US State Privacy Laws: The 2026 Compliance Guide
There is no comprehensive federal privacy law in the United States. Instead, twenty states have written their own — each with different applicability thresholds, consumer rights, opt-out mechanics, penalty structures, and cure periods. A visitor from Denver and a visitor from Boise trigger different legal duties on the same page view. This hub maps the whole patchwork, with a detailed compliance guide for every state.
- state laws covered
- 20
- require GPC honoring
- 12
- newest effective dates
- 2026
The patchwork problem
One website, twenty different rulebooks
Every US state privacy law follows the same broad shape — an opt-out model, a required privacy choices link, a set of consumer rights — but the details diverge in ways that matter. Thresholds run from 10,000 consumers in Delaware to 175,000 in Tennessee, and Nebraska has no volume threshold at all. Montana and New Jersey require opt-in consent for teens; Florida requires it for sensitive data; Maryland bans the sale of sensitive data outright.
Penalties range from $2,500 to $20,000 per violation, cure periods are expiring state by state, and twelve states now require honoring Global Privacy Control signals automatically. Keeping up manually is not realistic — a geo-aware consent layer is the practical answer.
All 20 follow the opt-out model
No state requires a GDPR-style cookie banner by default. The legal minimum everywhere is a clear opt-out link — but the required text and mechanics differ.
The GPC divide
Twelve states require honoring Global Privacy Control browser signals automatically; eight do not. Your consent setup needs to know which visitor is which.
Enforcement is tightening
Colorado eliminated its cure period in 2026; Virginia, Minnesota, and New Hampshire let theirs sunset in 2025–2026. The grace-window era is ending.
One script tag covers all 20
ConsentKit detects each visitor's state at the edge and renders the right opt-out link, GPC handling, and consent records automatically.
State by state
All 20 US state privacy laws
Every guide below covers who must comply, the full consumer rights list, opt-out and GPC requirements with exact dates, penalties and cure periods, and what makes that state different.
California
CCPA/CPRAEffective January 1, 2020 (CCPA); January 1, 2023 (CPRA amendments)
The original US privacy law — private right of action for breaches and a dedicated enforcement agency.
Colorado
CPAEffective July 1, 2023
First state to mandate Global Privacy Control; no cure period since January 1, 2026.
Connecticut
CTDPAEffective July 1, 2023
Low 25% data-sales revenue trigger plus mandatory universal opt-out signals.
Delaware
DPDPAEffective January 1, 2025
Lowest coverage thresholds in the country — 35,000 or 10,000 consumers.
Florida
FDBREffective July 1, 2024
$1B revenue prong and the only broad opt-in requirement for sensitive data.
Indiana
ICDPAEffective January 1, 2026
Took effect January 1, 2026 — part of the newest class of state laws.
Iowa
ICDPAEffective January 1, 2025
Business-friendly opt-out framework targeting large-scale data operations.
Kentucky
KCDPAEffective January 1, 2026
New for 2026; no GPC mandate and a permanent discretionary cure period.
Maryland
MODPAEffective October 1, 2025
The strictest US law: sensitive-data sales banned, true data minimization.
Minnesota
MNCDPAEffective July 31, 2025
The only state with a right to question automated decisions.
Montana
MCDPAEffective October 1, 2024
Strictest teen rule in America — opt-in for ages 13–16; 50,000 threshold.
Nebraska
NDPAEffective January 1, 2025
No volume thresholds at all — the broadest applicability of any state.
New Hampshire
NHPAEffective January 1, 2025
Small-state thresholds (35,000) with full-strength GPC duties from day one.
New Jersey
NJDPAEffective January 15, 2025
“Revenue or discounted services” trigger pulls loyalty programs into scope.
Oregon
OCPAEffective July 1, 2024
Full-featured law; universal opt-out signals mandatory since January 1, 2026.
Rhode Island
RIDTPPAEffective January 15, 2026
Must name every third party that may buy personal data — not just categories.
Tennessee
TIPAEffective July 1, 2025
Highest bar in the country: 175,000 consumers or $25M revenue.
Texas
TDPSAEffective July 1, 2024
Biometric and health-data restrictions plus mandatory GPC since 2025.
Utah
UCPAEffective December 31, 2023
Most business-friendly law: $25M revenue gate and no sensitive-data opt-in.
Virginia
VCDPAEffective January 1, 2023
The template most later states copied; sensitive data requires opt-in.
Universal opt-out
The 12 states where GPC is the law
Global Privacy Control is a browser or device-level signal that tells every site the user has opted out of the sale and sharing of their personal information. In these twelve states, ignoring the signal is a violation — the opt-out must happen automatically, with no click required.
ConsentKit honors GPC automatically for visitors from every state that mandates it, and records the resulting opt-out with the same audit metadata as a manual choice.
| State | Law | GPC required |
|---|---|---|
| California | CCPA/CPRA | Required — 11 CCR §7025 |
| Colorado | CPA | Required since July 1, 2024 |
| Connecticut | CTDPA | Required since January 1, 2025 |
| Delaware | DPDPA | Required since January 1, 2026 |
| Maryland | MODPA | Required since October 1, 2025 |
| Minnesota | MNCDPA | Required since July 31, 2025 |
| Montana | MCDPA | Required since January 1, 2025 |
| Nebraska | NDPA | Required since January 1, 2025 |
| New Hampshire | NHPA | Required since January 1, 2025 |
| New Jersey | NJDPA | Required since July 15, 2025 |
| Oregon | OCPA | Required since January 1, 2026 |
| Texas | TDPSA | Required since January 1, 2025 |
Comply with all 20 state laws with one script tag
ConsentKit detects each visitor's state at the Cloudflare edge, renders the exact opt-out link their law requires, honors GPC automatically in the 12 states that mandate it, and records every choice for your audit trail.