US state comprehensive privacy laws
Now enforceable law. This one affects you today.
The United States still has no comprehensive federal privacy law. In its absence, states have built the patchwork themselves — and as of mid-2026, 20 states have comprehensive consumer privacy laws in effect. This is genuinely good news that most people don’t know they can use: if you live in one of these states, you have enforceable rights to access, correct, delete, and opt out of the sale of your personal data. This entry is the standing reference for what those rights are and where they apply.
The 20 states (in effect, 2026)
California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and Washington.
Indiana, Kentucky, and Rhode Island came into effect at the start of 2026; Connecticut, Arkansas, and Utah saw new provisions take effect mid-year. More states (Alabama, Louisiana, Oklahoma, Vermont, and others) have laws passed or pending that are not yet in effect as of July 2026.
What rights you actually get
Most of these laws follow the “Virginia model” and give you the right to:
| Right | What it means |
|---|---|
| Access | See what personal data a company holds about you. |
| Correct | Fix inaccurate data. |
| Delete | Require a company to delete your data. |
| Portability | Get a copy of your data in a usable format. |
| Opt out of sale | Tell companies not to sell your data. |
| Opt out of targeted ads | Stop the use of your data for targeted advertising. |
| Opt out of profiling | Limit automated decisions with legal or significant effects. |
Two states stand out. California has the broadest law — it uniquely covers employee and business-to-business data too, and its dedicated agency actively enforces. Maryland is the strictest on data minimization, limiting what companies can collect in the first place rather than just letting you opt out afterward.
The most useful lever: opt out of sale, at scale
You don’t have to file a request with every company one by one. In several states, the Global Privacy Control (GPC) — a browser setting — sends a legally recognized “do not sell my data” signal automatically to every site you visit. Turn it on (Brave sends it by default; Firefox has a toggle) and you exercise your opt-out rights across the web in one move. It’s the highest-leverage action in this entire entry.
For removing existing profiles from data brokers, your deletion rights are the legal backbone of the process laid out in our data-broker opt-out guide. Some states are also building one-stop deletion mechanisms that hit many brokers at once.
Timeline
- 2018–2020 — California’s CCPA/CPRA establishes the template.
- 2021–2023 — Virginia, Colorado, Connecticut, Utah, and others follow.
- Jan 1, 2026 — Indiana, Kentucky, and Rhode Island laws take effect.
- July 1, 2026 — New provisions take effect in Connecticut, Arkansas, and Utah; total reaches 20 in effect.
- Ongoing — More states passing laws; pressure builds for a federal standard.
What it means for you
Check whether your state is on the list above — and if it is, use your rights. Turn on Global Privacy Control today, and lean on your deletion and opt-out rights when you clean up data brokers. If your state isn’t listed yet, this is a concrete, winnable thing to raise with your state legislators: comprehensive privacy laws have passed in red, blue, and purple states alike.
Where to follow it: the IAPP and state-law trackers maintain up-to-date effective dates. We’ll keep this grouped entry current as new state laws cross into effect.