As of July 2024, 20 states - California, Colorado, Connecticut, Delaware, Florida,* Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia - have enacted privacy laws designed to increase protections for consumers' personal data, provide consumers with certain rights to control their personal data, and regulate businesses’ use of consumers’ personal data, including sensitive personal data.
*Importantly, while Florida’s privacy law contains similar rights and regulations to other state privacy laws, it is aimed primarily at Big Tech companies, and its scope is largely different than the other, more comprehensive state privacy laws.
California’s law, the California Privacy Rights Act of 2020 (CPRA), which amends the California Consumer Privacy Act of 2018 (CCPA), and Virginia’s law, the Virginia Consumer Data Protection Act (VA CDPA), took effect January 1, 2023. Colorado’s law, the Colorado Privacy Act (ColoPA), and Connecticut’s law, the Connecticut Act Concerning Personal Data Privacy and Online Monitoring (CT DPA), took effect July 1, 2023. Utah’s law, the Utah Consumer Privacy Act (UCPA), took effect December 31, 2023.
Texas’s law, the Texas Data Privacy and Security Act (TDPSA), and Florida’s law, the Florida Digital Bill of Rights (FDBR), took effect on July 1, 2024. Oregon’s law, the Oregon Consumer Data Privacy Act (OCDPA), also took effect on July 1, 2024 for subject businesses other than non-profit businesses. The OCDPA will take effect for non-profits on July 1, 2025. Montana’s law, Montana Consumer Data Privacy Act (MCDPA), took effect October 1, 2024.
Iowa’s law, an Act relating to Consumer Data Protection (Iowa CDPA); Delaware’s law, the Delaware Personal Data Privacy Act (DPDPA); Nebraska’s law, the Nebraska Data Privacy Act (NDPA); and New Hampshire's law, an Act relative to the Expectation of Privacy (NHPA) took effect January 1, 2025. New Jersey’s law, an Act Concerning Online Services, Consumers, and Personal Data (NJDPA), took effect on January 15, 2025. Tennessee’s law, the Tennessee Information Protection Act (TIPA), along with the OCDPA as it applies to non-profits, will take effect July 1, 2025. Minnesota’s law, the Minnesota Consumer Data Privacy Act (MNDPA), will take effect on July 31, 2025. Maryland’s law, the Maryland Online Data Privacy Act (MODPA), will take effect on October 1, 2025. Indiana’s law, the Indiana Consumer Data Protection Act, (Indiana CPDA), Kentucky’s law, the Kentucky Consumer Data Protection Act (KCDPA), and Rhode Island’s law, the Rhode Island Data Transparency and Privacy Protection Act (RIDPA), will take effect January 1, 2026.
The inclusion of certain rights for individuals regarding their own personal data is part of what sets these new privacy laws apart from previous privacy regulation in the United States. From a compliance perspective, these consumer rights, and how to facilitate them, are key considerations and could require substantial work for businesses. These consumer rights allow respective residents to: (1) access their personal data; (2) correct inaccuracies in their personal data (not provided in the UCPA or the Iowa CDPA); (3) delete their personal data; (4) obtain a copy of their personal data in a portable format, or a representative summary (only in Indiana CDPA); and/or (5) opt out of processing for purposes of the sale of personal data, targeted advertising (not expressly provided in the Iowa CDPA), or profiling (not expressly provided in the Iowa CDPA).
Another critical component of these laws is the regulation of “targeted advertising” or “cross-context behavioral advertising,” both of which include the concept of displaying advertisements to a consumer based on personal data obtained from that consumer’s activities over time and across non-affiliated or distinctly-branded websites to predict such consumer’s preferences or interests. It is subject to certain exceptions.
Under several of the new laws, businesses must perform and document a privacy impact assessment that weighs the benefits of processing for the business against the potential risks for the individual prior to selling personal data, processing personal data for targeted advertising, or processing sensitive data. Some of these state laws also require businesses to obtain consent to process sensitive data, which includes, among other things, information related to race or ethnicity, religion, health, sexual orientation, citizenship, and genetic or biometric data used to identify a person.
Businesses may be directly subject to these laws as “controllers” (i.e., those that determine the purposes and means for processing personal data) or indirectly as “processors” (i.e., those that process personal data on behalf of controllers). Businesses subject to these laws, whether directly or indirectly, will need to formulate a plan for compliance that accounts for the nuances of each applicable law. To assist businesses in understanding and complying with these laws, our Data Protection attorneys have compiled numerous resources for you, including our Quick Reference Guides to the right and our client alerts found in the Publications tab above.
If you would like assistance with, or have any questions about, complying with these laws or other data privacy laws, or need assistance reviewing your data privacy practices, please contact one of our Data Protection attorneys.

These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.
These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance.
These cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.
These cookies enable the website to provide enhanced functionality and personalisation. They may be set by us or by third party providers whose services we have added to our pages. If you do not allow these cookies then some or all of these services may not function properly.