US state consumer-privacy law calendar (23 states)
US state consumer data-privacy law calendar, agent-curated 2026-09-30: 23 states with comprehensive privacy laws (19 in effect, 4 taking effect 2027-2028), one row per state law with effective date, applicability threshold, private-right-of-action flag, enforcer, universal opt-out duty, and a documented 0-100 demand_trigger_score (status + recency + threshold breadth + enforcement teeth). A sales team joins on state_code to prioritize compliance/consent/martech prospects by live-or-imminent regulatory pressure; shops and subscription businesses join on state to see which customer states are regulated and when the next wave (Oklahoma, Louisiana 2027-01-01; Alabama 2027-05-01; Vermont 2028-01-01) hits. Every effective date cross-verified against >=2 independent outlets; the widely copied 'Vermont VDPA effective 2025' claim is false (vetoed 2024) — Vermont's real law is the VDPOSA effective 2028-01-01. Excludes Florida's narrow FDBR. Re-verify annually: legislatures amend these laws every session.
- Rows
- 23
- Columns
- 22
- Source cadence
- Yearly
- Last refreshed
- Sep 30, 2026
- Theme
- government
| Column | Type | Description |
|---|---|---|
| law_id | string | Deterministic primary key: stable slug per (state, law). |
| state | string | US state name. |
| state_code | string | USPS 2-letter state code — the join key for sales prioritization. |
| state_fips | string | 2-digit state FIPS code. |
| country_code | string | ISO alpha-3 country (always USA). |
| law_name | string | Full official law name. |
| law_short | string | Common short name / acronym. |
| status | string | in_effect (effective_date <= 2026-09-30) or upcoming. |
| effective_date | date | Date the law's operative provisions take effect (cross-verified against >=2 independent outlets). |
| days_until_effective | integer | Days from 2026-09-30 to effective_date; negative = days already in effect. (unit: days) |
| years_in_effect | float | Years since effective_date (in-effect rows only; null for upcoming). (unit: years) |
| threshold_consumers | integer | Headline consumer-count applicability prong; NULL where the law has no numeric threshold (Texas, Nebraska). Alternative prongs in threshold_note. (unit: consumers) |
| threshold_note | string | Full applicability picture: alternative prongs (revenue-share, sensitive-data counts), revenue prongs, enactment dates and scheduled threshold changes. |
| private_right_of_action | string | limited (California data-breach right only) or none (AG-only enforcement everywhere else). |
| enforcement | string | CPPA_AG (California: agency + attorney general) or AG (attorney-general-only). |
| universal_optout_required | string | Whether the law requires honoring universal opt-out signals (e.g. Global Privacy Control); unknown where unconfirmed (Alabama). |
| demand_trigger_score | integer | 0-100 sales-prioritization score: status (in_effect 30 / upcoming 10) + recency (|days_until|<=365: 25; <=730: 15; else 5) + breadth (no threshold: 25; <=35k: 20; <=100k: 10; else 5) + teeth (private right of action: 20; else universal opt-out: 10; else 0). |
| note | string | Row context: cure periods, amendments, distinctive provisions, and what was deliberately excluded. |
| verification_status | string | multi_source: every effective date confirmed against >=2 independent outlets. |
| source_basis | string | Outlets/analyses confirming this row, semicolon-joined. |
| collected_at | string | Curation snapshot date (2026-09-30). |
| row_hash | string | SHA-256 (16 hex chars) of the row payload; changes when any field changes. |
First 10 sample rows — a preview, not the complete dataset.
| law_id | state | state_code | state_fips | country_code | law_name | law_short | status | effective_date | days_until_effective | years_in_effect | threshold_consumers | threshold_note | private_right_of_action | enforcement | universal_optout_required | demand_trigger_score | note | verification_status | source_basis | collected_at | row_hash |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ca_ccpa_cpra | California | CA | 06 | USA | California Consumer Privacy Act / California Privacy Rights Act | CCPA/CPRA | in_effect | 2023-01-01 | -1,368 | 3.75 | 100,000 | 100,000 consumers/households; also $26.625M+ annual revenue or 50%+ revenue from sale/share of 100k+ consumers' personal information (CPRA; revenue figure inflation-adjusted 2026). | limited | CPPA_AG | yes | 65 | CPRA operative 2023-01-01 (CCPA 2020-01-01). Only state with a dedicated enforcement agency (CPPA) plus AG; limited private right of action for data breaches. DELETE Act data-broker mechanism fully operational 2026-08-01; CPPA risk-assessment rules effective 2026-01-01, ADMT duties from 2027-01-01. | multi_source | mn-lrl-guide-2026;iapp.org;mukul975/privacy-data-protection-skills;mimi1vx/ocskillz;kenkaiii/gg-framework | 2026-09-30 | 71af7378990eacdf |
| va_vcdpa | Virginia | VA | 51 | USA | Virginia Consumer Data Protection Act | VCDPA | in_effect | 2023-01-01 | -1,368 | 3.75 | 100,000 | 100,000 consumers; or 25,000+ if >50% of gross revenue from sale of personal data. | none | AG | no | 45 | Template law most other states copied. AG-only enforcement; no universal opt-out duty. | multi_source | mn-lrl-guide-2026;mukul975/privacy-data-protection-skills;wnallen/dpia-generator;kenkaiii/gg-framework | 2026-09-30 | 1abf15703334537d |
| co_cpa | Colorado | CO | 08 | USA | Colorado Privacy Act | CPA | in_effect | 2023-07-01 | -1,187 | 3.25 | 100,000 | 100,000 consumers; or 25,000+ if revenue/discount from sale of personal data. | none | AG | yes | 55 | Universal opt-out mechanism required; AG enforcement. | multi_source | mn-lrl-guide-2026;mukul975/privacy-data-protection-skills;kenkaiii/gg-framework;eigenlegal/counsel-os | 2026-09-30 | d31002f57b42f863 |
| ct_ctdpa | Connecticut | CT | 09 | USA | Connecticut Data Privacy Act | CTDPA | in_effect | 2023-07-01 | -1,187 | 3.25 | 35,000 | SB 1295 lowers the headline threshold from 100,000 to 35,000 consumers effective 2026-07-01 (payment-transaction data excluded); no threshold where the controller sells personal data or processes sensitive data. | none | AG | yes | 65 | 2026 amendments (SB 1295): LLM-training disclosure in privacy notices, expanded sensitive-data categories, impact-assessment duties from 2026-08-01, further amendments 2026-10-01. | multi_source | mn-lrl-guide-2026;mukul975/privacy-data-protection-skills;jdsupra-foster-swift-2026-07;wnallen/dpia-generator | 2026-09-30 | e0d82791fba88351 |
| ut_ucpa | Utah | UT | 49 | USA | Utah Consumer Privacy Act | UCPA | in_effect | 2023-12-31 | -1,004 | 2.75 | 100,000 | 100,000 consumers AND $25M+ annual revenue; or 25,000+ if >50% of revenue from sale of personal data. | none | AG | no | 45 | Most business-friendly of the early laws (no right to correct, no sensitive-data opt-in beyond notice). HB 418 amendments effective 2026-07-01. | multi_source | mn-lrl-guide-2026;mukul975/privacy-data-protection-skills;jdsupra-foster-swift-2026-07 | 2026-09-30 | 3223aa0a25673faa |
| tx_tdpsa | Texas | TX | 48 | USA | Texas Data Privacy and Security Act | TDPSA | in_effect | 2024-07-01 | -821 | 2.25 | — | No consumer-count threshold: applies to any person doing business in Texas (or targeting Texans) that processes or sells personal data, unless an SBA-defined small business. | none | AG | yes | 70 | Broadest reach of any state law by threshold design; universal opt-out recognition required from 2025. | multi_source | mn-lrl-guide-2026;mukul975/privacy-data-protection-skills;computerweekly-2025;wnallen/dpia-generator;eigenlegal/counsel-os | 2026-09-30 | e0b1ecaa388e36f5 |
| or_ocpa | Oregon | OR | 41 | USA | Oregon Consumer Privacy Act | OCPA | in_effect | 2024-07-01 | -821 | 2.25 | 100,000 | 100,000 consumers (payment-transaction data excluded); or 25,000+ if >=25% of revenue from sale of personal data. | none | AG | yes | 55 | 2025 amendments expanded scope; universal opt-out required from 2026; right to know the specific third parties data was sold to. | multi_source | mn-lrl-guide-2026;mukul975/privacy-data-protection-skills;computerweekly-2025;eigenlegal/counsel-os | 2026-09-30 | e5f5c769412ecc9c |
| mt_mcdpa | Montana | MT | 30 | USA | Montana Consumer Data Privacy Act | MCDPA | in_effect | 2024-10-01 | -729 | 2 | 25,000 | SB 297 lowered the headline threshold from 50,000 to 25,000 consumers effective 2025-10-01; alternative prong 15,000+ with >25% revenue from sale. | none | AG | yes | 75 | SB 297 also removed the 60-day cure period and added a duty of care plus minors'-data restrictions. Universal opt-out required since 2025-01-01. | multi_source | mn-lrl-guide-2026;mukul975/privacy-data-protection-skills;computerweekly-2025;eigenlegal/counsel-os;wnallen/dpia-generator | 2026-09-30 | c2f0d8c3a9353c44 |
| ia_icdpa | Iowa | IA | 19 | USA | Iowa Consumer Data Protection Act | ICDPA | in_effect | 2025-01-01 | -637 | 1.74 | 100,000 | 100,000 consumers; or 25,000+ if >50% of revenue from sale of personal data. | none | AG | no | 55 | Narrow rights package (no correction right); 90-day cure period with no sunset. | multi_source | mn-lrl-guide-2026;mukul975/privacy-data-protection-skills;eigenlegal/counsel-os | 2026-09-30 | 11e9951f438b3b1b |
| de_dpdpa | Delaware | DE | 10 | USA | Delaware Personal Data Privacy Act | DPDPA | in_effect | 2025-01-01 | -637 | 1.74 | 35,000 | 35,000 consumers; or 10,000+ if >20% of revenue from sale of personal data. HB-380 lowers to 10,000 (5,000 if >20% revenue from sale) effective 2027-01-01. | none | AG | yes | 75 | Covers non-profits (unusual). No cure period after 2025-12-31. HB-380 (signed 2026-09) also bans sale of sensitive data and narrows the GLBA exemption. | multi_source | mn-lrl-guide-2026;mukul975/privacy-data-protection-skills;eigenlegal/counsel-os;privacy-daily-2026-09;mondaq-2026-09 | 2026-09-30 | fc74c2b2b09ff417 |
Profiled Oct 1, 2026 from snapshot 20260930T210550Z-7de34851c640
Measured- Completeness
- 98.8%
- Rows
- 23
- Columns
- 22
- Columns with gaps
- 2
| Column | Missing | Distinct | Range | Distribution |
|---|---|---|---|---|
| law_idvarchar | 0% | 29 | — |
|
| statevarchar | 0% | 25 | — |
|
| state_codevarchar | 0% | 24 | — |
|
| state_fipsvarchar | 0% | 19 | — |
|
| country_codevarchar | 0% | 1 | — |
|
| law_namevarchar | 0% | 21 | — |
|
| law_shortvarchar | 0% | 20 | — |
|
| statusvarchar | 0% | 2 | — |
|
| effective_datedate | 0% | 15 | Jan 1, 2023 → Jan 1, 2028 | — |
| days_until_effectivebigint | 0% | 13 | -1,368 → 458median -637 | 1 outside 1st–99th percentile |
| years_in_effectdouble | 17.4% | 12 | 0.74 → 3.75median 1.74 | |
| threshold_consumersbigint | 8.7% | 5 | 25,000 → 175,000median 100,000 | 1 outside 1st–99th percentile |
| threshold_notevarchar | 0% | 23 | — |
|
| private_right_of_actionvarchar | 0% | 2 | — |
|
| enforcementvarchar | 0% | 2 | — |
|
| universal_optout_requiredvarchar | 0% | 3 | — |
|
| demand_trigger_scorebigint | 0% | 9 | 45 → 85median 65 | 1 outside 1st–99th percentile |
| notevarchar | 0% | 24 | — |
|
| verification_statusvarchar | 0% | 1 | — |
|
| source_basisvarchar | 0% | 18 | — |
|
| collected_atvarchar | 0% | 1 | — |
|
| row_hashvarchar | 0% | 24 | — |
|
- Current
20260930T210550Z-7de34851c640 · sha256 7de34851c640…
23 rows · first snapshot
Point any LLM at the metadata endpoint — the documentation above is machine-readable too (JSON-LD + Croissant).
curl "https://datazimuts.com/v1/datasets/us_privacy_law_intel/us_state_privacy_law_calendar" | jq '{title, rows, columns_count, license}'import requests
ds = requests.get("https://datazimuts.com/v1/datasets/us_privacy_law_intel/us_state_privacy_law_calendar").json()
print(ds["title"], ds["rows"], "rows")
# Sample rows for an LLM context window
for row in ds.get("sample_rows", [])[:5]:
print(row)API endpoint: https://datazimuts.com/v1/datasets/us_privacy_law_intel/us_state_privacy_law_calendar
Tip: fetch /llms.txt for the full machine-readable catalog.
Where this data comes from and what was made from it. Other people's work shows as counts; only shared projects are named.
Cite this snapshot
Pinned to snapshot 20260930T210550Z-7de34851c640 and its content hash, so readers get exactly the data you used.
US state consumer-privacy law calendar (agent-curated). (2026). US state consumer-privacy law calendar (23 states) [Data set, snapshot 20260930T210550Z-7de34851c640, sha256 7de34851c640]. Datazimuts. Retrieved 2026-10-01, from https://datazimuts.com/en/datasets/us_privacy_law_intel/us_state_privacy_law_calendar?snapshot=20260930T210550Z-7de34851c640
@misc{dz_us_privacy_law_intel_us_state_privacy_la_7de34851,
title = {{US state consumer-privacy law calendar (23 states)}},
author = {{US state consumer-privacy law calendar (agent-curated)}},
year = {2026},
publisher = {Datazimuts},
howpublished = {\url{https://datazimuts.com/en/datasets/us_privacy_law_intel/us_state_privacy_law_calendar?snapshot=20260930T210550Z-7de34851c640}},
note = {Snapshot 20260930T210550Z-7de34851c640, sha256 7de34851c6402490b078ed16c3b40b57f89d290acbc817cd1579a6e69cba9f71; accessed 2026-10-01}
}Embed a table or a chart
Paste this into any page. The embed is pinned to the same snapshot, follows the reader's light or dark setting, and always shows the source, license and a link back.
<iframe src="https://datazimuts.com/embed/chart?dataset=us_privacy_law_intel%2Fus_state_privacy_law_calendar&lang=en&theme=auto&snapshot=20260930T210550Z-7de34851c640&x=effective_date&y=days_until_effective&agg=avg" title="US state consumer-privacy law calendar (23 states)" width="100%" height="380" style="border:0" loading="lazy"></iframe>
Ask about this dataset. Answers come only from its catalog record, measured profile and change history, and list the facts they used.