Summary. The United States has no comprehensive federal privacy law, and roughly twenty states have filled the gap with statutes that are similar enough to invite a single compliance program and different enough to punish anyone who builds one carelessly. This article maps that landscape: the structure every one of these laws shares, and the places where they genuinely diverge. California receives extended treatment because it remains the outlier, with a dedicated regulator, coverage of employee and business-to-business data, treatment of cross-context behavioral advertising as "sharing," and the only private right of action among the comprehensive laws. The article then covers the sector-specific statutes that often matter more in practice, including Illinois biometric law, Washington health data law, the federal video privacy statute, and the wiretapping theories driving website tracking litigation. It closes with a program build-out, a worked example, an FAQ, and related reading.
Ask a general counsel what keeps them up at night about privacy and you will rarely hear "the CCPA." You will hear something like: "We have a pixel on our checkout page that our marketing team installed in 2021, I do not know exactly what it sends, and I have seen four demand letters about pixels this quarter."
That is the actual state of American privacy practice. The comprehensive state statutes set the framework, generate the notices and the rights-request workflows, and occupy most of the compliance budget. Meanwhile the litigation risk concentrates in a handful of older, narrower statutes with private rights of action, aimed at technology nobody was thinking about when they were enacted.
A good program addresses both.
The short answer
- No federal comprehensive law exists as of this writing. Proposals have advanced further in recent Congresses than ever before without being enacted.
- Roughly twenty states have comprehensive consumer privacy statutes in effect, with more taking effect on staggered dates.
- Almost all follow a common template derived from the Virginia model: applicability thresholds, controller/processor roles, a notice obligation, consumer rights (access, delete, correct, portability, opt-out), opt-in consent for sensitive data, purpose limitation and data minimization, processor contracts, and data protection assessments for higher-risk processing.
- California is different in several structural ways and requires its own workstream.
- Enforcement is by state attorneys general (plus the California Privacy Protection Agency), and cure periods are disappearing.
- The comprehensive laws mostly lack private rights of action. The exception is California's breach provision. But sector statutes (Illinois biometrics, Washington health data, the federal video privacy law, state wiretapping statutes) do have them, and that is where class action exposure lives.
Part I: The common template
Nearly every state law shares this architecture. Learn it once and you can read any of them quickly.
Applicability
Two typical triggers, satisfied by doing business in the state and either:
- Volume: processing personal data of a threshold number of consumers in a year (commonly 100,000, sometimes 175,000 or 35,000 depending on the state); or
- Revenue from data: processing a lower number (commonly 25,000) while deriving a specified percentage of gross revenue from the sale of personal data (commonly 25 percent or 50 percent).
California uses different triggers, including a gross annual revenue threshold (currently $25 million, adjusted for inflation), 100,000 California consumers or households, or 50 percent of annual revenue from selling or sharing personal information.
Note what is not there: most of these statutes have no small business exemption based on employee count. A 12-person company that processes data on 100,000 consumers is covered.
Entity-level exemptions commonly cover nonprofits (though not in Colorado, Delaware, New Jersey, Oregon, or Minnesota, among others), government entities, and entities regulated by the Gramm-Leach-Bliley Act or HIPAA. Data-level exemptions cover protected health information, GLBA financial data, FCRA data, driver's license data, and employment data in most states other than California.
Roles
- Controller determines the purposes and means of processing.
- Processor processes on the controller's behalf under contract.
California uses business, service provider, contractor, and third party, and the distinctions carry real consequences: a disclosure to a "service provider" under a compliant contract is not a "sale," while a disclosure to a "third party" may be.
Consumer rights
The standard set:
- Access / know what is processed.
- Delete personal data, subject to exceptions.
- Correct inaccuracies (not in Iowa or Utah).
- Portability in a readily usable format.
- Opt out of sale of personal data.
- Opt out of targeted advertising.
- Opt out of profiling in furtherance of decisions producing legal or similarly significant effects.
- Appeal a denied request (in most states other than California).
Response deadline is generally 45 days, extendable by 45 (California) or 45 to 60 (others).
Authentication is required, and over-collecting identity data to authenticate a request is itself a privacy problem. Ask only for what you need to match the request to an existing record.
Opt-out mechanics and universal signals
This is the area with the most operational complexity.
- Opt-out links. California requires a "Do Not Sell or Share My Personal Information" link (or an alternative opt-out link) and a "Limit the Use of My Sensitive Personal Information" link where applicable. Most other states require a "clear and conspicuous" method.
- Universal opt-out mechanisms must be honored in a growing list of states, including California, Colorado, Connecticut, Texas, Montana, Oregon, Delaware, New Jersey, Nebraska, New Hampshire, Minnesota, and Maryland. The Global Privacy Control is the mechanism in practice, and Colorado maintains a public list of recognized mechanisms.
- Authorized agents may submit opt-outs on a consumer's behalf.
- The technical reality is that honoring an opt-out means suppressing tags, disabling identifiers, and propagating the signal to ad platforms through their consent APIs. This is engineering work, not policy work, and it is where most programs actually fail.
Sensitive data
Most states require opt-in consent before processing sensitive data. California instead gives a right to limit use and disclosure to specified business purposes.
Typical sensitive categories: racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data processed to identify an individual, precise geolocation (commonly within a 1,750-foot radius), and personal data of a known child.
Maryland's law is materially stricter, prohibiting the sale of sensitive data outright and imposing a hard data minimization standard that limits collection to what is "reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumer." That is closer to European-style purpose limitation than to the rest of the American statutes, and companies should not assume a Virginia-model program satisfies it.
Data minimization and purpose limitation
Every comprehensive law contains some version: collect only what is adequate, relevant, and reasonably necessary for the disclosed purposes; do not process for incompatible purposes without consent.
These provisions were widely treated as aspirational at first. They are now enforcement priorities. See Data Minimization and Avoiding the Over-Retention of Personal Information.
Processor contracts
Every statute requires a contract with specified terms: processing instructions, confidentiality, deletion or return at termination, subprocessor flow-down, cooperation with assessments and audits, and assistance with consumer rights and security obligations.
Practical guidance: maintain one data processing addendum keyed to the strictest requirements, rather than negotiating state-by-state variants. See Cloud and SaaS contracting considerations in Indemnification and Limitation of Liability.
Data protection assessments
Required for higher-risk processing: targeted advertising, sale of personal data, sensitive data processing, profiling with heightened risk, and any processing presenting a heightened risk of harm.
They must be documented, retained, and produced to the attorney general on request. Most states provide that such disclosure does not waive privilege or trade secret protection, but read the specific provision.
Part II: California in detail
California deserves its own treatment because it diverges structurally, not merely in detail.
The statute and the regulator
The California Consumer Privacy Act, Cal. Civ. Code §§ 1798.100 to 1798.199.100, took effect in 2020 and was substantially amended by the California Privacy Rights Act, a 2020 ballot initiative effective January 1, 2023.
The CPRA created the California Privacy Protection Agency, the only dedicated state privacy regulator in the country, with rulemaking, investigative, and enforcement authority concurrent with the Attorney General. That matters: California is the only state where a specialized agency writes detailed regulations and audits compliance.
What makes California different
1. Employee and B2B data are covered. Exemptions for human resources and business-to-business data expired on January 1, 2023. California employees, applicants, contractors, and business contacts have access, deletion, correction, and opt-out rights, and employers must provide notice at collection. No other state does this. For the employment overlay see How to Write an Employee Handbook.
2. "Sharing" is a defined term. In addition to "sale," California regulates "sharing" personal information for cross-context behavioral advertising, whether or not for money. That closes the loophole many companies used to argue that ad-tech disclosures were not "sales."
3. Sensitive personal information gets a right to limit rather than an opt-in consent requirement.
4. There is a private right of action for breaches. Section 1798.150 permits a consumer whose nonencrypted and nonredacted personal information is subject to unauthorized access, exfiltration, theft, or disclosure "as a result of the business's violation of the duty to implement and maintain reasonable security procedures" to recover statutory damages of $100 to $750 per consumer per incident, or actual damages, whichever is greater. A 30-day cure notice is required for statutory damages claims where cure is possible.
5. Contract requirements are prescriptive. Section 1798.100(d) and the regulations specify what a service provider or contractor agreement must contain, and a disclosure without a compliant contract may be a "sale."
6. There is an opt-out preference signal mandate that has been enforced.
7. Regulations reach further than the statute. The CPPA has adopted regulations addressing risk assessments, cybersecurity audits, and automated decisionmaking technology, phased in over several years. Companies engaged in significant automated decisionmaking or high-risk processing should track those requirements specifically, because they impose documentation and, in some cases, audit obligations that no other state imposes.
8. The Delete Act created a centralized deletion mechanism directed at data brokers, requiring registered brokers to check a state-run deletion request platform and honor requests. If your company might be a data broker (and the definition is broader than most companies assume), check the registration requirement.
Enforcement
The Attorney General and the CPPA both enforce. Early public enforcement actions have concentrated on: failure to honor opt-out preference signals, defective or missing notices, treating ad-tech disclosures as non-sales without compliant contracts, dark patterns in consent flows, and failure to provide required links. Penalties run to $2,500 per violation and $7,500 for intentional violations or violations involving minors' data.
The 30-day cure period sunset with the CPRA. Cure is now discretionary, not a right.
Part III: The rest of the map
Rather than a state-by-state recitation, here are the divergences that actually change engineering and policy work.
Thresholds. Texas uses a different model, applying to any person conducting business in Texas that processes or sells personal data, except small businesses as defined by the SBA, which is a broader sweep than the volume-based thresholds elsewhere.
Sensitive data consent. Opt-in in most states; right to limit in California. Maryland bans sale outright.
Cure periods. Some states provide a permanent cure period (Iowa, Utah, Virginia in effect); others provided one that sunsets (Colorado, Connecticut, Montana, Oregon, Texas, Delaware). Track the sunset dates.
Universal opt-out signals. Required in a growing majority; not required in Virginia, Iowa, Utah, Indiana, Tennessee, Kentucky, or Florida. Building the capability once and applying it everywhere is simpler than geo-conditioning it.
Right to correct. Absent in Iowa and Utah.
Appeals. Required in most states other than California.
Profiling opt-out. Absent in Iowa and Utah; present elsewhere with varying definitions.
Nonprofit coverage. Colorado, Delaware, New Jersey, Oregon, and Minnesota reach nonprofits in whole or part.
Minors. Several states require opt-in consent for targeted advertising or sale of data of consumers between 13 and 16 (California) or under 17 (Connecticut, Delaware, and others), and Connecticut has adopted enhanced minors' protections including default settings and design duties.
Data broker registration. California, Vermont, Texas, and Oregon impose registration obligations with different definitions and deadlines.
Part IV: The statutes that actually generate litigation
The comprehensive laws generate compliance work. These generate lawsuits.
Illinois Biometric Information Privacy Act
740 ILCS 14. Requires written notice, a written release, and a publicly available retention and destruction schedule before collecting biometric identifiers (retina or iris scans, fingerprints, voiceprints, scans of hand or face geometry).
- Private right of action with liquidated damages of $1,000 for negligent and $5,000 for intentional or reckless violations, plus fees.
- Rosenbach v. Six Flags Entertainment Corp., 129 N.E.3d 1197 (Ill. 2019), held that a person "aggrieved" need not show actual injury beyond the statutory violation.
- Cothron v. White Castle System, Inc., 216 N.E.3d 918 (Ill. 2023), held that a claim accrues with each scan or transmission, producing potentially ruinous exposure. The Illinois legislature responded in 2024 with an amendment limiting recovery to a single violation per person per modality, which materially reduced exposure going forward.
- BIPA reaches voice assistants, facial recognition in retail, timekeeping systems, and increasingly AI training on biometric data. See Biometric Data Privacy Laws and Their Impact on AI Development.
Texas and Washington have biometric statutes without private rights of action; Texas's has been enforced aggressively by its attorney general.
Washington My Health My Data Act
Effective in 2024, covering "consumer health data" defined extremely broadly (any information that identifies a consumer's past, present, or future physical or mental health status, including inferences). It requires consent for collection and separate authorization for sale, and it is enforceable through the state Consumer Protection Act, which supplies a private right of action. Nevada enacted a similar statute without a private right of action.
The breadth of "health data" is the point: purchase histories, location near a clinic, and search behavior can all qualify.
The federal Video Privacy Protection Act
18 U.S.C. § 2710, enacted in 1988 after a newspaper published a Supreme Court nominee's video rental records. It prohibits a "video tape service provider" from knowingly disclosing "personally identifiable information" about a "consumer," with liquidated damages of $2,500 per violation.
It has been revived as a vehicle against websites that embed advertising pixels on pages containing video content, on the theory that the pixel transmits the viewer's identifier and the video watched. Courts have divided on who counts as a "consumer" and what counts as personally identifiable information, and the Second Circuit's decision in Salazar v. National Basketball Association, 118 F.4th 533 (2d Cir. 2024), adopted a relatively broad reading of "consumer." If your site has video and third-party tags, this is a live risk.
Wiretapping and pen register theories
Plaintiffs have repurposed state wiretapping statutes against website session replay, chat tools, and tracking pixels, arguing that a third-party vendor is an unauthorized "party" intercepting communications. California's Invasion of Privacy Act, Cal. Penal Code §§ 631 and 632.7, is the most-used, and a newer theory invokes § 638.51's prohibition on pen registers and trap-and-trace devices, arguing that tracking scripts capture routing and addressing information.
Results have been mixed and highly fact-dependent, turning on consent, the vendor's role, and whether the communication content was intercepted. But the demand-letter volume is substantial, and the fix is straightforward: know what tags are on your site, disclose them, obtain consent where required, and configure vendors as service providers under contract.
Other sector statutes worth knowing
- COPPA, 15 U.S.C. §§ 6501-6506, and the FTC's rule, governing sites and services directed to children under 13. The FTC amended the rule in 2025 to strengthen consent and retention requirements.
- TCPA, 47 U.S.C. § 227, for calls and texts, with statutory damages of $500 to $1,500 per call.
- FCRA, for background checks and consumer reports.
- GLBA Safeguards Rule for financial institutions, now with a breach notification requirement.
- HIPAA for covered entities and business associates. See HIPAA, Business Associates, and Cloud Computing.
- State breach notification statutes in all fifty states, with divergent triggers and deadlines.
Part V: Building a program that works across states
The strategic question every company faces is whether to build to the strictest standard everywhere or to geo-condition behavior by state. Both are defensible; the choice should be deliberate.
Build once, apply everywhere when: your user base is national, your product is uniform, your engineering cost of conditional logic exceeds the cost of broader compliance, and your marketing team can live with the constraints. Most companies under a few hundred million dollars in revenue land here.
Geo-condition when: a specific state's requirement materially damages your business model, your data flows already segment by geography, and you have the engineering capacity to maintain the logic reliably. Be aware that geo-conditioning creates a defect surface, because a misconfigured rule produces violations at scale.
The build, in order
1. Data inventory and mapping. You cannot comply with rules about data you cannot describe. Inventory: what personal data you collect, from whom, through what mechanism, for what purpose, where it is stored, who it goes to, and how long it is kept.
2. Tag and vendor audit. Enumerate every script, pixel, SDK, and tag on your web properties and in your apps. For each: what does it collect, where does it send it, what is the contract, and is it a service provider or a third party? This single exercise addresses the largest share of actual litigation risk.
3. Classify and minimize. Identify sensitive data. Then ask, honestly, whether you need it. The cheapest compliance measure available is not collecting data.
4. Notices. A privacy policy that describes categories collected, purposes, sources, disclosures, retention periods, and rights, plus a notice at collection. Write it to be accurate rather than comprehensive; a policy that describes practices you do not follow is a Section 5 problem.
5. Rights request workflow. Intake (web form, toll-free number where required, email), authentication, routing to systems of record, response within deadlines, appeals where required, and a log. Test it end to end with a real request.
6. Opt-out plumbing. Honor the Global Privacy Control. Suppress tags. Propagate signals to ad platforms. Verify with a browser extension and network trace, not with a vendor's assurance.
7. Consent management. For sensitive data opt-ins, minors, and jurisdictions requiring consent. Avoid dark patterns; several statutes and the CPPA regulations define and prohibit them specifically.
8. Contracts. A single DPA keyed to the strictest requirements, flowed down to subprocessors.
9. Data protection assessments. A repeatable template with a documented trigger (new processing, targeted advertising, sensitive data, profiling, material change).
10. Security. Reasonable security is both a compliance obligation and the predicate for California's private right of action. Map to a recognized framework and document it. See Developing a Privacy Compliance Program and Privacy Compliance Program Checklist.
11. Retention schedule. Written, enforced, and reconciled against litigation hold obligations. See Litigation Holds, Spoliation, and Rule 37(e).
12. Incident response. Breach notification obligations in fifty states plus sector rules, with divergent deadlines. Have the plan and test it.
13. Governance. A named owner, a cadence, training, and a record of decisions. Regulators ask who is accountable, and "everyone" is the wrong answer.
A worked example
Meridian Fitness App, Inc. (fictional) offers a subscription workout app with 1.4 million U.S. users. It collects account data, workout logs, heart rate from connected wearables, approximate location for outdoor route mapping, and behavioral data used for in-app recommendations. It runs advertising campaigns using a major social platform's pixel on its marketing site and a mobile measurement SDK in the app. It has 60 employees, 22 of them in California.
Applicability. Covered in essentially every comprehensive-law state on volume. Covered in California on the consumer-count threshold, and California coverage extends to its 22 California employees.
Sensitive data. Heart rate and workout data are health-related. Under Washington's My Health My Data Act, this is almost certainly "consumer health data," which requires consent for collection and a separate authorization for any sale. Precise location, if collected within the statutory radius, is sensitive in most states. Meridian needs opt-in consent in the opt-in states and a "limit" mechanism in California.
The pixel problem. The marketing site pixel transmits identifiers and page URLs to the social platform. If any of those pages reveal health interests, Meridian has a sensitive data disclosure without consent, a potential "sale" or "sharing" in California, and exposure under Washington's statute. If any pages contain video content, the federal video privacy statute is in play. This is where the litigation risk is concentrated, and it is fixable in an afternoon of engineering work plus a contract amendment.
The SDK problem. The mobile measurement SDK receives device identifiers and event data. Meridian must determine whether the vendor is a service provider under a compliant contract or a third party receiving a sale. The answer depends on the contract terms and on whether the vendor uses the data for its own purposes.
Employee data. Meridian owes its California employees notice at collection, access, deletion, and correction rights. Most companies discover this obligation when the first employee request arrives, usually from a departing employee with a lawyer.
Opt-out signals. Meridian must honor the Global Privacy Control on its web properties in a dozen states. Its current cookie banner has an "accept all" button and a settings link, and it does not read the signal at all. That is the highest-priority fix.
Data protection assessments. Required for the targeted advertising, the sensitive data processing, and the recommendation profiling.
Realistic remediation plan, in priority order:
- Tag audit and pixel remediation on health-related pages.
- Global Privacy Control implementation and tag suppression.
- Consent flow for health and location data, with a real reject path.
- Service provider contract amendments with ad vendors.
- Notice rewrite reflecting actual practice.
- Employee-facing notice and rights workflow for California.
- Data protection assessments documented.
- Retention schedule and deletion implementation.
Note that items 1 through 4 are engineering and contracting work, not drafting. That ratio is typical, and it is the reason privacy programs staffed only with lawyers do not succeed.
Compliance checklist
Foundational
- Data inventory and map, refreshed at least annually.
- Tag, pixel, and SDK register with purpose, recipient, and contract status.
- Vendor list classified as processor/service provider or third party.
- Written retention schedule reconciled with legal holds.
- Named program owner and governance cadence.
Notices and rights
- Privacy policy accurate to actual practice; notice at collection.
- Required links (opt-out; limit sensitive use, if applicable).
- Rights intake channels, including any state-specific requirements.
- Authentication procedure that does not over-collect.
- 45-day response tracking with extension logic.
- Appeals process for states requiring it.
- Request log retained.
Opt-outs and consent
- Global Privacy Control honored and verified by network trace.
- Tag suppression on opt-out, propagated to ad platforms.
- Authorized agent handling.
- Opt-in consent for sensitive data where required; "limit" mechanism in California.
- Minors' consent rules by state.
- No dark patterns; symmetrical accept and reject choices.
Contracts and assessments
- Single DPA meeting the strictest requirements, with subprocessor flow-down.
- Service provider restrictions actually match the vendor's real practices.
- Data protection assessment template and trigger list.
- Assessments completed and retained for high-risk processing.
Security and incidents
- Reasonable security mapped to a recognized framework and documented.
- Encryption of personal information at rest and in transit (this directly affects the California private right of action).
- Incident response plan with 50-state notification analysis.
- Vendor incident notification obligations in contracts.
Sector-specific
- Biometric data: notice, written release, retention schedule (Illinois).
- Consumer health data: consent and separate sale authorization (Washington).
- Video content plus tags: video privacy statute analysis.
- Children's data: COPPA analysis.
- Data broker registration analysis (California, Vermont, Texas, Oregon).
Frequently asked questions
Do we have to comply if we are not in California? Yes, if you meet the applicability thresholds and process the personal data of residents of a covered state. These statutes reach conduct directed at state residents, not just companies located there.
We are a small startup. Are we exempt? Usually not on size alone. The thresholds are volume and revenue based, and a consumer-facing app can cross 100,000 users quickly. Texas uses a small-business exemption tied to SBA size standards, which is the notable exception.
Is using an advertising pixel a "sale" of data? Under California law it can be a "sale" or a "share," depending on the arrangement and the contract. In other states it usually implicates the targeted advertising opt-out even if it is not a "sale." The contract terms and the vendor's own use of the data determine the answer.
Do we need a cookie banner? American law does not require a European-style consent banner for all cookies. It requires honoring opt-outs, obtaining consent for sensitive data in opt-in states, and giving notice. Many companies deploy a banner anyway for global consistency; if you do, make sure the reject path actually works, because a banner that does not suppress tags is worse than none.
Can individuals sue us? Under the comprehensive laws, generally not, with the exception of California's data breach provision. Under Illinois biometric law, Washington health data law, the federal video privacy statute, and state wiretapping statutes, yes, and those are where the class actions are.
What is a data protection assessment and who reads it? A documented analysis of the benefits and risks of a high-risk processing activity and the safeguards applied. It is retained internally and produced to the attorney general on request. Write it as though a regulator will read it, because one might.
How do we handle employee data? In California, employees have full rights and you owe notice at collection. Elsewhere, employment data is generally exempt from the comprehensive laws, though other statutes (biometrics, background checks, breach notification) still apply.
What happens if we get it wrong? Attorney general enforcement with civil penalties, plus, in California, the CPPA. Penalty amounts vary by state, commonly up to $7,500 per violation, and "per violation" can mean per consumer. Cure rights are shrinking.
Is a federal law coming? Proposals continue to advance and stall, mostly over preemption of state law and whether to include a private right of action. Do not build a program on the assumption that one will arrive.
How does this interact with the EU GDPR? The architectures are similar enough that a mature GDPR program covers most American requirements, but not all: the American statutes have their own definitions, their own opt-out mechanics, and their own contract language, and California's coverage of employee data and its breach private right of action have no direct European analogue. For cross-border transfers see International Data Transfers After Schrems II.
Closing thought
The most common mistake in American privacy compliance is treating it as a documentation exercise. Companies write an excellent privacy policy, publish it, and then discover in litigation that the policy describes a company they do not operate: it promises that data is not shared with third parties, while eleven vendors receive event streams from the checkout page.
The second most common mistake is the reverse: treating it as purely technical, with engineering suppressing tags and nobody documenting why, so that when the attorney general asks for the data protection assessment, there is nothing to produce.
A working program is a loop. Know what data you have and where it goes. Configure systems to match what you promise. Document the decisions. Test the whole thing, including the opt-out path, from the outside. Then do it again when the product changes, because the product always changes and the tag that creates the exposure is usually added by someone who has never read the privacy policy.
Related articles
- Developing a Privacy Compliance Program — the program architecture in depth.
- Privacy Compliance Program Checklist — the implementation checklist.
- Privacy and Data Protection Toolkit — the full resource library.
- Data Minimization and Avoiding the Over-Retention of Personal Information — the obligation regulators now enforce hardest.
- Biometric Data Privacy Laws and Their Impact on AI Development — Illinois biometric exposure.
- International Data Transfers After Schrems II — the cross-border layer.
- HIPAA, Business Associates, and Cloud Computing — the health sector overlay.
- Legal Issues for Mobile Applications: Privacy — app-specific requirements.
- Class Actions Under Rule 23 — how privacy claims get aggregated.
- AI Governance and Compliance — the profiling and automated decisionmaking overlay.
This article is provided for general informational purposes and does not constitute legal advice. State privacy statutes, regulations, and effective dates change frequently; verify current requirements for each applicable state. Consult qualified privacy counsel about any particular program or incident.