LawFlash

New US State Consumer Privacy Laws: What Businesses Should Know

28 июля 2026 г.

Four additional states—Alabama, Louisiana, Oklahoma, and Vermont—have adopted comprehensive consumer privacy legislation this year, further expanding the increasingly complex landscape of state privacy laws in the United States. While these state laws share commonalities and generally follow a Virginia-style approach, each includes unique specifications, applicability thresholds, or compliance requirements that warrant careful attention.

Companies with mature privacy programs should assess whether these recent additions require updates to privacy notices, consumer rights processes, or internal governance practices. Organizations that have not yet implemented comprehensive state privacy compliance programs should evaluate whether these new laws require modification of compliance processes before the applicable effective dates.

WHICH BUSINESSES ARE IMPACTED?

As with most state privacy laws, these laws generally apply to companies that collect and use the personal data of traditional consumers, but each law has a distinct threshold of applicability.

Alabama

The Alabama Personal Data Protection Act applies to persons that conduct business in Alabama or produce products or services targeted to Alabama residents while meeting either of the following thresholds:

  • Control or process the personal data of more than 25,000 Alabama consumers, a consumer threshold that is among the lowest in the United States (excluding data processed solely for payment transactions); or
  • Derive more than 25% of gross revenue from the “sale” of personal data.

Louisiana

The Louisiana Data Privacy Act (LDPA) adopts applicability thresholds more akin to those found in the California Consumer Privacy Act. Specifically, the LDPA applies to persons or entities who do business in Louisiana and satisfy one or more of the following criteria:

  • Has annual gross revenues in excess of $25 million;
  • Annually buys, receives for the business’s commercial purposes, sells, or shares for commercial purposes the personal information of 75,000 or more Louisiana consumers, households, or devices; or
  • Derives 50% or more of its annual revenues from the sale of consumer personal information.

Oklahoma

The Oklahoma Consumer Data Privacy Act applies to controllers or processors who do business in Oklahoma and during a calendar year either:

  • Control or process the personal data of 100,000 or more Oklahoma residents; or
  • Control or process the personal data of at least 25,000 consumers and derive over 50% of gross revenue from the sale of personal data.

Vermont

Unlike the other state laws, the applicability thresholds under the Vermont Data Privacy and Online Surveillance Act (VTDPOSA) are quite low and may hinge on an entity’s processing of sensitive personal data. The VTDPOSA applies to persons that conduct business in Vermont or produce products or services targeted to Vermont residents and have in the preceding calendar year met one or more of the following criteria:

  • Controlled or processed the personal data of at least 35,000 Vermont consumers (excluding data processed solely to complete a payment transaction);
  • Controlled or processed the sensitive data of at least 3,000 Vermont consumers (excluding data processed solely to complete a payment transaction); or
  • Offered for sale in trade or commerce the personal data of at least 3,000 Vermont consumers. Notably, the VTDPOSA’s consumer health data provisions apply to any person that conducts business in Vermont or produces products or services targeted at Vermont residents. In the event of a conflict between the VTDPOSA and any other law, the law that affords the greatest privacy protections for consumers will control.

EXEMPTIONS

All four laws provide entity- and data-level exemptions for certain organizations and information subject to federal privacy laws. Specifically, each law exempts entities and data regulated by the Health Insurance Portability and Accountability Act and by the Gramm-Leach-Bliley Act, data maintained by institutions of higher education, and various categories of federally regulated information, such as information subject to the Family Educational Rights and Privacy Act.

Each law also excludes personal data processed in employment and business-to-business contexts.

The laws differ, however, with respect to nonprofit organizations and small businesses. Alabama, Louisiana, and Oklahoma generally provide entity-level exemptions for nonprofit organizations, although Alabama’s exemption applies only to nonprofits with fewer than 100 employees. Vermont does not provide a broad exemption for nonprofits, instead exempting only certain nonprofit entities established to detect and prevent fraudulent acts in connection with insurance.

In addition, Alabama exempts businesses with fewer than 500 employees, provided that such businesses do not sell personal data.

WHAT ARE COMPANIES REQUIRED TO DO?

The four new state laws are largely Virginia-style laws in their approach to consumer privacy regulation. As with previously enacted comprehensive consumer privacy laws, the laws generally establish the following compliance obligations for covered entities:

  • Privacy Notices. Provide consumers with clear, transparent, and reasonably accessible privacy notices describing, among other things, the categories of personal data to be processed, the purpose of processing personal data, how consumers may exercise their rights (including opt-out rights), categories of data shared with third parties, and categories of third parties with whom personal data is shared, and include contact information for consumers to submit requests regarding their personal data. Vermont further requires controllers to disclose in their privacy notices whether personal data is collected, used, or sold for the purpose of training large language models.
  • Consent. Obtain consumer consent before processing sensitive data;
  • Data Minimization. Limit the collection of personal data to what is reasonably necessary in relation to the purposes for which the data is processed. Vermont, however, adopts a heightened standard, requiring controllers to limit the collection of a consumer’s personal data to what is “reasonably necessary and proportionate” in relation to the purposes for which the data is processed.
  • Security Safeguards. Implement reasonable administrative, technical, and physical safeguards to protect personal data.
  • Data Protection and Impact Assessments. Conduct data protection assessments for certain processing activities, including targeted advertising, sale of personal data, processing of sensitive data, and any processing that might present a heightened risk of harm to consumers. This requirement applies under the Louisiana, Oklahoma, and Vermont laws; Alabama does not require controllers to conduct or document data protection assessments.
  • Vendor Contracts. Enter into agreements with any processors of personal data on their behalf. 

ADDITIONAL REQUIREMENTS REGARDING CONSUMER HEALTH DATA

Similar to the Connecticut and Maryland privacy laws, Vermont’s new law includes enhanced protections related to the processing of consumer health data. Among other things, it prohibits a person from:

  • Providing employees or contractors with access to consumer health data unless they are subject to a contractual or statutory duty of confidentiality;
  • Providing processors with access to consumer health data unless they comply with the law’s contractual requirements;
  • Using a geofence to establish a virtual boundary that is within 1,850 feet of a healthcare facility to identify, track, collect data from, or send notifications to consumers regarding their consumer health data; or
  • Selling or offering to sell consumer health data without first obtaining the consumer’s consent.

WHAT RIGHTS DO CONSUMERS HAVE?

Similar to the state privacy laws that are currently in effect, the four new state laws grant consumers with several core privacy rights, including:

  • Access. The right to confirm whether a controller is processing the consumer’s personal data and to access and request a copy of that personal data.
  • Deletion. The right to request deletion of personal data.
  • Correction. The right to correct inaccuracies in the consumer’s personal data.
  • Data Portability. The right to obtain a portable and readily usable copy of the consumer’s personal data.
  • Opt-Out Rights. The right to opt out of targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects.
  • Protection for Minors. All four laws incorporate enhanced protections for minors, but Alabama requires entities to obtain consent before processing the personal data of a child between the ages of 13 and 15 for targeted advertising or the sale of personal data, in accordance with the Children’s Online Privacy Protection Act.

ENFORCEMENT

Each law is enforced exclusively by the applicable state attorney general, with none creating a private right of action. Before initiating an enforcement action, however, state attorneys general must provide notice of an alleged violation and an opportunity to cure. The available cure period varies by state: Alabama provides a 45-day cure period, Louisiana and Oklahoma provide a 30-day cure period, and Vermont offers a 60-day cure period, although the Louisiana and Vermont cure periods sunset on July 31, 2027 and June 30, 2029, respectively.

WHEN DO THE NEW LAWS TAKE EFFECT?

Both the Louisiana and Oklahoma laws will take effect on January 1, 2027, while Alabama’s law will take effect a few months later on May 1, 2027. Vermont’s law will take effect on January 1, 2028.

HOW WE CAN HELP

We are prepared to guide companies and institutions of all sizes through the challenges they face in this new regulatory environment. We closely follow developments in all 50 states as data privacy legislation is proposed, enacted, and amended. Our lawyers assist clients in virtually all of the major industries around the world in understanding how these critical changes affect their businesses and how to navigate the changing data privacy landscape.

Contacts

If you have any questions or would like more information on the issues discussed in this LawFlash, please contact any of the following: