11 min read

Between January 2025 and January 2026, twelve new state privacy laws took effect in the US, more than doubling the number of states enforcing comprehensive consumer privacy rights in a single year. Twenty states now have these laws in force, and the grace periods that used to soften them are steadily disappearing.
This guide breaks down what each law actually requires, which cure periods have already expired, and what's coming next.
Effective January 1, 2025, Delaware's privacy law applies to businesses that conduct business in Delaware or produce products or services targeted to Delaware residents, and that in a calendar year control or process the personal data of at least 35,000 Delaware consumers (excluding data processed solely for payment transactions), or at least 10,000 Delaware consumers while deriving more than 20 percent of annual gross revenue from the sale of personal data.
The DPDPA gives consumers the right to access, confirm, correct, delete, and transfer their data, plus the right to opt out of data sales and targeted advertising. Businesses must also honor universal opt-out signals (effective January 1, 2026), conduct data protection assessments above the 100,000-consumer threshold, and obtain parental consent for processing children's data under 13. A 60-day cure period was automatic through January 1, 2026; it's now discretionary. Willful violations can result in fines of up to $10,000 per violation.
Learn more: Diving into Delaware's Privacy Law: Key Requirements for Compliance
Effective January 1, 2025, the NDPA applies to entities that conduct business in Nebraska or produce products or services consumed by Nebraska residents, process or engage in the sale of personal data, and aren't classified as a small business under the federal Small Business Act.
Consumers have the right to access, confirm processing, correct, delete, transfer, and opt out of data sales and targeted advertising. Selling sensitive personal data without consent is prohibited, and universal opt-out signals have been required from the law's effective date. A 30-day cure period applies, after which businesses may face civil penalties of up to $7,500 per violation, enforced by the Attorney General with no private right of action.
Learn more: The Nebraska Data Privacy Act: Key Requirements for Compliance
Effective January 1, 2025, New Hampshire's law applies to businesses that conduct business in or target products or services to New Hampshire residents, and that process the personal data of at least 35,000 consumers (excluding payment-only data) or process the data of at least 10,000 consumers while deriving over 25 percent of revenue from the sale of personal data.
SB 255 provides the typical consumer rights, access, correction, deletion, portability, and opt-out of data sales and targeted advertising, and required universal opt-out signal recognition from day one. It includes specific protections for sensitive data, restricting processing for children under 13 and imposing extra safeguards for consumers aged 13 to 15. The Attorney General can impose civil fines of up to $10,000 per violation, with criminal penalties up to $100,000 for willful disregard.
Learn more: Navigating New Hampshire's Data Privacy Law: Compliance Requirements for Businesses
Effective January 1, 2025, the ICDPA applies to businesses that conduct business in Iowa or produce products or services targeted at Iowa consumers, and that control or process personal data of at least 100,000 Iowa consumers, or derive over 50 percent of revenue from selling the personal data of at least 25,000 Iowa consumers.
Iowa's law grants rights to access, confirm processing, delete, and port data, and to opt out of targeted advertising and data sales, but notably omits a right to correct inaccurate information or opt out of profiling, the only comprehensive state law missing both. Procedurally, it's also the most business-friendly: a 90-day response window (with a possible 45-day extension) and a permanent, non-expiring 90-day cure period, the longest of any state.
Learn more: Unveiling Iowa's Privacy Law: What Businesses Need to Know
Effective January 15, 2025, New Jersey's law applies to entities that determine the purpose and means of processing personal information while conducting business in or targeting New Jersey residents, and that control or process the data of at least 100,000 New Jersey consumers, or 25,000 consumers while deriving revenue or discounts from the sale of personal data.
Consumers have the right to access, delete, correct, and transfer their data, plus the right to opt out of data sales, targeted advertising, automated decision-making, and profiling, and the right to appeal a denied request. Universal opt-out signal enforcement began July 15, 2025, after an initial six-month grace period.
Learn more: New Jersey's Privacy Law Explained: What Businesses Need to Know
Effective July 1, 2025, TIPA applies to businesses that conduct business in Tennessee or target Tennessee residents, exceed $25 million in revenue, and either control or process personal information of at least 25,000 consumers while deriving more than 50 percent of gross revenue from selling it, or control or process the data of at least 175,000 consumers.
Consumers get rights to access, confirm processing, correct, delete, transfer, and opt out of targeted advertising and data sales. Sensitive data processing must comply with COPPA. A 60-day cure period applies, with fines up to $7,500 per violation. TIPA also includes a distinctive affirmative defense: a written privacy program aligned with a recognized framework like NIST's can be used as a defense against alleged violations.
Learn more: The Tennessee Information Protection Act: Compliance Requirements and Checklist
Effective July 31, 2025, the MCDPA applies to entities that conduct business in or target Minnesota residents, and that control or process personal data of at least 100,000 consumers annually (excluding payment-only data), or derive more than 25 percent of gross revenue from selling data while processing at least 25,000 consumers' data.
Minnesota's law is one of the strictest in the country. Consumers can access, confirm processing, correct, delete, transfer, and opt out of data sales and targeted advertising, and where profiling produces a legally significant effect, such as a mortgage decision, they can question the result and ask what different inputs would have changed the outcome. Minnesota is also the only state to explicitly require data inventories, plus a data minimization obligation: controllers can't retain data no longer relevant to its original purpose. Its 30-day cure period expired January 31, 2026, so Minnesota now enforces without a grace period, with fines up to $7,500 per violation.
Learn more: The Minnesota Consumer Data Privacy Act: Everything Businesses Need to Know
Effective October 1, 2025, MODPA applies to businesses that conduct business in or target Maryland residents, and that process personal data of at least 35,000 consumers (excluding payment-only data), or process data of at least 10,000 consumers while deriving more than 20 percent of gross revenue from its sale.
Maryland introduces some of the strictest sensitive-data rules of any state law: collection, processing, or sharing is permitted only when strictly necessary for the product or service requested, selling sensitive data is banned outright, and targeted advertising to consumers under 18 is prohibited entirely. Whether universal opt-out signals are mandatory remains unsettled: the statutory text reads as optional, but many practitioners believe the drafters intended otherwise. A discretionary 60-day cure period applies only to violations before April 1, 2027. Fines reach $7,500 per violation, $25,000 for repeats, with criminal penalties possible in severe cases.
Learn more: Maryland's Data Privacy Law: What Businesses Need to Know
Get a skimmable, searchable guide to every US state privacy law, including which require data subject request fulfillment.
Get the trackerThree more comprehensive privacy laws took effect January 1, 2026: Indiana's and Kentucky's Consumer Data Protection Acts, and Rhode Island's Data Transparency and Privacy Protection Act. Indiana and Kentucky track the Virginia model, each with a 30-day cure period. Rhode Island stands apart, applying to businesses processing data of as few as 35,000 residents, with no cure period at all.
That absence fits a broader pattern. Virginia's original 30-day cure period, Colorado's 60-day period, and Connecticut's 60-day period all sunset in 2025, so three of the earliest, most-copied state laws now enforce without a grace period, on top of Minnesota's expiring in January 2026. The generous cure windows that made early state privacy laws easier to adjust to are steadily disappearing as the landscape matures.
Twenty states now have comprehensive privacy laws in effect (some trackers reach that count by including Florida, whose law has a narrower scope than the others), with more than a dozen additional states actively considering legislation for 2027 and beyond.
See how Privacy, Legal & Risk teams keep up with the expanding state law patchwork
See the solutionMaryland's sensitive-data rules are among the strictest in the country. Collection, processing, and sharing are permitted only when strictly necessary for the requested product or service, and selling sensitive data is banned outright, not just restricted.
Tennessee combines a high revenue threshold with an affirmative defense. Few businesses meet TIPA's $25 million bar, and those that do can point to a written privacy program aligned with a recognized standard, like NIST's Privacy Framework, as a defense against alleged violations.
Minnesota's profiling rights go further than most. Consumers can contest a profiling decision with a significant effect, learn how it was reached, and ask what would have produced a different result, not just opt out after the fact.
New Hampshire layered in a data broker registration requirement on top of biometric data protections that classify fingerprints and facial recognition data as sensitive by default.
Iowa remains the most procedurally generous law to businesses, with a 90-day response window, a 45-day possible extension, and a permanent 90-day cure period, a useful benchmark when comparing compliance timelines across a multi-state footprint.
Twelve new laws in twelve months, expiring cure periods, and a state list that keeps growing make a manually maintained, jurisdiction-by-jurisdiction compliance program difficult to sustain. Every new state adds its own thresholds, rights, and deadlines on top of the ones already in place, and a program built to track each one individually falls further behind with each new law that passes.
Talk to Transcend about building a compliance program that scales automatically as new state privacy laws take effect.
Reach out