US State Privacy Laws: The 2026 Landscape
How many US states have comprehensive privacy laws, what they have in common, where they differ, and how to comply across a moving patchwork.
8 min read
With no federal privacy law, the United States regulates privacy state by state, and the map keeps filling in. As of 2026, 24 states have enacted comprehensive consumer privacy laws, with about 20 currently in effect and several more, including Louisiana, Oklahoma, Alabama, and Vermont, phasing in through 2027 and 2028. This is a moving target: dates shift, and new states join, so treat any snapshot as something to re-verify.
What the Laws Have in Common
Despite the patchwork, most state comprehensive laws share a common core, largely inherited from California and Virginia:
- A set of consumer rights: access, deletion, correction, and portability.
- The right to opt out of the sale of personal data, targeted advertising, and certain profiling.
- Sensitive-data protections, usually requiring consent or a right to limit use.
- Obligations on businesses: transparency, data minimization, and, in most states, data protection assessments for higher-risk processing.
If you build to the stricter states, you cover most of the others by default.
Where They Differ
The differences are what make multi-state compliance work:
- Thresholds. Who is covered varies by revenue, number of residents' records processed, or share of revenue from selling data.
- Opt-out signals. Some states require you to honor a browser-level opt-out like the Global Privacy Control; others do not.
- Enforcement. Most are enforced only by the state attorney general. California is the notable exception, with a dedicated regulator and a limited private right of action for certain data breaches.
- Cure periods. Some give businesses time to fix a violation before penalties; several are phasing these out.
How to Comply Across States
Trying to run a separate program per state does not scale. The workable approach is to build one privacy program to a high baseline, geo-aware consent and opt-out, a single request workflow, and a current data map, then apply state-specific rules on top. That way a new state law becomes a configuration change, not a new project.
How Concord Fits
Concord Privacy is built for the multi-state reality: geo-targeted consent and opt-out handling, one configurable request workflow across jurisdictions, and data mapping underneath. You meet each state's rules from a single platform rather than stitching together a tool per law.