New State-Based Data Privacy Legislation Reshapes Compliance Obligations
June 16, 2026
Oklahoma and Alabama have joined the growing roster of jurisdictions that are imposing comprehensive data protection obligations on businesses, as Perkins Coie writes in a recent article. They have become the 20th and 21st states to enact these types of laws, creating new compliance obligations for businesses.
Meanwhile, Utah, Kentucky, and Virginia have amended existing laws to address emerging data categories. The Secure Data Act, a federal proposal for a unified national standard, has also entered the picture.
Since California launched the modern era of state privacy regulation, businesses have faced varying obligations across dozens of jurisdictions. Each new state law introduces its own thresholds, definitions, consumer rights, and enforcement mechanisms.
Companies that have already built compliance infrastructure around earlier state frameworks must now determine if the newest additions alter their obligations. The issue is often whether key definitions, such as what constitutes a data sale, differ meaningfully.
Oklahoma’s law takes effect January 1, 2027, and Alabama’s on May 1, 2027. Alabama’s lower applicability thresholds extend coverage to a broader set of businesses. Some small businesses are exempt.
Both states narrowed the definition of data “sale,” potentially reducing opt-out obligations in certain transfer scenarios. Neither state creates a private right of action, and both offer an indefinite cure period before enforcement escalates.
Developments in other states include Utah’s extension of privacy protections to motor vehicle manufacturers, and its revised app store law. Kentucky added consent requirements for smart TV content-recognition data. Virginia banned the outright sale of precise geolocation information.
Federally, the Secure Data Act proposes a preemptive national framework enforced by the Federal Trade Commission and state attorneys general.
Managing legal operations across multiple legal systems is increasingly central to privacy compliance as state frameworks multiply, with divergent definitions and thresholds. Cross-border data transfer considerations intensify when state-specific restrictions on geolocation and biometric data apply differently depending on jurisdiction.
Critical intelligence for general counsel
Stay on top of the latest news, solutions and best practices by reading Daily Updates from Today's General Counsel.
Daily Updates
Sign up for our free daily newsletter for the latest news and business legal developments.