Skip to main content
GuidesBy Rutvi VaderaAugust 28, 20269 min read

Which State Privacy Laws Apply to Your Company in 2026?

Which State Privacy Laws Apply to Your Company in 2026?

The direct answer: a state privacy law applies to your company when you process personal data of that state's residents above the law's numeric threshold. Physical presence is irrelevant. As of August 2026 there are 20 comprehensive state privacy laws in effect, including three that arrived on January 1, 2026: Indiana, Kentucky, and Rhode Island. Nearly all of them impose the same two security obligations: a duty to establish, implement, and maintain reasonable administrative, technical, and physical data security practices, and documented data protection assessments for higher-risk processing. So the applicability question is arithmetic, and the compliance question is whether your security program can survive being benchmarked against a recognized controls framework.

Status verified August 27, 2026. This page is updated when the regulatory status changes.

Why applicability is arithmetic, not geography

Every comprehensive state privacy law reaches companies by counting consumers, not by checking incorporation records. A Texas SaaS company with 40,000 Rhode Island users is covered by Rhode Island law. A Chicago manufacturer running a direct-to-consumer channel that touches 100,000 Indiana residents is covered by Indiana law. The test is where your data subjects live, and the counting happens per state, per statute, against each statute's own numbers.

Most of the 20 laws in effect follow the Virginia model: coverage begins at roughly 100,000 consumers in a calendar year, or a lower count combined with a revenue test tied to selling personal data. That model kept most mid-market companies out of scope in any single state. The January 2026 class changed the math in one important way, covered below: Rhode Island set its floor at 35,000 consumers.

The January 2026 class: Indiana, Kentucky, Rhode Island

Three laws took effect on January 1, 2026, bringing the national total to 20, per the effective-date tracking maintained by MultiState and analysis from Koley Jessen. All three follow the Virginia model, and all three carry the reasonable-security duty and the data protection assessment requirement.

Law Effective Applies if you process data of Enforcement posture
Indiana (ICDPA)Jan 1, 2026100,000 consumers, or 25,000 plus 50% of revenue from data salesUp to $7,500 per violation, 30-day cure period
Kentucky (KCDPA)Jan 1, 2026Thresholds track Indiana's Virginia-model numbersPermanent cure period
Rhode Island (RIDTPPA)Jan 1, 202635,000 consumers, or 10,000 plus 20% of revenue from data salesNotably low thresholds pull in far smaller companies

Rhode Island is the row to reread. At 35,000 consumers, or 10,000 with a fifth of revenue from data sales, RIDTPPA covers companies an order of magnitude smaller than the ones Virginia-model laws were written for. If you have any consumer-facing volume in New England and you have never run a state privacy applicability analysis, this statute is the reason to run one now.

What the laws actually require of your security program

Two obligations matter most for security leaders, and they are the same across Indiana, Kentucky, Rhode Island, and the rest of the Virginia-model family.

1. Reasonable security. The statutory duty is to establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data at issue. The statutes do not define reasonable, and that vagueness cuts against you, not for you. When an attorney general or a court has to decide whether your practices were reasonable, the benchmark will be a recognized controls framework, not your own judgment after the fact. The defensible move is to map your program to NIST CSF or the CIS Controls, close the gaps that matter for consumer data, and keep dated evidence that the controls run. A duty this open-ended is met with artifacts, not intentions.

2. Data protection assessments. All three January 2026 laws require documented assessments before processing that presents a heightened risk of harm: targeted advertising, selling personal data, certain profiling, and sensitive data processing. These are producible records that weigh the benefits of the processing against the risks to consumers and the safeguards in place. Third-party tools are where most companies fail this quietly: the ad pixel, the analytics SDK, and the AI-powered enrichment vendor are all processing activities that may each need an assessment. Our third-party AI risk assessment checklist covers the vendor-facing half of that exercise.

Not sure which of the 20 laws reach you?

A Z Cyber advisor can walk your data footprint through a privacy assessment, map the reasonable-security duty to a controls baseline, and hand you the applicability analysis in writing.

Talk to an Advisor →

The health data overlay most companies miss

Comprehensive privacy laws are only one layer. A separate wave of consumer health data laws reaches health-adjacent data that HIPAA never covered, and it applies even to companies that are otherwise fully HIPAA compliant. Washington's My Health My Data Act has been in effect since 2024 and carries a private right of action, which turns compliance gaps into class-action exposure rather than a regulator's letter. Nevada's equivalent has also been in effect since 2024 and is enforced by the state attorney general. California's consumer health data law took effect January 1, 2026: it bans geofencing near in-person healthcare facilities and restricts collecting or selling data near family planning centers.

The trap is scope. These laws define consumer health data broadly enough to cover marketing pixels on a hospital's website, wellness app telemetry, and inferences about health status drawn from browsing behavior. HIPAA governs the ePHI in your EHR; it does not govern the ad tech on your marketing site, and MHMD-style statutes do. If you are a covered entity, your security rule obligations and this overlay run in parallel; our HIPAA Security Rule compliance checklist covers the federal half.

One pending item deserves a flag: the revised New York Health Information Privacy Act (S9269) passed the New York Senate on June 3, 2026 and the Assembly on June 4, 2026, and sits on Governor Hochul's desk as of this writing. If signed, it takes effect six months after enactment and would be the most expansive non-HIPAA health data statute in the country. The January 2025 version was vetoed in December 2025, so signature is not guaranteed. Track the bill at the New York Senate.

What takes effect in 2027 and 2028

State Effective date Notes
Oklahoma (OCDPA)Jan 1, 2027Comprehensive Virginia-model law
LouisianaJan 1, 2027 (reverify)Date has thinner sourcing than the others; confirm before planning against it
Alabama (PDPA)May 1, 2027Penalties up to $15,000 per violation
VermontJan 1, 2028Comprehensive law

Colorado's amended AI law also takes effect January 1, 2027, and it interacts with privacy obligations for any company doing consequential automated decision-making. That is a separate compliance track with its own tracker: see our state AI laws tracker for the full picture. The mid-year survey from Venable is a useful checkpoint on the comprehensive-law wave as a whole.

How to run the applicability analysis this quarter

The exercise is smaller than it looks, and it produces a durable artifact. First, count consumers by state: unique residents whose personal data you process per calendar year, from your CRM, product analytics, and marketing lists. Second, compare each state's count against that state's thresholds, watching the revenue-from-data-sales prong if you share data with ad platforms, because sale is defined broadly in most statutes. Third, for each state where you are covered, inventory the higher-risk processing that triggers data protection assessments and write the assessments you owe. Fourth, benchmark your security program against NIST CSF or CIS and document the mapping, because that single artifact serves every state's reasonable-security duty at once. One controls baseline, twenty statutes.

What to watch next

Three dates and one signature. Watch Governor Hochul's decision on the New York Health Information Privacy Act, which starts a six-month compliance clock the day it is signed. Watch January 1, 2027, when Oklahoma arrives, Louisiana is expected (reverify that date), and Colorado's AI act amendments take effect. Watch May 1, 2027 for Alabama and its 15,000 dollar per violation ceiling, and January 1, 2028 for Vermont. This page is updated as statuses change. If you want the applicability analysis done with an advisor rather than a spreadsheet, talk to a Z Cyber advisor and start with the consumer counts; coverage is usually obvious within the first session.

Frequently Asked Questions

How do I know which state privacy laws apply to my company?

Apply the threshold test state by state. Comprehensive state privacy laws reach any company that processes personal data of that state's residents above a numeric threshold, regardless of where the company is located. Most Virginia-model states use 100,000 consumers, or a lower count combined with a revenue-from-data-sales test. Rhode Island is the outlier: 35,000 consumers, or 10,000 consumers if more than 20 percent of revenue comes from selling personal data. Count residents per state, then check each state's numbers.

Which state privacy laws took effect in 2026?

Three comprehensive state privacy laws took effect on January 1, 2026: the Indiana Consumer Data Protection Act, the Kentucky Consumer Data Protection Act, and the Rhode Island Data Transparency and Privacy Protection Act. That brought the national total to 20 comprehensive state privacy laws in effect as of August 2026. All three follow the Virginia model and impose a duty to maintain reasonable administrative, technical, and physical data security practices, plus data protection assessments for higher-risk processing.

What does reasonable data security mean under state privacy laws?

The statutes do not define it, which is why it matters. The operative duty in the Virginia-model laws is to establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the data. In practice, regulators and courts benchmark reasonableness against recognized controls frameworks. Mapping your program to NIST CSF or the CIS Controls, and keeping dated evidence of it, is the defensible way to meet a duty the statute leaves open.

Do state privacy laws require data protection assessments?

Yes, for higher-risk processing. Indiana, Kentucky, and Rhode Island, like the other Virginia-model states, require documented data protection assessments before processing that presents a heightened risk of harm, which typically covers targeted advertising, the sale of personal data, certain profiling, and sensitive data. These are written, producible records. If a state attorney general asks for the assessment behind your ad pixel or your profiling model, a policy PDF is not an answer.

Which state privacy laws take effect in 2027 and 2028?

Oklahoma's comprehensive privacy law takes effect January 1, 2027, and Louisiana's law is also slated for January 1, 2027, though that date has thinner sourcing and is worth reverifying before you plan against it. Alabama's Personal Data Protection Act follows on May 1, 2027 with penalties up to 15,000 dollars per violation. Vermont's law takes effect January 1, 2028. Companies near the thresholds should run applicability analysis in 2026, not in the month before each effective date.

Subscribe for Updates

Get cybersecurity insights delivered to your inbox.