ConsentPixel – Privacy · Verified

Privacy · The Organization's Duty · 2026

Data Protection Explained: What Your Organization Must Do

People use "data protection" and "data privacy" interchangeably, but the difference is the whole point of this guide. Start with the data protection and privacy definition that actually matters in practice: privacy is the individual's right to control their information; data protection is the organization's duty to safeguard it. This article is about the duty side — which laws reach your business in 2026, and what a real data-protection program looks like once you know they do.

CPConsentPixel Team Updated September 2026 15 min read Information, not legal advice
20 states
US states with a comprehensive privacy law in force in 2026 — four more already enacted for 2027–28
No federal law
The US has no comprehensive federal privacy law — the state patchwork is the durable planning reality
$1.4B
Texas AG's settlement with Meta — proof that state data-protection enforcement now rivals federal scale

Key takeaways

  • Privacy is a right; data protection is a duty. Privacy is what the individual is owed; data protection is what your organization must actively do to deliver it.
  • The first question is "does it apply to me?" Applicability turns on thresholds — and in Texas and Nebraska there's no revenue or size threshold at all.
  • The US is a 20-state patchwork, not one rulebook. Maryland is the strictest, only California has a private right of action, and 12 states now legally require honoring Global Privacy Control.
  • There is no "US GDPR." The federal ADPPA expired in 2025 and hasn't returned, so the state-by-state matrix is the plan through at least 2028.
  • A data-protection program is operational, not paperwork. Inventory what you collect, map which laws apply, assess risk, control consent and signals, and keep proof.

Data protection vs data privacy: the definition that matters

The clearest data protection and privacy definition isn't one sentence — it's a distinction between two vantage points on the same thing. Data privacy is the individual's right to control how their personal information is collected, used, and shared. Data protection is the organization's duty to safeguard that information and honor that right. Privacy is what a person is owed; data protection is what a company has to do about it.

The terminology splits along geography. In Europe the umbrella term is "data protection" — the GDPR is literally the General Data Protection Regulation, and companies appoint a Data Protection Officer. In the US, people say "privacy." But they describe the same domain from opposite ends: the right, and the duty to uphold it. This guide is the duty side. (For the concept itself — what privacy is, privacy versus security, your rights as an individual — see data and privacy explained.)

DATA PRIVACY the individual's RIGHT "What happens to information about me?" Covered in: Data & Privacy Explained DATA PROTECTION the organization's DUTY "Which laws apply, and what must we actually do?" Covered here ↓

Everything that follows answers the duty-side questions a business actually asks: Does any of this apply to me? Which laws? What do I have to build? Those are practical, operational questions — and in 2026 the answers have real financial stakes.

Does data-protection law even apply to me?

This is the first real question, and most guides skip it. You don't comply with "data protection law" in the abstract — you comply with the specific laws whose applicability thresholds you cross. So the starting move is an honest applicability check across every place your users are.

In the US, most state laws use volume-and-revenue triggers. The common pattern: a law applies if you process the personal data of 100,000+ residents of that state, or 25,000+ residents while earning more than half your revenue from selling data, or you meet a revenue threshold. Miss all the triggers and that particular law may not reach you. But three important exceptions break the pattern:

!Texas and Nebraska have no threshold at allThe Texas Data Privacy and Security Act (TDPSA) and Nebraska's law apply to any business doing business in the state or targeting its residents — excluding only federally-defined small businesses. If you have Texas customers, assume you're in scope. (Even a small business must get consent to sell sensitive data under TDPSA.)
$Florida is the opposite — an effectively unreachable $1B thresholdThe Florida Digital Bill of Rights targets only very large technology platforms, so most businesses aren't covered by it (though other states may still apply).
Sensitive data and minors can trigger obligations regardless of sizeProcessing sensitive categories (health, biometrics, precise location) or children's data can pull you into scope in some states even below the usual thresholds.

The practical takeaway for anyone operating nationally: assume you're in scope somewhere. The moment you have Texas customers, or you handle sensitive data, the "we're too small" assumption stops holding — so build to the strictest common denominator rather than dodging each law individually. That's what a data-protection program is for.

The US state patchwork you have to map

Here's the reality that defines US data protection in 2026: there is no single American rulebook. Instead, 20 states have a comprehensive privacy law in force, with four more already enacted and arriving through 2028 (Oklahoma and Louisiana in 2027, Alabama in 2027, Vermont in 2028). Each has its own thresholds, its own definitions, and its own enforcement. A business operating nationally isn't complying with "US privacy law" — it's mapping a patchwork.

The good news is that most of these laws rhyme (they follow the Virginia template and grant the same core rights: access, delete, correct, port, and opt out). What varies is the fine print that changes your obligations. A few states you specifically need to know:

State lawWhat makes it distinctEnforcement
California (CCPA/CPRA)The strictest overall; dedicated agency (CalPrivacy); ADM & risk-assessment rules from Jan 2026Agency + AG; only state with a private right of action (breaches)
Texas (TDPSA)No revenue/volume threshold — broadest scope; treat like CaliforniaAG; $1.4B Meta settlement shows the scale
Maryland (MODPA)The strictest since California — strict data minimization; bans selling sensitive data even with consentAG (applies to processing after April 1, 2026)
Minnesota (MCDPA)Profiling rights (question a profiling result); mandatory privacy impact assessmentsAG; cure period ended Jan 31, 2026
Indiana, Kentucky, Rhode IslandNewest — effective Jan 1, 2026; Virginia-modelAG only; penalties $7,500–$10,000/violation

Three cross-cutting facts matter more than any single law. First, only California gives individuals a private right of action (and only for data breaches) — everywhere else, the state attorney general enforces. Second, twelve states now legally require you to honor Global Privacy Control (California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon and Texas), so a browser opt-out signal is a binding instruction, not a suggestion. Third, the grace periods are disappearing — Delaware's cure period ended December 2025, Minnesota's in January 2026, Montana's in April 2026 — which means attorneys general can now act without giving you time to fix things first. For the full law-by-law rundown, see our 2026 privacy laws overview and the individual pages in our regulations hub.

Is there a "US GDPR" or a federal data-protection law?

People search for "the US equivalent of GDPR" or "the American Data Privacy and Protection Act" hoping for one federal law that settles everything. The honest answer: there isn't one, and there isn't one coming soon.

The most serious attempt, the American Data Privacy and Protection Act (ADPPA), cleared a committee in 2022 but never reached a floor vote and expired in January 2025. It hasn't been reintroduced, and federal preemption isn't on the near-term horizon — which means the state-by-state matrix is the durable planning assumption through at least 2028, not a temporary mess to wait out. The closest thing to a "US GDPR" is California's CCPA/CPRA, but it governs one state.

What still applies federally. The absence of a comprehensive federal law doesn't mean no federal rules. Sector-specific laws still bind: HIPAA (health data), the Gramm-Leach-Bliley Act (financial institutions), COPPA (children under 13), and the FTC Act's general prohibition on unfair or deceptive practices. But for an ordinary business website, your obligations come from state law and — if you have overseas users — international law.

The international layer, in brief

If your users cross borders, so do your duties — nearly every modern privacy law follows the visitor, not the business. As of early 2025, roughly 144 countries had national data-protection laws, covering about 82% of the world's population. You don't need to memorize them, just recognize the ones most likely to reach a typical business:

🇪🇺EU / UK — GDPR (the model)The strictest major regime and the template most others copy. Opt-in consent before non-essential processing; fines to €20 million or 4% of global turnover. Note the name: General Data Protection Regulation.
🇮🇳India — DPDP ActIndia's Digital Personal Data Protection Rules were notified in November 2025 and are phasing in — consent-manager provisions by November 2026, the full substantive obligations by May 2027, with penalties up to ₹250 crore (about $30M). Treat 2026 as a build-and-test year.
🌎Brazil, Singapore, Australia, Switzerland, Mexico, CanadaBrazil's LGPD (GDPR-style, now with EU adequacy) and Singapore's PDPA are mature and enforced; Australia's Privacy Act is being reformed toward GDPR-equivalence; Switzerland's FADP, Mexico's federal law, and Canada's PIPEDA round out the set most global businesses meet.

The vocabulary looks similar across all of them — lawful basis, access, deletion, breach notification — but the specific obligations don't match. The detailed country-by-country picture is in the privacy laws overview; here, the point is that "data protection" is a global duty the moment your audience is.

Data protection starts with knowing what you collect

Every program below begins the same way: seeing what your site actually does. Scan your site to inventory the third-party trackers firing before consent — in about 10 seconds, no account.

Scan your site free →

What a data-protection program actually looks like

Once you know a law applies, "data protection" stops being a definition and becomes a set of things your organization does. A data-protection (or privacy compliance) program is simply the structured answer to "how do we uphold the duty?" It doesn't have to be enormous — but it does have to be real. Here's the operational core, in the order you'd build it.

1Inventory what you collect (data mapping)You can't protect data you can't see. Start by mapping what personal data you collect, where it lives, and who it's shared with. For most websites, the biggest surprise is third-party trackers the owner never knew were running — so a scan of your own site is the fastest first inventory.
2Run an applicability auditMap which laws actually reach you — every US state where you cross a threshold, plus any international regimes your visitors trigger. This is what turns a vague worry into a specific to-do list.
3Assess risk (DPIAs)Higher-risk processing — profiling, sensitive data, large-scale monitoring — increasingly requires a documented Data Protection Impact Assessment. Maryland, Minnesota, Colorado and Connecticut require assessments, as does GDPR Article 35. A DPIA is both a legal requirement and a useful way to catch problems early.
4Control consent and signalsThis is the operational crux. For EU visitors, block non-essential trackers until opt-in; for US visitors, honor opt-out and Global Privacy Control. Whether tracking fires before or after the visitor's choice is the single fact that most data-protection duties turn on.
5Get the documents rightA privacy policy that reflects what you actually do, data-processing agreements (DPAs) with your vendors, records of processing, and consent records. More on these below — the key is that they describe reality, not a template.
6Manage vendors and contractsYour duty extends to the processors you use: keep a current sub-processor list, sign DPAs, and watch ad-tech vendors especially, since that's where most consent obligations are met or missed.
7Train people — and appoint a DPO where requiredData-protection and security training keeps staff from creating exposure by accident. Some regimes (the GDPR in defined cases, India, Malaysia) require a designated Data Protection Officer; even where one isn't mandatory, someone should own the program.
8Keep proof, and re-auditA timestamped record of each consent decision turns "we respect privacy" into something you can demonstrate. And because your stack drifts, a program isn't a one-time project — periodic re-auditing is part of it.

Read that list and a pattern emerges: data protection is mostly about visibility and proof. Know what you collect, know which rules apply, control the moment of consent, and keep evidence. The organizations that get into trouble usually aren't the ones without a policy — they're the ones whose actual behavior drifted away from the policy they had.

The documents you'll hear about

A cluster of data-protection documents comes up constantly, and it's worth knowing what each one actually is — and one honest warning about templates.

  • Privacy policy / privacy notice — the public disclosure of what you collect and why. It should describe your real practices; a generic template that doesn't match your site is a liability, not a shield.
  • Data privacy disclaimer — a short notice (often on a form or email) clarifying how submitted data will be used. It's a disclosure, not consent.
  • Data-processing agreement (DPA) — the contract between you (controller) and a vendor (processor) governing how they handle data on your behalf. Required under GDPR, increasingly expected under US state laws.
  • Data privacy clause — privacy terms embedded inside a larger contract (an employment agreement, a vendor MSA) rather than a standalone document.
  • Consent form / consent record — how you capture and store proof that someone agreed. The record matters as much as the form.
A word on templates
Searching for a "data protection consent form template" or "data privacy agreement" template is a reasonable start — but a template can't know your actual data flows, your vendors, or which laws apply to you, and those determine what it needs to say. Use one to draft, then make it describe what you really do, and have anything high-stakes reviewed by counsel. For a website, generating your privacy policy from a real scan — rather than a static template that drifts out of date — is far more durable. This is information, not legal advice.

Industries, and the "golden rule" of data protection

Data-protection duties aren't uniform across sectors — the same underlying rights get sharper obligations depending on the data involved. Healthcare adds HIPAA on top of state privacy law; financial services add the Gramm-Leach-Bliley Act; anything touching children adds COPPA; and adtech and ordinary websites carry the state-law and wiretapping exposure (like California's CIPA) that comes with third-party tracking. If you're wondering how data protection differs between industries, that's the shape of it: a common baseline, plus a sector-specific layer determined by how sensitive your data is.

And the "golden rule" people ask about? It isn't a statute — it's data minimization: collect only the personal data you genuinely need, use it only for the purpose you disclosed, and keep it only as long as necessary. Nearly every modern law (Maryland's minimization standard most strictly of all) is a variation on that single principle. If you internalize one thing about data protection, make it that — most violations are just data minimization ignored.

Where it all lands for a website

Strip away the state list and the acronyms, and data protection for a website comes down to one operational question: does what your site actually does match what the law — and your own privacy policy — requires? The gap between those two is where the risk lives, and it almost always shows up at one specific moment: when a tracker sends a visitor's data to a third party before that visitor has agreed.

That's why the duty side of privacy is, in practice, a prevention problem more than a paperwork one. The organizations that stay out of trouble make their behavior provable: they know what they collect, hold non-essential trackers until consent, honor opt-out signals like GPC, and keep records. That's what ConsentPixel — Privacy · Verified operationalizes — from a single pixel it blocks third-party trackers until a visitor consents, honors GPC, scans what fires, and logs each decision as evidence, so your data-protection practice matches your promise. It's a consent-management and detection tool, not legal advice. See the whole platform on the consent management platform page, and generate a policy from your real scan with the privacy policy generator.

Frequently asked questions

What is the difference between data protection and data privacy?

They're two vantage points on the same thing. Data privacy is the individual's right to control how their personal information is collected, used, and shared. Data protection is the organization's duty to safeguard that information and honor that right — the policies, controls, and processes a business puts in place. The terms split by geography: Europe uses "data protection" (the GDPR is the General Data Protection Regulation), while the US tends to say "privacy." Privacy is what a person is owed; data protection is what a company must actually do about it. This is general information, not legal advice.

Does data-protection law apply to my business?

It depends on where your users are and how much data you handle. Most US state laws apply above thresholds (commonly 100,000+ state residents, or 25,000+ while earning over half your revenue from data sales) — but Texas and Nebraska have no threshold at all and apply to any business targeting their residents. Sensitive or children's data can trigger obligations regardless of size, and international laws like the GDPR apply based on where your visitors are. For anyone operating nationally, assume some law applies somewhere and run an applicability audit rather than assuming you're exempt.

Is there a US federal data-protection law (a "US GDPR")?

No. The United States has no comprehensive federal privacy law. The American Data Privacy and Protection Act (ADPPA) cleared a committee in 2022 but never got a floor vote and expired in January 2025; it hasn't been reintroduced, and federal preemption isn't on the near-term horizon. That makes the state-by-state patchwork — 20 comprehensive state laws in force in 2026, with more coming — the durable planning assumption through at least 2028. The closest thing to a "US GDPR" is California's CCPA/CPRA, but it governs one state. Sector-specific federal laws (HIPAA, GLBA, COPPA) still apply on top.

How many US states have data-protection laws?

As of 2026, 20 states have a comprehensive consumer privacy law in force: California, Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Tennessee, Montana, Oregon, Texas, Florida, Delaware, New Hampshire, New Jersey, Kentucky, Nebraska, Minnesota, Maryland and Rhode Island. Indiana, Kentucky and Rhode Island were the newest, effective January 1, 2026. Four more are already enacted and arriving later — Oklahoma and Louisiana in 2027, Alabama in 2027, and Vermont in 2028. Each has its own thresholds and enforcement, so a national business maps a patchwork rather than following one rule.

What does a data-protection program involve?

It's the operational answer to your legal duty: inventory what personal data you collect (data mapping), audit which laws reach you, assess risk with DPIAs where required, control consent and opt-out signals (including honoring Global Privacy Control), keep documents that reflect your real practices (privacy policy, DPAs, consent records), manage vendor contracts, train staff and appoint a Data Protection Officer where required, and keep timestamped proof while re-auditing periodically. The through-line is visibility and proof: know what you collect, control the moment of consent, and demonstrate it.

What is the "golden rule" of data protection?

The closest thing to a golden rule is data minimization: collect only the personal data you genuinely need, use it only for the purpose you disclosed, and keep it only as long as necessary. Nearly every modern privacy law is a variation on that principle — Maryland's data-protection law enforces it most strictly, requiring collection to be "reasonably necessary and proportionate." A useful plain-language version is to handle other people's data the way you'd want yours handled. Most data-protection violations, at bottom, are data minimization ignored — collecting or keeping more than was necessary or agreed to.

The bottom line

The cleanest way to hold "data and privacy" straight is to separate the right from the duty. Data privacy is the individual's right to control their information; data protection is your organization's duty to deliver it. This guide has been about the duty — and in 2026 that duty is concrete: 20 US state laws in force, no federal law to unify them, a dozen states where a browser signal is legally binding, and enforcement that now reaches billion-dollar scale.

But the operational core is smaller than the acronym list suggests. Find out which laws apply, know what you collect, control the moment of consent, keep the documents honest, and hold proof. Do that, and data protection stops being a source of anxiety and becomes something you can actually demonstrate.

And it all starts the same way, whichever law reaches you: by seeing what your site really does.

Turn the duty into something you can prove

ConsentPixel — Privacy · Verified operationalizes data protection from one pixel: it blocks trackers until consent, honors GPC, scans what fires, and logs each decision as evidence. Start with a free scan, then a 14-day trial.

Scan your site free →
No account needed for the scan · then a 14-day free trial, no credit card required
CP

The ConsentPixel Team

Privacy & Consent Compliance

ConsentPixel — Privacy · Verified helps website owners and agencies operationalize data protection — blocking third-party trackers until a visitor genuinely consents, honoring opt-out and Global Privacy Control signals, continuously scanning what fires, and logging each decision as evidence. This article is general educational information, not legal advice. ConsentPixel is not a law firm.

Information, not legal advice. This article explains data-protection concepts, laws, and organizational obligations for general educational purposes and does not constitute legal advice or create an attorney–client relationship. Privacy and data-protection laws vary by jurisdiction and change frequently; effective dates, thresholds, and penalties described here reflect publicly reported information as of September 2026 and may change. Whether and how any law applies to your organization depends on your specific facts — verify current requirements and consult qualified counsel. ConsentPixel — Privacy · Verified is a consent-management and detection tool, not a law firm, and no single tool or document by itself makes an organization compliant with any law.

Scroll to Top