State Privacy Laws 2026: The Vendor Contract Gap
As of August 2026, 23 US states have enacted comprehensive privacy laws — and every one requires specific written contract clauses with your vendors. Here's what to audit.
Generate a privacy policy in 60 seconds
Describe what you need in plain English. A panel of AI agents (Researcher, Drafter, Critic, Validator, Adversary) writes a review-ready draft you can edit, sign, and send.
What Do US State Privacy Laws Require in 2026?
As of August 2026, twenty-three US states have enacted comprehensive consumer privacy laws, and twenty of those are already in force. All of them require businesses to provide consumer rights (access, deletion, correction, portability, opt-out) and to publish accurate privacy notices — but every one also requires specific written contract clauses with your vendors, service providers, and sub-processors. Missing those clauses is now among the most cited bases for enforcement action.
Key takeaways
- Twenty-three US states have enacted comprehensive privacy laws as of August 2026; Indiana, Kentucky, Rhode Island, and Arkansas brought the in-force count to twenty this year, and Oklahoma, Alabama, Louisiana, and Vermont enacted laws between March and June 2026 that phase in during 2027 and 2028.
- Every comprehensive state privacy law requires a written contract between the data controller (you) and any processor or service provider handling personal data on your behalf.
- US state privacy fines totaled an estimated $3.425 billion in 2025 — nearly double the prior year — and regulators are increasingly citing deficient vendor contracts alongside broken opt-out links.
- Cure periods are expiring: Delaware's ended December 31, 2025; Oregon's ended January 1, 2026; Montana's ended April 1, 2026. Rhode Island launched with no cure period at all.
- No federal privacy law is imminent — the American Privacy Rights Act expired in January 2025 and has not been reintroduced.
Which State Privacy Laws Are Active in 2026?
Twenty states had active comprehensive consumer privacy laws as of July 1, 2026: California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia — the last of these, Arkansas, joined when its law took effect July 1, 2026.
Twenty-three states have enacted comprehensive consumer privacy laws in total, counting four that were signed in 2026 but haven't taken effect yet (see the update below). Most adopt the same basic structural model pioneered by Virginia. California adopted a different model that creates a dedicated state privacy agency charged with issuing regulations on more than 20 topics.
The table below covers the laws with the highest compliance exposure as of this writing.
| State | Law (short name) | Effective Date | Applicability Threshold | Max Penalty/Violation |
|---|---|---|---|---|
| California | CCPA/CPRA (Cal. Civ. Code § 1798.100) | Jan 1, 2020 / Jan 1, 2023 | Revenue >$26.6M; or 100K consumers; or 50% revenue from data sales | $7,988 (intentional) |
| Virginia | VCDPA (Va. Code Ann. § 59.1-575) | Jan 1, 2023 | 100K consumers; or 25K + 50% revenue from data sales | $7,500 |
| Colorado | CPA (Colo. Rev. Stat. § 6-1-1301) | Jul 1, 2023 | 100K consumers; or 25K + revenue from data sales | $20,000 |
| Connecticut | CTDPA (Conn. Gen. Stat. § 42-515) | Jul 1, 2023 (amended Jul 1, 2026) | 35K consumers; or any 1 resident's sensitive data | $5,000 |
| Texas | TDPSA (Tex. Bus. & Com. Code § 541.001) | Jul 1, 2024 | All businesses (small business exception applies) | $7,500 |
| Maryland | MODPA (Md. Code Com. Law § 14-4601) | Oct 1, 2025 | 35K consumers; or 10K + 20% revenue from data sales | $10,000 |
| Indiana | ICDPA (IN SB 5) | Jan 1, 2026 | 100K consumers; or 25K + 50% revenue from data sales | $7,500 |
| Kentucky | KCDPA (KY HB 15) | Jan 1, 2026 | 100K consumers; or 25K + 50% revenue from data sales | $7,500 |
| Rhode Island | RIDTPPA (RI HB 7787) | Jan 1, 2026 | 35K consumers; or 10K + 20% revenue from data sales | $10,000 |
| Arkansas | ADPPA (AR SB 970) | Jul 1, 2026 | Standard Virginia-model thresholds | $7,500 |
| Oklahoma | OCDPA (OK SB 546) | Jan 1, 2027 (not yet in force) | 100K consumers; or 25K + 50% revenue from data sales | $7,500 |
| Louisiana | LDPA (LA SB 386) | Jan 1, 2027 (not yet in force) | 100K consumers; or 25K + revenue from data sales | Under Louisiana Unfair Trade Practices Act |
| Alabama | APDPA (AL HB 351) | May 1, 2027 (not yet in force) | 25K consumers; or 25% revenue from data sales | $15,000 |
| Vermont | VDPOSA (VT S.71 / Act 145) | Jan 1, 2028 (not yet in force) | 35K consumers; or 3K + sale of sensitive/personal data | Enforced under Vermont Consumer Protection Act |
All three new 2026-effective laws largely mirror the template set in Virginia, although Rhode Island's law has notably low applicability thresholds, covering entities that control or process the data of at least 35,000 consumers, or 10,000 consumers if more than 20 percent of revenue is derived from the sale of personal data.
Update (August 22, 2026): Four States Enacted New Laws in 2026, Not Two
Four states enacted new comprehensive privacy laws in 2026, in this order — none of them takes effect immediately, but all four are worth tracking now if your vendor contracts and data-sharing footprint reach residents of any of them.
Oklahoma — Governor Kevin Stitt signed the Oklahoma Consumer Data Privacy Act (SB 546) on March 20, 2026, making Oklahoma the 20th state with a comprehensive privacy law. It's one of the more business-friendly versions on the books: a 100,000-consumer threshold (or 25,000 consumers plus more than 50% of revenue from data sales), a narrow definition of "sale," and a permanent 30-day cure period that never sunsets. It takes effect January 1, 2027.
Alabama — Governor Kay Ivey signed the Alabama Personal Data Protection Act (HB 351) on April 17, 2026, making Alabama the 21st state. Its applicability threshold is lower than Oklahoma's — 25,000 Alabama residents, or a business deriving more than 25% of gross revenue from selling personal data — and its penalty ceiling is higher, up to $15,000 per violation, though it also carries a permanent 45-day cure period. It takes effect May 1, 2027.
Louisiana — Governor Jeff Landry signed the Louisiana Data Privacy Act (SB 386) on May 29, 2026, making Louisiana the 22nd state. The LDPA closely tracks Texas's model and takes effect January 1, 2027 — the same day as Oklahoma's law.
Vermont — Governor Phil Scott signed S.71, the Vermont Data Privacy and Online Surveillance Act (VDPOSA, codified as Act 145), on June 16, 2026, making Vermont the 23rd state. It applies to businesses that control or process the personal data of at least 35,000 Vermont consumers, or the sensitive data of at least 3,000 — thresholds close to Rhode Island's and Maryland's. VDPOSA doesn't take effect until January 1, 2028, with a 60-day cure period running only through June 30, 2029.
None of the four laws changes your compliance obligations today. But all follow the same processor-contract structure as the rest of the states in the table above (processing instructions, confidentiality duty, deletion/return on termination, subprocessor flow-down, audit rights) — so if you're already auditing vendor contracts against this checklist, add Oklahoma, Alabama, Louisiana, and Vermont to the list of states you're tracking rather than treating any of them as a separate project once their effective dates arrive.
Update (July 28, 2026): California's DROP Deadline Lands August 1
This one is a hard deadline, not a "starts phasing in" date. California's Delete Request and Opt-out Platform (DROP) — the one-stop tool the Delete Act (SB 362) created for consumers to request deletion from every registered data broker at once — went live January 1, 2026, and more than 260,000 Californians have already filed requests through it. Until now, a broker could leave those requests unprocessed without a specific penalty attached to inaction.
That changes August 1, 2026. From that date, every registered data broker must check DROP at least once every 45 days, act on each deletion request within 90 days (deleting the associated data, including inferences, and adding the consumer to a suppression list so the data isn't re-collected or resold), and report status back through the platform. A broker who lets a request sit unprocessed is liable for an administrative fine of $200 per request, per day, under Cal. Civ. Code § 1798.99.82 — on top of the separate $200-per-day registration-failure fine for brokers that never registered at all.
The practical takeaway for anyone running a US privacy program: if your business qualifies as a "data broker" under Cal. Civ. Code § 1798.99.80 (you sell or share consumers' personal information you didn't collect directly from them), confirm your DROP registration is current and that someone owns the 45-day check-in as a recurring calendar task — not a one-time compliance project. If you're not a data broker yourself but you use one as a vendor, this is also a good moment to confirm your vendor contract's deletion-flow-down clause actually references DROP compliance, not just the older CCPA deletion-request timelines.
The Compliance Gap Nobody Talks About: Your Vendor Contracts
Consumer-facing compliance — privacy notices, cookie banners, opt-out links, GPC signal recognition — gets almost all the attention. But regulators are increasingly treating your vendor contracts as primary evidence of program maturity or its absence.
When the California Privacy Protection Agency announced a $1.35 million settlement — the largest CCPA penalty at that time — one of the itemized grievances stood out: the company had failed to amend or enter into third-party data protection vendor contracts by regulatory deadlines. The consumer-facing side of privacy compliance is visible and testable. But the back-end architecture of a compliant privacy program lives at least in part in vendor contracts, and regulators increasingly treat those contracts as evidence of program maturity.
Contractual oversight with third parties remains a focus. The CCPA and every other state comprehensive privacy law require businesses that share data with third parties to have several explicit provisions to ensure consumer protection. The California AG and CalPrivacy alleged that entities failed to craft contracts that meet the CCPA's requirements, resulting in settlements of $1.35 million and $1.55 million.
The record for this kind of case has since grown. In February 2026, the California Attorney General secured a $2.75 million settlement with Disney and ABC — the largest CCPA penalty issued to date — over the same enforcement theme running through this guide: consumers had to submit a separate opt-out request on every Disney streaming app and device instead of one signal that propagated everywhere, and some TV-app users were redirected off-app entirely just to finish the request. The CCPA requires opt-out mechanisms to be simple and easy to use; a mechanism that works on the web but not inside a connected-TV app, or that only covers one product line at a time, doesn't clear that bar. If your vendor contracts don't obligate every vendor and every surface — web, mobile, connected TV, in-app — to honor a single opt-out signal, Disney's settlement is now the benchmark for how expensive that gap can get.
All current and upcoming state data privacy laws require that processors and controllers enter into a binding contract that clearly sets forth instructions, policies, and procedures with regard to the personal data that the processor will process on behalf of the controller.
The required clauses are not identical across all states. The table below maps the core requirements.
| Required Contract Clause | CA (11 CCR § 7051) | VA/IN/KY/CO Model | MD MODPA | RI RIDTPPA |
|---|---|---|---|---|
| Processing instructions + stated purpose | ✓ | ✓ | ✓ | ✓ |
| Confidentiality duty on processing personnel | ✓ | ✓ | ✓ | ✓ |
| Deletion or return of data at contract end | ✓ | ✓ | ✓ | ✓ |
| Subprocessor flow-down (prior notice + written contract) | ✓ | ✓ | ✓ | ✓ |
| Audit / assessment rights for controller | ✓ | ✓ | ✓ | ✓ |
| Security measures obligation | ✓ | ✓ | ✓ (heightened) | ✓ |
| Prohibition on selling or sharing personal information | ✓ (CPRA-specific) | ✗ | ✗ | ✗ |
| No-commingling with data from other clients | ✓ (CPRA-specific) | ✗ | ✗ | ✗ |
| Notice to controller if vendor can no longer comply | ✓ | ✓ | ✓ | ✗ |
| ADMT cooperation clause | ✓ (Jan 2026 new) | CO only (profiling) | ✗ | ✗ |
California's automated decision-making technology (ADMT), risk assessment, and cybersecurity audit regulations took effect January 1, 2026, and expressly layer new contracting expectations onto the § 7051 baseline — including vendor cooperation with Pre-Use Notice obligations, opt-out and appeal mechanics, and the fifteen-day downstream-notification window for third parties following a post-processing opt-out.
If you operate a business with a SaaS stack typical of a mid-sized company — a CRM, a cloud analytics vendor, a payment processor, and a customer support platform — each of those vendors is likely a "processor" or "service provider" under the laws of every state where your users live. A missing clause in any one of those agreements is a compliance gap you can verify today by pulling the contracts and running them against the table above.
You can generate a compliant data processing agreement as a starting point, then layer in state-specific clauses. Understanding how GDPR DPAs compare to US state requirements is covered in detail in our GDPR DPA guide — the structures overlap but the terminology and specific prohibitions differ enough that a GDPR DPA alone does not satisfy CCPA § 7051.
How to Audit Your Vendor Contracts for State Privacy Compliance
This is a step-by-step process, not a one-time legal project. Treat it as a recurring workflow.
Step 1 — Map which states' laws apply to your business. Identify the states where your consumers live, count them, and check the applicability thresholds in the table above. A B2B SaaS company with 150,000 US users is almost certainly subject to California, Virginia, Texas, and likely Indiana, Kentucky, and several others. Texas's TDPSA is the most expansive: it applies to most businesses conducting commercial activity in Texas regardless of revenue or consumer-count thresholds.
Step 2 — Inventory every vendor that touches personal data. Build a simple spreadsheet: vendor name, data categories shared, states whose residents' data is involved, and whether a written contract exists. Many businesses discover that third-party analytics and advertising pixels represent data-sharing relationships with no contract at all.
Step 3 — Pull and review each contract against the mandatory clause checklist. Compare to the table above. Flag any contract missing processing instructions, a confidentiality clause, a deletion/return clause, or subprocessor controls. For California-covered data, also check for the prohibition on selling or sharing and the no-commingling clause.
Step 4 — Add a US State Privacy Addendum to deficient contracts. Many vendors already have standard data processing addenda available. If yours does not, negotiate one. The CPPA's CCPA regulations and the VCDPA guidance from the Virginia AG both publish the required clause language. Pactlio's DPA template provides a drafting baseline you can take to a vendor negotiation.
Step 5 — Add subprocessor flow-down language. The remaining states require controllers to enter into contractual requirements with data processors that describe the processing and relevant data, require processor personnel to be bound to a duty of confidentiality, require deletion or return of data at the termination of the contract, and bind any subprocessors to the same requirements as the processor.
Step 6 — Set a calendar reminder for cure-period and amendment deadlines. Several state amendments and enforcement triggers have specific dates. Connecticut's CTDPA amendments (Public Act 25-113, SB 1295) took effect July 1, 2026, cutting the applicability threshold from 100,000 consumers to 35,000, adding a no-threshold trigger for any single resident's sensitive data, and adding neural data to the definition of sensitive data. Utah's right-to-correct amendment takes effect July 1, 2026. California's DELETE Act DROP platform requires brokers to honor deletion requests by August 1, 2026.
For a broader view of how to structure a privacy policy that works alongside these vendor contracts, see our guide on how to create a privacy policy and our breakdown of GDPR vs. CCPA.
Jurisdiction Notes: Cure Periods and Enforcement Posture
Cure periods — the grace window a business gets to fix a violation before a fine is issued — are shrinking across the board.
| State | Cure Period Status (July 2026) | Enforcement Lead |
|---|---|---|
| California | None (CPPA enforces immediately) | California Privacy Protection Agency + AG |
| Virginia | 30 days (permanent) | Attorney General |
| Colorado | 60 days (permanent) | Attorney General |
| Connecticut | Limited; AG signaling tougher stance in 2026 | Attorney General |
| Texas | 30 days (cure available before suit) | Attorney General |
| Maryland | None | Attorney General |
| Indiana | 30 days (permanent) | Attorney General |
| Kentucky | 30 days | Attorney General |
| Rhode Island | None | Attorney General |
| Oregon | Expired January 1, 2026 | Attorney General |
| Delaware | Expired December 31, 2025 | Attorney General |
| Montana | Expired April 1, 2026 | Attorney General |
Cure periods are expiring across multiple states, enabling immediate enforcement without a grace period. Delaware's 60-day cure period ended December 31, 2025. Montana's expired April 1, 2026. New Jersey's expires mid-2026.
State privacy regulators across the United States collected $3.425 billion in privacy-related fines in 2025, nearly double the 2024 figure of $1.827 billion. Twenty-three states have now enacted privacy laws covering more than half of the US population.
Ten states came together to form the Consortium of Privacy Regulators, pledging to coordinate investigations and enforcement of common privacy laws around accessing, deleting, and preventing the sale of personal information. Cross-state coordinated actions mean a single opt-out failure can trigger simultaneous investigations in multiple jurisdictions.
For California-specific obligations under the CCPA and CPRA, see our dedicated CCPA privacy policy guide for California.
Common Mistakes to Avoid
- Treating a GDPR DPA as a US compliance document. GDPR's opt-in model for consent is more stringent than CCPA's opt-out approach in some ways, but CCPA's specific requirements — opt-out links, GPC signal recognition, specific privacy notice categories, service provider contract provisions — are operationally distinct and not automatically satisfied by a GDPR-compliant program. Businesses discover this gap when they receive a cure notice from a state AG.
- Using a generic "we comply with applicable law" clause instead of enumerated obligations. Generic cross-references to the underlying services agreement do not satisfy California's regulations. Identify the specific business purpose(s) for the processing and prohibit the service provider or contractor from retaining, using, or disclosing personal information for any purpose other than the specified business purposes.
- Ignoring newer state laws until they hit the news. Indiana, Kentucky, and Rhode Island were enacted in 2023 and 2024 — businesses with national footprints had two to three years to prepare. Maryland, Minnesota, and New Hampshire have active laws that receive less coverage than California but carry real enforcement exposure for covered businesses.
- Skipping subprocessor clauses. Every state law requires your vendors to flow privacy obligations down to their own sub-vendors. A contract that binds the vendor but not its subprocessors leaves a gap regulators will identify.
- Failing to honor Global Privacy Control signals. On September 9, 2025, the California Privacy Protection Agency, Colorado Attorney General, and Connecticut Attorney General announced a coordinated investigative sweep of companies for non-compliance with opt-out preference signals — the first cross-state coordinated action on a specific privacy-technical issue.
- Letting privacy programs atrophy. Many organizations built their privacy programs in 2020 and have allowed them to atrophy in the years since, leaving them poorly positioned for the current enforcement environment.
Sources
- California Consumer Privacy Act (CCPA/CPRA): https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.100
- California CCPA Regulations (11 CCR § 7051, including 2026 ADMT/risk assessment rules): https://cppa.ca.gov/regulations/
- California Delete Act (SB 362) and DROP requirements, Cal. Civ. Code §§ 1798.99.80–.86: https://cppa.ca.gov/data_brokers
- Virginia Consumer Data Protection Act (VCDPA): https://law.lis.virginia.gov/vacode/title59.1/chapter53/
- Colorado Privacy Act (CPA): https://leg.colorado.gov/bills/sb21-190
- Indiana Consumer Data Protection Act (IN SB 5): https://iga.in.gov/legislative/2023/bills/senate/5
- Kentucky Consumer Data Protection Act (KY HB 15): https://apps.legislature.ky.gov/record/24rs/hb15.html
- Rhode Island RIDTPPA (RI HB 7787): https://webserver.rileg.us/BillText/2024/H7787Aaa.pdf
- Maryland Online Data Privacy Act (MODPA): https://mgaleg.maryland.gov/mgawebsite/Legislation/Details/hb0567
- Texas Data Privacy and Security Act (TDPSA): https://capitol.texas.gov/tlodocs/88R/billtext/pdf/HB04181F.pdf
- Oklahoma Consumer Data Privacy Act (OCDPA, SB 546), signed March 20, 2026: https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20260327-oklahoma-enacts-nations-twentieth-state-comprehensive-privacy-law
- Alabama Personal Data Protection Act (APDPA, HB 351), signed April 17, 2026: https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20260422-alabama-enacts-nations-twenty-first-state-comprehensive-privacy-law
- Louisiana Data Privacy Act (LDPA, SB 386), signed May 29, 2026: https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20260622-louisiana-enacts-nations-twenty-second-state-comprehensive-privacy-law
- Vermont Data Privacy and Online Surveillance Act (VDPOSA, S.71 / Act 145), signed June 16, 2026: https://legislature.vermont.gov/bill/status/2026/S.71
- Connecticut Public Act 25-113 (SB 1295), CTDPA amendments effective July 1, 2026: https://www.wiley.law/alert-Major-Changes-to-Connecticut-Consumer-Privacy-Law-Will-Take-Effect-July-1-2026
- IAPP US State Privacy Legislation Tracker: https://iapp.org/resources/article/us-state-privacy-legislation-tracker
- MultiState: 20 State Privacy Laws in Effect in 2026: https://www.multistate.us/insider/2026/2/4/all-of-the-comprehensive-privacy-laws-that-take-effect-in-2026
- Gartner / CyberScoop — US State Privacy Fines $3.425B in 2025: https://cyberscoop.com/privacy-companies-hit-with-record-fines-2025-gartner/
- Help Net Security — US State Privacy Fines 2025: https://www.helpnetsecurity.com/2026/04/28/us-state-privacy-fines-2025/
- Global Privacy Watch — State Privacy Law Contracting Requirements: https://www.globalprivacywatch.com/2026/05/the-paper-trail-state-privacy-law-contracting-requirements/
- O'Melveny 2026 Data Security and Privacy Compliance Checklist: https://www.omm.com/insights/alerts-publications/2026-data-security-and-privacy-compliance-checklist-key-us-state-law-updates-ai-rules-coppa-changes-and-global-data-protection-risks/
- Koley Jessen — Processor Audit Requirements Under State Privacy Laws: https://www.koleyjessen.com/insights/publications/requirements-for-data-processor-audits-under-state-data-privacy-laws
- Venable — Data Contract Requirements Under State Privacy Laws: https://www.venable.com/insights/publications/ip-quick-bytes/data-contract-requirements-under-new-state
- ArentFox Schiff — New Era of US Privacy Enforcement: https://www.afslaw.com/perspectives/privacy-counsel/new-era-us-privacy-enforcement-has-only-just-begun-2025-trends-and
- California DOJ — Attorney General Bonta Announces $2.75 Million Settlement with Disney (Feb 11, 2026): https://www.oag.ca.gov/news/press-releases/california-wont-let-it-go-attorney-general-bonta-announces-275-million
This article is general information, not legal advice. Laws vary by jurisdiction. Pactlio generates professional drafts for review — have a licensed attorney review anything important.
Frequently Asked Questions
How many US states have comprehensive privacy laws in 2026?▾
Twenty-three US states have enacted comprehensive consumer privacy laws as of August 2026, though not all are in force yet. Twenty are already active — Indiana, Kentucky, and Rhode Island joined January 1, 2026, and Arkansas followed July 1, 2026. Oklahoma (20th), Alabama (21st), Louisiana (22nd), and Vermont (23rd) all enacted new laws in 2026 that take effect between 2027 and 2028.
Did any new states pass privacy laws in 2026?▾
Yes — four. Oklahoma enacted the Oklahoma Consumer Data Privacy Act (SB 546) on March 20, 2026, becoming the 20th state; Alabama followed with the Alabama Personal Data Protection Act (HB 351) on April 17, 2026 as the 21st state; Louisiana enacted the Louisiana Data Privacy Act (SB 386) on May 29, 2026 as the 22nd state; and Vermont enacted the Vermont Data Privacy and Online Surveillance Act (S.71, Act 145) on June 16, 2026 as the 23rd state. None of the four is in force yet — they phase in between January 2027 and January 2028.
What do Oklahoma's and Alabama's new privacy laws require?▾
Both follow the Virginia model and take effect in 2027. Oklahoma's OCDPA (effective Jan 1, 2027) applies to businesses handling 100,000+ Oklahoma consumers' data, or 25,000+ with over 50% of revenue from data sales, and caps fines at $7,500 per violation with a permanent 30-day cure period. Alabama's APDPA (effective May 1, 2027) applies at a lower 25,000-consumer threshold, caps fines higher at $15,000 per violation, and gives businesses a permanent 45-day cure period before the Attorney General can sue.
Which state privacy laws took effect on January 1, 2026?▾
Three new comprehensive privacy laws took effect January 1, 2026: the Indiana Consumer Data Protection Act (IN SB 5), the Kentucky Consumer Data Protection Act (KY HB 15), and the Rhode Island Data Transparency and Privacy Protection Act (RI HB 7787). All three follow the Virginia VCDPA model.
Do state privacy laws require written contracts with vendors and service providers?▾
Yes. Every current comprehensive US state privacy law requires controllers to enter a written contract with processors and service providers. The contract must cover at minimum: processing instructions, a confidentiality duty on personnel, deletion or return of data on termination, subprocessor flow-down obligations, and audit rights for the controller.
What are the penalties for violating state privacy laws in 2026?▾
Penalties vary by state. California's CPRA allows up to $7,988 per intentional violation, with the California Privacy Protection Agency actively investigating hundreds of cases. Indiana and Kentucky allow up to $7,500 per violation. Rhode Island allows up to $10,000 per violation with no cure period. Colorado allows up to $20,000 per violation.
Is there a federal privacy law that preempts state laws?▾
No. The American Privacy Rights Act expired at the end of the 118th Congress in January 2025 and has not been reintroduced as of July 2026. The FTC's Section 5 unfair-practices authority remains the federal backstop, but state laws are the primary source of US privacy compliance obligations.
What is the Global Privacy Control (GPC) and is it required in 2026?▾
The Global Privacy Control is a browser signal that communicates a user's opt-out from data sales and targeted advertising. In 2026 it is a mandatory opt-out mechanism in California, Colorado, Connecticut, Oregon, and at least seven other states. Failure to honor GPC signals is one of the most common enforcement triggers.
Which state has the strictest privacy law in 2026?▾
That depends on the axis. Maryland's Online Data Privacy Act (MODPA), effective October 2025, has the strictest data minimization standard — requiring collection be 'reasonably necessary and proportionate' rather than consent-based. California has the most active enforcement record and the most developed regulatory apparatus.
What vendor contract changes did California add in 2026?▾
California's CPRA regulations at 11 CCR § 7051, fully operative January 1, 2026, require three new categories of vendor cooperation: ADMT (automated decision-making) cooperation clauses covering opt-out mechanics and appeal windows, risk assessment support obligations, and cybersecurity audit cooperation provisions.
What changed in Connecticut's privacy law on July 1, 2026?▾
Public Act 25-113 (SB 1295) cut the CTDPA's applicability threshold from 100,000 Connecticut residents to 35,000, added a no-threshold trigger for businesses processing even one resident's sensitive data, and expanded the definition of sensitive data to include neural data. Vendor contracts written against the old 100K threshold should be re-checked.
What happens on August 1, 2026 for California data brokers?▾
Registered data brokers must start actively working the Delete Request and Opt-out Platform (DROP) queue — logging in at least every 45 days, deleting the personal data behind each request within 90 days, and reporting compliance back to the CPPA. A data broker that misses a request faces a $200-per-request, per-day fine under Cal. Civ. Code § 1798.99.82, layered on top of the underlying Delete Act obligations in § 1798.99.86.
What is the largest CCPA settlement to date?▾
In February 2026, Disney and ABC agreed to pay $2.75 million to settle California Attorney General allegations that their streaming apps failed to fully honor opt-out requests — consumers had to opt out separately on each app and device instead of once. It's the largest CCPA penalty issued to date, centered on exactly the opt-out-mechanism gap this guide covers.