
US state data privacy laws timeline
US data privacy laws effective in 2023
California Privacy Rights Act (amendment to CCPA)
Effective date: January 1, 2023
Official Text: Proposition 24
Virginia Consumer Data Protection Act
Effective date: January 1, 2023
Official Text: SB 1392
Colorado Privacy Act
Effective date: July 1, 2023
Official Text: SB 190
Connecticut Personal Data Privacy and Online Monitoring Act
Effective date: July 1, 2023
Official Text: SB 6
Utah Consumer Privacy Act
Effective date: December 31, 2023
Official Text: SB 227
Steps for compliance with state privacy laws in the US
As laws in California, Virginia, Colorado and Connecticut are already in place and the operative date for Utah is nearing by the end of 2023, you need to be prepared for compliance. It is important to carefully assess the differences and nuances of the law(s) that apply to your business, through a legal counsel.
Here are the foundational steps that you can build upon to achieve compliance with specific provisions of laws that apply to your business.
Data mapping: Perform a comprehensive data inventory to identify the types of personal information your business collects, uses, and shares. Map how personal information moves through your business processes and systems.
Data processing impact assessments: Evaluate the risks associated with the processing of personal data and the potential impact on consumer privacy. This is especially important for processing sensitive personal data.
Review and update privacy policies: Implement clear and transparent privacy policies that inform consumers about the types of personal information collected, how it is used, and who it is shared with, including disclosures of consumer rights that apply to the respective privacy law.
Establish an opt-out mechanism: Implement a consent management platform (CMP) for users to opt out of the sale or sharing of personal data for targeted advertising and profiling (in the case of Colorado, Connecticut, and Virginia). States of California and Colorado require at least two opt-out methods such as online forms, email, telephone, and CMPs.
Respect universal opt-out signals: Receive and honour user choices made through universal opt-out browser signals on or global privacy controls (GPC), a requirement under California, Colorado, and Connecticut privacy laws.
Handle consumer data requests: Establish processes to handle consumer data requests, such as providing access to their data, deleting their data, or opting out of data sharing. You should address consumer requests within the stipulated time period of the respective laws.
Implement data security: Implement robust data security measures to ensure compliance with CIS controls or other industry standards to protect consumer data from unauthorized access, use, or disclosure.
Update third-party agreements: Conduct audits of third-party processors, vendors and service providers who have access to or process personal information on your behalf. Review and update data processing agreements to include contain specific provisions and obligations required by the respective laws.
Train your employees: Educate employees on best practices for handling consumer data securely and responsibly. Implement internal policies and procedures to ensure that your organization responds to consumer requests as required by the law.
Other federal data privacy laws in the US
While there is an absence of a unified federal data privacy law in the US, there are federal privacy laws addressing specific areas like healthcare, financial services, and credit reporting.
Privacy Act of 1974
The Privacy Act of 1974 regulates the collection, use, and disclosure of personal information by the federal government and agencies. The act establishes guidelines for federal agencies on how they can collect and maintain personal information and provides individuals with the right to access and correct their records.
Children's Online Privacy Protection Act (COPPA)
COPPA is a federal law enacted in 1998 that aims to protect the online privacy of children under the age of 13. It requires websites, online platforms and service providers to obtain parental consent before collecting any personal information from children and to have a clear privacy policy that explains how they collect, use, and disclose personal information.
Controlling the Assault of Non-Solicited Pornography and Marketing (CAN-SPAM)
CAN-SPAM is a legislation that came into effect in 2003 to protect individuals from the onslaught of unsolicited emails and online marketing campaigns. The act established various obligations for sending commercial email messages, including the need for accurate sender information, clear identification of advertisement or commercial content, and an unsubscribe mechanism.
The Health Insurance Portability and Accountability Act (HIPAA)
HIPAA is a federal law in the United States that was enacted in 1996 and governs the privacy and security of individuals' protected health information (PHI). HIPAA sets standards to safeguard PHI and applies to healthcare providers, health plans, and healthcare clearinghouses, as well as their business associates.
The Gramm-Leach-Bliley Act (GLBA)
GLBA is a federal legislation that was enacted in 1999 and governs the privacy and security of consumer financial information. It requires financial institutions and companies that offer consumers financial products or services like loans, financial or investment advice, or insurance to implement various measures to protect the personal information of their customers.
The Fair Credit Reporting Act (FCRA)
FCRA is a federal law that was passed in 1970 and regulates the collection, accuracy, and use of consumer credit information. It aims to promote fairness, accuracy, and privacy in the credit reporting system and establishes guidelines for credit reporting agencies, creditors, and consumers.
American Data Privacy Protection Act (ADPPA) - Proposed bill
ADDPA is a proposed federal law that was introduced in 2022 aimed at safeguarding the privacy of individuals' personal information. If enacted into law, this bill will establish comprehensive regulations for collecting, using and processing personal data by businesses and organizations operating in the United States.



