Obtainer
Blog / Fundamentals 13 min read

States With Data Privacy Laws: All 20 State Privacy Laws in 2026

Last updated July 2026 · Obtainer

Request Studio
Requester
Compiled the manifest and drafted the response - illustrative sample request
0
records found
0
systems scanned
Data manifest
Response draft

Assembling the cover letter from the template...

You approve what is disclosed before anything ships

Helps you comply, not legal advice

Twenty US states have a comprehensive consumer data privacy law in effect in 2026. Every one of them gives residents the right to access and delete the personal data a business holds about them, and eighteen of the twenty give you 45 days to respond, extendable once by another 45 days with notice. The two exceptions are Iowa, which allows 90 days plus a 45-day extension, and Florida, which caps its extension at 15 days for a 60-day ceiling. The laws differ mostly in who they apply to, not in what they ask you to do. If you can answer an access request and a deletion request on a 45-day clock, you are most of the way to compliance in all twenty.

General information, not legal advice. Applicability thresholds and exemptions are fact-specific, so take advice on the calls that are close for your business.

Which states have data privacy laws in 2026?

These twenty states have a comprehensive consumer privacy law in effect. "Comprehensive" is the operative word: it means a law covering personal data broadly, as opposed to a narrow sectoral law covering health records, student data, or biometrics, which many more states have. Washington and Nevada are the clearest example of that distinction: neither has a comprehensive law, but both regulate consumer health data outside HIPAA with no size threshold at all, which is covered separately in our guide to consumer health data privacy laws.

StateLawIn effect sinceResponse deadline
CaliforniaCCPA, amended by CPRAJanuary 202045 days, +45 with notice
VirginiaVCDPAJanuary 202345 days, +45 with notice
ColoradoCPAJuly 202345 days, +45 with notice
ConnecticutCTDPAJuly 202345 days, +45 with notice
UtahUCPADecember 202345 days, +45 with notice
OregonOCPAJuly 202445 days, +45 with notice
TexasTDPSAJuly 202445 days, +45 with notice
FloridaFDBRJuly 202445 days, +15 with notice
MontanaMCDPAOctober 202445 days, +45 with notice
DelawareDPDPAJanuary 202545 days, +45 with notice
IowaICDPAJanuary 202590 days, +45 with notice
NebraskaNDPAJanuary 202545 days, +45 with notice
New HampshireNHDPAJanuary 202545 days, +45 with notice
New JerseyNJDPAJanuary 202545 days, +45 with notice
MinnesotaMCDPAJuly 202545 days, +45 with notice
TennesseeTIPAJuly 202545 days, +45 with notice
MarylandMODPAOctober 202545 days, +45 with notice
IndianaICDPAJanuary 202645 days, +45 with notice
KentuckyKCDPAJanuary 202645 days, +45 with notice
Rhode IslandRIDTPPAJanuary 202645 days, +45 with notice

Indiana, Kentucky, and Rhode Island are the newest, all switching on in January 2026. All three largely follow the template the Virginia Consumer Data Protection Act set in 2023, which is the single most useful thing to know about the state privacy landscape: after California, almost everyone copied Virginia.

What all 20 state privacy laws have in common

The convergence is real, and it is what makes this tractable. Across all twenty laws, residents get some version of the same core rights:

  • The right to access a copy of the personal data you hold about them, and to confirm whether you are processing it at all.
  • The right to delete the personal data you hold, subject to exceptions.
  • The right to correct inaccurate personal data, in every state except Iowa, since Utah switched its correction right on with House Bill 418 on July 1, 2026.
  • The right to data portability, meaning a copy in a portable and readily usable format where technically feasible.
  • The right to opt out of targeted advertising, the sale of personal data, and certain profiling.
  • The right to appeal a refused request, which is a Virginia-template feature California does not have.

That last one catches people out. Under most of the state laws, if you decline a request you have to give the consumer a way to appeal your decision, respond to the appeal within a set window, usually 45 or 60 days, and tell them how to complain to the state attorney general if you deny the appeal. It is a second clock hiding behind the first one, and there is no equivalent in the CCPA.

Where the state privacy laws actually differ

The differences are concentrated in who has to comply, not what compliance looks like. Three things vary in ways that matter:

Thresholds. Most states use the Virginia model: you are covered if you process the data of 100,000 or more residents, or 25,000 or more residents while deriving revenue from selling data. But the numbers move. Delaware, New Hampshire, Maryland, and Rhode Island drop to 35,000 residents, and the Connecticut Data Privacy Act joined them at 35,000 in July 2026. The Montana Consumer Data Privacy Act now triggers at 25,000, down from 50,000 after its 2025 amendments, and the Oregon Consumer Privacy Act keeps 100,000 but also covers nonprofits, which most states exempt. The Texas Data Privacy and Security Act and Nebraska abandon consumer counts entirely and cover essentially any business that is not a small business under the SBA definition, which is the broadest approach in the country. The Colorado Privacy Act sticks with the 100,000-consumer threshold, or 25,000 if you sell data. The Tennessee Information Protection Act goes the other way with the highest volume trigger in the country, 175,000 consumers, and it must be paired with more than $25 million in revenue. California is the odd one out, keyed to an inflation-adjusted $26,625,000 in annual revenue, 100,000 consumers, or 50% of revenue from selling or sharing data.

Sensitive data. Most states require opt-in consent before processing sensitive data such as race, health, precise geolocation, or biometrics. California instead lets consumers limit its use after the fact. The Maryland Online Data Privacy Act goes furthest and bans the sale of sensitive data outright, rather than merely requiring consent, and pairs it with a genuine data minimization rule, which makes it the strictest law in the country if you handle sensitive categories. Health data also gets its own treatment outside these laws: Washington's My Health My Data Act regulates consumer health data with no threshold and lets consumers sue directly, so a company under the size cutoff everywhere on this list can still be fully in scope there.

Enforcement. California has a dedicated regulator, the California Privacy Protection Agency, and it is the only state with even a limited private right of action, which applies to certain data breaches rather than to request handling. Everywhere else, enforcement runs through the attorney general. Several states offer a cure period, a window to fix a violation before enforcement, but a number of them are time-limited and have already expired or are set to sunset, so treating a cure period as a safety net is unwise.

Does my business have to comply with state privacy laws?

Work it out in this order, because it saves time. First, do you fall under an entity-level exemption? Most of these laws exempt nonprofits, government bodies, and organizations already regulated under HIPAA or the Gramm-Leach-Bliley Act, though the exemptions are narrower than people assume and some states exempt the data rather than the entity. Second, count residents, not customers: the threshold usually counts consumers whose data you process, which includes prospects, website visitors you can identify, and job applicants in some states. Third, check whether you sell or share data as those laws define it, because the definitions reach further than a cash sale and often catch ordinary adtech arrangements.

Here is the pragmatic reality for most mid-sized US companies. You will clear the threshold in a handful of states and fall under it in the rest, but you will not know which residents are which until a request arrives with an address on it. Building twenty different processes is not a serious plan. Most teams pick the strictest operational standard, usually a 45-day response with an appeal path, and run everything through it, then apply state-specific exceptions when a request actually lands. If you want to read the statutory text behind any of these rather than a vendor's summary of it, you can look the law up in plain English and check the definitions yourself, because the definitions are where these laws hide their differences.

The 45-day clock and the part teams get wrong

Nearly every state gives you 45 calendar days from receipt of the request, with one extension of 45 more where reasonably necessary given complexity or volume, provided you notify the consumer within the original window and explain why. Two details cause most of the failures.

The clock starts when the request arrives, not when you verify the requester. Verification time is inside your 45 days. Teams that spend three weeks confirming identity have three weeks left to find the data, review it, and write the response. That is the most common way a compliant intent becomes a late response.

The second detail is that a request does not have to look like a request. It does not need a form, a subject line, or the word "CCPA" in it. An email to a support inbox saying "please delete my account and everything you have on me" starts the clock. If your intake depends on consumers finding a web form, you are already missing requests, and the clock on those is running regardless.

Do I need separate processes for GDPR and US state laws?

No, but you do need separate clocks and separate exception lists. The GDPR runs on one month, extendable by two further months for complex or numerous requests. The state laws run on 45 days plus 45. The exceptions genuinely differ: the CCPA has nine statutory exceptions to deletion, the GDPR has five under Article 17(3), and they do not line up. A blended process built on a single merged rule tends to over-delete on one side and under-document on the other. The comparison of GDPR and CCPA data requests walks through where the two diverge, and the data subject rights overview covers how the eight GDPR rights and the six California rights map onto each other.

What happens if you ignore a state privacy request?

The exposure varies. California penalties run to $2,663 per violation, or $7,988 for intentional violations and violations involving a consumer known to be under 16, assessed per consumer; those are the inflation-adjusted figures in force through 2026, above the statute's original $2,500 and $7,500. Most other states set a maximum civil penalty per violation, commonly $7,500, enforced by the attorney general, though Colorado reaches $20,000 and Florida $50,000. The number that matters is not the per-violation figure but the multiplier: these penalties are usually assessed per affected consumer, which is why a systematic failure to honor requests is a different category of problem from one late response. See the maximum civil penalty in all twenty states for the full comparison.

The more common cost is quieter. Attorneys general have been running sweeps, sending inquiry letters to businesses whose opt-out mechanisms do not work or whose request handling stalls. Answering one of those with "we do not have a process, we handle them ad hoc" is expensive in a way that does not show up as a fine.

How to actually run this

The operational problem underneath all twenty laws is the same, and it is not legal. It is that you cannot answer an access or deletion request until you know where the person's data lives, and in most companies it lives in a CRM, a help desk, a billing system, a warehouse, a marketing tool, and several spreadsheets nobody has opened in a year. The law is the easy part. Finding the data is the work.

That is the step to systematize first. Whatever tooling you use, the sequence is the same: capture every request wherever it arrives, start the right clock, verify the person, find the data across your systems, decide what an exception covers, and have a human review the response before it goes out. DSAR automation runs that sequence, and data deletion request software handles the harder half of it, where the action is irreversible and you still have to prove you took it.

Twenty states, one process, twenty sets of exceptions applied at the end. That is the shape of a compliance program that survives the next five state laws, and there will be more.

Run a data subject access request end to end

Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.