Privacy Laws by State 2025

Other Applicable Law
24
Comprehensive privacy laws
20
Narrow Privacy Law
6
State
Type of Consumer Data Privacy Law
Effective Date
Additional Consumer Privacy Data Law Details
Alabama Flag
AlabamaOther Applicable Law
Alaska Flag
AlaskaOther Applicable Law
Arizona Flag
ArizonaOther Applicable Law
Arkansas Flag
ArkansasOther Applicable Law
Georgia Flag
GeorgiaOther Applicable Law
Hawaii Flag
HawaiiOther Applicable Law
Idaho Flag
IdahoOther Applicable Law
Illinois Flag
IllinoisOther Applicable Law
Kansas Flag
KansasOther Applicable Law
Louisiana Flag
LouisianaOther Applicable Law
Massachusetts Flag
MassachusettsOther Applicable Law
Mississippi Flag
MississippiOther Applicable Law
Missouri Flag
MissouriOther Applicable Law
New Mexico Flag
New MexicoOther Applicable Law
North Carolina Flag
North CarolinaOther Applicable Law
North Dakota Flag
North DakotaOther Applicable Law
Ohio Flag
OhioOther Applicable Law
Oklahoma Flag
OklahomaOther Applicable Law
Pennsylvania Flag
PennsylvaniaOther Applicable Law
South Carolina Flag
South CarolinaOther Applicable Law
South Dakota Flag
South DakotaOther Applicable Law
West Virginia Flag
West VirginiaOther Applicable Law
Wisconsin Flag
WisconsinOther Applicable Law
Wyoming Flag
WyomingOther Applicable Law
Maine Flag
MaineNarrow Privacy Law
Michigan Flag
MichiganNarrow Privacy Law
Nevada Flag
NevadaNarrow Privacy Law
New York Flag
New YorkNarrow Privacy Law
Vermont Flag
VermontNarrow Privacy Law
Washington Flag
WashingtonNarrow Privacy Law
California Flag
CaliforniaComprehensive privacy laws2023California led the charge in being the first state to enact comprehensive data privacy legislation via the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). CCPA, signed into law on June 8, 2018, and which went into effect on Jan. 1, 2020, establishes privacy rights and business requirements for collecting and selling Californians’ personal information
Colorado Flag
ColoradoComprehensive privacy laws2023The Colorado Privacy Act (CPA), effective July 1, 2023, grants Colorado consumers five key rights related to their personal data: access, correction, deletion, data portability, and the ability to opt out. It protects information that can identify an individual, excluding de-identifiable and publicly available data.
Connecticut Flag
ConnecticutComprehensive privacy laws2023The Connecticut Data Privacy Act (CTDPA), effective as of July 1, 2023, includes stronger data protections for children but a similar framework as its predecessors.
Delaware Flag
DelawareComprehensive privacy laws2025Delaware Personal Data Privacy Act has stronger privacy rights for consumers, such as heightening protections for children’s data, broadening definitions of sensitive data, and being able to opt out of the processing of personal data for targeted advertising purposes.
Florida Flag
FloridaComprehensive privacy laws2024The Sunshine State tackles issues related to tech platforms, like addressing alleged censorship of conservative viewpoints. The law requires search engines, such as Google, to disclose if they prioritize results based on political ideology and prohibits government-mandated content moderation on social media.
Indiana Flag
IndianaComprehensive privacy laws2026The Indiana Consumer Data Protection Act will regulate businesses that process the personal data of at least 100,000 Indiana residents, or ones that handle the information of at least 25,000 state consumers but derive more than 50% of their revenue from selling data.
Iowa Flag
IowaComprehensive privacy laws2025Data Protection Act (ICDPA), is considered one of the most business-friendly so far, which privacy advocates say results in weaker data protections. Slated to go in effect Jan. 1, 2025, Iowa’s law does not grant consumers the right to delete or correct data collected by third parties.
Kentucky Flag
KentuckyComprehensive privacy laws2026The Kentucky Consumer Data Act (KCDPA) applies to entities that conduct business in the state or target residents and manage the personal data of at least 100,000 consumers per year. That threshold drops to 25,000 consumers if a business derives more than half its gross revenue from selling personal data. Businesses will have the opportunity to remedy violations within 30 days without penalty. Exemptions under the law include government entities, federally regulated financial institutions, and nonprofits
Maryland Flag
MarylandComprehensive privacy laws2025Maryland’s law applies to companies that handle the personal data of at least 35,000 residents per year, or 10,000 residents if more than 20% of the company’s revenue comes from selling personal data. Children will receive heightened data privacy protections, as will sensitive data related to a person’s religious beliefs, sexual orientation, immigration status, and other similar information.
Minnesota Flag
MinnesotaComprehensive privacy laws2025The law cover companies that handle the personal data of at least 100,000 Minnesota consumers each year. That threshold will drop to 25,000 consumers if the company makes more than a quarter of its revenue from selling personal data. Companies that fall under the federal definition of a small business will be exempt.
Montana Flag
MontanaComprehensive privacy laws2024Montana’s Consumer Data Privacy Act limits the collection of personal data to only “adequate, relevant, and reasonably necessary” information. Residents have the right to opt-out or decline the sale of their personal data.
Nebraska Flag
NebraskaComprehensive privacy laws2025The Nebraska Data Privacy Act (NDPA) applies to companies that do business in the state or target its residents and also process or sell personal data. The law excludes federally defined small businesses and includes numerous exemptions, such as for federally regulated financial institutions. Residents have the right to request that companies correct or delete their data.
New Hampshire Flag
New HampshireComprehensive privacy laws2025The New Hampshire Privacy Act (NHPA) will apply to companies that handle the data of at least 35,000 state residents a year, or 10,000 if more than a quarter of their gross revenue comes from selling personal data. Consumers will have the right to know what data a company collects and opt out of certain uses, such as targeted advertising.
New Jersey Flag
New JerseyComprehensive privacy laws2025The New Jersey Data Privacy Act (NJDPA) provides New Jersey residents with comprehensive privacy protections against how companies collect and use their personal information. The law applies to entities that do business in the state and handle the personal data of at least 100,000 consumers per year, or at least 25,000 if the company also sells personal data
Oregon Flag
OregonComprehensive privacy laws2024One of the strongest data privacy laws passed to date, the Oregon Consumer Privacy Act (OCPA) includes provisions on biometric data, sensitive and personal data, and children’s data protections, and it doesn't have the same exemptions found in other state privacy laws.
Rhode Island Flag
Rhode IslandComprehensive privacy laws2026Consumers will have the right to confirm what data a company collects, correct it, receive a copy, and opt out of certain uses. Companies must also secure consent before processing sensitive data.
Tennessee Flag
TennesseeComprehensive privacy laws2025Backed with bipartisan support, the Tennessee Information Protection Act enables consumers to confirm that a business has collected their personal data, obtain a copy of the information, and request that inaccuracies be corrected
Texas Flag
TexasComprehensive privacy laws2024Texas Data Privacy and Security Act (TDPSA) will apply to large companies that do business in Texas or sell, collect, or process personal data. Small businesses will mostly be exempt.
Utah Flag
UtahComprehensive privacy laws2023On March 24, 2022, Utah became the fourth state to pass comprehensive data legislation.
Virginia Flag
VirginiaComprehensive privacy laws2023The law gives Virginians the right to access their data and request that their personal information be deleted by businesses. It also requires companies to conduct data protection assessments to process personal data for targeted advertising and sales purposes.