A free reference to the state and federal laws that govern personal data in the United States. Every page describes what a statute, regulation or court record says and links to it, so the description can be checked against the text.
Each cited to that state’s own code
Every enacted comprehensive statute, as of August 2026
Each state page shows when it was reviewed
Errors fixed on the page, with a note saying what changed
Twenty-four states have enacted a comprehensive consumer privacy law, 20 of them in effect as of August 2026. Every state has a breach notification law.
A page for each state: its comprehensive law if it has one, its sectoral statutes, its breach notification rules and its enforcement record, with a numbered source list.
All 50 states →Thresholds, consumer rights, sensitive data, cure periods and penalties for every enacted state statute, from California’s CCPA (in effect since 2020) to Vermont’s, which takes effect January 1, 2028.
Read the comparison →Deadlines and regulator-notice rules for 48 states. Twenty-one set a fixed outer limit for notifying individuals, from 30 to 60 days; the other 27 use a reasonableness standard.
Read the guide →The seven rights California residents hold over their personal information, the 45-day response window, the nine exceptions to deletion, and opt-out preference signals.
Read the guide →Some statutes regulate one category of information wherever it is held, rather than a type of business.
Written notice and a written release before a biometric identifier is collected, with damages of $1,000 or $5,000 per violation and the only broad private right of action among state biometric laws.
Read the guide →Texas, Washington and Colorado regulate biometric identifiers and reserve enforcement to the state, including the $1.4 billion Texas settlement with Meta announced July 30, 2024.
Read the guide →How Washington, Nevada and Maryland regulate health information held by companies HIPAA does not reach, including geofencing bans around health facilities.
Read the guide →The four state registries (California, Vermont, Texas and Oregon), how each defines a data broker, and what registration discloses.
Read the guide →There is no general federal privacy statute. Federal law regulates particular sectors and activities, each under its own statute and regulator.
The Privacy, Security and Breach Notification Rules, the covered entities and business associates they bind, and the four-factor breach risk assessment.
Read the guide →What 16 CFR Part 314 requires of non-bank financial institutions, including the FTC notice duty for events involving 500 or more consumers, in force since May 13, 2024.
Read the guide →The disclosure, authorization and adverse action steps the Fair Credit Reporting Act attaches to employment background checks.
Read the guide →When an online service counts as directed to children under 13, what counts as personal information, and the approved methods of verifiable parental consent.
Read the guide →Which calls and texts need which grade of consent, the autodialer definition after Facebook v. Duguid, and damages of $500 per violation, trebled for willful ones.
Read the guide →Which schools the statute binds, what counts as an education record, the school official exception edtech vendors rely on, and why there is no private right of action.
Read the guide →Six guides describe the federal and state rules that reach one sector, from the statute that defines who is covered to how it is enforced.
Every page is reported from primary documents: statute and bill text, regulations, agency releases and guidance, enforcement orders, court opinions and docket filings. Each is linked where it is used and listed again in a numbered source list at the foot of the page, labelled by type.
State pages carry the date they were last checked against the law they describe. Articles carry a publication date and, when materially revised, an updated date. Substantive errors are corrected on the page with a dated note saying what changed, rather than edited silently.
The pages describe what laws and regulators say and to whom, by the terms of the documents themselves. They do not assess whether a law covers a particular reader. Privacy Law Network does not refer readers to attorneys and receives no referral compensation. The full policy is in the editorial standards.