Privacy Regulation Database

A reference of privacy regulations tracked by the Fine Tracker. Regulations are grouped by jurisdiction type.

Supranational

Digital Markets Act

DMA
active

Jurisdiction: European Union

Effective: 5/2/2023

Authority: European Commission

Max Fine: Up to 10% of annual global turnover (20% for repeat offenders)

EU regulation targeting large online platforms designated as gatekeepers. Imposes obligations on core platform services.

gatekeepersinteroperabilitydata_portabilityself_preferencing
View Details →

Digital Services Act

DSA
active

Jurisdiction: European Union

Effective: 2/17/2024

Authority: Digital Services Coordinators + European Commission (for VLOPs)

Max Fine: Up to 6% of annual global turnover

EU regulation on digital services establishing transparency and accountability obligations for online platforms.

platform_liabilitycontent_moderationtransparencyadvertisingminors
View Details →

EU AI Act

AI Act
active

Jurisdiction: European Union

Effective: 8/1/2024

Authority: National AI supervisory authorities + European AI Office

Max Fine: Up to €35M or 7% of annual global turnover for prohibited AI

EU regulation on artificial intelligence. Risk-based framework with strict rules for high-risk AI systems and prohibitions on certain AI practices.

ai_systemshigh_risktransparencybiometricfacial_recognition
View Details →

EU ePrivacy Directive

ePrivacy
active

Jurisdiction: European Union

Effective: 7/12/2002

Authority: National Data Protection Authorities

Max Fine: Determined by member states

EU directive on privacy in electronic communications. Governs cookies, direct marketing, and confidentiality of communications. Often enforced alongside GDPR.

cookieselectronic_communicationsdirect_marketingtracking
View Details →

General Data Protection Regulation

GDPR
active

Jurisdiction: European Union

Effective: 5/25/2018

Authority: National Data Protection Authorities (DPAs)

Max Fine: Up to €20M or 4% of annual global turnover

EU-wide data protection law governing the processing of personal data of individuals in the EU/EEA. Sets strict requirements for consent, data subject rights, breach notification, and cross-border transfers.

Key Articles

Art. 5: Principles of processing

Art. 6: Lawful basis

Art. 7: Conditions for consent

Art. 9: Special categories

Art. 15: Right of access

Art. 17: Right to erasure

Art. 20: Data portability

Art. 25: Data protection by design

Art. 32: Security of processing

Art. 33: Breach notification to authority

Art. 35: Data protection impact assessment

Art. 83: Fines and penalties

Art. 12-14: Transparency and information

Art. 44-49: International transfers

consentdata_subject_rightsbreach_notificationcross_border_transferdpoprivacy_by_designchildren
View Details →

Federal

Act on the Protection of Personal Information

APPI
active

Jurisdiction: Japan

Effective: 5/30/2003

Authority: Personal Information Protection Commission (PPC)

Max Fine: Up to JPY 100M (~K) for corporations

Japan comprehensive data protection law. Amended in 2020 and 2022 with strengthened individual rights and cross-border transfer rules.

consentdata_subject_rightscross_border_transferanonymization
View Details →

Americans with Disabilities Act, Title I medical examination and inquiry confidentiality provisions

ADA medical confidentiality
active

Jurisdiction: United States

Effective: 7/26/1992

Authority: Equal Employment Opportunity Commission; private plaintiffs after an EEOC charge

The ADA limits when employers may ask disability-related questions or require medical exams: none before a job offer, post-offer exams if required of all entering employees, and job-related, business-necessary exams for current employees. Medical information obtained must be kept in separate, confidential medical files.

View Details →

Brazil General Data Protection Law

LGPD
active

Jurisdiction: Brazil

Effective: 9/18/2020

Authority: National Data Protection Authority (ANPD)

Max Fine: Up to 2% of revenue, capped at R$50M per violation

Brazil's comprehensive data protection law, modeled on GDPR.

consentdata_subject_rightsdpocross_border_transfer
View Details →

Cable Communications Policy Act (Cable Privacy)

CCPA-Cable
superseded

Jurisdiction: United States

Effective: 10/30/1984

Authority: FCC / Private right of action

Max Fine: Actual damages (minimum ,000) plus punitive damages

Protects cable TV subscriber privacy. Requires notice and consent before collecting or disclosing personally identifiable information about subscribers viewing habits.

cable_recordsviewing_habitssubscriber_dataconsent
View Details →

Cable Communications Policy Act of 1984, Section 631 (Protection of Subscriber Privacy)

Cable Act s.631
active

Jurisdiction: United States

Effective: 12/29/1984

Authority: Private civil actions; Federal Communications Commission

Section 631 requires cable operators to give subscribers an annual privacy notice, limits collection and disclosure of subscriber personal information without consent, gives subscribers access to their data, and requires destruction of data no longer needed.

View Details →

Children's Internet Protection Act

CIPA
active

Jurisdiction: United States

Effective: 4/20/2001

Authority: Federal Communications Commission (E-rate); Institute of Museum and Library Services (LSTA funds)

CIPA conditions E-rate and certain library funding on adopting an internet safety policy with technology protection measures that block obscene images, child sexual abuse material, and content harmful to minors. School policies must also address minors' online safety and the unauthorized disclosure of minors' personal information, and schools must educate students about appropriate online behavior.

View Details →

Children's Online Privacy Protection Act of 1998 and COPPA Rule

COPPA
active

Jurisdiction: United States

Effective: 4/21/2000

Authority: Federal Trade Commission; state attorneys general (parens patriae, 15 U.S.C. 6504)

Max Fine: Up to $50,120 per violation (adjusted for inflation)

COPPA requires notice to parents and verifiable parental consent before collecting personal information from children under 13 online. The FTC's COPPA Rule was substantially amended in 2025 (effective June 23, 2025, with most compliance required by April 22, 2026), adding separate consent for third-party disclosures, a written security program, a written retention policy, and biometric and government identifiers to the definition of personal information.

Key Articles

§312.2: Definitions

§312.3: Regulation of unfair/deceptive acts

§312.4: Notice requirements

§312.5: Parental consent

§312.6: Right to review

§312.7: Prohibition against conditioning

§312.8: Confidentiality and security

§312.10: Data retention and deletion

childrenconsentparental_consentdata_collectionthird_party_sharing
View Details →

China Personal Information Protection Law

PIPL
active

Jurisdiction: China

Effective: 11/1/2021

Authority: Cyberspace Administration of China (CAC)

Max Fine: Up to RMB 50M (~M) or 5% of annual revenue

China comprehensive personal information protection law. Strict cross-border transfer restrictions. Applies extraterritorially to processing of Chinese residents data.

consentdata_subject_rightscross_border_transferautomated_decision_makingfacial_recognition
View Details →

Communications Act Section 222 (Customer Proprietary Network Information) and CPNI Rules

CPNI
active

Jurisdiction: United States

Effective: 2/8/1996

Authority: Federal Communications Commission

Section 222 requires carriers to protect the confidentiality of customer proprietary network information, such as call details and location, and limits its use without customer approval. FCC rules require authentication before disclosing call detail records and breach reporting to the Secret Service and FBI. A broader 2024 FCC breach rule covering personally identifiable information was upheld by a Sixth Circuit panel in August 2025, but en banc rehearing was granted on July 31, 2026 and the amended 47 CFR 64.2011 is not yet in effect.

View Details →

Computer Fraud and Abuse Act

CFAA
active

Jurisdiction: United States

Effective: 10/12/1984

Authority: U.S. Department of Justice (criminal); private civil actions by persons suffering damage or loss

The CFAA is an anti-hacking law, included here because section 1030(a)(2) protects the confidentiality of information on computers, including financial records, consumer reports, and information on any protected computer. It is the main federal basis for prosecuting data theft and gives victims of unauthorized access a civil remedy.

View Details →

Confidentiality of Substance Use Disorder Patient Records

42 CFR Part 2
active

Jurisdiction: United States

Effective: 12/31/1970

Authority: HHS Office for Civil Rights (civil enforcement program began Feb. 16, 2026); DOJ for criminal violations

Part 2 makes records identifying a patient as having a substance use disorder diagnosis or treatment in a federally assisted program confidential, allowing disclosure mainly with patient consent or under narrow exceptions and court orders. The 2024 final rule (effective April 16, 2024; compliance Feb. 16, 2026) aligned Part 2 with HIPAA, allowing a single consent for treatment, payment, and operations and adding breach notification and HIPAA-style penalties.

View Details →

Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003

CAN-SPAM
active

Jurisdiction: United States

Effective: 1/1/2004

Authority: Federal Trade Commission (and other agencies by sector); state attorneys general; internet access service providers

Max Fine: Up to ,120 per email in violation

CAN-SPAM sets rules for commercial email rather than banning it. Senders must not use false headers or deceptive subject lines, must identify messages as ads, include a physical postal address, and offer a working opt-out honored within 10 business days. It preempts most state commercial email laws.

email_marketingopt_outcommercial_messagesdeceptive_headers
View Details →

Cyber Incident Reporting for Critical Infrastructure Act of 2022

CIRCIA
enacted_not_effective

Jurisdiction: United States

Authority: Cybersecurity and Infrastructure Security Agency (DHS)

CIRCIA will require covered critical infrastructure entities to report covered cyber incidents to CISA within 72 hours and ransom payments within 24 hours. The reporting duties take effect only on the dates set in CISA's final rule; as of September 2026 the final rule had not been published (CISA held further town halls in 2026 and targeted fall 2026).

View Details →

Digital Personal Data Protection Act

DPDPA-India
active

Jurisdiction: India

Effective: 8/11/2023

Authority: Data Protection Board of India

Max Fine: Up to INR 250 crore (~M)

India comprehensive data protection law. Enforcement beginning 2025. Applies to processing of digital personal data within India and outside India if processing is for offering goods/services to Indian data principals.

consentdata_subject_rightschildrencross_border_transfer
View Details →

Dodd-Frank Act Section 1033 and CFPB Personal Financial Data Rights Rule

Section 1033 Rule
enjoined

Jurisdiction: United States

Effective: 1/17/2025

Authority: Consumer Financial Protection Bureau

Section 1033 gives consumers a right to access their financial account data. The CFPB's 2024 rule would require providers to share data through interfaces and would limit third parties' collection, use, and retention of that data to what the consumer requested. Compliance dates (originally April 1, 2026 to April 1, 2030) are stayed, and the CFPB opened a reconsideration (ANPR, Aug. 22, 2025).

View Details →

DOJ Data Security Program: Preventing Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons

DOJ Bulk Data Rule
active

Jurisdiction: United States

Effective: 4/8/2025

Authority: U.S. Department of Justice, National Security Division

This regulation bars U.S. persons from data brokerage and genomic-data transactions that give countries of concern or covered persons access to bulk sensitive personal data or government-related data. Other vendor, employment, and investment transactions are allowed only if CISA security requirements are met. Bulk thresholds range from 100 persons (genomic data) to 100,000 persons (covered identifiers); due diligence, audit, and reporting duties began October 6, 2025.

View Details →

Driver's Privacy Protection Act of 1994

DPPA
active

Jurisdiction: United States

Effective: 9/13/1997

Authority: U.S. Department of Justice (criminal fines; civil penalties against states); private civil actions

Max Fine: ,500 per violation plus actual damages

The DPPA limits disclosure of personal information in state driver and vehicle records to listed permissible uses, such as law enforcement, insurance, and certain business verification, and requires express consent for uses like marketing. It binds private recipients and resellers, not just state agencies.

driver_recordsmotor_vehicle_recordspermissible_uses
View Details →

Electronic Communications Privacy Act

ECPA
superseded

Jurisdiction: United States

Effective: 10/21/1986

Authority: Department of Justice

Max Fine: Criminal fines and up to 5 years imprisonment

Extends government restrictions on wiretaps to include electronic data transmissions. Includes the Wiretap Act (Title I), Stored Communications Act (Title II), and Pen Register Act (Title III).

electronic_communicationswiretappingstored_communicationspen_registers
View Details →

Electronic Communications Privacy Act, Title I (Wiretap Act)

Wiretap Act
active

Jurisdiction: United States

Effective: 6/19/1968

Authority: U.S. Department of Justice (criminal); private civil actions

The Wiretap Act, as expanded by ECPA in 1986, makes it a crime to intentionally intercept the contents of wire, oral, or electronic communications in transit, or to use or disclose unlawfully intercepted contents. Federal law is one-party consent: a private party may record a communication it participates in, or where one party consents, unless done for a criminal or tortious purpose. Many states require all-party consent.

View Details →

Electronic Communications Privacy Act, Title II (Stored Communications Act)

SCA
active

Jurisdiction: United States

Effective: 1/19/1987

Authority: U.S. Department of Justice (criminal); private civil actions

The SCA protects email and other stored communications and records held by service providers. It bars unauthorized access to stored communications, restricts public providers from voluntarily disclosing customer content and records, and sets the legal process the government must use to compel disclosure (amended by the CLOUD Act in 2018).

View Details →

Electronic Communications Privacy Act, Title III (Pen Register and Trap and Trace Devices)

Pen Register Act
active

Jurisdiction: United States

Effective: 1/19/1987

Authority: U.S. Department of Justice

The Pen Register Act bars installing or using devices that capture non-content routing and addressing information (such as numbers dialed or email headers) without a court order, subject to provider exceptions. It is primarily a limit on government surveillance but also reaches private parties.

View Details →

Employee Polygraph Protection Act of 1988

EPPA
active

Jurisdiction: United States

Effective: 12/27/1988

Authority: U.S. Department of Labor, Wage and Hour Division; private plaintiffs

EPPA generally bars private employers from requiring, requesting, or using lie detector tests on employees or job applicants, or taking action based on results or refusal. A limited exception allows polygraphs during ongoing investigations of economic loss, with strict procedural protections and confidentiality of results.

View Details →

Fair and Accurate Credit Transactions Act of 2003 (identity theft, disposal, truncation, affiliate marketing provisions)

FACTA
active

Jurisdiction: United States

Effective: 12/4/2003

Authority: FTC, CFPB, and federal banking agencies (by entity type)

FACTA amended the FCRA to fight identity theft. It requires card receipt truncation, fraud alerts, written identity theft prevention programs for creditors (Red Flags Rule), secure disposal of consumer report information, and an opt-out before affiliates use shared data for marketing.

View Details →

Fair Credit Reporting Act

FCRA
active

Jurisdiction: United States

Effective: 4/25/1971

Authority: CFPB and FTC (plus banking agencies and state attorneys general)

Max Fine: Statutory damages up to ,000 per violation; actual damages; punitive damages

The FCRA governs the collection, accuracy, and use of consumer report information. It limits who may obtain reports and for what purposes, requires accuracy procedures and dispute handling, and gives consumers rights to their files, free credit freezes, and adverse action notices. The Homebuyers Privacy Protection Act (effective March 4, 2026) restricts mortgage 'trigger leads'; the CFPB's 2025 medical debt rule was vacated in July 2025.

credit_reportsconsumer_rightsaccuracypermissible_purpose
View Details →

Fair Debt Collection Practices Act, third-party communication limits (and Regulation F)

FDCPA
active

Jurisdiction: United States

Effective: 3/20/1978

Authority: CFPB and FTC; private plaintiffs

The FDCPA protects debtor privacy by barring collectors from discussing a debt with third parties such as employers, family members, or neighbors, except in narrow cases. Regulation F adds rules on electronic communications, including opt-out notices.

View Details →

Family Educational Rights and Privacy Act

FERPA
active

Jurisdiction: United States

Effective: 11/19/1974

Authority: U.S. Department of Education (Student Privacy Policy Office)

Max Fine: Loss of federal funding

FERPA gives parents, and students once they turn 18 or enter postsecondary school, the right to inspect and seek amendment of education records and generally requires written consent before personally identifiable information from those records is disclosed. It lists exceptions such as school officials with legitimate educational interests, directory information, and health or safety emergencies.

Key Articles

§99.3: Definitions

§99.10: Right to inspect records

§99.20: Right to amend records

§99.30: Consent for disclosure

§99.31: Disclosure exceptions

§99.33: Redisclosure limitations

educationstudent_recordsparental_consent
View Details →

Federal Trade Commission Act, Section 5 (unfair or deceptive acts or practices)

FTC Act
active

Jurisdiction: United States

Effective: 9/26/1914

Authority: Federal Trade Commission

Max Fine: No statutory maximum; consent orders with monetary penalties

Section 5 bans unfair or deceptive acts or practices in commerce. The FTC uses it as the main federal privacy and data security authority: misrepresenting data practices is deception, and failing to use reasonable security or making harmful data uses can be unfair. Several later privacy statutes (COPPA, PADFA, TAKE IT DOWN) are enforced as if they were FTC rules.

Key Articles

Section 5(a): Unfair or deceptive acts prohibited

Section 5(b): FTC enforcement proceedings

deceptive_practicesunfair_practicesdata_securityprivacy_promises
View Details →

FTC Health Breach Notification Rule

HBNR
active

Jurisdiction: United States

Effective: 9/24/2009

Authority: Federal Trade Commission

Max Fine: Up to $50,120 per violation per day

The HBNR requires vendors of personal health records and related entities outside HIPAA to notify individuals, the FTC, and sometimes the media after a breach of unsecured identifiable health information. The 2024 amendments (effective July 29, 2024) confirm the rule covers health apps and treat unauthorized disclosures, not just hacks, as breaches.

Key Articles

§318.1: Purpose and scope

§318.2: Definitions

§318.3: Breach notification requirement

§318.4: Timeliness

§318.5: Methods of notice

§318.6: Content of notice

health_databreach_notificationhealth_apps
View Details →

Genetic Information Nondiscrimination Act of 2008

GINA
active

Jurisdiction: United States

Effective: 5/22/2009

Authority: Equal Employment Opportunity Commission (Title II); Departments of Labor, HHS, and Treasury (Title I)

GINA bars health insurers and employers from using genetic information, including family medical history, to make coverage or employment decisions. Employers generally may not request, require, or buy genetic information, and must keep any they hold confidential in separate medical files.

View Details →

Gramm-Leach-Bliley Act, Title V (Privacy Rule, Safeguards Rule, and pretexting provisions)

GLBA
active

Jurisdiction: United States

Effective: 7/1/2001

Authority: CFPB, federal banking agencies, SEC, CFTC, NCUA, FTC (non-bank financial institutions), and state insurance regulators, by sector (15 U.S.C. 6805)

Max Fine: Up to ,000 per violation; criminal penalties up to ,000 and 5 years

GLBA requires financial institutions to give privacy notices, let consumers opt out of most sharing with nonaffiliated third parties, and protect customer information. The FTC's 2021 Safeguards Rule amendments require a detailed security program (qualified individual, encryption, MFA), and since May 13, 2024 require notice to the FTC of incidents involving 500 or more consumers. The SEC's 2024 Regulation S-P amendments require incident response programs and 30-day customer breach notice (compliance Dec. 3, 2025 for larger and June 3, 2026 for smaller entities).

Key Articles

§501: Protection of nonpublic personal information

§502: Obligations for financial institutions

§521: Privacy of consumer financial information

Title V: Privacy

financial_dataconsumer_noticesafeguardspretexting
View Details →

Health Information Technology for Economic and Clinical Health Act, Subtitle D (Privacy)

HITECH
active

Jurisdiction: United States

Effective: 2/17/2009

Authority: HHS Office for Civil Rights; state attorneys general; FTC for section 13407

HITECH's privacy subtitle created the federal breach notification duty for HIPAA covered entities and business associates, made business associates directly subject to HIPAA security and penalty provisions, and raised HIPAA penalties. A 2021 amendment requires HHS to consider an entity's recognized security practices when setting fines and audit outcomes.

View Details →

Health Insurance Portability and Accountability Act Administrative Simplification: Privacy, Security, and Breach Notification Rules

HIPAA
active

Jurisdiction: United States

Effective: 4/14/2003

Authority: HHS Office for Civil Rights; state attorneys general (42 U.S.C. 1320d-5(d)); DOJ for criminal violations

Max Fine: Up to $1.5M per violation category per year; criminal penalties up to $250K and 10 years

The Privacy Rule limits how covered entities and business associates use and disclose protected health information and gives individuals rights of access, amendment, and accounting. The Security Rule requires administrative, physical, and technical safeguards for electronic PHI, and the Breach Notification Rule requires notice of breaches of unsecured PHI. A 2024 reproductive health amendment was vacated nationwide in June 2025 except most Notice of Privacy Practices changes, which had a February 16, 2026 compliance date.

Key Articles

Privacy Rule: Use and disclosure of PHI

Security Rule: Administrative, physical, technical safeguards

Enforcement Rule: Compliance and penalties

Breach Notification Rule: Notification requirements for breaches

health_dataphibreach_notificationbusiness_associatesminimum_necessary
View Details →

Homebuyers Privacy Protection Act

HPPA
active

Jurisdiction: United States

Effective: 3/4/2026

Authority: CFPB and FTC (through FCRA enforcement), plus FCRA private actions

This 2025 law limits 'trigger leads', which are credit reports sold to other lenders when a consumer applies for a mortgage. From March 4, 2026, an agency may pass on such a report only for a firm offer of credit or insurance to a party that has the consumer's documented consent or already originates, services, or holds an account relationship with the consumer.

View Details →

Personal Data Protection Act

PDPA-Singapore
active

Jurisdiction: Singapore

Effective: 10/15/2012

Authority: Personal Data Protection Commission (PDPC)

Max Fine: Up to SGD 1M (~K) or 10% of annual turnover

Singapore comprehensive data protection law with Do Not Call Registry.

consentdo_not_calldata_breach_notificationdata_portability
View Details →

Personal Data Protection Law

PDPL
active

Jurisdiction: Saudi Arabia

Effective: 9/14/2023

Authority: Saudi Data & AI Authority (SDAIA)

Max Fine: Up to SAR 5M (~.3M)

Saudi Arabia comprehensive data protection law, heavily influenced by GDPR.

consentdata_subject_rightscross_border_transfersensitive_data
View Details →

Personal Information Protection and Electronic Documents Act

PIPEDA
active

Jurisdiction: Canada

Effective: 4/13/2000

Authority: Office of the Privacy Commissioner of Canada

Max Fine: Up to CAD ,000 per violation

Canada federal private-sector privacy law. Based on 10 fair information principles. Being replaced by Consumer Privacy Protection Act (CPPA).

consentdata_subject_rightsaccountabilitycross_border_transfer
View Details →

Privacy Act 1988

Australian Privacy Act
active

Jurisdiction: Australia

Effective: 12/14/1988

Authority: Office of the Australian Information Commissioner (OAIC)

Max Fine: Up to AUD 50M or 30% of turnover

Australia comprehensive privacy law. 13 Australian Privacy Principles (APPs). Major reform package pending with significantly increased penalties.

australian_privacy_principlesbreach_notificationcredit_reportinghealth_records
View Details →

Privacy Act 2020

NZ Privacy Act
active

Jurisdiction: New Zealand

Effective: 12/1/2020

Authority: Office of the Privacy Commissioner

Max Fine: Up to NZD ,000 per offense

New Zealand comprehensive privacy law replacing the 1993 Privacy Act. 13 information privacy principles.

information_privacy_principlesbreach_notificationcross_border_transfer
View Details →

Privacy Act of 1974

Privacy Act
active

Jurisdiction: United States

Effective: 9/27/1975

Authority: Federal courts (civil actions); OMB guidance; DOJ for criminal misdemeanors

The Privacy Act governs how federal agencies collect, maintain, use, and disclose records about individuals kept in systems of records. It requires consent for most disclosures, public notice of record systems, access and amendment rights, and accuracy and security safeguards. A 2024 amendment (Pub. L. 118-104) added a disclosure exception for the Congressional Budget Office.

View Details →

Privacy Rights of Satellite Subscribers

Satellite privacy s.338(i)
active

Jurisdiction: United States

Effective: 11/29/1999

Authority: Private civil actions; Federal Communications Commission

Added by the Satellite Home Viewer Improvement Act of 1999, this provision gives satellite TV subscribers privacy protections that mirror the Cable Act: annual notice, consent for collection and disclosure, access, and destruction of unneeded data.

View Details →

Protecting Americans' Data from Foreign Adversaries Act of 2024

PADFA
active

Jurisdiction: United States

Effective: 6/23/2024

Authority: Federal Trade Commission

PADFA makes it unlawful for data brokers to sell, license, transfer, or otherwise make available personally identifiable sensitive data of U.S. individuals to a foreign adversary country (currently China, Iran, North Korea, Russia) or an entity controlled by one. It took effect 60 days after enactment on April 24, 2024.

View Details →

Protection of Personal Information Act

POPIA
active

Jurisdiction: South Africa

Effective: 7/1/2020

Authority: Information Regulator

Max Fine: Up to ZAR 10M (~K) or imprisonment up to 10 years

South Africa comprehensive data protection law modeled on GDPR.

consentdata_subject_rightscross_border_transferdirect_marketing
View Details →

Protection of Pupil Rights Amendment

PPRA
active

Jurisdiction: United States

Effective: 8/21/1974

Authority: U.S. Department of Education (Student Privacy Policy Office)

PPRA limits surveys, analyses, and evaluations that ask students about eight protected areas, such as political beliefs, mental health, sexual behavior, and family income. It also requires local policies and parent notice on surveys, physical exams, and the collection or use of student information for marketing.

View Details →

Right to Financial Privacy Act of 1978

RFPA
active

Jurisdiction: United States

Effective: 3/10/1979

Authority: Courts (private civil actions); federal agencies' own compliance

The RFPA limits federal government access to individuals' financial records held by financial institutions. Agencies generally need customer authorization, a subpoena, a search warrant, or a formal written request with notice to the customer, and institutions may not release records until the agency certifies compliance.

View Details →

South Korea Personal Information Protection Act

PIPA
active

Jurisdiction: South Korea

Effective: 9/30/2011

Authority: Personal Information Protection Commission (PIPC)

Max Fine: Up to 3% of related revenue

South Korea comprehensive data protection law. One of the strictest in Asia with significant penalties.

consentdata_subject_rightscross_border_transferpseudonymization
View Details →

Telemarketing and Consumer Fraud and Abuse Prevention Act and Telemarketing Sales Rule (National Do Not Call Registry)

TSR
active

Jurisdiction: United States

Effective: 8/16/1994

Authority: Federal Trade Commission; state attorneys general (15 U.S.C. 6103); private persons with over $50,000 in damages (15 U.S.C. 6104)

The TSR bars deceptive and abusive telemarketing and houses the FTC's National Do Not Call Registry. It restricts calls to registered numbers, sets calling hours, limits abandoned calls and robocalls, and requires sellers to pay for registry access.

View Details →

Telephone Consumer Protection Act of 1991

TCPA
active

Jurisdiction: United States

Effective: 12/20/1992

Authority: Federal Communications Commission; state attorneys general; private plaintiffs

Max Fine: -,500 per violation

The TCPA restricts autodialed and prerecorded-voice calls and texts to cell phones without prior express consent, prerecorded calls to residential lines, and unsolicited faxes, and underpins the National Do-Not-Call Registry rules. FCC rules effective April 11, 2025 require honoring consent revocations by any reasonable means within 10 business days; the 'revoke-all' portion was delayed to January 31, 2027. The FCC's 2023 'one-to-one consent' rule was vacated by the Eleventh Circuit and removed in August 2025.

telemarketingrobocallstext_messagesdo_not_callconsent
View Details →

Telephone Records and Privacy Protection Act of 2006

TRPPA
active

Jurisdiction: United States

Effective: 1/12/2007

Authority: U.S. Department of Justice

This law makes 'pretexting' for phone records a federal crime. It bars obtaining confidential phone records by false statements or unauthorized account access, and selling or buying such records without the customer's authorization.

View Details →

Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act (TAKE IT DOWN Act)

TAKE IT DOWN Act
active

Jurisdiction: United States

Effective: 5/19/2025

Authority: Federal Trade Commission (platform duties, including over nonprofits); U.S. Department of Justice (criminal provisions)

The TAKE IT DOWN Act criminalizes knowingly publishing nonconsensual intimate images, including AI-generated 'digital forgeries', and requires covered platforms to run a notice-and-removal process. Since May 19, 2026, platforms must remove a validly reported image within 48 hours and make reasonable efforts to remove known identical copies.

View Details →

UK Data Protection Act 2018

UK DPA
active

Jurisdiction: United Kingdom

Effective: 5/25/2018

Authority: Information Commissioner's Office (ICO)

Max Fine: Up to £17.5M or 4% of annual global turnover

UK implementation of GDPR (post-Brexit: UK GDPR). Supplemented by Data Protection Act 2018.

consentdata_subject_rightsbreach_notificationchildren
View Details →

Video Privacy Protection Act of 1988

VPPA
active

Jurisdiction: United States

Effective: 11/5/1988

Authority: Private civil actions

Max Fine: Actual damages (minimum ,500) plus punitive damages and attorney fees

The VPPA bars video tape service providers from knowingly disclosing personally identifiable information about the videos a consumer requested or obtained, with limited exceptions. The 2013 amendment allows consent to be given electronically and in advance for up to two years. It is now a frequent basis for class actions over tracking pixels on video pages.

video_recordsrental_recordsstreaming_dataconsent
View Details →

Video Voyeurism Prevention Act of 2004

VVPA
active

Jurisdiction: United States

Effective: 12/23/2004

Authority: U.S. Department of Justice

This criminal law bars intentionally capturing images of a person's private areas without consent where the person has a reasonable expectation of privacy. It applies only within federal maritime and territorial jurisdiction; state laws cover most other places.

View Details →

State & Provincial

Access to personnel files and records

Colorado personnel file access
active

Jurisdiction: Colorado

Effective: 1/1/2017

Authority: Not specified in the portion reviewed

Colorado private-sector employees may inspect and copy their own personnel file at least once a year on request, and former employees may inspect once after separation. Employers may require supervision and charge reasonable copying costs.

View Details →

Age Attestation on Computing Devices

SB 26-051
enacted_not_effective

Jurisdiction: Colorado

Effective: 7/1/2028

Authority: Colorado Attorney General

SB 26-051 requires device operating systems with app stores to ask for a user's birth date or age bracket at account setup and send an age signal to apps through an API, starting July 1, 2028. Apps must request the signal and are then treated as knowing the user's age range. It includes data-minimization limits: the age signal may not be shared with third parties for other purposes.

View Details →

Age verification and liability for publishing material harmful to minors (2024 SB 1959)

OK Age Verification Law
active

Jurisdiction: Oklahoma

Effective: 11/1/2024

Authority: Private civil actions by minors (through parents or guardians) and adults; Oklahoma Attorney General (injunctive relief and compliance guidance)

Makes commercial pornography websites liable to minors, through their parents, unless they use reasonable age verification (a digitized state ID, a third-party verification database, or transactional data). Sites must also offer Internet and cellular subscribers a free option to block the site on their subscriptions. Verifiers may not retain identifying information once access is granted.

View Details →

Age Verification for Adult Oriented Websites

IN Adult Website Age Verification
active

Jurisdiction: Indiana

Effective: 7/1/2024

Authority: Indiana Attorney General; parents or guardians; any person (injunction); individuals whose data is retained

Enacted as SEA 17 (2024), this chapter requires adult websites to verify that visitors are 18 or older using a mobile credential, an independent third-party verification service, or transactional data. Operators and their verification vendors may not keep users' identifying information and must secure it. Verification data counts as 'personal information' under the breach law. A preliminary injunction was vacated after Free Speech Coalition v. Paxton (2025), and the law is enforceable.

View Details →

Age verification for adult websites; consent to publish private images (Act 2024-97)

AL Adult Website Age Verification
active

Jurisdiction: Alabama

Effective: 10/1/2024

Authority: Alabama Attorney General (Consumer Interest Division); private plaintiffs

Requires adult websites to use a reasonable age-verification method so that minors cannot access sexual material harmful to minors, and bars the site or its verification vendor from keeping users' identifying information after access is granted. It also requires notarized written consent from every person depicted before an adult website publishes a private image, mandated health warnings, and (from September 1, 2025) a 10% gross receipts tax on adult websites.

View Details →

Age Verification for Internet Sites Containing Content Pornographic for Minors (2026 HF 864)

Iowa Age Verification Law
active

Jurisdiction: Iowa

Effective: 7/1/2026

Authority: Iowa Attorney General (with rulemaking authority)

Iowa's 2026 age verification law requires adult websites and apps with a substantial portion of content pornographic for minors to use reasonable age verification, such as digital ID, commercially reasonable transactional data, or an Attorney General-approved method. It also limits the privacy impact: verifiers may not retain, sell, or share identifying information and must secure the data.

View Details →

Age verification for material harmful to minors

Utah Age Verification Act
active

Jurisdiction: Utah

Authority: Utah Division of Consumer Protection; private actions

Requires age verification for access to material harmful to minors and bars keeping the identifying information used. 2026 S.B. 73 added VPN-circumvention rules, an excise tax, and Division rulemaking on age-verification data privacy, security, and disposal.

View Details →

Age Verification for Material Harmful to Minors

MT Age Verification Act
active

Jurisdiction: Montana

Effective: 1/1/2024

Authority: Private individuals only (30-14-159(6), as amended by SB 488 (2025))

Adult websites with a substantial share of material harmful to minors must use reasonable age verification (digitized ID, government ID, or transactional-data checks) before granting access. The verifier may not keep identifying information after access is granted. SB 488 (Ch. 199, L. 2025) made the law privately enforceable only, and a federal challenge (Free Speech Coalition v. Knudsen) was dismissed on August 6, 2025.

View Details →

Age Verification for Online Access to Materials Harmful to Minors; Anonymous Age Verification

Florida Age Verification Law
active

Jurisdiction: Florida

Effective: 1/1/2025

Authority: Florida Department of Legal Affairs (Attorney General)

Enacted in HB 3 (2024), this law requires adult sites to verify that visitors are 18 or older, and to offer both an anonymous and a standard verification method. It also limits what third-party anonymous age verifiers can do with the identifying information they receive: no retention after verification, no other use, no sharing, and reasonable security.

View Details →

Age Verification for Online Matter Harmful to Minors

KY Adult Site Age Verification
active

Jurisdiction: Kentucky

Effective: 7/15/2024

Authority: Private civil actions only; the Commonwealth, the Attorney General, prosecutors, and state officers are barred from enforcing

Requires commercial adult websites to verify that users are at least 18 using government ID or commercially reasonable transactional-data methods, and lets injured persons or parents sue for failures. To protect user privacy, platforms and verification vendors may not keep identifying information after access is granted. Enforcement is exclusively private; state officials may not enforce it.

View Details →

Age verification for websites distributing material harmful to minors (civil liability and Attorney General enforcement)

LA Adult Website Age Verification
active

Jurisdiction: Louisiana

Effective: 1/1/2023

Authority: Private plaintiffs (R.S. 9:2800.29); Louisiana Attorney General (R.S. 51:2121)

Requires commercial pornography websites to use reasonable age verification, such as Louisiana's digitized ID (LA Wallet) or a commercial system using government ID or transactional data, before granting access. Neither the site nor its verification vendor may retain the user's identifying information after access is granted. The 2022 law created a private damages remedy; a 2023 law added Attorney General enforcement with daily civil penalties.

View Details →

Age Verification for Websites with Sexual Material Harmful to Minors (H.B. 1181)

Texas HB 1181
active

Jurisdiction: Texas

Effective: 9/1/2023

Authority: Texas Attorney General

Requires covered adult websites to verify that users are 18 or older using digital identification or a commercial age verification system, and bars retaining identifying information from verification. The U.S. Supreme Court upheld the age-verification requirement in Free Speech Coalition v. Paxton (June 27, 2025); the Fifth Circuit's 2024 affirmance of the injunction against the mandatory health warnings (129B.004) was not disturbed.

View Details →

Age-Appropriate Online Design Code Act

Nebraska AADC
active

Jurisdiction: Nebraska

Effective: 1/1/2026

Authority: Nebraska Attorney General (violations are also deceptive trade practices under the Uniform Deceptive Trade Practices Act)

Enacted by LB504 (2025) and expanded by LB838 (2026), this law requires large online services to give known minors protective, high-privacy defaults and tools to limit contact, engagement-driving design features, recommendations, purchases, time spent, and geolocation sharing. It restricts data collection, profiling, targeted advertising, and overnight and school-hour notifications for minors, and requires parental tools for children under 13.

View Details →

Agent Billy Clardy III Act (state wiretap law)

Clardy Act
active

Jurisdiction: Alabama

Effective: 2/1/2023

Authority: Circuit courts (intercept orders); Attorney General and district attorneys (criminal penalties); aggrieved individuals (civil suits)

Alabama's state wiretap statute lets the Attorney General seek court orders to intercept wire and electronic communications in felony drug investigations and bars anyone other than ALEA from owning interception devices. It creates a civil cause of action against any person who unlawfully intercepts, discloses, or uses a communication, with exceptions for carrier operations and for a party to the communication or one who has a party's prior consent (unless the purpose is criminal, tortious, or injurious). A 2025 amendment made the program permanent and broadened who can be sued.

View Details →

Agricultural Data Privacy Act

Nebraska Agricultural Data Privacy Act
active

Jurisdiction: Nebraska

Effective: 7/18/2026

Authority: Nebraska Attorney General (exclusive; actions in Lancaster County district court)

Enacted as sections 1-11 of LB525 (2026), this law declares farmers the owners of agricultural data from their farms, land, devices, and equipment. Ag-tech companies get only a nonexclusive right to use the data to provide authorized services and may not sell it without the producer's separate express written consent. It also requires reasonable data security and, from 2027, a no-sale clause in new contracts.

View Details →

AI and algorithms in health plan utilization review (SB 1120, 'Physicians Make Decisions Act')

SB 1120
active

Jurisdiction: California

Effective: 1/1/2025

Authority: Department of Managed Health Care; Department of Insurance

Requires health plans and insurers that use AI or algorithms in utilization review to base decisions on the individual patient's clinical information rather than group data alone, to apply them fairly, and to leave medical-necessity denials to licensed clinicians.

View Details →

AI Chatbot Solicitation of Children (HB 143, 2025)

NH AI Chatbot Child Safety Law
active

Jurisdiction: New Hampshire

Effective: 1/1/2026

Authority: New Hampshire Attorney General (sole right of civil action); criminal prosecution under RSA 639:3

Makes owners and operators of dedicated generative AI chat services liable when they knowingly direct communications to a child intended to encourage the child to imminently engage in sexually explicit conduct, producing sexual images, illegal drug or alcohol use, self-harm or suicide, or violence. The Attorney General enforces the civil provision after giving 90 days to cure, and the same conduct is a form of the crime of endangering the welfare of a child.

View Details →

AIDS Prevention Act: Confidentiality of HIV Test Records

MT HIV Confidentiality
active

Jurisdiction: Montana

Effective: 10/1/1989

Authority: Montana Department of Public Health and Human Services (civil); county attorneys (criminal); private plaintiffs

Montana bars disclosing the identity of a person tested for HIV or their results in an identifiable way, except as allowed under the Uniform Health Care Information Act and related law. People harmed can sue for statutory damages.

View Details →

AIDS/HIV Records Confidentiality

NJ HIV Confidentiality Law
active

Jurisdiction: New Jersey

Authority: Private civil action by the aggrieved person; Commissioner of Health rules

Records identifying someone with, or suspected of having, HIV or AIDS are confidential in New Jersey no matter who holds them. They may be disclosed only with the person's prior written informed consent or under narrow exceptions for IRB-reviewed research, audits, treating personnel, required public health reporting, and other legally authorized purposes.

View Details →

Alabama Data Breach Notification Act of 2018

ADBNA
active

Jurisdiction: Alabama

Effective: 6/1/2018

Authority: Alabama Attorney General (exclusive)

Requires covered entities to protect sensitive personally identifying information with reasonable security measures, investigate suspected breaches, and notify affected Alabama residents within 45 days when a breach is reasonably likely to cause substantial harm. Larger breaches also require notice to the Attorney General and the national consumer reporting agencies, and records must be disposed of securely.

View Details →

Alabama Do-Not-Call law (telephone solicitation objection database)

AL Do-Not-Call
active

Jurisdiction: Alabama

Authority: Alabama Public Service Commission; private plaintiffs

Bars telephone solicitations to Alabama residential subscribers who have registered their objection on the state do-not-call list maintained by the Public Service Commission, which incorporates Alabama numbers from the national registry. Solicitors must identify themselves and may not block caller ID.

View Details →

Alabama Genetic Data Privacy Act

AGDPA
active

Jurisdiction: Alabama

Effective: 10/1/2024

Authority: Alabama Attorney General (Consumer Interest Division)

Regulates direct-to-consumer genetic testing companies. They must post plain-language privacy notices and get express consent for initial collection and use, for each transfer to third parties, for secondary uses, and for genetic-data-based marketing, plus informed consent for research. Consumers can access their data, delete their accounts, and have samples destroyed.

View Details →

Alabama Personal Data Protection Act

APDPA
enacted_not_effective

Jurisdiction: Alabama

Effective: 5/1/2027

Authority: Alabama Attorney General

Alabama's comprehensive consumer privacy law gives Alabama residents rights to confirm, access, correct, delete, and port their personal data and to opt out of targeted advertising, sale, and profiling for solely automated significant decisions. Controllers must minimize data, secure it, get consent before processing sensitive data, publish a privacy notice, and may not sell or use for targeted advertising the data of known 13- to 15-year-olds without consent. It takes effect May 1, 2027 and has a lower applicability threshold (25,000 consumers) than most state privacy laws, offset by a broad small-business exemption.

View Details →

Alabama Telemarketing Act

ATA
active

Jurisdiction: Alabama

Authority: Consumer Division of the Alabama Attorney General's Office; district attorneys; private plaintiffs

Requires commercial telephone sellers and their salespeople to be licensed by the Attorney General's Consumer Division before soliciting Alabama purchasers, and imposes disclosure and cancellation rules on telemarketing sales. It is mainly an anti-fraud telemarketing law; the related do-not-call rules are in chapter 8-19C.

View Details →

All Party Notification for In-Person Conversation (wearable eyeglass recording devices)

LA Smart Glasses Recording Law
active

Jurisdiction: Louisiana

Effective: 8/1/2026

Authority: Private civil actions

Requires anyone using smart glasses to video and record or transcribe a direct in-person conversation to specifically notify all participants first. The law responds to covert smart-glasses filming posted to social media, and exempts public meetings, law enforcement and first responders, recordings of officials and police in public, evidence preservation, and recordings made in the recorder's own home, workplace, or vehicle. It does not change the one-party consent rule of the Electronic Surveillance Act. It became law without the Governor's signature.

View Details →

Allen Toussaint Legacy Act (right of publicity and digital replicas)

LA Allen Toussaint Legacy Act
active

Jurisdiction: Louisiana

Effective: 8/1/2022

Authority: Private civil actions

Creates a heritable, transferable property right in each person's identity for commercial purposes, and makes it a violation to use someone's identity commercially in Louisiana without consent. It also bars using a realistic digital replica of a professional performer to create the impression that the performer is actually playing a fictional role. News, commentary, parody, expressive works, and other listed uses are exempt.

View Details →

Altered Sexual Depictions; Brooke's Law (platform notice-and-removal)

Florida Altered Sexual Depictions Law (Brooke's Law)
active

Jurisdiction: Florida

Effective: 10/1/2022

Authority: State attorneys (criminal); Florida Department of Legal Affairs and FDUTPA enforcers (platform duties); private plaintiffs

Florida's deepfake sexual-imagery law, created in 2022 (SB 1798). It criminalizes generating, soliciting, or maliciously promoting realistic altered sexual images of real people without consent and gives victims a civil claim. Brooke's Law (HB 1161, 2025) added a platform duty: by December 31, 2025, covered platforms had to set up a process to take down such images within 48 hours of a valid request.

View Details →

An Act Banning TikTok in Montana (SB 419, 2023)

MT TikTok Ban (SB 419)
expired

Jurisdiction: Montana

Authority: Montana Department of Justice (Attorney General)

SB 419 would have barred TikTok from operating in Montana from January 1, 2024, citing user-data privacy and national-security concerns about Chinese control. A federal court preliminarily enjoined it on November 30, 2023, before it took effect. Its own section 4 voids the Act if TikTok is sold to a company not incorporated in a foreign-adversary country; the parties agreed that happened with the 2025-2026 TikTok divestiture, and the case was dismissed on February 23, 2026, with the Ninth Circuit appeal closed by mandate on September 23, 2026.

View Details →

Anti-Caller ID Spoofing Act

OK Caller ID Spoofing Act
active

Jurisdiction: Oklahoma

Effective: 11/1/2007

Authority: District attorneys (misdemeanor); Attorney General under the Consumer Protection Act

Makes it a misdemeanor to knowingly insert false information into caller ID with intent to mislead, defraud, or deceive a call recipient. The Legislature cited loss of personal information to spoofing scams.

View Details →

Anti-Phishing Act

OK Anti-Phishing Act
active

Jurisdiction: Oklahoma

Effective: 11/1/2006

Authority: Civil actions by adversely affected Internet access providers and web page or trademark owners; Attorney General under the Consumer Protection Act

Prohibits creating a web page or domain name that impersonates a legitimate online business and using it to induce people to provide identifying information such as SSNs, biometric data, or account numbers. Internet access providers and affected brand owners may sue.

View Details →

Anti-Phishing Act of 2006

Tenn. Anti-Phishing Act
active

Jurisdiction: Tennessee

Effective: 7/1/2006

Authority: Tennessee Attorney General and Reporter or district attorneys general; internet access providers, web page owners, trademark owners, and injured individuals

Outlaws phishing: impersonating another person or business through the internet, e-mail, or wireless communications to get Tennessee residents to hand over identifying information, fraudulently obtaining such information, and mimicking or hijacking websites and e-mail traffic to defraud. It gives strong civil remedies to service providers, site and trademark owners, and victims.

View Details →

App Store Accountability Act

Texas App Store Accountability Act
active

Jurisdiction: Texas

Effective: 1/1/2026

Authority: Texas Attorney General (deceptive trade practice under Bus. & Com. Code ch. 17 subch. E)

Requires app stores to verify each Texas account holder's age category, link minors' accounts to a verified parent account, and obtain parental consent for minors' downloads and purchases, and requires developers to assign age ratings and use the app store's age signals. A federal district court preliminarily enjoined it on December 23, 2025, but the Fifth Circuit stayed that injunction and the U.S. Supreme Court declined to vacate the stay in July 2026, so the law is enforceable while litigation continues.

View Details →

App Store Accountability Act

Utah ASAA
enacted_not_effective

Jurisdiction: Utah

Effective: 5/6/2027

Authority: None; private action by a harmed minor or parent only (public enforcement removed by 2026 H.B. 498)

Enacted by 2025 S.B. 142 and amended by 2026 H.B. 498, it requires app stores to verify age category, affiliate minor accounts with a parent, and obtain parental consent for downloads and purchases, with a parental consent disclosure about the app's data practices. The chapter is enacted but its duties begin May 6, 2027. Industry challenges (CCIA v. Brown, M.M. v. Brown, D. Utah) were terminated on April 21, 2026.

View Details →

App Store Age Verification and Parental Consent Law (commonly called the Alabama App Store Accountability Act)

AL App Store Act
enacted_not_effective

Jurisdiction: Alabama

Effective: 1/1/2027

Authority: Alabama Attorney General (exclusive jurisdiction under the Deceptive Trade Practices Act)

Requires app stores to request and verify the age category (under 13, 13-15, 16-17, 18+) of Alabama account holders, link minors' accounts to a parent account, and obtain verifiable parental consent before a minor downloads or buys an app or makes in-app purchases. Developers must check age category and consent status through the app store and may use that data only for age-related protections and legal compliance. Age verification data must be minimized and encrypted.

View Details →

Artificial Intelligence Applications Relating to Mental Health

Utah Mental Health Chatbot Act
active

Jurisdiction: Utah

Effective: 5/7/2025

Authority: Utah Division of Consumer Protection

Enacted by 2025 H.B. 452, it requires mental health chatbots to disclose they are AI, bars selling or sharing users' health information and inputs, and limits advertising based on user input. A separate affirmative defense against unlicensed-practice claims is available to suppliers that file a written policy with the Division (58-60-118).

View Details →

Artificial Intelligence Companion Models

RI AI Companion Act
enacted_not_effective

Jurisdiction: Rhode Island

Effective: 1/1/2027

Authority: Rhode Island Attorney General

Beginning January 1, 2027, companion chatbots offered in Rhode Island must include protocols to respond to users who express suicidal ideation, self-harm or intent to harm others, including referral to crisis services, and must remind users at the start of a conversation and at least every three hours that they are not talking to a human. Operators must file annual safety-protocol reports with the Attorney General starting July 1, 2027.

View Details →

Artificial intelligence companion safeguards

SB 1546 (2026)
enacted_not_effective

Jurisdiction: Oregon

Effective: 1/1/2027

Authority: Private enforcement by injured individuals

Regulates AI companion chatbots designed to simulate ongoing personal or romantic relationships. Operators must disclose that output is artificial where a user could be misled, run a suicide and self-harm protocol with crisis referrals, and apply extra protections for users they know or have reason to believe are minors, with annual public reporting.

View Details →

Artificial Intelligence Consumer Protection (generative AI disclosures)

Utah GenAI Disclosure Act
active

Jurisdiction: Utah

Effective: 5/7/2025

Authority: Utah Division of Consumer Protection

Replaced the 2024 AI disclosure rule (former 13-2-12) with a duty to tell consumers they are dealing with generative AI when they clearly ask, and a duty for licensed professionals to disclose AI use up front in high-risk interactions. Using generative AI is no defense to a consumer-protection violation.

View Details →

Artificial intelligence disclosures in political calls and electioneering communications

LA AI Political Communications Disclosure
active

Jurisdiction: Louisiana

Effective: 8/1/2026

Authority: Louisiana Supervisory Committee on Campaign Finance Disclosure / state election enforcement (not confirmed)

Two 2026 laws require disclosure when artificial intelligence is used in Louisiana political messaging. Political calls that use an AI-generated voice of a public figure must say at the start that AI created them, and electioneering communications that use AI to falsely depict a candidate's or recall target's speech or conduct must carry a clear AI disclosure in the statutory format.

View Details →

Artificial intelligence mental health professional representation ban

Tenn. AI Mental Health Representation Law
active

Jurisdiction: Tennessee

Effective: 7/1/2026

Authority: Tennessee Attorney General and private plaintiffs under the Tennessee Consumer Protection Act

Bars developers and deployers of AI systems from advertising or representing to the public that the system is, or can act as, a qualified mental health professional. Violations are added to the Tennessee Consumer Protection Act's list of unfair or deceptive practices.

View Details →

Artificial Intelligence Policy Act (Office of Artificial Intelligence Policy and Learning Laboratory)

Utah AI Policy Act
active

Jurisdiction: Utah

Effective: 5/1/2024

Authority: Office of Artificial Intelligence Policy

Created by 2024 S.B. 149 and restructured by 2026 H.B. 320, it sets up the Office of AI Policy, its learning laboratory, and regulatory mitigation agreements. It imposes no general private-sector notice duties. The chapter is repealed July 1, 2027.

View Details →

Automated Calling Equipment Restrictions

KY Autodialer Law
active

Jurisdiction: Kentucky

Effective: 7/14/1992

Authority: Kentucky Attorney General (Consumer Protection Act remedies)

Restricts recorded-message robocalls used for polls, information gathering, or advertising. Unless an exemption applies (for example, existing customers, debt collection, school absence calls, or return calls), the called person must consent, the message must identify the caller and a staffed number, and calls must avoid random or sequential dialing, unlisted numbers, emergency facilities, and late hours.

View Details →

Automated Decision-Making Technology in Consequential Decisions

Colorado ADMT Act (SB 26-189)
enacted_not_effective

Jurisdiction: Colorado

Effective: 1/1/2027

Authority: Colorado Attorney General (exclusive for the disclosure and consumer-rights duties; 6-1-1706)

SB 26-189, signed May 14, 2026, repeals and replaces the 2024 Colorado AI Act starting January 1, 2027. It drops the duty of care, risk-management programs, and impact assessments and instead requires developer documentation, deployer notice at the point of interaction, a plain-language explanation after an adverse outcome, and consumer rights to correct inaccurate personal data and get meaningful human review. The Attorney General must adopt rules by January 1, 2027.

View Details →

Automated dialing systems with prerecorded messages

Colorado autodialer law
active

Jurisdiction: Colorado

Effective: 7/1/1979

Authority: District attorneys (criminal prosecution)

Colorado bans prerecorded autodialed sales calls unless the caller has an existing business relationship with the person called and that person consents to hear the message.

View Details →

Automated License Plate Reader Restrictions

KY ALPR Law
active

Jurisdiction: Kentucky

Effective: 7/15/2026

Authority: Prosecutors (criminal penalty); Transportation Cabinet (permit process for highway rights-of-way)

Makes it unlawful for anyone, public or private, to use automated license plate readers except for listed purposes such as parking regulation, access control to secured areas, public safety and auto theft, law enforcement, tolling, and commercial vehicle enforcement. Captured data (plate, location, time, photos, vehicle details) generally must be deleted after 90 days and may not be sold or shared except to law enforcement, under subpoena, or to insurers and lenders for specified purposes, with notice to new insurance and loan applicants starting in 2027.

View Details →

Automated license plate recognition systems (private operators)

ALPR law
active

Jurisdiction: California

Effective: 1/1/2016

Authority: Private plaintiffs

Requires operators of license plate reader systems to secure the data and adopt a public usage and privacy policy covering authorized uses, access, sharing, accuracy, and retention.

View Details →

Automated-decision systems in employment (Civil Rights Council FEHA regulations)

FEHA ADS Regulations
active

Jurisdiction: California

Effective: 10/1/2025

Authority: California Civil Rights Department

Regulations approved June 27, 2025 and effective October 1, 2025 that confirm using an automated-decision system (including AI) in hiring, promotion, or other employment decisions can violate California's anti-discrimination law if it harms people based on protected traits. They require keeping automated-decision data with other employment records for four years and treat some AI assessments as unlawful medical inquiries.

View Details →

Automatic dialing and announcing devices (robocalls and robotexts); caller ID spoofing

Oregon ADAD Law
active

Jurisdiction: Oregon

Authority: Oregon Attorney General (ORS 646A.376); private enforcement of ORS 646A.374 violations under ORS 646.638

Regulates automated calls and texts that play prerecorded or synthesized messages: they must disconnect promptly, offer a one-digit opt-out, and avoid emergency and health numbers, opted-out subscribers, and (for random or sequential dialing) do-not-call listed numbers. Callers may not misrepresent their identity or purpose or spoof caller ID.

View Details →

Automatic Dialing-Announcing Devices

VA ADAD law
active

Jurisdiction: Virginia

Effective: 7/1/2009

Authority: Virginia Attorney General and local attorneys under the VCPA; consumers via VCPA private action (59.1-518.4)

Restricts robocalls: callers may use automatic dialing-announcing devices for commercial solicitations only in listed circumstances, and prerecorded-message devices must disconnect within five seconds after the called party hangs up.

View Details →

Automatic Dialing-Announcing Devices (autodialer and prerecorded message restrictions)

IN Autodialer Law
active

Jurisdiction: Indiana

Authority: Indiana Attorney General; county prosecutors; private petitioners (injunction)

Indiana bars robocalls using prerecorded or synthesized voice messages unless the subscriber consented or a live operator gets consent first. Exceptions cover school messages, existing relationships, and employee scheduling. The chapter also sets calling hours, disclosure and disconnect rules, and a ban on robocalls to hospitals and emergency services.

View Details →

Automatic dialing-announcing devices (robocalls)

ADAD law
active

Jurisdiction: California

Authority: California Public Utilities Commission

Regulates prerecorded-message autodialers. Operators must follow CPUC rules, may not place ADAD calls to California phones between 9 p.m. and 9 a.m., and (under 2874) generally need a live operator to introduce the call and obtain consent before the recorded message plays.

View Details →

Automatic Dialing-Announcing Devices Act

Nebraska ADAD Act
active

Jurisdiction: Nebraska

Authority: Nebraska Public Service Commission

This law regulates robocalls and junk faxes in Nebraska. Sellers must obtain a Public Service Commission permit for each autodialer used for solicitations, may not robocall emergency lines, hospital rooms, cell phones, or pagers, must identify themselves, respect calling hours, and keep an internal do-not-call list.

View Details →

Automatic Dialing-Announcing Devices and Telephone Solicitation Hours

MN ADAD Law
active

Jurisdiction: Minnesota

Authority: Minnesota Attorney General; private actions for damages via 8.31 (325E.31)

Bars robocalls using prerecorded or synthesized voice messages unless the subscriber consented or a live operator first obtains consent, requires live operators to identify the caller and the call's purpose, and requires devices to disconnect within ten seconds after the subscriber hangs up. It also bans commercial telephone solicitations and robocalls before 9 a.m. or after 9 p.m. Minnesota's separate state do-not-call list statute (325E.311 to 325E.316) has expired.

View Details →

Automatic License Plate Reader Privacy Act

Nebraska ALPR Privacy Act
active

Jurisdiction: Nebraska

Effective: 7/19/2018

Authority: Courts (civil damages; evidentiary exclusion); Nebraska Commission on Law Enforcement and Criminal Justice receives annual reports

This law limits government use of automatic license plate readers to listed purposes such as traffic enforcement, stolen vehicles, warrants, missing persons, parking, secured-area access, tolling, and weigh stations. It caps retention at 180 days absent evidentiary need, requires posted use and privacy policies and annual reports, and keeps captured plate data out of public records.

View Details →

Automatic license plate recognition systems (law enforcement use and vendor duties)

VA ALPR law
active

Jurisdiction: Virginia

Effective: 7/1/2025

Authority: Criminal prosecution for misuse; Department of General Services approval of systems

Limits police use of automatic license plate readers to criminal investigations with reasonable suspicion and missing or endangered person cases, requires system data to be purged after 21 days and audit trails after two years, and bars selling or sharing the data with private or out-of-state databases. Vendors must certify they will not sell or share Virginia ALPR data and must notify the agency of third-party data requests; contract terms under subsection C apply from July 1, 2026.

View Details →

Ban on using school board public records for solicitation; redaction of payment data in public contract records

AL School Records Solicitation Ban
active

Jurisdiction: Alabama

Effective: 4/16/2026

Authority: Alabama Attorney General

Prohibits knowingly selling, giving, or receiving lists of names and addresses from local school board public records for commercial solicitation, and lets custodians demand a written no-solicitation certification from requesters. It also requires redaction of account and similar payment information that could initiate a financial transaction from public records about public contracts.

View Details →

Bolstering Online Transparency (bot disclosure) law (SB 1001)

SB 1001 Bot Disclosure
active

Jurisdiction: California

Effective: 7/1/2019

Authority: California Attorney General and local prosecutors (Unfair Competition Law)

Makes it unlawful to use an automated online account (a bot) to mislead people in California about its artificial identity to sell goods or services or influence a vote, unless the bot clearly discloses that it is a bot.

View Details →

Breach of medical information notification

VA medical breach notification
active

Jurisdiction: Virginia

Authority: No express enforcement provision; notices go to the Attorney General and the Commissioner of Health

Requires publicly funded entities that own or license computerized medical or health insurance information of Virginia residents to notify the Attorney General, the Commissioner of Health, and affected residents without unreasonable delay after a breach. HIPAA-regulated entities and those under the FTC Health Breach Notification Rule are excluded.

View Details →

Breach of personal information notification

VA breach notification
active

Jurisdiction: Virginia

Effective: 7/1/2008

Authority: Virginia Attorney General; primary state regulator for state-chartered or licensed financial institutions (18.2-186.6(I)-(J))

Requires anyone who owns or licenses computerized personal information of Virginia residents to notify the Attorney General and affected residents without unreasonable delay after a breach that causes or is reasonably believed to cause identity theft or other fraud. Personal information is name plus SSN, driver's license or state ID, financial account or card number with access code, passport number, or military ID number, when unencrypted and unredacted.

View Details →

Breach of Security Involving Computerized Personal Information (data breach notification)

CT Breach Notification
active

Jurisdiction: Connecticut

Effective: 1/1/2006

Authority: Connecticut Attorney General (Conn. Gen. Stat. 36a-701b(j))

Requires anyone holding computerized personal information of Connecticut residents to notify affected residents and the Attorney General of a breach of unencrypted data within 60 days of discovery. Where Social Security or taxpayer ID numbers are exposed, the data owner must offer at least two years of free identity theft prevention services.

View Details →

California Age-Appropriate Design Code Act (AB 2273, 2022)

CAADCA
enjoined

Jurisdiction: California

Effective: 7/1/2024

Authority: California Attorney General

Required online services likely to be used by children to assess risks to children, default to high privacy, estimate users' ages, and avoid harmful data uses, profiling, precise geolocation collection, and dark patterns. It has never been fully enforceable: NetChoice v. Bonta produced preliminary injunctions in 2023 and 2025, and on March 12, 2026 the Ninth Circuit (No. 25-2366) narrowed the injunction, leaving the impact-assessment duties, the data-use restrictions, and the dark-patterns ban enjoined while vacating the injunction as to coverage and age estimation and remanding. AB 2246 (2026) repeals and replaces this title effective January 1, 2027.

View Details →

California AI Transparency Act (SB 942, as amended by AB 853)

AI Transparency Act
active

Jurisdiction: California

Effective: 8/2/2026

Authority: California Attorney General, city attorneys, and county counsel

Requires large generative AI providers to embed hidden (latent) provenance disclosures in AI-generated images, video, and audio, offer users a visible disclosure option, and provide a free public AI detection tool that does not collect users' personal information. The law became operative August 2, 2026 after AB 853 delayed it and extended provenance duties to large platforms and device makers.

View Details →

California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (Proposition 24)

CCPA/CPRA
active

Jurisdiction: California

Effective: 1/1/2020

Authority: California Privacy Protection Agency (administrative enforcement; now styled CalPrivacy) and California Attorney General (civil actions)

Max Fine: Up to $7,500 per intentional violation; $2,500 per unintentional

California's comprehensive consumer privacy law. It gives California residents rights to know, delete, correct, opt out of the sale or sharing of their personal information, and limit the use of sensitive personal information, and it bars retaliation for exercising those rights. Proposition 24 (the CPRA, approved November 3, 2020) amended the law, created the California Privacy Protection Agency, and made most changes operative January 1, 2023.

Key Articles

§1798.100: Right to know

§1798.105: Right to delete

§1798.110: Right to disclosure

§1798.115: Right to opt-out of sale

§1798.120: Right to opt-out

§1798.125: Non-discrimination

§1798.130: Notice and request procedures

§1798.135: Do Not Sell link

§1798.140: Definitions

§1798.155: Administrative fines

consumer_rightsright_to_knowright_to_deleteopt_out_saledata_brokerssensitive_data
View Details →

California Consumer Privacy Act Regulations (including 2025 Cybersecurity Audit, Risk Assessment, and Automated Decisionmaking Technology rules)

CCPA Regulations
active

Jurisdiction: California

Effective: 8/14/2020

Authority: California Privacy Protection Agency; California Attorney General

Regulations adopted first by the Attorney General (2020) and then by the California Privacy Protection Agency (2023, 2025) that spell out how businesses give notices, handle consumer requests, honor opt-out preference signals, and avoid dark patterns. The package approved by the Office of Administrative Law on September 22, 2025 (effective January 1, 2026) added mandatory cybersecurity audits, privacy risk assessments submitted to the Agency, and rights to pre-use notice, opt-out, and access for automated decisionmaking technology used for significant decisions.

View Details →

California Financial Information Privacy Act

CalFIPA
active

Jurisdiction: California

Effective: 7/1/2004

Authority: California Attorney General, Department of Financial Protection and Innovation, Department of Insurance

California's stricter counterpart to the federal Gramm-Leach-Bliley Act. Financial institutions need a consumer's explicit opt-in consent before sharing nonpublic personal information with nonaffiliated third parties, and must give consumers a chance to opt out of certain affiliate and joint-marketing sharing.

View Details →

California Invasion of Privacy Act

CA CIPA
active

Jurisdiction: California

Effective: 1/1/1967

Authority: District attorneys and the Attorney General (criminal); private plaintiffs (civil)

California's wiretap and eavesdropping law. It makes it a crime, and a basis for a private suit, to tap or read communications in transit without all parties' consent, to record or eavesdrop on confidential communications without all parties' consent, to use pen registers or trap-and-trace devices without a court order, and to use electronic tracking devices to follow a person. Plaintiffs have used these provisions in large numbers of suits over website tracking tools.

View Details →

California Online Privacy Protection Act

CalOPPA
active

Jurisdiction: California

Effective: 7/1/2004

Authority: California Attorney General and local prosecutors (through the Unfair Competition Law)

The first U.S. state law requiring commercial websites and online services to post a privacy policy. The policy must describe what personally identifiable information is collected, who it is shared with, and, since 2014, how the site responds to browser Do Not Track signals and whether third parties track users across sites.

View Details →

Caller Identification Spoofing

IN Caller ID Spoofing
active

Jurisdiction: Indiana

Effective: 7/1/2013

Authority: Indiana Attorney General

Indiana prohibits knowingly transmitting misleading or inaccurate caller ID information with intent to defraud, cause harm, or wrongfully obtain anything of value. Blocking caller ID and authorized law enforcement and intelligence activity are exempt.

View Details →

Candidate Election Deepfake Disclosures

Colorado election deepfakes (HB 24-1147)
active

Jurisdiction: Colorado

Effective: 7/1/2024

Authority: Colorado Secretary of State (Fair Campaign Practices Act complaints); candidates (civil action)

HB 24-1147 bars distributing AI deepfakes of candidates close to an election unless the communication carries a clear disclosure that the media was edited and depicts false speech or conduct. The disclosure must also be embedded in metadata where feasible.

View Details →

Capture or Use of Biometric Identifier Act

CUBI
active

Jurisdiction: Texas

Effective: 4/1/2009

Authority: Texas Attorney General

Requires notice and consent before capturing biometric identifiers for a commercial purpose, limits their sale or disclosure, and requires secure storage and timely destruction. H.B. 149 (2025) clarified that a publicly available image alone does not supply consent unless the individual posted it, and added AI-related exemptions.

View Details →

Child Digital Protection Act

MT Child Digital Protection Act
active

Jurisdiction: Montana

Effective: 10/1/2025

Authority: Private enforcement by the affected individual (no agency named)

Montana's 'kidfluencer' law requires parents who earn money from videos featuring their children to set aside a share of gross earnings in trust for the child and keep records. When the child turns 18, they can ask the platform that paid for the videos to permanently delete them, a statutory 'right to be forgotten'.

View Details →

Child Protection Registry

Utah CPR
active

Jurisdiction: Utah

Authority: Utah Attorney General (Internet Crimes Against Children unit)

Lets parents and schools register children's email addresses and other contact points; senders of adult-product or harmful-to-minors marketing must scrub their lists against the registry.

View Details →

Civil Action for Interception of Communication

Texas Civil Wiretap Remedy
active

Jurisdiction: Texas

Effective: 9/1/1985

Authority: Private civil action by a party to the communication

Gives a party to a communication a civil claim against anyone who intercepts it without any party's consent or who uses or divulges intercepted information. Consent of one party takes the acquisition outside the definition of interception.

View Details →

Clean Credit and Identity Theft Prevention Act (security freezes)

DE Security Freeze Law
active

Jurisdiction: Delaware

Effective: 9/28/2006

Authority: Affected consumers (private action); identity-theft police reports taken by local police (2204)

Lets Delaware consumers freeze their credit reports so new credit cannot be opened without their PIN or password, with deadlines for credit bureaus to place, lift, and remove freezes. A 2013 amendment lets parents and guardians freeze or create a record for children under 16 and protected adults, and the chapter guarantees identity-theft victims a local police report.

View Details →

Colorado Artificial Intelligence Act (Consumer Protections for Artificial Intelligence)

Colorado AI Act (SB 24-205)
enjoined

Jurisdiction: Colorado

Effective: 6/30/2026

Authority: Colorado Attorney General (exclusive; 6-1-1706)

Enacted in 2024 as the first comprehensive U.S. state law on algorithmic discrimination, it requires developers and deployers of high-risk AI systems to use reasonable care against algorithmic discrimination, with risk-management programs, impact assessments, consumer notices, correction and appeal rights, and disclosure when consumers interact with AI. The 2025 special session (SB 25B-004) moved its start date from February 1, 2026 to June 30, 2026. SB 26-189 repeals and reenacts Part 17 with a narrower automated decision-making framework effective January 1, 2027, so these duties are in force only for the interim. Enforcement is also on hold: in X.AI LLC v. Weiser (D. Colo. No. 1:26-cv-01515), a court order entered April 27, 2026 on the parties' stipulation bars the Attorney General from starting enforcement, including investigations, of SB 24-205 or legislation replacing it for conduct through 14 days after the court rules on xAI's forthcoming preliminary injunction motion.

View Details →

Colorado Consumer Credit Reporting Act

Colorado CCRA
active

Jurisdiction: Colorado

Effective: 8/9/2017

Authority: Consumers through private actions; Colorado Attorney General (Uniform Consumer Credit Code administrator)

Colorado's credit reporting law (recodified in 2017 from earlier law) limits when consumer reports may be furnished, restricts reporting of old or sensitive items, and gives consumers free disclosure, dispute, identity-theft block, and security freeze rights, including freezes for protected minors. Since 2023 agencies may not report adverse medical debt information (HB 23-1126), a provision set to repeal July 1, 2028.

View Details →

Colorado data breach notification law (Notification of security breach)

Colorado breach notification
active

Jurisdiction: Colorado

Effective: 9/1/2006

Authority: Colorado Attorney General (6-1-716(4))

Colorado requires businesses to investigate a possible breach promptly and notify affected Colorado residents within 30 days after determining that a breach occurred, unless misuse is not reasonably likely. The Attorney General must be notified within 30 days if 500 or more residents are affected, and national consumer reporting agencies if more than 1,000. Personal information includes name plus SSN, ID numbers, medical or health insurance information, or biometric data, and online credentials.

View Details →

Colorado No-Call List Act

Colorado No-Call List Act
active

Jurisdiction: Colorado

Effective: 8/8/2001

Authority: Colorado Attorney General and district attorneys; the list is administered by the Public Utilities Commission (6-1-905(1))

Colorado maintains its own do-not-call list. Telemarketers must register, scrub against the list at least quarterly, not call listed numbers, and not block caller ID.

View Details →

Colorado Privacy Act

CPA
active

Jurisdiction: Colorado

Effective: 7/1/2023

Authority: Colorado Attorney General and district attorneys (exclusive; 6-1-1311(1)(a))

Max Fine: Up to $20,000 per violation

Colorado's comprehensive consumer privacy law gives residents rights to opt out of targeted advertising, sale, and significant-decision profiling, and to access, correct, delete, and port their personal data, with an appeal process. Controllers must give a privacy notice, minimize and secure data, get opt-in consent for sensitive data, honor universal opt-out signals, and run data protection assessments. Amendments added biological and neural data (2024), biometric rules (2025), minors' online protections (2025), and precise geolocation as sensitive data with consent required to sell sensitive data (2025).

consumer_rightsopt_outuniversal_opt_out
View Details →

Colorado Privacy Act biological and neural data amendment (Protect Privacy of Biological Data)

CPA neural data (HB 24-1058)
active

Jurisdiction: Colorado

Effective: 8/7/2024

Authority: Colorado Attorney General and district attorneys

HB 24-1058 made Colorado the first state to add neural data to its privacy law. It defines biological data (including neural data) and treats it as sensitive data, so controllers need opt-in consent and a data protection assessment to process it.

View Details →

Colorado Privacy Act biometric amendments (Privacy of Biometric Identifiers and Data)

CPA biometric (HB 24-1130)
active

Jurisdiction: Colorado

Effective: 7/1/2025

Authority: Colorado Attorney General and district attorneys

HB 24-1130 added biometric-specific duties to the Colorado Privacy Act, reaching any controller that handles biometric identifiers regardless of size and covering employees. Controllers need a public written retention and deletion policy, advance notice, consent, and may not sell biometric identifiers. Employers may require consent only for listed purposes such as secure access, timekeeping, and safety.

View Details →

Colorado Privacy Act minors' online protections (Privacy Protections for Children's Online Data)

CPA minors (SB 24-041)
active

Jurisdiction: Colorado

Effective: 10/1/2025

Authority: Colorado Attorney General and district attorneys

SB 24-041 added a minors' duty of care to the Colorado Privacy Act for online services known to be used by anyone under 18. Without the minor's consent (or a parent's for children under 13), controllers may not use minors' data for targeted ads, sale, or significant profiling, use engagement-extending design features, or collect precise geolocation beyond what is needed. Heightened-risk services need a minors' data protection assessment.

View Details →

Colorado Privacy Act Rules

CPA Rules
active

Jurisdiction: Colorado

Effective: 7/1/2023

Authority: Colorado Attorney General (Department of Law, Consumer Protection Section)

The Attorney General's rules implementing the Colorado Privacy Act. They set detailed requirements for privacy notices, rights requests, universal opt-out mechanisms, valid consent and dark patterns, data protection assessments, profiling, and opinion letters. Amendments effective January 30, 2025 added biometric and opinion-letter rules, and amendments effective December 1, 2025 implemented the minors' (SB 24-041) and precise geolocation (SB 25-276) changes.

View Details →

Colorado telemarketing law (commercial telephone sellers)

Colorado telemarketing registration
active

Jurisdiction: Colorado

Effective: 7/1/1993

Authority: Colorado Attorney General and district attorneys

Commercial telephone sellers must register annually with the Attorney General and must honor a three-business-day cancellation right with refunds. Misleading prize and 'free' claims are prohibited.

View Details →

Colorado wiretapping and eavesdropping laws

Colorado wiretap/eavesdropping
active

Jurisdiction: Colorado

Effective: 7/1/1971

Authority: District attorneys (criminal prosecution)

Colorado is a one-party consent state. Recording or intercepting a phone or electronic communication is a crime unless the sender or a receiver consents, and recording an in-person conversation by someone not visibly present requires consent of at least one principal party. Using or disclosing unlawfully obtained contents is also prohibited.

View Details →

Commercial and fraudulent electronic mail laws

OK Anti-Spam Law
active

Jurisdiction: Oklahoma

Effective: 7/1/1999

Authority: Private civil actions by injured persons and email service providers; district attorneys (criminal); Attorney General under the Consumer Protection Act

Prohibits falsified routing information, misleading subject lines, and phishing-style fraudulent email, and requires unsolicited commercial email to be labeled 'ADV:' ('ADV-ADULT:' for sexually explicit content) and to offer a free opt-out that senders must honor. Violations are felonies and give recipients and email providers a damages claim.

View Details →

Commercial email advertisements (anti-spam) and unsolicited text message ads

Anti-spam (17529.5, 17538.41)
active

Jurisdiction: California

Authority: California Attorney General; email service providers; recipients

Bars commercial email advertising that uses a third party's domain without permission, falsified or forged headers, or misleading subject lines, and lets recipients, email providers, and the AG sue. A separate provision bars unsolicited text message advertisements to California mobile numbers except with consent or a business relationship. Much of the broader state spam law is preempted by the federal CAN-SPAM Act, but these deception-based rules remain.

View Details →

Commercial Use of Booking Photographs Prohibited

KY Mugshot Removal-Fee Ban
active

Jurisdiction: Kentucky

Effective: 7/15/2016

Authority: Persons depicted, via civil action in Circuit Court

Bars publishers and websites from using booking or inmate photographs obtained from public agencies for a commercial purpose when removal requires paying a fee. A person who asked for removal can sue for an injunction, fees, and escalating daily damages.

View Details →

Common ownership communities: sensitive information as a condition of access to recreational common areas

MD COC Sensitive Information Law
active

Jurisdiction: Maryland

Effective: 10/1/2025

Authority: Not specified in the section reviewed

Enacted by 2025 Md. Laws ch. 523 (HB 755), this law bars condominiums and other common ownership communities from requiring owners, occupants, guests, or children to hand over sensitive information, such as Social Security numbers, birth certificates, citizenship or immigration status, race or national origin, religion, or medical records, to use pools, playgrounds, game rooms, or similar recreational areas. Government photo ID may still be requested.

View Details →

Communicable Disease: Confidentiality Requirements

IN Communicable Disease Confidentiality
active

Jurisdiction: Indiana

Authority: Criminal prosecution (county prosecutors)

This chapter keeps medical and epidemiological information about reportable communicable diseases, including HIV, confidential. It may be released only in de-identified statistical form, with written consent, for public health or specified legal purposes, or to a nonprofit health data service during a declared public health response.

View Details →

Companion chatbots (SB 243)

SB 243
active

Jurisdiction: California

Effective: 1/1/2026

Authority: Private plaintiffs; Office of Suicide Prevention receives reports

Requires companion chatbot operators to tell users when they might think they are talking to a human that the bot is AI, to keep and publish suicide and self-harm prevention protocols, and to report crisis referrals annually starting July 1, 2027. For users known to be minors it required AI disclosures, three-hour break reminders, and sexual-content safeguards; SB 1119 (2026) moves minors' protections into a new chapter operative July 1, 2027. SB 867 (2026) separately bans toys with companion chatbots until 2031.

View Details →

Companion Chatbots: Children's Safety ('Adam's Law', SB 1119)

SB 1119
enacted_not_effective

Jurisdiction: California

Effective: 1/1/2027

Authority: California Attorney General and public prosecutors; children (or parents) who suffer actual harm

Signed September 10, 2026. Beginning July 1, 2027, companion chatbot operators must determine users' ages through the Digital Age Assurance Act (or treat everyone as a child), run and document child-safety risk assessments before release, set protective defaults, and undergo independent child-safety audits. It bars behavioral advertising to children, selling children's chatbot data, and using it beyond what is needed.

View Details →

Compensation History Inquiry Ban

DE Salary History Ban
active

Jurisdiction: Delaware

Effective: 12/14/2017

Authority: Delaware Department of Labor (709B(g))

Bars employers from asking job applicants or their former employers about pay history or screening applicants by past compensation. Employers may discuss pay expectations and may confirm history only after an offer with compensation terms has been accepted.

View Details →

Comprehensive Computer Data Access and Fraud Act

CDAFA (Penal Code 502)
active

Jurisdiction: California

Authority: Prosecutors (criminal); owners or lessees of computers or data (civil)

California's computer crime law. It makes it a crime to knowingly access and, without permission, take, copy, use, alter, or delete data or use computer services, and gives owners of the affected computers or data a civil claim for damage or loss.

View Details →

Computer Crime (computer trespass, spam header forgery, cyberstalking and online impersonation)

RI Computer Crime Act
active

Jurisdiction: Rhode Island

Authority: Prosecutors; injured persons and email service providers via civil action

Rhode Island's computer crime law covers unauthorized access and copying of computer data, forging email headers to send bulk spam, cyberstalking and cyberharassment, and online impersonation using another person's name, persona or identifying information (including biometric data) to harm, defraud, intimidate or threaten. Injured people, including email service providers, can sue for damages.

View Details →

Computer Crimes: Misuse of Computer System Information (private personal data)

DE Computer Data Misuse
active

Jurisdiction: Delaware

Authority: Criminal prosecution by the State; civil actions by aggrieved persons (941)

Criminalizes unauthorized display, use, disclosure, or copying of data obtained by accessing a computer system, and receiving or using such data. A civil remedy lets victims sue, and for misuse of private personal data (data about a person that a reasonable person would want kept private) actual damages can be recovered without proving financial loss.

View Details →

Computer Crimes: Unrequested Commercial Email and Failure to Cease Email on Request

DE Commercial Email Law
active

Jurisdiction: Delaware

Effective: 7/2/1999

Authority: Criminal prosecution by the State; civil actions by aggrieved persons in the Court of Chancery or for damages (941)

Delaware makes it a computer crime to send unsolicited bulk commercial email without authorization, to forge email header information to send spam, or to keep sending commercial email after the recipient asks the sender to stop. All commercial email sent to Delaware addresses must explain how to unsubscribe. Note that the federal CAN-SPAM Act (15 U.S.C. § 7707(b)) preempts state commercial email rules except those targeting falsity or deception.

View Details →

Computer Security Breach Notification

MT Breach Notification
active

Jurisdiction: Montana

Effective: 10/1/2005

Authority: Montana Department of Justice, Office of Consumer Protection (Attorney General)

Montana requires businesses to notify Montana residents without unreasonable delay when unencrypted personal information is reasonably believed to have been acquired in a breach that causes or is reasonably believed to cause loss or injury. Copies of resident notices must be sent at the same time to the Attorney General's Office of Consumer Protection.

View Details →

Computer Security Breaches (data security and breach notification)

DE Breach Law
active

Jurisdiction: Delaware

Effective: 6/28/2005

Authority: Delaware Attorney General (Director of Consumer Protection, Department of Justice) (12B-104(a))

Requires businesses holding Delaware residents' personal information to keep reasonable security procedures and to notify affected residents of a breach within 60 days of determining it occurred, unless an investigation shows harm is unlikely. Breaches affecting more than 500 residents must also be reported to the Attorney General, and breaches of Social Security numbers require a free year of credit monitoring. HB 381 (signed and effective Sept. 2, 2026) adds the Attorney General to substitute notice, requires Attorney General notice within 60 days where residents' involvement is identified late, and limits the HIPAA/GLBA safe harbor to the timing rule.

View Details →

Computer Spyware

NH Spyware Law
active

Jurisdiction: New Hampshire

Effective: 7/14/2005

Authority: State prosecutors (Department of Justice)

Prohibits businesses from knowingly installing software on a consumer's computer and using it deceptively to hijack the computer, change browser or security settings, collect personal information through keystroke logging or similar means, block removal, or disable security software.

View Details →

Computer Spyware, Malware, and Ransomware Protection

Iowa Spyware Law
active

Jurisdiction: Iowa

Authority: County attorneys and the Attorney General (criminal prosecution); ransomware victims (civil action)

Iowa's spyware law makes it a crime to install software on someone else's computer that deceptively collects personal information (such as keylogging, browsing-history profiling, or extracting ID and account numbers), hijacks browser settings, disables security software, or resists removal. A 2023 amendment added ransomware offenses and a civil claim for ransomware victims.

View Details →

Confidentiality of bank customer financial records

LA Bank Financial Records Privacy
active

Jurisdiction: Louisiana

Effective: 1/1/1985

Authority: Courts (civil procedure); bank regulators

Bars banks and their affiliates from disclosing a customer's financial records to anyone but the customer unless the request is a disclosure demand served on both the bank and the customer with an affidavit, a written customer authorization meeting statutory requirements, or another listed exception. It functions as Louisiana's state-level financial privacy act, supplementing federal GLBA and the Right to Financial Privacy Act. Act 142 of 2026 updated the supervisory-agency definition and service rules.

View Details →

Confidentiality of Employee Assistance Programs and Ban on Requesting Applicants' Tax Returns

RI EAP Confidentiality / Applicant Tax Records
active

Jurisdiction: Rhode Island

Authority: Courts via employee or applicant civil actions

Two short Rhode Island employee privacy laws. One bars employers from releasing names, addresses or other confidential information obtained through an employee's participation in an employee assistance program; the other bars employers from asking job applicants for copies of their tax returns or W-2 forms as a condition of being considered.

View Details →

Confidentiality of Financial Institution Books and Records

Florida Bank Records Confidentiality Law
active

Jurisdiction: Florida

Authority: Florida Office of Financial Regulation; state attorneys

Makes a Florida financial institution's books and records confidential and requires records of customers' trust accounts, deposits, and loans to be released only with the account holder's express authorization, subject to listed exceptions such as subpoenas, regulators, credit reporting, and disclosures allowed under the Gramm-Leach-Bliley Act.

View Details →

Confidentiality of Financial Institution Customer Records

CT Financial Records Privacy
active

Jurisdiction: Connecticut

Authority: Connecticut Banking Commissioner; customers may move to quash subpoenas (36a-43(b))

Bars financial institutions from disclosing a customer's financial records to anyone other than the customer without authorization, except under listed legal processes, and requires that customers be served with subpoenas for their records at least ten days before disclosure so they can challenge them.

View Details →

Confidentiality of Health Care Communications and Information Act

RI CHCCIA
active

Jurisdiction: Rhode Island

Authority: Courts via patient suits; criminal prosecution

Rhode Island's general medical privacy law. It bars providers and anyone who receives patient information from releasing or re-disclosing confidential health care information without the patient's written consent on a compliant form, subject to listed exceptions such as emergencies, treatment coordination, insurers, research without identification and certain law-enforcement reports. It also gives patients rights to have adverse-decision records sent to a physician, to seek amendment, and to have insurers send communications to an address they choose.

View Details →

Confidentiality of HIV test results

VA HIV test confidentiality
active

Jurisdiction: Virginia

Effective: 7/1/1989

Authority: Virginia Attorney General, attorneys for the Commonwealth, and local attorneys (civil penalty); subjects of disclosure (private action) (32.1-36.1(B)-(C))

Makes the results of every HIV test confidential and allows release only to persons or entities authorized to receive protected health information under state or federal law.

View Details →

Confidentiality of HIV-Related Information

CT HIV Confidentiality
active

Jurisdiction: Connecticut

Authority: Private action; Department of Public Health

Prohibits anyone who obtains confidential HIV-related information from disclosing it except to the person, those with a signed release, and a limited list of health, legal and public-health recipients, and gives injured individuals a right to sue for wilful violations.

View Details →

Confidentiality of Medical Information Act

CMIA
active

Jurisdiction: California

Authority: California Attorney General, district attorneys and other public prosecutors, State Department of Public Health and licensing boards; private plaintiffs

California's main medical privacy law. It bars health care providers, health plans, and their contractors from disclosing medical information without the patient's written authorization except as listed, requires confidential storage and disposal, and extends these duties to consumer health apps, mental health and reproductive health digital services, and employers. Recent amendments protect reproductive and gender-affirming care records from out-of-state disclosure and (SB 81, 2025) bar disclosure for immigration enforcement without a warrant or court order.

View Details →

Confidentiality of mental health and substance abuse treatment information

OK Mental Health Confidentiality
active

Jurisdiction: Oklahoma

Effective: 11/1/1987

Authority: Courts; Department of Mental Health and Substance Abuse Services and licensing boards

Makes all mental health and drug or alcohol treatment information, and the identity of people receiving such treatment, privileged and confidential. Disclosure generally requires a detailed written release or a court order (a subpoena alone is not enough), with limited minimum-necessary exceptions, and consumers have a right to access their own records subject to listed exceptions.

View Details →

Confidentiality of Mental Health Services Information and Records

RI Mental Health Records Law
active

Jurisdiction: Rhode Island

Authority: Rhode Island Department of Behavioral Healthcare, Developmental Disabilities and Hospitals; courts

Makes confidential the fact that a person was admitted or certified for mental health treatment and all records compiled in providing services under Rhode Island's Mental Health Law, allowing disclosure only with written consent or in listed situations such as coordination among treating professionals, insurance claims, emergencies, approved research under confidentiality oaths, and court proceedings.

View Details →

Confidentiality of motor vehicle title and registration records

OK Vehicle Records Privacy
active

Jurisdiction: Oklahoma

Effective: 7/1/1985

Authority: Service Oklahoma and the Corporation Commission; district attorneys

Oklahoma's state counterpart to the federal Driver's Privacy Protection Act for vehicle title and registration records. Personal information (name, street address, phone) is confidential and may be released only for listed permissible purposes, such as government functions, vehicle safety and recalls, verifying information in the normal course of business, litigation, and towing notices, and requesters must certify a lawful purpose and no further dissemination.

View Details →

Confidentiality of Prescription Information (Prescriber Data Law)

VT Prescription Confidentiality Law
enjoined

Jurisdiction: Vermont

Authority: Vermont Attorney General

Barred the sale or marketing use of prescriber-identifying prescription records without the prescriber's consent. The U.S. Supreme Court held in Sorrell v. IMS Health Inc., 564 U.S. 552 (2011), that § 4631(d) violates the First Amendment, affirming the Second Circuit. The subsection still appears in the Vermont Statutes but cannot be enforced.

View Details →

Confidentiality of reportable disease and public health investigation information

OK Communicable Disease Confidentiality
active

Jurisdiction: Oklahoma

Effective: 7/1/1988

Authority: District attorneys (misdemeanor); private civil actions by the subject of a disclosure

Makes Health Department records on reportable communicable and noncommunicable diseases, including HIV and hepatitis B, and public health investigation participants confidential, with release only in listed circumstances such as court order, written informed consent, or de-identified statistics. Anyone who wrongfully discloses such information faces criminal and civil liability.

View Details →

Confidentiality of sexually transmitted disease medical records

AL STD Records Confidentiality
active

Jurisdiction: Alabama

Authority: District attorneys (criminal prosecution)

Makes information, reports, and medical records about people infected with designated sexually transmitted diseases confidential. They are not open to public inspection or admissible in court except in commitment proceedings, and individual records may be released with the patient's written consent.

View Details →

Confidentiality of social security numbers

Colorado SSN protection
active

Jurisdiction: Colorado

Effective: 1/1/2007

Authority: Colorado Attorney General (Colorado Consumer Protection Act article)

Colorado limits how businesses display and transmit Social Security numbers. They may not publicly post SSNs, print them on access cards or on mailings (with exceptions for forms and applications), or require them to be sent over unsecured internet connections or used alone to log in.

View Details →

Confidentiality of Social Security Numbers

SSN Protection (1798.85)
active

Jurisdiction: California

Effective: 7/1/2002

Authority: California Attorney General and local prosecutors; private plaintiffs

Limits how businesses display and use Social Security numbers: no public posting, no printing on access cards or on most mailings, no requiring SSN transmission over unsecured connections or as a sole website login, and no selling SSNs.

View Details →

Connected Devices with Cameras or Microphones (P.A. 25-44)

CT Connected Devices
active

Jurisdiction: Connecticut

Effective: 7/1/2026

Authority: Connecticut Attorney General / Department of Consumer Protection under CUTPA

Before a connected device with a camera or microphone can be activated, the provider must show the initial purchaser a prescribed disclaimer and plain disclosures about recording, retention and sharing, and let them decline to activate the camera or microphone. Recordings may not be used or sold for targeted advertising without opt-in consent, and collected information must be reasonably secured.

View Details →

Connected television voice recognition

Smart TV law
active

Jurisdiction: California

Effective: 1/1/2016

Authority: California Attorney General and district attorneys (exclusive)

Requires smart TV makers to tell users during setup that the TV has voice recognition, and bars selling or using recordings collected to improve voice recognition for advertising.

View Details →

Connected Vehicle Services: Survivor Requests (P.A. 25-113, s. 19)

CT Connected Vehicle Safety
active

Jurisdiction: Connecticut

Effective: 7/1/2026

Authority: Not specified in the section

Lets adult survivors of domestic violence, sexual assault, stalking or trafficking require a car maker to cut off an abuser's remote access to a vehicle's connected services, including location tracking. The provider must act within two business days, deny the abuser newly generated data, and keep the survivor's information confidential.

View Details →

Connecticut Artificial Intelligence Responsibility and Transparency Act (CART Act; An Act Concerning Online Safety)

CT CART Act
enacted_not_effective

Jurisdiction: Connecticut

Effective: 10/1/2026

Authority: Connecticut Attorney General (CUTPA); Commission on Human Rights and Opportunities for employment discrimination provisions

A broad 2026 AI law signed May 27, 2026. For privacy purposes it requires AI companion operators to detect self-harm risk and bars manipulative, romantic or sexual interactions with minors; requires employers using automated employment decision tools to tell workers and applicants, including what personal data is analyzed; makes clear that using such tools is no defense to discrimination; and from 2028 bars personalized recommendation feeds for minors without parental consent, with limits on age-verification data use.

View Details →

Connecticut Data Privacy Act (Act Concerning Personal Data Privacy and Online Monitoring)

CTDPA
active

Jurisdiction: Connecticut

Effective: 7/1/2023

Authority: Connecticut Attorney General (exclusive; Conn. Gen. Stat. 42-525(a))

Max Fine: Up to $5,000 per violation

Connecticut's comprehensive consumer privacy law gives residents rights to access, correct, delete and port their data and to opt out of targeted advertising, sale and consequential profiling, and requires consent for sensitive data, privacy notices, recognition of opt-out preference signals, and data protection assessments. P.A. 25-113 (effective July 1, 2026) sharply broadened coverage (35,000-consumer threshold, any processor of sensitive data, any seller of data), added neural and financial-account data as sensitive data, added profiling rights and impact assessments, extended the teen targeted-advertising and sale ban to under-18s, and required disclosure of LLM training. P.A. 26-64 (effective October 1, 2026) bans the sale of precise geolocation data, restricts facial recognition used for security, and expands deletion rights over people-search profiles built from public information.

consumer_rightsopt_outchildrensensitive_data
View Details →

Connecticut Insurance Information and Privacy Protection Act

CT IIPPA
active

Jurisdiction: Connecticut

Effective: 10/1/1982

Authority: Connecticut Insurance Commissioner; individuals in court for certain violations

Based on the NAIC model, this act governs how insurers and agents collect, use and disclose personal and medical information: notices of information practices, limits on pretext interviews, access and correction rights, reasons for adverse underwriting decisions, and consent for most disclosures. It also bars anyone from selling individually identifiable medical record information.

View Details →

Consumer and protected-consumer security freeze

Tenn. Security Freeze
active

Jurisdiction: Tennessee

Effective: 9/1/2008

Authority: Tennessee Attorney General (sole authority over § 47-18-2108(f)); consumers for other violations

Lets Tennessee consumers freeze their credit reports so that a consumer reporting agency cannot release the report or score for new credit without the consumer's authorization. A separate section lets a parent or guardian place a freeze for a child under 16 or an incapacitated adult, creating a record if no credit file yet exists.

View Details →

Consumer credit report security freeze

AL Security Freeze Law
active

Jurisdiction: Alabama

Authority: Not specified in the chapter (courts)

Lets Alabama consumers place a security freeze on their credit reports so agencies cannot release them for credit purposes without the consumer's authorization. Agencies must place, lift, and remove freezes within set deadlines, give a PIN or password, and include an Alabama freeze-rights notice with the federal FCRA summary of rights.

View Details →

Consumer Credit Reporting Agencies Act (including security freezes)

CCRAA
active

Jurisdiction: California

Effective: 1/1/1976

Authority: Private plaintiffs; California Attorney General and local prosecutors

California's counterpart to the federal Fair Credit Reporting Act. It governs who may obtain consumer credit reports and for what purposes, accuracy and dispute rights, and gives consumers the right to place, lift, and remove security freezes on their credit files.

View Details →

Consumer Credit Security (security freeze law)

Iowa Security Freeze Law
active

Jurisdiction: Iowa

Effective: 7/1/2008

Authority: Iowa Attorney General (violation of Consumer Fraud Act 714.16(2)(a))

Iowa's security freeze law lets residents block release of their credit reports, free of charge, and lets parents and guardians place a protected-consumer freeze for children under 16 and incapacitated adults, even creating a record if none exists. It sets short deadlines for credit bureaus to place, lift, and remove freezes.

View Details →

Consumer Data Protection Act, social media platforms and minors (SB 854)

VA SB 854
enjoined

Jurisdiction: Virginia

Effective: 1/1/2026

Authority: Virginia Attorney General (VCDPA enforcement, 59.1-584)

Requires social media platforms to use commercially reasonable methods, such as a neutral age screen, to identify users under 16, and to limit those users to one hour per day per service unless a parent gives verifiable consent to change the limit. Age data may be used only for age determination. On February 27, 2026 the U.S. District Court for the Eastern District of Virginia preliminarily enjoined the Attorney General from enforcing it against any NetChoice member (NetChoice v. Jones, No. 1:25-cv-02067); the Fourth Circuit denied a stay on August 24, 2026 and set argument for October 28, 2026 (No. 26-1252).

View Details →

Consumer Empowerment and Identity Theft Prevention Act of 2006 (credit security freeze and Social Security number protection)

RI Security Freeze / SSN Act
active

Jurisdiction: Rhode Island

Authority: Courts via consumer suits; civil fines and misdemeanor prosecution for SSN violations

Lets Rhode Island residents freeze their credit reports free of charge so credit cannot be opened in their name without authorization, and sets deadlines for credit bureaus to place, lift and remove freezes. It also restricts how businesses and agencies may display, mail or require transmission of Social Security numbers.

View Details →

Consumer Genetic Testing Providers

IN Consumer Genetic Testing
active

Jurisdiction: Indiana

Effective: 5/6/2025

Authority: Indiana Attorney General (exclusive authority, IC 24-4-24-11(a))

Enacted by HEA 1521 (2025) and effective on passage, this chapter regulates direct-to-consumer genetic testing companies. Before testing, they must give a written privacy disclosure. They need separate, specific consent for extra testing, secondary uses, third-party access, retention beyond 30 days, and genetics-based marketing, and they may never give identifiable genetic data to insurers or employers.

View Details →

Consumer Health Data Privacy (CTDPA consumer health data provisions)

CT Consumer Health Data
active

Jurisdiction: Connecticut

Effective: 10/1/2023

Authority: Connecticut Attorney General (exclusive; Conn. Gen. Stat. 42-525(a))

P.A. 23-56 added 'consumer health data' (including reproductive, sexual and gender-affirming health data) to the CTDPA as sensitive data and imposed threshold-free duties on anyone handling it. It bars selling consumer health data without consent and bans geofences within 1,750 feet of mental health or reproductive or sexual health facilities used to track or message consumers about their health data.

View Details →

Consumer Identity Protection Act

AL CIPA (identity theft)
active

Jurisdiction: Alabama

Authority: District attorneys and Attorney General (criminal); victims (civil)

Makes identity theft and trafficking in stolen identities crimes, gives victims a civil action with statutory damages, and provides court orders confirming the victim's innocence. On such an order, consumer reporting agencies must block fraudulent information from the victim's credit report within 30 days.

View Details →

Consumer Privacy in Mortgage Applications (mortgage trigger leads)

RI Mortgage Trigger Lead Law
active

Jurisdiction: Rhode Island

Authority: Rhode Island Department of Business Regulation (director); aggrieved lenders or brokers via civil action

Regulates mortgage solicitations based on 'trigger leads' sold by credit bureaus after a consumer applies for a mortgage. Solicitors must disclose up front that they are not affiliated with the consumer's lender and that they bought the consumer's information from a credit bureau, must comply with FCRA prescreening rules, and may not use trigger leads to reach consumers who opted out of prescreened offers or are on do-not-call lists.

View Details →

Consumer Protection Against Computer Spyware Act

Texas Spyware Act
active

Jurisdiction: Texas

Effective: 4/1/2009

Authority: Texas Attorney General; software providers, web page or trademark owners, carriers, cable operators, and ISPs

Prohibits installing software on someone else's computer to deceptively collect personal information through keystroke logging or browsing tracking, hijack settings, or block removal. Private suits are limited to affected software providers, site and trademark owners, carriers, cable operators, and ISPs; botnet victims have a separate action.

View Details →

Consumer Protection Against Computer Spyware Act

Spyware Act
active

Jurisdiction: California

Effective: 1/1/2005

Authority: California Attorney General and local prosecutors

Bars installing software on a Californian's computer that, through deception, hijacks browser settings, logs keystrokes or browsing history, extracts sensitive data, blocks removal, or disables security software.

View Details →

Consumer Report Security Freeze

Florida Security Freeze Law
active

Jurisdiction: Florida

Effective: 7/1/2006

Authority: Private civil actions; Florida Department of Agriculture and Consumer Services

Lets Florida consumers freeze their credit reports so agencies cannot release them to third parties without the consumer's authorization. Agencies must place freezes within 5 business days, lift them temporarily within 3 business days, and remove them within 3 business days of a request.

View Details →

Consumer Report Security Freeze Law (including protected persons)

KY Security Freeze
active

Jurisdiction: Kentucky

Effective: 7/12/2006

Authority: Consumers via civil action; Attorney General retains other enforcement powers

Lets Kentucky consumers freeze their credit reports so they cannot be released to new creditors without the consumer's authorization, and sets deadlines for placing, lifting, and removing freezes. A 2017 addition lets parents, guardians, and other representatives freeze the record or report of a child under 16 or an incapacitated person.

View Details →

Consumer Reporting Agencies (security freezes; medical debt reporting ban)

VA credit freeze
active

Jurisdiction: Virginia

Effective: 7/1/2008

Authority: Consumers by private action; Attorney General exclusively for electronic-lift timing and protected-consumer placement violations (59.1-444.2(U), 59.1-444.3(M)); medical debt reporting through the VCPA (59.1-444.4(C))

Lets Virginia consumers freeze their credit reports free of charge, with deadlines for placing and temporarily lifting freezes, and lets parents or guardians freeze or create a record for children under 16 and incapacitated adults. Since 2024 it also bars health care providers and collectors from reporting medical debt to credit bureaus.

View Details →

Consumer Reporting Agency Records Restriction (criminal charges without conviction)

KY CRA Criminal Charge Restriction
active

Jurisdiction: Kentucky

Effective: 7/15/1980

Authority: Not specified in the section

Bars consumer reporting agencies from keeping information in their files about a criminal charge in a Kentucky court unless the charge resulted in a conviction.

View Details →

Consumer Telemarketing Protection (automatic dialing and telephone solicitation)

Tenn. Telemarketing Protection Law
active

Jurisdiction: Tennessee

Authority: District attorneys general and recipients (ADAD rules); Tennessee Attorney General (§ 47-18-1526)

Limits robocalls made with automatic dialing and announcing devices: prior consent is required, calls are limited to 8 a.m. to 9 p.m., random or sequential dialing and calls to unlisted numbers and emergency services are barred, and the recorded message must identify the caller. Telephone solicitors must keep an internal do-not-call list consistent with federal rules and may not block caller ID.

View Details →

Conversational Artificial Intelligence Safety Act

Nebraska CAISA
enacted_not_effective

Jurisdiction: Nebraska

Effective: 7/1/2027

Authority: Nebraska Attorney General

Enacted as sections 12-18 of LB525 (2026) and operative July 1, 2027, this law regulates companion-style AI chatbots. It requires AI disclosure where users could be misled, extra disclosures and content safeguards for minors, privacy and account-setting tools for minors and parents, and a crisis-referral protocol for self-harm prompts.

View Details →

Conversational Artificial Intelligence Service Operator Requirements (Chatbot Safety Act)

Chatbot Safety Act (HB 26-1263)
enacted_not_effective

Jurisdiction: Colorado

Effective: 1/1/2027

Authority: Colorado Attorney General

HB 26-1263, signed May 29, 2026, sets safety and disclosure duties for companion-style and general chatbots starting January 1, 2027. Operators must estimate users' ages, disclose that the service is AI, run suicide and self-harm referral protocols, and, for known minors, block sexual content and emotional-dependence tactics and offer privacy controls over memory and training use. The act itself took effect August 12, 2026.

View Details →

Conversational Artificial Intelligence Services Act (2026 SF 2417)

Iowa Conversational AI Act
enacted_not_effective

Jurisdiction: Iowa

Effective: 7/1/2027

Authority: Iowa Attorney General (with rulemaking authority)

Iowa's 2026 companion-chatbot law requires public conversational AI services to disclose to minors that they are talking to AI, block sexual content and human-like emotional or romantic manipulation of minors, avoid variable engagement rewards for minors, and give minors and parents privacy and account controls. For all users, operators must disclose AI status when a reasonable person could think it is human, keep suicide and self-harm referral protocols, and not present the bot as a licensed mental health provider. It applies from July 1, 2027.

View Details →

Covered platform age restriction: no addictive features for users under 16 (AB 1709)

AB 1709
enacted_not_effective

Jurisdiction: California

Effective: 1/1/2027

Authority: California Attorney General and local public prosecutors

Signed September 10, 2026, AB 1709 bars covered platforms from offering addictive features (addictive feeds, autoplay, and others the Attorney General defines) to users under 16. Platforms must verify age through the Digital Age Assurance Act before offering those features and must delete accounts and data of under-16 users unless the account is kept free of addictive features. It also creates an e-Safety Advisory Commission.

View Details →

Credit and debit card receipt truncation

OK Card Receipt Truncation
active

Jurisdiction: Oklahoma

Effective: 11/1/2002

Authority: Not specified in the section

Bars merchants from printing more than the last five digits of a card number, or the expiration date, on electronically printed customer receipts. Applies to all electronic receipt devices since January 1, 2007.

View Details →

Credit and debit card receipt truncation and card-transaction information limits

ORS 646A.200-646A.214
active

Jurisdiction: Oregon

Authority: Oregon Attorney General (rules under ORS 646A.206); ORS 646A.210 and 646A.214 violations are unlawful practices under ORS 646.608(1)(mm)

Limits card receipts to the customer's name and five digits of the card number, requires destruction of fuller receipt copies within 36 months, and limits collecting card numbers or recording extra personal information on card slips.

View Details →

Credit Report Protection Act

Nebraska Credit Report Protection Act
active

Jurisdiction: Nebraska

Effective: 9/1/2007

Authority: Nebraska Attorney General

Nebraska's credit freeze law lets consumers place, temporarily lift, and remove a security freeze on their credit files, and lets a parent or representative freeze the file of a child under 16 or an incapacitated person, creating a record if none exists. Freezes are free, and a frozen file cannot be released to third parties without authorization.

View Details →

Credit Report Security Freeze

MT Security Freeze
active

Jurisdiction: Montana

Effective: 10/1/2007

Authority: Private enforcement by consumers (30-14-1736)

Montana consumers may place a security freeze on their credit reports so that reports cannot be released to new creditors without consent. Consumer reporting agencies must place, temporarily lift and remove freezes on set timelines and give consumers a notice of rights.

View Details →

Credit Report Submission Prohibitions (ambulance balance billing)

MT Ambulance Credit Reporting Limit
active

Jurisdiction: Montana

Effective: 10/1/2017

Authority: Montana Department of Justice, Office of Consumer Protection (placement in Title 30, ch. 14)

Licensed ambulance services may not report patients to credit bureaus over balance bills once the patient's insurer or health plan has paid based on plan charges, or when an uninsured patient has paid toward the bill and filed an AG complaint that it is not based on usual and customary charges. Bills sent to collections must carry the same limit.

View Details →

Credit reporting agency duties, security alerts, and security freezes

LA Credit Report and Security Freeze Law
active

Jurisdiction: Louisiana

Authority: Private civil actions

Gives Louisiana consumers rights to copies of their credit reports, to dispute inaccurate items with a 45-day investigation deadline, to place free 90-day security alerts, and to place free security freezes that credit bureaus must apply within set deadlines. A separate section lets parents and guardians freeze the credit file of a child under 16 or an incapacitated person, including creating a file for that purpose.

View Details →

Crime of doxing

AL Doxing Law
active

Jurisdiction: Alabama

Effective: 9/1/2023

Authority: Alabama district attorneys and Attorney General (criminal prosecution)

Makes it a crime to intentionally publish someone's personal identifying information online intending that others use it to harass or harm the person, when the person is actually harassed or harmed. A second prong protects law enforcement officers, firefighters, and public servants, including against being impeded in their duties. Political speech and publishing officials' official contact information are carved out.

View Details →

Crime of phishing

AL Phishing Law
active

Jurisdiction: Alabama

Authority: Alabama Attorney General and district attorneys (criminal and civil); private plaintiffs

Makes it a felony to use the Internet to trick people into providing identifying information by impersonating a business without its authority. It gives prosecutors civil remedies and lets affected individuals and businesses sue.

View Details →

Criminal eavesdropping and surveillance (one-party consent)

AL Eavesdropping Law
active

Jurisdiction: Alabama

Authority: Alabama district attorneys and Attorney General (criminal prosecution)

Alabama is a one-party consent state: it is a crime to use a device to overhear, record, or transmit a private communication without the consent of at least one participant. The article also criminalizes secret surveillance while trespassing in a private place, planting eavesdropping devices, and using or disclosing information obtained illegally.

View Details →

Criminal History on Applications for Employment (ban-the-box)

RI Ban-the-Box Law
active

Jurisdiction: Rhode Island

Authority: Rhode Island Department of Labor and Training, with the Commission for Human Rights

Prohibits employers from asking on job applications whether an applicant has ever been arrested, charged or convicted, except for law enforcement positions, jobs where law mandates disqualification for specified convictions, and jobs requiring a fidelity bond that specified convictions would bar.

View Details →

Criminal Impersonation, Identity Theft, and Identity Fraud

Nebraska Identity Theft Law
active

Jurisdiction: Nebraska

Authority: County attorneys and the Attorney General (criminal prosecution)

Nebraska criminalizes identity theft, defined broadly to cover knowingly obtaining, possessing, or using another person's or entity's identifying information (such as name, birth date, SSN, license number, employer, account numbers, or biometric data) without consent to commit fraud, cause loss, obtain employment, or gain a benefit. Victims may report to their local law enforcement agency.

View Details →

Criminal Invasion of Personal Privacy (pretexting)

MT Criminal Invasion of Privacy
active

Jurisdiction: Montana

Effective: 10/1/2007

Authority: County attorneys and the Attorney General (criminal prosecution)

Montana makes it a crime to get someone's personal or confidential information by pretending to be that person, a practice often called pretexting. Posing as someone with their express consent is allowed.

View Details →

Customer Records: disposal of records containing personal information

Records Disposal (1798.81)
active

Jurisdiction: California

Authority: Private plaintiffs; California Attorney General

Requires businesses to destroy customer records containing personal information when they no longer keep them, by shredding, erasing, or otherwise making the information unreadable.

View Details →

Cybersecurity Affirmative Defense Act

Utah Cybersecurity Affirmative Defense Act
active

Jurisdiction: Utah

Effective: 5/5/2021

Authority: None (creates an affirmative defense)

Enacted by 2021 H.B. 80 and unchanged since, it gives a defense against claims of failing to implement reasonable controls, respond, or notify after a breach if the person had a written cybersecurity program reasonably conforming to NIST, CIS, ISO 27000, PCI DSS, HIPAA, GLBA, 13-44, or similar frameworks.

View Details →

Cybersecurity Event Class Action Liability Limit

Nebraska Cybersecurity Event Liability Law
active

Jurisdiction: Nebraska

Effective: 9/3/2025

Authority: Courts (limits private litigation)

Enacted by LB241 (2025), this law raises the liability standard for data breach class actions against private entities. A cybersecurity event is unauthorized access to, or disruption or misuse of, an information system or nonpublic information such as SSNs, driver's license numbers, financial account numbers, access codes, or biometric records.

View Details →

Cybersecurity Program Safe Harbor (S.B. 2610)

Texas Cybersecurity Safe Harbor
active

Jurisdiction: Texas

Effective: 9/1/2025

Authority: None (liability defense only)

Gives small and mid-sized Texas businesses a defense against exemplary (punitive) damages in data breach lawsuits if, at the time of the breach, they maintained a cybersecurity program scaled to their size and conforming to a recognized framework such as NIST, CIS Controls, ISO 27000, SOC 2, or applicable HIPAA, GLBA, or PCI DSS requirements.

View Details →

Daniel's Law (nondisclosure of covered persons' home addresses and unpublished telephone numbers)

Daniel's Law
active

Jurisdiction: New Jersey

Effective: 11/20/2020

Authority: Private civil action in Superior Court by the covered person or an assignee; county prosecutors and the Attorney General for the criminal offense in N.J.S.A. 2C:20-31.1

Enacted after the 2020 killing of Daniel Anderl, son of U.S. District Judge Esther Salas, Daniel's Law lets judges, prosecutors, law enforcement officers, child protective investigators, and their household family members demand that anyone stop publishing their home address or unpublished home phone number. After written notice, the recipient has 10 business days to stop disclosing and remove the information, or face civil liability (which can be pursued by an assignee) and possible criminal charges.

View Details →

Data Accessibility, Transparency and Accountability Act

Tenn. DATA Act
active

Jurisdiction: Tennessee

Effective: 7/1/2014

Authority: Tennessee Department of Education and State Board of Education

Governs how Tennessee's education agencies and schools collect and share student data. It requires the Department of Education to publish a data inventory and adopt privacy and security policies, gives parents the right to inspect their children's education records, bars schools from collecting data on students' political affiliation, religion, voting history, or gun ownership, and requires written consent before collecting student biometric or physiological data such as facial-expression analysis, brain waves, or eye tracking.

View Details →

Data Broker and Data Collector Registration and Sensitive Data Sale Ban (P.L.2026, c.25)

NJ Data Broker Law
active

Jurisdiction: New Jersey

Effective: 6/30/2026

Authority: New Jersey Division of Consumer Affairs (registration, fees, and penalties collected in a summary proceeding under the Penalty Enforcement Law of 1999)

This 2026 law creates an annual registry of data brokers and data collectors that sell or license New Jersey consumers' personal data, with fees scaled by the number of consumers affected, and requires detailed disclosures about opt-out, deletion, breach history, and minors' data. It also bars data brokers and data collectors from selling or licensing sensitive data to anyone, backed by a $50,000-per-record penalty. The law took effect on signing, but the Division's public registry duty became operative 270 days later.

View Details →

Data Broker Registration and Accessible Deletion Mechanism (P.A. 26-64, ss. 1-10)

CT Data Broker Registry
enacted_not_effective

Jurisdiction: Connecticut

Effective: 10/1/2026

Authority: Connecticut Department of Consumer Protection (Commissioner of Consumer Protection)

Creates Connecticut's first data broker registry: from January 1, 2027 no data broker may sell or license brokered personal data in the state unless registered with the Department of Consumer Protection. By July 1, 2028 the Department must launch a one-stop deletion mechanism, and from August 2028 registered brokers must check it at least every 45 days and delete participating consumers' data.

View Details →

Data Broker Registration law and the Delete Act (SB 362), with the Delete Request and Opt-out Platform (DROP)

Delete Act
active

Jurisdiction: California

Effective: 1/1/2020

Authority: California Privacy Protection Agency (CalPrivacy)

Requires data brokers to register every year with the California Privacy Protection Agency and disclose what data they collect. The 2023 Delete Act (SB 362) moved the registry from the Attorney General to the Agency and required a single, free deletion mechanism; the Agency launched DROP on January 1, 2026, and registered brokers must process DROP deletion requests every 45 days starting August 1, 2026. SB 361 (2025) added more registration disclosures.

View Details →

Database Security Breach Notification Law

LA DSBNL
active

Jurisdiction: Louisiana

Effective: 1/1/2006

Authority: Louisiana Attorney General (Consumer Protection Section)

Louisiana's breach law requires businesses and agencies to protect computerized personal information with reasonable security, destroy it securely when no longer retained, and notify affected Louisiana residents within 60 days of discovering a breach. An Attorney General rule adds notice to the AG within 10 days of notifying residents. Personal information is name plus SSN, driver's license or state ID number, financial account or card number with access code, passport number, or biometric data.

View Details →

Deceptive and Fraudulent Synthetic Media in Elections

RI Election Deepfake Law
active

Jurisdiction: Rhode Island

Effective: 7/2/2025

Authority: Courts via actions by depicted candidates

Bars campaigns, PACs and independent spenders from distributing, within 90 days of an election, AI-manipulated images, audio or video of a person that they know or should know are deceptive and fraudulent, unless the media carries a clear disclosure that it was manipulated or generated by artificial intelligence.

View Details →

Deceptive Audio or Visual Media (Deepfake) Law

NJ Deepfake Law
active

Jurisdiction: New Jersey

Effective: 4/2/2025

Authority: County prosecutors and the Attorney General (criminal); private civil action by victims in Superior Court

This 2025 law makes it a crime to create or spread AI-generated or other technically produced deepfakes to commit or further crimes such as harassment, sexual exploitation, or election interference. It also lets victims, including families of deceased victims, sue for damages.

View Details →

Deceptive Commercial Electronic Mail

IN Commercial Email
active

Jurisdiction: Indiana

Authority: Private enforcement by recipients and interactive computer services

Enacted in 2003, this chapter bans commercial email that uses a third party's domain without permission, misrepresents its origin or path, or has a false or misleading subject line. It also requires 'ADV:' and 'ADV:ADLT' subject labels on unsolicited ads and a free opt-out. Many of its labeling and opt-out rules likely overlap with, and may be preempted by, the federal CAN-SPAM Act, which preserves state laws only as to falsity or deception.

View Details →

Deepfake Regulation in Election Communications (SB 25)

MT Election Deepfake Law
active

Jurisdiction: Montana

Effective: 10/1/2025

Authority: Montana Commissioner of Political Practices; county attorneys and Attorney General for criminal referrals; aggrieved candidates or parties (injunction)

Montana bars distributing AI-generated or synthetic 'deepfakes' of candidates or parties in election communications within 60 days of an election unless a prescribed disclosure says the content was significantly edited by AI. On September 16, 2026, a federal court preliminarily enjoined enforcement of the law, but only as to the plaintiffs, in Accountability in State Government v. Knudsen, No. 6:26-cv-00038-SPW (D. Mont.).

View Details →

Delaware Discrimination in Employment Act: genetic information provisions

DDEA Genetic Information
active

Jurisdiction: Delaware

Authority: Delaware Department of Labor (charge process), followed by a Delaware Right to Sue Notice for Superior Court suits (712)

Delaware's employment discrimination law bars discrimination based on genetic information and bars employers, agencies, and unions from intentionally collecting genetic information about employees, applicants, or their family members unless it is job-related and consistent with business necessity or needed for retirement or benefit plan administration.

View Details →

Delaware Online Privacy and Protection Act

DOPPA
active

Jurisdiction: Delaware

Effective: 1/1/2016

Authority: Consumer Protection Unit, Delaware Department of Justice (1203C)

Delaware's online privacy law has three parts: it bars marketing listed adult products (alcohol, tobacco, firearms, lottery, tattoos, sexually oriented material, and others) to children under 18 on child-directed services and restricts use of children's personal information for such marketing; it requires any commercial website or app collecting personal information from Delaware users to post a conspicuous privacy policy; and it limits disclosure of e-book and book-service user records.

View Details →

Delaware Personal Data Privacy Act

DPDPA
active

Jurisdiction: Delaware

Effective: 1/1/2025

Authority: Delaware Department of Justice (Attorney General), exclusively (12D-111(a), (e))

Max Fine: Up to ,000 per violation

Delaware's comprehensive consumer privacy law gives residents rights to access, correct, delete, and port their personal data, to get a list of third parties that received it, and to opt out of targeted advertising, sale, and significant-decision profiling. It has low applicability thresholds, requires opt-in consent for sensitive data and for targeted advertising or sale of data about known 13-17-year-olds, and requires honoring universal opt-out signals from 2026-01-01. HB 380 (signed 2026-09-02, effective 2027-01-01) lowers thresholds further and adds third-party contract and diligence duties, adverse-action notices for profiling reports, automated-decision impact assessments, a broader sensitive-data definition (including neural data and financial credentials), and narrows the employee-data exclusion for profiling.

consumer_rightsopt_outchildrensensitive_data
View Details →

Delaware Telemarketing Fraud Act (Telemarketing Registration and Fraud Prevention)

DE Telemarketing Fraud Act
active

Jurisdiction: Delaware

Effective: 1/28/2000

Authority: Delaware Attorney General (Consumer Protection Unit), under 29 Del. C. ch. 25 (2509A)

Requires telemarketing sellers and businesses reaching Delaware customers to register with the Department of Justice, make opening disclosures, and give written confirmation before a sale is final. It bars calling a customer about sales for 10 years after the customer says to stop, and gives harmed customers a right to sue.

View Details →

Delaware Uniform Civil Remedies for Unauthorized Disclosure of Intimate Images Act

DUCRUDIIA
active

Jurisdiction: Delaware

Effective: 9/23/2020

Authority: Private civil action by the depicted individual (7803)

Gives people a civil claim against anyone who knowingly or recklessly shares, or threatens to share, private intimate images of them without consent. A 2024 amendment (the Amelia Kramer Act) extends the claim to AI-generated sexual deep fakes and lets plaintiffs proceed with identifying details redacted.

View Details →

Destruction of Customer Records Containing Personally Identifiable Information

KY Records Disposal
active

Jurisdiction: Kentucky

Effective: 7/12/2006

Authority: Injured customers via civil action; injunctive relief available

Requires businesses that discard customer records they no longer need to keep to take reasonable steps to destroy the personally identifiable information in them. Personally identifiable information is defined broadly and includes contact details, SSNs, government ID numbers, and medical, financial, tax, and disability information.

View Details →

Digital Age Assurance Act (AB 1043, 2025, amended by AB 1856, 2026)

DAAA
enacted_not_effective

Jurisdiction: California

Effective: 1/1/2027

Authority: California Attorney General

Creates a device-level age signal. Operating systems must ask for the user's birth date or age at account setup and send app developers an age-bracket signal (under 13, 13-15, 16-17, 18+) on request; developers must request the signal and are treated as knowing the user's age range. AB 1856 (2026) broadened the account-setup duty, set a July 1, 2027 deadline for devices set up before 2027, and bars requesting a signal when not required by law. Other 2026 laws (AB 1709, AB 2246, SB 1119) rely on this signal.

View Details →

Digital Content Provenance Standards Act

Utah Content Provenance Act
enacted_not_effective

Jurisdiction: Utah

Effective: 1/1/2027

Authority: Utah Division of Consumer Protection

Enacted by 2026 H.B. 276, effective January 1, 2027, it requires provenance data handling for AI-generated and captured content. It is a disclosure-standards law rather than a privacy-notice law.

View Details →

Digital Voyeurism

Florida Digital Voyeurism Law
active

Jurisdiction: Florida

Authority: State attorneys (criminal)

Makes it a crime to secretly view, broadcast, or record someone who is dressing, undressing, or privately exposing their body where they expect privacy, or to record under or through their clothing, without their knowledge and consent. HB 1389 (2024) renamed the offense from 'video voyeurism' to 'digital voyeurism' and revised its elements.

View Details →

Digital Voyeurism Prevention Act

Utah DVPA
enacted_not_effective

Jurisdiction: Utah

Effective: 1/1/2027

Authority: None; private civil actions

Enacted by 2026 H.B. 276, effective January 1, 2027, it treats non-consensual counterfeit intimate images as a violation of the reasonable expectation of privacy. Generation services must verify consent and publish policies; covered platforms must offer a 48-hour takedown process.

View Details →

Direct-to-Consumer Genetic Testing Privacy (P.A. 26-64, ss. 17-19)

CT DTC Genetic Privacy
enacted_not_effective

Jurisdiction: Connecticut

Effective: 10/1/2026

Authority: Connecticut Attorney General (solely; P.A. 26-64, s. 19(b))

Gives consumers a property right in, and exclusive control over, their biological samples and genetic test results held by direct-to-consumer genetic testing companies. Companies must obtain express consent for collection, use, transfer, secondary use and sample retention, may not share genetic data with employers, insurers or marketers, and must let consumers access and delete data and destroy samples.

View Details →

Disclosure of Confidential Financial Records

Nebraska Financial Records Disclosure Law
active

Jurisdiction: Nebraska

Authority: Courts (governs compelled disclosure)

This law protects customer financial records by providing that covered institutions cannot be required to disclose records they deem confidential except in listed situations, such as a court subpoena, summons, warrant, or order, a supervisory regulator's examination, an agency subpoena, a statutory requirement, discovery rules, or a law enforcement request where the institution is a crime victim. Requesters generally pay the actual cost of producing records.

View Details →

Disclosure of Mental Health and Psychological Information

Iowa Mental Health Information Law
active

Jurisdiction: Iowa

Authority: County attorneys (criminal, for payors and peer reviewers); Commissioner of Insurance receives payor filings

Iowa bars mental health professionals, facilities, and data collectors from disclosing a person's mental health information except under written authorization or listed exceptions (emergencies, administrative needs, court orders, claims administration, limited family and law enforcement disclosures). Each disclosure must be logged, and recipients may not redisclose.

View Details →

Disclosure of Nonpublic Personal Financial Information (insurance)

IN Insurance NPI Privacy
active

Jurisdiction: Indiana

Authority: Indiana Insurance Commissioner (rulemaking, IC 27-2-20-3)

This short chapter makes GLBA Title V's limits on sharing nonpublic personal information with non-affiliated third parties part of Indiana insurance law. It authorizes the Insurance Commissioner to adopt rules consistent with, and no stricter than, GLBA.

View Details →

Disclosure of Protected Health Information Prohibited (Health Care Privacy)

VT Health Care Privacy
active

Jurisdiction: Vermont

Effective: 10/1/2016

Authority: Not specified in § 1881

Makes HIPAA's disclosure limits a matter of Vermont law by barring covered entities and business associates from disclosing protected health information unless HIPAA permits it. Amendments in 2023 and 2025 add shield-law protections: PHI about legally protected health care activity, such as reproductive and gender-affirming care, may not be disclosed to out-of-state governments for investigations or used in legal proceedings, except with patient authorization or in listed cases.

View Details →

Disclosure of Security Breach (data breach notification and data security)

IN Breach Notification
active

Jurisdiction: Indiana

Effective: 7/1/2006

Authority: Indiana Attorney General (actionable only by the AG, IC 24-4.9-4-1, 24-4.9-3-3.5(e))

Indiana's breach law requires data base owners to notify affected Indiana residents, and the Attorney General, when a breach of computerized personal information could result in identity theft, identity deception, or fraud. Notice must go out without unreasonable delay and within 45 days of discovery. The article also requires reasonable security procedures and secure disposal of records containing personal information.

View Details →

Disclosure of Sexually Explicit Images Without Consent

VT NCII Law
active

Jurisdiction: Vermont

Authority: State's Attorneys and Attorney General (criminal); victims (civil)

Makes it a crime to knowingly share nude or sexual images of an identifiable person without consent, with intent to harm, harass, intimidate, threaten or coerce, including realistic digitally altered or AI-generated images. Websites may not charge to remove such images, and victims have a civil cause of action.

View Details →

Disclosure of synthetic media in campaign communications

ORS 260.268 (election deepfakes)
active

Jurisdiction: Oregon

Effective: 3/27/2024

Authority: Oregon Secretary of State (Attorney General as to Secretary of State races)

Requires campaign communications that use realistic AI-manipulated images, audio or video of a person to carry a disclosure that the content has been manipulated.

View Details →

Discrimination Based on Vaccination Status or Immunity Passport Prohibited

MT Vaccination Status Law
active

Jurisdiction: Montana

Authority: Montana Human Rights Bureau / Human Rights Commission (unlawful discriminatory practice under Title 49)

Montana makes it an unlawful discriminatory practice for employers, businesses and government to deny services, jobs or access based on a person's vaccination status or whether they hold an 'immunity passport'. Health care facilities may ask employees to volunteer vaccination status only to plan accommodations.

View Details →

Disposal and protection of personal identifying information

Colorado data disposal and security
active

Jurisdiction: Colorado

Effective: 8/4/2004

Authority: Colorado Attorney General (6-1-716(4))

Colorado businesses must have a written policy to destroy paper and electronic records containing personal identifying information when no longer needed, rendering it unreadable. Since 2018 they must also maintain reasonable security procedures appropriate to the data and the business, and require service providers to do the same.

View Details →

Disposal of Business Records Containing Personal Identifying Information

Texas Records Disposal Law
active

Jurisdiction: Texas

Effective: 4/1/2009

Authority: Texas Attorney General

Requires businesses to shred, erase, or otherwise make customers' personal identifying information unreadable when disposing of records, and to delete disputed dishonored-check records within 30 days of agreement or a police report.

View Details →

Distributing or creating a private image (nonconsensual intimate images, including AI-generated)

AL Private Image Law
active

Jurisdiction: Alabama

Authority: District attorneys (criminal prosecution); Alabama Attorney General (emergency injunctions); depicted individuals (civil suits)

Criminalizes distributing a sexually explicit image of an identifiable person without their written consent, and (since 2024) creating, recording, or altering such an image without consent, when the person had a reasonable expectation of privacy. The definition expressly reaches altered and AI-generated images that a reasonable person would believe depict a real, identifiable individual.

View Details →

Distribution of materially deceptive media to influence an election

AL Election Deepfake Law
active

Jurisdiction: Alabama

Effective: 10/1/2024

Authority: Alabama Attorney General and district attorneys; depicted individuals, injured candidates, and voter-interest entities (injunctive relief)

Prohibits knowingly distributing AI-generated media that falsely depicts a person's speech or conduct within 90 days of an election, with intent to harm a candidate and deceive voters. Distribution is allowed if the media carries a prescribed disclaimer that it has been manipulated and depicts speech or conduct that did not occur.

View Details →

Distribution of Sexually Explicit Images Without Consent and Civil Takedown Remedy

KY Nonconsensual Intimate Images
active

Jurisdiction: Kentucky

Effective: 7/14/2018

Authority: Prosecutors (criminal); persons depicted (civil takedown action)

Criminalizes sharing another person's private sexual images without written consent when done to profit or to harm, harass, or coerce, and clarifies that consent to create an image is not consent to distribute it. Sites and apps that distribute such images must take them down at the depicted person's request without charging a removal fee, and face daily civil damages if they do not.

View Details →

Document Safe Destruction Act

VT Document Destruction Act
active

Jurisdiction: Vermont

Effective: 1/1/2007

Authority: Vermont Attorney General and State's Attorneys; Department of Financial Regulation for its licensees

Requires businesses to destroy customer records containing personal information, such as SSNs, ID numbers and financial account numbers, when they no longer keep them, by shredding, erasing or otherwise making the data unreadable. Disposal companies must adopt and monitor policies that protect the information during collection, transport and disposal.

View Details →

Downcoding of Health Benefits Claims (AI use limits and disclosure)

IN Health Claims AI Disclosure
active

Jurisdiction: Indiana

Effective: 7/1/2026

Authority: Indiana Department of Insurance (rulemaking, IC 27-1-52-14)

Enacted by HEA 1271 (2026) and effective July 1, 2026, this chapter limits claim downcoding by health insurers. Insurers may not use automated tools, including AI, as the sole basis for a medical-necessity downcode without human review of the medical record. Providers may not submit claims generated by automated tools without human review. Insurers must disclose when AI is used to deny prior authorization or downcode a claim.

View Details →

Drug and Alcohol Testing in the Workplace Act (privacy safeguards)

MN DATWA
active

Jurisdiction: Minnesota

Authority: Employees and applicants by civil action; state, county, or city attorneys and bargaining agents for injunctive relief (181.956)

Allows workplace drug, alcohol, and cannabis testing only under a written policy and only in listed situations (post-offer applicant testing, annual physicals with notice, random testing for safety-sensitive jobs, reasonable suspicion, and treatment follow-up). Laboratories may tell employers only whether substances were present, and test results are private and confidential, not usable in criminal cases against the employee.

View Details →

Drug-Free Workplace Program: Confidentiality of Employee Drug Test Information

Florida Drug-Free Workplace Confidentiality
active

Jurisdiction: Florida

Authority: Florida Department of Financial Services (Division of Workers' Compensation); Agency for Health Care Administration (laboratories)

Sets rules for employers that choose Florida's drug-free workplace program. Employers must give employees and applicants a written policy before testing, and drug-test information is confidential and may be released only with the tested person's signed written consent or when compelled in listed proceedings.

View Details →

Early Learning Personal Information Protection Act

ELPIPA
active

Jurisdiction: California

Effective: 1/1/2017

Authority: California Attorney General and local prosecutors; pupils actually harmed (from 2027)

Applies the same limits as the K-12 law to technology used in preschool and prekindergarten: no targeted advertising, profiling, sale, or unauthorized disclosure of children's information; reasonable security; and deletion on request. AB 1159 (2026) extends and tightens it, including a bar on AI training.

View Details →

Eavesdropping, Wiretapping and Tampering with Private Communications (criminal)

CT Eavesdropping Law
active

Jurisdiction: Connecticut

Authority: State criminal prosecution

Criminalizes wiretapping by a non-party without either party's consent and mechanically overhearing or recording an in-person conversation without the consent of at least one party (a one-party-consent rule for criminal liability), and bars obtaining or divulging call contents through telephone company employees. Civil liability for recording phone calls without all-party consent is separate (52-570d).

View Details →

Education Privacy Act (student social media and device privacy in higher education)

DE Education Privacy Act
active

Jurisdiction: Delaware

Effective: 8/19/2012

Authority: Not specified in the chapter

Bars Delaware colleges and universities from demanding students' or applicants' social media passwords, making them log in in front of staff, requiring them to add the school as a contact, accessing their accounts through their contacts, or installing tracking software on their personal devices. Campus police investigations and threat assessments are exempt.

View Details →

Education Records of K-12 Students; Limits on Collection of Student Information

Florida K-12 Education Records Law
active

Jurisdiction: Florida

Authority: State Board of Education (rules); circuit courts (injunctions)

Applies FERPA-style rights to Florida K-12 records and adds a 2014 rule barring schools and education agencies from collecting students' (or their parents' or siblings') political affiliation, voting history, religious affiliation, or biometric information. It mainly binds public schools and those that perform services for them.

View Details →

Educational Institution Policies on Social Media

NH Student Social Media Privacy
active

Jurisdiction: New Hampshire

Effective: 9/19/2015

Authority: Not specified in the section

Stops schools and colleges from demanding access to students' or applicants' personal social media accounts. Institutions may still investigate specific misconduct reports without login credentials and monitor their own networks.

View Details →

Educational Records Bill of Rights Act

RI Educational Records Bill of Rights
active

Jurisdiction: Rhode Island

Authority: Rhode Island Commissioner of Elementary and Secondary Education (appeals under ch. 16-39)

Rhode Island's state counterpart to FERPA for K-12 schools. It gives parents and adult students rights to inspect student records within 10 days, get copies at no more than 15 cents per page, request amendment or expungement, add a statement to contested records, and keep records confidential absent written consent or a FERPA-authorized release.

View Details →

Educational Technology Provider Registration

VT EdTech Registration
enacted_not_effective

Jurisdiction: Vermont

Effective: 1/1/2027

Authority: Vermont Secretary of State (filings); Vermont Attorney General

Starting in 2027, edtech providers must give the Secretary of State more information whenever they make a filing, including links to each product's privacy policy, the schools they serve under paid contracts and a description of each product. They must also attest that each product meets Vermont's student privacy law, the Age-Appropriate Design Code, COPPA and other privacy laws.

View Details →

Electronic and Mechanical Eavesdropping

Iowa Eavesdropping Law
active

Jurisdiction: Iowa

Authority: County attorneys and the Attorney General (criminal prosecution)

Iowa is a one-party consent state: a person who is a party to a conversation, or openly present and listening, may record it, but secretly listening to or recording others' conversations without authority is a crime. A 2018 amendment added an exception for doorbell and outdoor security cameras on a person's own property.

View Details →

Electronic Health Records Requirements (S.B. 1188)

Texas EHR Law (SB 1188)
active

Jurisdiction: Texas

Effective: 9/1/2025

Authority: Texas Attorney General (civil penalties and injunctions); Health and Human Services Commission and regulatory agencies (investigation and discipline)

Requires electronic health records of Texans to be physically stored in the United States and accessible only to staff who need them, bars recording credit scores or voter registration status in health records, gives parents immediate access to minors' records, and requires practitioners to disclose diagnostic AI use. It also adds biological-sex recording rules for records.

View Details →

Electronic Mail (unsolicited bulk email law)

Iowa Anti-Spam Law
active

Jurisdiction: Iowa

Authority: Iowa Attorney General (as a Consumer Fraud Act violation under 714.16(2)(a)); county attorneys (criminal); injured persons (civil)

Iowa's anti-spam law targets bulk commercial email senders who forge or falsify routing and header information, and people who sell software built to do so. It carries criminal penalties that rise with volume, lets injured email providers and recipients sue for statutory damages, and treats violations as consumer fraud enforceable by the Attorney General. Much of state spam regulation is preempted by the federal CAN-SPAM Act, except for falsity and deception rules like this one.

View Details →

Electronic Mail Communications Act (commercial e-mail)

Florida Electronic Mail Communications Act
active

Jurisdiction: Florida

Effective: 7/1/2004

Authority: Florida Department of Legal Affairs; interactive computer services, telephone companies, and cable providers; state attorneys (criminal)

Florida's anti-spam law. It prohibits unsolicited commercial e-mail that uses a third party's domain without permission, falsifies or hides routing information, carries a false or misleading subject line, or contains deceptive content meant to damage the recipient's device.

View Details →

Electronic Mail Fraud Regulatory Act (anti-phishing)

RI Anti-Phishing Act
active

Jurisdiction: Rhode Island

Authority: Courts via consumer, ISP, website-owner and trademark-owner actions

Rhode Island's anti-phishing law. It prohibits using websites, emails or other internet means to trick people into giving personal identifying information, such as SSNs, account numbers, passwords or biometric data, by pretending to be a business or person without authorization.

View Details →

Electronic Monitoring in Nursing and Assisted Living Facilities

RI Resident Room Camera Law
active

Jurisdiction: Rhode Island

Effective: 1/30/2025

Authority: Rhode Island Department of Health

Lets nursing home and assisted living residents place cameras or audio recorders in their own rooms with written consent on a state form, including consent from any roommate. Facilities must post notices, may not retaliate or refuse admission over monitoring, and no one may access recordings without the resident's written consent; recordings are the resident's property and may be shared only for health, safety or welfare concerns.

View Details →

Electronic Monitoring of Employees: Prior Notice

CT Employee Monitoring Notice
active

Jurisdiction: Connecticut

Authority: Connecticut Labor Commissioner

Employers that electronically monitor employees on their premises (computers, phones, cameras and similar means) must give prior written notice of the types of monitoring, which can be done by a conspicuous posting. Covert monitoring is allowed when there are reasonable grounds to suspect illegal conduct, rights violations or a hostile work environment.

View Details →

Electronic Protected Health Information of Minor: Disclosure to Legal Guardian

Iowa Minor ePHI Guardian Access Law
active

Jurisdiction: Iowa

Effective: 7/1/2024

Authority: Not specified in the section

This 2024 law requires Iowa health care providers and facilities to give a minor's legal guardian access to the minor's electronic health information, or a free printed copy instead. It does not cover care the minor may legally consent to alone, or disclosures barred by other state or federal law.

View Details →

Electronic stalking (unauthorized electronic tracking devices)

AL Electronic Stalking Law
active

Jurisdiction: Alabama

Effective: 9/1/2023

Authority: Alabama district attorneys and Attorney General (criminal prosecution)

Makes it a crime to place a GPS or other electronic tracking device on someone else's property without the owner's consent or legal authority. Doing so to surveil, stalk, or harass is a felony.

View Details →

Electronic Surveillance Act

LA Electronic Surveillance Act
active

Jurisdiction: Louisiana

Effective: 7/23/1985

Authority: District attorneys and courts (criminal); private civil actions

Louisiana's wiretap law makes it a crime to intercept wire, electronic, or oral communications, or to use or disclose intercepted contents, unless an exception applies. It is a one-party consent law: a private person may record a communication they take part in, or with one party's prior consent, unless the purpose is to commit a criminal, tortious, or other injurious act. Victims have a civil damages action.

View Details →

Electronic tracking of motor vehicles

Tenn. Vehicle Tracking Law
active

Jurisdiction: Tennessee

Authority: District attorneys (criminal prosecution)

Makes it a crime to knowingly install or hide an electronic tracking device on a motor vehicle to monitor its occupants without the consent of all owners, and bars lessors from tracking leased vehicles without the lessee's consent. Exceptions cover law enforcement investigations, parents monitoring a minor child in a vehicle they own or lease, stolen goods or stolen vehicles, and manufacturer-installed systems.

View Details →

Electronic Tracking of Motor Vehicles

RI Vehicle Tracking Law
active

Jurisdiction: Rhode Island

Authority: Prosecutors (criminal misdemeanor)

Makes it a crime to secretly put or use a GPS or other electronic tracking device on a vehicle to follow its driver or passengers without the consent of the operator and all occupants. Exceptions cover law enforcement investigations, parents tracking minor children in vehicles they own, theft-recovery devices, dealers with written consent in credit sales or leases, and businesses tracking their own fleet vehicles driven by employees or contractors.

View Details →

Employee Access to Personnel Files

NH Personnel File Access Law
active

Jurisdiction: New Hampshire

Authority: New Hampshire Department of Labor

Gives employees the right to inspect and copy their personnel files and to add a rebuttal statement that must travel with any disclosure of the disputed information. Health and lifestyle information gathered for wellness programs may not be kept in personnel files.

View Details →

Employee Access to Personnel Records

MN Personnel Records Act
active

Jurisdiction: Minnesota

Authority: Employees by civil action (181.965)

Gives Minnesota employees the right to review their personnel records on written request (once every six months) and former employees the right to a free copy, and lets employees dispute information and attach a position statement. Records improperly withheld from review generally cannot be used against the employee in later proceedings, and retaliation is prohibited.

View Details →

Employee and applicant social media account privacy

ORS 659A.330
active

Jurisdiction: Oregon

Authority: Oregon Bureau of Labor and Industries (ORS 659A.820)

Bars employers from demanding access to workers' or applicants' personal social media accounts, forcing them to add the employer as a contact, or punishing them for refusing. Employers may still investigate specific misconduct reports and view public content.

View Details →

Employee and applicant social media privacy

Lab. Code 980
active

Jurisdiction: California

Effective: 1/1/2013

Authority: Labor Commissioner; courts

Bars employers from requiring or asking employees or applicants for personal social media usernames and passwords, to open personal accounts in front of the employer, or to divulge personal social media, with limited exceptions for misconduct investigations and employer-issued devices.

View Details →

Employee Online Privacy Act of 2014

Tenn. Employee Online Privacy Act
active

Jurisdiction: Tennessee

Effective: 1/1/2015

Authority: Not specified in the act

Bars employers from requesting or requiring employees or applicants to disclose passwords to personal internet accounts, to add the employer as a contact, or to open a personal account in the employer's presence, and from retaliating when they refuse. Employers may still access employer-provided devices and accounts, investigate specific reports of misconduct or data leaks, monitor their own networks, and view public information.

View Details →

Employee Personnel and Medical Files

CT Personnel Files Act
active

Jurisdiction: Connecticut

Authority: Connecticut Labor Commissioner (investigations and subpoenas, 31-128j)

Gives current and former employees the right to inspect and copy their personnel files and medical records, requires medical records to be kept separately, and forbids employers from disclosing identifiable personnel or medical file information to outsiders without written authorization, subject to listed exceptions. Participation in employee assistance programs is also confidential.

View Details →

Employee photographs and fingerprints furnished to third parties

Lab. Code 1051
active

Jurisdiction: California

Authority: Local prosecutors

Makes it a misdemeanor to require employees or applicants, as a condition of employment, to be photographed or fingerprinted for the purpose of furnishing the images or prints to another employer or third party where they could be used to the worker's detriment. Often cited in biometric timekeeping cases.

View Details →

Employee social media account privacy

OK Social Media Password Law
active

Jurisdiction: Oklahoma

Effective: 11/1/2014

Authority: Private civil actions by employees and applicants

Bars Oklahoma employers from requiring employees or applicants to hand over personal social media usernames and passwords or to open private accounts in front of the employer, and from retaliating or refusing to hire over a refusal. Employers keep access to employer-provided devices and accounts and may investigate specific reports of misconduct or data leaks.

View Details →

Employee Social Media Privacy

RI Employee Social Media Privacy Act
active

Jurisdiction: Rhode Island

Authority: Courts via employee or applicant civil actions

Bars employers from requiring or asking employees and job applicants for passwords to personal social media accounts, from making them log in while the employer watches, from forcing them to add the employer as a contact or change privacy settings, and from punishing or refusing to hire anyone who says no.

View Details →

Employer Access to Employees' and Applicants' Personal Online Accounts

CT Social Media Password Law
active

Jurisdiction: Connecticut

Authority: Connecticut Labor Commissioner

Bars employers from requiring employees or job applicants to hand over passwords to personal online accounts, log in in front of them, or connect with them on social media, and from retaliating against those who refuse. Employer-provided accounts and devices and specific-information investigations are excepted.

View Details →

Employer access to employees' personal online accounts

Colorado social media password law
active

Jurisdiction: Colorado

Effective: 5/11/2013

Authority: Colorado Department of Labor and Employment (8-2-127(5))

Colorado employers may not ask or require employees or applicants to disclose usernames or passwords for personal online accounts on personal devices, or to add the employer as a contact or change privacy settings, and may not retaliate for refusal. Limited exceptions cover securities and financial compliance investigations and investigations of unauthorized downloads of proprietary data.

View Details →

Employer Access to Personal Social Media Accounts

MT Social Media Privacy (Employment)
active

Jurisdiction: Montana

Effective: 10/1/2015

Authority: Private action by employee or applicant in small claims court

Montana employers may not require or ask employees or applicants for personal social media usernames or passwords, to open accounts in front of them, or to hand over account content. Narrow exceptions apply to specific workplace-misconduct, data-theft and regulatory investigations. A 2023 amendment also bars retaliation for lawful free speech on personal social media, subject to written policies and contracts.

View Details →

Employer Access to Personal Social Media Accounts Prohibited

NJ Social Media Privacy (Employment) Law
active

Jurisdiction: New Jersey

Effective: 12/1/2013

Authority: New Jersey Commissioner of Labor and Workforce Development

New Jersey employers may not require or ask current or prospective employees to hand over usernames or passwords, or otherwise give access, to their personal social media accounts. Employers also may not retaliate against people who refuse or who report or oppose violations.

View Details →

Employer Electronic Surveillance of Restrooms, Locker Rooms and Lounges; Recording of Contract Negotiations

CT Workplace Surveillance Limits
active

Jurisdiction: Connecticut

Authority: Criminal prosecution

Forbids employers from using cameras or audio recording to monitor employees in areas meant for their health, comfort or belongings, such as restrooms, locker rooms and lounges, and bars either side from secretly recording employment contract negotiations without all parties' consent.

View Details →

Employer Genetic Testing Restrictions

Nebraska Employment Genetic Testing Law
active

Jurisdiction: Nebraska

Authority: Not stated in the section

This 2001 law bars Nebraska employers, unless federal law requires otherwise, from requiring genetic tests or genetic information as a condition of employment or promotion and from hiring, firing, or classifying workers based on genetic information unrelated to job duties. Employees may voluntarily share health-related genetic information for workplace safety.

View Details →

Employer restrictions on use of Social Security numbers

OK Employee SSN Protection
active

Jurisdiction: Oklahoma

Effective: 11/1/2004

Authority: Not specified in the section

Restricts how Oklahoma employers handle employee Social Security numbers: no public posting, no printing on access cards or mailed materials, and no transmission over the Internet without encryption or use as a sole website login. Employees may consent in writing to otherwise prohibited uses.

View Details →

Employer testing restrictions (polygraph, breathalyzer, psychological stress, brain-wave and genetic tests)

ORS 659A.300
active

Jurisdiction: Oregon

Authority: Oregon Bureau of Labor and Industries (ORS 659A.820); civil action under ORS 659A.885

Bars employers from subjecting workers or applicants to breathalyzer, polygraph, psychological stress, brain-wave or genetic tests, with narrow exceptions for consensual breath tests (or required tests on reasonable suspicion), consensual polygraphs in legal proceedings, and consented genetic tests for a bona fide occupational qualification.

View Details →

Employer use of credit history restricted

ORS 659A.320
active

Jurisdiction: Oregon

Authority: Oregon Bureau of Labor and Industries; civil action under ORS 659A.885

Bars most employers from obtaining or using consumer credit report information to make hiring, firing, promotion, pay or other employment decisions, unless an exception applies.

View Details →

Employer Use of Credit Reports

CT Employer Credit Check Law
active

Jurisdiction: Connecticut

Authority: Connecticut Labor Commissioner; Attorney General collects penalties

Prohibits employers from requiring employees or applicants to consent to a credit report as a condition of employment unless the employer is a financial institution, the report is legally required, the employer suspects job-related illegal conduct, or the report is substantially related to the job.

View Details →

Employer use of genetic information prohibited

ORS 659A.303
active

Jurisdiction: Oregon

Authority: Oregon Bureau of Labor and Industries (ORS 659A.820)

Makes it an unlawful employment practice to seek, obtain or use genetic information about a worker, applicant or their blood relative to discriminate or deny any job right or benefit.

View Details →

Employer Use of Social Media

DE Employee Social Media Privacy
active

Jurisdiction: Delaware

Effective: 8/7/2015

Authority: Not specified in the section

Bars Delaware employers from demanding access to employees' or applicants' personal social media, such as asking for passwords, requiring them to log in in front of the employer, or requiring them to add the employer as a contact. Employers may still investigate misconduct, access employer-provided devices and accounts, and view public information.

View Details →

Employer Use of Social Security Numbers

Nebraska Employee SSN Protection Law
active

Jurisdiction: Nebraska

Effective: 9/1/2008

Authority: County attorneys (criminal prosecution)

Enacted in LB674 (2007), this law restricts how Nebraska employers display and use employees' Social Security numbers. Employers may not post or share more than the last four digits publicly or with coworkers, use full SSNs as employee IDs or unsecured web logins, or keep them in unrestricted files.

View Details →

Employer Vehicle Tracking Device Notice Law

NJ Employee Vehicle Tracking Law
active

Jurisdiction: New Jersey

Effective: 4/18/2022

Authority: New Jersey Commissioner of Labor and Workforce Development

New Jersey employers must give employees written notice before knowingly using a tracking device in a vehicle the employee uses. Federal motor carrier rules on electronic devices are not displaced.

View Details →

Employment Based on Credit Information; Prohibitions

VT Employment Credit Check Law
active

Jurisdiction: Vermont

Authority: Vermont Attorney General or State's Attorneys (21 V.S.A. § 495b)

Bars most Vermont employers from asking about or basing employment decisions on an applicant's or employee's credit report or credit history. Exempt employers may not use credit as the sole factor, and must get written consent, explain adverse actions and keep reports confidential.

View Details →

Employment Opportunity Act (employer use of consumer credit information)

Colorado Employment Opportunity Act
active

Jurisdiction: Colorado

Effective: 7/1/2013

Authority: Colorado Department of Labor and Employment, Division of Labor Standards and Statistics (8-2-126(6))

Colorado employers may use consumer credit information for hiring or other employment decisions only when it is substantially related to the job, and may not require consent to a credit report except for banks, legally required reports, or disclosed bona fide job-related purposes. Employees must be told if credit information was the basis of an adverse action.

View Details →

Ensuring Likeness, Voice, and Image Security Act of 2024 (formerly Personal Rights Protection Act of 1984)

ELVIS Act
active

Jurisdiction: Tennessee

Authority: Private civil actions in chancery or circuit court; criminal prosecution for unauthorized commercial use

Tennessee's right-of-publicity statute gives every individual a property right in the use of their name, photograph, voice, and likeness. The 2024 ELVIS Act added voice (including simulated or AI-generated voice) as a protected right and created liability for publishing unauthorized voice or likeness replicas and for distributing tools whose primary purpose is cloning a particular person. Rights survive death and pass to heirs, subject to First Amendment fair-use exceptions.

View Details →

Event Data Recording Devices in Motor Vehicles

NH Event Data Recorder Law
active

Jurisdiction: New Hampshire

Effective: 7/1/2006

Authority: New Hampshire Attorney General (under RSA 358-A)

Requires manufacturers to disclose event data recorders in the owner's manual and makes the recorder and its data (speed, location, braking, seatbelt use, crash transmissions) the property of the vehicle owner. Others may retrieve the data only with owner consent, a court order, for servicing, or for emergency medical response; subscription services must disclose recording in their terms instead.

View Details →

Fabricated Media in Campaign Communications (election deepfake disclosure)

IN Election Deepfake Disclosure
active

Jurisdiction: Indiana

Effective: 3/12/2024

Authority: Private civil action by the depicted candidate

Enacted by HEA 1133 (2024), this chapter requires campaign ads with AI-generated or deceptively altered audio, images, or video of a candidate to carry a disclaimer that elements were 'digitally altered or artificially generated.' Candidates depicted in unlabeled fabricated media may sue.

View Details →

Facial recognition in job interviews

MD Facial Recognition Interview Law
active

Jurisdiction: Maryland

Effective: 10/1/2020

Authority: Not specified in § 3-717

Enacted by 2020 Md. Laws ch. 446 (HB 1202), this law bars employers from using facial recognition services to create a facial template during a job interview unless the applicant consents by signing a plain-language waiver.

View Details →

Fair Price Protection Act (surveillance pricing of groceries)

NJ Fair Price Protection Act
enacted_not_effective

Jurisdiction: New Jersey

Effective: 8/1/2027

Authority: New Jersey Attorney General / Division of Consumer Affairs (Consumer Fraud Act and a separate Attorney General civil action)

Signed July 23, 2026, this law bars retailers from using algorithms fed by personal data (including location, online activity, purchase history, biometric monitoring, or in-store sensors) to set individualized prices for groceries and household essentials. Cost-based price differences, publicly disclosed group discounts, and opt-in loyalty programs with uniform terms remain allowed. It also imposes a one-year moratorium on new electronic shelf labels.

View Details →

False or Misleading Commercial Electronic Mail Messages

MN Commercial Email Law
active

Jurisdiction: Minnesota

Effective: 3/1/2003

Authority: Injured recipients and email service providers by civil action; Attorney General remedies under 8.31 also preserved (325F.694, subd. 7)

Prohibits commercial email that spoofs a third party's domain, misrepresents its origin or path, or has a false or misleading subject line, and requires unsolicited commercial email to start the subject line with 'ADV' ('ADV-ADULT' for adult content) and to offer a toll-free number or return address for opt-outs. By its own terms the section expires when federal law preempting state regulation of such email takes effect; the federal CAN-SPAM Act (2003) preempts state email laws except those addressing falsity or deception, so the labeling and opt-out requirements are likely unenforceable while the anti-falsity provisions remain.

View Details →

Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006

Nebraska Data Breach Notification and Data Security Act
active

Jurisdiction: Nebraska

Effective: 7/14/2006

Authority: Nebraska Attorney General

Nebraska's breach law requires businesses and government entities that own or license computerized personal information to investigate a breach promptly and, if misuse has occurred or is reasonably likely, to notify affected residents and the Attorney General. Since 2018 it also requires reasonable security procedures, including for disposal, and contracts requiring vendors to safeguard the data. Notice to the Attorney General and the username/email-and-password element were added by LB835, effective July 21, 2016.

View Details →

Financial Privacy Act

OK Financial Privacy Act
active

Jurisdiction: Oklahoma

Authority: Courts (customer motions to quash); supervisory agencies

Protects the confidentiality of bank and credit union customer records against disclosure to Oklahoma government authorities. An institution may release a customer's records to state government only with the customer's written consent for the specific record or in response to a lawful subpoena, and the customer must receive a copy and may move to quash. A 2026 amendment (SB 2067, effective November 1, 2026) adds a disclosure exception for reporting suspected financial exploitation of protected adults.

View Details →

Financial Records Privacy Act

Tenn. FRPA
active

Jurisdiction: Tennessee

Authority: Courts (subpoena requirements); no enforcing agency identified in the reviewed sections

Prohibits financial institutions from disclosing a customer's financial records to anyone other than the customer or the customer's agent unless the customer authorizes it or a subpoena meeting the act's requirements is served. Listed exceptions cover supervisory examinations, tax reporting, credit information exchanges, anonymized data, suspected-crime reports to government, and (since October 1, 2024) records given to the TBI about suspected elder financial exploitation.

View Details →

Fingerprinting in connection with business transactions

VA fingerprint return
active

Jurisdiction: Virginia

Effective: 7/1/1999

Authority: Not stated in the section

Virginia's only general biometric-type rule for businesses: unless the parties agree otherwise, anyone who requires fingerprints in a business transaction must return or destroy the prints and all copies, including electronic copies, within 21 days after the transaction ends. Virginia has no BIPA-style biometric privacy statute; biometric data used to identify a person is otherwise 'sensitive data' under the VCDPA.

View Details →

Florida Consumer Collection Practices Act: Privacy-Related Prohibited Practices

FCCPA
active

Jurisdiction: Florida

Authority: Florida Office of Financial Regulation; private plaintiffs

Florida's debt collection law, which covers creditors as well as collection agencies. Several of its rules protect debtor privacy: limits on contacting employers, on disclosing debts to third parties, on publishing 'deadbeat lists' or using embarrassing envelopes, and a ban on contacting debtors between 9 p.m. and 8 a.m. without consent (revised in 2025 to exempt e-mails that otherwise comply).

View Details →

Florida Digital Bill of Rights

FDBR
active

Jurisdiction: Florida

Effective: 7/1/2024

Authority: Florida Department of Legal Affairs (Attorney General), exclusively (501.72(1))

Florida's comprehensive privacy law, enacted in SB 262 (2023). Unlike most state privacy laws, its core consumer-rights duties reach only very large companies (over $1 billion in revenue plus an ad-revenue, smart-speaker, or app-store test), but its rule against selling sensitive data without consent applies to for-profit businesses of any size. It also bars devices from surveilling users through voice, facial, video, or audio features when not in active use, and requires search engines to disclose ranking parameters, including political prioritization. The Attorney General's first enforcement action, against Roku (filed October 2025), was resolved in June 2026 with Roku committing to child-protection changes estimated at $25 million and no civil fine.

View Details →

Florida Electronic Health Records Exchange Act: Offshore Storage Restriction and Emergency Release

Florida EHR Data Localization Law
active

Jurisdiction: Florida

Effective: 7/1/2023

Authority: Florida Agency for Health Care Administration

Added by SB 264 (2023, ch. 2023-33), this subsection requires providers using certified EHR technology to keep all patient information stored offsite, including with cloud vendors, physically in the continental United States, its territories, or Canada. It adds to the HIPAA Security Rule.

View Details →

Florida Information Protection Act of 2014

FIPA
active

Jurisdiction: Florida

Effective: 7/1/2014

Authority: Florida Department of Legal Affairs (Attorney General)

Florida's data breach and data security law. It requires businesses to reasonably secure electronic personal information and dispose of customer records securely, and to notify affected Floridians and, for breaches affecting 500 or more Floridians, the Attorney General, within 30 days. Personal information includes biometric data and geolocation (added by SB 262, effective July 1, 2024).

View Details →

Florida Telemarketing Act

Florida Telemarketing Act
active

Jurisdiction: Florida

Authority: Florida Department of Agriculture and Consumer Services; state attorneys (criminal); private plaintiffs

Licenses commercial telemarketers and sets conduct rules. Since 2021 it limits solicitation calls to 8 a.m. to 8 p.m. in the called person's time zone, caps them at three calls in 24 hours on the same subject, and bars blocking or spoofing caller ID. Those call-conduct rules apply even to sellers otherwise exempt from the Act.

View Details →

Florida Telephone Solicitation Act (including the 'mini-TCPA' autodialer rule)

FTSA
active

Jurisdiction: Florida

Authority: Florida Department of Agriculture and Consumer Services; Department of Legal Affairs; private plaintiffs

Florida's telemarketing privacy law, which includes the state do-not-call list and, since 2021, a 'mini-TCPA' requiring prior express written consent for autodialed or prerecorded sales calls and texts. HB 761 (2023) narrowed the autodialer definition and added a pre-suit 'STOP' notice for text claims. Calls to Florida area codes are presumed to reach Florida residents.

View Details →

Fraudulent Electronic Misrepresentation (anti-phishing)

MT Anti-Phishing
active

Jurisdiction: Montana

Effective: 10/1/2007

Authority: Attorney General or county attorney (criminal); private plaintiffs (civil)

Montana's anti-phishing law makes it identity theft to use a website, email or other internet means to trick people into giving up personal information by pretending to be another person or business. Victims, including impersonated website and trademark owners, can sue.

View Details →

Fraudulent Use of Deepfakes (criminal offense and civil action)

NH Deepfake Law
active

Jurisdiction: New Hampshire

Effective: 1/1/2025

Authority: State prosecutors (criminal); injured individuals (civil)

Criminalizes knowingly making or spreading AI-altered video, audio or other media of a real, identifiable person to harm, harass, defame, entrap or extort them, and lets the person depicted sue for damages. Platforms hosting third-party content, news reports that flag authenticity doubts, and satire are exempt.

View Details →

Freedom from Unwarranted Surveillance Act (drones)

Florida Drone Surveillance Law
active

Jurisdiction: Florida

Authority: Private civil actions (for private-property surveillance); courts

Mainly limits police drone use, but it also bars any person from using a camera drone to record privately owned property or the people on it with intent to conduct surveillance in violation of their reasonable expectation of privacy, without written consent. People are presumed to have that expectation on private property when they cannot be seen from ground level.

View Details →

Generative AI in patient communications (AB 3030)

AB 3030
active

Jurisdiction: California

Effective: 1/1/2025

Authority: Medical Board of California, Osteopathic Medical Board, and California Department of Public Health (licensing enforcement)

Requires health care providers that use generative AI to write or speak to patients about clinical information to say so and to tell patients how to reach a human, unless a licensed provider reviewed the message first.

View Details →

Generative Artificial Intelligence Training Data Transparency (AB 2013)

AB 2013
active

Jurisdiction: California

Effective: 1/1/2025

Authority: Not specified in the title (general state enforcement)

Requires developers of generative AI systems available to Californians to post documentation on their websites summarizing the datasets used to train the system, including whether the data contain personal information or copyrighted material, where it came from, and how it was processed.

View Details →

Genetic Data Privacy (direct-to-consumer genetic testing companies)

VA Genetic Data Privacy
active

Jurisdiction: Virginia

Effective: 7/1/2023

Authority: Virginia Attorney General (exclusive, 59.1-601(A))

Regulates direct-to-consumer genetic testing companies. They must publish plain-language privacy summaries, get separate express consent for each use, sample storage, secondary use, third-party transfer, and genetic-data-based marketing, honor consent revocation within 30 days, secure the data, and let consumers access and delete it. Disclosure to insurers or employers requires express consent.

View Details →

Genetic Discrimination (consumer genetic testing)

IN Genetic Testing Nondiscrimination
active

Jurisdiction: Indiana

Effective: 5/6/2025

Authority: Not specified in the chapter

Enacted alongside the consumer genetic testing chapter, this law bars discrimination against a person for using consumer genetic testing services or because of the results. It covers denying goods or services, charging different rates, or suggesting either will happen.

View Details →

Genetic Discrimination Act (insurance)

MN Genetic Discrimination Act
active

Jurisdiction: Minnesota

Authority: Commissioner of Commerce, or Commissioner of Health for health plan companies it regulates (72A.139, subds. 2(a), 8)

Bars health plan companies from requiring or asking about genetic tests of applicants or their relatives, or using test results or refusals, in underwriting. Life insurers that require genetic tests must obtain written informed consent, notify the person of results, and pay for the test.

View Details →

Genetic Information (informed consent and confidentiality)

DE Genetic Privacy Law
active

Jurisdiction: Delaware

Effective: 7/17/1998

Authority: Superior Court (fines) and the affected individual (civil damages) (1208)

Requires written informed consent before anyone obtains, keeps, or discloses a person's identifiable genetic information, requires prompt destruction of samples unless an exception applies, and gives individuals the right to see and correct their genetic records. Exceptions cover criminal and death investigations, paternity, court orders, the state DNA database, newborn screening, and anonymous research.

View Details →

Genetic Information Amendments (genetic sequencing data and foreign adversaries)

Utah H.B. 182 (2026)
enacted_not_effective

Jurisdiction: Utah

Authority: Utah Attorney General (receives sworn compliance statements)

Bars medical and genomic research facilities from using genetic sequencers or software from foreign adversaries and from storing genetic sequencing data inside a foreign adversary. It requires encryption and access controls and sworn compliance statements to the Attorney General by December 31, 2028.

View Details →

Genetic Information and Automated Decision Tools in Employment (Fair Employment Practices Act)

CT Employment Genetic Info
active

Jurisdiction: Connecticut

Authority: Connecticut Commission on Human Rights and Opportunities (CHRO); courts after release

Makes it a discriminatory employment practice to request or require genetic information from employees, applicants or union members, or to discriminate based on it. From October 1, 2026, P.A. 26-15 adds that using an automated employment decision technology is no defense to a discrimination complaint.

View Details →

Genetic information and privacy in employment

LA Employment Genetic Privacy
active

Jurisdiction: Louisiana

Authority: Louisiana Commission on Human Rights; private civil actions under the Louisiana Employment Discrimination Law

Prohibits employment discrimination based on protected genetic information or requests for genetic services, bars employers from requiring, collecting, or buying employees' genetic information (with limited exceptions such as post-offer requests), and restricts disclosure. Genetic information must be kept as a confidential medical record separate from personnel files.

View Details →

Genetic Information Consent Requirement

MN Genetic Information (13.386)
active

Jurisdiction: Minnesota

Authority: Remedies under the Minnesota Government Data Practices Act, chapter 13 (see 325F.995, subd. 6)

Requires written informed consent before anyone, whether a government entity or any other person, collects genetic information about an individual, and limits its use, storage period, and dissemination to what the individual consented to. Dissemination consents must be signed and dated and generally last no more than one year. Genetic information held by government is private data.

View Details →

Genetic information disclosure protections and Genetic Research Studies Nondisclosure Act

OK Genetic Disclosure Laws
active

Jurisdiction: Oklahoma

Effective: 7/1/1998

Authority: Courts (subpoena and discovery limits)

Shields genetic information from compelled disclosure in judicial, legislative, or administrative proceedings except in listed situations (paternity, the person's own claims, insurance disputes, law enforcement or fraud). Research records of genetic study subjects are confidential, not subject to civil discovery, and may not go to employers or health insurers without informed consent.

View Details →

Genetic Information for Insurance Purposes

Florida Insurance Genetic Privacy Law
active

Jurisdiction: Florida

Authority: Florida Office of Insurance Regulation

Florida extended its genetic nondiscrimination rule from health insurance to life and long-term care insurance in 2020. Covered insurers cannot use genetic test results, absent a diagnosis, to cancel, limit, or deny coverage or set rates, and cannot require or solicit genetic information for any insurance purpose.

View Details →

Genetic Information in Employment (Labor Code Subchapter H)

Texas Employment Genetic Privacy
active

Jurisdiction: Texas

Effective: 9/1/1997

Authority: Texas Workforce Commission civil rights division (unlawful employment practices under ch. 21); Texas Attorney General (disclosure penalty)

Bars employers, unions, and employment agencies from discriminating based on genetic information or refusal to take a genetic test, makes genetic information confidential and privileged, and gives tested individuals a right to their results. Samples must be destroyed once their purpose is accomplished, with limited exceptions.

View Details →

Genetic information in employment (Maryland Fair Employment Practices Act)

MD FEPA genetic provisions
active

Jurisdiction: Maryland

Authority: Maryland Commission on Civil Rights; civil action after administrative exhaustion

Maryland's employment discrimination law bars employers from discriminating based on genetic information or an individual's refusal to take a genetic test or share results, and from requesting or requiring genetic tests or genetic information as a condition of hiring or benefits.

View Details →

Genetic information in health insurance

Colorado genetic information (health insurance)
active

Jurisdiction: Colorado

Effective: 7/1/2009

Authority: Colorado Commissioner of Insurance (Division of Insurance); private suits

Genetic information, including family history and genetic test results, is confidential and privileged in Colorado health insurance. Release for purposes other than diagnosis or treatment requires specific written consent, and health insurers may not seek, use, or keep genetic information for underwriting or require genetic tests.

View Details →

Genetic information in insurance

ORS 746.135
active

Jurisdiction: Oregon

Authority: Director of the Department of Consumer and Business Services

Requires specific written authorization before asking an insurance applicant to take a genetic test, bars using genetic information in health coverage decisions, and bars using a blood relative's genetic information for any insurance decision.

View Details →

Genetic Information in Insurance (genetic discrimination and DTC test data)

CT Insurance Genetic Privacy
active

Jurisdiction: Connecticut

Authority: Connecticut Insurance Commissioner (Connecticut Unfair Insurance Practices Act)

Bars health insurers from refusing, limiting or pricing coverage based on genetic information, and bars life, disability, long-term care and similar insurers from using direct-to-consumer genetic test results without the tested person's informed written consent or requiring genetic testing as a condition of coverage.

View Details →

Genetic information in insurance (health insurance genetic nondiscrimination and the Genetic Testing Protection Act)

MD Insurance Genetic Protections
active

Jurisdiction: Maryland

Authority: Maryland Insurance Commissioner (27-909(f), 27-909.1(d))

Health insurers may not use genetic tests or genetic information to deny, limit, or price coverage, may not require genetic tests to decide coverage, and may not release identifiable genetic information outside the plan and its providers without authorization. The 2025 Genetic Testing Protection Act adds that life and disability insurers may not access genetic data or other sensitive medical information without signed written consent or require genetic testing for eligibility.

View Details →

Genetic Information Privacy Act

Nebraska GIPA
active

Jurisdiction: Nebraska

Effective: 7/19/2024

Authority: Nebraska Attorney General

Enacted by LB308 (2024), this law regulates consumer DNA testing companies. It requires privacy notices, layered express consent for uses, transfers, sample retention, research, and marketing, a comprehensive security program, and consumer rights to access and delete genetic data and have samples destroyed.

View Details →

Genetic Information Privacy Act

GIPA
active

Jurisdiction: California

Effective: 1/1/2022

Authority: California Attorney General, district attorneys, and specified city attorneys; also on complaint of a person who suffered injury and lost money or property

Regulates direct-to-consumer genetic testing companies. It requires plain-language privacy notices, separate express consent for each use, storage, transfer, and marketing use of genetic data or samples, reasonable security, and ways for consumers to access and delete data and have samples destroyed. It also bars sharing genetic data with health, life, disability, or long-term care insurers or employers.

View Details →

Genetic Information Privacy Act

Tenn. GIPA
active

Jurisdiction: Tennessee

Effective: 7/1/2023

Authority: Division of Consumer Affairs, Office of the Tennessee Attorney General and Reporter (complaints and rulemaking)

Regulates direct-to-consumer genetic testing companies. They must give clear notice of their genetic data practices, get express consent to collect and use genetic data, get separate consent for third-party transfers, secondary uses, sample retention, and genetic-data-based marketing, and let consumers access and delete their data and have samples destroyed. Disclosure to insurers or employers needs written consent, and law enforcement access requires valid legal process.

View Details →

Genetic Information Privacy Act

VT GIPA
active

Jurisdiction: Vermont

Effective: 7/1/2026

Authority: Vermont Attorney General (Consumer Protection Act); consumers

Vermont's 2026 genetic privacy law requires direct-to-consumer genetic testing companies to publish plain-language privacy terms, get separate express consent for each use, storage or transfer of genetic data and samples, protect the data, and let consumers access and delete data and destroy samples. It bans disclosing genetic data to insurers or employers, and requires a warrant or the consumer's consent before disclosure to the government.

View Details →

Genetic Information Privacy Act (direct-to-consumer genetic testing)

RI GIPA
active

Jurisdiction: Rhode Island

Effective: 6/19/2026

Authority: Rhode Island Attorney General (exclusive)

Enacted in June 2026 and effective on passage, this law regulates consumer genetic testing companies such as ancestry and health DNA services. They must publish plain-language privacy information, get separate express consent for each use, storage, transfer and genetic-based marketing, let consumers access and delete data and destroy samples, secure genetic data, and not share it with insurers or employers.

View Details →

Genetic Information Privacy Act (including 2025 neurotechnology data amendments)

MT GIPA
active

Jurisdiction: Montana

Effective: 10/1/2023

Authority: Montana Attorney General (sole authority; 30-23-106(1))

Montana's direct-to-consumer genetic privacy law requires consent, notice, security and consumer control over genetic data and biological samples. A 2025 amendment (SB 163) extended every protection to neurotechnology (neural) data, making Montana one of the first states to regulate neural data this way. It also bars storing covered data in sanctioned or foreign-adversary countries and requires consent to store it outside the United States.

View Details →

Genetic Information Privacy Act (Part 1) and Genetic Testing and Procedure Privacy Act (Part 2)

Utah GIPA
active

Jurisdiction: Utah

Effective: 5/5/2021

Authority: Utah Attorney General

Part 1 regulates direct-to-consumer genetic testing companies: public privacy notice, express consent for use and sharing, separate consent for transfers, secondary uses, sample retention and marketing, and consumer access and deletion. Part 2 restricts employer and health-insurer use of genetic testing information and carries a private right of action.

View Details →

Genetic information privacy in health insurance

VA insurance genetic privacy
active

Jurisdiction: Virginia

Effective: 7/1/1996

Authority: State Corporation Commission, Bureau of Insurance

Bars health insurers, health plans, and HMOs from using genetic information, or a request for genetic services, to deny, limit, cancel, condition, exclude, rate, or add waiting periods or riders to coverage, and bars agent commission differences based on genetic characteristics.

View Details →

Genetic Nondiscrimination in Employment Act

OK Genetic Employment Act
active

Jurisdiction: Oklahoma

Effective: 7/1/1998

Authority: District attorneys (criminal prosecution)

Prohibits employers from seeking, using, or requiring genetic tests or genetic test results to distinguish between, discriminate against, or restrict the rights of employees or job applicants, other than for insurance coverage determinations.

View Details →

Genetic Nondiscrimination in Insurance Act

OK GNIA
active

Jurisdiction: Oklahoma

Effective: 7/1/1998

Authority: Oklahoma Insurance Commissioner

Bars health insurers from using genetic information (including family history and requests for genetic services) to deny, condition, or price coverage, and from requesting, requiring, or purchasing genetic information for underwriting or before enrollment. Insurers may not require genetic tests, with a narrow voluntary research exception.

View Details →

Genetic Screening or Testing (health insurance)

IN Insurance Genetic Testing
active

Jurisdiction: Indiana

Effective: 1/1/1998

Authority: Indiana Insurance Commissioner (IC 27-8-26-10)

Indiana bars health insurers and HMOs from requiring genetic tests, asking about genetic test results, or using those results to deny, cancel, limit, or price coverage. Favorable results that an applicant volunteers may be considered.

View Details →

Genetic Sequencing Foreign Adversary Restrictions

Nebraska Genetic Sequencing Security Law
active

Jurisdiction: Nebraska

Effective: 10/1/2025

Authority: Not stated in these sections

Enacted in LB644 (2025), this law bars Nebraska medical and research facilities from using genetic sequencers or sequencing software produced by foreign adversaries (as listed in 15 C.F.R. 791.4) or their state-owned or domiciled businesses, and requires existing equipment to be disabled or removed. Genetic sequencing data used in Nebraska may not be stored in, or remotely accessed from, a foreign adversary country.

View Details →

Genetic Test Protections in Health and Disability Insurance

KY Insurance Genetic Testing
active

Jurisdiction: Kentucky

Effective: 4/10/1998

Authority: Kentucky Department of Insurance (Commissioner)

Bars health plans and insurers from denying, cancelling, refusing to renew, or re-pricing coverage based on a genetic test for an unmanifested condition or on use of genetic services. Health and disability insurers may not ask applicants or members to disclose genetic test results, and health insurers may not disclose a member's genetic test without separate prior authorization for each disclosure.

View Details →

Genetic Testing

NH Genetic Testing Law
active

Jurisdiction: New Hampshire

Effective: 1/1/1996

Authority: Courts, through individual civil actions

Requires prior written informed consent before genetic testing and before disclosing that someone was tested or the results, with narrow exceptions (paternity, newborn screening, criminal investigations, medical examiner, clinical care). It bars employers and licensing bodies from requiring or using genetic tests and bars health insurers from requesting, requiring or rating on genetic test information.

View Details →

Genetic Testing (employment, consent, and health insurance protections)

Iowa Genetic Testing Law
active

Jurisdiction: Iowa

Effective: 7/1/1992

Authority: Civil actions by aggrieved individuals; injunctions may also be sought by the county attorney or Attorney General; the Commissioner of Insurance for the insurance provisions (unfair insurance trade practice under 507B.4)

Iowa bans employers, employment agencies, unions, and licensing agencies from requiring or administering genetic tests or taking action based on them, and requires informed written consent before anyone obtains genetic samples or tests, collects, keeps, shares, or uses genetic information, with limited exceptions. Health insurers may not release genetic information without written authorization or use it for underwriting.

View Details →

Genetic Testing and Genetic Information in Health Insurance

RI Health Insurance Genetic Privacy
active

Jurisdiction: Rhode Island

Authority: Rhode Island Department of Business Regulation / Office of the Health Insurance Commissioner

Parallel provisions across Rhode Island's health insurance chapters forbid health insurers, hospital and medical service corporations and HMOs from using genetic tests or genetic information in coverage, pricing or eligibility decisions, from requiring or asking about genetic tests, and from releasing genetic results without the person's written authorization for each disclosure.

View Details →

Genetic Testing as a Condition of Employment

RI Employment Genetic Testing Law
active

Jurisdiction: Rhode Island

Authority: Courts via employee or applicant civil actions

Bars employers, employment agencies and licensing agencies from requiring or administering genetic tests, from penalizing workers or applicants who refuse to take a test, give family health history or reveal results, and from using or revealing genetic information against them.

View Details →

Genetic testing for cancer predisposition in health benefit plans

AL Cancer Genetic Test Insurance Law
active

Jurisdiction: Alabama

Authority: Alabama Commissioner of Insurance

Bars health benefit plans from requiring a genetic test for cancer predisposition as a condition of coverage, and from using such test results to decide insurability or to discriminate in rates or benefits. It is narrow: it covers only genetic tests showing a predisposition to cancer.

View Details →

Genetic Testing in Employment

MN Employment Genetic Testing
active

Jurisdiction: Minnesota

Authority: Private civil action by aggrieved persons (181.974, subd. 3)

Prohibits employers and employment agencies from administering genetic tests, or requesting, requiring, or collecting genetic information about a person or the person's blood relatives, as a condition of employment, and from basing employment decisions on such information. Third parties may not supply or interpret that information for employers.

View Details →

Genetic testing in group disability, long-term care, life, and individual disability insurance

Colorado genetic testing (other insurance)
active

Jurisdiction: Colorado

Effective: 6/2/1994

Authority: Colorado Commissioner of Insurance (Division of Insurance); private suits

Genetic test information is confidential and privileged and may be released for non-treatment purposes only with written consent. Group disability and long-term care insurers may not use it for underwriting, and life and individual disability insurers need specific written informed consent before requiring or performing a genetic test.

View Details →

Genetic testing or genetic characteristics as a condition of employment

VA employer genetic testing
active

Jurisdiction: Virginia

Effective: 7/1/2002

Authority: Employees by private action (the Department of Labor and Industry is not required to investigate) (40.1-28.7:1(B)-(C))

Bars employers from requesting, requiring, or administering genetic tests as a condition of employment and from taking adverse employment action based solely on a genetic characteristic or genetic test result, however obtained.

View Details →

Genetic Testing Protections

VT Genetic Testing Law
active

Jurisdiction: Vermont

Effective: 1/1/1999

Authority: Courts (private actions); criminal prosecution; Department of Financial Regulation for insurance (8 V.S.A. § 4724)

Bars compulsory genetic testing except in listed cases such as parentage, newborn screening, criminal investigations and the DNA data bank. Genetic testing needs prior written informed consent, and results may be disclosed only with written authorization. Employers, unions, licensing bodies and insurers may not require or use genetic tests or genetic information.

View Details →

Genetic Testing; Express Consent; Confidentiality (DNA analysis)

Florida Genetic Privacy Law
active

Jurisdiction: Florida

Authority: State attorneys (criminal penalties under s. 817.5655)

Requires express consent before anyone performs DNA analysis on a person, and makes the results the tested person's exclusive property, confidential, and not disclosable without express consent. Anyone who performs the analysis or receives results must tell the person and say whether the results were used in insurance, employment, lending, credit, or education decisions.

View Details →

Genetics-Based Discrimination Prohibited (health insurance, life insurance and annuities)

DE Insurance Genetic Nondiscrimination
active

Jurisdiction: Delaware

Authority: Delaware Insurance Commissioner

Bars insurers from discriminating in issuing, renewing, or pricing insurance based on genetic characteristics or genetic information. A 2024 law adds life insurance and annuity rules: no adverse decisions based solely on genetic test results outside the medical record, no requesting genetic tests, and no obtaining direct-to-consumer genetic testing data without written informed consent under 16 Del. C. § 1202.

View Details →

Harassment by Nonconsensual Dissemination of Nude or Sexual Visual Depictions (including digitally created depictions)

Iowa Criminal NCII and Deepfake Law
active

Jurisdiction: Iowa

Authority: County attorneys and the Attorney General (criminal prosecution)

Iowa's harassment statute makes nonconsensual sharing of nude or sexual images a first-degree harassment crime. A 2024 amendment extends it to images that were created, adapted, or modified from a recognizable person's face or likeness, which covers AI-generated sexual deepfakes, and requires adult offenders to register as sex offenders.

View Details →

Health and Location Data Privacy: family planning centers and geofencing health care providers

Health & Location Privacy (AB 45)
active

Jurisdiction: California

Effective: 1/1/2026

Authority: California Attorney General; aggrieved persons and family planning centers

Prohibits collecting, using, selling, sharing, or keeping personal information of people at or within a precise geolocation (1,850-foot radius) of a family planning center except as needed to provide requested goods or services, and bans geofencing in-person health care providers to track, collect data from, notify, or advertise to patients or staff. AB 45 (2025) also shields identifiable health research records from out-of-state and law-enforcement demands tied to reproductive care.

View Details →

Health Care Information Privacy Requirements for Providers Subject to HIPAA (including 2026 electronic health record result release)

MT HIPAA Provider Privacy Law
active

Jurisdiction: Montana

Effective: 10/1/2003

Authority: Private plaintiffs (50-16-817)

This part supplements HIPAA for Montana providers covered by it, setting state rules on disclosures (for example to workers' compensation insurers and law enforcement), compulsory process and fees. HB 590 (Ch. 694, L. 2025), effective July 1, 2026, bars information blocking by providers ordering lab tests and requires certain sensitive results, including genetic-marker tests and positive HIV tests, to be released in the patient's electronic health record within 72 hours of finalization unless released earlier.

View Details →

Health facility reporting of unauthorized access to medical information

HSC 1280.15
active

Jurisdiction: California

Effective: 1/1/2009

Authority: California Department of Public Health

Requires licensed health facilities to prevent unauthorized access to patients' medical information and to report any unlawful or unauthorized access, use, or disclosure to the Department of Public Health and to the affected patient within 15 business days of detection.

View Details →

Health Insurance Carrier Encryption of Personal Information

NJ Health Carrier Encryption Law
active

Jurisdiction: New Jersey

Effective: 8/1/2015

Authority: New Jersey Attorney General / Division of Consumer Affairs (Consumer Fraud Act)

Health insurance carriers may not keep personal information (name plus SSN, driver's license number, address, or identifiable health information) on laptops, desktops, mobile devices, or removable media, or send it over public networks, unless it is encrypted or otherwise unreadable. Password protection alone is not enough.

View Details →

Health insurance genetic information protections

LA Health Insurance Genetic Privacy
active

Jurisdiction: Louisiana

Authority: Private civil actions; Louisiana Commissioner of Insurance

Bars health insurers from using genetic information, genetic services, or refusal of a genetic test to terminate, limit, or price coverage, and requires written informed consent before obtaining genetic information or a DNA sample. It declares an insured's genetic information the insured's property and forbids retaining it without authorization. Violations carry some of the largest statutory damages of any U.S. genetic privacy law.

View Details →

Health Insurance Genetic Testing Prohibition

Nebraska Insurance Genetic Testing Law
active

Jurisdiction: Nebraska

Authority: Nebraska Department of Insurance

This 2001 law bars health insurers and non-preempted self-funded plans from requiring covered persons, dependents, or asymptomatic applicants to undergo genetic testing before issuing, renewing, or continuing coverage. Insurers may still ask about family history.

View Details →

Health insurance utilization review: use of artificial intelligence

MD AI Utilization Review Law
active

Jurisdiction: Maryland

Effective: 10/1/2025

Authority: Maryland Insurance Commissioner

Enacted by 2025 Md. Laws ch. 747 (HB 820), this law sets guardrails on AI and algorithms used by health insurers and their review agents to decide whether care is medically necessary. Tools must rely on the individual patient's clinical information rather than group data alone, may not deny, delay, or modify care, must not discriminate, must be auditable by the Commissioner, and may not use patient data beyond its stated purpose. Carriers must also report whether AI was used in adverse decisions.

View Details →

Health Records (patient access, confidentiality, and retention)

IN Health Records
active

Jurisdiction: Indiana

Authority: Indiana Department of Health (fines for access violations); professional licensing boards (retention); Department of Insurance (copy fee rules)

Indiana's health records article gives patients a right to copies of their records and sets confidentiality rules for mental health records. It requires written consents with specified content, limits providers' business use of records, and requires providers to keep records for seven years. Since July 1, 2025, providers may not charge for digital copies or interoperability access to electronic health records.

View Details →

Health Records and Identifying Information Protection (abandoned records)

IN Abandoned Records
active

Jurisdiction: Indiana

Authority: Indiana Attorney General

When a health care provider or regulated professional abandons patient health records or other records containing personal information (including by treating them recklessly or negligently so strangers can reach them), the Attorney General may take, store, protect, and eventually destroy them. The AG notifies affected people and recovers costs from the provider.

View Details →

Health records privacy

VA health records privacy
active

Jurisdiction: Virginia

Effective: 7/1/1997

Authority: Not stated in the section; enforced through health regulatory boards and courts

Recognizes an individual's right of privacy in the content of his or her health records and bars health care entities from disclosing them except as the section or other state law allows. Patients may obtain their records (with audit trails on request) and direct transfers to other providers, and recipients may not redisclose records beyond the authorized purpose without specific authorization.

View Details →

Healthcare professional disclosure of AI transcription of patient encounters

LA AI Medical Transcription Disclosure
active

Jurisdiction: Louisiana

Effective: 8/1/2026

Authority: The professional's licensing board

Requires licensed healthcare professionals to tell patients out loud, before recording any part of an appointment or treatment, that a recording device, software, or service will be used and the recording transcribed by artificial intelligence. Violations are handled by licensing boards rather than lawsuits.

View Details →

Healthier Social Media Use by Youth (social media warnings for minors)

HB 24-1136
enjoined

Jurisdiction: Colorado

Effective: 1/1/2026

Authority: Colorado Attorney General

HB 24-1136 would require large social media platforms, from January 1, 2026, to show users who say they are under 18 research-based pop-up information about social media's effects on youth after one hour of use in a day or when on between 10 p.m. and 6 a.m., repeating every 30 minutes. The U.S. District Court for Colorado preliminarily enjoined enforcement on November 6, 2025 in NetChoice v. Weiser on First Amendment compelled-speech grounds; the state appealed to the Tenth Circuit (No. 25-1456).

View Details →

Higher Education Student Information Protection Act (AB 1159, 2026)

HESIPA
enacted_not_effective

Jurisdiction: California

Effective: 7/1/2027

Authority: California Attorney General and local prosecutors; students actually harmed

Extends K-12-style student data protections to college and university students: limits on targeted advertising, profiling, sale, disclosure, and AI training using student data, plus security and deletion duties. Operative July 1, 2027.

View Details →

HIV Testing and Counseling (consent and confidentiality)

DE HIV Test Confidentiality
active

Jurisdiction: Delaware

Authority: Aggrieved persons in Superior Court; the Attorney General may also sue (718)

Sets consent rules for HIV testing (routine opt-out testing in clinical settings with notice and a chance to refuse; written informed consent in nonclinical settings; minors 12 and older may consent) and bars disclosure of the identity of anyone tested or of identifiable HIV-related test results except to listed recipients, including redisclosure by recipients.

View Details →

HIV Testing Confidentiality and Anti-Discrimination

RI HIV Confidentiality Law
active

Jurisdiction: Rhode Island

Authority: Courts via private actions; Department of Health

Makes it unlawful to disclose a person's HIV test results to a third party without prior written consent, apart from listed reporting and treatment exceptions, and requires record holders to secure HIV information. It also requires advance notice to the person of certain permitted disclosures and bans HIV-based discrimination, including requiring HIV tests as a condition of employment.

View Details →

HIV Testing Consent and Test Result Confidentiality

KY HIV Confidentiality
active

Jurisdiction: Kentucky

Effective: 7/13/1990

Authority: Prosecutors (criminal penalty); Cabinet for Health and Family Services for public-health reporting

Requires informed consent before HIV testing (a general medical consent suffices if it tells the patient HIV testing may be ordered) and requires confirmatory testing before a positive result is revealed. Anyone who knows an HIV test result may not disclose the tested person's identity or identifiable results except to listed recipients such as the patient, persons named in a release, treating providers, and public health authorities.

View Details →

HIV Testing for Insurance Act

DE HIV Testing for Insurance Act
active

Jurisdiction: Delaware

Authority: Delaware Insurance Commissioner

Requires insurers to get an applicant's prior written informed consent before HIV testing, and limits disclosure of applicants' HIV test results to the applicant's consent and narrow insurance purposes such as reinsurers and contracted medical personnel.

View Details →

HIV Testing: Informed Consent and Confidentiality of Results

Florida HIV Test Confidentiality Law
active

Jurisdiction: Florida

Authority: Florida Department of Health; licensing boards; state attorneys

Requires informed consent for HIV testing and makes the identity of anyone tested, and their results, confidential. Results may be disclosed only to listed persons, and each authorized disclosure must carry a written warning against re-disclosure.

View Details →

HIV-Related Test Confidentiality

Iowa HIV Confidentiality Law
active

Jurisdiction: Iowa

Authority: Aggrieved individuals (civil action); Iowa Attorney General (civil enforcement)

Iowa treats HIV-related test information as strictly confidential medical information. Test results may be released only to the person tested, to people with the subject's written release, to treating providers and staff with a medical need to know, to public health authorities, and under narrow court orders that use pseudonyms and weigh privacy interests.

View Details →

Hospital and health center protection of immigration status and country-of-birth information

SB 1570 (2026)
active

Jurisdiction: Oregon

Effective: 6/5/2026

Authority: Not specified in the act

Requires hospitals and federally qualified health centers to protect patients' citizenship, immigration status and country-of-birth information the same way as protected health information, and bars disclosing it for law enforcement purposes unless law or a court order requires. The act also requires hospitals to adopt policies for responding to law enforcement visits.

View Details →

Hospital Patient Records; Confidentiality

Florida Hospital Records Law
active

Jurisdiction: Florida

Authority: Florida Agency for Health Care Administration

The facility-level counterpart to the practitioner records law. Licensed hospitals must give patients copies of their records after discharge on written request, and must keep patient records confidential unless the patient or representative consents or a listed exception applies.

View Details →

Human Immunodeficiency Virus Education, Prevention, and Control (HIV testing confidentiality)

NH HIV Confidentiality Law
active

Jurisdiction: New Hampshire

Effective: 4/30/1988

Authority: NH Department of Health and Human Services; prosecutors; individual civil suits

Requires consent for HIV testing (with limited exceptions) and keeps the identity of people tested and their results confidential. Any entity, public or private, holding HIV test information must protect it from unwarranted disclosure, and it may be shared only with written authorization or in narrow clinical, blood-supply and public-health situations.

View Details →

Identity Deception (criminal identity theft)

IN Identity Deception
active

Jurisdiction: Indiana

Authority: County prosecutors; the Attorney General's Identity Theft Unit assists victims (IC 4-6-13)

Indiana's core identity theft crime covers obtaining, possessing, transferring, or using someone's identifying information, with intent to harm or defraud, to pose as that person. It is the offense referenced by the breach notification law's risk-of-harm trigger and by the identity theft victim protections in IC 24-5-26.

View Details →

Identity fraud: artificial intelligence and deepfake representations

MD AI Deepfake Identity Fraud Law
enacted_not_effective

Jurisdiction: Maryland

Effective: 10/1/2026

Authority: State's Attorneys (criminal); victims (civil action)

Enacted by 2026 Md. Laws ch. 445 (SB 8), this amendment to Maryland's identity fraud statute makes it a crime to knowingly and fraudulently use AI or a deepfake to impersonate or falsely depict someone to cause harm, or to create false records to cause harm, obtain personal identifying information, or obtain something of value. It also lets victims sue for injunctive relief.

View Details →

Identity theft

OK Identity Theft Law
active

Jurisdiction: Oklahoma

Effective: 5/3/1999

Authority: District attorneys (criminal); victims (civil action)

Criminalizes fraudulently obtaining or using another person's identifying information (name, SSN, date of birth, account and driver license numbers, and similar data) to obtain money, credit, or other benefits, and gives victims a civil damages action. Local law enforcement must take identity theft incident reports.

View Details →

Identity Theft (civil remedies)

NH Identity Theft Act
active

Jurisdiction: New Hampshire

Effective: 1/1/2008

Authority: Victims through civil actions

Creates a civil cause of action against anyone who, with fraudulent intent and without permission, obtains, records, possesses or uses another person's personal information or financial device. Victims can use court orders or convictions to clear fraudulent accounts and judgments.

View Details →

Identity Theft (duties to identity theft victims)

IN Identity Theft Victim Protections
active

Jurisdiction: Indiana

Authority: Indiana Attorney General

This chapter protects identity theft victims: businesses may not deny credit or utility service, or cut credit limits, solely because a documented victim was defrauded. It also restricts unsolicited credit offers, such as convenience checks, that carry personal identifying information.

View Details →

Identity Theft Enforcement and Protection Act (breach notification and sensitive personal information protection)

Texas Breach Notification Law
active

Jurisdiction: Texas

Effective: 4/1/2009

Authority: Texas Attorney General

Requires businesses to protect and properly destroy sensitive personal information and to notify affected individuals and, for breaches affecting 250 or more Texans, the attorney general. Notice to individuals is due within 60 days and to the attorney general within 30 days of determining that a breach occurred.

View Details →

Identity Theft Impediments: Credit Card Address Changes

MT Credit Card ID Theft Impediments
active

Jurisdiction: Montana

Effective: 10/1/2005

Authority: Montana Department of Justice, Office of Consumer Protection (Attorney General)

To curb identity theft, credit card issuers must verify address changes on returned card applications that differ from the solicitation address, and must send change-of-address notices to the old address when a replacement card is requested close to an address change.

View Details →

Identity Theft Prevention Act: Credit Report Security Freeze and Identity Theft Victim Credit Protection

NJ Security Freeze Law
active

Jurisdiction: New Jersey

Effective: 1/1/2006

Authority: Consumers through private suits (56:11-50); Commissioner of Banking and Insurance for creditor penalties (56:11-52)

Consumers can place, lift, or remove a security freeze on their credit reports at New Jersey consumer reporting agencies, which must act within set deadlines and, since December 2018, may not charge any fee. Agencies must confirm changes to key identifying data while a freeze is in place, and creditors may not deny or cut credit solely because someone was an identity theft victim.

View Details →

Identity Theft Prevention Act: Data Breach Notification

NJ Breach Notification Law
active

Jurisdiction: New Jersey

Effective: 1/1/2006

Authority: New Jersey Attorney General / Division of Consumer Affairs (Consumer Fraud Act); breaches are reported first to the Division of State Police

New Jersey's breach law requires businesses and public entities to notify New Jersey residents whose unencrypted personal information was, or is reasonably believed to have been, accessed by an unauthorized person, unless misuse is not reasonably possible. The New Jersey State Police must be notified before consumers, and consumer reporting agencies must be notified when more than 1,000 people are affected.

View Details →

Identity Theft Prevention Act: Record Disposal and Social Security Number Protection

NJ SSN and Disposal Law
active

Jurisdiction: New Jersey

Effective: 1/1/2006

Authority: New Jersey Attorney General / Division of Consumer Affairs (Consumer Fraud Act)

Businesses and public entities must destroy customer records containing personal information so the data is unreadable when the records are no longer kept. Anyone is barred from publicly posting Social Security numbers (or four or more consecutive digits), printing them on mailings or access cards, or requiring their transmission or use online without security.

View Details →

Identity theft victim rights (police reports and creditor records)

LA Identity Theft Victim Law
active

Jurisdiction: Louisiana

Authority: None specified

Lets identity theft victims file police reports with the Attorney General or local police where they live, and requires creditors that extended credit to an identity thief to give the victim the application and transaction records needed to undo the fraud, after the victim submits a signed statement, police report, and ID.

View Details →

Identity Theft: Civil Cause of Action

Iowa Identity Theft Civil Remedy
active

Jurisdiction: Iowa

Authority: Victims and financial institutions (civil action)

Iowa gives identity theft victims who lose money a civil claim against the thief for the greater of $5,000 or triple damages, plus credit repair costs and attorney fees. Banks and insurers can sue on behalf of account holders.

View Details →

Illinois Biometric Information Privacy Act

BIPA
active

Jurisdiction: Illinois

Effective: 10/3/2008

Authority: Private right of action

Max Fine: ,000-,000 per violation (private lawsuits)

Most aggressive US biometric privacy law. Requires informed written consent before collecting biometric identifiers. Private right of action has generated billions in settlements (Meta M, Google M, TikTok M).

biometricfingerprintsfacial_recognitionconsentretention
View Details →

Impersonation and Identity Fraud (including digital forgery)

RI Identity Fraud Law
active

Jurisdiction: Rhode Island

Authority: Prosecutors

Rhode Island's criminal identity fraud statute. It covers producing or trafficking false IDs, using another person's means of identification (including biometric data) or financial information to defraud, and impersonating a person or entity with intent to defraud. A 2026 amendment added 'digital forgery': creating or distributing AI-generated or other forged likenesses or voice recordings of real people to facilitate fraud.

View Details →

Indiana Consumer Data Protection Act

INCDPA
active

Jurisdiction: Indiana

Effective: 1/1/2026

Authority: Indiana Attorney General (exclusive authority, IC 24-15-10-1)

Max Fine: Up to ,500 per violation

Indiana's comprehensive consumer privacy law, modeled on Virginia's, took effect January 1, 2026. It gives Indiana residents rights to confirm and access, correct, delete, and obtain a copy or representative summary of their personal data, and to opt out of targeted advertising, sale, and significant profiling. Controllers must get opt-in consent for sensitive data, publish a privacy notice, maintain reasonable security, and conduct data protection impact assessments for high-risk processing.

consumer_rightsopt_out
View Details →

Information Security Program and Security Event Notification for Financial Services Licensees

RI Licensee Information Security Law
active

Jurisdiction: Rhode Island

Effective: 7/2/2025

Authority: Rhode Island Department of Business Regulation, Division of Banking (director)

Enacted in 2025 and modeled on the FTC Safeguards Rule, this law requires non-bank financial services licensees to keep a written, risk-based information security program for customer information, including encryption, multi-factor authentication, annual penetration testing, secure disposal and an incident response plan. Licensees must report qualifying security events to the Division of Banking within three business days.

View Details →

Installation or Use of Tracking Devices or Tracking Applications

Florida Tracking Device Law
active

Jurisdiction: Florida

Authority: State attorneys (criminal)

Makes it a crime to knowingly install a tracking device or app on another person's property, or to use one to follow someone's location or movement, without consent. Consent is presumed revoked once a divorce petition or protective injunction is filed between the parties. Good-faith business use for a legitimate purpose is exempt.

View Details →

Insurance Code Privacy Chapter (Gramm-Leach-Bliley implementation)

Texas Insurance Privacy Law
active

Jurisdiction: Texas

Effective: 4/1/2005

Authority: Texas Department of Insurance; Texas Attorney General after conferring with the Commissioner

Makes insurers and other TDI-authorized entities comply with the Gramm-Leach-Bliley Act's privacy notice and opt-out rules (15 U.S.C. 6802-6803) as if they were financial institutions, and directs the Commissioner to adopt privacy rules and safeguard standards.

View Details →

Insurance Data Security

IN Insurance Data Security
active

Jurisdiction: Indiana

Effective: 7/1/2021

Authority: Indiana Insurance Commissioner / Department of Insurance

Indiana's version of the NAIC Insurance Data Security Model Law requires insurance licensees to run a written, risk-based information security program, oversee vendors, and keep an incident response plan. They must investigate cybersecurity events and notify the Insurance Commissioner within three business days of certain events. Consumer notice follows the general breach law, IC 24-4.9.

View Details →

Insurance Data Security Act

DE Insurance Data Security Act
active

Jurisdiction: Delaware

Effective: 7/31/2019

Authority: Delaware Insurance Commissioner (8607, 8610)

Delaware's version of the NAIC model law requires insurance licensees to run a written, risk-based information security program, investigate cybersecurity events, and notify the Insurance Commissioner within 3 business days and affected consumers within 60 days. Domestic insurers must certify compliance to the Commissioner each year.

View Details →

Insurance Data Security Act

OK IDSA
active

Jurisdiction: Oklahoma

Effective: 7/1/2024

Authority: Oklahoma Insurance Commissioner

Oklahoma's version of the NAIC Insurance Data Security Model Law. Insurance licensees must maintain a risk-based written information security program with an incident response plan and vendor oversight, investigate cybersecurity events, and notify the Insurance Commissioner within three business days of determining a qualifying event, while notifying consumers under the Security Breach Notification Act. It is the exclusive state data security law for licensees.

View Details →

Insurance Data Security Act

Iowa Insurance Data Security Act
active

Jurisdiction: Iowa

Effective: 1/1/2022

Authority: Iowa Commissioner of Insurance (Iowa Insurance Division)

Iowa's version of the NAIC Insurance Data Security Model Law requires insurance licensees to run a risk-based written information security program, oversee third-party service providers, investigate cybersecurity events, and report qualifying events to the Insurance Commissioner within three business days. Consumer notice follows the general breach law in chapter 715C.

View Details →

Insurance Data Security Law

AL IDSL
active

Jurisdiction: Alabama

Effective: 5/1/2019

Authority: Alabama Commissioner of Insurance (Department of Insurance)

Alabama's version of the NAIC Insurance Data Security Model Law. Insurance licensees must maintain a risk-based written information security program, oversee vendors, investigate cybersecurity events, and notify the Commissioner within three business days of qualifying events. They must also follow the state breach notification act for consumer notices.

View Details →

Insurance Data Security Law

NH Insurance Data Security Law
active

Jurisdiction: New Hampshire

Effective: 1/1/2020

Authority: New Hampshire Insurance Commissioner

New Hampshire's adoption of the NAIC Insurance Data Security Model Law requires insurance licensees to run a risk-based written information security program, oversee vendors, keep an incident response plan, investigate cybersecurity events and report qualifying events to the Insurance Commissioner within 3 business days. Consumer notice follows the general breach law, RSA 359-C:20.

View Details →

Insurance Data Security Law

CT Insurance Data Security Law
active

Jurisdiction: Connecticut

Effective: 10/1/2020

Authority: Connecticut Insurance Commissioner

Connecticut's version of the NAIC Insurance Data Security Model Law. Insurers, producers and other licensees must run a risk-based written information security program, oversee vendors, keep an incident response plan, certify compliance annually (domestic insurers), and report cybersecurity events to the Insurance Commissioner within three business days.

View Details →

Insurance Data Security Law

LA Insurance Data Security Law
active

Jurisdiction: Louisiana

Effective: 8/1/2020

Authority: Louisiana Commissioner of Insurance

Louisiana's version of the NAIC Insurance Data Security Model Law. Insurance licensees must maintain a risk-based written information security program with board oversight and vendor controls, investigate cybersecurity events, and notify the Commissioner of Insurance within three business days of determining a qualifying event occurred. Consumer notice follows the general breach notification law.

View Details →

Insurance Data Security Law

Tenn. Insurance Data Security Law
active

Jurisdiction: Tennessee

Effective: 7/1/2021

Authority: Tennessee Commissioner of Commerce and Insurance

Tennessee's version of the NAIC Insurance Data Security Model Law. Insurance licensees must run a risk-based written information security program, oversee third-party service providers, investigate cybersecurity events, notify the Commissioner within three business days of qualifying events, and notify affected Tennessee consumers within 45 days when an event is reasonably likely to cause them material harm.

View Details →

Insurance Information and Privacy Protection Act

IIPPA
active

Jurisdiction: California

Effective: 10/1/1981

Authority: California Insurance Commissioner; private plaintiffs for listed rights

Sets standards for how insurers and agents collect, use, and disclose personal information from insurance transactions. It requires notices of information practices, gives consumers access and correction rights, and limits disclosure without written authorization. SB 354 (2026), which would modernize the Act effective 2028, was on the Governor's desk as of September 25, 2026.

View Details →

Insurance Information and Privacy Protection Act

MT Insurance Privacy Act
active

Jurisdiction: Montana

Authority: Montana Commissioner of Securities and Insurance (State Auditor)

Montana's version of the NAIC insurance privacy model law governs how insurers, producers and insurance-support organizations collect, use and disclose personal and health information. It gives individuals notice, access, correction and adverse-decision explanation rights, limits disclosure and marketing use, and contains an insurance-specific data breach notification and security policy requirement.

View Details →

Insurance Information and Privacy Protection Act and Insurance Data Security Act

VA insurance privacy
active

Jurisdiction: Virginia

Effective: 7/1/1981

Authority: State Corporation Commission, Bureau of Insurance (38.2-614, 38.2-627)

Virginia's insurance privacy law limits pretext interviews, requires notices of information practices, gives consumers access and correction rights and reasons for adverse underwriting decisions, and restricts disclosure of medical and privileged information without written authorization. The 2020 Insurance Data Security Act adds a written information security program, cybersecurity-event investigation, notice to the Commissioner within three business days, and consumer breach notice.

View Details →

Insurance Privacy of Nonpublic Personal Financial and Health Information

Florida Insurance Privacy Law
active

Jurisdiction: Florida

Authority: Florida Department of Financial Services; Financial Services Commission; Office of Insurance Regulation

Directs Florida insurance regulators to adopt privacy rules for consumers' nonpublic personal financial and health information, modeled on and no stricter than the NAIC privacy model regulation and GLBA Title V. Health insurers and HMOs complying with the HIPAA privacy rules are deemed compliant.

View Details →

Insurance privacy of nonpublic personal information

OK Insurance GLBA Privacy
active

Jurisdiction: Oklahoma

Effective: 7/1/2001

Authority: Oklahoma Insurance Commissioner

Prohibits disclosure of nonpublic personal information in violation of Title V of the Gramm-Leach-Bliley Act and authorizes the Insurance Commissioner to adopt implementing privacy rules for the insurance industry.

View Details →

Insurer Information Security Program and Cybersecurity Event Notification

RI Insurance Data Security Law
active

Jurisdiction: Rhode Island

Effective: 1/1/2025

Authority: Rhode Island Department of Business Regulation, Insurance Division (commissioner/director)

Enacted in 2024 and effective January 1, 2025, this law adapts the NAIC Insurance Data Security Model Law. Insurers must keep a written, risk-based information security program for nonpublic consumer information with encryption, multi-factor authentication, training, vendor oversight and board oversight, and must notify the insurance commissioner within three business days of qualifying cybersecurity events.

View Details →

Insurers' use of external consumer data, algorithms, and predictive models

Colorado insurance AI law (SB 21-169)
active

Jurisdiction: Colorado

Effective: 9/7/2021

Authority: Colorado Commissioner of Insurance (Division of Insurance)

SB 21-169 bars insurers from unfairly discriminating based on race, color, national or ethnic origin, religion, sex, sexual orientation, disability, gender identity, or gender expression, including through external consumer data, algorithms, and predictive models. The Commissioner adopts line-by-line rules requiring insurers to test and govern those models. SB 26-189 added authority for rules on notices and disclosures to consumers and deems compliant insurers compliant with the ADMT Act.

View Details →

Interception of Communications (Iowa wiretap act)

Iowa Wiretap Act
active

Jurisdiction: Iowa

Authority: County attorneys and the Attorney General (criminal); aggrieved persons (civil)

Iowa's wiretap act makes it a felony to willfully intercept wire, oral, or electronic communications, or to use or disclose unlawfully intercepted contents, and gives victims a civil damages claim. Interception is lawful when the interceptor is a party or one party consents, unless done to commit a crime or tort, and property owners may capture oral communications with consented surveillance systems for crime prevention.

View Details →

Interception of Telephonic or Telegraphic Communications (Indiana wiretap act)

IN Wiretap Act
active

Jurisdiction: Indiana

Authority: County prosecutors (criminal); private civil actions

Indiana's wiretap law is a one-party consent statute. 'Interception' means acquisition by someone who is neither a sender nor a receiver and lacks the consent of the sender or receiver, so a participant may record, or another person may record with one party's consent. The article also sets the warrant process for law enforcement wiretaps. It is framed around communications transmitted by wire, radio, or similar systems; purely in-person conversations are not expressly addressed by the definition.

View Details →

Interception of Wire, Electronic and Oral Communications (wiretap and one-party consent recording)

RI Wiretap Law
active

Jurisdiction: Rhode Island

Authority: Rhode Island Attorney General and local prosecutors; courts via civil suits

Rhode Island is a one-party consent state: it is a crime to intercept a phone call, electronic communication or in-person conversation unless the interceptor is a party or one party has consented in advance, and even then not if the recording is made to commit a crime, tort or other injurious act. Chapter 12-5.1 sets the court-order procedure for law-enforcement wiretaps and gives victims of unlawful interception a civil damages claim.

View Details →

Interception of Wire, Electronic or Oral Communications (Virginia wiretap act)

VA wiretap act
active

Jurisdiction: Virginia

Effective: 7/1/1973

Authority: Criminal prosecution by Commonwealth's attorneys; injured persons by civil action (19.2-69)

Virginia is a one-party consent state: recording or intercepting a call or conversation is lawful if the recorder is a party or one party consented, and otherwise a felony. Victims can sue for liquidated damages. Service providers may not divulge communication contents in transit and may give subscriber records to law enforcement only under a subpoena, warrant, court order, or the customer's consent.

View Details →

Interference with Privacy (surreptitious observation and recording)

MN Interference with Privacy
active

Jurisdiction: Minnesota

Authority: Criminal prosecution

Criminalizes peeping into homes and other private places and surreptitiously installing or using devices to observe, photograph, record, or broadcast people there, including recording someone's intimate parts without consent in bathrooms, locker rooms, hotel rooms, and similar places. Penalties increase for repeat offenders and offenses involving minors.

View Details →

Internet-Connected Baby Monitor Security Requirements

NJ Baby Monitor Security Law
active

Jurisdiction: New Jersey

Effective: 12/1/2018

Authority: New Jersey Attorney General / Division of Consumer Affairs (Consumer Fraud Act)

Internet-connected baby monitors sold in New Jersey must include end-to-end encryption, certificate-based authentication, a ban on unauthenticated access, and security settings that consumers cannot disable. Selling a non-compliant monitor is a consumer fraud violation.

View Details →

Invasion of personal privacy (voyeurism and nonconsensual nude recording): crime and civil action

ORS 163.700-163.701; 30.831
active

Jurisdiction: Oregon

Authority: District attorneys (criminal); private civil action (ORS 30.831)

Criminalizes secretly viewing someone nude for sexual gratification, recording a person's intimate area without consent, and recording someone nude in a private place such as a bathroom or locker room. A companion civil action lets victims sue, and since September 2025 also reaches hotels and short-term rental hosts or platforms that record guests in private spaces.

View Details →

Invasion of Privacy (non-consensual intimate observation, recording, and disclosure)

NJ Invasion of Privacy Law
active

Jurisdiction: New Jersey

Effective: 1/8/2004

Authority: County prosecutors and the Attorney General (criminal); private civil action by the person depicted

New Jersey criminalizes secretly watching, photographing, or recording people who are nude, partly clothed, or engaged in sexual activity where they expect privacy, and disclosing such images (including online) without consent. Victims can sue for liquidated damages. Retailers may watch dressing-room entrances only with posted notice and may never observe or record inside private stalls.

View Details →

Invasive Visual Recording

Texas Invasive Visual Recording Law
active

Jurisdiction: Texas

Effective: 9/1/2001

Authority: State prosecutors

Criminalizes non-consensual photography or video of intimate areas or of people in bathrooms, changing rooms, and similar private places, and promoting such recordings. Posted signs alone do not establish consent to recording in private places.

View Details →

Investigative Consumer Reporting Agencies Act

ICRAA
active

Jurisdiction: California

Authority: Private plaintiffs

Regulates background reports on a person's character, reputation, and way of living, often used for employment and tenant screening. Agencies must limit reports to permitted purposes, maintain accuracy, and disclose on their websites whether personal information is sent outside the United States.

View Details →

Iowa Consumer Data Protection Act (Consumer Data Protections)

ICDPA
active

Jurisdiction: Iowa

Effective: 1/1/2025

Authority: Iowa Attorney General (exclusive authority, 715D.8(1))

Max Fine: Up to ,500 per violation

Iowa's comprehensive consumer privacy law gives Iowa residents the right to confirm and access their personal data, delete data they provided, obtain a portable copy, and opt out of the sale of personal data. It requires notice and an opportunity to opt out before processing sensitive data (and COPPA-compliant processing for a known child's data), rather than opt-in consent. It has no right to correct, no data protection assessments, and a 90-day cure period enforced only by the Attorney General.

consumer_rightsopt_out
View Details →

Job Applicant Fairness Act (employer use of credit history)

MD Job Applicant Fairness Act
active

Jurisdiction: Maryland

Authority: Commissioner of Labor and Industry (3-711(d))

Maryland generally bars employers from using an applicant's or employee's credit report or history to deny employment, fire, or set pay or terms. Employers may use it after a job offer for non-prohibited purposes, or where there is a bona fide, substantially job-related reason disclosed in writing, such as managerial, fiduciary, or personal-information-access roles.

View Details →

Judge Andrew F. Wilkinson Judicial Security Act

Wilkinson Judicial Security Act
active

Jurisdiction: Maryland

Effective: 6/1/2024

Authority: Protected individuals and the Office of Information Privacy in the Administrative Office of the Courts (civil actions); State's Attorneys (criminal)

Named for a Maryland judge killed in 2023, this law lets judges and their families, or the judiciary's Office of Information Privacy on their behalf, demand that anyone who has published their home address, phone numbers, personal email, financial or ID numbers, children's names, schools, or similar details online remove it within 72 hours. It also creates a judicial address confidentiality program and criminalizes threatening publication.

View Details →

K-12 Pupil Online Personal Information Protection Act (formerly SOPIPA)

KOPIPA (SOPIPA)
active

Jurisdiction: California

Effective: 1/1/2016

Authority: California Attorney General and local prosecutors; pupils actually harmed (from 2027)

Protects K-12 students' data held by education technology operators. Operators may not use student data for targeted advertising, build non-school profiles, sell it, or disclose it except as listed, and must secure it and delete it on request. AB 1159 (signed Sept. 10, 2026, Chapter 182) widens coverage, bars using student data to train generative AI or develop AI systems, and adds a private right of action from January 1, 2027.

View Details →

Kelsey Smith Act

Nebraska Kelsey Smith Act
active

Jurisdiction: Nebraska

Effective: 7/15/2010

Authority: No specific enforcement provision (law enforcement agencies request data; Nebraska State Patrol keeps the carrier contact register)

This law requires wireless carriers, on request of a law enforcement agency, to provide a device's call location information (including historical cell-site data) as soon as practicable in an emergency involving risk of death or serious physical harm. It makes a narrow, emergency-only exception to location privacy and shields carriers from liability for such disclosures.

View Details →

Kelsey Smith Act

Kelsey Smith Act
active

Jurisdiction: Oklahoma

Effective: 11/1/2021

Authority: Oklahoma State Bureau of Investigation (contact database and rules); requesting law enforcement agencies

Requires wireless carriers to give law enforcement a device's call location information on request in an emergency involving risk of death or serious physical harm, and to notify the user afterward. Carriers must register emergency contacts with the OSBI.

View Details →

Kentucky Consumer Data Protection Act

KCDPA
active

Jurisdiction: Kentucky

Effective: 1/1/2026

Authority: Kentucky Attorney General (exclusive authority; complaints handled by the AG's Office of Data Privacy)

Kentucky's comprehensive consumer privacy law gives Kentucky residents rights to confirm, access, correct, delete, and port their personal data and to opt out of targeted advertising, sale, and significant-decision profiling. Controllers must minimize collection, secure data, obtain consent before processing sensitive data, publish a privacy notice, and conduct data protection impact assessments for higher-risk processing. A 2026 amendment (effective July 1, 2027) bars collection of smart-TV and smart-monitor automatic content recognition data without consent.

View Details →

Kentucky Eavesdropping and Related Offenses

KY Eavesdropping
active

Jurisdiction: Kentucky

Effective: 1/1/1975

Authority: Commonwealth's and county attorneys (criminal prosecution)

Kentucky is a one-party consent state: it is a felony to use a device to overhear, record, amplify, or transmit any part of a wire or oral communication of others without the consent of at least one party. The chapter also criminalizes installing or possessing eavesdropping devices, opening sealed private communications, and using or disclosing illegally obtained communications.

View Details →

Kentucky Family Educational Rights and Privacy Act (student education records)

KY FERPA
active

Jurisdiction: Kentucky

Effective: 7/15/1994

Authority: Not specified in the sections reviewed

Makes public school students' education records confidential and bars their release to third parties, other than directory information, without parent or eligible-student consent except to listed recipients such as school officials, transfer schools, authorized government officials, de-identified researchers, and accreditors. Schools must preserve unedited master copies of recordings of school activities for set periods, and must log releases.

View Details →

Kentucky Insurance Data Security Law

KY Insurance Data Security
active

Jurisdiction: Kentucky

Effective: 1/1/2023

Authority: Kentucky Department of Insurance (Commissioner)

Kentucky's version of the NAIC Insurance Data Security Model Law. Covered insurance licensees must run a risk-based written information security program, oversee third-party service providers, investigate cybersecurity events, and report qualifying events to the Commissioner within three business days. Domestic insurers must certify compliance annually.

View Details →

Kentucky Security Breach Notification Law

KY Breach Notification
active

Jurisdiction: Kentucky

Effective: 7/15/2014

Authority: Not specified in KRS 365.732

Requires businesses to notify Kentucky residents when unencrypted, unredacted computerized personal information (name plus SSN, driver's license number, or financial account or card number with its access code) is acquired without authorization in a way that causes or is reasonably believed to cause identity theft or fraud. Notice must go out in the most expedient time possible and without unreasonable delay, and consumer reporting agencies must be told when more than 1,000 people are notified.

View Details →

Kentucky Telephone Solicitation (Telemarketing) Law

KY Telemarketing Act
active

Jurisdiction: Kentucky

Effective: 7/15/1994

Authority: Kentucky Attorney General (Office of Consumer Protection) with concurrent criminal enforcement powers; prosecutors

Regulates telephone solicitation in Kentucky: callers must identify themselves at the start of the call, may not call numbers on the national Do Not Call Registry, may not call minors or outside 10 a.m. to 9 p.m., may not spoof caller ID, and may not sell information learned during a call without written consent. Telemarketing companies must register with the Attorney General and post a bond. Kentucky's former zero call list was folded into the national registry in 2007.

View Details →

Kids Online Protection and Anti-Grooming Act

LA KOPAG Act
enacted_not_effective

Jurisdiction: Louisiana

Effective: 1/1/2027

Authority: Louisiana Attorney General

Imposes a duty of care on platforms, online games, messaging apps, and streaming services that contract with minors, requiring privacy-protective default settings: no adult connections without parental consent (or parental visibility into connections), no direct messages from unconnected adults, no sharing of a minor's precise geolocation, and private-mode accounts. Parents must get supervision tools, including limits on microtransactions, and only a linked parent can change the defaults. Act 552 of 2026 raised the covered age to under 18 and set the effective date at January 1, 2027.

View Details →

Kristil's Law: communications provider response to domestic violence and stalking search warrants

HB 4045 (2026)
active

Jurisdiction: Oregon

Effective: 5/1/2026

Authority: Courts issuing the warrants; no separate penalty specified

Sets fast deadlines for providers to answer search warrants for records in domestic violence and stalking cases: 72 hours for social media platforms and five business days for other communications providers. It governs how quickly private providers must hand stored user data to law enforcement.

View Details →

Laboratory Genetic Sequencing Software from Foreign Countries of Concern

Florida Genetic Sequencing Software Law
active

Jurisdiction: Florida

Effective: 7/1/2025

Authority: Florida Department of Health

Added by SB 768 (ch. 2025-96), this subsection bars the Department of Health from allowing its public-health laboratories under s. 381.0202 to use genetic-sequencing software produced by China, Russia, Iran, North Korea, Cuba, the Maduro regime in Venezuela, or Syria, or by their state-owned enterprises or domestic companies. It is Florida's main 2025 genetic-data change. It covers state laboratory services, not private consumer genetic-testing companies, and does not amend s. 760.40.

View Details →

Legal representative consent for contracts between a minor and an interactive computer service

LA Minor Online Contract Consent Law
active

Jurisdiction: Louisiana

Effective: 5/8/2024

Authority: None specified (civil-law contract nullity)

Declares it Louisiana policy that online services should not contract with minors without a parent's or tutor's consent, and bars interactive computer services from entering contracts, including opening an online account, with anyone under 18 without that consent. Contracts made without express written consent are relatively null and can be annulled. Third parties may be used to collect consent.

View Details →

Library User Records Confidentiality

NH Library Records Law
active

Jurisdiction: New Hampshire

Effective: 7/21/1989

Authority: Not specified in the section

Makes library records identifying users, including circulation, information system and electronic viewing records, confidential at both public and non-public libraries. Records may be disclosed only for library operations, with the user's consent, or under subpoena, court order or statute; a 2025 amendment effective Jan. 1, 2026 gives parents or guardians access to a minor's current borrowing records.

View Details →

Lie Detector Tests as Conditions of Employment

RI Polygraph Ban
active

Jurisdiction: Rhode Island

Authority: Prosecutors (misdemeanor); courts via civil actions

Forbids employers from requesting, requiring or subjecting employees or applicants to lie detector tests, which include polygraphs and any device or written test used by an examiner to judge honesty. Written honesty examinations may be used only if they are not the primary basis for an employment decision.

View Details →

Lie Detector Tests Prohibited

MT Polygraph Ban
active

Jurisdiction: Montana

Authority: Not specified in the section

Montana bars employers from requiring a polygraph or other mechanical lie detector test as a condition of getting or keeping a job.

View Details →

Life, long-term care, and annuity genetic nondiscrimination

LA Life and LTC Genetic Nondiscrimination
active

Jurisdiction: Louisiana

Effective: 8/1/2021

Authority: Louisiana Commissioner of Insurance

Stops life, long-term care, and annuity insurers from considering an applicant's or family member's participation in genetic or clinical research, or (since 2024) their genetic test results, for coverage or underwriting. Insurers may not cancel, refuse to renew, limit coverage, or raise premiums based on genetic testing or genetic services.

View Details →

Limitations on use of artificial intelligence by health benefit plan providers

AL AI Prior Authorization Law
enacted_not_effective

Jurisdiction: Alabama

Effective: 10/1/2026

Authority: Alabama Department of Insurance

Regulates insurers that use AI to decide medical-necessity prior authorization requests. AI determinations must rest on the individual enrollee's medical history and clinical circumstances, not group datasets, and any denial, delay, or modification must be made by a licensed clinician. Plans must disclose their AI use and keep patient data used by AI within its stated purpose consistent with HIPAA. The effective date is October 1, 2026.

View Details →

Limits on employer use of consumer credit reports

Lab. Code 1024.5
active

Jurisdiction: California

Effective: 1/1/2012

Authority: Labor Commissioner; courts

Bars employers from using consumer credit reports for employment decisions except for listed positions, such as managerial jobs, law enforcement, positions with access to large sums or sensitive financial data, and jobs where the law requires the check. Employers using a report must give advance written notice.

View Details →

Louisiana Data Privacy Act

LDPA
enacted_not_effective

Jurisdiction: Louisiana

Effective: 1/1/2027

Authority: Louisiana Attorney General

Louisiana's comprehensive consumer privacy law, enacted by Act 502 of the 2026 Regular Session and effective January 1, 2027. It gives Louisiana residents rights to confirm, access, correct, delete, and port their personal data and to opt out of targeted advertising, sale, and significant-decision profiling, and it requires controllers to minimize data, secure it, get consent for sensitive data, publish a privacy notice, and conduct data protection assessments. Unlike most state models, applicability turns on a $25 million revenue threshold (CCPA-style) rather than only a consumer-count threshold.

View Details →

Malicious Sharing of Personal Information of a General Assembly Member or Judicial Officer (2026 SF 2280, Division III)

Iowa Official Doxxing Law
active

Jurisdiction: Iowa

Effective: 7/1/2026

Authority: County attorneys and the Attorney General (criminal prosecution)

This 2026 criminal law makes it a serious misdemeanor to share the home address, personal phone number, or physical location of an Iowa legislator, judge, or their immediate family with intent to cause harm, to put them in fear of serious harm, or to interfere with their official duties. It is narrow: it covers only those officials and requires malicious intent.

View Details →

Maryland Age-Appropriate Design Code Act (Maryland Kids Code)

Maryland Kids Code
active

Jurisdiction: Maryland

Effective: 10/1/2024

Authority: Consumer Protection Division, Office of the Attorney General (14-4808)

The Maryland Kids Code requires large online businesses whose products children under 18 are reasonably likely to use to design those products in children's best interests. Covered entities must complete data protection impact assessments, set high-privacy defaults for children, and avoid default profiling, default precise geolocation tracking, unnecessary data collection, and dark patterns. NetChoice's First Amendment challenge (NetChoice v. Brown, D. Md. No. 1:25-cv-00322) survived a motion to dismiss in November 2025 and is in discovery; the law has not been enjoined.

View Details →

Maryland Commercial Electronic Mail Act

MD Commercial Email Act
active

Jurisdiction: Maryland

Authority: Private civil actions by recipients, domain owners, and interactive computer service providers (14-3003)

Maryland's anti-spam law prohibits sending commercial email that uses a third party's domain or address without permission, falsifies its origin or transmission path, or has a deceptive subject line. Email providers may block suspected violating messages without liability.

View Details →

Maryland Confidential Financial Records law

MD Financial Records Confidentiality
active

Jurisdiction: Maryland

Authority: State's Attorneys (criminal); Attorney General (civil penalties for failure to file elder-abuse reports)

Maryland bars banks and other fiduciary institutions from disclosing a customer's financial records unless the customer authorizes it, a statutory exception applies (such as guardians, estate representatives, public assistance verification, adult protective services, child support, or tax liens), or a properly certified subpoena is served with notice to the customer. A 2026 amendment (ch. 510, effective 2026-10-01) adds disbursement-delay authority and disclosure duties to protect seniors and vulnerable adults from exploitation.

View Details →

Maryland Confidentiality of Medical Records Act

MCMRA
active

Jurisdiction: Maryland

Authority: State's Attorneys (criminal); Maryland Health Care Commission (HIE regulations); private civil actions for actual damages

Maryland's medical records law requires health care providers to keep patient records confidential and disclose them only as the subtitle or other law allows, gives patients rights to see, copy, and seek corrections to their records, and criminalizes obtaining records under false pretenses. Recent amendments restrict health information exchanges and electronic health networks from sharing abortion, mifepristone, and other legally protected sensitive-service data, and require HIE opt-out consent management.

View Details →

Maryland Consumer Credit Reporting Agencies Act

MD CCRA
active

Jurisdiction: Maryland

Authority: Commissioner of Financial Regulation (14-1218, 14-1225); private civil actions (14-1221)

Maryland's credit reporting law limits when consumer reports may be furnished, bars reporting of stale information, criminal records that did not end in conviction or were expunged, and (since 2025) any medical debt, and gives consumers rights to free reports, disputes, and security freezes. Agencies must register and post a bond, and users must give adverse action notices.

View Details →

Maryland employer access to personal accounts (User Name and Password Privacy Protection)

MD Social Media Password Law
active

Jurisdiction: Maryland

Authority: Commissioner of Labor and Industry; Attorney General may sue on the employee's or applicant's behalf (3-712(f))

Maryland bars employers from asking employees or job applicants for usernames, passwords, or other access to their personal online accounts, and from punishing or refusing to hire anyone who declines. Employers may still require credentials for company systems and may investigate securities-law compliance or leaks of proprietary data.

View Details →

Maryland Genetic Information Privacy law (direct-to-consumer genetic testing)

MD Genetic Information Privacy
active

Jurisdiction: Maryland

Effective: 10/1/2022

Authority: Consumer Protection Division, Office of the Attorney General (14-4406; Com. Law 13-301(14)(xxxvi))

Enacted by 2022 Md. Laws ch. 501 (HB 866), this law requires direct-to-consumer genetic testing companies to publish clear privacy information, obtain separate express consents for each use, transfer, sample retention, and marketing, secure genetic data, and let consumers access and delete their data and have samples destroyed. It bars disclosure to insurers or employers without written consent. The same act also regulated forensic genetic genealogy in the Criminal Procedure Article.

View Details →

Maryland Insurance Data Security law (Insurance Article Title 33)

MD Insurance Data Security
active

Jurisdiction: Maryland

Effective: 10/1/2022

Authority: Maryland Insurance Commissioner

Enacted by 2022 Md. Laws ch. 231 (SB 207), Maryland's version of the NAIC Insurance Data Security Model Law requires insurance carriers to run a risk-based written information security program, oversee vendors, investigate cybersecurity events, and notify the Insurance Commissioner within 3 business days of determining a qualifying event, along with consumer notice under the Personal Information Protection Act.

View Details →

Maryland lie detector test prohibition

MD Polygraph Law
active

Jurisdiction: Maryland

Authority: Commissioner of Labor and Industry; Attorney General may sue (3-702(f)-(g))

Maryland employers may not require a polygraph or similar test as a condition of employment, and every job application must carry a bold, capitalized notice of this right with a signed acknowledgment.

View Details →

Maryland Online Data Privacy Act of 2024

MODPA
active

Jurisdiction: Maryland

Effective: 10/1/2025

Authority: Consumer Protection Division, Office of the Attorney General (14-4713; Com. Law Title 13)

Maryland's comprehensive consumer privacy law gives residents rights to access, correct, delete, and port their personal data, to get a list of categories of third parties that received it, and to opt out of targeted advertising, sale, and significant-decision profiling. It is stricter than most state laws: data collection must be limited to what is reasonably necessary for a requested product or service, sensitive data may be collected only when strictly necessary and may never be sold, and minors' data may not be sold or used for targeted advertising. A 2026 amendment (HB 711, ch. 874) extends sensitive data to inferences and bars knowing sales of personal data to government units engaged in civil immigration enforcement.

View Details →

Maryland Pen Register and Trap and Trace Devices law

MD Pen Register Act
active

Jurisdiction: Maryland

Authority: State's Attorneys (criminal)

This law bars anyone from installing or using a device that records the numbers or routing information of calls and electronic communications without first getting a court order, except for service providers protecting their networks and users.

View Details →

Maryland Personal Information Protection Act

MPIPA
active

Jurisdiction: Maryland

Authority: Consumer Protection Division, Office of the Attorney General (14-3508; Com. Law Title 13)

Maryland's data security and breach notification law requires businesses holding Maryland residents' personal information to keep reasonable security, destroy records securely, and flow security requirements down to service providers. After a breach, a business must investigate and, unless misuse is not likely, notify affected residents within 45 days, notifying the Attorney General first. The 2022 revisions added genetic information and set the 45-day and 10-day deadlines.

View Details →

Maryland Stored Wire and Electronic Communications and Transactional Records Access

MD Stored Communications Act
active

Jurisdiction: Maryland

Authority: State's Attorneys (criminal); private civil action by aggrieved providers, subscribers, or customers (10-4A-08)

Maryland's counterpart to the federal Stored Communications Act makes it a crime to access a communications facility without authorization to obtain, alter, or block stored messages. It also bars public communication and remote computing service providers from knowingly disclosing stored message contents except to recipients, with consent, or as the subtitle allows, and it gives aggrieved users a civil remedy.

View Details →

Maryland Student Data Privacy Act (operators of PreK-12 online services)

MD Student Data Privacy Act
active

Jurisdiction: Maryland

Authority: No enforcement provision in § 4-131 (contract remedies by schools; see unverified)

Maryland's student data privacy law limits what education-technology operators working under contract with public schools may do with student information. Operators must secure covered information and delete it on school request, and may not use it for targeted advertising, build non-educational student profiles, sell it, or disclose it outside listed exceptions. The 2022 amendments (ch. 164) expanded covered information, added persistent identifiers, and tied coverage to school contracts.

View Details →

Maryland Telephone Consumer Protection Act

MD TCPA
active

Jurisdiction: Maryland

Authority: Consumer Protection Division, Office of the Attorney General (14-3202(a)); private actions (14-3202(b))

This law makes any violation of the federal Telemarketing Sales Rule or the federal Telephone Consumer Protection Act and its FCC telemarketing rules (including the national do-not-call rules) a violation of Maryland law, enforceable by the Attorney General and by individuals for $500 per violation.

View Details →

Maryland Telephone Solicitations Act

MD Telephone Solicitations Act
active

Jurisdiction: Maryland

Authority: Consumer Protection Division, Office of the Attorney General (Com. Law 13-301(14)(xiv))

This older telemarketing law protects consumers from phone sales by making contracts formed through telephone solicitations unenforceable unless put in writing and signed by the consumer with required disclosures, and by barring charges to a consumer's account until the signed contract is received.

View Details →

Maryland visual surveillance and hidden camera crimes

MD Visual Surveillance Law
active

Jurisdiction: Maryland

Authority: State's Attorneys (criminal); private civil actions by individuals surveilled

These laws make it a crime to watch or record people without consent in retail dressing rooms and restrooms, to conduct surreptitious surveillance with prurient intent of people in private places or of their private areas, and to place a camera on residential property to secretly observe people inside a home. Each gives victims a civil claim. A 2025 amendment (ch. 153) extended 3-902 to camera surveillance of private areas regardless of location.

View Details →

Maryland Wiretap and Electronic Surveillance Act

MD Wiretap Act
active

Jurisdiction: Maryland

Authority: State's Attorneys and the Attorney General (criminal); private civil action by persons whose communications are intercepted, disclosed, or used (10-410)

Maryland is an all-party consent state: a private person may record or intercept a phone call, electronic communication, or private in-person conversation only if they are a party and every party has consented in advance. The Act also bars disclosing or using contents known to be illegally intercepted, and it sets out narrow exceptions for service providers, law enforcement investigations, and police and correctional body-worn cameras.

View Details →

Medical Debt Reporting

RI Medical Debt Reporting Ban
active

Jurisdiction: Rhode Island

Effective: 1/1/2025

Authority: Rhode Island Attorney General; consumers

Since January 1, 2025, Rhode Island bars medical debt from appearing on credit reports. Providers may not furnish medical debt to credit bureaus and must bar their collectors by contract from doing so, credit bureaus may not record or report it, and collectors must tell consumers in writing that Rhode Island law prohibits medical debt reporting and must pause reporting and collection while insurance appeals are pending.

View Details →

Medical record retention and destruction

MD Medical Records Retention Law
active

Jurisdiction: Maryland

Authority: Maryland Department of Health and the relevant health occupations boards (not specified in section)

Maryland health care providers must keep medical records and lab and X-ray reports for 7 years (for minors, until age of majority plus 7 years) unless they notify the patient first. The notice, now allowed by email with a mail fallback under 2025 ch. 695, must give the destruction date and where to retrieve the record, and records must be available for retrieval for 60 days before destruction.

View Details →

Medical records disclosure rules (patient access and subpoenas to health care providers)

LA Medical Records Disclosure Rules
active

Jurisdiction: Louisiana

Authority: Courts

Louisiana has no general medical confidentiality act, but these statutes set the exclusive routes by which health care providers may disclose patient records: to the patient or authorized persons under R.S. 40:1165.1, under the health care provider-patient privilege of Code of Evidence article 510, or under a subpoena or court order that follows notice procedures protecting the patient. Patients may also get copies of information a provider has sent to third parties.

View Details →

Medical Records, Patient Information, and the Health Information Organization Corporation

NH Medical Records Privacy Law
active

Jurisdiction: New Hampshire

Authority: Courts, through individual civil actions (RSA 332-I:4-5); provider licensing boards

Declares medical information in provider records to be the patient's property, sets deadlines and fee caps for copies, and forbids providers from revealing confidential information without consent except as law requires. It adds state-law limits beyond HIPAA on using health information for marketing and fundraising, requires notice to patients of disclosures that HIPAA allows but state law forbids, and gives patients an opt-out from the state health information exchange.

View Details →

Mental Health Clinical Records; Confidentiality (Baker Act facilities)

Florida Mental Health Records Law
active

Jurisdiction: Florida

Authority: Florida Department of Children and Families; Agency for Health Care Administration

Makes clinical records of mental-health patients confidential. The confidential status is not lost by authorized or unauthorized disclosure unless the patient or representative waives it, and the records may be released only in listed circumstances, such as patient authorization.

View Details →

Mental Health Records Confidentiality

Texas Mental Health Records Law
active

Jurisdiction: Texas

Effective: 9/1/1991

Authority: Aggrieved patients (courts); licensing boards

Makes communications with mental health professionals and their records of identity, diagnosis, evaluation, and treatment confidential, allows disclosure only under listed exceptions, and gives patients a right to access their records unless a professional documents that access would be harmful.

View Details →

Minnesota Consumer Data Privacy Act

MCDPA
active

Jurisdiction: Minnesota

Effective: 7/31/2025

Authority: Minnesota Attorney General (325M.20)

Max Fine: Up to ,500 per violation

Minnesota's comprehensive consumer privacy law gives Minnesota residents rights to access, correct, delete, and port their personal data, to opt out of targeted advertising, sale, and significant-effect profiling, and to get a list of the specific third parties that received their data. It is unusual in giving consumers a right to question the result of a profiling decision, learn the reason for it, and have it reevaluated on corrected data, and it requires a data inventory and documented privacy policies. Enforcement is by the Attorney General only.

consumer_rightsopt_outsensitive_dataprofiling
View Details →

Minnesota Consumer Reports and Security Freeze Law

MN Consumer Reports and Security Freeze
active

Jurisdiction: Minnesota

Authority: Minnesota Attorney General or county attorney under 8.31 or 325F.70 (13C.04)

Gives Minnesota consumers the right to freeze their credit reports for free, with agencies required to place, lift, and remove freezes within three business days, and lets parents or representatives freeze a record for children under 16. It also requires written disclosure before an employer obtains a consumer report for employment purposes, adverse-action notices, and bars selling 'trigger lead' information about mortgage credit inquiries to third parties without an existing mortgage relationship.

View Details →

Minnesota Data Breach Notification Law

MN Breach Notification
active

Jurisdiction: Minnesota

Effective: 1/1/2006

Authority: Minnesota Attorney General under 8.31 (325E.61, subd. 6)

Requires businesses to notify Minnesota residents whose unencrypted personal information (name plus SSN, driver's license or state ID number, or financial account or card number with its access code) was, or is reasonably believed to have been, acquired by an unauthorized person, in the most expedient time possible and without unreasonable delay. Service providers must notify the data owner immediately, and breaches affecting more than 500 people require notice to the nationwide consumer reporting agencies within 48 hours.

View Details →

Minnesota Genetic Information Privacy Act (direct-to-consumer genetic testing)

MN Genetic Information Privacy Act
active

Jurisdiction: Minnesota

Effective: 8/1/2023

Authority: Minnesota Commissioner of Commerce under 45.027 (325F.995, subd. 4)

Requires direct-to-consumer genetic testing companies to give plain-language privacy notices, get express consent for collecting and using genetic data and separate consent for each third-party disclosure, secondary use, sample retention, research transfer, and genetic-data-based marketing, and to let consumers access and delete their data and have samples destroyed. Companies may not give genetic data to law enforcement without consent or a warrant or court order, or to insurers or employers without written consent.

View Details →

Minnesota Government Data Practices Act: private contractors and government breach notice

MN MGDPA (contractor provisions)
active

Jurisdiction: Minnesota

Authority: Individuals by civil action; courts may enjoin violations (13.08)

Private companies that perform government functions under contract with a Minnesota government entity must handle the resulting data under the Minnesota Government Data Practices Act as if they were the government, and every such contract must say so. Government entities must notify individuals of breaches of private or confidential data and prepare an investigation report.

View Details →

Minnesota Health Records Act

MN Health Records Act
active

Jurisdiction: Minnesota

Authority: Patients by civil action; licensing boards through disciplinary action (144.298)

Minnesota's health privacy statute, stricter than HIPAA in key respects, generally requires a signed and dated patient consent before a provider (or anyone who received records from a provider) releases health records, even for many treatment and payment disclosures, with limited exceptions such as emergencies and current treatment within related entities. It also gives patients rights to see and copy their records within 30 days at capped fees, and lets patients sue for unauthorized release.

View Details →

Minnesota Insurance Fair Information Reporting Act

MN Insurance Fair Information Reporting Act
active

Jurisdiction: Minnesota

Authority: Aggrieved persons by civil action (72A.503); Commissioner of Commerce (general insurance regulatory authority)

Minnesota's version of the NAIC insurance information privacy model law. It requires insurers and agents to give a written notice of information practices, lets individuals see and copy personal information held about them and learn who received it, lets them seek correction, requires reasons for adverse underwriting decisions, and bars disclosing personal or privileged information without authorization except in listed cases such as fraud prevention.

View Details →

Minnesota Internet Service Provider Privacy Law

MN ISP Privacy
active

Jurisdiction: Minnesota

Effective: 3/1/2003

Authority: Private civil action by consumers (325M.07)

Enacted in 2002, this law bars Internet service providers from knowingly disclosing a subscriber's personally identifiable information, including the sites the subscriber visits and the contents of the subscriber's storage devices, except where disclosure is required by legal process or permitted for ordinary business, abuse reporting, or with the subscriber's authorization. The sections expire if federal law preempts state regulation of ISP disclosure of such information.

View Details →

Minnesota Plastic Card Security Act (access device data retention)

MN Plastic Card Security Act
active

Jurisdiction: Minnesota

Effective: 8/1/2007

Authority: Civil action by card-issuing financial institutions (325E.64, subd. 3)

Prohibits businesses that accept payment cards from keeping the card security code, PIN verification code, or full magnetic-stripe track data after a transaction is authorized (48 hours for PIN debit). If a business (or its service provider) that violated the rule is breached, it must reimburse the banks and credit unions that issued the affected cards.

View Details →

Minnesota Privacy of Communications Act (wiretap and recording consent)

MN Wiretap Act
active

Jurisdiction: Minnesota

Authority: Criminal prosecution; private civil action by persons whose communications were intercepted, disclosed, or used (626A.02, subds. 4-5; 626A.13)

Minnesota's wiretap law makes it a crime, and a civil wrong, to intentionally intercept, disclose, or use the contents of phone calls, electronic communications, or in-person conversations without authorization. Minnesota is a one-party consent state: a participant, or someone with a participant's prior consent, may record a conversation unless it is done to commit a crime or tort.

View Details →

Minnesota Social Security Number Protection Law

MN SSN Protection
active

Jurisdiction: Minnesota

Effective: 7/1/2008

Authority: Minnesota Attorney General (general authority under Minn. Stat. 8.31)

Restricts how businesses use Social Security numbers: no public display, no printing on access cards or on mailed materials unless required by law, no unencrypted transmission over the Internet, no SSN-only website logins, no SSN-based account numbers (outside benefits and payroll), and no sale of SSNs. Businesses must also limit internal access to employees who need the numbers. The section applies to uses on or after July 1, 2008.

View Details →

Minnesota Stored Communications Provisions

MN Stored Communications
active

Jurisdiction: Minnesota

Authority: Criminal prosecution (626A.26, subd. 2); civil action by aggrieved providers, subscribers, or customers (626A.32)

Modeled on the federal Stored Communications Act, these sections make it a crime to access an electronic communications facility without authorization and obtain or alter stored messages, and bar public email and cloud providers from knowingly divulging the contents of stored communications except to recipients, with consent, as needed to provide service, under legal process, or to law enforcement when contents were inadvertently obtained and relate to a crime.

View Details →

Misrepresentation in privacy policies (unlawful trade practice)

ORS 646.607(12)
active

Jurisdiction: Oregon

Effective: 1/1/2016

Authority: Oregon Attorney General and district attorneys (ORS 646.632)

Makes it an unlawful trade practice to handle consumer information in a way that is materially inconsistent with what a business says in a website privacy statement or consumer agreement. It works as Oregon's enforcement hook for privacy promises rather than requiring any particular policy.

View Details →

Montana Consumer Data Privacy Act

MTCDPA
active

Jurisdiction: Montana

Effective: 10/1/2024

Authority: Montana Attorney General (exclusive; 30-14-2817(1)), using Montana Unfair Trade Practices and Consumer Protection Act powers

Max Fine: Up to ,500 per violation

Montana's comprehensive consumer privacy law gives Montana residents rights to access, correct, delete and port their personal data and to opt out of targeted advertising, sale and significant profiling, and requires opt-in consent for sensitive data. The 2025 amendments (SB 297, Ch. 567, L. 2025) lowered the applicability thresholds, narrowed the financial-institution exemption to entity-level exemptions for banks, credit unions and insurers, expanded privacy-notice rules, removed the cure period, and added a duty of care and design limits for online services offered to known minors under 18.

consumer_rightsopt_outsensitive_data
View Details →

Montana Pupil Online Personal Information Protection Act

MT Pupil Online Privacy Act
active

Jurisdiction: Montana

Authority: County attorneys (criminal misdemeanor); contract voidness between parties

Montana's student privacy law bars edtech operators from targeted advertising, profiling pupils for non-school purposes, selling pupil information, and most disclosures of protected student information, and requires reasonable security and deletion on school request. It also sets mandatory terms for school-district contracts with vendors that store or use pupil records.

View Details →

Montana Telemarketing Registration and Fraud Prevention Act

MT Telemarketing Act
active

Jurisdiction: Montana

Effective: 10/1/1999

Authority: Montana Department of Justice, Office of Consumer Protection, or county attorneys

Montana requires most telemarketers and sellers to register annually with the Department of Justice before soliciting Montanans. The Act also requires call disclosures, record keeping and cancellation rights, and bans abusive practices such as calling outside 8 a.m. to 9 p.m. or calling people who have asked not to be called.

View Details →

Motor Vehicle Administration records: personal information disclosure and recipient limits

MD MVA Records Privacy
active

Jurisdiction: Maryland

Authority: Motor Vehicle Administration (regulations and compliance monitoring, 4-320(h)-(i))

Maryland's counterpart to the federal Driver's Privacy Protection Act bars the MVA from disclosing personal information in its records except for listed purposes, and never for marketing or telephone solicitation without written consent. Businesses that receive the data may use it only for the permitted purpose, must log redisclosures for 5 years, and may not pass it to federal immigration enforcement without a court warrant; the 2026 Data Privacy Act (ch. 874) broadened the immigration-related limits.

View Details →

Motor Vehicle Consumer Data Protection

Utah Dealer Data Act
active

Jurisdiction: Utah

Effective: 5/1/2024

Authority: None stated; contract and indemnity remedies

Enacted by 2024 S.B. 215, it governs access to car dealers' protected dealer data, including consumers' nonpublic personal information. It is business-to-business and imposes no consumer notice duty.

View Details →

Motor vehicle recording devices (event data recorders)

VA vehicle data recorders
active

Jurisdiction: Virginia

Effective: 7/1/2006

Authority: Not stated in the section

Vehicle recording device data, including speed, location, braking, seatbelt, and crash data, belongs to the vehicle owner and may be accessed only with the owner's consent or under listed exceptions (subscription contracts, repair, emergency response, court order, or law enforcement with probable cause). Insurers may not ask for consent until after a claim event or make it a condition of paying a claim.

View Details →

Motor Vehicle Records Confidentiality (state driver privacy law)

NH Motor Vehicle Records Privacy
active

Jurisdiction: New Hampshire

Authority: NH Department of Safety (commissioner); prosecutors; aggrieved persons

Makes New Hampshire motor vehicle records confidential and not public, releasing them only for listed permissible uses on proof of identity and a signed representation of the intended use, and never including photographs or Social Security numbers for those uses. Recipients may not resell or redisclose the information outside the permitted use, and misuse carries criminal penalties and liquidated civil damages.

View Details →

Mug shot website removal requirement

ORS 646A.806
active

Jurisdiction: Oregon

Authority: Oregon Attorney General; private enforcement under ORS 646.638

Requires fee-charging mug shot websites to take down an arrested person's photo, name and personal information for free within 30 days when the person shows the charges ended without conviction, were reduced to violations, or were expunged or set aside.

View Details →

Nebraska Data Privacy Act

NDPA
active

Jurisdiction: Nebraska

Effective: 1/1/2025

Authority: Nebraska Attorney General (exclusive, 87-1119 to 87-1124)

Nebraska's comprehensive consumer privacy law, modeled on the Texas Data Privacy and Security Act, gives Nebraska consumers rights to access, correct, delete, and port their personal data and to opt out of targeted advertising, sale, and significant profiling. It covers almost every for-profit business that is not a federally defined small business, requires opt-in consent for sensitive data (including precise geolocation, genetic and biometric data, and a known child's data), and is enforced only by the Attorney General.

View Details →

Nebraska Interception of Wire, Electronic, and Oral Communications and Stored Communications Law

Nebraska Wiretap and Stored Communications Law
active

Jurisdiction: Nebraska

Authority: County attorneys and the Attorney General (criminal); private civil actions

Nebraska's wiretap law, modeled on the federal Wiretap Act and Stored Communications Act, bans intercepting, disclosing, or using wire, electronic, or oral communications without authorization. It is a one-party consent state: a participant, or someone with one party's prior consent, may record unless the purpose is a criminal or tortious act. It also restricts public communications providers from disclosing stored message contents and limits employer random monitoring.

View Details →

Nebraska Statutory Right of Privacy

Nebraska Privacy Tort Statute
active

Jurisdiction: Nebraska

Authority: Courts (private civil action by the person whose privacy was invaded)

Nebraska does not recognize common-law privacy torts beyond this statute, which creates three causes of action: commercial exploitation of a person's name, picture, or personality (right of publicity), intrusion upon seclusion that would be highly offensive to a reasonable person, and false light publicity. Consent within its scope is a defense, and news and certain other uses are exempt.

View Details →

New Hampshire Fair Credit Reporting Act (including Security Freeze)

NH FCRA
active

Jurisdiction: New Hampshire

Effective: 8/29/1971

Authority: New Hampshire Attorney General (administrative enforcement); consumers through civil actions

New Hampshire's own credit reporting statute limits when consumer reporting agencies may furnish reports, requires accuracy, dispute and disclosure procedures, and imposes adverse-action notice duties on users. Its security freeze subdivision lets consumers freeze, temporarily lift and remove freezes for free on short deadlines, and gives identity theft victims free reports and police reports.

View Details →

New Hampshire Privacy Act (Expectation of Privacy)

NHPA
active

Jurisdiction: New Hampshire

Effective: 1/1/2025

Authority: New Hampshire Attorney General (exclusive authority)

New Hampshire's comprehensive consumer privacy law gives NH residents rights to access, correct, delete and port their personal data and to opt out of targeted advertising, sales and significant automated profiling. Covered controllers must minimise collection, get opt-in consent for sensitive data, honor universal opt-out signals, publish a privacy notice and run data protection assessments for high-risk processing. A 2026 amendment bars selling a child's personal data starting Jan. 1, 2027.

View Details →

New Hampshire Right to Privacy Act (financial and credit records)

NH Right to Privacy Act
active

Jurisdiction: New Hampshire

Effective: 9/17/1977

Authority: Courts, through customer suits and criminal prosecution

Protects the confidentiality of customers' financial and credit records by barring financial institutions and creditors from handing them to state or local agencies investigating the customer unless the customer authorizes it or the agency uses a qualifying administrative subpoena, search warrant or judicial subpoena. It sets notice and record-keeping duties around those disclosures.

View Details →

New Jersey Data Privacy Act

NJDPA
active

Jurisdiction: New Jersey

Effective: 1/15/2025

Authority: New Jersey Attorney General (sole and exclusive authority, 56:8-166.19), acting through the Division of Consumer Affairs

Max Fine: Up to ,000 per first violation; ,000 per subsequent

New Jersey's comprehensive consumer privacy law gives residents rights to confirm, access, correct, delete and port their personal data and to opt out of targeted advertising, sale, and significant-decision profiling. It requires consent for processing sensitive data and for targeted advertising, sale, or profiling of known 13-to-16-year-olds, and requires data protection assessments for high-risk processing. A January 2026 amendment (P.L.2025, c.367) added exemptions and a HIPAA-based de-identification standard, and a June 2026 amendment (P.L.2026, c.25) flatly bans the sale of sensitive data by anyone.

consumer_rightsopt_outsensitive_datachildren
View Details →

New Jersey Fair Credit Reporting Act

NJ FCRA
active

Jurisdiction: New Jersey

Authority: Consumers through private civil actions; overlapping federal FCRA enforcement by the FTC and CFPB

New Jersey's credit reporting law mirrors and supplements the federal FCRA: consumer reporting agencies may furnish reports only for listed permissible purposes, and employers must give a standalone written disclosure and get written authorization before obtaining a report. Medical information may not be furnished for employment, credit, insurance, or direct marketing without written consent, and consumers can sue for willful or negligent violations.

View Details →

New Jersey Genetic Privacy Act

NJ Genetic Privacy Act
active

Jurisdiction: New Jersey

Authority: Criminal prosecution (disorderly persons offense); private civil action by the individual

New Jersey's Genetic Privacy Act treats genetic information as the individual's own: it may not be obtained, kept, or disclosed without informed consent, subject to listed law-enforcement, paternity, court-order, newborn-screening, and anonymous-research exceptions. People can ask for their DNA samples to be destroyed and can inspect and correct their genetic records.

View Details →

New Jersey Insurance Information Practices Act

NJ IIPA
active

Jurisdiction: New Jersey

Authority: New Jersey Commissioner of Banking and Insurance; individuals (remedies not verified)

New Jersey's version of the NAIC insurance privacy model law requires insurers, agents, and insurance-support organizations to give written notices of their information practices, to let people see and correct recorded personal information about them, and to disclose personal or privileged information only with written authorization or under listed exceptions.

View Details →

New Jersey Kids Code Act (New Jersey Age-Appropriate Design Code)

NJ Kids Code
enacted_not_effective

Jurisdiction: New Jersey

Effective: 9/1/2027

Authority: New Jersey Attorney General (Consumer Fraud Act powers and rulemaking); Commissioner of Health may add compulsive-use criteria; private actions by injured minors or their parents

Signed August 11, 2026 and effective September 1, 2027, the Kids Code requires social-media-type services that know a user is under 18 to set the highest privacy defaults, block unsolicited adult contact, hide location, limit data use and algorithmic feeds, and restrict engagement-driving design such as infinite scroll, autoplay, streaks, and night-time or school-hours notifications. Violations are consumer fraud and give injured minors a private right of action.

View Details →

New Jersey No Telemarketing Call Law

NJ Do Not Call Law
active

Jurisdiction: New Jersey

Authority: New Jersey Division of Consumer Affairs / Attorney General (Consumer Fraud Act)

New Jersey requires telemarketers to register annually with the Division of Consumer Affairs and bars unsolicited sales calls to numbers on the no-call list (which uses the FTC's national registry), to mobile devices, and between 9 p.m. and 8 a.m. Telemarketers must identify themselves, the seller, and the purpose within 30 seconds and may not block or spoof caller ID.

View Details →

New Jersey Wiretapping and Electronic Surveillance Control Act

NJ Wiretap Act
active

Jurisdiction: New Jersey

Authority: County prosecutors and the Attorney General (criminal); private civil actions by persons whose communications were unlawfully intercepted, disclosed, or used

New Jersey's wiretap law makes it a crime to intercept, disclose, or use wire, electronic, or oral communications without authorization and gives victims a civil damages claim. New Jersey is a one-party consent state: a private person may record a communication they are a party to, or where one party has consented, unless the purpose is criminal, tortious, or otherwise injurious. The Act also protects stored communications and limits provider disclosures of customer records, including device location, to law enforcement.

View Details →

No recording in employee restrooms, locker rooms, and changing rooms

Lab. Code 435
active

Jurisdiction: California

Effective: 1/1/1999

Authority: Local prosecutors

Prohibits employers from audio or video recording employees in restrooms, locker rooms, or changing rooms without a court order, and bars use of any such recording.

View Details →

Non-academic Student Surveys (parental consent policy)

NH Student Survey Consent Law
active

Jurisdiction: New Hampshire

Authority: New Hampshire State Board of Education / Department of Education

Requires school districts to adopt a policy under which students may not be required to take non-academic surveys (about social behavior, family life, religion, politics, sexual orientation or activity, drug use and similar topics) without written parental consent, except the CDC Youth Risk Behavior Survey, which parents may opt out of. Surveys must be posted for parental review at least 10 days before use.

View Details →

Nonconsensual Dissemination of Private Sexual Images

NH Intimate Image Law
active

Jurisdiction: New Hampshire

Effective: 7/19/2016

Authority: State and county prosecutors

Criminalizes purposely sharing an identifiable person's sexual or intimate images, obtained in circumstances where privacy was expected, to harass, intimidate, threaten or coerce them without consent. A 2024 amendment effective Jan. 1, 2025 extends the offense to realistic synthetic images created by manipulating a recognizable person's likeness.

View Details →

Nonconsensual Dissemination of Private Sexual Images (civil and criminal)

MN NCII Law
active

Jurisdiction: Minnesota

Authority: Depicted individual by civil action (604.31); criminal prosecution (617.261)

Enacted in 2016, these sections let a person sue, and allow prosecution of anyone, who shares sexual images of an identifiable person without consent when the image was made or obtained with a reasonable expectation of privacy. The civil section also covers using someone's personal information to solicit sexual acts in a way meant to harass or frighten them, and it preserves Section 230 protections for platforms.

View Details →

Nonconsensual dissemination of private sexual images (including AI-generated depictions)

OK Intimate Image Law
active

Jurisdiction: Oklahoma

Effective: 11/1/2016

Authority: District attorneys (criminal prosecution)

Criminalizes disseminating sexual images obtained under circumstances indicating they were to remain private, without the depicted person's consent. A 2025 amendment (Laws 2025, c. 23, effective November 1, 2025) extends the crime to artificially generated sexual depictions ('deepfakes') disseminated to harass or harm the depicted person.

View Details →

Nonconsensual Dissemination of Sexual Deep Fakes (civil and criminal)

MN Intimate Deepfake Law
active

Jurisdiction: Minnesota

Effective: 8/1/2023

Authority: Depicted individual by civil action (604.32); criminal prosecution (617.262)

Creates a civil cause of action and a crime for spreading AI-generated or otherwise technically produced sexual deep fakes of an identifiable person without consent to public dissemination. Consent to creation or private sharing is not a defense, and courts must allow confidential filings to protect the plaintiff's privacy.

View Details →

Nonconsensual distribution of intimate images (revenge porn), including computer-generated images

MD Revenge Porn Law
active

Jurisdiction: Maryland

Authority: State's Attorneys (criminal); civil actions by the person depicted

Maryland criminalizes knowingly distributing intimate images of an identifiable person, with intent to harm, harass, or coerce, when the person knew or recklessly disregarded that the subject did not consent and the subject reasonably expected the image to stay private. A 2025 amendment (ch. 219) extended the definition to computer-generated images indistinguishable from the person and strengthened the civil action.

View Details →

Nonconsensual distribution of intimate images and sexually explicit deepfakes (civil actions)

Civ. Code 1708.85-1708.86
active

Jurisdiction: California

Effective: 1/1/2015

Authority: Private plaintiffs (courts)

Gives victims a civil claim against people who share their intimate images without consent (revenge porn) and against those who create or distribute sexually explicit AI or digitally altered depictions of them without consent. Plaintiffs may proceed under a pseudonym.

View Details →

Nonconsensual Intimate Images (criminal distribution and civil action), including AI-generated images

IN Intimate Image Law
active

Jurisdiction: Indiana

Effective: 7/1/2019

Authority: County prosecutors (criminal); depicted individuals (civil)

Indiana makes it a crime to distribute an intimate image when the distributor knows or should know the person shown did not consent. Since July 1, 2024, this covers images created or altered with AI or editing software. A separate civil action lets identifiable victims sue people who disclose intimate images to harass, intimidate, embarrass, or profit.

View Details →

Notice of Intent to Sell Nonpublic Personal Information Act

Utah NPI Notice Act
active

Jurisdiction: Utah

Authority: None stated; private individual actions only

Requires a commercial entity that may sell consumers' nonpublic personal information (such as SSN, creditworthiness, purchasing patterns, or preferences) to give a prescribed, conspicuous notice before collecting it. 2025 S.B. 150 limited coverage to entities with a staffed physical office in Utah and barred class actions.

View Details →

Notice of Monitoring of Telephone Transmissions, Electronic Mail and Internet Usage

DE Employee Monitoring Notice
active

Jurisdiction: Delaware

Effective: 8/9/2001

Authority: Civil penalty claims may be filed in any court of competent jurisdiction (705(c))

Delaware employers may not monitor or intercept employees' phone calls, email, or Internet use unless they give notice, either a daily electronic notice when the employee logs on or a one-time written or electronic notice the employee acknowledges. Automated volume-management and system-maintenance processes not aimed at a particular person are exempt.

View Details →

Notice of Security Breach

NH Breach Notification Law
active

Jurisdiction: New Hampshire

Effective: 1/1/2007

Authority: New Hampshire Attorney General (under RSA 358-A:4); private individuals may also sue

Requires anyone doing business in New Hampshire to investigate a breach of computerized personal information (name plus SSN, driver's license or government ID number, or financial account/card number with access code) and notify affected individuals as soon as possible when misuse has occurred, is reasonably likely, or cannot be ruled out. The Attorney General or the entity's primary regulator must also be told, and nationwide consumer reporting agencies when more than 1,000 consumers are notified.

View Details →

Notification of tax return data breach (income tax return preparers)

VA tax preparer breach
active

Jurisdiction: Virginia

Effective: 7/1/2018

Authority: Virginia Department of Taxation (receives notices)

Requires paid tax return preparers to notify the Virginia Department of Taxation without unreasonable delay after unauthorized acquisition of unencrypted taxpayer return information that causes or may cause identity theft or fraud, so the Department can guard against fraudulent refunds.

View Details →

Obtaining personal information by false representation (anti-phishing)

ORS 646A.808
active

Jurisdiction: Oregon

Effective: 5/21/2015

Authority: Oregon Attorney General and district attorneys (ORS 646.632)

Bars phishing: using electronic means to get someone's personal information by pretending, without permission, to be another person or business.

View Details →

Off Duty Use of Tobacco by Employee

IN Off-Duty Tobacco Use
active

Jurisdiction: Indiana

Authority: Private enforcement by employees and applicants

Indiana employers may not require employees or applicants to avoid tobacco use outside work, or discriminate against them for it. Health-benefit incentives meant to reduce tobacco use are allowed.

View Details →

Oklahoma Consumer Data Privacy Act (data privacy provisions of 2026 SB 546)

OKCDPA
enacted_not_effective

Jurisdiction: Oklahoma

Effective: 1/1/2027

Authority: Oklahoma Attorney General (exclusive authority)

Oklahoma's comprehensive consumer privacy law, signed March 20, 2026, gives Oklahoma residents rights to confirm, access, correct, delete, and port their personal data and to opt out of targeted advertising, sale, and significant-decision profiling. Controllers must minimize collection, secure data, get consent before processing sensitive data (COPPA-compliant processing for known children), publish a privacy notice, and conduct data protection assessments for higher-risk processing. It takes effect January 1, 2027.

View Details →

Oklahoma Consumer Report Security Freeze Act

OK Security Freeze Act
active

Jurisdiction: Oklahoma

Effective: 1/1/2007

Authority: Private enforcement by consumers in court

Lets Oklahoma residents place a security freeze on their credit reports so consumer reporting agencies cannot release the report or score for new credit without the consumer's authorization. Sets deadlines for placing, temporarily lifting, and removing freezes and gives consumers a damages remedy.

View Details →

Oklahoma Hospital Cybersecurity Protection Act of 2023

OK Hospital Cybersecurity Act
active

Jurisdiction: Oklahoma

Effective: 11/1/2023

Authority: None (safe-harbor statute applied by courts)

A voluntary cybersecurity safe harbor for Oklahoma hospitals. A hospital that keeps a documented written cybersecurity program reasonably conforming to the HIPAA Security Rule and HITECH requirements, reviewed annually, gets an affirmative defense to tort suits over data breaches of personal or other identifying information.

View Details →

Oklahoma Responsible Technology in Schools Act

OK Responsible Technology in Schools Act
active

Jurisdiction: Oklahoma

Effective: 7/1/2026

Authority: State Board of Education (rulemaking) and State Department of Education (guidance)

Sets guardrails for AI use in Oklahoma public schools: AI must be educator-directed with a human in the loop, may not be the primary basis for grading, discipline, or placement, and must comply with student data privacy laws with data minimization. Districts must give parents an annual written disclosure of AI tools, vendors, and student data collected and shared, let parents opt students out of student-facing AI, and adopt an AI policy before the 2027-2028 school year.

View Details →

Online Age Verification Liability Act

Nebraska Online Age Verification Liability Act
active

Jurisdiction: Nebraska

Effective: 7/19/2024

Authority: Private civil action only (no agency enforcement provision in the act)

Enacted by LB1092 (2024), this law requires adult-content websites to verify that users are at least 18 using a digitized ID, government ID, financial or other reliable document, or a commercially reasonable transactional-data method. It has a privacy component: the site or its verifier may not keep identifying information after granting access.

View Details →

Online Education Services and Student Educational Records Act (student data privacy)

NJ Student Online Privacy Law
active

Jurisdiction: New Jersey

Effective: 7/19/2020

Authority: New Jersey Attorney General / Division of Consumer Affairs (Consumer Fraud Act), with rulemaking in consultation with the Commissioner of Education

This student data privacy law bars K-12 ed-tech operators from using students' information for targeted advertising, building non-school profiles, or selling or renting it, and limits when they may disclose it. Operators must secure student data and delete it at the request of the school, the district, or a student who has turned 18.

View Details →

Online Services, Products or Features Offered to Minors (heightened-risk duty of care)

CT Minors Online Services
active

Jurisdiction: Connecticut

Effective: 10/1/2024

Authority: Connecticut Attorney General (solely; Conn. Gen. Stat. 42-529e(a))

Requires online services that know or wilfully disregard that users are minors to use reasonable care to avoid a heightened risk of harm to them, document data protection assessments, and limit how minors' data is used. From July 1, 2026 (P.A. 25-113), targeted advertising and sale of minors' data are flatly banned regardless of consent, adult-to-minor unsolicited messaging must be blocked by default, and engagement-maximizing design features are restricted.

View Details →

Online services, products, or features likely to be accessed by children (AB 2246, 2026 replacement of the Age-Appropriate Design Code)

AB 2246 Children's Online Design Law
enacted_not_effective

Jurisdiction: California

Effective: 1/1/2027

Authority: California Attorney General and public prosecutors

Signed September 10, 2026, AB 2246 repeals the 2022 Age-Appropriate Design Code and re-enacts a narrower version: age estimation (tied to the Digital Age Assurance Act signals) or child protections for all users, high-privacy defaults, limits on profiling, data collection, and precise geolocation, and a new duty to take reasonable steps to prevent listed harms to children. It drops the data protection impact assessment and 'best interests' tests that courts had enjoined, and it lets a child void contract terms obtained through a design feature.

View Details →

Opportunity to Compete Act (criminal history inquiries in hiring)

NJ Opportunity to Compete Act
active

Jurisdiction: New Jersey

Effective: 3/1/2015

Authority: New Jersey Commissioner of Labor and Workforce Development

New Jersey's ban-the-box law bars covered employers from asking about an applicant's criminal record, including expunged records, on applications or otherwise during the initial application process, which ends after the first interview. Employers may ask later, or earlier if the applicant volunteers the information, but may not refuse to hire based on an expunged record.

View Details →

Oregon Consumer Information Protection Act: breach notification

OCIPA breach notification
active

Jurisdiction: Oregon

Effective: 10/1/2007

Authority: Oregon Attorney General (unlawful practice under ORS 646.607) and the Director of the Department of Consumer and Business Services (ORS 646A.624)

Requires any business or other entity holding Oregon residents' personal information to notify affected consumers of a data breach within 45 days, and the Attorney General when more than 250 Oregonians are affected. Vendors must alert the covered entity within 10 days. Notice may be skipped only after a documented determination that harm is unlikely.

View Details →

Oregon Consumer Information Protection Act: data security, disposal and SSN protection

OCIPA safeguards and SSN
active

Jurisdiction: Oregon

Effective: 10/1/2007

Authority: Oregon Attorney General (ORS 646.607(9)) and Director of the Department of Consumer and Business Services (ORS 646A.624)

Requires covered entities and vendors to keep reasonable administrative, technical and physical safeguards for personal information, including secure disposal, with safe harbors for GLBA or HIPAA compliance and a scaled standard for small businesses. It also restricts printing, posting and careless disposal of Social Security numbers.

View Details →

Oregon Consumer Information Protection Act: security freeze

OCIPA security freeze
active

Jurisdiction: Oregon

Effective: 10/1/2007

Authority: Director of the Department of Consumer and Business Services (ORS 646A.624) and Oregon Attorney General (ORS 646.607(9))

Lets Oregon consumers, and representatives of children 16 and under or incapacitated adults, freeze their credit reports for free. Agencies must place a freeze within five business days and create a frozen protective record for a protected consumer who has no file.

View Details →

Oregon Consumer Privacy Act

OCPA
active

Jurisdiction: Oregon

Effective: 7/1/2024

Authority: Oregon Attorney General (Department of Justice), exclusive (ORS 646A.589(7))

Max Fine: Up to $7,500 per violation

Oregon's comprehensive consumer privacy law gives residents rights to confirm processing, get a list of specific third parties that received their data, access, correct, delete, and port their data, and opt out of targeted advertising, sale, and significant-decision profiling. Controllers must give a privacy notice, minimize data, secure it, get opt-in consent for sensitive data, run data protection assessments, and (since 2026-01-01) honor universal opt-out signals. 2025 amendments bar selling precise geolocation data and data of known under-16 consumers and extend coverage to all vehicle makers.

consumer_rightsopt_outsensitive_datachildren
View Details →

Oregon Data Broker Registry law

Data Broker Registry
active

Jurisdiction: Oregon

Effective: 1/1/2024

Authority: Oregon Department of Consumer and Business Services (Division of Financial Regulation)

Requires data brokers to register annually (mandatory since January 1, 2024; $600 fee) with the Department of Consumer and Business Services before collecting, selling or licensing brokered personal data about Oregon residents. Registration discloses whether and how residents can opt out, and the department publishes registrant information online.

View Details →

Oregon financial records privacy law

ORS 192.583-192.607
active

Jurisdiction: Oregon

Authority: Private civil action by customers (ORS 192.606)

Bars Oregon financial institutions from handing customer financial records to state or local agencies, and bars agencies from requesting them, except through listed channels such as customer authorization, subpoena or summons, search warrant, or abuse investigations.

View Details →

Oregon Genetic Privacy Act

Oregon Genetic Privacy Act
active

Jurisdiction: Oregon

Authority: Oregon Attorney General and district attorneys (ORS 192.545); Oregon Health Authority rules (ORS 192.547); private actions (ORS 192.541)

Treats genetic information and DNA samples as private property of the individual in practice: they may not be obtained without informed consent, must be kept confidential, and may not be disclosed in identifiable form without specific written consent except in narrow cases. It carries some of the highest statutory damages of any state genetic privacy law.

View Details →

Oregon insurance information and privacy protection law

ORS 746.600-746.690
active

Jurisdiction: Oregon

Authority: Director of the Department of Consumer and Business Services (Division of Financial Regulation) (ORS 746.670); limited private remedies (ORS 746.680)

Oregon's version of the NAIC insurance privacy model, combined with GLBA-style notice rules. It requires privacy notices, limits pretext interviews and disclosures, gives consumers rights to access and correct recorded personal information and to learn the reasons for adverse underwriting decisions, and limits use of credit history and insurance scores in personal lines.

View Details →

Oregon interception and recording of communications law

ORS 165.540 (recording consent)
active

Jurisdiction: Oregon

Authority: District attorneys and Oregon Attorney General (criminal); private civil actions under ORS 133.739

Oregon is one-party consent for telephone and radio communications but requires that all participants be specifically informed before an in-person conversation is recorded with a device. It also bars using or disclosing unlawfully obtained communications, with exceptions for open recordings of public meetings, classes, police officers performing duties, and certain video-conference recordings.

View Details →

Oregon motor vehicle records privacy law

ORS 802.175-802.191
active

Jurisdiction: Oregon

Authority: Attorney General, district attorneys, and aggrieved individuals (ORS 802.191)

Oregon's counterpart to the federal Driver's Privacy Protection Act. It bars DMV disclosure of personal information from motor vehicle records except for permitted purposes and restricts resale and redisclosure by recipients, with record-keeping duties and a private right of action.

View Details →

Oregon protected health information law

ORS 192.553-192.581 (PHI)
active

Jurisdiction: Oregon

Authority: No specific enforcer named; no new private right of action (ORS 192.571)

Oregon's state counterpart to HIPAA declares a right to have protected health information safeguarded and to access it, and sets when health care providers and state health plans may use or disclose it with or without authorization. It works alongside the federal HIPAA Privacy Rule.

View Details →

Oregon Student Information Protection Act

OSIPA
active

Jurisdiction: Oregon

Effective: 7/1/2016

Authority: Oregon Attorney General (unlawful trade practice under ORS 646.607(11))

Oregon's K-12 edtech privacy law, modeled on California's SOPIPA. It bars operators of school-purpose sites and apps from targeted advertising, building student profiles for non-school purposes, selling student information, and most disclosures, and requires reasonable security and deletion at a school's request.

View Details →

Oregon telephone solicitation laws (telephonic seller registration, no-call list, solicitation limits)

Oregon Telephone Solicitation Laws
active

Jurisdiction: Oregon

Authority: Oregon Attorney General (Department of Justice); private enforcement under ORS 646.638

Oregon requires telephonic sellers to register with the Department of Justice, bars telephone solicitations to numbers on the do-not-call list (Oregon uses the federal registry), and limits when and how often sellers may call or text. A 2025 law (HB 3865) extended the solicitation rules to text messages starting January 1, 2026.

View Details →

Oversight of Artificial Intelligence Technology in Mental Health Care Act

RI Mental Health AI Act
active

Jurisdiction: Rhode Island

Effective: 6/22/2026

Authority: Rhode Island Executive Office of Health and Human Services (investigation and rules); courts and prosecutors for confidentiality penalties

Limits how AI may be used in mental health care. Licensed therapists may use AI for administrative and supplementary tasks, but may not let it make therapeutic decisions, set treatment plans or talk with clients therapeutically, and must get written informed consent before using emotionally engaging or companion-type AI in recorded or transcribed sessions. Only licensed professionals may offer therapy to the public, including through AI apps, and therapy records and communications stay confidential.

View Details →

Ownership and Control of Patient Records; Confidentiality (health care practitioners)

Florida Patient Records Law
active

Jurisdiction: Florida

Authority: Professional licensing boards and the Department of Health; Florida Attorney General for records owners not licensed by the state

Florida's core medical-records privacy rule for doctors and other licensed practitioners. It requires practitioners to give patients copies of their records promptly and at no more than cost, bars disclosing records or discussing a patient's condition without written authorization except in listed cases, and sets duties when a practice closes or moves.

View Details →

Parent's Accountability and Child Protection Act (online sales of age-restricted products)

Civ. Code 1798.99.1
active

Jurisdiction: California

Effective: 1/1/2020

Authority: California Attorney General and local prosecutors

Requires sellers of products and services that minors may not legally buy to take reasonable steps (such as checking government ID, requiring a non-prepaid credit card, or shipping only to an adult) to confirm buyers are of legal age, and bars using the age-verification data for anything else.

View Details →

Parental Access to Student Records (education records disclosures)

IN Student Records Access
active

Jurisdiction: Indiana

Authority: Not specified in the chapter

Indiana requires public and private schools to give custodial and noncustodial parents equal access to a child's education records unless a court order limits access. It also sets when FERPA-covered schools may share education records with juvenile justice agencies or in health and safety emergencies without parental consent.

View Details →

Parental Bill of Rights (school records, data collection and recording provisions)

NH Parental Bill of Rights
active

Jurisdiction: New Hampshire

Effective: 7/1/2025

Authority: Courts, through parent lawsuits

Lists parental rights that public schools may not infringe without clear and convincing evidence of a narrowly tailored compelling interest. Privacy-related rights include opting a child out of nonacademic surveys and district-level data collection not required by law, accessing education and school-held medical records within 10 business days, and written consent before the school or state makes video or voice recordings of the child, with limited exceptions.

View Details →

Parental Rights in Social Media Act

Nebraska PRSMA
enjoined

Jurisdiction: Nebraska

Effective: 7/1/2026

Authority: Nebraska Attorney General

Enacted as sections 26-30 of LB383 (2025), this law requires social media platforms to verify the age of new account holders, bar minors from opening accounts without verified parental consent, delete verification data, and give parents tools to supervise a minor's account. On June 27, 2026, the U.S. District Court for the District of Nebraska (NetChoice v. Hilgers, No. 4:26-cv-3149) preliminarily enjoined the Attorney General from enforcing the age verification requirement in 86-1703(1)(a) and the parental consent requirement in 86-1703(2); the court held the remaining provisions, including parental supervision of posts and messages, may be enforced. Status is recorded as enjoined because the core account-creation duties are blocked; the other duties are in force.

View Details →

Parents' Bill of Rights

OK Parents' Bill of Rights
active

Jurisdiction: Oklahoma

Effective: 11/1/2014

Authority: Courts; district attorneys for the misdemeanor consent provisions

Reserves parental rights to direct a child's upbringing, education, and health care, including rights to review the child's school and medical records and to give written consent before a child's biometric scan is made, shared, or stored or a record of the child's blood or DNA is created, stored, or shared. It also requires written parental consent before government records video or voice of a child (with exceptions) and before most medical or mental health treatment of minors.

View Details →

Patient access to medical records

OK Medical Records Access
active

Jurisdiction: Oklahoma

Effective: 4/8/1976

Authority: District attorneys (misdemeanor for refusal); courts

Gives current and former patients a right to access and obtain copies of their medical records, images, and bills, and caps copy fees (with lower digital rates and no search or retrieval fees for patients). It also sets rules for release of a deceased patient's records and waiver of privilege in medical injury suits.

View Details →

Patient access to medical records

Colorado patient records access
active

Jurisdiction: Colorado

Effective: 7/1/1976

Authority: Colorado Department of Public Health and Environment and professional licensing boards

Colorado gives patients and their personal representatives the right to inspect and obtain copies of their medical records, including X-rays, from health facilities and individual providers, consistent with HIPAA's access exceptions. Records must be delivered electronically when requested and kept electronically, inspection is free, and copy fees are limited to what HIPAA allows. The Colorado Privacy Act exempts health-care information governed by this part for purposes of records access.

View Details →

Patient Access to Medical Records

Nebraska Medical Records Access Law
active

Jurisdiction: Nebraska

Authority: No specific enforcement provision

This law gives patients and their authorized representatives a right to examine and copy their medical records, with fee caps. Written authorizations that lack an expiration expire after 12 months, and mental health records may be withheld if a treating professional finds release is not in the patient's best interest.

View Details →

Patient Access to Medical Records and Test Results

CT Medical Records Access
active

Jurisdiction: Connecticut

Authority: Connecticut Department of Public Health (licensing)

Requires providers to give patients, on request, complete and current information about their diagnosis, treatment and prognosis, to notify patients of test results, and to furnish copies of records; clinical labs must release results to patients on request.

View Details →

Patient's Privacy Protection Act

Tenn. Patient's Privacy Protection Act
active

Jurisdiction: Tennessee

Authority: Tennessee Department of Health and licensing board (penalties and injunctions under title 68, chapter 11); patients through civil actions

Gives every patient at a licensed Tennessee health care facility a right to privacy for the care received there. Facilities may not divulge a patient's name, address, or other identifying information except for required reports, payer administrative access, treating providers, directory information when the patient has been told of and not used the right to object, and certain fraud investigations.

View Details →

Patients' Bill of Rights (licensed health facilities, confidentiality of records)

NH Patients' Bill of Rights
active

Jurisdiction: New Hampshire

Authority: NH Department of Health and Human Services (facility licensing)

Requires every licensed health facility's patient rights policy to guarantee privacy in treatment and personal care and confidential handling of personal and clinical records, including electronically stored data. Release to anyone not authorized by law requires the patient's written consent, and patients own and may copy the medical information in their facility records.

View Details →

Payment card receipt truncation

MD Card Receipt Truncation
active

Jurisdiction: Maryland

Authority: Attorney General (14-1318(d))

Merchants in Maryland may not print more than five digits of a credit or debit card number, or the card's expiration date, on electronically printed customer receipts.

View Details →

Peeping Tom and clandestine video voyeurism law

OK Peeping Tom Law
active

Jurisdiction: Oklahoma

Authority: District attorneys (criminal prosecution)

Criminalizes lurking to secretly watch people in homes, locker rooms, restrooms, and similar private places, and using cameras or electronic equipment to secretly view or record people there or to capture images of their private areas, including publishing such images.

View Details →

Pen Register, Trap and Trace, and Mobile Tracking Device Restrictions

MN Tracking Device Law
active

Jurisdiction: Minnesota

Authority: Private civil action by harmed persons (626A.391); court orders govern law enforcement use (626A.36 to 626A.38)

No one may install or use a pen register, trap and trace device, or mobile tracking device (such as a GPS tracker) without a court order, unless an exception applies, most notably consent of the owner of the object to which a tracker is attached. People harmed by unlawful tracking or call-data capture can sue for damages and attorney fees.

View Details →

Personal Information and Privacy Protection Act (retail ID card scanning)

NJ PIPPA
active

Jurisdiction: New Jersey

Effective: 10/1/2017

Authority: Civil penalties collected in a summary proceeding under the Penalty Enforcement Law of 1999; aggrieved persons may sue in Superior Court

New Jersey retailers may scan a customer's ID card only for eight listed purposes, such as verifying identity for non-cash payments or returns, checking age, preventing return or credit fraud, or meeting legal requirements. They may capture only name, address, date of birth, issuing state, and ID number, may not keep data scanned for identity or age checks, and may not sell or share scanned data for marketing.

View Details →

Personal information on the internet: protected persons (anti-doxxing)

Colorado protected-person doxxing law
active

Jurisdiction: Colorado

Effective: 7/1/2002

Authority: District attorneys (criminal prosecution)

Colorado makes it a crime to knowingly post a protected person's personal information online when doing so poses an imminent and serious threat to their or their family's safety. Protected persons can also ask government officials to remove their personal information from online public records. Recent amendments added educators (2022), health-care workers and others (2023), and firefighters (2024).

View Details →

Personal Information Privacy Act (merchant sale of purchaser information, check DOB, driver's license scanning)

VA PIPA
active

Jurisdiction: Virginia

Effective: 7/1/1992

Authority: Aggrieved persons in general district court (59.1-444)

An older retail privacy law. Merchants must give notice (a sign is enough) before selling purchaser information gathered in a sale and must honor a customer's request not to sell it; they cannot sell information gathered only from check, card, or ID-number payment records. It also bars requiring a date of birth to accept a check and limits when merchants may scan, keep, or sell data from a driver's license barcode.

View Details →

Personal Information Security and Breach Investigation Law for Public Agencies and Nonaffiliated Third Parties

KY Public Agency / Vendor Data Security (HB 5)
active

Jurisdiction: Kentucky

Effective: 1/1/2015

Authority: Kentucky Attorney General (Franklin Circuit Court)

Requires public agencies and the private contractors that receive personal information from them to maintain reasonable security and breach investigation procedures. Contractors must report breaches to the agency within 72 hours, and agencies must notify state officials within 72 hours, investigate, and notify affected individuals within 35 days of concluding misuse is likely. Personal information includes name, personal mark, or a biometric or genetic print combined with identifiers such as SSN, account numbers, ID numbers, or health information.

View Details →

Personal Information Security Breach Protection

Iowa Breach Notification Law
active

Jurisdiction: Iowa

Effective: 7/1/2008

Authority: Iowa Attorney General (Consumer Protection Division), as an unlawful practice under Iowa Code 714.16

Iowa's breach law requires anyone who owns or licenses computerized personal information of Iowa residents to notify affected residents of a breach of security without unreasonable delay, and to notify the Attorney General within five business days if more than 500 Iowans are notified. It also covers paper records that were printed from computerized form. Notice is not required if a documented investigation finds no reasonable likelihood of financial harm.

View Details →

Personal Online Account Privacy Protection Act

LA POAPPA
active

Jurisdiction: Louisiana

Effective: 8/1/2014

Authority: None specified

Bars employers and schools from requiring employees, applicants, students, or prospective students to hand over usernames, passwords, or other login credentials for their personal online accounts, and from punishing them for refusing. Employers may still require credentials for employer-provided devices and business accounts and may investigate specific reports of misconduct or data leakage. The law creates no duty to monitor personal accounts.

View Details →

Personnel Information: Employee Access to Personnel Files

Iowa Personnel File Access Law
active

Jurisdiction: Iowa

Authority: Not specified in the section

Iowa employees have the right to see and copy their personnel files, including performance evaluations and disciplinary records. Employers may set a mutually agreed time, have a representative present, withhold references, and charge commercial-rate copy fees.

View Details →

Persons Holding a Customer's Personal Information (disposal of customer records)

IN Customer Data Disposal
active

Jurisdiction: Indiana

Authority: Prosecuted as an infraction (no agency named in the chapter)

This chapter makes it an infraction to throw away or abandon customers' unencrypted, unredacted personal information (as defined in the breach law, such as SSNs and financial account numbers) in a publicly accessible place without first destroying it. It covers paper and digital records.

View Details →

Physician-Patient Communication (Medical Practice Act confidentiality)

Texas Physician-Patient Confidentiality
active

Jurisdiction: Texas

Effective: 9/1/1999

Authority: Texas Medical Board; aggrieved patients

Makes physician-patient communications and physician records of identity, diagnosis, evaluation, and treatment confidential and privileged, with listed exceptions, and gives patients a right to copies within 15 business days of written consent. S.B. 922 (2025) delays online release of sensitive test results such as possible cancer findings and genetic markers until the third day after they are finalized.

View Details →

Polygraph and Lie Detector Test Prohibition

DE Polygraph Ban
active

Jurisdiction: Delaware

Authority: Civil penalty claims may be filed in any court of competent jurisdiction (704(c))

Prohibits requiring, requesting, or suggesting that an employee or job applicant take a polygraph, lie detector, or voice-stress test as a condition of employment. Law-enforcement agencies are exempt for their own official duties.

View Details →

Polygraph Examination Prohibited (employment)

Iowa Employee Polygraph Protection Law
active

Jurisdiction: Iowa

Authority: Aggrieved employees and applicants (civil action); county attorneys and the Attorney General (injunctions and criminal prosecution)

Iowa bars employers from requesting, requiring, or administering lie detector tests to employees or job applicants as a condition of employment or benefits, or asking them to waive this protection. Employees who complain or testify are protected from retaliation.

View Details →

Polygraph Protection Act

VT Polygraph Protection Act
active

Jurisdiction: Vermont

Authority: Criminal prosecution (State's Attorneys / Attorney General)

Generally bars employers from requiring, requesting or giving lie detector tests to employees or job applicants, or from refusing to hire or promote someone who declines one. Limited exceptions are listed in § 494b.

View Details →

Predictive Genetic Testing Informed Consent

Nebraska Genetic Testing Informed Consent Law
active

Jurisdiction: Nebraska

Authority: Not stated in the section (professional regulation by the Department of Health and Human Services)

Nebraska requires written informed consent before a physician orders a predictive genetic test. The consent must explain the test's purpose and limits, future uses of the sample and genetic information, who can access them, and the patient's right to confidential treatment.

View Details →

Prescription Information to be Kept Confidential

NH Prescription Confidentiality Act
active

Jurisdiction: New Hampshire

Effective: 6/30/2006

Authority: Not specified in the section (pharmacy board and Attorney General have general authority)

Bars pharmacies, PBMs, insurers and transmission intermediaries from licensing, transferring, using or selling prescription records containing patient- or prescriber-identifiable data for commercial purposes, apart from reimbursement, formulary compliance, care management, utilization review, health care research, or as otherwise allowed by law. The First Circuit upheld the law in IMS Health v. Ayotte (2008), but that ruling was abrogated by Sorrell v. IMS Health (2011), which struck down a similar Vermont prescriber-data law, so the prescriber-data restriction is constitutionally vulnerable.

View Details →

Preventing Deepfake Images Act

Preventing Deepfake Images Act
active

Jurisdiction: Tennessee

Effective: 7/1/2025

Authority: Depicted individuals (civil action); district attorneys (criminal prosecution)

Creates a civil cause of action and a crime for intentionally disclosing a sexually explicit or intimate digital depiction of an identifiable person, created or altered by digital manipulation including AI deepfakes, without the person's consent. Consent to creation is not consent to disclosure, valid consent must be a signed plain-language agreement, and a disclaimer that the image is fake is not a defense.

View Details →

Preventing Unauthorized Disclosure of Intimate Digital Depictions Act

Colorado intimate deepfakes (SB 25-288)
active

Jurisdiction: Colorado

Effective: 8/6/2025

Authority: Depicted individuals (civil action); district attorneys (criminal offenses)

SB 25-288 lets people sue anyone who knowingly or recklessly discloses, or threatens to disclose, a realistic AI-generated or edited intimate image of them without consent. It also extends Colorado's crimes for posting private intimate images, and its child sexual exploitation laws, to realistic computer-generated depictions.

View Details →

Privacy Act Governing the Release of Motor Vehicle Driving History and License Records

DE Driver Privacy Act
active

Jurisdiction: Delaware

Authority: Criminal prosecution by the State; civil actions by the individual (305(n)-(o))

Delaware's counterpart to the federal Driver's Privacy Protection Act limits disclosure of personal information in DMV records to listed permissible uses, binds private recipients who resell or redisclose it, and lets individuals ask for added confidentiality of their address, phone number, and SSN. Misuse is a crime and gives the affected person a civil claim.

View Details →

Privacy and Disclosure of Bureau of Motor Vehicles Records

IN BMV Records Privacy
active

Jurisdiction: Indiana

Authority: Indiana Bureau of Motor Vehicles; county prosecutors

Indiana's state counterpart to the federal Driver's Privacy Protection Act bars BMV disclosure of personal information except for listed permissible uses, such as government functions, vehicle safety and recalls, fraud prevention by businesses, and litigation. Highly restricted information (photos, SSNs, medical and disability data) generally needs express written consent. Private recipients who resell or redisclose the data must stay within permitted uses and keep records of who received it.

View Details →

Privacy in Communications (recording consent and interception)

MT Privacy in Communications
active

Jurisdiction: Montana

Authority: County attorneys and the Attorney General (criminal prosecution)

Montana is an all-party-consent state for hidden recording: it is a crime to record a conversation with a hidden device without the knowledge of all parties, unless the parties were warned. It is also a crime to purposely intercept electronic communications without warning. A 2025 amendment (Ch. 686, L. 2025) added AI-generated ('digitally fabricated') intimate images to the image-disclosure and sextortion offenses.

View Details →

Privacy in Private Spaces (employee recording in restrooms and locker rooms)

RI Employee Private Spaces Law
active

Jurisdiction: Rhode Island

Authority: Courts via employee civil actions

Prohibits employers from making audio or video recordings of employees in restrooms, locker rooms or employer-designated changing rooms unless a court order authorizes it, and bars any use of recordings made in violation.

View Details →

Privacy of Consumer Financial and Health Information (Insurance Department rules)

NH Ins 3000
active

Jurisdiction: New Hampshire

Effective: 7/1/2001

Authority: New Hampshire Insurance Commissioner

New Hampshire's insurance privacy rules, modeled on the NAIC privacy model regulation, require licensees to give privacy notices and let consumers opt out before nonpublic personal financial information is shared with nonaffiliated third parties. They also require the consumer's written or electronic authorization before a licensee discloses nonpublic personal health information, apart from listed insurance functions.

View Details →

Privacy of Consumer Financial and Health Information (Iowa Insurance Division rules)

Iowa Insurance Privacy Rule
active

Jurisdiction: Iowa

Effective: 11/13/2000

Authority: Iowa Commissioner of Insurance (Iowa Insurance Division)

Iowa's insurance privacy rules, based on the NAIC model, require insurance licensees to give privacy notices, let consumers opt out of sharing financial information with nonaffiliated third parties, and obtain authorization before disclosing health information except for core insurance functions. They also require an information security program.

View Details →

Privacy of Consumer Financial and Health Information and Standards for Safeguarding Customer Information (insurance regulations)

RI Insurance Privacy Regulations
active

Jurisdiction: Rhode Island

Authority: Rhode Island Department of Business Regulation, Insurance Division

Rhode Island's insurance-sector implementation of Gramm-Leach-Bliley privacy and safeguards rules, adopted under R.I. Gen. Laws §§ 27-58-4 and 27-58-10. Licensees must give initial and annual privacy notices and an opt-out before sharing consumers' nonpublic financial information with nonaffiliated third parties, must obtain written authorization before disclosing nonpublic health information outside listed insurance functions, and must maintain written information security programs.

View Details →

Privacy of Firearms Financial Transactions

IN Firearms Transaction Privacy
active

Jurisdiction: Indiana

Effective: 10/1/2024

Authority: The provider's primary financial regulator; the Indiana Attorney General for the registry ban as applied to persons who are not regulated financial services providers (IC 24-5-27.5-25)

Enacted by HEA 1084 (2024), this law bars payment networks and acquirers from assigning a separate firearms merchant category code to Indiana gun retailers. It restricts financial providers from disclosing transaction records grouped by a firearms code and from declining transactions based solely on such a code. It also bars anyone from keeping a registry of privately owned firearms or their owners, with exceptions.

View Details →

Privacy of genetic test results

LA Genetic Test Confidentiality
active

Jurisdiction: Louisiana

Authority: None specified

Makes the results of prenatal and postnatal genetic tests confidential medical information that becomes part of the tested person's medical record. Results may be released only with the tested person's express written consent, except for genetic tests the law specifically requires to be reported.

View Details →

Privacy of Insurance Consumer Information Act

Nebraska Insurance Privacy Act
active

Jurisdiction: Nebraska

Authority: Nebraska Department of Insurance (Director of Insurance)

Nebraska's insurance privacy law implements Gramm-Leach-Bliley Title V for insurance licensees, based on the NAIC model. It requires initial and annual privacy notices, an opt-out before sharing nonpublic personal financial information with nonaffiliated third parties, and written authorization before disclosing nonpublic personal health information, subject to listed insurance-function exceptions.

View Details →

Privacy Rights for California Minors in the Digital World (online eraser and harmful-product marketing limits)

Minors Online Privacy (22580)
active

Jurisdiction: California

Effective: 1/1/2015

Authority: California Attorney General and local prosecutors (Unfair Competition Law)

Lets registered minor users remove content they posted (the 'online eraser') and bars marketing of alcohol, firearms, tobacco, cannabis, and other listed age-restricted products to minors, including using minors' personal information for that marketing.

View Details →

Private Sector Drug-Free Workplaces (employee drug and alcohol testing)

Iowa Workplace Drug Testing Law
active

Jurisdiction: Iowa

Authority: Aggrieved employees and applicants (civil action); county attorneys and the Attorney General (injunctions; Attorney General civil penalties for certain provisions)

Iowa permits private employers to drug and alcohol test employees and applicants only under a written policy and strict procedures. The law protects privacy during sample collection, keeps test communications confidential, gives tested workers access to their records and a right to a confirmatory retest, and lets aggrieved workers sue.

View Details →

Prohibited Spyware

IN Spyware Act
active

Jurisdiction: Indiana

Authority: Private enforcement by adversely affected software providers, website owners, and trademark owners

Indiana's spyware law bars installing software on someone else's computer that deceptively changes browser settings, logs keystrokes, or ties personal information to browsing history. It also bars extracting financial or identity data from the hard drive and tricking users into installing software with false security or privacy claims.

View Details →

Prohibited Use of Crime Victim or Motor Vehicle Collision Information

Texas Crime Victim Information Law
active

Jurisdiction: Texas

Effective: 4/1/2009

Authority: Texas Attorney General (DTPA 17.47 action); prosecutors

Bars using crime victim or crash information obtained from law enforcement to directly solicit victims, crash participants, or their families, and bars selling that information for profit.

View Details →

Prohibited use of employee's Social Security number

VA employee SSN
active

Jurisdiction: Virginia

Effective: 7/1/2023

Authority: Commissioner of Labor and Industry (40.1-28.7:10(B)-(C))

Bars employers from using an employee's Social Security number, or a number derived from it, as the employee's ID number or printing it on ID, access, or similar badges.

View Details →

Prohibited Uses of Artificial Intelligence in Mental Health Services

VT AI Mental Health Law
active

Jurisdiction: Vermont

Effective: 6/17/2026

Authority: Vermont Attorney General (Consumer Protection Act); Office of Professional Regulation and Board of Medical Practice for licensees

Bars companies from offering mental health services to the public, including AI therapy chatbots, unless a licensed or rostered mental health professional provides them or they are part of an approved IRB or privacy board study. Professionals may use HIPAA-compliant AI tools and FDA-authorized digital therapeutics if they review and approve the services.

View Details →

Prohibiting Social Media Manipulation Act

MN Social Media Manipulation Act
active

Jurisdiction: Minnesota

Effective: 7/1/2025

Authority: Minnesota Attorney General (325M.34)

Requires large social media platforms to publicly post how they limit excessive account interactions, how their ranking algorithms weigh content quality and users' expressed preferences, usage and late-night notification statistics by percentile, and the results of product experiments on 1,000 or more users. A 2026 amendment adds a duty to explain the platform's age estimation process, effective July 1, 2027. Under a court-filed stipulation, the Attorney General agreed not to enforce the Act against NetChoice members until the court rules on NetChoice's preliminary-injunction request (NetChoice v. Ellison, D. Minn. No. 0:25-cv-02741).

View Details →

Prohibition Against Requiring the Implantation of Devices (employee microchipping)

IN Employee Implant Ban
active

Jurisdiction: Indiana

Authority: Private enforcement by employees and applicants

Indiana employers may not require employees or applicants to have a device, such as an RFID microchip, implanted, injected, ingested, or otherwise put in their bodies as a condition of employment or benefits. They also may not retaliate against those who refuse, unless a court order requires the device.

View Details →

Prohibition on Nudification Technology

MN Nudification Ban
active

Jurisdiction: Minnesota

Effective: 8/1/2026

Authority: Minnesota Attorney General under 8.31; depicted individuals by civil action (325E.91, subds. 4-5)

Effective August 1, 2026, Minnesota bars operators of websites, apps, and software from letting users generate realistic fake nude images or videos of identifiable people ('nudification'), and bars advertising such services. Depicted people can sue for treble damages and punitive damages, and the Attorney General can seek civil penalties of up to $500,000 per use.

View Details →

Prohibition on selling higher-education student data to creditors

OK Student Data Sale Ban
active

Jurisdiction: Oklahoma

Effective: 7/1/2007

Authority: Not specified in the statute

Bars Oklahoma public colleges, universities, and technology center schools from entering agreements to sell student directory information to creditors for marketing consumer credit to students. Release under the Open Records Act is still allowed.

View Details →

Prohibition on unauthorized use of newborn DNA

OK Newborn DNA Law
active

Jurisdiction: Oklahoma

Effective: 5/10/2010

Authority: District attorneys (criminal statute)

Bars laboratories, hospitals, and birthing facilities from storing, transferring, using, or databasing a newborn's DNA without the parents' express consent.

View Details →

Proof of Vaccination for COVID-19

Iowa COVID-19 Vaccine Proof Ban
active

Jurisdiction: Iowa

Effective: 5/20/2021

Authority: State agencies awarding grants and contracts (loss of state funding)

Iowa bars businesses and government entities from requiring customers or visitors to show proof of COVID-19 vaccination before entering, and bars state and local ID cards from showing COVID-19 vaccination status. Screening protocols that do not require vaccine proof are allowed, and health care facilities are exempt.

View Details →

Property Owner's Consent Required for Smart Meter Gateway Devices

NH Smart Meter Gateway Consent Law
active

Jurisdiction: New Hampshire

Effective: 6/7/2012

Authority: New Hampshire Public Utilities Commission

Prohibits electric utilities from installing smart meter gateway devices, meaning meters or components that communicate with, monitor or control appliances inside a home or business, without the owner's written opt-in consent. Utilities must disclose whether such a device is installed and remove it on written request.

View Details →

Property Right in Name, Voice, and Visual Likeness (digital replicas)

MT Likeness Rights (HB 513)
active

Jurisdiction: Montana

Effective: 1/1/2026

Authority: Private enforcement by the individual or rights holder

HB 513 (Ch. 685, L. 2025) makes a person's name, voice and visual likeness a transferable, descendible property right lasting 20 years after death. It creates liability for commercially publishing AI or other computer-generated voice or visual replicas without consent, and for distributing tools built primarily to make them, with news, commentary, parody and similar First Amendment exceptions.

View Details →

Protect Tennessee Minors Act

PTMA
active

Jurisdiction: Tennessee

Effective: 1/1/2025

Authority: Tennessee Attorney General and Reporter (civil actions against commercial entities); district attorneys (criminal); private plaintiffs for damages

Requires adult-content websites to verify, with a photo-ID match or a commercially reasonable transactional-data method, that each visitor is 18 or older, and to re-verify after each age-verified session (at most 60 minutes). Verifiers must keep seven years of anonymized verification records but may not keep the user's identifying information after access is granted. A federal district court enjoined it in December 2024, but the Sixth Circuit stayed that injunction on January 13, 2025, and after Free Speech Coalition v. Paxton vacated it in November 2025; the challenge continues in the Western District of Tennessee without an injunction.

View Details →

Protected Consumer Report Security Freeze (minors under 16 and represented persons)

Florida Protected Consumer Freeze Law
active

Jurisdiction: Florida

Effective: 9/1/2014

Authority: Florida Department of Agriculture and Consumer Services; private civil actions

Lets a parent, guardian, or other representative freeze the credit file of a child under 16 or a represented adult. If no file exists, the agency must create a 'record' so it can be frozen. Agencies may not charge a fee to place or remove the freeze.

View Details →

Protected health information in legal advertising

Tenn. PHI Legal Solicitation Law
active

Jurisdiction: Tennessee

Effective: 7/1/2019

Authority: Tennessee Attorney General and Reporter (TCPA authority); district attorneys (criminal)

Bars anyone from using, obtaining, selling, transferring, or disclosing a person's protected health information to solicit them for legal services without the person's written authorization. The same part regulates legal advertisements about drugs and medical devices, requiring paid-advertisement disclosures and banning misleading "medical alert" or government-style framing.

View Details →

Protecting Children from Social Media Act

Protecting Children from Social Media Act
active

Jurisdiction: Tennessee

Effective: 1/1/2025

Authority: Tennessee Attorney General and Reporter, using Tennessee Consumer Protection Act investigation and enforcement powers (§§ 47-18-106, 47-18-108)

Requires social media companies to verify the age of anyone opening a new account and to get verified express parental consent before a minor under 18 can hold an account. Parents must get tools to view privacy settings, set daily time limits, and schedule breaks, and data used for verification may not be retained. NetChoice's challenge is pending: the district court denied a preliminary injunction in June 2025, and on August 28, 2026 the Sixth Circuit vacated that denial and remanded, so the law is in effect but under active challenge.

View Details →

Protecting DNA Privacy Act: Unlawful Use of DNA

Florida DNA Privacy Act
active

Jurisdiction: Florida

Effective: 10/1/2021

Authority: State attorneys (criminal)

Enacted by HB 833 (2021), this law makes it a crime to collect, analyze, disclose, or sell someone's DNA without their express consent. It applies even where the sample was first collected with consent, so a genetic-testing company that later sells or transfers a sample or results needs fresh express consent.

View Details →

Protecting Our Kids from Social Media Addiction Act (SB 976)

SB 976
active

Jurisdiction: California

Effective: 1/1/2025

Authority: California Attorney General (exclusive)

Bars platforms from giving minors personalized 'addictive feeds' without verifiable parental consent, limits notifications to minors overnight and during school hours, and requires parental controls with protective defaults. It is partly enjoined in NetChoice v. Bonta: the district court blocked the notification limits and the Ninth Circuit (Sept. 9, 2025; en banc denied Nov. 6, 2025) also blocked the like-count default, but let the addictive-feed ban and other defaults take effect. Age-assurance duties start January 1, 2027, and the Attorney General's implementing rules were in rulemaking as of September 2026.

View Details →

Protecting social security numbers from disclosure

Tenn. SSN Protection
active

Jurisdiction: Tennessee

Effective: 1/1/2008

Authority: Tennessee Attorney General (civil, as a part 21 and Tennessee Consumer Protection Act violation); district attorneys (criminal)

Requires businesses that hold Social Security numbers to make reasonable efforts to keep them from public disclosure. SSNs may not be publicly displayed, sent over the internet without a secure connection or encryption, used alone as a website login, printed on mailed materials unless required, or printed on cards or badges consumers must show to get services.

View Details →

Protection From Predatory Pricing Act (dynamic pricing and personal data in food retail and delivery)

MD Protection From Predatory Pricing Act
enacted_not_effective

Jurisdiction: Maryland

Effective: 10/1/2026

Authority: Consumer Protection Division, Office of the Attorney General

This 2026 administration bill bars large grocery stores and food delivery apps from using consumers' personal data to charge an individual consumer a higher, personalized price for tax-exempt food (for example through AI-driven pricing), and from using protected-class data in a way that denies a consumer an advantage or privilege offered to others. Loyalty programs, cost- and location-based differences, consented data-for-price offers, and error corrections are excluded.

View Details →

Protection of Children in Online Spaces

Florida Children in Online Spaces Law
active

Jurisdiction: Florida

Effective: 7/1/2024

Authority: Florida Department of Legal Affairs (Attorney General), exclusively

Created by the same 2023 bill as the Florida Digital Bill of Rights, this section limits how online platforms predominantly accessed by children may process minors' data. It bars processing that the platform knows or willfully disregards may cause substantial harm or privacy risk to children, restricts profiling, data collection beyond what is needed, precise geolocation, and dark patterns, and places the burden of proof on the platform.

View Details →

Protection of Children on Applications (Louisiana App Store Accountability Act)

LA App Store Act
enacted_not_effective

Jurisdiction: Louisiana

Effective: 7/1/2027

Authority: Louisiana Attorney General

Requires app stores to verify the age category (under 13, 13-15, 16-17, adult) of Louisiana users at account creation, link minors' accounts to a parent account, and obtain verifiable parental consent before a minor downloads or buys apps or makes in-app purchases. Developers must use the store's age signal and consent status, may not sell age category data, and may not enforce terms against minors without parental consent. Act 185 of 2026 stopped the 2025 version (Act 481) from taking effect on July 1, 2026 and re-enacted the scheme effective July 1, 2027.

View Details →

Protection of Children's Internet Data (social media targeted advertising and sale of minors' sensitive data)

LA Children's Internet Data Law
active

Jurisdiction: Louisiana

Effective: 7/1/2025

Authority: Louisiana Attorney General

Bars large social media platforms from showing targeted advertising to account holders they know are minors (under 18) and from selling minors' sensitive personal data, such as race, religion, gender, immigration status, health information, genetic or biometric identifiers, and specific geolocation. Contextual ads, first-party ads, and ad measurement are excluded from 'targeted advertising'. Platforms are shielded from liability for good-faith residency and age-estimation processing.

View Details →

Protection of Consumer Telephone Records

Texas Telephone Records Law
active

Jurisdiction: Texas

Effective: 9/1/2009

Authority: Texas Attorney General Consumer Protection Division; prosecutors

Criminalizes pretexting for telephone records: obtaining a Texan's phone records by lying to a phone company, fraudulent website access, or false documents, and selling or receiving records obtained that way.

View Details →

Protection of Driver's License and Social Security Numbers

Texas SSN Protection Law
active

Jurisdiction: Texas

Effective: 4/1/2009

Authority: Texas Attorney General or county prosecuting attorney

Restricts public display and insecure transmission of Social Security numbers, requires a privacy policy before a business may demand an SSN, and limits merchants' use of driver's license and Social Security numbers collected for returns. It also bars printing driver's license numbers on sales receipts.

View Details →

Protection of Identifying Financial Information (card receipt truncation)

Texas Card Receipt Law
active

Jurisdiction: Texas

Effective: 4/1/2009

Authority: Texas Attorney General or county prosecuting attorney

Bars printing more than the last four digits of a card number, or the expiration date, on receipts given to cardholders. Handwritten or imprinted receipts are exempt.

View Details →

Protection of Personal Information Act

Utah PPIA
active

Jurisdiction: Utah

Authority: Utah Attorney General

Utah's data security, disposal, and breach notification law. It covers name plus SSN, financial account or card number with access code, or driver license or state ID number. It requires reasonable safeguards, secure disposal, and notice to affected Utah residents, and at scale to the Attorney General, the Utah Cyber Center, and consumer reporting agencies.

View Details →

Protections for Minors Featured in Digital Content

HB 26-1058
enacted_not_effective

Jurisdiction: Colorado

Effective: 6/1/2027

Authority: Private enforcement by affected individuals; courts

HB 26-1058 protects child influencers from June 1, 2027: creators must keep records and put part of earnings in trust for featured minors. Adults (or emancipated minors) who were featured as identifiable minors may demand deletion or editing of posts, and platforms must offer a removal-request mechanism. Profiting from sexualized content of minors is prohibited.

View Details →

Psychotherapy Artificial Intelligence Restrictions

HB 26-1195
active

Jurisdiction: Colorado

Effective: 8/12/2026

Authority: Mental health licensing boards in the Department of Regulatory Agencies (professional discipline); Attorney General for the consumer-protection section

HB 26-1195 limits how therapists may use AI: AI may not conduct therapy or make treatment decisions without the professional's real-time involvement and approval, and clients must be told of the limits. Recording or transcribing a session with AI requires advance written disclosure and written consent. Separately, no one may market an AI system as providing psychotherapy or imply therapist-level confidentiality for user data.

View Details →

Public body disclosures to data brokers (immigration attestation)

SB 1587 (2026)
active

Jurisdiction: Oregon

Effective: 6/5/2026

Authority: None specified in the act

Bars Oregon public bodies from giving personally identifiable information to a data broker unless the broker first attests in writing that the data will not be sold or transferred to anyone who will use it to enforce federal immigration law. It binds data brokers indirectly, as a condition of receiving government data.

View Details →

Public School Student Records Access and Confidentiality

Nebraska Student Records Law
active

Jurisdiction: Nebraska

Authority: No specific enforcement provision (State Board of Education rules on data sharing)

Nebraska's student records law gives public school students and parents the right to inspect, review, and copy school records and bars disclosure to others without written consent, except to auditors, education authorities, and as FERPA allows. Disciplinary material must be kept separate and destroyed after three years of continuous absence.

View Details →

Publishing or distributing material harmful to minors on the Internet (adult website age verification)

VA age verification
active

Jurisdiction: Virginia

Effective: 7/1/2023

Authority: Private civil action

Requires commercial adult websites to verify that users are 18 or older through a commercial age and identity verification database or another commercially reasonable method, and makes them liable for damages when a minor gains access.

View Details →

Pupil records: contracts with third-party digital service providers

Educ. Code 49073.1
active

Jurisdiction: California

Effective: 1/1/2015

Authority: Parties to the contract; local educational agencies

Requires school contracts with cloud and education software vendors to keep pupil records under school control and bar vendors from using them for other purposes or targeted advertising, with security, breach notice, and deletion terms.

View Details →

Reader Privacy Act

Reader Privacy Act
active

Jurisdiction: California

Effective: 1/1/2012

Authority: Private plaintiffs; courts

Protects records of what people read. Book service providers may not disclose users' personal information to government entities, or be compelled to disclose it, except with a court order meeting strict findings (probable cause, compelling interest, no less intrusive means, notice) or other listed circumstances.

View Details →

Reasonable security for personal information (Customer Records)

Data Security (1798.81.5)
active

Jurisdiction: California

Effective: 1/1/2004

Authority: California Attorney General; private plaintiffs

Requires businesses holding Californians' personal information (names with SSNs, ID numbers, financial account data, medical and health insurance data, biometrics, genetic data, or online credentials) to use reasonable security, and to require the same by contract of third parties they share it with.

View Details →

Record Destruction (Personal Information Disposal)

MT Record Destruction
active

Jurisdiction: Montana

Effective: 10/1/2005

Authority: Montana Department of Justice, Office of Consumer Protection (Attorney General)

Businesses must destroy customer records containing personal information once they no longer need to keep them, by shredding, erasing or otherwise making the information unreadable. The law is part of Montana's identity-theft prevention statutes.

View Details →

Recording of Private Telephone Conversations (all-party consent, civil action)

CT Telephone Recording Consent
active

Jurisdiction: Connecticut

Authority: Private civil action in Superior Court

Makes Connecticut an all-party-consent state for recording private phone calls as a civil matter: a recording is lawful only with every party's prior consent (in writing or captured at the start of the recording), a recorded verbal warning at the start, or an automatic beep tone about every 15 seconds.

View Details →

Redaction of Social Security numbers and birthdates in probate court filings

AL Probate SSN Redaction
active

Jurisdiction: Alabama

Authority: Probate judges (filing condition)

Requires people recording property and other documents in probate court to remove Social Security numbers, and in property documents birthdates, before filing. Probate judges may also redact them and may post records online.

View Details →

Regulation of Biometric Information (government agencies)

NH Government Biometric Law
active

Jurisdiction: New Hampshire

Effective: 7/1/2014

Authority: Aggrieved individuals through civil actions against government agencies

Bars New Hampshire government agencies from issuing ID cards that require biometric data, requiring biometrics as a condition of service, or otherwise collecting or sharing biometric data, apart from employee and contractor access cards, public safety screening and grandfathered practices. It does not apply to private companies; private-sector biometric data is covered as sensitive data under RSA 507-H.

View Details →

Regulation of Consumer Credit Reporting Agencies (including security freeze)

Texas Credit Reporting Law
active

Jurisdiction: Texas

Authority: Texas Attorney General; consumers

Texas's state credit reporting law limits consumer reports to permissible purposes, gives consumers disclosure and dispute rights, and lets consumers and protected minors place security alerts and freezes. Agencies must place a freeze within five business days of a request and honor freezes placed at other agencies.

View Details →

Regulation of Electronic Mail

Texas Commercial Email Law
active

Jurisdiction: Texas

Effective: 4/1/2009

Authority: Texas Attorney General or county prosecuting attorney; injured persons

Bans falsified routing, deceptive subject lines, and domain spoofing in commercial email, requires 'ADV:' labeling and a working opt-out for unsolicited commercial email, and bars selling opted-out addresses. H.B. 20 (2021) added a rule against email providers impeding messages.

View Details →

Regulation of Telephone Solicitation (registration with the Secretary of State)

Texas Telephone Solicitation Act
active

Jurisdiction: Texas

Effective: 4/1/2009

Authority: Texas Attorney General; Texas Secretary of State (registration); consumers under the DTPA

Requires telemarketers that are not exempt to register each calling location with the Texas Secretary of State, post security, and make disclosures. S.B. 140 (2025) extended the law to text and image messages, which, combined with the DTPA private remedy, opened these marketing texts to private suits.

View Details →

Reidentification of Deidentified Information

Texas Reidentification Law
active

Jurisdiction: Texas

Effective: 9/1/2015

Authority: Texas Attorney General; prosecutors

Prohibits reidentifying people in deidentified data released by Texas state agencies and requires notice when such data is sold or transferred. Scholarly research that does not publish identities is a defense.

View Details →

Release of employee's personal identifying information

VA employee PII release
active

Jurisdiction: Virginia

Effective: 7/1/2013

Authority: Not stated in the section

Provides that an employer cannot be required to release employees' home or mobile phone numbers, email addresses, shift times, or work schedules to a third party unless federal or state law, a court order, a warrant, or a subpoena or discovery in a pending case requires it.

View Details →

Remotely Piloted Aircraft (drone intrusion and surveillance)

Iowa Drone Surveillance Law
active

Jurisdiction: Iowa

Effective: 7/1/2024

Authority: County attorneys (criminal prosecution); homestead and farmstead owners or lessees (injunctions)

Iowa's drone law makes it a crime to hover a drone over someone else's rural home or near livestock, equipment, or buildings on a working farm, and a more serious crime to do so with a camera or recording device capable of identifying people or farm property. Owners can get court injunctions against harassing drone operators, and unlawful recordings must be destroyed. It does not reach property inside city limits.

View Details →

Reproductive and Gender-Affirming Health Information Shield (covered entity disclosure limits)

CT Reproductive Health Info Shield
active

Jurisdiction: Connecticut

Authority: Courts (evidentiary privilege)

Part of Connecticut's post-Dobbs shield laws. In civil, probate, legislative or administrative proceedings, covered entities may not disclose patient communications or examination information about reproductive or gender-affirming health care lawful in Connecticut without the patient's explicit written consent, and must tell patients they may withhold consent.

View Details →

Reproductive Health Care Information Shield (patient information disclosure limits)

NJ Reproductive Health Shield Law
active

Jurisdiction: New Jersey

Effective: 7/1/2022

Authority: Courts and agencies applying the evidentiary privilege; Attorney General and prosecutors for related 2026 provisions

New Jersey's 2022 shield law bars HIPAA covered entities from disclosing patients' communications and examination findings about lawful reproductive health care in civil, probate, legislative, or administrative proceedings without the patient's explicit written consent, and requires providers to tell patients they may withhold that consent. It also bars state entities from helping out-of-state investigations into care that is legal in New Jersey. An August 2026 amendment extends these protections to gender-affirming care.

View Details →

Restricted use of Social Security numbers

VA SSN protection
active

Jurisdiction: Virginia

Effective: 7/1/2005

Authority: Virginia Attorney General and local attorneys under the Virginia Consumer Protection Act; consumers via VCPA private action (59.1-444, 59.1-200(A)(43), 59.1-204)

Bars businesses from publicly displaying Social Security numbers, printing them on access cards, requiring them as a sole website login, showing them on mailings, or embedding them in barcodes, chips, or magnetic strips. Internal verification and administrative uses remain allowed.

View Details →

Restrictions on credit card receipts

Colorado receipt truncation
active

Jurisdiction: Colorado

Effective: 4/25/2002

Authority: Colorado Attorney General (Colorado Consumer Protection Act article)

Businesses may not print more than the last five digits of a card number, or the expiration date, on electronically printed card receipts.

View Details →

Restrictions on Information Printed on Payment-Card Receipts

Florida Card Receipt Law
active

Jurisdiction: Florida

Effective: 7/1/2003

Authority: State attorneys (county court)

Limits what merchants may print on card receipts to reduce identity theft. An electronically printed receipt may show no more than the last five digits of the card number and may not show the expiration date. The rule has covered all electronically printed receipts since July 1, 2005.

View Details →

Restrictions on Use of Genetic Information in Insurance

MT Genetic Insurance Law
active

Jurisdiction: Montana

Effective: 10/1/1999

Authority: Montana Commissioner of Securities and Insurance

Health insurers in Montana may not require genetic tests, underwrite or price coverage based on genetic traits or family genetic information, or seek genetic information for non-therapeutic purposes. Life, disability income and long-term care insurance are excluded.

View Details →

Revised Uniform Fiduciary Access to Digital Assets Act

RI RUFADAA
active

Jurisdiction: Rhode Island

Authority: Courts (orders directing custodian compliance)

Governs when online service providers must give executors, agents, trustees and guardians access to a person's digital accounts. The content of electronic communications is disclosed only if the user consented (through an online tool or an estate document) or a court orders it, and a user's choice in a provider's online tool overrides conflicting wills and ordinary terms of service.

View Details →

Rhode Island Data Transparency and Privacy Protection Act

RIDTPPA
active

Jurisdiction: Rhode Island

Effective: 1/1/2026

Authority: Rhode Island Attorney General (sole enforcement authority)

Rhode Island's comprehensive consumer privacy law, effective January 1, 2026. It requires commercial websites and internet service providers that sell customers' personal information to disclose what they collect and to whom they sell it, and gives residents of larger covered businesses rights to access, correct, delete and port their data and to opt out of targeted advertising, sales and significant automated profiling. Covered controllers need opt-in consent for sensitive data (including health, biometric, genetic, precise geolocation and known-child data) and must run data protection assessments for high-risk processing.

View Details →

Rhode Island Health Information Exchange Act of 2008

RI HIE Act
active

Jurisdiction: Rhode Island

Authority: Rhode Island Department of Health (regulatory oversight); Attorney General and courts for penalties

Creates Rhode Island's statewide electronic health information exchange and sets its privacy rules. Patients are included by default but may opt out of disclosure from the exchange (with exceptions for emergencies, public health, exchange operations and health-plan care management), and participating providers must tell patients about the exchange and the opt-out. Patients can obtain copies of their HIE data and disclosure reports.

View Details →

Rhode Island Identity Theft Protection Act of 2015 (information security and breach notification)

RI ITPA
active

Jurisdiction: Rhode Island

Authority: Rhode Island Attorney General

Rhode Island's main data security and breach notification statute. It requires businesses and government agencies holding Rhode Island residents' personal information to keep a risk-based information security program, limit retention, destroy data securely and bind vendors by contract to reasonable security. When a breach poses a significant risk of identity theft, affected residents must be notified within 45 days (30 days for agencies), with notice to the Attorney General and credit bureaus if more than 500 residents are affected.

View Details →

Rhode Island Judicial Security Act (removal of judges' personal information)

RI Judicial Security Act
active

Jurisdiction: Rhode Island

Effective: 1/1/2026

Authority: Courts via actions by protected individuals

Lets judges and their families send written notices requiring data brokers, businesses and government agencies to remove and stop posting their home addresses, phone numbers and personal emails. Data aggregators may not sell or trade the information after notice, and businesses must take it down within 10 business days (agencies within 72 hours). A 2026 amendment allows requests through an authorized agent.

View Details →

Right of privacy, California Constitution

Cal. Const. art. I, sec. 1
active

Jurisdiction: California

Effective: 11/7/1972

Authority: Courts (private suits)

Lists privacy among Californians' inalienable rights. The privacy language was added by voters in 1972 (Proposition 11), and the current wording of Section 1 dates to 1974 (Proposition 7). Courts have held it can be enforced against private entities as well as the state, which is why it appears in privacy suits against businesses.

View Details →

Right of publicity and statutory right of privacy (use of name or likeness)

OK Right of Publicity
active

Jurisdiction: Oklahoma

Effective: 1/1/1986

Authority: Private civil actions; district attorneys for the criminal misdemeanor (21 O.S. § 839.1)

Oklahoma protects against commercial appropriation of identity. A living person (and, under § 1448, the successors of a deceased personality) may sue anyone who knowingly uses their name, voice, signature, photograph, or likeness in products or advertising without prior consent. Uses in news, public affairs, sports, and political campaigns are exempt.

View Details →

Rights of Publicity

IN Right of Publicity
active

Jurisdiction: Indiana

Effective: 7/1/1994

Authority: Private enforcement by the personality or rights holders

Indiana's broad right-of-publicity statute requires prior written consent before anyone uses a person's name, voice, likeness, or other identifying traits for commercial purposes, during life and for 100 years after death. Rights are transferable and descendible. News, entertainment, literary, and political uses are exempt.

View Details →

Safe Destruction of Documents Containing Personal Information

RI Document Destruction Law
active

Jurisdiction: Rhode Island

Authority: Rhode Island Attorney General; injured customers

Requires businesses to take reasonable steps to destroy customers' personal information they no longer keep, by shredding, erasing or otherwise making it unreadable. Personal information is defined broadly to include signatures, Social Security, passport, license, insurance and financial account numbers, physical descriptions, and confidential health care information.

View Details →

Safe Destruction of Records Containing Personal Identifying Information

DE Records Destruction Law
active

Jurisdiction: Delaware

Effective: 1/1/2015

Authority: Private enforcement by affected consumers (5003C)

Requires businesses that permanently dispose of consumer records containing a name plus sensitive identifiers (SSN, ID, account, card, insurance, tax, payroll, or health information) to shred, erase, or otherwise make the information unreadable. Consumers harmed by reckless or intentional violations can sue for actual damages.

View Details →

Safeguarding of Personal Information; SSN Privacy Protection Policy; Secure Retention of Employment Applications

CT Data Safeguards & Disposal
active

Jurisdiction: Connecticut

Authority: Connecticut Department of Consumer Protection and Attorney General; licensing agencies for their licensees (42-471(d))

Requires anyone holding personal information to protect it from misuse and to destroy or render it unreadable before disposal, and requires businesses that collect Social Security numbers to publish a privacy protection policy. Employers must keep job applications secure and shred them on disposal.

View Details →

Scanning or swiping driver's licenses and ID cards

Civ. Code 1798.90.1
active

Jurisdiction: California

Authority: Local prosecutors

Businesses may electronically scan California driver's licenses and IDs only for listed purposes (age or ID verification, legal recordkeeping, check approval, fraud prevention) and may not keep or use the data for anything else.

View Details →

School-Issued Electronic Device Monitoring Notice

NJ School Device Notice Law
active

Jurisdiction: New Jersey

Effective: 7/1/2013

Authority: New Jersey Department of Education (fines remitted to the Department)

Schools that hand out laptops, phones, or other devices able to record or track students must tell students in writing or electronically that the device may collect information about their activity, and promise not to use those capabilities to violate the privacy of the student or anyone in the household. A parent must acknowledge the notice.

View Details →

Second Amendment Financial Privacy Act

AL 2A Financial Privacy Act
active

Jurisdiction: Alabama

Effective: 10/1/2024

Authority: Alabama Attorney General (exclusive)

Stops payment card networks from requiring the firearms-retailer merchant category code in a way that singles out gun sellers, and stops financial institutions from declining transactions solely because of that code. It also bars state and local governments from keeping lists or registries of privately owned firearms or their owners, outside criminal investigations or as required by law.

View Details →

Secure Online Child Interaction and Age Limitation Act

LA SOCIAL Act
enjoined

Jurisdiction: Louisiana

Effective: 7/1/2024

Authority: Louisiana Department of Justice, Division of Public Protection (Attorney General)

Requires large social media platforms to make commercially reasonable efforts to verify Louisiana users' ages and to obtain a parent's express consent before a Louisiana minor under 16 may hold an account. For minor accounts it bars unconnected adults from direct messaging, bars ads based on personal information other than age and location, limits data collection, and requires parental supervision tools. On December 15, 2025, the U.S. District Court for the Middle District of Louisiana held R.S. 51:1751-1754 unconstitutional as applied to ten NetChoice members and permanently enjoined enforcement of R.S. 51:1751-1756 against them; the state's appeal is pending in the Fifth Circuit.

View Details →

Securing Children Online through Parental Empowerment (SCOPE) Act

SCOPE Act
active

Jurisdiction: Texas

Effective: 9/1/2024

Authority: Texas Attorney General, Consumer Protection Division (deceptive trade practice)

H.B. 18 (2023) requires covered social platforms to register users' ages, treat users under 18 as known minors, limit collection and sharing of minors' data, block targeted ads and precise geolocation collection for minors, and give verified parents tools and data access. The harmful-content monitoring and filtering duty (509.053) and the related algorithm duty (509.056(1)) remain preliminarily enjoined for CCIA and NetChoice; on July 24, 2026 the Fifth Circuit affirmed that injunction on Section 230 preemption grounds and vacated the broader injunction won by the SEAT plaintiffs (targeted-ads, unlawful-ads, and age-verification provisions).

View Details →

Security Breach Notice Act

VT SBNA
active

Jurisdiction: Vermont

Effective: 1/1/2007

Authority: Vermont Attorney General and State's Attorneys; Department of Financial Regulation for its licensees

Requires businesses and other data collectors to tell Vermont consumers about a breach of their personally identifiable information or login credentials within 45 days of discovery, and to give the Attorney General (or DFR) a preliminary report within 14 business days. Notices must contain specified content, and large breaches require notice to the national credit bureaus.

View Details →

Security breach notification (businesses)

Breach Notification (1798.82)
active

Jurisdiction: California

Effective: 7/1/2003

Authority: California Attorney General; private plaintiffs

Requires notice to California residents when their unencrypted personal information (or encrypted data with a compromised key) is, or is reasonably believed to have been, acquired by an unauthorized person. SB 446 (2025) added a firm 30-calendar-day deadline from January 1, 2026.

View Details →

Security Breach Notification Act

OK Breach Act
active

Jurisdiction: Oklahoma

Effective: 11/1/2008

Authority: Oklahoma Attorney General or a district attorney (exclusive), as an unlawful practice under the Oklahoma Consumer Protection Act; the primary state regulator for state-chartered or state-licensed financial institutions

Requires anyone owning or licensing computerized personal information of Oklahoma residents to notify affected residents without unreasonable delay after a breach that causes or is reasonably believed to cause identity theft or fraud. 2025 SB 626 (effective January 1, 2026) added biometric data and government ID numbers to personal information, a new Attorney General notice duty for breaches affecting 500 or more residents, and a safe harbor tied to 'reasonable safeguards'.

View Details →

Security Freeze on Credit Reports

CT Security Freeze
active

Jurisdiction: Connecticut

Authority: Connecticut Banking Commissioner (regulations under 36a-701c); Attorney General

Lets any consumer, and a parent for a minor child, freeze a credit report free of charge so it cannot be released for new credit without the consumer's authorization, and requires agencies to lift or remove freezes promptly on request.

View Details →

Security Freezes for Consumer Reports

IN Security Freeze
active

Jurisdiction: Indiana

Authority: Indiana Attorney General; consumers

Indiana residents may freeze their credit reports for free so that agencies cannot release them without the consumer's authorization. Agencies must confirm a freeze and issue a PIN or password, and must lift or remove a freeze within set times. The federal Economic Growth, Regulatory Relief, and Consumer Protection Act of 2018 (15 U.S.C. 1681c-1(i)) now also sets nationwide free-freeze rules and timelines.

View Details →

Security Freezes for Protected Consumers (minors under 16 and incapacitated persons)

IN Protected Consumer Freeze
active

Jurisdiction: Indiana

Authority: Not specified in the chapter

A parent, guardian, or other representative may freeze the credit report of a child under 16 or an incapacitated adult. If no report exists, the agency must create a record and freeze it, so no credit file can be opened in the child's name until the freeze is lifted.

View Details →

Security of Communications Act

OK SCA (wiretap)
active

Jurisdiction: Oklahoma

Authority: District attorneys and the Attorney General (criminal prosecution); courts for interception orders

Oklahoma's wiretap law makes it a felony to willfully intercept wire, oral, or electronic communications, or to disclose or use their contents knowing they were unlawfully obtained. Oklahoma is a one-party consent state: a private person may record a communication they are a party to, or with one party's prior consent, unless the purpose is to commit a crime. The act also governs court-ordered interception by law enforcement.

View Details →

Security of Communications Act: Interception and Disclosure of Wire, Oral, or Electronic Communications (all-party consent)

Florida Wiretap Act
active

Jurisdiction: Florida

Authority: State attorneys and statewide prosecutor (criminal); private civil actions

Florida is an all-party-consent state: intercepting or recording a wire, oral, or electronic communication is lawful only if all parties consent, unless a statutory exception applies (934.03(2)(d)). 'Oral communications' are protected only when the speaker reasonably expects not to be intercepted (934.02(2)). Exceptions allow children, and since 2024 their parents or guardians, to record abusers in defined circumstances, and let people protected by injunctions record violating communications.

View Details →

Security of Connected Devices (IoT security law)

IoT Security (SB 327)
active

Jurisdiction: California

Effective: 1/1/2020

Authority: California Attorney General, city attorneys, county counsel, and district attorneys (exclusive; 1798.91.06(e))

Requires makers of internet-connected devices to build in reasonable security features suited to the device and the data it handles. A unique preprogrammed password per device, or forcing the user to set new credentials at first use, satisfies the rule for remote authentication, as does meeting a NIST-conforming labeling scheme.

View Details →

Security requirements for Internet-connected devices

ORS 646A.813 (IoT security)
active

Jurisdiction: Oregon

Effective: 1/1/2020

Authority: Oregon Attorney General (unlawful trade practice under ORS 646.607)

Requires makers of consumer internet-connected devices sold in Oregon to build in reasonable security features, such as a unique preset password or forcing the user to set new credentials on first use.

View Details →

Sexual Cyberharassment (nonconsensual intimate images)

Florida Sexual Cyberharassment Law
active

Jurisdiction: Florida

Authority: State attorneys (criminal); private plaintiffs

Florida's 'revenge porn' law. It makes it a crime to willfully and maliciously post or send a sexually explicit image of someone, together with identifying information, without consent when the person expected it to stay private. Sharing the image with one person does not by itself end that expectation of privacy. A 2025 amendment (HB 1451) added penalties for doing this for money.

View Details →

Shine the Light law (disclosure of personal information shared for direct marketing)

Shine the Light
active

Jurisdiction: California

Effective: 1/1/2005

Authority: Private plaintiffs; courts (injunctions)

Lets California customers ask businesses once a year which categories of their personal information were shared with third parties for those third parties' direct marketing, and with whom. Businesses must designate a way to receive these requests and answer within 30 days, or may instead adopt a qualifying opt-out or opt-in policy.

View Details →

Social media account deletion (AB 656)

AB 656
active

Jurisdiction: California

Effective: 1/1/2026

Authority: Not specified in the title (CCPA enforcement applies to the deletion request)

Requires large social media platforms to put a clearly labeled 'Delete Account' button in settings, walk users through deleting their account and personal information, and not obstruct deletion with dark patterns. The request counts as a CCPA deletion request.

View Details →

Social Media Account Privacy (Employers)

VT Employee Social Media Privacy
active

Jurisdiction: Vermont

Effective: 1/1/2018

Authority: Vermont Attorney General or State's Attorneys (21 V.S.A. § 495b)

Prevents employers from requiring or pressuring workers or job applicants to hand over personal social media passwords, log in in front of them, show account content, weaken privacy settings, or add the employer as a contact. Employers may still ask for specific content during certain legal-compliance, misconduct or data-leak investigations.

View Details →

Social media accounts of current and prospective employees

VA employer social media
active

Jurisdiction: Virginia

Effective: 7/1/2015

Authority: Not stated in the section

Bars employers from requiring current or prospective employees to disclose personal social media usernames and passwords or to add a supervisor or co-worker as a contact, and from retaliating against those who refuse. Employers may view public information and may request credentials for formal misconduct investigations.

View Details →

Social Media Mental Health Warning Label Law

MN Social Media Warning Label
active

Jurisdiction: Minnesota

Effective: 7/1/2026

Authority: Minnesota Attorney General (325M.34(a)); Commissioner of Health sets label guidelines (325M.335, subd. 2)

From July 1, 2026, social media platforms must show a conspicuous mental health warning label each time a user accesses the platform, which disappears only when the user exits or acknowledges the risk and proceeds, and which links to crisis resources such as the 988 Lifeline. Label content follows guidelines from the Commissioner of Health. NetChoice challenged the law on First Amendment grounds (NetChoice v. Ellison, D. Minn. No. 0:26-cv-02405), and press reports state the Attorney General agreed not to enforce it while the court considers the case; no court injunction has been reported.

View Details →

Social Media Platforms and Minors (account unpublish/deletion; online safety center)

CT Social Media Minors
active

Jurisdiction: Connecticut

Effective: 7/1/2024

Authority: Connecticut Attorney General (solely; Conn. Gen. Stat. 42-528(d))

Requires social media platforms to unpublish a minor's account within 15 business days and delete it (and stop processing the minor's data) within 45 business days of a request by the minor or, for under-16s, a parent. From July 1, 2026 parents cannot be forced to open an account to make the request, and platforms must provide an online safety center and a cyberbullying policy by October 1, 2026.

View Details →

Social media private right of action for minors

Utah Social Media PRA
active

Jurisdiction: Utah

Effective: 10/1/2024

Authority: None; private actions

Enacted by 2024 H.B. 464, effective October 1, 2024, it lets minors and parents sue social media companies for mental health harm from excessive use. Companies that limit minors' use and disable engagement features get the opposite presumption. The 13-71 injunction does not name this Part.

View Details →

Social Media Providers: Adolescent Use of Social Media

IN Social Media Minors Act
enacted_not_effective

Jurisdiction: Indiana

Effective: 1/1/2027

Authority: Indiana Attorney General (as a deceptive act under IC 24-5-0.5)

Added by HEA 1408 (2026), P.L.100-2026, and effective January 1, 2027, this article requires large, addictive-design social media platforms to screen the age of Indiana account applicants. Users under 16 need verifiable parental consent to open an account. Minors' accounts must have direct messaging, search visibility, personalized feeds and ads, and addictive features turned off, and parents get monitoring and time-limit controls.

View Details →

Social Media Use for Minors (HB 3, 2024)

Florida HB 3 Social Media
active

Jurisdiction: Florida

Effective: 1/1/2025

Authority: Florida Department of Legal Affairs (Attorney General)

HB 3 (ch. 2024-42) requires covered social media platforms to bar Florida minors under 14 from holding accounts, and to require parental consent for 14- and 15-year-olds, terminating non-compliant accounts and deleting their data. A federal district court preliminarily enjoined the law in June 2025, but the Eleventh Circuit stayed that injunction on November 25, 2025, so the law is enforceable while the merits appeal (argued March 2026) is pending.

View Details →

Social Media Warning Law (AB 56)

AB 56
enacted_not_effective

Jurisdiction: California

Effective: 1/1/2027

Authority: Public prosecutors (no private right of action)

Requires covered social media platforms to show users a black-box mental health warning when they first open the platform each day, after three hours of cumulative use, and at least hourly after that. Operative January 1, 2027. Included because it regulates minors' social media use, though it is not a data privacy rule.

View Details →

Social Security Number Privacy Act

MD SSN Privacy Act
active

Jurisdiction: Maryland

Authority: Consumer Protection Division, Office of the Attorney General (Com. Law 13-301(14)(xxi))

This law restricts how businesses display and transmit Social Security numbers. It bars publicly posting SSNs, printing them on access cards, requiring or sending them over unsecured internet connections, and using them alone as a website login, and limits SSNs in mailed, emailed, or faxed materials.

View Details →

Social Security Number Protection

CT SSN Protection
active

Jurisdiction: Connecticut

Authority: Criminal prosecution; civil penalties (deposited into the privacy protection guaranty and enforcement account)

Bars businesses from publicly posting Social Security numbers, printing them on access cards, or requiring people to send them over unsecured internet connections or use them alone to log in to websites.

View Details →

Social Security Number Protection Act

VT SSN Act
active

Jurisdiction: Vermont

Effective: 7/1/2007

Authority: Vermont Attorney General and State's Attorneys; Department of Financial Regulation for its licensees

Limits how businesses and government bodies display, transmit and disclose Social Security numbers. Businesses may not publicly post SSNs, print them on access cards or mailings, or sell them to third parties without a legitimate purpose, subject to listed exceptions. Individuals may ask town clerks and courts to redact SSNs and other identifiers from records posted online.

View Details →

Song-Beverly Credit Card Act: limits on collecting personal information at checkout

Song-Beverly 1747.08
active

Jurisdiction: California

Effective: 1/1/1991

Authority: Cardholders, California Attorney General, district attorneys, and city attorneys

Stops merchants from requesting or requiring a cardholder's personal identification information (such as address, phone number, or ZIP code) as a condition of accepting a credit card, or recording it on the transaction form, except where needed for shipping, delivery, or other listed purposes.

View Details →

Spam Reduction Act of 2008 (commercial electronic mail)

Colorado Spam Reduction Act
active

Jurisdiction: Colorado

Effective: 8/5/2008

Authority: Colorado Attorney General and district attorneys; email service providers

Colorado makes violations of the federal CAN-SPAM Act a state deceptive trade practice and separately bans falsified sender and routing information, unauthorized use of third-party domains, and emailing people who have opted out. Email service providers can sue for statutory damages.

View Details →

Standards for Workplace Drug and Alcohol Testing Act

OK Workplace Drug Testing Act
active

Jurisdiction: Oklahoma

Effective: 6/10/1993

Authority: Private civil actions; State Department of Health (licensing of testing facilities)

Sets standards for employer drug and alcohol testing, including confidentiality of results. Employers must keep test records confidential and may disclose them only to the person tested, the review officer, those administering the program, or under court or agency order; testing facilities may not reveal other health information learned from samples.

View Details →

State Agency Protection of Personal Information and Breach Notification

MT State Agency Breach Law
active

Jurisdiction: Montana

Effective: 10/1/2015

Authority: Montana Department of Administration (chief information security officer); Attorney General receives notice copies

Montana state agencies must protect personal information and notify affected people of data breaches without unreasonable delay. Contractors that hold agency data must notify the agency immediately, notify affected individuals, keep a security policy, and file notice copies with the state CISO and the Attorney General.

View Details →

Statutory Right to Privacy (civil action)

RI Privacy Act (tort)
active

Jurisdiction: Rhode Island

Authority: Courts via private civil actions

Codifies four privacy torts as statutory rights: freedom from unreasonable intrusion upon seclusion, from appropriation of name or likeness without permission, from unreasonable publicity given to private life, and from false-light publicity. It sets the elements a plaintiff must prove for each.

View Details →

Stop Harms from Addictive Social Media

MN Addictive Social Media (Minors)
enacted_not_effective

Jurisdiction: Minnesota

Effective: 7/1/2027

Authority: Private action by children and parents; Minnesota Attorney General under 8.31 for knowing or reckless violations (325M.40, subds. 9-10)

Signed May 26, 2026 and effective July 1, 2027, this law requires large social media platforms to estimate users' ages, obtain verifiable parental consent before creating or keeping accounts for children 15 and under, set children's accounts to the most private settings, and give parents time-limit tools. It bars addictive features such as infinite scroll, autoplay, and profile-based feeds, and bars targeted advertising, in children's accounts, and forbids selling or disclosing children's account information.

View Details →

Stop the Spam Calls Act of 2023

MD Stop the Spam Calls Act
active

Jurisdiction: Maryland

Effective: 1/1/2024

Authority: Consumer Protection Division, Office of the Attorney General (14-4503(a)(1)); private actions by called parties (14-4503(a)(2))

Maryland's mini-TCPA requires prior express written consent before a telephone solicitation uses an automated dialing system or a prerecorded message, and limits solicitation calls to 8 a.m. to 8 p.m. and three per day on the same subject. Solicitors must transmit accurate caller ID and may not spoof numbers or disguise their voice. A 2024 emergency amendment (ch. 214) adjusted exemptions and remedies.

View Details →

Student and Teacher Information Protection and Privacy

NH Student and Teacher Privacy Act
active

Jurisdiction: New Hampshire

Authority: New Hampshire Department of Education and State Board of Education

Limits what student and teacher personal data the state education department may collect, keep and disclose, and requires public data inventories, a state data security and breach plan, and annual local data and privacy governance plans that vet every school software tool. It also bars schools from RFID tracking, remote surveillance software on school-issued devices, and classroom recording for teacher evaluation without school board approval and written consent.

View Details →

Student Data Accessibility, Transparency and Accountability Act of 2013

Student DATA Act
active

Jurisdiction: Oklahoma

Effective: 7/1/2013

Authority: State Board of Education (rulemaking and compliance oversight); reports to the Governor and Legislature

Governs Oklahoma's statewide student data system. It requires a public inventory of student data elements, FERPA-compliant access and release policies, a data security plan, and legislative approval of new data collections, and it bars most out-of-state transfers of confidential student data. Student data excludes Social Security numbers and biometric information unless in the educational record.

View Details →

Student Data Privacy (Act Concerning Student Data Privacy)

CT Student Data Privacy
active

Jurisdiction: Connecticut

Effective: 10/1/2016

Authority: Not specified; noncompliant contracts are void (10-234bb(e)-(f)); State Department of Education issues guidance (10-234ee)

Requires school boards to sign written contracts with ed-tech vendors that keep student data under school control, limit use to school purposes, and require deletion and security. Ed-tech operators may not use student data for targeted advertising, sell it, or build non-school profiles, and both contractors and operators must report student data breaches within set deadlines.

View Details →

Student Data Privacy Protection Act

SDPPA
active

Jurisdiction: Delaware

Effective: 8/1/2016

Authority: Consumer Protection Unit, Delaware Department of Justice (8103A)

Delaware's K-12 ed-tech privacy law bars operators of school-focused online services from using student data for targeted advertising, building non-school profiles, selling student data, or disclosing it except for listed school, legal, safety, or service-provider purposes. Operators must meet state cloud-hosting security standards and delete student data within 45 days when a school asks.

View Details →

Student Data Privacy: Technology Providers and School-Issued Devices (Educational Data)

MN Student Data Privacy
active

Jurisdiction: Minnesota

Effective: 8/1/2022

Authority: Minnesota Government Data Practices Act remedies; technology providers are bound as if government entities under 13.05, subd. 11 (13.32, subd. 13(a))

Minnesota's 2022 student data privacy provisions bar technology providers serving public schools from selling, sharing, or commercially using student educational data, including for advertising, and require them to protect the data, report breaches to the school, and return or destroy data at contract end. Schools and providers generally may not remotely access a school-issued device's location tracking, camera, microphone, keystrokes, or browsing, except for listed purposes such as noncommercial instruction with advance notice, warrants, stolen devices, or imminent threats.

View Details →

Student Data Protection Act (third-party contractor provisions)

Utah SDPA
active

Jurisdiction: Utah

Authority: Utah State Board of Education

Governs ed-tech and other contractors that handle Utah student data: use limited to the contracted service, mandatory contract terms, return or deletion at contract end, and no sale or targeted advertising. 2026 H.B. 55 and S.B. 296 amendments took effect July 1, 2026.

View Details →

Student Data Protections for Cloud Computing Service Providers

KY Student Cloud Data
active

Jurisdiction: Kentucky

Effective: 7/15/2014

Authority: Not specified; the Kentucky Board of Education may issue implementing regulations

Limits how cloud service providers serving K-12 schools may use student data, such as names, emails, messages, documents, and photos. Providers may use it only to provide and maintain the service unless a parent expressly permits more, and may never use it for advertising, ad profiling, sale, or other commercial purposes.

View Details →

Student Data Transparency and Security Act

Colorado Student Data Act
active

Jurisdiction: Colorado

Effective: 8/10/2016

Authority: Contracting public education entities (contract remedies and termination after public hearing); Colorado Department of Education

Colorado's student privacy law requires education technology vendors under contract with public schools to disclose what student data they collect and why, use it only for contracted purposes, and never sell it or use it for targeted advertising. Vendors must maintain an information security program, notify schools of misuse, and destroy data on request or at contract end. Parents gain inspection, correction, and complaint rights.

View Details →

Student Data-Cloud Computing

RI Student Cloud Data Law
active

Jurisdiction: Rhode Island

Authority: Not specified in the statute

Requires cloud service providers serving Rhode Island schools to use K-12 student data only to provide the service to the school, and forbids processing it for commercial purposes such as advertising. Providers must certify compliance in writing when they contract.

View Details →

Student information privacy (personally identifiable student information)

LA Student Privacy Law
active

Jurisdiction: Louisiana

Effective: 8/1/2014

Authority: Criminal prosecution (district attorneys)

One of the strictest state student-data laws: it bars local school officials from collecting sensitive information (such as political or religious beliefs, family income, biometric information, gun ownership, home IP address) unless a parent volunteers it, and bars disclosing personally identifiable student information except in narrow, mostly parent-authorized cases. It limits who may access school computer systems, sets mandatory privacy and security terms for vendor contracts, and bans selling or using student data for advertising or other commercial purposes. A companion section requires the Department of Education and school systems to publish their student-data transfer agreements.

View Details →

Student Information Protection (school-purpose online operators)

Texas Student Data Privacy Law
active

Jurisdiction: Texas

Effective: 9/1/2017

Authority: Not specified in the subchapter (see unverified)

Texas's student online privacy law (H.B. 2087, 2017) bars ed-tech operators from targeted advertising, non-school profiling, and selling or renting students' covered information, and requires reasonable security and deletion on district request. Operators approved by the Texas Education Agency must mask data with the state student identifier.

View Details →

Student Online Personal Information

NH SOPIPA
active

Jurisdiction: New Hampshire

Effective: 1/1/2016

Authority: Not specified in the section

New Hampshire's version of the student online privacy model bars K-12 education technology operators from targeted advertising, building student profiles, and selling or disclosing student information gathered through their services. Operators must secure student data and delete it at a school's request, while de-identified data may be used to improve educational products.

View Details →

Student Online Personal Information Protection

Iowa Student Online Privacy Law
active

Jurisdiction: Iowa

Effective: 7/1/2018

Authority: Not specified in the section

Iowa's student online privacy law bars K-12 edtech operators from using student information for targeted advertising, building non-school profiles, selling or renting student information, or disclosing it except for listed purposes. Operators must also secure covered information and delete it when a school district asks.

View Details →

Student Online Personal Information Protection Act

Florida SOPIPA
active

Jurisdiction: Florida

Effective: 7/1/2023

Authority: Florida Department of Legal Affairs (Attorney General), exclusively, under FDUTPA

Enacted by SB 662 (2023), this is Florida's version of California's SOPIPA. It bars K-12 edtech operators from targeted advertising, building student profiles for non-school purposes, and selling or renting student information, and requires data minimization, reasonable security, and deletion of student data after the course ends.

View Details →

Student Online Personal Protection Act

Nebraska SOPPA
active

Jurisdiction: Nebraska

Effective: 9/1/2017

Authority: No enforcement provision stated in the act

Nebraska's version of the SOPIPA model law restricts K-12 edtech operators' use of student data. Operators may not use covered student information for targeted advertising or non-school profiles, may not sell or rent it, may disclose it only for listed purposes, and must secure it and delete it on a school's request.

View Details →

Student Online Personal Protection Act

Tenn. SOPPA
active

Jurisdiction: Tennessee

Effective: 7/1/2016

Authority: Tennessee Attorney General and Reporter (sole enforcement, as a Tennessee Consumer Protection Act violation)

Tennessee's student-privacy law for education technology vendors. Operators of K-12 online services may not use student information for targeted advertising, build student profiles for non-school purposes, sell or rent student information, or disclose it except for listed purposes. They must keep reasonable security and delete student data when a school or district asks.

View Details →

Student Personal Analysis, Evaluation, or Survey (third-party vendor surveys)

IN Student Survey Privacy
active

Jurisdiction: Indiana

Effective: 7/1/2023

Authority: School grievance procedures; contract enforcement by schools

When Indiana public schools use outside vendors for surveys or evaluations of students' attitudes, beliefs, or feelings, neither the vendor nor the school may keep results in a form that identifies individual students. Schools must also get written parental consent (or the adult student's) before giving such surveys. Academic tests, career surveys, crisis screenings, and satisfaction surveys are exempt.

View Details →

Student personal information; school service providers and school-issued devices

VA student data privacy
active

Jurisdiction: Virginia

Effective: 7/1/2015

Authority: Not stated in the section (enforced mainly through school division contracts)

Virginia's K-12 student privacy law. Edtech providers and school device providers must publish clear privacy policies, run information security programs, let students and parents access and correct data, delete data on request, and use data only with consent or as the school contract allows. They may not use student data for targeted advertising, build non-school profiles, or sell it, and may not remotely use school-issued devices' location, camera, microphone, or interaction monitoring except for limited educational, support, proctoring, or safety purposes.

View Details →

Student Privacy (Student Online Personal Information Protection)

VT Student Privacy
active

Jurisdiction: Vermont

Effective: 7/1/2020

Authority: Vermont Attorney General (Consumer Protection Act)

Vermont's student privacy law, modeled on California's SOPIPA, stops edtech operators from using student information gathered for PreK-12 school purposes to target ads, build non-educational profiles, or sell student data. Operators must protect the data, delete it when a school asks, and publish their data practices.

View Details →

Student Social Media Privacy

RI Student Social Media Privacy Act
active

Jurisdiction: Rhode Island

Authority: Courts via student or applicant civil actions

Bars schools and colleges from requiring or asking students and applicants for personal social media passwords, making them log in in front of school staff, forcing them to add coaches or teachers as contacts or change privacy settings, and from disciplining or refusing admission to those who refuse.

View Details →

Student social media privacy (postsecondary institutions)

Educ. Code 99120-99122
active

Jurisdiction: California

Effective: 1/1/2013

Authority: Courts

Bars colleges and universities from requiring or asking students or applicants for social media passwords, to open their accounts in front of staff, or to divulge personal social media, and from punishing refusal.

View Details →

Surveillance Pricing and Price-Setting Device Disclosure (P.A. 26-64, s. 11)

CT Surveillance Pricing
enacted_not_effective

Jurisdiction: Connecticut

Effective: 10/1/2026

Authority: Connecticut Attorney General (solely; P.A. 26-64, s. 11(e))

Requires businesses that use personal data in an automated price-setting device (other than to offer a discount) to label online prices with a prescribed warning, and bars retailers and delivery apps from charging individualized prices based on personal data gathered through tracking technologies. Cost-based, supply-and-demand, retention and uniformly available discounts are carved out.

View Details →

Synthetic Media and Deceptive and Fraudulent Deepfakes in Elections

NH Election Deepfake Disclosure Law
active

Jurisdiction: New Hampshire

Effective: 8/1/2024

Authority: Depicted candidates and election officials through civil suits

Bars distributing AI-generated deepfakes of candidates, election officials or parties within 90 days of an election unless the media carries a prescribed disclosure that it was manipulated or generated by AI and depicts speech or conduct that did not occur. Depicted candidates and officials may sue for injunctive relief and damages.

View Details →

Synthetic Media in Electioneering Communications

KY Election Deepfake Disclosure
active

Jurisdiction: Kentucky

Effective: 3/24/2025

Authority: Affected candidates via civil action in Circuit Court

Lets a candidate whose appearance, actions, or speech are altered with synthetic media (AI-generated or manipulated content) in an electioneering communication sue the sponsor to require a clear and conspicuous disclosure. Including such a disclosure is an affirmative defense, and platforms and media outlets are generally not liable.

View Details →

Synthetic Media in Elections

VT Election Deepfake Law
active

Jurisdiction: Vermont

Effective: 3/5/2026

Authority: Vermont Attorney General and State's Attorneys; candidates (injunctive relief)

Requires a set disclosure on AI-generated or manipulated media that realistically but falsely depicts a candidate, or gives materially false election information, when distributed within 90 days before a Vermont election. Visual disclosures must stay readable for the whole video, and audio disclosures must be spoken at the start and end and at least every two minutes.

View Details →

Synthetic performers in advertising (SB 1050)

SB 1050
enacted_not_effective

Jurisdiction: California

Effective: 1/1/2027

Authority: Public prosecutors; courts

Signed September 16, 2026. Requires a clear disclosure, such as 'this performance features a synthetic performer', when an ad prominently uses an AI-generated performer who is not a recognizable real person.

View Details →

Telemarketer Restriction Act

OK Do-Not-Call Act
active

Jurisdiction: Oklahoma

Effective: 7/1/2002

Authority: Oklahoma Attorney General (Oklahoma Consumer Protection Act actions or administrative fines)

Creates Oklahoma's state do-not-call registry maintained by the Attorney General and bars telemarketers from calling or texting registered consumers more than 30 days after their numbers appear on the list. Calls to consumers with an established business relationship (within 24 months) are exempt.

View Details →

Telemarketing (autodialers, caller ID and do-not-call)

NH Telemarketing Law
active

Jurisdiction: New Hampshire

Effective: 1/1/1990

Authority: New Hampshire Department of Justice, Consumer Protection and Antitrust Bureau

Requires anyone using prerecorded autodialers for solicitation to register with the Attorney General's consumer protection bureau, identify themselves and the call's purpose, and disconnect promptly, and bans solicitors from blocking or spoofing caller ID. It also incorporates the national do-not-call registry and the FTC Telemarketing Sales Rule into state law, with state penalties and a private right of action.

View Details →

Telemarketing and Do-Not-Call Law (including text messages)

CT Telemarketing / Do Not Call
active

Jurisdiction: Connecticut

Effective: 1/1/2001

Authority: Connecticut Department of Consumer Protection and Attorney General (CUTPA)

Connecticut adopts the National Do Not Call Registry as its no-call list and, after 2023 amendments, requires prior express written consent for all telephonic sales calls and texts. Calls are limited to 9 a.m. to 8 p.m., callers must identify themselves within 10 seconds and honor removal requests, caller ID spoofing is barred, and anyone knowingly assisting illegal robocallers is liable.

View Details →

Telemarketing and Prize Promotions Act

Nebraska Telemarketing and Prize Promotions Act
active

Jurisdiction: Nebraska

Authority: Nebraska Attorney General

This consumer protection law governs telephone sales and prize promotions. It requires verifiable consumer authorization before a seller draws on a bank account, gives a five-business-day cancellation right unless a qualifying refund policy exists, bans prize misrepresentations, and requires sellers to keep telemarketing records.

View Details →

Telephone records protection (pretexting) law

OK Telephone Records Act
active

Jurisdiction: Oklahoma

Effective: 11/1/2006

Authority: District attorneys (criminal); Attorney General (Consumer Protection Act)

Criminalizes obtaining, selling, or receiving a person's call records without the customer's authorization or through fraud or pretexting. Telephone companies must maintain reasonable procedures to protect records, which is satisfied by good-faith compliance with the federal CPNI rules.

View Details →

Telephone Sales Solicitation Act (telemarketer registration, do-not-call, robocalls and text advertising)

RI TSSA
active

Jurisdiction: Rhode Island

Authority: Rhode Island Attorney General (Consumer Protection Unit); prosecutors; purchasers via civil action

Requires covered telemarketers to register annually with the Attorney General and post a ,000 bond, identify themselves at the start of calls, and call only during set hours. It requires all telephone sellers to keep internal do-not-call lists, limits prerecorded messages to consenting subscribers, and broadly bans unsolicited text-message advertising to Rhode Island cell phones except from carriers and businesses with an existing relationship that offer an opt-out.

View Details →

Telephone Solicitation Act of 2022

OTSA
active

Jurisdiction: Oklahoma

Effective: 11/1/2022

Authority: Private civil actions by called parties

Oklahoma's 'mini-TCPA' requires prior express written consent before making commercial sales calls or texts that use an automated system for selecting or dialing numbers or a recorded message, bars calls before 8 a.m. or after 8 p.m. and more than three calls in 24 hours on the same subject, and requires accurate caller ID. Called parties may sue.

View Details →

Telephone solicitation and do-not-call rules

Cal. Do Not Call (17592)
active

Jurisdiction: California

Authority: California Attorney General and local prosecutors

Adopts the federal Do Not Call Registry for California: telephone solicitors may not call numbers on the current national list (obtained within the last three months) except with written consent or other listed exceptions, and list sellers must scrub registered numbers.

View Details →

Telephone Solicitation No-Call List

MT No-Call Law
active

Jurisdiction: Montana

Effective: 10/1/2003

Authority: Montana Department of Justice or county attorneys

Montana keeps a state no-call list that includes the Montana portion of the national Do Not Call registry. Telephone solicitors may not call listed residential subscribers, must identify themselves at the start of the call, and may not block caller ID.

View Details →

Telephone Solicitation of Consumers (Indiana Do Not Call list)

IN Do Not Call
active

Jurisdiction: Indiana

Authority: Indiana Attorney General, Consumer Protection Division

Indiana keeps its own no-telephone-sales-solicitation list, run by the Attorney General's Consumer Protection Division, and bars telephone sales calls to numbers on it. Since 2024, sales texts and other device messages count as telephone sales calls. The article also requires caller disclosures and bars selling listed numbers or knowingly helping violators.

View Details →

Telephone Solicitation Relief Act of 2001 (Louisiana Do Not Call)

LA Do Not Call Law
active

Jurisdiction: Louisiana

Effective: 5/24/2001

Authority: Louisiana Public Service Commission

Louisiana's do-not-call law, run by the Public Service Commission, protects residential telephone subscribers who object to unsolicited sales calls. The state list incorporates Louisiana numbers on the National Do Not Call Registry; solicitors must register with the PSC, pay fees, buy the list, and not call listed numbers except as the Chapter or federal law allows.

View Details →

Telephone Solicitations (seller registration and caller ID blocking)

IN Telephone Seller Registration
active

Jurisdiction: Indiana

Authority: Indiana Attorney General, Consumer Protection Division; county prosecutors (criminal); private parties

Covered telephone sellers must register with the Attorney General and update their registration every year. The chapter also makes it a crime to block one's number or identity from caller ID while making a telephone solicitation outside an existing course of dealing.

View Details →

Telephonic Communications Made for Purpose of Solicitation (state TCPA remedy)

Texas Mobile Solicitation Call Law
active

Jurisdiction: Texas

Effective: 4/1/2009

Authority: Prosecutors (criminal); private plaintiffs; DTPA public and private remedies

Bars unconsented sales calls to mobile phones that are charged per call and certain fax practices, and gives Texans a state-court action for violations of the federal Telephone Consumer Protection Act and its rules.

View Details →

Tennessee data breach notification law (Release of personal consumer information)

Tenn. Breach Notification
active

Jurisdiction: Tennessee

Effective: 7/1/2005

Authority: Tennessee Attorney General (a violation of part 21 is a Tennessee Consumer Protection Act violation, § 47-18-2106); private suits by injured customers

Requires businesses and government bodies holding computerized personal information of Tennesseans to notify affected residents no later than 45 days after discovering a breach, with a law-enforcement delay. Personal information means name plus SSN, driver license number, or a financial account or card number with its access code. Encrypted data (FIPS 140-2) is covered only if the key is also taken, and large breaches must also be reported to the nationwide credit bureaus.

View Details →

Tennessee Do Not Call and text solicitation law

Tenn. Do Not Call Law
active

Jurisdiction: Tennessee

Authority: Tennessee Public Utility Commission; Tennessee Attorney General at the commission's request

Creates Tennessee's Do Not Call Register, run by the Public Utility Commission, and bars telephone and (since July 1, 2023) text message solicitations to residential subscribers who have registered their objection. Solicitors must register and pay an annual fee to access the list, identify themselves at the start of each call or text, and contact people only between 8 a.m. and 9 p.m.

View Details →

Tennessee Information Protection Act

TIPA
active

Jurisdiction: Tennessee

Effective: 7/1/2025

Authority: Tennessee Attorney General and Reporter (exclusive authority)

Max Fine: Up to ,500 per violation

Tennessee's comprehensive consumer privacy law gives residents rights to access, correct, delete, and port their personal information and to opt out of sale, targeted advertising, and significant-decision profiling. It applies only to businesses with more than $25 million in revenue that also meet a data-volume threshold, requires opt-in consent for sensitive data, and gives a unique affirmative defense to businesses whose written privacy program reasonably conforms to the NIST Privacy Framework.

consumer_rightsopt_outdata_protection_assessment
View Details →

Tennessee wiretapping and electronic surveillance law (including cellular and cordless telephone recording)

Tenn. Wiretap Act
active

Jurisdiction: Tennessee

Authority: District attorneys (criminal prosecution)

Tennessee is a one-party consent state: a person who is a party to a wire, oral, or electronic communication, or who has one party's prior consent, may intercept it unless the purpose is a criminal or tortious act. A 2024 amendment repealed the statute's civil damages action and declared that the law does not restrict businesses from disclosing communications to vendors or using vendor cookies and pixels on websites and apps, a response to web-tracking wiretap suits.

View Details →

Texas Data Broker Law

Texas Data Broker Law
active

Jurisdiction: Texas

Effective: 9/1/2023

Authority: Texas Attorney General; Texas Secretary of State administers registration and the registry

Requires data brokers to register annually with the Texas Secretary of State, post a conspicuous data-broker notice, and keep a written comprehensive information security program. The 2025 session broadened the definition of data broker, added a TDPSA-rights link to the registration and website notice, and moved the law from chapter 509 to chapter 510.

View Details →

Texas Data Privacy and Security Act

TDPSA
active

Jurisdiction: Texas

Effective: 7/1/2024

Authority: Texas Attorney General (exclusive; 541.151)

Max Fine: Up to $7,500 per violation

Texas's comprehensive consumer privacy law. It gives Texas consumers rights to access, correct, delete, and port their personal data and to opt out of targeted advertising, sale, and significant profiling, and requires controllers to give privacy notices, get consent for sensitive data, and run data protection assessments. It has no revenue threshold; it applies to any covered business that is not an SBA-defined small business.

consumer_rightsopt_outdata_brokerssensitive_data
View Details →

Texas Genomic Act of 2025

Texas Genomic Act
active

Jurisdiction: Texas

Effective: 9/1/2025

Authority: Texas Attorney General

Keeps Texans' genome sequencing data away from foreign adversaries (as defined in 15 C.F.R. 791.4(a)). Covered entities may not use sequencers or software from foreign-adversary sources, may not store or allow access to Texans' sequencing data in adversary countries, must secure that data, and must certify compliance to the attorney general each year.

View Details →

Texas Medical Records Privacy Act

Texas Medical Records Privacy Act
active

Jurisdiction: Texas

Effective: 9/1/2001

Authority: Texas Attorney General; Health and Human Services Commission and licensing agencies (audits, discipline)

Texas's health privacy law, strengthened by H.B. 300 (2011), reaches anyone who handles protected health information, not just HIPAA covered entities. It requires workforce privacy training, electronic record access within 15 business days, and consent for marketing uses, and it bans the sale of PHI and reidentification and requires notice and authorization for electronic disclosures.

View Details →

Texas Responsible Artificial Intelligence Governance Act

TRAIGA
active

Jurisdiction: Texas

Effective: 1/1/2026

Authority: Texas Attorney General (exclusive); licensing agencies may add sanctions on AG recommendation (552.101, 552.106)

Texas's AI statute sets baseline prohibitions on developing or deploying AI to manipulate people toward self-harm or crime, to unlawfully discriminate, to infringe constitutional rights, or to produce child sexual abuse material. It requires government agencies and health care providers to tell people they are interacting with AI, bars government social scoring and non-consensual biometric identification, and creates an AI regulatory sandbox and the Texas Artificial Intelligence Council. It also amended the biometric law (503.001) and TDPSA processor duties (541.104).

View Details →

Texas Telemarketing Disclosure and Privacy Act (Texas no-call list)

Texas No-Call Act
active

Jurisdiction: Texas

Effective: 4/1/2009

Authority: Public Utility Commission of Texas; Texas Attorney General; state licensing agencies

Creates the Texas no-call list and bars telemarketing calls to listed numbers more than 60 days after they appear. It also bars caller-ID blocking or spoofing by telemarketers and regulates fax solicitations.

View Details →

Texas Wiretap Law (Unlawful Interception, Use, or Disclosure of Communications)

Texas Wiretap Act
active

Jurisdiction: Texas

Effective: 8/31/1981

Authority: State prosecutors (criminal); federal or state government civil suits (Code Crim. Proc. art. 18A.503)

Texas is a one-party consent state: intercepting a wire, oral, or electronic communication is a crime unless the person is a party to it or a party gave prior consent. The chapter also criminalizes unauthorized access to stored communications, unauthorized pen registers, and divulgence of communications by public service providers, and the Code of Criminal Procedure gives victims a civil damages action.

View Details →

Theft of Identity and Trafficking in Stolen Identities (criminal offense and civil action)

KY Identity Theft
active

Jurisdiction: Kentucky

Effective: 7/14/2000

Authority: Prosecutors; victims via civil action; Consumer Protection Act enforcement for repeat business violators

Criminalizes knowingly possessing or using another person's identifying information, including name, SSN, account PINs, and unique biometric data, to impersonate them for gain, credit transactions, evading detection, or commercial or political benefit. Victims have a civil cause of action for compensatory and punitive damages and fees.

View Details →

Tort Liability for Cybersecurity Programs (cybersecurity safe harbor)

Iowa Cybersecurity Safe Harbor
active

Jurisdiction: Iowa

Effective: 7/1/2023

Authority: None (courts apply the affirmative defense in tort suits)

Iowa's cybersecurity safe harbor gives businesses an affirmative defense against tort lawsuits over data breaches if they maintain a written cybersecurity program that reasonably conforms to a recognized framework such as the NIST Cybersecurity Framework, NIST SP 800-171 or 800-53, FedRAMP, CIS Controls, or ISO/IEC 27000. It is voluntary: it rewards good security rather than mandating it.

View Details →

Tracking device prohibition and vehicle remote-access suspension for abuse survivors

LA Location Tracking Protections
active

Jurisdiction: Louisiana

Authority: District attorneys (R.S. 14:323); Louisiana Attorney General (R.S. 46:2193)

Louisiana makes it a crime to use a tracking device to follow another person's location or movements without consent, with exceptions for vehicle owners, parents of minors, law enforcement with a court order, and others. A 2025 law removes the owner exception for abusers subject to protective orders and requires vehicle manufacturers to cut off an abuser's remote access to a survivor's vehicle within two business days of a complete request.

View Details →

Transparency in Frontier Artificial Intelligence Act (SB 53)

TFAIA
active

Jurisdiction: California

Effective: 1/1/2026

Authority: California Attorney General (civil penalties); Office of Emergency Services (incident reports)

An AI safety transparency law rather than a privacy law: large frontier AI developers must publish a framework for managing catastrophic risk, publish transparency reports when releasing frontier models, and report critical safety incidents to the Office of Emergency Services. Included here because it is one of California's core AI statutes.

View Details →

Unauthorized Placement of Global Positioning Device; Stalking by Technological Device

Iowa GPS Tracking Law
active

Jurisdiction: Iowa

Effective: 7/1/2017

Authority: County attorneys and the Attorney General (criminal prosecution)

Iowa makes it a crime to secretly put a GPS tracker on another person or their property to follow their movements without consent or a legitimate purpose. The same 2017 act expanded the stalking law so that repeatedly using phones, cameras, recorders, or GPS devices to locate, listen to, or watch someone without authorization can form a stalking course of conduct.

View Details →

Unauthorized use of electronic tracking device

VA tracking device
active

Jurisdiction: Virginia

Effective: 7/1/2013

Authority: Criminal prosecution

Makes it a crime to deceptively place a GPS or other electronic tracking device without consent and use it to track a person's location. Fleet owners and electronic communications providers that disclose tracking in their terms or privacy policy are exempt.

View Details →

Unauthorized use of name, picture, voice, or likeness (statutory right of privacy and publicity)

VA right of publicity
active

Jurisdiction: Virginia

Authority: Private civil action

Virginia's only statutory privacy tort: a person, or a deceased person's spouse or next of kin, may sue to stop and recover damages for the use of their name, portrait, picture, voice, or likeness for advertising or trade without written consent (a parent's consent for minors).

View Details →

Uniform Civil Remedies for Unauthorized Disclosure of Intimate Images Act

Nebraska Intimate Images Civil Remedies Act
active

Jurisdiction: Nebraska

Effective: 9/1/2019

Authority: Courts (private civil action)

This uniform act gives people depicted in private intimate images a civil claim against anyone who shares or threatens to share those images without consent. A 2025 amendment (LB371) extends it to computer-generated or digitally manipulated images, covering sexual deepfakes. Consenting to an image's creation or earlier sharing does not by itself mean consent to later disclosure.

View Details →

Uniform Civil Remedies for Unauthorized Disclosure of Intimate Images Act

Iowa Intimate Images Civil Remedy Act
active

Jurisdiction: Iowa

Effective: 7/1/2021

Authority: Depicted individuals (civil action)

Iowa adopted the Uniform Law Commission's civil remedy for nonconsensual disclosure of intimate images. A depicted person can sue someone who knowingly or recklessly shares, or threatens to share, a private intimate image without consent, and may proceed with identifying details redacted. Consent to creating an image or an earlier consensual sharing does not by itself mean consent to later disclosure.

View Details →

Uniform Deceptive Trade Practices Act: Privacy Policy and Related Online Provisions

Nebraska UDTPA Privacy Provisions
active

Jurisdiction: Nebraska

Authority: Nebraska Attorney General; private injunctive actions

Nebraska's deceptive trade practices statute makes it a deceptive practice to knowingly make a false or misleading statement in a published privacy policy about how personal information from the public is used, which works as Nebraska's online privacy policy accuracy rule. Later amendments added a ban on publishing sexually explicit depictions of minors or nonconsenting people (LB383, 2025) and, from 2027, duties on paid-ad social media platforms to verify advertisers' identities and fight impersonation scams (LB838, 2026).

View Details →

Uniform Health Care Information Act (providers not subject to HIPAA)

MT UHCIA
active

Jurisdiction: Montana

Effective: 10/1/1987

Authority: Attorney General or county attorney (civil, 50-16-552); private plaintiffs (50-16-553)

Montana's Uniform Health Care Information Act protects patient health information held by providers not covered by HIPAA, limiting disclosure without written patient authorization and giving patients rights to see, copy and correct their records. A 2025 amendment extends its confidentiality rules to mental health and substance-use apps and websites.

View Details →

Uniform Motor Vehicle Records Disclosure Act

Nebraska UMVRDA
active

Jurisdiction: Nebraska

Authority: Nebraska Department of Motor Vehicles; criminal prosecution for false statements

Nebraska's implementation of the federal Driver's Privacy Protection Act bars the DMV from disclosing personal information in motor vehicle records except for listed permissible purposes, and bars disclosure of sensitive personal information (such as photos and SSNs) without express written consent except as listed. Private recipients may resell or redisclose only for permitted uses and must keep five years of records; bulk marketing use requires notarized written consent of each individual.

View Details →

Unlawful Access to Stored Communications

Florida Stored Communications Law
active

Jurisdiction: Florida

Authority: State attorneys (criminal)

Florida's counterpart to the federal Stored Communications Act. It makes it a crime to access an electronic communication service facility without authorization and obtain, alter, or prevent access to messages in electronic storage. Conduct authorized by the service provider, or by the user for that user's own communications, is excepted.

View Details →

Unlawful Automated Telephone Solicitation

MT Robocall Law
active

Jurisdiction: Montana

Effective: 10/1/1991

Authority: County attorneys and the Attorney General (criminal prosecution)

Montana bans automated dialing with prerecorded messages for selling, soliciting, gathering data or political campaigning. Informational calls about purchased goods, responses to inquiries, and calls where there is a preexisting business relationship are allowed.

View Details →

Unlawful creation of image of another (voyeurism)

VA unlawful image creation
active

Jurisdiction: Virginia

Effective: 7/1/1994

Authority: Criminal prosecution

Criminalizes secretly creating video or still images of a nonconsenting person who is nude, in undergarments, or partly undressed in places such as restrooms, dressing rooms, locker rooms, hotel rooms, and bedrooms, and upskirt-style images taken from beneath a person.

View Details →

Unlawful deepfakes and AI-generated intimate images

LA AI Deepfake Image Crimes
active

Jurisdiction: Louisiana

Effective: 8/1/2023

Authority: District attorneys (criminal)

Louisiana criminalizes sexual deepfakes of minors, the distribution or sale of nonconsensual sexual deepfakes of anyone, and the malicious dissemination or sale of AI-created nude images of an identifiable real person. Act 782 of 2026 raised penalties, added enhancements for educators who target students, and created a new crime of possessing such AI images. These laws protect people's intimate image privacy against synthetic media.

View Details →

Unlawful disclosure of private information (doxxing): civil action and crime

ORS 30.835; 163.720
active

Jurisdiction: Oregon

Effective: 6/15/2021

Authority: Private civil action (ORS 30.835); district attorneys for the crime (ORS 163.720)

Gives doxxing victims a civil claim when someone knowingly publishes their personal contact details or information about their children to stalk, harass or injure them, and since January 1, 2026 makes doxxing that leads to stalking, injury or property damage a crime.

View Details →

Unlawful dissemination of intimate images, including realistic digitally created depictions

ORS 163.472; 30.833
active

Jurisdiction: Oregon

Authority: District attorneys (criminal); private civil actions (ORS 30.833, 30.834)

Oregon's nonconsensual intimate image law makes it a crime, and a civil wrong, to share someone's intimate images to harass, humiliate or injure them. HB 2299 (2025) extended it from January 1, 2026 to realistic AI-generated or digitally altered 'deepfake' images.

View Details →

Unlawful dissemination or sale of images of another (including synthetic images)

VA intimate images
active

Jurisdiction: Virginia

Effective: 7/1/2014

Authority: Criminal prosecution

Criminalizes maliciously disseminating or selling nude or sexual images of another person without authorization, with intent to coerce, harass, or intimidate. Since 2019 the section covers images 'created by any means whatsoever', which reaches AI-generated or altered deepfake images.

View Details →

Unlawful Installation of Tracking Device

Texas Tracking Device Law
active

Jurisdiction: Texas

Effective: 9/1/1999

Authority: State prosecutors

Makes it a crime to knowingly install a location-tracking device on another person's vehicle. Consent of the owner or lessee, assisting police, and licensed private investigators acting with written consent or court authorization are affirmative defenses.

View Details →

Unlawful Intrusion and Nonconsensual Intimate Image Crimes

Nebraska Unlawful Intrusion Law
active

Jurisdiction: Nebraska

Authority: County attorneys and the Attorney General (criminal prosecution)

Nebraska's voyeurism statute criminalizes intruding on people in a state of undress, secretly recording intimate areas even in public places, distributing such recordings, distributing private intimate or sexual images without consent (revenge porn), and threatening to do so. Drones are expressly covered.

View Details →

Unlawful Photography, Surveillance, and Tracking on Private Property

IN Unlawful Surveillance and Tracking
active

Jurisdiction: Indiana

Authority: County prosecutors

Indiana makes it a crime to leave recording cameras or surveillance equipment on someone else's private property without the owner's or tenant's consent. It is also a crime to place a tracking device on a person or their property without that person's knowledge or consent. Exceptions cover law enforcement with a warrant, family-member tracking (unless a protective order applies), owners of the tracked property, factory-installed vehicle equipment, and communications providers whose tracking is disclosed in their terms or privacy policy.

View Details →

Unlawful Production or Distribution of Certain Sexually Explicit Media (deepfakes)

Texas Deepfake Law
active

Jurisdiction: Texas

Effective: 9/1/2023

Authority: State prosecutors

Criminalizes creating or distributing AI-generated or altered sexual images or videos of real people without their written consent, and threatening to do so. Disclaimers are no defense; S.B. 441 (2025) added written-consent requirements and defenses for intermediaries and AI providers whose terms prohibit such content.

View Details →

Unlawful use of drones for surveillance

OK Drone Surveillance Law
active

Jurisdiction: Oklahoma

Effective: 11/1/2022

Authority: District attorneys (criminal prosecution)

Makes it a misdemeanor to use a drone to trespass onto private property or low airspace for eavesdropping or surveillance, to photograph or record people where they have a reasonable expectation of privacy, to install recording devices on private property without consent, or to land on private property without consent.

View Details →

Unlawful Use of Mobile Tracking Devices

Nebraska Mobile Tracking Device Law
active

Jurisdiction: Nebraska

Effective: 7/18/2026

Authority: County attorneys and the Attorney General (criminal prosecution)

Enacted by LB935 (2026), this law makes it a felony to put a tracking device or app on someone else's property, or to track a person or their property, without consent, and to fail to remove a device after consent is revoked. Consent is automatically revoked when a spouse files for divorce, annulment, or separation or when a protection order is issued.

View Details →

Unmanned aircraft image capture and surveillance law

Tenn. Drone Surveillance Law
active

Jurisdiction: Tennessee

Effective: 7/1/2014

Authority: District attorneys (criminal prosecution)

Makes it a crime to use a drone to capture images of a person or privately owned real property in Tennessee with intent to conduct surveillance, and to keep or share such images. Later amendments add drone restrictions over large ticketed events, fireworks sites, correctional facilities, and critical infrastructure. Destroying or ceasing to share an image once its unlawful origin is known is a defense.

View Details →

Unmanned Aircraft System Privacy Restrictions

KY Drone Surveillance Law
active

Jurisdiction: Kentucky

Effective: 7/14/2018

Authority: Prosecutors; property owners, tenants, occupants, invitees, and licensees via civil action

Allows commercial, recreational, and educational drone use but, since 2025, bars operators from recording images of private property or the people on it with intent to surveil them or publish unauthorized images in violation of their reasonable expectation of privacy. People on private property are presumed to have that expectation if they cannot be seen from ground level. Law enforcement drone searches require a warrant or other Fourth Amendment authority and must minimize data on nonsuspects.

View Details →

Unsolicited Advertisement Facsimile Transmissions

MT Junk Fax Law
active

Jurisdiction: Montana

Effective: 10/1/2003

Authority: Montana Department of Justice, Office of Consumer Protection

Montana bans sending unsolicited advertisements to fax machines. Public-safety faxes from law enforcement or public-safety entities are exempt.

View Details →

Unsolicited advertising by electronic means (commercial e-mail)

Tenn. Commercial Email Law
active

Jurisdiction: Tennessee

Authority: Injured recipients and e-mail service providers (private civil action)

Requires senders of unsolicited advertising e-mail to provide a toll-free number or return e-mail address for opting out, to honor opt-outs, and to begin the subject line with "ADV:" ("ADV: ADLT" for adult material). It also bans distributing software built to falsify e-mail routing information. The statute says it becomes inoperative when federal law regulates unsolicited commercial e-mail, which raises a real question about its current force after CAN-SPAM (2003).

View Details →

Unsolicited Facsimile Advertisement Law

NJ Junk Fax Law
active

Jurisdiction: New Jersey

Effective: 12/1/2005

Authority: Private actions in Superior Court; Attorney General / Division of Consumer Affairs under the Consumer Fraud Act (56:8-160)

New Jersey bans sending unsolicited fax advertisements within the state, except to recipients with an existing business relationship or fellow members of a nonprofit or trade association. Even permitted faxes must carry a first-page opt-out notice, and recipients can sue for statutory damages.

View Details →

Unsolicited Facsimile Advertising

MN Junk Fax Law
active

Jurisdiction: Minnesota

Authority: Minnesota Attorney General and private parties via 8.31 (325E.395, subd. 3)

Businesses may send unsolicited fax advertisements only if they provide a toll-free number and mailing address where recipients can ask not to receive more, state that information on the fax in at least 9-point type, and stop sending to anyone who asks.

View Details →

Unsolicited facsimiles

Colorado junk fax law
active

Jurisdiction: Colorado

Effective: 5/18/1999

Authority: Colorado Attorney General and district attorneys

Sending unsolicited fax advertisements, faxing without identifying header information, or violating the federal TCPA fax rules is a Colorado deceptive trade practice. Existing business relationships and consented nonprofit faxes are exempt.

View Details →

Unsolicited Fax Advertising and Unsolicited Commercial Email

RI Fax and Email Advertising Law
active

Jurisdiction: Rhode Island

Authority: Rhode Island Attorney General (fax violations as deceptive trade practices); recipients via civil action

Requires senders of unsolicited advertising faxes and unsolicited commercial emails to give recipients a toll-free number (or, for email, a working reply address) to stop further messages, and to honor those requests. It also prohibits commercial emails that spoof a third party's domain name or falsify the message's origin or transmission path. Federal CAN-SPAM likely preempts parts of the email section; see unverified.

View Details →

Unsolicited Fax, Recorded Telephone Messages and Commercial Email

CT Unsolicited Fax & Email
active

Jurisdiction: Connecticut

Authority: Private civil action in Superior Court

Bans unsolicited advertising faxes and automated recorded sales messages, and requires unsolicited commercial email to Connecticut residents to carry an opt-out method and an 'ADV' subject-line label and to stop after an opt-out. The email rules are likely largely preempted by the federal CAN-SPAM Act.

View Details →

Urine and Blood Tests as a Condition of Employment

RI Workplace Drug Testing Law
active

Jurisdiction: Rhode Island

Authority: Prosecutors (misdemeanor); courts via employee civil actions

Limits employer drug testing of current employees to reasonable-suspicion testing based on documented observations, with private sample collection, confirmatory lab testing, an independent retest, a chance to explain, referral to treatment instead of firing for a first positive, and confidentiality of results. Applicants may be tested only after a conditional job offer.

View Details →

Use of Artificial Intelligence by Healthcare Providers Notification Act

RI Healthcare AI Notification Act
active

Jurisdiction: Rhode Island

Effective: 6/22/2026

Authority: Rhode Island Department of Health (licensing authority; the act names no enforcer)

Requires doctors, nurses and other licensed providers and facilities that use artificial intelligence (such as ambient AI scribes) to document patient visits to tell patients about that use and to review the AI-generated documentation for accuracy after the visit.

View Details →

Use of Artificial Intelligence in Health Care (utilization review)

HB 26-1139
enacted_not_effective

Jurisdiction: Colorado

Effective: 1/1/2027

Authority: Colorado Division of Insurance; Department of Human Services; Department of Health Care Policy and Financing

From January 1, 2027, AI used in health coverage utilization review must base decisions on the individual's clinical data, not solely group data, and any medical-necessity denial must be reviewed by a qualified clinician. Entities must periodically review the AI for accuracy and ensure health data is not used beyond its stated purpose, and must disclose their AI use to regulators.

View Details →

Use of Artificial Intelligence in Political Advertising

Florida AI Political Ad Disclaimer Law
active

Jurisdiction: Florida

Effective: 7/1/2024

Authority: Florida Elections Commission; state attorneys

Enacted by HB 919 (2024), this law requires a prominent 'Created in whole or in part with the use of generative artificial intelligence (AI)' disclaimer on political ads that use generative AI to depict a real person doing something that did not happen, when made with intent to injure a candidate or deceive about a ballot issue. It sets size and duration rules for print, video, online, audio, and graphic formats.

View Details →

Use of Credit Information (personal insurance)

IN Insurance Credit Scoring
active

Jurisdiction: Indiana

Effective: 1/1/2004

Authority: Indiana Insurance Commissioner / Department of Insurance

Based on the NCOIL credit-scoring model, this chapter limits how personal-lines insurers use credit information. It bans scores built on income, gender, address, ZIP code, ethnicity, religion, marital status, or nationality, and bars decisions based solely on credit. It also requires disclosure, adverse-action notices, re-rating after credit corrections, and filing of scoring models.

View Details →

Use of Credit Information in Personal Insurance

DE Insurance Credit Scoring Law
active

Jurisdiction: Delaware

Effective: 1/1/2008

Authority: Delaware Insurance Commissioner

Limits how personal-lines insurers use credit information: insurance scores may not use income, gender, sexual orientation, gender identity, education, address, zip code, race, religion, marital status, or nationality, and credit alone cannot drive denial, cancellation, or renewal rates. Insurers must disclose that they may use credit and give specific reasons for credit-based adverse actions.

View Details →

Use of Deep Fake Technology to Influence an Election

MN Election Deepfake Law
active

Jurisdiction: Minnesota

Effective: 8/1/2023

Authority: Criminal prosecution; injunctive relief actions by the Attorney General, county or city attorneys, the depicted individual, or an injured candidate (609.771, subds. 3-4)

Makes it a crime to knowingly or recklessly disseminate a realistic deep fake of a person without consent, with intent to injure a candidate or influence an election, within 90 days before a party nominating convention or after absentee voting begins. The Eighth Circuit affirmed the denial of a preliminary injunction in Kohls v. Ellison on February 9, 2026, so the law remains enforceable while the challenge continues.

View Details →

Use of Deep Fake Technology to Influence an Election

DE Election Deep Fake Law
active

Jurisdiction: Delaware

Effective: 10/9/2024

Authority: Criminal prosecution by the State; depicted candidates may sue in the Court of Chancery (5145(f)-(g))

Makes it a crime to knowingly distribute an AI-generated or digitally manipulated deep fake of a candidate or party within 90 days before an election without the depicted person's consent, unless the media carries a prescribed disclosure that it was altered or artificially generated.

View Details →

Use of Genetic Information in Occupational Licensing

Texas Occupational Licensing Genetic Privacy
active

Jurisdiction: Texas

Effective: 9/1/2003

Authority: Texas Attorney General (civil penalty)

Prevents licensing authorities from denying, suspending, or disciplining occupational licenses based on genetic information or refusal to take a genetic test, and makes genetic information confidential with a right to test results and sample destruction.

View Details →

Use of Genetic Testing Information by Health Benefit Plans

Texas Insurance Genetic Privacy
active

Jurisdiction: Texas

Effective: 4/1/2005

Authority: Texas Commissioner of Insurance (Texas Department of Insurance)

Limits how health plan issuers may request and use genetic tests. Issuers may not use genetic information or a refusal to be tested to reject, deny, limit, or price coverage, must keep genetic information confidential, and must destroy samples after use.

View Details →

Use of Lawful Products During Nonworking Hours

MT Lawful Product Law
active

Jurisdiction: Montana

Effective: 10/1/1993

Authority: Private civil action (see 39-2-314)

Employers may not refuse to hire or discriminate against people for legally using lawful products, including food, alcohol, tobacco and marijuana, off premises during nonworking hours. The rule protects off-duty private conduct, with exceptions for impairment and job-related qualifications.

View Details →

Use of Social Media and Electronic Mail (employee and applicant account privacy)

NH Employee Social Media Privacy Law
active

Jurisdiction: New Hampshire

Effective: 9/30/2014

Authority: New Hampshire Labor Commissioner

Bars employers from demanding login credentials for employees' or applicants' personal social media accounts, forcing them to add contacts, or lowering privacy settings, and from disciplining those who refuse. Employers may still set equipment-use policies, monitor their own systems and accounts, and investigate specific misconduct reports.

View Details →

Utah Commercial Email Act

Utah Commercial Email Act
active

Jurisdiction: Utah

Effective: 5/3/2023

Authority: Utah Division of Consumer Protection

Prohibits commercial email that uses an unauthorized third-party domain, forged header information, or a misleading subject line. It is an anti-deception marketing law rather than a privacy-notice law.

View Details →

Utah Consumer Privacy Act

UCPA
active

Jurisdiction: Utah

Effective: 12/31/2023

Authority: Utah Attorney General (exclusive enforcement, 13-61-402(1)); the Division of Consumer Protection receives complaints and refers matters (13-61-401)

Max Fine: Up to $7,500 per violation

Utah's comprehensive consumer privacy law gives Utah residents rights to confirm and access, delete data they provided, obtain a portable copy, correct inaccuracies (since July 1, 2026), and opt out of sale and targeted advertising. Sensitive data uses notice plus opt-out rather than opt-in consent, and there is no statutory appeal right. From January 1, 2027, Part 5 adds in-vehicle privacy duties for motor vehicle manufacturers.

consumer_rightsopt_out
View Details →

Utah Digital Choice Act

Utah Digital Choice Act
active

Jurisdiction: Utah

Effective: 7/1/2026

Authority: Utah Division of Consumer Protection

Enacted by 2025 H.B. 418, it makes social media data portable (including the user's social graph) through the UCPA copy right and requires interoperability interfaces with user consent. 2026 H.B. 408 amendments take effect July 1, 2027, adding a five-business-day deadline and a public open-protocol disclosure.

View Details →

Utah E-Commerce Integrity Act

Utah E-Commerce Integrity Act
active

Jurisdiction: Utah

Authority: Utah Attorney General; ISPs and affected owners may also sue

Prohibits phishing, pharming, and deceptive spyware that changes computer settings or collects information. Enforcement is by civil action from listed plaintiffs and the Attorney General.

View Details →

Utah Minor Protection in Social Media Act

Utah MPSMA
enjoined

Jurisdiction: Utah

Effective: 10/1/2024

Authority: Utah Division of Consumer Protection (enforcement preliminarily enjoined)

Replaced the repealed 2023 Social Media Regulation Act (13-63) with age assurance, maximum-privacy defaults for minors, supervisory tools, and parental consent rules. On September 10, 2024 the federal district court preliminarily enjoined enforcement of every part of 13-71-101 to 401 (NetChoice v. Reyes, D. Utah No. 2:23-cv-00911); the state's appeal (10th Cir. No. 24-4100) was argued November 20, 2025 and was pending as last verified.

View Details →

Vehicle event data recorders

Veh. Code 9951
active

Jurisdiction: California

Authority: Not specified in the section

Requires carmakers to disclose event data recorders in the owner's manual and bars anyone other than the registered owner from retrieving the recorded crash data (speed, direction, location history, braking, seatbelt use) without the owner's consent, a court order, or listed safety-research and repair uses.

View Details →

Vermont Age-Appropriate Design Code Act

VT AADC
enacted_not_effective

Jurisdiction: Vermont

Effective: 1/1/2027

Authority: Vermont Attorney General (rulemaking and enforcement under the Consumer Protection Act, 9 V.S.A. ch. 63)

Vermont's Kids Code requires online businesses likely to be used by minors to design their services so that the use of minors' data does not cause foreseeable emotional distress, compulsive use or discrimination. It sets most-protective default privacy settings for minors, limits data collection and personalised feeds, bans overnight push notifications, requires algorithm transparency and restricts reuse of age assurance data. The Attorney General's implementing rules on design practices and age assurance must be adopted by Jan. 1, 2027 and were out for public comment in September 2026.

View Details →

Vermont Data Broker Law (including the Data Broker Security Breach Notice Act)

VT Data Broker Law
active

Jurisdiction: Vermont

Effective: 1/1/2019

Authority: Vermont Attorney General; Vermont Secretary of State maintains the registry

Vermont passed the first U.S. data broker registration law in 2018. Data brokers must register each year with the Secretary of State, run a written information security program, and may not sell data for fraud, stalking or discrimination. 2026 Act No. 138, effective Jan. 1, 2027, broadens the definitions, raises the fee to $900, requires a $20,000 bond and much more detailed disclosures, adds buyer verification duties, and creates a separate Data Broker Security Breach Notice Act.

View Details →

Vermont Data Privacy and Online Surveillance Act

VDPOSA
enacted_not_effective

Jurisdiction: Vermont

Effective: 1/1/2028

Authority: Vermont Attorney General (exclusive), under the Vermont Consumer Protection Act, 9 V.S.A. ch. 63

Vermont's comprehensive privacy law, signed June 16, 2026, gives Vermont consumers rights to access, correct, delete and port their personal data, opt out of targeted advertising, sales and certain profiling, and get a list of the third parties their data was sold to. Controllers must minimise collection, get consent before processing or selling sensitive data, honor opt-out preference signals and run data protection and profiling impact assessments. It adds consumer health data protections, including a ban on geofencing within 1,850 feet of health care facilities, that apply to businesses of any size. Sensitive data is defined broadly and includes consumer health, genetic, biometric, neural and precise geolocation data and government ID numbers (§ 2415a(b)(47)).

View Details →

Vermont Electronic Communication Privacy Act

VECPA
active

Jurisdiction: Vermont

Effective: 10/1/2016

Authority: Courts (suppression and motions to quash)

Requires Vermont law enforcement to get a warrant, a recognised warrant exception, user consent or an emergency justification before compelling service providers to hand over protected user information, and to notify the targets. It bans real-time interception of communications content and cell-tower or GPS location except to find a fugitive under an arrest warrant. Service providers must produce warranted records within 30 days, or within 72 hours if the court orders it.

View Details →

Vermont Fair Credit Reporting Act (including security freeze and medical debt provisions)

VT FCRA
active

Jurisdiction: Vermont

Authority: Vermont Attorney General; private plaintiffs

Vermont's credit reporting law goes beyond the federal FCRA by requiring a consumer's consent (or a court order) before anyone pulls their credit report. It gives consumers free disclosures, dispute rights and free security freezes, including freezes for protected consumers such as minors. Since July 1, 2025, credit reporting agencies may not report or keep medical debt in a consumer's file.

View Details →

Vermont Financial Privacy Act

VT Financial Privacy
active

Jurisdiction: Vermont

Effective: 1/1/2001

Authority: Commissioner of Financial Regulation

Vermont's financial privacy law generally bars financial institutions from disclosing a customer's financial information to anyone, subject to a list of exceptions such as customer authorization, legal process and routine business exchanges. It also regulates loan lead solicitations that use a financial institution's name or a consumer's loan details.

View Details →

Vermont Telemarketing, Do-Not-Call and Robocall Law

VT Telemarketing Law
active

Jurisdiction: Vermont

Authority: Vermont Attorney General; Secretary of State (registration); private plaintiffs

Vermont requires telemarketers to register with the Secretary of State, makes federal Do-Not-Call violations a state-law violation, and requires solicitation calls to transmit caller ID. A 2022 law, effective 2023, mirrors the federal TCPA and Telemarketing Sales Rule limits on robocalls as Vermont law. Call recipients have a private right of action with statutory damages.

View Details →

Video Consumer Privacy Act

Tenn. VCPA
active

Jurisdiction: Tennessee

Authority: Aggrieved consumers (private civil action)

Tennessee's state analogue to the federal Video Privacy Protection Act bars sellers and renters of prerecorded video and similar audiovisual materials from knowingly disclosing information that identifies a consumer as having requested or obtained specific video materials. Disclosure is allowed to the consumer, with informed written consent, for ordinary business operations, or for direct marketing after a clear opt-out opportunity, and records must be destroyed within a year after they are no longer needed.

View Details →

Video Voyeurism and Unauthorized Dissemination of Intimate Images (including digitally created images)

RI Voyeurism / NCII Law
active

Jurisdiction: Rhode Island

Authority: Prosecutors

Criminalizes secretly capturing intimate images where a person expects privacy, peering into homes with imaging devices, and sharing sexually explicit or intimate images of an identifiable adult without consent when the sharer knows or recklessly disregards likely harm. A 2025 amendment extends the dissemination offense to images created by a digital device or altered by digitization, covering AI-generated intimate deepfakes, and adds sextortion and pay-to-remove offenses.

View Details →

Video, Audio and Publication Rental Records Confidentiality (including library borrowing records)

RI Video and Library Records Law
active

Jurisdiction: Rhode Island

Authority: Prosecutors; injured persons via civil action

Makes it unlawful to reveal records linking a person's name and address to the titles or nature of videos, recordings or publications they bought, rented or borrowed from libraries, bookstores, video or music stores or other retailers. Such records must be kept confidential and released only on written waiver.

View Details →

Videotape Rental and Sales Records

NH Video Records Privacy Law
active

Jurisdiction: New Hampshire

Effective: 6/18/1990

Authority: Not specified in the section

Makes records identifying who rented or bought videotapes confidential. Sellers and rental businesses may disclose them only for business operations, with the customer's (or a minor's parent's) consent, to police investigating unreturned tapes, under subpoena or court order, where a statute requires, or for debt collection and order fulfillment.

View Details →

Videotape Rental and Sales Records Privacy

MN Video Privacy Law
active

Jurisdiction: Minnesota

Authority: Minnesota Attorney General under 8.31; consumers by civil action (325I.03)

Minnesota's video privacy law bars video rental and sales businesses from knowingly disclosing information identifying which video materials a customer requested or obtained, except to the customer, under subpoena, court order or warrant, in a transfer of the business, or with written informed consent given on a separate bold-type notice. Records must be destroyed within a year after they are no longer needed.

View Details →

Violation of Privacy (criminal)

DE Violation of Privacy
active

Jurisdiction: Delaware

Authority: Criminal prosecution by the State (Delaware Department of Justice)

Delaware's criminal privacy statute covers trespassing to eavesdrop, hidden recording devices in private places, intercepting or divulging private messages without the consent of all parties, voyeuristic recording, placing a location tracker on someone else's vehicle without the owner's consent, and distributing nude or sexual images, including AI deep fakes, without consent.

View Details →

Violation of Privacy (surveillance and voyeurism offenses)

NH Violation of Privacy Statute
active

Jurisdiction: New Hampshire

Authority: State and county prosecutors

Makes it a crime to install or use a device without consent to observe, photograph, record or transmit images or sounds in a private place (restrooms, locker rooms, homes), to capture a person's private body parts, or to capture from outside a private place images, sounds, location or movement not ordinarily perceptible outside. It also criminalizes sharing one's own sexual recordings without the other participant's consent. Investigative surveillance by employees acting on articulable suspicion is carved out.

View Details →

Virginia Computer Crimes Act (privacy provisions: computer invasion of privacy, keystroke loggers, spam)

VA Computer Crimes Act
active

Jurisdiction: Virginia

Effective: 7/1/1984

Authority: Criminal prosecution; injured persons and email service providers by civil action (18.2-152.12)

Virginia's computer crime law makes it a crime to use a computer to examine another person's employment, salary, credit, financial, or identifying information without authority, to install keystroke-logging software on another's computer, and to forge routing information to send spam. Injured people can sue for damages.

View Details →

Virginia Consumer Data Protection Act

VCDPA
active

Jurisdiction: Virginia

Effective: 1/1/2023

Authority: Virginia Attorney General (exclusive authority, 59.1-584(A))

Max Fine: Up to $7,500 per violation

Virginia's comprehensive consumer privacy law gives residents rights to access, correct, delete, and port their personal data and to opt out of targeted advertising, sale, and significant-decision profiling, with an appeal process. Controllers need opt-in consent for sensitive data, must run data protection assessments for higher-risk processing, and face extra limits on known children's data (2025) and a ban on selling precise geolocation data (from July 1, 2026). Section 59.1-577.1 on minors' social media time limits is listed as a separate entry because it is enjoined.

consumer_rightsopt_outdata_protection_assessmentsensitive_data
View Details →

Virginia Consumer Protection Act, reproductive or sexual health information

VCPA reproductive health
active

Jurisdiction: Virginia

Effective: 7/1/2025

Authority: Virginia Attorney General, attorneys for the Commonwealth, and local attorneys (59.1-203, 59.1-206); consumers via private action (59.1-204)

Makes it a prohibited practice under the Virginia Consumer Protection Act to obtain, disclose, sell, or disseminate personally identifiable reproductive or sexual health information without the consumer's consent. 'Consent' borrows the VCDPA's opt-in definition, and the protected information includes location data suggesting an attempt to obtain reproductive or sexual health services.

View Details →

Virginia Telephone Privacy Protection Act

VTPPA
active

Jurisdiction: Virginia

Effective: 7/1/2001

Authority: Virginia Attorney General, Commonwealth's attorneys, and local attorneys (59.1-517); aggrieved persons (59.1-515)

Virginia's telemarketing law limits sales calls and texts to 8 a.m. to 9 p.m., requires callers to identify themselves and transmit caller ID, restricts abandoned calls, and bars solicitations to numbers on the National Do Not Call Registry or to people who asked not to be contacted. Since January 1, 2026, a reply of STOP or UNSUBSCRIBE to a sales text must be honored for at least 10 years.

View Details →

Voter list dissemination and commercial-use ban

AL Voter List Law
active

Jurisdiction: Alabama

Authority: Alabama Secretary of State (list access); no enforcement mechanism specified in the section

Makes voter lists and 10 cycles of election history available electronically for a fee of up to $1,000 per list, but keeps Social Security numbers, driver license numbers, email addresses, telephone numbers, and other protected voter data confidential. Voters registering or updating from June 1, 2026 can opt in to share their phone number. Anyone who gets the data may not sell, publish, or use it for commercial purposes; election and campaign uses are allowed.

View Details →

Voyeurism

VT Voyeurism Law
active

Jurisdiction: Vermont

Authority: State's Attorneys and Attorney General (criminal)

Criminalises secretly viewing or recording another person's intimate areas where they expect privacy, covert surveillance or recording of people inside a home, and recording people engaged in sexual conduct without consent. Sharing such recordings is a separate crime. Vermont has no general wiretap or eavesdropping statute, so this and the images law are its main recording-privacy crimes.

View Details →

Voyeurism and Video Voyeurism

KY Voyeurism
active

Jurisdiction: Kentucky

Effective: 7/15/2002

Authority: Commonwealth's and county attorneys (criminal prosecution)

Makes it a crime to view, photograph, or film another person's sexual conduct, genitals, private undergarments, or female breast without consent in a place where the person reasonably expects privacy. Selling or distributing such images, including over the internet, is a felony.

View Details →

Voyeurism, Public Voyeurism, and Remote Aerial Voyeurism

IN Voyeurism
active

Jurisdiction: Indiana

Authority: County prosecutors

Indiana criminalizes peeping into occupied homes and places where people undress, recording someone's private areas without consent, and using drones to capture images or audio of people at home in places not visible to the public. Since July 1, 2024, 'peep' includes using a concealed camera to capture an intimate image.

View Details →

Wiretapping and Eavesdropping

NH Wiretap Act
active

Jurisdiction: New Hampshire

Effective: 8/31/1969

Authority: Attorney General and county attorneys (criminal); private civil actions

New Hampshire is an all-party consent state: it is a crime to intercept, record, disclose or use a telephone or in-person oral communication without the consent of every party, subject to narrow exceptions for carriers, emergency services and authorized law enforcement. The chapter also bans surreptitious interception devices, restricts cell site simulator tracking of phones without consent or a warrant, and sets the court-order process for government wiretaps.

View Details →

Wiretapping, Electronic Surveillance and Interception of Communications; Stored Wire and Electronic Communications

DE Wiretap Act
active

Jurisdiction: Delaware

Effective: 7/23/1999

Authority: Criminal prosecution by the State (Attorney General); private civil actions by aggrieved persons (2409, 2427)

Delaware's wiretap law makes it a felony to intercept, disclose, or use wire, oral, or electronic communications, but allows interception by a party to the communication or with one party's prior consent unless done to commit a crime or tort. A separate subchapter bars unauthorized access to stored communications and limits when public communication and remote computing providers may disclose stored contents. Note that the separate violation-of-privacy statute, 11 Del. C. § 1335(a)(4), makes intercepting private messages without the consent of all parties a misdemeanor, so Delaware's recording-consent rule is often described as unsettled.

View Details →

Workforce Drug and Alcohol Testing Act

MT Drug Testing Act
active

Jurisdiction: Montana

Effective: 10/1/1997

Authority: Not verified

Montana employers that drug or alcohol test must follow a written, pre-announced testing program with federal-standard collection, medical review officer certification, and employee rebuttal rights. Test results and related records are confidential.

View Details →

Workplace Drug and Alcohol Testing

Nebraska Workplace Drug Testing Law
active

Jurisdiction: Nebraska

Authority: No administrative enforcer named; tampering offenses are prosecuted criminally

Nebraska does not require workplace drug testing, but employers that test must confirm positive screens with approved laboratory or breath-test methods before acting on them, preserve positive specimens, keep a chain of custody, and keep results confidential.

View Details →

Workplace Drug Testing Law

VT Drug Testing Law
active

Jurisdiction: Vermont

Effective: 9/1/1987

Authority: Courts (private actions); State civil and criminal enforcement

Sharply limits workplace drug testing in Vermont. Applicants may be tested only after a conditional job offer and written notice. Employees may be tested only on probable cause and when a rehabilitation program is available, and random or company-wide testing is banned unless federal law requires it. Test results and related health information must be kept confidential.

View Details →

Workplace Privacy Act

Nebraska Workplace Privacy Act
active

Jurisdiction: Nebraska

Effective: 7/21/2016

Authority: Courts (private civil action by employees and applicants)

This social media password law bars employers from demanding access to employees' or applicants' personal online accounts, making them log in in front of the employer, forcing them to add the employer as a contact or change privacy settings, or retaliating for refusals. Employers keep rights over their own devices, accounts, and networks and may investigate specific misconduct.

View Details →