Compliance

U.S. Data Privacy Laws and Regulations in 2026

March 20, 2026by Bill Tolson

Subscribe to the Smarsh Blog Digest

Subscribe to receive a monthly digest of articles exploring regulatory updates, news, trends and best practices in electronic communications capture and archiving.

Smarsh handles information you submit to Smarsh in accordance with its Privacy Policy. By clicking "submit", you consent to Smarsh processing your information and storing it in accordance with the Privacy Policy and agree to receive communications from Smarsh and its third-party partners regarding products and services that may be of interest to you. You may withdraw your consent at any time by emailing [email protected].

In 2026, organizations are navigating a growing landscape of U.S. data privacy laws, with nearly 20 states now introducing their own regulations. While early privacy legislation focused primarily on California’s Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), the modern privacy landscape is far broader. Multiple states have enacted comprehensive privacy statutes, and several existing laws now include new regulatory requirements.

Key takeaways

  • Three new comprehensive privacy laws take effect in Indiana, Kentucky, and Rhode Island.
  • Regulatory updates take effect in California, Connecticut, Oregon, and Utah.
  • Arkansas introduces a new privacy law effective July 2026.
  • Regulatory focus on minors’ data, automated decision-making, and data broker transparency increases.
  • Consumer rights, such as data correction and universal opt-out mechanisms, expand.

What to know about privacy laws in 2026

The U.S. privacy landscape is a patchwork of emerging and diverging regulations.

Major 2026 developments include new state laws, expanded consumer rights, and heightened regulatory focus on minors’ data and automated decision-making. These mark a significant shift in how organizations must manage and protect personal information across the United States.

For organizations operating across multiple states, privacy compliance now requires ongoing governance rather than a one-time legal review.

For 2026, the most important question for companies is whether existing data privacy compliance programs remain sufficient.

Explore how data sovereignty rules have shifted in the U.S. and the rest of the world and how you can stay compliant no matter where you do business.

How many states have privacy laws?

As of 2026, approximately 19 U.S. states have comprehensive consumer privacy laws. Some analysts put the number at 20 data privacy laws, depending on how Florida’s Digital Bill of Rights is categorized.

This expanding patchwork of state legislation reflects the rising importance of data protection nationwide, as lawmakers respond to evolving concerns about personal information, digital rights, and technological change.

The introduction of new statutes in states such as Indiana, Kentucky, and Rhode Island — along with ongoing updates in states like California and Connecticut — demonstrates a nationwide shift toward stronger privacy governance. For organizations, this means navigating an increasingly complex and dynamic regulatory environment, where compliance requirements vary from state to state and are regularly updated to address emerging risks and consumer expectations.

These new laws increasingly include unique requirements that call for state-specific compliance programs, adding complexity.

New U.S. state privacy laws taking effect in 2026

Three new privacy laws came into effect on January 1, 2026, expanding the number of states with comprehensive privacy legislation. This wave of new regulations reflects a broader national trend toward strengthening consumer data protections and addressing the rapidly evolving landscape of digital privacy. By enacting these statutes, state lawmakers continue to respond to growing public concerns about how personal information is collected, used, and shared online.

Indiana Consumer Data Protection Act

The Indiana Consumer Data Protection Act provides residents with several key rights, including:

  • Rights to access and delete personal data
  • Correction of inaccurate data
  • Data portability
  • Opt-out rights for targeted advertising and data sales

The law closely mirrors the Virginia model used by several other states.

Kentucky Consumer Data Protection Act

Kentucky’s privacy law also took effect January 1, 2026.

The law introduces:

  • Rights to access and delete personal data
  • Data portability requirements
  • Opt-out rights for targeted advertising and data sales
  • Enforcement authority for the Kentucky Attorney General

Kentucky also created an Office of Data Privacy, demonstrating the state’s commitment to enforcement and oversight.

Rhode Island Data Transparency and Privacy Protection Act

Rhode Island’s privacy law establishes a comprehensive framework that includes:

  • Rights to access and delete personal data
  • Data portability rights
  • Opt-out rights for data sales and targeted advertising
  • Transparency obligations for businesses collecting personal data

Rhode Island’s adoption further expands the nationwide privacy compliance landscape.

Recent privacy law changes in 2026

Several states with existing privacy laws have introduced important amendments or regulatory updates.

California Privacy Rights Act updates

California remains the most influential privacy regulator in the United States.

Two major changes occur in 2026:

  • New California Privacy Protection Agency regulations require risk assessments and cybersecurity audits for certain businesses.
  • The Delete Act creates a centralized deletion system for data brokers beginning August 1, 2026.

These changes further expand California’s already robust privacy framework.

While they share the same acronym (CPRA), the California Privacy Rights Act should not be confused with the California Public Records Act. The California Public Records Act grants the public the right to inspect and copy records held by state and local government agencies to ensure government transparency.

Connecticut Data Privacy Act amendments

Connecticut passed amendments to its Connecticut Data Privacy Act (CTDPA) that take effect July 1, 2026.

The amendments introduce:

  • Expanded consumer access rights
  • Stronger protections for minors
  • Additional limitations on profiling and automated decision-making

Oregon Consumer Privacy Act updates

The Oregon Consumer Privacy Act introduces several significant new restrictions beginning January 1, 2026.

These include:

  • Mandatory recognition of universal opt-out signals
  • Restrictions on selling precise geolocation data
  • Prohibitions on selling personal data of consumers under age 16

Utah Consumer Privacy Act amendment

Utah’s privacy law now includes a right to correct inaccurate personal data, effective July 1, 2026.

Although Utah’s law remains relatively business-friendly compared with other states, this change still requires updates to consumer rights workflows.

Arkansas Consumer Data Protection Act

Arkansas joins the growing list of privacy states when its law takes effect July 1, 2026.

The new law introduces standard privacy rights and requirements, including:

  • Data access
  • Data deletion
  • Data portability
  • Opt-out rights for targeted advertising

Common trends in state privacy bills

The biggest trend in state privacy legislation is greater specificity and stronger enforcement frameworks.

States are increasingly focusing on:

  • Minors’ data protections
  • Automated decision-making oversight
  • Data minimization requirements
  • Geolocation data restrictions
  • Universal opt-out mechanisms
  • Data broker transparency


Although many laws still follow the original Virginia-style model, new amendments are beginning to cause the various state laws to diverge significantly.

There has been a notable, rapid expansion of data privacy legislation in the United States over the last several years. New privacy laws have been enacted across multiple states, each introducing a variety of consumer rights and compliance obligations for businesses.

States such as Utah and Arkansas have introduced comprehensive data protection measures, including rights to access, correct, delete, and transfer personal information, as well as opt-out provisions for targeted advertising. Organizations operating across these jurisdictions need to monitor ongoing law changes to keep data practices aligned with current requirements.

AI, PII, and data privacy compliance

State AI regulation is increasingly intersecting with data privacy requirements. Several states, including California, Illinois, and Connecticut are addressing AI regulation and personal data privacy issues regarding minors, the elderly, and the use of biometric data.

Using personally identifiable information (PII) to train AI can conflict with principles of purpose limitation and data minimization when organizations use the data for alternative purposes or process more of the data than necessary. Deletion is harder after training because PII could be distributed beyond immediate detection.

Practical AI governance should include:

  • Document training data sources, preprocessing steps, model versions, and data lineage
  • Share how AI uses personal data and how individuals can exercise their rights
  • Assign owners to test, audit, and monitor AI systems
  • Use consent forms when PII may be used for AI training
  • Monitor state-specific AI, privacy, and age-related requirements

Before approving a provider’s AI model, review these five questions to assess a third-party's AI model’s data protection, training processes, retention capabilities, and governance controls.

Are there U.S. federal data privacy laws?

Despite multiple legislative proposals, the United States still lacks a comprehensive federal privacy law that would preempt all existing state data privacy laws.

Congress has considered several proposals, but none have been enacted, including the stalled federal data privacy law, American Data Privacy and Protection Act.

As a result, organizations bear the burden of managing compliance rather than relying on a unified federal framework.

What are the penalties for violating state privacy laws?

Most privacy laws authorize enforcement by state attorneys general and include civil penalties. And because violations can apply to individual consumer records, regulatory exposure can escalate quickly (each consumer whose rights are violated may be treated as a separate offense, multiplying the total fines and liabilities).

Many states share similar penalties. Fines of $7,500 to $10,000 per violation are common. There is often additional exposure for violations involving minors. Additional penalties also can be added under other consumer protection laws.

Tip

Managing and protecting personal information can get complicated the more data you collect. Learn how search tiering gives you control over indexing depth across your entire archive without compromising compliance or access.

States with distinct enforcement provisions

California remains the most mature in terms of enforcement infrastructure and recent history of large settlements. Colorado has also pursued active enforcement, including conducting joint sweeps with California and Connecticut. Texas and Illinois stand out for provisions that go beyond the typical state privacy law framework.

  • Colorado
    • Penalties are set at $20,000 per violation, increasing to $50,000 for violations affecting consumers aged 60 or older.
    • Colorado enforces its privacy law through the Colorado Consumer Protection Act, which can allow regulators to pursue substantial penalties.
  • Montana
    • The law does not specify a maximum amount for civil penalties.
    • Only the state attorney general is authorized to enforce the law.
  • California
    • Penalties can be substantial, especially when based on the age of the consumer and assessed per affected individual.
    • Penalties range from $2,663 to $7,988 per violation as of 2025.
  • Texas
    • The state's primary privacy law caps penalties at $7,500 per violation, enforced exclusively by the Texas attorney general.
    • A separate law governing biometric data allows penalties up to $25,000 per violation, the highest civil penalty found under any state consumer privacy law.
  • Illinois
    • Illinois is the only state that gives individuals a private right of action for biometric privacy violations, meaning consumers can sue directly without involving the attorney general.
    • Damages run $1,000 per negligent violation and $5,000 per intentional violation, a structure that has driven a wave of class-action litigation.
  • Tennessee
    • Courts may impose civil penalties of up to $15,000 per violation.
    • Willful or knowing violations may result in damages of up to $45,000 with enforcement handled by the Tennessee attorney general.

State attorneys general have the power to investigate potential violations, issue fines, and pursue legal action against organizations that fail to comply with state privacy statutes. Civil penalties are designed to deter noncompliance and encourage organizations to adopt robust privacy practices. In addition to government enforcement, some states allow private citizens to bring lawsuits in certain circumstances, further increasing the risk to organizations.

What data privacy updates mean for compliance teams

The expansion of state privacy regulation has created several new compliance challenges for organizations.

  • Data inventory management
    Keep clear, accurate records of the personal data you collect, process, and store using an enterprise data map to identify what qualifies as PII, where it resides, how it moves, why it is processed, and who can access it.
  • Cross-border privacy exposure
    U.S. companies processing EU residents’ PII may fall within the GDPR’s territorial scope, including when they offer goods or services to people in the EU or monitor their behavior.
  • Consumer rights fulfillment
    Respond promptly to requests related to personal data, including access, data deletion, correction of inaccurate data, and data portability.
  • Vendor and processor management
    Stay informed about how third-party vendors handle and protect personal data to support compliance and reduce risk.
  • Data retention and governance
    Retain personal data only for legitimate business purposes and only for as long as it’s appropriate or required.

Why privacy compliance now requires strong data governance

Modern data privacy laws increasingly function as data governance mandates. Organizations are expected to show they can:

  • Identify personal data across systems
  • Enforce retention policies
  • Secure the data properly
  • Support deletion requests
  • Respond to regulatory investigations
  • Maintain secure communications archives

This means privacy compliance now intersects directly with records management, eDiscovery, and regulatory archiving.

Retention and deletion for regulated industries

There is some tension between consumer deletion rights and the recordkeeping and retention obligations in regulated industries like financial services. While privacy laws generally allow firms to retain records needed for legal or regulatory obligations, that exception doesn’t mean keeping all data indefinitely.

A defensible approach should:

  • Clearly define which approved communication sources employees may use for business and which content is subject to retention requirements.
  • Direct employees to conduct business communications through approved tools and keep those channels focused on business-related topics.

U.S. regulatory mandates for data storage compliance

Organizations conducting business in the U.S. are expected to adopt specific practices for managing information.

  • Retention: Define and follow clear policies for how long data (especially personal and communications data) is stored, with guidelines for both minimum and maximum timeframes.
  • Security: Put strong safeguards in place to protect personal information from unauthorized access or misuse.
  • Access: Manage and monitor who can access personal data to help ensure it’s only available to the right people.
  • Disposition: Manage archived business communications according to documented retention schedules after applicable regulatory obligations and legal holds expire.
  • Regulatory response: Maintain processes to respond quickly and accurately to regulatory investigations or information requests.

By enforcing these rules around retention, security, access, and deletion, data privacy laws ensure that organizations protect personal information, respect individuals' rights, and remain accountable to regulators.

A defensible archive and centralized data governance strategy help organizations meet privacy requirements while maintaining readiness for legal, regulatory, and eDiscovery demands.

Did you know?

Call recordings can contain personal information. Get our voice compliance checklist to see the seven control areas that shape a defensible voice compliance program.

How archiving supports data governance

A secure, centralized repository helps organizations manage dual obligations of adhering to state-level retention mandates while providing the infrastructure, policy controls, and information extraction capabilities to meet privacy needs.

Such an archive enforces data-retention policies, ensuring information is held only for as long as needed and defensibly disposed when appropriate. It incorporates security measures to protect sensitive personal and communications data from unauthorized access or breaches.

Access controls are foundational, allowing organizations to monitor and restrict who can view, modify, or delete archived information — thereby upholding privacy rights and regulatory mandates.

A centralized archive helps teams locate relevant business communications and manage them according to documented retention and disposition policies. Audit trails and supporting documentation help teams respond accurately and promptly to regulatory inquiries and eDiscovery requests.

By integrating retention, security, access management, and deletion processes, a privacy-compliant archive helps organizations protect personal information, maintain regulatory accountability, and stay prepared for legal, regulatory, and investigative demands.

How does Smarsh help with data privacy laws?

The Smarsh cloud-based archiving platform connects with leading communication tools, capturing and preserving relevant data in a secure, centralized repository. This approach supports compliance with data privacy laws by making it easier to monitor, audit, and respond to regulatory requests.

Organizations of all sizes can maintain data privacy consistently across all communication channels:

  • Gain visibility across digital channels all in one place
  • Retain communications data as long as policies require
  • Find relevant data faster for legal, regulatory, and audit requests
  • Protect sensitive information with advanced encryption, access controls, and monitoring
  • Secure voice records with encryption and PII redaction
  • Maintain defensible trails for regulatory investigations

By centralizing communications data, organizations can better meet evolving data privacy, compliance, and governance obligations.

Frequently asked questions

Share this post!

Bill Tolson
Smarsh Blog

Our internal subject matter experts and our network of external industry experts are featured with insights into the technology and industry trends that affect your electronic communications compliance initiatives. Sign up to benefit from their deep understanding, tips and best practices regarding how your company can manage compliance risk while unlocking the business value of your communications data.

Ready to enable compliant productivity?

Join the 6,500+ customers using Smarsh to drive their business forward.

Contact Us

Tell us about yourself, and we’ll be in touch right away.

icon-angle icon-bars icon-times