US State Privacy Laws Explained
California's CCPA/CPRA and the wider patchwork of US state privacy laws, who they apply to, the rights they grant, and how to comply across states.
The United States has no single federal privacy law, so privacy compliance here means keeping up with a growing patchwork of state laws. California's CCPA/CPRA is the most mature and most litigated, and it is the flagship, but as of 2026, 24 states have enacted comprehensive privacy laws, with about 20 now in effect and more phasing in.
Because this area changes constantly, treat the specifics here as current guidance to verify, not settled facts.
Want every state at a glance? The US State Privacy Law Tracker lists all 24 laws with their effective dates, opt-out rules, sensitive-data requirements, and which ones require honoring the Global Privacy Control.
US State Privacy Guides
- 1What Is CCPA/CPRA? California's Privacy Law ExplainedGuideThe California Consumer Privacy Act, the CPRA amendments that expanded it, and the rights and obligations they create.8 min read
- 2US State Privacy Laws: The 2026 LandscapeGuideHow many US states have comprehensive privacy laws, what they have in common, where they differ, and how to comply across a moving patchwork.8 min read
- 3CCPA/CPRA's ADMT and Risk-Assessment Rules: What to Do NowGuideCalifornia's finalized rules on automated decision-making technology and risk assessments, what is in effect today, and what phases in during 2027.8 min read
- 4Do Not Sell or Share: How Opt-Out Rights WorkGuideWhat "sell" and "share" actually mean under CCPA/CPRA, and how a compliant opt-out has to behave.6 min read
- 5Global Privacy Control (GPC): What It Is and How to Honor ItGuideThe browser-level opt-out signal a growing number of US states require businesses to detect and respect automatically.6 min read