The United States still has no comprehensive federal data privacy law, and there's no serious indication that's changing soon. In its absence, states have filled the gap one legislative session at a time — and as of this year, more than 20 states have comprehensive consumer privacy laws in effect, with Indiana, Kentucky, and Rhode Island the newest additions on January 1, 2026.

The laws aren't identical, but most follow a recognizably similar structure inherited from California's original framework: consumers get rights to access, delete, correct, and port their data, along with the right to opt out of having it sold. Where they diverge matters more in practice — thresholds for which businesses are covered vary significantly, and a handful of states, California chief among them, allow consumers to actually sue over a data breach rather than relying solely on regulator enforcement.

One technical requirement worth knowing specifically: twelve states now require businesses to honor Global Privacy Control, a browser-level signal that communicates a consumer's opt-out preference automatically, without requiring them to visit each individual website's settings page. A business that isn't actively detecting and honoring that signal is out of compliance in those states regardless of what its own cookie banner says.

For a business operating online and serving customers in multiple states — which describes nearly every business with a website — the practical reality is that “which state's privacy law applies to us” is rarely a single clean answer anymore. The states aren't slowing down either: several additional states have moved on new comprehensive frameworks even within this year, expanding the list further while Congress remains at a standstill on any unifying federal approach.

This article is general information, not legal advice. Consult a qualified attorney for guidance specific to your situation.