State Data Privacy Laws

Stay informed about your privacy rights with our comprehensive guide to state data privacy laws. This page provides a complete overview of the current data protection regulations across U.S. states, helping you understand how your personal information is safeguarded.

Georgia Data Privacy Laws

Several states have enacted major data privacy laws, including California and Virginia. Georgia may follow with new legislation that imposes restrictions on data collection and gives consumers greater control over their data.

One law under consideration recently in the state is the Georgia Privacy Protection Act. Its provisions include:

  • Limitations on the collection and resale of consumer data
  • Rights for consumers to decline collection of their personal data
  • Penalties for organizations that fail to protect consumer data

The prospective law failed to pass the Georgia General Assembly’s 2025-2026 legislative session. However, it may be reintroduced next year.

Data privacy laws are crucial to protect the identities, finances, and personal information of consumers across New York. The state takes a proactive stance on data protection to minimize the impact of data breaches on residents and businesses alike. Because there is no comprehensive federal law governing data privacy, many individual states, including New York, have established their own privacy laws to safeguard consumer data.

As of 2025, New York’s two main data privacy laws include the Stop Hacks and Improve Electronic Data Security Act (SHIELD Act) and the New York Personal Privacy Protection Law (PPPL). However, several other data privacy laws with more comprehensive protections are pending in the state legislature.

Pennsylvania law currently requires businesses to have a detailed information security plan and provide prompt notifications for data breaches.

The Pennsylvania General Assembly is currently considering a privacy bill that would impose additional requirements on businesses and grant consumers greater rights over their data once it is collected.

Maryland’s data privacy laws require organizations to take steps to protect personal data and promptly notify consumers in the event of a breach. A new state law coming into force in 2025 and 2026 will place additional requirements on businesses and provide consumers with more rights regarding their data.

Texas has enacted several strong privacy laws that require businesses to protect consumer data and notify affected individuals if a data breach occurs. If your personal or sensitive information is compromised, these laws may give you the right to take legal action or join a class action lawsuit.

Several Ohio regulations protect consumers from the misuse of their sensitive data. These laws place strict requirements on how entities use your data and their responsibilities if a data breach occurs.

In Illinois, three key laws protect residents’ personal information from unauthorized access and give consumers the right to take legal action if their information is not properly protected. State law protects several types of personal data, including traditional identifiers like Social Security numbers and driver’s license information, as well as other personal information like financial data, biometric data, and health information. Illinois’ three main data privacy laws include:

  • The Illinois Personal Information Protection Act (PIPA)
  • The Illinois Biometric Information Privacy Act (BIPA)
  • The Illinois Insurance Data Security Law

California law requires businesses and government agencies to notify all California residents whose unencrypted personal information was acquired by an unauthorized person. The three main laws that protect consumer privacy in California are the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and the California Data Breach Notification Law.

Under Florida law, businesses, government agencies, and third-party organizations must take reasonable steps to protect and secure consumers’ data if it contains personal information. Additionally, the law requires these entities to notify the government of any security breach affecting more than 500 people statewide within 30 days of discovering the breach. Businesses and organizations that experience data breaches must also provide notice within 30 days to affected individuals whose personal information was accessed. Violations of these laws qualify as unfair or deceptive trade practices.