State Privacy Laws
What is State Privacy Laws?
Data protection regulations enacted by individual US states to protect residents' personal information, each with varying requirements and rights.
Terms that appear alongside state privacy laws
Each of these is named in at least one of the same controls as state privacy laws. The number is how many controls name both.
- gdpr 24 shared controls
- ccpa 21 shared controls
- hipaa 15 shared controls
- compliance 14 shared controls
- glba 12 shared controls
- consent 11 shared controls
- data subject 11 shared controls
- nist 10 shared controls
Frameworks that govern state privacy laws
What the standards actually require on state privacy laws
Requirements naming state privacy laws across 6 standards, quoted from the control text.
Per Iowa Code 715D.8 + 715D.9 ICDPA enforcement is exclusively vested in the Iowa Attorney General with no private right of action and offers the LONGEST cure period among US state privacy laws (90 days vs 30 days in Virginia/Indiana/Utah + 60 days original in...
ICDPA-Enforcement-90DayCure-AttorneyGeneralOnly-NoPrivateRight-CivilPenalties-7500-PerViolation-Longest-Cure · Iowa CDPA Enforcement - Attorney General Exclusive + 90-Day Cure Period (LONGEST among US State Privacy Laws) + No Private Right of Action + Civil Penalties Up to USD 7500 Per Violation →Coordination positions INCDPA within the broader US and international privacy regulatory landscape. (1) US State Privacy Law Patchwork: 20+ comprehensive US state privacy laws as of 2026 (California CCPA/CPRA + Virginia VCDPA + Colorado CPA + Utah UCPA + Conne...
INCDPA-Coord-USStatePrivacy-VCDPA-CPA-CTDPA-CCPA-Federal-FTC-DPDP-GDPR-International · Indiana CDPA Coordination - US State Privacy Laws (Virginia/Colorado/Connecticut/Utah/Texas/Iowa+) + Federal Sectoral (HIPAA/GLBA/FCRA/FERPA/COPPA) + FTC Section 5 + GDPR + India DPDP + International Privacy Frameworks →Florida FDBR coordination with the rapidly-growing US state privacy law ecosystem. COMPARABLE STATE LAWS (as of 2026 - approximately 20 comprehensive state privacy laws): California (CCPA + CPRA + 2018/2020) + Virginia VCDPA (2021) + Colorado CPA (2021) + Conn...
FDBR-Coord-CCPA-CPRA-State-Privacy · Coordination with US State Privacy Laws (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, ICDPA, TIPA, RIDTPPA, WDPA, MMCL, OCPA, NHDPA, MDPA, TDPSA, KCDPA, NJDPA, DPDPA, INCDPA) →GLBA coordination with related US privacy + financial frameworks. (a) FCRA (FAIR CREDIT REPORTING ACT, 15 USC 1681) - regulates consumer-reporting agencies + furnishers of information + users of consumer reports;
GLBA-Coordination-FCRA-HIPAA-CCPA-Sectoral · GLBA Coordination with FCRA, ECOA, HIPAA, CCPA, State Privacy Laws and Sectoral Frameworks →FTC Safeguards Rule crosswalk to comprehensive cybersecurity + privacy frameworks. NIST CSF 2.0 mapping: GOVERN (Qualified Individual + Board reporting + program governance) + IDENTIFY (314.4(b) risk assessment + 314.4(c)(2) data inventory) + PROTECT (314.4(c)...
FTC-Safeguards-Crosswalk-NIST-ISO-SOC · Crosswalk to NIST CSF 2.0, NIST SP 800-53, ISO 27001 and SOC 2 →Global CBPR Forum US multi-state adequacy mechanism. US STATE PRIVACY LAW RECOGNITION OF CBPR/PRP: as of 2026, many US state privacy laws explicitly recognize CBPR or binding/enforceable cross-border programs as adequacy mechanism + reducing compliance complex...
CBPR-Implementation-MultiState-AdequacyMechanism · Global CBPR Forum: US Multi-State Adequacy Mechanism, State-by-State Recognition →Questions people ask about state privacy laws
What is State Privacy Laws?
Why is State Privacy Laws important for compliance?
Which compliance frameworks address State Privacy Laws?
Where can I learn more about State Privacy Laws?
See how State Privacy Laws applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.