On May 29, 2026, Louisiana Governor Jeff Landry signed Senate Bill 386 into law as Act No. 502, creating the Louisiana Data Privacy Act (LDPA). It makes Louisiana the 22nd US state with a comprehensive consumer privacy statute and takes effect January 1, 2027 — giving covered businesses a short runway to prepare.
What is the Louisiana Data Privacy Act?
The LDPA is a state consumer privacy law that gives Louisiana residents the right to access, correct, delete, and port their personal data, and to opt out of targeted advertising, the sale of their data, and certain profiling. It follows the opt-out model used by most US state privacy laws — meaning businesses don't need blanket prior consent to process most personal data, but must give consumers a clear way to opt out and must obtain opt-in consent for sensitive data.
Enforcement rests exclusively with the Louisiana Attorney General. Like several other state laws — and unlike California's CCPA — the LDPA does not create a private right of action, so the compliance risk runs to the state rather than to consumer lawsuits.
Who does the LDPA apply to?
The law applies to any person or entity that conducts business in Louisiana and, during a calendar year, meets at least one of these thresholds:
- Earns annual gross revenues exceeding $25 million; or
- Buys, receives, sells, or shares the personal data of 75,000 or more consumers, households, or devices; or
- Derives 50% or more of annual revenue from selling consumers' personal data.
Who is exempt?
State agencies, GLBA-regulated financial institutions, HIPAA covered entities and business associates, nonprofits, higher-education institutions, and certain utilities sit outside the LDPA's scope. Several data categories are also exempt, including HIPAA-protected health information and data used solely for employment and benefits administration.
Consumer rights under the LDPA
Residents may submit a verified request to a controller, who must respond within 45 days (with a single 45-day extension where reasonably necessary). The rights are:
- Access & confirmation — confirm whether their data is processed and obtain a copy.
- Correction — fix inaccuracies, considering the nature and purpose of processing.
- Deletion — delete data they provided or that the controller collected about them.
- Portability — receive their data in a portable, readily usable format where feasible.
- Opt-out — of the sale of personal data, targeted advertising, and profiling that produces legal or similarly significant effects.
Controllers must offer a conspicuous appeal process and respond to appeals in writing within 60 days; a denied appeal must point the consumer to the Attorney General's complaint mechanism.
Sensitive data & opt-in consent
Processing sensitive data requires affirmative opt-in consent. Under the LDPA, sensitive data includes:
- Racial or ethnic origin, religious beliefs, or sexuality
- Mental or physical health diagnosis
- Citizenship or immigration status
- Genetic data, and biometric data processed to uniquely identify an individual
- Precise geolocation data
- Personal data of a known child (processed in accordance with COPPA)
The LDPA defines consent as a clear affirmative act that is freely given, specific, informed, and unambiguous. It explicitly does not count acceptance of broad terms of use, passive actions like hovering or closing content, or anything obtained through dark patterns.
Opt-out signals & Global Privacy Control
The LDPA allows consumers to exercise opt-out rights through authorized agents using technologies such as browser settings, browser extensions, or global device controls, where the business can verify the request using commercially reasonable efforts. Honoring a recognized universal opt-out signal such as Global Privacy Control (GPC) is the practical way to meet this — and reflects the clear direction of US state privacy law, where a growing majority of states now expect GPC support.
Business obligations at a glance
- Data minimization & purpose limitation — collect only what's reasonably necessary; get consent for new, unrelated uses.
- Reasonable security — administrative, technical, and physical safeguards appropriate to the data.
- Clear opt-out mechanisms — for sale, targeted advertising, and significant-effect profiling.
- Transparent privacy notice — categories of data, purposes, how to exercise and appeal rights, and (if applicable) sale disclosures.
- Sensitive/biometric sale notice — a posted notice if you sell sensitive or biometric data.
- Two request methods — at least two secure ways for consumers to submit rights requests.
- Data protection assessments — for higher-risk processing, required for activities from Jan 1, 2027 onward (not retroactive).
- Processor contracts (DPAs) — written agreements specifying nature, purpose, data types, duration, and deletion procedures.
Penalties, enforcement & the cure period
The Louisiana Attorney General has exclusive enforcement authority, treating violations as unfair and deceptive trade practices under Louisiana's Unfair Trade Practices and Consumer Protection Law. The LDPA itself doesn't set a separate civil-penalty figure; penalties flow through that existing statute.
A transitional 30-day cure period applies from January 1 through July 31, 2027: during that window the AG must give written notice and may not proceed if the business cures the violation and documents the fix. After July 31, 2027, the mandatory cure period disappears.
LDPA vs. CCPA — quick comparison
| Dimension | Louisiana (LDPA) | California (CCPA/CPRA) |
|---|---|---|
| Consumer threshold | 75,000 records | 100,000 consumers |
| Sensitive data | Opt-in consent model | Right-to-limit model |
| Private right of action | None | Limited (data breaches) |
| Enforcement | Attorney General | CPPA + Attorney General |
| Scope trigger | Operating in Louisiana | Targeting California residents |
LDPA readiness checklist
- Confirm whether you cross any of the three coverage thresholds.
- Map the personal data you collect, its uses, storage, and sharing.
- Publish a clear privacy notice (plus a sale notice if selling sensitive/biometric data).
- Enable opt-out of targeted advertising, sale, and profiling — and honor GPC.
- Obtain opt-in consent before processing sensitive data; follow COPPA for known children.
- Provide two secure rights-request methods and an appeal process.
- Run data protection assessments for higher-risk processing.
- Put DPAs in place with all processors.
Be ready for January 1, 2027
ConsentPixel deploys as a single JavaScript pixel that blocks tracking until consent, honors GPC, handles opt-in for sensitive data, and adapts the banner to each visitor's state — including Louisiana.
Start protecting your site