Privacy regulations changing in your state: What the 2026 laws actually mean

Fourteen states enacted comprehensive privacy laws between 2023 and 2025. Nine of those laws take effect in 2026. If you live in Delaware, Iowa, Kentucky, Maryland, Minnesota, Nebraska, New Hampshire, New Jersey, or Tennessee, your data rights changed this year.
The laws share a common structure borrowed from California's 2018 CCPA and Europe's GDPR, but the details differ enough that understanding what you can actually do requires looking at your specific state. Here's the underlying mechanism behind these laws, what rights they grant, and the practical process to use them.
The core mechanism: opt-in versus opt-out
Privacy laws fall into two categories based on how they handle consent. Opt-in laws require companies to ask permission before collecting or using your data. Opt-out laws let companies collect data by default but require them to stop when you ask.
Every U.S. state privacy law enacted so far is opt-out. Companies can track you, build profiles, and sell your data unless you explicitly tell them to stop. The laws don't prevent collection. They give you a mechanism to limit what happens after collection.
This matters because exercising your rights requires action on your part. The default state is maximum data collection. Privacy protection happens only when you submit requests, one company at a time.
The European model works differently. GDPR requires opt-in consent for most data processing, shifting the default to privacy-protective. American state laws preserve the opposite default and give you tools to push back.
What rights the 2026 laws grant
State privacy laws cluster around five core rights, though not every state includes all five:
Right to know. You can request a copy of the personal data a company holds about you. The company must tell you what categories of data they collect, where they got it, why they collect it, and who they share it with.
Right to delete. You can request deletion of your personal data. Companies must delete information they collected directly from you and instruct their service providers to delete it too. Exceptions exist for data needed to complete transactions, detect fraud, comply with legal obligations, or exercise free speech.
Right to opt out. You can tell companies to stop selling your data to third parties or using it for targeted advertising. Some states extend this to profiling and automated decision-making.
Right to correct. You can request correction of inaccurate personal data. The company must make reasonable efforts to fix errors in the information they maintain about you.
Right to data portability. You can request your data in a portable format to move it to another service. Not all state laws include this right.
The laws define "personal data" broadly: information that identifies, relates to, or could reasonably be linked to you. That includes obvious identifiers like name and email, but also browsing history, purchase records, location data, and inferred characteristics.
Who the laws cover and who they don't
State privacy laws apply to businesses that meet size or revenue thresholds. The specifics vary, but most laws cover companies that either process data for a large number of state residents or derive significant revenue from selling data.
Common thresholds across the 2026 laws:
- Process data for 100,000+ state residents annually, or
- Process data for 25,000+ residents and derive more than 50% of revenue from selling data
Small businesses typically fall below these thresholds. Local retailers, independent service providers, and companies without significant online operations aren't covered.
The laws also carve out entire categories of data. Information covered by sector-specific federal laws, HIPAA for health data, FERPA for education records, GLBA for financial information, stays under those frameworks. Nonprofit organizations, government agencies, and higher education institutions get exemptions in most states.
If you work for a company, the privacy law doesn't cover data your employer collects about you as an employee. Job applicant data and contractor data also fall outside most state laws. Employment relationships operate under different legal frameworks.
How to actually use your rights
Exercising privacy rights follows a standard process across states, though the details vary by company.
Step 1: Find the company's privacy request mechanism. State laws require businesses to provide a clear method for submitting requests. Most companies add a "Do Not Sell My Personal Information" link to their website footer or privacy policy. Some provide web forms. Others accept requests by email.
Step 2: Submit your request. Specify which right you're exercising, access, deletion, opt-out, or correction. Include enough information for the company to identify your account or records. You don't need to cite the specific law or explain why you're making the request.
Step 3: Verify your identity. Companies can ask for additional information to confirm you're the person whose data is at stake. Reasonable verification might include matching your email address to their records, answering security questions, or providing a government ID. The verification requirement prevents someone else from accessing or deleting your data.
Step 4: Wait for the response. Most state laws give companies 30 to 45 days to respond to your request. They can extend the deadline if your request is complex, but they must notify you of the extension.
Step 5: Review what you receive. For access requests, companies must provide data in a readable format. For deletion requests, they should confirm deletion. For opt-out requests, they must honor your choice going forward.
If a company denies your request, they must explain why. Valid reasons include exceptions written into the law, fraud prevention, legal compliance, free speech protections, or security needs.
What "sale" actually means in these laws
The term "sale" in state privacy laws doesn't match the common understanding of the word. You don't need to receive money for a data transfer to count as a sale under these statutes.
Most state laws define "sale" as sharing personal data with a third party for monetary or other valuable consideration. "Other valuable consideration" is broad. It includes:
- Trading data for advertising services
- Sharing data with partners who provide analytics
- Providing data to affiliates who use it for their own purposes
When you opt out of sales, you're opting out of this entire category of data sharing, not just literal cash transactions. The mechanism stops companies from monetizing your data through any kind of exchange with third parties.
Targeted advertising works the same way. Opting out of targeted ads means companies can't use your personal data to show you ads based on your behavior across different websites and services. Generic ads based on the content you're currently viewing still appear. The difference is whether your individual profile drives the ad selection.
The enforcement gap
State privacy laws rely on attorney general enforcement. You can't sue companies for violating your privacy rights under most of these statutes. If a company ignores your request or violates the law, your recourse is filing a complaint with your state AG's office.
Some states build in a "cure period." Companies get 30 to 60 days to fix violations after receiving notice from the AG. If they cure the violation within that window, they face no penalties. This reduces the incentive for companies to take initial requests seriously.
Enforcement capacity varies dramatically by state. Attorney general offices have limited resources and competing priorities. Privacy violations compete with consumer fraud, antitrust cases, and criminal matters for attention and staff time.
California's law is an outlier. CCPA includes a private right of action for data breaches, letting consumers sue directly when companies fail to implement reasonable security and their data gets exposed. Most other state laws don't include this provision.
The practical result: companies face minimal immediate consequences for ignoring individual privacy requests. Systematic violations that affect thousands of residents might draw AG attention. One person's unanswered deletion request probably won't.
The verification problem
Identity verification creates a catch-22 for privacy requests. You want to delete your data, but first you need to prove you're you, which often means providing more data.
Companies can require verification that's "reasonable" under the circumstances. What counts as reasonable isn't precisely defined. Some companies accept an email confirmation. Others demand government IDs, utility bills, or answers to knowledge-based authentication questions.
The verification data itself becomes personal information the company holds. If you're making a deletion request, you want the company to delete your original data plus the verification data you just provided. State laws don't clearly address this layering problem.
From the company's perspective, verification protects against malicious requests. Someone could submit a deletion request for your account to cause harm. Someone could request access to your data to steal it. Verification requirements make these attacks harder.
From your perspective, verification adds friction to exercising rights the law supposedly guarantees. The more steps involved, the fewer people follow through. Companies know this.
Global Privacy Control and automated opt-outs
Global Privacy Control is a browser signal that tells websites you're opting out of data sales and targeted advertising. You enable it once in your browser settings. Every site you visit receives the signal automatically.
Several state laws, including California, Colorado, Connecticut, and some of the 2026 laws, require businesses to honor GPC signals. Companies must treat the browser signal the same way they treat a manual opt-out request submitted through a web form.
GPC works through an HTTP header that browsers send with every request. Websites can read the header and adjust their data practices accordingly. The mechanism is technically simple, but adoption has been slow on both sides.
Not all browsers support GPC yet. Firefox, Brave, and DuckDuckGo's browsers include it. Chrome and Safari don't. You can add GPC through browser extensions, but that requires knowing the option exists.
Not all companies honor GPC even in states where the law requires it. Enforcement is minimal. The benefit of GPC is that it scales your opt-out across hundreds of sites without requiring individual requests. The limitation is that it only works when companies comply.
What happens at state borders
Privacy laws are territorial. Delaware's law protects Delaware residents. Iowa's law protects Iowa residents. If you live in a state without a comprehensive privacy law, you don't get the rights these statutes grant.
Some companies extend privacy rights to all U.S. users rather than building separate systems for each state. This happens when the engineering cost of geofencing rights exceeds the business value of maintaining different data practices by location.
Other companies verify your state residency before honoring requests. They might check your IP address, billing address, or account information. If you can't prove you're a resident of a covered state, they deny the request.
The patchwork creates confusion. You might have deletion rights for data collected while you lived in one state but not for data collected after you moved. Companies aren't required to track where you were located when they collected each piece of data.
Cross-border data flows add another layer. If a California company collects data from a Tennessee resident, does Tennessee law apply? What if the company has no physical presence in Tennessee? State laws typically assert jurisdiction based on where the consumer resides, but enforcement across state lines is complicated.
The industry response
Large tech companies and data brokers responded to the first wave of state privacy laws by building centralized request portals. You submit one request through their system, and it processes across all their services and subsidiaries.
Smaller companies often lack the infrastructure to handle privacy requests efficiently. They might receive a dozen requests per year and process each one manually. Response times vary. Some companies treat privacy requests as customer service tickets. Others ignore them until they receive a complaint.
Industry lobbying focuses on federal preemption. Companies prefer one national privacy law to fifty state laws with different requirements. A federal law that sets a floor while allowing states to go further would still create complexity. A federal law that preempts all state laws would eliminate the patchwork but might weaken protections in states with strong existing laws.
The advertising industry built alternative identifiers to replace third-party cookies as those phase out. Privacy laws restrict some uses of personal data, but they don't eliminate behavioral advertising. Companies shift to first-party data collection, contextual targeting, and probabilistic matching techniques that infer identity without explicit identifiers.
The practical limits of individual rights
Privacy laws frame data protection as an individual right you exercise through individual requests. This model has structural limitations.
You need to know which companies hold your data before you can request deletion. Most people can name ten companies they've given data to. Data brokers and advertising networks number in the hundreds. You can't request deletion from companies you don't know exist.
Each request takes time. Finding the privacy request form, filling it out, verifying your identity, and waiting for a response adds up. If you wanted to opt out of data sales at every company that holds your data, you'd need to submit thousands of requests.
Data collection is continuous. Even if you successfully delete your data from fifty companies today, those same companies will collect new data about you tomorrow. Exercising privacy rights is an ongoing process, not a one-time action.
The laws don't prevent collection. They give you tools to limit what happens after collection. If a company's business model depends on data, they'll keep collecting. Your deletion request removes historical data but doesn't stop future data flows.
In The Return of the King, Gandalf tells Frodo that not all who wander are lost
Some are looking for something specific. They know what they're searching for and why. Others wander because the path isn't clear yet.
The same distinction applies to privacy laws. Some people have specific data they want deleted, an old account, an embarrassing post, information from a relationship that ended badly. They know exactly what they're looking for and which company holds it.
Others want privacy in the abstract. They feel uncomfortable with surveillance capitalism but don't have a clear picture of what data exists, where it lives, or what they'd do with access to it. They wander through privacy settings and opt-out forms without a specific destination.
The 2026 state privacy laws are tools for both groups. If you know what you want, deletion of your data from a specific data broker, for instance, the laws give you a mechanism to get it. If you're still figuring out what privacy means to you, the laws provide structure for that exploration.
Neither approach is wrong. Specific goals lead to focused action. Wandering leads to understanding what's possible. Both matter.
What to do now
If you live in one of the nine states with new privacy laws in 2026, you have options you didn't have before. Here's the practical sequence:
Identify your priorities. What data concerns you most? Old accounts you don't use anymore? Information held by data brokers? Targeted advertising that follows you around the web? Start with what matters to you.
Use automated tools where they exist. Global Privacy Control handles opt-outs at scale if your browser supports it. Data broker removal services submit requests on your behalf for a monthly fee. These tools won't catch everything, but they reduce the manual work.
Submit individual requests for high-priority companies. If there's a specific company whose data practices bother you, find their privacy request form and submit a deletion or opt-out request. Focus on companies where you have an active relationship or where you know they hold significant data.
Set up ongoing monitoring. Check your credit reports regularly. Use Have I Been Pwned to watch for new breaches. Review the devices and apps logged into your accounts. Privacy isn't a one-time setup. It's an ongoing practice.
Recognize the limits. State privacy laws give you tools, not solutions. Companies will keep collecting data. Exercising your rights takes time and effort. The laws shift power slightly in your direction, but they don't eliminate the surveillance economy.
The 2026 state privacy laws are incremental progress in a long fight over who controls personal data. They're not the end of that fight. They're not even the middle. They're another step in a process that started before these laws existed and will continue long after.
You can use the tools these laws provide. You can push companies to respect your choices. You can make your data footprint smaller and more intentional. What you can't do is opt out of the system entirely while participating in modern digital life.
That's the tension these laws try to manage. They give you rights without changing the fundamental economic model that makes those rights necessary in the first place. Whether that's enough depends on what you're trying to accomplish.
For some people, the ability to delete old accounts and opt out of targeted ads is meaningful progress. For others, it's rearranging deck chairs. Both perspectives are valid. The laws exist now. What you do with them is up to you.



