Policy ยท Privacy

The 20-State Privacy Patchwork in 2026: A Compliance Map for a Fractured United States

๐Ÿ“… Aug 26, 2026 ๐Ÿท๏ธ Privacy / Law ๐Ÿ—ฝ Privacy
๐Ÿ—ฝ
The United States still has no federal consumer privacy law, and in 2026 it has twenty of them at state level. Indiana, Kentucky and Rhode Island joined on 1 January 2026, Connecticut and Oregon added Global Privacy Control recognition on the same day, and the enforcement record is getting thicker. This explainer maps the patchwork, the obligations that repeat across states, and the differences that make compliance expensive.

The twenty states, and the three that just joined

As of mid-2026, twenty states have comprehensive consumer privacy laws on the books: California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia. Indiana, Kentucky and Rhode Island joined on 1 January 2026, and several more states are moving through their legislatures.

The twenty laws share a common skeleton. All grant residents some combination of access, deletion, correction, portability and the right to opt out of data sales or targeted advertising. All require privacy notices. Most define sensitive data - health, biometric, geolocation, children's information - and require consent or a documented opt-out to process it. The shared baseline is real, but the details are where the cost lives.

The Global Privacy Control is now a compliance baseline

Twelve states now require websites to treat the Global Privacy Control browser signal as a binding opt-out: California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon and Texas. Firefox and Brave send GPC by default. A site that does not detect and honour the signal has a compliance gap in over half the states with privacy laws, and GPC failures have become the most common trigger for enforcement actions.

The practical implication: GPC handling is not an optional feature any more. It is the single highest-leverage compliance investment for a site that collects data from US residents, because it is both required in most states and easily verifiable by regulators.

California, Texas, Maryland: the three outliers

California stands alone: the only state with a dedicated privacy regulator (the CPPA), the only one with a private right of action (limited to breach scenarios), and the only one with no cure period - violations trigger enforcement immediately. It also covers employee and B2B contact data, which nearly every other state exempts.

Texas catches everyone: the Texas Data Privacy and Security Act has no revenue or volume threshold, applying to any business operating in the state subject only to small-business exemptions, and the Texas Attorney General has been the most aggressive non-California enforcer. Maryland is the strictest on data minimisation: its Online Data Privacy Act, effective for new data collection from April 2026, prohibits collecting beyond what is reasonably necessary, bans the sale of sensitive data outright, and bans targeting anyone under 18.

Enforcement is real and concentrated

Public enforcement so far has come mainly from California (AG and CPPA), Texas and Connecticut, with Colorado, Maryland, Minnesota, New Jersey and Oregon expected to bring first cases through 2026. The fines are growing: California's record settlement rose to $2.75 million (Disney, February 2026), Texas finalised a settlement over $1 billion in 2025 against a major technology company, and the CPPA has begun issuing public enforcement decisions.

For smaller companies, the risk is less about the headline fines and more about the pattern: GPC failures, webform opt-out failures and opaque privacy notices are the cases being brought. The cheapest compliance is also the most visible - honour the signals, answer the requests, write an honest notice.

The compliance baseline for 2026

For a business operating nationally, the baseline is now clear: recognise GPC universally, offer all consumer rights with a working response process, obtain opt-in consent for sensitive data, audit ad-tech vendors contractually, and keep the privacy notice accurate. Data-protection assessments are required in more states for high-risk processing such as targeted advertising and profiling.

The strategic point is that the patchwork is converging on a floor. A business that meets the strictest common requirements - Maryland-style minimisation, California-style rights handling, GPC recognition everywhere - is compliant in most states with one system rather than twenty. The next few years will determine whether Congress eventually replaces the patchwork with a federal floor; until then, the floor is being set state by state.

Frequently asked questions

How many US states have privacy laws in 2026?

Twenty states have comprehensive consumer privacy laws in force. Indiana, Kentucky and Rhode Island joined on 1 January 2026. Several more states have legislation moving through their legislatures.

What is Global Privacy Control and do I have to honour it?

GPC is a browser signal that tells websites the user wants to opt out of data sales and targeted advertising. Twelve states now require treating it as a binding opt-out, including California, Colorado, Texas and Maryland. Ignoring it is one of the most common triggers for enforcement.

Which state law is the strictest?

Maryland's Online Data Privacy Act is widely considered the closest US analogue to GDPR's purpose-limitation: it bans collection beyond what is reasonably necessary, bans selling sensitive data outright and bans targeting anyone under 18. California remains unique for its private right of action and no cure period.