Skip to content

United States — state level · California's law has applied since 2020, amended by the CPRA; many other states have followed

US State Privacy Laws (CCPA/CPRA as the anchor)

The United States has no single general privacy statute. A growing set of state laws — with California's CCPA as amended by the CPRA as the most developed — creates consumer rights and business duties that apply above defined thresholds.

Regulator: California Privacy Protection Agency and state attorneys generalLast reviewed August 2026

There is no comprehensive federal privacy law of general application in the United States. Instead, sector laws such as HIPAA and GLBA cover specific data, and a growing group of states have enacted general consumer privacy statutes.

California's Consumer Privacy Act, as amended by the California Privacy Rights Act, is the most developed of these and the practical anchor for multi-state compliance. It is threshold-based: a business must meet defined criteria on revenue, volume of consumer data, or revenue derived from selling or sharing personal information.

Most state laws share a common shape — notice at collection, consumer rights, opt-out of targeted advertising and sale, contractual duties for service providers and processors, and heightened treatment for sensitive data — while differing in thresholds, definitions, exemptions and whether a cure period exists.

The practical approach is to build to the strictest common denominator across the states you serve and then handle genuine divergences, rather than maintaining a separate programme per state.

Who and what it applies to

Threshold-based applicability
Unlike the GDPR, these laws generally apply only above stated thresholds — for example annual revenue, the number of consumers whose data is processed, or the share of revenue from selling or sharing personal information.
Consumer focus
Most state laws protect residents acting in a personal capacity. California is notable for also covering employee and business-contact data.
Entity and data exemptions
Many states exempt data already regulated by HIPAA, GLBA, FCRA or FERPA, and some exempt non-profits or certain entity types outright.

Core principles

  • Notice at or before collection, describing categories collected, purposes and retention.
  • Purpose and retention limits — collect and keep only what is reasonably necessary and proportionate to the disclosed purpose.
  • Consumer control over sale, sharing and targeted advertising through accessible opt-out mechanisms.
  • Heightened treatment of sensitive personal information, whether through limit-use rights or opt-in consent depending on the state.
  • Non-discrimination for exercising rights, subject to permitted financial incentive programmes.
  • Contractual flow-down to service providers, processors, contractors and third parties.

Individual rights

Know / access

Learn what personal information is collected, used, disclosed and sold or shared, and obtain a copy.

Delete

Request deletion of personal information, subject to statutory exceptions, with instructions passed to service providers.

Correct

Request correction of inaccurate personal information.

Opt out of sale or sharing

Opt out of the sale of personal information and of sharing for cross-context behavioural advertising, including through opt-out preference signals where required.

Limit sensitive data use

Restrict the use of sensitive personal information to specified permitted purposes.

Appeal

Several states require an internal appeal route when a request is refused.

Organisational obligations

Notice at collection

Provide categories, purposes, retention and rights information at or before the point of collection, plus a full privacy policy.

Opt-out mechanisms

Offer clear opt-out links or an equivalent mechanism and honour recognised browser opt-out preference signals where the state requires it.

Contracts

Put in place service provider, contractor and third-party terms that restrict purposes and require deletion and assistance.

Risk assessments

Several states require documented assessments for higher-risk processing such as targeted advertising, sale, profiling and sensitive data.

Security

Implement reasonable security appropriate to the nature of the personal information.

Breach notification

Every state has a data breach notification statute; timing, triggers and content differ by state and often by data type.

Cross-border considerations

  • US state laws do not generally restrict cross-border transfers the way the GDPR does; the constraint is contractual and purpose-based rather than geographic.
  • Disclosures to a service provider or processor under compliant terms are usually treated differently from a sale or share, so contract language directly changes obligations.
  • Organisations subject to both EU and US regimes still need EU transfer mechanisms for data leaving the EEA, regardless of US treatment.

Enforcement overview

  • California enforcement is shared between the California Privacy Protection Agency and the Attorney General; other states are typically enforced by the state attorney general.
  • Statutory penalties are generally assessed per violation, with higher amounts for violations involving minors in California.
  • California provides a limited private right of action for certain data breaches involving specified unencrypted personal information; general private rights of action are otherwise rare.
  • Some states include a cure period before enforcement, and several of those cure periods are time-limited or have expired — check the current position for each state.

Implementation checklist

  1. 1Test applicability state by state against thresholds and exemptions rather than assuming uniformity.
  2. 2Inventory ad-tech and analytics tags and determine whether their use constitutes a sale or share.
  3. 3Publish notice at collection and a compliant privacy policy, and keep the categories accurate.
  4. 4Implement opt-out links, and honour opt-out preference signals where required.
  5. 5Classify sensitive personal information and apply the correct opt-in or limit-use treatment.
  6. 6Update vendor contracts with service provider or processor language and purpose restrictions.
  7. 7Document risk assessments for targeted advertising, profiling, sale and sensitive data.
  8. 8Build a rights workflow with identity verification, authorised agents and an appeal path.

Frequently asked questions

Is there a federal US privacy law?

There is no comprehensive federal statute of general application. Sector laws cover specific data types, and general consumer privacy duties come from state law.

Does using analytics or advertising tags count as a sale?

It can. Several states define sale and share broadly enough to capture disclosures to advertising partners for value, which is why tag inventories matter more than policy wording.

Official sources

Privacy Practice Lab publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation. This page was last reviewed on August 2026.