Personal data now moves through daily life, from shopping apps and streaming services to connected cars, loyalty programs, financial platforms and smart devices. Yet the rules governing that information are not set by one simple nationwide privacy law. In 2026, the data privacy rights consumers can exercise still depend heavily on where they live, which company holds the information and what type of data is involved.
That patchwork can feel frustrating, but millions of Americans now have tools to control how businesses collect, use, share and sell personal information. Understanding common rights across state privacy laws is the first step toward using them effectively.
Why Your Privacy Rights Depend on Your State
The United States relies on federal sector-specific rules and state-level consumer data protection laws. Federal laws may protect credit reports, certain health records, financial data and children’s information. Comprehensive state privacy laws are broader, but their definitions, thresholds, exemptions and enforcement systems differ.
More laws joined the patchwork in 2026. Comprehensive statutes in Indiana, Kentucky and Rhode Island became effective at the start of the year, adding to laws already operating in states such as California, Colorado, Oregon, Texas and Virginia.
Coverage is not automatic. A law may apply only to businesses that process data from a certain number of residents or earn revenue from selling it. Some laws also exclude employee records, nonprofits, small businesses or information governed by another legal framework.
The Core Data Privacy Rights Consumers Commonly Have
The right to know and access
Many state privacy laws let you ask whether a covered business is processing your personal data and request access to it. The company may need to disclose categories of information, specific data, processing purposes and types of third parties receiving it. This can show whether its practices match its privacy notice.
The right to correct inaccurate information
If a business holds inaccurate personal data, you may have the right to request a correction. This can matter when an error affects an account, customer profile, eligibility decision or other significant outcome. The exact scope varies according to the nature of the information and how it is used.
The right to request deletion
A data deletion request asks a business to remove personal information covered by the applicable law. Some states focus on data collected directly from you, while others provide broader deletion rights.
Deletion is not absolute. A company may keep information needed to complete a transaction, detect fraud, maintain security, comply with another law or handle legal claims. A valid exception should not become an excuse to ignore the entire request. The company should explain what it can and cannot delete.
The right to data portability
Portability rights generally allow you to receive a copy of certain personal data in a usable format. This may help you review your records or transfer information to another service. The law may limit request frequency or exclude information that would reveal trade secrets or create security risks.
The right to opt out
Opt-out rights are a major part of modern consumer data protection. Depending on your state, you may be able to stop a business from selling personal data, using it for targeted advertising or processing it for certain profiling that produces legal or similarly significant effects.
The meaning of “sale” is not identical everywhere. Some states focus on exchanges for money, while others cover certain transfers for other valuable consideration. This is why a company’s “Do Not Sell or Share” link, privacy choices page or state-specific notice deserves attention.
How CCPA Rights Differ from Many Other State Laws
California’s privacy framework remains one of the country’s most detailed. CCPA rights include the right to know, delete, correct and opt out of the sale or sharing of personal information. Californians may also have the right to limit certain uses and disclosures of sensitive personal information and the right not to receive discriminatory treatment for exercising privacy rights.
California recognizes user-enabled opt-out preference signals such as Global Privacy Control for covered online activity. Colorado similarly requires covered businesses to honor a recognized universal opt-out mechanism for sales and targeted advertising. These tools can communicate a privacy preference across websites, although consumers may need to activate the setting separately on each browser or device.
How to Submit a Privacy Request
Start with the company’s privacy policy. Look for headings such as “Your Privacy Rights,” “State Privacy Notice,” “Data Request” or “Do Not Sell or Share My Personal Information.” Covered businesses generally explain the available request methods, which may include an online form, email address, telephone number or account setting.
State clearly which right you are exercising. Include enough information for the company to identify your account, but avoid sending unnecessary sensitive data through an unsecured channel. A basic request might identify your name, account email, state of residence and the data you want accessed, corrected or deleted.
Keep copies of the request, confirmation number and response. Many laws give businesses around 45 days to respond, although deadlines, extensions and verification rules vary. If the company denies the request, some state laws require an internal appeal process. Follow the appeal instructions and explain why you believe the decision was incorrect.
What to Do When a Business Does Not Respond
Confirm that you used the method listed in the privacy notice and completed any reasonable identity-verification step. Then send a concise follow-up referencing the original submission date.
If the matter remains unresolved, review your state attorney general’s complaint process or the relevant privacy regulator’s website. Many comprehensive statutes are enforced primarily by government agencies rather than through individual lawsuits for every violation. The Federal Trade Commission may also act when a company makes deceptive privacy promises or engages in unfair data practices.
FAQ
Do all US consumers have the same data privacy rights?
No. Rights vary by state, business, type of data and legal exemption. Comprehensive rights such as access, deletion and targeted-advertising opt-outs are often created by state privacy laws.
Can a company refuse my data deletion request?
Yes, in limited circumstances. A business may retain information required for fraud prevention, security, transactions, legal compliance or other permitted purposes. It should still process any part of the request that is not covered by an exception.
How long does a company have to answer?
Many state laws use a 45-day response period and allow an extension when reasonably necessary, but the exact rule depends on the applicable statute. Check the company’s privacy notice and your state regulator’s guidance.
Can I use Global Privacy Control instead of contacting every website?
In some states and for certain opt-out rights, yes. California and Colorado recognize qualifying browser-based preference signals, but the setting may not cover every privacy right or every business.
Taking Control of Your Personal Data
The expanding mix of state privacy laws gives consumers more control than they had only a few years ago, but using those protections still requires attention. Read privacy notices, activate available opt-out tools, submit focused requests and keep records of your communications. Your rights may differ across state lines, yet the central principle is increasingly clear: personal data should not be collected and used without meaningful transparency, accountability and consumer choice.