Get Demo
↑

US State Privacy Laws: The 2026 Evergreen Map

Evergreen 2026 map of US comprehensive state privacy laws —.

Published: September 2026 Compliance · US Privacy 10–14 min read

As of 2026 the United States still lacks a single federal comprehensive privacy law. Organisations must navigate a growing patchwork of state consumer privacy acts. This page is CyberSilo’s evergreen 2026 hub (replacing the dated 2025 URL).

Related: CCPA hub · What is CCPA/CPRA · CCPA vs other states.

CCPA/CPRA business thresholds (current): For-profit doing business in California that collects CA consumers’ personal information and meets one or more of: (1) annual gross revenues in excess of $26,625,000 (CPI-adjusted amount effective Jan 1, 2025 under §1798.199.95(d); statutory base was $25M) in the preceding calendar year; (2) annually buys, sells, or shares the personal information of 100,000 or more consumers or households; (3) derives 50% or more of annual revenues from selling or sharing consumers’ personal information. The older pre-CPRA 50,000 consumers/households/devices threshold is no longer the current test.

Major Comprehensive State Privacy Laws

Effective/enforcement dates below are summarised carefully for programme planning. Always verify the current statute and AG/agency rules before relying on a date in production playbooks.

State
Law
Effective / enforcement (summary)
California
CCPA/CPRA
CCPA Jan 1, 2020; CPRA amendments Jan 1, 2023
Virginia
VCDPA
Jan 1, 2023
Colorado
CPA
July 1, 2023 (enforcement phased)
Connecticut
CTDPA
July 1, 2023
Utah
UCPA
Dec 31, 2023
Texas
TDPSA
July 1, 2024
Oregon
OCPA
July 1, 2024 (fuller obligations phased)
Montana
MTCDPA
Oct 1, 2024
Delaware
DPDPA
Jan 1, 2025
Iowa
ICDPA
Jan 1, 2025
Nebraska
NDPA
Jan 1, 2025
New Hampshire
NHPA
Jan 1, 2025
New Jersey
NJDPA
Jan 15, 2025
Tennessee
TIPA
July 1, 2025
Minnesota
MCDPA
July 31, 2025
Maryland
MODPA
Oct 1, 2025
Indiana
INCDPA
Jan 1, 2026
Kentucky
KCDPA
Jan 1, 2026
Rhode Island
RIDTPA
Jan 1, 2026

Additional states continue to enact or amend comprehensive laws — re-check this hub and counsel updates each quarter.

CCPA Consumer Request Clocks

Respond to verifiable consumer requests to know, delete, or correct within 45 days; one extension of an additional 45 days when reasonably necessary with notice in the first period (§1798.130). Regulations also expect acknowledgment within 10 business days.

Breach Notice vs CCPA Rights

California security breach notice to residents is under Civil Code §1798.82 (most expedient time / without unreasonable delay). That is distinct from CCPA consumer-rights clocks. See the breach deadlines matrix.

How CyberSilo Helps

CSA Privacy configures multi-state rights clocks and inventory evidence shared with GDPR/PDPL programmes.

Operate Multi-State Rights From One Desk

Map thresholds, clocks, and inventory once — reuse across state laws.

Frequently Asked Questions

What is the current CCPA revenue threshold?

Annual gross revenues in excess of $26,625,000 (CPI-adjusted effective Jan 1, 2025), or the volume/share tests — one or more of the three statutory tests.

Is there a federal privacy law?

Not a comprehensive one as of 2026. Sector laws (HIPAA, GLBA, COPPA, etc.) still apply.

Where did the 2025 URL go?

us-state-privacy-laws-2025 redirects to this evergreen /us-state-privacy-laws hub.

CCPA hub · DSAR automation · CSA Privacy

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!