{"id":2787,"date":"2024-12-19T14:42:00","date_gmt":"2024-12-19T14:42:00","guid":{"rendered":"https:\/\/clockify.me\/learn\/?p=2787"},"modified":"2026-04-14T06:15:00","modified_gmt":"2026-04-14T06:15:00","slug":"data-privacy-laws","status":"publish","type":"post","link":"https:\/\/clockify.me\/learn\/de\/business-management\/data-privacy-laws\/","title":{"rendered":"Datenschutzgesetze \u2013 Umfassender Leitfaden nach US-Bundesstaat f\u00fcr 2025"},"content":{"rendered":"\n<p class=\"translation-block wp-block-paragraph\">The 21st century will be remembered as the time of the digital revolution, and you\u2019ll probably agree that the Internet has changed the world forever.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Although it comes with many benefits, you should be aware that the Internet has exposed us to many issues that we didn\u2019t have before \u2014 mainly concerning our privacy.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Companies make millions of dollars by accessing and using your personal data for advertising and other purposes.&nbsp;<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Although this seems scary when you hear it, you should know that countries worldwide are implementing strict laws to keep your data protected while browsing the Internet.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">In this article, we will look at data privacy laws in the US and help you better understand your rights on the web.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"600\" src=\"https:\/\/clockify.me\/learn\/wp-content\/uploads\/2024\/12\/Data-privacy-laws-cover.jpg\" alt=\"Data privacy laws - cover\" class=\"wp-image-2789\" srcset=\"https:\/\/clockify.me\/learn\/wp-content\/uploads\/2024\/12\/Data-privacy-laws-cover.jpg 1200w, https:\/\/clockify.me\/learn\/wp-content\/uploads\/2024\/12\/Data-privacy-laws-cover-300x150.jpg 300w, https:\/\/clockify.me\/learn\/wp-content\/uploads\/2024\/12\/Data-privacy-laws-cover-1024x512.jpg 1024w, https:\/\/clockify.me\/learn\/wp-content\/uploads\/2024\/12\/Data-privacy-laws-cover-768x384.jpg 768w, https:\/\/clockify.me\/learn\/wp-content\/uploads\/2024\/12\/Data-privacy-laws-cover-18x9.jpg 18w\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" \/><\/figure>\n<\/div>\n\n\n<ul class=\"wp-block-list key-takeaways\">\n<li class=\"translation-block\">Data privacy laws regulate how organizations and companies can collect personal information from their consumers.&nbsp;<\/li>\n\n\n\n<li class=\"translation-block\">There is no federal data privacy law in the United States yet.<\/li>\n\n\n\n<li class=\"translation-block\">The Fair Trade Commission is the main governing body that protects the rights of American consumers online.&nbsp;<\/li>\n\n\n\n<li class=\"translation-block\">Currently, there are 20 states in the US with data protection regulations.<\/li>\n\n\n\n<li class=\"translation-block\">One of the world&#8217;s most well-known data privacy policies is the EU\u2019s General Data Protection Regulation (GDPR).<\/li>\n<\/ul>\n\n\n\n<h2 id=\"what-is-a-data-privacy-law\" class=\"wp-block-heading translation-block\">What is a data privacy law?<\/h2>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">A data privacy law is a <strong>legal framework that protects consumers<\/strong> from unapproved access to their data while using the internet. These laws also regulate how websites gather information, and how they are allowed to use it.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Every time you visit a website, you leave data behind that the website later uses for advertising and other purposes (e.g., enhancing the user experience). Data privacy laws ensure that this data is well protected, and that users can safely browse the web without someone accessing their personal information by:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Defining which organizations must use data privacy laws,<\/li>\n\n\n\n<li class=\"translation-block\">Determining what type of data must be protected,<\/li>\n\n\n\n<li class=\"translation-block\">Defining how organizations can gather, store, and share data,&nbsp;<\/li>\n\n\n\n<li class=\"translation-block\">Granting individuals the rights to their data (in some states), and<\/li>\n\n\n\n<li class=\"translation-block\">Ensuring that organizations comply with legal standards.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Data privacy laws can vary, and each state formulates its own rules. Yet, there are several key components that every data privacy legislation has::<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\"><strong>Scope and applicability <\/strong>\u2014 defines what types of data have to be protected and which organizations have to comply with these rules,<\/li>\n\n\n\n<li class=\"translation-block\"><strong>User rights<\/strong> \u2014 determine what the users can do with their data. For example, users in some states are allowed to access, transfer, or delete their information,<\/li>\n\n\n\n<li class=\"translation-block\"><strong>Legal consent<\/strong> \u2014 before websites can gather data, the users must give their consent. This is also known as \u201ccookie consent,\u201d and there are rules on how websites need to do this accordingly, and<\/li>\n\n\n\n<li class=\"translation-block\"><strong>Transparency<\/strong> \u2014 websites must inform users how their data will be gathered and for what purposes they\u2019ll use it.<\/li>\n<\/ul>\n\n\n\n<h2 id=\"is-there-an-official-data-privacy-law-in-the-us\" class=\"wp-block-heading translation-block\">Is there an official data privacy law in the US?<\/h2>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The US still <strong>has no official federal data privacy law<\/strong>. The main proposal for this type of law is the <a href=\"https:\/\/www.congress.gov\/bill\/118th-congress\/house-bill\/8818\/text\" target=\"_blank\" rel=\"noreferrer noopener\">American Privacy Rights Act (APRA)<\/a>, which was introduced to Congress in 2024 but has yet to pass.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Nonetheless, there are several laws worth mentioning when it comes to data privacy and protection online:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\"><a href=\"https:\/\/www.ftc.gov\/legal-library\/browse\/rules\/childrens-online-privacy-protection-rule-coppa\" target=\"_blank\" rel=\"noreferrer noopener\">Children&#8217;s Online Privacy Protection Act (COPPA)<\/a> \u2014 regulates how children&#8217;s information is collected,&nbsp;<\/li>\n\n\n\n<li class=\"translation-block\"><a href=\"https:\/\/www.cdc.gov\/phlp\/php\/resources\/health-insurance-portability-and-accountability-act-of-1996-hipaa.html\" target=\"_blank\" rel=\"noreferrer noopener\">Health Insurance Portability and Accounting Act (HIPAA)<\/a> \u2014 is a federal rule that protects sensitive health information from disclosure,<\/li>\n\n\n\n<li class=\"translation-block\"><a href=\"https:\/\/www.ftc.gov\/business-guidance\/privacy-security\/gramm-leach-bliley-act\" target=\"_blank\" rel=\"noreferrer noopener\">Gramm Leach Bliley Act (GLBA)<\/a> \u2014 regulates how banks and financial institutions collect information,<\/li>\n\n\n\n<li class=\"translation-block\"><a href=\"https:\/\/www.ftc.gov\/legal-library\/browse\/statutes\/fair-credit-reporting-act\" target=\"_blank\" rel=\"noreferrer noopener\">Fair Credit Reporting Act (FCRA)<\/a> \u2014 regulates the collection of credit information, and<\/li>\n\n\n\n<li class=\"translation-block\"><a href=\"https:\/\/studentprivacy.ed.gov\/faq\/what-ferpa\" target=\"_blank\" rel=\"noreferrer noopener\">Family Educational Rights and Privacy Act (FERPA)<\/a> \u2014 protects student education records.<\/li>\n<\/ul>\n\n\n\n<h3 id=\"what-organization-governs-data-privacy-laws-in-the-us\" class=\"wp-block-heading translation-block\">What organization governs data privacy laws in the US?<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">When it comes to enforcing data privacy laws, the main governing body in the US is the <a href=\"https:\/\/www.ftc.gov\/\" target=\"_blank\" rel=\"noreferrer noopener\">Federal Trade Commission (FTC)<\/a>. The FTC is there to protect consumers in all aspects of commerce, and its primary statute is the <a href=\"https:\/\/www.ftc.gov\/legal-library\/browse\/statutes\/federal-trade-commission-act\" target=\"_blank\" rel=\"noreferrer noopener\">Federal Trade Commission Act<\/a>, allowing the Commission to:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li class=\"translation-block\">Stop unfair competition methods and unfair trade practices,<\/li>\n\n\n\n<li class=\"translation-block\">Pursue financial redress for violations of consumer rights,<\/li>\n\n\n\n<li class=\"translation-block\">Define acts and practices that are deceptive and establish rules to prevent them,<\/li>\n\n\n\n<li class=\"translation-block\">Collect information and investigate organizations, businesses, practices, and management of entities in trade, and<\/li>\n\n\n\n<li class=\"translation-block\">Report and suggest legislation to Congress and the public.<\/li>\n<\/ol>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">A good example of how the FTC handles data privacy infringements is when they <a href=\"https:\/\/www.ftc.gov\/news-events\/news\/press-releases\/2011\/03\/ftc-charges-deceptive-privacy-practices-googles-rollout-its-buzz-social-network\" target=\"_blank\" rel=\"noreferrer noopener\">accused Google of violating user privacy<\/a> upon launching its social media platform, Google Buzz, back in 2010. This resulted in a settlement that prohibited Google from repeating any violation of this kind and required them to implement a comprehensive privacy program for the next 20 years.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">\ud83c\udf93 To learn more about the Federal Trade Commission visit their website \u2014 <a href=\"https:\/\/www.ftc.gov\/news-events\/media-resources\/what-ftc-does\" target=\"_blank\" rel=\"noreferrer noopener\">What the FTC does?<\/a><\/p>\n\n\n\n<h2 id=\"what-us-states-have-data-privacy-laws\" class=\"wp-block-heading translation-block\">What US states have data privacy laws?<\/h2>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">In recent years, more and more states are adopting data privacy laws. This is due to the lack of a federal law governing privacy protection. Currently, <strong>there are 20 states with data privacy laws in the US<\/strong>.&nbsp;<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Let\u2019s look at each of them in more detail.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"1150\" src=\"https:\/\/clockify.me\/learn\/wp-content\/uploads\/2024\/12\/States-with-data-privacy-laws-in-the-US.jpg\" alt=\"States with data privacy laws in the US\" class=\"wp-image-2786\" srcset=\"https:\/\/clockify.me\/learn\/wp-content\/uploads\/2024\/12\/States-with-data-privacy-laws-in-the-US.jpg 1200w, https:\/\/clockify.me\/learn\/wp-content\/uploads\/2024\/12\/States-with-data-privacy-laws-in-the-US-300x288.jpg 300w, https:\/\/clockify.me\/learn\/wp-content\/uploads\/2024\/12\/States-with-data-privacy-laws-in-the-US-1024x981.jpg 1024w, https:\/\/clockify.me\/learn\/wp-content\/uploads\/2024\/12\/States-with-data-privacy-laws-in-the-US-768x736.jpg 768w, https:\/\/clockify.me\/learn\/wp-content\/uploads\/2024\/12\/States-with-data-privacy-laws-in-the-US-13x12.jpg 13w\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" \/><figcaption class=\"wp-element-caption\">States with data privacy laws<\/figcaption><\/figure>\n<\/div>\n\n\n<h3 id=\"1-california-privacy-rights-act-cpra\" class=\"wp-block-heading translation-block\">1. California Privacy Rights Act (CPRA)<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Status<\/strong>: Effective since January 1, 2023.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/thecpra.org\/\" target=\"_blank\" rel=\"noreferrer noopener\">California Privacy Rights Act<\/a><\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The CPRA is one of the largest data privacy laws out there and is an amendment to the <a href=\"https:\/\/oag.ca.gov\/privacy\/ccpa\" target=\"_blank\" rel=\"noreferrer noopener\">California Consumer Privacy Act (CCPA)<\/a>. The law grants Californian citizens the rights to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Disallow entities from collecting their data,<\/li>\n\n\n\n<li class=\"translation-block\">Access and correct data,<\/li>\n\n\n\n<li class=\"translation-block\">Delete data, and<\/li>\n\n\n\n<li class=\"translation-block\">Prohibit entities from sharing data.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">In addition to enhanced consumer protection, the law also sets responsibilities for entities that collect personal information, such as asking users for consent.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The governing body for the CPRA is the <a href=\"https:\/\/cppa.ca.gov\/\" target=\"_blank\" rel=\"noreferrer noopener\">California Privacy Protection Agency (CPPA)<\/a>, which can hold hearings and impose fines for potential violations.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">\ud83c\udf93 To learn more about employment laws in California, visit our website \u2014 <a href=\"https:\/\/clockify.me\/state-labor-laws\/california-labor-law\" target=\"_blank\" rel=\"noreferrer noopener\">California Labor Laws Guide<\/a><\/p>\n\n\n\n<p class=\"has-text-align-left has-background translation-block wp-block-paragraph\" style=\"background-color:#e5f6fe\">Clockify&#8217;s <a href=\"https:\/\/clockify.me\/features\/auto-tracker\">Auto tracker<\/a> is privacy-first: Admins cannot see their employees\u2019 logs until employees manually save an entry to their timesheet. <a href=\"https:\/\/app.clockify.me\/signup\">Get Auto tracker FREE \u2192<\/a><\/p>\n\n\n\n<h3 id=\"2-colorado-privacy-act-cpa\" class=\"wp-block-heading translation-block\">2. Colorado Privacy Act (CPA)<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Status<\/strong>: Effective since July 1, 2023.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/coag.gov\/resources\/colorado-privacy-act\/\" target=\"_blank\" rel=\"noreferrer noopener\">Colorado Privacy Act<\/a><\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The CPA is a part of <a href=\"https:\/\/leg.colorado.gov\/bills\/hb19-1289\" target=\"_blank\" rel=\"noreferrer noopener\">Colorado\u2019s Consumer Protection Act<\/a> and is enforced and implemented by the Colorado Attorney General. This law grants Colorado consumers the following rights:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">To access, delete, and correct personal information, and<\/li>\n\n\n\n<li class=\"translation-block\">To reject the use of their data for advertising purposes or other types of profiling.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Covered entities that collect personal information must protect data, acquire consent, and inform Colorado citizens on how their data is collected and used. The CPA applies to organizations that:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Gather information from 100,000 consumers, and&nbsp;<\/li>\n\n\n\n<li class=\"translation-block\">Gather information from 25,000 consumers and generate revenue from it.<\/li>\n<\/ul>\n\n\n\n<h3 id=\"3-connecticut-data-privacy-act-ctdpa\" class=\"wp-block-heading translation-block\">3. Connecticut Data Privacy Act (CTDPA)<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Status<\/strong>: Effective since July 1, 2023.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The CTDPA grants Connecticut residents the same rights as the other similar laws, which include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete their data,&nbsp;<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of their personal information, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">This law applies to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather the data of at least 100,000 consumers, or&nbsp;<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather the data of at least 25,000 consumers, but generate 25% of their revenue from selling that data.<\/li>\n<\/ul>\n\n\n\n<h3 id=\"4-delaware-personal-data-privacy-act-dpdpa\" class=\"wp-block-heading translation-block\">4. Delaware Personal Data Privacy Act (DPDPA)<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Status<\/strong>: It will take effect on January 1, 2025.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/legis.delaware.gov\/json\/BillDetail\/GenerateHtmlDocument?legislationId=140388&amp;legislationTypeId=1&amp;docTypeId=2&amp;legislationName=HB154#:~:text=The%20Act%20delineates%20a%20consumer's,maintained%20by%20entities%20or%20people.\" target=\"_blank\" rel=\"noreferrer noopener\">Delaware Personal Data Privacy Act<\/a><\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The DPDPA is modeled after other data privacy legislations, and it will grant Delaware citizens the following consumer rights:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to allow or disallow entities to collect personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to correct or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire copies of their personal information,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a list of third-party entities that have access to their data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the use of their data for advertising or other similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The law will apply to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather information from more at least 35,000 consumers in Delaware, or<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather information from at least 10,000 consumers in Delaware and generate at least 20% of revenue from selling it.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The <a href=\"https:\/\/www.justice.gov\/\" target=\"_blank\" rel=\"noreferrer noopener\">Department of Justice<\/a> enforces this law, which can impose fines of up to $10,000 per violation.<\/p>\n\n\n\n<h3 id=\"5-indiana-consumer-data-protection-act-incdpa\" class=\"wp-block-heading translation-block\">5. Indiana Consumer Data Protection Act (INCDPA)<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Status<\/strong>: It will take effect on January 1, 2026.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/iga.in.gov\/legislative\/2023\/bills\/senate\/5\/details\" target=\"_blank\" rel=\"noreferrer noopener\">Indiana Consumer Data Protection Act<\/a><\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The INCDPA will grant Indiana residents the following rights concerning their data privacy and protection:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">This law will apply to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather the data from at least 100,000 Indiana residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather the data from 25,000 Indiana residents and earn at least 50% of their revenue by selling it.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The attorney general will enforce data privacy law in Indiana and may impose sanctions of up to $7,500 per violation. The law predicts a cure period of 30 days before penalties.<\/p>\n\n\n\n<h3 id=\"6-iowa-consumer-data-protection-act-icdpa\" class=\"wp-block-heading translation-block\">6. Iowa Consumer Data Protection Act (ICDPA)<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Status<\/strong>: It will take effect on January 1, 2025.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/www.legis.iowa.gov\/docs\/publications\/LGE\/90\/SF262.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">Iowa Consumer Data Protection Act<\/a><\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The ICDPA will grant Iowa residents the same rights:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to confirm data processing,<\/li>\n\n\n\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the selling of their data.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">This law will apply to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather the data from at least 100,000 Indiana residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather the data from 25,000 Indiana residents and earn at least 50% of their revenue by selling it.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The attorney general will enforce data privacy law in Iowa and may impose sanctions of up to $7,500 per violation. The law predicts a cure period of 90 days before penalties.<\/p>\n\n\n\n<h3 id=\"7-kentucky-consumer-data-protection-act-kcdpa\" class=\"wp-block-heading translation-block\">7. Kentucky Consumer Data Protection Act (KCDPA)<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Status<\/strong>: Will take effect on January 1, 2025.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/apps.legislature.ky.gov\/record\/24rs\/hb15.html\" target=\"_blank\" rel=\"noreferrer noopener\">Kentucky Consumer Data Protection Act<\/a><\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The KCDPA will grant Kentucky residents the following rights concerning their data privacy and protection:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">This law will apply to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather the data from at least 100,000 Indiana residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather the data from 25,000 Kentucky residents and earn at least 50% of their revenue by selling it.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The attorney general will enforce data privacy law in Kentucky and may impose sanctions of up to $7,500 per violation. The law predicts a cure period of 90 days before penalties.<\/p>\n\n\n\n<h3 id=\"8-maryland-online-data-privacy-act-mdodpa\" class=\"wp-block-heading translation-block\">8. Maryland Online Data Privacy Act (MDODPA)<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Status<\/strong>: It will take effect on October 1, 2025.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/mgaleg.maryland.gov\/mgawebsite\/Legislation\/Details\/sb0541?ys=2024RS\" target=\"_blank\" rel=\"noreferrer noopener\">Maryland Online Data Privacy Act<\/a><\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The MDODPA is known as a more strict data privacy law as it requires organizations to take additional measures to protect consumers, such as allowing consumers not to accept the processing of their personal data.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">This law grants Maryland residents the following rights:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data,&nbsp;<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes,<\/li>\n\n\n\n<li class=\"translation-block\">The right to get a list of all third parties with access to the data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to revoke their consent.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">This law will apply to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather the data from at least 35,000 Maryland residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather the data from 10,000 Maryland residents and earn at least 20% of their revenue by selling it.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Maryland&#8217;s Consumer Protection Division will enforce the data privacy law in Maryland and may impose fines from $10,000 to $25,000, depending on the violation.<\/p>\n\n\n\n<p class=\"has-text-align-left has-background translation-block wp-block-paragraph\" style=\"background-color:#e5f6fe\">Clockify&#8217;s <a href=\"https:\/\/clockify.me\/features\/auto-tracker\">Auto tracker<\/a> is privacy-first: Admins cannot see their employees\u2019 logs until employees manually save an entry to their timesheet. <a href=\"https:\/\/app.clockify.me\/signup\">Get Auto tracker FREE \u2192<\/a><\/p>\n\n\n\n<h3 id=\"9-minnesota-consumer-data-privacy-act-mcdpa\" class=\"wp-block-heading translation-block\">9. Minnesota Consumer Data Privacy Act (MCDPA)<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Status<\/strong>: Will take effect on July 31, 2025.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/www.house.mn.gov\/hrd\/bs\/93\/hf2309.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">Minnesota Consumer Data Privacy Act<\/a><\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The MCDPA grants Minnesota residents the following rights:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data,&nbsp;<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to review and understand how data is being profiled.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">This law will apply to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather the data from at least 100,000 Minnesota residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather the data from 25,000 Minnesota residents and earn at least 25% of their revenue by selling it.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The attorney general will enforce data privacy law in Minnesota and may impose fines of up to $7,500 per violation. However, the attorney general must issue a warning letter first and provide a way to cure the breach.<\/p>\n\n\n\n<h3 id=\"10-montana-consumer-data-privacy-act-mtcdpa\" class=\"wp-block-heading translation-block\">10. Montana Consumer Data Privacy Act (MTCDPA)<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Status<\/strong>: Effective since October 1, 2024.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/www.house.mn.gov\/hrd\/bs\/93\/hf2309.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">Montana Consumer Data Privacy Act<\/a><\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Under the MTCDPA, consumers have the right to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">Acquire a copy of the data, and<\/li>\n\n\n\n<li class=\"translation-block\">Reject the processing of their data for advertising or similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The law applies to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather the data from at least 50,000 Montana residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather the data from 25,000 Montana residents and earn at least 25% of their revenue by selling it.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The attorney general will enforce data privacy law in Montana, but there are no specific fines for violations. The cure period for violations is 60 days.<\/p>\n\n\n\n<h3 id=\"11-nebraska-data-privacy-act-ndpa\" class=\"wp-block-heading translation-block\">11. Nebraska Data Privacy Act (NDPA)<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Status<\/strong>: It will take effect on January 1, 2025.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/nebraskalegislature.gov\/FloorDocs\/108\/PDF\/Slip\/LB1074.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">Nebraska Data Privacy Act<\/a><\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Under the NDPA, residents in Nebraska will have the following rights:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The Nebraska data privacy law will apply to individuals or organizations (excluding small businesses) that collect personal and sensitive data from consumers. However, there is no revenue or volume requirement as in most other states.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The attorney general will enforce data privacy law in Nebraska and impose fines of up to $7,500 per violation. The attorney general must first inform the subject of the breach and give them a 30-day cure period. After curing the violation, the subject must provide a written statement declaring they won\u2019t repeat it.<\/p>\n\n\n\n<h3 id=\"12-new-hampshire-privacy-act-nhpa\" class=\"wp-block-heading translation-block\">12. New Hampshire Privacy Act (NHPA)<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Status<\/strong>: It will take effect on January 1, 2025.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/www.doj.nh.gov\/news-and-media\/attorney-general-formella-announces-creation-new-data-privacy-unit\" target=\"_blank\" rel=\"noreferrer noopener\">New Hampshire Privacy Act<\/a><\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Under the NHPA, residents in New Hampshire will have the following rights:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The law will apply to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather the data from at least 35,000 New Hampshire residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather the data from 10,000 New Hampshire residents and earn at least 25% of their revenue by selling it.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The attorney general will enforce New Hampshire data privacy law and may impose fines of up to $10,000 per violation. If the violation is on purpose, the attorney general may seek criminal penalties of up to $100,000 per violation.<\/p>\n\n\n\n<h3 id=\"13-new-jersey-data-privacy-act-njdpa\" class=\"wp-block-heading translation-block\">13. New Jersey Data Privacy Act (NJDPA)<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Status<\/strong>: It will take effect on January 15, 2025.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/pub.njleg.state.nj.us\/Bills\/2022\/AL23\/266_.PDF\" target=\"_blank\" rel=\"noreferrer noopener\">New Jersey Data Privacy Act<\/a><\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Under NJDPA, residents of New Jersey will have the following rights:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The law will apply to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather the data from at least 100,000 New Jersey residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather the data from 25,000 New Jersey residents and earn revenue by selling it (no amount is specified).<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The attorney general will enforce New Jersey data privacy law and may impose fines of up to $2,500 for the first violation, up to $5,000 for the second violation, up to $10,000 for the third violation, and up to $20,000 for the fourth and every consecutive violation.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">\ud83c\udf93 To learn more about employment laws in New Jersey, visit our website \u2014 <a href=\"https:\/\/clockify.me\/state-labor-laws\/new-jersey-labor-law\" target=\"_blank\" rel=\"noreferrer noopener\">New Jersey Labor Laws Guide<\/a><\/p>\n\n\n\n<h3 id=\"14-oregon-consumer-privacy-act-ocpa\" class=\"wp-block-heading translation-block\">14. Oregon Consumer Privacy Act (OCPA)<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Status<\/strong>: Effective since July 1, 2024.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/www.doj.state.or.us\/consumer-protection\/id-theft-data-breaches\/privacy\/\" target=\"_blank\" rel=\"noreferrer noopener\">Oregon Consumer Privacy Act<\/a><\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Under OCPA, residents of Oregon have several rights. The law explains this easily by using the phrase <strong>LOCKED<\/strong>, which includes the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Users have the right to get a <strong>list<\/strong> of all third-party entities that handle their data,<\/li>\n\n\n\n<li class=\"translation-block\">Users can <strong>opt-out<\/strong> from letting entities sell their information for advertising or other purposes,&nbsp;<\/li>\n\n\n\n<li class=\"translation-block\">Users can ask for a <strong>copy<\/strong> of the personal data that businesses have about them,<\/li>\n\n\n\n<li class=\"translation-block\">Users can <strong>know<\/strong> what information an organization has about them,<\/li>\n\n\n\n<li class=\"translation-block\">Users can <strong>edit<\/strong> inaccurate data, and<\/li>\n\n\n\n<li class=\"translation-block\">Users can <strong>delete<\/strong> personal or sensitive information a business has about them.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">This law applies to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather data from at least 100,000 Oregon residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather data from at least 25,000 Oregon residents and earn a minimum of 25% of their revenue by selling it.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The attorney general will enforce Oregon data privacy law and may impose fines of up to $7,500 per violation. There is a 30-day cure period for the breach.<\/p>\n\n\n\n<h3 id=\"15-rhode-island-data-transparency-and-privacy-protection-act-ridtppa\" class=\"wp-block-heading translation-block\">15. Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Status<\/strong>: It will take effect on January 1, 2026.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/www.rilegislature.gov\/pressrelease\/_layouts\/15\/ril.pressrelease.inputform\/DisplayForm.aspx?List=c8baae31-3c10-431c-8dcd-9dbbe21ce3e9&amp;ID=374664\" target=\"_blank\" rel=\"noreferrer noopener\">Rhode Island Data Transparency and Privacy Protection Act<\/a><\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Under RIDTPPA, residents of Rhode Island have the right to know how their personal information is collected and for what it is used. In addition, before collecting information, users must give consent to entities that gather it. However, companies aren\u2019t required to create an opt-out mechanism.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">This law applies to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather data from at least 35,000 Rhode Island residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather data from at least 10,000 Rhode Island residents and earn a minimum of 20% of their revenue by selling it.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The attorney general will enforce Rhode Island data privacy law and may impose fines from $100 to $500 per violation. There is no cure period for the breach.<\/p>\n\n\n\n<h3 id=\"16-tennessee-information-protection-act-tipa\" class=\"wp-block-heading translation-block\">16. Tennessee Information Protection Act (TIPA)<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Status<\/strong>: It will take effect on July 1, 2025.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/www.capitol.tn.gov\/Bills\/113\/Bill\/HB1181.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">Tennessee Information Protection Act<\/a><\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Under TIPA, residents of Tennessee will have the following rights:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">This law applies to entities that exceed $25 million in revenue and either:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Gather data from at least 175,000 Tennessee residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Gather data from at least 25,000 Oregon residents and earn a minimum of 50% of their revenue by selling it.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The attorney general will enforce Tennessee data privacy law and may impose fines of up to $7,500 per violation, or in some cases the triple amount if the violation is wilful. There is a 60-day cure period for the breach.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">\ud83c\udf93 To learn more about employment laws in Tennessee, visit our website \u2014 <a href=\"https:\/\/clockify.me\/state-labor-laws\/tennessee-labor-law\" target=\"_blank\" rel=\"noreferrer noopener\">Tennessee Labor Laws Guide<\/a><\/p>\n\n\n\n<h3 id=\"17-texas-data-privacy-and-security-act-tdpsa\" class=\"wp-block-heading translation-block\">17. Texas Data Privacy and Security Act (TDPSA)<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Status<\/strong>: Enforceable since January 1, 2024, but businesses have a grace period until January 1, 2025, to comply with the law.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/www.texasattorneygeneral.gov\/consumer-protection\/file-consumer-complaint\/consumer-privacy-rights\/texas-data-privacy-and-security-act\" target=\"_blank\" rel=\"noreferrer noopener\">Texas Data Privacy and Security Act<\/a><\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Under TDPSA, users have the common data privacy laws used in most states, which include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">This law doesn\u2019t have the standard eligibility requirements (revenue-based) used by other states. Instead, entities that are covered by this law are businesses that gather or sell data in Texas.&nbsp;<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The attorney general will enforce Texas data privacy law and may impose fines of up to $7,500 per violation. There is a 30-day cure period.<\/p>\n\n\n\n<p class=\"has-text-align-left has-background translation-block wp-block-paragraph\" style=\"background-color:#e5f6fe\">Clockify&#8217;s <a href=\"https:\/\/clockify.me\/features\/auto-tracker\">Auto tracker<\/a> is privacy-first: Admins cannot see their employees\u2019 logs until employees manually save an entry to their timesheet. <a href=\"https:\/\/app.clockify.me\/signup\">Get Auto tracker FREE \u2192<\/a><\/p>\n\n\n\n<h3 id=\"18-utah-consumer-privacy-act-ucpa\" class=\"wp-block-heading translation-block\">18. Utah Consumer Privacy Act (UCPA)<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Status<\/strong>: Effective since December 31, 2023.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/dcp.utah.gov\/ucpa\/\" target=\"_blank\" rel=\"noreferrer noopener\">Utah Consumer Privacy Act<\/a><\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The UCPA grants Utah residents the following rights:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The law has similar eligibility requirements as TIPA and applies to entities that exceed $25 million in revenue and either:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Gather data from at least 100,000 Utah residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Gather data from at least 25,000 Utah residents and earn a minimum of 50% of their revenue by selling it.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The attorney general enforces Utah data privacy law and may impose fines of up to $7,500 per violation. There is a 30-day cure period.<\/p>\n\n\n\n<h3 id=\"19-virginias-consumer-data-protection-act-vcdpa\" class=\"wp-block-heading translation-block\">19. Virginia&#8217;s Consumer Data Protection Act (VCDPA)<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Status<\/strong>: Effective since January 1, 2023.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/www.oag.state.va.us\/consumer-protection\/files\/tips-and-info\/Virginia-Consumer-Data-Protection-Act-Summary-2-2-23.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">Virginia&#8217;s Consumer Data Protection Act<\/a><\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Under VCDPA, the residents of Virginia have the usual data privacy rights, which include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The law applies to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather the data from at least 100,000 Virginia residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather the data from 25,000 Virginia residents and earn at least 50% of their revenue by selling it.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The attorney general enforces the Virginia data privacy law and may impose fines of up to $7,500 per violation. There is a 30-day cure period.<\/p>\n\n\n\n<h3 id=\"20-florida-digital-bill-of-rights-fdbr\" class=\"wp-block-heading translation-block\">20. Florida Digital Bill of Rights (FDBR)<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Status<\/strong>: Effective since July 1, 2024.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\"><strong>Official<\/strong> <strong>legislation<\/strong>: <a href=\"https:\/\/www.flsenate.gov\/Session\/Bill\/2023\/262\/BillText\/er\/HTML\" target=\"_blank\" rel=\"noreferrer noopener\">Florida Digital Bill of Rights<\/a><\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Under FDBR, residents of Florida have the following online privacy rights:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The law applies to the entities in Florida that earn at least $1 billion of annual revenue and:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">At least 50% of their revenue comes from digital platforms,<\/li>\n\n\n\n<li class=\"translation-block\">Use an app with more than 250,000 applications, and<\/li>\n\n\n\n<li class=\"translation-block\">Have a smart speaker that is connected to the cloud.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The attorney general enforces the Florida data privacy law and may impose fines of up to $50,000 per violation. There is a 45-day cure period.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">\ud83c\udf93 To learn more about employment laws in Florida, visit our website \u2014 <a href=\"https:\/\/clockify.me\/state-labor-laws\/florida-labor-law\" target=\"_blank\" rel=\"noreferrer noopener\">Florida Labor Laws Guide<\/a><\/p>\n\n\n\n<h2 id=\"what-are-the-data-privacy-laws-in-europe\" class=\"wp-block-heading translation-block\">What are the data privacy laws in Europe?<\/h2>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Europe has several data privacy laws that are used to protect the right to privacy of its residents. The most popular among these laws is the <a href=\"https:\/\/gdpr-info.eu\/\" target=\"_blank\" rel=\"noreferrer noopener\">General Data Protection Regulation (GDPR)<\/a>, one of the world&#8217;s most comprehensive data privacy laws.&nbsp;<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">In addition to the GDPR, in recent years, Europe has enacted a few additional data privacy legislations, such as the <a href=\"https:\/\/digital-markets-act.ec.europa.eu\/index_en\" target=\"_blank\" rel=\"noreferrer noopener\">Digital Markets Act (DMA)<\/a>.&nbsp;<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Let\u2019s look at these laws in more detail.<\/p>\n\n\n\n<h3 id=\"1-general-data-protection-regulation-gdpr\" class=\"wp-block-heading translation-block\">1. General Data Protection Regulation (GDPR)<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The General Data Protection Regulation (GDPR) is a very strict privacy and security law affecting countries worldwide. The European Union (EU) drafted this document and signed it into law in 2016, and it became effective on May 25, 2018.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Every company that processes personal data or sells goods and services to EU residents must comply with the GDPR rules. The GDPR outlines 7 key protection and responsibility principles that include:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li class=\"translation-block\"><strong>Lawfulness, fairness, and transparency<\/strong> \u2014 all processed data must be fair, transparent, and compliant with the law,<\/li>\n\n\n\n<li class=\"translation-block\"><strong>Purpose<\/strong> \u2014 data can only be gathered for legitimate purposes specified to the user,<\/li>\n\n\n\n<li class=\"translation-block\"><strong>Minimization <\/strong>\u2014 the amount of data gathered must be minimal for the required purpose,<\/li>\n\n\n\n<li class=\"translation-block\"><strong>Accuracy<\/strong> \u2014 all data must be accurate,<\/li>\n\n\n\n<li class=\"translation-block\"><strong>Storage limitation<\/strong> \u2014 data can be stored only for the amount of time necessary for the purpose,<\/li>\n\n\n\n<li class=\"translation-block\"><strong>Integrity &amp; confidentiality<\/strong> \u2014&nbsp; all processing must ensure security, integrity, and privacy (e.g., encryption), and<\/li>\n\n\n\n<li class=\"translation-block\"><strong>Accountability<\/strong> \u2014 every organization that processes data is accountable for demonstrating compliance with the GDPR rules.<\/li>\n<\/ol>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">When it comes to penalties, the <a href=\"https:\/\/gdpr.eu\/fines\/\" target=\"_blank\" rel=\"noreferrer noopener\">GDPR fines<\/a> are incredibly high. They can max out at \u20ac20 million or 4% of the company\u2019s revenue. In addition, subjects have the right to seek compensation for damages.&nbsp;<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">\ud83c\udf93 To learn more about the GDPR, visit their official website \u2014 <a href=\"https:\/\/gdpr.eu\/what-is-gdpr\/\" target=\"_blank\" rel=\"noreferrer noopener\">What is GDPR, the EU\u2019s new data protection law?<\/a><\/p>\n\n\n\n<p class=\"has-text-align-left has-background translation-block wp-block-paragraph\" style=\"background-color:#e5f6fe\">Clockify&#8217;s <a href=\"https:\/\/clockify.me\/features\/auto-tracker\">Auto tracker<\/a> is privacy-first: Admins cannot see their employees\u2019 logs until employees manually save an entry to their timesheet. <a href=\"https:\/\/app.clockify.me\/signup\">Get Auto tracker FREE \u2192<\/a><\/p>\n\n\n\n<h3 id=\"2-digital-markets-act-dma\" class=\"wp-block-heading translation-block\">2. Digital Markets Act (DMA)<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The Digital Markets Act (DMA) is a European law that applies to the largest digital platforms in the EU, such as Facebook, Google, and Apple. This law, effective since March 2024, aims to prevent large companies from imposing unfair market conditions on their competitors.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Companies that fail to comply with the DMA can be fined up to 10% of their revenue and sometimes up to 20% if they repeat the violation.<\/p>\n\n\n\n<h3 id=\"3-european-union-ai-act\" class=\"wp-block-heading translation-block\">3. European Union AI Act<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">With artificial intelligence becoming increasingly popular, the EU has approved the <a href=\"https:\/\/artificialintelligenceact.eu\/\" target=\"_blank\" rel=\"noreferrer noopener\">European Union AI Act<\/a>, which will go into effect in late 2025 or 2026. This law will apply to all companies that develop AI systems and require them to respect ethical and fundamental rights when designing them.<\/p>\n\n\n\n<h3 id=\"4-digital-services-act-dsa\" class=\"wp-block-heading translation-block\">4. Digital Services Act (DSA)<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/digital-services-act-package\" target=\"_blank\" rel=\"noreferrer noopener\">Digital Services Act (DSA)<\/a> sets clear rules protecting consumers and their online rights. The main purpose of this law is to prevent illegal and harmful online activities, such as spreading misinformation or posting prohibited content.<\/p>\n\n\n\n<h2 id=\"frequently-asked-questions-about-data-privacy-laws\" class=\"wp-block-heading translation-block\">Frequently asked questions about data privacy laws<\/h2>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">To make this guide as comprehensive as possible, we\u2019ve included an FAQ section where we\u2019ll answer the most common questions about this topic.<\/p>\n\n\n\n<h3 id=\"do-us-companies-need-to-comply-with-gdpr\" class=\"wp-block-heading translation-block\">Do US companies need to comply with GDPR?<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Yes, if a company operates on EU soil or has customers from the EU, it will have to respect GDPR rules.<\/p>\n\n\n\n<h3 id=\"what-is-the-difference-between-gdpr-and-ccpa\" class=\"wp-block-heading translation-block\">What is the difference between GDPR and CCPA?<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">The main difference between the two is that GDPR applies to all companies that operate on EU soil, and the CCPA applies only to California residents.<\/p>\n\n\n\n<h3 id=\"how-many-states-have-data-privacy-laws\" class=\"wp-block-heading translation-block\">How many states have data privacy laws?<\/h3>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Currently, there are 20 states in the US that have enacted data protection laws. Some of them are already effective, and some will become effective in 2025 or 2026.<\/p>\n\n\n\n<h2 id=\"protect-your-companys-privacy-with-the-cake-com-bundle\" class=\"wp-block-heading translation-block\">Protect your company\u2019s privacy with the CAKE.com Bundle<\/h2>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">With the rise of data privacy laws, companies must find ways to improve their <a href=\"https:\/\/cake.com\/security\" target=\"_blank\" rel=\"noreferrer noopener\">security<\/a> and keep their customer\u2019s data safe.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">For many, this can be pretty expensive.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Why, you ask? Well, you\u2019ll need appropriate, secure software.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">That\u2019s where CAKE.com can help you: it offers 3 robust pieces of software to keep all your data safe.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">With <a href=\"https:\/\/app.clockify.me\/en\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">Clockify<\/a> by <a href=\"https:\/\/cake.com\/\" type=\"link\" id=\"https:\/\/cake.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">CAKE.com<\/a>, you get a time tracking software you can use to track employee activities, send invoices, schedule shifts, and much more. <\/p>\n\n\n\n<figure class=\"wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Clockify Tour\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/NMZhFs_b0Aw?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">With <a href=\"https:\/\/pumble.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Pumble<\/a>, you get access to a modern team communication software that keeps all information your team shares safe and secure.<\/p>\n\n\n\n<figure class=\"wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Introduction to Pumble\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/0UUEStUkgJM?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Last but not least, <a href=\"https:\/\/plaky.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Plaky<\/a> is your go-to project management software that lets you track tasks and projects within your team.<\/p>\n\n\n\n<figure class=\"wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Getting Started With Plaky\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/IYQCi9y-lNU?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Oh, and did I mention that you can get all 3 of these tools for the amount you spend on your regular project management software?&nbsp;<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">\n<div class=\"banner banner-dark clockify-gradient-bundle\">\n    <div class=\"banner-text lg:pr-[6rem]\">\n        <h2 class=\"translation-block text-2xl !mb-4\">3 tools = 1 price<\/h2>\n        <p class=\"translation-block !text-sm\">Instead of paying for each tool separately, get CAKE.com Bundle and save 53% on subscriptions.<\/p>\n\n        <div class=\"banner-buttons d-flex space-x-4 translation-block\">\n            <a class=\"rounded-md px-6 py-2 bg-white\" href=\"https:\/\/cake.com\/bundle\" target=\"_blank\">Sign up<\/a>\n\n                            <a class=\"button-2\" href=\"https:\/\/clockify.me\/apps\" target=\"_blank\">Download<\/a>\n                    <\/div>\n    <\/div>\n\n    <div class=\"banner-image banner-image-bottom \">\n        <picture>\n            <source srcset=\"https:\/\/clockify.me\/learn\/wp-content\/themes\/cake-learn\/src\/images\/clockify\/banners\/bundle@2x.png 2x\" alt=\"Illustration\"  media=\"(min-width: 1022px)\" \/>\n            <img decoding=\"async\" src=\"https:\/\/clockify.me\/learn\/wp-content\/themes\/cake-learn\/src\/images\/clockify\/banners\/bundle.png\"  alt=\"Illustration\" \/>\n        <\/picture>\n    <\/div>\n<\/div>\n    <\/p>\n\n\n\n<h2 id=\"conclusion-disclaimer\" class=\"wp-block-heading translation-block\">Conclusion\/Disclaimer<\/h2>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">We hope this data privacy laws guide will be helpful. Please pay attention to the links provided, which will lead you to the official government websites and other relevant information.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Please note that this guide was written in December 2024, so any changes in the laws that were included later may not be in this guide.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">We strongly advise you to consult with the appropriate institutions or certified representatives before acting on legal matters.<\/p>\n\n\n\n<p class=\"translation-block wp-block-paragraph\">Clockify isn\u2019t responsible for any losses or risks incurred should this guide be used without further guidance from legal or tax advisors.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Erfahre, welche US-Bundesstaaten im Jahr 2025 Datenschutzgesetze zum Schutz von Verbrauchern im Internet eingef\u00fchrt haben, um konform zu bleiben und potenzielle Klagen zu vermeiden.<\/p>","protected":false},"author":29,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[4,5],"tags":[],"class_list":["post-2787","post","type-post","status-publish","format-standard","hentry","category-business-management","category-business-regulations"],"acf":[],"_links":{"self":[{"href":"https:\/\/clockify.me\/learn\/de\/wp-json\/wp\/v2\/posts\/2787","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/clockify.me\/learn\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/clockify.me\/learn\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/clockify.me\/learn\/de\/wp-json\/wp\/v2\/users\/29"}],"replies":[{"embeddable":true,"href":"https:\/\/clockify.me\/learn\/de\/wp-json\/wp\/v2\/comments?post=2787"}],"version-history":[{"count":27,"href":"https:\/\/clockify.me\/learn\/de\/wp-json\/wp\/v2\/posts\/2787\/revisions"}],"predecessor-version":[{"id":5290,"href":"https:\/\/clockify.me\/learn\/de\/wp-json\/wp\/v2\/posts\/2787\/revisions\/5290"}],"wp:attachment":[{"href":"https:\/\/clockify.me\/learn\/de\/wp-json\/wp\/v2\/media?parent=2787"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/clockify.me\/learn\/de\/wp-json\/wp\/v2\/categories?post=2787"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/clockify.me\/learn\/de\/wp-json\/wp\/v2\/tags?post=2787"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}