Privacy Regulation Database
A reference of privacy regulations tracked by the Fine Tracker. Regulations are grouped by jurisdiction type.
Supranational
Digital Markets Act
DMAJurisdiction: European Union
Effective: 5/2/2023
Authority: European Commission
Max Fine: Up to 10% of annual global turnover (20% for repeat offenders)
EU regulation targeting large online platforms designated as gatekeepers. Imposes obligations on core platform services.
Digital Services Act
DSAJurisdiction: European Union
Effective: 2/17/2024
Authority: Digital Services Coordinators + European Commission (for VLOPs)
Max Fine: Up to 6% of annual global turnover
EU regulation on digital services establishing transparency and accountability obligations for online platforms.
EU AI Act
AI ActJurisdiction: European Union
Effective: 8/1/2024
Authority: National AI supervisory authorities + European AI Office
Max Fine: Up to €35M or 7% of annual global turnover for prohibited AI
EU regulation on artificial intelligence. Risk-based framework with strict rules for high-risk AI systems and prohibitions on certain AI practices.
EU ePrivacy Directive
ePrivacyJurisdiction: European Union
Effective: 7/12/2002
Authority: National Data Protection Authorities
Max Fine: Determined by member states
EU directive on privacy in electronic communications. Governs cookies, direct marketing, and confidentiality of communications. Often enforced alongside GDPR.
General Data Protection Regulation
GDPRJurisdiction: European Union
Effective: 5/25/2018
Authority: National Data Protection Authorities (DPAs)
Max Fine: Up to €20M or 4% of annual global turnover
EU-wide data protection law governing the processing of personal data of individuals in the EU/EEA. Sets strict requirements for consent, data subject rights, breach notification, and cross-border transfers.
Key Articles
Art. 5: Principles of processing
Art. 6: Lawful basis
Art. 7: Conditions for consent
Art. 9: Special categories
Art. 15: Right of access
Art. 17: Right to erasure
Art. 20: Data portability
Art. 25: Data protection by design
Art. 32: Security of processing
Art. 33: Breach notification to authority
Art. 35: Data protection impact assessment
Art. 83: Fines and penalties
Art. 12-14: Transparency and information
Art. 44-49: International transfers
Federal
Act on the Protection of Personal Information
APPIJurisdiction: Japan
Effective: 5/30/2003
Authority: Personal Information Protection Commission (PPC)
Max Fine: Up to JPY 100M (~K) for corporations
Japan comprehensive data protection law. Amended in 2020 and 2022 with strengthened individual rights and cross-border transfer rules.
Americans with Disabilities Act, Title I medical examination and inquiry confidentiality provisions
ADA medical confidentialityJurisdiction: United States
Effective: 7/26/1992
Authority: Equal Employment Opportunity Commission; private plaintiffs after an EEOC charge
The ADA limits when employers may ask disability-related questions or require medical exams: none before a job offer, post-offer exams if required of all entering employees, and job-related, business-necessary exams for current employees. Medical information obtained must be kept in separate, confidential medical files.
Brazil General Data Protection Law
LGPDJurisdiction: Brazil
Effective: 9/18/2020
Authority: National Data Protection Authority (ANPD)
Max Fine: Up to 2% of revenue, capped at R$50M per violation
Brazil's comprehensive data protection law, modeled on GDPR.
Cable Communications Policy Act (Cable Privacy)
CCPA-CableJurisdiction: United States
Effective: 10/30/1984
Authority: FCC / Private right of action
Max Fine: Actual damages (minimum ,000) plus punitive damages
Protects cable TV subscriber privacy. Requires notice and consent before collecting or disclosing personally identifiable information about subscribers viewing habits.
Cable Communications Policy Act of 1984, Section 631 (Protection of Subscriber Privacy)
Cable Act s.631Jurisdiction: United States
Effective: 12/29/1984
Authority: Private civil actions; Federal Communications Commission
Section 631 requires cable operators to give subscribers an annual privacy notice, limits collection and disclosure of subscriber personal information without consent, gives subscribers access to their data, and requires destruction of data no longer needed.
Children's Internet Protection Act
CIPAJurisdiction: United States
Effective: 4/20/2001
Authority: Federal Communications Commission (E-rate); Institute of Museum and Library Services (LSTA funds)
CIPA conditions E-rate and certain library funding on adopting an internet safety policy with technology protection measures that block obscene images, child sexual abuse material, and content harmful to minors. School policies must also address minors' online safety and the unauthorized disclosure of minors' personal information, and schools must educate students about appropriate online behavior.
Children's Online Privacy Protection Act of 1998 and COPPA Rule
COPPAJurisdiction: United States
Effective: 4/21/2000
Authority: Federal Trade Commission; state attorneys general (parens patriae, 15 U.S.C. 6504)
Max Fine: Up to $50,120 per violation (adjusted for inflation)
COPPA requires notice to parents and verifiable parental consent before collecting personal information from children under 13 online. The FTC's COPPA Rule was substantially amended in 2025 (effective June 23, 2025, with most compliance required by April 22, 2026), adding separate consent for third-party disclosures, a written security program, a written retention policy, and biometric and government identifiers to the definition of personal information.
Key Articles
§312.2: Definitions
§312.3: Regulation of unfair/deceptive acts
§312.4: Notice requirements
§312.5: Parental consent
§312.6: Right to review
§312.7: Prohibition against conditioning
§312.8: Confidentiality and security
§312.10: Data retention and deletion
China Personal Information Protection Law
PIPLJurisdiction: China
Effective: 11/1/2021
Authority: Cyberspace Administration of China (CAC)
Max Fine: Up to RMB 50M (~M) or 5% of annual revenue
China comprehensive personal information protection law. Strict cross-border transfer restrictions. Applies extraterritorially to processing of Chinese residents data.
Communications Act Section 222 (Customer Proprietary Network Information) and CPNI Rules
CPNIJurisdiction: United States
Effective: 2/8/1996
Authority: Federal Communications Commission
Section 222 requires carriers to protect the confidentiality of customer proprietary network information, such as call details and location, and limits its use without customer approval. FCC rules require authentication before disclosing call detail records and breach reporting to the Secret Service and FBI. A broader 2024 FCC breach rule covering personally identifiable information was upheld by a Sixth Circuit panel in August 2025, but en banc rehearing was granted on July 31, 2026 and the amended 47 CFR 64.2011 is not yet in effect.
Computer Fraud and Abuse Act
CFAAJurisdiction: United States
Effective: 10/12/1984
Authority: U.S. Department of Justice (criminal); private civil actions by persons suffering damage or loss
The CFAA is an anti-hacking law, included here because section 1030(a)(2) protects the confidentiality of information on computers, including financial records, consumer reports, and information on any protected computer. It is the main federal basis for prosecuting data theft and gives victims of unauthorized access a civil remedy.
Confidentiality of Substance Use Disorder Patient Records
42 CFR Part 2Jurisdiction: United States
Effective: 12/31/1970
Authority: HHS Office for Civil Rights (civil enforcement program began Feb. 16, 2026); DOJ for criminal violations
Part 2 makes records identifying a patient as having a substance use disorder diagnosis or treatment in a federally assisted program confidential, allowing disclosure mainly with patient consent or under narrow exceptions and court orders. The 2024 final rule (effective April 16, 2024; compliance Feb. 16, 2026) aligned Part 2 with HIPAA, allowing a single consent for treatment, payment, and operations and adding breach notification and HIPAA-style penalties.
Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003
CAN-SPAMJurisdiction: United States
Effective: 1/1/2004
Authority: Federal Trade Commission (and other agencies by sector); state attorneys general; internet access service providers
Max Fine: Up to ,120 per email in violation
CAN-SPAM sets rules for commercial email rather than banning it. Senders must not use false headers or deceptive subject lines, must identify messages as ads, include a physical postal address, and offer a working opt-out honored within 10 business days. It preempts most state commercial email laws.
Cyber Incident Reporting for Critical Infrastructure Act of 2022
CIRCIAJurisdiction: United States
Authority: Cybersecurity and Infrastructure Security Agency (DHS)
CIRCIA will require covered critical infrastructure entities to report covered cyber incidents to CISA within 72 hours and ransom payments within 24 hours. The reporting duties take effect only on the dates set in CISA's final rule; as of September 2026 the final rule had not been published (CISA held further town halls in 2026 and targeted fall 2026).
Digital Personal Data Protection Act
DPDPA-IndiaJurisdiction: India
Effective: 8/11/2023
Authority: Data Protection Board of India
Max Fine: Up to INR 250 crore (~M)
India comprehensive data protection law. Enforcement beginning 2025. Applies to processing of digital personal data within India and outside India if processing is for offering goods/services to Indian data principals.
Dodd-Frank Act Section 1033 and CFPB Personal Financial Data Rights Rule
Section 1033 RuleJurisdiction: United States
Effective: 1/17/2025
Authority: Consumer Financial Protection Bureau
Section 1033 gives consumers a right to access their financial account data. The CFPB's 2024 rule would require providers to share data through interfaces and would limit third parties' collection, use, and retention of that data to what the consumer requested. Compliance dates (originally April 1, 2026 to April 1, 2030) are stayed, and the CFPB opened a reconsideration (ANPR, Aug. 22, 2025).
DOJ Data Security Program: Preventing Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons
DOJ Bulk Data RuleJurisdiction: United States
Effective: 4/8/2025
Authority: U.S. Department of Justice, National Security Division
This regulation bars U.S. persons from data brokerage and genomic-data transactions that give countries of concern or covered persons access to bulk sensitive personal data or government-related data. Other vendor, employment, and investment transactions are allowed only if CISA security requirements are met. Bulk thresholds range from 100 persons (genomic data) to 100,000 persons (covered identifiers); due diligence, audit, and reporting duties began October 6, 2025.
Driver's Privacy Protection Act of 1994
DPPAJurisdiction: United States
Effective: 9/13/1997
Authority: U.S. Department of Justice (criminal fines; civil penalties against states); private civil actions
Max Fine: ,500 per violation plus actual damages
The DPPA limits disclosure of personal information in state driver and vehicle records to listed permissible uses, such as law enforcement, insurance, and certain business verification, and requires express consent for uses like marketing. It binds private recipients and resellers, not just state agencies.
Electronic Communications Privacy Act
ECPAJurisdiction: United States
Effective: 10/21/1986
Authority: Department of Justice
Max Fine: Criminal fines and up to 5 years imprisonment
Extends government restrictions on wiretaps to include electronic data transmissions. Includes the Wiretap Act (Title I), Stored Communications Act (Title II), and Pen Register Act (Title III).
Electronic Communications Privacy Act, Title I (Wiretap Act)
Wiretap ActJurisdiction: United States
Effective: 6/19/1968
Authority: U.S. Department of Justice (criminal); private civil actions
The Wiretap Act, as expanded by ECPA in 1986, makes it a crime to intentionally intercept the contents of wire, oral, or electronic communications in transit, or to use or disclose unlawfully intercepted contents. Federal law is one-party consent: a private party may record a communication it participates in, or where one party consents, unless done for a criminal or tortious purpose. Many states require all-party consent.
Electronic Communications Privacy Act, Title II (Stored Communications Act)
SCAJurisdiction: United States
Effective: 1/19/1987
Authority: U.S. Department of Justice (criminal); private civil actions
The SCA protects email and other stored communications and records held by service providers. It bars unauthorized access to stored communications, restricts public providers from voluntarily disclosing customer content and records, and sets the legal process the government must use to compel disclosure (amended by the CLOUD Act in 2018).
Electronic Communications Privacy Act, Title III (Pen Register and Trap and Trace Devices)
Pen Register ActJurisdiction: United States
Effective: 1/19/1987
Authority: U.S. Department of Justice
The Pen Register Act bars installing or using devices that capture non-content routing and addressing information (such as numbers dialed or email headers) without a court order, subject to provider exceptions. It is primarily a limit on government surveillance but also reaches private parties.
Employee Polygraph Protection Act of 1988
EPPAJurisdiction: United States
Effective: 12/27/1988
Authority: U.S. Department of Labor, Wage and Hour Division; private plaintiffs
EPPA generally bars private employers from requiring, requesting, or using lie detector tests on employees or job applicants, or taking action based on results or refusal. A limited exception allows polygraphs during ongoing investigations of economic loss, with strict procedural protections and confidentiality of results.
Fair and Accurate Credit Transactions Act of 2003 (identity theft, disposal, truncation, affiliate marketing provisions)
FACTAJurisdiction: United States
Effective: 12/4/2003
Authority: FTC, CFPB, and federal banking agencies (by entity type)
FACTA amended the FCRA to fight identity theft. It requires card receipt truncation, fraud alerts, written identity theft prevention programs for creditors (Red Flags Rule), secure disposal of consumer report information, and an opt-out before affiliates use shared data for marketing.
Fair Credit Reporting Act
FCRAJurisdiction: United States
Effective: 4/25/1971
Authority: CFPB and FTC (plus banking agencies and state attorneys general)
Max Fine: Statutory damages up to ,000 per violation; actual damages; punitive damages
The FCRA governs the collection, accuracy, and use of consumer report information. It limits who may obtain reports and for what purposes, requires accuracy procedures and dispute handling, and gives consumers rights to their files, free credit freezes, and adverse action notices. The Homebuyers Privacy Protection Act (effective March 4, 2026) restricts mortgage 'trigger leads'; the CFPB's 2025 medical debt rule was vacated in July 2025.
Fair Debt Collection Practices Act, third-party communication limits (and Regulation F)
FDCPAJurisdiction: United States
Effective: 3/20/1978
Authority: CFPB and FTC; private plaintiffs
The FDCPA protects debtor privacy by barring collectors from discussing a debt with third parties such as employers, family members, or neighbors, except in narrow cases. Regulation F adds rules on electronic communications, including opt-out notices.
Family Educational Rights and Privacy Act
FERPAJurisdiction: United States
Effective: 11/19/1974
Authority: U.S. Department of Education (Student Privacy Policy Office)
Max Fine: Loss of federal funding
FERPA gives parents, and students once they turn 18 or enter postsecondary school, the right to inspect and seek amendment of education records and generally requires written consent before personally identifiable information from those records is disclosed. It lists exceptions such as school officials with legitimate educational interests, directory information, and health or safety emergencies.
Key Articles
§99.3: Definitions
§99.10: Right to inspect records
§99.20: Right to amend records
§99.30: Consent for disclosure
§99.31: Disclosure exceptions
§99.33: Redisclosure limitations
Federal Trade Commission Act, Section 5 (unfair or deceptive acts or practices)
FTC ActJurisdiction: United States
Effective: 9/26/1914
Authority: Federal Trade Commission
Max Fine: No statutory maximum; consent orders with monetary penalties
Section 5 bans unfair or deceptive acts or practices in commerce. The FTC uses it as the main federal privacy and data security authority: misrepresenting data practices is deception, and failing to use reasonable security or making harmful data uses can be unfair. Several later privacy statutes (COPPA, PADFA, TAKE IT DOWN) are enforced as if they were FTC rules.
Key Articles
Section 5(a): Unfair or deceptive acts prohibited
Section 5(b): FTC enforcement proceedings
FTC Health Breach Notification Rule
HBNRJurisdiction: United States
Effective: 9/24/2009
Authority: Federal Trade Commission
Max Fine: Up to $50,120 per violation per day
The HBNR requires vendors of personal health records and related entities outside HIPAA to notify individuals, the FTC, and sometimes the media after a breach of unsecured identifiable health information. The 2024 amendments (effective July 29, 2024) confirm the rule covers health apps and treat unauthorized disclosures, not just hacks, as breaches.
Key Articles
§318.1: Purpose and scope
§318.2: Definitions
§318.3: Breach notification requirement
§318.4: Timeliness
§318.5: Methods of notice
§318.6: Content of notice
Genetic Information Nondiscrimination Act of 2008
GINAJurisdiction: United States
Effective: 5/22/2009
Authority: Equal Employment Opportunity Commission (Title II); Departments of Labor, HHS, and Treasury (Title I)
GINA bars health insurers and employers from using genetic information, including family medical history, to make coverage or employment decisions. Employers generally may not request, require, or buy genetic information, and must keep any they hold confidential in separate medical files.
Gramm-Leach-Bliley Act, Title V (Privacy Rule, Safeguards Rule, and pretexting provisions)
GLBAJurisdiction: United States
Effective: 7/1/2001
Authority: CFPB, federal banking agencies, SEC, CFTC, NCUA, FTC (non-bank financial institutions), and state insurance regulators, by sector (15 U.S.C. 6805)
Max Fine: Up to ,000 per violation; criminal penalties up to ,000 and 5 years
GLBA requires financial institutions to give privacy notices, let consumers opt out of most sharing with nonaffiliated third parties, and protect customer information. The FTC's 2021 Safeguards Rule amendments require a detailed security program (qualified individual, encryption, MFA), and since May 13, 2024 require notice to the FTC of incidents involving 500 or more consumers. The SEC's 2024 Regulation S-P amendments require incident response programs and 30-day customer breach notice (compliance Dec. 3, 2025 for larger and June 3, 2026 for smaller entities).
Key Articles
§501: Protection of nonpublic personal information
§502: Obligations for financial institutions
§521: Privacy of consumer financial information
Title V: Privacy
Health Information Technology for Economic and Clinical Health Act, Subtitle D (Privacy)
HITECHJurisdiction: United States
Effective: 2/17/2009
Authority: HHS Office for Civil Rights; state attorneys general; FTC for section 13407
HITECH's privacy subtitle created the federal breach notification duty for HIPAA covered entities and business associates, made business associates directly subject to HIPAA security and penalty provisions, and raised HIPAA penalties. A 2021 amendment requires HHS to consider an entity's recognized security practices when setting fines and audit outcomes.
Health Insurance Portability and Accountability Act Administrative Simplification: Privacy, Security, and Breach Notification Rules
HIPAAJurisdiction: United States
Effective: 4/14/2003
Authority: HHS Office for Civil Rights; state attorneys general (42 U.S.C. 1320d-5(d)); DOJ for criminal violations
Max Fine: Up to $1.5M per violation category per year; criminal penalties up to $250K and 10 years
The Privacy Rule limits how covered entities and business associates use and disclose protected health information and gives individuals rights of access, amendment, and accounting. The Security Rule requires administrative, physical, and technical safeguards for electronic PHI, and the Breach Notification Rule requires notice of breaches of unsecured PHI. A 2024 reproductive health amendment was vacated nationwide in June 2025 except most Notice of Privacy Practices changes, which had a February 16, 2026 compliance date.
Key Articles
Privacy Rule: Use and disclosure of PHI
Security Rule: Administrative, physical, technical safeguards
Enforcement Rule: Compliance and penalties
Breach Notification Rule: Notification requirements for breaches
Homebuyers Privacy Protection Act
HPPAJurisdiction: United States
Effective: 3/4/2026
Authority: CFPB and FTC (through FCRA enforcement), plus FCRA private actions
This 2025 law limits 'trigger leads', which are credit reports sold to other lenders when a consumer applies for a mortgage. From March 4, 2026, an agency may pass on such a report only for a firm offer of credit or insurance to a party that has the consumer's documented consent or already originates, services, or holds an account relationship with the consumer.
Personal Data Protection Act
PDPA-SingaporeJurisdiction: Singapore
Effective: 10/15/2012
Authority: Personal Data Protection Commission (PDPC)
Max Fine: Up to SGD 1M (~K) or 10% of annual turnover
Singapore comprehensive data protection law with Do Not Call Registry.
Personal Data Protection Law
PDPLJurisdiction: Saudi Arabia
Effective: 9/14/2023
Authority: Saudi Data & AI Authority (SDAIA)
Max Fine: Up to SAR 5M (~.3M)
Saudi Arabia comprehensive data protection law, heavily influenced by GDPR.
Personal Information Protection and Electronic Documents Act
PIPEDAJurisdiction: Canada
Effective: 4/13/2000
Authority: Office of the Privacy Commissioner of Canada
Max Fine: Up to CAD ,000 per violation
Canada federal private-sector privacy law. Based on 10 fair information principles. Being replaced by Consumer Privacy Protection Act (CPPA).
Privacy Act 1988
Australian Privacy ActJurisdiction: Australia
Effective: 12/14/1988
Authority: Office of the Australian Information Commissioner (OAIC)
Max Fine: Up to AUD 50M or 30% of turnover
Australia comprehensive privacy law. 13 Australian Privacy Principles (APPs). Major reform package pending with significantly increased penalties.
Privacy Act 2020
NZ Privacy ActJurisdiction: New Zealand
Effective: 12/1/2020
Authority: Office of the Privacy Commissioner
Max Fine: Up to NZD ,000 per offense
New Zealand comprehensive privacy law replacing the 1993 Privacy Act. 13 information privacy principles.
Privacy Act of 1974
Privacy ActJurisdiction: United States
Effective: 9/27/1975
Authority: Federal courts (civil actions); OMB guidance; DOJ for criminal misdemeanors
The Privacy Act governs how federal agencies collect, maintain, use, and disclose records about individuals kept in systems of records. It requires consent for most disclosures, public notice of record systems, access and amendment rights, and accuracy and security safeguards. A 2024 amendment (Pub. L. 118-104) added a disclosure exception for the Congressional Budget Office.
Privacy Rights of Satellite Subscribers
Satellite privacy s.338(i)Jurisdiction: United States
Effective: 11/29/1999
Authority: Private civil actions; Federal Communications Commission
Added by the Satellite Home Viewer Improvement Act of 1999, this provision gives satellite TV subscribers privacy protections that mirror the Cable Act: annual notice, consent for collection and disclosure, access, and destruction of unneeded data.
Protecting Americans' Data from Foreign Adversaries Act of 2024
PADFAJurisdiction: United States
Effective: 6/23/2024
Authority: Federal Trade Commission
PADFA makes it unlawful for data brokers to sell, license, transfer, or otherwise make available personally identifiable sensitive data of U.S. individuals to a foreign adversary country (currently China, Iran, North Korea, Russia) or an entity controlled by one. It took effect 60 days after enactment on April 24, 2024.
Protection of Personal Information Act
POPIAJurisdiction: South Africa
Effective: 7/1/2020
Authority: Information Regulator
Max Fine: Up to ZAR 10M (~K) or imprisonment up to 10 years
South Africa comprehensive data protection law modeled on GDPR.
Protection of Pupil Rights Amendment
PPRAJurisdiction: United States
Effective: 8/21/1974
Authority: U.S. Department of Education (Student Privacy Policy Office)
PPRA limits surveys, analyses, and evaluations that ask students about eight protected areas, such as political beliefs, mental health, sexual behavior, and family income. It also requires local policies and parent notice on surveys, physical exams, and the collection or use of student information for marketing.
Right to Financial Privacy Act of 1978
RFPAJurisdiction: United States
Effective: 3/10/1979
Authority: Courts (private civil actions); federal agencies' own compliance
The RFPA limits federal government access to individuals' financial records held by financial institutions. Agencies generally need customer authorization, a subpoena, a search warrant, or a formal written request with notice to the customer, and institutions may not release records until the agency certifies compliance.
South Korea Personal Information Protection Act
PIPAJurisdiction: South Korea
Effective: 9/30/2011
Authority: Personal Information Protection Commission (PIPC)
Max Fine: Up to 3% of related revenue
South Korea comprehensive data protection law. One of the strictest in Asia with significant penalties.
Telemarketing and Consumer Fraud and Abuse Prevention Act and Telemarketing Sales Rule (National Do Not Call Registry)
TSRJurisdiction: United States
Effective: 8/16/1994
Authority: Federal Trade Commission; state attorneys general (15 U.S.C. 6103); private persons with over $50,000 in damages (15 U.S.C. 6104)
The TSR bars deceptive and abusive telemarketing and houses the FTC's National Do Not Call Registry. It restricts calls to registered numbers, sets calling hours, limits abandoned calls and robocalls, and requires sellers to pay for registry access.
Telephone Consumer Protection Act of 1991
TCPAJurisdiction: United States
Effective: 12/20/1992
Authority: Federal Communications Commission; state attorneys general; private plaintiffs
Max Fine: -,500 per violation
The TCPA restricts autodialed and prerecorded-voice calls and texts to cell phones without prior express consent, prerecorded calls to residential lines, and unsolicited faxes, and underpins the National Do-Not-Call Registry rules. FCC rules effective April 11, 2025 require honoring consent revocations by any reasonable means within 10 business days; the 'revoke-all' portion was delayed to January 31, 2027. The FCC's 2023 'one-to-one consent' rule was vacated by the Eleventh Circuit and removed in August 2025.
Telephone Records and Privacy Protection Act of 2006
TRPPAJurisdiction: United States
Effective: 1/12/2007
Authority: U.S. Department of Justice
This law makes 'pretexting' for phone records a federal crime. It bars obtaining confidential phone records by false statements or unauthorized account access, and selling or buying such records without the customer's authorization.
Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act (TAKE IT DOWN Act)
TAKE IT DOWN ActJurisdiction: United States
Effective: 5/19/2025
Authority: Federal Trade Commission (platform duties, including over nonprofits); U.S. Department of Justice (criminal provisions)
The TAKE IT DOWN Act criminalizes knowingly publishing nonconsensual intimate images, including AI-generated 'digital forgeries', and requires covered platforms to run a notice-and-removal process. Since May 19, 2026, platforms must remove a validly reported image within 48 hours and make reasonable efforts to remove known identical copies.
UK Data Protection Act 2018
UK DPAJurisdiction: United Kingdom
Effective: 5/25/2018
Authority: Information Commissioner's Office (ICO)
Max Fine: Up to £17.5M or 4% of annual global turnover
UK implementation of GDPR (post-Brexit: UK GDPR). Supplemented by Data Protection Act 2018.
Video Privacy Protection Act of 1988
VPPAJurisdiction: United States
Effective: 11/5/1988
Authority: Private civil actions
Max Fine: Actual damages (minimum ,500) plus punitive damages and attorney fees
The VPPA bars video tape service providers from knowingly disclosing personally identifiable information about the videos a consumer requested or obtained, with limited exceptions. The 2013 amendment allows consent to be given electronically and in advance for up to two years. It is now a frequent basis for class actions over tracking pixels on video pages.
Video Voyeurism Prevention Act of 2004
VVPAJurisdiction: United States
Effective: 12/23/2004
Authority: U.S. Department of Justice
This criminal law bars intentionally capturing images of a person's private areas without consent where the person has a reasonable expectation of privacy. It applies only within federal maritime and territorial jurisdiction; state laws cover most other places.
State & Provincial
Access to personnel files and records
Colorado personnel file accessJurisdiction: Colorado
Effective: 1/1/2017
Authority: Not specified in the portion reviewed
Colorado private-sector employees may inspect and copy their own personnel file at least once a year on request, and former employees may inspect once after separation. Employers may require supervision and charge reasonable copying costs.
Age Attestation on Computing Devices
SB 26-051Jurisdiction: Colorado
Effective: 7/1/2028
Authority: Colorado Attorney General
SB 26-051 requires device operating systems with app stores to ask for a user's birth date or age bracket at account setup and send an age signal to apps through an API, starting July 1, 2028. Apps must request the signal and are then treated as knowing the user's age range. It includes data-minimization limits: the age signal may not be shared with third parties for other purposes.
Age verification and liability for publishing material harmful to minors (2024 SB 1959)
OK Age Verification LawJurisdiction: Oklahoma
Effective: 11/1/2024
Authority: Private civil actions by minors (through parents or guardians) and adults; Oklahoma Attorney General (injunctive relief and compliance guidance)
Makes commercial pornography websites liable to minors, through their parents, unless they use reasonable age verification (a digitized state ID, a third-party verification database, or transactional data). Sites must also offer Internet and cellular subscribers a free option to block the site on their subscriptions. Verifiers may not retain identifying information once access is granted.
Age Verification for Adult Oriented Websites
IN Adult Website Age VerificationJurisdiction: Indiana
Effective: 7/1/2024
Authority: Indiana Attorney General; parents or guardians; any person (injunction); individuals whose data is retained
Enacted as SEA 17 (2024), this chapter requires adult websites to verify that visitors are 18 or older using a mobile credential, an independent third-party verification service, or transactional data. Operators and their verification vendors may not keep users' identifying information and must secure it. Verification data counts as 'personal information' under the breach law. A preliminary injunction was vacated after Free Speech Coalition v. Paxton (2025), and the law is enforceable.
Age verification for adult websites; consent to publish private images (Act 2024-97)
AL Adult Website Age VerificationJurisdiction: Alabama
Effective: 10/1/2024
Authority: Alabama Attorney General (Consumer Interest Division); private plaintiffs
Requires adult websites to use a reasonable age-verification method so that minors cannot access sexual material harmful to minors, and bars the site or its verification vendor from keeping users' identifying information after access is granted. It also requires notarized written consent from every person depicted before an adult website publishes a private image, mandated health warnings, and (from September 1, 2025) a 10% gross receipts tax on adult websites.
Age Verification for Internet Sites Containing Content Pornographic for Minors (2026 HF 864)
Iowa Age Verification LawJurisdiction: Iowa
Effective: 7/1/2026
Authority: Iowa Attorney General (with rulemaking authority)
Iowa's 2026 age verification law requires adult websites and apps with a substantial portion of content pornographic for minors to use reasonable age verification, such as digital ID, commercially reasonable transactional data, or an Attorney General-approved method. It also limits the privacy impact: verifiers may not retain, sell, or share identifying information and must secure the data.
Age verification for material harmful to minors
Utah Age Verification ActJurisdiction: Utah
Authority: Utah Division of Consumer Protection; private actions
Requires age verification for access to material harmful to minors and bars keeping the identifying information used. 2026 S.B. 73 added VPN-circumvention rules, an excise tax, and Division rulemaking on age-verification data privacy, security, and disposal.
Age Verification for Material Harmful to Minors
MT Age Verification ActJurisdiction: Montana
Effective: 1/1/2024
Authority: Private individuals only (30-14-159(6), as amended by SB 488 (2025))
Adult websites with a substantial share of material harmful to minors must use reasonable age verification (digitized ID, government ID, or transactional-data checks) before granting access. The verifier may not keep identifying information after access is granted. SB 488 (Ch. 199, L. 2025) made the law privately enforceable only, and a federal challenge (Free Speech Coalition v. Knudsen) was dismissed on August 6, 2025.
Age Verification for Online Access to Materials Harmful to Minors; Anonymous Age Verification
Florida Age Verification LawJurisdiction: Florida
Effective: 1/1/2025
Authority: Florida Department of Legal Affairs (Attorney General)
Enacted in HB 3 (2024), this law requires adult sites to verify that visitors are 18 or older, and to offer both an anonymous and a standard verification method. It also limits what third-party anonymous age verifiers can do with the identifying information they receive: no retention after verification, no other use, no sharing, and reasonable security.
Age Verification for Online Matter Harmful to Minors
KY Adult Site Age VerificationJurisdiction: Kentucky
Effective: 7/15/2024
Authority: Private civil actions only; the Commonwealth, the Attorney General, prosecutors, and state officers are barred from enforcing
Requires commercial adult websites to verify that users are at least 18 using government ID or commercially reasonable transactional-data methods, and lets injured persons or parents sue for failures. To protect user privacy, platforms and verification vendors may not keep identifying information after access is granted. Enforcement is exclusively private; state officials may not enforce it.
Age verification for websites distributing material harmful to minors (civil liability and Attorney General enforcement)
LA Adult Website Age VerificationJurisdiction: Louisiana
Effective: 1/1/2023
Authority: Private plaintiffs (R.S. 9:2800.29); Louisiana Attorney General (R.S. 51:2121)
Requires commercial pornography websites to use reasonable age verification, such as Louisiana's digitized ID (LA Wallet) or a commercial system using government ID or transactional data, before granting access. Neither the site nor its verification vendor may retain the user's identifying information after access is granted. The 2022 law created a private damages remedy; a 2023 law added Attorney General enforcement with daily civil penalties.
Age Verification for Websites with Sexual Material Harmful to Minors (H.B. 1181)
Texas HB 1181Jurisdiction: Texas
Effective: 9/1/2023
Authority: Texas Attorney General
Requires covered adult websites to verify that users are 18 or older using digital identification or a commercial age verification system, and bars retaining identifying information from verification. The U.S. Supreme Court upheld the age-verification requirement in Free Speech Coalition v. Paxton (June 27, 2025); the Fifth Circuit's 2024 affirmance of the injunction against the mandatory health warnings (129B.004) was not disturbed.
Age-Appropriate Online Design Code Act
Nebraska AADCJurisdiction: Nebraska
Effective: 1/1/2026
Authority: Nebraska Attorney General (violations are also deceptive trade practices under the Uniform Deceptive Trade Practices Act)
Enacted by LB504 (2025) and expanded by LB838 (2026), this law requires large online services to give known minors protective, high-privacy defaults and tools to limit contact, engagement-driving design features, recommendations, purchases, time spent, and geolocation sharing. It restricts data collection, profiling, targeted advertising, and overnight and school-hour notifications for minors, and requires parental tools for children under 13.
Agent Billy Clardy III Act (state wiretap law)
Clardy ActJurisdiction: Alabama
Effective: 2/1/2023
Authority: Circuit courts (intercept orders); Attorney General and district attorneys (criminal penalties); aggrieved individuals (civil suits)
Alabama's state wiretap statute lets the Attorney General seek court orders to intercept wire and electronic communications in felony drug investigations and bars anyone other than ALEA from owning interception devices. It creates a civil cause of action against any person who unlawfully intercepts, discloses, or uses a communication, with exceptions for carrier operations and for a party to the communication or one who has a party's prior consent (unless the purpose is criminal, tortious, or injurious). A 2025 amendment made the program permanent and broadened who can be sued.
Agricultural Data Privacy Act
Nebraska Agricultural Data Privacy ActJurisdiction: Nebraska
Effective: 7/18/2026
Authority: Nebraska Attorney General (exclusive; actions in Lancaster County district court)
Enacted as sections 1-11 of LB525 (2026), this law declares farmers the owners of agricultural data from their farms, land, devices, and equipment. Ag-tech companies get only a nonexclusive right to use the data to provide authorized services and may not sell it without the producer's separate express written consent. It also requires reasonable data security and, from 2027, a no-sale clause in new contracts.
AI and algorithms in health plan utilization review (SB 1120, 'Physicians Make Decisions Act')
SB 1120Jurisdiction: California
Effective: 1/1/2025
Authority: Department of Managed Health Care; Department of Insurance
Requires health plans and insurers that use AI or algorithms in utilization review to base decisions on the individual patient's clinical information rather than group data alone, to apply them fairly, and to leave medical-necessity denials to licensed clinicians.
AI Chatbot Solicitation of Children (HB 143, 2025)
NH AI Chatbot Child Safety LawJurisdiction: New Hampshire
Effective: 1/1/2026
Authority: New Hampshire Attorney General (sole right of civil action); criminal prosecution under RSA 639:3
Makes owners and operators of dedicated generative AI chat services liable when they knowingly direct communications to a child intended to encourage the child to imminently engage in sexually explicit conduct, producing sexual images, illegal drug or alcohol use, self-harm or suicide, or violence. The Attorney General enforces the civil provision after giving 90 days to cure, and the same conduct is a form of the crime of endangering the welfare of a child.
AIDS Prevention Act: Confidentiality of HIV Test Records
MT HIV ConfidentialityJurisdiction: Montana
Effective: 10/1/1989
Authority: Montana Department of Public Health and Human Services (civil); county attorneys (criminal); private plaintiffs
Montana bars disclosing the identity of a person tested for HIV or their results in an identifiable way, except as allowed under the Uniform Health Care Information Act and related law. People harmed can sue for statutory damages.
AIDS/HIV Records Confidentiality
NJ HIV Confidentiality LawJurisdiction: New Jersey
Authority: Private civil action by the aggrieved person; Commissioner of Health rules
Records identifying someone with, or suspected of having, HIV or AIDS are confidential in New Jersey no matter who holds them. They may be disclosed only with the person's prior written informed consent or under narrow exceptions for IRB-reviewed research, audits, treating personnel, required public health reporting, and other legally authorized purposes.
Alabama Data Breach Notification Act of 2018
ADBNAJurisdiction: Alabama
Effective: 6/1/2018
Authority: Alabama Attorney General (exclusive)
Requires covered entities to protect sensitive personally identifying information with reasonable security measures, investigate suspected breaches, and notify affected Alabama residents within 45 days when a breach is reasonably likely to cause substantial harm. Larger breaches also require notice to the Attorney General and the national consumer reporting agencies, and records must be disposed of securely.
Alabama Do-Not-Call law (telephone solicitation objection database)
AL Do-Not-CallJurisdiction: Alabama
Authority: Alabama Public Service Commission; private plaintiffs
Bars telephone solicitations to Alabama residential subscribers who have registered their objection on the state do-not-call list maintained by the Public Service Commission, which incorporates Alabama numbers from the national registry. Solicitors must identify themselves and may not block caller ID.
Alabama Genetic Data Privacy Act
AGDPAJurisdiction: Alabama
Effective: 10/1/2024
Authority: Alabama Attorney General (Consumer Interest Division)
Regulates direct-to-consumer genetic testing companies. They must post plain-language privacy notices and get express consent for initial collection and use, for each transfer to third parties, for secondary uses, and for genetic-data-based marketing, plus informed consent for research. Consumers can access their data, delete their accounts, and have samples destroyed.
Alabama Personal Data Protection Act
APDPAJurisdiction: Alabama
Effective: 5/1/2027
Authority: Alabama Attorney General
Alabama's comprehensive consumer privacy law gives Alabama residents rights to confirm, access, correct, delete, and port their personal data and to opt out of targeted advertising, sale, and profiling for solely automated significant decisions. Controllers must minimize data, secure it, get consent before processing sensitive data, publish a privacy notice, and may not sell or use for targeted advertising the data of known 13- to 15-year-olds without consent. It takes effect May 1, 2027 and has a lower applicability threshold (25,000 consumers) than most state privacy laws, offset by a broad small-business exemption.
Alabama Telemarketing Act
ATAJurisdiction: Alabama
Authority: Consumer Division of the Alabama Attorney General's Office; district attorneys; private plaintiffs
Requires commercial telephone sellers and their salespeople to be licensed by the Attorney General's Consumer Division before soliciting Alabama purchasers, and imposes disclosure and cancellation rules on telemarketing sales. It is mainly an anti-fraud telemarketing law; the related do-not-call rules are in chapter 8-19C.
All Party Notification for In-Person Conversation (wearable eyeglass recording devices)
LA Smart Glasses Recording LawJurisdiction: Louisiana
Effective: 8/1/2026
Authority: Private civil actions
Requires anyone using smart glasses to video and record or transcribe a direct in-person conversation to specifically notify all participants first. The law responds to covert smart-glasses filming posted to social media, and exempts public meetings, law enforcement and first responders, recordings of officials and police in public, evidence preservation, and recordings made in the recorder's own home, workplace, or vehicle. It does not change the one-party consent rule of the Electronic Surveillance Act. It became law without the Governor's signature.
Allen Toussaint Legacy Act (right of publicity and digital replicas)
LA Allen Toussaint Legacy ActJurisdiction: Louisiana
Effective: 8/1/2022
Authority: Private civil actions
Creates a heritable, transferable property right in each person's identity for commercial purposes, and makes it a violation to use someone's identity commercially in Louisiana without consent. It also bars using a realistic digital replica of a professional performer to create the impression that the performer is actually playing a fictional role. News, commentary, parody, expressive works, and other listed uses are exempt.
Altered Sexual Depictions; Brooke's Law (platform notice-and-removal)
Florida Altered Sexual Depictions Law (Brooke's Law)Jurisdiction: Florida
Effective: 10/1/2022
Authority: State attorneys (criminal); Florida Department of Legal Affairs and FDUTPA enforcers (platform duties); private plaintiffs
Florida's deepfake sexual-imagery law, created in 2022 (SB 1798). It criminalizes generating, soliciting, or maliciously promoting realistic altered sexual images of real people without consent and gives victims a civil claim. Brooke's Law (HB 1161, 2025) added a platform duty: by December 31, 2025, covered platforms had to set up a process to take down such images within 48 hours of a valid request.
An Act Banning TikTok in Montana (SB 419, 2023)
MT TikTok Ban (SB 419)Jurisdiction: Montana
Authority: Montana Department of Justice (Attorney General)
SB 419 would have barred TikTok from operating in Montana from January 1, 2024, citing user-data privacy and national-security concerns about Chinese control. A federal court preliminarily enjoined it on November 30, 2023, before it took effect. Its own section 4 voids the Act if TikTok is sold to a company not incorporated in a foreign-adversary country; the parties agreed that happened with the 2025-2026 TikTok divestiture, and the case was dismissed on February 23, 2026, with the Ninth Circuit appeal closed by mandate on September 23, 2026.
Anti-Caller ID Spoofing Act
OK Caller ID Spoofing ActJurisdiction: Oklahoma
Effective: 11/1/2007
Authority: District attorneys (misdemeanor); Attorney General under the Consumer Protection Act
Makes it a misdemeanor to knowingly insert false information into caller ID with intent to mislead, defraud, or deceive a call recipient. The Legislature cited loss of personal information to spoofing scams.
Anti-Phishing Act
OK Anti-Phishing ActJurisdiction: Oklahoma
Effective: 11/1/2006
Authority: Civil actions by adversely affected Internet access providers and web page or trademark owners; Attorney General under the Consumer Protection Act
Prohibits creating a web page or domain name that impersonates a legitimate online business and using it to induce people to provide identifying information such as SSNs, biometric data, or account numbers. Internet access providers and affected brand owners may sue.
Anti-Phishing Act of 2006
Tenn. Anti-Phishing ActJurisdiction: Tennessee
Effective: 7/1/2006
Authority: Tennessee Attorney General and Reporter or district attorneys general; internet access providers, web page owners, trademark owners, and injured individuals
Outlaws phishing: impersonating another person or business through the internet, e-mail, or wireless communications to get Tennessee residents to hand over identifying information, fraudulently obtaining such information, and mimicking or hijacking websites and e-mail traffic to defraud. It gives strong civil remedies to service providers, site and trademark owners, and victims.
App Store Accountability Act
Texas App Store Accountability ActJurisdiction: Texas
Effective: 1/1/2026
Authority: Texas Attorney General (deceptive trade practice under Bus. & Com. Code ch. 17 subch. E)
Requires app stores to verify each Texas account holder's age category, link minors' accounts to a verified parent account, and obtain parental consent for minors' downloads and purchases, and requires developers to assign age ratings and use the app store's age signals. A federal district court preliminarily enjoined it on December 23, 2025, but the Fifth Circuit stayed that injunction and the U.S. Supreme Court declined to vacate the stay in July 2026, so the law is enforceable while litigation continues.
App Store Accountability Act
Utah ASAAJurisdiction: Utah
Effective: 5/6/2027
Authority: None; private action by a harmed minor or parent only (public enforcement removed by 2026 H.B. 498)
Enacted by 2025 S.B. 142 and amended by 2026 H.B. 498, it requires app stores to verify age category, affiliate minor accounts with a parent, and obtain parental consent for downloads and purchases, with a parental consent disclosure about the app's data practices. The chapter is enacted but its duties begin May 6, 2027. Industry challenges (CCIA v. Brown, M.M. v. Brown, D. Utah) were terminated on April 21, 2026.
App Store Age Verification and Parental Consent Law (commonly called the Alabama App Store Accountability Act)
AL App Store ActJurisdiction: Alabama
Effective: 1/1/2027
Authority: Alabama Attorney General (exclusive jurisdiction under the Deceptive Trade Practices Act)
Requires app stores to request and verify the age category (under 13, 13-15, 16-17, 18+) of Alabama account holders, link minors' accounts to a parent account, and obtain verifiable parental consent before a minor downloads or buys an app or makes in-app purchases. Developers must check age category and consent status through the app store and may use that data only for age-related protections and legal compliance. Age verification data must be minimized and encrypted.
Artificial Intelligence Applications Relating to Mental Health
Utah Mental Health Chatbot ActJurisdiction: Utah
Effective: 5/7/2025
Authority: Utah Division of Consumer Protection
Enacted by 2025 H.B. 452, it requires mental health chatbots to disclose they are AI, bars selling or sharing users' health information and inputs, and limits advertising based on user input. A separate affirmative defense against unlicensed-practice claims is available to suppliers that file a written policy with the Division (58-60-118).
Artificial Intelligence Companion Models
RI AI Companion ActJurisdiction: Rhode Island
Effective: 1/1/2027
Authority: Rhode Island Attorney General
Beginning January 1, 2027, companion chatbots offered in Rhode Island must include protocols to respond to users who express suicidal ideation, self-harm or intent to harm others, including referral to crisis services, and must remind users at the start of a conversation and at least every three hours that they are not talking to a human. Operators must file annual safety-protocol reports with the Attorney General starting July 1, 2027.
Artificial intelligence companion safeguards
SB 1546 (2026)Jurisdiction: Oregon
Effective: 1/1/2027
Authority: Private enforcement by injured individuals
Regulates AI companion chatbots designed to simulate ongoing personal or romantic relationships. Operators must disclose that output is artificial where a user could be misled, run a suicide and self-harm protocol with crisis referrals, and apply extra protections for users they know or have reason to believe are minors, with annual public reporting.
Artificial Intelligence Consumer Protection (generative AI disclosures)
Utah GenAI Disclosure ActJurisdiction: Utah
Effective: 5/7/2025
Authority: Utah Division of Consumer Protection
Replaced the 2024 AI disclosure rule (former 13-2-12) with a duty to tell consumers they are dealing with generative AI when they clearly ask, and a duty for licensed professionals to disclose AI use up front in high-risk interactions. Using generative AI is no defense to a consumer-protection violation.
Artificial intelligence disclosures in political calls and electioneering communications
LA AI Political Communications DisclosureJurisdiction: Louisiana
Effective: 8/1/2026
Authority: Louisiana Supervisory Committee on Campaign Finance Disclosure / state election enforcement (not confirmed)
Two 2026 laws require disclosure when artificial intelligence is used in Louisiana political messaging. Political calls that use an AI-generated voice of a public figure must say at the start that AI created them, and electioneering communications that use AI to falsely depict a candidate's or recall target's speech or conduct must carry a clear AI disclosure in the statutory format.
Artificial intelligence mental health professional representation ban
Tenn. AI Mental Health Representation LawJurisdiction: Tennessee
Effective: 7/1/2026
Authority: Tennessee Attorney General and private plaintiffs under the Tennessee Consumer Protection Act
Bars developers and deployers of AI systems from advertising or representing to the public that the system is, or can act as, a qualified mental health professional. Violations are added to the Tennessee Consumer Protection Act's list of unfair or deceptive practices.
Artificial Intelligence Policy Act (Office of Artificial Intelligence Policy and Learning Laboratory)
Utah AI Policy ActJurisdiction: Utah
Effective: 5/1/2024
Authority: Office of Artificial Intelligence Policy
Created by 2024 S.B. 149 and restructured by 2026 H.B. 320, it sets up the Office of AI Policy, its learning laboratory, and regulatory mitigation agreements. It imposes no general private-sector notice duties. The chapter is repealed July 1, 2027.
Automated Calling Equipment Restrictions
KY Autodialer LawJurisdiction: Kentucky
Effective: 7/14/1992
Authority: Kentucky Attorney General (Consumer Protection Act remedies)
Restricts recorded-message robocalls used for polls, information gathering, or advertising. Unless an exemption applies (for example, existing customers, debt collection, school absence calls, or return calls), the called person must consent, the message must identify the caller and a staffed number, and calls must avoid random or sequential dialing, unlisted numbers, emergency facilities, and late hours.
Automated Decision-Making Technology in Consequential Decisions
Colorado ADMT Act (SB 26-189)Jurisdiction: Colorado
Effective: 1/1/2027
Authority: Colorado Attorney General (exclusive for the disclosure and consumer-rights duties; 6-1-1706)
SB 26-189, signed May 14, 2026, repeals and replaces the 2024 Colorado AI Act starting January 1, 2027. It drops the duty of care, risk-management programs, and impact assessments and instead requires developer documentation, deployer notice at the point of interaction, a plain-language explanation after an adverse outcome, and consumer rights to correct inaccurate personal data and get meaningful human review. The Attorney General must adopt rules by January 1, 2027.
Automated dialing systems with prerecorded messages
Colorado autodialer lawJurisdiction: Colorado
Effective: 7/1/1979
Authority: District attorneys (criminal prosecution)
Colorado bans prerecorded autodialed sales calls unless the caller has an existing business relationship with the person called and that person consents to hear the message.
Automated License Plate Reader Restrictions
KY ALPR LawJurisdiction: Kentucky
Effective: 7/15/2026
Authority: Prosecutors (criminal penalty); Transportation Cabinet (permit process for highway rights-of-way)
Makes it unlawful for anyone, public or private, to use automated license plate readers except for listed purposes such as parking regulation, access control to secured areas, public safety and auto theft, law enforcement, tolling, and commercial vehicle enforcement. Captured data (plate, location, time, photos, vehicle details) generally must be deleted after 90 days and may not be sold or shared except to law enforcement, under subpoena, or to insurers and lenders for specified purposes, with notice to new insurance and loan applicants starting in 2027.
Automated license plate recognition systems (private operators)
ALPR lawJurisdiction: California
Effective: 1/1/2016
Authority: Private plaintiffs
Requires operators of license plate reader systems to secure the data and adopt a public usage and privacy policy covering authorized uses, access, sharing, accuracy, and retention.
Automated-decision systems in employment (Civil Rights Council FEHA regulations)
FEHA ADS RegulationsJurisdiction: California
Effective: 10/1/2025
Authority: California Civil Rights Department
Regulations approved June 27, 2025 and effective October 1, 2025 that confirm using an automated-decision system (including AI) in hiring, promotion, or other employment decisions can violate California's anti-discrimination law if it harms people based on protected traits. They require keeping automated-decision data with other employment records for four years and treat some AI assessments as unlawful medical inquiries.
Automatic dialing and announcing devices (robocalls and robotexts); caller ID spoofing
Oregon ADAD LawJurisdiction: Oregon
Authority: Oregon Attorney General (ORS 646A.376); private enforcement of ORS 646A.374 violations under ORS 646.638
Regulates automated calls and texts that play prerecorded or synthesized messages: they must disconnect promptly, offer a one-digit opt-out, and avoid emergency and health numbers, opted-out subscribers, and (for random or sequential dialing) do-not-call listed numbers. Callers may not misrepresent their identity or purpose or spoof caller ID.
Automatic Dialing-Announcing Devices
VA ADAD lawJurisdiction: Virginia
Effective: 7/1/2009
Authority: Virginia Attorney General and local attorneys under the VCPA; consumers via VCPA private action (59.1-518.4)
Restricts robocalls: callers may use automatic dialing-announcing devices for commercial solicitations only in listed circumstances, and prerecorded-message devices must disconnect within five seconds after the called party hangs up.
Automatic Dialing-Announcing Devices (autodialer and prerecorded message restrictions)
IN Autodialer LawJurisdiction: Indiana
Authority: Indiana Attorney General; county prosecutors; private petitioners (injunction)
Indiana bars robocalls using prerecorded or synthesized voice messages unless the subscriber consented or a live operator gets consent first. Exceptions cover school messages, existing relationships, and employee scheduling. The chapter also sets calling hours, disclosure and disconnect rules, and a ban on robocalls to hospitals and emergency services.
Automatic dialing-announcing devices (robocalls)
ADAD lawJurisdiction: California
Authority: California Public Utilities Commission
Regulates prerecorded-message autodialers. Operators must follow CPUC rules, may not place ADAD calls to California phones between 9 p.m. and 9 a.m., and (under 2874) generally need a live operator to introduce the call and obtain consent before the recorded message plays.
Automatic Dialing-Announcing Devices Act
Nebraska ADAD ActJurisdiction: Nebraska
Authority: Nebraska Public Service Commission
This law regulates robocalls and junk faxes in Nebraska. Sellers must obtain a Public Service Commission permit for each autodialer used for solicitations, may not robocall emergency lines, hospital rooms, cell phones, or pagers, must identify themselves, respect calling hours, and keep an internal do-not-call list.
Automatic Dialing-Announcing Devices and Telephone Solicitation Hours
MN ADAD LawJurisdiction: Minnesota
Authority: Minnesota Attorney General; private actions for damages via 8.31 (325E.31)
Bars robocalls using prerecorded or synthesized voice messages unless the subscriber consented or a live operator first obtains consent, requires live operators to identify the caller and the call's purpose, and requires devices to disconnect within ten seconds after the subscriber hangs up. It also bans commercial telephone solicitations and robocalls before 9 a.m. or after 9 p.m. Minnesota's separate state do-not-call list statute (325E.311 to 325E.316) has expired.
Automatic License Plate Reader Privacy Act
Nebraska ALPR Privacy ActJurisdiction: Nebraska
Effective: 7/19/2018
Authority: Courts (civil damages; evidentiary exclusion); Nebraska Commission on Law Enforcement and Criminal Justice receives annual reports
This law limits government use of automatic license plate readers to listed purposes such as traffic enforcement, stolen vehicles, warrants, missing persons, parking, secured-area access, tolling, and weigh stations. It caps retention at 180 days absent evidentiary need, requires posted use and privacy policies and annual reports, and keeps captured plate data out of public records.
Automatic license plate recognition systems (law enforcement use and vendor duties)
VA ALPR lawJurisdiction: Virginia
Effective: 7/1/2025
Authority: Criminal prosecution for misuse; Department of General Services approval of systems
Limits police use of automatic license plate readers to criminal investigations with reasonable suspicion and missing or endangered person cases, requires system data to be purged after 21 days and audit trails after two years, and bars selling or sharing the data with private or out-of-state databases. Vendors must certify they will not sell or share Virginia ALPR data and must notify the agency of third-party data requests; contract terms under subsection C apply from July 1, 2026.
Ban on using school board public records for solicitation; redaction of payment data in public contract records
AL School Records Solicitation BanJurisdiction: Alabama
Effective: 4/16/2026
Authority: Alabama Attorney General
Prohibits knowingly selling, giving, or receiving lists of names and addresses from local school board public records for commercial solicitation, and lets custodians demand a written no-solicitation certification from requesters. It also requires redaction of account and similar payment information that could initiate a financial transaction from public records about public contracts.
Bolstering Online Transparency (bot disclosure) law (SB 1001)
SB 1001 Bot DisclosureJurisdiction: California
Effective: 7/1/2019
Authority: California Attorney General and local prosecutors (Unfair Competition Law)
Makes it unlawful to use an automated online account (a bot) to mislead people in California about its artificial identity to sell goods or services or influence a vote, unless the bot clearly discloses that it is a bot.
Breach of medical information notification
VA medical breach notificationJurisdiction: Virginia
Authority: No express enforcement provision; notices go to the Attorney General and the Commissioner of Health
Requires publicly funded entities that own or license computerized medical or health insurance information of Virginia residents to notify the Attorney General, the Commissioner of Health, and affected residents without unreasonable delay after a breach. HIPAA-regulated entities and those under the FTC Health Breach Notification Rule are excluded.
Breach of personal information notification
VA breach notificationJurisdiction: Virginia
Effective: 7/1/2008
Authority: Virginia Attorney General; primary state regulator for state-chartered or licensed financial institutions (18.2-186.6(I)-(J))
Requires anyone who owns or licenses computerized personal information of Virginia residents to notify the Attorney General and affected residents without unreasonable delay after a breach that causes or is reasonably believed to cause identity theft or other fraud. Personal information is name plus SSN, driver's license or state ID, financial account or card number with access code, passport number, or military ID number, when unencrypted and unredacted.
Breach of Security Involving Computerized Personal Information (data breach notification)
CT Breach NotificationJurisdiction: Connecticut
Effective: 1/1/2006
Authority: Connecticut Attorney General (Conn. Gen. Stat. 36a-701b(j))
Requires anyone holding computerized personal information of Connecticut residents to notify affected residents and the Attorney General of a breach of unencrypted data within 60 days of discovery. Where Social Security or taxpayer ID numbers are exposed, the data owner must offer at least two years of free identity theft prevention services.
California Age-Appropriate Design Code Act (AB 2273, 2022)
CAADCAJurisdiction: California
Effective: 7/1/2024
Authority: California Attorney General
Required online services likely to be used by children to assess risks to children, default to high privacy, estimate users' ages, and avoid harmful data uses, profiling, precise geolocation collection, and dark patterns. It has never been fully enforceable: NetChoice v. Bonta produced preliminary injunctions in 2023 and 2025, and on March 12, 2026 the Ninth Circuit (No. 25-2366) narrowed the injunction, leaving the impact-assessment duties, the data-use restrictions, and the dark-patterns ban enjoined while vacating the injunction as to coverage and age estimation and remanding. AB 2246 (2026) repeals and replaces this title effective January 1, 2027.
California AI Transparency Act (SB 942, as amended by AB 853)
AI Transparency ActJurisdiction: California
Effective: 8/2/2026
Authority: California Attorney General, city attorneys, and county counsel
Requires large generative AI providers to embed hidden (latent) provenance disclosures in AI-generated images, video, and audio, offer users a visible disclosure option, and provide a free public AI detection tool that does not collect users' personal information. The law became operative August 2, 2026 after AB 853 delayed it and extended provenance duties to large platforms and device makers.
California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (Proposition 24)
CCPA/CPRAJurisdiction: California
Effective: 1/1/2020
Authority: California Privacy Protection Agency (administrative enforcement; now styled CalPrivacy) and California Attorney General (civil actions)
Max Fine: Up to $7,500 per intentional violation; $2,500 per unintentional
California's comprehensive consumer privacy law. It gives California residents rights to know, delete, correct, opt out of the sale or sharing of their personal information, and limit the use of sensitive personal information, and it bars retaliation for exercising those rights. Proposition 24 (the CPRA, approved November 3, 2020) amended the law, created the California Privacy Protection Agency, and made most changes operative January 1, 2023.
Key Articles
§1798.100: Right to know
§1798.105: Right to delete
§1798.110: Right to disclosure
§1798.115: Right to opt-out of sale
§1798.120: Right to opt-out
§1798.125: Non-discrimination
§1798.130: Notice and request procedures
§1798.135: Do Not Sell link
§1798.140: Definitions
§1798.155: Administrative fines
California Consumer Privacy Act Regulations (including 2025 Cybersecurity Audit, Risk Assessment, and Automated Decisionmaking Technology rules)
CCPA RegulationsJurisdiction: California
Effective: 8/14/2020
Authority: California Privacy Protection Agency; California Attorney General
Regulations adopted first by the Attorney General (2020) and then by the California Privacy Protection Agency (2023, 2025) that spell out how businesses give notices, handle consumer requests, honor opt-out preference signals, and avoid dark patterns. The package approved by the Office of Administrative Law on September 22, 2025 (effective January 1, 2026) added mandatory cybersecurity audits, privacy risk assessments submitted to the Agency, and rights to pre-use notice, opt-out, and access for automated decisionmaking technology used for significant decisions.
California Financial Information Privacy Act
CalFIPAJurisdiction: California
Effective: 7/1/2004
Authority: California Attorney General, Department of Financial Protection and Innovation, Department of Insurance
California's stricter counterpart to the federal Gramm-Leach-Bliley Act. Financial institutions need a consumer's explicit opt-in consent before sharing nonpublic personal information with nonaffiliated third parties, and must give consumers a chance to opt out of certain affiliate and joint-marketing sharing.
California Invasion of Privacy Act
CA CIPAJurisdiction: California
Effective: 1/1/1967
Authority: District attorneys and the Attorney General (criminal); private plaintiffs (civil)
California's wiretap and eavesdropping law. It makes it a crime, and a basis for a private suit, to tap or read communications in transit without all parties' consent, to record or eavesdrop on confidential communications without all parties' consent, to use pen registers or trap-and-trace devices without a court order, and to use electronic tracking devices to follow a person. Plaintiffs have used these provisions in large numbers of suits over website tracking tools.
California Online Privacy Protection Act
CalOPPAJurisdiction: California
Effective: 7/1/2004
Authority: California Attorney General and local prosecutors (through the Unfair Competition Law)
The first U.S. state law requiring commercial websites and online services to post a privacy policy. The policy must describe what personally identifiable information is collected, who it is shared with, and, since 2014, how the site responds to browser Do Not Track signals and whether third parties track users across sites.
Caller Identification Spoofing
IN Caller ID SpoofingJurisdiction: Indiana
Effective: 7/1/2013
Authority: Indiana Attorney General
Indiana prohibits knowingly transmitting misleading or inaccurate caller ID information with intent to defraud, cause harm, or wrongfully obtain anything of value. Blocking caller ID and authorized law enforcement and intelligence activity are exempt.
Candidate Election Deepfake Disclosures
Colorado election deepfakes (HB 24-1147)Jurisdiction: Colorado
Effective: 7/1/2024
Authority: Colorado Secretary of State (Fair Campaign Practices Act complaints); candidates (civil action)
HB 24-1147 bars distributing AI deepfakes of candidates close to an election unless the communication carries a clear disclosure that the media was edited and depicts false speech or conduct. The disclosure must also be embedded in metadata where feasible.
Capture or Use of Biometric Identifier Act
CUBIJurisdiction: Texas
Effective: 4/1/2009
Authority: Texas Attorney General
Requires notice and consent before capturing biometric identifiers for a commercial purpose, limits their sale or disclosure, and requires secure storage and timely destruction. H.B. 149 (2025) clarified that a publicly available image alone does not supply consent unless the individual posted it, and added AI-related exemptions.
Child Digital Protection Act
MT Child Digital Protection ActJurisdiction: Montana
Effective: 10/1/2025
Authority: Private enforcement by the affected individual (no agency named)
Montana's 'kidfluencer' law requires parents who earn money from videos featuring their children to set aside a share of gross earnings in trust for the child and keep records. When the child turns 18, they can ask the platform that paid for the videos to permanently delete them, a statutory 'right to be forgotten'.
Child Protection Registry
Utah CPRJurisdiction: Utah
Authority: Utah Attorney General (Internet Crimes Against Children unit)
Lets parents and schools register children's email addresses and other contact points; senders of adult-product or harmful-to-minors marketing must scrub their lists against the registry.
Civil Action for Interception of Communication
Texas Civil Wiretap RemedyJurisdiction: Texas
Effective: 9/1/1985
Authority: Private civil action by a party to the communication
Gives a party to a communication a civil claim against anyone who intercepts it without any party's consent or who uses or divulges intercepted information. Consent of one party takes the acquisition outside the definition of interception.
Clean Credit and Identity Theft Prevention Act (security freezes)
DE Security Freeze LawJurisdiction: Delaware
Effective: 9/28/2006
Authority: Affected consumers (private action); identity-theft police reports taken by local police (2204)
Lets Delaware consumers freeze their credit reports so new credit cannot be opened without their PIN or password, with deadlines for credit bureaus to place, lift, and remove freezes. A 2013 amendment lets parents and guardians freeze or create a record for children under 16 and protected adults, and the chapter guarantees identity-theft victims a local police report.
Colorado Artificial Intelligence Act (Consumer Protections for Artificial Intelligence)
Colorado AI Act (SB 24-205)Jurisdiction: Colorado
Effective: 6/30/2026
Authority: Colorado Attorney General (exclusive; 6-1-1706)
Enacted in 2024 as the first comprehensive U.S. state law on algorithmic discrimination, it requires developers and deployers of high-risk AI systems to use reasonable care against algorithmic discrimination, with risk-management programs, impact assessments, consumer notices, correction and appeal rights, and disclosure when consumers interact with AI. The 2025 special session (SB 25B-004) moved its start date from February 1, 2026 to June 30, 2026. SB 26-189 repeals and reenacts Part 17 with a narrower automated decision-making framework effective January 1, 2027, so these duties are in force only for the interim. Enforcement is also on hold: in X.AI LLC v. Weiser (D. Colo. No. 1:26-cv-01515), a court order entered April 27, 2026 on the parties' stipulation bars the Attorney General from starting enforcement, including investigations, of SB 24-205 or legislation replacing it for conduct through 14 days after the court rules on xAI's forthcoming preliminary injunction motion.
Colorado Consumer Credit Reporting Act
Colorado CCRAJurisdiction: Colorado
Effective: 8/9/2017
Authority: Consumers through private actions; Colorado Attorney General (Uniform Consumer Credit Code administrator)
Colorado's credit reporting law (recodified in 2017 from earlier law) limits when consumer reports may be furnished, restricts reporting of old or sensitive items, and gives consumers free disclosure, dispute, identity-theft block, and security freeze rights, including freezes for protected minors. Since 2023 agencies may not report adverse medical debt information (HB 23-1126), a provision set to repeal July 1, 2028.
Colorado data breach notification law (Notification of security breach)
Colorado breach notificationJurisdiction: Colorado
Effective: 9/1/2006
Authority: Colorado Attorney General (6-1-716(4))
Colorado requires businesses to investigate a possible breach promptly and notify affected Colorado residents within 30 days after determining that a breach occurred, unless misuse is not reasonably likely. The Attorney General must be notified within 30 days if 500 or more residents are affected, and national consumer reporting agencies if more than 1,000. Personal information includes name plus SSN, ID numbers, medical or health insurance information, or biometric data, and online credentials.
Colorado No-Call List Act
Colorado No-Call List ActJurisdiction: Colorado
Effective: 8/8/2001
Authority: Colorado Attorney General and district attorneys; the list is administered by the Public Utilities Commission (6-1-905(1))
Colorado maintains its own do-not-call list. Telemarketers must register, scrub against the list at least quarterly, not call listed numbers, and not block caller ID.
Colorado Privacy Act
CPAJurisdiction: Colorado
Effective: 7/1/2023
Authority: Colorado Attorney General and district attorneys (exclusive; 6-1-1311(1)(a))
Max Fine: Up to $20,000 per violation
Colorado's comprehensive consumer privacy law gives residents rights to opt out of targeted advertising, sale, and significant-decision profiling, and to access, correct, delete, and port their personal data, with an appeal process. Controllers must give a privacy notice, minimize and secure data, get opt-in consent for sensitive data, honor universal opt-out signals, and run data protection assessments. Amendments added biological and neural data (2024), biometric rules (2025), minors' online protections (2025), and precise geolocation as sensitive data with consent required to sell sensitive data (2025).
Colorado Privacy Act biological and neural data amendment (Protect Privacy of Biological Data)
CPA neural data (HB 24-1058)Jurisdiction: Colorado
Effective: 8/7/2024
Authority: Colorado Attorney General and district attorneys
HB 24-1058 made Colorado the first state to add neural data to its privacy law. It defines biological data (including neural data) and treats it as sensitive data, so controllers need opt-in consent and a data protection assessment to process it.
Colorado Privacy Act biometric amendments (Privacy of Biometric Identifiers and Data)
CPA biometric (HB 24-1130)Jurisdiction: Colorado
Effective: 7/1/2025
Authority: Colorado Attorney General and district attorneys
HB 24-1130 added biometric-specific duties to the Colorado Privacy Act, reaching any controller that handles biometric identifiers regardless of size and covering employees. Controllers need a public written retention and deletion policy, advance notice, consent, and may not sell biometric identifiers. Employers may require consent only for listed purposes such as secure access, timekeeping, and safety.
Colorado Privacy Act minors' online protections (Privacy Protections for Children's Online Data)
CPA minors (SB 24-041)Jurisdiction: Colorado
Effective: 10/1/2025
Authority: Colorado Attorney General and district attorneys
SB 24-041 added a minors' duty of care to the Colorado Privacy Act for online services known to be used by anyone under 18. Without the minor's consent (or a parent's for children under 13), controllers may not use minors' data for targeted ads, sale, or significant profiling, use engagement-extending design features, or collect precise geolocation beyond what is needed. Heightened-risk services need a minors' data protection assessment.
Colorado Privacy Act Rules
CPA RulesJurisdiction: Colorado
Effective: 7/1/2023
Authority: Colorado Attorney General (Department of Law, Consumer Protection Section)
The Attorney General's rules implementing the Colorado Privacy Act. They set detailed requirements for privacy notices, rights requests, universal opt-out mechanisms, valid consent and dark patterns, data protection assessments, profiling, and opinion letters. Amendments effective January 30, 2025 added biometric and opinion-letter rules, and amendments effective December 1, 2025 implemented the minors' (SB 24-041) and precise geolocation (SB 25-276) changes.
Colorado telemarketing law (commercial telephone sellers)
Colorado telemarketing registrationJurisdiction: Colorado
Effective: 7/1/1993
Authority: Colorado Attorney General and district attorneys
Commercial telephone sellers must register annually with the Attorney General and must honor a three-business-day cancellation right with refunds. Misleading prize and 'free' claims are prohibited.
Colorado wiretapping and eavesdropping laws
Colorado wiretap/eavesdroppingJurisdiction: Colorado
Effective: 7/1/1971
Authority: District attorneys (criminal prosecution)
Colorado is a one-party consent state. Recording or intercepting a phone or electronic communication is a crime unless the sender or a receiver consents, and recording an in-person conversation by someone not visibly present requires consent of at least one principal party. Using or disclosing unlawfully obtained contents is also prohibited.
Commercial and fraudulent electronic mail laws
OK Anti-Spam LawJurisdiction: Oklahoma
Effective: 7/1/1999
Authority: Private civil actions by injured persons and email service providers; district attorneys (criminal); Attorney General under the Consumer Protection Act
Prohibits falsified routing information, misleading subject lines, and phishing-style fraudulent email, and requires unsolicited commercial email to be labeled 'ADV:' ('ADV-ADULT:' for sexually explicit content) and to offer a free opt-out that senders must honor. Violations are felonies and give recipients and email providers a damages claim.
Commercial email advertisements (anti-spam) and unsolicited text message ads
Anti-spam (17529.5, 17538.41)Jurisdiction: California
Authority: California Attorney General; email service providers; recipients
Bars commercial email advertising that uses a third party's domain without permission, falsified or forged headers, or misleading subject lines, and lets recipients, email providers, and the AG sue. A separate provision bars unsolicited text message advertisements to California mobile numbers except with consent or a business relationship. Much of the broader state spam law is preempted by the federal CAN-SPAM Act, but these deception-based rules remain.
Commercial Use of Booking Photographs Prohibited
KY Mugshot Removal-Fee BanJurisdiction: Kentucky
Effective: 7/15/2016
Authority: Persons depicted, via civil action in Circuit Court
Bars publishers and websites from using booking or inmate photographs obtained from public agencies for a commercial purpose when removal requires paying a fee. A person who asked for removal can sue for an injunction, fees, and escalating daily damages.
Common ownership communities: sensitive information as a condition of access to recreational common areas
MD COC Sensitive Information LawJurisdiction: Maryland
Effective: 10/1/2025
Authority: Not specified in the section reviewed
Enacted by 2025 Md. Laws ch. 523 (HB 755), this law bars condominiums and other common ownership communities from requiring owners, occupants, guests, or children to hand over sensitive information, such as Social Security numbers, birth certificates, citizenship or immigration status, race or national origin, religion, or medical records, to use pools, playgrounds, game rooms, or similar recreational areas. Government photo ID may still be requested.
Communicable Disease: Confidentiality Requirements
IN Communicable Disease ConfidentialityJurisdiction: Indiana
Authority: Criminal prosecution (county prosecutors)
This chapter keeps medical and epidemiological information about reportable communicable diseases, including HIV, confidential. It may be released only in de-identified statistical form, with written consent, for public health or specified legal purposes, or to a nonprofit health data service during a declared public health response.
Companion chatbots (SB 243)
SB 243Jurisdiction: California
Effective: 1/1/2026
Authority: Private plaintiffs; Office of Suicide Prevention receives reports
Requires companion chatbot operators to tell users when they might think they are talking to a human that the bot is AI, to keep and publish suicide and self-harm prevention protocols, and to report crisis referrals annually starting July 1, 2027. For users known to be minors it required AI disclosures, three-hour break reminders, and sexual-content safeguards; SB 1119 (2026) moves minors' protections into a new chapter operative July 1, 2027. SB 867 (2026) separately bans toys with companion chatbots until 2031.
Companion Chatbots: Children's Safety ('Adam's Law', SB 1119)
SB 1119Jurisdiction: California
Effective: 1/1/2027
Authority: California Attorney General and public prosecutors; children (or parents) who suffer actual harm
Signed September 10, 2026. Beginning July 1, 2027, companion chatbot operators must determine users' ages through the Digital Age Assurance Act (or treat everyone as a child), run and document child-safety risk assessments before release, set protective defaults, and undergo independent child-safety audits. It bars behavioral advertising to children, selling children's chatbot data, and using it beyond what is needed.
Compensation History Inquiry Ban
DE Salary History BanJurisdiction: Delaware
Effective: 12/14/2017
Authority: Delaware Department of Labor (709B(g))
Bars employers from asking job applicants or their former employers about pay history or screening applicants by past compensation. Employers may discuss pay expectations and may confirm history only after an offer with compensation terms has been accepted.
Comprehensive Computer Data Access and Fraud Act
CDAFA (Penal Code 502)Jurisdiction: California
Authority: Prosecutors (criminal); owners or lessees of computers or data (civil)
California's computer crime law. It makes it a crime to knowingly access and, without permission, take, copy, use, alter, or delete data or use computer services, and gives owners of the affected computers or data a civil claim for damage or loss.
Computer Crime (computer trespass, spam header forgery, cyberstalking and online impersonation)
RI Computer Crime ActJurisdiction: Rhode Island
Authority: Prosecutors; injured persons and email service providers via civil action
Rhode Island's computer crime law covers unauthorized access and copying of computer data, forging email headers to send bulk spam, cyberstalking and cyberharassment, and online impersonation using another person's name, persona or identifying information (including biometric data) to harm, defraud, intimidate or threaten. Injured people, including email service providers, can sue for damages.
Computer Crimes: Misuse of Computer System Information (private personal data)
DE Computer Data MisuseJurisdiction: Delaware
Authority: Criminal prosecution by the State; civil actions by aggrieved persons (941)
Criminalizes unauthorized display, use, disclosure, or copying of data obtained by accessing a computer system, and receiving or using such data. A civil remedy lets victims sue, and for misuse of private personal data (data about a person that a reasonable person would want kept private) actual damages can be recovered without proving financial loss.
Computer Crimes: Unrequested Commercial Email and Failure to Cease Email on Request
DE Commercial Email LawJurisdiction: Delaware
Effective: 7/2/1999
Authority: Criminal prosecution by the State; civil actions by aggrieved persons in the Court of Chancery or for damages (941)
Delaware makes it a computer crime to send unsolicited bulk commercial email without authorization, to forge email header information to send spam, or to keep sending commercial email after the recipient asks the sender to stop. All commercial email sent to Delaware addresses must explain how to unsubscribe. Note that the federal CAN-SPAM Act (15 U.S.C. § 7707(b)) preempts state commercial email rules except those targeting falsity or deception.
Computer Security Breach Notification
MT Breach NotificationJurisdiction: Montana
Effective: 10/1/2005
Authority: Montana Department of Justice, Office of Consumer Protection (Attorney General)
Montana requires businesses to notify Montana residents without unreasonable delay when unencrypted personal information is reasonably believed to have been acquired in a breach that causes or is reasonably believed to cause loss or injury. Copies of resident notices must be sent at the same time to the Attorney General's Office of Consumer Protection.
Computer Security Breaches (data security and breach notification)
DE Breach LawJurisdiction: Delaware
Effective: 6/28/2005
Authority: Delaware Attorney General (Director of Consumer Protection, Department of Justice) (12B-104(a))
Requires businesses holding Delaware residents' personal information to keep reasonable security procedures and to notify affected residents of a breach within 60 days of determining it occurred, unless an investigation shows harm is unlikely. Breaches affecting more than 500 residents must also be reported to the Attorney General, and breaches of Social Security numbers require a free year of credit monitoring. HB 381 (signed and effective Sept. 2, 2026) adds the Attorney General to substitute notice, requires Attorney General notice within 60 days where residents' involvement is identified late, and limits the HIPAA/GLBA safe harbor to the timing rule.
Computer Spyware
NH Spyware LawJurisdiction: New Hampshire
Effective: 7/14/2005
Authority: State prosecutors (Department of Justice)
Prohibits businesses from knowingly installing software on a consumer's computer and using it deceptively to hijack the computer, change browser or security settings, collect personal information through keystroke logging or similar means, block removal, or disable security software.
Computer Spyware, Malware, and Ransomware Protection
Iowa Spyware LawJurisdiction: Iowa
Authority: County attorneys and the Attorney General (criminal prosecution); ransomware victims (civil action)
Iowa's spyware law makes it a crime to install software on someone else's computer that deceptively collects personal information (such as keylogging, browsing-history profiling, or extracting ID and account numbers), hijacks browser settings, disables security software, or resists removal. A 2023 amendment added ransomware offenses and a civil claim for ransomware victims.
Confidentiality of bank customer financial records
LA Bank Financial Records PrivacyJurisdiction: Louisiana
Effective: 1/1/1985
Authority: Courts (civil procedure); bank regulators
Bars banks and their affiliates from disclosing a customer's financial records to anyone but the customer unless the request is a disclosure demand served on both the bank and the customer with an affidavit, a written customer authorization meeting statutory requirements, or another listed exception. It functions as Louisiana's state-level financial privacy act, supplementing federal GLBA and the Right to Financial Privacy Act. Act 142 of 2026 updated the supervisory-agency definition and service rules.
Confidentiality of Employee Assistance Programs and Ban on Requesting Applicants' Tax Returns
RI EAP Confidentiality / Applicant Tax RecordsJurisdiction: Rhode Island
Authority: Courts via employee or applicant civil actions
Two short Rhode Island employee privacy laws. One bars employers from releasing names, addresses or other confidential information obtained through an employee's participation in an employee assistance program; the other bars employers from asking job applicants for copies of their tax returns or W-2 forms as a condition of being considered.
Confidentiality of Financial Institution Books and Records
Florida Bank Records Confidentiality LawJurisdiction: Florida
Authority: Florida Office of Financial Regulation; state attorneys
Makes a Florida financial institution's books and records confidential and requires records of customers' trust accounts, deposits, and loans to be released only with the account holder's express authorization, subject to listed exceptions such as subpoenas, regulators, credit reporting, and disclosures allowed under the Gramm-Leach-Bliley Act.
Confidentiality of Financial Institution Customer Records
CT Financial Records PrivacyJurisdiction: Connecticut
Authority: Connecticut Banking Commissioner; customers may move to quash subpoenas (36a-43(b))
Bars financial institutions from disclosing a customer's financial records to anyone other than the customer without authorization, except under listed legal processes, and requires that customers be served with subpoenas for their records at least ten days before disclosure so they can challenge them.
Confidentiality of Health Care Communications and Information Act
RI CHCCIAJurisdiction: Rhode Island
Authority: Courts via patient suits; criminal prosecution
Rhode Island's general medical privacy law. It bars providers and anyone who receives patient information from releasing or re-disclosing confidential health care information without the patient's written consent on a compliant form, subject to listed exceptions such as emergencies, treatment coordination, insurers, research without identification and certain law-enforcement reports. It also gives patients rights to have adverse-decision records sent to a physician, to seek amendment, and to have insurers send communications to an address they choose.
Confidentiality of HIV test results
VA HIV test confidentialityJurisdiction: Virginia
Effective: 7/1/1989
Authority: Virginia Attorney General, attorneys for the Commonwealth, and local attorneys (civil penalty); subjects of disclosure (private action) (32.1-36.1(B)-(C))
Makes the results of every HIV test confidential and allows release only to persons or entities authorized to receive protected health information under state or federal law.
Confidentiality of HIV-Related Information
CT HIV ConfidentialityJurisdiction: Connecticut
Authority: Private action; Department of Public Health
Prohibits anyone who obtains confidential HIV-related information from disclosing it except to the person, those with a signed release, and a limited list of health, legal and public-health recipients, and gives injured individuals a right to sue for wilful violations.
Confidentiality of Medical Information Act
CMIAJurisdiction: California
Authority: California Attorney General, district attorneys and other public prosecutors, State Department of Public Health and licensing boards; private plaintiffs
California's main medical privacy law. It bars health care providers, health plans, and their contractors from disclosing medical information without the patient's written authorization except as listed, requires confidential storage and disposal, and extends these duties to consumer health apps, mental health and reproductive health digital services, and employers. Recent amendments protect reproductive and gender-affirming care records from out-of-state disclosure and (SB 81, 2025) bar disclosure for immigration enforcement without a warrant or court order.
Confidentiality of mental health and substance abuse treatment information
OK Mental Health ConfidentialityJurisdiction: Oklahoma
Effective: 11/1/1987
Authority: Courts; Department of Mental Health and Substance Abuse Services and licensing boards
Makes all mental health and drug or alcohol treatment information, and the identity of people receiving such treatment, privileged and confidential. Disclosure generally requires a detailed written release or a court order (a subpoena alone is not enough), with limited minimum-necessary exceptions, and consumers have a right to access their own records subject to listed exceptions.
Confidentiality of Mental Health Services Information and Records
RI Mental Health Records LawJurisdiction: Rhode Island
Authority: Rhode Island Department of Behavioral Healthcare, Developmental Disabilities and Hospitals; courts
Makes confidential the fact that a person was admitted or certified for mental health treatment and all records compiled in providing services under Rhode Island's Mental Health Law, allowing disclosure only with written consent or in listed situations such as coordination among treating professionals, insurance claims, emergencies, approved research under confidentiality oaths, and court proceedings.
Confidentiality of motor vehicle title and registration records
OK Vehicle Records PrivacyJurisdiction: Oklahoma
Effective: 7/1/1985
Authority: Service Oklahoma and the Corporation Commission; district attorneys
Oklahoma's state counterpart to the federal Driver's Privacy Protection Act for vehicle title and registration records. Personal information (name, street address, phone) is confidential and may be released only for listed permissible purposes, such as government functions, vehicle safety and recalls, verifying information in the normal course of business, litigation, and towing notices, and requesters must certify a lawful purpose and no further dissemination.
Confidentiality of Prescription Information (Prescriber Data Law)
VT Prescription Confidentiality LawJurisdiction: Vermont
Authority: Vermont Attorney General
Barred the sale or marketing use of prescriber-identifying prescription records without the prescriber's consent. The U.S. Supreme Court held in Sorrell v. IMS Health Inc., 564 U.S. 552 (2011), that § 4631(d) violates the First Amendment, affirming the Second Circuit. The subsection still appears in the Vermont Statutes but cannot be enforced.
Confidentiality of reportable disease and public health investigation information
OK Communicable Disease ConfidentialityJurisdiction: Oklahoma
Effective: 7/1/1988
Authority: District attorneys (misdemeanor); private civil actions by the subject of a disclosure
Makes Health Department records on reportable communicable and noncommunicable diseases, including HIV and hepatitis B, and public health investigation participants confidential, with release only in listed circumstances such as court order, written informed consent, or de-identified statistics. Anyone who wrongfully discloses such information faces criminal and civil liability.
Confidentiality of sexually transmitted disease medical records
AL STD Records ConfidentialityJurisdiction: Alabama
Authority: District attorneys (criminal prosecution)
Makes information, reports, and medical records about people infected with designated sexually transmitted diseases confidential. They are not open to public inspection or admissible in court except in commitment proceedings, and individual records may be released with the patient's written consent.
Confidentiality of social security numbers
Colorado SSN protectionJurisdiction: Colorado
Effective: 1/1/2007
Authority: Colorado Attorney General (Colorado Consumer Protection Act article)
Colorado limits how businesses display and transmit Social Security numbers. They may not publicly post SSNs, print them on access cards or on mailings (with exceptions for forms and applications), or require them to be sent over unsecured internet connections or used alone to log in.
Confidentiality of Social Security Numbers
SSN Protection (1798.85)Jurisdiction: California
Effective: 7/1/2002
Authority: California Attorney General and local prosecutors; private plaintiffs
Limits how businesses display and use Social Security numbers: no public posting, no printing on access cards or on most mailings, no requiring SSN transmission over unsecured connections or as a sole website login, and no selling SSNs.
Connected Devices with Cameras or Microphones (P.A. 25-44)
CT Connected DevicesJurisdiction: Connecticut
Effective: 7/1/2026
Authority: Connecticut Attorney General / Department of Consumer Protection under CUTPA
Before a connected device with a camera or microphone can be activated, the provider must show the initial purchaser a prescribed disclaimer and plain disclosures about recording, retention and sharing, and let them decline to activate the camera or microphone. Recordings may not be used or sold for targeted advertising without opt-in consent, and collected information must be reasonably secured.
Connected television voice recognition
Smart TV lawJurisdiction: California
Effective: 1/1/2016
Authority: California Attorney General and district attorneys (exclusive)
Requires smart TV makers to tell users during setup that the TV has voice recognition, and bars selling or using recordings collected to improve voice recognition for advertising.
Connected Vehicle Services: Survivor Requests (P.A. 25-113, s. 19)
CT Connected Vehicle SafetyJurisdiction: Connecticut
Effective: 7/1/2026
Authority: Not specified in the section
Lets adult survivors of domestic violence, sexual assault, stalking or trafficking require a car maker to cut off an abuser's remote access to a vehicle's connected services, including location tracking. The provider must act within two business days, deny the abuser newly generated data, and keep the survivor's information confidential.
Connecticut Artificial Intelligence Responsibility and Transparency Act (CART Act; An Act Concerning Online Safety)
CT CART ActJurisdiction: Connecticut
Effective: 10/1/2026
Authority: Connecticut Attorney General (CUTPA); Commission on Human Rights and Opportunities for employment discrimination provisions
A broad 2026 AI law signed May 27, 2026. For privacy purposes it requires AI companion operators to detect self-harm risk and bars manipulative, romantic or sexual interactions with minors; requires employers using automated employment decision tools to tell workers and applicants, including what personal data is analyzed; makes clear that using such tools is no defense to discrimination; and from 2028 bars personalized recommendation feeds for minors without parental consent, with limits on age-verification data use.
Connecticut Data Privacy Act (Act Concerning Personal Data Privacy and Online Monitoring)
CTDPAJurisdiction: Connecticut
Effective: 7/1/2023
Authority: Connecticut Attorney General (exclusive; Conn. Gen. Stat. 42-525(a))
Max Fine: Up to $5,000 per violation
Connecticut's comprehensive consumer privacy law gives residents rights to access, correct, delete and port their data and to opt out of targeted advertising, sale and consequential profiling, and requires consent for sensitive data, privacy notices, recognition of opt-out preference signals, and data protection assessments. P.A. 25-113 (effective July 1, 2026) sharply broadened coverage (35,000-consumer threshold, any processor of sensitive data, any seller of data), added neural and financial-account data as sensitive data, added profiling rights and impact assessments, extended the teen targeted-advertising and sale ban to under-18s, and required disclosure of LLM training. P.A. 26-64 (effective October 1, 2026) bans the sale of precise geolocation data, restricts facial recognition used for security, and expands deletion rights over people-search profiles built from public information.
Connecticut Insurance Information and Privacy Protection Act
CT IIPPAJurisdiction: Connecticut
Effective: 10/1/1982
Authority: Connecticut Insurance Commissioner; individuals in court for certain violations
Based on the NAIC model, this act governs how insurers and agents collect, use and disclose personal and medical information: notices of information practices, limits on pretext interviews, access and correction rights, reasons for adverse underwriting decisions, and consent for most disclosures. It also bars anyone from selling individually identifiable medical record information.
Consumer and protected-consumer security freeze
Tenn. Security FreezeJurisdiction: Tennessee
Effective: 9/1/2008
Authority: Tennessee Attorney General (sole authority over § 47-18-2108(f)); consumers for other violations
Lets Tennessee consumers freeze their credit reports so that a consumer reporting agency cannot release the report or score for new credit without the consumer's authorization. A separate section lets a parent or guardian place a freeze for a child under 16 or an incapacitated adult, creating a record if no credit file yet exists.
Consumer credit report security freeze
AL Security Freeze LawJurisdiction: Alabama
Authority: Not specified in the chapter (courts)
Lets Alabama consumers place a security freeze on their credit reports so agencies cannot release them for credit purposes without the consumer's authorization. Agencies must place, lift, and remove freezes within set deadlines, give a PIN or password, and include an Alabama freeze-rights notice with the federal FCRA summary of rights.
Consumer Credit Reporting Agencies Act (including security freezes)
CCRAAJurisdiction: California
Effective: 1/1/1976
Authority: Private plaintiffs; California Attorney General and local prosecutors
California's counterpart to the federal Fair Credit Reporting Act. It governs who may obtain consumer credit reports and for what purposes, accuracy and dispute rights, and gives consumers the right to place, lift, and remove security freezes on their credit files.
Consumer Credit Security (security freeze law)
Iowa Security Freeze LawJurisdiction: Iowa
Effective: 7/1/2008
Authority: Iowa Attorney General (violation of Consumer Fraud Act 714.16(2)(a))
Iowa's security freeze law lets residents block release of their credit reports, free of charge, and lets parents and guardians place a protected-consumer freeze for children under 16 and incapacitated adults, even creating a record if none exists. It sets short deadlines for credit bureaus to place, lift, and remove freezes.
Consumer Data Protection Act, social media platforms and minors (SB 854)
VA SB 854Jurisdiction: Virginia
Effective: 1/1/2026
Authority: Virginia Attorney General (VCDPA enforcement, 59.1-584)
Requires social media platforms to use commercially reasonable methods, such as a neutral age screen, to identify users under 16, and to limit those users to one hour per day per service unless a parent gives verifiable consent to change the limit. Age data may be used only for age determination. On February 27, 2026 the U.S. District Court for the Eastern District of Virginia preliminarily enjoined the Attorney General from enforcing it against any NetChoice member (NetChoice v. Jones, No. 1:25-cv-02067); the Fourth Circuit denied a stay on August 24, 2026 and set argument for October 28, 2026 (No. 26-1252).
Consumer Empowerment and Identity Theft Prevention Act of 2006 (credit security freeze and Social Security number protection)
RI Security Freeze / SSN ActJurisdiction: Rhode Island
Authority: Courts via consumer suits; civil fines and misdemeanor prosecution for SSN violations
Lets Rhode Island residents freeze their credit reports free of charge so credit cannot be opened in their name without authorization, and sets deadlines for credit bureaus to place, lift and remove freezes. It also restricts how businesses and agencies may display, mail or require transmission of Social Security numbers.
Consumer Genetic Testing Providers
IN Consumer Genetic TestingJurisdiction: Indiana
Effective: 5/6/2025
Authority: Indiana Attorney General (exclusive authority, IC 24-4-24-11(a))
Enacted by HEA 1521 (2025) and effective on passage, this chapter regulates direct-to-consumer genetic testing companies. Before testing, they must give a written privacy disclosure. They need separate, specific consent for extra testing, secondary uses, third-party access, retention beyond 30 days, and genetics-based marketing, and they may never give identifiable genetic data to insurers or employers.
Consumer Health Data Privacy (CTDPA consumer health data provisions)
CT Consumer Health DataJurisdiction: Connecticut
Effective: 10/1/2023
Authority: Connecticut Attorney General (exclusive; Conn. Gen. Stat. 42-525(a))
P.A. 23-56 added 'consumer health data' (including reproductive, sexual and gender-affirming health data) to the CTDPA as sensitive data and imposed threshold-free duties on anyone handling it. It bars selling consumer health data without consent and bans geofences within 1,750 feet of mental health or reproductive or sexual health facilities used to track or message consumers about their health data.
Consumer Identity Protection Act
AL CIPA (identity theft)Jurisdiction: Alabama
Authority: District attorneys and Attorney General (criminal); victims (civil)
Makes identity theft and trafficking in stolen identities crimes, gives victims a civil action with statutory damages, and provides court orders confirming the victim's innocence. On such an order, consumer reporting agencies must block fraudulent information from the victim's credit report within 30 days.
Consumer Privacy in Mortgage Applications (mortgage trigger leads)
RI Mortgage Trigger Lead LawJurisdiction: Rhode Island
Authority: Rhode Island Department of Business Regulation (director); aggrieved lenders or brokers via civil action
Regulates mortgage solicitations based on 'trigger leads' sold by credit bureaus after a consumer applies for a mortgage. Solicitors must disclose up front that they are not affiliated with the consumer's lender and that they bought the consumer's information from a credit bureau, must comply with FCRA prescreening rules, and may not use trigger leads to reach consumers who opted out of prescreened offers or are on do-not-call lists.
Consumer Protection Against Computer Spyware Act
Texas Spyware ActJurisdiction: Texas
Effective: 4/1/2009
Authority: Texas Attorney General; software providers, web page or trademark owners, carriers, cable operators, and ISPs
Prohibits installing software on someone else's computer to deceptively collect personal information through keystroke logging or browsing tracking, hijack settings, or block removal. Private suits are limited to affected software providers, site and trademark owners, carriers, cable operators, and ISPs; botnet victims have a separate action.
Consumer Protection Against Computer Spyware Act
Spyware ActJurisdiction: California
Effective: 1/1/2005
Authority: California Attorney General and local prosecutors
Bars installing software on a Californian's computer that, through deception, hijacks browser settings, logs keystrokes or browsing history, extracts sensitive data, blocks removal, or disables security software.
Consumer Report Security Freeze
Florida Security Freeze LawJurisdiction: Florida
Effective: 7/1/2006
Authority: Private civil actions; Florida Department of Agriculture and Consumer Services
Lets Florida consumers freeze their credit reports so agencies cannot release them to third parties without the consumer's authorization. Agencies must place freezes within 5 business days, lift them temporarily within 3 business days, and remove them within 3 business days of a request.
Consumer Report Security Freeze Law (including protected persons)
KY Security FreezeJurisdiction: Kentucky
Effective: 7/12/2006
Authority: Consumers via civil action; Attorney General retains other enforcement powers
Lets Kentucky consumers freeze their credit reports so they cannot be released to new creditors without the consumer's authorization, and sets deadlines for placing, lifting, and removing freezes. A 2017 addition lets parents, guardians, and other representatives freeze the record or report of a child under 16 or an incapacitated person.
Consumer Reporting Agencies (security freezes; medical debt reporting ban)
VA credit freezeJurisdiction: Virginia
Effective: 7/1/2008
Authority: Consumers by private action; Attorney General exclusively for electronic-lift timing and protected-consumer placement violations (59.1-444.2(U), 59.1-444.3(M)); medical debt reporting through the VCPA (59.1-444.4(C))
Lets Virginia consumers freeze their credit reports free of charge, with deadlines for placing and temporarily lifting freezes, and lets parents or guardians freeze or create a record for children under 16 and incapacitated adults. Since 2024 it also bars health care providers and collectors from reporting medical debt to credit bureaus.
Consumer Reporting Agency Records Restriction (criminal charges without conviction)
KY CRA Criminal Charge RestrictionJurisdiction: Kentucky
Effective: 7/15/1980
Authority: Not specified in the section
Bars consumer reporting agencies from keeping information in their files about a criminal charge in a Kentucky court unless the charge resulted in a conviction.
Consumer Telemarketing Protection (automatic dialing and telephone solicitation)
Tenn. Telemarketing Protection LawJurisdiction: Tennessee
Authority: District attorneys general and recipients (ADAD rules); Tennessee Attorney General (§ 47-18-1526)
Limits robocalls made with automatic dialing and announcing devices: prior consent is required, calls are limited to 8 a.m. to 9 p.m., random or sequential dialing and calls to unlisted numbers and emergency services are barred, and the recorded message must identify the caller. Telephone solicitors must keep an internal do-not-call list consistent with federal rules and may not block caller ID.
Conversational Artificial Intelligence Safety Act
Nebraska CAISAJurisdiction: Nebraska
Effective: 7/1/2027
Authority: Nebraska Attorney General
Enacted as sections 12-18 of LB525 (2026) and operative July 1, 2027, this law regulates companion-style AI chatbots. It requires AI disclosure where users could be misled, extra disclosures and content safeguards for minors, privacy and account-setting tools for minors and parents, and a crisis-referral protocol for self-harm prompts.
Conversational Artificial Intelligence Service Operator Requirements (Chatbot Safety Act)
Chatbot Safety Act (HB 26-1263)Jurisdiction: Colorado
Effective: 1/1/2027
Authority: Colorado Attorney General
HB 26-1263, signed May 29, 2026, sets safety and disclosure duties for companion-style and general chatbots starting January 1, 2027. Operators must estimate users' ages, disclose that the service is AI, run suicide and self-harm referral protocols, and, for known minors, block sexual content and emotional-dependence tactics and offer privacy controls over memory and training use. The act itself took effect August 12, 2026.
Conversational Artificial Intelligence Services Act (2026 SF 2417)
Iowa Conversational AI ActJurisdiction: Iowa
Effective: 7/1/2027
Authority: Iowa Attorney General (with rulemaking authority)
Iowa's 2026 companion-chatbot law requires public conversational AI services to disclose to minors that they are talking to AI, block sexual content and human-like emotional or romantic manipulation of minors, avoid variable engagement rewards for minors, and give minors and parents privacy and account controls. For all users, operators must disclose AI status when a reasonable person could think it is human, keep suicide and self-harm referral protocols, and not present the bot as a licensed mental health provider. It applies from July 1, 2027.
Covered platform age restriction: no addictive features for users under 16 (AB 1709)
AB 1709Jurisdiction: California
Effective: 1/1/2027
Authority: California Attorney General and local public prosecutors
Signed September 10, 2026, AB 1709 bars covered platforms from offering addictive features (addictive feeds, autoplay, and others the Attorney General defines) to users under 16. Platforms must verify age through the Digital Age Assurance Act before offering those features and must delete accounts and data of under-16 users unless the account is kept free of addictive features. It also creates an e-Safety Advisory Commission.
Credit and debit card receipt truncation
OK Card Receipt TruncationJurisdiction: Oklahoma
Effective: 11/1/2002
Authority: Not specified in the section
Bars merchants from printing more than the last five digits of a card number, or the expiration date, on electronically printed customer receipts. Applies to all electronic receipt devices since January 1, 2007.
Credit and debit card receipt truncation and card-transaction information limits
ORS 646A.200-646A.214Jurisdiction: Oregon
Authority: Oregon Attorney General (rules under ORS 646A.206); ORS 646A.210 and 646A.214 violations are unlawful practices under ORS 646.608(1)(mm)
Limits card receipts to the customer's name and five digits of the card number, requires destruction of fuller receipt copies within 36 months, and limits collecting card numbers or recording extra personal information on card slips.
Credit Report Protection Act
Nebraska Credit Report Protection ActJurisdiction: Nebraska
Effective: 9/1/2007
Authority: Nebraska Attorney General
Nebraska's credit freeze law lets consumers place, temporarily lift, and remove a security freeze on their credit files, and lets a parent or representative freeze the file of a child under 16 or an incapacitated person, creating a record if none exists. Freezes are free, and a frozen file cannot be released to third parties without authorization.
Credit Report Security Freeze
MT Security FreezeJurisdiction: Montana
Effective: 10/1/2007
Authority: Private enforcement by consumers (30-14-1736)
Montana consumers may place a security freeze on their credit reports so that reports cannot be released to new creditors without consent. Consumer reporting agencies must place, temporarily lift and remove freezes on set timelines and give consumers a notice of rights.
Credit Report Submission Prohibitions (ambulance balance billing)
MT Ambulance Credit Reporting LimitJurisdiction: Montana
Effective: 10/1/2017
Authority: Montana Department of Justice, Office of Consumer Protection (placement in Title 30, ch. 14)
Licensed ambulance services may not report patients to credit bureaus over balance bills once the patient's insurer or health plan has paid based on plan charges, or when an uninsured patient has paid toward the bill and filed an AG complaint that it is not based on usual and customary charges. Bills sent to collections must carry the same limit.
Credit reporting agency duties, security alerts, and security freezes
LA Credit Report and Security Freeze LawJurisdiction: Louisiana
Authority: Private civil actions
Gives Louisiana consumers rights to copies of their credit reports, to dispute inaccurate items with a 45-day investigation deadline, to place free 90-day security alerts, and to place free security freezes that credit bureaus must apply within set deadlines. A separate section lets parents and guardians freeze the credit file of a child under 16 or an incapacitated person, including creating a file for that purpose.
Crime of doxing
AL Doxing LawJurisdiction: Alabama
Effective: 9/1/2023
Authority: Alabama district attorneys and Attorney General (criminal prosecution)
Makes it a crime to intentionally publish someone's personal identifying information online intending that others use it to harass or harm the person, when the person is actually harassed or harmed. A second prong protects law enforcement officers, firefighters, and public servants, including against being impeded in their duties. Political speech and publishing officials' official contact information are carved out.
Crime of phishing
AL Phishing LawJurisdiction: Alabama
Authority: Alabama Attorney General and district attorneys (criminal and civil); private plaintiffs
Makes it a felony to use the Internet to trick people into providing identifying information by impersonating a business without its authority. It gives prosecutors civil remedies and lets affected individuals and businesses sue.
Criminal eavesdropping and surveillance (one-party consent)
AL Eavesdropping LawJurisdiction: Alabama
Authority: Alabama district attorneys and Attorney General (criminal prosecution)
Alabama is a one-party consent state: it is a crime to use a device to overhear, record, or transmit a private communication without the consent of at least one participant. The article also criminalizes secret surveillance while trespassing in a private place, planting eavesdropping devices, and using or disclosing information obtained illegally.
Criminal History on Applications for Employment (ban-the-box)
RI Ban-the-Box LawJurisdiction: Rhode Island
Authority: Rhode Island Department of Labor and Training, with the Commission for Human Rights
Prohibits employers from asking on job applications whether an applicant has ever been arrested, charged or convicted, except for law enforcement positions, jobs where law mandates disqualification for specified convictions, and jobs requiring a fidelity bond that specified convictions would bar.
Criminal Impersonation, Identity Theft, and Identity Fraud
Nebraska Identity Theft LawJurisdiction: Nebraska
Authority: County attorneys and the Attorney General (criminal prosecution)
Nebraska criminalizes identity theft, defined broadly to cover knowingly obtaining, possessing, or using another person's or entity's identifying information (such as name, birth date, SSN, license number, employer, account numbers, or biometric data) without consent to commit fraud, cause loss, obtain employment, or gain a benefit. Victims may report to their local law enforcement agency.
Criminal Invasion of Personal Privacy (pretexting)
MT Criminal Invasion of PrivacyJurisdiction: Montana
Effective: 10/1/2007
Authority: County attorneys and the Attorney General (criminal prosecution)
Montana makes it a crime to get someone's personal or confidential information by pretending to be that person, a practice often called pretexting. Posing as someone with their express consent is allowed.
Customer Records: disposal of records containing personal information
Records Disposal (1798.81)Jurisdiction: California
Authority: Private plaintiffs; California Attorney General
Requires businesses to destroy customer records containing personal information when they no longer keep them, by shredding, erasing, or otherwise making the information unreadable.
Cybersecurity Affirmative Defense Act
Utah Cybersecurity Affirmative Defense ActJurisdiction: Utah
Effective: 5/5/2021
Authority: None (creates an affirmative defense)
Enacted by 2021 H.B. 80 and unchanged since, it gives a defense against claims of failing to implement reasonable controls, respond, or notify after a breach if the person had a written cybersecurity program reasonably conforming to NIST, CIS, ISO 27000, PCI DSS, HIPAA, GLBA, 13-44, or similar frameworks.
Cybersecurity Event Class Action Liability Limit
Nebraska Cybersecurity Event Liability LawJurisdiction: Nebraska
Effective: 9/3/2025
Authority: Courts (limits private litigation)
Enacted by LB241 (2025), this law raises the liability standard for data breach class actions against private entities. A cybersecurity event is unauthorized access to, or disruption or misuse of, an information system or nonpublic information such as SSNs, driver's license numbers, financial account numbers, access codes, or biometric records.
Cybersecurity Program Safe Harbor (S.B. 2610)
Texas Cybersecurity Safe HarborJurisdiction: Texas
Effective: 9/1/2025
Authority: None (liability defense only)
Gives small and mid-sized Texas businesses a defense against exemplary (punitive) damages in data breach lawsuits if, at the time of the breach, they maintained a cybersecurity program scaled to their size and conforming to a recognized framework such as NIST, CIS Controls, ISO 27000, SOC 2, or applicable HIPAA, GLBA, or PCI DSS requirements.
Daniel's Law (nondisclosure of covered persons' home addresses and unpublished telephone numbers)
Daniel's LawJurisdiction: New Jersey
Effective: 11/20/2020
Authority: Private civil action in Superior Court by the covered person or an assignee; county prosecutors and the Attorney General for the criminal offense in N.J.S.A. 2C:20-31.1
Enacted after the 2020 killing of Daniel Anderl, son of U.S. District Judge Esther Salas, Daniel's Law lets judges, prosecutors, law enforcement officers, child protective investigators, and their household family members demand that anyone stop publishing their home address or unpublished home phone number. After written notice, the recipient has 10 business days to stop disclosing and remove the information, or face civil liability (which can be pursued by an assignee) and possible criminal charges.
Data Accessibility, Transparency and Accountability Act
Tenn. DATA ActJurisdiction: Tennessee
Effective: 7/1/2014
Authority: Tennessee Department of Education and State Board of Education
Governs how Tennessee's education agencies and schools collect and share student data. It requires the Department of Education to publish a data inventory and adopt privacy and security policies, gives parents the right to inspect their children's education records, bars schools from collecting data on students' political affiliation, religion, voting history, or gun ownership, and requires written consent before collecting student biometric or physiological data such as facial-expression analysis, brain waves, or eye tracking.
Data Broker and Data Collector Registration and Sensitive Data Sale Ban (P.L.2026, c.25)
NJ Data Broker LawJurisdiction: New Jersey
Effective: 6/30/2026
Authority: New Jersey Division of Consumer Affairs (registration, fees, and penalties collected in a summary proceeding under the Penalty Enforcement Law of 1999)
This 2026 law creates an annual registry of data brokers and data collectors that sell or license New Jersey consumers' personal data, with fees scaled by the number of consumers affected, and requires detailed disclosures about opt-out, deletion, breach history, and minors' data. It also bars data brokers and data collectors from selling or licensing sensitive data to anyone, backed by a $50,000-per-record penalty. The law took effect on signing, but the Division's public registry duty became operative 270 days later.
Data Broker Registration and Accessible Deletion Mechanism (P.A. 26-64, ss. 1-10)
CT Data Broker RegistryJurisdiction: Connecticut
Effective: 10/1/2026
Authority: Connecticut Department of Consumer Protection (Commissioner of Consumer Protection)
Creates Connecticut's first data broker registry: from January 1, 2027 no data broker may sell or license brokered personal data in the state unless registered with the Department of Consumer Protection. By July 1, 2028 the Department must launch a one-stop deletion mechanism, and from August 2028 registered brokers must check it at least every 45 days and delete participating consumers' data.
Data Broker Registration law and the Delete Act (SB 362), with the Delete Request and Opt-out Platform (DROP)
Delete ActJurisdiction: California
Effective: 1/1/2020
Authority: California Privacy Protection Agency (CalPrivacy)
Requires data brokers to register every year with the California Privacy Protection Agency and disclose what data they collect. The 2023 Delete Act (SB 362) moved the registry from the Attorney General to the Agency and required a single, free deletion mechanism; the Agency launched DROP on January 1, 2026, and registered brokers must process DROP deletion requests every 45 days starting August 1, 2026. SB 361 (2025) added more registration disclosures.
Database Security Breach Notification Law
LA DSBNLJurisdiction: Louisiana
Effective: 1/1/2006
Authority: Louisiana Attorney General (Consumer Protection Section)
Louisiana's breach law requires businesses and agencies to protect computerized personal information with reasonable security, destroy it securely when no longer retained, and notify affected Louisiana residents within 60 days of discovering a breach. An Attorney General rule adds notice to the AG within 10 days of notifying residents. Personal information is name plus SSN, driver's license or state ID number, financial account or card number with access code, passport number, or biometric data.
Deceptive and Fraudulent Synthetic Media in Elections
RI Election Deepfake LawJurisdiction: Rhode Island
Effective: 7/2/2025
Authority: Courts via actions by depicted candidates
Bars campaigns, PACs and independent spenders from distributing, within 90 days of an election, AI-manipulated images, audio or video of a person that they know or should know are deceptive and fraudulent, unless the media carries a clear disclosure that it was manipulated or generated by artificial intelligence.
Deceptive Audio or Visual Media (Deepfake) Law
NJ Deepfake LawJurisdiction: New Jersey
Effective: 4/2/2025
Authority: County prosecutors and the Attorney General (criminal); private civil action by victims in Superior Court
This 2025 law makes it a crime to create or spread AI-generated or other technically produced deepfakes to commit or further crimes such as harassment, sexual exploitation, or election interference. It also lets victims, including families of deceased victims, sue for damages.
Deceptive Commercial Electronic Mail
IN Commercial EmailJurisdiction: Indiana
Authority: Private enforcement by recipients and interactive computer services
Enacted in 2003, this chapter bans commercial email that uses a third party's domain without permission, misrepresents its origin or path, or has a false or misleading subject line. It also requires 'ADV:' and 'ADV:ADLT' subject labels on unsolicited ads and a free opt-out. Many of its labeling and opt-out rules likely overlap with, and may be preempted by, the federal CAN-SPAM Act, which preserves state laws only as to falsity or deception.
Deepfake Regulation in Election Communications (SB 25)
MT Election Deepfake LawJurisdiction: Montana
Effective: 10/1/2025
Authority: Montana Commissioner of Political Practices; county attorneys and Attorney General for criminal referrals; aggrieved candidates or parties (injunction)
Montana bars distributing AI-generated or synthetic 'deepfakes' of candidates or parties in election communications within 60 days of an election unless a prescribed disclosure says the content was significantly edited by AI. On September 16, 2026, a federal court preliminarily enjoined enforcement of the law, but only as to the plaintiffs, in Accountability in State Government v. Knudsen, No. 6:26-cv-00038-SPW (D. Mont.).
Delaware Discrimination in Employment Act: genetic information provisions
DDEA Genetic InformationJurisdiction: Delaware
Authority: Delaware Department of Labor (charge process), followed by a Delaware Right to Sue Notice for Superior Court suits (712)
Delaware's employment discrimination law bars discrimination based on genetic information and bars employers, agencies, and unions from intentionally collecting genetic information about employees, applicants, or their family members unless it is job-related and consistent with business necessity or needed for retirement or benefit plan administration.
Delaware Online Privacy and Protection Act
DOPPAJurisdiction: Delaware
Effective: 1/1/2016
Authority: Consumer Protection Unit, Delaware Department of Justice (1203C)
Delaware's online privacy law has three parts: it bars marketing listed adult products (alcohol, tobacco, firearms, lottery, tattoos, sexually oriented material, and others) to children under 18 on child-directed services and restricts use of children's personal information for such marketing; it requires any commercial website or app collecting personal information from Delaware users to post a conspicuous privacy policy; and it limits disclosure of e-book and book-service user records.
Delaware Personal Data Privacy Act
DPDPAJurisdiction: Delaware
Effective: 1/1/2025
Authority: Delaware Department of Justice (Attorney General), exclusively (12D-111(a), (e))
Max Fine: Up to ,000 per violation
Delaware's comprehensive consumer privacy law gives residents rights to access, correct, delete, and port their personal data, to get a list of third parties that received it, and to opt out of targeted advertising, sale, and significant-decision profiling. It has low applicability thresholds, requires opt-in consent for sensitive data and for targeted advertising or sale of data about known 13-17-year-olds, and requires honoring universal opt-out signals from 2026-01-01. HB 380 (signed 2026-09-02, effective 2027-01-01) lowers thresholds further and adds third-party contract and diligence duties, adverse-action notices for profiling reports, automated-decision impact assessments, a broader sensitive-data definition (including neural data and financial credentials), and narrows the employee-data exclusion for profiling.
Delaware Telemarketing Fraud Act (Telemarketing Registration and Fraud Prevention)
DE Telemarketing Fraud ActJurisdiction: Delaware
Effective: 1/28/2000
Authority: Delaware Attorney General (Consumer Protection Unit), under 29 Del. C. ch. 25 (2509A)
Requires telemarketing sellers and businesses reaching Delaware customers to register with the Department of Justice, make opening disclosures, and give written confirmation before a sale is final. It bars calling a customer about sales for 10 years after the customer says to stop, and gives harmed customers a right to sue.
Delaware Uniform Civil Remedies for Unauthorized Disclosure of Intimate Images Act
DUCRUDIIAJurisdiction: Delaware
Effective: 9/23/2020
Authority: Private civil action by the depicted individual (7803)
Gives people a civil claim against anyone who knowingly or recklessly shares, or threatens to share, private intimate images of them without consent. A 2024 amendment (the Amelia Kramer Act) extends the claim to AI-generated sexual deep fakes and lets plaintiffs proceed with identifying details redacted.
Destruction of Customer Records Containing Personally Identifiable Information
KY Records DisposalJurisdiction: Kentucky
Effective: 7/12/2006
Authority: Injured customers via civil action; injunctive relief available
Requires businesses that discard customer records they no longer need to keep to take reasonable steps to destroy the personally identifiable information in them. Personally identifiable information is defined broadly and includes contact details, SSNs, government ID numbers, and medical, financial, tax, and disability information.
Digital Age Assurance Act (AB 1043, 2025, amended by AB 1856, 2026)
DAAAJurisdiction: California
Effective: 1/1/2027
Authority: California Attorney General
Creates a device-level age signal. Operating systems must ask for the user's birth date or age at account setup and send app developers an age-bracket signal (under 13, 13-15, 16-17, 18+) on request; developers must request the signal and are treated as knowing the user's age range. AB 1856 (2026) broadened the account-setup duty, set a July 1, 2027 deadline for devices set up before 2027, and bars requesting a signal when not required by law. Other 2026 laws (AB 1709, AB 2246, SB 1119) rely on this signal.
Digital Content Provenance Standards Act
Utah Content Provenance ActJurisdiction: Utah
Effective: 1/1/2027
Authority: Utah Division of Consumer Protection
Enacted by 2026 H.B. 276, effective January 1, 2027, it requires provenance data handling for AI-generated and captured content. It is a disclosure-standards law rather than a privacy-notice law.
Digital Voyeurism
Florida Digital Voyeurism LawJurisdiction: Florida
Authority: State attorneys (criminal)
Makes it a crime to secretly view, broadcast, or record someone who is dressing, undressing, or privately exposing their body where they expect privacy, or to record under or through their clothing, without their knowledge and consent. HB 1389 (2024) renamed the offense from 'video voyeurism' to 'digital voyeurism' and revised its elements.
Digital Voyeurism Prevention Act
Utah DVPAJurisdiction: Utah
Effective: 1/1/2027
Authority: None; private civil actions
Enacted by 2026 H.B. 276, effective January 1, 2027, it treats non-consensual counterfeit intimate images as a violation of the reasonable expectation of privacy. Generation services must verify consent and publish policies; covered platforms must offer a 48-hour takedown process.
Direct-to-Consumer Genetic Testing Privacy (P.A. 26-64, ss. 17-19)
CT DTC Genetic PrivacyJurisdiction: Connecticut
Effective: 10/1/2026
Authority: Connecticut Attorney General (solely; P.A. 26-64, s. 19(b))
Gives consumers a property right in, and exclusive control over, their biological samples and genetic test results held by direct-to-consumer genetic testing companies. Companies must obtain express consent for collection, use, transfer, secondary use and sample retention, may not share genetic data with employers, insurers or marketers, and must let consumers access and delete data and destroy samples.
Disclosure of Confidential Financial Records
Nebraska Financial Records Disclosure LawJurisdiction: Nebraska
Authority: Courts (governs compelled disclosure)
This law protects customer financial records by providing that covered institutions cannot be required to disclose records they deem confidential except in listed situations, such as a court subpoena, summons, warrant, or order, a supervisory regulator's examination, an agency subpoena, a statutory requirement, discovery rules, or a law enforcement request where the institution is a crime victim. Requesters generally pay the actual cost of producing records.
Disclosure of Mental Health and Psychological Information
Iowa Mental Health Information LawJurisdiction: Iowa
Authority: County attorneys (criminal, for payors and peer reviewers); Commissioner of Insurance receives payor filings
Iowa bars mental health professionals, facilities, and data collectors from disclosing a person's mental health information except under written authorization or listed exceptions (emergencies, administrative needs, court orders, claims administration, limited family and law enforcement disclosures). Each disclosure must be logged, and recipients may not redisclose.
Disclosure of Nonpublic Personal Financial Information (insurance)
IN Insurance NPI PrivacyJurisdiction: Indiana
Authority: Indiana Insurance Commissioner (rulemaking, IC 27-2-20-3)
This short chapter makes GLBA Title V's limits on sharing nonpublic personal information with non-affiliated third parties part of Indiana insurance law. It authorizes the Insurance Commissioner to adopt rules consistent with, and no stricter than, GLBA.
Disclosure of Protected Health Information Prohibited (Health Care Privacy)
VT Health Care PrivacyJurisdiction: Vermont
Effective: 10/1/2016
Authority: Not specified in § 1881
Makes HIPAA's disclosure limits a matter of Vermont law by barring covered entities and business associates from disclosing protected health information unless HIPAA permits it. Amendments in 2023 and 2025 add shield-law protections: PHI about legally protected health care activity, such as reproductive and gender-affirming care, may not be disclosed to out-of-state governments for investigations or used in legal proceedings, except with patient authorization or in listed cases.
Disclosure of Security Breach (data breach notification and data security)
IN Breach NotificationJurisdiction: Indiana
Effective: 7/1/2006
Authority: Indiana Attorney General (actionable only by the AG, IC 24-4.9-4-1, 24-4.9-3-3.5(e))
Indiana's breach law requires data base owners to notify affected Indiana residents, and the Attorney General, when a breach of computerized personal information could result in identity theft, identity deception, or fraud. Notice must go out without unreasonable delay and within 45 days of discovery. The article also requires reasonable security procedures and secure disposal of records containing personal information.
Disclosure of Sexually Explicit Images Without Consent
VT NCII LawJurisdiction: Vermont
Authority: State's Attorneys and Attorney General (criminal); victims (civil)
Makes it a crime to knowingly share nude or sexual images of an identifiable person without consent, with intent to harm, harass, intimidate, threaten or coerce, including realistic digitally altered or AI-generated images. Websites may not charge to remove such images, and victims have a civil cause of action.
Disclosure of synthetic media in campaign communications
ORS 260.268 (election deepfakes)Jurisdiction: Oregon
Effective: 3/27/2024
Authority: Oregon Secretary of State (Attorney General as to Secretary of State races)
Requires campaign communications that use realistic AI-manipulated images, audio or video of a person to carry a disclosure that the content has been manipulated.
Discrimination Based on Vaccination Status or Immunity Passport Prohibited
MT Vaccination Status LawJurisdiction: Montana
Authority: Montana Human Rights Bureau / Human Rights Commission (unlawful discriminatory practice under Title 49)
Montana makes it an unlawful discriminatory practice for employers, businesses and government to deny services, jobs or access based on a person's vaccination status or whether they hold an 'immunity passport'. Health care facilities may ask employees to volunteer vaccination status only to plan accommodations.
Disposal and protection of personal identifying information
Colorado data disposal and securityJurisdiction: Colorado
Effective: 8/4/2004
Authority: Colorado Attorney General (6-1-716(4))
Colorado businesses must have a written policy to destroy paper and electronic records containing personal identifying information when no longer needed, rendering it unreadable. Since 2018 they must also maintain reasonable security procedures appropriate to the data and the business, and require service providers to do the same.
Disposal of Business Records Containing Personal Identifying Information
Texas Records Disposal LawJurisdiction: Texas
Effective: 4/1/2009
Authority: Texas Attorney General
Requires businesses to shred, erase, or otherwise make customers' personal identifying information unreadable when disposing of records, and to delete disputed dishonored-check records within 30 days of agreement or a police report.
Distributing or creating a private image (nonconsensual intimate images, including AI-generated)
AL Private Image LawJurisdiction: Alabama
Authority: District attorneys (criminal prosecution); Alabama Attorney General (emergency injunctions); depicted individuals (civil suits)
Criminalizes distributing a sexually explicit image of an identifiable person without their written consent, and (since 2024) creating, recording, or altering such an image without consent, when the person had a reasonable expectation of privacy. The definition expressly reaches altered and AI-generated images that a reasonable person would believe depict a real, identifiable individual.
Distribution of materially deceptive media to influence an election
AL Election Deepfake LawJurisdiction: Alabama
Effective: 10/1/2024
Authority: Alabama Attorney General and district attorneys; depicted individuals, injured candidates, and voter-interest entities (injunctive relief)
Prohibits knowingly distributing AI-generated media that falsely depicts a person's speech or conduct within 90 days of an election, with intent to harm a candidate and deceive voters. Distribution is allowed if the media carries a prescribed disclaimer that it has been manipulated and depicts speech or conduct that did not occur.
Distribution of Sexually Explicit Images Without Consent and Civil Takedown Remedy
KY Nonconsensual Intimate ImagesJurisdiction: Kentucky
Effective: 7/14/2018
Authority: Prosecutors (criminal); persons depicted (civil takedown action)
Criminalizes sharing another person's private sexual images without written consent when done to profit or to harm, harass, or coerce, and clarifies that consent to create an image is not consent to distribute it. Sites and apps that distribute such images must take them down at the depicted person's request without charging a removal fee, and face daily civil damages if they do not.
Document Safe Destruction Act
VT Document Destruction ActJurisdiction: Vermont
Effective: 1/1/2007
Authority: Vermont Attorney General and State's Attorneys; Department of Financial Regulation for its licensees
Requires businesses to destroy customer records containing personal information, such as SSNs, ID numbers and financial account numbers, when they no longer keep them, by shredding, erasing or otherwise making the data unreadable. Disposal companies must adopt and monitor policies that protect the information during collection, transport and disposal.
Downcoding of Health Benefits Claims (AI use limits and disclosure)
IN Health Claims AI DisclosureJurisdiction: Indiana
Effective: 7/1/2026
Authority: Indiana Department of Insurance (rulemaking, IC 27-1-52-14)
Enacted by HEA 1271 (2026) and effective July 1, 2026, this chapter limits claim downcoding by health insurers. Insurers may not use automated tools, including AI, as the sole basis for a medical-necessity downcode without human review of the medical record. Providers may not submit claims generated by automated tools without human review. Insurers must disclose when AI is used to deny prior authorization or downcode a claim.
Drug and Alcohol Testing in the Workplace Act (privacy safeguards)
MN DATWAJurisdiction: Minnesota
Authority: Employees and applicants by civil action; state, county, or city attorneys and bargaining agents for injunctive relief (181.956)
Allows workplace drug, alcohol, and cannabis testing only under a written policy and only in listed situations (post-offer applicant testing, annual physicals with notice, random testing for safety-sensitive jobs, reasonable suspicion, and treatment follow-up). Laboratories may tell employers only whether substances were present, and test results are private and confidential, not usable in criminal cases against the employee.
Drug-Free Workplace Program: Confidentiality of Employee Drug Test Information
Florida Drug-Free Workplace ConfidentialityJurisdiction: Florida
Authority: Florida Department of Financial Services (Division of Workers' Compensation); Agency for Health Care Administration (laboratories)
Sets rules for employers that choose Florida's drug-free workplace program. Employers must give employees and applicants a written policy before testing, and drug-test information is confidential and may be released only with the tested person's signed written consent or when compelled in listed proceedings.
Early Learning Personal Information Protection Act
ELPIPAJurisdiction: California
Effective: 1/1/2017
Authority: California Attorney General and local prosecutors; pupils actually harmed (from 2027)
Applies the same limits as the K-12 law to technology used in preschool and prekindergarten: no targeted advertising, profiling, sale, or unauthorized disclosure of children's information; reasonable security; and deletion on request. AB 1159 (2026) extends and tightens it, including a bar on AI training.
Eavesdropping, Wiretapping and Tampering with Private Communications (criminal)
CT Eavesdropping LawJurisdiction: Connecticut
Authority: State criminal prosecution
Criminalizes wiretapping by a non-party without either party's consent and mechanically overhearing or recording an in-person conversation without the consent of at least one party (a one-party-consent rule for criminal liability), and bars obtaining or divulging call contents through telephone company employees. Civil liability for recording phone calls without all-party consent is separate (52-570d).
Education Privacy Act (student social media and device privacy in higher education)
DE Education Privacy ActJurisdiction: Delaware
Effective: 8/19/2012
Authority: Not specified in the chapter
Bars Delaware colleges and universities from demanding students' or applicants' social media passwords, making them log in in front of staff, requiring them to add the school as a contact, accessing their accounts through their contacts, or installing tracking software on their personal devices. Campus police investigations and threat assessments are exempt.
Education Records of K-12 Students; Limits on Collection of Student Information
Florida K-12 Education Records LawJurisdiction: Florida
Authority: State Board of Education (rules); circuit courts (injunctions)
Applies FERPA-style rights to Florida K-12 records and adds a 2014 rule barring schools and education agencies from collecting students' (or their parents' or siblings') political affiliation, voting history, religious affiliation, or biometric information. It mainly binds public schools and those that perform services for them.
Educational Institution Policies on Social Media
NH Student Social Media PrivacyJurisdiction: New Hampshire
Effective: 9/19/2015
Authority: Not specified in the section
Stops schools and colleges from demanding access to students' or applicants' personal social media accounts. Institutions may still investigate specific misconduct reports without login credentials and monitor their own networks.
Educational Records Bill of Rights Act
RI Educational Records Bill of RightsJurisdiction: Rhode Island
Authority: Rhode Island Commissioner of Elementary and Secondary Education (appeals under ch. 16-39)
Rhode Island's state counterpart to FERPA for K-12 schools. It gives parents and adult students rights to inspect student records within 10 days, get copies at no more than 15 cents per page, request amendment or expungement, add a statement to contested records, and keep records confidential absent written consent or a FERPA-authorized release.
Educational Technology Provider Registration
VT EdTech RegistrationJurisdiction: Vermont
Effective: 1/1/2027
Authority: Vermont Secretary of State (filings); Vermont Attorney General
Starting in 2027, edtech providers must give the Secretary of State more information whenever they make a filing, including links to each product's privacy policy, the schools they serve under paid contracts and a description of each product. They must also attest that each product meets Vermont's student privacy law, the Age-Appropriate Design Code, COPPA and other privacy laws.
Electronic and Mechanical Eavesdropping
Iowa Eavesdropping LawJurisdiction: Iowa
Authority: County attorneys and the Attorney General (criminal prosecution)
Iowa is a one-party consent state: a person who is a party to a conversation, or openly present and listening, may record it, but secretly listening to or recording others' conversations without authority is a crime. A 2018 amendment added an exception for doorbell and outdoor security cameras on a person's own property.
Electronic Health Records Requirements (S.B. 1188)
Texas EHR Law (SB 1188)Jurisdiction: Texas
Effective: 9/1/2025
Authority: Texas Attorney General (civil penalties and injunctions); Health and Human Services Commission and regulatory agencies (investigation and discipline)
Requires electronic health records of Texans to be physically stored in the United States and accessible only to staff who need them, bars recording credit scores or voter registration status in health records, gives parents immediate access to minors' records, and requires practitioners to disclose diagnostic AI use. It also adds biological-sex recording rules for records.
Electronic Mail (unsolicited bulk email law)
Iowa Anti-Spam LawJurisdiction: Iowa
Authority: Iowa Attorney General (as a Consumer Fraud Act violation under 714.16(2)(a)); county attorneys (criminal); injured persons (civil)
Iowa's anti-spam law targets bulk commercial email senders who forge or falsify routing and header information, and people who sell software built to do so. It carries criminal penalties that rise with volume, lets injured email providers and recipients sue for statutory damages, and treats violations as consumer fraud enforceable by the Attorney General. Much of state spam regulation is preempted by the federal CAN-SPAM Act, except for falsity and deception rules like this one.
Electronic Mail Communications Act (commercial e-mail)
Florida Electronic Mail Communications ActJurisdiction: Florida
Effective: 7/1/2004
Authority: Florida Department of Legal Affairs; interactive computer services, telephone companies, and cable providers; state attorneys (criminal)
Florida's anti-spam law. It prohibits unsolicited commercial e-mail that uses a third party's domain without permission, falsifies or hides routing information, carries a false or misleading subject line, or contains deceptive content meant to damage the recipient's device.
Electronic Mail Fraud Regulatory Act (anti-phishing)
RI Anti-Phishing ActJurisdiction: Rhode Island
Authority: Courts via consumer, ISP, website-owner and trademark-owner actions
Rhode Island's anti-phishing law. It prohibits using websites, emails or other internet means to trick people into giving personal identifying information, such as SSNs, account numbers, passwords or biometric data, by pretending to be a business or person without authorization.
Electronic Monitoring in Nursing and Assisted Living Facilities
RI Resident Room Camera LawJurisdiction: Rhode Island
Effective: 1/30/2025
Authority: Rhode Island Department of Health
Lets nursing home and assisted living residents place cameras or audio recorders in their own rooms with written consent on a state form, including consent from any roommate. Facilities must post notices, may not retaliate or refuse admission over monitoring, and no one may access recordings without the resident's written consent; recordings are the resident's property and may be shared only for health, safety or welfare concerns.
Electronic Monitoring of Employees: Prior Notice
CT Employee Monitoring NoticeJurisdiction: Connecticut
Authority: Connecticut Labor Commissioner
Employers that electronically monitor employees on their premises (computers, phones, cameras and similar means) must give prior written notice of the types of monitoring, which can be done by a conspicuous posting. Covert monitoring is allowed when there are reasonable grounds to suspect illegal conduct, rights violations or a hostile work environment.
Electronic Protected Health Information of Minor: Disclosure to Legal Guardian
Iowa Minor ePHI Guardian Access LawJurisdiction: Iowa
Effective: 7/1/2024
Authority: Not specified in the section
This 2024 law requires Iowa health care providers and facilities to give a minor's legal guardian access to the minor's electronic health information, or a free printed copy instead. It does not cover care the minor may legally consent to alone, or disclosures barred by other state or federal law.
Electronic stalking (unauthorized electronic tracking devices)
AL Electronic Stalking LawJurisdiction: Alabama
Effective: 9/1/2023
Authority: Alabama district attorneys and Attorney General (criminal prosecution)
Makes it a crime to place a GPS or other electronic tracking device on someone else's property without the owner's consent or legal authority. Doing so to surveil, stalk, or harass is a felony.
Electronic Surveillance Act
LA Electronic Surveillance ActJurisdiction: Louisiana
Effective: 7/23/1985
Authority: District attorneys and courts (criminal); private civil actions
Louisiana's wiretap law makes it a crime to intercept wire, electronic, or oral communications, or to use or disclose intercepted contents, unless an exception applies. It is a one-party consent law: a private person may record a communication they take part in, or with one party's prior consent, unless the purpose is to commit a criminal, tortious, or other injurious act. Victims have a civil damages action.
Electronic tracking of motor vehicles
Tenn. Vehicle Tracking LawJurisdiction: Tennessee
Authority: District attorneys (criminal prosecution)
Makes it a crime to knowingly install or hide an electronic tracking device on a motor vehicle to monitor its occupants without the consent of all owners, and bars lessors from tracking leased vehicles without the lessee's consent. Exceptions cover law enforcement investigations, parents monitoring a minor child in a vehicle they own or lease, stolen goods or stolen vehicles, and manufacturer-installed systems.
Electronic Tracking of Motor Vehicles
RI Vehicle Tracking LawJurisdiction: Rhode Island
Authority: Prosecutors (criminal misdemeanor)
Makes it a crime to secretly put or use a GPS or other electronic tracking device on a vehicle to follow its driver or passengers without the consent of the operator and all occupants. Exceptions cover law enforcement investigations, parents tracking minor children in vehicles they own, theft-recovery devices, dealers with written consent in credit sales or leases, and businesses tracking their own fleet vehicles driven by employees or contractors.
Employee Access to Personnel Files
NH Personnel File Access LawJurisdiction: New Hampshire
Authority: New Hampshire Department of Labor
Gives employees the right to inspect and copy their personnel files and to add a rebuttal statement that must travel with any disclosure of the disputed information. Health and lifestyle information gathered for wellness programs may not be kept in personnel files.
Employee Access to Personnel Records
MN Personnel Records ActJurisdiction: Minnesota
Authority: Employees by civil action (181.965)
Gives Minnesota employees the right to review their personnel records on written request (once every six months) and former employees the right to a free copy, and lets employees dispute information and attach a position statement. Records improperly withheld from review generally cannot be used against the employee in later proceedings, and retaliation is prohibited.
Employee and applicant social media account privacy
ORS 659A.330Jurisdiction: Oregon
Authority: Oregon Bureau of Labor and Industries (ORS 659A.820)
Bars employers from demanding access to workers' or applicants' personal social media accounts, forcing them to add the employer as a contact, or punishing them for refusing. Employers may still investigate specific misconduct reports and view public content.
Employee and applicant social media privacy
Lab. Code 980Jurisdiction: California
Effective: 1/1/2013
Authority: Labor Commissioner; courts
Bars employers from requiring or asking employees or applicants for personal social media usernames and passwords, to open personal accounts in front of the employer, or to divulge personal social media, with limited exceptions for misconduct investigations and employer-issued devices.
Employee Online Privacy Act of 2014
Tenn. Employee Online Privacy ActJurisdiction: Tennessee
Effective: 1/1/2015
Authority: Not specified in the act
Bars employers from requesting or requiring employees or applicants to disclose passwords to personal internet accounts, to add the employer as a contact, or to open a personal account in the employer's presence, and from retaliating when they refuse. Employers may still access employer-provided devices and accounts, investigate specific reports of misconduct or data leaks, monitor their own networks, and view public information.
Employee Personnel and Medical Files
CT Personnel Files ActJurisdiction: Connecticut
Authority: Connecticut Labor Commissioner (investigations and subpoenas, 31-128j)
Gives current and former employees the right to inspect and copy their personnel files and medical records, requires medical records to be kept separately, and forbids employers from disclosing identifiable personnel or medical file information to outsiders without written authorization, subject to listed exceptions. Participation in employee assistance programs is also confidential.
Employee photographs and fingerprints furnished to third parties
Lab. Code 1051Jurisdiction: California
Authority: Local prosecutors
Makes it a misdemeanor to require employees or applicants, as a condition of employment, to be photographed or fingerprinted for the purpose of furnishing the images or prints to another employer or third party where they could be used to the worker's detriment. Often cited in biometric timekeeping cases.
Employee social media account privacy
OK Social Media Password LawJurisdiction: Oklahoma
Effective: 11/1/2014
Authority: Private civil actions by employees and applicants
Bars Oklahoma employers from requiring employees or applicants to hand over personal social media usernames and passwords or to open private accounts in front of the employer, and from retaliating or refusing to hire over a refusal. Employers keep access to employer-provided devices and accounts and may investigate specific reports of misconduct or data leaks.
Employee Social Media Privacy
RI Employee Social Media Privacy ActJurisdiction: Rhode Island
Authority: Courts via employee or applicant civil actions
Bars employers from requiring or asking employees and job applicants for passwords to personal social media accounts, from making them log in while the employer watches, from forcing them to add the employer as a contact or change privacy settings, and from punishing or refusing to hire anyone who says no.
Employer Access to Employees' and Applicants' Personal Online Accounts
CT Social Media Password LawJurisdiction: Connecticut
Authority: Connecticut Labor Commissioner
Bars employers from requiring employees or job applicants to hand over passwords to personal online accounts, log in in front of them, or connect with them on social media, and from retaliating against those who refuse. Employer-provided accounts and devices and specific-information investigations are excepted.
Employer access to employees' personal online accounts
Colorado social media password lawJurisdiction: Colorado
Effective: 5/11/2013
Authority: Colorado Department of Labor and Employment (8-2-127(5))
Colorado employers may not ask or require employees or applicants to disclose usernames or passwords for personal online accounts on personal devices, or to add the employer as a contact or change privacy settings, and may not retaliate for refusal. Limited exceptions cover securities and financial compliance investigations and investigations of unauthorized downloads of proprietary data.
Employer Access to Personal Social Media Accounts
MT Social Media Privacy (Employment)Jurisdiction: Montana
Effective: 10/1/2015
Authority: Private action by employee or applicant in small claims court
Montana employers may not require or ask employees or applicants for personal social media usernames or passwords, to open accounts in front of them, or to hand over account content. Narrow exceptions apply to specific workplace-misconduct, data-theft and regulatory investigations. A 2023 amendment also bars retaliation for lawful free speech on personal social media, subject to written policies and contracts.
Employer Access to Personal Social Media Accounts Prohibited
NJ Social Media Privacy (Employment) LawJurisdiction: New Jersey
Effective: 12/1/2013
Authority: New Jersey Commissioner of Labor and Workforce Development
New Jersey employers may not require or ask current or prospective employees to hand over usernames or passwords, or otherwise give access, to their personal social media accounts. Employers also may not retaliate against people who refuse or who report or oppose violations.
Employer Electronic Surveillance of Restrooms, Locker Rooms and Lounges; Recording of Contract Negotiations
CT Workplace Surveillance LimitsJurisdiction: Connecticut
Authority: Criminal prosecution
Forbids employers from using cameras or audio recording to monitor employees in areas meant for their health, comfort or belongings, such as restrooms, locker rooms and lounges, and bars either side from secretly recording employment contract negotiations without all parties' consent.
Employer Genetic Testing Restrictions
Nebraska Employment Genetic Testing LawJurisdiction: Nebraska
Authority: Not stated in the section
This 2001 law bars Nebraska employers, unless federal law requires otherwise, from requiring genetic tests or genetic information as a condition of employment or promotion and from hiring, firing, or classifying workers based on genetic information unrelated to job duties. Employees may voluntarily share health-related genetic information for workplace safety.
Employer restrictions on use of Social Security numbers
OK Employee SSN ProtectionJurisdiction: Oklahoma
Effective: 11/1/2004
Authority: Not specified in the section
Restricts how Oklahoma employers handle employee Social Security numbers: no public posting, no printing on access cards or mailed materials, and no transmission over the Internet without encryption or use as a sole website login. Employees may consent in writing to otherwise prohibited uses.
Employer testing restrictions (polygraph, breathalyzer, psychological stress, brain-wave and genetic tests)
ORS 659A.300Jurisdiction: Oregon
Authority: Oregon Bureau of Labor and Industries (ORS 659A.820); civil action under ORS 659A.885
Bars employers from subjecting workers or applicants to breathalyzer, polygraph, psychological stress, brain-wave or genetic tests, with narrow exceptions for consensual breath tests (or required tests on reasonable suspicion), consensual polygraphs in legal proceedings, and consented genetic tests for a bona fide occupational qualification.
Employer use of credit history restricted
ORS 659A.320Jurisdiction: Oregon
Authority: Oregon Bureau of Labor and Industries; civil action under ORS 659A.885
Bars most employers from obtaining or using consumer credit report information to make hiring, firing, promotion, pay or other employment decisions, unless an exception applies.
Employer Use of Credit Reports
CT Employer Credit Check LawJurisdiction: Connecticut
Authority: Connecticut Labor Commissioner; Attorney General collects penalties
Prohibits employers from requiring employees or applicants to consent to a credit report as a condition of employment unless the employer is a financial institution, the report is legally required, the employer suspects job-related illegal conduct, or the report is substantially related to the job.
Employer use of genetic information prohibited
ORS 659A.303Jurisdiction: Oregon
Authority: Oregon Bureau of Labor and Industries (ORS 659A.820)
Makes it an unlawful employment practice to seek, obtain or use genetic information about a worker, applicant or their blood relative to discriminate or deny any job right or benefit.
Employer Use of Social Media
DE Employee Social Media PrivacyJurisdiction: Delaware
Effective: 8/7/2015
Authority: Not specified in the section
Bars Delaware employers from demanding access to employees' or applicants' personal social media, such as asking for passwords, requiring them to log in in front of the employer, or requiring them to add the employer as a contact. Employers may still investigate misconduct, access employer-provided devices and accounts, and view public information.
Employer Use of Social Security Numbers
Nebraska Employee SSN Protection LawJurisdiction: Nebraska
Effective: 9/1/2008
Authority: County attorneys (criminal prosecution)
Enacted in LB674 (2007), this law restricts how Nebraska employers display and use employees' Social Security numbers. Employers may not post or share more than the last four digits publicly or with coworkers, use full SSNs as employee IDs or unsecured web logins, or keep them in unrestricted files.
Employer Vehicle Tracking Device Notice Law
NJ Employee Vehicle Tracking LawJurisdiction: New Jersey
Effective: 4/18/2022
Authority: New Jersey Commissioner of Labor and Workforce Development
New Jersey employers must give employees written notice before knowingly using a tracking device in a vehicle the employee uses. Federal motor carrier rules on electronic devices are not displaced.
Employment Based on Credit Information; Prohibitions
VT Employment Credit Check LawJurisdiction: Vermont
Authority: Vermont Attorney General or State's Attorneys (21 V.S.A. § 495b)
Bars most Vermont employers from asking about or basing employment decisions on an applicant's or employee's credit report or credit history. Exempt employers may not use credit as the sole factor, and must get written consent, explain adverse actions and keep reports confidential.
Employment Opportunity Act (employer use of consumer credit information)
Colorado Employment Opportunity ActJurisdiction: Colorado
Effective: 7/1/2013
Authority: Colorado Department of Labor and Employment, Division of Labor Standards and Statistics (8-2-126(6))
Colorado employers may use consumer credit information for hiring or other employment decisions only when it is substantially related to the job, and may not require consent to a credit report except for banks, legally required reports, or disclosed bona fide job-related purposes. Employees must be told if credit information was the basis of an adverse action.
Ensuring Likeness, Voice, and Image Security Act of 2024 (formerly Personal Rights Protection Act of 1984)
ELVIS ActJurisdiction: Tennessee
Authority: Private civil actions in chancery or circuit court; criminal prosecution for unauthorized commercial use
Tennessee's right-of-publicity statute gives every individual a property right in the use of their name, photograph, voice, and likeness. The 2024 ELVIS Act added voice (including simulated or AI-generated voice) as a protected right and created liability for publishing unauthorized voice or likeness replicas and for distributing tools whose primary purpose is cloning a particular person. Rights survive death and pass to heirs, subject to First Amendment fair-use exceptions.
Event Data Recording Devices in Motor Vehicles
NH Event Data Recorder LawJurisdiction: New Hampshire
Effective: 7/1/2006
Authority: New Hampshire Attorney General (under RSA 358-A)
Requires manufacturers to disclose event data recorders in the owner's manual and makes the recorder and its data (speed, location, braking, seatbelt use, crash transmissions) the property of the vehicle owner. Others may retrieve the data only with owner consent, a court order, for servicing, or for emergency medical response; subscription services must disclose recording in their terms instead.
Fabricated Media in Campaign Communications (election deepfake disclosure)
IN Election Deepfake DisclosureJurisdiction: Indiana
Effective: 3/12/2024
Authority: Private civil action by the depicted candidate
Enacted by HEA 1133 (2024), this chapter requires campaign ads with AI-generated or deceptively altered audio, images, or video of a candidate to carry a disclaimer that elements were 'digitally altered or artificially generated.' Candidates depicted in unlabeled fabricated media may sue.
Facial recognition in job interviews
MD Facial Recognition Interview LawJurisdiction: Maryland
Effective: 10/1/2020
Authority: Not specified in § 3-717
Enacted by 2020 Md. Laws ch. 446 (HB 1202), this law bars employers from using facial recognition services to create a facial template during a job interview unless the applicant consents by signing a plain-language waiver.
Fair Price Protection Act (surveillance pricing of groceries)
NJ Fair Price Protection ActJurisdiction: New Jersey
Effective: 8/1/2027
Authority: New Jersey Attorney General / Division of Consumer Affairs (Consumer Fraud Act and a separate Attorney General civil action)
Signed July 23, 2026, this law bars retailers from using algorithms fed by personal data (including location, online activity, purchase history, biometric monitoring, or in-store sensors) to set individualized prices for groceries and household essentials. Cost-based price differences, publicly disclosed group discounts, and opt-in loyalty programs with uniform terms remain allowed. It also imposes a one-year moratorium on new electronic shelf labels.
False or Misleading Commercial Electronic Mail Messages
MN Commercial Email LawJurisdiction: Minnesota
Effective: 3/1/2003
Authority: Injured recipients and email service providers by civil action; Attorney General remedies under 8.31 also preserved (325F.694, subd. 7)
Prohibits commercial email that spoofs a third party's domain, misrepresents its origin or path, or has a false or misleading subject line, and requires unsolicited commercial email to start the subject line with 'ADV' ('ADV-ADULT' for adult content) and to offer a toll-free number or return address for opt-outs. By its own terms the section expires when federal law preempting state regulation of such email takes effect; the federal CAN-SPAM Act (2003) preempts state email laws except those addressing falsity or deception, so the labeling and opt-out requirements are likely unenforceable while the anti-falsity provisions remain.
Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006
Nebraska Data Breach Notification and Data Security ActJurisdiction: Nebraska
Effective: 7/14/2006
Authority: Nebraska Attorney General
Nebraska's breach law requires businesses and government entities that own or license computerized personal information to investigate a breach promptly and, if misuse has occurred or is reasonably likely, to notify affected residents and the Attorney General. Since 2018 it also requires reasonable security procedures, including for disposal, and contracts requiring vendors to safeguard the data. Notice to the Attorney General and the username/email-and-password element were added by LB835, effective July 21, 2016.
Financial Privacy Act
OK Financial Privacy ActJurisdiction: Oklahoma
Authority: Courts (customer motions to quash); supervisory agencies
Protects the confidentiality of bank and credit union customer records against disclosure to Oklahoma government authorities. An institution may release a customer's records to state government only with the customer's written consent for the specific record or in response to a lawful subpoena, and the customer must receive a copy and may move to quash. A 2026 amendment (SB 2067, effective November 1, 2026) adds a disclosure exception for reporting suspected financial exploitation of protected adults.
Financial Records Privacy Act
Tenn. FRPAJurisdiction: Tennessee
Authority: Courts (subpoena requirements); no enforcing agency identified in the reviewed sections
Prohibits financial institutions from disclosing a customer's financial records to anyone other than the customer or the customer's agent unless the customer authorizes it or a subpoena meeting the act's requirements is served. Listed exceptions cover supervisory examinations, tax reporting, credit information exchanges, anonymized data, suspected-crime reports to government, and (since October 1, 2024) records given to the TBI about suspected elder financial exploitation.
Fingerprinting in connection with business transactions
VA fingerprint returnJurisdiction: Virginia
Effective: 7/1/1999
Authority: Not stated in the section
Virginia's only general biometric-type rule for businesses: unless the parties agree otherwise, anyone who requires fingerprints in a business transaction must return or destroy the prints and all copies, including electronic copies, within 21 days after the transaction ends. Virginia has no BIPA-style biometric privacy statute; biometric data used to identify a person is otherwise 'sensitive data' under the VCDPA.
Florida Consumer Collection Practices Act: Privacy-Related Prohibited Practices
FCCPAJurisdiction: Florida
Authority: Florida Office of Financial Regulation; private plaintiffs
Florida's debt collection law, which covers creditors as well as collection agencies. Several of its rules protect debtor privacy: limits on contacting employers, on disclosing debts to third parties, on publishing 'deadbeat lists' or using embarrassing envelopes, and a ban on contacting debtors between 9 p.m. and 8 a.m. without consent (revised in 2025 to exempt e-mails that otherwise comply).
Florida Digital Bill of Rights
FDBRJurisdiction: Florida
Effective: 7/1/2024
Authority: Florida Department of Legal Affairs (Attorney General), exclusively (501.72(1))
Florida's comprehensive privacy law, enacted in SB 262 (2023). Unlike most state privacy laws, its core consumer-rights duties reach only very large companies (over $1 billion in revenue plus an ad-revenue, smart-speaker, or app-store test), but its rule against selling sensitive data without consent applies to for-profit businesses of any size. It also bars devices from surveilling users through voice, facial, video, or audio features when not in active use, and requires search engines to disclose ranking parameters, including political prioritization. The Attorney General's first enforcement action, against Roku (filed October 2025), was resolved in June 2026 with Roku committing to child-protection changes estimated at $25 million and no civil fine.
Florida Electronic Health Records Exchange Act: Offshore Storage Restriction and Emergency Release
Florida EHR Data Localization LawJurisdiction: Florida
Effective: 7/1/2023
Authority: Florida Agency for Health Care Administration
Added by SB 264 (2023, ch. 2023-33), this subsection requires providers using certified EHR technology to keep all patient information stored offsite, including with cloud vendors, physically in the continental United States, its territories, or Canada. It adds to the HIPAA Security Rule.
Florida Information Protection Act of 2014
FIPAJurisdiction: Florida
Effective: 7/1/2014
Authority: Florida Department of Legal Affairs (Attorney General)
Florida's data breach and data security law. It requires businesses to reasonably secure electronic personal information and dispose of customer records securely, and to notify affected Floridians and, for breaches affecting 500 or more Floridians, the Attorney General, within 30 days. Personal information includes biometric data and geolocation (added by SB 262, effective July 1, 2024).
Florida Telemarketing Act
Florida Telemarketing ActJurisdiction: Florida
Authority: Florida Department of Agriculture and Consumer Services; state attorneys (criminal); private plaintiffs
Licenses commercial telemarketers and sets conduct rules. Since 2021 it limits solicitation calls to 8 a.m. to 8 p.m. in the called person's time zone, caps them at three calls in 24 hours on the same subject, and bars blocking or spoofing caller ID. Those call-conduct rules apply even to sellers otherwise exempt from the Act.
Florida Telephone Solicitation Act (including the 'mini-TCPA' autodialer rule)
FTSAJurisdiction: Florida
Authority: Florida Department of Agriculture and Consumer Services; Department of Legal Affairs; private plaintiffs
Florida's telemarketing privacy law, which includes the state do-not-call list and, since 2021, a 'mini-TCPA' requiring prior express written consent for autodialed or prerecorded sales calls and texts. HB 761 (2023) narrowed the autodialer definition and added a pre-suit 'STOP' notice for text claims. Calls to Florida area codes are presumed to reach Florida residents.
Fraudulent Electronic Misrepresentation (anti-phishing)
MT Anti-PhishingJurisdiction: Montana
Effective: 10/1/2007
Authority: Attorney General or county attorney (criminal); private plaintiffs (civil)
Montana's anti-phishing law makes it identity theft to use a website, email or other internet means to trick people into giving up personal information by pretending to be another person or business. Victims, including impersonated website and trademark owners, can sue.
Fraudulent Use of Deepfakes (criminal offense and civil action)
NH Deepfake LawJurisdiction: New Hampshire
Effective: 1/1/2025
Authority: State prosecutors (criminal); injured individuals (civil)
Criminalizes knowingly making or spreading AI-altered video, audio or other media of a real, identifiable person to harm, harass, defame, entrap or extort them, and lets the person depicted sue for damages. Platforms hosting third-party content, news reports that flag authenticity doubts, and satire are exempt.
Freedom from Unwarranted Surveillance Act (drones)
Florida Drone Surveillance LawJurisdiction: Florida
Authority: Private civil actions (for private-property surveillance); courts
Mainly limits police drone use, but it also bars any person from using a camera drone to record privately owned property or the people on it with intent to conduct surveillance in violation of their reasonable expectation of privacy, without written consent. People are presumed to have that expectation on private property when they cannot be seen from ground level.
Generative AI in patient communications (AB 3030)
AB 3030Jurisdiction: California
Effective: 1/1/2025
Authority: Medical Board of California, Osteopathic Medical Board, and California Department of Public Health (licensing enforcement)
Requires health care providers that use generative AI to write or speak to patients about clinical information to say so and to tell patients how to reach a human, unless a licensed provider reviewed the message first.
Generative Artificial Intelligence Training Data Transparency (AB 2013)
AB 2013Jurisdiction: California
Effective: 1/1/2025
Authority: Not specified in the title (general state enforcement)
Requires developers of generative AI systems available to Californians to post documentation on their websites summarizing the datasets used to train the system, including whether the data contain personal information or copyrighted material, where it came from, and how it was processed.
Genetic Data Privacy (direct-to-consumer genetic testing companies)
VA Genetic Data PrivacyJurisdiction: Virginia
Effective: 7/1/2023
Authority: Virginia Attorney General (exclusive, 59.1-601(A))
Regulates direct-to-consumer genetic testing companies. They must publish plain-language privacy summaries, get separate express consent for each use, sample storage, secondary use, third-party transfer, and genetic-data-based marketing, honor consent revocation within 30 days, secure the data, and let consumers access and delete it. Disclosure to insurers or employers requires express consent.
Genetic Discrimination (consumer genetic testing)
IN Genetic Testing NondiscriminationJurisdiction: Indiana
Effective: 5/6/2025
Authority: Not specified in the chapter
Enacted alongside the consumer genetic testing chapter, this law bars discrimination against a person for using consumer genetic testing services or because of the results. It covers denying goods or services, charging different rates, or suggesting either will happen.
Genetic Discrimination Act (insurance)
MN Genetic Discrimination ActJurisdiction: Minnesota
Authority: Commissioner of Commerce, or Commissioner of Health for health plan companies it regulates (72A.139, subds. 2(a), 8)
Bars health plan companies from requiring or asking about genetic tests of applicants or their relatives, or using test results or refusals, in underwriting. Life insurers that require genetic tests must obtain written informed consent, notify the person of results, and pay for the test.
Genetic Information (informed consent and confidentiality)
DE Genetic Privacy LawJurisdiction: Delaware
Effective: 7/17/1998
Authority: Superior Court (fines) and the affected individual (civil damages) (1208)
Requires written informed consent before anyone obtains, keeps, or discloses a person's identifiable genetic information, requires prompt destruction of samples unless an exception applies, and gives individuals the right to see and correct their genetic records. Exceptions cover criminal and death investigations, paternity, court orders, the state DNA database, newborn screening, and anonymous research.
Genetic Information Amendments (genetic sequencing data and foreign adversaries)
Utah H.B. 182 (2026)Jurisdiction: Utah
Authority: Utah Attorney General (receives sworn compliance statements)
Bars medical and genomic research facilities from using genetic sequencers or software from foreign adversaries and from storing genetic sequencing data inside a foreign adversary. It requires encryption and access controls and sworn compliance statements to the Attorney General by December 31, 2028.
Genetic Information and Automated Decision Tools in Employment (Fair Employment Practices Act)
CT Employment Genetic InfoJurisdiction: Connecticut
Authority: Connecticut Commission on Human Rights and Opportunities (CHRO); courts after release
Makes it a discriminatory employment practice to request or require genetic information from employees, applicants or union members, or to discriminate based on it. From October 1, 2026, P.A. 26-15 adds that using an automated employment decision technology is no defense to a discrimination complaint.
Genetic information and privacy in employment
LA Employment Genetic PrivacyJurisdiction: Louisiana
Authority: Louisiana Commission on Human Rights; private civil actions under the Louisiana Employment Discrimination Law
Prohibits employment discrimination based on protected genetic information or requests for genetic services, bars employers from requiring, collecting, or buying employees' genetic information (with limited exceptions such as post-offer requests), and restricts disclosure. Genetic information must be kept as a confidential medical record separate from personnel files.
Genetic Information Consent Requirement
MN Genetic Information (13.386)Jurisdiction: Minnesota
Authority: Remedies under the Minnesota Government Data Practices Act, chapter 13 (see 325F.995, subd. 6)
Requires written informed consent before anyone, whether a government entity or any other person, collects genetic information about an individual, and limits its use, storage period, and dissemination to what the individual consented to. Dissemination consents must be signed and dated and generally last no more than one year. Genetic information held by government is private data.
Genetic information disclosure protections and Genetic Research Studies Nondisclosure Act
OK Genetic Disclosure LawsJurisdiction: Oklahoma
Effective: 7/1/1998
Authority: Courts (subpoena and discovery limits)
Shields genetic information from compelled disclosure in judicial, legislative, or administrative proceedings except in listed situations (paternity, the person's own claims, insurance disputes, law enforcement or fraud). Research records of genetic study subjects are confidential, not subject to civil discovery, and may not go to employers or health insurers without informed consent.
Genetic Information for Insurance Purposes
Florida Insurance Genetic Privacy LawJurisdiction: Florida
Authority: Florida Office of Insurance Regulation
Florida extended its genetic nondiscrimination rule from health insurance to life and long-term care insurance in 2020. Covered insurers cannot use genetic test results, absent a diagnosis, to cancel, limit, or deny coverage or set rates, and cannot require or solicit genetic information for any insurance purpose.
Genetic Information in Employment (Labor Code Subchapter H)
Texas Employment Genetic PrivacyJurisdiction: Texas
Effective: 9/1/1997
Authority: Texas Workforce Commission civil rights division (unlawful employment practices under ch. 21); Texas Attorney General (disclosure penalty)
Bars employers, unions, and employment agencies from discriminating based on genetic information or refusal to take a genetic test, makes genetic information confidential and privileged, and gives tested individuals a right to their results. Samples must be destroyed once their purpose is accomplished, with limited exceptions.
Genetic information in employment (Maryland Fair Employment Practices Act)
MD FEPA genetic provisionsJurisdiction: Maryland
Authority: Maryland Commission on Civil Rights; civil action after administrative exhaustion
Maryland's employment discrimination law bars employers from discriminating based on genetic information or an individual's refusal to take a genetic test or share results, and from requesting or requiring genetic tests or genetic information as a condition of hiring or benefits.
Genetic information in health insurance
Colorado genetic information (health insurance)Jurisdiction: Colorado
Effective: 7/1/2009
Authority: Colorado Commissioner of Insurance (Division of Insurance); private suits
Genetic information, including family history and genetic test results, is confidential and privileged in Colorado health insurance. Release for purposes other than diagnosis or treatment requires specific written consent, and health insurers may not seek, use, or keep genetic information for underwriting or require genetic tests.
Genetic information in insurance
ORS 746.135Jurisdiction: Oregon
Authority: Director of the Department of Consumer and Business Services
Requires specific written authorization before asking an insurance applicant to take a genetic test, bars using genetic information in health coverage decisions, and bars using a blood relative's genetic information for any insurance decision.
Genetic Information in Insurance (genetic discrimination and DTC test data)
CT Insurance Genetic PrivacyJurisdiction: Connecticut
Authority: Connecticut Insurance Commissioner (Connecticut Unfair Insurance Practices Act)
Bars health insurers from refusing, limiting or pricing coverage based on genetic information, and bars life, disability, long-term care and similar insurers from using direct-to-consumer genetic test results without the tested person's informed written consent or requiring genetic testing as a condition of coverage.
Genetic information in insurance (health insurance genetic nondiscrimination and the Genetic Testing Protection Act)
MD Insurance Genetic ProtectionsJurisdiction: Maryland
Authority: Maryland Insurance Commissioner (27-909(f), 27-909.1(d))
Health insurers may not use genetic tests or genetic information to deny, limit, or price coverage, may not require genetic tests to decide coverage, and may not release identifiable genetic information outside the plan and its providers without authorization. The 2025 Genetic Testing Protection Act adds that life and disability insurers may not access genetic data or other sensitive medical information without signed written consent or require genetic testing for eligibility.
Genetic Information Privacy Act
Nebraska GIPAJurisdiction: Nebraska
Effective: 7/19/2024
Authority: Nebraska Attorney General
Enacted by LB308 (2024), this law regulates consumer DNA testing companies. It requires privacy notices, layered express consent for uses, transfers, sample retention, research, and marketing, a comprehensive security program, and consumer rights to access and delete genetic data and have samples destroyed.
Genetic Information Privacy Act
GIPAJurisdiction: California
Effective: 1/1/2022
Authority: California Attorney General, district attorneys, and specified city attorneys; also on complaint of a person who suffered injury and lost money or property
Regulates direct-to-consumer genetic testing companies. It requires plain-language privacy notices, separate express consent for each use, storage, transfer, and marketing use of genetic data or samples, reasonable security, and ways for consumers to access and delete data and have samples destroyed. It also bars sharing genetic data with health, life, disability, or long-term care insurers or employers.
Genetic Information Privacy Act
Tenn. GIPAJurisdiction: Tennessee
Effective: 7/1/2023
Authority: Division of Consumer Affairs, Office of the Tennessee Attorney General and Reporter (complaints and rulemaking)
Regulates direct-to-consumer genetic testing companies. They must give clear notice of their genetic data practices, get express consent to collect and use genetic data, get separate consent for third-party transfers, secondary uses, sample retention, and genetic-data-based marketing, and let consumers access and delete their data and have samples destroyed. Disclosure to insurers or employers needs written consent, and law enforcement access requires valid legal process.
Genetic Information Privacy Act
VT GIPAJurisdiction: Vermont
Effective: 7/1/2026
Authority: Vermont Attorney General (Consumer Protection Act); consumers
Vermont's 2026 genetic privacy law requires direct-to-consumer genetic testing companies to publish plain-language privacy terms, get separate express consent for each use, storage or transfer of genetic data and samples, protect the data, and let consumers access and delete data and destroy samples. It bans disclosing genetic data to insurers or employers, and requires a warrant or the consumer's consent before disclosure to the government.
Genetic Information Privacy Act (direct-to-consumer genetic testing)
RI GIPAJurisdiction: Rhode Island
Effective: 6/19/2026
Authority: Rhode Island Attorney General (exclusive)
Enacted in June 2026 and effective on passage, this law regulates consumer genetic testing companies such as ancestry and health DNA services. They must publish plain-language privacy information, get separate express consent for each use, storage, transfer and genetic-based marketing, let consumers access and delete data and destroy samples, secure genetic data, and not share it with insurers or employers.
Genetic Information Privacy Act (including 2025 neurotechnology data amendments)
MT GIPAJurisdiction: Montana
Effective: 10/1/2023
Authority: Montana Attorney General (sole authority; 30-23-106(1))
Montana's direct-to-consumer genetic privacy law requires consent, notice, security and consumer control over genetic data and biological samples. A 2025 amendment (SB 163) extended every protection to neurotechnology (neural) data, making Montana one of the first states to regulate neural data this way. It also bars storing covered data in sanctioned or foreign-adversary countries and requires consent to store it outside the United States.
Genetic Information Privacy Act (Part 1) and Genetic Testing and Procedure Privacy Act (Part 2)
Utah GIPAJurisdiction: Utah
Effective: 5/5/2021
Authority: Utah Attorney General
Part 1 regulates direct-to-consumer genetic testing companies: public privacy notice, express consent for use and sharing, separate consent for transfers, secondary uses, sample retention and marketing, and consumer access and deletion. Part 2 restricts employer and health-insurer use of genetic testing information and carries a private right of action.
Genetic information privacy in health insurance
VA insurance genetic privacyJurisdiction: Virginia
Effective: 7/1/1996
Authority: State Corporation Commission, Bureau of Insurance
Bars health insurers, health plans, and HMOs from using genetic information, or a request for genetic services, to deny, limit, cancel, condition, exclude, rate, or add waiting periods or riders to coverage, and bars agent commission differences based on genetic characteristics.
Genetic Nondiscrimination in Employment Act
OK Genetic Employment ActJurisdiction: Oklahoma
Effective: 7/1/1998
Authority: District attorneys (criminal prosecution)
Prohibits employers from seeking, using, or requiring genetic tests or genetic test results to distinguish between, discriminate against, or restrict the rights of employees or job applicants, other than for insurance coverage determinations.
Genetic Nondiscrimination in Insurance Act
OK GNIAJurisdiction: Oklahoma
Effective: 7/1/1998
Authority: Oklahoma Insurance Commissioner
Bars health insurers from using genetic information (including family history and requests for genetic services) to deny, condition, or price coverage, and from requesting, requiring, or purchasing genetic information for underwriting or before enrollment. Insurers may not require genetic tests, with a narrow voluntary research exception.
Genetic Screening or Testing (health insurance)
IN Insurance Genetic TestingJurisdiction: Indiana
Effective: 1/1/1998
Authority: Indiana Insurance Commissioner (IC 27-8-26-10)
Indiana bars health insurers and HMOs from requiring genetic tests, asking about genetic test results, or using those results to deny, cancel, limit, or price coverage. Favorable results that an applicant volunteers may be considered.
Genetic Sequencing Foreign Adversary Restrictions
Nebraska Genetic Sequencing Security LawJurisdiction: Nebraska
Effective: 10/1/2025
Authority: Not stated in these sections
Enacted in LB644 (2025), this law bars Nebraska medical and research facilities from using genetic sequencers or sequencing software produced by foreign adversaries (as listed in 15 C.F.R. 791.4) or their state-owned or domiciled businesses, and requires existing equipment to be disabled or removed. Genetic sequencing data used in Nebraska may not be stored in, or remotely accessed from, a foreign adversary country.
Genetic Test Protections in Health and Disability Insurance
KY Insurance Genetic TestingJurisdiction: Kentucky
Effective: 4/10/1998
Authority: Kentucky Department of Insurance (Commissioner)
Bars health plans and insurers from denying, cancelling, refusing to renew, or re-pricing coverage based on a genetic test for an unmanifested condition or on use of genetic services. Health and disability insurers may not ask applicants or members to disclose genetic test results, and health insurers may not disclose a member's genetic test without separate prior authorization for each disclosure.
Genetic Testing
NH Genetic Testing LawJurisdiction: New Hampshire
Effective: 1/1/1996
Authority: Courts, through individual civil actions
Requires prior written informed consent before genetic testing and before disclosing that someone was tested or the results, with narrow exceptions (paternity, newborn screening, criminal investigations, medical examiner, clinical care). It bars employers and licensing bodies from requiring or using genetic tests and bars health insurers from requesting, requiring or rating on genetic test information.
Genetic Testing (employment, consent, and health insurance protections)
Iowa Genetic Testing LawJurisdiction: Iowa
Effective: 7/1/1992
Authority: Civil actions by aggrieved individuals; injunctions may also be sought by the county attorney or Attorney General; the Commissioner of Insurance for the insurance provisions (unfair insurance trade practice under 507B.4)
Iowa bans employers, employment agencies, unions, and licensing agencies from requiring or administering genetic tests or taking action based on them, and requires informed written consent before anyone obtains genetic samples or tests, collects, keeps, shares, or uses genetic information, with limited exceptions. Health insurers may not release genetic information without written authorization or use it for underwriting.
Genetic Testing and Genetic Information in Health Insurance
RI Health Insurance Genetic PrivacyJurisdiction: Rhode Island
Authority: Rhode Island Department of Business Regulation / Office of the Health Insurance Commissioner
Parallel provisions across Rhode Island's health insurance chapters forbid health insurers, hospital and medical service corporations and HMOs from using genetic tests or genetic information in coverage, pricing or eligibility decisions, from requiring or asking about genetic tests, and from releasing genetic results without the person's written authorization for each disclosure.
Genetic Testing as a Condition of Employment
RI Employment Genetic Testing LawJurisdiction: Rhode Island
Authority: Courts via employee or applicant civil actions
Bars employers, employment agencies and licensing agencies from requiring or administering genetic tests, from penalizing workers or applicants who refuse to take a test, give family health history or reveal results, and from using or revealing genetic information against them.
Genetic testing for cancer predisposition in health benefit plans
AL Cancer Genetic Test Insurance LawJurisdiction: Alabama
Authority: Alabama Commissioner of Insurance
Bars health benefit plans from requiring a genetic test for cancer predisposition as a condition of coverage, and from using such test results to decide insurability or to discriminate in rates or benefits. It is narrow: it covers only genetic tests showing a predisposition to cancer.
Genetic Testing in Employment
MN Employment Genetic TestingJurisdiction: Minnesota
Authority: Private civil action by aggrieved persons (181.974, subd. 3)
Prohibits employers and employment agencies from administering genetic tests, or requesting, requiring, or collecting genetic information about a person or the person's blood relatives, as a condition of employment, and from basing employment decisions on such information. Third parties may not supply or interpret that information for employers.
Genetic testing in group disability, long-term care, life, and individual disability insurance
Colorado genetic testing (other insurance)Jurisdiction: Colorado
Effective: 6/2/1994
Authority: Colorado Commissioner of Insurance (Division of Insurance); private suits
Genetic test information is confidential and privileged and may be released for non-treatment purposes only with written consent. Group disability and long-term care insurers may not use it for underwriting, and life and individual disability insurers need specific written informed consent before requiring or performing a genetic test.
Genetic testing or genetic characteristics as a condition of employment
VA employer genetic testingJurisdiction: Virginia
Effective: 7/1/2002
Authority: Employees by private action (the Department of Labor and Industry is not required to investigate) (40.1-28.7:1(B)-(C))
Bars employers from requesting, requiring, or administering genetic tests as a condition of employment and from taking adverse employment action based solely on a genetic characteristic or genetic test result, however obtained.
Genetic Testing Protections
VT Genetic Testing LawJurisdiction: Vermont
Effective: 1/1/1999
Authority: Courts (private actions); criminal prosecution; Department of Financial Regulation for insurance (8 V.S.A. § 4724)
Bars compulsory genetic testing except in listed cases such as parentage, newborn screening, criminal investigations and the DNA data bank. Genetic testing needs prior written informed consent, and results may be disclosed only with written authorization. Employers, unions, licensing bodies and insurers may not require or use genetic tests or genetic information.
Genetic Testing; Express Consent; Confidentiality (DNA analysis)
Florida Genetic Privacy LawJurisdiction: Florida
Authority: State attorneys (criminal penalties under s. 817.5655)
Requires express consent before anyone performs DNA analysis on a person, and makes the results the tested person's exclusive property, confidential, and not disclosable without express consent. Anyone who performs the analysis or receives results must tell the person and say whether the results were used in insurance, employment, lending, credit, or education decisions.
Genetics-Based Discrimination Prohibited (health insurance, life insurance and annuities)
DE Insurance Genetic NondiscriminationJurisdiction: Delaware
Authority: Delaware Insurance Commissioner
Bars insurers from discriminating in issuing, renewing, or pricing insurance based on genetic characteristics or genetic information. A 2024 law adds life insurance and annuity rules: no adverse decisions based solely on genetic test results outside the medical record, no requesting genetic tests, and no obtaining direct-to-consumer genetic testing data without written informed consent under 16 Del. C. § 1202.
Harassment by Nonconsensual Dissemination of Nude or Sexual Visual Depictions (including digitally created depictions)
Iowa Criminal NCII and Deepfake LawJurisdiction: Iowa
Authority: County attorneys and the Attorney General (criminal prosecution)
Iowa's harassment statute makes nonconsensual sharing of nude or sexual images a first-degree harassment crime. A 2024 amendment extends it to images that were created, adapted, or modified from a recognizable person's face or likeness, which covers AI-generated sexual deepfakes, and requires adult offenders to register as sex offenders.
Health and Location Data Privacy: family planning centers and geofencing health care providers
Health & Location Privacy (AB 45)Jurisdiction: California
Effective: 1/1/2026
Authority: California Attorney General; aggrieved persons and family planning centers
Prohibits collecting, using, selling, sharing, or keeping personal information of people at or within a precise geolocation (1,850-foot radius) of a family planning center except as needed to provide requested goods or services, and bans geofencing in-person health care providers to track, collect data from, notify, or advertise to patients or staff. AB 45 (2025) also shields identifiable health research records from out-of-state and law-enforcement demands tied to reproductive care.
Health Care Information Privacy Requirements for Providers Subject to HIPAA (including 2026 electronic health record result release)
MT HIPAA Provider Privacy LawJurisdiction: Montana
Effective: 10/1/2003
Authority: Private plaintiffs (50-16-817)
This part supplements HIPAA for Montana providers covered by it, setting state rules on disclosures (for example to workers' compensation insurers and law enforcement), compulsory process and fees. HB 590 (Ch. 694, L. 2025), effective July 1, 2026, bars information blocking by providers ordering lab tests and requires certain sensitive results, including genetic-marker tests and positive HIV tests, to be released in the patient's electronic health record within 72 hours of finalization unless released earlier.
Health facility reporting of unauthorized access to medical information
HSC 1280.15Jurisdiction: California
Effective: 1/1/2009
Authority: California Department of Public Health
Requires licensed health facilities to prevent unauthorized access to patients' medical information and to report any unlawful or unauthorized access, use, or disclosure to the Department of Public Health and to the affected patient within 15 business days of detection.
Health Insurance Carrier Encryption of Personal Information
NJ Health Carrier Encryption LawJurisdiction: New Jersey
Effective: 8/1/2015
Authority: New Jersey Attorney General / Division of Consumer Affairs (Consumer Fraud Act)
Health insurance carriers may not keep personal information (name plus SSN, driver's license number, address, or identifiable health information) on laptops, desktops, mobile devices, or removable media, or send it over public networks, unless it is encrypted or otherwise unreadable. Password protection alone is not enough.
Health insurance genetic information protections
LA Health Insurance Genetic PrivacyJurisdiction: Louisiana
Authority: Private civil actions; Louisiana Commissioner of Insurance
Bars health insurers from using genetic information, genetic services, or refusal of a genetic test to terminate, limit, or price coverage, and requires written informed consent before obtaining genetic information or a DNA sample. It declares an insured's genetic information the insured's property and forbids retaining it without authorization. Violations carry some of the largest statutory damages of any U.S. genetic privacy law.
Health Insurance Genetic Testing Prohibition
Nebraska Insurance Genetic Testing LawJurisdiction: Nebraska
Authority: Nebraska Department of Insurance
This 2001 law bars health insurers and non-preempted self-funded plans from requiring covered persons, dependents, or asymptomatic applicants to undergo genetic testing before issuing, renewing, or continuing coverage. Insurers may still ask about family history.
Health insurance utilization review: use of artificial intelligence
MD AI Utilization Review LawJurisdiction: Maryland
Effective: 10/1/2025
Authority: Maryland Insurance Commissioner
Enacted by 2025 Md. Laws ch. 747 (HB 820), this law sets guardrails on AI and algorithms used by health insurers and their review agents to decide whether care is medically necessary. Tools must rely on the individual patient's clinical information rather than group data alone, may not deny, delay, or modify care, must not discriminate, must be auditable by the Commissioner, and may not use patient data beyond its stated purpose. Carriers must also report whether AI was used in adverse decisions.
Health Records (patient access, confidentiality, and retention)
IN Health RecordsJurisdiction: Indiana
Authority: Indiana Department of Health (fines for access violations); professional licensing boards (retention); Department of Insurance (copy fee rules)
Indiana's health records article gives patients a right to copies of their records and sets confidentiality rules for mental health records. It requires written consents with specified content, limits providers' business use of records, and requires providers to keep records for seven years. Since July 1, 2025, providers may not charge for digital copies or interoperability access to electronic health records.
Health Records and Identifying Information Protection (abandoned records)
IN Abandoned RecordsJurisdiction: Indiana
Authority: Indiana Attorney General
When a health care provider or regulated professional abandons patient health records or other records containing personal information (including by treating them recklessly or negligently so strangers can reach them), the Attorney General may take, store, protect, and eventually destroy them. The AG notifies affected people and recovers costs from the provider.
Health records privacy
VA health records privacyJurisdiction: Virginia
Effective: 7/1/1997
Authority: Not stated in the section; enforced through health regulatory boards and courts
Recognizes an individual's right of privacy in the content of his or her health records and bars health care entities from disclosing them except as the section or other state law allows. Patients may obtain their records (with audit trails on request) and direct transfers to other providers, and recipients may not redisclose records beyond the authorized purpose without specific authorization.
Healthcare professional disclosure of AI transcription of patient encounters
LA AI Medical Transcription DisclosureJurisdiction: Louisiana
Effective: 8/1/2026
Authority: The professional's licensing board
Requires licensed healthcare professionals to tell patients out loud, before recording any part of an appointment or treatment, that a recording device, software, or service will be used and the recording transcribed by artificial intelligence. Violations are handled by licensing boards rather than lawsuits.
Healthier Social Media Use by Youth (social media warnings for minors)
HB 24-1136Jurisdiction: Colorado
Effective: 1/1/2026
Authority: Colorado Attorney General
HB 24-1136 would require large social media platforms, from January 1, 2026, to show users who say they are under 18 research-based pop-up information about social media's effects on youth after one hour of use in a day or when on between 10 p.m. and 6 a.m., repeating every 30 minutes. The U.S. District Court for Colorado preliminarily enjoined enforcement on November 6, 2025 in NetChoice v. Weiser on First Amendment compelled-speech grounds; the state appealed to the Tenth Circuit (No. 25-1456).
Higher Education Student Information Protection Act (AB 1159, 2026)
HESIPAJurisdiction: California
Effective: 7/1/2027
Authority: California Attorney General and local prosecutors; students actually harmed
Extends K-12-style student data protections to college and university students: limits on targeted advertising, profiling, sale, disclosure, and AI training using student data, plus security and deletion duties. Operative July 1, 2027.
HIV Testing and Counseling (consent and confidentiality)
DE HIV Test ConfidentialityJurisdiction: Delaware
Authority: Aggrieved persons in Superior Court; the Attorney General may also sue (718)
Sets consent rules for HIV testing (routine opt-out testing in clinical settings with notice and a chance to refuse; written informed consent in nonclinical settings; minors 12 and older may consent) and bars disclosure of the identity of anyone tested or of identifiable HIV-related test results except to listed recipients, including redisclosure by recipients.
HIV Testing Confidentiality and Anti-Discrimination
RI HIV Confidentiality LawJurisdiction: Rhode Island
Authority: Courts via private actions; Department of Health
Makes it unlawful to disclose a person's HIV test results to a third party without prior written consent, apart from listed reporting and treatment exceptions, and requires record holders to secure HIV information. It also requires advance notice to the person of certain permitted disclosures and bans HIV-based discrimination, including requiring HIV tests as a condition of employment.
HIV Testing Consent and Test Result Confidentiality
KY HIV ConfidentialityJurisdiction: Kentucky
Effective: 7/13/1990
Authority: Prosecutors (criminal penalty); Cabinet for Health and Family Services for public-health reporting
Requires informed consent before HIV testing (a general medical consent suffices if it tells the patient HIV testing may be ordered) and requires confirmatory testing before a positive result is revealed. Anyone who knows an HIV test result may not disclose the tested person's identity or identifiable results except to listed recipients such as the patient, persons named in a release, treating providers, and public health authorities.
HIV Testing for Insurance Act
DE HIV Testing for Insurance ActJurisdiction: Delaware
Authority: Delaware Insurance Commissioner
Requires insurers to get an applicant's prior written informed consent before HIV testing, and limits disclosure of applicants' HIV test results to the applicant's consent and narrow insurance purposes such as reinsurers and contracted medical personnel.
HIV Testing: Informed Consent and Confidentiality of Results
Florida HIV Test Confidentiality LawJurisdiction: Florida
Authority: Florida Department of Health; licensing boards; state attorneys
Requires informed consent for HIV testing and makes the identity of anyone tested, and their results, confidential. Results may be disclosed only to listed persons, and each authorized disclosure must carry a written warning against re-disclosure.
HIV-Related Test Confidentiality
Iowa HIV Confidentiality LawJurisdiction: Iowa
Authority: Aggrieved individuals (civil action); Iowa Attorney General (civil enforcement)
Iowa treats HIV-related test information as strictly confidential medical information. Test results may be released only to the person tested, to people with the subject's written release, to treating providers and staff with a medical need to know, to public health authorities, and under narrow court orders that use pseudonyms and weigh privacy interests.
Hospital and health center protection of immigration status and country-of-birth information
SB 1570 (2026)Jurisdiction: Oregon
Effective: 6/5/2026
Authority: Not specified in the act
Requires hospitals and federally qualified health centers to protect patients' citizenship, immigration status and country-of-birth information the same way as protected health information, and bars disclosing it for law enforcement purposes unless law or a court order requires. The act also requires hospitals to adopt policies for responding to law enforcement visits.
Hospital Patient Records; Confidentiality
Florida Hospital Records LawJurisdiction: Florida
Authority: Florida Agency for Health Care Administration
The facility-level counterpart to the practitioner records law. Licensed hospitals must give patients copies of their records after discharge on written request, and must keep patient records confidential unless the patient or representative consents or a listed exception applies.
Human Immunodeficiency Virus Education, Prevention, and Control (HIV testing confidentiality)
NH HIV Confidentiality LawJurisdiction: New Hampshire
Effective: 4/30/1988
Authority: NH Department of Health and Human Services; prosecutors; individual civil suits
Requires consent for HIV testing (with limited exceptions) and keeps the identity of people tested and their results confidential. Any entity, public or private, holding HIV test information must protect it from unwarranted disclosure, and it may be shared only with written authorization or in narrow clinical, blood-supply and public-health situations.
Identity Deception (criminal identity theft)
IN Identity DeceptionJurisdiction: Indiana
Authority: County prosecutors; the Attorney General's Identity Theft Unit assists victims (IC 4-6-13)
Indiana's core identity theft crime covers obtaining, possessing, transferring, or using someone's identifying information, with intent to harm or defraud, to pose as that person. It is the offense referenced by the breach notification law's risk-of-harm trigger and by the identity theft victim protections in IC 24-5-26.
Identity fraud: artificial intelligence and deepfake representations
MD AI Deepfake Identity Fraud LawJurisdiction: Maryland
Effective: 10/1/2026
Authority: State's Attorneys (criminal); victims (civil action)
Enacted by 2026 Md. Laws ch. 445 (SB 8), this amendment to Maryland's identity fraud statute makes it a crime to knowingly and fraudulently use AI or a deepfake to impersonate or falsely depict someone to cause harm, or to create false records to cause harm, obtain personal identifying information, or obtain something of value. It also lets victims sue for injunctive relief.
Identity theft
OK Identity Theft LawJurisdiction: Oklahoma
Effective: 5/3/1999
Authority: District attorneys (criminal); victims (civil action)
Criminalizes fraudulently obtaining or using another person's identifying information (name, SSN, date of birth, account and driver license numbers, and similar data) to obtain money, credit, or other benefits, and gives victims a civil damages action. Local law enforcement must take identity theft incident reports.
Identity Theft (civil remedies)
NH Identity Theft ActJurisdiction: New Hampshire
Effective: 1/1/2008
Authority: Victims through civil actions
Creates a civil cause of action against anyone who, with fraudulent intent and without permission, obtains, records, possesses or uses another person's personal information or financial device. Victims can use court orders or convictions to clear fraudulent accounts and judgments.
Identity Theft (duties to identity theft victims)
IN Identity Theft Victim ProtectionsJurisdiction: Indiana
Authority: Indiana Attorney General
This chapter protects identity theft victims: businesses may not deny credit or utility service, or cut credit limits, solely because a documented victim was defrauded. It also restricts unsolicited credit offers, such as convenience checks, that carry personal identifying information.
Identity Theft Enforcement and Protection Act (breach notification and sensitive personal information protection)
Texas Breach Notification LawJurisdiction: Texas
Effective: 4/1/2009
Authority: Texas Attorney General
Requires businesses to protect and properly destroy sensitive personal information and to notify affected individuals and, for breaches affecting 250 or more Texans, the attorney general. Notice to individuals is due within 60 days and to the attorney general within 30 days of determining that a breach occurred.
Identity Theft Impediments: Credit Card Address Changes
MT Credit Card ID Theft ImpedimentsJurisdiction: Montana
Effective: 10/1/2005
Authority: Montana Department of Justice, Office of Consumer Protection (Attorney General)
To curb identity theft, credit card issuers must verify address changes on returned card applications that differ from the solicitation address, and must send change-of-address notices to the old address when a replacement card is requested close to an address change.
Identity Theft Prevention Act: Credit Report Security Freeze and Identity Theft Victim Credit Protection
NJ Security Freeze LawJurisdiction: New Jersey
Effective: 1/1/2006
Authority: Consumers through private suits (56:11-50); Commissioner of Banking and Insurance for creditor penalties (56:11-52)
Consumers can place, lift, or remove a security freeze on their credit reports at New Jersey consumer reporting agencies, which must act within set deadlines and, since December 2018, may not charge any fee. Agencies must confirm changes to key identifying data while a freeze is in place, and creditors may not deny or cut credit solely because someone was an identity theft victim.
Identity Theft Prevention Act: Data Breach Notification
NJ Breach Notification LawJurisdiction: New Jersey
Effective: 1/1/2006
Authority: New Jersey Attorney General / Division of Consumer Affairs (Consumer Fraud Act); breaches are reported first to the Division of State Police
New Jersey's breach law requires businesses and public entities to notify New Jersey residents whose unencrypted personal information was, or is reasonably believed to have been, accessed by an unauthorized person, unless misuse is not reasonably possible. The New Jersey State Police must be notified before consumers, and consumer reporting agencies must be notified when more than 1,000 people are affected.
Identity Theft Prevention Act: Record Disposal and Social Security Number Protection
NJ SSN and Disposal LawJurisdiction: New Jersey
Effective: 1/1/2006
Authority: New Jersey Attorney General / Division of Consumer Affairs (Consumer Fraud Act)
Businesses and public entities must destroy customer records containing personal information so the data is unreadable when the records are no longer kept. Anyone is barred from publicly posting Social Security numbers (or four or more consecutive digits), printing them on mailings or access cards, or requiring their transmission or use online without security.
Identity theft victim rights (police reports and creditor records)
LA Identity Theft Victim LawJurisdiction: Louisiana
Authority: None specified
Lets identity theft victims file police reports with the Attorney General or local police where they live, and requires creditors that extended credit to an identity thief to give the victim the application and transaction records needed to undo the fraud, after the victim submits a signed statement, police report, and ID.
Identity Theft: Civil Cause of Action
Iowa Identity Theft Civil RemedyJurisdiction: Iowa
Authority: Victims and financial institutions (civil action)
Iowa gives identity theft victims who lose money a civil claim against the thief for the greater of $5,000 or triple damages, plus credit repair costs and attorney fees. Banks and insurers can sue on behalf of account holders.
Illinois Biometric Information Privacy Act
BIPAJurisdiction: Illinois
Effective: 10/3/2008
Authority: Private right of action
Max Fine: ,000-,000 per violation (private lawsuits)
Most aggressive US biometric privacy law. Requires informed written consent before collecting biometric identifiers. Private right of action has generated billions in settlements (Meta M, Google M, TikTok M).
Impersonation and Identity Fraud (including digital forgery)
RI Identity Fraud LawJurisdiction: Rhode Island
Authority: Prosecutors
Rhode Island's criminal identity fraud statute. It covers producing or trafficking false IDs, using another person's means of identification (including biometric data) or financial information to defraud, and impersonating a person or entity with intent to defraud. A 2026 amendment added 'digital forgery': creating or distributing AI-generated or other forged likenesses or voice recordings of real people to facilitate fraud.
Indiana Consumer Data Protection Act
INCDPAJurisdiction: Indiana
Effective: 1/1/2026
Authority: Indiana Attorney General (exclusive authority, IC 24-15-10-1)
Max Fine: Up to ,500 per violation
Indiana's comprehensive consumer privacy law, modeled on Virginia's, took effect January 1, 2026. It gives Indiana residents rights to confirm and access, correct, delete, and obtain a copy or representative summary of their personal data, and to opt out of targeted advertising, sale, and significant profiling. Controllers must get opt-in consent for sensitive data, publish a privacy notice, maintain reasonable security, and conduct data protection impact assessments for high-risk processing.
Information Security Program and Security Event Notification for Financial Services Licensees
RI Licensee Information Security LawJurisdiction: Rhode Island
Effective: 7/2/2025
Authority: Rhode Island Department of Business Regulation, Division of Banking (director)
Enacted in 2025 and modeled on the FTC Safeguards Rule, this law requires non-bank financial services licensees to keep a written, risk-based information security program for customer information, including encryption, multi-factor authentication, annual penetration testing, secure disposal and an incident response plan. Licensees must report qualifying security events to the Division of Banking within three business days.
Installation or Use of Tracking Devices or Tracking Applications
Florida Tracking Device LawJurisdiction: Florida
Authority: State attorneys (criminal)
Makes it a crime to knowingly install a tracking device or app on another person's property, or to use one to follow someone's location or movement, without consent. Consent is presumed revoked once a divorce petition or protective injunction is filed between the parties. Good-faith business use for a legitimate purpose is exempt.
Insurance Code Privacy Chapter (Gramm-Leach-Bliley implementation)
Texas Insurance Privacy LawJurisdiction: Texas
Effective: 4/1/2005
Authority: Texas Department of Insurance; Texas Attorney General after conferring with the Commissioner
Makes insurers and other TDI-authorized entities comply with the Gramm-Leach-Bliley Act's privacy notice and opt-out rules (15 U.S.C. 6802-6803) as if they were financial institutions, and directs the Commissioner to adopt privacy rules and safeguard standards.
Insurance Data Security
IN Insurance Data SecurityJurisdiction: Indiana
Effective: 7/1/2021
Authority: Indiana Insurance Commissioner / Department of Insurance
Indiana's version of the NAIC Insurance Data Security Model Law requires insurance licensees to run a written, risk-based information security program, oversee vendors, and keep an incident response plan. They must investigate cybersecurity events and notify the Insurance Commissioner within three business days of certain events. Consumer notice follows the general breach law, IC 24-4.9.
Insurance Data Security Act
DE Insurance Data Security ActJurisdiction: Delaware
Effective: 7/31/2019
Authority: Delaware Insurance Commissioner (8607, 8610)
Delaware's version of the NAIC model law requires insurance licensees to run a written, risk-based information security program, investigate cybersecurity events, and notify the Insurance Commissioner within 3 business days and affected consumers within 60 days. Domestic insurers must certify compliance to the Commissioner each year.
Insurance Data Security Act
OK IDSAJurisdiction: Oklahoma
Effective: 7/1/2024
Authority: Oklahoma Insurance Commissioner
Oklahoma's version of the NAIC Insurance Data Security Model Law. Insurance licensees must maintain a risk-based written information security program with an incident response plan and vendor oversight, investigate cybersecurity events, and notify the Insurance Commissioner within three business days of determining a qualifying event, while notifying consumers under the Security Breach Notification Act. It is the exclusive state data security law for licensees.
Insurance Data Security Act
Iowa Insurance Data Security ActJurisdiction: Iowa
Effective: 1/1/2022
Authority: Iowa Commissioner of Insurance (Iowa Insurance Division)
Iowa's version of the NAIC Insurance Data Security Model Law requires insurance licensees to run a risk-based written information security program, oversee third-party service providers, investigate cybersecurity events, and report qualifying events to the Insurance Commissioner within three business days. Consumer notice follows the general breach law in chapter 715C.
Insurance Data Security Law
AL IDSLJurisdiction: Alabama
Effective: 5/1/2019
Authority: Alabama Commissioner of Insurance (Department of Insurance)
Alabama's version of the NAIC Insurance Data Security Model Law. Insurance licensees must maintain a risk-based written information security program, oversee vendors, investigate cybersecurity events, and notify the Commissioner within three business days of qualifying events. They must also follow the state breach notification act for consumer notices.
Insurance Data Security Law
NH Insurance Data Security LawJurisdiction: New Hampshire
Effective: 1/1/2020
Authority: New Hampshire Insurance Commissioner
New Hampshire's adoption of the NAIC Insurance Data Security Model Law requires insurance licensees to run a risk-based written information security program, oversee vendors, keep an incident response plan, investigate cybersecurity events and report qualifying events to the Insurance Commissioner within 3 business days. Consumer notice follows the general breach law, RSA 359-C:20.
Insurance Data Security Law
CT Insurance Data Security LawJurisdiction: Connecticut
Effective: 10/1/2020
Authority: Connecticut Insurance Commissioner
Connecticut's version of the NAIC Insurance Data Security Model Law. Insurers, producers and other licensees must run a risk-based written information security program, oversee vendors, keep an incident response plan, certify compliance annually (domestic insurers), and report cybersecurity events to the Insurance Commissioner within three business days.
Insurance Data Security Law
LA Insurance Data Security LawJurisdiction: Louisiana
Effective: 8/1/2020
Authority: Louisiana Commissioner of Insurance
Louisiana's version of the NAIC Insurance Data Security Model Law. Insurance licensees must maintain a risk-based written information security program with board oversight and vendor controls, investigate cybersecurity events, and notify the Commissioner of Insurance within three business days of determining a qualifying event occurred. Consumer notice follows the general breach notification law.
Insurance Data Security Law
Tenn. Insurance Data Security LawJurisdiction: Tennessee
Effective: 7/1/2021
Authority: Tennessee Commissioner of Commerce and Insurance
Tennessee's version of the NAIC Insurance Data Security Model Law. Insurance licensees must run a risk-based written information security program, oversee third-party service providers, investigate cybersecurity events, notify the Commissioner within three business days of qualifying events, and notify affected Tennessee consumers within 45 days when an event is reasonably likely to cause them material harm.
Insurance Information and Privacy Protection Act
IIPPAJurisdiction: California
Effective: 10/1/1981
Authority: California Insurance Commissioner; private plaintiffs for listed rights
Sets standards for how insurers and agents collect, use, and disclose personal information from insurance transactions. It requires notices of information practices, gives consumers access and correction rights, and limits disclosure without written authorization. SB 354 (2026), which would modernize the Act effective 2028, was on the Governor's desk as of September 25, 2026.
Insurance Information and Privacy Protection Act
MT Insurance Privacy ActJurisdiction: Montana
Authority: Montana Commissioner of Securities and Insurance (State Auditor)
Montana's version of the NAIC insurance privacy model law governs how insurers, producers and insurance-support organizations collect, use and disclose personal and health information. It gives individuals notice, access, correction and adverse-decision explanation rights, limits disclosure and marketing use, and contains an insurance-specific data breach notification and security policy requirement.
Insurance Information and Privacy Protection Act and Insurance Data Security Act
VA insurance privacyJurisdiction: Virginia
Effective: 7/1/1981
Authority: State Corporation Commission, Bureau of Insurance (38.2-614, 38.2-627)
Virginia's insurance privacy law limits pretext interviews, requires notices of information practices, gives consumers access and correction rights and reasons for adverse underwriting decisions, and restricts disclosure of medical and privileged information without written authorization. The 2020 Insurance Data Security Act adds a written information security program, cybersecurity-event investigation, notice to the Commissioner within three business days, and consumer breach notice.
Insurance Privacy of Nonpublic Personal Financial and Health Information
Florida Insurance Privacy LawJurisdiction: Florida
Authority: Florida Department of Financial Services; Financial Services Commission; Office of Insurance Regulation
Directs Florida insurance regulators to adopt privacy rules for consumers' nonpublic personal financial and health information, modeled on and no stricter than the NAIC privacy model regulation and GLBA Title V. Health insurers and HMOs complying with the HIPAA privacy rules are deemed compliant.
Insurance privacy of nonpublic personal information
OK Insurance GLBA PrivacyJurisdiction: Oklahoma
Effective: 7/1/2001
Authority: Oklahoma Insurance Commissioner
Prohibits disclosure of nonpublic personal information in violation of Title V of the Gramm-Leach-Bliley Act and authorizes the Insurance Commissioner to adopt implementing privacy rules for the insurance industry.
Insurer Information Security Program and Cybersecurity Event Notification
RI Insurance Data Security LawJurisdiction: Rhode Island
Effective: 1/1/2025
Authority: Rhode Island Department of Business Regulation, Insurance Division (commissioner/director)
Enacted in 2024 and effective January 1, 2025, this law adapts the NAIC Insurance Data Security Model Law. Insurers must keep a written, risk-based information security program for nonpublic consumer information with encryption, multi-factor authentication, training, vendor oversight and board oversight, and must notify the insurance commissioner within three business days of qualifying cybersecurity events.
Insurers' use of external consumer data, algorithms, and predictive models
Colorado insurance AI law (SB 21-169)Jurisdiction: Colorado
Effective: 9/7/2021
Authority: Colorado Commissioner of Insurance (Division of Insurance)
SB 21-169 bars insurers from unfairly discriminating based on race, color, national or ethnic origin, religion, sex, sexual orientation, disability, gender identity, or gender expression, including through external consumer data, algorithms, and predictive models. The Commissioner adopts line-by-line rules requiring insurers to test and govern those models. SB 26-189 added authority for rules on notices and disclosures to consumers and deems compliant insurers compliant with the ADMT Act.
Interception of Communications (Iowa wiretap act)
Iowa Wiretap ActJurisdiction: Iowa
Authority: County attorneys and the Attorney General (criminal); aggrieved persons (civil)
Iowa's wiretap act makes it a felony to willfully intercept wire, oral, or electronic communications, or to use or disclose unlawfully intercepted contents, and gives victims a civil damages claim. Interception is lawful when the interceptor is a party or one party consents, unless done to commit a crime or tort, and property owners may capture oral communications with consented surveillance systems for crime prevention.
Interception of Telephonic or Telegraphic Communications (Indiana wiretap act)
IN Wiretap ActJurisdiction: Indiana
Authority: County prosecutors (criminal); private civil actions
Indiana's wiretap law is a one-party consent statute. 'Interception' means acquisition by someone who is neither a sender nor a receiver and lacks the consent of the sender or receiver, so a participant may record, or another person may record with one party's consent. The article also sets the warrant process for law enforcement wiretaps. It is framed around communications transmitted by wire, radio, or similar systems; purely in-person conversations are not expressly addressed by the definition.
Interception of Wire, Electronic and Oral Communications (wiretap and one-party consent recording)
RI Wiretap LawJurisdiction: Rhode Island
Authority: Rhode Island Attorney General and local prosecutors; courts via civil suits
Rhode Island is a one-party consent state: it is a crime to intercept a phone call, electronic communication or in-person conversation unless the interceptor is a party or one party has consented in advance, and even then not if the recording is made to commit a crime, tort or other injurious act. Chapter 12-5.1 sets the court-order procedure for law-enforcement wiretaps and gives victims of unlawful interception a civil damages claim.
Interception of Wire, Electronic or Oral Communications (Virginia wiretap act)
VA wiretap actJurisdiction: Virginia
Effective: 7/1/1973
Authority: Criminal prosecution by Commonwealth's attorneys; injured persons by civil action (19.2-69)
Virginia is a one-party consent state: recording or intercepting a call or conversation is lawful if the recorder is a party or one party consented, and otherwise a felony. Victims can sue for liquidated damages. Service providers may not divulge communication contents in transit and may give subscriber records to law enforcement only under a subpoena, warrant, court order, or the customer's consent.
Interference with Privacy (surreptitious observation and recording)
MN Interference with PrivacyJurisdiction: Minnesota
Authority: Criminal prosecution
Criminalizes peeping into homes and other private places and surreptitiously installing or using devices to observe, photograph, record, or broadcast people there, including recording someone's intimate parts without consent in bathrooms, locker rooms, hotel rooms, and similar places. Penalties increase for repeat offenders and offenses involving minors.
Internet-Connected Baby Monitor Security Requirements
NJ Baby Monitor Security LawJurisdiction: New Jersey
Effective: 12/1/2018
Authority: New Jersey Attorney General / Division of Consumer Affairs (Consumer Fraud Act)
Internet-connected baby monitors sold in New Jersey must include end-to-end encryption, certificate-based authentication, a ban on unauthenticated access, and security settings that consumers cannot disable. Selling a non-compliant monitor is a consumer fraud violation.
Invasion of personal privacy (voyeurism and nonconsensual nude recording): crime and civil action
ORS 163.700-163.701; 30.831Jurisdiction: Oregon
Authority: District attorneys (criminal); private civil action (ORS 30.831)
Criminalizes secretly viewing someone nude for sexual gratification, recording a person's intimate area without consent, and recording someone nude in a private place such as a bathroom or locker room. A companion civil action lets victims sue, and since September 2025 also reaches hotels and short-term rental hosts or platforms that record guests in private spaces.
Invasion of Privacy (non-consensual intimate observation, recording, and disclosure)
NJ Invasion of Privacy LawJurisdiction: New Jersey
Effective: 1/8/2004
Authority: County prosecutors and the Attorney General (criminal); private civil action by the person depicted
New Jersey criminalizes secretly watching, photographing, or recording people who are nude, partly clothed, or engaged in sexual activity where they expect privacy, and disclosing such images (including online) without consent. Victims can sue for liquidated damages. Retailers may watch dressing-room entrances only with posted notice and may never observe or record inside private stalls.
Invasive Visual Recording
Texas Invasive Visual Recording LawJurisdiction: Texas
Effective: 9/1/2001
Authority: State prosecutors
Criminalizes non-consensual photography or video of intimate areas or of people in bathrooms, changing rooms, and similar private places, and promoting such recordings. Posted signs alone do not establish consent to recording in private places.
Investigative Consumer Reporting Agencies Act
ICRAAJurisdiction: California
Authority: Private plaintiffs
Regulates background reports on a person's character, reputation, and way of living, often used for employment and tenant screening. Agencies must limit reports to permitted purposes, maintain accuracy, and disclose on their websites whether personal information is sent outside the United States.
Iowa Consumer Data Protection Act (Consumer Data Protections)
ICDPAJurisdiction: Iowa
Effective: 1/1/2025
Authority: Iowa Attorney General (exclusive authority, 715D.8(1))
Max Fine: Up to ,500 per violation
Iowa's comprehensive consumer privacy law gives Iowa residents the right to confirm and access their personal data, delete data they provided, obtain a portable copy, and opt out of the sale of personal data. It requires notice and an opportunity to opt out before processing sensitive data (and COPPA-compliant processing for a known child's data), rather than opt-in consent. It has no right to correct, no data protection assessments, and a 90-day cure period enforced only by the Attorney General.
Job Applicant Fairness Act (employer use of credit history)
MD Job Applicant Fairness ActJurisdiction: Maryland
Authority: Commissioner of Labor and Industry (3-711(d))
Maryland generally bars employers from using an applicant's or employee's credit report or history to deny employment, fire, or set pay or terms. Employers may use it after a job offer for non-prohibited purposes, or where there is a bona fide, substantially job-related reason disclosed in writing, such as managerial, fiduciary, or personal-information-access roles.
Judge Andrew F. Wilkinson Judicial Security Act
Wilkinson Judicial Security ActJurisdiction: Maryland
Effective: 6/1/2024
Authority: Protected individuals and the Office of Information Privacy in the Administrative Office of the Courts (civil actions); State's Attorneys (criminal)
Named for a Maryland judge killed in 2023, this law lets judges and their families, or the judiciary's Office of Information Privacy on their behalf, demand that anyone who has published their home address, phone numbers, personal email, financial or ID numbers, children's names, schools, or similar details online remove it within 72 hours. It also creates a judicial address confidentiality program and criminalizes threatening publication.
K-12 Pupil Online Personal Information Protection Act (formerly SOPIPA)
KOPIPA (SOPIPA)Jurisdiction: California
Effective: 1/1/2016
Authority: California Attorney General and local prosecutors; pupils actually harmed (from 2027)
Protects K-12 students' data held by education technology operators. Operators may not use student data for targeted advertising, build non-school profiles, sell it, or disclose it except as listed, and must secure it and delete it on request. AB 1159 (signed Sept. 10, 2026, Chapter 182) widens coverage, bars using student data to train generative AI or develop AI systems, and adds a private right of action from January 1, 2027.
Kelsey Smith Act
Nebraska Kelsey Smith ActJurisdiction: Nebraska
Effective: 7/15/2010
Authority: No specific enforcement provision (law enforcement agencies request data; Nebraska State Patrol keeps the carrier contact register)
This law requires wireless carriers, on request of a law enforcement agency, to provide a device's call location information (including historical cell-site data) as soon as practicable in an emergency involving risk of death or serious physical harm. It makes a narrow, emergency-only exception to location privacy and shields carriers from liability for such disclosures.
Kelsey Smith Act
Kelsey Smith ActJurisdiction: Oklahoma
Effective: 11/1/2021
Authority: Oklahoma State Bureau of Investigation (contact database and rules); requesting law enforcement agencies
Requires wireless carriers to give law enforcement a device's call location information on request in an emergency involving risk of death or serious physical harm, and to notify the user afterward. Carriers must register emergency contacts with the OSBI.
Kentucky Consumer Data Protection Act
KCDPAJurisdiction: Kentucky
Effective: 1/1/2026
Authority: Kentucky Attorney General (exclusive authority; complaints handled by the AG's Office of Data Privacy)
Kentucky's comprehensive consumer privacy law gives Kentucky residents rights to confirm, access, correct, delete, and port their personal data and to opt out of targeted advertising, sale, and significant-decision profiling. Controllers must minimize collection, secure data, obtain consent before processing sensitive data, publish a privacy notice, and conduct data protection impact assessments for higher-risk processing. A 2026 amendment (effective July 1, 2027) bars collection of smart-TV and smart-monitor automatic content recognition data without consent.
Kentucky Eavesdropping and Related Offenses
KY EavesdroppingJurisdiction: Kentucky
Effective: 1/1/1975
Authority: Commonwealth's and county attorneys (criminal prosecution)
Kentucky is a one-party consent state: it is a felony to use a device to overhear, record, amplify, or transmit any part of a wire or oral communication of others without the consent of at least one party. The chapter also criminalizes installing or possessing eavesdropping devices, opening sealed private communications, and using or disclosing illegally obtained communications.
Kentucky Family Educational Rights and Privacy Act (student education records)
KY FERPAJurisdiction: Kentucky
Effective: 7/15/1994
Authority: Not specified in the sections reviewed
Makes public school students' education records confidential and bars their release to third parties, other than directory information, without parent or eligible-student consent except to listed recipients such as school officials, transfer schools, authorized government officials, de-identified researchers, and accreditors. Schools must preserve unedited master copies of recordings of school activities for set periods, and must log releases.
Kentucky Insurance Data Security Law
KY Insurance Data SecurityJurisdiction: Kentucky
Effective: 1/1/2023
Authority: Kentucky Department of Insurance (Commissioner)
Kentucky's version of the NAIC Insurance Data Security Model Law. Covered insurance licensees must run a risk-based written information security program, oversee third-party service providers, investigate cybersecurity events, and report qualifying events to the Commissioner within three business days. Domestic insurers must certify compliance annually.
Kentucky Security Breach Notification Law
KY Breach NotificationJurisdiction: Kentucky
Effective: 7/15/2014
Authority: Not specified in KRS 365.732
Requires businesses to notify Kentucky residents when unencrypted, unredacted computerized personal information (name plus SSN, driver's license number, or financial account or card number with its access code) is acquired without authorization in a way that causes or is reasonably believed to cause identity theft or fraud. Notice must go out in the most expedient time possible and without unreasonable delay, and consumer reporting agencies must be told when more than 1,000 people are notified.
Kentucky Telephone Solicitation (Telemarketing) Law
KY Telemarketing ActJurisdiction: Kentucky
Effective: 7/15/1994
Authority: Kentucky Attorney General (Office of Consumer Protection) with concurrent criminal enforcement powers; prosecutors
Regulates telephone solicitation in Kentucky: callers must identify themselves at the start of the call, may not call numbers on the national Do Not Call Registry, may not call minors or outside 10 a.m. to 9 p.m., may not spoof caller ID, and may not sell information learned during a call without written consent. Telemarketing companies must register with the Attorney General and post a bond. Kentucky's former zero call list was folded into the national registry in 2007.
Kids Online Protection and Anti-Grooming Act
LA KOPAG ActJurisdiction: Louisiana
Effective: 1/1/2027
Authority: Louisiana Attorney General
Imposes a duty of care on platforms, online games, messaging apps, and streaming services that contract with minors, requiring privacy-protective default settings: no adult connections without parental consent (or parental visibility into connections), no direct messages from unconnected adults, no sharing of a minor's precise geolocation, and private-mode accounts. Parents must get supervision tools, including limits on microtransactions, and only a linked parent can change the defaults. Act 552 of 2026 raised the covered age to under 18 and set the effective date at January 1, 2027.
Kristil's Law: communications provider response to domestic violence and stalking search warrants
HB 4045 (2026)Jurisdiction: Oregon
Effective: 5/1/2026
Authority: Courts issuing the warrants; no separate penalty specified
Sets fast deadlines for providers to answer search warrants for records in domestic violence and stalking cases: 72 hours for social media platforms and five business days for other communications providers. It governs how quickly private providers must hand stored user data to law enforcement.
Laboratory Genetic Sequencing Software from Foreign Countries of Concern
Florida Genetic Sequencing Software LawJurisdiction: Florida
Effective: 7/1/2025
Authority: Florida Department of Health
Added by SB 768 (ch. 2025-96), this subsection bars the Department of Health from allowing its public-health laboratories under s. 381.0202 to use genetic-sequencing software produced by China, Russia, Iran, North Korea, Cuba, the Maduro regime in Venezuela, or Syria, or by their state-owned enterprises or domestic companies. It is Florida's main 2025 genetic-data change. It covers state laboratory services, not private consumer genetic-testing companies, and does not amend s. 760.40.
Legal representative consent for contracts between a minor and an interactive computer service
LA Minor Online Contract Consent LawJurisdiction: Louisiana
Effective: 5/8/2024
Authority: None specified (civil-law contract nullity)
Declares it Louisiana policy that online services should not contract with minors without a parent's or tutor's consent, and bars interactive computer services from entering contracts, including opening an online account, with anyone under 18 without that consent. Contracts made without express written consent are relatively null and can be annulled. Third parties may be used to collect consent.
Library User Records Confidentiality
NH Library Records LawJurisdiction: New Hampshire
Effective: 7/21/1989
Authority: Not specified in the section
Makes library records identifying users, including circulation, information system and electronic viewing records, confidential at both public and non-public libraries. Records may be disclosed only for library operations, with the user's consent, or under subpoena, court order or statute; a 2025 amendment effective Jan. 1, 2026 gives parents or guardians access to a minor's current borrowing records.
Lie Detector Tests as Conditions of Employment
RI Polygraph BanJurisdiction: Rhode Island
Authority: Prosecutors (misdemeanor); courts via civil actions
Forbids employers from requesting, requiring or subjecting employees or applicants to lie detector tests, which include polygraphs and any device or written test used by an examiner to judge honesty. Written honesty examinations may be used only if they are not the primary basis for an employment decision.
Lie Detector Tests Prohibited
MT Polygraph BanJurisdiction: Montana
Authority: Not specified in the section
Montana bars employers from requiring a polygraph or other mechanical lie detector test as a condition of getting or keeping a job.
Life, long-term care, and annuity genetic nondiscrimination
LA Life and LTC Genetic NondiscriminationJurisdiction: Louisiana
Effective: 8/1/2021
Authority: Louisiana Commissioner of Insurance
Stops life, long-term care, and annuity insurers from considering an applicant's or family member's participation in genetic or clinical research, or (since 2024) their genetic test results, for coverage or underwriting. Insurers may not cancel, refuse to renew, limit coverage, or raise premiums based on genetic testing or genetic services.
Limitations on use of artificial intelligence by health benefit plan providers
AL AI Prior Authorization LawJurisdiction: Alabama
Effective: 10/1/2026
Authority: Alabama Department of Insurance
Regulates insurers that use AI to decide medical-necessity prior authorization requests. AI determinations must rest on the individual enrollee's medical history and clinical circumstances, not group datasets, and any denial, delay, or modification must be made by a licensed clinician. Plans must disclose their AI use and keep patient data used by AI within its stated purpose consistent with HIPAA. The effective date is October 1, 2026.
Limits on employer use of consumer credit reports
Lab. Code 1024.5Jurisdiction: California
Effective: 1/1/2012
Authority: Labor Commissioner; courts
Bars employers from using consumer credit reports for employment decisions except for listed positions, such as managerial jobs, law enforcement, positions with access to large sums or sensitive financial data, and jobs where the law requires the check. Employers using a report must give advance written notice.
Louisiana Data Privacy Act
LDPAJurisdiction: Louisiana
Effective: 1/1/2027
Authority: Louisiana Attorney General
Louisiana's comprehensive consumer privacy law, enacted by Act 502 of the 2026 Regular Session and effective January 1, 2027. It gives Louisiana residents rights to confirm, access, correct, delete, and port their personal data and to opt out of targeted advertising, sale, and significant-decision profiling, and it requires controllers to minimize data, secure it, get consent for sensitive data, publish a privacy notice, and conduct data protection assessments. Unlike most state models, applicability turns on a $25 million revenue threshold (CCPA-style) rather than only a consumer-count threshold.
Malicious Sharing of Personal Information of a General Assembly Member or Judicial Officer (2026 SF 2280, Division III)
Iowa Official Doxxing LawJurisdiction: Iowa
Effective: 7/1/2026
Authority: County attorneys and the Attorney General (criminal prosecution)
This 2026 criminal law makes it a serious misdemeanor to share the home address, personal phone number, or physical location of an Iowa legislator, judge, or their immediate family with intent to cause harm, to put them in fear of serious harm, or to interfere with their official duties. It is narrow: it covers only those officials and requires malicious intent.
Maryland Age-Appropriate Design Code Act (Maryland Kids Code)
Maryland Kids CodeJurisdiction: Maryland
Effective: 10/1/2024
Authority: Consumer Protection Division, Office of the Attorney General (14-4808)
The Maryland Kids Code requires large online businesses whose products children under 18 are reasonably likely to use to design those products in children's best interests. Covered entities must complete data protection impact assessments, set high-privacy defaults for children, and avoid default profiling, default precise geolocation tracking, unnecessary data collection, and dark patterns. NetChoice's First Amendment challenge (NetChoice v. Brown, D. Md. No. 1:25-cv-00322) survived a motion to dismiss in November 2025 and is in discovery; the law has not been enjoined.
Maryland Commercial Electronic Mail Act
MD Commercial Email ActJurisdiction: Maryland
Authority: Private civil actions by recipients, domain owners, and interactive computer service providers (14-3003)
Maryland's anti-spam law prohibits sending commercial email that uses a third party's domain or address without permission, falsifies its origin or transmission path, or has a deceptive subject line. Email providers may block suspected violating messages without liability.
Maryland Confidential Financial Records law
MD Financial Records ConfidentialityJurisdiction: Maryland
Authority: State's Attorneys (criminal); Attorney General (civil penalties for failure to file elder-abuse reports)
Maryland bars banks and other fiduciary institutions from disclosing a customer's financial records unless the customer authorizes it, a statutory exception applies (such as guardians, estate representatives, public assistance verification, adult protective services, child support, or tax liens), or a properly certified subpoena is served with notice to the customer. A 2026 amendment (ch. 510, effective 2026-10-01) adds disbursement-delay authority and disclosure duties to protect seniors and vulnerable adults from exploitation.
Maryland Confidentiality of Medical Records Act
MCMRAJurisdiction: Maryland
Authority: State's Attorneys (criminal); Maryland Health Care Commission (HIE regulations); private civil actions for actual damages
Maryland's medical records law requires health care providers to keep patient records confidential and disclose them only as the subtitle or other law allows, gives patients rights to see, copy, and seek corrections to their records, and criminalizes obtaining records under false pretenses. Recent amendments restrict health information exchanges and electronic health networks from sharing abortion, mifepristone, and other legally protected sensitive-service data, and require HIE opt-out consent management.
Maryland Consumer Credit Reporting Agencies Act
MD CCRAJurisdiction: Maryland
Authority: Commissioner of Financial Regulation (14-1218, 14-1225); private civil actions (14-1221)
Maryland's credit reporting law limits when consumer reports may be furnished, bars reporting of stale information, criminal records that did not end in conviction or were expunged, and (since 2025) any medical debt, and gives consumers rights to free reports, disputes, and security freezes. Agencies must register and post a bond, and users must give adverse action notices.
Maryland employer access to personal accounts (User Name and Password Privacy Protection)
MD Social Media Password LawJurisdiction: Maryland
Authority: Commissioner of Labor and Industry; Attorney General may sue on the employee's or applicant's behalf (3-712(f))
Maryland bars employers from asking employees or job applicants for usernames, passwords, or other access to their personal online accounts, and from punishing or refusing to hire anyone who declines. Employers may still require credentials for company systems and may investigate securities-law compliance or leaks of proprietary data.
Maryland Genetic Information Privacy law (direct-to-consumer genetic testing)
MD Genetic Information PrivacyJurisdiction: Maryland
Effective: 10/1/2022
Authority: Consumer Protection Division, Office of the Attorney General (14-4406; Com. Law 13-301(14)(xxxvi))
Enacted by 2022 Md. Laws ch. 501 (HB 866), this law requires direct-to-consumer genetic testing companies to publish clear privacy information, obtain separate express consents for each use, transfer, sample retention, and marketing, secure genetic data, and let consumers access and delete their data and have samples destroyed. It bars disclosure to insurers or employers without written consent. The same act also regulated forensic genetic genealogy in the Criminal Procedure Article.
Maryland Insurance Data Security law (Insurance Article Title 33)
MD Insurance Data SecurityJurisdiction: Maryland
Effective: 10/1/2022
Authority: Maryland Insurance Commissioner
Enacted by 2022 Md. Laws ch. 231 (SB 207), Maryland's version of the NAIC Insurance Data Security Model Law requires insurance carriers to run a risk-based written information security program, oversee vendors, investigate cybersecurity events, and notify the Insurance Commissioner within 3 business days of determining a qualifying event, along with consumer notice under the Personal Information Protection Act.
Maryland lie detector test prohibition
MD Polygraph LawJurisdiction: Maryland
Authority: Commissioner of Labor and Industry; Attorney General may sue (3-702(f)-(g))
Maryland employers may not require a polygraph or similar test as a condition of employment, and every job application must carry a bold, capitalized notice of this right with a signed acknowledgment.
Maryland Online Data Privacy Act of 2024
MODPAJurisdiction: Maryland
Effective: 10/1/2025
Authority: Consumer Protection Division, Office of the Attorney General (14-4713; Com. Law Title 13)
Maryland's comprehensive consumer privacy law gives residents rights to access, correct, delete, and port their personal data, to get a list of categories of third parties that received it, and to opt out of targeted advertising, sale, and significant-decision profiling. It is stricter than most state laws: data collection must be limited to what is reasonably necessary for a requested product or service, sensitive data may be collected only when strictly necessary and may never be sold, and minors' data may not be sold or used for targeted advertising. A 2026 amendment (HB 711, ch. 874) extends sensitive data to inferences and bars knowing sales of personal data to government units engaged in civil immigration enforcement.
Maryland Pen Register and Trap and Trace Devices law
MD Pen Register ActJurisdiction: Maryland
Authority: State's Attorneys (criminal)
This law bars anyone from installing or using a device that records the numbers or routing information of calls and electronic communications without first getting a court order, except for service providers protecting their networks and users.
Maryland Personal Information Protection Act
MPIPAJurisdiction: Maryland
Authority: Consumer Protection Division, Office of the Attorney General (14-3508; Com. Law Title 13)
Maryland's data security and breach notification law requires businesses holding Maryland residents' personal information to keep reasonable security, destroy records securely, and flow security requirements down to service providers. After a breach, a business must investigate and, unless misuse is not likely, notify affected residents within 45 days, notifying the Attorney General first. The 2022 revisions added genetic information and set the 45-day and 10-day deadlines.
Maryland Stored Wire and Electronic Communications and Transactional Records Access
MD Stored Communications ActJurisdiction: Maryland
Authority: State's Attorneys (criminal); private civil action by aggrieved providers, subscribers, or customers (10-4A-08)
Maryland's counterpart to the federal Stored Communications Act makes it a crime to access a communications facility without authorization to obtain, alter, or block stored messages. It also bars public communication and remote computing service providers from knowingly disclosing stored message contents except to recipients, with consent, or as the subtitle allows, and it gives aggrieved users a civil remedy.
Maryland Student Data Privacy Act (operators of PreK-12 online services)
MD Student Data Privacy ActJurisdiction: Maryland
Authority: No enforcement provision in § 4-131 (contract remedies by schools; see unverified)
Maryland's student data privacy law limits what education-technology operators working under contract with public schools may do with student information. Operators must secure covered information and delete it on school request, and may not use it for targeted advertising, build non-educational student profiles, sell it, or disclose it outside listed exceptions. The 2022 amendments (ch. 164) expanded covered information, added persistent identifiers, and tied coverage to school contracts.
Maryland Telephone Consumer Protection Act
MD TCPAJurisdiction: Maryland
Authority: Consumer Protection Division, Office of the Attorney General (14-3202(a)); private actions (14-3202(b))
This law makes any violation of the federal Telemarketing Sales Rule or the federal Telephone Consumer Protection Act and its FCC telemarketing rules (including the national do-not-call rules) a violation of Maryland law, enforceable by the Attorney General and by individuals for $500 per violation.
Maryland Telephone Solicitations Act
MD Telephone Solicitations ActJurisdiction: Maryland
Authority: Consumer Protection Division, Office of the Attorney General (Com. Law 13-301(14)(xiv))
This older telemarketing law protects consumers from phone sales by making contracts formed through telephone solicitations unenforceable unless put in writing and signed by the consumer with required disclosures, and by barring charges to a consumer's account until the signed contract is received.
Maryland visual surveillance and hidden camera crimes
MD Visual Surveillance LawJurisdiction: Maryland
Authority: State's Attorneys (criminal); private civil actions by individuals surveilled
These laws make it a crime to watch or record people without consent in retail dressing rooms and restrooms, to conduct surreptitious surveillance with prurient intent of people in private places or of their private areas, and to place a camera on residential property to secretly observe people inside a home. Each gives victims a civil claim. A 2025 amendment (ch. 153) extended 3-902 to camera surveillance of private areas regardless of location.
Maryland Wiretap and Electronic Surveillance Act
MD Wiretap ActJurisdiction: Maryland
Authority: State's Attorneys and the Attorney General (criminal); private civil action by persons whose communications are intercepted, disclosed, or used (10-410)
Maryland is an all-party consent state: a private person may record or intercept a phone call, electronic communication, or private in-person conversation only if they are a party and every party has consented in advance. The Act also bars disclosing or using contents known to be illegally intercepted, and it sets out narrow exceptions for service providers, law enforcement investigations, and police and correctional body-worn cameras.
Medical Debt Reporting
RI Medical Debt Reporting BanJurisdiction: Rhode Island
Effective: 1/1/2025
Authority: Rhode Island Attorney General; consumers
Since January 1, 2025, Rhode Island bars medical debt from appearing on credit reports. Providers may not furnish medical debt to credit bureaus and must bar their collectors by contract from doing so, credit bureaus may not record or report it, and collectors must tell consumers in writing that Rhode Island law prohibits medical debt reporting and must pause reporting and collection while insurance appeals are pending.
Medical record retention and destruction
MD Medical Records Retention LawJurisdiction: Maryland
Authority: Maryland Department of Health and the relevant health occupations boards (not specified in section)
Maryland health care providers must keep medical records and lab and X-ray reports for 7 years (for minors, until age of majority plus 7 years) unless they notify the patient first. The notice, now allowed by email with a mail fallback under 2025 ch. 695, must give the destruction date and where to retrieve the record, and records must be available for retrieval for 60 days before destruction.
Medical records disclosure rules (patient access and subpoenas to health care providers)
LA Medical Records Disclosure RulesJurisdiction: Louisiana
Authority: Courts
Louisiana has no general medical confidentiality act, but these statutes set the exclusive routes by which health care providers may disclose patient records: to the patient or authorized persons under R.S. 40:1165.1, under the health care provider-patient privilege of Code of Evidence article 510, or under a subpoena or court order that follows notice procedures protecting the patient. Patients may also get copies of information a provider has sent to third parties.
Medical Records, Patient Information, and the Health Information Organization Corporation
NH Medical Records Privacy LawJurisdiction: New Hampshire
Authority: Courts, through individual civil actions (RSA 332-I:4-5); provider licensing boards
Declares medical information in provider records to be the patient's property, sets deadlines and fee caps for copies, and forbids providers from revealing confidential information without consent except as law requires. It adds state-law limits beyond HIPAA on using health information for marketing and fundraising, requires notice to patients of disclosures that HIPAA allows but state law forbids, and gives patients an opt-out from the state health information exchange.
Mental Health Clinical Records; Confidentiality (Baker Act facilities)
Florida Mental Health Records LawJurisdiction: Florida
Authority: Florida Department of Children and Families; Agency for Health Care Administration
Makes clinical records of mental-health patients confidential. The confidential status is not lost by authorized or unauthorized disclosure unless the patient or representative waives it, and the records may be released only in listed circumstances, such as patient authorization.
Mental Health Records Confidentiality
Texas Mental Health Records LawJurisdiction: Texas
Effective: 9/1/1991
Authority: Aggrieved patients (courts); licensing boards
Makes communications with mental health professionals and their records of identity, diagnosis, evaluation, and treatment confidential, allows disclosure only under listed exceptions, and gives patients a right to access their records unless a professional documents that access would be harmful.
Minnesota Consumer Data Privacy Act
MCDPAJurisdiction: Minnesota
Effective: 7/31/2025
Authority: Minnesota Attorney General (325M.20)
Max Fine: Up to ,500 per violation
Minnesota's comprehensive consumer privacy law gives Minnesota residents rights to access, correct, delete, and port their personal data, to opt out of targeted advertising, sale, and significant-effect profiling, and to get a list of the specific third parties that received their data. It is unusual in giving consumers a right to question the result of a profiling decision, learn the reason for it, and have it reevaluated on corrected data, and it requires a data inventory and documented privacy policies. Enforcement is by the Attorney General only.
Minnesota Consumer Reports and Security Freeze Law
MN Consumer Reports and Security FreezeJurisdiction: Minnesota
Authority: Minnesota Attorney General or county attorney under 8.31 or 325F.70 (13C.04)
Gives Minnesota consumers the right to freeze their credit reports for free, with agencies required to place, lift, and remove freezes within three business days, and lets parents or representatives freeze a record for children under 16. It also requires written disclosure before an employer obtains a consumer report for employment purposes, adverse-action notices, and bars selling 'trigger lead' information about mortgage credit inquiries to third parties without an existing mortgage relationship.
Minnesota Data Breach Notification Law
MN Breach NotificationJurisdiction: Minnesota
Effective: 1/1/2006
Authority: Minnesota Attorney General under 8.31 (325E.61, subd. 6)
Requires businesses to notify Minnesota residents whose unencrypted personal information (name plus SSN, driver's license or state ID number, or financial account or card number with its access code) was, or is reasonably believed to have been, acquired by an unauthorized person, in the most expedient time possible and without unreasonable delay. Service providers must notify the data owner immediately, and breaches affecting more than 500 people require notice to the nationwide consumer reporting agencies within 48 hours.
Minnesota Genetic Information Privacy Act (direct-to-consumer genetic testing)
MN Genetic Information Privacy ActJurisdiction: Minnesota
Effective: 8/1/2023
Authority: Minnesota Commissioner of Commerce under 45.027 (325F.995, subd. 4)
Requires direct-to-consumer genetic testing companies to give plain-language privacy notices, get express consent for collecting and using genetic data and separate consent for each third-party disclosure, secondary use, sample retention, research transfer, and genetic-data-based marketing, and to let consumers access and delete their data and have samples destroyed. Companies may not give genetic data to law enforcement without consent or a warrant or court order, or to insurers or employers without written consent.
Minnesota Government Data Practices Act: private contractors and government breach notice
MN MGDPA (contractor provisions)Jurisdiction: Minnesota
Authority: Individuals by civil action; courts may enjoin violations (13.08)
Private companies that perform government functions under contract with a Minnesota government entity must handle the resulting data under the Minnesota Government Data Practices Act as if they were the government, and every such contract must say so. Government entities must notify individuals of breaches of private or confidential data and prepare an investigation report.
Minnesota Health Records Act
MN Health Records ActJurisdiction: Minnesota
Authority: Patients by civil action; licensing boards through disciplinary action (144.298)
Minnesota's health privacy statute, stricter than HIPAA in key respects, generally requires a signed and dated patient consent before a provider (or anyone who received records from a provider) releases health records, even for many treatment and payment disclosures, with limited exceptions such as emergencies and current treatment within related entities. It also gives patients rights to see and copy their records within 30 days at capped fees, and lets patients sue for unauthorized release.
Minnesota Insurance Fair Information Reporting Act
MN Insurance Fair Information Reporting ActJurisdiction: Minnesota
Authority: Aggrieved persons by civil action (72A.503); Commissioner of Commerce (general insurance regulatory authority)
Minnesota's version of the NAIC insurance information privacy model law. It requires insurers and agents to give a written notice of information practices, lets individuals see and copy personal information held about them and learn who received it, lets them seek correction, requires reasons for adverse underwriting decisions, and bars disclosing personal or privileged information without authorization except in listed cases such as fraud prevention.
Minnesota Internet Service Provider Privacy Law
MN ISP PrivacyJurisdiction: Minnesota
Effective: 3/1/2003
Authority: Private civil action by consumers (325M.07)
Enacted in 2002, this law bars Internet service providers from knowingly disclosing a subscriber's personally identifiable information, including the sites the subscriber visits and the contents of the subscriber's storage devices, except where disclosure is required by legal process or permitted for ordinary business, abuse reporting, or with the subscriber's authorization. The sections expire if federal law preempts state regulation of ISP disclosure of such information.
Minnesota Plastic Card Security Act (access device data retention)
MN Plastic Card Security ActJurisdiction: Minnesota
Effective: 8/1/2007
Authority: Civil action by card-issuing financial institutions (325E.64, subd. 3)
Prohibits businesses that accept payment cards from keeping the card security code, PIN verification code, or full magnetic-stripe track data after a transaction is authorized (48 hours for PIN debit). If a business (or its service provider) that violated the rule is breached, it must reimburse the banks and credit unions that issued the affected cards.
Minnesota Privacy of Communications Act (wiretap and recording consent)
MN Wiretap ActJurisdiction: Minnesota
Authority: Criminal prosecution; private civil action by persons whose communications were intercepted, disclosed, or used (626A.02, subds. 4-5; 626A.13)
Minnesota's wiretap law makes it a crime, and a civil wrong, to intentionally intercept, disclose, or use the contents of phone calls, electronic communications, or in-person conversations without authorization. Minnesota is a one-party consent state: a participant, or someone with a participant's prior consent, may record a conversation unless it is done to commit a crime or tort.
Minnesota Social Security Number Protection Law
MN SSN ProtectionJurisdiction: Minnesota
Effective: 7/1/2008
Authority: Minnesota Attorney General (general authority under Minn. Stat. 8.31)
Restricts how businesses use Social Security numbers: no public display, no printing on access cards or on mailed materials unless required by law, no unencrypted transmission over the Internet, no SSN-only website logins, no SSN-based account numbers (outside benefits and payroll), and no sale of SSNs. Businesses must also limit internal access to employees who need the numbers. The section applies to uses on or after July 1, 2008.
Minnesota Stored Communications Provisions
MN Stored CommunicationsJurisdiction: Minnesota
Authority: Criminal prosecution (626A.26, subd. 2); civil action by aggrieved providers, subscribers, or customers (626A.32)
Modeled on the federal Stored Communications Act, these sections make it a crime to access an electronic communications facility without authorization and obtain or alter stored messages, and bar public email and cloud providers from knowingly divulging the contents of stored communications except to recipients, with consent, as needed to provide service, under legal process, or to law enforcement when contents were inadvertently obtained and relate to a crime.
Misrepresentation in privacy policies (unlawful trade practice)
ORS 646.607(12)Jurisdiction: Oregon
Effective: 1/1/2016
Authority: Oregon Attorney General and district attorneys (ORS 646.632)
Makes it an unlawful trade practice to handle consumer information in a way that is materially inconsistent with what a business says in a website privacy statement or consumer agreement. It works as Oregon's enforcement hook for privacy promises rather than requiring any particular policy.
Montana Consumer Data Privacy Act
MTCDPAJurisdiction: Montana
Effective: 10/1/2024
Authority: Montana Attorney General (exclusive; 30-14-2817(1)), using Montana Unfair Trade Practices and Consumer Protection Act powers
Max Fine: Up to ,500 per violation
Montana's comprehensive consumer privacy law gives Montana residents rights to access, correct, delete and port their personal data and to opt out of targeted advertising, sale and significant profiling, and requires opt-in consent for sensitive data. The 2025 amendments (SB 297, Ch. 567, L. 2025) lowered the applicability thresholds, narrowed the financial-institution exemption to entity-level exemptions for banks, credit unions and insurers, expanded privacy-notice rules, removed the cure period, and added a duty of care and design limits for online services offered to known minors under 18.
Montana Pupil Online Personal Information Protection Act
MT Pupil Online Privacy ActJurisdiction: Montana
Authority: County attorneys (criminal misdemeanor); contract voidness between parties
Montana's student privacy law bars edtech operators from targeted advertising, profiling pupils for non-school purposes, selling pupil information, and most disclosures of protected student information, and requires reasonable security and deletion on school request. It also sets mandatory terms for school-district contracts with vendors that store or use pupil records.
Montana Telemarketing Registration and Fraud Prevention Act
MT Telemarketing ActJurisdiction: Montana
Effective: 10/1/1999
Authority: Montana Department of Justice, Office of Consumer Protection, or county attorneys
Montana requires most telemarketers and sellers to register annually with the Department of Justice before soliciting Montanans. The Act also requires call disclosures, record keeping and cancellation rights, and bans abusive practices such as calling outside 8 a.m. to 9 p.m. or calling people who have asked not to be called.
Motor Vehicle Administration records: personal information disclosure and recipient limits
MD MVA Records PrivacyJurisdiction: Maryland
Authority: Motor Vehicle Administration (regulations and compliance monitoring, 4-320(h)-(i))
Maryland's counterpart to the federal Driver's Privacy Protection Act bars the MVA from disclosing personal information in its records except for listed purposes, and never for marketing or telephone solicitation without written consent. Businesses that receive the data may use it only for the permitted purpose, must log redisclosures for 5 years, and may not pass it to federal immigration enforcement without a court warrant; the 2026 Data Privacy Act (ch. 874) broadened the immigration-related limits.
Motor Vehicle Consumer Data Protection
Utah Dealer Data ActJurisdiction: Utah
Effective: 5/1/2024
Authority: None stated; contract and indemnity remedies
Enacted by 2024 S.B. 215, it governs access to car dealers' protected dealer data, including consumers' nonpublic personal information. It is business-to-business and imposes no consumer notice duty.
Motor vehicle recording devices (event data recorders)
VA vehicle data recordersJurisdiction: Virginia
Effective: 7/1/2006
Authority: Not stated in the section
Vehicle recording device data, including speed, location, braking, seatbelt, and crash data, belongs to the vehicle owner and may be accessed only with the owner's consent or under listed exceptions (subscription contracts, repair, emergency response, court order, or law enforcement with probable cause). Insurers may not ask for consent until after a claim event or make it a condition of paying a claim.
Motor Vehicle Records Confidentiality (state driver privacy law)
NH Motor Vehicle Records PrivacyJurisdiction: New Hampshire
Authority: NH Department of Safety (commissioner); prosecutors; aggrieved persons
Makes New Hampshire motor vehicle records confidential and not public, releasing them only for listed permissible uses on proof of identity and a signed representation of the intended use, and never including photographs or Social Security numbers for those uses. Recipients may not resell or redisclose the information outside the permitted use, and misuse carries criminal penalties and liquidated civil damages.
Mug shot website removal requirement
ORS 646A.806Jurisdiction: Oregon
Authority: Oregon Attorney General; private enforcement under ORS 646.638
Requires fee-charging mug shot websites to take down an arrested person's photo, name and personal information for free within 30 days when the person shows the charges ended without conviction, were reduced to violations, or were expunged or set aside.
Nebraska Data Privacy Act
NDPAJurisdiction: Nebraska
Effective: 1/1/2025
Authority: Nebraska Attorney General (exclusive, 87-1119 to 87-1124)
Nebraska's comprehensive consumer privacy law, modeled on the Texas Data Privacy and Security Act, gives Nebraska consumers rights to access, correct, delete, and port their personal data and to opt out of targeted advertising, sale, and significant profiling. It covers almost every for-profit business that is not a federally defined small business, requires opt-in consent for sensitive data (including precise geolocation, genetic and biometric data, and a known child's data), and is enforced only by the Attorney General.
Nebraska Interception of Wire, Electronic, and Oral Communications and Stored Communications Law
Nebraska Wiretap and Stored Communications LawJurisdiction: Nebraska
Authority: County attorneys and the Attorney General (criminal); private civil actions
Nebraska's wiretap law, modeled on the federal Wiretap Act and Stored Communications Act, bans intercepting, disclosing, or using wire, electronic, or oral communications without authorization. It is a one-party consent state: a participant, or someone with one party's prior consent, may record unless the purpose is a criminal or tortious act. It also restricts public communications providers from disclosing stored message contents and limits employer random monitoring.
Nebraska Statutory Right of Privacy
Nebraska Privacy Tort StatuteJurisdiction: Nebraska
Authority: Courts (private civil action by the person whose privacy was invaded)
Nebraska does not recognize common-law privacy torts beyond this statute, which creates three causes of action: commercial exploitation of a person's name, picture, or personality (right of publicity), intrusion upon seclusion that would be highly offensive to a reasonable person, and false light publicity. Consent within its scope is a defense, and news and certain other uses are exempt.
New Hampshire Fair Credit Reporting Act (including Security Freeze)
NH FCRAJurisdiction: New Hampshire
Effective: 8/29/1971
Authority: New Hampshire Attorney General (administrative enforcement); consumers through civil actions
New Hampshire's own credit reporting statute limits when consumer reporting agencies may furnish reports, requires accuracy, dispute and disclosure procedures, and imposes adverse-action notice duties on users. Its security freeze subdivision lets consumers freeze, temporarily lift and remove freezes for free on short deadlines, and gives identity theft victims free reports and police reports.
New Hampshire Privacy Act (Expectation of Privacy)
NHPAJurisdiction: New Hampshire
Effective: 1/1/2025
Authority: New Hampshire Attorney General (exclusive authority)
New Hampshire's comprehensive consumer privacy law gives NH residents rights to access, correct, delete and port their personal data and to opt out of targeted advertising, sales and significant automated profiling. Covered controllers must minimise collection, get opt-in consent for sensitive data, honor universal opt-out signals, publish a privacy notice and run data protection assessments for high-risk processing. A 2026 amendment bars selling a child's personal data starting Jan. 1, 2027.
New Hampshire Right to Privacy Act (financial and credit records)
NH Right to Privacy ActJurisdiction: New Hampshire
Effective: 9/17/1977
Authority: Courts, through customer suits and criminal prosecution
Protects the confidentiality of customers' financial and credit records by barring financial institutions and creditors from handing them to state or local agencies investigating the customer unless the customer authorizes it or the agency uses a qualifying administrative subpoena, search warrant or judicial subpoena. It sets notice and record-keeping duties around those disclosures.
New Jersey Data Privacy Act
NJDPAJurisdiction: New Jersey
Effective: 1/15/2025
Authority: New Jersey Attorney General (sole and exclusive authority, 56:8-166.19), acting through the Division of Consumer Affairs
Max Fine: Up to ,000 per first violation; ,000 per subsequent
New Jersey's comprehensive consumer privacy law gives residents rights to confirm, access, correct, delete and port their personal data and to opt out of targeted advertising, sale, and significant-decision profiling. It requires consent for processing sensitive data and for targeted advertising, sale, or profiling of known 13-to-16-year-olds, and requires data protection assessments for high-risk processing. A January 2026 amendment (P.L.2025, c.367) added exemptions and a HIPAA-based de-identification standard, and a June 2026 amendment (P.L.2026, c.25) flatly bans the sale of sensitive data by anyone.
New Jersey Fair Credit Reporting Act
NJ FCRAJurisdiction: New Jersey
Authority: Consumers through private civil actions; overlapping federal FCRA enforcement by the FTC and CFPB
New Jersey's credit reporting law mirrors and supplements the federal FCRA: consumer reporting agencies may furnish reports only for listed permissible purposes, and employers must give a standalone written disclosure and get written authorization before obtaining a report. Medical information may not be furnished for employment, credit, insurance, or direct marketing without written consent, and consumers can sue for willful or negligent violations.
New Jersey Genetic Privacy Act
NJ Genetic Privacy ActJurisdiction: New Jersey
Authority: Criminal prosecution (disorderly persons offense); private civil action by the individual
New Jersey's Genetic Privacy Act treats genetic information as the individual's own: it may not be obtained, kept, or disclosed without informed consent, subject to listed law-enforcement, paternity, court-order, newborn-screening, and anonymous-research exceptions. People can ask for their DNA samples to be destroyed and can inspect and correct their genetic records.
New Jersey Insurance Information Practices Act
NJ IIPAJurisdiction: New Jersey
Authority: New Jersey Commissioner of Banking and Insurance; individuals (remedies not verified)
New Jersey's version of the NAIC insurance privacy model law requires insurers, agents, and insurance-support organizations to give written notices of their information practices, to let people see and correct recorded personal information about them, and to disclose personal or privileged information only with written authorization or under listed exceptions.
New Jersey Kids Code Act (New Jersey Age-Appropriate Design Code)
NJ Kids CodeJurisdiction: New Jersey
Effective: 9/1/2027
Authority: New Jersey Attorney General (Consumer Fraud Act powers and rulemaking); Commissioner of Health may add compulsive-use criteria; private actions by injured minors or their parents
Signed August 11, 2026 and effective September 1, 2027, the Kids Code requires social-media-type services that know a user is under 18 to set the highest privacy defaults, block unsolicited adult contact, hide location, limit data use and algorithmic feeds, and restrict engagement-driving design such as infinite scroll, autoplay, streaks, and night-time or school-hours notifications. Violations are consumer fraud and give injured minors a private right of action.
New Jersey No Telemarketing Call Law
NJ Do Not Call LawJurisdiction: New Jersey
Authority: New Jersey Division of Consumer Affairs / Attorney General (Consumer Fraud Act)
New Jersey requires telemarketers to register annually with the Division of Consumer Affairs and bars unsolicited sales calls to numbers on the no-call list (which uses the FTC's national registry), to mobile devices, and between 9 p.m. and 8 a.m. Telemarketers must identify themselves, the seller, and the purpose within 30 seconds and may not block or spoof caller ID.
New Jersey Wiretapping and Electronic Surveillance Control Act
NJ Wiretap ActJurisdiction: New Jersey
Authority: County prosecutors and the Attorney General (criminal); private civil actions by persons whose communications were unlawfully intercepted, disclosed, or used
New Jersey's wiretap law makes it a crime to intercept, disclose, or use wire, electronic, or oral communications without authorization and gives victims a civil damages claim. New Jersey is a one-party consent state: a private person may record a communication they are a party to, or where one party has consented, unless the purpose is criminal, tortious, or otherwise injurious. The Act also protects stored communications and limits provider disclosures of customer records, including device location, to law enforcement.
No recording in employee restrooms, locker rooms, and changing rooms
Lab. Code 435Jurisdiction: California
Effective: 1/1/1999
Authority: Local prosecutors
Prohibits employers from audio or video recording employees in restrooms, locker rooms, or changing rooms without a court order, and bars use of any such recording.
Non-academic Student Surveys (parental consent policy)
NH Student Survey Consent LawJurisdiction: New Hampshire
Authority: New Hampshire State Board of Education / Department of Education
Requires school districts to adopt a policy under which students may not be required to take non-academic surveys (about social behavior, family life, religion, politics, sexual orientation or activity, drug use and similar topics) without written parental consent, except the CDC Youth Risk Behavior Survey, which parents may opt out of. Surveys must be posted for parental review at least 10 days before use.
Nonconsensual Dissemination of Private Sexual Images
NH Intimate Image LawJurisdiction: New Hampshire
Effective: 7/19/2016
Authority: State and county prosecutors
Criminalizes purposely sharing an identifiable person's sexual or intimate images, obtained in circumstances where privacy was expected, to harass, intimidate, threaten or coerce them without consent. A 2024 amendment effective Jan. 1, 2025 extends the offense to realistic synthetic images created by manipulating a recognizable person's likeness.
Nonconsensual Dissemination of Private Sexual Images (civil and criminal)
MN NCII LawJurisdiction: Minnesota
Authority: Depicted individual by civil action (604.31); criminal prosecution (617.261)
Enacted in 2016, these sections let a person sue, and allow prosecution of anyone, who shares sexual images of an identifiable person without consent when the image was made or obtained with a reasonable expectation of privacy. The civil section also covers using someone's personal information to solicit sexual acts in a way meant to harass or frighten them, and it preserves Section 230 protections for platforms.
Nonconsensual dissemination of private sexual images (including AI-generated depictions)
OK Intimate Image LawJurisdiction: Oklahoma
Effective: 11/1/2016
Authority: District attorneys (criminal prosecution)
Criminalizes disseminating sexual images obtained under circumstances indicating they were to remain private, without the depicted person's consent. A 2025 amendment (Laws 2025, c. 23, effective November 1, 2025) extends the crime to artificially generated sexual depictions ('deepfakes') disseminated to harass or harm the depicted person.
Nonconsensual Dissemination of Sexual Deep Fakes (civil and criminal)
MN Intimate Deepfake LawJurisdiction: Minnesota
Effective: 8/1/2023
Authority: Depicted individual by civil action (604.32); criminal prosecution (617.262)
Creates a civil cause of action and a crime for spreading AI-generated or otherwise technically produced sexual deep fakes of an identifiable person without consent to public dissemination. Consent to creation or private sharing is not a defense, and courts must allow confidential filings to protect the plaintiff's privacy.
Nonconsensual distribution of intimate images (revenge porn), including computer-generated images
MD Revenge Porn LawJurisdiction: Maryland
Authority: State's Attorneys (criminal); civil actions by the person depicted
Maryland criminalizes knowingly distributing intimate images of an identifiable person, with intent to harm, harass, or coerce, when the person knew or recklessly disregarded that the subject did not consent and the subject reasonably expected the image to stay private. A 2025 amendment (ch. 219) extended the definition to computer-generated images indistinguishable from the person and strengthened the civil action.
Nonconsensual distribution of intimate images and sexually explicit deepfakes (civil actions)
Civ. Code 1708.85-1708.86Jurisdiction: California
Effective: 1/1/2015
Authority: Private plaintiffs (courts)
Gives victims a civil claim against people who share their intimate images without consent (revenge porn) and against those who create or distribute sexually explicit AI or digitally altered depictions of them without consent. Plaintiffs may proceed under a pseudonym.
Nonconsensual Intimate Images (criminal distribution and civil action), including AI-generated images
IN Intimate Image LawJurisdiction: Indiana
Effective: 7/1/2019
Authority: County prosecutors (criminal); depicted individuals (civil)
Indiana makes it a crime to distribute an intimate image when the distributor knows or should know the person shown did not consent. Since July 1, 2024, this covers images created or altered with AI or editing software. A separate civil action lets identifiable victims sue people who disclose intimate images to harass, intimidate, embarrass, or profit.
Notice of Intent to Sell Nonpublic Personal Information Act
Utah NPI Notice ActJurisdiction: Utah
Authority: None stated; private individual actions only
Requires a commercial entity that may sell consumers' nonpublic personal information (such as SSN, creditworthiness, purchasing patterns, or preferences) to give a prescribed, conspicuous notice before collecting it. 2025 S.B. 150 limited coverage to entities with a staffed physical office in Utah and barred class actions.
Notice of Monitoring of Telephone Transmissions, Electronic Mail and Internet Usage
DE Employee Monitoring NoticeJurisdiction: Delaware
Effective: 8/9/2001
Authority: Civil penalty claims may be filed in any court of competent jurisdiction (705(c))
Delaware employers may not monitor or intercept employees' phone calls, email, or Internet use unless they give notice, either a daily electronic notice when the employee logs on or a one-time written or electronic notice the employee acknowledges. Automated volume-management and system-maintenance processes not aimed at a particular person are exempt.
Notice of Security Breach
NH Breach Notification LawJurisdiction: New Hampshire
Effective: 1/1/2007
Authority: New Hampshire Attorney General (under RSA 358-A:4); private individuals may also sue
Requires anyone doing business in New Hampshire to investigate a breach of computerized personal information (name plus SSN, driver's license or government ID number, or financial account/card number with access code) and notify affected individuals as soon as possible when misuse has occurred, is reasonably likely, or cannot be ruled out. The Attorney General or the entity's primary regulator must also be told, and nationwide consumer reporting agencies when more than 1,000 consumers are notified.
Notification of tax return data breach (income tax return preparers)
VA tax preparer breachJurisdiction: Virginia
Effective: 7/1/2018
Authority: Virginia Department of Taxation (receives notices)
Requires paid tax return preparers to notify the Virginia Department of Taxation without unreasonable delay after unauthorized acquisition of unencrypted taxpayer return information that causes or may cause identity theft or fraud, so the Department can guard against fraudulent refunds.
Obtaining personal information by false representation (anti-phishing)
ORS 646A.808Jurisdiction: Oregon
Effective: 5/21/2015
Authority: Oregon Attorney General and district attorneys (ORS 646.632)
Bars phishing: using electronic means to get someone's personal information by pretending, without permission, to be another person or business.
Off Duty Use of Tobacco by Employee
IN Off-Duty Tobacco UseJurisdiction: Indiana
Authority: Private enforcement by employees and applicants
Indiana employers may not require employees or applicants to avoid tobacco use outside work, or discriminate against them for it. Health-benefit incentives meant to reduce tobacco use are allowed.
Oklahoma Consumer Data Privacy Act (data privacy provisions of 2026 SB 546)
OKCDPAJurisdiction: Oklahoma
Effective: 1/1/2027
Authority: Oklahoma Attorney General (exclusive authority)
Oklahoma's comprehensive consumer privacy law, signed March 20, 2026, gives Oklahoma residents rights to confirm, access, correct, delete, and port their personal data and to opt out of targeted advertising, sale, and significant-decision profiling. Controllers must minimize collection, secure data, get consent before processing sensitive data (COPPA-compliant processing for known children), publish a privacy notice, and conduct data protection assessments for higher-risk processing. It takes effect January 1, 2027.
Oklahoma Consumer Report Security Freeze Act
OK Security Freeze ActJurisdiction: Oklahoma
Effective: 1/1/2007
Authority: Private enforcement by consumers in court
Lets Oklahoma residents place a security freeze on their credit reports so consumer reporting agencies cannot release the report or score for new credit without the consumer's authorization. Sets deadlines for placing, temporarily lifting, and removing freezes and gives consumers a damages remedy.
Oklahoma Hospital Cybersecurity Protection Act of 2023
OK Hospital Cybersecurity ActJurisdiction: Oklahoma
Effective: 11/1/2023
Authority: None (safe-harbor statute applied by courts)
A voluntary cybersecurity safe harbor for Oklahoma hospitals. A hospital that keeps a documented written cybersecurity program reasonably conforming to the HIPAA Security Rule and HITECH requirements, reviewed annually, gets an affirmative defense to tort suits over data breaches of personal or other identifying information.
Oklahoma Responsible Technology in Schools Act
OK Responsible Technology in Schools ActJurisdiction: Oklahoma
Effective: 7/1/2026
Authority: State Board of Education (rulemaking) and State Department of Education (guidance)
Sets guardrails for AI use in Oklahoma public schools: AI must be educator-directed with a human in the loop, may not be the primary basis for grading, discipline, or placement, and must comply with student data privacy laws with data minimization. Districts must give parents an annual written disclosure of AI tools, vendors, and student data collected and shared, let parents opt students out of student-facing AI, and adopt an AI policy before the 2027-2028 school year.
Online Age Verification Liability Act
Nebraska Online Age Verification Liability ActJurisdiction: Nebraska
Effective: 7/19/2024
Authority: Private civil action only (no agency enforcement provision in the act)
Enacted by LB1092 (2024), this law requires adult-content websites to verify that users are at least 18 using a digitized ID, government ID, financial or other reliable document, or a commercially reasonable transactional-data method. It has a privacy component: the site or its verifier may not keep identifying information after granting access.
Online Education Services and Student Educational Records Act (student data privacy)
NJ Student Online Privacy LawJurisdiction: New Jersey
Effective: 7/19/2020
Authority: New Jersey Attorney General / Division of Consumer Affairs (Consumer Fraud Act), with rulemaking in consultation with the Commissioner of Education
This student data privacy law bars K-12 ed-tech operators from using students' information for targeted advertising, building non-school profiles, or selling or renting it, and limits when they may disclose it. Operators must secure student data and delete it at the request of the school, the district, or a student who has turned 18.
Online Services, Products or Features Offered to Minors (heightened-risk duty of care)
CT Minors Online ServicesJurisdiction: Connecticut
Effective: 10/1/2024
Authority: Connecticut Attorney General (solely; Conn. Gen. Stat. 42-529e(a))
Requires online services that know or wilfully disregard that users are minors to use reasonable care to avoid a heightened risk of harm to them, document data protection assessments, and limit how minors' data is used. From July 1, 2026 (P.A. 25-113), targeted advertising and sale of minors' data are flatly banned regardless of consent, adult-to-minor unsolicited messaging must be blocked by default, and engagement-maximizing design features are restricted.
Online services, products, or features likely to be accessed by children (AB 2246, 2026 replacement of the Age-Appropriate Design Code)
AB 2246 Children's Online Design LawJurisdiction: California
Effective: 1/1/2027
Authority: California Attorney General and public prosecutors
Signed September 10, 2026, AB 2246 repeals the 2022 Age-Appropriate Design Code and re-enacts a narrower version: age estimation (tied to the Digital Age Assurance Act signals) or child protections for all users, high-privacy defaults, limits on profiling, data collection, and precise geolocation, and a new duty to take reasonable steps to prevent listed harms to children. It drops the data protection impact assessment and 'best interests' tests that courts had enjoined, and it lets a child void contract terms obtained through a design feature.
Opportunity to Compete Act (criminal history inquiries in hiring)
NJ Opportunity to Compete ActJurisdiction: New Jersey
Effective: 3/1/2015
Authority: New Jersey Commissioner of Labor and Workforce Development
New Jersey's ban-the-box law bars covered employers from asking about an applicant's criminal record, including expunged records, on applications or otherwise during the initial application process, which ends after the first interview. Employers may ask later, or earlier if the applicant volunteers the information, but may not refuse to hire based on an expunged record.
Oregon Consumer Information Protection Act: breach notification
OCIPA breach notificationJurisdiction: Oregon
Effective: 10/1/2007
Authority: Oregon Attorney General (unlawful practice under ORS 646.607) and the Director of the Department of Consumer and Business Services (ORS 646A.624)
Requires any business or other entity holding Oregon residents' personal information to notify affected consumers of a data breach within 45 days, and the Attorney General when more than 250 Oregonians are affected. Vendors must alert the covered entity within 10 days. Notice may be skipped only after a documented determination that harm is unlikely.
Oregon Consumer Information Protection Act: data security, disposal and SSN protection
OCIPA safeguards and SSNJurisdiction: Oregon
Effective: 10/1/2007
Authority: Oregon Attorney General (ORS 646.607(9)) and Director of the Department of Consumer and Business Services (ORS 646A.624)
Requires covered entities and vendors to keep reasonable administrative, technical and physical safeguards for personal information, including secure disposal, with safe harbors for GLBA or HIPAA compliance and a scaled standard for small businesses. It also restricts printing, posting and careless disposal of Social Security numbers.
Oregon Consumer Information Protection Act: security freeze
OCIPA security freezeJurisdiction: Oregon
Effective: 10/1/2007
Authority: Director of the Department of Consumer and Business Services (ORS 646A.624) and Oregon Attorney General (ORS 646.607(9))
Lets Oregon consumers, and representatives of children 16 and under or incapacitated adults, freeze their credit reports for free. Agencies must place a freeze within five business days and create a frozen protective record for a protected consumer who has no file.
Oregon Consumer Privacy Act
OCPAJurisdiction: Oregon
Effective: 7/1/2024
Authority: Oregon Attorney General (Department of Justice), exclusive (ORS 646A.589(7))
Max Fine: Up to $7,500 per violation
Oregon's comprehensive consumer privacy law gives residents rights to confirm processing, get a list of specific third parties that received their data, access, correct, delete, and port their data, and opt out of targeted advertising, sale, and significant-decision profiling. Controllers must give a privacy notice, minimize data, secure it, get opt-in consent for sensitive data, run data protection assessments, and (since 2026-01-01) honor universal opt-out signals. 2025 amendments bar selling precise geolocation data and data of known under-16 consumers and extend coverage to all vehicle makers.
Oregon Data Broker Registry law
Data Broker RegistryJurisdiction: Oregon
Effective: 1/1/2024
Authority: Oregon Department of Consumer and Business Services (Division of Financial Regulation)
Requires data brokers to register annually (mandatory since January 1, 2024; $600 fee) with the Department of Consumer and Business Services before collecting, selling or licensing brokered personal data about Oregon residents. Registration discloses whether and how residents can opt out, and the department publishes registrant information online.
Oregon financial records privacy law
ORS 192.583-192.607Jurisdiction: Oregon
Authority: Private civil action by customers (ORS 192.606)
Bars Oregon financial institutions from handing customer financial records to state or local agencies, and bars agencies from requesting them, except through listed channels such as customer authorization, subpoena or summons, search warrant, or abuse investigations.
Oregon Genetic Privacy Act
Oregon Genetic Privacy ActJurisdiction: Oregon
Authority: Oregon Attorney General and district attorneys (ORS 192.545); Oregon Health Authority rules (ORS 192.547); private actions (ORS 192.541)
Treats genetic information and DNA samples as private property of the individual in practice: they may not be obtained without informed consent, must be kept confidential, and may not be disclosed in identifiable form without specific written consent except in narrow cases. It carries some of the highest statutory damages of any state genetic privacy law.
Oregon insurance information and privacy protection law
ORS 746.600-746.690Jurisdiction: Oregon
Authority: Director of the Department of Consumer and Business Services (Division of Financial Regulation) (ORS 746.670); limited private remedies (ORS 746.680)
Oregon's version of the NAIC insurance privacy model, combined with GLBA-style notice rules. It requires privacy notices, limits pretext interviews and disclosures, gives consumers rights to access and correct recorded personal information and to learn the reasons for adverse underwriting decisions, and limits use of credit history and insurance scores in personal lines.
Oregon interception and recording of communications law
ORS 165.540 (recording consent)Jurisdiction: Oregon
Authority: District attorneys and Oregon Attorney General (criminal); private civil actions under ORS 133.739
Oregon is one-party consent for telephone and radio communications but requires that all participants be specifically informed before an in-person conversation is recorded with a device. It also bars using or disclosing unlawfully obtained communications, with exceptions for open recordings of public meetings, classes, police officers performing duties, and certain video-conference recordings.
Oregon motor vehicle records privacy law
ORS 802.175-802.191Jurisdiction: Oregon
Authority: Attorney General, district attorneys, and aggrieved individuals (ORS 802.191)
Oregon's counterpart to the federal Driver's Privacy Protection Act. It bars DMV disclosure of personal information from motor vehicle records except for permitted purposes and restricts resale and redisclosure by recipients, with record-keeping duties and a private right of action.
Oregon protected health information law
ORS 192.553-192.581 (PHI)Jurisdiction: Oregon
Authority: No specific enforcer named; no new private right of action (ORS 192.571)
Oregon's state counterpart to HIPAA declares a right to have protected health information safeguarded and to access it, and sets when health care providers and state health plans may use or disclose it with or without authorization. It works alongside the federal HIPAA Privacy Rule.
Oregon Student Information Protection Act
OSIPAJurisdiction: Oregon
Effective: 7/1/2016
Authority: Oregon Attorney General (unlawful trade practice under ORS 646.607(11))
Oregon's K-12 edtech privacy law, modeled on California's SOPIPA. It bars operators of school-purpose sites and apps from targeted advertising, building student profiles for non-school purposes, selling student information, and most disclosures, and requires reasonable security and deletion at a school's request.
Oregon telephone solicitation laws (telephonic seller registration, no-call list, solicitation limits)
Oregon Telephone Solicitation LawsJurisdiction: Oregon
Authority: Oregon Attorney General (Department of Justice); private enforcement under ORS 646.638
Oregon requires telephonic sellers to register with the Department of Justice, bars telephone solicitations to numbers on the do-not-call list (Oregon uses the federal registry), and limits when and how often sellers may call or text. A 2025 law (HB 3865) extended the solicitation rules to text messages starting January 1, 2026.
Oversight of Artificial Intelligence Technology in Mental Health Care Act
RI Mental Health AI ActJurisdiction: Rhode Island
Effective: 6/22/2026
Authority: Rhode Island Executive Office of Health and Human Services (investigation and rules); courts and prosecutors for confidentiality penalties
Limits how AI may be used in mental health care. Licensed therapists may use AI for administrative and supplementary tasks, but may not let it make therapeutic decisions, set treatment plans or talk with clients therapeutically, and must get written informed consent before using emotionally engaging or companion-type AI in recorded or transcribed sessions. Only licensed professionals may offer therapy to the public, including through AI apps, and therapy records and communications stay confidential.
Ownership and Control of Patient Records; Confidentiality (health care practitioners)
Florida Patient Records LawJurisdiction: Florida
Authority: Professional licensing boards and the Department of Health; Florida Attorney General for records owners not licensed by the state
Florida's core medical-records privacy rule for doctors and other licensed practitioners. It requires practitioners to give patients copies of their records promptly and at no more than cost, bars disclosing records or discussing a patient's condition without written authorization except in listed cases, and sets duties when a practice closes or moves.
Parent's Accountability and Child Protection Act (online sales of age-restricted products)
Civ. Code 1798.99.1Jurisdiction: California
Effective: 1/1/2020
Authority: California Attorney General and local prosecutors
Requires sellers of products and services that minors may not legally buy to take reasonable steps (such as checking government ID, requiring a non-prepaid credit card, or shipping only to an adult) to confirm buyers are of legal age, and bars using the age-verification data for anything else.
Parental Access to Student Records (education records disclosures)
IN Student Records AccessJurisdiction: Indiana
Authority: Not specified in the chapter
Indiana requires public and private schools to give custodial and noncustodial parents equal access to a child's education records unless a court order limits access. It also sets when FERPA-covered schools may share education records with juvenile justice agencies or in health and safety emergencies without parental consent.
Parental Bill of Rights (school records, data collection and recording provisions)
NH Parental Bill of RightsJurisdiction: New Hampshire
Effective: 7/1/2025
Authority: Courts, through parent lawsuits
Lists parental rights that public schools may not infringe without clear and convincing evidence of a narrowly tailored compelling interest. Privacy-related rights include opting a child out of nonacademic surveys and district-level data collection not required by law, accessing education and school-held medical records within 10 business days, and written consent before the school or state makes video or voice recordings of the child, with limited exceptions.
Parental Rights in Social Media Act
Nebraska PRSMAJurisdiction: Nebraska
Effective: 7/1/2026
Authority: Nebraska Attorney General
Enacted as sections 26-30 of LB383 (2025), this law requires social media platforms to verify the age of new account holders, bar minors from opening accounts without verified parental consent, delete verification data, and give parents tools to supervise a minor's account. On June 27, 2026, the U.S. District Court for the District of Nebraska (NetChoice v. Hilgers, No. 4:26-cv-3149) preliminarily enjoined the Attorney General from enforcing the age verification requirement in 86-1703(1)(a) and the parental consent requirement in 86-1703(2); the court held the remaining provisions, including parental supervision of posts and messages, may be enforced. Status is recorded as enjoined because the core account-creation duties are blocked; the other duties are in force.
Parents' Bill of Rights
OK Parents' Bill of RightsJurisdiction: Oklahoma
Effective: 11/1/2014
Authority: Courts; district attorneys for the misdemeanor consent provisions
Reserves parental rights to direct a child's upbringing, education, and health care, including rights to review the child's school and medical records and to give written consent before a child's biometric scan is made, shared, or stored or a record of the child's blood or DNA is created, stored, or shared. It also requires written parental consent before government records video or voice of a child (with exceptions) and before most medical or mental health treatment of minors.
Patient access to medical records
OK Medical Records AccessJurisdiction: Oklahoma
Effective: 4/8/1976
Authority: District attorneys (misdemeanor for refusal); courts
Gives current and former patients a right to access and obtain copies of their medical records, images, and bills, and caps copy fees (with lower digital rates and no search or retrieval fees for patients). It also sets rules for release of a deceased patient's records and waiver of privilege in medical injury suits.
Patient access to medical records
Colorado patient records accessJurisdiction: Colorado
Effective: 7/1/1976
Authority: Colorado Department of Public Health and Environment and professional licensing boards
Colorado gives patients and their personal representatives the right to inspect and obtain copies of their medical records, including X-rays, from health facilities and individual providers, consistent with HIPAA's access exceptions. Records must be delivered electronically when requested and kept electronically, inspection is free, and copy fees are limited to what HIPAA allows. The Colorado Privacy Act exempts health-care information governed by this part for purposes of records access.
Patient Access to Medical Records
Nebraska Medical Records Access LawJurisdiction: Nebraska
Authority: No specific enforcement provision
This law gives patients and their authorized representatives a right to examine and copy their medical records, with fee caps. Written authorizations that lack an expiration expire after 12 months, and mental health records may be withheld if a treating professional finds release is not in the patient's best interest.
Patient Access to Medical Records and Test Results
CT Medical Records AccessJurisdiction: Connecticut
Authority: Connecticut Department of Public Health (licensing)
Requires providers to give patients, on request, complete and current information about their diagnosis, treatment and prognosis, to notify patients of test results, and to furnish copies of records; clinical labs must release results to patients on request.
Patient's Privacy Protection Act
Tenn. Patient's Privacy Protection ActJurisdiction: Tennessee
Authority: Tennessee Department of Health and licensing board (penalties and injunctions under title 68, chapter 11); patients through civil actions
Gives every patient at a licensed Tennessee health care facility a right to privacy for the care received there. Facilities may not divulge a patient's name, address, or other identifying information except for required reports, payer administrative access, treating providers, directory information when the patient has been told of and not used the right to object, and certain fraud investigations.
Patients' Bill of Rights (licensed health facilities, confidentiality of records)
NH Patients' Bill of RightsJurisdiction: New Hampshire
Authority: NH Department of Health and Human Services (facility licensing)
Requires every licensed health facility's patient rights policy to guarantee privacy in treatment and personal care and confidential handling of personal and clinical records, including electronically stored data. Release to anyone not authorized by law requires the patient's written consent, and patients own and may copy the medical information in their facility records.
Payment card receipt truncation
MD Card Receipt TruncationJurisdiction: Maryland
Authority: Attorney General (14-1318(d))
Merchants in Maryland may not print more than five digits of a credit or debit card number, or the card's expiration date, on electronically printed customer receipts.
Peeping Tom and clandestine video voyeurism law
OK Peeping Tom LawJurisdiction: Oklahoma
Authority: District attorneys (criminal prosecution)
Criminalizes lurking to secretly watch people in homes, locker rooms, restrooms, and similar private places, and using cameras or electronic equipment to secretly view or record people there or to capture images of their private areas, including publishing such images.
Pen Register, Trap and Trace, and Mobile Tracking Device Restrictions
MN Tracking Device LawJurisdiction: Minnesota
Authority: Private civil action by harmed persons (626A.391); court orders govern law enforcement use (626A.36 to 626A.38)
No one may install or use a pen register, trap and trace device, or mobile tracking device (such as a GPS tracker) without a court order, unless an exception applies, most notably consent of the owner of the object to which a tracker is attached. People harmed by unlawful tracking or call-data capture can sue for damages and attorney fees.
Personal Information and Privacy Protection Act (retail ID card scanning)
NJ PIPPAJurisdiction: New Jersey
Effective: 10/1/2017
Authority: Civil penalties collected in a summary proceeding under the Penalty Enforcement Law of 1999; aggrieved persons may sue in Superior Court
New Jersey retailers may scan a customer's ID card only for eight listed purposes, such as verifying identity for non-cash payments or returns, checking age, preventing return or credit fraud, or meeting legal requirements. They may capture only name, address, date of birth, issuing state, and ID number, may not keep data scanned for identity or age checks, and may not sell or share scanned data for marketing.
Personal information on the internet: protected persons (anti-doxxing)
Colorado protected-person doxxing lawJurisdiction: Colorado
Effective: 7/1/2002
Authority: District attorneys (criminal prosecution)
Colorado makes it a crime to knowingly post a protected person's personal information online when doing so poses an imminent and serious threat to their or their family's safety. Protected persons can also ask government officials to remove their personal information from online public records. Recent amendments added educators (2022), health-care workers and others (2023), and firefighters (2024).
Personal Information Privacy Act (merchant sale of purchaser information, check DOB, driver's license scanning)
VA PIPAJurisdiction: Virginia
Effective: 7/1/1992
Authority: Aggrieved persons in general district court (59.1-444)
An older retail privacy law. Merchants must give notice (a sign is enough) before selling purchaser information gathered in a sale and must honor a customer's request not to sell it; they cannot sell information gathered only from check, card, or ID-number payment records. It also bars requiring a date of birth to accept a check and limits when merchants may scan, keep, or sell data from a driver's license barcode.
Personal Information Security and Breach Investigation Law for Public Agencies and Nonaffiliated Third Parties
KY Public Agency / Vendor Data Security (HB 5)Jurisdiction: Kentucky
Effective: 1/1/2015
Authority: Kentucky Attorney General (Franklin Circuit Court)
Requires public agencies and the private contractors that receive personal information from them to maintain reasonable security and breach investigation procedures. Contractors must report breaches to the agency within 72 hours, and agencies must notify state officials within 72 hours, investigate, and notify affected individuals within 35 days of concluding misuse is likely. Personal information includes name, personal mark, or a biometric or genetic print combined with identifiers such as SSN, account numbers, ID numbers, or health information.
Personal Information Security Breach Protection
Iowa Breach Notification LawJurisdiction: Iowa
Effective: 7/1/2008
Authority: Iowa Attorney General (Consumer Protection Division), as an unlawful practice under Iowa Code 714.16
Iowa's breach law requires anyone who owns or licenses computerized personal information of Iowa residents to notify affected residents of a breach of security without unreasonable delay, and to notify the Attorney General within five business days if more than 500 Iowans are notified. It also covers paper records that were printed from computerized form. Notice is not required if a documented investigation finds no reasonable likelihood of financial harm.
Personal Online Account Privacy Protection Act
LA POAPPAJurisdiction: Louisiana
Effective: 8/1/2014
Authority: None specified
Bars employers and schools from requiring employees, applicants, students, or prospective students to hand over usernames, passwords, or other login credentials for their personal online accounts, and from punishing them for refusing. Employers may still require credentials for employer-provided devices and business accounts and may investigate specific reports of misconduct or data leakage. The law creates no duty to monitor personal accounts.
Personnel Information: Employee Access to Personnel Files
Iowa Personnel File Access LawJurisdiction: Iowa
Authority: Not specified in the section
Iowa employees have the right to see and copy their personnel files, including performance evaluations and disciplinary records. Employers may set a mutually agreed time, have a representative present, withhold references, and charge commercial-rate copy fees.
Persons Holding a Customer's Personal Information (disposal of customer records)
IN Customer Data DisposalJurisdiction: Indiana
Authority: Prosecuted as an infraction (no agency named in the chapter)
This chapter makes it an infraction to throw away or abandon customers' unencrypted, unredacted personal information (as defined in the breach law, such as SSNs and financial account numbers) in a publicly accessible place without first destroying it. It covers paper and digital records.
Physician-Patient Communication (Medical Practice Act confidentiality)
Texas Physician-Patient ConfidentialityJurisdiction: Texas
Effective: 9/1/1999
Authority: Texas Medical Board; aggrieved patients
Makes physician-patient communications and physician records of identity, diagnosis, evaluation, and treatment confidential and privileged, with listed exceptions, and gives patients a right to copies within 15 business days of written consent. S.B. 922 (2025) delays online release of sensitive test results such as possible cancer findings and genetic markers until the third day after they are finalized.
Polygraph and Lie Detector Test Prohibition
DE Polygraph BanJurisdiction: Delaware
Authority: Civil penalty claims may be filed in any court of competent jurisdiction (704(c))
Prohibits requiring, requesting, or suggesting that an employee or job applicant take a polygraph, lie detector, or voice-stress test as a condition of employment. Law-enforcement agencies are exempt for their own official duties.
Polygraph Examination Prohibited (employment)
Iowa Employee Polygraph Protection LawJurisdiction: Iowa
Authority: Aggrieved employees and applicants (civil action); county attorneys and the Attorney General (injunctions and criminal prosecution)
Iowa bars employers from requesting, requiring, or administering lie detector tests to employees or job applicants as a condition of employment or benefits, or asking them to waive this protection. Employees who complain or testify are protected from retaliation.
Polygraph Protection Act
VT Polygraph Protection ActJurisdiction: Vermont
Authority: Criminal prosecution (State's Attorneys / Attorney General)
Generally bars employers from requiring, requesting or giving lie detector tests to employees or job applicants, or from refusing to hire or promote someone who declines one. Limited exceptions are listed in § 494b.
Predictive Genetic Testing Informed Consent
Nebraska Genetic Testing Informed Consent LawJurisdiction: Nebraska
Authority: Not stated in the section (professional regulation by the Department of Health and Human Services)
Nebraska requires written informed consent before a physician orders a predictive genetic test. The consent must explain the test's purpose and limits, future uses of the sample and genetic information, who can access them, and the patient's right to confidential treatment.
Prescription Information to be Kept Confidential
NH Prescription Confidentiality ActJurisdiction: New Hampshire
Effective: 6/30/2006
Authority: Not specified in the section (pharmacy board and Attorney General have general authority)
Bars pharmacies, PBMs, insurers and transmission intermediaries from licensing, transferring, using or selling prescription records containing patient- or prescriber-identifiable data for commercial purposes, apart from reimbursement, formulary compliance, care management, utilization review, health care research, or as otherwise allowed by law. The First Circuit upheld the law in IMS Health v. Ayotte (2008), but that ruling was abrogated by Sorrell v. IMS Health (2011), which struck down a similar Vermont prescriber-data law, so the prescriber-data restriction is constitutionally vulnerable.
Preventing Deepfake Images Act
Preventing Deepfake Images ActJurisdiction: Tennessee
Effective: 7/1/2025
Authority: Depicted individuals (civil action); district attorneys (criminal prosecution)
Creates a civil cause of action and a crime for intentionally disclosing a sexually explicit or intimate digital depiction of an identifiable person, created or altered by digital manipulation including AI deepfakes, without the person's consent. Consent to creation is not consent to disclosure, valid consent must be a signed plain-language agreement, and a disclaimer that the image is fake is not a defense.
Preventing Unauthorized Disclosure of Intimate Digital Depictions Act
Colorado intimate deepfakes (SB 25-288)Jurisdiction: Colorado
Effective: 8/6/2025
Authority: Depicted individuals (civil action); district attorneys (criminal offenses)
SB 25-288 lets people sue anyone who knowingly or recklessly discloses, or threatens to disclose, a realistic AI-generated or edited intimate image of them without consent. It also extends Colorado's crimes for posting private intimate images, and its child sexual exploitation laws, to realistic computer-generated depictions.
Privacy Act Governing the Release of Motor Vehicle Driving History and License Records
DE Driver Privacy ActJurisdiction: Delaware
Authority: Criminal prosecution by the State; civil actions by the individual (305(n)-(o))
Delaware's counterpart to the federal Driver's Privacy Protection Act limits disclosure of personal information in DMV records to listed permissible uses, binds private recipients who resell or redisclose it, and lets individuals ask for added confidentiality of their address, phone number, and SSN. Misuse is a crime and gives the affected person a civil claim.
Privacy and Disclosure of Bureau of Motor Vehicles Records
IN BMV Records PrivacyJurisdiction: Indiana
Authority: Indiana Bureau of Motor Vehicles; county prosecutors
Indiana's state counterpart to the federal Driver's Privacy Protection Act bars BMV disclosure of personal information except for listed permissible uses, such as government functions, vehicle safety and recalls, fraud prevention by businesses, and litigation. Highly restricted information (photos, SSNs, medical and disability data) generally needs express written consent. Private recipients who resell or redisclose the data must stay within permitted uses and keep records of who received it.
Privacy in Communications (recording consent and interception)
MT Privacy in CommunicationsJurisdiction: Montana
Authority: County attorneys and the Attorney General (criminal prosecution)
Montana is an all-party-consent state for hidden recording: it is a crime to record a conversation with a hidden device without the knowledge of all parties, unless the parties were warned. It is also a crime to purposely intercept electronic communications without warning. A 2025 amendment (Ch. 686, L. 2025) added AI-generated ('digitally fabricated') intimate images to the image-disclosure and sextortion offenses.
Privacy in Private Spaces (employee recording in restrooms and locker rooms)
RI Employee Private Spaces LawJurisdiction: Rhode Island
Authority: Courts via employee civil actions
Prohibits employers from making audio or video recordings of employees in restrooms, locker rooms or employer-designated changing rooms unless a court order authorizes it, and bars any use of recordings made in violation.
Privacy of Consumer Financial and Health Information (Insurance Department rules)
NH Ins 3000Jurisdiction: New Hampshire
Effective: 7/1/2001
Authority: New Hampshire Insurance Commissioner
New Hampshire's insurance privacy rules, modeled on the NAIC privacy model regulation, require licensees to give privacy notices and let consumers opt out before nonpublic personal financial information is shared with nonaffiliated third parties. They also require the consumer's written or electronic authorization before a licensee discloses nonpublic personal health information, apart from listed insurance functions.
Privacy of Consumer Financial and Health Information (Iowa Insurance Division rules)
Iowa Insurance Privacy RuleJurisdiction: Iowa
Effective: 11/13/2000
Authority: Iowa Commissioner of Insurance (Iowa Insurance Division)
Iowa's insurance privacy rules, based on the NAIC model, require insurance licensees to give privacy notices, let consumers opt out of sharing financial information with nonaffiliated third parties, and obtain authorization before disclosing health information except for core insurance functions. They also require an information security program.
Privacy of Consumer Financial and Health Information and Standards for Safeguarding Customer Information (insurance regulations)
RI Insurance Privacy RegulationsJurisdiction: Rhode Island
Authority: Rhode Island Department of Business Regulation, Insurance Division
Rhode Island's insurance-sector implementation of Gramm-Leach-Bliley privacy and safeguards rules, adopted under R.I. Gen. Laws §§ 27-58-4 and 27-58-10. Licensees must give initial and annual privacy notices and an opt-out before sharing consumers' nonpublic financial information with nonaffiliated third parties, must obtain written authorization before disclosing nonpublic health information outside listed insurance functions, and must maintain written information security programs.
Privacy of Firearms Financial Transactions
IN Firearms Transaction PrivacyJurisdiction: Indiana
Effective: 10/1/2024
Authority: The provider's primary financial regulator; the Indiana Attorney General for the registry ban as applied to persons who are not regulated financial services providers (IC 24-5-27.5-25)
Enacted by HEA 1084 (2024), this law bars payment networks and acquirers from assigning a separate firearms merchant category code to Indiana gun retailers. It restricts financial providers from disclosing transaction records grouped by a firearms code and from declining transactions based solely on such a code. It also bars anyone from keeping a registry of privately owned firearms or their owners, with exceptions.
Privacy of genetic test results
LA Genetic Test ConfidentialityJurisdiction: Louisiana
Authority: None specified
Makes the results of prenatal and postnatal genetic tests confidential medical information that becomes part of the tested person's medical record. Results may be released only with the tested person's express written consent, except for genetic tests the law specifically requires to be reported.
Privacy of Insurance Consumer Information Act
Nebraska Insurance Privacy ActJurisdiction: Nebraska
Authority: Nebraska Department of Insurance (Director of Insurance)
Nebraska's insurance privacy law implements Gramm-Leach-Bliley Title V for insurance licensees, based on the NAIC model. It requires initial and annual privacy notices, an opt-out before sharing nonpublic personal financial information with nonaffiliated third parties, and written authorization before disclosing nonpublic personal health information, subject to listed insurance-function exceptions.
Privacy Rights for California Minors in the Digital World (online eraser and harmful-product marketing limits)
Minors Online Privacy (22580)Jurisdiction: California
Effective: 1/1/2015
Authority: California Attorney General and local prosecutors (Unfair Competition Law)
Lets registered minor users remove content they posted (the 'online eraser') and bars marketing of alcohol, firearms, tobacco, cannabis, and other listed age-restricted products to minors, including using minors' personal information for that marketing.
Private Sector Drug-Free Workplaces (employee drug and alcohol testing)
Iowa Workplace Drug Testing LawJurisdiction: Iowa
Authority: Aggrieved employees and applicants (civil action); county attorneys and the Attorney General (injunctions; Attorney General civil penalties for certain provisions)
Iowa permits private employers to drug and alcohol test employees and applicants only under a written policy and strict procedures. The law protects privacy during sample collection, keeps test communications confidential, gives tested workers access to their records and a right to a confirmatory retest, and lets aggrieved workers sue.
Prohibited Spyware
IN Spyware ActJurisdiction: Indiana
Authority: Private enforcement by adversely affected software providers, website owners, and trademark owners
Indiana's spyware law bars installing software on someone else's computer that deceptively changes browser settings, logs keystrokes, or ties personal information to browsing history. It also bars extracting financial or identity data from the hard drive and tricking users into installing software with false security or privacy claims.
Prohibited Use of Crime Victim or Motor Vehicle Collision Information
Texas Crime Victim Information LawJurisdiction: Texas
Effective: 4/1/2009
Authority: Texas Attorney General (DTPA 17.47 action); prosecutors
Bars using crime victim or crash information obtained from law enforcement to directly solicit victims, crash participants, or their families, and bars selling that information for profit.
Prohibited use of employee's Social Security number
VA employee SSNJurisdiction: Virginia
Effective: 7/1/2023
Authority: Commissioner of Labor and Industry (40.1-28.7:10(B)-(C))
Bars employers from using an employee's Social Security number, or a number derived from it, as the employee's ID number or printing it on ID, access, or similar badges.
Prohibited Uses of Artificial Intelligence in Mental Health Services
VT AI Mental Health LawJurisdiction: Vermont
Effective: 6/17/2026
Authority: Vermont Attorney General (Consumer Protection Act); Office of Professional Regulation and Board of Medical Practice for licensees
Bars companies from offering mental health services to the public, including AI therapy chatbots, unless a licensed or rostered mental health professional provides them or they are part of an approved IRB or privacy board study. Professionals may use HIPAA-compliant AI tools and FDA-authorized digital therapeutics if they review and approve the services.
Prohibiting Social Media Manipulation Act
MN Social Media Manipulation ActJurisdiction: Minnesota
Effective: 7/1/2025
Authority: Minnesota Attorney General (325M.34)
Requires large social media platforms to publicly post how they limit excessive account interactions, how their ranking algorithms weigh content quality and users' expressed preferences, usage and late-night notification statistics by percentile, and the results of product experiments on 1,000 or more users. A 2026 amendment adds a duty to explain the platform's age estimation process, effective July 1, 2027. Under a court-filed stipulation, the Attorney General agreed not to enforce the Act against NetChoice members until the court rules on NetChoice's preliminary-injunction request (NetChoice v. Ellison, D. Minn. No. 0:25-cv-02741).
Prohibition Against Requiring the Implantation of Devices (employee microchipping)
IN Employee Implant BanJurisdiction: Indiana
Authority: Private enforcement by employees and applicants
Indiana employers may not require employees or applicants to have a device, such as an RFID microchip, implanted, injected, ingested, or otherwise put in their bodies as a condition of employment or benefits. They also may not retaliate against those who refuse, unless a court order requires the device.
Prohibition on Nudification Technology
MN Nudification BanJurisdiction: Minnesota
Effective: 8/1/2026
Authority: Minnesota Attorney General under 8.31; depicted individuals by civil action (325E.91, subds. 4-5)
Effective August 1, 2026, Minnesota bars operators of websites, apps, and software from letting users generate realistic fake nude images or videos of identifiable people ('nudification'), and bars advertising such services. Depicted people can sue for treble damages and punitive damages, and the Attorney General can seek civil penalties of up to $500,000 per use.
Prohibition on selling higher-education student data to creditors
OK Student Data Sale BanJurisdiction: Oklahoma
Effective: 7/1/2007
Authority: Not specified in the statute
Bars Oklahoma public colleges, universities, and technology center schools from entering agreements to sell student directory information to creditors for marketing consumer credit to students. Release under the Open Records Act is still allowed.
Prohibition on unauthorized use of newborn DNA
OK Newborn DNA LawJurisdiction: Oklahoma
Effective: 5/10/2010
Authority: District attorneys (criminal statute)
Bars laboratories, hospitals, and birthing facilities from storing, transferring, using, or databasing a newborn's DNA without the parents' express consent.
Proof of Vaccination for COVID-19
Iowa COVID-19 Vaccine Proof BanJurisdiction: Iowa
Effective: 5/20/2021
Authority: State agencies awarding grants and contracts (loss of state funding)
Iowa bars businesses and government entities from requiring customers or visitors to show proof of COVID-19 vaccination before entering, and bars state and local ID cards from showing COVID-19 vaccination status. Screening protocols that do not require vaccine proof are allowed, and health care facilities are exempt.
Property Owner's Consent Required for Smart Meter Gateway Devices
NH Smart Meter Gateway Consent LawJurisdiction: New Hampshire
Effective: 6/7/2012
Authority: New Hampshire Public Utilities Commission
Prohibits electric utilities from installing smart meter gateway devices, meaning meters or components that communicate with, monitor or control appliances inside a home or business, without the owner's written opt-in consent. Utilities must disclose whether such a device is installed and remove it on written request.
Property Right in Name, Voice, and Visual Likeness (digital replicas)
MT Likeness Rights (HB 513)Jurisdiction: Montana
Effective: 1/1/2026
Authority: Private enforcement by the individual or rights holder
HB 513 (Ch. 685, L. 2025) makes a person's name, voice and visual likeness a transferable, descendible property right lasting 20 years after death. It creates liability for commercially publishing AI or other computer-generated voice or visual replicas without consent, and for distributing tools built primarily to make them, with news, commentary, parody and similar First Amendment exceptions.
Protect Tennessee Minors Act
PTMAJurisdiction: Tennessee
Effective: 1/1/2025
Authority: Tennessee Attorney General and Reporter (civil actions against commercial entities); district attorneys (criminal); private plaintiffs for damages
Requires adult-content websites to verify, with a photo-ID match or a commercially reasonable transactional-data method, that each visitor is 18 or older, and to re-verify after each age-verified session (at most 60 minutes). Verifiers must keep seven years of anonymized verification records but may not keep the user's identifying information after access is granted. A federal district court enjoined it in December 2024, but the Sixth Circuit stayed that injunction on January 13, 2025, and after Free Speech Coalition v. Paxton vacated it in November 2025; the challenge continues in the Western District of Tennessee without an injunction.
Protected Consumer Report Security Freeze (minors under 16 and represented persons)
Florida Protected Consumer Freeze LawJurisdiction: Florida
Effective: 9/1/2014
Authority: Florida Department of Agriculture and Consumer Services; private civil actions
Lets a parent, guardian, or other representative freeze the credit file of a child under 16 or a represented adult. If no file exists, the agency must create a 'record' so it can be frozen. Agencies may not charge a fee to place or remove the freeze.
Protected health information in legal advertising
Tenn. PHI Legal Solicitation LawJurisdiction: Tennessee
Effective: 7/1/2019
Authority: Tennessee Attorney General and Reporter (TCPA authority); district attorneys (criminal)
Bars anyone from using, obtaining, selling, transferring, or disclosing a person's protected health information to solicit them for legal services without the person's written authorization. The same part regulates legal advertisements about drugs and medical devices, requiring paid-advertisement disclosures and banning misleading "medical alert" or government-style framing.
Protecting Children from Social Media Act
Protecting Children from Social Media ActJurisdiction: Tennessee
Effective: 1/1/2025
Authority: Tennessee Attorney General and Reporter, using Tennessee Consumer Protection Act investigation and enforcement powers (§§ 47-18-106, 47-18-108)
Requires social media companies to verify the age of anyone opening a new account and to get verified express parental consent before a minor under 18 can hold an account. Parents must get tools to view privacy settings, set daily time limits, and schedule breaks, and data used for verification may not be retained. NetChoice's challenge is pending: the district court denied a preliminary injunction in June 2025, and on August 28, 2026 the Sixth Circuit vacated that denial and remanded, so the law is in effect but under active challenge.
Protecting DNA Privacy Act: Unlawful Use of DNA
Florida DNA Privacy ActJurisdiction: Florida
Effective: 10/1/2021
Authority: State attorneys (criminal)
Enacted by HB 833 (2021), this law makes it a crime to collect, analyze, disclose, or sell someone's DNA without their express consent. It applies even where the sample was first collected with consent, so a genetic-testing company that later sells or transfers a sample or results needs fresh express consent.
Protecting Our Kids from Social Media Addiction Act (SB 976)
SB 976Jurisdiction: California
Effective: 1/1/2025
Authority: California Attorney General (exclusive)
Bars platforms from giving minors personalized 'addictive feeds' without verifiable parental consent, limits notifications to minors overnight and during school hours, and requires parental controls with protective defaults. It is partly enjoined in NetChoice v. Bonta: the district court blocked the notification limits and the Ninth Circuit (Sept. 9, 2025; en banc denied Nov. 6, 2025) also blocked the like-count default, but let the addictive-feed ban and other defaults take effect. Age-assurance duties start January 1, 2027, and the Attorney General's implementing rules were in rulemaking as of September 2026.
Protecting social security numbers from disclosure
Tenn. SSN ProtectionJurisdiction: Tennessee
Effective: 1/1/2008
Authority: Tennessee Attorney General (civil, as a part 21 and Tennessee Consumer Protection Act violation); district attorneys (criminal)
Requires businesses that hold Social Security numbers to make reasonable efforts to keep them from public disclosure. SSNs may not be publicly displayed, sent over the internet without a secure connection or encryption, used alone as a website login, printed on mailed materials unless required, or printed on cards or badges consumers must show to get services.
Protection From Predatory Pricing Act (dynamic pricing and personal data in food retail and delivery)
MD Protection From Predatory Pricing ActJurisdiction: Maryland
Effective: 10/1/2026
Authority: Consumer Protection Division, Office of the Attorney General
This 2026 administration bill bars large grocery stores and food delivery apps from using consumers' personal data to charge an individual consumer a higher, personalized price for tax-exempt food (for example through AI-driven pricing), and from using protected-class data in a way that denies a consumer an advantage or privilege offered to others. Loyalty programs, cost- and location-based differences, consented data-for-price offers, and error corrections are excluded.
Protection of Children in Online Spaces
Florida Children in Online Spaces LawJurisdiction: Florida
Effective: 7/1/2024
Authority: Florida Department of Legal Affairs (Attorney General), exclusively
Created by the same 2023 bill as the Florida Digital Bill of Rights, this section limits how online platforms predominantly accessed by children may process minors' data. It bars processing that the platform knows or willfully disregards may cause substantial harm or privacy risk to children, restricts profiling, data collection beyond what is needed, precise geolocation, and dark patterns, and places the burden of proof on the platform.
Protection of Children on Applications (Louisiana App Store Accountability Act)
LA App Store ActJurisdiction: Louisiana
Effective: 7/1/2027
Authority: Louisiana Attorney General
Requires app stores to verify the age category (under 13, 13-15, 16-17, adult) of Louisiana users at account creation, link minors' accounts to a parent account, and obtain verifiable parental consent before a minor downloads or buys apps or makes in-app purchases. Developers must use the store's age signal and consent status, may not sell age category data, and may not enforce terms against minors without parental consent. Act 185 of 2026 stopped the 2025 version (Act 481) from taking effect on July 1, 2026 and re-enacted the scheme effective July 1, 2027.
Protection of Children's Internet Data (social media targeted advertising and sale of minors' sensitive data)
LA Children's Internet Data LawJurisdiction: Louisiana
Effective: 7/1/2025
Authority: Louisiana Attorney General
Bars large social media platforms from showing targeted advertising to account holders they know are minors (under 18) and from selling minors' sensitive personal data, such as race, religion, gender, immigration status, health information, genetic or biometric identifiers, and specific geolocation. Contextual ads, first-party ads, and ad measurement are excluded from 'targeted advertising'. Platforms are shielded from liability for good-faith residency and age-estimation processing.
Protection of Consumer Telephone Records
Texas Telephone Records LawJurisdiction: Texas
Effective: 9/1/2009
Authority: Texas Attorney General Consumer Protection Division; prosecutors
Criminalizes pretexting for telephone records: obtaining a Texan's phone records by lying to a phone company, fraudulent website access, or false documents, and selling or receiving records obtained that way.
Protection of Driver's License and Social Security Numbers
Texas SSN Protection LawJurisdiction: Texas
Effective: 4/1/2009
Authority: Texas Attorney General or county prosecuting attorney
Restricts public display and insecure transmission of Social Security numbers, requires a privacy policy before a business may demand an SSN, and limits merchants' use of driver's license and Social Security numbers collected for returns. It also bars printing driver's license numbers on sales receipts.
Protection of Identifying Financial Information (card receipt truncation)
Texas Card Receipt LawJurisdiction: Texas
Effective: 4/1/2009
Authority: Texas Attorney General or county prosecuting attorney
Bars printing more than the last four digits of a card number, or the expiration date, on receipts given to cardholders. Handwritten or imprinted receipts are exempt.
Protection of Personal Information Act
Utah PPIAJurisdiction: Utah
Authority: Utah Attorney General
Utah's data security, disposal, and breach notification law. It covers name plus SSN, financial account or card number with access code, or driver license or state ID number. It requires reasonable safeguards, secure disposal, and notice to affected Utah residents, and at scale to the Attorney General, the Utah Cyber Center, and consumer reporting agencies.
Protections for Minors Featured in Digital Content
HB 26-1058Jurisdiction: Colorado
Effective: 6/1/2027
Authority: Private enforcement by affected individuals; courts
HB 26-1058 protects child influencers from June 1, 2027: creators must keep records and put part of earnings in trust for featured minors. Adults (or emancipated minors) who were featured as identifiable minors may demand deletion or editing of posts, and platforms must offer a removal-request mechanism. Profiting from sexualized content of minors is prohibited.
Psychotherapy Artificial Intelligence Restrictions
HB 26-1195Jurisdiction: Colorado
Effective: 8/12/2026
Authority: Mental health licensing boards in the Department of Regulatory Agencies (professional discipline); Attorney General for the consumer-protection section
HB 26-1195 limits how therapists may use AI: AI may not conduct therapy or make treatment decisions without the professional's real-time involvement and approval, and clients must be told of the limits. Recording or transcribing a session with AI requires advance written disclosure and written consent. Separately, no one may market an AI system as providing psychotherapy or imply therapist-level confidentiality for user data.
Public body disclosures to data brokers (immigration attestation)
SB 1587 (2026)Jurisdiction: Oregon
Effective: 6/5/2026
Authority: None specified in the act
Bars Oregon public bodies from giving personally identifiable information to a data broker unless the broker first attests in writing that the data will not be sold or transferred to anyone who will use it to enforce federal immigration law. It binds data brokers indirectly, as a condition of receiving government data.
Public School Student Records Access and Confidentiality
Nebraska Student Records LawJurisdiction: Nebraska
Authority: No specific enforcement provision (State Board of Education rules on data sharing)
Nebraska's student records law gives public school students and parents the right to inspect, review, and copy school records and bars disclosure to others without written consent, except to auditors, education authorities, and as FERPA allows. Disciplinary material must be kept separate and destroyed after three years of continuous absence.
Publishing or distributing material harmful to minors on the Internet (adult website age verification)
VA age verificationJurisdiction: Virginia
Effective: 7/1/2023
Authority: Private civil action
Requires commercial adult websites to verify that users are 18 or older through a commercial age and identity verification database or another commercially reasonable method, and makes them liable for damages when a minor gains access.
Pupil records: contracts with third-party digital service providers
Educ. Code 49073.1Jurisdiction: California
Effective: 1/1/2015
Authority: Parties to the contract; local educational agencies
Requires school contracts with cloud and education software vendors to keep pupil records under school control and bar vendors from using them for other purposes or targeted advertising, with security, breach notice, and deletion terms.
Reader Privacy Act
Reader Privacy ActJurisdiction: California
Effective: 1/1/2012
Authority: Private plaintiffs; courts
Protects records of what people read. Book service providers may not disclose users' personal information to government entities, or be compelled to disclose it, except with a court order meeting strict findings (probable cause, compelling interest, no less intrusive means, notice) or other listed circumstances.
Reasonable security for personal information (Customer Records)
Data Security (1798.81.5)Jurisdiction: California
Effective: 1/1/2004
Authority: California Attorney General; private plaintiffs
Requires businesses holding Californians' personal information (names with SSNs, ID numbers, financial account data, medical and health insurance data, biometrics, genetic data, or online credentials) to use reasonable security, and to require the same by contract of third parties they share it with.
Record Destruction (Personal Information Disposal)
MT Record DestructionJurisdiction: Montana
Effective: 10/1/2005
Authority: Montana Department of Justice, Office of Consumer Protection (Attorney General)
Businesses must destroy customer records containing personal information once they no longer need to keep them, by shredding, erasing or otherwise making the information unreadable. The law is part of Montana's identity-theft prevention statutes.
Recording of Private Telephone Conversations (all-party consent, civil action)
CT Telephone Recording ConsentJurisdiction: Connecticut
Authority: Private civil action in Superior Court
Makes Connecticut an all-party-consent state for recording private phone calls as a civil matter: a recording is lawful only with every party's prior consent (in writing or captured at the start of the recording), a recorded verbal warning at the start, or an automatic beep tone about every 15 seconds.
Redaction of Social Security numbers and birthdates in probate court filings
AL Probate SSN RedactionJurisdiction: Alabama
Authority: Probate judges (filing condition)
Requires people recording property and other documents in probate court to remove Social Security numbers, and in property documents birthdates, before filing. Probate judges may also redact them and may post records online.
Regulation of Biometric Information (government agencies)
NH Government Biometric LawJurisdiction: New Hampshire
Effective: 7/1/2014
Authority: Aggrieved individuals through civil actions against government agencies
Bars New Hampshire government agencies from issuing ID cards that require biometric data, requiring biometrics as a condition of service, or otherwise collecting or sharing biometric data, apart from employee and contractor access cards, public safety screening and grandfathered practices. It does not apply to private companies; private-sector biometric data is covered as sensitive data under RSA 507-H.
Regulation of Consumer Credit Reporting Agencies (including security freeze)
Texas Credit Reporting LawJurisdiction: Texas
Authority: Texas Attorney General; consumers
Texas's state credit reporting law limits consumer reports to permissible purposes, gives consumers disclosure and dispute rights, and lets consumers and protected minors place security alerts and freezes. Agencies must place a freeze within five business days of a request and honor freezes placed at other agencies.
Regulation of Electronic Mail
Texas Commercial Email LawJurisdiction: Texas
Effective: 4/1/2009
Authority: Texas Attorney General or county prosecuting attorney; injured persons
Bans falsified routing, deceptive subject lines, and domain spoofing in commercial email, requires 'ADV:' labeling and a working opt-out for unsolicited commercial email, and bars selling opted-out addresses. H.B. 20 (2021) added a rule against email providers impeding messages.
Regulation of Telephone Solicitation (registration with the Secretary of State)
Texas Telephone Solicitation ActJurisdiction: Texas
Effective: 4/1/2009
Authority: Texas Attorney General; Texas Secretary of State (registration); consumers under the DTPA
Requires telemarketers that are not exempt to register each calling location with the Texas Secretary of State, post security, and make disclosures. S.B. 140 (2025) extended the law to text and image messages, which, combined with the DTPA private remedy, opened these marketing texts to private suits.
Reidentification of Deidentified Information
Texas Reidentification LawJurisdiction: Texas
Effective: 9/1/2015
Authority: Texas Attorney General; prosecutors
Prohibits reidentifying people in deidentified data released by Texas state agencies and requires notice when such data is sold or transferred. Scholarly research that does not publish identities is a defense.
Release of employee's personal identifying information
VA employee PII releaseJurisdiction: Virginia
Effective: 7/1/2013
Authority: Not stated in the section
Provides that an employer cannot be required to release employees' home or mobile phone numbers, email addresses, shift times, or work schedules to a third party unless federal or state law, a court order, a warrant, or a subpoena or discovery in a pending case requires it.
Remotely Piloted Aircraft (drone intrusion and surveillance)
Iowa Drone Surveillance LawJurisdiction: Iowa
Effective: 7/1/2024
Authority: County attorneys (criminal prosecution); homestead and farmstead owners or lessees (injunctions)
Iowa's drone law makes it a crime to hover a drone over someone else's rural home or near livestock, equipment, or buildings on a working farm, and a more serious crime to do so with a camera or recording device capable of identifying people or farm property. Owners can get court injunctions against harassing drone operators, and unlawful recordings must be destroyed. It does not reach property inside city limits.
Reproductive and Gender-Affirming Health Information Shield (covered entity disclosure limits)
CT Reproductive Health Info ShieldJurisdiction: Connecticut
Authority: Courts (evidentiary privilege)
Part of Connecticut's post-Dobbs shield laws. In civil, probate, legislative or administrative proceedings, covered entities may not disclose patient communications or examination information about reproductive or gender-affirming health care lawful in Connecticut without the patient's explicit written consent, and must tell patients they may withhold consent.
Reproductive Health Care Information Shield (patient information disclosure limits)
NJ Reproductive Health Shield LawJurisdiction: New Jersey
Effective: 7/1/2022
Authority: Courts and agencies applying the evidentiary privilege; Attorney General and prosecutors for related 2026 provisions
New Jersey's 2022 shield law bars HIPAA covered entities from disclosing patients' communications and examination findings about lawful reproductive health care in civil, probate, legislative, or administrative proceedings without the patient's explicit written consent, and requires providers to tell patients they may withhold that consent. It also bars state entities from helping out-of-state investigations into care that is legal in New Jersey. An August 2026 amendment extends these protections to gender-affirming care.
Restricted use of Social Security numbers
VA SSN protectionJurisdiction: Virginia
Effective: 7/1/2005
Authority: Virginia Attorney General and local attorneys under the Virginia Consumer Protection Act; consumers via VCPA private action (59.1-444, 59.1-200(A)(43), 59.1-204)
Bars businesses from publicly displaying Social Security numbers, printing them on access cards, requiring them as a sole website login, showing them on mailings, or embedding them in barcodes, chips, or magnetic strips. Internal verification and administrative uses remain allowed.
Restrictions on credit card receipts
Colorado receipt truncationJurisdiction: Colorado
Effective: 4/25/2002
Authority: Colorado Attorney General (Colorado Consumer Protection Act article)
Businesses may not print more than the last five digits of a card number, or the expiration date, on electronically printed card receipts.
Restrictions on Information Printed on Payment-Card Receipts
Florida Card Receipt LawJurisdiction: Florida
Effective: 7/1/2003
Authority: State attorneys (county court)
Limits what merchants may print on card receipts to reduce identity theft. An electronically printed receipt may show no more than the last five digits of the card number and may not show the expiration date. The rule has covered all electronically printed receipts since July 1, 2005.
Restrictions on Use of Genetic Information in Insurance
MT Genetic Insurance LawJurisdiction: Montana
Effective: 10/1/1999
Authority: Montana Commissioner of Securities and Insurance
Health insurers in Montana may not require genetic tests, underwrite or price coverage based on genetic traits or family genetic information, or seek genetic information for non-therapeutic purposes. Life, disability income and long-term care insurance are excluded.
Revised Uniform Fiduciary Access to Digital Assets Act
RI RUFADAAJurisdiction: Rhode Island
Authority: Courts (orders directing custodian compliance)
Governs when online service providers must give executors, agents, trustees and guardians access to a person's digital accounts. The content of electronic communications is disclosed only if the user consented (through an online tool or an estate document) or a court orders it, and a user's choice in a provider's online tool overrides conflicting wills and ordinary terms of service.
Rhode Island Data Transparency and Privacy Protection Act
RIDTPPAJurisdiction: Rhode Island
Effective: 1/1/2026
Authority: Rhode Island Attorney General (sole enforcement authority)
Rhode Island's comprehensive consumer privacy law, effective January 1, 2026. It requires commercial websites and internet service providers that sell customers' personal information to disclose what they collect and to whom they sell it, and gives residents of larger covered businesses rights to access, correct, delete and port their data and to opt out of targeted advertising, sales and significant automated profiling. Covered controllers need opt-in consent for sensitive data (including health, biometric, genetic, precise geolocation and known-child data) and must run data protection assessments for high-risk processing.
Rhode Island Health Information Exchange Act of 2008
RI HIE ActJurisdiction: Rhode Island
Authority: Rhode Island Department of Health (regulatory oversight); Attorney General and courts for penalties
Creates Rhode Island's statewide electronic health information exchange and sets its privacy rules. Patients are included by default but may opt out of disclosure from the exchange (with exceptions for emergencies, public health, exchange operations and health-plan care management), and participating providers must tell patients about the exchange and the opt-out. Patients can obtain copies of their HIE data and disclosure reports.
Rhode Island Identity Theft Protection Act of 2015 (information security and breach notification)
RI ITPAJurisdiction: Rhode Island
Authority: Rhode Island Attorney General
Rhode Island's main data security and breach notification statute. It requires businesses and government agencies holding Rhode Island residents' personal information to keep a risk-based information security program, limit retention, destroy data securely and bind vendors by contract to reasonable security. When a breach poses a significant risk of identity theft, affected residents must be notified within 45 days (30 days for agencies), with notice to the Attorney General and credit bureaus if more than 500 residents are affected.
Rhode Island Judicial Security Act (removal of judges' personal information)
RI Judicial Security ActJurisdiction: Rhode Island
Effective: 1/1/2026
Authority: Courts via actions by protected individuals
Lets judges and their families send written notices requiring data brokers, businesses and government agencies to remove and stop posting their home addresses, phone numbers and personal emails. Data aggregators may not sell or trade the information after notice, and businesses must take it down within 10 business days (agencies within 72 hours). A 2026 amendment allows requests through an authorized agent.
Right of privacy, California Constitution
Cal. Const. art. I, sec. 1Jurisdiction: California
Effective: 11/7/1972
Authority: Courts (private suits)
Lists privacy among Californians' inalienable rights. The privacy language was added by voters in 1972 (Proposition 11), and the current wording of Section 1 dates to 1974 (Proposition 7). Courts have held it can be enforced against private entities as well as the state, which is why it appears in privacy suits against businesses.
Right of publicity and statutory right of privacy (use of name or likeness)
OK Right of PublicityJurisdiction: Oklahoma
Effective: 1/1/1986
Authority: Private civil actions; district attorneys for the criminal misdemeanor (21 O.S. § 839.1)
Oklahoma protects against commercial appropriation of identity. A living person (and, under § 1448, the successors of a deceased personality) may sue anyone who knowingly uses their name, voice, signature, photograph, or likeness in products or advertising without prior consent. Uses in news, public affairs, sports, and political campaigns are exempt.
Rights of Publicity
IN Right of PublicityJurisdiction: Indiana
Effective: 7/1/1994
Authority: Private enforcement by the personality or rights holders
Indiana's broad right-of-publicity statute requires prior written consent before anyone uses a person's name, voice, likeness, or other identifying traits for commercial purposes, during life and for 100 years after death. Rights are transferable and descendible. News, entertainment, literary, and political uses are exempt.
Safe Destruction of Documents Containing Personal Information
RI Document Destruction LawJurisdiction: Rhode Island
Authority: Rhode Island Attorney General; injured customers
Requires businesses to take reasonable steps to destroy customers' personal information they no longer keep, by shredding, erasing or otherwise making it unreadable. Personal information is defined broadly to include signatures, Social Security, passport, license, insurance and financial account numbers, physical descriptions, and confidential health care information.
Safe Destruction of Records Containing Personal Identifying Information
DE Records Destruction LawJurisdiction: Delaware
Effective: 1/1/2015
Authority: Private enforcement by affected consumers (5003C)
Requires businesses that permanently dispose of consumer records containing a name plus sensitive identifiers (SSN, ID, account, card, insurance, tax, payroll, or health information) to shred, erase, or otherwise make the information unreadable. Consumers harmed by reckless or intentional violations can sue for actual damages.
Safeguarding of Personal Information; SSN Privacy Protection Policy; Secure Retention of Employment Applications
CT Data Safeguards & DisposalJurisdiction: Connecticut
Authority: Connecticut Department of Consumer Protection and Attorney General; licensing agencies for their licensees (42-471(d))
Requires anyone holding personal information to protect it from misuse and to destroy or render it unreadable before disposal, and requires businesses that collect Social Security numbers to publish a privacy protection policy. Employers must keep job applications secure and shred them on disposal.
Scanning or swiping driver's licenses and ID cards
Civ. Code 1798.90.1Jurisdiction: California
Authority: Local prosecutors
Businesses may electronically scan California driver's licenses and IDs only for listed purposes (age or ID verification, legal recordkeeping, check approval, fraud prevention) and may not keep or use the data for anything else.
School-Issued Electronic Device Monitoring Notice
NJ School Device Notice LawJurisdiction: New Jersey
Effective: 7/1/2013
Authority: New Jersey Department of Education (fines remitted to the Department)
Schools that hand out laptops, phones, or other devices able to record or track students must tell students in writing or electronically that the device may collect information about their activity, and promise not to use those capabilities to violate the privacy of the student or anyone in the household. A parent must acknowledge the notice.
Second Amendment Financial Privacy Act
AL 2A Financial Privacy ActJurisdiction: Alabama
Effective: 10/1/2024
Authority: Alabama Attorney General (exclusive)
Stops payment card networks from requiring the firearms-retailer merchant category code in a way that singles out gun sellers, and stops financial institutions from declining transactions solely because of that code. It also bars state and local governments from keeping lists or registries of privately owned firearms or their owners, outside criminal investigations or as required by law.
Secure Online Child Interaction and Age Limitation Act
LA SOCIAL ActJurisdiction: Louisiana
Effective: 7/1/2024
Authority: Louisiana Department of Justice, Division of Public Protection (Attorney General)
Requires large social media platforms to make commercially reasonable efforts to verify Louisiana users' ages and to obtain a parent's express consent before a Louisiana minor under 16 may hold an account. For minor accounts it bars unconnected adults from direct messaging, bars ads based on personal information other than age and location, limits data collection, and requires parental supervision tools. On December 15, 2025, the U.S. District Court for the Middle District of Louisiana held R.S. 51:1751-1754 unconstitutional as applied to ten NetChoice members and permanently enjoined enforcement of R.S. 51:1751-1756 against them; the state's appeal is pending in the Fifth Circuit.
Securing Children Online through Parental Empowerment (SCOPE) Act
SCOPE ActJurisdiction: Texas
Effective: 9/1/2024
Authority: Texas Attorney General, Consumer Protection Division (deceptive trade practice)
H.B. 18 (2023) requires covered social platforms to register users' ages, treat users under 18 as known minors, limit collection and sharing of minors' data, block targeted ads and precise geolocation collection for minors, and give verified parents tools and data access. The harmful-content monitoring and filtering duty (509.053) and the related algorithm duty (509.056(1)) remain preliminarily enjoined for CCIA and NetChoice; on July 24, 2026 the Fifth Circuit affirmed that injunction on Section 230 preemption grounds and vacated the broader injunction won by the SEAT plaintiffs (targeted-ads, unlawful-ads, and age-verification provisions).
Security Breach Notice Act
VT SBNAJurisdiction: Vermont
Effective: 1/1/2007
Authority: Vermont Attorney General and State's Attorneys; Department of Financial Regulation for its licensees
Requires businesses and other data collectors to tell Vermont consumers about a breach of their personally identifiable information or login credentials within 45 days of discovery, and to give the Attorney General (or DFR) a preliminary report within 14 business days. Notices must contain specified content, and large breaches require notice to the national credit bureaus.
Security breach notification (businesses)
Breach Notification (1798.82)Jurisdiction: California
Effective: 7/1/2003
Authority: California Attorney General; private plaintiffs
Requires notice to California residents when their unencrypted personal information (or encrypted data with a compromised key) is, or is reasonably believed to have been, acquired by an unauthorized person. SB 446 (2025) added a firm 30-calendar-day deadline from January 1, 2026.
Security Breach Notification Act
OK Breach ActJurisdiction: Oklahoma
Effective: 11/1/2008
Authority: Oklahoma Attorney General or a district attorney (exclusive), as an unlawful practice under the Oklahoma Consumer Protection Act; the primary state regulator for state-chartered or state-licensed financial institutions
Requires anyone owning or licensing computerized personal information of Oklahoma residents to notify affected residents without unreasonable delay after a breach that causes or is reasonably believed to cause identity theft or fraud. 2025 SB 626 (effective January 1, 2026) added biometric data and government ID numbers to personal information, a new Attorney General notice duty for breaches affecting 500 or more residents, and a safe harbor tied to 'reasonable safeguards'.
Security Freeze on Credit Reports
CT Security FreezeJurisdiction: Connecticut
Authority: Connecticut Banking Commissioner (regulations under 36a-701c); Attorney General
Lets any consumer, and a parent for a minor child, freeze a credit report free of charge so it cannot be released for new credit without the consumer's authorization, and requires agencies to lift or remove freezes promptly on request.
Security Freezes for Consumer Reports
IN Security FreezeJurisdiction: Indiana
Authority: Indiana Attorney General; consumers
Indiana residents may freeze their credit reports for free so that agencies cannot release them without the consumer's authorization. Agencies must confirm a freeze and issue a PIN or password, and must lift or remove a freeze within set times. The federal Economic Growth, Regulatory Relief, and Consumer Protection Act of 2018 (15 U.S.C. 1681c-1(i)) now also sets nationwide free-freeze rules and timelines.
Security Freezes for Protected Consumers (minors under 16 and incapacitated persons)
IN Protected Consumer FreezeJurisdiction: Indiana
Authority: Not specified in the chapter
A parent, guardian, or other representative may freeze the credit report of a child under 16 or an incapacitated adult. If no report exists, the agency must create a record and freeze it, so no credit file can be opened in the child's name until the freeze is lifted.
Security of Communications Act
OK SCA (wiretap)Jurisdiction: Oklahoma
Authority: District attorneys and the Attorney General (criminal prosecution); courts for interception orders
Oklahoma's wiretap law makes it a felony to willfully intercept wire, oral, or electronic communications, or to disclose or use their contents knowing they were unlawfully obtained. Oklahoma is a one-party consent state: a private person may record a communication they are a party to, or with one party's prior consent, unless the purpose is to commit a crime. The act also governs court-ordered interception by law enforcement.
Security of Communications Act: Interception and Disclosure of Wire, Oral, or Electronic Communications (all-party consent)
Florida Wiretap ActJurisdiction: Florida
Authority: State attorneys and statewide prosecutor (criminal); private civil actions
Florida is an all-party-consent state: intercepting or recording a wire, oral, or electronic communication is lawful only if all parties consent, unless a statutory exception applies (934.03(2)(d)). 'Oral communications' are protected only when the speaker reasonably expects not to be intercepted (934.02(2)). Exceptions allow children, and since 2024 their parents or guardians, to record abusers in defined circumstances, and let people protected by injunctions record violating communications.
Security of Connected Devices (IoT security law)
IoT Security (SB 327)Jurisdiction: California
Effective: 1/1/2020
Authority: California Attorney General, city attorneys, county counsel, and district attorneys (exclusive; 1798.91.06(e))
Requires makers of internet-connected devices to build in reasonable security features suited to the device and the data it handles. A unique preprogrammed password per device, or forcing the user to set new credentials at first use, satisfies the rule for remote authentication, as does meeting a NIST-conforming labeling scheme.
Security requirements for Internet-connected devices
ORS 646A.813 (IoT security)Jurisdiction: Oregon
Effective: 1/1/2020
Authority: Oregon Attorney General (unlawful trade practice under ORS 646.607)
Requires makers of consumer internet-connected devices sold in Oregon to build in reasonable security features, such as a unique preset password or forcing the user to set new credentials on first use.
Sexual Cyberharassment (nonconsensual intimate images)
Florida Sexual Cyberharassment LawJurisdiction: Florida
Authority: State attorneys (criminal); private plaintiffs
Florida's 'revenge porn' law. It makes it a crime to willfully and maliciously post or send a sexually explicit image of someone, together with identifying information, without consent when the person expected it to stay private. Sharing the image with one person does not by itself end that expectation of privacy. A 2025 amendment (HB 1451) added penalties for doing this for money.
Shine the Light law (disclosure of personal information shared for direct marketing)
Shine the LightJurisdiction: California
Effective: 1/1/2005
Authority: Private plaintiffs; courts (injunctions)
Lets California customers ask businesses once a year which categories of their personal information were shared with third parties for those third parties' direct marketing, and with whom. Businesses must designate a way to receive these requests and answer within 30 days, or may instead adopt a qualifying opt-out or opt-in policy.
Social media account deletion (AB 656)
AB 656Jurisdiction: California
Effective: 1/1/2026
Authority: Not specified in the title (CCPA enforcement applies to the deletion request)
Requires large social media platforms to put a clearly labeled 'Delete Account' button in settings, walk users through deleting their account and personal information, and not obstruct deletion with dark patterns. The request counts as a CCPA deletion request.
Social Media Account Privacy (Employers)
VT Employee Social Media PrivacyJurisdiction: Vermont
Effective: 1/1/2018
Authority: Vermont Attorney General or State's Attorneys (21 V.S.A. § 495b)
Prevents employers from requiring or pressuring workers or job applicants to hand over personal social media passwords, log in in front of them, show account content, weaken privacy settings, or add the employer as a contact. Employers may still ask for specific content during certain legal-compliance, misconduct or data-leak investigations.
Social media accounts of current and prospective employees
VA employer social mediaJurisdiction: Virginia
Effective: 7/1/2015
Authority: Not stated in the section
Bars employers from requiring current or prospective employees to disclose personal social media usernames and passwords or to add a supervisor or co-worker as a contact, and from retaliating against those who refuse. Employers may view public information and may request credentials for formal misconduct investigations.
Social Media Mental Health Warning Label Law
MN Social Media Warning LabelJurisdiction: Minnesota
Effective: 7/1/2026
Authority: Minnesota Attorney General (325M.34(a)); Commissioner of Health sets label guidelines (325M.335, subd. 2)
From July 1, 2026, social media platforms must show a conspicuous mental health warning label each time a user accesses the platform, which disappears only when the user exits or acknowledges the risk and proceeds, and which links to crisis resources such as the 988 Lifeline. Label content follows guidelines from the Commissioner of Health. NetChoice challenged the law on First Amendment grounds (NetChoice v. Ellison, D. Minn. No. 0:26-cv-02405), and press reports state the Attorney General agreed not to enforce it while the court considers the case; no court injunction has been reported.
Social Media Platforms and Minors (account unpublish/deletion; online safety center)
CT Social Media MinorsJurisdiction: Connecticut
Effective: 7/1/2024
Authority: Connecticut Attorney General (solely; Conn. Gen. Stat. 42-528(d))
Requires social media platforms to unpublish a minor's account within 15 business days and delete it (and stop processing the minor's data) within 45 business days of a request by the minor or, for under-16s, a parent. From July 1, 2026 parents cannot be forced to open an account to make the request, and platforms must provide an online safety center and a cyberbullying policy by October 1, 2026.
Social media private right of action for minors
Utah Social Media PRAJurisdiction: Utah
Effective: 10/1/2024
Authority: None; private actions
Enacted by 2024 H.B. 464, effective October 1, 2024, it lets minors and parents sue social media companies for mental health harm from excessive use. Companies that limit minors' use and disable engagement features get the opposite presumption. The 13-71 injunction does not name this Part.
Social Media Providers: Adolescent Use of Social Media
IN Social Media Minors ActJurisdiction: Indiana
Effective: 1/1/2027
Authority: Indiana Attorney General (as a deceptive act under IC 24-5-0.5)
Added by HEA 1408 (2026), P.L.100-2026, and effective January 1, 2027, this article requires large, addictive-design social media platforms to screen the age of Indiana account applicants. Users under 16 need verifiable parental consent to open an account. Minors' accounts must have direct messaging, search visibility, personalized feeds and ads, and addictive features turned off, and parents get monitoring and time-limit controls.
Social Media Use for Minors (HB 3, 2024)
Florida HB 3 Social MediaJurisdiction: Florida
Effective: 1/1/2025
Authority: Florida Department of Legal Affairs (Attorney General)
HB 3 (ch. 2024-42) requires covered social media platforms to bar Florida minors under 14 from holding accounts, and to require parental consent for 14- and 15-year-olds, terminating non-compliant accounts and deleting their data. A federal district court preliminarily enjoined the law in June 2025, but the Eleventh Circuit stayed that injunction on November 25, 2025, so the law is enforceable while the merits appeal (argued March 2026) is pending.
Social Media Warning Law (AB 56)
AB 56Jurisdiction: California
Effective: 1/1/2027
Authority: Public prosecutors (no private right of action)
Requires covered social media platforms to show users a black-box mental health warning when they first open the platform each day, after three hours of cumulative use, and at least hourly after that. Operative January 1, 2027. Included because it regulates minors' social media use, though it is not a data privacy rule.
Social Security Number Privacy Act
MD SSN Privacy ActJurisdiction: Maryland
Authority: Consumer Protection Division, Office of the Attorney General (Com. Law 13-301(14)(xxi))
This law restricts how businesses display and transmit Social Security numbers. It bars publicly posting SSNs, printing them on access cards, requiring or sending them over unsecured internet connections, and using them alone as a website login, and limits SSNs in mailed, emailed, or faxed materials.
Social Security Number Protection
CT SSN ProtectionJurisdiction: Connecticut
Authority: Criminal prosecution; civil penalties (deposited into the privacy protection guaranty and enforcement account)
Bars businesses from publicly posting Social Security numbers, printing them on access cards, or requiring people to send them over unsecured internet connections or use them alone to log in to websites.
Social Security Number Protection Act
VT SSN ActJurisdiction: Vermont
Effective: 7/1/2007
Authority: Vermont Attorney General and State's Attorneys; Department of Financial Regulation for its licensees
Limits how businesses and government bodies display, transmit and disclose Social Security numbers. Businesses may not publicly post SSNs, print them on access cards or mailings, or sell them to third parties without a legitimate purpose, subject to listed exceptions. Individuals may ask town clerks and courts to redact SSNs and other identifiers from records posted online.
Song-Beverly Credit Card Act: limits on collecting personal information at checkout
Song-Beverly 1747.08Jurisdiction: California
Effective: 1/1/1991
Authority: Cardholders, California Attorney General, district attorneys, and city attorneys
Stops merchants from requesting or requiring a cardholder's personal identification information (such as address, phone number, or ZIP code) as a condition of accepting a credit card, or recording it on the transaction form, except where needed for shipping, delivery, or other listed purposes.
Spam Reduction Act of 2008 (commercial electronic mail)
Colorado Spam Reduction ActJurisdiction: Colorado
Effective: 8/5/2008
Authority: Colorado Attorney General and district attorneys; email service providers
Colorado makes violations of the federal CAN-SPAM Act a state deceptive trade practice and separately bans falsified sender and routing information, unauthorized use of third-party domains, and emailing people who have opted out. Email service providers can sue for statutory damages.
Standards for Workplace Drug and Alcohol Testing Act
OK Workplace Drug Testing ActJurisdiction: Oklahoma
Effective: 6/10/1993
Authority: Private civil actions; State Department of Health (licensing of testing facilities)
Sets standards for employer drug and alcohol testing, including confidentiality of results. Employers must keep test records confidential and may disclose them only to the person tested, the review officer, those administering the program, or under court or agency order; testing facilities may not reveal other health information learned from samples.
State Agency Protection of Personal Information and Breach Notification
MT State Agency Breach LawJurisdiction: Montana
Effective: 10/1/2015
Authority: Montana Department of Administration (chief information security officer); Attorney General receives notice copies
Montana state agencies must protect personal information and notify affected people of data breaches without unreasonable delay. Contractors that hold agency data must notify the agency immediately, notify affected individuals, keep a security policy, and file notice copies with the state CISO and the Attorney General.
Statutory Right to Privacy (civil action)
RI Privacy Act (tort)Jurisdiction: Rhode Island
Authority: Courts via private civil actions
Codifies four privacy torts as statutory rights: freedom from unreasonable intrusion upon seclusion, from appropriation of name or likeness without permission, from unreasonable publicity given to private life, and from false-light publicity. It sets the elements a plaintiff must prove for each.
Stop Harms from Addictive Social Media
MN Addictive Social Media (Minors)Jurisdiction: Minnesota
Effective: 7/1/2027
Authority: Private action by children and parents; Minnesota Attorney General under 8.31 for knowing or reckless violations (325M.40, subds. 9-10)
Signed May 26, 2026 and effective July 1, 2027, this law requires large social media platforms to estimate users' ages, obtain verifiable parental consent before creating or keeping accounts for children 15 and under, set children's accounts to the most private settings, and give parents time-limit tools. It bars addictive features such as infinite scroll, autoplay, and profile-based feeds, and bars targeted advertising, in children's accounts, and forbids selling or disclosing children's account information.
Stop the Spam Calls Act of 2023
MD Stop the Spam Calls ActJurisdiction: Maryland
Effective: 1/1/2024
Authority: Consumer Protection Division, Office of the Attorney General (14-4503(a)(1)); private actions by called parties (14-4503(a)(2))
Maryland's mini-TCPA requires prior express written consent before a telephone solicitation uses an automated dialing system or a prerecorded message, and limits solicitation calls to 8 a.m. to 8 p.m. and three per day on the same subject. Solicitors must transmit accurate caller ID and may not spoof numbers or disguise their voice. A 2024 emergency amendment (ch. 214) adjusted exemptions and remedies.
Student and Teacher Information Protection and Privacy
NH Student and Teacher Privacy ActJurisdiction: New Hampshire
Authority: New Hampshire Department of Education and State Board of Education
Limits what student and teacher personal data the state education department may collect, keep and disclose, and requires public data inventories, a state data security and breach plan, and annual local data and privacy governance plans that vet every school software tool. It also bars schools from RFID tracking, remote surveillance software on school-issued devices, and classroom recording for teacher evaluation without school board approval and written consent.
Student Data Accessibility, Transparency and Accountability Act of 2013
Student DATA ActJurisdiction: Oklahoma
Effective: 7/1/2013
Authority: State Board of Education (rulemaking and compliance oversight); reports to the Governor and Legislature
Governs Oklahoma's statewide student data system. It requires a public inventory of student data elements, FERPA-compliant access and release policies, a data security plan, and legislative approval of new data collections, and it bars most out-of-state transfers of confidential student data. Student data excludes Social Security numbers and biometric information unless in the educational record.
Student Data Privacy (Act Concerning Student Data Privacy)
CT Student Data PrivacyJurisdiction: Connecticut
Effective: 10/1/2016
Authority: Not specified; noncompliant contracts are void (10-234bb(e)-(f)); State Department of Education issues guidance (10-234ee)
Requires school boards to sign written contracts with ed-tech vendors that keep student data under school control, limit use to school purposes, and require deletion and security. Ed-tech operators may not use student data for targeted advertising, sell it, or build non-school profiles, and both contractors and operators must report student data breaches within set deadlines.
Student Data Privacy Protection Act
SDPPAJurisdiction: Delaware
Effective: 8/1/2016
Authority: Consumer Protection Unit, Delaware Department of Justice (8103A)
Delaware's K-12 ed-tech privacy law bars operators of school-focused online services from using student data for targeted advertising, building non-school profiles, selling student data, or disclosing it except for listed school, legal, safety, or service-provider purposes. Operators must meet state cloud-hosting security standards and delete student data within 45 days when a school asks.
Student Data Privacy: Technology Providers and School-Issued Devices (Educational Data)
MN Student Data PrivacyJurisdiction: Minnesota
Effective: 8/1/2022
Authority: Minnesota Government Data Practices Act remedies; technology providers are bound as if government entities under 13.05, subd. 11 (13.32, subd. 13(a))
Minnesota's 2022 student data privacy provisions bar technology providers serving public schools from selling, sharing, or commercially using student educational data, including for advertising, and require them to protect the data, report breaches to the school, and return or destroy data at contract end. Schools and providers generally may not remotely access a school-issued device's location tracking, camera, microphone, keystrokes, or browsing, except for listed purposes such as noncommercial instruction with advance notice, warrants, stolen devices, or imminent threats.
Student Data Protection Act (third-party contractor provisions)
Utah SDPAJurisdiction: Utah
Authority: Utah State Board of Education
Governs ed-tech and other contractors that handle Utah student data: use limited to the contracted service, mandatory contract terms, return or deletion at contract end, and no sale or targeted advertising. 2026 H.B. 55 and S.B. 296 amendments took effect July 1, 2026.
Student Data Protections for Cloud Computing Service Providers
KY Student Cloud DataJurisdiction: Kentucky
Effective: 7/15/2014
Authority: Not specified; the Kentucky Board of Education may issue implementing regulations
Limits how cloud service providers serving K-12 schools may use student data, such as names, emails, messages, documents, and photos. Providers may use it only to provide and maintain the service unless a parent expressly permits more, and may never use it for advertising, ad profiling, sale, or other commercial purposes.
Student Data Transparency and Security Act
Colorado Student Data ActJurisdiction: Colorado
Effective: 8/10/2016
Authority: Contracting public education entities (contract remedies and termination after public hearing); Colorado Department of Education
Colorado's student privacy law requires education technology vendors under contract with public schools to disclose what student data they collect and why, use it only for contracted purposes, and never sell it or use it for targeted advertising. Vendors must maintain an information security program, notify schools of misuse, and destroy data on request or at contract end. Parents gain inspection, correction, and complaint rights.
Student Data-Cloud Computing
RI Student Cloud Data LawJurisdiction: Rhode Island
Authority: Not specified in the statute
Requires cloud service providers serving Rhode Island schools to use K-12 student data only to provide the service to the school, and forbids processing it for commercial purposes such as advertising. Providers must certify compliance in writing when they contract.
Student information privacy (personally identifiable student information)
LA Student Privacy LawJurisdiction: Louisiana
Effective: 8/1/2014
Authority: Criminal prosecution (district attorneys)
One of the strictest state student-data laws: it bars local school officials from collecting sensitive information (such as political or religious beliefs, family income, biometric information, gun ownership, home IP address) unless a parent volunteers it, and bars disclosing personally identifiable student information except in narrow, mostly parent-authorized cases. It limits who may access school computer systems, sets mandatory privacy and security terms for vendor contracts, and bans selling or using student data for advertising or other commercial purposes. A companion section requires the Department of Education and school systems to publish their student-data transfer agreements.
Student Information Protection (school-purpose online operators)
Texas Student Data Privacy LawJurisdiction: Texas
Effective: 9/1/2017
Authority: Not specified in the subchapter (see unverified)
Texas's student online privacy law (H.B. 2087, 2017) bars ed-tech operators from targeted advertising, non-school profiling, and selling or renting students' covered information, and requires reasonable security and deletion on district request. Operators approved by the Texas Education Agency must mask data with the state student identifier.
Student Online Personal Information
NH SOPIPAJurisdiction: New Hampshire
Effective: 1/1/2016
Authority: Not specified in the section
New Hampshire's version of the student online privacy model bars K-12 education technology operators from targeted advertising, building student profiles, and selling or disclosing student information gathered through their services. Operators must secure student data and delete it at a school's request, while de-identified data may be used to improve educational products.
Student Online Personal Information Protection
Iowa Student Online Privacy LawJurisdiction: Iowa
Effective: 7/1/2018
Authority: Not specified in the section
Iowa's student online privacy law bars K-12 edtech operators from using student information for targeted advertising, building non-school profiles, selling or renting student information, or disclosing it except for listed purposes. Operators must also secure covered information and delete it when a school district asks.
Student Online Personal Information Protection Act
Florida SOPIPAJurisdiction: Florida
Effective: 7/1/2023
Authority: Florida Department of Legal Affairs (Attorney General), exclusively, under FDUTPA
Enacted by SB 662 (2023), this is Florida's version of California's SOPIPA. It bars K-12 edtech operators from targeted advertising, building student profiles for non-school purposes, and selling or renting student information, and requires data minimization, reasonable security, and deletion of student data after the course ends.
Student Online Personal Protection Act
Nebraska SOPPAJurisdiction: Nebraska
Effective: 9/1/2017
Authority: No enforcement provision stated in the act
Nebraska's version of the SOPIPA model law restricts K-12 edtech operators' use of student data. Operators may not use covered student information for targeted advertising or non-school profiles, may not sell or rent it, may disclose it only for listed purposes, and must secure it and delete it on a school's request.
Student Online Personal Protection Act
Tenn. SOPPAJurisdiction: Tennessee
Effective: 7/1/2016
Authority: Tennessee Attorney General and Reporter (sole enforcement, as a Tennessee Consumer Protection Act violation)
Tennessee's student-privacy law for education technology vendors. Operators of K-12 online services may not use student information for targeted advertising, build student profiles for non-school purposes, sell or rent student information, or disclose it except for listed purposes. They must keep reasonable security and delete student data when a school or district asks.
Student Personal Analysis, Evaluation, or Survey (third-party vendor surveys)
IN Student Survey PrivacyJurisdiction: Indiana
Effective: 7/1/2023
Authority: School grievance procedures; contract enforcement by schools
When Indiana public schools use outside vendors for surveys or evaluations of students' attitudes, beliefs, or feelings, neither the vendor nor the school may keep results in a form that identifies individual students. Schools must also get written parental consent (or the adult student's) before giving such surveys. Academic tests, career surveys, crisis screenings, and satisfaction surveys are exempt.
Student personal information; school service providers and school-issued devices
VA student data privacyJurisdiction: Virginia
Effective: 7/1/2015
Authority: Not stated in the section (enforced mainly through school division contracts)
Virginia's K-12 student privacy law. Edtech providers and school device providers must publish clear privacy policies, run information security programs, let students and parents access and correct data, delete data on request, and use data only with consent or as the school contract allows. They may not use student data for targeted advertising, build non-school profiles, or sell it, and may not remotely use school-issued devices' location, camera, microphone, or interaction monitoring except for limited educational, support, proctoring, or safety purposes.
Student Privacy (Student Online Personal Information Protection)
VT Student PrivacyJurisdiction: Vermont
Effective: 7/1/2020
Authority: Vermont Attorney General (Consumer Protection Act)
Vermont's student privacy law, modeled on California's SOPIPA, stops edtech operators from using student information gathered for PreK-12 school purposes to target ads, build non-educational profiles, or sell student data. Operators must protect the data, delete it when a school asks, and publish their data practices.
Student Social Media Privacy
RI Student Social Media Privacy ActJurisdiction: Rhode Island
Authority: Courts via student or applicant civil actions
Bars schools and colleges from requiring or asking students and applicants for personal social media passwords, making them log in in front of school staff, forcing them to add coaches or teachers as contacts or change privacy settings, and from disciplining or refusing admission to those who refuse.
Student social media privacy (postsecondary institutions)
Educ. Code 99120-99122Jurisdiction: California
Effective: 1/1/2013
Authority: Courts
Bars colleges and universities from requiring or asking students or applicants for social media passwords, to open their accounts in front of staff, or to divulge personal social media, and from punishing refusal.
Surveillance Pricing and Price-Setting Device Disclosure (P.A. 26-64, s. 11)
CT Surveillance PricingJurisdiction: Connecticut
Effective: 10/1/2026
Authority: Connecticut Attorney General (solely; P.A. 26-64, s. 11(e))
Requires businesses that use personal data in an automated price-setting device (other than to offer a discount) to label online prices with a prescribed warning, and bars retailers and delivery apps from charging individualized prices based on personal data gathered through tracking technologies. Cost-based, supply-and-demand, retention and uniformly available discounts are carved out.
Synthetic Media and Deceptive and Fraudulent Deepfakes in Elections
NH Election Deepfake Disclosure LawJurisdiction: New Hampshire
Effective: 8/1/2024
Authority: Depicted candidates and election officials through civil suits
Bars distributing AI-generated deepfakes of candidates, election officials or parties within 90 days of an election unless the media carries a prescribed disclosure that it was manipulated or generated by AI and depicts speech or conduct that did not occur. Depicted candidates and officials may sue for injunctive relief and damages.
Synthetic Media in Electioneering Communications
KY Election Deepfake DisclosureJurisdiction: Kentucky
Effective: 3/24/2025
Authority: Affected candidates via civil action in Circuit Court
Lets a candidate whose appearance, actions, or speech are altered with synthetic media (AI-generated or manipulated content) in an electioneering communication sue the sponsor to require a clear and conspicuous disclosure. Including such a disclosure is an affirmative defense, and platforms and media outlets are generally not liable.
Synthetic Media in Elections
VT Election Deepfake LawJurisdiction: Vermont
Effective: 3/5/2026
Authority: Vermont Attorney General and State's Attorneys; candidates (injunctive relief)
Requires a set disclosure on AI-generated or manipulated media that realistically but falsely depicts a candidate, or gives materially false election information, when distributed within 90 days before a Vermont election. Visual disclosures must stay readable for the whole video, and audio disclosures must be spoken at the start and end and at least every two minutes.
Synthetic performers in advertising (SB 1050)
SB 1050Jurisdiction: California
Effective: 1/1/2027
Authority: Public prosecutors; courts
Signed September 16, 2026. Requires a clear disclosure, such as 'this performance features a synthetic performer', when an ad prominently uses an AI-generated performer who is not a recognizable real person.
Telemarketer Restriction Act
OK Do-Not-Call ActJurisdiction: Oklahoma
Effective: 7/1/2002
Authority: Oklahoma Attorney General (Oklahoma Consumer Protection Act actions or administrative fines)
Creates Oklahoma's state do-not-call registry maintained by the Attorney General and bars telemarketers from calling or texting registered consumers more than 30 days after their numbers appear on the list. Calls to consumers with an established business relationship (within 24 months) are exempt.
Telemarketing (autodialers, caller ID and do-not-call)
NH Telemarketing LawJurisdiction: New Hampshire
Effective: 1/1/1990
Authority: New Hampshire Department of Justice, Consumer Protection and Antitrust Bureau
Requires anyone using prerecorded autodialers for solicitation to register with the Attorney General's consumer protection bureau, identify themselves and the call's purpose, and disconnect promptly, and bans solicitors from blocking or spoofing caller ID. It also incorporates the national do-not-call registry and the FTC Telemarketing Sales Rule into state law, with state penalties and a private right of action.
Telemarketing and Do-Not-Call Law (including text messages)
CT Telemarketing / Do Not CallJurisdiction: Connecticut
Effective: 1/1/2001
Authority: Connecticut Department of Consumer Protection and Attorney General (CUTPA)
Connecticut adopts the National Do Not Call Registry as its no-call list and, after 2023 amendments, requires prior express written consent for all telephonic sales calls and texts. Calls are limited to 9 a.m. to 8 p.m., callers must identify themselves within 10 seconds and honor removal requests, caller ID spoofing is barred, and anyone knowingly assisting illegal robocallers is liable.
Telemarketing and Prize Promotions Act
Nebraska Telemarketing and Prize Promotions ActJurisdiction: Nebraska
Authority: Nebraska Attorney General
This consumer protection law governs telephone sales and prize promotions. It requires verifiable consumer authorization before a seller draws on a bank account, gives a five-business-day cancellation right unless a qualifying refund policy exists, bans prize misrepresentations, and requires sellers to keep telemarketing records.
Telephone records protection (pretexting) law
OK Telephone Records ActJurisdiction: Oklahoma
Effective: 11/1/2006
Authority: District attorneys (criminal); Attorney General (Consumer Protection Act)
Criminalizes obtaining, selling, or receiving a person's call records without the customer's authorization or through fraud or pretexting. Telephone companies must maintain reasonable procedures to protect records, which is satisfied by good-faith compliance with the federal CPNI rules.
Telephone Sales Solicitation Act (telemarketer registration, do-not-call, robocalls and text advertising)
RI TSSAJurisdiction: Rhode Island
Authority: Rhode Island Attorney General (Consumer Protection Unit); prosecutors; purchasers via civil action
Requires covered telemarketers to register annually with the Attorney General and post a ,000 bond, identify themselves at the start of calls, and call only during set hours. It requires all telephone sellers to keep internal do-not-call lists, limits prerecorded messages to consenting subscribers, and broadly bans unsolicited text-message advertising to Rhode Island cell phones except from carriers and businesses with an existing relationship that offer an opt-out.
Telephone Solicitation Act of 2022
OTSAJurisdiction: Oklahoma
Effective: 11/1/2022
Authority: Private civil actions by called parties
Oklahoma's 'mini-TCPA' requires prior express written consent before making commercial sales calls or texts that use an automated system for selecting or dialing numbers or a recorded message, bars calls before 8 a.m. or after 8 p.m. and more than three calls in 24 hours on the same subject, and requires accurate caller ID. Called parties may sue.
Telephone solicitation and do-not-call rules
Cal. Do Not Call (17592)Jurisdiction: California
Authority: California Attorney General and local prosecutors
Adopts the federal Do Not Call Registry for California: telephone solicitors may not call numbers on the current national list (obtained within the last three months) except with written consent or other listed exceptions, and list sellers must scrub registered numbers.
Telephone Solicitation No-Call List
MT No-Call LawJurisdiction: Montana
Effective: 10/1/2003
Authority: Montana Department of Justice or county attorneys
Montana keeps a state no-call list that includes the Montana portion of the national Do Not Call registry. Telephone solicitors may not call listed residential subscribers, must identify themselves at the start of the call, and may not block caller ID.
Telephone Solicitation of Consumers (Indiana Do Not Call list)
IN Do Not CallJurisdiction: Indiana
Authority: Indiana Attorney General, Consumer Protection Division
Indiana keeps its own no-telephone-sales-solicitation list, run by the Attorney General's Consumer Protection Division, and bars telephone sales calls to numbers on it. Since 2024, sales texts and other device messages count as telephone sales calls. The article also requires caller disclosures and bars selling listed numbers or knowingly helping violators.
Telephone Solicitation Relief Act of 2001 (Louisiana Do Not Call)
LA Do Not Call LawJurisdiction: Louisiana
Effective: 5/24/2001
Authority: Louisiana Public Service Commission
Louisiana's do-not-call law, run by the Public Service Commission, protects residential telephone subscribers who object to unsolicited sales calls. The state list incorporates Louisiana numbers on the National Do Not Call Registry; solicitors must register with the PSC, pay fees, buy the list, and not call listed numbers except as the Chapter or federal law allows.
Telephone Solicitations (seller registration and caller ID blocking)
IN Telephone Seller RegistrationJurisdiction: Indiana
Authority: Indiana Attorney General, Consumer Protection Division; county prosecutors (criminal); private parties
Covered telephone sellers must register with the Attorney General and update their registration every year. The chapter also makes it a crime to block one's number or identity from caller ID while making a telephone solicitation outside an existing course of dealing.
Telephonic Communications Made for Purpose of Solicitation (state TCPA remedy)
Texas Mobile Solicitation Call LawJurisdiction: Texas
Effective: 4/1/2009
Authority: Prosecutors (criminal); private plaintiffs; DTPA public and private remedies
Bars unconsented sales calls to mobile phones that are charged per call and certain fax practices, and gives Texans a state-court action for violations of the federal Telephone Consumer Protection Act and its rules.
Tennessee data breach notification law (Release of personal consumer information)
Tenn. Breach NotificationJurisdiction: Tennessee
Effective: 7/1/2005
Authority: Tennessee Attorney General (a violation of part 21 is a Tennessee Consumer Protection Act violation, § 47-18-2106); private suits by injured customers
Requires businesses and government bodies holding computerized personal information of Tennesseans to notify affected residents no later than 45 days after discovering a breach, with a law-enforcement delay. Personal information means name plus SSN, driver license number, or a financial account or card number with its access code. Encrypted data (FIPS 140-2) is covered only if the key is also taken, and large breaches must also be reported to the nationwide credit bureaus.
Tennessee Do Not Call and text solicitation law
Tenn. Do Not Call LawJurisdiction: Tennessee
Authority: Tennessee Public Utility Commission; Tennessee Attorney General at the commission's request
Creates Tennessee's Do Not Call Register, run by the Public Utility Commission, and bars telephone and (since July 1, 2023) text message solicitations to residential subscribers who have registered their objection. Solicitors must register and pay an annual fee to access the list, identify themselves at the start of each call or text, and contact people only between 8 a.m. and 9 p.m.
Tennessee Information Protection Act
TIPAJurisdiction: Tennessee
Effective: 7/1/2025
Authority: Tennessee Attorney General and Reporter (exclusive authority)
Max Fine: Up to ,500 per violation
Tennessee's comprehensive consumer privacy law gives residents rights to access, correct, delete, and port their personal information and to opt out of sale, targeted advertising, and significant-decision profiling. It applies only to businesses with more than $25 million in revenue that also meet a data-volume threshold, requires opt-in consent for sensitive data, and gives a unique affirmative defense to businesses whose written privacy program reasonably conforms to the NIST Privacy Framework.
Tennessee wiretapping and electronic surveillance law (including cellular and cordless telephone recording)
Tenn. Wiretap ActJurisdiction: Tennessee
Authority: District attorneys (criminal prosecution)
Tennessee is a one-party consent state: a person who is a party to a wire, oral, or electronic communication, or who has one party's prior consent, may intercept it unless the purpose is a criminal or tortious act. A 2024 amendment repealed the statute's civil damages action and declared that the law does not restrict businesses from disclosing communications to vendors or using vendor cookies and pixels on websites and apps, a response to web-tracking wiretap suits.
Texas Data Broker Law
Texas Data Broker LawJurisdiction: Texas
Effective: 9/1/2023
Authority: Texas Attorney General; Texas Secretary of State administers registration and the registry
Requires data brokers to register annually with the Texas Secretary of State, post a conspicuous data-broker notice, and keep a written comprehensive information security program. The 2025 session broadened the definition of data broker, added a TDPSA-rights link to the registration and website notice, and moved the law from chapter 509 to chapter 510.
Texas Data Privacy and Security Act
TDPSAJurisdiction: Texas
Effective: 7/1/2024
Authority: Texas Attorney General (exclusive; 541.151)
Max Fine: Up to $7,500 per violation
Texas's comprehensive consumer privacy law. It gives Texas consumers rights to access, correct, delete, and port their personal data and to opt out of targeted advertising, sale, and significant profiling, and requires controllers to give privacy notices, get consent for sensitive data, and run data protection assessments. It has no revenue threshold; it applies to any covered business that is not an SBA-defined small business.
Texas Genomic Act of 2025
Texas Genomic ActJurisdiction: Texas
Effective: 9/1/2025
Authority: Texas Attorney General
Keeps Texans' genome sequencing data away from foreign adversaries (as defined in 15 C.F.R. 791.4(a)). Covered entities may not use sequencers or software from foreign-adversary sources, may not store or allow access to Texans' sequencing data in adversary countries, must secure that data, and must certify compliance to the attorney general each year.
Texas Medical Records Privacy Act
Texas Medical Records Privacy ActJurisdiction: Texas
Effective: 9/1/2001
Authority: Texas Attorney General; Health and Human Services Commission and licensing agencies (audits, discipline)
Texas's health privacy law, strengthened by H.B. 300 (2011), reaches anyone who handles protected health information, not just HIPAA covered entities. It requires workforce privacy training, electronic record access within 15 business days, and consent for marketing uses, and it bans the sale of PHI and reidentification and requires notice and authorization for electronic disclosures.
Texas Responsible Artificial Intelligence Governance Act
TRAIGAJurisdiction: Texas
Effective: 1/1/2026
Authority: Texas Attorney General (exclusive); licensing agencies may add sanctions on AG recommendation (552.101, 552.106)
Texas's AI statute sets baseline prohibitions on developing or deploying AI to manipulate people toward self-harm or crime, to unlawfully discriminate, to infringe constitutional rights, or to produce child sexual abuse material. It requires government agencies and health care providers to tell people they are interacting with AI, bars government social scoring and non-consensual biometric identification, and creates an AI regulatory sandbox and the Texas Artificial Intelligence Council. It also amended the biometric law (503.001) and TDPSA processor duties (541.104).
Texas Telemarketing Disclosure and Privacy Act (Texas no-call list)
Texas No-Call ActJurisdiction: Texas
Effective: 4/1/2009
Authority: Public Utility Commission of Texas; Texas Attorney General; state licensing agencies
Creates the Texas no-call list and bars telemarketing calls to listed numbers more than 60 days after they appear. It also bars caller-ID blocking or spoofing by telemarketers and regulates fax solicitations.
Texas Wiretap Law (Unlawful Interception, Use, or Disclosure of Communications)
Texas Wiretap ActJurisdiction: Texas
Effective: 8/31/1981
Authority: State prosecutors (criminal); federal or state government civil suits (Code Crim. Proc. art. 18A.503)
Texas is a one-party consent state: intercepting a wire, oral, or electronic communication is a crime unless the person is a party to it or a party gave prior consent. The chapter also criminalizes unauthorized access to stored communications, unauthorized pen registers, and divulgence of communications by public service providers, and the Code of Criminal Procedure gives victims a civil damages action.
Theft of Identity and Trafficking in Stolen Identities (criminal offense and civil action)
KY Identity TheftJurisdiction: Kentucky
Effective: 7/14/2000
Authority: Prosecutors; victims via civil action; Consumer Protection Act enforcement for repeat business violators
Criminalizes knowingly possessing or using another person's identifying information, including name, SSN, account PINs, and unique biometric data, to impersonate them for gain, credit transactions, evading detection, or commercial or political benefit. Victims have a civil cause of action for compensatory and punitive damages and fees.
Tort Liability for Cybersecurity Programs (cybersecurity safe harbor)
Iowa Cybersecurity Safe HarborJurisdiction: Iowa
Effective: 7/1/2023
Authority: None (courts apply the affirmative defense in tort suits)
Iowa's cybersecurity safe harbor gives businesses an affirmative defense against tort lawsuits over data breaches if they maintain a written cybersecurity program that reasonably conforms to a recognized framework such as the NIST Cybersecurity Framework, NIST SP 800-171 or 800-53, FedRAMP, CIS Controls, or ISO/IEC 27000. It is voluntary: it rewards good security rather than mandating it.
Tracking device prohibition and vehicle remote-access suspension for abuse survivors
LA Location Tracking ProtectionsJurisdiction: Louisiana
Authority: District attorneys (R.S. 14:323); Louisiana Attorney General (R.S. 46:2193)
Louisiana makes it a crime to use a tracking device to follow another person's location or movements without consent, with exceptions for vehicle owners, parents of minors, law enforcement with a court order, and others. A 2025 law removes the owner exception for abusers subject to protective orders and requires vehicle manufacturers to cut off an abuser's remote access to a survivor's vehicle within two business days of a complete request.
Transparency in Frontier Artificial Intelligence Act (SB 53)
TFAIAJurisdiction: California
Effective: 1/1/2026
Authority: California Attorney General (civil penalties); Office of Emergency Services (incident reports)
An AI safety transparency law rather than a privacy law: large frontier AI developers must publish a framework for managing catastrophic risk, publish transparency reports when releasing frontier models, and report critical safety incidents to the Office of Emergency Services. Included here because it is one of California's core AI statutes.
Unauthorized Placement of Global Positioning Device; Stalking by Technological Device
Iowa GPS Tracking LawJurisdiction: Iowa
Effective: 7/1/2017
Authority: County attorneys and the Attorney General (criminal prosecution)
Iowa makes it a crime to secretly put a GPS tracker on another person or their property to follow their movements without consent or a legitimate purpose. The same 2017 act expanded the stalking law so that repeatedly using phones, cameras, recorders, or GPS devices to locate, listen to, or watch someone without authorization can form a stalking course of conduct.
Unauthorized use of electronic tracking device
VA tracking deviceJurisdiction: Virginia
Effective: 7/1/2013
Authority: Criminal prosecution
Makes it a crime to deceptively place a GPS or other electronic tracking device without consent and use it to track a person's location. Fleet owners and electronic communications providers that disclose tracking in their terms or privacy policy are exempt.
Unauthorized use of name, picture, voice, or likeness (statutory right of privacy and publicity)
VA right of publicityJurisdiction: Virginia
Authority: Private civil action
Virginia's only statutory privacy tort: a person, or a deceased person's spouse or next of kin, may sue to stop and recover damages for the use of their name, portrait, picture, voice, or likeness for advertising or trade without written consent (a parent's consent for minors).
Uniform Civil Remedies for Unauthorized Disclosure of Intimate Images Act
Nebraska Intimate Images Civil Remedies ActJurisdiction: Nebraska
Effective: 9/1/2019
Authority: Courts (private civil action)
This uniform act gives people depicted in private intimate images a civil claim against anyone who shares or threatens to share those images without consent. A 2025 amendment (LB371) extends it to computer-generated or digitally manipulated images, covering sexual deepfakes. Consenting to an image's creation or earlier sharing does not by itself mean consent to later disclosure.
Uniform Civil Remedies for Unauthorized Disclosure of Intimate Images Act
Iowa Intimate Images Civil Remedy ActJurisdiction: Iowa
Effective: 7/1/2021
Authority: Depicted individuals (civil action)
Iowa adopted the Uniform Law Commission's civil remedy for nonconsensual disclosure of intimate images. A depicted person can sue someone who knowingly or recklessly shares, or threatens to share, a private intimate image without consent, and may proceed with identifying details redacted. Consent to creating an image or an earlier consensual sharing does not by itself mean consent to later disclosure.
Uniform Deceptive Trade Practices Act: Privacy Policy and Related Online Provisions
Nebraska UDTPA Privacy ProvisionsJurisdiction: Nebraska
Authority: Nebraska Attorney General; private injunctive actions
Nebraska's deceptive trade practices statute makes it a deceptive practice to knowingly make a false or misleading statement in a published privacy policy about how personal information from the public is used, which works as Nebraska's online privacy policy accuracy rule. Later amendments added a ban on publishing sexually explicit depictions of minors or nonconsenting people (LB383, 2025) and, from 2027, duties on paid-ad social media platforms to verify advertisers' identities and fight impersonation scams (LB838, 2026).
Uniform Health Care Information Act (providers not subject to HIPAA)
MT UHCIAJurisdiction: Montana
Effective: 10/1/1987
Authority: Attorney General or county attorney (civil, 50-16-552); private plaintiffs (50-16-553)
Montana's Uniform Health Care Information Act protects patient health information held by providers not covered by HIPAA, limiting disclosure without written patient authorization and giving patients rights to see, copy and correct their records. A 2025 amendment extends its confidentiality rules to mental health and substance-use apps and websites.
Uniform Motor Vehicle Records Disclosure Act
Nebraska UMVRDAJurisdiction: Nebraska
Authority: Nebraska Department of Motor Vehicles; criminal prosecution for false statements
Nebraska's implementation of the federal Driver's Privacy Protection Act bars the DMV from disclosing personal information in motor vehicle records except for listed permissible purposes, and bars disclosure of sensitive personal information (such as photos and SSNs) without express written consent except as listed. Private recipients may resell or redisclose only for permitted uses and must keep five years of records; bulk marketing use requires notarized written consent of each individual.
Unlawful Access to Stored Communications
Florida Stored Communications LawJurisdiction: Florida
Authority: State attorneys (criminal)
Florida's counterpart to the federal Stored Communications Act. It makes it a crime to access an electronic communication service facility without authorization and obtain, alter, or prevent access to messages in electronic storage. Conduct authorized by the service provider, or by the user for that user's own communications, is excepted.
Unlawful Automated Telephone Solicitation
MT Robocall LawJurisdiction: Montana
Effective: 10/1/1991
Authority: County attorneys and the Attorney General (criminal prosecution)
Montana bans automated dialing with prerecorded messages for selling, soliciting, gathering data or political campaigning. Informational calls about purchased goods, responses to inquiries, and calls where there is a preexisting business relationship are allowed.
Unlawful creation of image of another (voyeurism)
VA unlawful image creationJurisdiction: Virginia
Effective: 7/1/1994
Authority: Criminal prosecution
Criminalizes secretly creating video or still images of a nonconsenting person who is nude, in undergarments, or partly undressed in places such as restrooms, dressing rooms, locker rooms, hotel rooms, and bedrooms, and upskirt-style images taken from beneath a person.
Unlawful deepfakes and AI-generated intimate images
LA AI Deepfake Image CrimesJurisdiction: Louisiana
Effective: 8/1/2023
Authority: District attorneys (criminal)
Louisiana criminalizes sexual deepfakes of minors, the distribution or sale of nonconsensual sexual deepfakes of anyone, and the malicious dissemination or sale of AI-created nude images of an identifiable real person. Act 782 of 2026 raised penalties, added enhancements for educators who target students, and created a new crime of possessing such AI images. These laws protect people's intimate image privacy against synthetic media.
Unlawful disclosure of private information (doxxing): civil action and crime
ORS 30.835; 163.720Jurisdiction: Oregon
Effective: 6/15/2021
Authority: Private civil action (ORS 30.835); district attorneys for the crime (ORS 163.720)
Gives doxxing victims a civil claim when someone knowingly publishes their personal contact details or information about their children to stalk, harass or injure them, and since January 1, 2026 makes doxxing that leads to stalking, injury or property damage a crime.
Unlawful dissemination of intimate images, including realistic digitally created depictions
ORS 163.472; 30.833Jurisdiction: Oregon
Authority: District attorneys (criminal); private civil actions (ORS 30.833, 30.834)
Oregon's nonconsensual intimate image law makes it a crime, and a civil wrong, to share someone's intimate images to harass, humiliate or injure them. HB 2299 (2025) extended it from January 1, 2026 to realistic AI-generated or digitally altered 'deepfake' images.
Unlawful dissemination or sale of images of another (including synthetic images)
VA intimate imagesJurisdiction: Virginia
Effective: 7/1/2014
Authority: Criminal prosecution
Criminalizes maliciously disseminating or selling nude or sexual images of another person without authorization, with intent to coerce, harass, or intimidate. Since 2019 the section covers images 'created by any means whatsoever', which reaches AI-generated or altered deepfake images.
Unlawful Installation of Tracking Device
Texas Tracking Device LawJurisdiction: Texas
Effective: 9/1/1999
Authority: State prosecutors
Makes it a crime to knowingly install a location-tracking device on another person's vehicle. Consent of the owner or lessee, assisting police, and licensed private investigators acting with written consent or court authorization are affirmative defenses.
Unlawful Intrusion and Nonconsensual Intimate Image Crimes
Nebraska Unlawful Intrusion LawJurisdiction: Nebraska
Authority: County attorneys and the Attorney General (criminal prosecution)
Nebraska's voyeurism statute criminalizes intruding on people in a state of undress, secretly recording intimate areas even in public places, distributing such recordings, distributing private intimate or sexual images without consent (revenge porn), and threatening to do so. Drones are expressly covered.
Unlawful Photography, Surveillance, and Tracking on Private Property
IN Unlawful Surveillance and TrackingJurisdiction: Indiana
Authority: County prosecutors
Indiana makes it a crime to leave recording cameras or surveillance equipment on someone else's private property without the owner's or tenant's consent. It is also a crime to place a tracking device on a person or their property without that person's knowledge or consent. Exceptions cover law enforcement with a warrant, family-member tracking (unless a protective order applies), owners of the tracked property, factory-installed vehicle equipment, and communications providers whose tracking is disclosed in their terms or privacy policy.
Unlawful Production or Distribution of Certain Sexually Explicit Media (deepfakes)
Texas Deepfake LawJurisdiction: Texas
Effective: 9/1/2023
Authority: State prosecutors
Criminalizes creating or distributing AI-generated or altered sexual images or videos of real people without their written consent, and threatening to do so. Disclaimers are no defense; S.B. 441 (2025) added written-consent requirements and defenses for intermediaries and AI providers whose terms prohibit such content.
Unlawful use of drones for surveillance
OK Drone Surveillance LawJurisdiction: Oklahoma
Effective: 11/1/2022
Authority: District attorneys (criminal prosecution)
Makes it a misdemeanor to use a drone to trespass onto private property or low airspace for eavesdropping or surveillance, to photograph or record people where they have a reasonable expectation of privacy, to install recording devices on private property without consent, or to land on private property without consent.
Unlawful Use of Mobile Tracking Devices
Nebraska Mobile Tracking Device LawJurisdiction: Nebraska
Effective: 7/18/2026
Authority: County attorneys and the Attorney General (criminal prosecution)
Enacted by LB935 (2026), this law makes it a felony to put a tracking device or app on someone else's property, or to track a person or their property, without consent, and to fail to remove a device after consent is revoked. Consent is automatically revoked when a spouse files for divorce, annulment, or separation or when a protection order is issued.
Unmanned aircraft image capture and surveillance law
Tenn. Drone Surveillance LawJurisdiction: Tennessee
Effective: 7/1/2014
Authority: District attorneys (criminal prosecution)
Makes it a crime to use a drone to capture images of a person or privately owned real property in Tennessee with intent to conduct surveillance, and to keep or share such images. Later amendments add drone restrictions over large ticketed events, fireworks sites, correctional facilities, and critical infrastructure. Destroying or ceasing to share an image once its unlawful origin is known is a defense.
Unmanned Aircraft System Privacy Restrictions
KY Drone Surveillance LawJurisdiction: Kentucky
Effective: 7/14/2018
Authority: Prosecutors; property owners, tenants, occupants, invitees, and licensees via civil action
Allows commercial, recreational, and educational drone use but, since 2025, bars operators from recording images of private property or the people on it with intent to surveil them or publish unauthorized images in violation of their reasonable expectation of privacy. People on private property are presumed to have that expectation if they cannot be seen from ground level. Law enforcement drone searches require a warrant or other Fourth Amendment authority and must minimize data on nonsuspects.
Unsolicited Advertisement Facsimile Transmissions
MT Junk Fax LawJurisdiction: Montana
Effective: 10/1/2003
Authority: Montana Department of Justice, Office of Consumer Protection
Montana bans sending unsolicited advertisements to fax machines. Public-safety faxes from law enforcement or public-safety entities are exempt.
Unsolicited advertising by electronic means (commercial e-mail)
Tenn. Commercial Email LawJurisdiction: Tennessee
Authority: Injured recipients and e-mail service providers (private civil action)
Requires senders of unsolicited advertising e-mail to provide a toll-free number or return e-mail address for opting out, to honor opt-outs, and to begin the subject line with "ADV:" ("ADV: ADLT" for adult material). It also bans distributing software built to falsify e-mail routing information. The statute says it becomes inoperative when federal law regulates unsolicited commercial e-mail, which raises a real question about its current force after CAN-SPAM (2003).
Unsolicited Facsimile Advertisement Law
NJ Junk Fax LawJurisdiction: New Jersey
Effective: 12/1/2005
Authority: Private actions in Superior Court; Attorney General / Division of Consumer Affairs under the Consumer Fraud Act (56:8-160)
New Jersey bans sending unsolicited fax advertisements within the state, except to recipients with an existing business relationship or fellow members of a nonprofit or trade association. Even permitted faxes must carry a first-page opt-out notice, and recipients can sue for statutory damages.
Unsolicited Facsimile Advertising
MN Junk Fax LawJurisdiction: Minnesota
Authority: Minnesota Attorney General and private parties via 8.31 (325E.395, subd. 3)
Businesses may send unsolicited fax advertisements only if they provide a toll-free number and mailing address where recipients can ask not to receive more, state that information on the fax in at least 9-point type, and stop sending to anyone who asks.
Unsolicited facsimiles
Colorado junk fax lawJurisdiction: Colorado
Effective: 5/18/1999
Authority: Colorado Attorney General and district attorneys
Sending unsolicited fax advertisements, faxing without identifying header information, or violating the federal TCPA fax rules is a Colorado deceptive trade practice. Existing business relationships and consented nonprofit faxes are exempt.
Unsolicited Fax Advertising and Unsolicited Commercial Email
RI Fax and Email Advertising LawJurisdiction: Rhode Island
Authority: Rhode Island Attorney General (fax violations as deceptive trade practices); recipients via civil action
Requires senders of unsolicited advertising faxes and unsolicited commercial emails to give recipients a toll-free number (or, for email, a working reply address) to stop further messages, and to honor those requests. It also prohibits commercial emails that spoof a third party's domain name or falsify the message's origin or transmission path. Federal CAN-SPAM likely preempts parts of the email section; see unverified.
Unsolicited Fax, Recorded Telephone Messages and Commercial Email
CT Unsolicited Fax & EmailJurisdiction: Connecticut
Authority: Private civil action in Superior Court
Bans unsolicited advertising faxes and automated recorded sales messages, and requires unsolicited commercial email to Connecticut residents to carry an opt-out method and an 'ADV' subject-line label and to stop after an opt-out. The email rules are likely largely preempted by the federal CAN-SPAM Act.
Urine and Blood Tests as a Condition of Employment
RI Workplace Drug Testing LawJurisdiction: Rhode Island
Authority: Prosecutors (misdemeanor); courts via employee civil actions
Limits employer drug testing of current employees to reasonable-suspicion testing based on documented observations, with private sample collection, confirmatory lab testing, an independent retest, a chance to explain, referral to treatment instead of firing for a first positive, and confidentiality of results. Applicants may be tested only after a conditional job offer.
Use of Artificial Intelligence by Healthcare Providers Notification Act
RI Healthcare AI Notification ActJurisdiction: Rhode Island
Effective: 6/22/2026
Authority: Rhode Island Department of Health (licensing authority; the act names no enforcer)
Requires doctors, nurses and other licensed providers and facilities that use artificial intelligence (such as ambient AI scribes) to document patient visits to tell patients about that use and to review the AI-generated documentation for accuracy after the visit.
Use of Artificial Intelligence in Health Care (utilization review)
HB 26-1139Jurisdiction: Colorado
Effective: 1/1/2027
Authority: Colorado Division of Insurance; Department of Human Services; Department of Health Care Policy and Financing
From January 1, 2027, AI used in health coverage utilization review must base decisions on the individual's clinical data, not solely group data, and any medical-necessity denial must be reviewed by a qualified clinician. Entities must periodically review the AI for accuracy and ensure health data is not used beyond its stated purpose, and must disclose their AI use to regulators.
Use of Artificial Intelligence in Political Advertising
Florida AI Political Ad Disclaimer LawJurisdiction: Florida
Effective: 7/1/2024
Authority: Florida Elections Commission; state attorneys
Enacted by HB 919 (2024), this law requires a prominent 'Created in whole or in part with the use of generative artificial intelligence (AI)' disclaimer on political ads that use generative AI to depict a real person doing something that did not happen, when made with intent to injure a candidate or deceive about a ballot issue. It sets size and duration rules for print, video, online, audio, and graphic formats.
Use of Credit Information (personal insurance)
IN Insurance Credit ScoringJurisdiction: Indiana
Effective: 1/1/2004
Authority: Indiana Insurance Commissioner / Department of Insurance
Based on the NCOIL credit-scoring model, this chapter limits how personal-lines insurers use credit information. It bans scores built on income, gender, address, ZIP code, ethnicity, religion, marital status, or nationality, and bars decisions based solely on credit. It also requires disclosure, adverse-action notices, re-rating after credit corrections, and filing of scoring models.
Use of Credit Information in Personal Insurance
DE Insurance Credit Scoring LawJurisdiction: Delaware
Effective: 1/1/2008
Authority: Delaware Insurance Commissioner
Limits how personal-lines insurers use credit information: insurance scores may not use income, gender, sexual orientation, gender identity, education, address, zip code, race, religion, marital status, or nationality, and credit alone cannot drive denial, cancellation, or renewal rates. Insurers must disclose that they may use credit and give specific reasons for credit-based adverse actions.
Use of Deep Fake Technology to Influence an Election
MN Election Deepfake LawJurisdiction: Minnesota
Effective: 8/1/2023
Authority: Criminal prosecution; injunctive relief actions by the Attorney General, county or city attorneys, the depicted individual, or an injured candidate (609.771, subds. 3-4)
Makes it a crime to knowingly or recklessly disseminate a realistic deep fake of a person without consent, with intent to injure a candidate or influence an election, within 90 days before a party nominating convention or after absentee voting begins. The Eighth Circuit affirmed the denial of a preliminary injunction in Kohls v. Ellison on February 9, 2026, so the law remains enforceable while the challenge continues.
Use of Deep Fake Technology to Influence an Election
DE Election Deep Fake LawJurisdiction: Delaware
Effective: 10/9/2024
Authority: Criminal prosecution by the State; depicted candidates may sue in the Court of Chancery (5145(f)-(g))
Makes it a crime to knowingly distribute an AI-generated or digitally manipulated deep fake of a candidate or party within 90 days before an election without the depicted person's consent, unless the media carries a prescribed disclosure that it was altered or artificially generated.
Use of Genetic Information in Occupational Licensing
Texas Occupational Licensing Genetic PrivacyJurisdiction: Texas
Effective: 9/1/2003
Authority: Texas Attorney General (civil penalty)
Prevents licensing authorities from denying, suspending, or disciplining occupational licenses based on genetic information or refusal to take a genetic test, and makes genetic information confidential with a right to test results and sample destruction.
Use of Genetic Testing Information by Health Benefit Plans
Texas Insurance Genetic PrivacyJurisdiction: Texas
Effective: 4/1/2005
Authority: Texas Commissioner of Insurance (Texas Department of Insurance)
Limits how health plan issuers may request and use genetic tests. Issuers may not use genetic information or a refusal to be tested to reject, deny, limit, or price coverage, must keep genetic information confidential, and must destroy samples after use.
Use of Lawful Products During Nonworking Hours
MT Lawful Product LawJurisdiction: Montana
Effective: 10/1/1993
Authority: Private civil action (see 39-2-314)
Employers may not refuse to hire or discriminate against people for legally using lawful products, including food, alcohol, tobacco and marijuana, off premises during nonworking hours. The rule protects off-duty private conduct, with exceptions for impairment and job-related qualifications.
Use of Social Media and Electronic Mail (employee and applicant account privacy)
NH Employee Social Media Privacy LawJurisdiction: New Hampshire
Effective: 9/30/2014
Authority: New Hampshire Labor Commissioner
Bars employers from demanding login credentials for employees' or applicants' personal social media accounts, forcing them to add contacts, or lowering privacy settings, and from disciplining those who refuse. Employers may still set equipment-use policies, monitor their own systems and accounts, and investigate specific misconduct reports.
Utah Commercial Email Act
Utah Commercial Email ActJurisdiction: Utah
Effective: 5/3/2023
Authority: Utah Division of Consumer Protection
Prohibits commercial email that uses an unauthorized third-party domain, forged header information, or a misleading subject line. It is an anti-deception marketing law rather than a privacy-notice law.
Utah Consumer Privacy Act
UCPAJurisdiction: Utah
Effective: 12/31/2023
Authority: Utah Attorney General (exclusive enforcement, 13-61-402(1)); the Division of Consumer Protection receives complaints and refers matters (13-61-401)
Max Fine: Up to $7,500 per violation
Utah's comprehensive consumer privacy law gives Utah residents rights to confirm and access, delete data they provided, obtain a portable copy, correct inaccuracies (since July 1, 2026), and opt out of sale and targeted advertising. Sensitive data uses notice plus opt-out rather than opt-in consent, and there is no statutory appeal right. From January 1, 2027, Part 5 adds in-vehicle privacy duties for motor vehicle manufacturers.
Utah Digital Choice Act
Utah Digital Choice ActJurisdiction: Utah
Effective: 7/1/2026
Authority: Utah Division of Consumer Protection
Enacted by 2025 H.B. 418, it makes social media data portable (including the user's social graph) through the UCPA copy right and requires interoperability interfaces with user consent. 2026 H.B. 408 amendments take effect July 1, 2027, adding a five-business-day deadline and a public open-protocol disclosure.
Utah E-Commerce Integrity Act
Utah E-Commerce Integrity ActJurisdiction: Utah
Authority: Utah Attorney General; ISPs and affected owners may also sue
Prohibits phishing, pharming, and deceptive spyware that changes computer settings or collects information. Enforcement is by civil action from listed plaintiffs and the Attorney General.
Utah Minor Protection in Social Media Act
Utah MPSMAJurisdiction: Utah
Effective: 10/1/2024
Authority: Utah Division of Consumer Protection (enforcement preliminarily enjoined)
Replaced the repealed 2023 Social Media Regulation Act (13-63) with age assurance, maximum-privacy defaults for minors, supervisory tools, and parental consent rules. On September 10, 2024 the federal district court preliminarily enjoined enforcement of every part of 13-71-101 to 401 (NetChoice v. Reyes, D. Utah No. 2:23-cv-00911); the state's appeal (10th Cir. No. 24-4100) was argued November 20, 2025 and was pending as last verified.
Vehicle event data recorders
Veh. Code 9951Jurisdiction: California
Authority: Not specified in the section
Requires carmakers to disclose event data recorders in the owner's manual and bars anyone other than the registered owner from retrieving the recorded crash data (speed, direction, location history, braking, seatbelt use) without the owner's consent, a court order, or listed safety-research and repair uses.
Vermont Age-Appropriate Design Code Act
VT AADCJurisdiction: Vermont
Effective: 1/1/2027
Authority: Vermont Attorney General (rulemaking and enforcement under the Consumer Protection Act, 9 V.S.A. ch. 63)
Vermont's Kids Code requires online businesses likely to be used by minors to design their services so that the use of minors' data does not cause foreseeable emotional distress, compulsive use or discrimination. It sets most-protective default privacy settings for minors, limits data collection and personalised feeds, bans overnight push notifications, requires algorithm transparency and restricts reuse of age assurance data. The Attorney General's implementing rules on design practices and age assurance must be adopted by Jan. 1, 2027 and were out for public comment in September 2026.
Vermont Data Broker Law (including the Data Broker Security Breach Notice Act)
VT Data Broker LawJurisdiction: Vermont
Effective: 1/1/2019
Authority: Vermont Attorney General; Vermont Secretary of State maintains the registry
Vermont passed the first U.S. data broker registration law in 2018. Data brokers must register each year with the Secretary of State, run a written information security program, and may not sell data for fraud, stalking or discrimination. 2026 Act No. 138, effective Jan. 1, 2027, broadens the definitions, raises the fee to $900, requires a $20,000 bond and much more detailed disclosures, adds buyer verification duties, and creates a separate Data Broker Security Breach Notice Act.
Vermont Data Privacy and Online Surveillance Act
VDPOSAJurisdiction: Vermont
Effective: 1/1/2028
Authority: Vermont Attorney General (exclusive), under the Vermont Consumer Protection Act, 9 V.S.A. ch. 63
Vermont's comprehensive privacy law, signed June 16, 2026, gives Vermont consumers rights to access, correct, delete and port their personal data, opt out of targeted advertising, sales and certain profiling, and get a list of the third parties their data was sold to. Controllers must minimise collection, get consent before processing or selling sensitive data, honor opt-out preference signals and run data protection and profiling impact assessments. It adds consumer health data protections, including a ban on geofencing within 1,850 feet of health care facilities, that apply to businesses of any size. Sensitive data is defined broadly and includes consumer health, genetic, biometric, neural and precise geolocation data and government ID numbers (§ 2415a(b)(47)).
Vermont Electronic Communication Privacy Act
VECPAJurisdiction: Vermont
Effective: 10/1/2016
Authority: Courts (suppression and motions to quash)
Requires Vermont law enforcement to get a warrant, a recognised warrant exception, user consent or an emergency justification before compelling service providers to hand over protected user information, and to notify the targets. It bans real-time interception of communications content and cell-tower or GPS location except to find a fugitive under an arrest warrant. Service providers must produce warranted records within 30 days, or within 72 hours if the court orders it.
Vermont Fair Credit Reporting Act (including security freeze and medical debt provisions)
VT FCRAJurisdiction: Vermont
Authority: Vermont Attorney General; private plaintiffs
Vermont's credit reporting law goes beyond the federal FCRA by requiring a consumer's consent (or a court order) before anyone pulls their credit report. It gives consumers free disclosures, dispute rights and free security freezes, including freezes for protected consumers such as minors. Since July 1, 2025, credit reporting agencies may not report or keep medical debt in a consumer's file.
Vermont Financial Privacy Act
VT Financial PrivacyJurisdiction: Vermont
Effective: 1/1/2001
Authority: Commissioner of Financial Regulation
Vermont's financial privacy law generally bars financial institutions from disclosing a customer's financial information to anyone, subject to a list of exceptions such as customer authorization, legal process and routine business exchanges. It also regulates loan lead solicitations that use a financial institution's name or a consumer's loan details.
Vermont Telemarketing, Do-Not-Call and Robocall Law
VT Telemarketing LawJurisdiction: Vermont
Authority: Vermont Attorney General; Secretary of State (registration); private plaintiffs
Vermont requires telemarketers to register with the Secretary of State, makes federal Do-Not-Call violations a state-law violation, and requires solicitation calls to transmit caller ID. A 2022 law, effective 2023, mirrors the federal TCPA and Telemarketing Sales Rule limits on robocalls as Vermont law. Call recipients have a private right of action with statutory damages.
Video Consumer Privacy Act
Tenn. VCPAJurisdiction: Tennessee
Authority: Aggrieved consumers (private civil action)
Tennessee's state analogue to the federal Video Privacy Protection Act bars sellers and renters of prerecorded video and similar audiovisual materials from knowingly disclosing information that identifies a consumer as having requested or obtained specific video materials. Disclosure is allowed to the consumer, with informed written consent, for ordinary business operations, or for direct marketing after a clear opt-out opportunity, and records must be destroyed within a year after they are no longer needed.
Video Voyeurism and Unauthorized Dissemination of Intimate Images (including digitally created images)
RI Voyeurism / NCII LawJurisdiction: Rhode Island
Authority: Prosecutors
Criminalizes secretly capturing intimate images where a person expects privacy, peering into homes with imaging devices, and sharing sexually explicit or intimate images of an identifiable adult without consent when the sharer knows or recklessly disregards likely harm. A 2025 amendment extends the dissemination offense to images created by a digital device or altered by digitization, covering AI-generated intimate deepfakes, and adds sextortion and pay-to-remove offenses.
Video, Audio and Publication Rental Records Confidentiality (including library borrowing records)
RI Video and Library Records LawJurisdiction: Rhode Island
Authority: Prosecutors; injured persons via civil action
Makes it unlawful to reveal records linking a person's name and address to the titles or nature of videos, recordings or publications they bought, rented or borrowed from libraries, bookstores, video or music stores or other retailers. Such records must be kept confidential and released only on written waiver.
Videotape Rental and Sales Records
NH Video Records Privacy LawJurisdiction: New Hampshire
Effective: 6/18/1990
Authority: Not specified in the section
Makes records identifying who rented or bought videotapes confidential. Sellers and rental businesses may disclose them only for business operations, with the customer's (or a minor's parent's) consent, to police investigating unreturned tapes, under subpoena or court order, where a statute requires, or for debt collection and order fulfillment.
Videotape Rental and Sales Records Privacy
MN Video Privacy LawJurisdiction: Minnesota
Authority: Minnesota Attorney General under 8.31; consumers by civil action (325I.03)
Minnesota's video privacy law bars video rental and sales businesses from knowingly disclosing information identifying which video materials a customer requested or obtained, except to the customer, under subpoena, court order or warrant, in a transfer of the business, or with written informed consent given on a separate bold-type notice. Records must be destroyed within a year after they are no longer needed.
Violation of Privacy (criminal)
DE Violation of PrivacyJurisdiction: Delaware
Authority: Criminal prosecution by the State (Delaware Department of Justice)
Delaware's criminal privacy statute covers trespassing to eavesdrop, hidden recording devices in private places, intercepting or divulging private messages without the consent of all parties, voyeuristic recording, placing a location tracker on someone else's vehicle without the owner's consent, and distributing nude or sexual images, including AI deep fakes, without consent.
Violation of Privacy (surveillance and voyeurism offenses)
NH Violation of Privacy StatuteJurisdiction: New Hampshire
Authority: State and county prosecutors
Makes it a crime to install or use a device without consent to observe, photograph, record or transmit images or sounds in a private place (restrooms, locker rooms, homes), to capture a person's private body parts, or to capture from outside a private place images, sounds, location or movement not ordinarily perceptible outside. It also criminalizes sharing one's own sexual recordings without the other participant's consent. Investigative surveillance by employees acting on articulable suspicion is carved out.
Virginia Computer Crimes Act (privacy provisions: computer invasion of privacy, keystroke loggers, spam)
VA Computer Crimes ActJurisdiction: Virginia
Effective: 7/1/1984
Authority: Criminal prosecution; injured persons and email service providers by civil action (18.2-152.12)
Virginia's computer crime law makes it a crime to use a computer to examine another person's employment, salary, credit, financial, or identifying information without authority, to install keystroke-logging software on another's computer, and to forge routing information to send spam. Injured people can sue for damages.
Virginia Consumer Data Protection Act
VCDPAJurisdiction: Virginia
Effective: 1/1/2023
Authority: Virginia Attorney General (exclusive authority, 59.1-584(A))
Max Fine: Up to $7,500 per violation
Virginia's comprehensive consumer privacy law gives residents rights to access, correct, delete, and port their personal data and to opt out of targeted advertising, sale, and significant-decision profiling, with an appeal process. Controllers need opt-in consent for sensitive data, must run data protection assessments for higher-risk processing, and face extra limits on known children's data (2025) and a ban on selling precise geolocation data (from July 1, 2026). Section 59.1-577.1 on minors' social media time limits is listed as a separate entry because it is enjoined.
Virginia Consumer Protection Act, reproductive or sexual health information
VCPA reproductive healthJurisdiction: Virginia
Effective: 7/1/2025
Authority: Virginia Attorney General, attorneys for the Commonwealth, and local attorneys (59.1-203, 59.1-206); consumers via private action (59.1-204)
Makes it a prohibited practice under the Virginia Consumer Protection Act to obtain, disclose, sell, or disseminate personally identifiable reproductive or sexual health information without the consumer's consent. 'Consent' borrows the VCDPA's opt-in definition, and the protected information includes location data suggesting an attempt to obtain reproductive or sexual health services.
Virginia Telephone Privacy Protection Act
VTPPAJurisdiction: Virginia
Effective: 7/1/2001
Authority: Virginia Attorney General, Commonwealth's attorneys, and local attorneys (59.1-517); aggrieved persons (59.1-515)
Virginia's telemarketing law limits sales calls and texts to 8 a.m. to 9 p.m., requires callers to identify themselves and transmit caller ID, restricts abandoned calls, and bars solicitations to numbers on the National Do Not Call Registry or to people who asked not to be contacted. Since January 1, 2026, a reply of STOP or UNSUBSCRIBE to a sales text must be honored for at least 10 years.
Voter list dissemination and commercial-use ban
AL Voter List LawJurisdiction: Alabama
Authority: Alabama Secretary of State (list access); no enforcement mechanism specified in the section
Makes voter lists and 10 cycles of election history available electronically for a fee of up to $1,000 per list, but keeps Social Security numbers, driver license numbers, email addresses, telephone numbers, and other protected voter data confidential. Voters registering or updating from June 1, 2026 can opt in to share their phone number. Anyone who gets the data may not sell, publish, or use it for commercial purposes; election and campaign uses are allowed.
Voyeurism
VT Voyeurism LawJurisdiction: Vermont
Authority: State's Attorneys and Attorney General (criminal)
Criminalises secretly viewing or recording another person's intimate areas where they expect privacy, covert surveillance or recording of people inside a home, and recording people engaged in sexual conduct without consent. Sharing such recordings is a separate crime. Vermont has no general wiretap or eavesdropping statute, so this and the images law are its main recording-privacy crimes.
Voyeurism and Video Voyeurism
KY VoyeurismJurisdiction: Kentucky
Effective: 7/15/2002
Authority: Commonwealth's and county attorneys (criminal prosecution)
Makes it a crime to view, photograph, or film another person's sexual conduct, genitals, private undergarments, or female breast without consent in a place where the person reasonably expects privacy. Selling or distributing such images, including over the internet, is a felony.
Voyeurism, Public Voyeurism, and Remote Aerial Voyeurism
IN VoyeurismJurisdiction: Indiana
Authority: County prosecutors
Indiana criminalizes peeping into occupied homes and places where people undress, recording someone's private areas without consent, and using drones to capture images or audio of people at home in places not visible to the public. Since July 1, 2024, 'peep' includes using a concealed camera to capture an intimate image.
Wiretapping and Eavesdropping
NH Wiretap ActJurisdiction: New Hampshire
Effective: 8/31/1969
Authority: Attorney General and county attorneys (criminal); private civil actions
New Hampshire is an all-party consent state: it is a crime to intercept, record, disclose or use a telephone or in-person oral communication without the consent of every party, subject to narrow exceptions for carriers, emergency services and authorized law enforcement. The chapter also bans surreptitious interception devices, restricts cell site simulator tracking of phones without consent or a warrant, and sets the court-order process for government wiretaps.
Wiretapping, Electronic Surveillance and Interception of Communications; Stored Wire and Electronic Communications
DE Wiretap ActJurisdiction: Delaware
Effective: 7/23/1999
Authority: Criminal prosecution by the State (Attorney General); private civil actions by aggrieved persons (2409, 2427)
Delaware's wiretap law makes it a felony to intercept, disclose, or use wire, oral, or electronic communications, but allows interception by a party to the communication or with one party's prior consent unless done to commit a crime or tort. A separate subchapter bars unauthorized access to stored communications and limits when public communication and remote computing providers may disclose stored contents. Note that the separate violation-of-privacy statute, 11 Del. C. § 1335(a)(4), makes intercepting private messages without the consent of all parties a misdemeanor, so Delaware's recording-consent rule is often described as unsettled.
Workforce Drug and Alcohol Testing Act
MT Drug Testing ActJurisdiction: Montana
Effective: 10/1/1997
Authority: Not verified
Montana employers that drug or alcohol test must follow a written, pre-announced testing program with federal-standard collection, medical review officer certification, and employee rebuttal rights. Test results and related records are confidential.
Workplace Drug and Alcohol Testing
Nebraska Workplace Drug Testing LawJurisdiction: Nebraska
Authority: No administrative enforcer named; tampering offenses are prosecuted criminally
Nebraska does not require workplace drug testing, but employers that test must confirm positive screens with approved laboratory or breath-test methods before acting on them, preserve positive specimens, keep a chain of custody, and keep results confidential.
Workplace Drug Testing Law
VT Drug Testing LawJurisdiction: Vermont
Effective: 9/1/1987
Authority: Courts (private actions); State civil and criminal enforcement
Sharply limits workplace drug testing in Vermont. Applicants may be tested only after a conditional job offer and written notice. Employees may be tested only on probable cause and when a rehabilitation program is available, and random or company-wide testing is banned unless federal law requires it. Test results and related health information must be kept confidential.
Workplace Privacy Act
Nebraska Workplace Privacy ActJurisdiction: Nebraska
Effective: 7/21/2016
Authority: Courts (private civil action by employees and applicants)
This social media password law bars employers from demanding access to employees' or applicants' personal online accounts, making them log in in front of the employer, forcing them to add the employer as a contact or change privacy settings, or retaliating for refusals. Employers keep rights over their own devices, accounts, and networks and may investigate specific misconduct.