Insight

Data Privacy Regulations: Global, Federal & State Laws (2026)

Insight Published 21 min read
Data privacy regulations illustrated by a shield with a checkmark over a government building.

Data privacy regulations govern how organizations collect, use, store, and share personal data and what rights people have over it. There is no single global rulebook. 172 countries now have data privacy laws; the United States has no comprehensive federal law, and most states have filled part of that gap with their own.

Key takeaways

  • Data privacy law comes in two shapes: comprehensive and sectoral. The world mostly chose the first. The US federal government has not, and twenty states have filled part of the gap.
  • Applicability is a four-question method, not a list: users, data, scale, sector.
  • The same six rights and the same short list of business duties recur under almost every regime.
  • Enforcement increasingly starts with what your website does: sweeps test mechanisms, and cure periods are expiring.
  • Every regime’s duties are discharged or violated at the browser layer, where observation is the proof.

What are data privacy regulations?

Data privacy regulations are rules that control how organizations collect, use, store, share, and delete personal data. These laws give rights to individuals and set responsibilities for the organizations handling their data.

The terms vary by jurisdiction more than by meaning. “Data privacy” is the American term. The European term is “data protection.” “Data security” is the narrower discipline of keeping data safe from unauthorized access, which most privacy laws require but none are limited to. A “law” or “act” comes from a legislature. A “regulation” is issued by an agency under a law’s authority. An EU “directive” tells member states what to achieve and lets each write its own statute.

Here are two notes about the scope of these laws.

  1. Personal data is information that can be linked to a specific person. Most laws also set aside certain types of sensitive data, like health, biometrics, precise location, or children’s data, and apply stricter rules to them.
  2. Different laws use different terms. US laws say “personal information” or “personally identifiable information (PII).” The GDPR uses “personal data,” and India uses “digital personal data.” The exact definitions can vary, so figuring out which law applies is a separate question.

In all cases, individuals have rights. Organizations bear the duties. The labels vary by statute: controllers, businesses, or data fiduciaries. There are rules at every level, including international frameworks, national laws, US state laws, and industry-specific rules.


What are the two shapes of data privacy law: comprehensive and sectoral?

Every regime comes in one of two shapes. Comprehensive data privacy laws cover nearly all personal data across nearly all sectors. Sectoral laws cover one kind of data or one industry at a time. The world mostly uses the first shape. The US federal government uses the second.

TypeHow it worksExampleWho it bindsConsent model
Comprehensive (national or regional)One statute governs personal data across the economyGDPR (EU/EEA), PIPL (China), LGPD (Brazil)Nearly every organization handling residents’ dataLawful bases, consent is one of several
Sectoral (federal, US-style)Separate statutes per domain: health, credit, children, education, videoHIPAA, GLBA, COPPA, FCRAOnly organizations in that domainVaries by statute
State comprehensive (US)State omnibus laws filling the federal gapCCPA/CPRA, Virginia VCDPA and successorsBusinesses meeting thresholds, state by stateOpt-out first (opt-in for sensitive data)
Voluntary frameworksStandards an organization chooses to adopt, not lawNIST Privacy Framework, ISO/IEC 27701Nobody, unless contracted or claimed publiclyNot applicable

The last row matters more than it looks. A framework binds no one by itself, but the Federal Trade Commission (FTC) has treated public claims about following a standard as enforceable promises, and contracts turn frameworks into obligations between companies. Binding law and chosen commitment are different rows on the map, and both end up on your website.

Privacy law landscape comparing global regulations, US federal sectoral laws, state privacy laws, and the federal privacy gap.

Why the US stayed sectoral

Congress has repeatedly come close to a comprehensive federal privacy law but stopped. The American Data Privacy and Protection Act passed the House Energy and Commerce Committee 53–2 in 2022 but never reached a floor vote (H.R. 8152, 117th Congress). Its successor, the American Privacy Rights Act, had its markup canceled in June 2024 and expired with the 118th Congress (H.R. 8818, 118th Congress). It has not been reintroduced.

The sticking points remain: whether federal law preempts stronger state laws and whether individuals can sue. The current attempt is the SECURE Data Act (H.R. 8413, introduced April 21, 2026). It leans hard on preemption, and the California Privacy Protection Agency (CPPA) has formally opposed it as a “low national ceiling.” There is still no federal omnibus, and the fight is now explicitly about whether federal law should cap the states.


What are the major data privacy regulations worldwide?

A few major laws set the global standard. The table below compares the ones a US-based company is most likely to meet, on the axes that matter at orientation: coverage, consent model, headline rights, and potential penalties.

RegimeJurisdictionIn forceConsent modelHeadline rightsMaximum penaltyEnforcer
General Data Protection Regulation (GDPR)EU/EEA (+ extraterritorial)May 25, 2018Six lawful bases, consent for processing personal data must be freely given, specific, and informedAccess, erasure, portability, object, restrict, refuse solely automated decisions€20M or 4% of worldwide annual turnoverNational DPAs, coordinated by the European Data Protection Board (EDPB)
UK GDPR + DPA 2018United KingdomJanuary 1, 2021Mirrors General Data Protection Regulation (GDPR)Mirrors GDPR£17.5M or 4% of worldwide turnoverICO
PIPLChina (+ extraterritorial)November 1, 2021Consent-centric, separate consent for sensitive data, sharing, cross-border transferKnow, decide, access, correct, delete, explain¥50M or 5% of prior-year revenue, business suspensionCAC and provincial regulators
LGPDBrazilSeptember 2020 (sanctions from August 2021)Ten legal bases, consent or legitimate interestAccess, correction, deletion, portability, revoke consent2% of Brazil revenue, capped at R$50M per infractionANPD
PIPEDACanada (private sector)In force since 2001Consent-centric (knowledge and consent)Access, correction, challenge complianceNo administrative fines, offenses to C$100,000 on indictment. Reform Bill C-36 would add fines to $10M or 3%Privacy Commissioner (OPC), Federal Court
DPDP Act + Rules 2025India (digital personal data)Act 2023, Rules notified November 2025, core duties from May 2027Consent-first, with “legitimate uses” carve-outsAccess, correction, erasure, nominate, grievance₹250 crore (about $30M) for security-safeguard failuresData Protection Board of India
US state model (contrast row)Individual US states2020 onward, rollingOpt-out first, opt-in for sensitive data and minorsKnow/access, correct, delete, opt out of sale, targeted ads, profilingPer violation: $7,500 (Virginia model), CCPA CPI-adjusted to $2,663 / $7,988State AGs. California also has the CPPA

Read the penalty column as orientation. The ceiling is what a regime can do. The enforcement section covers what regulators actually do. The property that matters most to a US reader is not a row but a shared column header: extraterritorial reach. GDPR, PIPL, LGPD, and DPDP all bind organizations outside their borders that offer goods or services to, or monitor, people inside them. A US company with European traffic is making GDPR decisions whether it knows it or not. 

Read GDPR explainer →

How many countries have data protection laws? 

As of 2026, 144 to 172 countries have enacted national data privacy laws. Graham Greenleaf’s ninth biennial global assessment (April 2025) counts 172 countries. UNCTAD’s tracker counts 79% of 195 economies with legislation in force, on a stricter definition.


What are the US federal data privacy laws?

The United States has no comprehensive federal privacy law. What it has, instead, is a stack of sectoral statutes. Each covers one domain. The FTC’s general authority against unfair or deceptive practices is the connective tissue.

StatuteDomainWho it bindsCore duty at orientationEnforcer
Health Insurance Portability and Accountability Act (HIPAA) (1996)Health informationHealth plans, providers, clearinghouses, business associatesProtect identifiable health information, breach notificationHHS Office for Civil Rights. State AGs can also sue
Gramm-Leach-Bliley Act (GLBA) (1999)Financial dataFinancial institutions (broadly defined, incl. many fintechs and auto dealers)Safeguards program, privacy notices, no pretextingFTC, banking regulators, CFPB
Children’s Online Privacy Protection Act (COPPA) (1998)Children under 13 onlineSites and services directed at children, or with actual knowledgeVerifiable parental consent before collecting children’s dataFTC and state AGs oversee compliance (see our COPPA explainer)
Fair Credit Reporting Act (FCRA) (1970)Credit and consumer reportsCredit bureaus, data furnishers, users of reportsAccuracy, permissible purpose, dispute rightsFTC, CFPB, state AGs, private lawsuits
Family Educational Rights and Privacy Act (FERPA) (1974)Education recordsSchools receiving federal fundsParental/student consent for record disclosureDept. of Education (via funding)
Video Privacy Protection Act (VPPA) (1988)Video viewing history“Video tape service providers” (courts apply it to streaming and websites)Consent before disclosing viewing dataPrivate lawsuits (statutory damages)
Electronic Communications Privacy Act (ECPA) / Telephone Consumer Protection Act (TCPA) / CAN-SPAM ActCommunications and marketingInterceptors, callers and texters, commercial emailersConsent for interception, calls, texts, honest email headersDOJ, FCC, FTC, state AGs, private lawsuits
Privacy Act (1974)Federal agencies’ recordsUS government agenciesFair information practices for citizen/resident recordsDOJ (via litigation)
DOJ Data Security Program (2025)Bulk sensitive data + countries of concernUS persons dealing in covered data with six named countriesProhibited/restricted transactions, due diligence and audits (effective April 8, 2025, full obligations October 5, 2025)Department of Justice

The FTC backstop

Where no sectoral statute applies, the FTC Act’s Section 5 prohibition on unfair or deceptive practices does. That is how the US gets de facto privacy enforcement without a privacy law. A privacy policy is a public claim, and a gap between claim and practice is a deception case. The doctrine has teeth in both directions.

The FTC has said that quietly changing your terms of service to use already-collected data for a new purpose can itself be unfair or deceptive (February 2024), citing enforcement history back to Gateway Learning in 2004. Retroactive policy edits do not launder past collection.


Which US states have comprehensive privacy laws? (the 2026 map)

As of September 2026, twenty states have comprehensive consumer privacy laws in effect (counting Florida’s narrower law, or nineteen under stricter definitions like IAPP’s). Four more have passed legislation that will officially take effect between 2027 and 2028. California led the charge in being the first state to enact comprehensive data privacy legislation via the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA).

StateLawIn effectFamily
CaliforniaCalifornia Consumer Privacy Act (CCPA) enacted in June 2018, as amended by the California Privacy Rights Act (CPRA)Jan 1, 2020 / Jan 1, 2023California model: dedicated agency (CPPA), employee and B2B data covered
VirginiaVirginia Consumer Data Protection Act (VCDPA)Jan 1, 2023Virginia model
ColoradoColorado Privacy Act (CPA)Jul 1, 2023Virginia model (stronger rulemaking)
ConnecticutConnecticut Data Privacy Act (CTDPA)Jul 1, 2023Virginia model
UtahUtah Consumer Privacy Act (UCPA)Dec 31, 2023Virginia model (narrowest)
FloridaFlorida Digital Bill of Rights (FDBR)Jun 29, 2023Narrow: binds mainly $1B+ tech platforms
MontanaMontana Consumer Data Privacy Act (MTCDPA)Oct 1, 2024Virginia model
TexasTexas Data Privacy and Security Act (TDPSA)Jul 1, 2024Virginia model, small-business carve-out instead of volume thresholds
OregonOregon Consumer Privacy Act (OCPA)Jul 1, 2024Virginia model
DelawareDelaware Personal Data Privacy Act (DPDPA)Jan 1, 2025Virginia model (low thresholds)
IowaIowa Consumer Data Protection Act (ICDPA)Jan 1, 2025Virginia model (weakest rights set)
NebraskaNebraska Data Privacy Act (NDPA)Jan 1, 2025Virginia model, applies regardless of volume
New HampshireNew Hampshire Privacy Act (NHPA)Mar 1, 2025Virginia model (low thresholds)
New JerseyNew Jersey Data Privacy Act (NJDPA)Jan 15, 2025Virginia model
TennesseeTennessee Information Protection Act (TIPA)Jul 1, 2025Virginia model
MinnesotaMinnesota Consumer Data Privacy Act (MCDPA)Jul 31, 2025Virginia model (plus profiling rights)
MarylandMaryland Online Data Privacy Act (MODPA)Oct 1, 2025Strictest: data minimization as a hard duty
KentuckyKentucky Consumer Data Protection Act (KCDPA)Jan 1, 2026Virginia model
IndianaIndiana Consumer Data Protection Act (INCDPA)Jan 1, 2026Virginia model
Rhode IslandRhode Island Data Transparency and Privacy Protection Act (RIDTPPA)Jan 1, 2026Virginia model, no cure period

Read the map as families, not fifty entries. The differences that matter at orientation:

  • Sensitive data: California-style laws allow collection with an opt-out or a right to limit. Most Virginia-model laws require opt-in consent first.
  • Cure periods are expiring: Early laws let businesses fix violations before penalties. Colorado’s and Connecticut’s are discretionary or gone. Delaware’s and New Hampshire’s ended December 31, 2025. Oregon’s ended January 1, 2026. New Jersey’s ended July 15, 2026. Maryland’s runs to April 2027. Rhode Island never had one.
  • Universal opt-out (GPC): Twelve states require honoring browser-level opt-out signals as of January 1, 2026 (CA, CO, CT, DE, MD, MN, MT, NE, NH, NJ, OR, TX), and California’s Opt Me Out Act (AB 566) will require browsers themselves to offer the signal by January 2027. See our Global Privacy Control page.
  • Scope: Only California covers employee and B2B data. Everywhere else, “consumer” means a resident acting personally.

States are shifting from defining rights to banning categories of sale outright. New Jersey banned sensitive personal data sales (June 30, 2026), Connecticut dropped its applicability threshold from 100,000 to 35,000 consumers (July 1, 2026) and banned precise-geolocation sales (October 1, 2026), Maryland barred sales to immigration-enforcement-linked government entities, and Virginia banned geolocation-data sales effective July 1, 2026. Rights give consumers a lever. Bans remove the market.

Nor is the comprehensive wave the whole state layer. It sits on top of older classes: breach-notification statutes in all fifty states (see our privacy-incident article), biometric laws like Illinois’ BIPA, data-security statutes like New York’s SHIELD Act, and data-broker registration laws in California, Vermont, Texas, and Oregon. California’s Delete Act platform (DROP) has been live since January 1, 2026. Over 575 brokers are registered.

What’s coming (2027 to 2028)

Four enacted laws await effective dates. Louisiana and Oklahoma take effect on January 1, 2027, Alabama on May 1, 2027, and Vermont on January 1, 2028, which treats neural data as sensitive. Illinois passed a comprehensive bill in May 2026 that still awaits the governor’s signature as of this writing, so it is not counted here. State health-data laws (Washington’s My Health My Data and successors) run on a parallel track.

HIPAA-preemption guide →


What rights do data privacy regulations give people?

Across almost every regime, the same six rights recur. The names differ by statute. The functions do not.

RightWhat it doesWhere it appears
Know / accessGet confirmation and a copy of your dataGDPR Art. 15, CCPA, all state laws, PIPL Art. 44, LGPD, DPDP
CorrectionFix inaccurate dataGDPR Art. 16, CPRA, most state laws, PIPL, LGPD, DPDP
Deletion / erasureHave your data deleted, with exceptionsGDPR Art. 17, CCPA, all state laws, PIPL Art. 47, LGPD, DPDP
PortabilityReceive your data in a usable format, or have it transferredGDPR Art. 20, CPRA, most state laws, LGPD
Opt out of sale / targeted ads / profilingStop the money flows and the profilingCCPA and all state laws, GDPR via the right to object (Art. 21)
Non-discriminationNo penalty for exercising your rightsCCPA and state laws, GDPR via the fairness principle

The “seven principles” question answered properly

Search “data privacy principles,” and you will find lists of seven: lawfulness, purpose limitation, data minimization, accuracy, storage limitation, security, accountability. Those are real, but they are not rights. They are the GDPR Article 5 principles, and they bind controllers, the organizations, as standing duties. The rights belong to individuals and live in Articles 12 through 22. The distinction is practical: principles tell a company how to behave at all times, while rights are levers a person can pull. Most US state laws encode fewer principles and more levers.

What do data privacy regulations require of a business?

Under every regime, the duties cluster into the same short list. Each row routes to the detailed workflow page.

DutyWhat it means at orientationPage 
Notice / disclosurePublish what you collect, why, who receives it, and keep it truePrivacy policy requirements
Consent and opt-out mechanicsWorking banners, preference signals, honoring GPC where requiredGlobal Privacy Control
AssessmentsDocumented risk/privacy impact assessments for high-risk processingPrivacy impact assessments
Minimization and retentionCollect what you need. Keep it only as long as you need itData retention policy
SecurityReasonable technical and organizational safeguardsStatute-specific.
Vendor contractsFlow-down terms for processors, service providers, third partiesThird-party privacy risk management
Breach notificationNotify regulators and affected people on statutory timelinesWhat is a privacy incident
Request handlingIntake, verification, response, and appeals for rights requestsData Subject Access Requests (DSARs)
Appointed responsibilityA DPO (GDPR Arts. 37 to 39) or named privacy officer where requiredGDPR requires one in defined cases. US law generally does not, with HIPAA, Massachusetts, and FTC Safeguards exceptions

Every duty listed in this table assumes you already know what your organization actually collects and where the data ends up. 


Which data privacy regulations apply to your company?

Applicability is answerable as a method. Four questions resolve it for almost any company: where your users are, what you collect, your scale against the thresholds, and your sector. 

Four-question privacy law applicability framework covering user location, data collected, business scale, and regulated sector.
  1. Where are your users? Not where you are based. GDPR reaches a Texas company with French visitors. CCPA reaches a German company with enough California customers. Extraterritorial reach is the default, not the exception.
  2. What do you collect? Sensitive personal information categories (health, biometrics, precise location, children’s data) trigger stricter rules and sometimes opt-in consent. Children’s data routes you to COPPA-style rules first.
  3. What is your scale? Most US state laws exempt small players below volume or revenue thresholds, which differ and move (next table).
  4. What is your sector? Health, finance, education, and credit route to the federal sectoral stack first. The comprehensive laws typically defer to it.

The threshold problem, with moving parts

RegimeApplicability triggerExample
GDPROffer goods/services to, or monitor, people in the EEA/UK, no thresholdA 10-person US SaaS with EU trial signups
California Consumer Privacy Act
CCPA/CPRA
California business over ~$26.6M revenue (CPI-adjusted), or 100K+ consumers’ data, or 50%+ revenue from selling/sharingA mid-market retailer with California customers and an ad stack
Virginia model100K consumers, or 25K plus 50% revenue from data salesA national e-commerce brand
Texas / Nebraska(Nebraska Data Privacy Act)No volume threshold, small-business carve-outs insteadAlmost any business serving Texans
Connecticut (from Jul 1, 2026)Threshold drops to 35K consumers, sensitive-data processing triggers with no volume floorA small health-adjacent app

The trend is toward more coverage: California’s revenue line adjusts for inflation every odd-numbered January, Connecticut’s threshold dropped in 2026, and Texas and Nebraska never had a volume test. The quiet part deserves saying out loud: applicability thresholds used to be pretty straightforward. Not anymore.

Two examples:

  • US mid-market e-commerce: Sells nationally, runs standard analytics and ad pixels. The state wave applies wherever thresholds are met (run question 3 per state, or adopt the strictest state’s rules as your floor). No federal sectoral statute unless you sell regulated products. GDPR only if you market into Europe. First move: the duties table, starting with notice and opt-out mechanics.
  • A company with EU traffic: Even without EU customers, “monitoring behavior” of people in the EEA can trigger GDPR Article 3. GDPR applies to that processing. State laws apply per question 3; the sectoral stack per question 4. First move: decide whether to serve the EU deliberately (then comply) or geo-fence it out.

Who enforces data privacy regulations?

Four enforcer classes cover the field: dedicated data protection authorities (EU DPAs, the ICO, the CPPA, India’s DPB), general consumer-protection regulators (the Federal Trade Commission (FTC)), state attorneys general, and private plaintiffs. Penalty shapes differ by regime. The discovery machinery is increasingly shared.

EnforcerRegimesInstrumentsOrientation penalty
EU/EEA DPAs + EDPBGDPROrders, fines, bans on processingUp to €20M or 4% of worldwide turnover
ICO (UK)UK GDPR, DPA 2018, PECR (e-privacy rules)Penalty notices, enforcement noticesUp to £17.5M or 4%, PECR £500K
FTC (US)Section 5 backstop, COPPA, GLBA, FCRAConsent orders (20-year audits), civil penaltiesCOPPA: over $50,000 per violation per day after CPI adjustment
State AGs (US)State comprehensive laws, some federal statutesCivil penalties, injunctions, cure letters$7,500 per violation (Virginia model), California $2,663 / $7,988 CPI-adjusted
CPPA (California)CCPA/CPRA + regulationsFines, enforcement actions, rulemakingSame CCPA figures. The only dedicated US privacy agency
CAC (China)PIPLFines, app takedowns, business suspension¥50M or 5% of prior-year revenue
ANPD (Brazil)LGPDWarning-to-fine ladder, publicization, blocking2% of Brazil revenue, capped R$50M per infraction
Data Protection Board (India)DPDPDigital-first complaints, penaltiesUp to ₹250 crore per category
Private plaintiffsCIPA, VPPA, BIPA, CCPA data breachesStatutory damages, class actionsCCPA breaches: $107 to $799 per consumer per incident

The private-plaintiff row is how most US companies first meet privacy law: old statutes with statutory damages, the California Invasion of Privacy Act and the Video Privacy Protection Act, have been repurposed against ordinary website tracking. Courts are split on how far that goes. A December 2025 Los Angeles ruling dismissed such claims on the ground that CIPA’s wiretap provisions were never intended for modern websites. Plaintiff-side theories keep evolving after Javier v. Assurance IQ (9th Cir. 2022) and Greenley v. Kochava (S.D. Cal. 2023). 

Read CIPA guide →

How violations actually get found

Regulators don’t wait for breaches in the news. The 2025 to 2026 record shows four working discovery channels:

  1. Sweeps: Regulators pick a mechanism and test it across an industry at once. September 9, 2025: a joint CPPA and three-AG sweep of businesses failing to honor Global Privacy Control signals. January 27, 2026: the California AG’s surveillance-pricing sweep sent information demands to retail, grocery, and hotel companies. The connected-vehicle sweep produced Honda ($632,500), then Ford ($375,703, March 5, 2026), then the GM settlement ($12.75 million, May 8, 2026), the largest CCPA penalty to date and the first built on data minimization.
  2. Cross-state coordination: The Consortium of Privacy Regulators links the CPPA with the attorneys general of California, Oregon, Colorado, Connecticut, Delaware, Indiana, New Jersey, Minnesota, and New Hampshire, sharing targets and expertise.
  3. Complaints and researcher scans: Consumer complaints feed DPA and AG offices, and independent scans surface violations at scale, handing regulators a pre-built target list. The webXray California Privacy Audit scanned 7,634 popular websites from a California IP address with the Global Privacy Control signal switched on and measured an 86% opt-out failure rate for Google-family advertising cookies.
  4. Plaintiff demand infrastructure: Law firms run automated website scans for specific pixels and signals, generating demand letters in volume. Whether or not the theory wins in court, the scan is the discovery.

Three of the four channels test what a website does, not what its policy says. A sweep is a machine checking whether your opt-out signal works. Cure periods are expiring, and the state map above has the dates. Enforcement moves straight from detection to penalty.


Where is compliance actually decided?

Every duty in the business table above is discharged or violated at the browser layer. Notice lives or dies on what your tags collect versus what your notice describes. Consent fails the moment anything fires before the visitor clicks. An opt-out means nothing if the GPC signal does not stop the flows, regardless of what your consent platform recorded. Minimization is measured by what leaves the page. Recipient disclosure comes down to naming who received the data, including the fourth parties your vendors loaded.

Duty (from the table above)Policy saysWebsite-layer failure mode
Notice / disclosure“We collect X for Y”Tags collect identifiers the notice never mentions
Consent“We ask before tracking”Pixels fire on page load, before the banner is answered
Opt-out / GPC“We honor opt-out signals”Signal received by the consent management platform (CMP). Advertising tags keep transmitting
Minimization“We collect only what we need”Session replay or form tools capture keystrokes and field contents
Recipient disclosure“We share with these categories”Vendors load their own vendors. Recipients nobody listed
Retention“We keep data for N months”Old tags from deprecated tools still firing years later

This is the shape of the enforcement record above. GM’s policy said it did not sell driving data while the data was being sold. Ford’s violation was one step too many in the mechanism. Healthline’s $1.55 million settlement (July 2025) alleged opt-outs failing across the banner, the Do Not Sell link, and the GPC signal at once. In each case, the document was fine. The wire was not.

What observation can and cannot see

Honesty about the boundary matters. Watching the browser layer shows what a site collects, which identifiers leave the first party, who receives them, and what initiated each transfer. It does not show server-to-server sharing that never touches the browser. It does not read your contracts. And it is not legal advice. Continued transmission is evidence for review, and its significance depends on the data, the recipient, the purpose, and the applicable law. Observation verifies the documentation, but neither replaces counsel nor paperwork.

How client-side observation works | Meta Pixel Examples | Session-replay Examples


How can you reduce privacy risk and actually comply?

Organizations must implement comprehensive data mapping to comply with data privacy laws. Emerging regulations also link data privacy to artificial intelligence governance. Complying with these rules comes down to a repeatable loop:

  • Determine which laws bind you (four questions above). 
  • Meet the recurring duties on paper (notices, consent mechanics, data protection assessments, retention, contracts). 
  • Verify the layer where those duties are actually discharged. 

The third step means checking what your website and apps send, to whom, and whether that still matches what you disclosed. It also decays: laws change quarterly, sites change weekly, and a policy true in January can be false by March without edits.

How does MELURNA help comply with data privacy regulations?

MELURNA monitors the layer where these duties are actually discharged. It works by watching what your websites, applications, and customer journeys actually do: which identifiers leave the first party, which vendors and AI services receive them (including the downstream recipients your vendors add), what initiated each transfer, and whether observed behavior still matches your disclosures. 

Specifically for consent, recorded consent is not enforced. MELURNA compares what your consent platform captured, including GPC signals, against what your tags actually did, and alerts you when a release or a vendor change quietly reopens a flow. It runs continuously with no agents or integrations required.

If you want to see your own properties the way a regulator’s sweep would, request an evidence briefing.


FAQ

What are the 7 principles of data privacy? 

The GDPR’s Article 5 principles: lawfulness/fairness/transparency (a single principle), purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality (security), and accountability. They are duties binding organizations, not individual rights. The rights live in GDPR Articles 12 to 22. Details in the rights section above.

Does the US use GDPR? 

No. The US has no comprehensive federal privacy law. It uses a sectoral federal stack plus state comprehensive laws. GDPR still applies to US companies that offer goods or services to, or monitor, people in the EEA or UK.

Which states have data privacy laws? 

As of September 2026, twenty states have comprehensive laws in effect, counting Florida’s narrower statute (nineteen under stricter definitions), with Louisiana, Oklahoma, Alabama, and Vermont enacted for 2027 to 2028. The dated map above is the canonical answer on this site.

Which states have privacy laws coming in 2026 and 2027?

Indiana, Kentucky, and Rhode Island took effect January 1, 2026. Four more follow. Louisiana and Oklahoma on January 1, 2027, Alabama on May 1, 2027, and Vermont on January 1, 2028.

How often do data privacy laws change? 

Continuously: new state laws each session, effective-date waves, CPI-adjusted thresholds (California adjusts every odd January), and phased rollouts like India’s 2025 to 2027. A quarterly review habit is the practical answer.

What happens if you violate data privacy regulations? 

Regulators can fine per violation (CCPA: $2,663, or $7,988 if intentional), as a share of turnover (GDPR: up to 4% worldwide), or per category (India: up to ₹250 crore), and can impose injunctions, audits, and deletion orders. Private plaintiffs add statutory-damages class actions under statutes like CIPA and the Video Privacy Protection Act(VPPA).

Do data privacy laws apply outside their jurisdiction? 

Usually yes. GDPR, PIPL, LGPD, and India’s DPDP all reach organizations abroad that target or monitor their residents, and US state laws bind out-of-state companies that meet their thresholds. The applicability section’s four questions resolve this for your company.


DISCLAIMER: This guide is for general informational purposes only and does not constitute legal advice. While we strive for accuracy, we make no warranties about the completeness or reliability of this information, and are not liable for any errors, omissions, or actions taken based on its contents. Consult a licensed attorney for guidance specific to your business.


Reference

Cite this page

Dany Mirza. “Data Privacy Regulations: Global, Federal & State Laws (2026).” Melurna, September 29, 2026. https://www.melurna.com/blog/data-privacy-regulations/