Data privacy regulations govern how organizations collect, use, store, and share personal data and what rights people have over it. There is no single global rulebook. 172 countries now have data privacy laws; the United States has no comprehensive federal law, and most states have filled part of that gap with their own.
Key takeaways
- Data privacy law comes in two shapes: comprehensive and sectoral. The world mostly chose the first. The US federal government has not, and twenty states have filled part of the gap.
- Applicability is a four-question method, not a list: users, data, scale, sector.
- The same six rights and the same short list of business duties recur under almost every regime.
- Enforcement increasingly starts with what your website does: sweeps test mechanisms, and cure periods are expiring.
- Every regime’s duties are discharged or violated at the browser layer, where observation is the proof.
This page shows which laws exist, how to tell which ones bind your company, who enforces them, and how they find violations.
What are data privacy regulations?
Data privacy regulations are rules that control how organizations collect, use, store, share, and delete personal data. These laws give rights to individuals and set responsibilities for the organizations handling their data.
The terms vary by jurisdiction more than by meaning. “Data privacy” is the American term. The European term is “data protection.” “Data security” is the narrower discipline of keeping data safe from unauthorized access, which most privacy laws require but none are limited to. A “law” or “act” comes from a legislature. A “regulation” is issued by an agency under a law’s authority. An EU “directive” tells member states what to achieve and lets each write its own statute.
Here are two notes about the scope of these laws.
- Personal data is information that can be linked to a specific person. Most laws also set aside certain types of sensitive data, like health, biometrics, precise location, or children’s data, and apply stricter rules to them.
- Different laws use different terms. US laws say “personal information” or “personally identifiable information (PII).” The GDPR uses “personal data,” and India uses “digital personal data.” The exact definitions can vary, so figuring out which law applies is a separate question.
In all cases, individuals have rights. Organizations bear the duties. The labels vary by statute: controllers, businesses, or data fiduciaries. There are rules at every level, including international frameworks, national laws, US state laws, and industry-specific rules.
What are the two shapes of data privacy law: comprehensive and sectoral?
Every regime comes in one of two shapes. Comprehensive data privacy laws cover nearly all personal data across nearly all sectors. Sectoral laws cover one kind of data or one industry at a time. The world mostly uses the first shape. The US federal government uses the second.
| Type | How it works | Example | Who it binds | Consent model |
| Comprehensive (national or regional) | One statute governs personal data across the economy | GDPR (EU/EEA), PIPL (China), LGPD (Brazil) | Nearly every organization handling residents’ data | Lawful bases, consent is one of several |
| Sectoral (federal, US-style) | Separate statutes per domain: health, credit, children, education, video | HIPAA, GLBA, COPPA, FCRA | Only organizations in that domain | Varies by statute |
| State comprehensive (US) | State omnibus laws filling the federal gap | CCPA/CPRA, Virginia VCDPA and successors | Businesses meeting thresholds, state by state | Opt-out first (opt-in for sensitive data) |
| Voluntary frameworks | Standards an organization chooses to adopt, not law | NIST Privacy Framework, ISO/IEC 27701 | Nobody, unless contracted or claimed publicly | Not applicable |
The last row matters more than it looks. A framework binds no one by itself, but the Federal Trade Commission (FTC) has treated public claims about following a standard as enforceable promises, and contracts turn frameworks into obligations between companies. Binding law and chosen commitment are different rows on the map, and both end up on your website.

Why the US stayed sectoral
Congress has repeatedly come close to a comprehensive federal privacy law but stopped. The American Data Privacy and Protection Act passed the House Energy and Commerce Committee 53–2 in 2022 but never reached a floor vote (H.R. 8152, 117th Congress). Its successor, the American Privacy Rights Act, had its markup canceled in June 2024 and expired with the 118th Congress (H.R. 8818, 118th Congress). It has not been reintroduced.
The sticking points remain: whether federal law preempts stronger state laws and whether individuals can sue. The current attempt is the SECURE Data Act (H.R. 8413, introduced April 21, 2026). It leans hard on preemption, and the California Privacy Protection Agency (CPPA) has formally opposed it as a “low national ceiling.” There is still no federal omnibus, and the fight is now explicitly about whether federal law should cap the states.
What are the major data privacy regulations worldwide?
A few major laws set the global standard. The table below compares the ones a US-based company is most likely to meet, on the axes that matter at orientation: coverage, consent model, headline rights, and potential penalties.
| Regime | Jurisdiction | In force | Consent model | Headline rights | Maximum penalty | Enforcer |
| General Data Protection Regulation (GDPR) | EU/EEA (+ extraterritorial) | May 25, 2018 | Six lawful bases, consent for processing personal data must be freely given, specific, and informed | Access, erasure, portability, object, restrict, refuse solely automated decisions | €20M or 4% of worldwide annual turnover | National DPAs, coordinated by the European Data Protection Board (EDPB) |
| UK GDPR + DPA 2018 | United Kingdom | January 1, 2021 | Mirrors General Data Protection Regulation (GDPR) | Mirrors GDPR | £17.5M or 4% of worldwide turnover | ICO |
| PIPL | China (+ extraterritorial) | November 1, 2021 | Consent-centric, separate consent for sensitive data, sharing, cross-border transfer | Know, decide, access, correct, delete, explain | ¥50M or 5% of prior-year revenue, business suspension | CAC and provincial regulators |
| LGPD | Brazil | September 2020 (sanctions from August 2021) | Ten legal bases, consent or legitimate interest | Access, correction, deletion, portability, revoke consent | 2% of Brazil revenue, capped at R$50M per infraction | ANPD |
| PIPEDA | Canada (private sector) | In force since 2001 | Consent-centric (knowledge and consent) | Access, correction, challenge compliance | No administrative fines, offenses to C$100,000 on indictment. Reform Bill C-36 would add fines to $10M or 3% | Privacy Commissioner (OPC), Federal Court |
| DPDP Act + Rules 2025 | India (digital personal data) | Act 2023, Rules notified November 2025, core duties from May 2027 | Consent-first, with “legitimate uses” carve-outs | Access, correction, erasure, nominate, grievance | ₹250 crore (about $30M) for security-safeguard failures | Data Protection Board of India |
| US state model (contrast row) | Individual US states | 2020 onward, rolling | Opt-out first, opt-in for sensitive data and minors | Know/access, correct, delete, opt out of sale, targeted ads, profiling | Per violation: $7,500 (Virginia model), CCPA CPI-adjusted to $2,663 / $7,988 | State AGs. California also has the CPPA |
Read the penalty column as orientation. The ceiling is what a regime can do. The enforcement section covers what regulators actually do. The property that matters most to a US reader is not a row but a shared column header: extraterritorial reach. GDPR, PIPL, LGPD, and DPDP all bind organizations outside their borders that offer goods or services to, or monitor, people inside them. A US company with European traffic is making GDPR decisions whether it knows it or not.
Read GDPR explainer →
How many countries have data protection laws?
As of 2026, 144 to 172 countries have enacted national data privacy laws. Graham Greenleaf’s ninth biennial global assessment (April 2025) counts 172 countries. UNCTAD’s tracker counts 79% of 195 economies with legislation in force, on a stricter definition.
What are the US federal data privacy laws?
The United States has no comprehensive federal privacy law. What it has, instead, is a stack of sectoral statutes. Each covers one domain. The FTC’s general authority against unfair or deceptive practices is the connective tissue.
| Statute | Domain | Who it binds | Core duty at orientation | Enforcer |
| Health Insurance Portability and Accountability Act (HIPAA) (1996) | Health information | Health plans, providers, clearinghouses, business associates | Protect identifiable health information, breach notification | HHS Office for Civil Rights. State AGs can also sue |
| Gramm-Leach-Bliley Act (GLBA) (1999) | Financial data | Financial institutions (broadly defined, incl. many fintechs and auto dealers) | Safeguards program, privacy notices, no pretexting | FTC, banking regulators, CFPB |
| Children’s Online Privacy Protection Act (COPPA) (1998) | Children under 13 online | Sites and services directed at children, or with actual knowledge | Verifiable parental consent before collecting children’s data | FTC and state AGs oversee compliance (see our COPPA explainer) |
| Fair Credit Reporting Act (FCRA) (1970) | Credit and consumer reports | Credit bureaus, data furnishers, users of reports | Accuracy, permissible purpose, dispute rights | FTC, CFPB, state AGs, private lawsuits |
| Family Educational Rights and Privacy Act (FERPA) (1974) | Education records | Schools receiving federal funds | Parental/student consent for record disclosure | Dept. of Education (via funding) |
| Video Privacy Protection Act (VPPA) (1988) | Video viewing history | “Video tape service providers” (courts apply it to streaming and websites) | Consent before disclosing viewing data | Private lawsuits (statutory damages) |
| Electronic Communications Privacy Act (ECPA) / Telephone Consumer Protection Act (TCPA) / CAN-SPAM Act | Communications and marketing | Interceptors, callers and texters, commercial emailers | Consent for interception, calls, texts, honest email headers | DOJ, FCC, FTC, state AGs, private lawsuits |
| Privacy Act (1974) | Federal agencies’ records | US government agencies | Fair information practices for citizen/resident records | DOJ (via litigation) |
| DOJ Data Security Program (2025) | Bulk sensitive data + countries of concern | US persons dealing in covered data with six named countries | Prohibited/restricted transactions, due diligence and audits (effective April 8, 2025, full obligations October 5, 2025) | Department of Justice |
The FTC backstop
Where no sectoral statute applies, the FTC Act’s Section 5 prohibition on unfair or deceptive practices does. That is how the US gets de facto privacy enforcement without a privacy law. A privacy policy is a public claim, and a gap between claim and practice is a deception case. The doctrine has teeth in both directions.
The FTC has said that quietly changing your terms of service to use already-collected data for a new purpose can itself be unfair or deceptive (February 2024), citing enforcement history back to Gateway Learning in 2004. Retroactive policy edits do not launder past collection.
Which US states have comprehensive privacy laws? (the 2026 map)
As of September 2026, twenty states have comprehensive consumer privacy laws in effect (counting Florida’s narrower law, or nineteen under stricter definitions like IAPP’s). Four more have passed legislation that will officially take effect between 2027 and 2028. California led the charge in being the first state to enact comprehensive data privacy legislation via the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA).
| State | Law | In effect | Family |
| California | California Consumer Privacy Act (CCPA) enacted in June 2018, as amended by the California Privacy Rights Act (CPRA) | Jan 1, 2020 / Jan 1, 2023 | California model: dedicated agency (CPPA), employee and B2B data covered |
| Virginia | Virginia Consumer Data Protection Act (VCDPA) | Jan 1, 2023 | Virginia model |
| Colorado | Colorado Privacy Act (CPA) | Jul 1, 2023 | Virginia model (stronger rulemaking) |
| Connecticut | Connecticut Data Privacy Act (CTDPA) | Jul 1, 2023 | Virginia model |
| Utah | Utah Consumer Privacy Act (UCPA) | Dec 31, 2023 | Virginia model (narrowest) |
| Florida | Florida Digital Bill of Rights (FDBR) | Jun 29, 2023 | Narrow: binds mainly $1B+ tech platforms |
| Montana | Montana Consumer Data Privacy Act (MTCDPA) | Oct 1, 2024 | Virginia model |
| Texas | Texas Data Privacy and Security Act (TDPSA) | Jul 1, 2024 | Virginia model, small-business carve-out instead of volume thresholds |
| Oregon | Oregon Consumer Privacy Act (OCPA) | Jul 1, 2024 | Virginia model |
| Delaware | Delaware Personal Data Privacy Act (DPDPA) | Jan 1, 2025 | Virginia model (low thresholds) |
| Iowa | Iowa Consumer Data Protection Act (ICDPA) | Jan 1, 2025 | Virginia model (weakest rights set) |
| Nebraska | Nebraska Data Privacy Act (NDPA) | Jan 1, 2025 | Virginia model, applies regardless of volume |
| New Hampshire | New Hampshire Privacy Act (NHPA) | Mar 1, 2025 | Virginia model (low thresholds) |
| New Jersey | New Jersey Data Privacy Act (NJDPA) | Jan 15, 2025 | Virginia model |
| Tennessee | Tennessee Information Protection Act (TIPA) | Jul 1, 2025 | Virginia model |
| Minnesota | Minnesota Consumer Data Privacy Act (MCDPA) | Jul 31, 2025 | Virginia model (plus profiling rights) |
| Maryland | Maryland Online Data Privacy Act (MODPA) | Oct 1, 2025 | Strictest: data minimization as a hard duty |
| Kentucky | Kentucky Consumer Data Protection Act (KCDPA) | Jan 1, 2026 | Virginia model |
| Indiana | Indiana Consumer Data Protection Act (INCDPA) | Jan 1, 2026 | Virginia model |
| Rhode Island | Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) | Jan 1, 2026 | Virginia model, no cure period |
Snapshot dated September 2026. Methodology: “comprehensive” means an omnibus consumer privacy statute. Florida is included in the broader count and excluded under IAPP’s stricter definition. Verify against current statute text before relying on any row.
Read the map as families, not fifty entries. The differences that matter at orientation:
- Sensitive data: California-style laws allow collection with an opt-out or a right to limit. Most Virginia-model laws require opt-in consent first.
- Cure periods are expiring: Early laws let businesses fix violations before penalties. Colorado’s and Connecticut’s are discretionary or gone. Delaware’s and New Hampshire’s ended December 31, 2025. Oregon’s ended January 1, 2026. New Jersey’s ended July 15, 2026. Maryland’s runs to April 2027. Rhode Island never had one.
- Universal opt-out (GPC): Twelve states require honoring browser-level opt-out signals as of January 1, 2026 (CA, CO, CT, DE, MD, MN, MT, NE, NH, NJ, OR, TX), and California’s Opt Me Out Act (AB 566) will require browsers themselves to offer the signal by January 2027. See our Global Privacy Control page.
- Scope: Only California covers employee and B2B data. Everywhere else, “consumer” means a resident acting personally.
States are shifting from defining rights to banning categories of sale outright. New Jersey banned sensitive personal data sales (June 30, 2026), Connecticut dropped its applicability threshold from 100,000 to 35,000 consumers (July 1, 2026) and banned precise-geolocation sales (October 1, 2026), Maryland barred sales to immigration-enforcement-linked government entities, and Virginia banned geolocation-data sales effective July 1, 2026. Rights give consumers a lever. Bans remove the market.
Nor is the comprehensive wave the whole state layer. It sits on top of older classes: breach-notification statutes in all fifty states (see our privacy-incident article), biometric laws like Illinois’ BIPA, data-security statutes like New York’s SHIELD Act, and data-broker registration laws in California, Vermont, Texas, and Oregon. California’s Delete Act platform (DROP) has been live since January 1, 2026. Over 575 brokers are registered.
What’s coming (2027 to 2028)
Four enacted laws await effective dates. Louisiana and Oklahoma take effect on January 1, 2027, Alabama on May 1, 2027, and Vermont on January 1, 2028, which treats neural data as sensitive. Illinois passed a comprehensive bill in May 2026 that still awaits the governor’s signature as of this writing, so it is not counted here. State health-data laws (Washington’s My Health My Data and successors) run on a parallel track.
HIPAA-preemption guide →
What rights do data privacy regulations give people?
Across almost every regime, the same six rights recur. The names differ by statute. The functions do not.
| Right | What it does | Where it appears |
| Know / access | Get confirmation and a copy of your data | GDPR Art. 15, CCPA, all state laws, PIPL Art. 44, LGPD, DPDP |
| Correction | Fix inaccurate data | GDPR Art. 16, CPRA, most state laws, PIPL, LGPD, DPDP |
| Deletion / erasure | Have your data deleted, with exceptions | GDPR Art. 17, CCPA, all state laws, PIPL Art. 47, LGPD, DPDP |
| Portability | Receive your data in a usable format, or have it transferred | GDPR Art. 20, CPRA, most state laws, LGPD |
| Opt out of sale / targeted ads / profiling | Stop the money flows and the profiling | CCPA and all state laws, GDPR via the right to object (Art. 21) |
| Non-discrimination | No penalty for exercising your rights | CCPA and state laws, GDPR via the fairness principle |
The “seven principles” question answered properly
Search “data privacy principles,” and you will find lists of seven: lawfulness, purpose limitation, data minimization, accuracy, storage limitation, security, accountability. Those are real, but they are not rights. They are the GDPR Article 5 principles, and they bind controllers, the organizations, as standing duties. The rights belong to individuals and live in Articles 12 through 22. The distinction is practical: principles tell a company how to behave at all times, while rights are levers a person can pull. Most US state laws encode fewer principles and more levers.
Appeals differ by state: Colorado’s law, for example, lets you appeal a refused request. California’s and Utah’s do not (verify against current statute text for any state you care about). And children’s data is a special case almost everywhere, explained in our Children’s Online Privacy Protection Act guide.
What do data privacy regulations require of a business?
Under every regime, the duties cluster into the same short list. Each row routes to the detailed workflow page.
| Duty | What it means at orientation | Page |
| Notice / disclosure | Publish what you collect, why, who receives it, and keep it true | Privacy policy requirements |
| Consent and opt-out mechanics | Working banners, preference signals, honoring GPC where required | Global Privacy Control |
| Assessments | Documented risk/privacy impact assessments for high-risk processing | Privacy impact assessments |
| Minimization and retention | Collect what you need. Keep it only as long as you need it | Data retention policy |
| Security | Reasonable technical and organizational safeguards | Statute-specific. |
| Vendor contracts | Flow-down terms for processors, service providers, third parties | Third-party privacy risk management |
| Breach notification | Notify regulators and affected people on statutory timelines | What is a privacy incident |
| Request handling | Intake, verification, response, and appeals for rights requests | Data Subject Access Requests (DSARs) |
| Appointed responsibility | A DPO (GDPR Arts. 37 to 39) or named privacy officer where required | GDPR requires one in defined cases. US law generally does not, with HIPAA, Massachusetts, and FTC Safeguards exceptions |
Every duty listed in this table assumes you already know what your organization actually collects and where the data ends up.
Which data privacy regulations apply to your company?
Applicability is answerable as a method. Four questions resolve it for almost any company: where your users are, what you collect, your scale against the thresholds, and your sector.

- Where are your users? Not where you are based. GDPR reaches a Texas company with French visitors. CCPA reaches a German company with enough California customers. Extraterritorial reach is the default, not the exception.
- What do you collect? Sensitive personal information categories (health, biometrics, precise location, children’s data) trigger stricter rules and sometimes opt-in consent. Children’s data routes you to COPPA-style rules first.
- What is your scale? Most US state laws exempt small players below volume or revenue thresholds, which differ and move (next table).
- What is your sector? Health, finance, education, and credit route to the federal sectoral stack first. The comprehensive laws typically defer to it.
The threshold problem, with moving parts
| Regime | Applicability trigger | Example |
| GDPR | Offer goods/services to, or monitor, people in the EEA/UK, no threshold | A 10-person US SaaS with EU trial signups |
| California Consumer Privacy Act CCPA/CPRA | California business over ~$26.6M revenue (CPI-adjusted), or 100K+ consumers’ data, or 50%+ revenue from selling/sharing | A mid-market retailer with California customers and an ad stack |
| Virginia model | 100K consumers, or 25K plus 50% revenue from data sales | A national e-commerce brand |
| Texas / Nebraska(Nebraska Data Privacy Act) | No volume threshold, small-business carve-outs instead | Almost any business serving Texans |
| Connecticut (from Jul 1, 2026) | Threshold drops to 35K consumers, sensitive-data processing triggers with no volume floor | A small health-adjacent app |
The trend is toward more coverage: California’s revenue line adjusts for inflation every odd-numbered January, Connecticut’s threshold dropped in 2026, and Texas and Nebraska never had a volume test. The quiet part deserves saying out loud: applicability thresholds used to be pretty straightforward. Not anymore.
Two examples:
- US mid-market e-commerce: Sells nationally, runs standard analytics and ad pixels. The state wave applies wherever thresholds are met (run question 3 per state, or adopt the strictest state’s rules as your floor). No federal sectoral statute unless you sell regulated products. GDPR only if you market into Europe. First move: the duties table, starting with notice and opt-out mechanics.
- A company with EU traffic: Even without EU customers, “monitoring behavior” of people in the EEA can trigger GDPR Article 3. GDPR applies to that processing. State laws apply per question 3; the sectoral stack per question 4. First move: decide whether to serve the EU deliberately (then comply) or geo-fence it out.
Sectoral override: in health, finance, education, credit, or children’s products, run the sectoral stack first. HIPAA, GLBA, FERPA, FCRA, and COPPA are not displaced by the state laws. They preempt or sit alongside them. And verify every applicability conclusion against current statute text: this screen tells you where to look, not what the law says.
Who enforces data privacy regulations?
Four enforcer classes cover the field: dedicated data protection authorities (EU DPAs, the ICO, the CPPA, India’s DPB), general consumer-protection regulators (the Federal Trade Commission (FTC)), state attorneys general, and private plaintiffs. Penalty shapes differ by regime. The discovery machinery is increasingly shared.
| Enforcer | Regimes | Instruments | Orientation penalty |
| EU/EEA DPAs + EDPB | GDPR | Orders, fines, bans on processing | Up to €20M or 4% of worldwide turnover |
| ICO (UK) | UK GDPR, DPA 2018, PECR (e-privacy rules) | Penalty notices, enforcement notices | Up to £17.5M or 4%, PECR £500K |
| FTC (US) | Section 5 backstop, COPPA, GLBA, FCRA | Consent orders (20-year audits), civil penalties | COPPA: over $50,000 per violation per day after CPI adjustment |
| State AGs (US) | State comprehensive laws, some federal statutes | Civil penalties, injunctions, cure letters | $7,500 per violation (Virginia model), California $2,663 / $7,988 CPI-adjusted |
| CPPA (California) | CCPA/CPRA + regulations | Fines, enforcement actions, rulemaking | Same CCPA figures. The only dedicated US privacy agency |
| CAC (China) | PIPL | Fines, app takedowns, business suspension | ¥50M or 5% of prior-year revenue |
| ANPD (Brazil) | LGPD | Warning-to-fine ladder, publicization, blocking | 2% of Brazil revenue, capped R$50M per infraction |
| Data Protection Board (India) | DPDP | Digital-first complaints, penalties | Up to ₹250 crore per category |
| Private plaintiffs | CIPA, VPPA, BIPA, CCPA data breaches | Statutory damages, class actions | CCPA breaches: $107 to $799 per consumer per incident |
The private-plaintiff row is how most US companies first meet privacy law: old statutes with statutory damages, the California Invasion of Privacy Act and the Video Privacy Protection Act, have been repurposed against ordinary website tracking. Courts are split on how far that goes. A December 2025 Los Angeles ruling dismissed such claims on the ground that CIPA’s wiretap provisions were never intended for modern websites. Plaintiff-side theories keep evolving after Javier v. Assurance IQ (9th Cir. 2022) and Greenley v. Kochava (S.D. Cal. 2023).
How violations actually get found
Regulators don’t wait for breaches in the news. The 2025 to 2026 record shows four working discovery channels:
- Sweeps: Regulators pick a mechanism and test it across an industry at once. September 9, 2025: a joint CPPA and three-AG sweep of businesses failing to honor Global Privacy Control signals. January 27, 2026: the California AG’s surveillance-pricing sweep sent information demands to retail, grocery, and hotel companies. The connected-vehicle sweep produced Honda ($632,500), then Ford ($375,703, March 5, 2026), then the GM settlement ($12.75 million, May 8, 2026), the largest CCPA penalty to date and the first built on data minimization.
- Cross-state coordination: The Consortium of Privacy Regulators links the CPPA with the attorneys general of California, Oregon, Colorado, Connecticut, Delaware, Indiana, New Jersey, Minnesota, and New Hampshire, sharing targets and expertise.
- Complaints and researcher scans: Consumer complaints feed DPA and AG offices, and independent scans surface violations at scale, handing regulators a pre-built target list. The webXray California Privacy Audit scanned 7,634 popular websites from a California IP address with the Global Privacy Control signal switched on and measured an 86% opt-out failure rate for Google-family advertising cookies.
- Plaintiff demand infrastructure: Law firms run automated website scans for specific pixels and signals, generating demand letters in volume. Whether or not the theory wins in court, the scan is the discovery.
Three of the four channels test what a website does, not what its policy says. A sweep is a machine checking whether your opt-out signal works. Cure periods are expiring, and the state map above has the dates. Enforcement moves straight from detection to penalty.
Where is compliance actually decided?
Every duty in the business table above is discharged or violated at the browser layer. Notice lives or dies on what your tags collect versus what your notice describes. Consent fails the moment anything fires before the visitor clicks. An opt-out means nothing if the GPC signal does not stop the flows, regardless of what your consent platform recorded. Minimization is measured by what leaves the page. Recipient disclosure comes down to naming who received the data, including the fourth parties your vendors loaded.
| Duty (from the table above) | Policy says | Website-layer failure mode |
| Notice / disclosure | “We collect X for Y” | Tags collect identifiers the notice never mentions |
| Consent | “We ask before tracking” | Pixels fire on page load, before the banner is answered |
| Opt-out / GPC | “We honor opt-out signals” | Signal received by the consent management platform (CMP). Advertising tags keep transmitting |
| Minimization | “We collect only what we need” | Session replay or form tools capture keystrokes and field contents |
| Recipient disclosure | “We share with these categories” | Vendors load their own vendors. Recipients nobody listed |
| Retention | “We keep data for N months” | Old tags from deprecated tools still firing years later |
This is the shape of the enforcement record above. GM’s policy said it did not sell driving data while the data was being sold. Ford’s violation was one step too many in the mechanism. Healthline’s $1.55 million settlement (July 2025) alleged opt-outs failing across the banner, the Do Not Sell link, and the GPC signal at once. In each case, the document was fine. The wire was not.
What observation can and cannot see
Honesty about the boundary matters. Watching the browser layer shows what a site collects, which identifiers leave the first party, who receives them, and what initiated each transfer. It does not show server-to-server sharing that never touches the browser. It does not read your contracts. And it is not legal advice. Continued transmission is evidence for review, and its significance depends on the data, the recipient, the purpose, and the applicable law. Observation verifies the documentation, but neither replaces counsel nor paperwork.
How client-side observation works | Meta Pixel Examples | Session-replay Examples
How can you reduce privacy risk and actually comply?
Organizations must implement comprehensive data mapping to comply with data privacy laws. Emerging regulations also link data privacy to artificial intelligence governance. Complying with these rules comes down to a repeatable loop:
- Determine which laws bind you (four questions above).
- Meet the recurring duties on paper (notices, consent mechanics, data protection assessments, retention, contracts).
- Verify the layer where those duties are actually discharged.
The third step means checking what your website and apps send, to whom, and whether that still matches what you disclosed. It also decays: laws change quarterly, sites change weekly, and a policy true in January can be false by March without edits.
How does MELURNA help comply with data privacy regulations?
MELURNA monitors the layer where these duties are actually discharged. It works by watching what your websites, applications, and customer journeys actually do: which identifiers leave the first party, which vendors and AI services receive them (including the downstream recipients your vendors add), what initiated each transfer, and whether observed behavior still matches your disclosures.
Specifically for consent, recorded consent is not enforced. MELURNA compares what your consent platform captured, including GPC signals, against what your tags actually did, and alerts you when a release or a vendor change quietly reopens a flow. It runs continuously with no agents or integrations required.
If you want to see your own properties the way a regulator’s sweep would, request an evidence briefing.
FAQ
What are the 7 principles of data privacy?
The GDPR’s Article 5 principles: lawfulness/fairness/transparency (a single principle), purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality (security), and accountability. They are duties binding organizations, not individual rights. The rights live in GDPR Articles 12 to 22. Details in the rights section above.
Does the US use GDPR?
No. The US has no comprehensive federal privacy law. It uses a sectoral federal stack plus state comprehensive laws. GDPR still applies to US companies that offer goods or services to, or monitor, people in the EEA or UK.
Which states have data privacy laws?
As of September 2026, twenty states have comprehensive laws in effect, counting Florida’s narrower statute (nineteen under stricter definitions), with Louisiana, Oklahoma, Alabama, and Vermont enacted for 2027 to 2028. The dated map above is the canonical answer on this site.
Which states have privacy laws coming in 2026 and 2027?
How often do data privacy laws change?
Continuously: new state laws each session, effective-date waves, CPI-adjusted thresholds (California adjusts every odd January), and phased rollouts like India’s 2025 to 2027. A quarterly review habit is the practical answer.
What happens if you violate data privacy regulations?
Regulators can fine per violation (CCPA: $2,663, or $7,988 if intentional), as a share of turnover (GDPR: up to 4% worldwide), or per category (India: up to ₹250 crore), and can impose injunctions, audits, and deletion orders. Private plaintiffs add statutory-damages class actions under statutes like CIPA and the Video Privacy Protection Act(VPPA).
Do data privacy laws apply outside their jurisdiction?
DISCLAIMER: This guide is for general informational purposes only and does not constitute legal advice. While we strive for accuracy, we make no warranties about the completeness or reliability of this information, and are not liable for any errors, omissions, or actions taken based on its contents. Consult a licensed attorney for guidance specific to your business.
