The State Privacy Law Wave Heading Into 2027: What Every Company Must Have in Place Now

October 1, 2026
AN Law Firm

As 2026 draws to a close, the U.S. state privacy law landscape looks nothing like it did even a year ago. If your company collects, uses, or sells personal data — and virtually every company does — this is not a year you can afford to coast on last year’s compliance program, and 2027 will bring another round of obligations for companies that haven’t kept pace.

Texas, Oregon, and Montana have had comprehensive consumer data privacy statutes in force since 2024. Iowa, Delaware, and Tennessee followed in 2025, with Indiana, Kentucky, and Rhode Island joining on January 1, 2026. Then, in 2026, four more states enacted their own comprehensive privacy statutes, bringing the national total to 24. Louisiana and Oklahoma take effect January 1, 2027; Alabama follows on May 1, 2027; and Vermont’s law — the most protective of the four — doesn’t take effect until January 1, 2028. Companies that think they’ve finished this project should plan for three more effective dates in 2027 alone, with a fourth still to come in 2028.

Why it matters for multistate companies: Unlike GDPR, there is no single U.S. federal privacy law. With 24 states now in the mix — and Louisiana, Oklahoma, and Alabama all coming online in 2027 — a mid-size SaaS company serving consumers nationwide may be tracking two dozen overlapping sets of obligations. Companies that built compliance programs around the California Consumer Privacy Act (CCPA) alone, or even around the original 2024–2026 wave, are already behind.

The good news: a well-structured privacy program scales. Below are the core compliance requirements that appear across most of these state laws — and that every company should have in place today.

✓ Updated Privacy Notice — discloses categories of data collected, purposes of use, consumer rights, and opt-out mechanisms, tailored to each applicable state.

✓ Universal Opt-Out Signal Recognition — most states (including Colorado and California) require honoring browser-based opt-out signals such as the Global Privacy Control (GPC).

✓ Data Subject Request Process — a verified, documented intake and response workflow for access, deletion, correction, and portability requests, with compliant response timelines.

✓ Data Processing Agreements — updated vendor contracts that include processor obligations, data use restrictions, security requirements, and subprocessor provisions.

✓ Data Protection Assessments — required by several states for high-risk processing activities, including targeted advertising, sale of personal data, and certain AI-driven decisions.

✓ Sensitive Data Consent — explicit consent requirements now apply to sensitive categories (biometric data, health data, precise geolocation, etc.) under most state laws.

✓ Multistate Applicability Review — confirming which of the now 24 state laws actually apply to your business, since revenue and data-volume thresholds, sensitive-data definitions, and B2B/employee-data exemptions vary meaningfully from state to state.

The consequences of non-compliance are not theoretical. Texas’s law, for example, authorizes civil penalties up to $7,500 per violation, and the Texas AG has signaled active enforcement. Montana and Oregon have similarly equipped enforcement authorities. Alabama’s new law goes further still, authorizing penalties up to $15,000 per violation — double the $7,500 cap used by most other states. Like most of the newer state laws, enforcement runs exclusively through the state attorney general rather than a private right of action, with cure periods before enforcement ranging from 30 days (Louisiana, Oklahoma) to 45 days (Alabama) to 60 days (Vermont).

Companies that have not yet conducted a data mapping exercise, reviewed their vendor agreements, or confirmed which of the 24 (and counting) state laws apply to their business should act now — before the next wave of effective dates arrives in 2027, with Vermont’s law close behind in 2028.