your product behavior matches your disclosures.


Enforcement is getting more operational and more state-specific. Treat the U.S. patchwork as a decision map. If you trigger California, expect scrutiny on Global Privacy Control, dark patterns, data broker obligations, and sensitive data use. If you trigger Texas, assume an aggressive attorney general and less patience for paper compliance. If you trigger multiple state laws, your risk turns on the strictest rule that applies to the same workflow, not the weakest one.


Where 2025 to 2026 enforcement is actually focused


The priority areas are clear:


  • AI and automated processing: Regulators want to know what data went into the model, what notices users saw, whether sensitive or minors' data was involved, and whether outputs create unfair or undisclosed downstream uses.

  • Dark patterns: Choice screens, cookie banners, account settings, and cancellation flows are being examined for friction, asymmetry, and misleading language.

  • Global Privacy Control: If a browser-level opt-out signal is valid under the applicable state law, your systems need to receive it, honor it, and propagate it to ad-tech and downstream processors.

  • Data brokers: Registration, deletion workflows, and suppression handling are moving from back-office disclosure work to active enforcement risk.


A recent enforcement analysis describes the shift plainly. Regulators are focusing on user choice integrity, GPC handling, protections for children and teens, and data broker governance, with California and Texas setting the pace and more states expected to become active in 2026 (2025 enforcement trends analysis).


The decision points compliance teams should track


Do not manage enforcement risk as a generic U.S. program. Map it by trigger and remedy.


First, identify which state laws you trigger by revenue, consumer volume, and data-sale or targeted-advertising activity. Then track cure periods state by state. Some laws gave businesses time to fix issues. Others narrowed that option or made cure discretionary. That difference matters when legal is deciding whether to launch a feature with unresolved consent or opt-out gaps.


Second, separate voluntary guidance from enforceable law. Regulator blog posts, FAQs, and technical explainers can signal priorities. They are not all binding. Statutes, regulations, and attorney general actions are what create direct exposure.


What good evidence looks like now


Policy text is weak evidence. Product behavior is strong evidence.


Expect regulators to ask for screenshots of choice flows, event logs showing when a GPC signal was received, vendor configuration showing suppression of targeted advertising, records proving a broker deletion request reached downstream systems, and documentation tying AI training inputs to disclosed purposes. If your consent tool says "opted out" while tags still fire and vendors still receive the event, the violation is in the system design, not the wording of the notice.


That is the shift. Enforcement in 2025 and 2026 is aimed at broken control paths, not missing adjectives in the privacy policy.


Engineering Privacy Controls Using the NIST Framework


NIST gives engineering teams a usable blueprint, but not a legal shield. Treat it as a control architecture, not immunity.


NIST's Privacy Framework says organizations should collect only what is necessary for an identified purpose, define retention periods, and implement scheduled deletion and logging aligned to those purposes. NIST also states clearly that the framework is voluntary and has no force of law (NIST Privacy Framework).


Controls that actually matter


Translate that guidance into product requirements:


  • Collection limits at ingress: block unnecessary fields in web forms, SDKs, APIs, and mobile events.

  • Retention clocks by purpose: tie each data category to a retention rule that engineering can enforce.

  • Deletion jobs: support both scheduled purge and request-based deletion.

  • Pseudonymization: separate analytics use from direct identity where possible.

  • Audit logging: preserve evidence showing when data was collected, why, where it flowed, and when it was deleted.


NIST Privacy Framework Functions Mapped to Engineering Controls

Engineering Control

Evidence Produced

Data minimization related controls

Field-level collection rules

Schema definitions, intake configs, change tickets

Purpose governance related controls

Purpose tags in data inventory

Records of processing, control matrices

Retention and deletion related controls

Scheduled deletion jobs and retention logic

Deletion logs, retention policies, execution reports

Access governance related controls

Role-based access and approvals

Access logs, review records

Response and monitoring related controls

Audit trails and incident workflows

Event logs, incident records, validation outputs


Don't oversell voluntary guidance


If your team needs a technical governance pattern for operationalizing these controls across services and integrations, this API governance best practices reference fits well with NIST-style implementation work.


One option for enterprises that need outside help on this buildout is Freeform Company. It has published work on data mapping, baseline assessments against GDPR, CCPA, sector requirements, contractual duties, and internal standards, which is the right operating scope for organizations trying to turn legal obligations into system controls. Freeform's role in marketing AI goes back to 2013, which matters because teams now need advisors who understand both compliance architecture and AI-enabled data operations. In practice, that matters for speed and economics too: industry comparisons published in 2026 report that AI marketing agencies can be about 30–60% cheaper on production-heavy work (Automaton comparison), can launch campaigns in 1–2 weeks instead of the 3–6 weeks traditional agencies commonly need (Etradewind comparison), and can test 10–50 times more creative variations while reducing marketing overhead by 30–60% (Hovi comparison).


How Federal and State Laws Interact in Practice


Most difficult privacy questions aren't about a single statute. They're about overlap. Your team needs interaction rules.


An infographic illustrating four key patterns regarding how federal and state data privacy laws interact in practice.


Four interaction patterns that matter


HIPAA plus state law. HIPAA governs PHI for covered entities and business associates. But the same organization can still face state-law duties for non-PHI datasets, including marketing, tracking, and nonclinical support data.


COPPA plus state law. COPPA remains the federal baseline for under-13 data. State laws may add separate duties around broader consumer rights or youth-oriented design, but they don't erase COPPA's consent structure.


GLBA plus state law. GLBA may exempt or narrow some state consumer-rights exposure for covered financial data. It does not automatically remove all state privacy risk for every other business process run by that institution.


State stacking. If your company triggers multiple state statutes, it often makes operational sense to implement the strictest workable standard across shared systems, then document justified exceptions.


The expensive mistake is assuming one exemption follows the data everywhere it goes. It usually doesn't.

The federal backstop still matters


When sectoral law doesn't fully apply and state law doesn't neatly address the conduct, the FTC remains the residual federal backstop. That's why product claims, ad-tech architecture, and user-choice integrity matter far beyond any single state statute.


Rethinking Compliance Beyond the Privacy Policy


A privacy policy is a disclosure artifact. It is not proof of compliant processing.


If your opt-out path is buried, your SDK sends data before consent logic resolves, your AI workflow ingests personal data beyond the disclosed purpose, or your vendors operate without usable contractual restrictions, the policy becomes evidence against you. Regulators read policies against technical behavior.


What to test instead


Walk your top user journeys and inspect the actual system actions.


  • Account creation: What fields are collected, which are optional, and where do they flow next?

  • Marketing interaction: Which vendors receive data, under what settings, and can those settings be suppressed consistently?

  • AI enablement: Which datasets feed model development, evaluation, or prompt logging, and what disclosures support that use?

  • Rights exercise: Can the user do what the policy promises?


For teams that need a disciplined method to identify disconnects between paper controls and operational reality, this guide from CloudCops GmbH is a helpful model for compliance gap analysis.


A mature privacy signoff isn't “the policy is live.” It's “we tested the journey, validated the data path, and confirmed the right can be exercised in the product.”


A 30 60 90 Day Compliance Roadmap for 2026


You don't need a grand transformation plan first. You need ninety days of disciplined execution.


A 30-60-90 day compliance roadmap infographic for navigating data privacy laws in 2026 effectively.


Days 1 to 30


Run the jurisdiction map. Identify which states you trigger, which datasets are in scope, where exemptions plausibly apply, and where they clearly do not. Refresh your records of processing and inventory all third-party recipients.


Days 31 to 60


Build the rights and preference plumbing. Validate request intake, verification, routing, and deadline tracking. Test universal opt-out handling and make sure preference signals propagate into analytics, advertising, and downstream vendor paths.


Recommended sequence: Map applicability first, then rights workflows, then AI and ad-tech defensibility. Teams that reverse that order waste time.

Days 61 to 90


Pressure-test high-risk uses. Review targeted advertising, profiling, sensitive-data handling, AI training inputs, and broker-like data sharing. Update vendor terms where restrictions don't match the states you trigger. Run a tabletop on a regulator request for deletion evidence, preference honoring, or training-data provenance.


Exit criteria should be concrete: an updated inventory, an applicability matrix, functioning rights workflows, tested suppression paths, and decision logs for the high-risk processing your executives care about most.


Quick Reference Catalog of US Privacy Statutes


You need a fast lookup tool, not another lecture. Use this table for first-pass issue spotting, then escalate edge cases to counsel.


US Privacy Statutes at a Glance

Scope

Trigger / Threshold

Core Rights

Cure Period

Enforcer

Privacy Act of 1974

Federal agency record systems

Federal records handling

Disclosure restrictions and fair information practices

Statutory framework specific

Federal agencies, courts

HIPAA

PHI and covered healthcare ecosystem

Covered entity or business associate status

Health privacy and access rights within HIPAA framework

Sector-specific

HHS OCR

GLBA

Covered financial information

GLBA-regulated institution status

Privacy notices and safeguard obligations

Sector-specific

Federal regulators, FTC

COPPA

Under-13 online data

Child-directed service or actual knowledge

Parental consent framework

Sector-specific

FTC

FCRA

Consumer report ecosystem

Use or furnishing of covered report data

Access, dispute, accuracy related rights

Sector-specific

FTC, CFPB, others

CAN-SPAM

Commercial email

Covered commercial email practices

Commercial email rule set

Sector-specific

FTC and others

CCPA-CPRA

California consumer data

California statutory applicability

Access, deletion, correction, opt-out and related rights

Varies by issue

CPPA, California AG

VCDPA

Virginia consumers

Threshold-based

Core consumer rights and opt-outs

State-specific

Virginia AG

CPA

Colorado consumers

Threshold-based

Core consumer rights and opt-outs including profiling

State-specific

Colorado AG

CTDPA

Connecticut consumers

Threshold-based

Core consumer rights and opt-outs

Expired temporary cure structure

Connecticut AG

UCPA

Utah consumers

Revenue plus threshold-based

Narrower core rights set

State-specific

Utah AG

TDPSA

Texas consumers

Business-activity model

Core consumer rights and opt-outs

Cure structure exists

Texas AG

MODPA

Maryland consumers

Lower-threshold model

Strong sensitive-data restrictions and consumer rights

State-specific

Maryland AG

MCDPA

Minnesota consumers

Threshold-based

Core consumer rights and assessments

State-specific

Minnesota AG

OCPA

Oregon consumers

Threshold-based

Core consumer rights and opt-outs

State-specific

Oregon AG

RIDTPPA

Rhode Island consumers

Lower-threshold model

Core consumer rights

No cure period

Rhode Island AG

ICDPA

Iowa consumers

Threshold-based

Narrower core rights set

Cure period exists

Iowa AG

INCDPA

Indiana consumers

Threshold-based

Core rights and assessments

Cure period exists

Indiana AG

KCDPA

Kentucky consumers

Threshold-based

Core rights

State-specific

Kentucky AG

TIPA

Tennessee consumers

Threshold-based

Core rights and business-friendly defenses

Cure period exists

Tennessee AG

NHPA

New Hampshire consumers

Lower-population-adjusted threshold model

Core rights and opt-outs

Cure period with sunset dynamic

New Hampshire AG

NJDPA

New Jersey consumers

Threshold-based

Core rights and broader sale framing

State-specific

New Jersey AG


Frequently Asked Questions for Compliance Teams


Which cure periods actually differ in practice


They differ enough to break a one-size-fits-all remediation plan. Some states keep a cure mechanism, some sunset it, and some are less forgiving. Don't let your incident playbook assume you'll always get time to fix first.


Are nonprofits exempt


Sometimes yes, sometimes no, depending on the statute. Don't generalize from one state to another. Check both the entity exemption and the data exemption. A nonprofit health or education affiliate can still create separate legal questions.


What about B2B and employee data


California changed the market's assumptions here. Teams that still treat B2B and workforce data as automatically out of scope are often relying on expired thinking. Confirm treatment by statute and dataset.


Does honoring Global Privacy Control solve all opt-out duties


No. It helps, and in some jurisdictions it is a critical signal, but it doesn't erase your need for functioning sale, sharing, and targeted advertising controls across systems and vendors.


How do GLBA exemptions interact with state consumer rights


Treat GLBA as a scoped carve-out, not a universal shield. Covered financial data may be treated differently, but adjacent marketing and operational datasets often remain exposed.


What counts as sensitive personal information


That depends on the statute, and the differences matter. Biometric data, precise geolocation, health-related inferences, government identifiers, and children's data often trigger special handling. Maryland deserves special attention because it takes a stricter posture on sensitive data processing.


Can one DPIA satisfy HIPAA, state law, and NIST


One assessment can support all three if it is written well. But don't assume one template automatically satisfies each legal requirement. Use a common fact base, then map the output to each regime's specific expectations. Where the requirement is interpretive rather than binding, document that judgment clearly and get counsel involved for edge cases.



Freeform Company helps enterprises turn privacy obligations into operating controls, with practical support on data mapping, compliance assessments, AI-enabled workflows, and program design that can stand up to regulator scrutiny. If your team needs a faster path from legal analysis to technical implementation, visit Freeform Company.


 
 
bottom of page