Privacy Laws That Apply to Website, App and CTV Tracking
Vault JS tracks 45 privacy laws that govern how websites, mobile apps and connected TV apps collect and share data. Each page covers what the law requires for cookies, pixels and SDKs, who enforces it, penalties, and key dates.
Updated October 2026. Summaries are for general information, not legal advice.
See which states have laws in force on the US privacy law map, check any country on the global privacy laws map, or estimate exposure with the privacy fine calculators.
24 laws
US State Privacy Laws
Comprehensive consumer privacy laws in 24 states. Most give residents the right to opt out of targeted advertising and the sale of their data, and a growing number require businesses to honor Global Privacy Control and other opt-out signals.
Alabama PDPA
Alabama's privacy law, effective May 1, 2027. 25,000-consumer threshold, opt-outs, consent for sensitive data, 45-day cure, $15,000 per violation.
CaliforniaCCPA / CPRA
California's privacy law, enforced by the CPPA and AG. Opt-outs and GPC must actually work; fines run to $7,988 per intentional violation.
ColoradoCPA
Colorado's privacy law. Universal opt-out signals like GPC must be honored since July 2024; cure period ended in 2025. AG enforced.
ConnecticutCTDPA
Connecticut's privacy law (July 2023). 35,000 threshold and no-threshold triggers since July 2026; opt-out signals required; AG enforced.
DelawareDPDPA
Delaware's privacy law (Jan 2025). Opt-out signals required since 2026; the threshold drops to 10,000 consumers in 2027. DOJ enforces.
FloridaFDBR
Florida's Digital Bill of Rights (July 2024) applies to $1B+ companies. $50,000 per violation, tripled for known children.
IndianaIndiana CDPA
Indiana's Virginia-model privacy law, effective Jan 1, 2026. Opt-outs, opt-in for sensitive data, AG enforcement, permanent 30-day cure.
IowaICDPA
Iowa's light-touch privacy law (Jan 2025). Opt-out of sale, notice-based sensitive data rules, 90-day cure, $7,500 per violation.
KentuckyKentucky CDPA
Kentucky's Virginia-model privacy law, effective Jan 1, 2026. Opt-outs of targeted ads and sale, AG enforcement, 30-day cure.
LouisianaEffective 2027Louisiana DPA
Louisiana's privacy law, effective Jan 1, 2027. $25M revenue or 75,000-consumer threshold, opt-outs, consent for sensitive data, AG enforces.
MarylandMODPA
Maryland's strict privacy law (Oct 2025). Data minimization standard, outright ban on selling sensitive data, no targeted ads to under-18s.
MinnesotaMinnesota CDPA
Minnesota's privacy law (July 2025). Right to a list of specific third parties, universal opt-out required, AG enforced, $7,500 per violation.
MontanaMontana CDPA
Montana's privacy law (Oct 2024). 2025 amendments cut the threshold to 25,000 consumers and removed the cure period. Universal opt-out required.
NebraskaNDPA
Nebraska's privacy law (Jan 2025), Texas-style scope with no consumer threshold. Universal opt-out required, 30-day cure, $7,500 per violation.
New HampshireNHDPA
New Hampshire's privacy law (Jan 2025). 35,000-consumer threshold, opt-out signals honored from day one, AG enforcement.
New JerseyNJDPA
New Jersey's privacy law (Jan 2025). Universal opt-out required since July 2025; cure period ended July 2026; financial data is sensitive.
OklahomaEffective 2027OKCDPA
Oklahoma's privacy law, effective Jan 1, 2027. Virginia model, 100,000-consumer threshold, AG enforcement, 30-day cure, $7,500 per violation.
OregonOCPA
Oregon's privacy law (July 2024). Broad sensitive-data rules, geolocation sale ban from 2026, universal opt-out required, DOJ enforced.
Rhode IslandRI Data
Rhode Island's privacy law (Jan 2026) requires naming every third party you sell data to. No cure period, up to $10,000 per violation.
TennesseeTIPA
Tennessee's privacy law (July 2025) with the highest thresholds and a NIST Privacy Framework affirmative defense. Treble damages if willful.
TexasTDPSA
Texas privacy law (July 2024) covering nearly every non-small business. Universal opt-out required; the Texas AG is an active enforcer.
UtahUCPA
Utah's business-friendly privacy law (Dec 2023). Opt-outs of targeted ads and sale, $25M revenue threshold, permanent 30-day cure.
VermontEffective 2028Vermont DPOSA
Vermont's privacy law, effective Jan 1, 2028. Data minimization, universal opt-out signals, health-data geofencing ban, AG enforcement.
VirginiaVCDPA
Virginia's consumer data law (Jan 2023). Opt-outs of targeted ads and sale, opt-in for sensitive data, AG enforcement, $7,500 per violation.
11 laws
US Federal and Sector Laws
Laws that apply because of the type of data or the way it is collected. Wiretap statutes like CIPA drive most pixel and session replay lawsuits; others cover video viewing history, health data, biometrics and children.
Age-Appropriate Design Codes
State codes for services likely used by children: high-privacy defaults, no dark patterns. California's is enjoined; Vermont's starts 2027.
IllinoisBIPA
Illinois biometric law. Written notice and release before collecting face, voice or fingerprint data; $1,000 to $5,000 per violation, private suits.
CaliforniaCIPA
California's wiretap law, the top source of privacy class actions. $5,000 per violation; SB 690 ends pen-register suits, wiretap claims continue.
CaliforniaCMIA
California's medical privacy law, broader than HIPAA. Private right of action, $1,000 per violation without proof of harm; pixel suits pair it with CIPA.
FederalCOPPA
Federal children's privacy law for under-13s. Parental consent before collecting identifiers; amended rule in full effect since April 2026.
FederalFTC Act, Section 5
The FTC's authority over unfair or deceptive practices. Tracking cases turn on the gap between what the privacy policy says and what pixels do.
FederalGLBA
Federal financial privacy law. Notice and opt-out before sharing customer data with nonaffiliated third parties; FTC, CFPB and bank regulators enforce.
FederalHIPAA / HITECH
Federal health privacy rules. Tracking pixels on patient portals and authenticated pages can transmit PHI; OCR enforces, settlements exceed $100M.
WashingtonMy Health My Data Act
Washington's consumer health data law. Consent to collect and share, authorization to sell, geofencing ban, private right of action. In force 2024.
FederalVPPA
Federal law on disclosing video viewing history. $2,500 per person; revived against sites and apps where pixels send video titles plus IDs.
FederalWiretap Act / Stored Communications Act
Federal ECPA claims against interception of communications. Wiretap Act damages of $10,000; the crime-tort exception drives pixel litigation.
10 laws
International Privacy Laws
Data protection and cookie laws outside the US. Most require opt-in consent before any non-essential cookie or tracker runs, and regulators like France’s CNIL have fined companies hundreds of millions of euros for getting it wrong.
Privacy Act 1988 (+ reforms)
Australia's privacy law and its 2024 reforms: a new privacy tort, new lower penalty tiers, and a children's online privacy code. Max penalty A$50M.
BrazilLGPD
Brazil's general data protection law (2020), modeled on GDPR and enforced by the ANPD. Fines up to 2% of Brazil revenue, R$50M per violation.
CanadaQuebec Law 25 (+ PIPEDA)
Quebec's privacy law: tracking that identifies, locates or profiles must be off by default since Sept 2023. Fines up to C$25M or 4%.
ChinaPIPL (+ DSL, CSL)
China's personal information law (Nov 2021). Separate consent for sharing and sensitive data; app SDKs are the CAC's main enforcement target.
EUePrivacy Directive
The EU cookie law. Prior consent before storing or reading anything on a device, enforced by national regulators like the CNIL.
EU / EEAGDPR
The EU's data protection regulation (May 2018). Consent must be freely given and withdrawable; fines reach €20M or 4% of global turnover.
IndiaDPDP Act + Rules 2025
India's data protection law and 2025 Rules. Verifiable parental consent for under-18s, no tracking or targeted ads to children, penalties to ₹250 crore.
Japan, Korea, SingaporeAPPI / PIPA / PDPA
Japan, Korea and Singapore's privacy laws. Opt-in third-party sharing in Japan, strict separate consent in Korea, PDPC enforcement in Singapore.
SwitzerlandFADP (revised)
Switzerland's revised data protection law (Sept 2023). GDPR-like duties, express consent for high-risk profiling, fines up to CHF 250,000 on individuals.
United KingdomUK GDPR + PECR
UK data protection and cookie rules enforced by the ICO. 2025 reforms raised PECR fines to £17.5M or 4% of global turnover.
See which of these laws apply to what your sites send
Vault JS tests your websites, mobile apps and CTV apps the way a regulator or plaintiff’s expert would, and maps every finding to the laws that apply to you.
Get a free site analysis