PRIVACY + SECURITY BLOG

News, Developments, and Insights

high-tech technology background with eyes on computer display

Originally posted on Substack

Starting in 2018, U.S. states began to enact broad consumer privacy laws. California was the first with the California Consumer Privacy Act (CCPA). By 2026, nearly half the states had enacted similar laws.

At first, the laws can seem like a daunting patchwork, but below, I’ll provide you with a primer that can help you understand them.

Many are structured similarly and take similar approaches. They have differences, but there are more commonalities than divergences.

Scope and Applicability

All the laws are extraterritorial—they apply to entities beyond state borders that do business in the state or collect data about state residents.

Most laws aim to exempt small businesses, and they have revenue and/or resident thresholds. Some laws explicitly exempt small businesses as defined by the U.S. Small Business Administration.

Many laws exempt non-profits and higher ed, though there are several that don’t.

All the laws exempt data covered by federal laws such as HIPAA, FERPA, GLBA, and others.

Basic Approach

Nearly all laws take the notice-and-choice approach, allowing entities significant freedom to determine how they want to collect and process data. They must provide notice about their data collection and processing.

Individuals can opt out of certain data collection, use, or transfers.

Many laws require opt in for sensitive data, and a few ban the sale of certain types of data.

Personal Data

All the laws adopt GDPR-style definitions of personal data, recognizing identified and identifiable data.

Most laws exempt publicly-available data.

Sensitive Data

All the laws provide heightened protection for sensitive data. Most laws require opt in and a privacy impact assessment to collect or process sensitive data. The laws differ on the categories of data they recognize as sensitive.

Some of the most commonly recognized categories of sensitive data include:

Other types of recognized categories include:

Individual Rights

Nearly all the laws provide for the following individual rights:

  • right to know
  • right to access
  • right to correct (except Iowa)
  • right to delete
  • right to data portability

Most laws provide for a right to opt out of certain types of data processing:

  • targeted ads
  • profiling
  • sale of data

A few states provide for automated profiling decision rights, such as a right to question the result of profiling, be informed of the reason for a decision, review data used in the decision, and have the decision reevaluated if data was incorrect.

Responsibilities for Data Processing

Most laws require the following responsibilities for data processing:

Some laws have special additional responsibilities and restrictions. A few examples include:

  • Maryland has a strict data minimization requirement, especially for sensitive data.
  • Some states have provisions that deem dark patterns to be invalid consent.
  • Some laws have additional restrictions for children’s data.

Enforcement

Most laws are enforced by state attorneys general. But California has a designated agency to enforce its law.

Most laws have fines for violations, which typically range from $5K to $10K. Some laws have large fines, including up to $50K.

Most laws lack a private right of action, except California, which has one for data security violations.

Many laws have a right to cure (30-60 days). Some sunset but others are permanent.

My Free Guide

If you found this post useful, I hope you download my free guide to U.S. state consumer privacy laws. The guide includes the information above plus a page for each state’s privacy law with key points about each law.

I put a ton of time into this to help make understanding the patchwork readily digestible. I hope you find it useful.

My Training

If you’re looking for privacy or data protection training for your organization, please check out my courses. Through TeachPrivacy, I provide workforce privacy, cybersecurity, and AI training to companies and organizations around the world.

 

* * * *

Daniel J. Solove is the Bernard Professor of Intellectual Property and Technology Law at the George Washington University Law School. He is the founder of TeachPrivacy, a company that provides workforce privacy, cybersecurity security, and AI training to companies and organizations around the world. He is the author of 10+ books and 100+ articles.

You can follow his events, writings, training, cartoons, and resources by subscribing to his free weekly newsletter.

Divider 01

Subscribe to Solove’s Free Substack

A supplement to Solove’s regular newsletter with more in-depth discussions

Subscribe to Daniel Solove's Substack

Button - Subscribe