Archive-Opsec

Search

/ to open · ↑↓ to move · Enter to open

Indexes guides, archive entries, news, resources and sources. Nothing is sent to a third party.

Archive categories

Privacy Laws

US State Privacy Laws

The wave of US state comprehensive privacy statutes from 2020, and what differs between them.

Event date 3 November 2020 Status In force Review UNCHECKED

Why a single national law has not happened

There is no comprehensive federal US consumer privacy statute. Sectional rules exist for health (HIPAA), financial services (GLBA), and children (COPPA), and they predate the state wave. Everything general-purpose is state law.

The statutes, in enactment order

StateActEnactedEffective
CaliforniaCCPA, as amended by the CPRA2018, amended 20201 January 2020, amended 1 January 2023
VirginiaVirginia CDPA20201 January 2023
ColoradoColorado Privacy Act20211 July 2023
ConnecticutConnecticut Data Privacy Act20221 July 2023
UtahUtah Consumer Privacy Act202331 December 2023
OregonOregon Consumer Privacy Act20231 July 2024
Texas, Florida, othersVarious2023 onwardVaries

Where they differ

The differences are not cosmetic, and a compliance plan written for one state will often be wrong for the next:

  1. Definition of sale versus sharing. Colorado and Connecticut both use “sale” and “targeted advertising”; others use “sale or sharing” and treat cross-context behavioural advertising as sharing.
  2. Sensitive data and consent. Some states require opt-in consent for sensitive data; others require only a right to opt out. Colorado’s universal opt-out mechanism for sale of sensitive data has no direct equivalent elsewhere.
  3. Children. Age thresholds vary, and the definitions of “child” and “minor” are not consistent across the states.
  4. Private right of action. Some statutes provide one, with a cure period and limited damages; others provide no private right of action and rely entirely on regulatory enforcement.
  5. Thresholds and exemptions. Revenue or record-count thresholds differ, and the exemptions for HIPAA, GLBA, and nonprofits are not identical.
  6. Racial profiling. A small number of states added a specific prohibition on using race or ethnicity in profiling decisions, which is unusual among general privacy statutes.

What this means in practice

For a person trying to use the rights, the practical differences are: which state law covers the business you are dealing with, whether the business must respond to a request without asking you to identify yourself, and how long the response may take. All of these vary. A single “privacy request” template is not portable across states.

For an organisation, geofenced compliance is the usual approach: apply the strictest substantive standard across all covered states. The differences in drafting are what make that approach imperfect rather than impossible.

Sources

The primary records are the state code sections linked above. They are the authoritative texts; summaries of the state-law landscape change frequently and should not be relied on in place of the statutes.

Claim labels

FACT

The California Consumer Privacy Act was enacted in 2018 and amended by the California Privacy Rights Act in 2020, which took effect on 1 January 2023.

FACT

Virginia enacted the Virginia CDPA in 2020, the first state law to take effect after the CCPA amendment, on 1 January 2023.

FACT

Colorado enacted the Colorado Privacy Act in 2021, effective 1 July 2023.

FACT

Connecticut enacted the Connecticut Data Privacy Act in 2022, effective 1 July 2023.

FACT

Utah enacted the Utah Consumer Privacy Act in 2023, effective 31 December 2023.

FACT

Oregon enacted the Oregon Consumer Privacy Act in 2023, effective 1 July 2024.

FACT

Texas, Florida, and several other states have enacted statutes of varying scope. This entry tracks the legislative acts and does not attempt to summarise the current status of litigation or of every amendment.

SOURCE CLAIM

Industry bodies and civil liberties organisations have characterised the state laws variously as a patchwork and as a national floor. Both are arguments about policy, not statements of the law.

Sources

Last link check: 2026-09-27. A link check confirms reachability, not that every claim has been independently reviewed.

  1. Virginia CDPA — Code of Virginia, Title 59.1-5200 et seq. Virginia Law Library government Accessed
  2. Colorado Privacy Act — CRS Title 6, Part 1 Colorado General Assembly government Accessed
  3. Connecticut Data Privacy Act — Connecticut General Statutes Connecticut General Assembly government Accessed
  4. Utah Consumer Privacy Act — Utah Code Title 13-61 Utah State Legislature government Accessed
  5. Oregon Consumer Privacy Act — Oregon Revised Statutes Chapter 646A Oregon Legislative Assembly government The oregonlegislature.gov host did not respond to the automated link check from the machine that ran it, so this URL is unconfirmed and is recorded as unverifiable rather than broken. It is the canonical citation for the statute; confirm it in a browser. Accessed
  6. California Civil Code Title 1.81.5 California Legislative Information government Accessed