ConsentPixel – Privacy · Verified

Privacy Law · 2026 Overview

US & Global Privacy Laws in 2026: The California Consumer Privacy Act & Beyond

There is still no single privacy law that covers a website. Instead there's a fast-growing patchwork — and at its center sits the California Consumer Privacy Act, the law that kicked off the modern US era and the one most site owners meet first. This is a plain-English map of what actually applies in 2026: California's two very different privacy laws, the twenty-state US patchwork, the missing federal law, and the UK, EU and Australian regimes that reach your site the moment their residents visit.

CPConsentPixel Team Updated September 2026 15 min read Information, not legal advice
20 states
US states with a comprehensive privacy law in effect in 2026 — with four more passed and coming
0 federal
Comprehensive US federal privacy laws — the US is the only G20 country without one
$5,000
Per-violation statutory damages under California's CIPA (Cal. Penal Code §637.2) — privately enforceable

Key takeaways

  • "Privacy law" is now plural. A US website is typically touched by California's laws, up to nineteen other state laws, and — for overseas visitors — the UK, EU and Australian regimes at once.
  • California has two privacy laws, not one. The CCPA is a notice-and-opt-out law enforced by regulators; CIPA is a 1967 wiretapping law that private plaintiffs use against website trackers — and CCPA compliance does not protect you from it.
  • There is no US federal privacy law. The American Privacy Rights Act failed, leaving the twenty-state patchwork as the reality for anyone serving US customers.
  • The rest of the world reaches your site too. The UK's new Data (Use and Access) Act, the EU's GDPR, and Australia's reformed Privacy Act all apply based on where your visitor is, not where you are.
  • The common thread is consent before tracking. Most of the litigation and enforcement turns on one question: did your trackers wait for the visitor's choice? That's a thing you can actually test.

The 2026 landscape at a glance

A decade ago, "do I need a privacy policy?" was roughly the whole conversation. In 2026 it's a map. Dozens of overlapping laws now govern what a website may collect, whether it needs consent, and who can sue when it gets it wrong — and they don't agree with each other. The result is a genuine patchwork, where a single site can sit under California's rules, a dozen other US states', and the UK's, EU's and Australia's all at the same time, purely based on who shows up.

Two ideas make the whole map easier to read. First, most privacy laws follow the visitor, not the business — a company in Ohio (or London, or Sydney) can owe duties to a California, UK or Australian resident the instant that person loads the page. Second, the laws split into two families by how they're enforced: some are enforced by government regulators (fines assessed by an agency), and a smaller, more dangerous set give private individuals the right to sue directly, often with fixed statutory damages. That enforcement distinction, more than the letter of any single statute, is what determines your real-world risk.

One website · many regimes · each follows the visitor YOUR SITE California CIPAprivate lawsuits 20 US state lawsregulator-enforced EU GDPRopt-in consent UK DUAAits own regime now Australia · statutory tort

California: the California Consumer Privacy Act vs CIPA

Start with California, because it's where the modern US era began and where the sharpest risk still lives. The crucial thing most site owners don't realize: California has two very different privacy laws, and they work in opposite ways.

The California Consumer Privacy Act (CCPA)

The California Consumer Privacy Act took effect in 2020 and was expanded by the California Privacy Rights Act (CPRA), which created a dedicated regulator, the California Privacy Protection Agency. In plain terms, the CCPA is a notice-and-opt-out law: you must tell people what you collect, give them a working way to opt out of the sale or sharing of their personal information (the "Do Not Sell or Share My Personal Information" link), and honor opt-out preference signals like Global Privacy Control. It's enforced by the California Attorney General and the Privacy Protection Agency, with civil penalties assessed per violation — and, importantly, it has no private right of action except in certain data-breach cases.

Enforcement is real and escalating. The Privacy Protection Agency reached its then-largest settlement of $1.35 million with Tractor Supply, and in February 2026 topped it with a $2.75 million settlement against a streaming company over opt-out failures — both resolved without any admission of wrongdoing. The lesson regulators keep repeating: an opt-out that doesn't actually work is treated as no opt-out at all.

CIPA — the wiretapping law that catches websites

Here's the trap. Doing everything the CCPA asks does not protect you from California's other privacy law — the California Invasion of Privacy Act (CIPA), a 1967 anti-wiretapping statute written for telephone eavesdropping. Plaintiffs' firms discovered that its all-party-consent rule maps neatly onto website tracking: when a third-party pixel, analytics tag, session-replay script or chat widget intercepts a visitor's interaction before they consent, plaintiffs argue an unlawful "interception" has already occurred. Unlike the CCPA, CIPA gives private individuals the right to sue, with statutory damages of $5,000 per violation under Cal. Penal Code §637.2. That combination — a private right of action plus fixed damages plus easy-to-plead fact patterns — is why CIPA has driven thousands of demand letters and class actions.

 California Consumer Privacy Act (CCPA/CPRA)CIPA (wiretapping)
What it governsNotice, and sale/sharing of personal infoInterception of communications (trackers)
Core dutyClear notice + working opt-out + honor GPCAll-party consent before tracking fires
Who enforcesCA Attorney General + Privacy Protection AgencyPrivate individuals (plus criminal)
Private right to sue?No (except certain data breaches)Yes
Penalty exposurePer-violation civil penalties, regulator-assessed$5,000 per violation (§637.2)
Reaches you if…You meet CCPA thresholds & have CA consumersA California resident visits your site
2026 update: SB 690
On 28 August 2026 the California legislature passed SB 690, which — if signed by the Governor — would narrow one CIPA theory: it amends only the pen-register / trap-and-trace sections (§638.50–§638.51), removes the private right of action for that theory in favor of Attorney-General enforcement, and applies retroactively for two years. Critically, it leaves the core §631 wiretapping theory untouched and does not change the CCPA. In other words, it narrows one lane of website-tracking litigation rather than ending the category. As of this writing it awaits the Governor's signature. This is information, not legal advice — follow the current status on our CIPA Lawsuit Tracker.

The practical takeaway from California is the theme of this whole guide: the decisive question is whether your trackers wait for consent. The CCPA wants a working opt-out; CIPA wants prior consent before interception. Both are, at heart, about controlling what fires and when — which is something you can verify rather than assume. (For the full picture, see our CIPA compliance guide and the CIPA regulation overview.)

The rest of the US: a twenty-state patchwork

Beyond California, the US has spent five years filling in a state-by-state map. As of 2026, twenty states have a comprehensive consumer privacy law in effect, and three of those — Indiana, Kentucky and Rhode Island — only switched on this January. Four more (Alabama, Louisiana, Oklahoma and Vermont) passed laws in 2026 that aren't yet effective, which will push the count toward twenty-four.

The good news for site owners is that most of these laws rhyme. Almost all follow the "Virginia model" and grant the same six core consumer rights: access, deletion, correction, portability, opt-out (of sale, targeted advertising and certain profiling), and non-discrimination for exercising those rights. What differs is the fine print that decides whether a law applies to you at all — the applicability thresholds — and how aggressively each state enforces.

State lawIn effectNotable detail
California (CCPA/CPRA)2020 / 2023The trailblazer; only state with any private right of action (breaches)
Virginia (VCDPA)2023The template most later laws copy
Colorado, Connecticut, Utah2023Early movers; Connecticut among the most active enforcers
Texas (TDPSA)2024Aggressive enforcement; large settlements reported
Indiana, KentuckyJan 1, 2026Virginia-model; 100,000-resident thresholds
Rhode IslandJan 1, 2026Lowest threshold (35,000); no cure period; up to $10,000/violation
Florida (FDBR)2024Narrow — only very large tech companies (>$1B revenue)
…plus Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland

Because the laws overlap so heavily, the sensible operating posture is to build to the strictest common denominator rather than tracking twenty rulebooks separately — clear notice, a genuine opt-out, honoring Global Privacy Control, and not letting non-essential trackers fire before a choice. Do that, and you're broadly aligned with the whole patchwork at once. Our GDPR vs CCPA comparison unpacks the opt-in-versus-opt-out difference that sits underneath all of this.

A common point of confusion: the "Privacy Act" of 1974
If you've searched for "Privacy Act violation," "Privacy Act statement," or "who is not an individual under the Privacy Act," you may have hit the US Privacy Act of 1974 — a different law entirely. It governs how federal government agencies handle records about individuals (and defines "individual" as a US citizen or lawful permanent resident, which is why non-citizens are often "not an individual" under it). It's the reason government emails carry a "Privacy Act Statement." It does not govern ordinary commercial websites — those are covered by the state consumer laws above. Worth knowing so you're reading the right rulebook.

Why there's still no US federal privacy law

The obvious fix for a twenty-state patchwork would be a single federal law — and Congress has tried, repeatedly, without success. The most recent serious attempt, the American Privacy Rights Act (APRA), was introduced in 2024, cleared an initial committee step, but never reached a floor vote and expired at the end of the 118th Congress in January 2025; it has not been reintroduced. Its predecessor, the American Data Privacy and Protection Act, stalled the same way. The recurring sticking points are always the same two: whether a federal law should preempt stronger state laws like California's, and whether it should include a private right of action.

The upshot: the United States remains the only G20 country without a comprehensive national privacy law, and has no national data-protection authority. That doesn't mean there are no federal rules — sector-specific laws still apply, including HIPAA (health data), the Gramm-Leach-Bliley Act (financial institutions), COPPA (children under 13), and the FTC Act's general prohibition on unfair or deceptive practices. But for the everyday website, the operative law is state law, and the patchwork is the reality for the foreseeable future.

Which of your trackers fire before consent?

Across almost every law on this page, the pivotal question is the same: does your site wait for the visitor's choice before tracking starts? See what actually fires before consent on your own site — in about 10 seconds, no account.

Scan your site free →

United Kingdom

The UK has quietly stopped being "just GDPR with a British accent." The Data (Use and Access) Act 2025 received Royal Assent in June 2025, and its main provisions came into force on 5 February 2026. It doesn't replace the UK GDPR or the Data Protection Act 2018 — it amends them — but the cumulative effect is real: a new set of "recognised legitimate interests" that reduce paperwork for specific purposes, softened rules for certain analytics cookies, relaxed (but still safeguarded) rules on automated decision-making, and higher, GDPR-aligned penalties for electronic-marketing breaches.

One date to put on the calendar: from 19 June 2026, individuals gain a right to complain directly to the organisation (not only to the regulator), and controllers must acknowledge such complaints within 30 days and have a formal process to handle them. Enforcement, meanwhile, has teeth — the Information Commissioner's Office issued its largest-ever fine, £14 million against Capita, in late 2025. For anyone serving UK visitors, the practical message is that UK compliance is now its own analysis, not a copy of your EU approach.

European Union

The EU's General Data Protection Regulation (GDPR) remains the strictest of the major regimes and the global benchmark. Its defining feature, in contrast to US state laws, is opt-in consent: for non-essential cookies and trackers, consent must be freely given, specific, informed and unambiguous, and collected before anything fires — reinforced by the ePrivacy Directive (the "cookie law"). Fines reach €20 million or 4% of global annual turnover, whichever is higher. The long-promised ePrivacy Regulation, intended to modernize the cookie rules, remains pending after years of delay.

New in 2026: the EU AI Act's Article 50 transparency duties became enforceable on 2 August 2026, requiring sites to disclose when visitors are interacting with AI (a chatbot, for instance). It's a different law from the GDPR but stacks on top of it — and it's a sign of where consent is heading. We cover it in depth in EU AI Act Article 50 for websites.

Australia

Australia is in the middle of its biggest privacy overhaul since the Privacy Act 1988 was enacted. The Privacy and Other Legislation Amendment Act 2024 (Royal Assent December 2024) is being rolled out in stages, and the headline change is already live: since 10 June 2025, a statutory tort for serious invasions of privacy lets individuals sue directly — covering both "intrusion upon seclusion" and "misuse of information." That turns a data mishap into a litigation risk, not just a regulatory one.

The penalties are substantial: a tiered civil-penalty regime tops out at A$50 million (or three times the benefit obtained, or 30% of adjusted turnover) for the most serious conduct, with a mid-tier option of A$3.3 million for companies. The Privacy Act applies to businesses with A$3 million-plus turnover, all health-service providers, and — importantly — overseas businesses that handle Australians' personal information. From 10 December 2026, organizations will also have to disclose in their privacy policy when automated decision-making is used. The regulator (the OAIC) has been running proactive compliance sweeps since January 2026, and imposed its first civil penalty — A$5.8 million against Australian Clinical Labs — in October 2025.

The rest of the world, briefly

If you have international visitors, a handful of other regimes follow them to your site. None are covered in depth here, but it's worth knowing they exist and roughly what they demand.

JurisdictionMain lawIn a sentence
CanadaPIPEDAConsent-based federal law; reform has been discussed for years
New ZealandPrivacy Act 2020Principles-based; notifiable-breach regime
ChinaPIPL (2021)Strict consent and data-localization rules; extraterritorial reach
SingaporePDPAConsent-and-notification model with an active regulator
MexicoFederal data-protection lawConsent-based; privacy-notice requirements
BrazilLGPDGDPR-style law with its own regulator (ANPD)

The pattern across all of them is the one you've now seen a dozen times: tell people what you're doing, get a real choice where required, and don't collect before you're allowed to.

What it all means for your website

Step back from the individual statutes and a single, practical throughline emerges. Whether it's the California Consumer Privacy Act's opt-out, CIPA's prior-consent rule, the GDPR's opt-in, or Australia's new tort, nearly every regime turns on the same underlying fact: what data your site collects, and whether it waited for the visitor's choice before doing so. Get that one thing right and you're aligned with the spirit — and most of the letter — of the entire patchwork.

That's also the thing most sites get wrong without realizing it. A consent banner can look perfect and still let trackers fire on page load, before anyone clicks anything — which is precisely the fact pattern behind the CIPA lawsuits and the CCPA opt-out enforcement alike. The fix isn't more legal text; it's prevention: making sure non-essential trackers are actually held until consent, and being able to prove it. That prevention-first, verify-don't-assume posture is exactly what ConsentPixel — Privacy · Verified is built around — blocking third-party trackers before consent by default and letting you see what really fires on your live site. This article is general information, not legal advice, but the one action that helps across almost every law on this page is the same: check what your site does before a visitor chooses.

Frequently asked questions

What is the California Consumer Privacy Act?

The California Consumer Privacy Act (CCPA) is California's consumer data-privacy law, in effect since 2020 and expanded by the California Privacy Rights Act (CPRA) in 2023. It requires businesses to disclose what personal information they collect, give consumers a working way to opt out of the sale or sharing of that information, honor opt-out preference signals like Global Privacy Control, and respect rights to access and delete data. It's enforced by the California Attorney General and the California Privacy Protection Agency, with per-violation civil penalties, and it has no private right of action except in certain data-breach cases. This is general information, not legal advice.

How many US states have privacy laws in 2026?

As of 2026, twenty US states have a comprehensive consumer privacy law in effect: California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island. Indiana, Kentucky and Rhode Island were the newest, all taking effect on January 1, 2026. Four more states — Alabama, Louisiana, Oklahoma and Vermont — passed laws in 2026 that are not yet effective, which will bring the total toward twenty-four. Florida's law is narrower than the others, applying mainly to very large technology companies.

Does CCPA compliance protect me from CIPA lawsuits?

No — and this is one of the most common and costly misunderstandings. The CCPA and CIPA are separate California laws that work differently. The CCPA is a notice-and-opt-out law enforced by regulators. CIPA is a 1967 wiretapping law that private individuals use to sue over website trackers that intercept a visitor's activity before consent, with statutory damages of $5,000 per violation under Cal. Penal Code §637.2. You can be fully aligned with the CCPA's opt-out requirements and still face a CIPA claim if third-party trackers fire before a California visitor consents. The two require different things.

Is there a US federal privacy law?

No. There is no comprehensive federal privacy law in the United States, which remains the only G20 country without one and has no national data-protection authority. The most recent serious attempt, the American Privacy Rights Act (APRA), cleared an initial committee step in 2024 but never reached a floor vote and expired at the end of the 118th Congress in January 2025; it has not been reintroduced. Sector-specific federal laws still apply — such as HIPAA for health data, the Gramm-Leach-Bliley Act for financial institutions, and COPPA for children — but for ordinary websites, state law governs.

Do UK, EU or Australian privacy laws apply to a US website?

They can, because most privacy laws follow the visitor rather than the business. If your site is used by people in the EU, the GDPR can apply; if by UK residents, the UK's Data (Use and Access) Act 2025 and UK GDPR; and Australia's Privacy Act 1988, as reformed, applies to overseas businesses that handle Australians' personal information. Each has its own requirements and penalties — the GDPR reaches €20 million or 4% of global turnover, and Australia's regime now includes a statutory right for individuals to sue for serious invasions of privacy. Where you're based does not by itself exempt you.

What's the single most important thing to get right across all these laws?

Controlling what your website collects and when. Nearly every regime on this page turns on the same underlying fact: whether your trackers waited for the visitor's choice before collecting data. The GDPR requires opt-in consent before non-essential trackers fire; CIPA requires prior consent before interception; the CCPA requires a working opt-out. A consent banner that looks fine but still lets trackers fire on page load fails all of these at once. The most useful action is to verify what actually fires on your live site before a visitor chooses — a prevention-first posture that aligns with the spirit of the whole patchwork. This is general information, not legal advice.

The bottom line

There is no single privacy law to comply with — there's a map. At its center is the California Consumer Privacy Act, flanked by California's tougher, privately-enforced CIPA, nineteen other state laws, and the UK, EU and Australian regimes that follow their residents to your door. No federal law ties it together, and none is coming soon.

But the map is easier to navigate than it looks, because the laws converge on one idea: tell people what you collect, give them a real choice, and don't collect before you're allowed to. The single highest-leverage thing you can do — good across California, the other states, the UK, the EU and Australia at once — is to make sure your trackers actually wait for consent, and to be able to prove it.

That's a fact about your site you can check today, rather than a legal question you have to guess at.

See what your site does before a visitor chooses

Across almost every law on this page, the pivotal question is the same. ConsentPixel — Privacy · Verified blocks third-party trackers before consent and shows you exactly what fires on your live site. Start with a free scan, then a 14-day trial.

Scan your site free →
No account needed for the scan · then a 14-day free trial, no credit card required
CP

The ConsentPixel Team

Privacy & Consent Compliance

ConsentPixel — Privacy · Verified is a consent platform delivered as a single JavaScript pixel: it blocks third-party trackers until affirmative consent, verifies what fires on your live site, honors opt-out signals like Global Privacy Control, and logs each decision as immutable evidence. This article is educational and not legal advice; legal facts reflect publicly reported information as of September 2026.

Information, not legal advice. This overview summarizes privacy laws for general educational purposes and does not constitute legal advice or create an attorney–client relationship. Laws, effective dates, thresholds and penalties described here reflect publicly reported information as of September 2026 and change frequently — including the status of California's SB 690, which awaited the Governor's signature at the time of writing. How any law applies to your website depends on your specific facts and jurisdictions; verify current requirements and consult qualified counsel. The $5,000-per-violation figure reflects statutory damages under California Penal Code §637.2. ConsentPixel — Privacy · Verified is not a law firm, and no single tool by itself makes a website compliant with any law.

Scroll to Top