close
close
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

US State Privacy Law Tracker

Every comprehensive state privacy law.
One fast answer.

Last updated

A free, fast reference for US state data-privacy regulations. Built for people who already know the law applies.

Browse by state

50 states + DC · colored by status

Geographic
Map of the United States, coloured by the legal status of each state’s data-privacy law. Alabama - Enacted: Alabama Personal Data Protection Act - live on DataGrail, opens a full state page - opens a preview Alaska - No comprehensive privacy law - no state page yet - opens a preview Arizona - No comprehensive privacy law - no state page yet - opens a preview Colorado - In force: Colorado Privacy Act - live on DataGrail, opens a full state page - opens a preview Florida - In force: Florida Digital Bill of Rights - live on DataGrail, opens a full state page - opens a preview Georgia - No comprehensive privacy law - no state page yet - opens a preview Indiana - In force: Indiana Consumer Data Protection Act - live on DataGrail, opens a full state page - opens a preview Kansas - No comprehensive privacy law - no state page yet - opens a preview Maine - No comprehensive privacy law - no state page yet - opens a preview Massachusetts - Proposed — pending in the state legislature - no state page yet - opens a preview Minnesota - In force: Minnesota Consumer Data Privacy Act - live on DataGrail, opens a full state page - opens a preview New Jersey - In force: New Jersey Data Privacy Act - live on DataGrail, opens a full state page - opens a preview North Carolina - Proposed — pending in the state legislature - no state page yet - opens a preview North Dakota - No comprehensive privacy law - no state page yet - opens a preview Oklahoma - Enacted: Oklahoma Consumer Data Privacy Act - live on DataGrail, opens a full state page - opens a preview Pennsylvania - Proposed — pending in the state legislature - no state page yet - opens a preview South Dakota - No comprehensive privacy law - no state page yet - opens a preview Texas - In force: Texas Data Privacy and Security Act - live on DataGrail, opens a full state page - opens a preview Wyoming - No comprehensive privacy law - no state page yet - opens a preview Connecticut - In force: Connecticut Data Privacy Act - live on DataGrail, opens a full state page - opens a preview Missouri - No comprehensive privacy law - no state page yet - opens a preview West Virginia - No comprehensive privacy law - no state page yet - opens a preview Illinois - No comprehensive privacy law - no state page yet - opens a preview New Mexico - No comprehensive privacy law - no state page yet - opens a preview Arkansas - No comprehensive privacy law - no state page yet - opens a preview California - In force: California Consumer Privacy Act (as amended by CPRA) - live on DataGrail, opens a full state page - opens a preview Delaware - In force: Delaware Personal Data Privacy Act - live on DataGrail, opens a full state page - opens a preview District of Columbia - No comprehensive privacy law - no state page yet - opens a preview Hawaii - No comprehensive privacy law - no state page yet - opens a preview Iowa - In force: Iowa Consumer Data Protection Act - live on DataGrail, opens a full state page - opens a preview Kentucky - In force: Kentucky Consumer Data Protection Act - live on DataGrail, opens a full state page - opens a preview Maryland - In force: Maryland Online Data Privacy Act - live on DataGrail, opens a full state page - opens a preview Michigan - Proposed — pending in the state legislature - no state page yet - opens a preview Mississippi - No comprehensive privacy law - no state page yet - opens a preview Montana - In force: Montana Consumer Data Privacy Act - live on DataGrail, opens a full state page - opens a preview New Hampshire - In force: New Hampshire Data Privacy Act - live on DataGrail, opens a full state page - opens a preview New York - No comprehensive privacy law - no state page yet - opens a preview Ohio - No comprehensive privacy law - no state page yet - opens a preview Oregon - In force: Oregon Consumer Privacy Act - live on DataGrail, opens a full state page - opens a preview Tennessee - In force: Tennessee Information Protection Act - live on DataGrail, opens a full state page - opens a preview Utah - In force: Utah Consumer Privacy Act - live on DataGrail, opens a full state page - opens a preview Virginia - In force: Virginia Consumer Data Protection Act - live on DataGrail, opens a full state page - opens a preview Washington - No comprehensive privacy law - no state page yet - opens a preview Wisconsin - No comprehensive privacy law - no state page yet - opens a preview Nebraska - In force: Nebraska Data Privacy Act - live on DataGrail, opens a full state page - opens a preview South Carolina - No comprehensive privacy law - no state page yet - opens a preview Idaho - No comprehensive privacy law - no state page yet - opens a preview Nevada - No comprehensive privacy law - no state page yet - opens a preview Vermont - Enacted: Vermont Data Privacy and Online Surveillance Act - live on DataGrail, opens a full state page - opens a preview Louisiana - Enacted: Louisiana Data Privacy Act - live on DataGrail, opens a full state page - opens a preview Rhode Island - In force: Rhode Island Data Transparency and Privacy Protection Act - live on DataGrail, opens a full state page - opens a preview
Hover a state to preview · click for its status and sources
Live now
Content on this page is not legal advice This page aggregates publicly cited regulatory facts for informational purposes only. It is not legal advice, and DataGrail is not responsible for decisions made in reliance on it. Consult qualified counsel for your specific compliance obligations.

Legal updates

Takes effect

New California

California expands CCPA deletion rights

From January 1, 2027, deletion rights reach data about consumers, and direct-to-consumer online-only businesses must also accept requests online.

See the California update

Timeline

Every deadline, across every state we track

Every dated milestone we publish for every state we track (signings, effective dates, enforcement starts, recurring duties) in one browsable view. Drag the quarter scrubber or filter by type to narrow it down, then jump into the state that matters to you.

Filter
Q1 '23 Q3 '23 Q4 '23 Q1 '24 Q3 '24 Q4 '24 Q1 '25 Q3 '25 Q4 '25 Q1 '26 Q3 '26 Q1 '27 Q2 '27 Q1 '28

Drag the handle or use the arrow keys to jump to a quarter — every milestone is already listed below.

Showing all 37

Ahead 5 upcoming

Recently passed 7 in the last 12 months

Recurring no single date: ongoing obligations

  • Recurring CA Annual data-broker registration Annual registration

    Data brokers doing business in California must register with the CPPA each year by January 31.

  • Recurring CA Report the outcome of each deletion request Report the outcome of each deletion request

    The DROP mechanism must let the consumer, or their authorized agent, verify the status of their deletion request — a distinct duty from checking DROP and deleting data (see "Data brokers must process via DROP" below).

Show earlier history 23 before Oct 5, 2025

Compare

Narrow the field, then compare what’s left

Filter to the states that fit your criteria, then pick two to four to compare side by side: rights, exemptions, penalties, and cure periods, each linked to the statute behind it.

24 / 24 states shown
Filter
law silent no source yet
States none selected
State / law
ALAlabamaAPDPA · Not yet in force
May 1, 2027
No
45 days (from May 1, 2027) (The AG must give notice first; no action if the violation is cured within 45 days with a written statement.)
$15,000
No
CACaliforniaCCPA · In force
January 1, 2020
Yes
No cure period (No mandatory cure; the CPPA may allow one at its discretion. Statutory-damage breach suits need 30 days' notice to cure.)
$2,663; up to $7,988 (intentional or minors) (Inflation-adjusted every odd year (next Jan 1, 2027). The AG penalty and the CPPA fine are alternatives.)
Yes
COColoradoCPA · In force
July 1, 2023
Yes
60 days, minors' provisions only (until Dec 31, 2026) (General cure repealed Jan 1, 2025. A 60-day cure still applies to the minors' provisions until Dec 31, 2026.)
$20,000; up to $50,000 (elderly) (Deemed a deceptive trade practice; 6-1-112 counts each consumer or transaction as a separate violation, with no cap.)
No
CTConnecticutCTDPA · In force
July 1, 2023
Yes
Mandatory cure lapsed Dec 31, 2024; now discretionary (The mandatory cure ended Dec 31, 2024; since then the AG may grant a cure at its discretion.)
$5,000 (Per wilful violation, under the Unfair Trade Practices Act (42-110o); enforced only by the AG.)
No
DEDelawareDPDPA · In force
January 1, 2025
Yes
Mandatory cure lapsed Dec 31, 2025; now discretionary (The mandatory cure ended Dec 31, 2025; since Jan 1, 2026 the DOJ may offer a cure at its discretion.)
$10,000 (Applies to wilful violations; enforced solely by the Department of Justice.)
No
FLFloridaFDBR · In force
July 1, 2024
No
45 days (discretionary) (Discretionary: the Department may allow 45 days to cure. No cure for violations involving a known child.)
$50,000; may be tripled (some violations) (May be tripled for violations involving a known child, ignored deletion requests, or selling after an opt-out.)
No
INIndianaICDPA · In force
January 1, 2026
No
30 days (30-day cure period, permanent.)
$7,500 (The AG may also recover investigation costs and attorney's fees.)
No
IAIowaICDPA · In force
January 1, 2025
No
90 days (90-day cure period, permanent.)
$7,500
No
KYKentuckyKCDPA · In force
January 1, 2026
No
30 days (30-day cure period, permanent.)
$7,500 (The AG may also recover investigation costs, court costs and attorney's fees. No private right of action.)
No
LALouisianaLDPA · Not yet in force
January 1, 2027
Yes
30 days (Jan 1, 2027 to Jul 31, 2027) (Jan 1-Jul 31, 2027 only: the AG gives 30 days' notice before investigating; a documented cure in time bars it.)
No stated cap; up to $5,000 (intent to defraud) (No stated cap in general; $5,000 on a finding of intent to defraud; up to $5,000 more if elderly or disabled.)
No
MDMarylandMODPA · In force
October 1, 2025
Yes
60 days (discretionary, until Apr 1, 2027) (Discretionary: the Division may give 60 days to cure. Only for violations on or before Apr 1, 2027.)
$10,000; up to $25,000 (repeat) (Enforced under Title 13; a criminal misdemeanor (up to $1,000 and one year) may also apply.)
No
MNMinnesotaMCDPA · In force
July 31, 2025
Yes
30 days (lapsed Jan 31, 2026) (The mandatory 30-day cure (AG warning letter first) ended Jan 31, 2026; the statute has no discretionary cure.)
$7,500
No
MTMontanaMCDPA · In force
October 1, 2024
Yes
60 days (lapsed Sep 30, 2025) (The 60-day cure was removed effective Oct 1, 2025 (SB 297); no cure applies to enforcement today.)
$7,500 (Consumer protection fines of up to $10,000 (willful or injunction violations) may also apply; not settled.)
No
NENebraskaNDPA · In force
January 1, 2025
Yes
30 days (30-day cure period, permanent.)
$7,500
No
NHNew HampshireNHDPA · In force
January 1, 2025
Yes
Mandatory cure lapsed Dec 31, 2025; now discretionary (Mandatory in 2025; since Jan 1, 2026 the AG may offer a 60-day cure. RSA 358-A:5 also requires 10 days' notice.)
$10,000 (Counted per unlawful act; a good-faith misunderstanding is a defense. Criminal liability only on conviction.)
No
NJNew JerseyNJDPA · In force
January 15, 2025
Yes
30 days (lapsed Jun 30, 2026) (A mandatory 30-day cure applied until July 1, 2026; that window has closed.)
$10,000; up to $20,000 (second or later offense) (Mostly Consumer Fraud Act penalties, plus restitution; a separate $50,000-per-record fine covers sensitive-data sales.)
No
OKOklahomaOKCDPA · Not yet in force
January 1, 2027
No
30 days (from Jan 1, 2027) (30-day cure period, begins Jan 1, 2027, permanent.)
$7,500
No
OROregonOCPA · In force
July 1, 2024
Yes
30 days (lapsed Jan 1, 2026) (The general cure ended Jan 1, 2026; a carve-out for certain educational broadcast stations ended July 1, 2026.)
$7,500
No
RIRhode IslandRIDTPPA · In force
January 1, 2026
No
No cure period (No cure period.)
$10,000 (Deceptive trade practice penalties apply, plus $100-$500 per intentional unlawful disclosure (e.g., to a shell company).)
No
TNTennesseeTIPA · In force
July 1, 2025
No
60 days (60-day cure period, permanent.)
$7,500 (Courts may award treble damages for willful or knowing violations. A NIST-conforming privacy program is a defense.)
No
TXTexasTDPSA · In force
July 1, 2024
Yes
30 days (Mandatory, no sunset. The cure needs a written statement to the AG, consumer notice and supporting documents.)
$7,500 (Only for violations not cured within 30 days or a breached cure statement. The AG may also recover fees and costs.)
No
UTUtahUCPA · In force
December 31, 2023
No
30 days (30-day cure period, permanent.)
$7,500 (The attorney general may also recover actual damages for consumers.)
No
VTVermontVDPOSA · Not yet in force
January 1, 2028
Yes
60 days (Jan 1, 2028 to Jun 30, 2029) (Mandatory where the AG finds a cure possible; 60 days from notice, Jan 1, 2028 to June 30, 2029.)
$10,000
No
VAVirginiaVCDPA · In force
January 1, 2023
No
30 days (The cure requires a written statement to the AG that violations are cured and will not recur.)
$7,500 (Enforced only by the AG after the 30-day cure period; the AG may also recover fees and seek an injunction.)
No

Values link to the specific provision that supports them; a dashed marker means a value is recorded but not yet tied to a citable source. We never invent a link. Reference only, not legal advice. Cross-state status index ↗

What changed

Recent enforcement actions and lawsuits

Regulatory actions, settlements, and lawsuits across the privacy laws we track. Every entry is a DataGrail summary that links to the primary source.

Showing 1-6 of 30

Administrative fine

Irish DPC fines Google €403M over unlawful location data processing

Google Ireland Limited

GDPR

€403,000,000Decided

The fourth-largest GDPR fine ever issued, for tracking exactly the kind of location data most apps collect by default.

Settlement / consent order

Meta pays $459M to settle Cambridge Analytica privacy claims with four states

Meta Platforms, Inc.

California

$459,300,000Settled

Eight years after Cambridge Analytica broke, states are still collecting on it. This time it's $459 million, folded into an even larger settlement over Meta's design choices for kids.

Settlement / consent order Pending

DOJ’s $400M TikTok privacy settlement hits a snag: a judge may reject part of it

TikTok Inc. and ByteDance Ltd.

COPPA Federal

$400,000,000Pending

A $400M privacy settlement isn't final just because the government announced it: a judge can still send both sides back to the table.

Settlement / consent order

Connecticut fines TaxAct $275K for sharing taxpayer data with Meta and Google

TaxAct, Inc.

Connecticut Data Privacy Act (CTDPA) Connecticut

$275,000Settled

The information you enter into tax software feels private by default. This is what happens when a company treats it as ad-targeting data instead.

Class-action lawsuit

Flagstar Bank reaches $31.5M settlement over 2021 data breaches affecting 2.2M people

Flagstar Bank, N.A.

Federal

$31,500,000Settled

A bank paid hackers a ransom to delete stolen data, then still had to pay $31.5 million to the customers whose data was stolen in the first place.

Settlement / consent order

23andMe reaches $18M multistate settlement over genetic data breach affecting 6.9M people

23andMe Holding Co.

Iowa Consumer Data Protection Act (ICDPA) Iowa

$18,000,000Settled

Genetic data is uniquely permanent and uniquely sensitive, and this is one of the largest privacy settlements ever tied to a single breach of it.

Regulator enforcement

FTC orders Illuminate Education to fix security after breach exposed 10.1M students’ data

Illuminate Education, Inc.

FTC Act Section 5 Federal

DecidedNo monetary penalty

There was no fine, but a company that ignores a two-year-old security warning can still be forced into a binding security overhaul.

Settlement / consent order

California AG fines GM and OnStar $12.75M for selling driver data

General Motors LLC / OnStar

CA Unfair Competition LawCCPA/CPRA California

$12,750,000Settled

Connected-vehicle data is squarely in scope, and data minimization is now being enforced. Collect only what a stated purpose needs, and get real consent before selling location or behavior data.

Regulator enforcement

FTC orders Match and OkCupid to stop misrepresenting how they share user data

Match Group, LLC and OkCupid

FTC Act Section 5 Federal

DecidedNo monetary penalty

There's no fine, but a privacy policy promise about who sees your data is now something the FTC will hold the company to directly.

Administrative fine

CPPA fines PlayOn Sports $1.1M for forcing tracking consent on school ticketing platform

PlayOn Sports, Inc. (GoFan)

CCPA/CPRA California

$1,100,000Settled

A first: California's privacy regulator drew a direct line from a school sports ticketing app to a company's ad-tracking practices, and fined it accordingly.

Settlement / consent order

FTC bars GM and OnStar from selling driver location data

General Motors LLC; OnStar LLC

FTC Act Section 5 Federal

DecidedNo monetary penalty

Federal and state regulators are moving in parallel on connected-car data. A confusing enrollment screen is treated as a lack of consent, so make disclosures and opt-in clear and specific.

Administrative fine

CPPA fines Datamasters $45K for selling lists of people with Alzheimer’s and addiction

Rickenbacher Data LLC (d/b/a Datamasters)

CCPA/CPRA California

$45,000Settled

Selling lists sorted by disease and addiction status, without ever registering as a data broker, is exactly what California's Delete Act exists to catch.

Settlement / consent order

FTC orders Disney to pay $10M over kids’ data collected on YouTube

The Walt Disney Company

COPPAFTC Act Section 5 Federal

$10,000,000Settled

Mislabeling children's content is a COPPA problem even when a platform does the collecting. If your videos reach kids, label them correctly and treat parental consent as mandatory.

Administrative fine

CPPA fines marketing firm ROR Partners $57K for building unregistered profiles on 262M Americans

ROR Partners LLC

CCPA/CPRA California

$56,600Settled

Unregistered, not just unlawful: California's Delete Act requires data brokers to register before they can legally sell audience data at all.

Administrative fine

CPPA fines Tractor Supply a record $1.35M for CCPA violations

Tractor Supply Company

CCPA/CPRA California

$1,350,000Settled

CPPA's largest fine to date, and its first decision addressing privacy protections for job applicants.

Administrative fine

CPPA fines data broker Accurate Append $55K for missing California’s registration deadline

Accurate Append, Inc.

CCPA/CPRA California

$55,400Settled

California's Delete Act now carries real teeth: even a missed registration deadline draws a five-figure fine.

Settlement / consent order

California AG fines Healthline $1.55M for sharing health data with advertisers

Healthline Media LLC

CA Unfair Competition LawCCPA/CPRA California

$1,550,000Settled

Tracking pixels that leak health-related signals draw the largest penalties. When a user opts out, the data flow to third parties has to actually stop, including page titles and identifiers.

Settlement / consent order

Texas secures $1.375B settlement with Google over biometric and location data

Google LLC

Biometric Identifier Act (CUBI) Texas

$1,375,000,000Settled

Biometric identifiers captured through convenience features like photo face-grouping or voice assistants fall under standalone state biometric statutes, not just general privacy law, and an 'off' setting has to actually stop tracking, including in a browser's private mode.

Administrative fine

CPPA fines National Public Data $46K for skipping California’s data broker registry

Jerico Pictures, Inc. (d/b/a National Public Data)

CCPA/CPRA California

$46,000Settled

The same data broker behind 2024's headline-making breach was also fined for skipping California's registration requirement entirely.

Administrative fine

CPPA fines retailer Todd Snyder $345K for blocking consumer opt-out requests

Todd Snyder, Inc.

CCPA/CPRA California

$345,178Settled

Six weeks of a broken opt-out portal turned into a $345,178 CPPA fine.

Administrative fine

Irish DPC fines TikTok €530M for unlawfully transferring EU data to China

TikTok Technology Limited

GDPR

€530,000,000Decided

A real deadline comes with this one: comply within six months, or TikTok has to stop sending EU user data to China altogether.

Class-action lawsuit

Court approves $51.75M settlement with Clearview AI over facial recognition scraping

Clearview AI, Inc.

Illinois Biometric Information Privacy Act (BIPA) Illinois

$51,750,000Settled

The facial-recognition company that scraped billions of photos without asking didn't pay cash. It gave away nearly a quarter of itself instead.

Settlement / consent order

CPPA fines Honda $632K for making privacy rights hard to exercise

American Honda Motor Co., Inc.

CCPA/CPRA California

$632,500Settled

A confusing privacy interface, not a data breach, was enough to draw this six-figure CPPA fine.

Administrative fine

CPPA fines data broker Key Marketing Advantage $56K for skipping registration

Key Marketing Advantage, LLC

CCPA/CPRA California

$55,800Settled

Nearly a year of unregistered operation before this data broker got caught.

Settlement / consent order

FTC and DOJ fine Amazon $25M for keeping kids’ Alexa voice recordings

Amazon.com, Inc.

COPPA Federal

$25,000,000Settled

A delete button has to actually delete once you tell parents it will. If retained data keeps feeding a model after a deletion request, that gap is the violation, not a technicality.

Settlement / consent order

FTC fines BetterHelp $7.8M for sharing mental-health data with advertisers

BetterHelp, Inc.

FTC Act Section 5 Federal

$7,800,000Settled

A privacy promise about sensitive data is independently enforceable. Breaking a stated commitment ("this stays between you and your therapist") is a violation on its own, before you even get to whether the sharing itself was disclosed.

Settlement / consent order

FTC fines GoodRx $1.5M for sharing health data with advertisers

GoodRx Holdings, Inc.

FTC Act Section 5Health Breach Notification Rule Federal

$1,500,000Settled

Sharing health-adjacent data with ad platforms can trigger the Health Breach Notification Rule even outside a traditional data breach, and a compliance seal you don't actually qualify for (like HIPAA) is its own separate violation.

Settlement / consent order

FTC fines Epic Games $520M for COPPA violations and dark patterns

Epic Games, Inc.

COPPAFTC Act Section 5 Federal

$520,000,000Settled

Default settings and confusing purchase flows are enforcement risk, not just UX debt. Defaulting a kids' product to voice chat or in-game messaging can itself be a COPPA violation, and a button layout that causes unintended charges is treated the same as a false claim.

Settlement / consent order

California AG fines Sephora $1.2M for ignoring opt-out signals

Sephora, Inc.

CCPA/CPRA California

$1,200,000Settled

Selling data through routine ad-tech and analytics tags still counts as a 'sale' under the CCPA. Honor Global Privacy Control automatically, and audit every vendor tag against your service-provider contracts.

Class-action lawsuit

Snap pays $35M to settle BIPA suit over Snapchat Lens face-tracking

Snap Inc.

Illinois Biometric Information Privacy Act (BIPA) Illinois

$35,000,000Settled

A face filter most people think of as a toy was, legally speaking, biometric data collection, and expensive to get wrong.

Summaries are DataGrail’s wording, not statutory text; amounts and outcomes come from the linked primary source.