The United States still has no comprehensive federal privacy law, so the rules come from the states. By most counts, 19 states have now enacted comprehensive consumer privacy laws, and five of them took effect in January 2025 alone. The laws share a common core: consumer rights, opt-outs for sale and targeted advertising, duties to minimize data and secure it, and contracts with processors. They differ on who's covered, how sensitive data is handled, universal opt-out signals and assessments. For most mid-sized organizations, the practical answer is one privacy program built to the strictest common requirements, with state-specific exceptions layered on top.

Here's where things stand, what's coming in 2025 and 2026, and how to build a program that doesn't need rebuilding every time a new state joins.

Which states have comprehensive privacy laws?

California went first with the California Consumer Privacy Act (CCPA), effective January 1, 2020 and expanded by the California Privacy Rights Act from 2023. Virginia's law, enacted in 2021 and effective in 2023, became the model most later states borrowed from.

Florida also has a Digital Bill of Rights, effective July 1, 2024, but it applies only to very large companies that meet additional criteria. Many trackers leave it out of the count, which is why you'll see both 19 and 20 cited.

State Effective date
California January 1, 2020 (CPRA amendments January 1, 2023)
Virginia January 1, 2023
Colorado July 1, 2023
Connecticut July 1, 2023
Utah December 31, 2023
Texas July 1, 2024
Oregon July 1, 2024
Montana October 1, 2024
Delaware January 1, 2025
Iowa January 1, 2025
Nebraska January 1, 2025
New Hampshire January 1, 2025
New Jersey January 15, 2025
Tennessee July 1, 2025
Minnesota July 31, 2025
Maryland October 1, 2025
Indiana January 1, 2026
Kentucky January 1, 2026
Rhode Island January 1, 2026

Which state privacy laws take effect in 2025 and 2026?

January 2025 was the busiest month yet. Delaware, Iowa, Nebraska and New Hampshire took effect on January 1, and New Jersey followed on January 15.

Three more states will come online later in 2025:

  • Tennessee on July 1, 2025
  • Minnesota on July 31, 2025, with postsecondary institutions following on July 31, 2029
  • Maryland on October 1, 2025, although the law won't apply to processing activities before April 1, 2026

Indiana, Kentucky and Rhode Island will follow on January 1, 2026. Several state legislatures are in session now, so expect more bills this year.

What do state privacy laws have in common?

Most of these laws follow the same basic shape, which is good news for anyone building a program.

Consumer rights. Residents can generally confirm whether you process their data, access it, correct it, delete it and get a portable copy. They can also opt out of the sale of their data, targeted advertising and certain profiling.

Controller duties. The business that decides how data is used (the controller) must publish a privacy notice, limit collection and use to disclosed purposes, obtain consent for certain processing, secure the data, and not discriminate against people for exercising their rights.

Processor contracts. Service providers that process data on your behalf (processors) need written contracts covering confidentiality, subcontracting, deletion or return of data, and your right to assess their compliance.

Enforcement. State attorneys general enforce most of these laws, and California also has a dedicated regulator, the California Privacy Protection Agency. Apart from California's limited right of action for certain security failures, individuals can't sue under these laws. Some states give businesses a period to cure violations before enforcement, and in several states that grace period is temporary.

How do state privacy laws differ?

The shared core covers most of the work. The differences below are where programs trip up.

Applicability thresholds

Most states apply to businesses that control or process the personal data of 100,000 or more state residents, or a smaller number combined with a share of revenue from selling data. The details vary widely:

  • California uses a revenue test, $25 million a year, adjusted for inflation, alongside volume and data-sale tests.
  • Delaware, New Hampshire, Maryland and Rhode Island drop the volume threshold to 35,000 residents. Montana uses 50,000.
  • Tennessee and Utah require both a revenue threshold and a volume threshold. Tennessee's volume test is 175,000 consumers.
  • Texas and Nebraska have no volume threshold. They apply to businesses that aren't small businesses under the U.S. Small Business Administration definition.

Exemptions also vary. Some states exempt entire organizations covered by federal laws such as HIPAA or the Gramm-Leach-Bliley Act, while others exempt only the regulated data. Several states, including Colorado and Oregon, cover nonprofits.

Sensitive data: opt-in vs. opt-out

Sensitive data typically covers health information, precise geolocation, biometric and genetic data, racial or ethnic origin, religious beliefs, sexual orientation, citizenship status and children's data. Definitions differ at the edges.

Most states require opt-in consent before you process sensitive data. California, Utah and Iowa take an opt-out approach instead, giving consumers the right to limit or object to its use.

Maryland goes further than everyone else. It allows collection or processing of sensitive data only when it's strictly necessary to provide or maintain a product or service the consumer asked for, and it bans the sale of sensitive data outright.

Universal opt-out signals

A universal opt-out mechanism, such as a browser privacy signal, lets a consumer opt out of sale and targeted advertising across every site they visit. A growing number of states require businesses to honor these signals.

California and Colorado already require it. Connecticut, Montana, New Hampshire and Texas began requiring it in January 2025. New Jersey will follow in July 2025, Minnesota and Maryland on their 2025 effective dates, and Oregon and Delaware in January 2026. Other states, including Virginia, Utah and Iowa, don't require it.

If you sell data or use targeted advertising, treat signal recognition as a baseline. It's an engineering task, not a policy one, so plan it early.

Data protection assessments

Most states require a documented data protection assessment before high-risk processing: targeted advertising, sale of personal data, processing sensitive data, and profiling that creates certain risks to consumers. Utah and Iowa don't require them.

California doesn't yet either, but that may change. In November 2024 the California Privacy Protection Agency opened formal rulemaking on proposed regulations that include risk assessments and annual cybersecurity audits for certain businesses. For now, these are still proposals.

What does "reasonable security" mean under state privacy laws?

Nearly every comprehensive state law requires controllers to "establish, implement, and maintain reasonable administrative, technical, and physical data security practices" to protect the confidentiality, integrity and accessibility of personal data. The standard scales with "the volume and nature of the personal data at issue." Processors must help controllers meet their security obligations.

None of the laws defines a control set. That's deliberate, but it leaves you to decide what "reasonable" means and to show your work. In practice, a recognized framework applied consistently, with documented risk decisions, is the most defensible way to show it.

A few states add specifics worth knowing:

  • California requires reasonable security and gives consumers a private right of action when certain unencrypted and unredacted personal information is accessed, stolen or disclosed without authorization because a business failed to maintain reasonable security.
  • Minnesota explicitly ties reasonable security to maintaining an inventory of the data you manage.
  • Tennessee gives controllers and processors an affirmative defense if they maintain a written privacy program that reasonably conforms to the NIST Privacy Framework.

For security teams, the takeaway is that privacy laws have turned data inventory, access control, encryption, retention and vendor oversight into legal obligations, not just good practice.

How do you comply with multiple state privacy laws?

Trying to run 19 separate programs doesn't scale. Build one program to the strictest common denominator, then handle the few true outliers individually.

  1. Map your footprint. Estimate how many residents of each state you process data about, and whether you sell data or use targeted advertising. That tells you which laws apply now and which ones you'll cross into soon.
  2. Build a data inventory. Know what personal data you hold, where it lives, why you have it and who you share it with. Every other step depends on it.
  3. Default to opt-in for sensitive data. It satisfies the opt-in states and exceeds the opt-out ones. Then check your practices against Maryland's "strictly necessary" standard.
  4. Honor universal opt-out signals everywhere. Recognizing signals for all users is usually simpler than geolocating each one.
  5. Run assessments for all high-risk processing. Use one template that covers the elements the stricter states require, and keep it on file.
  6. Standardize processor contracts. One data processing addendum with confidentiality, subprocessor, deletion and audit terms covers nearly every state.
  7. Anchor security to a framework. Map controls to a recognized framework, document risk decisions, and review them regularly.
  8. Unify request handling. One intake process for access, deletion, correction, portability and opt-out requests, with response times set to the shortest deadline that applies to you.
  9. Track what's coming. Assign someone to watch new laws, amendments and regulations, including California's pending rulemaking.

Frequently asked questions

Do state privacy laws cover employee and B2B data?

Mostly not. Most state laws exclude data about people acting in an employment or commercial context. California is the major exception, and its law has covered employee and business-contact data since January 1, 2023.

Do these laws apply to businesses based outside the state?

Yes. They generally apply to businesses that conduct business in the state or target products or services to its residents, and that meet the applicability thresholds. Physical presence doesn't matter.

Is a federal privacy law going to replace the state laws?

Not any time soon. Congress has considered comprehensive privacy bills for years without passing one. Plan on the state patchwork continuing to grow.

Key takeaways

  • By most counts, 19 states have comprehensive privacy laws, and five took effect in January 2025.
  • Tennessee, Minnesota and Maryland follow later in 2025. Indiana, Kentucky and Rhode Island take effect on January 1, 2026.
  • The core obligations are shared. The differences are in thresholds, sensitive data consent, universal opt-out signals and assessments.
  • "Reasonable security" is a legal obligation in nearly every state, and a data inventory is the foundation for meeting it.
  • Build once to the strictest common denominator, then manage outliers such as Maryland individually.

This post summarizes the laws as they stand and isn't legal advice. Confirm which laws apply to you, and how, with counsel.