The United States has no comprehensive federal consumer privacy law. What it has instead is a growing patchwork of state statutes — roughly twenty comprehensive privacy laws are now in effect or scheduled across states led by California, Virginia, Colorado, Connecticut, Utah, and Texas — each granting consumers rights to access, delete, and correct their data and to opt out of targeted advertising and data sales, with different thresholds, exemptions, and enforcement dates. Your practical rights depend on where you live and, in some states, whether the law's thresholds apply to the company holding your data. Here is the map and what you can actually do with it.
KAJ News publishes information, not legal advice.
How did we get a patchwork instead of a law?
Congress has debated comprehensive privacy bills repeatedly without passing one — the American Data Privacy and Protection Act advanced furthest in 2022 before stalling — leaving states to fill the vacuum. California moved first after its 2018 consumer privacy ballot initiative became the CCPA, then hardened into the CPRA with a dedicated enforcement agency. Virginia (2021), Colorado and Connecticut (2022), Utah and others followed with a broadly similar model law; states like Texas, Oregon, Montana, and Iowa joined in successive waves through 2024-2026 effective dates. The result is a de facto national standard: most large companies apply the strictest common denominator nationwide rather than building fifty state-by-state experiences, which is why your rights often work even in states without a law.
What do these laws give you?
The shared core, with variations:
- Right to know and access — what personal data a company holds about you, in a usable format.
- Right to delete — with broad exceptions for legal obligations, security, and completing transactions.
- Right to correct inaccurate data.
- Right to opt out of targeted advertising, the sale of data, and (in the stronger states) profiling that produces significant decisions.
- Non-discrimination — companies cannot punish you with worse service or prices for exercising rights.
California goes further than the pack: the Delete Act's state-run deletion mechanism, opt-out preference signals it requires businesses to honor, and agency rulemaking on risk assessments and automated decision-making. Colorado and Connecticut add universal opt-out signals and data-protection-assessment requirements. Enforcement is by state attorneys general (and California's agency), with penalty structures that matter mostly to businesses.
What is not covered?
Real gaps remain. Most state laws exempt or partially exempt employee and business-to-business data — a long-running criticism. They apply only above thresholds (typically revenue or numbers of consumers whose data is processed), which excludes many small data brokers — precisely the least scrupulous operators — although California's Delete Act registration regime reaches any broker doing business with Californians. Sensitive-data categories (health, precise location, sexual orientation) get special treatment in most states but the definitions vary. And the biggest category of all — the collection itself — is regulated by notice and consent mechanics rather than hard limits; nothing in the state model stops a compliant company from collecting a great deal, provided it discloses and honors opt-outs.
How do you actually use these rights?
- Find the privacy page. Regulated companies must provide a "Do Not Sell or Share My Personal Information" link and a rights-request process — usually a web form or email listed in the policy.
- Submit the request. Access, deletion, correction, and opt-out; companies generally must respond within 45 days.
- Use Global Privacy Control. A browser signal that the stronger states legally require businesses to honor as an opt-out of sale and sharing — set it once, and it covers compliant sites automatically.
- California residents: use the Delete Act's registered deletion mechanism to reach registered data brokers in bulk.
- Escalate failures. If a covered company ignores a valid request, complaints go to your state attorney general's consumer protection office — enforcement actions have already been brought under several of these laws.
What is likely next?
The trajectory through 2026: more states joining (the count keeps climbing), California's agency tightening rules on data brokers, risk assessments, and automated decision-making, and continued congressional drifting. The patchwork's costs — compliance complexity for business, uneven protection for consumers — keep the federal-debate pressure on, but the state laws keep hardening in the meantime. For individuals, the practical stance is unchanged: exercise the rights that exist in your state, lean on the de facto national adoption of the strictest rules, and remember that deletion rights and opt-outs are maintenance, not a one-time fix — the data economy re-collects what you do not keep opting out of.
For more context, read AI robocalls: the rules that exist, the ones coming, and what actually works.
For more context, read school ransomware attacks.
For more context, read cybersecurity skills shortage.

