Twenty US states now have a comprehensive consumer privacy law in effect. If your marketing team runs paid campaigns, tracks conversions in GA4, or personalizes a website based on browsing behavior, that fact already governs how you can do it, whether or not anyone on your team has read a single statute.
This guide translates that patchwork into what marketing operations actually need to do: which states apply to you, what counts as "targeted advertising" and "sharing" under these laws, how platform-level consent gating works for GA4 and Meta, and where enforcement is actually landing in 2026.
Why enforcement changed in 2026
For most of 2023 and 2024, state privacy enforcement focused on the basics: was there a working "Do Not Sell" link, did the privacy policy exist. That's no longer where the risk is.
On September 9, 2025, California's Privacy Protection Agency and Attorney General, joined by the Colorado and Connecticut Attorneys General, announced a joint investigative sweep targeting one specific failure: businesses that display an "opt-out honored" message while continuing to fire retargeting pixels for visitors whose browsers send a Global Privacy Control (GPC) signal. The three states sent letters to non-compliant businesses ordering them to fix it, building on California's earlier $1.2 million settlement with Sephora over the same underlying issue.
That sweep matters for marketing teams specifically because GPC compliance isn't a legal-team checkbox. It's a tag-management problem: your ad and analytics scripts have to detect the signal and stop firing in response to it, in real time, regardless of what a user clicked in a cookie banner last week.
Three converging pressures explain why 2026 is the year this stopped being deferrable:
- Universal opt-out signals are now mandatory in twelve states. California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas all require businesses to treat a GPC signal as a valid "do not sell or share" request.
- Sensitive-data categories keep expanding. Precise geolocation, health inferences, and (in Oregon and Connecticut) neural data now require opt-in consent before marketing use in most states, not the opt-out standard that applies to ordinary personal data.
- "Sharing" now clearly includes ad-platform pixels. State laws define sharing as transferring data to an ad platform to improve targeting or build lookalike audiences, whether or not money changes hands. Under that definition, a Meta Pixel, TikTok Pixel, or LinkedIn Insight Tag is a data-sharing mechanism that triggers opt-out obligations.
Which states have a privacy law in 2026
Twenty states have a comprehensive privacy law in effect as of today, per IAPP's state privacy legislation tracker (Secure Privacy keeps its own running US state privacy law tracker updated alongside it). Four more (Alabama, Louisiana, Oklahoma, and Vermont) have enacted laws that aren't yet in force, bringing the total enacted to 24.
| State | Statute | Effective date | Enforcement |
|---|---|---|---|
| California | CCPA/CPRA | Jan 1, 2023 (amended) | CPPA / Attorney General |
| Virginia | VCDPA | Jan 1, 2023 | Attorney General |
| Colorado | CPA | July 1, 2023 | Attorney General / DAs |
| Connecticut | CTDPA | July 1, 2023 | Attorney General |
| Utah | UCPA | Dec 31, 2023 | Attorney General |
| Texas | TDPSA | July 1, 2024 | Attorney General |
| Oregon | OCPA | July 1, 2024 | Attorney General |
| Florida | FDBR | July 1, 2024 | Attorney General |
| Montana | MTCDPA | Oct 1, 2024 | Attorney General |
| Iowa | ICDPA | Jan 1, 2025 | Attorney General |
| Delaware | DPDPA | Jan 1, 2025 | Attorney General |
| Nebraska | NDPA | Jan 1, 2025 | Attorney General |
| New Hampshire | NHPA | Jan 1, 2025 | Attorney General |
| New Jersey | NJDPA | Jan 15, 2025 | Attorney General |
| Tennessee | TIPA | July 1, 2025 | Attorney General |
| Minnesota | MCDPA | July 31, 2025 | Attorney General |
| Maryland | MODPA | Oct 1, 2025 | Attorney General |
| Indiana | ICDPA | Jan 1, 2026 | Attorney General |
| Kentucky | KCDPA | Jan 1, 2026 | Attorney General |
| Rhode Island | RIDTPPA | Jan 1, 2026 | Attorney General |
Florida is a partial exception worth flagging explicitly rather than folding in quietly: the Florida Digital Bill of Rights only applies to for-profit businesses with over $1 billion in global annual revenue that also meet a second condition, like deriving half their revenue from online advertising or operating a large app store. Most marketing teams never trigger it, which is why some trackers count 19 states rather than 20.
Indiana, Kentucky, and Rhode Island are the newest additions, and Rhode Island is the one to watch closest. Its applicability threshold is lower than most states (35,000 residents, or 10,000 if data sales exceed 20% of revenue), and unlike Indiana and Kentucky's 30-day cure periods, it gives businesses no opportunity to fix a violation before facing enforcement.
What these laws require, regardless of state
Despite the state-by-state variation in thresholds and penalties, four requirements show up in every comprehensive state privacy law and directly affect how marketing teams operate.
Consumer data rights. Every state grants residents the right to access, correct, and delete their personal information. For a marketing team, that means being able to locate one person's record across your CRM, email platform, CDP, and any data warehouse, not just your primary database.
Opt-out of targeted advertising. State laws define targeted advertising as serving ads based on a consumer's activity across different businesses or websites. Retargeting someone who visited your product page with a Facebook ad meets that definition. So does building a lookalike audience from your customer list. Each state requires a clear, accessible way for consumers to opt out, and that opt-out has to actually suppress the pixels and API calls involved, not just stop showing a banner.
Data minimization and purpose limitation. You can only collect data that's adequate and relevant to the purpose you disclosed. If your privacy notice says you collect email addresses to send promotional offers, using that same list to build a suppression list for a different campaign type is a separate purpose that needs its own disclosure.
Vendor contract terms. Every third party that processes personal data on your behalf needs a data processing agreement naming it as a "service provider" or "processor," barring it from using your customers' data for its own purposes, and requiring it to assist with consumer rights requests. Your compliance posture is only as strong as your weakest vendor contract; state laws hold the business responsible for a vendor's data practices, not just the vendor.
GPC and the universal opt-out signal
Global Privacy Control has moved from an experimental browser feature to a legally mandated signal in the twelve states listed above. It works through two channels: an HTTP header sent with every browser request, and a JavaScript property that scripts on your site can read. When a user turns on GPC in their browser or a privacy extension, every site they visit receives that preference automatically, without the user filling out a form.
The compliance requirement is straightforward to state and hard to fully execute: a business has to detect the GPC signal and immediately stop any tracking or sharing that the law defines as requiring an opt-out, before the user ever interacts with a cookie banner and regardless of any consent given previously. That's the exact gap the September 2025 joint sweep targeted, since it's easy to display a compliant-looking banner while the underlying scripts keep firing.
California added a wrinkle for 2026: businesses now have to show visible confirmation, typically a footer notice or privacy-center message, when a GPC signal has been honored. And because consumers increasingly move between devices, the opt-out has to follow a logged-in user across sessions and devices tied to their account, not reset every time they open a new browser.
Consent gating on GA4 and Meta
Two platform-level changes are worth marketing teams' direct attention in 2026, at the level of what's required rather than how to click through the setup.
Google Analytics 4 has a hard deadline of June 15, 2026, after which Google Signals retires and a single parameter (ad_storage) becomes the sole gate on advertising data. GA4's Consent Mode was built specifically to let a site keep collecting some analytics signal even when a regulated-state user denies tracking consent, by substituting anonymous "cookieless pings" and behavioral modeling for identified events. The tradeoff is precision for coverage: reporting for non-consenting users becomes probabilistic, not deterministic, and marketing teams need to plan for that gap in year-over-year comparisons rather than be surprised by it.
Meta's Limited Data Use (LDU) parameter is still the primary US compliance mechanism for the Pixel and Conversions API. When it's applied to an event, Meta is contractually restricted from using that data to build its own audience models or target other advertisers, operating instead as a processor for your campaign alone. Which states' users need LDU applied keeps expanding as more states pass privacy laws, so treat this as a moving target checked against Meta's current documentation rather than a fixed list. The Conversions API's server-side delivery also means the compliance check (has this user opted out) can happen before data ever leaves your server, which is a meaningfully more reliable enforcement point than a browser-side pixel that a consumer's ad blocker or privacy extension might interfere with anyway.
Where marketing teams get this wrong
Enforcement activity from 2025 and early 2026 points to a small number of recurring failure patterns.
- Performative GPC handling. A banner says the opt-out is honored while tag management continues firing retargeting pixels. Regulators test this directly, by visiting a site with GPC enabled and inspecting the network traffic that actually fires.
- No consent records to produce. When an Attorney General's office asks for proof a business honored a specific opt-out request, the inability to produce a log creates a presumption of non-compliance. A retained, exportable record of consent decisions and opt-out events is now table stakes, not a nice-to-have.
- Asymmetric consent interfaces. Making "Reject All" visually secondary to "Accept All," or requiring more clicks to opt out than to opt in, is one of the most commonly cited dark-pattern violations.
- Geolocation tracking without opt-in. Location tracking accurate to within roughly 1,750 to 1,850 feet (the exact radius varies by state; California's CPRA and Virginia's VCDPA don't use the same figure) counts as sensitive precise geolocation in most states, which means it needs opt-in consent, not the opt-out default that covers ordinary personal data. Mobile geofencing campaigns are a common blind spot here.
- Untracked vendor relationships. A new martech tool gets added to the stack without legal or privacy review, and without a compliant data processing agreement in place every data transfer to that vendor is arguably an unauthorized sale or share.
Building a compliance program that holds up
Marketing teams still building out their state privacy compliance program tend to get further, faster, by working through it in a defined order rather than trying to fix everything simultaneously.
Start with an honest technical inventory: what scripts, pixels, and beacons are actually live across your properties, what each one does, and whether it changes behavior correctly when a GPC signal is present. From there, close the gaps in your public-facing notices, particularly anything specific to newer states like Indiana, Kentucky, and Rhode Island. Then work through your vendor contracts, since a data processing agreement that doesn't name state-law sale and sharing prohibitions specifically is a real gap, and remove any tracking script tied to a vendor relationship that's no longer active. Treat the result as an ongoing operational responsibility rather than a one-time project: quarterly tag audits and a monthly export of consent decision records are the two habits that most directly reduce enforcement exposure.
Two state-specific details are worth keeping in your back pocket regardless of where you are in that process. Texas gives businesses a 30-day cure period to fix a TDPSA violation before facing enforcement, which most other states don't offer. Virginia requires a response to a consumer rights request within 45 days, a shorter window than some teams assume.
Frequently asked questions
Do state privacy laws apply based on where my business is located or where my customers are?
Customer location, not business headquarters. If you have consumers in California, Colorado, Virginia, or any of the other states with a comprehensive law now in effect, that law applies to you regardless of where your company is based.
Does a "Do Not Sell" opt-out actually stop my retargeting ads?
It should, and regulators are actively checking. An opt-out that only removes a cookie banner without also suppressing the retargeting pixel or API call is exactly the "performative" gap the 2025 GPC enforcement sweep targeted.
Is Google Analytics 4 itself non-compliant with state privacy law?
No. GA4 is a tool, and its Consent Mode is built to help a business comply, but the business is still responsible for configuring it correctly, honoring opt-outs and GPC signals, and not collecting more than the consent given allows.
How is "sharing" different from "selling" personal data under these laws?
Selling generally means an exchange for money. Sharing is broader: sending data to an ad platform to improve targeting or build lookalike audiences counts as sharing even when nothing is paid, which is why a Meta or TikTok pixel triggers the same opt-out obligations as a data sale would.
Where a consent management platform fits
None of this is manageable by manually tracking twenty states' requirements in a spreadsheet, which is part of why consent management for marketing teams has become its own discipline. Secure Privacy's platform supports 55+ privacy laws, automatically detects and honors GPC signals without extra configuration, and includes built-in DSAR handling, which covers the operational core of what this guide describes: detecting the right signal, suppressing the right tracking, and keeping a record that proves it happened.
The state privacy landscape isn't done changing. Four more states have already enacted laws that will take effect after this one, and the enforcement pattern from 2025's GPC sweep suggests regulators are moving from policy checks to technical verification. Marketing teams that build consent handling into their martech stack now, rather than treating it as a legal-team afterthought, are the ones that won't be scrambling at the next effective date.


