Data Privacy Laws in the U.S.: Four States Shaping the Future

Understand how emerging state privacy laws are reshaping your rights over personal data and what businesses must do to stay compliant.

By Sneha Tete, Integrated MA, Certified Relationship Coach
Created on

In the absence of a single, comprehensive federal privacy statute, the United States has developed a patchwork of state-level data privacy laws. These laws determine how companies collect, use, and share personal information and what rights individuals have over their data. While more than twenty states now have broad consumer privacy laws, a handful of states stand out for their influence, scope, or innovative features.

This guide explains the broader U.S. data privacy landscape and then highlights four particularly important states that are shaping how privacy will work for years to come.

Why State Data Privacy Laws Matter

State privacy laws affect nearly every digital interaction, from shopping online and using mobile apps to streaming entertainment and interacting with social media platforms. These laws generally:

  • Define what counts as personal data
  • Grant individuals specific rights regarding their data
  • Impose obligations on businesses that collect or process data
  • Provide enforcement mechanisms for regulators and, in some cases, individuals

Because businesses often operate across multiple states, they must navigate overlapping, and sometimes differing, requirements. This can be complex but also gives consumers new leverage over how their information is handled.

The U.S. Privacy Landscape at a Glance

The U.S. has numerous sector-specific federal privacy laws, but no general law that applies to all personal data. Instead, federal law focuses on specific areas such as:

  • Children’s online data (for example, rules restricting the collection and use of data about children under 13)
  • Financial records and consumer reporting
  • Health information and educational records

To fill the gaps, states have stepped in. As of the mid‑2020s, around twenty states—including California, Virginia, Colorado, Connecticut, Utah, and many others—have enacted comprehensive consumer data privacy laws that cut across industries.

Key Features of Comprehensive State Privacy Laws
Feature Typical Approach
Scope Applies to businesses that process personal data of state residents, with thresholds based on revenue or number of consumers.
Core Rights Access, correction, deletion, data portability, and opt-out of certain processing.
Business Duties Transparency, data security, contracts with processors, and sometimes data protection assessments.
Enforcement Primarily state attorneys general; some states allow limited private lawsuits.

Four Influential States to Watch

While many states now regulate consumer privacy, four have emerged as particularly influential due to their early adoption, unique enforcement models, or especially stringent protections. This article focuses on:

  • California – widely viewed as the national benchmark
  • Virginia – an early follower with a business‑friendly model
  • Colorado – strong rights and robust compliance duties
  • Maryland – notable for strict data minimization and sensitive data rules

1. California: The Privacy Trendsetter

California was the first U.S. state to enact a broad consumer data privacy law, and its framework remains one of the most comprehensive. Its law gives California residents significant control over their personal information, influencing legislation in other states and even in other countries.

Notable Consumer Rights in California

  • Right to know what categories and specific pieces of personal information a business collects
  • Right to access copies of personal data collected by a business
  • Right to delete certain personal information, subject to exceptions
  • Right to correct inaccurate personal information
  • Right to opt out of the sale or sharing of personal data and certain targeted advertising
  • Enhanced protections for sensitive personal information

Business Obligations Under California Law

Companies that meet certain thresholds (for example, based on annual revenue or volume of California residents’ data) must:

  • Publish detailed and clear privacy notices
  • Offer user‑friendly mechanisms to exercise rights, including opt‑out links for sale or sharing
  • Honor browser‑based or platform‑based global privacy control signals in some circumstances
  • Implement reasonable security measures to protect personal data
  • Enter into contracts with service providers that limit their use of the data

California also stands out because it allows certain private lawsuits when data breaches occur, and it has created a dedicated regulatory authority to enforce privacy rules.

2. Virginia: A Structured, Business‑Oriented Model

Virginia became one of the first states after California to pass a comprehensive data privacy law. Its law is often cited as more structured and predictable for businesses, while still providing meaningful rights for residents.

Key Rights for Virginia Residents

  • Right to access personal data that businesses hold
  • Right to correct inaccuracies in personal data
  • Right to delete certain personal data collected by businesses
  • Right to data portability to receive data in a usable format
  • Right to opt out of targeted advertising, sale of personal data, and some profiling activities

Business Duties and Risk Assessments

Covered businesses must fulfill several obligations, including:

  • Maintaining privacy notices describing processing activities
  • Limiting data use to reasonably necessary and proportionate purposes
  • Obtaining consent before processing sensitive data
  • Conducting data protection assessments for higher‑risk processing such as targeted advertising or the sale of personal data

Enforcement in Virginia is handled exclusively by the Attorney General, and the law provides an opportunity for businesses to cure certain violations before penalties are imposed. This approach aims to encourage compliance rather than simply punish non‑compliance.

3. Colorado: Strong Rights and Compliance Requirements

Colorado’s privacy law is often considered one of the more robust state frameworks, offering consumers a wide range of rights and imposing detailed obligations on businesses in areas such as data processing agreements and risk assessments.

Consumer Rights Under Colorado Law

Colorado residents generally enjoy the following rights:

  • Right to access personal data held by a controller
  • Right to correction of inaccurate data
  • Right to delete personal data
  • Right to data portability so that data can be moved to another service
  • Right to opt out of targeted advertising, sale of personal data, and certain profiling

Compliance Thresholds and Duties

Colorado’s law applies to entities that meet specific thresholds based on the number of consumers whose data they handle or the volume of data they sell. Obligations for covered businesses include:

  • Providing clear privacy notices describing the categories and purposes of data processing
  • Honoring consumer rights requests within statutory time frames
  • Entering into contracts with processors that define permitted data uses
  • Conducting data protection assessments for certain high‑risk activities, such as targeted advertising and selling personal data

Colorado’s law reflects a growing consensus among states that higher‑risk data processing should undergo formal risk assessment and documentation.

4. Maryland: A New Wave of Strict Protections

Maryland has recently enacted a comprehensive privacy law that is noteworthy for its emphasis on data minimization and strict controls on sensitive personal information. It represents a newer wave of state legislation that moves beyond simple notice and choice to substantive limits on data use.

What Makes Maryland’s Law Different?

  • Businesses are restricted from collecting or using personal data beyond what is necessary and proportionate for the service requested.
  • The law contains strong protections for sensitive categories of data and for children’s information.
  • Covered companies must implement mechanisms that respect user preferences, such as universal opt‑out signals, for certain types of processing.
  • There are heightened compliance obligations for companies that track or target Maryland residents online.

Maryland’s approach demonstrates a shift from merely informing consumers and offering opt‑outs to actually limiting how data may be collected and processed in the first place.

Common Consumer Rights Across States

Although each state’s law is unique, several core rights appear repeatedly in modern U.S. data privacy legislation.

Typical Rights You May Have

  • Access: The ability to request confirmation that a business processes your data and to obtain a copy.
  • Correction: The ability to ask businesses to correct inaccurate personal information.
  • Deletion: The right to request deletion of certain personal data held by a business, subject to exceptions (for example, legal obligations).
  • Data portability: The right to receive your data in a machine‑readable format so that you can transfer it to another service.
  • Opt‑out: The ability to opt out of the sale of your data, targeted advertising, or certain types of profiling.
  • Appeals: In some states, the right to appeal when a business denies your request.

How to Use Your Rights Effectively

To make use of these rights:

  • Review the privacy notices of the services you use to find instructions for submitting requests.
  • Be prepared to verify your identity so that businesses can protect your account from fraudulent requests.
  • Keep records of your requests and any responses you receive.
  • If a business denies your request and your state allows an appeal, follow the appeal process described in the company’s response.

What Businesses Need to Know

For organizations operating in multiple states, staying compliant with the evolving privacy landscape is an ongoing challenge. Nevertheless, there are recurring compliance themes across most comprehensive state privacy laws.

Core Compliance Responsibilities

  • Data mapping: Understand what personal data you collect, where it is stored, and with whom it is shared.
  • Role identification: Determine whether you act as a controller (deciding how data is used) or a processor (acting on another entity’s instructions).
  • Transparent notices: Provide privacy policies that clearly describe data types, purposes, sharing, and consumer rights.
  • Consumer rights workflows: Implement systems for receiving, verifying, and responding to data subject requests within statutory time frames.
  • Data protection assessments: In states that require them, conduct documented risk assessments for high‑risk processing such as targeted advertising or profiling.
  • Contracts with processors: Ensure vendors that process data on your behalf are bound by written agreements limiting data use and requiring security measures.

Strategies for Multi‑State Compliance

Instead of treating each law separately, many organizations adopt a unified baseline standard that meets or exceeds the strictest rules among the states in which they operate. This can help reduce complexity and the risk of overlooking obligations in a particular jurisdiction.

  • Use California or another strict jurisdiction as a baseline to design your privacy program.
  • Track new laws and amendments regularly using reputable legal or industry trackers.
  • Collaborate with privacy counsel to tailor your approach to your industry and risk profile.

Practical Tips for Individuals to Protect Their Data

Even with stronger laws, individuals play a key role in safeguarding their information. Consider these steps:

  • Regularly review privacy settings on major platforms and apps.
  • Exercise your rights to access and delete data where available.
  • Use browser and device tools that allow you to send global privacy signals or limit tracking.
  • Be cautious about sharing sensitive information, especially on public Wi‑Fi or untrusted websites.
  • Monitor your financial statements and credit reports for unusual activity.

Frequently Asked Questions

Do all U.S. residents have the same data privacy rights?

No. Data privacy rights vary significantly depending on the state in which you live and sometimes where a business operates. Residents of states with comprehensive privacy laws—such as California, Virginia, Colorado, and others—typically have more clearly defined rights than residents of states without such laws.

How do I know whether a business has to follow my state’s privacy law?

Most laws apply when a business conducts business in the state or offers products or services to residents there and meets certain thresholds based on revenue or the number of consumers whose data it processes. Many privacy policies specify which laws apply and how they handle requests from different states.

Can I sue a company directly for violating my privacy rights?

It depends on the state and the type of violation. Some state privacy laws are enforced exclusively by the state attorney general, while others allow limited private lawsuits, often focused on data breaches or specific kinds of misconduct. You may need to consult a lawyer or your state attorney general’s office for guidance.

Are small businesses covered by these laws?

Many state privacy laws apply only to entities that meet certain thresholds, such as processing a minimum number of consumers’ data or generating a specified amount of revenue. Some laws exempt small businesses outright, while others apply more broadly. The details differ by state, so small organizations should still evaluate their obligations carefully.

Will there eventually be a single federal privacy law?

There have been multiple proposals for a comprehensive federal privacy statute, but as of now, none has been enacted. In the meantime, the number of state privacy laws continues to grow, making the regulatory landscape increasingly complex.

References

  1. Digital Privacy Legislation by State — Security.org. 2026-02-01. https://www.security.org/resources/digital-privacy-legislation-by-state/
  2. Which States Have Consumer Data Privacy Laws? — Bloomberg Law. 2025-11-15. https://pro.bloomberglaw.com/insights/privacy/state-privacy-legislation-tracker/
  3. Cybersecurity and Data Privacy: State Laws — American University Washington College of Law Library. 2024-09-10. https://wcl.american.libguides.com/cybersecurity-and-data-privacy/state-laws
  4. U.S. Data Privacy Laws: A Guide to the 2026 Landscape — Osano. 2026-01-05. https://www.osano.com/us-data-privacy-laws
  5. US Data Privacy Guide — White & Case LLP. 2025-07-30. https://www.whitecase.com/insight-our-thinking/us-data-privacy-guide
  6. U.S. State Privacy Laws Resource Center — Morrison & Foerster LLP. 2025-06-20. https://www.mofo.com/us-state-privacy-laws/
  7. Privacy Laws of the United States — Various federal statutes summarized. Last updated 2024-03-01. https://en.wikipedia.org/wiki/Privacy_laws_of_the_United_States
Sneha Tete
Sneha TeteBeauty & Lifestyle Writer
Sneha is a relationships and lifestyle writer with a strong foundation in applied linguistics and certified training in relationship coaching. She brings over five years of writing experience to waytolegal,  crafting thoughtful, research-driven content that empowers readers to build healthier relationships, boost emotional well-being, and embrace holistic living.

Read full bio of Sneha Tete