{"id":2787,"date":"2024-12-19T14:42:00","date_gmt":"2024-12-19T14:42:00","guid":{"rendered":"https:\/\/clockify.me\/learn\/?p=2787"},"modified":"2026-03-10T12:58:02","modified_gmt":"2026-03-10T12:58:02","slug":"data-privacy-laws","status":"publish","type":"post","link":"https:\/\/clockify.me\/learn\/business-management\/data-privacy-laws\/","title":{"rendered":"Data Privacy Laws \u2014 Comprehensive State Guide for 2025"},"content":{"rendered":"\n<p class=\"translation-block\">The 21st century will be remembered as the time of the digital revolution, and you\u2019ll probably agree that the Internet has changed the world forever.<\/p>\n\n\n\n<p class=\"translation-block\">Although it comes with many benefits, you should be aware that the Internet has exposed us to many issues that we didn\u2019t have before \u2014 mainly concerning our privacy.<\/p>\n\n\n\n<p class=\"translation-block\">Companies make millions of dollars by accessing and using your personal data for advertising and other purposes.&nbsp;<\/p>\n\n\n\n<p class=\"translation-block\">Although this seems scary when you hear it, you should know that countries worldwide are implementing strict laws to keep your data protected while browsing the Internet.<\/p>\n\n\n\n<p class=\"translation-block\">In this article, we will look at data privacy laws in the US and help you better understand your rights on the web.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"600\" src=\"https:\/\/clockify.me\/learn\/wp-content\/uploads\/2024\/12\/Data-privacy-laws-cover.jpg\" alt=\"Data privacy laws - cover\" class=\"wp-image-2789\" srcset=\"https:\/\/clockify.me\/learn\/wp-content\/uploads\/2024\/12\/Data-privacy-laws-cover.jpg 1200w, https:\/\/clockify.me\/learn\/wp-content\/uploads\/2024\/12\/Data-privacy-laws-cover-300x150.jpg 300w, https:\/\/clockify.me\/learn\/wp-content\/uploads\/2024\/12\/Data-privacy-laws-cover-1024x512.jpg 1024w, https:\/\/clockify.me\/learn\/wp-content\/uploads\/2024\/12\/Data-privacy-laws-cover-768x384.jpg 768w, https:\/\/clockify.me\/learn\/wp-content\/uploads\/2024\/12\/Data-privacy-laws-cover-18x9.jpg 18w\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" \/><\/figure>\n<\/div>\n\n\n<ul class=\"wp-block-list key-takeaways\">\n<li class=\"translation-block\">Data privacy laws regulate how organizations and companies can collect personal information from their consumers.&nbsp;<\/li>\n\n\n\n<li class=\"translation-block\">There is no federal data privacy law in the United States yet.<\/li>\n\n\n\n<li class=\"translation-block\">The Fair Trade Commission is the main governing body that protects the rights of American consumers online.&nbsp;<\/li>\n\n\n\n<li class=\"translation-block\">Currently, there are 20 states in the US with data protection regulations.<\/li>\n\n\n\n<li class=\"translation-block\">One of the world&#8217;s most well-known data privacy policies is the EU\u2019s General Data Protection Regulation (GDPR).<\/li>\n<\/ul>\n\n\n\n<h2 id=\"what-is-a-data-privacy-law\" class=\"wp-block-heading translation-block\">What is a data privacy law?<\/h2>\n\n\n\n<p class=\"translation-block\">A data privacy law is a <strong>legal framework that protects consumers<\/strong> from unapproved access to their data while using the internet. These laws also regulate how websites gather information, and how they are allowed to use it.<\/p>\n\n\n\n<p class=\"translation-block\">Every time you visit a website, you leave data behind, which websites later use for advertising and other purposes (e.g., enhancing user experience). Data privacy laws ensure that this data is well protected, and that users can safely browse the web without someone accessing their personal information by:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Defining which organizations must use data privacy laws,<\/li>\n\n\n\n<li class=\"translation-block\">Determining what type of data must be protected,<\/li>\n\n\n\n<li class=\"translation-block\">Defining how organizations can gather, store, and share data,&nbsp;<\/li>\n\n\n\n<li class=\"translation-block\">Granting individuals the rights to their data (in some states), and<\/li>\n\n\n\n<li class=\"translation-block\">Ensuring that organizations comply with legal standards.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">Data privacy laws can vary, and each state formulates its own rules. Yet, there are several key components that every data privacy legislation has::<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\"><strong>Scope and applicability <\/strong>\u2014 defines what types of data have to be protected and which organizations have to comply with these rules,<\/li>\n\n\n\n<li class=\"translation-block\"><strong>User rights<\/strong> \u2014 determine what the users can do with their data. For example, users in some states are allowed to access, transfer, or delete their information,<\/li>\n\n\n\n<li class=\"translation-block\"><strong>Legal consent<\/strong> \u2014 before websites can gather data, the users must give their consent. This is also known as \u201ccookie consent,\u201d and there are rules on how websites need to do this accordingly, and<\/li>\n\n\n\n<li class=\"translation-block\"><strong>Transparency<\/strong> \u2014 websites must inform users how their data will be gathered and for what purposes they\u2019ll use it.<\/li>\n<\/ul>\n\n\n\n<h2 id=\"is-there-an-official-data-privacy-law-in-the-us\" class=\"wp-block-heading translation-block\">Is there an official data privacy law in the US?<\/h2>\n\n\n\n<p class=\"translation-block\">The US still <strong>has no official federal data privacy law<\/strong>. The main proposal for this type of law is the <a href=\"https:\/\/www.congress.gov\/bill\/118th-congress\/house-bill\/8818\/text\" target=\"_blank\" rel=\"noreferrer noopener\">American Privacy Rights Act (APRA)<\/a>, which was introduced to Congress in 2024 but has yet to pass.<\/p>\n\n\n\n<p class=\"translation-block\">Nonetheless, there are several laws worth mentioning when it comes to data privacy and protection online:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\"><a href=\"https:\/\/www.ftc.gov\/legal-library\/browse\/rules\/childrens-online-privacy-protection-rule-coppa\" target=\"_blank\" rel=\"noreferrer noopener\">Children&#8217;s Online Privacy Protection Act (COPPA)<\/a> \u2014 regulates how children&#8217;s information is collected,&nbsp;<\/li>\n\n\n\n<li class=\"translation-block\"><a href=\"https:\/\/www.cdc.gov\/phlp\/php\/resources\/health-insurance-portability-and-accountability-act-of-1996-hipaa.html\" target=\"_blank\" rel=\"noreferrer noopener\">Health Insurance Portability and Accounting Act (HIPAA)<\/a> \u2014 is a federal rule that protects sensitive health information from disclosure,<\/li>\n\n\n\n<li class=\"translation-block\"><a href=\"https:\/\/www.ftc.gov\/business-guidance\/privacy-security\/gramm-leach-bliley-act\" target=\"_blank\" rel=\"noreferrer noopener\">Gramm Leach Bliley Act (GLBA)<\/a> \u2014 regulates how banks and financial institutions collect information,<\/li>\n\n\n\n<li class=\"translation-block\"><a href=\"https:\/\/www.ftc.gov\/legal-library\/browse\/statutes\/fair-credit-reporting-act\" target=\"_blank\" rel=\"noreferrer noopener\">Fair Credit Reporting Act (FCRA)<\/a> \u2014 regulates the collection of credit information, and<\/li>\n\n\n\n<li class=\"translation-block\"><a href=\"https:\/\/studentprivacy.ed.gov\/faq\/what-ferpa\" target=\"_blank\" rel=\"noreferrer noopener\">Family Educational Rights and Privacy Act (FERPA)<\/a> \u2014 protects student education records.<\/li>\n<\/ul>\n\n\n\n<h3 id=\"what-organization-governs-data-privacy-laws-in-the-us\" class=\"wp-block-heading translation-block\">What organization governs data privacy laws in the US?<\/h3>\n\n\n\n<p class=\"translation-block\">When it comes to enforcing data privacy laws, the main governing body in the US is the <a href=\"https:\/\/www.ftc.gov\/\" target=\"_blank\" rel=\"noreferrer noopener\">Federal Trade Commission (FTC)<\/a>. The FTC is there to protect consumers in all aspects of commerce, and its primary statute is the <a href=\"https:\/\/www.ftc.gov\/legal-library\/browse\/statutes\/federal-trade-commission-act\" target=\"_blank\" rel=\"noreferrer noopener\">Federal Trade Commission Act<\/a>, allowing the Commission to:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li class=\"translation-block\">Stop unfair competition methods and unfair trade practices,<\/li>\n\n\n\n<li class=\"translation-block\">Pursue financial redress for violations of consumer rights,<\/li>\n\n\n\n<li class=\"translation-block\">Define acts and practices that are deceptive and establish rules to prevent them,<\/li>\n\n\n\n<li class=\"translation-block\">Collect information and investigate organizations, businesses, practices, and management of entities in trade, and<\/li>\n\n\n\n<li class=\"translation-block\">Report and suggest legislation to Congress and the public.<\/li>\n<\/ol>\n\n\n\n<p class=\"translation-block\">A good example of how the FTC handles data privacy infringements is when they <a href=\"https:\/\/www.ftc.gov\/news-events\/news\/press-releases\/2011\/03\/ftc-charges-deceptive-privacy-practices-googles-rollout-its-buzz-social-network\" target=\"_blank\" rel=\"noreferrer noopener\">accused Google of violating user privacy<\/a> upon launching its social media platform, Google Buzz, back in 2010. This resulted in a settlement that prohibited Google from repeating any violation of this kind and required them to implement a comprehensive privacy program for the next 20 years.<\/p>\n\n\n\n<p class=\"translation-block\">\ud83c\udf93 To learn more about the Federal Trade Commission visit their website \u2014 <a href=\"https:\/\/www.ftc.gov\/news-events\/media-resources\/what-ftc-does\" target=\"_blank\" rel=\"noreferrer noopener\">What the FTC does?<\/a><\/p>\n\n\n\n<h2 id=\"what-us-states-have-data-privacy-laws\" class=\"wp-block-heading translation-block\">What US states have data privacy laws?<\/h2>\n\n\n\n<p class=\"translation-block\">In recent years, more and more states are adopting data privacy laws. This is due to the lack of a federal law governing privacy protection. Currently, <strong>there are 20 states with data privacy laws in the US<\/strong>.&nbsp;<\/p>\n\n\n\n<p class=\"translation-block\">Let\u2019s look at each of them in more detail.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"1150\" src=\"https:\/\/clockify.me\/learn\/wp-content\/uploads\/2024\/12\/States-with-data-privacy-laws-in-the-US.jpg\" alt=\"States with data privacy laws in the US\" class=\"wp-image-2786\" srcset=\"https:\/\/clockify.me\/learn\/wp-content\/uploads\/2024\/12\/States-with-data-privacy-laws-in-the-US.jpg 1200w, https:\/\/clockify.me\/learn\/wp-content\/uploads\/2024\/12\/States-with-data-privacy-laws-in-the-US-300x288.jpg 300w, https:\/\/clockify.me\/learn\/wp-content\/uploads\/2024\/12\/States-with-data-privacy-laws-in-the-US-1024x981.jpg 1024w, https:\/\/clockify.me\/learn\/wp-content\/uploads\/2024\/12\/States-with-data-privacy-laws-in-the-US-768x736.jpg 768w, https:\/\/clockify.me\/learn\/wp-content\/uploads\/2024\/12\/States-with-data-privacy-laws-in-the-US-13x12.jpg 13w\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" \/><figcaption class=\"wp-element-caption\">States with data privacy laws<\/figcaption><\/figure>\n<\/div>\n\n\n<h3 id=\"1-california-privacy-rights-act-cpra\" class=\"wp-block-heading translation-block\">1. California Privacy Rights Act (CPRA)<\/h3>\n\n\n\n<p class=\"translation-block\"><strong>Status<\/strong>: Effective since January 1, 2023.<\/p>\n\n\n\n<p class=\"translation-block\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/thecpra.org\/\" target=\"_blank\" rel=\"noreferrer noopener\">California Privacy Rights Act<\/a><\/p>\n\n\n\n<p class=\"translation-block\">The CPRA is one of the largest data privacy laws out there and is an amendment to the <a href=\"https:\/\/oag.ca.gov\/privacy\/ccpa\" target=\"_blank\" rel=\"noreferrer noopener\">California Consumer Privacy Act (CCPA)<\/a>. The law grants Californian citizens the rights to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Disallow entities from collecting their data,<\/li>\n\n\n\n<li class=\"translation-block\">Access and correct data,<\/li>\n\n\n\n<li class=\"translation-block\">Delete data, and<\/li>\n\n\n\n<li class=\"translation-block\">Prohibit entities from sharing data.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">In addition to enhanced consumer protection, the law also sets responsibilities for entities that collect personal information, such as asking users for consent.<\/p>\n\n\n\n<p class=\"translation-block\">The governing body for the CPRA is the <a href=\"https:\/\/cppa.ca.gov\/\" target=\"_blank\" rel=\"noreferrer noopener\">California Privacy Protection Agency (CPPA)<\/a>, which can hold hearings and impose fines for potential violations.<\/p>\n\n\n\n<p class=\"translation-block\">\ud83c\udf93 To learn more about employment laws in California, visit our website \u2014 <a href=\"https:\/\/clockify.me\/state-labor-laws\/california-labor-law\" target=\"_blank\" rel=\"noreferrer noopener\">California Labor Laws Guide<\/a><\/p>\n\n\n\n<h3 id=\"2-colorado-privacy-act-cpa\" class=\"wp-block-heading translation-block\">2. Colorado Privacy Act (CPA)<\/h3>\n\n\n\n<p class=\"translation-block\"><strong>Status<\/strong>: Effective since July 1, 2023.<\/p>\n\n\n\n<p class=\"translation-block\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/coag.gov\/resources\/colorado-privacy-act\/\" target=\"_blank\" rel=\"noreferrer noopener\">Colorado Privacy Act<\/a><\/p>\n\n\n\n<p class=\"translation-block\">The CPA is a part of <a href=\"https:\/\/leg.colorado.gov\/bills\/hb19-1289\" target=\"_blank\" rel=\"noreferrer noopener\">Colorado\u2019s Consumer Protection Act<\/a> and is enforced and implemented by the Colorado Attorney General. This law grants Colorado consumers the following rights:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">To access, delete, and correct personal information, and<\/li>\n\n\n\n<li class=\"translation-block\">To reject the use of their data for advertising purposes or other types of profiling.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">Covered entities that collect personal information must protect data, acquire consent, and inform Colorado citizens on how their data is collected and used. The CPA applies to organizations that:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Gather information from 100,000 consumers, and&nbsp;<\/li>\n\n\n\n<li class=\"translation-block\">Gather information from 25,000 consumers and generate revenue from it.<\/li>\n<\/ul>\n\n\n\n<h3 id=\"3-connecticut-data-privacy-act-ctdpa\" class=\"wp-block-heading translation-block\">3. Connecticut Data Privacy Act (CTDPA)<\/h3>\n\n\n\n<p class=\"translation-block\"><strong>Status<\/strong>: Effective since July 1, 2023.<\/p>\n\n\n\n<p class=\"translation-block\">The CTDPA grants Connecticut residents the same rights as the other similar laws, which include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete their data,&nbsp;<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of their personal information, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">This law applies to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather the data of at least 100,000 consumers, or&nbsp;<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather the data of at least 25,000 consumers, but generate 25% of their revenue from selling that data.<\/li>\n<\/ul>\n\n\n\n<h3 id=\"4-delaware-personal-data-privacy-act-dpdpa\" class=\"wp-block-heading translation-block\">4. Delaware Personal Data Privacy Act (DPDPA)<\/h3>\n\n\n\n<p class=\"translation-block\"><strong>Status<\/strong>: It will take effect on January 1, 2025.<\/p>\n\n\n\n<p class=\"translation-block\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/legis.delaware.gov\/json\/BillDetail\/GenerateHtmlDocument?legislationId=140388&amp;legislationTypeId=1&amp;docTypeId=2&amp;legislationName=HB154#:~:text=The%20Act%20delineates%20a%20consumer's,maintained%20by%20entities%20or%20people.\" target=\"_blank\" rel=\"noreferrer noopener\">Delaware Personal Data Privacy Act<\/a><\/p>\n\n\n\n<p class=\"translation-block\">The DPDPA is modeled after other data privacy legislations, and it will grant Delaware citizens the following consumer rights:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to allow or disallow entities to collect personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to correct or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire copies of their personal information,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a list of third-party entities that have access to their data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the use of their data for advertising or other similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">The law will apply to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather information from more at least 35,000 consumers in Delaware, or<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather information from at least 10,000 consumers in Delaware and generate at least 20% of revenue from selling it.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">The <a href=\"https:\/\/www.justice.gov\/\" target=\"_blank\" rel=\"noreferrer noopener\">Department of Justice<\/a> enforces this law, which can impose fines of up to $10,000 per violation.<\/p>\n\n\n\n<h3 id=\"5-indiana-consumer-data-protection-act-incdpa\" class=\"wp-block-heading translation-block\">5. Indiana Consumer Data Protection Act (INCDPA)<\/h3>\n\n\n\n<p class=\"translation-block\"><strong>Status<\/strong>: It will take effect on January 1, 2026.<\/p>\n\n\n\n<p class=\"translation-block\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/iga.in.gov\/legislative\/2023\/bills\/senate\/5\/details\" target=\"_blank\" rel=\"noreferrer noopener\">Indiana Consumer Data Protection Act<\/a><\/p>\n\n\n\n<p class=\"translation-block\">The INCDPA will grant Indiana residents the following rights concerning their data privacy and protection:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">This law will apply to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather the data from at least 100,000 Indiana residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather the data from 25,000 Indiana residents and earn at least 50% of their revenue by selling it.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">The attorney general will enforce data privacy law in Indiana and may impose sanctions of up to $7,500 per violation. The law predicts a cure period of 30 days before penalties.<\/p>\n\n\n\n<h3 id=\"6-iowa-consumer-data-protection-act-icdpa\" class=\"wp-block-heading translation-block\">6. Iowa Consumer Data Protection Act (ICDPA)<\/h3>\n\n\n\n<p class=\"translation-block\"><strong>Status<\/strong>: It will take effect on January 1, 2025.<\/p>\n\n\n\n<p class=\"translation-block\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/www.legis.iowa.gov\/docs\/publications\/LGE\/90\/SF262.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">Iowa Consumer Data Protection Act<\/a><\/p>\n\n\n\n<p class=\"translation-block\">The ICDPA will grant Iowa residents the same rights:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to confirm data processing,<\/li>\n\n\n\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the selling of their data.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">This law will apply to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather the data from at least 100,000 Indiana residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather the data from 25,000 Indiana residents and earn at least 50% of their revenue by selling it.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">The attorney general will enforce data privacy law in Iowa and may impose sanctions of up to $7,500 per violation. The law predicts a cure period of 90 days before penalties.<\/p>\n\n\n\n<h3 id=\"7-kentucky-consumer-data-protection-act-kcdpa\" class=\"wp-block-heading translation-block\">7. Kentucky Consumer Data Protection Act (KCDPA)<\/h3>\n\n\n\n<p class=\"translation-block\"><strong>Status<\/strong>: Will take effect on January 1, 2025.<\/p>\n\n\n\n<p class=\"translation-block\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/apps.legislature.ky.gov\/record\/24rs\/hb15.html\" target=\"_blank\" rel=\"noreferrer noopener\">Kentucky Consumer Data Protection Act<\/a><\/p>\n\n\n\n<p class=\"translation-block\">The KCDPA will grant Kentucky residents the following rights concerning their data privacy and protection:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">This law will apply to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather the data from at least 100,000 Indiana residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather the data from 25,000 Kentucky residents and earn at least 50% of their revenue by selling it.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">The attorney general will enforce data privacy law in Kentucky and may impose sanctions of up to $7,500 per violation. The law predicts a cure period of 90 days before penalties.<\/p>\n\n\n\n<h3 id=\"8-maryland-online-data-privacy-act-mdodpa\" class=\"wp-block-heading translation-block\">8. Maryland Online Data Privacy Act (MDODPA)<\/h3>\n\n\n\n<p class=\"translation-block\"><strong>Status<\/strong>: It will take effect on October 1, 2025.<\/p>\n\n\n\n<p class=\"translation-block\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/mgaleg.maryland.gov\/mgawebsite\/Legislation\/Details\/sb0541?ys=2024RS\" target=\"_blank\" rel=\"noreferrer noopener\">Maryland Online Data Privacy Act<\/a><\/p>\n\n\n\n<p class=\"translation-block\">The MDODPA is known as a more strict data privacy law as it requires organizations to take additional measures to protect consumers, such as allowing consumers not to accept the processing of their personal data.<\/p>\n\n\n\n<p class=\"translation-block\">This law grants Maryland residents the following rights:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data,&nbsp;<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes,<\/li>\n\n\n\n<li class=\"translation-block\">The right to get a list of all third parties with access to the data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to revoke their consent.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">This law will apply to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather the data from at least 35,000 Maryland residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather the data from 10,000 Maryland residents and earn at least 20% of their revenue by selling it.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">Maryland&#8217;s Consumer Protection Division will enforce data privacy law in Maryland and may impose fines from $10,000 to $25,000 depending on the violation.<\/p>\n\n\n\n<h3 id=\"9-minnesota-consumer-data-privacy-act-mcdpa\" class=\"wp-block-heading translation-block\">9. Minnesota Consumer Data Privacy Act (MCDPA)<\/h3>\n\n\n\n<p class=\"translation-block\"><strong>Status<\/strong>: Will take effect on July 31, 2025.<\/p>\n\n\n\n<p class=\"translation-block\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/www.house.mn.gov\/hrd\/bs\/93\/hf2309.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">Minnesota Consumer Data Privacy Act<\/a><\/p>\n\n\n\n<p class=\"translation-block\">The MCDPA grants Minnesota residents the following rights:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data,&nbsp;<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to review and understand how data is being profiled.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">This law will apply to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather the data from at least 100,000 Minnesota residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather the data from 25,000 Minnesota residents and earn at least 25% of their revenue by selling it.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">The attorney general will enforce data privacy law in Minnesota and may impose fines of up to $7,500 per violation. However, the attorney general must issue a warning letter first and provide a way to cure the breach.<\/p>\n\n\n\n<h3 id=\"10-montana-consumer-data-privacy-act-mtcdpa\" class=\"wp-block-heading translation-block\">10. Montana Consumer Data Privacy Act (MTCDPA)<\/h3>\n\n\n\n<p class=\"translation-block\"><strong>Status<\/strong>: Effective since October 1, 2024.<\/p>\n\n\n\n<p class=\"translation-block\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/www.house.mn.gov\/hrd\/bs\/93\/hf2309.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">Montana Consumer Data Privacy Act<\/a><\/p>\n\n\n\n<p class=\"translation-block\">Under the MTCDPA, consumers have the right to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">Acquire a copy of the data, and<\/li>\n\n\n\n<li class=\"translation-block\">Reject the processing of their data for advertising or similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">The law applies to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather the data from at least 50,000 Montana residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather the data from 25,000 Montana residents and earn at least 25% of their revenue by selling it.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">The attorney general will enforce data privacy law in Montana, but there are no specific fines for violations. The cure period for violations is 60 days.<\/p>\n\n\n\n<h3 id=\"11-nebraska-data-privacy-act-ndpa\" class=\"wp-block-heading translation-block\">11. Nebraska Data Privacy Act (NDPA)<\/h3>\n\n\n\n<p class=\"translation-block\"><strong>Status<\/strong>: It will take effect on January 1, 2025.<\/p>\n\n\n\n<p class=\"translation-block\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/nebraskalegislature.gov\/FloorDocs\/108\/PDF\/Slip\/LB1074.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">Nebraska Data Privacy Act<\/a><\/p>\n\n\n\n<p class=\"translation-block\">Under the NDPA, residents in Nebraska will have the following rights:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">The Nebraska data privacy law will apply to individuals or organizations (excluding small businesses) that collect personal and sensitive data from consumers. However, there is no revenue or volume requirement as in most other states.<\/p>\n\n\n\n<p class=\"translation-block\">The attorney general will enforce data privacy law in Nebraska and impose fines of up to $7,500 per violation. The attorney general must first inform the subject of the breach and give them a 30-day cure period. After curing the violation, the subject must provide a written statement declaring they won\u2019t repeat it.<\/p>\n\n\n\n<h3 id=\"12-new-hampshire-privacy-act-nhpa\" class=\"wp-block-heading translation-block\">12. New Hampshire Privacy Act (NHPA)<\/h3>\n\n\n\n<p class=\"translation-block\"><strong>Status<\/strong>: It will take effect on January 1, 2025.<\/p>\n\n\n\n<p class=\"translation-block\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/www.doj.nh.gov\/news-and-media\/attorney-general-formella-announces-creation-new-data-privacy-unit\" target=\"_blank\" rel=\"noreferrer noopener\">New Hampshire Privacy Act<\/a><\/p>\n\n\n\n<p class=\"translation-block\">Under the NHPA, residents in New Hampshire will have the following rights:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">The law will apply to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather the data from at least 35,000 New Hampshire residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather the data from 10,000 New Hampshire residents and earn at least 25% of their revenue by selling it.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">The attorney general will enforce New Hampshire data privacy law and may impose fines of up to $10,000 per violation. If the violation is on purpose, the attorney general may seek criminal penalties of up to $100,000 per violation.<\/p>\n\n\n\n<h3 id=\"13-new-jersey-data-privacy-act-njdpa\" class=\"wp-block-heading translation-block\">13. New Jersey Data Privacy Act (NJDPA)<\/h3>\n\n\n\n<p class=\"translation-block\"><strong>Status<\/strong>: It will take effect on January 15, 2025.<\/p>\n\n\n\n<p class=\"translation-block\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/pub.njleg.state.nj.us\/Bills\/2022\/AL23\/266_.PDF\" target=\"_blank\" rel=\"noreferrer noopener\">New Jersey Data Privacy Act<\/a><\/p>\n\n\n\n<p class=\"translation-block\">Under NJDPA, residents of New Jersey will have the following rights:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">The law will apply to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather the data from at least 100,000 New Jersey residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather the data from 25,000 New Jersey residents and earn revenue by selling it (no amount is specified).<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">The attorney general will enforce New Jersey data privacy law and may impose fines of up to $2,500 for the first violation, up to $5,000 for the second violation, up to $10,000 for the third violation, and up to $20,000 for the fourth and every consecutive violation.<\/p>\n\n\n\n<p class=\"translation-block\">\ud83c\udf93 To learn more about employment laws in New Jersey, visit our website \u2014 <a href=\"https:\/\/clockify.me\/state-labor-laws\/new-jersey-labor-law\" target=\"_blank\" rel=\"noreferrer noopener\">New Jersey Labor Laws Guide<\/a><\/p>\n\n\n\n<h3 id=\"14-oregon-consumer-privacy-act-ocpa\" class=\"wp-block-heading translation-block\">14. Oregon Consumer Privacy Act (OCPA)<\/h3>\n\n\n\n<p class=\"translation-block\"><strong>Status<\/strong>: Effective since July 1, 2024.<\/p>\n\n\n\n<p class=\"translation-block\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/www.doj.state.or.us\/consumer-protection\/id-theft-data-breaches\/privacy\/\" target=\"_blank\" rel=\"noreferrer noopener\">Oregon Consumer Privacy Act<\/a><\/p>\n\n\n\n<p class=\"translation-block\">Under OCPA, residents of Oregon have several rights. The law explains this easily by using the phrase <strong>LOCKED<\/strong>, which includes the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Users have the right to get a <strong>list<\/strong> of all third-party entities that handle their data,<\/li>\n\n\n\n<li class=\"translation-block\">Users can <strong>opt-out<\/strong> from letting entities sell their information for advertising or other purposes,&nbsp;<\/li>\n\n\n\n<li class=\"translation-block\">Users can ask for a <strong>copy<\/strong> of the personal data that businesses have about them,<\/li>\n\n\n\n<li class=\"translation-block\">Users can <strong>know<\/strong> what information an organization has about them,<\/li>\n\n\n\n<li class=\"translation-block\">Users can <strong>edit<\/strong> inaccurate data, and<\/li>\n\n\n\n<li class=\"translation-block\">Users can <strong>delete<\/strong> personal or sensitive information a business has about them.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">This law applies to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather data from at least 100,000 Oregon residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather data from at least 25,000 Oregon residents and earn a minimum of 25% of their revenue by selling it.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">The attorney general will enforce Oregon data privacy law and may impose fines of up to $7,500 per violation. There is a 30-day cure period for the breach.<\/p>\n\n\n\n<h3 id=\"15-rhode-island-data-transparency-and-privacy-protection-act-ridtppa\" class=\"wp-block-heading translation-block\">15. Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)<\/h3>\n\n\n\n<p class=\"translation-block\"><strong>Status<\/strong>: It will take effect on January 1, 2026.<\/p>\n\n\n\n<p class=\"translation-block\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/www.rilegislature.gov\/pressrelease\/_layouts\/15\/ril.pressrelease.inputform\/DisplayForm.aspx?List=c8baae31-3c10-431c-8dcd-9dbbe21ce3e9&amp;ID=374664\" target=\"_blank\" rel=\"noreferrer noopener\">Rhode Island Data Transparency and Privacy Protection Act<\/a><\/p>\n\n\n\n<p class=\"translation-block\">Under RIDTPPA, residents of Rhode Island have the right to know how their personal information is collected and for what it is used. In addition, before collecting information, users must give consent to entities that gather it. However, companies aren\u2019t required to create an opt-out mechanism.<\/p>\n\n\n\n<p class=\"translation-block\">This law applies to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather data from at least 35,000 Rhode Island residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather data from at least 10,000 Rhode Island residents and earn a minimum of 20% of their revenue by selling it.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">The attorney general will enforce Rhode Island data privacy law and may impose fines from $100 to $500 per violation. There is no cure period for the breach.<\/p>\n\n\n\n<h3 id=\"16-tennessee-information-protection-act-tipa\" class=\"wp-block-heading translation-block\">16. Tennessee Information Protection Act (TIPA)<\/h3>\n\n\n\n<p class=\"translation-block\"><strong>Status<\/strong>: It will take effect on July 1, 2025.<\/p>\n\n\n\n<p class=\"translation-block\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/www.capitol.tn.gov\/Bills\/113\/Bill\/HB1181.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">Tennessee Information Protection Act<\/a><\/p>\n\n\n\n<p class=\"translation-block\">Under TIPA, residents of Tennessee will have the following rights:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">This law applies to entities that exceed $25 million in revenue and either:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Gather data from at least 175,000 Tennessee residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Gather data from at least 25,000 Oregon residents and earn a minimum of 50% of their revenue by selling it.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">The attorney general will enforce Tennessee data privacy law and may impose fines of up to $7,500 per violation, or in some cases the triple amount if the violation is wilful. There is a 60-day cure period for the breach.<\/p>\n\n\n\n<p class=\"translation-block\">\ud83c\udf93 To learn more about employment laws in Tennessee, visit our website \u2014 <a href=\"https:\/\/clockify.me\/state-labor-laws\/tennessee-labor-law\" target=\"_blank\" rel=\"noreferrer noopener\">Tennessee Labor Laws Guide<\/a><\/p>\n\n\n\n<h3 id=\"17-texas-data-privacy-and-security-act-tdpsa\" class=\"wp-block-heading translation-block\">17. Texas Data Privacy and Security Act (TDPSA)<\/h3>\n\n\n\n<p class=\"translation-block\"><strong>Status<\/strong>: Enforceable since January 1, 2024, but businesses have a grace period until January 1, 2025, to comply with the law.<\/p>\n\n\n\n<p class=\"translation-block\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/www.texasattorneygeneral.gov\/consumer-protection\/file-consumer-complaint\/consumer-privacy-rights\/texas-data-privacy-and-security-act\" target=\"_blank\" rel=\"noreferrer noopener\">Texas Data Privacy and Security Act<\/a><\/p>\n\n\n\n<p class=\"translation-block\">Under TDPSA, users have the common data privacy laws used in most states, which include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">This law doesn\u2019t have the standard eligibility requirements (revenue-based) used by other states. Instead, entities that are covered by this law are businesses that gather or sell data in Texas.&nbsp;<\/p>\n\n\n\n<p class=\"translation-block\">The attorney general will enforce Texas data privacy law and may impose fines of up to $7,500 per violation. There is a 30-day cure period.<\/p>\n\n\n\n<h3 id=\"18-utah-consumer-privacy-act-ucpa\" class=\"wp-block-heading translation-block\">18. Utah Consumer Privacy Act (UCPA)<\/h3>\n\n\n\n<p class=\"translation-block\"><strong>Status<\/strong>: Effective since December 31, 2023.<\/p>\n\n\n\n<p class=\"translation-block\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/dcp.utah.gov\/ucpa\/\" target=\"_blank\" rel=\"noreferrer noopener\">Utah Consumer Privacy Act<\/a><\/p>\n\n\n\n<p class=\"translation-block\">The UCPA grants Utah residents the following rights:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">The law has similar eligibility requirements as TIPA and applies to entities that exceed $25 million in revenue and either:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Gather data from at least 100,000 Utah residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Gather data from at least 25,000 Utah residents and earn a minimum of 50% of their revenue by selling it.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">The attorney general enforces Utah data privacy law and may impose fines of up to $7,500 per violation. There is a 30-day cure period.<\/p>\n\n\n\n<h3 id=\"19-virginias-consumer-data-protection-act-vcdpa\" class=\"wp-block-heading translation-block\">19. Virginia&#8217;s Consumer Data Protection Act (VCDPA)<\/h3>\n\n\n\n<p class=\"translation-block\"><strong>Status<\/strong>: Effective since January 1, 2023.<\/p>\n\n\n\n<p class=\"translation-block\"><strong>Official legislation<\/strong>: <a href=\"https:\/\/www.oag.state.va.us\/consumer-protection\/files\/tips-and-info\/Virginia-Consumer-Data-Protection-Act-Summary-2-2-23.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">Virginia&#8217;s Consumer Data Protection Act<\/a><\/p>\n\n\n\n<p class=\"translation-block\">Under VCDPA, the residents of Virginia have the usual data privacy rights, which include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">The law applies to the following entities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">Organizations or individuals that gather the data from at least 100,000 Virginia residents, or<\/li>\n\n\n\n<li class=\"translation-block\">Organizations or individuals that gather the data from 25,000 Virginia residents and earn at least 50% of their revenue by selling it.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">The attorney general enforces Virginia data privacy law and may impose fines of up to $7,500 per violation. There is a 30-day cure period.<\/p>\n\n\n\n<h3 id=\"20-florida-digital-bill-of-rights-fdbr\" class=\"wp-block-heading translation-block\">20. Florida Digital Bill of Rights (FDBR)<\/h3>\n\n\n\n<p class=\"translation-block\"><strong>Status<\/strong>: Effective since July 1, 2024.<\/p>\n\n\n\n<p class=\"translation-block\"><strong>Official<\/strong> <strong>legislation<\/strong>: <a href=\"https:\/\/www.flsenate.gov\/Session\/Bill\/2023\/262\/BillText\/er\/HTML\" target=\"_blank\" rel=\"noreferrer noopener\">Florida Digital Bill of Rights<\/a><\/p>\n\n\n\n<p class=\"translation-block\">Under FDBR, residents of Florida have the following online privacy rights:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">The right to access, correct, or delete personal data,<\/li>\n\n\n\n<li class=\"translation-block\">The right to acquire a copy of the data, and<\/li>\n\n\n\n<li class=\"translation-block\">The right to reject the processing of their data for advertising or similar purposes.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">The law applies to the entities in Florida that earn at least $1 billion of annual revenue and:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"translation-block\">At least 50% of their revenue comes from digital platforms,<\/li>\n\n\n\n<li class=\"translation-block\">Use an app with more than 250,000 applications, and<\/li>\n\n\n\n<li class=\"translation-block\">Have a smart speaker that is connected to the cloud.<\/li>\n<\/ul>\n\n\n\n<p class=\"translation-block\">The attorney general enforces Florida data privacy law and may impose fines of up to $50,000 per violation. There is a 45-day cure period.<\/p>\n\n\n\n<p class=\"translation-block\">\ud83c\udf93 To learn more about employment laws in Florida, visit our website \u2014 <a href=\"https:\/\/clockify.me\/state-labor-laws\/florida-labor-law\" target=\"_blank\" rel=\"noreferrer noopener\">Florida Labor Laws Guide<\/a><\/p>\n\n\n\n<h2 id=\"what-are-the-data-privacy-laws-in-europe\" class=\"wp-block-heading translation-block\">What are the data privacy laws in Europe?<\/h2>\n\n\n\n<p class=\"translation-block\">Europe has several data privacy laws that are used to protect the right to privacy of its residents. The most popular among these laws is the <a href=\"https:\/\/gdpr-info.eu\/\" target=\"_blank\" rel=\"noreferrer noopener\">General Data Protection Regulation (GDPR)<\/a>, one of the world&#8217;s most comprehensive data privacy laws.&nbsp;<\/p>\n\n\n\n<p class=\"translation-block\">In addition to the GDPR, in recent years, Europe has enacted a few additional data privacy legislations, such as the <a href=\"https:\/\/digital-markets-act.ec.europa.eu\/index_en\" target=\"_blank\" rel=\"noreferrer noopener\">Digital Markets Act (DMA)<\/a>.&nbsp;<\/p>\n\n\n\n<p class=\"translation-block\">Let\u2019s look at these laws in more detail.<\/p>\n\n\n\n<h3 id=\"1-general-data-protection-regulation-gdpr\" class=\"wp-block-heading translation-block\">1. General Data Protection Regulation (GDPR)<\/h3>\n\n\n\n<p class=\"translation-block\">The General Data Protection Regulation (GDPR) is a very strict privacy and security law affecting countries worldwide. The European Union (EU) drafted this document and signed it into law in 2016, and it became effective on May 25, 2018.<\/p>\n\n\n\n<p class=\"translation-block\">Every company that processes personal data or sells goods and services to EU residents must comply with the GDPR rules. The GDPR outlines 7 key protection and responsibility principles that include:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li class=\"translation-block\"><strong>Lawfulness, fairness, and transparency<\/strong> \u2014 all processed data must be fair, transparent, and compliant with the law,<\/li>\n\n\n\n<li class=\"translation-block\"><strong>Purpose<\/strong> \u2014 data can only be gathered for legitimate purposes specified to the user,<\/li>\n\n\n\n<li class=\"translation-block\"><strong>Minimization <\/strong>\u2014 the amount of data gathered must be minimal for the required purpose,<\/li>\n\n\n\n<li class=\"translation-block\"><strong>Accuracy<\/strong> \u2014 all data must be accurate,<\/li>\n\n\n\n<li class=\"translation-block\"><strong>Storage limitation<\/strong> \u2014 data can be stored only for the amount of time necessary for the purpose,<\/li>\n\n\n\n<li class=\"translation-block\"><strong>Integrity &amp; confidentiality<\/strong> \u2014&nbsp; all processing must ensure security, integrity, and privacy (e.g., encryption), and<\/li>\n\n\n\n<li class=\"translation-block\"><strong>Accountability<\/strong> \u2014 every organization that processes data is accountable for demonstrating compliance with the GDPR rules.<\/li>\n<\/ol>\n\n\n\n<p class=\"translation-block\">When it comes to penalties, the <a href=\"https:\/\/gdpr.eu\/fines\/\" target=\"_blank\" rel=\"noreferrer noopener\">GDPR fines<\/a> are incredibly high. They can max out at \u20ac20 million or 4% of the company\u2019s revenue. In addition, subjects have the right to seek compensation for damages.&nbsp;<\/p>\n\n\n\n<p class=\"translation-block\">\ud83c\udf93 To learn more about the GDPR, visit their official website \u2014 <a href=\"https:\/\/gdpr.eu\/what-is-gdpr\/\" target=\"_blank\" rel=\"noreferrer noopener\">What is GDPR, the EU\u2019s new data protection law?<\/a><\/p>\n\n\n\n<h3 id=\"2-digital-markets-act-dma\" class=\"wp-block-heading translation-block\">2. Digital Markets Act (DMA)<\/h3>\n\n\n\n<p class=\"translation-block\">The Digital Markets Act (DMA) is a European law that covers the largest digital platforms, such as Facebook, Google, and Apple, in the EU. This law became effective in March 2024 and aims to prevent large companies from imposing unfair market conditions on their competitors.<\/p>\n\n\n\n<p class=\"translation-block\">Companies that fail to comply with the DMA can be fined up to 10% of their revenue and sometimes up to 20% if they repeat the violation.<\/p>\n\n\n\n<h3 id=\"3-european-union-ai-act\" class=\"wp-block-heading translation-block\">3. European Union AI Act<\/h3>\n\n\n\n<p class=\"translation-block\">With artificial intelligence becoming increasingly popular, the EU has approved the <a href=\"https:\/\/artificialintelligenceact.eu\/\" target=\"_blank\" rel=\"noreferrer noopener\">European Union AI Act<\/a>, which will go into effect in late 2025 or 2026. This law will apply to all companies that develop AI systems and require them to respect ethical and fundamental rights when designing them.<\/p>\n\n\n\n<h3 id=\"4-digital-services-act-dsa\" class=\"wp-block-heading translation-block\">4. Digital Services Act (DSA)<\/h3>\n\n\n\n<p class=\"translation-block\">The <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/digital-services-act-package\" target=\"_blank\" rel=\"noreferrer noopener\">Digital Services Act (DSA)<\/a> sets clear rules protecting consumers and their online rights. The main purpose of this law is to prevent illegal and harmful online activities, such as spreading misinformation or posting prohibited content.<\/p>\n\n\n\n<h2 id=\"frequently-asked-questions-about-data-privacy-laws\" class=\"wp-block-heading translation-block\">Frequently asked questions about data privacy laws<\/h2>\n\n\n\n<p class=\"translation-block\">To make this guide as comprehensive as possible, we\u2019ve included an FAQ section where we\u2019ll answer the most common questions about this topic.<\/p>\n\n\n\n<h3 id=\"do-us-companies-need-to-comply-with-gdpr\" class=\"wp-block-heading translation-block\">Do US companies need to comply with GDPR?<\/h3>\n\n\n\n<p class=\"translation-block\">Yes, if a company operates on EU soil or has customers from the EU, it will have to respect GDPR rules.<\/p>\n\n\n\n<h3 id=\"what-is-the-difference-between-gdpr-and-ccpa\" class=\"wp-block-heading translation-block\">What is the difference between GDPR and CCPA?<\/h3>\n\n\n\n<p class=\"translation-block\">The main difference between the two is that GDPR applies to all companies that operate on EU soil, and the CCPA applies only to California residents.<\/p>\n\n\n\n<h3 id=\"how-many-states-have-data-privacy-laws\" class=\"wp-block-heading translation-block\">How many states have data privacy laws?<\/h3>\n\n\n\n<p class=\"translation-block\">Currently, there are 20 states in the US that have enacted data protection laws. Some of them are already effective, and some will become effective in 2025 or 2026.<\/p>\n\n\n\n<h2 id=\"protect-your-companys-privacy-with-the-cake-com-bundle\" class=\"wp-block-heading translation-block\">Protect your company\u2019s privacy with the CAKE.com Bundle<\/h2>\n\n\n\n<p class=\"translation-block\">With the rise of data privacy laws, companies must find ways to improve their <a href=\"https:\/\/cake.com\/security\" target=\"_blank\" rel=\"noreferrer noopener\">security<\/a> and keep their customer\u2019s data safe.<\/p>\n\n\n\n<p class=\"translation-block\">For many, this can be pretty expensive.<\/p>\n\n\n\n<p class=\"translation-block\">Why, you ask? Well, you\u2019ll need appropriate software that is secure.<\/p>\n\n\n\n<p class=\"translation-block\">That\u2019s where CAKE.com can help you, as it offers 3 robust pieces of software that keep all your data safe.<\/p>\n\n\n\n<p class=\"translation-block\">With <a href=\"https:\/\/app.clockify.me\/en\/signup\" target=\"_blank\" rel=\"noreferrer noopener\">Clockify<\/a> by <a href=\"https:\/\/cake.com\/\" type=\"link\" id=\"https:\/\/cake.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">CAKE.com<\/a>, you get a time tracking software you can use to track employee activities, send invoices, schedule shifts, and much more.<\/p>\n\n\n\n<figure class=\"wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Clockify Tour\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/NMZhFs_b0Aw?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"translation-block\">With <a href=\"https:\/\/pumble.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Pumble<\/a>, you get access to a modern team communication software that keeps all information your team shares safe and secure.<\/p>\n\n\n\n<figure class=\"wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Introduction to Pumble\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/0UUEStUkgJM?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"translation-block\">Last but not least, <a href=\"https:\/\/plaky.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Plaky<\/a> is your go-to project management software that lets you track tasks and projects within your team.<\/p>\n\n\n\n<figure class=\"wp-block-embed aligncenter is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Getting Started With Plaky\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/IYQCi9y-lNU?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"translation-block\">Oh, and did I mention that you can get all 3 of these tools for the amount you spend on your regular project management software?&nbsp;<\/p>\n\n\n\n<p class=\"translation-block\">\n<div class=\"banner banner-dark clockify-gradient-bundle\">\n    <div class=\"banner-text lg:pr-[6rem]\">\n        <h2 class=\"translation-block text-2xl !mb-4\">3 tools = 1 price<\/h2>\n        <p class=\"translation-block !text-sm\">Instead of paying for each tool separately, get CAKE.com Bundle and save 53% on subscriptions.<\/p>\n\n        <div class=\"banner-buttons d-flex space-x-4 translation-block\">\n            <a class=\"rounded-md px-6 py-2 bg-white\" href=\"https:\/\/cake.com\/bundle\" target=\"_blank\">Sign up<\/a>\n\n                            <a class=\"button-2\" href=\"https:\/\/clockify.me\/apps\" target=\"_blank\">Download<\/a>\n                    <\/div>\n    <\/div>\n\n    <div class=\"banner-image banner-image-bottom \">\n        <picture>\n            <source srcset=\"https:\/\/clockify.me\/learn\/wp-content\/themes\/cake-learn\/src\/images\/clockify\/banners\/bundle@2x.png 2x\" alt=\"Illustration\"  media=\"(min-width: 1022px)\" \/>\n            <img decoding=\"async\" src=\"https:\/\/clockify.me\/learn\/wp-content\/themes\/cake-learn\/src\/images\/clockify\/banners\/bundle.png\"  alt=\"Illustration\" \/>\n        <\/picture>\n    <\/div>\n<\/div>\n    <\/p>\n\n\n\n<h2 id=\"conclusion-disclaimer\" class=\"wp-block-heading translation-block\">Conclusion\/Disclaimer<\/h2>\n\n\n\n<p class=\"translation-block\">We hope this data privacy laws guide will be helpful. Please pay attention to the links provided, which will lead you to the official government websites and other relevant information.<\/p>\n\n\n\n<p class=\"translation-block\">Please note that this guide was written in December 2024, so any changes in the laws that were included later may not be in this guide.<\/p>\n\n\n\n<p class=\"translation-block\">We strongly advise you to consult with the appropriate institutions or certified representatives before acting on legal matters.<\/p>\n\n\n\n<p class=\"translation-block\">Clockify isn\u2019t responsible for any losses or risks incurred should this guide be used without further guidance from legal or tax advisors.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Learn what states have adopted data privacy laws to protect consumers online in 2025 and stay compliant to avoid potential lawsuits.<\/p>\n","protected":false},"author":29,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[4,5],"tags":[],"class_list":["post-2787","post","type-post","status-publish","format-standard","hentry","category-business-management","category-business-regulations"],"acf":[],"_links":{"self":[{"href":"https:\/\/clockify.me\/learn\/wp-json\/wp\/v2\/posts\/2787","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/clockify.me\/learn\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/clockify.me\/learn\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/clockify.me\/learn\/wp-json\/wp\/v2\/users\/29"}],"replies":[{"embeddable":true,"href":"https:\/\/clockify.me\/learn\/wp-json\/wp\/v2\/comments?post=2787"}],"version-history":[{"count":21,"href":"https:\/\/clockify.me\/learn\/wp-json\/wp\/v2\/posts\/2787\/revisions"}],"predecessor-version":[{"id":5007,"href":"https:\/\/clockify.me\/learn\/wp-json\/wp\/v2\/posts\/2787\/revisions\/5007"}],"wp:attachment":[{"href":"https:\/\/clockify.me\/learn\/wp-json\/wp\/v2\/media?parent=2787"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/clockify.me\/learn\/wp-json\/wp\/v2\/categories?post=2787"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/clockify.me\/learn\/wp-json\/wp\/v2\/tags?post=2787"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}