Skip to main content

On-demand webinar coming soon...

US Privacy

Operationalize US State Privacy Compliance at Scale 

US privacy compliance is the process of meeting federal, state, and industry privacy laws governing the collection, processing, storage, sharing, and deletion of personal information. Today, US privacy compliance is no longer a one-state exercise. The California Consumer Privacy Act (CCPA), amended by the California Privacy Rights Act (CPRA), introduced a broad consumer-rights framework. Since then, additional enacted state privacy laws have expanded requirements for access, correction, deletion, portability, opt-outs, sensitive data, risk assessments, appeals, and transparency.

OneTrust helps organizations operationalize those requirements through configurable workflows for privacy rights, consent and preferences, policy management, privacy operations, and risk assessments. With one AI-Ready Governance Platform™, teams can apply a consistent privacy operating model across jurisdictions while adapting execution to each state’s requirements.

Diagram illustrating a US Privacy Program within a continuous governance framework. The central module highlights connected controls, continuous monitoring, and audit readiness. Surrounding panels show map requirements, monitor risk and report, share specific execution, operationalize rights and preferences, and conformity by jurisdiction. The design uses a clean white background with green accents and minimal icons for a modern, technical look. Diagram illustrating a US Privacy Program within a continuous governance framework. The central module highlights connected controls, continuous monitoring, and audit readiness. Surrounding panels show map requirements, monitor risk and report, share specific execution, operationalize rights and preferences, and conformity by jurisdiction. The design uses a clean white background with green accents and minimal icons for a modern, technical look.

Turn State Privacy Requirements Into Repeatable Workflows

Automate CCPA and CPRA consumer rights fulfillment in California 

CCPA and CPRA give California consumers rights to access, correct, delete, and obtain portable copies of personal information. It also includes opt-out rights tied to sale, sharing, profiling, and targeted advertising.

Privacy Automation helps organizations operationalize those requirements by enabling teams to:

  • Provide configurable intake forms across digital touchpoints Automate identity verification
  • Find relevant personal information across connected systems
  • Coordinate access, correction, deletion, and portability workflows
  • Automate redaction, review, approval, and response processes
  • Maintain records of requests, decisions, and fulfillment activity

OneTrust also supports preference centers and opt-out mechanisms for the sale or sharing of personal information, including Global Privacy Control where applicable.

User interface screen shows an incident management dashboard with a prominent "Add New Incident" form. The form includes fields for incident type, description, date occurred, date discovered, and number of individuals, along with a blue submit button. On the left, a donut chart labeled "Incidents by Type" visualizes incident distribution. Below it, a card labeled "Open Incidents" displays the number 13 incidents. The layout is clean and minimal, emphasizing data entry and monitoring of incidents.

Apply opt-out and sensitive-data controls across Colorado, Connecticut, and other enacted state laws 

The Colorado Privacy Act (CPA) and Connecticut Data Privacy Act (CTDPA) include rights to opt out of sale, profiling, and targeted advertising. Both also require opt-in treatment for sensitive personal information, as reflected in the state comparison below.

Consent & Preferences helps organizations:

  • Identify third-party trackers automatically
  • Deliver a consumer-first preference center where choices can be changed at any time
  • Apply preferences across websites, apps, and other touchpoints
  • Enforce opt-outs and processing limitations based on applicable requirements
  • Respect user preferences and support Global Privacy Control signals
  • Maintain auditable records of consent and preference changes
The image shows a digital interface for managing privacy and cookie consent. A notification from Zentoso highlights that user privacy matters with an option to Accept All. Another panel displays CCPA | CPRA compliance alongside a Manage Consent Preferences section. Toggle switches control Performance Cookies, Functional Cookies, and Targeting Cookies, emphasizing data protection and user choice.

Coordinate Virginia privacy assessments and accountability workflows 

The Virginia Consumer Data Protection Act (VCDPA) requires covered organizations to operationalize consumer rights and assess specified processing activities. Privacy teams need a repeatable way to identify processing, assign owners, evaluate risk, document decisions, and track remediation.

Privacy Automation helps legal, privacy, security, marketing, and data teams coordinate assessments, document evidence, and maintain consistent workflows across the business.

The image shows a digital dashboard interface with multiple risk summary cards. One vertical card displays the text "Aggregated Risk" with a red flag icon and the number 8. Two horizontal cards show risk items with IDs 3515 and 1920, including fields such as Name, Type, and Criticality labeled High and Low, each with colored flag icons. The layout suggests a data risk management or compliance monitoring system with a clean, minimal design.

Configure Iowa and Utah requirements without overextending workflows 

US state privacy laws do not provide identical rights. For example, the comparison below outlines that Iowa does not provide a right to correction. Iowa does. The Iowa and Utah Consumer Privacy Act (UCPA) also fail to provide for the right to opt-out of profiling. While neither Iowa law or UCPA requires consumer opt-in o the use of sensitive personal information, the UCPA does provide the right to opt-out of the processing of sensitive personal information. 

OneTrust enables teams to configure jurisdiction-specific workflows instead of applying one state’s rules indiscriminately. Organizations can tailor request forms, response paths, preference options, notices, and assessment triggers according to the law, the consumer, and the processing activity involved.

Digital interface screenshot shows the Onetrust Copilot assistant panel on a light background. The panel greets the user with the text "Hi, I'm your Onetrust Copilot" and offers help summarizing information. Example questions about privacy laws, third-party cookies, and data transfer mechanisms are displayed as selectable prompts. A text input field at the bottom invites the user to "Ask a question..." alongside a blue arrow button for submission.

Manage transparency obligations with dynamic privacy notices 

All enacted US privacy laws included in this comparison require notice and transparency for covered individuals. Static policies become harder to maintain as processing changes and additional laws are enacted or amended.

Privacy Automation helps teams centralize notice management by enabling them to:

  • Schedule website and mobile-app scans that can trigger policy reviews
  • Use pre-built templates to support notice creation and maintenance
  • Synchronize approved updates across web and app properties
  • Connect notices to data inventories, processing activities, and owners
  • Maintain review and approval histories for audit readiness
The image displays a minimal analytics dashboard with request metrics and a line chart. One card shows received requests with the number 7 and the word Requests. Another card indicates average days to complete with the number 10 and the word Days. To the right, a chart titled Requests by Date plots two lines over dates from the 14th to the 19th, labeled OCT/2021. The design uses a clean, light background and simple blue and green lines for data visualization.

Streamline privacy risk assessments across enacted state laws 

All enacted US privacy laws included in this page’s comparison, aside from Iowa and Utah, require formal risk assessments of privacy and or security projects or procedures.

Privacy Automation helps organizations standardize assessment intake, apply jurisdiction-specific logic, assign remediation, and retain evidence. Privacy awareness training, third-party risk management, and incident response can also be coordinated to unify privacy program activity.

Digital interface screenshot shows an AI tools panel for finishing faster with assessment questions. The upper section offers options to scan documents and scan related assessments, each with checkboxes and brief descriptions. The lower section displays a suggested response card about metadata manipulation, including references and an accept button. The overall layout uses light backgrounds with green and gray accents and icon buttons for audio and information.

Compare Consumer Rights Across Enacted US State Privacy Laws

Access, correction, deletion, and portability rights

OneTrust privacy comparison chart
Comparison of access, correction, deletion, and portability rights across enacted US state privacy laws.
State privacy law Right to access Right to correct Right to delete Right to portability
California: CPRAXXXX
ColoradoXXXX
ConnecticutXXXX
DelawareXXXX
FloridaXXXX
IndianaXXXX
IowaXXX
KentuckyXXXX
MarylandXXXX
MinnesotaXXXX
MontanaXXXX
NebraskaXXXX
New HampshireXXXX
New JerseyXXXX
OregonXXXX
Rhode IslandXXXX
TennesseeXXXX
TexasXXXX
UtahXXXX
VirginiaXXXX

How to read this table: An X indicates that the corresponding law requires that particular right. A dash indicates that the right is not marked as required in this comparison.

On-demand webinar coming soon...

Sale, profiling, targeted-advertising, and sensitive-data requirements

OneTrust privacy comparison chart
Comparison of sale, profiling, targeted-advertising, and sensitive-data requirements across enacted US state privacy laws.
State privacy law Opt out of sale Opt out of profiling Opt out of targeted advertising Limit use and disclosure of sensitive personal information
California: CPRAXXXX
ColoradoXXXOpt-in required
ConnecticutXXXOpt-in required
DelawareXXXOpt-in required
FloridaXXXOpt-in required
IndianaXXXOpt-in required
IowaXX
KentuckyXXXOpt-in required
MarylandXXXOpt-in required
MinnesotaXXXOpt-in required
MontanaXXXOpt-in required
NebraskaXXXOpt-in required
New HampshireXXXOpt-in required
New JerseyXXXOpt-in required
OregonXXXOpt-in required
Rhode IslandXXXOpt-in required
TennesseeXXXOpt-in required
TexasXXXOpt-in required
UtahXX
VirginiaXXXOpt-in required

How to read this table: An X indicates that the corresponding law requires that particular right. “Opt-in required” reflects the treatment shown for sensitive personal information. A dash indicates that the requirement is not marked in this comparison.

On-demand webinar coming soon...

Consent & Preferences helps operationalize these requirements by identifying third-party trackers, capturing preferences, supporting Global Privacy Control signals, and enforcing opt-outs and processing limitations across connected touchpoints.

GDPR Vs. CCPA and CCPA Vs. LGPD: Key Differences 

The GDPR, California’s CCPA as amended by the CPRA, and Brazil’s LGPD all regulate personal data, but they are not interchangeable. They differ in scope, legal structure, terminology, individual rights, and operational obligations. 

GDPR vs. CCPA and CCPA vs. LGPD: Key Differences
Comparison of key differences among the GDPR, California CCPA and CPRA, and Brazil LGPD.
Comparison area EU General Data Protection Regulation (GDPR) California CCPA and CPRA Brazil Lei Geral de Proteção de Dados (LGPD)
Primary jurisdictionEuropean Union and European Economic Area, with extraterritorial application in specified circumstancesCalifornia, with requirements applying to qualifying businesses and related entities in the statutory frameworkBrazil, with extraterritorial application in specified circumstances
Core regulatory modelRequires a lawful basis for processing and emphasizes data protection principles, accountability, and individual rightsEmphasizes notice, consumer rights, opt-outs, and requirements involving the sale or sharing of personal informationRequires a legal basis for processing and emphasizes data protection principles, accountability, and data-subject rights
People protectedData subjects whose personal data falls within the GDPR’s scopeCalifornia consumers whose personal information falls within the law’s scopeData subjects whose personal data falls within the LGPD’s scope
Access and transparencyProvides rights involving access and information about processingProvides rights involving knowledge of and access to personal informationProvides rights involving confirmation of processing and access to personal data
CorrectionProvides a right to rectificationProvides a right to correct inaccurate personal informationProvides a right to correct incomplete, inaccurate, or outdated data
DeletionProvides a right to erasure subject to conditions and exceptionsProvides a right to deletion subject to exceptionsProvides rights involving deletion, anonymization, or blocking in specified circumstances
PortabilityProvides a right to data portability when statutory conditions applyProvides portability as part of the consumer access frameworkProvides a portability right subject to applicable requirements
Sale, sharing, and advertisingDoes not use California’s sale-or-sharing opt-out model; processing must have a lawful basis and may be subject to objection or consent requirementsProvides rights to opt out of sale or sharing and includes requirements relevant to targeted advertisingDoes not use California’s sale-or-sharing opt-out model; processing must have an appropriate legal basis and satisfy transparency requirements
Sensitive dataApplies additional protections to special categories of personal dataProvides a right to limit certain uses and disclosures of sensitive personal informationApplies specific requirements to sensitive personal data
Risk and impact assessmentsData protection impact assessments are required for processing likely to result in high riskRisk-based assessment and accountability requirements apply under the California privacy frameworkData protection impact documentation may be required in applicable circumstances
Primary regulator or enforcement authorityNational data protection authorities within the EU and EEACalifornia Privacy Protection Agency (CPPA) or CalPrivacy, and the California Attorney GeneralAutoridade Nacional de Proteção de Dados (ANPD)
Operational priorityEstablish lawful processing, accountability, privacy by design, data-subject rights, security, and governanceMaintain notices, consumer request workflows, opt-outs, sensitive-information controls, vendor governance, and evidenceEstablish legal bases, transparency, data-subject rights, security, governance, and accountability

How to read this table: The comparison summarizes the key differences described in the source copy. A common privacy operating model can reduce duplicate work, but notices, legal-basis records, request workflows, consent controls, retention rules, assessments, and enforcement processes should be configured for the laws that apply.

On-demand webinar coming soon...

A shared privacy operating model can reduce duplicate work, but notices, legal-basis records, request workflows, consent controls, retention rules, assessments, and enforcement processes should still be configured for the laws that apply. 

Learn more about GDPR compliance, CCPA compliance, and Privacy Automation. 

Build a Privacy Program That Adapts As Laws Change 

US privacy compliance is an ongoing operating process, not a one-time project. OneTrust provides a centralized system for monitoring applicability, maintaining data and processing inventories, updating policies, fulfilling consumer rights, enforcing preferences, assessing risk, and documenting compliance activity.

Teams can use OneTrust to:

  • Map laws and requirements to reusable controls
  • Assign ownership for regulatory and operational updates
  • Configure workflows by jurisdiction
  • Connect consumer requests to data discovery and fulfillment
  • Update notices and preference experiences
  • Trigger assessments when processing changes
  • Track remediation and retain audit-ready evidence
  • Report on privacy program performance across states

For additional information about enacted and emerging requirements, explore the DataGuidance US privacy laws comparison.

You May Also Like

Frequently Asked Questions

The GDPR and LGPD are comprehensive data protection laws built around legal bases for processing, accountability principles, and data-subject rights. California’s CCPA, as amended by the CPRA, focuses heavily on transparency, consumer requests, sale-or-sharing opt-outs, targeted advertising, and controls involving sensitive personal information.

These laws also differ in terminology, applicability tests, regulator structure, and operational requirements. Organizations should use a common governance foundation while configuring notices, rights workflows, consent or opt-out controls, assessments, and records for each applicable law.

As of July 2026, there is no single comprehensive US privacy law equivalent to the GDPR.

The enactment of the CCPA on January 1, 2020, marked the first comprehensive US state privacy law. Since then, many states have enacted their own privacy legislation.

The US also has federal and state laws governing specific sectors or data types. For example, HIPAA protects sensitive patient health information, and COPPA protects children’s online privacy.

This page compares 20 enacted comprehensive US state privacy laws across California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia.

Applicability depends on the law, your business model, and the personal-data processing activities in scope. Organizations may also need to account for federal, sector-specific, local, and international requirements.

Organizations need a repeatable regulatory-change process that accurately connects legal monitoring and policies to operational controls. That process should include:
 

  • Monitoring new laws, amendments, regulations, and enforcement activity

  • Determining which jurisdictions and processing activities are in scope

  • Mapping new requirements to existing controls

  • Identifying gaps in notices, rights workflows, consent, opt-outs, contracts, and assessments

  • Assigning owners and remediation deadlines

  • Testing updated workflows before requirements apply

  • Retaining evidence of reviews, decisions, and completed changes
     

OneTrust helps centralize these activities so privacy teams can update shared controls while preserving jurisdiction-specific workflows.

The GDPR focuses on lawful processing, accountability, and data-subject rights. Much US privacy legislation focuses on consumer rights, transparency, opt-outs, and data-security safeguards, with requirements varying by state and sector.

Regardless of whether a business is located in the EU, the US, or elsewhere, relevant privacy and data protection laws may still apply when personal data is processed across borders.

The OneTrust AI-Ready Governance Platform™ brings together privacy rights automation, consent and preference management, data discovery, policy management, assessments, and reporting. Organizations can use shared controls across states while configuring request workflows, notices, opt-outs, and assessments according to applicable requirements.

Operationalize US Privacy Compliance with OneTrust

OneTrust helps organizations turn changing state privacy requirements into scalable workflows for consumer rights, consent and preferences, transparency, risk assessments, data governance, and compliance reporting.