HomeFrameworksAI Governance & Privacy FrameworksUS State Privacy Laws

Framework  AI Governance & Privacy Frameworks

US State Privacy Laws

In the absence of a federal comprehensive privacy statute, US states have passed their own consumer privacy laws, beginning with California's CCPA (2018, amended by the CPRA) and followed by Virginia, Colorado, Connecticut, Utah, and a steady stream of others.

By early 2026 around twenty states had comprehensive laws in force, with Indiana, Kentucky, and Rhode Island taking effect on January 1, 2026 and further effective dates through the year; Alabama's law is reported to take effect May 1, 2027 (verify the current count and dates against a maintained tracker).

The laws share a common shape: consumer rights to access, delete, correct, and port data and to opt out of sale, targeted advertising, and profiling; duties on controllers to publish a privacy notice, minimize data, secure it, contract with processors, and assess high-risk processing; and enforcement by state attorneys general (and in California the California Privacy Protection Agency).

What these laws force into writing is a privacy notice that matches actual practice, a data inventory that supports rights requests, written processor and service provider contracts, data protection assessments for targeted advertising, sale, profiling, and sensitive data processing, a documented method for honoring opt-out signals such as Global Privacy Control, records of rights requests and responses, and (in California) recognized employee training.

Thresholds differ by state and are usually based on state resident counts or revenue from selling data, so many small businesses fall outside some laws and inside others.

AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedPrivacy policy v4by name, on record
Every State One Trailwith AllyMatter
Fifty Ways the Modern WayOne privacy policy set, acknowledged in every state you sell in
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every employee on record
Who read which version, and when
03
Show the attorney general the trail
From $29/mo, 20 editors, unlimited staff (published)

Who has to comply

Businesses that process personal data of state residents and meet the state's threshold, typically a count of consumers (often 100,000, lower in smaller states such as 35,000 in Montana or Rhode Island) or a percentage of revenue from data sales. Exemptions commonly cover data already regulated under HIPAA, GLBA, and FCRA, and some states exempt nonprofits or higher education.

Texas has no volume threshold and applies to any non-small business that processes personal data.

What the assessor asks to see

When a regulator inquires or a customer performs due diligence: applicability analysis by state; privacy notice and notice at collection; data inventory and map; processor and service provider contracts; data protection assessments; opt-out mechanisms and GPC handling records; rights-request logs with response times and verification method; sensitive data consent records; data retention schedule; security program summary; training records; data broker registrations where applicable.

Where the requirement sits: CO, VA, CT, TX et al. comprehensive privacy acts

2026 effective dates

Reported effective dates in 2026 include Indiana, Kentucky, and Rhode Island on January 1; Connecticut amendments, Arkansas, and Utah amendments on July 1; and new California data broker registration duties on August 1. Alabama's act was signed April 17, 2026 with an effective date of May 1, 2027. Verify against the IAPP or MultiState trackers, which are updated as laws pass.

What AllyMatter does here

Policy and training-acknowledgment layer.

AllyMatter publishes this site.

Assessors

Who assesses US State Privacy Laws

None. Compliance is enforced by state attorneys general and the California Privacy Protection Agency through investigations and civil actions; there is no certification or licensed assessor.

California's regulations on cybersecurity audits and risk assessments, when in force, will require certain businesses to obtain an independent audit and file certifications with the agency (verify the current CPPA regulation status and effective dates).

No firm has claimed a US State Privacy Laws assessor listing yet. Claim yours →

Consultants

Who helps with US State Privacy Laws

A large ecosystem of privacy law firms, consultancies, and consent and rights-request platform vendors. Typical engagements map which states apply, build the data inventory, draft notices and processor contracts, stand up rights-request workflows, and prepare data protection assessments.

Engagements run from a few weeks for a single-state update to several months for a multi-state program.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

XpertDPOUK/IrelandNot yet verified
What they do
Privacy governance + ISO 27001
Who they help
XpertDPO is a privacy governance + ISO 27001 based in UK/Ireland. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published

Software

Tools for US State Privacy Laws

Tools that name this framework in their own material.

Related reading

  1. US State Privacy Legislation TrackerThe reference chart and map for which states have comprehensive laws, tracking fourteen provisions that recur across them.IAPP
  2. New year, new rules: US state privacy requirements coming online as 2026 beginsExplains which obligations newly bite each January and how the requirements differ state to state.IAPP
  3. 20 state privacy laws in effect in 2026: key dates and changesDate-by-date view of when each state law takes effect and where amendments have shifted the goalposts.MultiState

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for US State Privacy Laws

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Run the Policy Side of US State Privacy Laws in AllyMatter

Approve the policies US State Privacy Laws asks for, keep every version, and record a named acknowledgment from each person who has to read them.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.