Legal Disclaimer: Validity Screening Solutions provides this material for educational and informational purposes only, and shall not be construed as legal advice, express or implied. For questions regarding your organization’s practices and compliance with applicable laws, please consult with your legal counsel.
As artificial intelligence (AI) and other technologies continue to advance, safeguarding consumer privacy remains a key priority for state legislatures. More than 20 states have enacted comprehensive consumer privacy laws. Below is a summary of the consumer privacy legislation that took effect in 2026.
California (SB 361, AB 45, & expanded privacy regulations)
California has implemented several legislative developments concerning consumer privacy. Beginning with the Defending Californians’ Data Act (SB 361), which builds upon the state’s previous Delete Act, the new legislation enhances transparency and reporting obligations for data brokers. Effective January 1, 2026, data brokers will be required to disclose whether they collect sensitive personal information, and they must also report if they have sold or shared consumer data in the past year with generative AI developers, foreign entities, or federal, state, or local government agencies.
Another California law that became effective on January 1 is Assembly Bill 45. This legislation establishes a consumer health data privacy framework that restricts the collection, use, sharing, or retention of personal data from individuals at or near family planning centers. Additionally, it prohibits the use of geofencing around in-person healthcare facilities to track individuals, collect data, or deliver targeted advertising.
Additionally, the California Privacy Protection Agency’s updated California Consumer Privacy Act (CCPA) regulations became effective on January 1. The regulations require mandatory risk assessments for processing activities that pose a significant risk to consumer privacy. The initial assessments are due by April 1, 2028. The regulations also establish notice and opt-out rights for consumers when automated decision-making technology is used to make significant decisions (e.g., in employment decisions). However, these provisions will not take effect until January 1, 2027.
Indiana (SB 5)
The Indiana Consumer Data Protection Act applies to entities conducting business in Indiana that process or control the personal data of at least 100,000 Indiana residents; or process or control the personal data of at least 25,000 Indiana residents and generate over 50% of their gross revenue from selling personal data. Under this law, Indiana residents are granted standard rights outlined in most consumer privacy laws, including the rights to confirm and access their personal data, correct, delete, data portability, and opt out of targeted advertising or data sales.
Kentucky (HB 15)
Similar to Indiana’s law, the Kentucky Consumer Data Protection Act applies to entities conducting business in Kentucky that process or control personal data of at least 100,000 Kentucky consumers; or process or control personal data of at least 25,000 Kentucky consumers and generate over 50% of their gross revenue from selling personal data. The rights granted to Kentucky residents under this act include the right to prevent businesses from processing sensitive data without explicit opt-in consent, in addition to the standard rights provided under most consumer privacy laws.
Nebraska (LB 504)
The Age-Appropriate Online Design Code Act has been enacted to enhance the protection of minors online by implementing rigorous safety and privacy standards for digital service providers. The law applies only when a covered online service has actual knowledge that data came from a minor, or when the service cannot reasonably determine that fewer than two (2) percent of its users are minors.
Rhode Island (HB 7787/SB 2500)
The Rhode Island Data Transparency and Privacy Protection Act applies to for-profit businesses that process or control the personal data of at least 35,000 customers; or process personal data of a minimum of 10,000 customers and derive more than 20% of their gross revenue from selling personal data. The Act grants Rhode Island residents the standard rights outlined in most consumer privacy laws.
Texas (HB 149)
The Texas Responsible Artificial Intelligence Governance Act applies to organizations doing business in, producing products or services utilized by individuals in Texas, or involved in developing or deploying AI systems within the state. It specifies permissible and prohibited uses of AI systems, and establishes the Texas Artificial Intelligence Council to oversee enforcement and compliance.
In addition to the laws that have recently gone into effect, several states enacted comprehensive consumer privacy legislation scheduled to take effect in 2027 or later.
Alabama (HB 351)
The Alabama Personal Data Protection Act will become effective on May 1, 2027. The legislation applies to entities doing business in Alabama that oversee or process the personal data of more than 25,000 consumers (excluding data processed solely for payment transactions), or those that generate more than 25% of their gross revenue from the sale of personal data. In addition to the standard consumer privacy rights typically provided under privacy laws, the Act requires businesses to respond to consumer requests within 45 days, with the possibility of a 45-day extension.
Louisiana (SB 386)
The Louisiana Data Privacy Act will become effective on January 1, 2027. The Act applies to commercial entities that meet any of the following criteria: have annual gross revenues exceeding $25 million; control or process the personal data of 75,000 or more Louisiana consumers, households, or devices; or derive 50% or more of their annual revenue from the sale of personal data. In addition to the standard rights generally provided under consumer privacy laws, this Act requires explicit consumer consent before processing sensitive personal data (e.g., health, biometric, genetic, or minors’ data).
Oklahoma (SB 546)
The Oklahoma Consumer Data Privacy Act will come into effect on January 1, 2027. The act applies to “controllers or processors” conducting business in Oklahoma and, within a calendar year, either control or process the personal data of 100,000 or more Oklahoma residents; or control or process the personal data of at least 25,000 consumers and generate over 50% of gross revenue from the sale of personal data. The rights granted to Oklahoma residents are consistent with the standard rights provided by most consumer privacy laws.
Vermont (Act No.145/S.71)
The Vermont Data Privacy and Online Surveillance Act will become effective on January 1, 2028. The law applies to entities conducting business in Vermont that meet any of the following criteria within the preceding calendar year: processing personal data of 35,000 or more consumers; processing sensitive data of 3,000 or more consumers; or selling personal data of 3,000 or more consumers. Additionally, consumer health data provisions under this law remain applicable to businesses regardless of any minimum threshold. Beyond the standard rights typically provided under consumer privacy laws, this act grants individuals the right to request a list of specific third parties to whom their personal data has been sold.
Next Steps For Employers
- Continue to monitor state legislative developments, as additional states are anticipated to enact their own versions of consumer privacy legislation.
- Review the applicable laws with qualified legal counsel to determine if any apply to your organization or if your organization is exempt.
- Update privacy policies and other applicable disclosures and notices.

