US State Privacy Legislation Tracker
Updated as of 10/15/2024
*scroll horizontally to view more cells
State | Consumer Rights | Business Obligations | Introduced | Signed | Bill & Link | Name | Effective Date |
---|---|---|---|---|---|---|---|
California |
• Right to access • Right to correct • Right to delete • Right to opt out of certain processing (sensitive data) • Right to portability • Right to opt out of sales • Right against automated decision-making • Private right of action (limited to certain violations only) |
• Required age of opt-in default (16) • Notice/transparency requirement • Risk assessments • Prohibition on discrimination (exercising rights) • Purpose/processing limitation |
x | x | CCPA | California Consumer Privacy Act | January 1, 2020 |
Colorado | • Right to access • Right to correct • Right to delete • Right to opt out of certain processing (for profiling/targeting purposes) • Right to portability • Right to opt out of sales • Right to opt in for sensitive data processing • Right against (certain) automated decision-making |
•Required age of opt-in default (13) • Notice/transparency requirement • Risk assessments • Prohibition on discrimination (exercising rights) • Purpose/processing limitation |
x | x | SB 190 | Colorado Privacy Act | July 1, 2023 |
Connecticut |
• Right to access • Right to correct • Right to delete • Right to opt out of certain processing (for profiling/targeting purposes) • Right to portability • Right to opt out of sales • Right to opt in for sensitive data processing • Right against (certain) automated decision-making |
• Required age of opt-in default (13) • Notice/transparency requirement • Risk assessments • Prohibition on discrimination (exercising rights) • Purpose/processing limitation |
x | x | SB 6 | Connecticut Data Privacy Act | July 1, 2023 |
Delaware |
• Right to access • Right to correct • Right to delete • Right to opt out of certain processing (for profiling/targeting purposes) • Right to portability • Right to opt out of sales • Right to opt in for sensitive data processing • Right against (certain) automated decision-making |
• Required age of opt-in default (17) • Notice/transparency requirement • Risk assessments • Prohibition on discrimination (exercising rights) • Purpose/processing limitation |
x | x | HB 154 | Delaware Personal Data Privacy Act | January 1, 2025 |
Indiana |
• Right to access • Right to correct • Right to delete • Right to opt out of certain processing (for profiling/targeting purposes) • Right to portability • Right to opt out of sales • Right to opt in for sensitive data processing • Right against (certain) automated decision-making |
• Required age of opt-in default (13) • Notice/transparency requirement • Risk assessments • Prohibition on discrimination (exercising rights) • Purpose/processing limitation |
x | x | SB 5 | Indiana Consumer Data Protection Act | January 1, 2026 |
Iowa |
• Right to access • Right to delete • Right to portability • Right to opt out of sales |
• Required age of opt-in default (13) • Notice/transparency requirement • Prohibition on discrimination (exercising rights) • Purpose/processing limitation |
x | x | SF 262 | Iowa Consumer Data Protection Act | January 1, 2025 |
Kentucky |
• Right to access • Right to correct • Right to delete • Right to opt out of certain processing (for profiling/targeting purposes) • Right to portability • Right to opt out of sales • Right to opt in for sensitive data processing • Right against (certain) automated decision-making |
• Required age of opt-in default (13) • Notice/transparency requirement • Risk assessments • Prohibition on discrimination (exercising rights) • Purpose/processing limitation |
x | x | HB 15 | Kentucky Consumer Data Protection Act | January 1, 2026 |
Maryland |
• Right to access • Right to correct • Right to delete • Right to opt out of certain processing (for profiling/targeting purposes) • Right to portability • Right to opt out of sales • Right to opt in for sensitive data processing • Right against (certain) automated decision-making |
• Required age of opt-in default (13) • Notice/transparency requirement • Risk assessments • Prohibition on discrimination (exercising rights) • Purpose/processing limitation |
x | x | SB 541 | Maryland Online Data Privacy Act | October 1, 2025 |
Minnesota |
• Right to access • Right to correct • Right to delete • Right to opt out of certain processing (for profiling/targeting purposes) • Right to portability • Right to opt out of sales • Right to opt in for sensitive data processing • Right against (certain) automated decision-making |
• Required age of opt-in default (13) • Notice/transparency requirement • Risk assessments • Prohibition on discrimination (exercising rights) • Purpose/processing limitation |
x | x | HF 2309 | Minnesota Consumer Data Privacy Act | July 31, 2025 |
Montana |
• Right to access • Right to correct • Right to delete • Right to opt out of certain processing (for profiling/targeting purposes) • Right to portability • Right to opt out of sales • Right to opt in for sensitive data processing • Right against (certain) automated decision-making |
• Required age of opt-in default (13) • Notice/transparency requirement • Risk assessments • Prohibition on discrimination (exercising rights) • Purpose/processing limitation |
x | x | SB 384 | Montana Consumer Data Privacy Act | October 1, 2024 |
Nebraska |
• Right to access • Right to correct • Right to delete • Right to opt out of certain processing (for profiling/targeting purposes) • Right to portability • Right to opt out of sales • Right to opt in for sensitive data processing • Right against (certain) automated decision-making |
• Required age of opt-in default (13) • Notice/transparency requirement • Risk assessments • Prohibition on discrimination (exercising rights) • Purpose/processing limitation |
x | x | LB 1074 | Nebraska Data Privacy Act | January 1, 2025 |
New Hampshire |
• Right to access • Right to correct • Right to delete • Right to opt out of certain processing (for profiling/targeting purposes) • Right to portability • Right to opt out of sales • Right to opt in for sensitive data processing • Right against (certain) automated decision-making |
• Required age of opt-in default (13) • Notice/transparency requirement • Risk assessments • Prohibition on discrimination (exercising rights) • Purpose/processing limitation |
x | x | SB 255 | January 1, 2025 | |
New Jersey |
• Right to access • Right to correct • Right to delete • Right to opt out of certain processing (for profiling/targeting purposes) • Right to portability • Right to opt out of sales • Right to opt in for sensitive data processing • Right against (certain) automated decision-making |
• Required age of opt-in default (13) • Notice/transparency requirement • Risk assessments • Prohibition on discrimination (exercising rights) • Purpose/processing limitation |
x | x | SB 332 | January 15, 2025 | |
Oregon |
• Right to access • Right to correct • Right to delete • Right to opt out of certain processing (for profiling/targeting purposes) • Right to portability • Right to opt out of sales • Right to opt in for sensitive data processing • Right against (certain) automated decision-making |
• Required age of opt-in default (13) • Notice/transparency requirement • Risk assessments • Prohibition on discrimination (exercising rights) • Purpose/processing limitation |
x | x | SB 619 | Oregon Consumer Privacy Act | July 1, 2024 |
Rhode Island |
• Right to access • Right to correct • Right to delete • Right to opt out of certain processing (for profiling/targeting purposes) • Right to portability • Right to opt out of sales • Right to opt in for sensitive data processing • Right against (certain) automated decision-making |
• Required age of opt-in default (13) • Notice/transparency requirement • Risk assessments • Prohibition on discrimination (exercising rights) • Purpose/processing limitation |
x | x | H 7787 | Rhode Island Data Transparency and Privacy Protection Act | January 1, 2026 |
Tennessee |
• Right to access • Right to correct • Right to delete • Right to opt out of certain processing (for profiling/targeting purposes) • Right to portability • Right to opt out of sales • Right to opt in for sensitive data processing • Right against (certain) automated decision-making |
• Required age of opt-in default (13) • Notice/transparency requirement • Risk assessments • Prohibition on discrimination (exercising rights) • Purpose/processing limitation |
x | x | HB 1181 | Tennessee Information Protection Act | July 1, 2025 |
Texas |
• Right to access • Right to correct • Right to delete • Right to opt out of certain processing (for profiling/targeting purposes) • Right to portability • Right to opt out of sales • Right to opt in for sensitive data processing • Right against (certain) automated decision-making |
• Required age of opt-in default (13) • Notice/transparency requirement • Risk assessments • Prohibition on discrimination (exercising rights) • Purpose/processing limitation |
x | x | HB 4 | Texas Data Privacy and Security Act | July 1, 2024 |
Utah |
• Right to access • Right to delete • Right to opt out of certain processing (for profiling/targeting purposes) • Right to portability • Right to opt out of sales |
• Required age of opt-in default (13) • Notice/transparency requirement • Risk assessments • Prohibition on discrimination (exercising rights) • Purpose/processing limitation |
x | x | SB 227 | Utah Consumer Privacy Act | December 31, 2023 |
Virginia |
• Right to access • Right to correct • Right to delete • Right to opt out of certain processing (for profiling/targeting purposes) • Right to portability • Right to opt out of sales • Right to opt in for sensitive data processing • Right against (certain) automated decision-making |
• Required age of opt-in default (13) • Notice/transparency requirement • Risk assessments • Prohibition on discrimination (exercising rights) • Purpose/processing limitation |
x | x | SB 1392 | Virginia Consumer Data Protection Act | January 1, 2023 |
Massachusetts |
• Right to access • Right to correct • Right to delete • Right to opt out of certain processing (for profiling/targeting purposes) • Right to portability • Right to opt out of sales • Right to opt in for sensitive data processing • Right against (certain) automated decision-making • Private right of action |
• Required age of opt-in default (17) • Notice/transparency requirement • Risk assessments • Prohibition on discrimination (exercising rights) • Purpose/processing limitation |
x | H 83 / S 25 / H 60 / S 227 / HD 3245 / S 2770 | Massachusetts Data Privacy Protection Act, Massachusetts Information Privacy and Security Act, Internet Bill of Rights, Massachusetts Data Privacy Act | ||
Michigan |
• Right to access • Right to correct • Right to delete • Right to opt out of certain processing (for profiling/targeting purposes) • Right to portability • Right to opt out of sales • Right to opt in for sensitive data processing • Right against (certain) automated decision-making • Private right of action |
• Required age of opt-in default (13) • Notice/transparency requirement • Risk assessments • Prohibition on discrimination (exercising rights) • Purpose/processing limitation |
x | SB 659 | Michigan Personal Data Privacy Act | ||
Ohio |
• Right to access • Right to correct • Right to delete • Right to opt out of certain processing (for profiling/targeting purposes) • Right to portability • Right to opt out of sales • Right against (certain) automated decision-making |
• Required age of opt-in default (13) • Notice/transparency requirement • Risk assessments • Prohibition on discrimination (exercising rights) • Purpose/processing limitation |
x | HB 345 | Ohio Personal Privacy Act | ||
Pennsylvania |
• Right to access • Right to correct • Right to delete • Right to opt out of certain processing (for profiling/targeting purposes) • Right to portability • Right to opt out of sales • Right to opt in for sensitive data processing • Right against (certain) automated decision-making |
• Required age of opt-in default (13) • Notice/transparency requirement • Risk assessments • Prohibition on discrimination (exercising rights) • Purpose/processing limitation |
x | HB 1947 / HB 1201 | Pennsylvania Consumer Data Protection Act |
Additional Resources
- Solutions Page Complying With United States New Privacy Laws
- Solutions Page Protect National Interests with Secure Content Communications
- Solutions Page Lock Down Confidential Agency Data and Preserve Constituent Privacy
- Case Studies Kiteworks Private Content Network
- Platform Page Protect Your EU Customers’ Personal Information With GDPR Compliance
- Brief Sensitive Content Communications Privacy and Compliance Report
Frequently Asked Questions
The California Consumer Privacy Act (CCPA) and the General Data Protection Regulation (GDPR) both aim to protect personal data, but they differ in various ways:
- Scope: The CCPA applies to businesses operating in California and collecting personal information of California residents, while the GDPR applies to all organizations working within the EU, or dealing with data of EU citizens, irrespective of their country location.
- Rights: Both give individuals the right to access and delete their data, but the GDPR also includes rights like rectification (correcting inaccurate data) and objection (objecting to processing personal data), which the CCPA does not explicitly provide.
- Enforcement: The GDPR has more vigorous enforcement and steeper penalties, with maximum fines of up to €20 million or 4% of annual global turnover, whichever is higher. CCPA’s penalties can reach up to $7,500 per intentional violation.
- Consent: The GDPR requires citizens’ explicit and informed consent before collecting personal data, while the CCPA does not require upfront approval but does provide citizens the right to opt out of data sales, preventing organizations from selling a citizen’s personal data.