US state privacy laws and effective dates
Every state comprehensive consumer privacy law, plus state AI, biometric, health data and cybersecurity laws.
27 states with tracked laws. Tap one to open it.
State privacy law effective dates
When each state law took or takes effect, oldest first.
38 regulations
Add to calendar
- Connecticut Data Privacy Act (CTDPA)
Connecticut
AmendedPrivacyChildrenNext: Oct 1, 2026 PA 26-64 (SB 4) amendments take effect
- California AI Transparency Act (SB 942)
California
AmendedAINext: Jan 1, 2027 Large online platform and hosting platform duties
- California SB 53 (TFAIA)
California
In forceAINext: Jan 1, 2027 First OES anonymized incident report and CDT definition review
- CCPA / CPRA
California
AmendedPrivacyAINext: Jan 1, 2027 ADMT requirements compliance date
- Colorado AI Act
Colorado
EnactedAIPrivacyNext: Jan 1, 2027 ADMT obligations apply
- AmendedPrivacyChildren
Next: Jan 1, 2027 Amended thresholds and third-party duties take effect
- Louisiana Data Privacy Act
Louisiana
EnactedPrivacyBiometricsNext: Jan 1, 2027 Louisiana Data Privacy Act takes effect
- New Hampshire Privacy Act
New Hampshire
AmendedPrivacyChildrenNext: Jan 1, 2027 Ban on selling personal data of children under 13 (HB 1460)
- NY RAISE Act
New York
EnactedAINext: Jan 1, 2027 RAISE Act takes effect
- Oklahoma OKCDPA
Oklahoma
EnactedPrivacyNext: Jan 1, 2027 Oklahoma Consumer Data Privacy Act takes effect
- Utah UCPA
Utah
AmendedPrivacyNext: Jan 1, 2027 UCPA extends to motor vehicle manufacturers
- California Delete Act / DROP
California
In forcePrivacyData access and sharingNext: Jan 31, 2027 Annual data broker registration deadline
- AmendedPrivacyChildren
Next: Apr 1, 2027 Discretionary 60-day cure period ends
- EnactedPrivacy
Next: May 1, 2027 APDPA takes effect
- California SB 243 (companion chatbots)
California
In forceAIChildrenNext: Jul 1, 2027 First annual report to Office of Suicide Prevention
- AmendedAI
Next: Jul 1, 2027 Scheduled repeal of Title 13, Ch. 72
- Vermont VDPOSA
Vermont
EnactedPrivacyHealth dataNext: Jan 1, 2028 Vermont Data Privacy and Online Surveillance Act takes effect
- In forcePrivacy
Next: Jul 31, 2029 Postsecondary institutions must comply
- In forceAIPrivacy
Effective Jan 1, 2026
- Colorado Privacy Act (CPA)
Colorado
AmendedPrivacyChildrenEffective Jul 1, 2023
- In forcePrivacyChildren
Effective Jul 1, 2024
- In forceAI
Effective Jan 1, 2026
- Illinois BIPA
Illinois
AmendedBiometricsPrivacyEffective Oct 3, 2008
- In forcePrivacy
Effective Jan 1, 2026
- In forcePrivacy
Effective Jan 1, 2025
- In forcePrivacy
Effective Jan 1, 2026
- AmendedPrivacyChildren
Effective Oct 1, 2024
- Nebraska NDPA
Nebraska
In forcePrivacyEffective Jan 1, 2025
- New Jersey NJDPA
New Jersey
AmendedPrivacyChildrenEffective Jan 15, 2025
- NYC Local Law 144 (AEDT)
New York City, New York
In forceAIEffective Jul 5, 2023
- AmendedCybersecurityBreach notification
Effective Mar 1, 2017
- Oregon OCPA
Oregon
AmendedPrivacyChildrenEffective Jul 1, 2024
- Rhode Island RIDTPPA
Rhode Island
In forcePrivacyEffective Jan 1, 2026
- Tennessee TIPA
Tennessee
In forcePrivacyEffective Jul 1, 2025
- Texas TDPSA
Texas
In forcePrivacyEffective Jul 1, 2024
- TRAIGA
Texas
In forceAIBiometricsEffective Jan 1, 2026
- Virginia VCDPA
Virginia
AmendedPrivacyChildrenEffective Jan 1, 2023
- Washington My Health My Data Act
Washington
In forceHealth dataPrivacyEffective Mar 31, 2024
Upcoming deadlines
October 20261 deadline
PA 26-64 (SB 4) amendments take effect
Prohibits controllers and third parties from selling precise geolocation data and enacts data broker and other consumer protection provisions.
January 202714 deadlines
Large online platform and hosting platform duties
Large online platforms and GenAI hosting platforms must meet the provenance duties added by AB 853.
First OES anonymized incident report and CDT definition review
OES begins publishing annual anonymized incident summaries and the Department of Technology begins annual review of the act's definitions; the CalCompute framework report is due to the Legislature.
ADMT requirements compliance date
Businesses using ADMT for significant decisions must comply with Article 11 (pre-use notice, opt-out, access rights) by this date (11 CCR 7200(b)).
Browsers must support opt-out preference signal (AB 566)
Businesses that develop or maintain a browser must include consumer-configurable functionality to send an opt-out preference signal (Civ. Code 1798.136, operative Jan 1, 2027).
ADMT obligations apply
Developer documentation, consumer notices, post-adverse-outcome disclosure, correction and human-review rights take effect.
AG rules due
Attorney General must adopt rules clarifying the post-adverse-outcome disclosure requirements.
Data broker registration required
Data brokers may not sell or license brokered personal data in Connecticut unless registered with the Department of Consumer Protection ($2,500 initial fee).
Amended thresholds and third-party duties take effect
Applicability drops to 10,000 consumers (or 5,000 + 20% revenue from sale) and new third-party duties (12D-107A) apply.
- Louisiana Data Privacy ActLouisiana
Louisiana Data Privacy Act takes effect
Consumer rights and controller duties apply (Act 502, Section 2); data protection assessment requirements apply to processing from this date.
- New Hampshire Privacy ActNew Hampshire
Ban on selling personal data of children under 13 (HB 1460)
HB 1460 (2026, ch. 168) prohibits controllers from selling the personal data of a child under 13.
RAISE Act takes effect
Transparency reports, frontier AI frameworks, incident reporting and DFS disclosure filings apply.
- Oklahoma OKCDPAOklahoma
Oklahoma Consumer Data Privacy Act takes effect
All OKCDPA obligations and consumer rights apply.
UCPA extends to motor vehicle manufacturers
Motor vehicle manufacturers whose vehicles are sold or leased in Utah and that collect personal data through vehicle data systems are covered regardless of the revenue and consumer thresholds (13-61-102, as amended by Laws 2026, ch. 193).
Annual data broker registration deadline
Data brokers must renew registration with CalPrivacy by January 31 following each year they meet the definition.
April 20271 deadline
Discretionary 60-day cure period ends
The Division's discretionary notice-and-cure (at least 60 days) applies only to violations occurring on or before April 1, 2027 (Com. Law 14-4614).
May 20271 deadline
APDPA takes effect
Consumer rights and controller/processor obligations apply (HB 351 section 12).
July 20273 deadlines
First annual report to Office of Suicide Prevention
Operators begin annual reporting on crisis referrals and detection protocols.
Scheduled repeal of Title 13, Ch. 72
SB 332 extends the AI Policy Act repeal date from May 1, 2025 to July 1, 2027.
- Louisiana Data Privacy ActLouisiana
30-day cure period expires
AG's obligation to give 30-day notice and allow cure before investigating applies only from Jan 1 through July 31, 2027 (R.S. 51:1780.5(D)).
December 20271 deadline
Risk assessments for pre-existing processing due
Risk assessments must be completed and documented for high-risk processing that began before Jan 1, 2026 and continues after (11 CCR 7155(b)).
January 20283 deadlines
Capture device manufacturer duties
Capture device manufacturer provenance requirements become operative.
Independent third-party audits begin
Beginning Jan 1, 2028 and every 3 years thereafter, data brokers must undergo an independent audit of Delete Act compliance.
Vermont Data Privacy and Online Surveillance Act takes effect
All obligations under Act 145 apply (sec. 4).
April 20282 deadlines
First risk assessment submission to CPPA
Businesses must submit required risk assessment information and attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(1)); annually by April 1 thereafter.
Cybersecurity audit due: revenue over $100M
First cybersecurity audit report (covering Jan 1, 2027 - Jan 1, 2028) and certification due for businesses with 2026 annual gross revenue over $100M (11 CCR 7121(a)(1)).
October 20281 deadline
Data brokers must process state deletion mechanism requests
Registered data brokers must access the DCP accessible deletion mechanism at least every 45 days and process deletion requests.
April 20291 deadline
Cybersecurity audit due: revenue $50M-$100M
First cybersecurity audit report (covering 2028) due for businesses with 2027 annual gross revenue between $50M and $100M (11 CCR 7121(a)(2)).
June 20291 deadline
Mandatory 60-day cure period expires
The AG's duty to issue a cure notice before enforcement ends June 30, 2029 (Act 145 sec. 3).
July 20291 deadline
Postsecondary institutions must comply
Postsecondary institutions regulated by the Office of Higher Education must comply by July 31, 2029.
January 20301 deadline
Mandatory cure period ends
The AG's obligation to offer a 60-day notice-and-cure period expires.
April 20301 deadline
Cybersecurity audit due: revenue under $50M
First cybersecurity audit report (covering 2029) due for covered businesses with 2028 annual gross revenue under $50M (11 CCR 7121(a)(3)); annual by April 1 thereafter.
Past deadlines
August 20263 deadlines
Covered provider duties apply
Detection tool, manifest and latent disclosures, and license-revocation duties become operative.
Profiling impact assessments apply
Impact assessment requirements apply to profiling activities created or generated on or after Aug 1, 2026 (Conn. Gen. Stat. 42-522 as amended).
Data brokers must begin processing DROP deletion requests
Brokers must access DROP at least every 45 days, process verified deletion requests within 45 days, and treat unverified requests as opt-outs of sale/sharing.
July 20264 deadlines
Ban on selling precise geolocation data (SB 338)
Controllers may not sell consumers' precise geolocation data (1,750-ft radius), replacing the prior consent-based treatment.
Mandatory 30-day cure period expires
The Division's duty to issue a cure notice before enforcement ends on the first day of the 18th month after the effective date (N.J.S.A. 56:8-166.17(b)).
PA 25-113 (SB 1295) amendments take effect
Thresholds drop to 35,000 consumers or any sensitive-data processing or data sale; expanded sensitive data, minors' protections, and LLM-training disclosure in privacy notices.
June 20263 deadlines
A5328 sensitive data sale ban takes effect
A5328, signed June 30, 2026, prohibits selling sensitive personal data; the ban took effect on signing.
Delayed effective date (superseded)
SB 25B-004 date; superseded by SB 26-189 before it arrived, so no obligations applied.
IDHR withdraws and postpones proposed rules
IDHR withdraws the Subpart J proposal and postpones the June 10, 2026 hearing; no new date announced.
May 20262 deadlines
IDHR proposed notice rules published
IDHR publishes proposed Subpart J rules on AI notice in the Illinois Register.
SB 26-189 signed (repeal and reenact)
SB 26-189 replaces SB 24-205 with a narrower ADMT disclosure framework and moves the effective date to January 1, 2027.
April 20263 deadlines
Annual compliance notification
Annual certification or acknowledgment covering calendar year 2025 due.
MODPA applies to personal data processing
The act applies to personal data processing activities from April 1, 2026 (Section 2 of ch. 455).
Seventh Circuit: amendment applies retroactively
Clay v. Union Pacific (No. 25-2185) holds the damages amendment is remedial and applies to pending cases.
March 20261 deadline
Chapter amendment S8828 signed
Chapter amendment (ch. 96) finalizes the RAISE Act text.
February 20262 deadlines
SB 854 preliminarily enjoined (NetChoice v. Jones)
E.D. Va. preliminarily enjoined enforcement of the SB 854 social media time-limit provisions on First Amendment grounds; Virginia has appealed.
Original effective date (superseded)
Original SB 24-205 date; postponed by SB 25B-004, so no obligations applied.
January 202619 deadlines
30-day cure period expires
The requirement that the AG send a warning letter and allow 30 days to cure before suing expires Jan 31, 2026 (325M.20(a)).
Annual data broker registration deadline
Data brokers must register with CalPrivacy and pay the annual fee ($6,000 for 2026) by January 31.
Under-16 social media time limit (SB 854) takes effect
Social media platforms must use commercially reasonable age determination and cap users under 16 at 1 hour/day unless a parent consents. A preliminary injunction issued Feb 27, 2026 bars enforcement.
RIDTPPA takes effect
All provisions of R.I. Gen. Laws ch. 6-48.1 apply (P.L. 2024, ch. 430/453, effective Jan 1, 2026).
Sale ban on precise geolocation and under-16 data (HB 2008)
Selling precise geolocation (1,750-ft radius) and the personal data of consumers the controller knows or willfully disregards are under 16 is prohibited.
Universal opt-out signals must be honored
Controllers must honor opt-out preference signals such as Global Privacy Control.
Cure period sunsets
The AG's 30-day notice-and-cure requirement expires; enforcement can proceed without a cure opportunity.
- New Hampshire Privacy ActNew Hampshire
Mandatory 60-day cure period expires
The AG's obligation to issue a cure notice ended Dec 31, 2025; from Jan 1, 2026 cure opportunities are discretionary (RSA 507-H:11 II-III).
KCDPA takes effect
Consumer rights and controller/processor obligations apply (HB 15 section 12).
ICDPA takes effect
Consumer rights and controller/processor obligations apply; assessments required for processing activities created on or after this date.
AI anti-discrimination and notice duties apply
Prohibition on discriminatory AI use and the employee notice requirement take effect.
Opt-out preference signals must be honored
Controllers must allow opt-out of targeted advertising and sale via opt-out preference signals (12D-106).
New CCPA regulations take effect
ADMT, risk assessment, cybersecurity audit and updated CCPA regulations become effective; risk assessments required for new high-risk processing.
Frontier developer obligations apply
Frontier AI frameworks, transparency reports, critical safety incident reporting (15 days, or 24 hours for imminent risk of death or serious injury) and whistleblower protections apply.
Chatbot safeguards apply
AI disclosure, suicide and self-harm protocols, and minor protections apply.
DROP opens to consumers
Consumers can submit a single deletion request to all registered data brokers through DROP.
Original operative date (superseded)
Original SB 942 date; delayed to August 2, 2026 by AB 853.
Training-data documentation due
Documentation must be posted for GenAI systems released since January 1, 2022, and before each later release or substantial modification.
December 20252 deadlines
Mandatory 60-day cure period expires
Mandatory notice-and-cure ends Dec 31, 2025; from Jan 1, 2026 DOJ decides whether to offer a cure using statutory factors.
RAISE Act signed
Governor Hochul signs the RAISE Act with an agreed chapter amendment.
November 20251 deadline
Universal MFA and asset inventory
500.12 multi-factor authentication for all users and 500.13(a) asset inventory requirements apply.