The US continues to see a surge in state-level consumer privacy laws in 2026, with added restrictions on sensitive data, geolocation, and profiling, making compliance more complex for national companies.
State consumer privacy law in the US is becoming more fragmented, not less. A mid-year review by privacy lawyers at Squire Patton Boggs says 2026 began with 20 comprehensive state consumer privacy laws in force, and four more were added in the first half of the year, taking the total to 24 since California introduced the CCPA in 2018. The firm says the latest wave of amendments is also pushing the rules further towards tighter limits on sensitive data, minors’ data, precise geolocation and profiling.
The newest laws, in Alabama, Louisiana, Oklahoma and Vermont, broadly follow the now-familiar state privacy framework, with entity and data thresholds, consumer rights and controller-processor contract requirements. But the review says Vermont stands out for its expansive treatment of derived data, consumer health data and profiling, while Alabama and Louisiana add narrower but still significant changes to sale definitions, opt-out mechanics and notice obligations. Venable’s separate mid-year update likewise describes the first half of 2026 as a period of heavy legislative activity, especially around sensitive data, data broker transparency and the overlap between privacy and AI regulation.
One of the clearest trends is the rising hostility to sales of sensitive data and precise geolocation data. The Squire Patton Boggs review says Vermont now requires extra consent before consumer health data can be sold, while Louisiana requires additional consent and a specific warning for sales of sensitive personal data. It also notes that several other states have tightened rules in the same direction: Maryland and New Jersey now ban sales of all sensitive personal data, Connecticut and Virginia prohibit sales of precise geolocation data, Oregon has restricted sales and targeted advertising involving minors’ data and precise location, and New Hampshire has barred sales of children’s data.
The practical burden on compliance teams is also rising around universal opt-out mechanisms and residency checks. Senator Ron Wyden has urged attorneys general in states with universal opt-out rules to make clear that organisations should honour opt-out signals from residents even when an IP address suggests they are outside the state, arguing that geolocation filtering can be unreliable. The Squire Patton Boggs review says that creates uncertainty for companies trying to decide whether IP-based filtering remains a defensible way to decide whose signal to honour, particularly as more states add restrictions on sales, sharing and targeted advertising.
The patchwork is also becoming harder to reconcile because the laws diverge on profiling, consumer health data, access rights and risk assessments. Vermont gives consumers unusually broad rights over profiling and inference data, and its notice rules are more detailed than most, including disclosure about whether personal data is used to train large language models. Louisiana and Oklahoma impose risk assessment duties for high-risk processing from 2027, while Vermont delays a similar requirement until 2028. The review says these differences mean firms can no longer rely on a single national template if they want to avoid the highest-risk conduct in each state.
Amendments already in force or due later in 2026 add to that complexity. Connecticut has broadened its rules on facial recognition, publicly available data and precise geolocation sales, while Maryland has expanded the definition of sensitive data and restricted certain disclosures to government entities involved in immigration enforcement. Virginia has now banned the sale of precise geolocation data, and New Jersey has moved further towards a near-total bar on sensitive data sales, with a separate data broker registry regime still waiting to be fully launched. A Delaware bill that would further lower thresholds and add new assessment and minimisation duties remains pending gubernatorial action.
The overall picture, according to the lawyers’ review and the supporting industry commentaries, is that state privacy compliance is shifting from a legal checkbox exercise into a continuous operational discipline. The direction of travel is towards more restrictions, more exceptions and more state-specific nuance, especially for health, biometric, minors’ and location data. For companies operating nationally, the safest course may increasingly be to design around the strictest rules rather than trying to maintain separate systems for each jurisdiction.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





