Article 13 min read

Data Privacy Regulation News Today: 9 Landmark State Laws, Statutory Deadlines, and Enforcement Rules

Sep 12, 2026 22 views
Data Privacy Regulation News Today: 9 Landmark State Laws, Statutory Deadlines, and Enforcement Rules

TL;DR

Today's consumer data privacy regulation news: Delaware enacts HB 380, Louisiana passes the LDPA, Alabama signs the APDPA as the 22nd state, and Montana sunsets cure periods. Here are the 9 critical statutory updates, enforcement dates, and engineering compliance steps.

Table of Contents

    State legislatures across the United States are accelerating consumer data privacy regulation. In September 2026, 22 states maintain active or imminent comprehensive privacy statutes. Delaware enacted major amendments under HB 380, Louisiana passed the LDPA, Alabama adopted the APDPA, and multiple states eliminated statutory cure periods. If your company processes personal data across state lines, these 9 regulatory developments dictate immediate adjustments to your data collection flows, consent banners, and engineering pipelines.

    Today's Data Privacy Regulatory Highlights

    1. Delaware HB 380 Lower Triggers & Minor Consent

    Governor Matt Meyer signed HB 380 into law on September 2, 2026. Effective January 1, 2027, the law expands controller duties, lowers processing thresholds, and requires mandatory universal opt-out processing.

    2. Louisiana & Alabama 22nd State Privacy Law

    Louisiana enacted the LDPA (SB 386) effective January 1, 2027. Alabama Governor Kay Ivey signed HB 351 (APDPA), setting an enforcement date of May 1, 2027.

    3. Enforcement Transitions Cure Period Sunsets

    Montana and New Jersey have eliminated 30-day and 60-day right-to-cure grace periods. State Attorneys General now issue immediate civil monetary penalties up to $50,000 per willful violation.

    Enterprise data privacy regulation compliance command center showing state legislative borders, privacy encryption status, and automated legal audit monitors
    Click to enlarge

    1. Delaware: Governor Meyer Signs HB 380 to Overhaul Consumer Privacy Rules

    On September 2, 2026, Delaware Governor Matt Meyer signed House Bill 380 into law. The statute significantly amends Title 6 of the Delaware Code, revising the Delaware Personal Data Privacy Act (DPDPA) that initially went into effect on January 1, 2025. The revisions take effect on January 1, 2027.

    Lawmakers amended the statute to match updated definitions established in Maryland, Colorado, and California while introducing strict controller requirements:

    • Lower Applicability Thresholds: The law covers any business operating in Delaware or providing products to Delaware residents that processed the personal data of 35,000 consumers during the preceding calendar year (reduced from 50,000), or 10,000 consumers if deriving over 20% of gross revenue from selling personal data.
    • Universal Opt-Out Mechanism (UOOM) Mandate: Controllers must process browser-based universal opt-out signals, including the Global Privacy Control (GPC), without requiring consumers to complete manual verification forms.
    • Strict Protections for Minors (Ages 13 to 17): Controllers may not sell personal data, process personal data for targeted advertising, or profile consumers aged 13 through 17 without affirmative opt-in consent.
    • Third-Party Processor Contracts: Contracts must require downstream processors to submit to independent technical audits every 24 months.
    State / Jurisdiction Enacted Statute Effective Date Applicability Threshold Cure Period Statutory Fine Limit
    Delaware HB 380 / Title 6 January 1, 2027 35,000 consumers or 10,000 + data sales 60 days (discretionary) $10,000 per violation
    Louisiana SB 386 (LDPA) January 1, 2027 100,000 consumers or 25,000 + 50% data sales 30 days $7,500 per violation
    Alabama HB 351 (APDPA) May 1, 2027 25,000 consumers + 50% data revenue or 100k 45 days $5,000 per violation
    Indiana ICDPA / IC 24-15 January 1, 2026 100,000 consumers or 25,000 + 50% sales 30 days $7,500 per violation
    Montana SB 384 Amendments October 1, 2025 50,000 consumers or 25,000 + 25% sales None (Sunset) $10,000 per violation
    New Jersey N.J. Stat. § 56:8-166.4 January 15, 2025 100,000 consumers or 25,000 + data sales Expired July 2025 $10,000 – $20,000
    Rhode Island SB 2500 / HB 7787 January 1, 2026 35,000 consumers or 10,000 + 20% sales None explicit $10,000 per violation

    2. Louisiana: Passage of Senate Bill 386 (Louisiana Data Privacy Act)

    The Louisiana State Legislature enacted the Louisiana Data Privacy Act (LDPA) via Senate Bill 386. The law takes direct effect on January 1, 2027, giving commercial enterprises doing business in Louisiana a 4-month preparation window.

    The LDPA combines consumer rights from the California Consumer Privacy Act (CCPA) with the operational structure of Connecticut's data protection statute. Covered entities include businesses that control or process the personal data of at least 100,000 Louisiana residents, or at least 25,000 residents while generating 50% or more of gross revenue from data sales.

    Consumers in Louisiana obtain 5 core statutory rights under the LDPA:

    • Right of Confirmation and Access: Confirm whether a controller is processing personal data and obtain a copy of that data in a portable format.
    • Right to Correct: Correct factual inaccuracies in stored personal records.
    • Right to Delete: Request deletion of personal data collected from or obtained about the consumer.
    • Right to Opt Out: Opt out of processing for targeted advertising, the sale of personal data, and profiling for decisions that produce legal or significant effects.
    • Right Against Discrimination: Protection against service denial, price discrimination, or penalty fees when exercising statutory rights.
    Comprehensive matrix of US state consumer data privacy regulatory frameworks comparing Delaware, Louisiana, Alabama, and Indiana compliance statuses
    Click to enlarge

    3. Alabama: Governor Ivey Signs House Bill 351 (APDPA)

    Governor Kay Ivey signed House Bill 351 into law, making Alabama the 22nd state to enact a comprehensive consumer data privacy act. The Alabama Personal Data Protection Act (APDPA) takes effect on May 1, 2027.

    The APDPA adopts specific provisions that distinguish it from the standard Virginia-style privacy framework:

    • Monetary "Sale" Definition: Alabama restricts the statutory definition of "sale" to exchanges of personal data for direct monetary consideration. It explicitly excludes transfers for non-monetary consideration, sparing businesses that exchange analytics cookies without direct financial compensation.
    • Absence of Mandatory DPA Filing: Unlike Virginia, Colorado, and Connecticut, the APDPA does not require formal Data Protection Assessments (DPAs) to be documented on regular annual schedules. Controllers must still demonstrate reasonable administrative and technical safeguards.
    • 45-Day Response Timeline: Controllers must respond to consumer requests within 45 days. The law allows a single 45-day extension when reasonably necessary given the complexity and volume of requests.

    4. Indiana: Attorney General Releases Compliance Roadmap for January 2026 Enforcement

    With the Indiana Consumer Data Protection Act (ICDPA, Indiana Code 24-15) taking effect on January 1, 2026, the Indiana Office of the Attorney General published an official compliance roadmap styled as the Consumer Data Privacy Bill of Rights. The document details enforcement priorities for state prosecutors.

    The guidance specifies strict enforcement across 4 technical operational categories:

    • Purpose Limitation: Controllers may not retain or process personal data for reasons incompatible with disclosed processing purposes without obtaining express consumer consent.
    • Sensitive Data Opt-In: Processing sensitive data (including biometric identifiers, genetic data, precise geolocation data within a radius of 1,750 feet, and data from children under 13) requires clear, affirmative opt-in consent.
    • Data Minimization Standards: Controllers must restrict data collection to what is strictly adequate, relevant, and reasonably necessary for disclosed purposes.
    • 30-Day Cure Notice: Before filing a civil lawsuit, the Indiana AG must provide a 30-day written notice. If the controller cures the violation and provides an express written statement within 30 days, no civil penalties will follow.

    5. Montana: Amendments Sunset the 60-Day Cure Period

    The Montana Consumer Data Privacy Act (SB 384) took effect on October 1, 2024. Montana lawmakers approved amendments that eliminate the statutory 60-day right-to-cure period. The cure period sunset takes full effect on October 1, 2025.

    Companies facing an investigation in Montana will no longer receive a mandatory 60-day warning to fix broken opt-out buttons or missing privacy disclosures before fines are calculated. The Montana Department of Justice can issue immediate civil penalties up to $10,000 per violation under the Montana Unfair Trade Practices and Consumer Protection Act.

    The amendments also lower the threshold to businesses handling 50,000 Montana consumers (down from previous exemptions) and mandate support for universal opt-out signals without intermediary landing pages.

    6. New Jersey: NJDPA Transition and Penalty Enforcement (N.J. Stat. § 56:8-166.4)

    The New Jersey Data Protection Act took effect on January 15, 2025. The statutory 18-month grace period established under N.J. Stat. § 56:8-166.4 expired in July 2025. The New Jersey Division of Consumer Affairs has transitioned into active audit enforcement.

    Enforcement reviews focus on retail e-commerce stores, data brokers, and financial technology platforms. Regulators inspect whether websites drop tracking pixels before obtaining cookie banner consent and whether mobile apps transmit precise device location identifiers without conspicuous opt-in disclosures. Violations carry penalties between $10,000 and $20,000 per statutory occurrence.

    7. Rhode Island: Data Transparency and Privacy Protection Act (Effective Jan 1, 2026)

    Passed as SB 2500 and HB 7787, the Rhode Island Data Transparency and Privacy Protection Act takes effect on January 1, 2026. The law introduces a transparency requirement absent from most other state statutes.

    Under Rhode Island's disclosure rule, controllers that sell or share personal data must disclose in their privacy notice the specific commercial entities and third parties to whom data has been sold or transferred, instead of broad categories like "analytics vendors" or "marketing partners." Controllers must also provide an active email address or online mechanism for consumers to reach privacy personnel directly.

    8. California: CPPA Sweeps Focus on Employee Data and Automated Decisionmaking (ADMT)

    The California Privacy Protection Agency (CPPA) and California Attorney General Rob Bonta expanded active enforcement sweeps targeting employee data and automated decisionmaking technology under the CCPA/CPRA.

    Following the expiration of the statutory personnel and business-to-business (B2B) exemptions, California employers must deliver full CCPA compliance for workforce data:

    • Job Applicant and Employee DSARs: Employees and job candidates can submit requests to access, correct, and delete internal performance notes, compensation histories, and interview assessments.
    • Automated Decisionmaking Technology (ADMT): The CPPA completed rulemaking on ADMT. Employers using algorithmic profiling to screen job applications, monitor keystrokes, or determine promotions must provide pre-use notices and opt-out mechanisms.
    • Connected Vehicle and IoT Investigations: The California AG issued investigative subpoenas to 14 automotive manufacturers inspecting location telemetry sharing and voice recording data retention practices.

    9. Federal & International Frameworks: FTC Biometric Crackdown and DPF Audits

    At the federal level, the American Privacy Rights Act (APRA) remains pending in Congress. In the absence of an overarching federal statute, federal and international regulators are enforcing privacy standards through existing regulatory powers:

    • FTC Section 5 Enforcement: The Federal Trade Commission issued consent orders against digital health applications and telemetry platforms, holding that unauthorized sharing of sensitive health or biometric data constitutes an unfair business practice under Section 5 of the FTC Act.
    • COPPA Revisions: The FTC finalized amendments to the Children's Online Privacy Protection Act (COPPA) Rule, restricting edtech software from conditioning classroom access on commercial tracking consent.
    • EU-US Data Privacy Framework (DPF) Reviews: The European Commission and US Department of Commerce concluded their annual review of the DPF, confirming compliance mechanisms while establishing mandatory commercial dispute resolution audits.
    Software engineering data compliance pipeline dashboard displaying DSAR tracking, right to delete requests, and automated audit logs
    Click to enlarge

    10. Engineering Architecture: 4 Technical Requirements for 2026 Privacy Compliance

    State data privacy laws establish concrete software engineering mandates. Legal notices alone do not satisfy regulatory scrutiny. Development and operations teams must deploy these 4 technical controls across their systems:

    1. Universal Opt-Out Signal Processing (Sec-GPC Headers)

    Delaware HB 380, California CCPA, Colorado SB 21-190, and Montana SB 384 require automated recognition of browser opt-out signals. Web servers and edge routers must inspect incoming HTTP request headers for the Sec-GPC directive and suppress advertising cookies without showing confirmation modals:

    // Express / Node.js Middleware for Universal Opt-Out (GPC) app.use((req, res, next) => { const gpcSignal = req.headers['sec-gpc']; if (gpcSignal === '1') { res.cookie('us_privacy_optout', 'true', { maxAge: 31536000000, httpOnly: false }); req.consumerOptedOut = true; // Suppress analytics tracking pixels and ad network syncs } next(); });

    2. Automated DSAR & Right-to-Delete Data Pipeline

    Controllers must execute deletion requests across all primary relational stores, document databases, and analytical lakes within 45 days. Production systems must execute asynchronous deletion jobs with verifiable JSON audit receipts:

    { "dsar_request_id": "req-del-2026-9042", "consumer_state": "Delaware", "statute_code": "DE_HB380", "verified_identifier_hash": "e9b21f...7c14", "action_executed": "RIGHT_TO_DELETE_PURGE", "primary_db_records_purged": 14, "analytics_warehouse_purged": 128, "downstream_processors_notified": ["crm_salesforce", "marketing_hubspot"], "completed_timestamp_utc": "2026-09-12T10:14:02Z", "retention_exempt_tax_records": 1 }

    Do not drop third-party advertising or profiling scripts prior to consumer consent in opt-in jurisdictions (New Jersey, Delaware minor provisions, and EU cross-border visitors). Implement strict tag firing triggers inside Google Tag Manager or your consent management platform (CMP) that block script loading until explicit consent records register in localStorage.

    4. Immutable Privacy Audit Logging

    State regulatory audits require proof of compliance. Retain immutable transaction logs recording consumer consent timestamp, IP address hash, consent preferences, and processor confirmation receipts for at least 24 months to defend against statutory enforcement actions.

    11. 30-Day Engineering & Legal Compliance Checklist

    Engineering and legal teams can follow this structured 4-week compliance roadmap to address multi-state exposures:

    Week Focus Area Required Tasks Deliverable
    Week 1 (Days 1–7) State Threshold Audit Audit consumer records by state. Compare user counts against Delaware (35,000), Louisiana (100,000), and Alabama (100,000) thresholds. State Exposure Matrix
    Week 2 (Days 8–14) GPC & Opt-Out Implementation Configure web servers to inspect Sec-GPC headers and automatically silence tracking pixels without modal prompts. GPC Listener Verification
    Week 3 (Days 15–21) Minor Consent & Privacy Notice Update Update website privacy policy with Rhode Island third-party disclosures. Add opt-in checkpoints for users aged 13–17 in Delaware. Updated Privacy Policy & Consent Modal
    Week 4 (Days 22–30) Processor Contract Amendments Review downstream vendor contracts. Insert mandatory 24-month audit terms and consumer deletion notification duties. Executed Vendor Data Protection Addenda

    12. 2026–2027 Statutory Compliance Calendar

    Track these verified enforcement dates and statutory milestones across state jurisdictions:

    • October 1, 2025: Montana Consumer Data Privacy Act right-to-cure period sunsets permanently. Immediate penalties apply.
    • January 1, 2026: Indiana Consumer Data Protection Act (ICDPA) takes effect. AG begins active investigations.
    • January 1, 2026: Rhode Island Data Transparency and Privacy Protection Act takes effect, requiring named third-party disclosures.
    • January 15, 2026: New Jersey Data Protection Act full enforcement audits launch following cure period expiration.
    • January 1, 2027: Delaware HB 380 amendments take effect, lowering thresholds to 35,000 consumers and mandating GPC processing.
    • January 1, 2027: Louisiana Data Privacy Act (LDPA, SB 386) takes effect for covered commercial entities.
    • May 1, 2027: Alabama Personal Data Protection Act (APDPA, HB 351) enforcement begins across Alabama.

    Frequently Asked Questions

    What are the key changes in Delaware HB 380 signed in September 2026?

    Delaware HB 380 lowers the statutory applicability threshold from 50,000 to 35,000 consumers, mandates automatic processing of Universal Opt-Out Mechanisms (such as Global Privacy Control) without requiring manual forms, prohibits selling or profiling data of minors aged 13 through 17 without affirmative opt-in consent, and requires 24-month audit terms in third-party processor contracts. The amendments take effect January 1, 2027.

    How many US states have enacted comprehensive consumer data privacy laws?

    With Alabama enacting House Bill 351 (the Alabama Personal Data Protection Act) in 2026, 22 states have enacted comprehensive consumer privacy statutes. These states include California, Virginia, Colorado, Utah, Connecticut, Iowa, Indiana, Tennessee, Texas, Florida, Montana, Oregon, Delaware, New Hampshire, New Jersey, Kentucky, Nebraska, Maryland, Minnesota, Rhode Island, Louisiana, and Alabama.

    What happens when a state privacy law cure period sunsets?

    During an active cure period, regulators must give a company written notice of an alleged violation (typically 30 to 60 days) to fix the issue before issuing fines. When a cure period sunsets (as in Montana and New Jersey), state Attorneys General can immediately file civil lawsuits and impose statutory fines up to $10,000 to $20,000 per violation without giving prior warning or grace periods.

    Does the Alabama Personal Data Protection Act require formal data protection assessments?

    The Alabama Personal Data Protection Act (HB 351) departs from the Virginia and Colorado models by omitting mandatory standalone Data Protection Assessments (DPAs). Businesses must maintain reasonable administrative, technical, and physical safeguards, but they do not face periodic state filing mandates for risk assessments.

    How must engineering teams handle the Global Privacy Control (GPC)?

    Engineers must configure edge servers and consent management platforms to detect the HTTP header Sec-GPC: 1 or the JavaScript property navigator.globalPrivacyControl === true. When detected, the application must automatically suppress third-party marketing tags, disable targeted ad pixels, and register a valid opt-out preference without redirecting the user to multi-step forms.

    What is Rhode Island's specific third-party disclosure requirement?

    Under Rhode Island's Data Transparency and Privacy Protection Act (effective January 1, 2026), controllers cannot rely solely on generic category descriptions (such as "marketing affiliates" or "service vendors") in their privacy notices. If a controller discloses or sells personal data, the privacy notice must list the specific commercial third parties receiving that information.

    Ayesha Hussain - Editor and Research Lead

    Written by Ayesha Hussain

    Editor and Research Lead · Cubbbix

    Ayesha Hussain tracks state and international data privacy statutes, algorithmic accountability regulations, and technical compliance architecture. Her engineering and legal analysis helps software teams implement compliant data pipelines and privacy workflows.

    Connect on LinkedIn · Updated September 12, 2026

    Was this article helpful?

    Comments

    Loading comments...