US Privacy
US Privacy
US privacy compliance is the process of meeting federal, state, and industry privacy laws governing the collection, processing, storage, sharing, and deletion of personal information. Today, US privacy compliance is no longer a one-state exercise. The California Consumer Privacy Act (CCPA), amended by the California Privacy Rights Act (CPRA), introduced a broad consumer-rights framework. Since then, additional enacted state privacy laws have expanded requirements for access, correction, deletion, portability, opt-outs, sensitive data, risk assessments, appeals, and transparency.
OneTrust helps organizations operationalize those requirements through configurable workflows for privacy rights, consent and preferences, policy management, privacy operations, and risk assessments. With one AI-Ready Governance Platform™, teams can apply a consistent privacy operating model across jurisdictions while adapting execution to each state’s requirements.
CCPA and CPRA give California consumers rights to access, correct, delete, and obtain portable copies of personal information. It also includes opt-out rights tied to sale, sharing, profiling, and targeted advertising.
Privacy Automation helps organizations operationalize those requirements by enabling teams to:
OneTrust also supports preference centers and opt-out mechanisms for the sale or sharing of personal information, including Global Privacy Control where applicable.
The Colorado Privacy Act (CPA) and Connecticut Data Privacy Act (CTDPA) include rights to opt out of sale, profiling, and targeted advertising. Both also require opt-in treatment for sensitive personal information, as reflected in the state comparison below.
Consent & Preferences helps organizations:
The Virginia Consumer Data Protection Act (VCDPA) requires covered organizations to operationalize consumer rights and assess specified processing activities. Privacy teams need a repeatable way to identify processing, assign owners, evaluate risk, document decisions, and track remediation.
Privacy Automation helps legal, privacy, security, marketing, and data teams coordinate assessments, document evidence, and maintain consistent workflows across the business.
US state privacy laws do not provide identical rights. For example, the comparison below outlines that Iowa does not provide a right to correction. Iowa does. The Iowa and Utah Consumer Privacy Act (UCPA) also fail to provide for the right to opt-out of profiling. While neither Iowa law or UCPA requires consumer opt-in o the use of sensitive personal information, the UCPA does provide the right to opt-out of the processing of sensitive personal information.
OneTrust enables teams to configure jurisdiction-specific workflows instead of applying one state’s rules indiscriminately. Organizations can tailor request forms, response paths, preference options, notices, and assessment triggers according to the law, the consumer, and the processing activity involved.
All enacted US privacy laws included in this comparison require notice and transparency for covered individuals. Static policies become harder to maintain as processing changes and additional laws are enacted or amended.
Privacy Automation helps teams centralize notice management by enabling them to:
All enacted US privacy laws included in this page’s comparison, aside from Iowa and Utah, require formal risk assessments of privacy and or security projects or procedures.
Privacy Automation helps organizations standardize assessment intake, apply jurisdiction-specific logic, assign remediation, and retain evidence. Privacy awareness training, third-party risk management, and incident response can also be coordinated to unify privacy program activity.
Access, correction, deletion, and portability rights
Sale, profiling, targeted-advertising, and sensitive-data requirements
Consent & Preferences helps operationalize these requirements by identifying third-party trackers, capturing preferences, supporting Global Privacy Control signals, and enforcing opt-outs and processing limitations across connected touchpoints.
The GDPR, California’s CCPA as amended by the CPRA, and Brazil’s LGPD all regulate personal data, but they are not interchangeable. They differ in scope, legal structure, terminology, individual rights, and operational obligations.
A shared privacy operating model can reduce duplicate work, but notices, legal-basis records, request workflows, consent controls, retention rules, assessments, and enforcement processes should still be configured for the laws that apply.
Learn more about GDPR compliance, CCPA compliance, and Privacy Automation.
US privacy compliance is an ongoing operating process, not a one-time project. OneTrust provides a centralized system for monitoring applicability, maintaining data and processing inventories, updating policies, fulfilling consumer rights, enforcing preferences, assessing risk, and documenting compliance activity.
Teams can use OneTrust to:
For additional information about enacted and emerging requirements, explore the DataGuidance US privacy laws comparison.
The GDPR and LGPD are comprehensive data protection laws built around legal bases for processing, accountability principles, and data-subject rights. California’s CCPA, as amended by the CPRA, focuses heavily on transparency, consumer requests, sale-or-sharing opt-outs, targeted advertising, and controls involving sensitive personal information.
These laws also differ in terminology, applicability tests, regulator structure, and operational requirements. Organizations should use a common governance foundation while configuring notices, rights workflows, consent or opt-out controls, assessments, and records for each applicable law.
As of July 2026, there is no single comprehensive US privacy law equivalent to the GDPR.
The enactment of the CCPA on January 1, 2020, marked the first comprehensive US state privacy law. Since then, many states have enacted their own privacy legislation.
The US also has federal and state laws governing specific sectors or data types. For example, HIPAA protects sensitive patient health information, and COPPA protects children’s online privacy.
This page compares 20 enacted comprehensive US state privacy laws across California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia.
Applicability depends on the law, your business model, and the personal-data processing activities in scope. Organizations may also need to account for federal, sector-specific, local, and international requirements.
Organizations need a repeatable regulatory-change process that accurately connects legal monitoring and policies to operational controls. That process should include:
Monitoring new laws, amendments, regulations, and enforcement activity
Determining which jurisdictions and processing activities are in scope
Mapping new requirements to existing controls
Identifying gaps in notices, rights workflows, consent, opt-outs, contracts, and assessments
Assigning owners and remediation deadlines
Testing updated workflows before requirements apply
Retaining evidence of reviews, decisions, and completed changes
OneTrust helps centralize these activities so privacy teams can update shared controls while preserving jurisdiction-specific workflows.
The GDPR focuses on lawful processing, accountability, and data-subject rights. Much US privacy legislation focuses on consumer rights, transparency, opt-outs, and data-security safeguards, with requirements varying by state and sector.
Regardless of whether a business is located in the EU, the US, or elsewhere, relevant privacy and data protection laws may still apply when personal data is processed across borders.
The OneTrust AI-Ready Governance Platform™ brings together privacy rights automation, consent and preference management, data discovery, policy management, assessments, and reporting. Organizations can use shared controls across states while configuring request workflows, notices, opt-outs, and assessments according to applicable requirements.
Operationalize US Privacy Compliance with OneTrust
OneTrust helps organizations turn changing state privacy requirements into scalable workflows for consumer rights, consent and preferences, transparency, risk assessments, data governance, and compliance reporting.