Where you stand in these 30 states
If you live in one of the 30 states without a comprehensive data privacy law, you can't compel most businesses to give you access to your data, delete it, or stop selling it under your state's own law. You have no state-level right to opt out of targeted advertising or profiling.
That doesn't mean you're unprotected. Every one of these states has a data breach notification statute: companies must tell you if your personal information is compromised. Most have consumer protection statutes (UDAP laws) that prohibit deceptive practices. Federal law and the laws of other states, especially California, extend rights that reach across state lines.
Enacted laws not yet in effect
- Alabama: Alabama Personal Data Protection Act, enacted April 2026, effective May 1, 2027. Virginia-model rights (access, delete, correct, and opt out of sale, targeting, and profiling), applying to businesses that handle data of 25,000 or more consumers.
- Louisiana: Louisiana Data Privacy Act (LDPA), enacted May 2026, effective January 1, 2027. Access, delete, and opt-out rights.
- Oklahoma: Oklahoma Consumer Data Privacy Act (OCDPA), enacted March 2026, effective January 1, 2027.
- Vermont: Vermont Data Privacy and Online Surveillance Act, enacted June 2026, effective January 1, 2028. Connecticut-model rights (access, delete, correct, and opt out of sale, targeting, and profiling).
All 30 states + D.C.
The table below shows each state's breach notification law and any notable special protections beyond the baseline. Every state listed has no comprehensive privacy law in effect as of 2026.
| State | Breach notification | Special protections | Upcoming law |
|---|---|---|---|
| Alabama | Data Breach Notification Act (2018) | App-store age verification (2026) | APDPA effective May 2027 |
| Alaska | Personal Information Protection Act | Address confidentiality (DV survivors) | Bills introduced, none enacted |
| Arizona | Ariz. Rev. Stat. § 18-552 | Address confidentiality (DV/stalking survivors) | None enacted |
| Arkansas | Personal Information Protection Act | None noted | None enacted |
| D.C. | Security Breach Protection Act | None noted | Bills proposed, not enacted |
| Georgia | Ga. Code Ann. § 10-1-910 | Address confidentiality program | Bills introduced, none enacted |
| Hawaii | Haw. Rev. Stat. § 487N | Student data privacy protections | Bills considered, none enacted |
| Idaho | Idaho Code § 28-51-104 | Address confidentiality (DV survivors) | None enacted |
| Illinois | Personal Information Protection Act | BIPA (biometric privacy, private right of action); SOPPA (student data); Genetic Information Privacy Act | Comprehensive bill in committee |
| Kansas | Kan. Stat. Ann. § 50-7a01 | Address confidentiality program | None enacted |
| Louisiana | Database Security Breach Notification Law | Address protection for officials | LDPA effective Jan 2027 |
| Maine | Notice of Risk to Personal Data Act | ISP privacy law (restricts ISP data use) | None enacted |
| Massachusetts | Data security regulations (201 CMR 17.00) | Strong data-security rules; broad consumer protection (private right of action) | Actively debated, not enacted |
| Michigan | Identity Theft Protection Act | Minors' online safety considered | Bills introduced, none enacted |
| Mississippi | Miss. Code Ann. § 75-24-29 | Address confidentiality program | None enacted |
| Missouri | Mo. Rev. Stat. § 407.1500 | Address protection for judicial officers | Bills moving, none enacted |
| Nevada | NRS 603A breach notification | Online sale opt-out (SB 220); Consumer health data law (SB 370) | None enacted |
| New Mexico | Data Breach Notification Act | Address confidentiality program | Bills introduced, none enacted |
| New York | SHIELD Act (data security + breach) | Child Data Protection Act (2025); strong UDAP | NY Privacy Act pending |
| North Carolina | Identity Theft Protection Act | Free security freezes | Bills introduced, none enacted |
| North Dakota | N.D. Cent. Code § 51-30 | None noted | None enacted |
| Ohio | Ohio Rev. Code § 1349.19 | Data Protection Act safe harbor | Personal Privacy Act reintroduced |
| Oklahoma | Security Breach Notification Act | Address confidentiality program | OCDPA effective Jan 2027 |
| Pennsylvania | Breach of Personal Information Notification Act | Address confidentiality program | Consumer Data Privacy Act introduced |
| South Carolina | S.C. Code Ann. § 39-1-90 | Judicial/LE Personal Privacy Protection Act (2026) | None enacted |
| South Dakota | S.D. Codified Laws § 22-40-19 | Address confidentiality program | None enacted |
| Vermont | Breach notification statute | Data broker registration law (nation's first); Minors' Age-Appropriate Design Code | VDPSA effective Jan 2028 |
| Washington | RCW 19.255.010 breach notification | My Health My Data Act (consumer health data); biometric law (RCW 19.375) | WA Privacy Act repeatedly failed |
| West Virginia | W.Va. Code § 46A-2A-101 | Daniel's Law-style address protection | None enacted |
| Wisconsin | Wis. Stat. § 134.98 | Judicial privacy (Wis. Stat. § 757.07) | WI Data Privacy Act introduced |
| Wyoming | Wyo. Stat. Ann. § 40-12-501 | Address confidentiality program | Bills introduced, none enacted |
Data as of July 2026. The "upcoming law" column reflects legislation enacted but not yet in effect, or active legislative efforts. Sources: IAPP US State Privacy Legislation Tracker, individual state AG offices, and the statutes cited.
State law doesn't have to be your only protection. A free scan shows which data brokers have your personal information. Delist files opt-outs on your behalf under federal and cross-state rights, then keeps checking for data that comes back.
Check your exposure free →What you can still do
You still have recourse. These steps work regardless of where you live.
Use California's CCPA against national brokers
Most large data brokers meet California's CCPA thresholds (annual revenue over $25 million, or buying or selling the data of 100,000 or more consumers). These businesses must honor deletion and opt-out requests from any consumer whose data they hold. You don't need to be a California resident to submit a request, though the broker is only obligated to honor it under CCPA if you are. In practice, most national brokers process requests from all states because it's simpler than filtering by geography.
Enable Global Privacy Control (GPC)
The Global Privacy Control is a browser-level signal that tells websites you don't want your data sold or shared. California requires CCPA-covered businesses to honor it, and Colorado requires it for CPA-covered businesses. Major browsers (Firefox, Brave, DuckDuckGo) support it natively; others through extensions. Enabling GPC is a one-time setting that sends a standing opt-out signal to every covered site you visit.
Submit direct opt-out requests
Most data brokers offer an opt-out process, whether or not your state requires it. The process varies by broker: some use a simple web form, others require identity verification by email or mail. The challenge is volume, since your information can appear on dozens of broker sites. A removal service automates these requests and re-files when your data reappears.
Use California DROP (California residents only)
If you live in California, the DELETE Request and Opt-out Platform (DROP) went live January 1, 2026. It lets you submit a single free deletion request covering every registered data broker (roughly 500 as of early 2026). Brokers must process requests every 45 days starting August 1, 2026. DROP only covers California-registered brokers and California residents.
File complaints under existing state law
Even without a comprehensive privacy law, your state's attorney general can pursue deceptive-practice claims against businesses that misrepresent their data handling. If a company's privacy policy says it will honor deletion requests and then ignores them, that is potentially a UDAP violation in every state. File complaints with your state AG's consumer protection division.
Frequently asked questions
Which states have no data privacy law?
As of 2026, 30 states plus D.C. have no comprehensive data privacy law in effect: Alabama, Alaska, Arizona, Arkansas, D.C., Georgia, Hawaii, Idaho, Illinois, Kansas, Louisiana, Maine, Massachusetts, Michigan, Mississippi, Missouri, Nevada, New Mexico, New York, North Carolina, North Dakota, Ohio, Oklahoma, Pennsylvania, South Carolina, South Dakota, Vermont, Washington, West Virginia, Wisconsin, and Wyoming. Four of these (Alabama, Louisiana, Oklahoma, and Vermont) have enacted comprehensive laws that aren't in effect yet. All have breach-notification laws.
Can I still get my data removed from brokers?
Yes. Most national data brokers are covered by California's CCPA regardless of where you live. You can submit opt-out and deletion requests to CCPA-covered brokers from any state. You can also enable the Global Privacy Control in your browser, which California and Colorado require businesses to honor. A data removal service handles these requests for you and re-files when your data reappears.
What protections do I have without a comprehensive privacy law?
Every state has a data breach notification law. Most have consumer protection statutes that prohibit deceptive practices. Some states have additional protections: Illinois has BIPA (biometric privacy), Massachusetts has strong data-security rules, Washington has the My Health My Data Act, and Vermont has a data-broker registration law. What you lack is the right to compel businesses to give you access to, delete, or stop selling your data under your own state's law.
See your exposure, whatever your state law
A free scan shows which data brokers have your personal information. Delist files removals under federal and cross-state rights, so you don't need a state privacy law to start.
Run a free scan →Sources
- IAPP, US State Privacy Legislation Tracker (iapp.org)
- California Consumer Privacy Act (CCPA/CPRA), Cal. Civ. Code § 1798.100 et seq.
- California DELETE Act and DROP platform (cppa.ca.gov)
- Global Privacy Control specification (globalprivacycontrol.org)
- Individual state statutes cited in the table above (verified against official state code databases and AG websites)