Alabama, Louisiana, Oklahoma, and Vermont have enacted new consumer privacy statutes, expanding the complex patchwork of US data regulation and demanding more nuanced compliance efforts from businesses across states.
A new cluster of state privacy laws is set to expand the compliance burden for companies operating across the US. Alabama, Louisiana, Oklahoma and Vermont have each enacted broad consumer privacy statutes that will take effect between 2027 and 2028, adding to an already fragmented national landscape. For businesses that collect, share or monetise personal data, the practical effect will be more notice requirements, more consumer rights requests and more variation in how state rules are written and enforced.
In Alabama, the Personal Data Protection Act will take effect on May 1, 2027. According to whitecase.com and other legal analyses, the law applies to companies that control or process personal data of more than 25,000 consumers, excluding data used only to complete a payment transaction, or that derive more than 25% of gross revenue from the sale of personal data. It gives residents rights to access, correct, delete and obtain a copy of their data, along with opt-outs from targeted advertising, sales and profiling. The statute also requires opt-in consent for sensitive data and adopts a broad definition of sale that can include transfers for other valuable consideration when the recipient is not limited in later use.
Louisiana’s law takes effect on January 1, 2027 and is written more like a California-style regime than some earlier state laws. Legal summaries say it reaches businesses that do business in Louisiana and meet one of three tests: annual gross revenue above $25 million, annual handling of personal information for 75,000 or more consumers, households or devices, or at least 50% of revenue from selling personal information. Residents will have rights to know, correct, delete and port their data, as well as to opt out of targeted advertising, sales and profiling. The law also requires consent for sensitive data and a specific warning when sensitive information is sold: “NOTICE: We may sell your sensitive personal data.”
Oklahoma’s Data Privacy Act also becomes effective on January 1, 2027 and is aimed at entities that do business in the state or target Oklahoma residents. The thresholds are either processing personal data of at least 100,000 consumers in a calendar year or processing data of at least 25,000 consumers while earning more than 50% of gross revenue from the sale of personal data, according to the materials reviewed. Residents receive the now-familiar package of rights to know, correct, delete and port data, plus opt-outs for targeted advertising, sales and profiling. Enforcement will sit with the attorney general, who must give 30 days’ written notice before filing suit and may be blocked from proceeding if the company cures the violation and commits in writing to compliance.
Vermont stands apart for both its lower thresholds and its broader reach. The Vermont Data Privacy and Online Surveillance Act takes effect on January 1, 2028 and applies to businesses that operate in the state or target Vermont residents if they control or process the personal data of 35,000 residents, process sensitive data of at least 3,000 residents or offer for sale the personal data of 3,000 or more residents. In addition to standard privacy rights, residents may question profiling and ask for a list of third parties to whom their data has been disclosed. The law also contains separate protections for consumer health data, including gender-affirming, reproductive and sexual health data. Enforcement will rest exclusively with the Vermont attorney general, who must issue a notice of violation during a specified cure period if a fix appears possible.
For compliance teams, the larger point is not just that four new laws are arriving, but that each one adds a slightly different rule set. Thresholds, consent standards, cure periods and definitions of sale all vary, which means multi-state privacy programmes will need to be mapped law by law rather than treated as interchangeable. The result is a sharper need for data inventories, consumer request workflows and vendor controls that can withstand a growing patchwork of state requirements.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





