US Privacy Law, Cited to the Source

A free reference to the state and federal laws that govern personal data in the United States. Every page describes what a statute, regulation or court record says and links to it, so the description can be checked against the text.

50 State Pages

Each cited to that state’s own code

24 State Laws Compared

Every enacted comprehensive statute, as of August 2026

Last-Checked Dates

Each state page shows when it was reviewed

Dated Corrections

Errors fixed on the page, with a note saying what changed

State Privacy Law

Twenty-four states have enacted a comprehensive consumer privacy law, 20 of them in effect as of August 2026. Every state has a breach notification law.

Privacy Law by State

A page for each state: its comprehensive law if it has one, its sectoral statutes, its breach notification rules and its enforcement record, with a numbered source list.

All 50 states →

The 24 Comprehensive Laws Compared

Thresholds, consumer rights, sensitive data, cure periods and penalties for every enacted state statute, from California’s CCPA (in effect since 2020) to Vermont’s, which takes effect January 1, 2028.

Read the comparison →

Breach Notification by State

Deadlines and regulator-notice rules for 48 states. Twenty-one set a fixed outer limit for notifying individuals, from 30 to 60 days; the other 27 use a reasonableness standard.

Read the guide →

Consumer Rights Under the CCPA

The seven rights California residents hold over their personal information, the 45-day response window, the nine exceptions to deletion, and opt-out preference signals.

Read the guide →

Laws Aimed at Particular Kinds of Data

Some statutes regulate one category of information wherever it is held, rather than a type of business.

Illinois BIPA

Written notice and a written release before a biometric identifier is collected, with damages of $1,000 or $5,000 per violation and the only broad private right of action among state biometric laws.

Read the guide →

Biometric Laws Outside Illinois

Texas, Washington and Colorado regulate biometric identifiers and reserve enforcement to the state, including the $1.4 billion Texas settlement with Meta announced July 30, 2024.

Read the guide →

Consumer Health Data

How Washington, Nevada and Maryland regulate health information held by companies HIPAA does not reach, including geofencing bans around health facilities.

Read the guide →

Data Broker Registries

The four state registries (California, Vermont, Texas and Oregon), how each defines a data broker, and what registration discloses.

Read the guide →

Federal Sectoral Laws

There is no general federal privacy statute. Federal law regulates particular sectors and activities, each under its own statute and regulator.

HIPAA

The Privacy, Security and Breach Notification Rules, the covered entities and business associates they bind, and the four-factor breach risk assessment.

Read the guide →

GLBA Safeguards Rule

What 16 CFR Part 314 requires of non-bank financial institutions, including the FTC notice duty for events involving 500 or more consumers, in force since May 13, 2024.

Read the guide →

FCRA Background Checks

The disclosure, authorization and adverse action steps the Fair Credit Reporting Act attaches to employment background checks.

Read the guide →

COPPA

When an online service counts as directed to children under 13, what counts as personal information, and the approved methods of verifiable parental consent.

Read the guide →

TCPA

Which calls and texts need which grade of consent, the autodialer definition after Facebook v. Duguid, and damages of $500 per violation, trebled for willful ones.

Read the guide →

FERPA

Which schools the statute binds, what counts as an education record, the school official exception edtech vendors rely on, and why there is no private right of action.

Read the guide →

Privacy Law by Industry

Six guides describe the federal and state rules that reach one sector, from the statute that defines who is covered to how it is enforced.

How These Pages Are Sourced

Every page is reported from primary documents: statute and bill text, regulations, agency releases and guidance, enforcement orders, court opinions and docket filings. Each is linked where it is used and listed again in a numbered source list at the foot of the page, labelled by type.

State pages carry the date they were last checked against the law they describe. Articles carry a publication date and, when materially revised, an updated date. Substantive errors are corrected on the page with a dated note saying what changed, rather than edited silently.

The pages describe what laws and regulators say and to whom, by the terms of the documents themselves. They do not assess whether a law covers a particular reader. Privacy Law Network does not refer readers to attorneys and receives no referral compensation. The full policy is in the editorial standards.