Twenty States Now Have Comprehensive Privacy Laws in 2026
The U.S. state privacy law patchwork grew again in 2026, with Indiana, Kentucky, and Rhode Island comprehensive privacy laws taking effect on January 1, bringing the total number of states with such laws to twenty, according to a tracker maintained by MultiState.
All three new laws largely mirror the template first set by Virginia's Consumer Data Protection Act, though Rhode Island's law has notably low applicability thresholds — covering any entity that controls or processes the data of at least 35,000 consumers, or just 10,000 consumers if more than a fifth of its revenue comes from selling personal data.
Beyond the three new states, several existing state laws were amended in 2026: Connecticut, Arkansas, and Utah changes took effect July 1, and California enacted new consumer health data protections effective January 1, alongside expanded data broker registration requirements that took effect August 1.
California also implemented new rules requiring mandatory risk assessments for high-risk data processing activities and established consumer notice and opt-out rights when automated decision-making technology is used for significant decisions, according to coverage from the IAPP, the privacy profession's main trade association.
Privacy attorneys note that while the new laws largely track existing templates, the growing number of overlapping state requirements is pushing companies toward unified, higher-common-denominator compliance programs rather than state-by-state approaches.
See our full rundown of 2026 data privacy laws and how they affect your rights to opt out of data sales.
Sources: MultiState, IAPP.