How to Request Your Personal Data: US Privacy Rights by State
Independently fact-checked against primary sources (last audited September 12, 2026). · 37 primary sources cited on this page. How we verify our legal content

A U.S. personal-data request starts with two questions: who holds the records, and which law covers that holder? State consumer privacy laws govern some private businesses. Health, credit, school, and government records use different federal or state routes. Residence alone does not establish a right or make an organization subject to a statute.
Information last verified from the cited sources on September 11, 2026. This article has not yet been reviewed by a licensed lawyer.
Jurisdiction scope: This guide covers selected federal record-access routes and all 50 states plus the District of Columbia as of September 11, 2026. It does not establish eligibility, catalog every exemption, or classify the 25 unresolved jurisdictions as lacking access rights.
Which US Data-Access Law Applies?
The correct law usually follows the holder and the reason the record exists. A private retailer's customer profile, a hospital chart, a credit file, a school record, and a federal agency file do not share one U.S. request procedure. Start with the organization's identity and privacy notice, then match the data to a positively identified statute.

A comprehensive state privacy law may provide confirmation, access, correction, deletion, or portability when it covers both the individual and the controller. “Controller” generally means the entity that determines why and how personal data is processed, but each statute supplies its own definition and thresholds. A resident may fall outside a consumer definition when acting in an employment or business context. An organization may be excluded because of its size, sector, nonprofit status, government role, or another statutory rule.
Data exemptions matter too. A law may exclude an entity, only data regulated by another law, or processing in a specified context. Financial, health, insurance, education, employment, and government records often require a different route. The fact that a business has a request form does not prove that every listed right applies to every submission.
This guide uses four labels. “Operative” means the reviewed comprehensive framework has taken effect. “Future” means it was enacted but its relevant rights are not yet operative. “Targeted” identifies a narrower right that should not be compared as access to all personal data. “Unclassified” means this review does not make a comprehensive-law classification, without implying that no other access right exists.
Health, Credit, School, and Government Records Use Different Routes
Federal sector laws answer different questions and should remain separate from the state consumer table.
| Record and holder | Possible route | Core boundary in the cited source |
|---|---|---|
| Protected health information held by a covered entity | 45 C.F.R. § 164.524 and HHS guidance | Access concerns a designated record set and remains subject to exclusions |
| File held by a consumer reporting agency | 15 U.S.C. § 1681g | The requester must make a request and provide proper identification |
| Education records at a covered school | 34 C.F.R. § 99.10 | Parents and eligible students generally receive inspection within no more than 45 days |
| Federal agency records | FOIA, 5 U.S.C. § 552 | Concerns agency records and is subject to exemptions and agency procedures |
| Records about oneself in a federal system of records | Privacy Act, 5 U.S.C. § 552a | Applies through the Act's system-of-records structure and exemptions |

HIPAA generally requires a covered entity to act on a covered access request within 30 calendar days and permits one written 30-day extension in the circumstances described by the rule. FCRA requires a consumer reporting agency, upon request and proper identification, to disclose the information in the consumer's file subject to the statute. FERPA uses its own requester definitions and outside 45-day inspection period.
FOIA concerns federal agency records, while the Privacy Act can supply a route to records about an individual in a federal system of records. State and local agencies follow their own public-records and privacy statutes. A request for government records such as 911 calls therefore raises a different question from a consumer request to a private controller.
Where a Comprehensive State Consumer Access Right Applies
As of September 11, 2026, this guide identifies 20 operative comprehensive state frameworks: California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia. This is a status count, not a promise that every resident or business falls within those laws.

Alabama, Louisiana, Oklahoma, and Vermont enacted future frameworks. Alabama's relevant provisions take effect May 1, 2027. Louisiana and Oklahoma take effect January 1, 2027. Vermont's relevant consumer privacy subchapter takes effect January 1, 2028, according to Act 145. A request filed before an effective date cannot rely on a future right as though it were already operative.
Nevada and Washington stay in a separate targeted category. The recovered official Nevada text confirms an opt-out for certain covered sales by online operators, with its own response structure, rather than the general confirmation-and-access right compared here. Washington's My Health My Data Act covers consumer health data and does not create access to every category of personal data.
Common coverage questions include the consumer's role, the controller's revenue or data-volume threshold, whether the entity conducts business in or targets the state, and whether an exemption applies. Government bodies, financial institutions or data, HIPAA-regulated entities or information, insurers, nonprofits, higher education, and employment-context data receive different treatment across statutes. The controlling text must answer each element.
Florida shows why labels need detail. Fla. Stat. § 501.702(9) covers a qualifying for-profit entity that exceeds $1 billion in global annual gross revenue and satisfies at least one of three branches: at least 50 percent of global gross annual revenue from online-ad sales; operation of the specified smart-speaker or voice-assistant service; or operation of an app store or digital distribution platform offering at least 250,000 applications. The definition also reaches entities within the statute's control relationship. Calling Florida broadly applicable would omit those gates.
How to Submit a Verifiable Consumer Access Request
Use the method identified in the covered organization's privacy notice or official instructions. This is a practical checklist drawn from common request provisions, not a universal statutory formula.
- Identify the account, transaction, device, service, or other relationship connected to the data.
- Name the positively identified access or confirmation right and describe the data sought clearly enough to locate it.
- Request the copy or portable format the governing law makes available.
- Provide only reasonably requested authentication information through a secure channel. Avoid sending unnecessary identity documents through ordinary email.
- Save the submitted request, date, delivery receipt, confirmation number, authentication exchanges, extension notice, and response.

Authorized-agent and parental requests follow statute-specific rules. A controller may explain that it cannot authenticate the requester or connect the person to the requested data. That response is not necessarily a final denial. The next step may be completion of a secure verification method.
Combining unrelated theories can obscure the request. A hospital records request, credit-file disclosure, school inspection, government public-record request, and consumer privacy request may need separate recipients and proof. If the organization cites an exemption or declines action, ask for the written reason and any appeal instructions required by the applicable law.
Response Deadlines, Extensions, Copies, and Fees
There is no single national deadline for personal-data access. Many operative comprehensive laws use 45 days for the initial response and allow one additional 45-day period when reasonably necessary, commonly with notice and reasons during the original period. The statute still determines when the period begins, whether it uses calendar days, and what counts as a completed response.

Iowa uses a 90-day initial period under Iowa Code § 715D.3. Florida uses 45 days initially and permits one additional 15-day extension when reasonably necessary with timely notice under Fla. Stat. § 501.706. California's right-to-know system has its own acknowledgment, verification, frequency, lookback, and disclosure rules in the current statute and regulations.
An acknowledgment is not the completed response. An extension notice is not necessarily a denial. Some laws permit a fee or refusal for requests that are manifestly unfounded, excessive, technically infeasible, or repetitive, but the wording and burden vary. Free-request frequency and delivery format also differ.
Calendar the date the controller received the request and preserve any confirmation. If the organization asks for additional authentication, retain that exchange and the date supplied. The chronology determines whether an appeal or regulator complaint route has matured.
What to Do After a Denial or No Response
Read the stated reason before choosing the next route. A controller may cite failed authentication, an entity or data exemption, excessive requests, lack of control over the data, or another statutory ground. A curable identification problem can be addressed through the secure channel without assuming that the controller has finally denied the right.
Where the governing law provides an internal appeal, follow the identified method and preserve proof of delivery. Florida requires a conspicuously available appeal process similar to the original request method. Under Fla. Stat. § 501.707, the controller must provide a written result and reasons within 60 days after receiving the appeal. The Florida source also directs the controller to provide the statutory contact route when the appeal is denied.
Vermont's future law provides another 60-day appeal result under enacted § 2415d(d), but that consumer privacy subchapter does not take effect until January 1, 2028. Current Connecticut text confirms a 60-day appeal result, while recovered official New Jersey text confirms 45 days. These examples do not create a universal appeal deadline.

If an appeal remains denied, use only the regulator, attorney-general, complaint, or court route the applicable law supports. Enforcement authority, cure provisions, and private remedies vary. The privacy complaint guide explains how to organize the record, while the data deletion guide addresses a separate consumer right.
Consumer Data-Access Rights in All 50 States and DC
Each section links to a state privacy guide. The operative and future rows identify only the access process and timing supported by the cited authority. They do not establish eligibility or present a complete exemption inventory. Targeted rows remain separate, and unclassified rows make no no-law claim.
Alabama
Future comprehensive framework, effective 2027-05-01. Alabama Personal Data Protection Act, Act 2026-552, Ala. Code § 8-44-5. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Alabama privacy guide.
Alaska
Unclassified in this comparison. This article makes no absence-of-law claim. Use the Alaska privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right.
Arizona
Unclassified in this comparison. This article makes no absence-of-law claim. Use the Arizona privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right.
Arkansas
Unclassified in this comparison. This article makes no absence-of-law claim. Use the Arkansas privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right.
California
Operative comprehensive framework, since 2020-01-01; current statute edition effective 2026-01-01. California Consumer Privacy Act as amended, Cal. Civ. Code §§ 1798.100, 1798.110, 1798.115; implementing regulations. Response: 45 days; possible extension: 45 days. Coverage and exemptions still control. See the California privacy guide.
Colorado
Operative comprehensive framework, since 2023-07-01. Colorado Privacy Act, Colo. Rev. Stat. § 6-1-1306; 4 CCR 904-3. Response: 45 days; possible extension: 45 days; appeal result: 45 days. Coverage and exemptions still control. See the Colorado privacy guide.
Connecticut
Operative comprehensive framework, since 2023-07-01. Connecticut Data Privacy Act, Conn. Gen. Stat. § 42-518. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Connecticut privacy guide.
Delaware
Operative comprehensive framework, since 2025-01-01. Delaware Personal Data Privacy Act, 6 Del. C. § 12D-104. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Delaware privacy guide.
District of Columbia
Unclassified in this comparison. This article makes no absence-of-law claim. Use the District of Columbia privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right.
Florida
Operative comprehensive framework, since 2024-07-01. Florida Digital Bill of Rights, Fla. Stat. §§ 501.705-.707. Response: 45 days; possible extension: 15 days; appeal result: 60 days. Coverage and exemptions still control. See the Florida privacy guide.
Georgia
Unclassified in this comparison. This article makes no absence-of-law claim. Use the Georgia privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right.
Hawaii
Unclassified in this comparison. This article makes no absence-of-law claim. Use the Hawaii privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right.
Idaho
Unclassified in this comparison. This article makes no absence-of-law claim. Use the Idaho privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right.
Illinois
Unclassified in this comparison. This article makes no absence-of-law claim. Use the Illinois privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right.
Indiana
Operative comprehensive framework, since 2026-01-01. Indiana Consumer Data Protection Act, Ind. Code § 24-15-3-1. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Indiana privacy guide.
Iowa
Operative comprehensive framework, since 2025-01-01. Iowa Consumer Data Protection Act, Iowa Code § 715D.3. Response: 90 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Iowa privacy guide.
Kansas
Unclassified in this comparison. This article makes no absence-of-law claim. Use the Kansas privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right.
Kentucky
Operative comprehensive framework, since 2026-01-01. Kentucky Consumer Data Protection Act, KRS 367.3615. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Kentucky privacy guide.
Louisiana
Future comprehensive framework, effective 2027-01-01. Louisiana Data Privacy Act, Act 502 (SB 386), La. R.S. 51:1780.3. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Louisiana privacy guide.
Maine
Unclassified in this comparison. This article makes no absence-of-law claim. Use the Maine privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right.
Maryland
Operative comprehensive framework, since 2025-10-01. Maryland Online Data Privacy Act, Md. Code, Commercial Law § 14-4605. Response: 45 days; possible extension: 45 days; appeal result: 45 days. Coverage and exemptions still control. See the Maryland privacy guide.
Massachusetts
Unclassified in this comparison. This article makes no absence-of-law claim. Use the Massachusetts privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right.
Michigan
Unclassified in this comparison. This article makes no absence-of-law claim. Use the Michigan privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right.
Minnesota
Operative comprehensive framework, since 2025-07-31. Minnesota Consumer Data Privacy Act, Minn. Stat. § 325M.13. Response: 45 days; possible extension: 45 days; appeal result: 45 days. Coverage and exemptions still control. See the Minnesota privacy guide.
Mississippi
Unclassified in this comparison. This article makes no absence-of-law claim. Use the Mississippi privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right.
Missouri
Unclassified in this comparison. This article makes no absence-of-law claim. Use the Missouri privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right.
Montana
Operative comprehensive framework, since 2023-10-01. Montana Consumer Data Privacy Act, Mont. Code Ann. § 30-14-2808. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Montana privacy guide.
Nebraska
Operative comprehensive framework, since 2025-01-01. Nebraska Data Privacy Act, Neb. Rev. Stat. § 87-1107. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Nebraska privacy guide.
Nevada
Targeted right. NRS 603A provides a verified opt-out for covered sales by online operators, not the general access right compared here. See NRS 603A.340 creates a verified opt-out of covered sales, not the general access/confirmation right compared here and the Nevada privacy guide.
New Hampshire
Operative comprehensive framework, since 2025-01-01. New Hampshire Data Privacy Act, RSA 507-H:4. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the New Hampshire privacy guide.
New Jersey
Operative comprehensive framework, since 2025-01-15. New Jersey Data Privacy Act, N.J. Stat. § 56:8-166.8. Response: 45 days; possible extension: 45 days; appeal result: 45 days. Coverage and exemptions still control. See the New Jersey privacy guide.
New Mexico
Unclassified in this comparison. This article makes no absence-of-law claim. Use the New Mexico privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right.
New York
Unclassified in this comparison. This article makes no absence-of-law claim. Use the New York privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right.
North Carolina
Unclassified in this comparison. This article makes no absence-of-law claim. Use the North Carolina privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right.
North Dakota
Unclassified in this comparison. This article makes no absence-of-law claim. Use the North Dakota privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right.
Ohio
Unclassified in this comparison. This article makes no absence-of-law claim. Use the Ohio privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right.
Oklahoma
Future comprehensive framework, effective 2027-01-01. Oklahoma consumer data privacy law, SB 546, Enrolled sections 2-4, to be codified at 75A O.S. §§ 301-303. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Oklahoma privacy guide.
Oregon
Operative comprehensive framework, since 2024-07-01. Oregon Consumer Privacy Act, ORS 646A.574 and 646A.578. Response: 45 days; possible extension: 45 days; appeal result: 45 days. Coverage and exemptions still control. See the Oregon privacy guide.
Pennsylvania
Unclassified in this comparison. This article makes no absence-of-law claim. Use the Pennsylvania privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right.
Rhode Island
Operative comprehensive framework, since 2026-01-01. Rhode Island Data Transparency and Privacy Protection Act, R.I. Gen. Laws §§ 6-48.1-5 and 6-48.1-6. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Rhode Island privacy guide.
South Carolina
Unclassified in this comparison. This article makes no absence-of-law claim. Use the South Carolina privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right.
South Dakota
Unclassified in this comparison. This article makes no absence-of-law claim. Use the South Dakota privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right.
Tennessee
Operative comprehensive framework, since 2025-07-01. Tennessee Information Protection Act, Tenn. Code Ann. § 47-18-3303. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Tennessee privacy guide.
Texas
Operative comprehensive framework, since 2024-07-01. Texas Data Privacy and Security Act, Tex. Bus. & Com. Code § 541.051. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Texas privacy guide.
Utah
Operative comprehensive framework, since 2023-12-31. Utah Consumer Privacy Act, Utah Code § 13-61-201. Response: 45 days; possible extension: 45 days. Coverage and exemptions still control. See the Utah privacy guide.
Vermont
Future comprehensive framework, effective 2028-01-01. Vermont Data Privacy and Online Surveillance Act, Act 145 (S.71), 9 V.S.A. chapter 61A, enacted § 2415d consumer rights. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Vermont privacy guide.
Virginia
Operative comprehensive framework, since 2023-01-01. Virginia Consumer Data Protection Act, Va. Code § 59.1-577. Response: 45 days; possible extension: 45 days; appeal result: 60 days. Coverage and exemptions still control. See the Virginia privacy guide.
Washington
Targeted right. Chapter 19.373 RCW provides access concerning covered consumer health data, not all personal data. See RCW 19.373.040 for consumer health data and the Washington privacy guide.
West Virginia
Unclassified in this comparison. This article makes no absence-of-law claim. Use the West Virginia privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right.
Wisconsin
Unclassified in this comparison. This article makes no absence-of-law claim. Use the Wisconsin privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right.
Wyoming
Unclassified in this comparison. This article makes no absence-of-law claim. Use the Wyoming privacy guide to investigate sector and subject-specific rights; the link is navigation, not proof of a comprehensive access right.
For the broader landscape, see US data privacy laws by state and the guide to opting out of data brokers.
Disclaimer: This guide provides general information about consumer data-access routes as of September 11, 2026. Coverage depends on the requester, residence, organization, data, collection context, statutory thresholds, exemptions, and request date. It is not legal advice. Check the current official statute and the organization's privacy notice before relying on a deadline or remedy. Consult a lawyer licensed in the relevant jurisdiction for advice about a specific request, denial, deadline, or remedy.
About the author: The RecordingLaw Editorial Team researches privacy and recording laws from official statutes and regulator materials.
Last updated: September 11, 2026.
Frequently Asked Questions
Is a data subject access request valid in the United States?
It can be when a state comprehensive law or a federal sector law covers the requester, holder, and data. The United States does not use one universal request right or procedure.
How long does a company have to answer?
Many state frameworks use 45 days and may allow an extension, but Iowa uses 90 days initially and Florida permits a 15-day extension after its initial 45 days. The applicable statute controls.
Can a company verify my identity?
State request processes generally contemplate authentication. Use the secure method provided and supply only information reasonably needed to connect you to the data.
Does every state provide a general consumer access right?
This comparison identifies 20 operative comprehensive frameworks, four future laws, and two targeted regimes. It leaves 25 jurisdictions unclassified and makes no claim that other access rights are absent.
Updates
Independently fact-checked against the cited primary sources
Sources and References
- 45 C.F.R. § 164.524(www.hhs.gov).gov
- 15 U.S.C. § 1681g(uscode.house.gov).gov
- 34 C.F.R. § 99.10(www.ecfr.gov).gov
- 5 U.S.C. §§ 552, 552a(www.justice.gov).gov
- Ala. Act 2026-552; La. Act 502 (2026); Okla. SB 546 (2026); Vt. Act 145 (2026)(alison.legislature.state.al.us).gov
- Ala. Act 2026-552; La. Act 502 (2026); Okla. SB 546 (2026); Vt. Act 145 (2026)(www.legis.la.gov).gov
- Ala. Act 2026-552; La. Act 502 (2026); Okla. SB 546 (2026); Vt. Act 145 (2026)(www.oklegislature.gov).gov
- Ala. Act 2026-552; La. Act 502 (2026); Okla. SB 546 (2026); Vt. Act 145 (2026)(legislature.vermont.gov).gov
- NRS Chapter 603A; chapter 19.373 RCW(www.leg.state.nv.us).gov
- NRS Chapter 603A; chapter 19.373 RCW(app.leg.wa.gov).gov
- Iowa Code § 715D.3; Fla. Stat. §§ 501.706-.707(www.legis.iowa.gov).gov
- Iowa Code § 715D.3; Fla. Stat. §§ 501.706-.707(www.leg.state.fl.us).gov
- Iowa Code § 715D.3; Fla. Stat. §§ 501.706-.707(www.leg.state.fl.us).gov
- Maine LD 1822 official status(legislature.maine.gov).gov
- Alabama Personal Data Protection Act, Act 2026-552: Ala. Code § 8-44-5(alison.legislature.state.al.us).gov
- California Consumer Privacy Act as amended: Cal. Civ. Code §§ 1798.100, 1798.110, 1798.115; implementing regulations(cppa.ca.gov).gov
- Colorado Privacy Act: Colo. Rev. Stat. § 6-1-1306; 4 CCR 904-3(coag.gov).gov
- Connecticut Data Privacy Act: Conn. Gen. Stat. § 42-518(www.cga.ct.gov).gov
- Delaware Personal Data Privacy Act: 6 Del. C. § 12D-104(delcode.delaware.gov).gov
- Florida Digital Bill of Rights: Fla. Stat. §§ 501.705-.707(www.leg.state.fl.us).gov
- Indiana Consumer Data Protection Act: Ind. Code § 24-15-3-1(iga.in.gov).gov
- Kentucky Consumer Data Protection Act: KRS 367.3615(apps.legislature.ky.gov).gov
- Louisiana Data Privacy Act, Act 502 (SB 386): La. R.S. 51:1780.3(www.legis.la.gov).gov
- Maryland Online Data Privacy Act: Md. Code, Commercial Law § 14-4605(mgaleg.maryland.gov).gov
- Minnesota Consumer Data Privacy Act: Minn. Stat. § 325M.13(www.revisor.mn.gov).gov
- Montana Consumer Data Privacy Act: Mont. Code Ann. § 30-14-2808(archive.legmt.gov).gov
- Nebraska Data Privacy Act: Neb. Rev. Stat. § 87-1107(nebraskalegislature.gov).gov
- New Hampshire Data Privacy Act: RSA 507-H:4(gc.nh.gov).gov
- New Jersey Data Privacy Act: N.J. Stat. § 56:8-166.8(pub.njleg.state.nj.us).gov
- Oklahoma consumer data privacy law, SB 546: Enrolled sections 2-4, to be codified at 75A O.S. §§ 301-303(www.oklegislature.gov).gov
- Oregon Consumer Privacy Act: ORS 646A.574 and 646A.578(www.oregonlegislature.gov).gov
- Rhode Island Data Transparency and Privacy Protection Act: R.I. Gen. Laws §§ 6-48.1-5 and 6-48.1-6(webserver.rilegislature.gov).gov
- Tennessee Information Protection Act: Tenn. Code Ann. § 47-18-3303(www.tn.gov).gov
- Texas Data Privacy and Security Act: Tex. Bus. & Com. Code § 541.051(statutes.capitol.texas.gov).gov
- Utah Consumer Privacy Act: Utah Code § 13-61-201(le.utah.gov).gov
- Vermont Data Privacy and Online Surveillance Act, Act 145 (S.71): 9 V.S.A. chapter 61A, enacted § 2415d consumer rights(legislature.vermont.gov).gov
- Virginia Consumer Data Protection Act: Va. Code § 59.1-577(law.lis.virginia.gov).gov