US State Privacy Laws

Privacy & Compliance / Law guide

US State Privacy Laws for Marketers: What Your Tags Must Do

Summary

There is no single US privacy law. More than a dozen states have their own comprehensive privacy laws, with a common baseline: residents can opt out of sale, sharing and targeted advertising, 12 states require acting on a browser opt-out signal like Global Privacy Control (nine directly, three through an authorized agent), and sensitive data gets extra protection.

Trying to track more than a dozen laws tag by tag is the wrong approach. Because the newer laws share much of the same structure, the practical job is to meet the shared requirements and watch the handful of state-specific rules.

The sections below list which states have privacy laws, set out the shared baseline that matters for tags, and explain how enforcement works. The last section covers how to comply across states without tracking every law.

Which states have privacy laws?

California started it with the CCPA. More than a dozen states now have comprehensive consumer privacy laws, and more take effect each year, so the list keeps growing, which is the reason to build to the shared baseline rather than to any one state.

The shared baseline that matters for tags

Four requirements recur across almost every state law, and all four touch what your tags do.

A browser with GPC turned on sends Sec-GPC: 1. If the site listens, ad tags stop. If it doesn't, ad tags keep firing.

Opt-out of sale, sharing, and targeted advertising. Residents can tell you to stop letting their data be used for cross-context advertising. In practice that means your advertising tags have to stop for them.

Honor a browser opt-out signal. Nine states directly require businesses to honor a browser opt-out signal such as GPC: California, Colorado, Connecticut, Delaware, Minnesota, Montana, New Hampshire, New Jersey and Oregon. Texas, Maryland and Nebraska let consumers opt out through a browser setting that acts as their authorized agent, with conditions. That makes 12. See Global Privacy Control.

Protect sensitive data. Precise location, health, and similar categories get extra protection, either an opt-in before use or a right to limit it. A tag that picks up sensitive data is squarely in scope.

Assess high-risk processing. Many laws require a data protection assessment for targeted advertising and sensitive-data processing, which assumes you actually know what your tags collect.

How enforcement works

For the comprehensive state laws, enforcement is by the state Attorney General, and in California also by the California Privacy Protection Agency. California allows private suits only for certain data breaches, so under these laws the main risk is regulator enforcement rather than the class actions brought under CIPA and the VPPA. That changes the shape of the risk but not the fix: the regulators look for opt-outs that are offered but not enforced, and for sensitive data being shared without a basis.

For specific state enforcement actions, see our Enforcement Watch tracker.

How to comply across states without tracking every law

Build to the baseline and verify it. Make your advertising and sharing tags stop when a resident opts out or sends a GPC signal, keep sensitive data out of tags that would share it, and know what every tag collects. Then confirm it with testing.

DataTrue loads your site in each relevant state, opt-out applied and GPC enabled, and records what each tag does, so you can confirm the opt-out actually stops the tags that share data and that no sensitive data is leaking. Sensitive Data Detection inspects the payloads with fictitious personas. Meeting and proving the shared baseline is what covers the state laws at once.

See how consent verification works

This law group is part of our US website tracking compliance hub.

Questions

How many US states have privacy laws?

More than a dozen states have comprehensive consumer privacy laws, and more take effect each year, so the count keeps growing.

Do I need to comply with all of them separately?

Not tag by tag. Most of the laws follow a shared template, so meeting the common baseline, opt-out of sale and sharing, honoring universal opt-out signals, and protecting sensitive data, covers most requirements. Watch the handful of state-specific rules on top.

Do state privacy laws let people sue me directly?

For tracking, mostly no. The comprehensive state privacy laws are enforced by state regulators, mainly Attorneys General, and in California also the CPPA. California allows private suits only for certain data breaches. Class actions over tracking are brought under other laws, such as CIPA and the VPPA.

What is the fastest way to reduce exposure across states?

Make your advertising tags stop on opt-out and on GPC, keep sensitive data out of sharing tags, and verify with testing that the opt-out actually works on every page. That single baseline satisfies most of what the state laws require of tags.

30-day free trial

See what your tags do in every consent state

DataTrue loads your real pages as a visitor who accepts, rejects, or sends an opt-out signal, and reads what each tag sends. A tag that ignores the visitor’s choice shows up in a test.

What DataTrue checks
  • Every page, with coverage scans
  • Scheduled runs, with alerts when a result changes
  • Full journeys, like checkout and signup, in each consent state
  • What each tag sent, field by field
Also in the full platform
  • PII detection with test personas
  • iOS and Android app testing
  • Pre-publish testing for GTM and Adobe Tags
  • REST API, plus Slack and Jira alerts
Start a free 30-day trial ★★★★★ 4.6/5 on G2

The full platform, every feature, free for 30 days.

A DataTrue opt-out consent test listing the tags that should be blocked, with pass or fail for each
A consent-state test in DataTrue