US State Consumer Privacy Law Count Reaches 24 As Stricter Data Rules Take Hold

The number of state consumer privacy laws in the United States has grown to 24, following the passage of four new laws during the first half of 2026.

The count began with just one law when the California legislature passed the California Consumer Privacy Act in June 2018, and the field has expanded rapidly since.

Three of the 20 laws already on the books entered into force on January 1, 2026, adding to compliance pressures for organisations operating across multiple states.

The four newly enacted laws are the Alabama Personal Data Protection Act, the Louisiana Data Privacy Act, the Oklahoma Act Relating to Data Privacy, and the Vermont Data Privacy and Online Surveillance Act, all effective in 2027.

All four apply only to personal data of state residents acting in personal, family, or household contexts, excluding business-to-business and employment data from their scope.

Vermont’s law stands out for its broad definitions, including “derived data” such as inferences, predictions, and conclusions drawn from other information about a consumer’s device.

Vermont also requires privacy notices to disclose whether a controller collects, uses, or sells personal data for the purpose of training large language models, a requirement shared only with Connecticut.

Louisiana and Vermont both introduce additional consent requirements for certain sensitive data sales, with Louisiana targeting sellers who derive at least 50 percent of annual revenues from selling personal information.

Senator Ron Wyden sent a letter to attorneys general in 11 states urging them to require organisations to honour opt-out signals from residents regardless of their physical location or IP address.

Wyden’s letter described geolocation filtering based on IP addresses as a “flawed” method of determining residency, arguing it allows organisations to “selectively ignore consumer opt-out requests.”

A significant trend in 2026 amendments is the growing number of restrictions on sensitive personal data sales, particularly precise geolocation data and information relating to minors.

Maryland and New Jersey have now banned all sensitive personal data sales, while Connecticut and Virginia have banned the sale of precise geolocation data specifically.

Connecticut’s May 2026 amendment, entering force on October 1, 2026, also adds new requirements for facial recognition technology and extends consumer deletion rights to certain publicly available information used to build consumer profiles.

The Maryland amendment in force from July 1, 2026, restricts the sale of personal data to governmental entities that have engaged in or supported immigration enforcement within the last six months.

New Jersey’s June 2026 amendment prohibits controllers from selling sensitive data without any minimum threshold and establishes a public data broker registry, though the attorney general has delayed enforcement until the registry system launches.

The Virginia amendment in force from July 1, 2026, prohibits the sale or offer for sale of precise geolocation data concerning any consumer.

The California legislature is currently considering AB 322, which would ban precise location data sales, and AB 1542, which would prohibit the sale or sharing of any sensitive personal information.

Vermont’s law includes a notable geofence restriction, prohibiting virtual boundaries within 1,850 feet of any health care facility for the purpose of identifying or tracking consumers based on their health data.

The four new laws do not create significant new high-watermark requirements for most organisations, but amendments enacted in 2026 do introduce stricter obligations that complicate compliance planning.

Most organisations update privacy notices and compliance programmes in the second half of the year, making 2026 a practical moment to assess gaps against the new laws and amendments before deadlines arrive.