US State Privacy Laws. Comparison Matrix
A source-linked research matrix of recorded US state privacy-law entries. It shows effective dates, response fields, regulator links, scope notes and state-guide connections. This is not legal advice or a live legal census: verify the current statute and regulator guidance before relying on a deadline, penalty, right or exemption. Read the jurisdiction coverage ledger for broader research status.
Comprehensive state privacy laws
These 23 state entries are flagged as comprehensive-law records in the current research dataset. Rights, thresholds, exemptions, response windows and enforcement routes differ by state and request type.
PRA = Private Right of Action. None of the comprehensive state privacy laws grant a general PRA. Illinois BIPA (biometric only), California CCPA (breaches only), and Washington MHMDA (health data only) offer narrow PRAs outside these comprehensive laws.
Dive deeper into each law
Each explainer walks through scope, covered data, consumer rights, penalties, enforcement history, and the practical implications for removing your data from brokers. Written in plain English, cited to the statute.
States without comprehensive laws
These 27 state entries do not have a comprehensive law recorded in this snapshot. Residents may still have broker-policy, sector-law or consumer-protection routes; CCPA rights do not automatically transfer to every requester.
Key concepts
Response deadline
The time a business has to respond to a request under the applicable law. Many laws use periods around 45 days, but the exact clock, extension, request type and exemption vary.
Cure period
A grace period during which a business may remedy a violation before enforcement. California sunset its cure period in 2023; Colorado sunset January 1, 2025; Connecticut sunset December 31, 2024. Texas, Indiana, Kentucky, and Tennessee still have cure periods.
Universal opt-out mechanism
Browser-level opt-out signals like Global Privacy Control (GPC). Recognition and controller scope vary by state, regulation, signal and processing purpose; GPC does not itself erase historical broker profiles.
Private right of action
The ability to sue directly rather than relying on AG enforcement. None of the comprehensive state privacy laws grant a general PRA. Illinois BIPA (biometric), California CCPA (breaches), and Washington MHMDA (health) offer narrow PRAs.
Notable distinguishing features by law
California (CCPA/CPRA)
Has a dedicated privacy agency and public data-broker registry. California materials describe a Delete Act mechanism; verify the current portal, covered scope and processing rules.
Maryland (MODPA)
Contains distinctive sensitive-data, minimization and under-18 consent provisions. Compare the current statute for thresholds, exemptions, response rules and discretionary cure notice.
Minnesota (MCDPA)
Includes specific rights to question profiling results, review data used in a significant decision, and seek correction and reevaluation when the data is inaccurate.
New Jersey (NJDPA + Daniel's Law)
Daniel's Law provides a separate, generally 10-business-day written-notice route for certain covered private-internet disclosures; the OIP government-site process and coverage are distinct from NJDPA.
Tennessee (TIPA)
Provides a conditional affirmative defense for a written privacy program that reasonably conforms to the NIST Privacy Framework or a comparable framework.
Nebraska (NBDPA)
Uses a non-small-business and processing/sale test instead of consumer-count thresholds; the Nebraska product/service connection and statutory exclusions still apply.
Oregon (OCPA)
Nonprofit entities are within scope from July 1, 2025, subject to statutory exemptions.
Iowa (ICDPA)
Lists access, deletion of personal data provided by the consumer, portability and sale opt-out rights; it does not list correction or profiling opt-out rights and uses a 90-day response framework.
Rhode Island (RIDTPPA)
For covered for-profit entities, the chapter adds customer rights and requires certain commercial websites or ISPs that collect, store, and sell personal information to identify data categories, relevant third parties, and a contact method in specified notices.
Generate requests in under 60 seconds
Generate requests for 1009 US/global broker workflows
FAQ: US privacy laws
How many US states have comprehensive consumer privacy laws?+
This matrix currently contains 23 state entries flagged as comprehensive-law records in OfflistMe's research dataset. That count is not a live legal census: enactment, effective dates, amendments, scope and definitions must be checked against the current official statute and regulator.
What is the strictest US state privacy law?+
There is no objective single strictest law for every use case. States differ across sensitive-data rules, thresholds, universal opt-out treatment, enforcement, cure periods and exemptions; compare the current statute for the issue you need to resolve.
Which states have a private right of action for privacy violations?+
Private enforcement rights are statute- and sector-specific. This matrix does not provide an exhaustive private-right-of-action census; check the controlling statute and current court or regulator guidance before assuming that a claim is available.
Do I need to be a resident of a state to use its privacy law?+
A state privacy law generally defines its own resident and controller scope, but eligibility also depends on the business, data, request type and exemptions. Some brokers publish nationwide workflows, while others vary verification and response practices; do not assume one state law applies to every requester.
What is a "cure period" and which states still have one?+
A cure period is a statutory grace period during which a business may remedy a violation before an enforcement action. Whether one exists, its duration and its effect can change by statute, amendment, violation and date; verify the current law rather than relying on a general list.
