Obtainer
Blog / State Laws 10 min read

State Privacy Law Cure Periods in 2026: Which States Still Give You One

Last updated July 2026 · Obtainer

Request Studio
Requester
Compiled the manifest and drafted the response - illustrative sample request
0
records found
0
systems scanned
Data manifest
Response draft

Assembling the cover letter from the template...

You approve what is disclosed before anything ships

Helps you comply, not legal advice

As of 2026, most US state privacy laws no longer give you a right to cure. California, Connecticut, Colorado, Delaware, Oregon, Montana, Minnesota, New Hampshire, and now New Jersey have all lost or removed their cure periods, which means a state attorney general can open an enforcement action over a missed data subject request without first sending a notice and waiting for you to fix it. New Jersey was the most recent to go, on July 15, 2026. Roughly nine states still offer a permanent cure window, led by Iowa at 90 days and Florida at 45. The practical effect for anyone handling privacy requests is simple: the first missed 45-day deadline is now the violation, not the warning.

What is a cure period in a state privacy law?

A cure period is a statutory grace window. When the attorney general believes you violated the law, they must notify you in writing and give you a set number of days, usually 30 or 60, to correct the problem before they can sue or seek civil penalties. If you fix it and provide a written statement that the violation is cured, the matter typically ends there. Cure periods were written into most first-generation state privacy laws as a transition device for businesses adapting to brand new obligations, and many of them carried an explicit sunset date.

That transition is over. Legislatures wrote the sunsets on purpose, and in 2025 and 2026 they started firing. Montana went further and repealed its cure period outright through Senate Bill 297. Rhode Island's law, effective January 1, 2026, never included one at all.

Which states still have a right to cure in 2026?

The table below shows where each comprehensive state privacy law stands. Dates reflect the position as of July 2026. Statutes and amendments move, so confirm against the current text before you rely on any single row.

StateCure periodStatus in 2026
California (CCPA/CPRA)30 daysGone, expired January 1, 2023
Connecticut (CTDPA)60 daysGone, expired December 31, 2024
Colorado (CPA)60 daysGone, expired January 1, 2025
Montana (MCDPA)60 daysGone, repealed by SB 297 effective October 1, 2025
New Hampshire (NHDPA)60 daysGone, discretionary after December 31, 2025
Delaware (DPDPA)60 daysGone, expired January 1, 2026
Oregon (OCPA)30 daysGone, expired January 1, 2026
Minnesota (MCDPA)30 daysGone, expired January 31, 2026
Rhode IslandNoneNever had one
New Jersey (NJDPA)30 daysGone, sunset July 15, 2026, discretionary since
Maryland (MODPA)60 daysDiscretionary from April 1, 2027
Virginia (VCDPA)30 daysPermanent
Texas (TDPSA)30 daysPermanent
Utah (UCPA)30 daysPermanent
Indiana30 daysPermanent
Kentucky30 daysPermanent
Nebraska (NDPA)30 daysPermanent
Tennessee (TIPA)60 daysPermanent
Iowa90 daysPermanent, the longest in the country
Florida (FDBR)45 daysPermanent, at the attorney general's discretion

Two patterns are worth noticing. First, the states with the most active enforcement postures, California, Colorado, and Connecticut, are all in the no-cure column, and they got there first. Second, the newer laws split: Indiana, Kentucky, and Nebraska deliberately wrote permanent cure periods, while Rhode Island wrote none. There is no national direction of travel you can plan around, which is exactly why a multi-state operator has to run one process that assumes the strictest state applies.

Does a discretionary cure period still help me?

Sometimes, but you cannot build a compliance plan on it. Several states, including Florida and Maryland after its window closes, let the attorney general offer a cure if they consider it appropriate given the number of violations, the size of the business, and whether the violation was intentional. That is not a right. It is a factor in someone else's decision, exercised after they have already looked at your conduct. A company that can show a documented request workflow, timestamps, and a good-faith response is in a much better position to be offered that discretion than one producing an ad hoc email thread.

What happens if you miss a data subject request deadline now?

Eighteen of the twenty comprehensive state privacy laws give you 45 days from a verified request, extendable once by another 45 days if you notify the consumer within the original window. Florida allows only a 15-day extension, and Iowa allows 90 days plus 45. Miss that, and in a no-cure state the attorney general can move directly to a civil investigative demand or a suit. Penalties run to $7,500 per violation in most states, $20,000 in Colorado under its consumer protection act, and $5,000 per willful violation in Connecticut. The multiplier matters more than the headline number: in several states, including Oregon, each affected consumer can count as a separate violation, so a systemic failure to honor deletion requests is not one $7,500 problem.

The consumer-facing part of this is also visible. Regulators have consistently opened inquiries after complaints from people who submitted a request and heard nothing back. Silence is the single most common trigger.

Why did states remove the right to cure?

Because the transition rationale expired. Cure periods were sold as a grace window while businesses learned a new regime, and legislators wrote sunset dates to make that temporary nature explicit. Enforcers also argued, with some evidence, that a permanent cure period turns the law into a free first violation: a company can ignore its obligations until it receives a notice, fix that one issue, and repeat. California's Privacy Protection Agency and several state attorneys general made that argument publicly before their sunsets took effect, and Montana's legislature accepted a version of it when it repealed the cure period in 2025.

How to operate when there is no cure period

The change is procedural, not legal, and the fix is procedural too. Four things separate companies that handle this cleanly from those that do not.

  • Log every request the day it arrives. The clock starts on receipt of a verified request, not when someone gets around to the ticket. A dated intake record is your evidence of good faith if a regulator ever asks.
  • Route it to a named owner immediately. Most missed deadlines are not refusals, they are requests that sat in a shared inbox. Whether you do it in a privacy tool or by routing every incoming request to the right owner automatically, the assignment has to happen on day one.
  • Know where the data lives before you need it. Discovery is the slow part. A person's records sit in your production database, warehouse, billing system, help desk, and email, and hunting them down manually is what pushes a response past day 45.
  • Use the extension properly. The extra 45 days is available in every state except Florida, which allows only 15, but only if you notify the consumer within the first 45 days and explain the reason. An extension you never told anyone about is just a late response.

Does this change what I have to do differently by state?

Less than you might expect on the response itself, more than you might expect on exposure. The core obligation is close to uniform: 18 of the 20 states use the same 45 plus 45 day structure, with Iowa at 90 plus 45 and Florida at 45 plus 15, and the rights are broadly the same set of access, correct, delete, port, and opt out. What differs is who is covered and what happens when you slip. Running one workflow that meets the strictest standard, then documenting it, is far cheaper than maintaining twenty variations. If you are unsure which laws reach you at all, start with the applicability thresholds by state, because coverage is driven by resident counts and data sales, not revenue.

The states that removed their cure periods are also, mostly, the ones with the more demanding operational requirements. Oregon lets a consumer demand the specific third parties that received their data. Colorado and Connecticut require an appeal process for denials. All of them require you to honor a browser-level opt-out signal. Those obligations are now enforceable on the first miss.

Frequently asked questions

Which state privacy law has the longest cure period?

Iowa, at 90 days, and it is permanent with no sunset date. Florida follows at 45 days, though Florida's is discretionary rather than guaranteed. Among the 30 and 60 day states, the ones that remain permanent are Virginia, Texas, Utah, Indiana, Kentucky, Nebraska, and Tennessee. Every other comprehensive state law has either lost its cure period to a sunset or never had one. Tennessee's 60 days is the most useful of them, because TIPA also lets you assert a documented privacy program as an affirmative defense if a cured violation still ends up in court.

Can a state attorney general sue immediately for a privacy violation?

In a state without a cure period, yes. California, Colorado, Connecticut, Delaware, Oregon, Montana, Minnesota, New Hampshire, and Rhode Island all allow enforcement without a mandatory notice-and-cure step. In practice most enforcers still open with an inquiry or a civil investigative demand rather than a lawsuit, but that is a choice they make, not a right you hold.

Does the CCPA still have a 30-day cure period?

No. The CCPA's 30-day cure period expired on January 1, 2023, when the CPRA amendments took effect. Both the California Attorney General and the California Privacy Protection Agency can now enforce without offering a chance to cure. California's limited private right of action, which applies only to certain data breaches, has its own separate 30-day notice provision that was not affected by that change.

How many US states have comprehensive privacy laws in 2026?

Twenty states have a comprehensive consumer privacy law in effect in 2026: California, Virginia, Colorado, Connecticut, Utah, Oregon, Texas, Florida, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Tennessee, Maryland, Indiana, Kentucky, and Rhode Island. Indiana, Kentucky, and Rhode Island were the most recent to switch on, all in January 2026. You can see the full state-by-state breakdown here.

The takeaway

The grace period era is ending state by state, and the states that ended it first are the ones most likely to enforce. What protects you now is not a statutory second chance, it is a request process that starts a timer on day one, finds the data without a manual hunt, and produces a record you can show a regulator. If you want the specific state rules, the Oregon Consumer Privacy Act page, the Montana Consumer Data Privacy Act page, and the Connecticut Data Privacy Act page cover thresholds, rights, and penalties for the three states whose cure periods disappeared most recently. If you want the workflow, Obtainer intakes the request, discovers where the person's data lives, drafts the response, and tracks the 45-day clock, with a human approving anything before it leaves. Obtainer helps you comply. It is not legal advice.

Run a data subject access request end to end

Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.