Short answer

Four states passed comprehensive privacy laws in 2026: Oklahoma and Louisiana (in force 1 January 2027), Alabama (1 May 2027) and Vermont (1 January 2028). Most small websites fall under none of them, because each law only applies above a size threshold. Louisiana adds two exact sentences to privacy notices if you sell sensitive or biometric data, and Vermont makes you say whether personal data trains large language models.

4New state privacy laws signed between March and June 2026
25,000Consumers: Alabama's threshold, one of the lowest in the country
$15,000Alabama's maximum civil penalty per violation

The first question is not what these laws say. It is whether they apply to you at all. Every one of them has a threshold, and a typical blog or small online store sits below it. The table below gives you the answer in thirty seconds. We read each enacted bill to build it.

The four laws at a glance

StateIn forceApplies if youCure periodMaximum penalty
Oklahoma (SB 546)1 January 2027Control or process data of 100,000 or more consumers, or 25,000 or more and earn over 50% of gross revenue from selling personal data30 days after written notice$7,500 per violation
Louisiana (SB 386, Act 502)1 January 2027Have annual gross revenue over $25 million, or buy, receive, sell or share the data of 75,000 or more consumers, households or devices, or earn 50% or more of revenue from selling personal data30 days, only from January to July 2027Treated as an unfair trade practice under state law
Alabama (HB 351)1 May 2027Control or process data of more than 25,000 consumers (payment only data excluded), or earn more than 25% of gross revenue from selling personal data45 days after notice$15,000 per violation
Vermont (Act 145)1 January 2028Process data of 35,000 or more consumers, sensitive data of 3,000 or more, or sell data of 3,000 or moreEnforced only by the Attorney GeneralUnder the Vermont Consumer Protection Act

All four are enforced by the state Attorney General. None gives consumers a private right to sue under the privacy law itself.

Oklahoma: the high threshold law

Oklahoma's Consumer Data Privacy Act follows the Virginia model closely. With a 100,000 consumer threshold, it mostly reaches larger companies. If you do cross it, you need the usual privacy notice (categories of data, purposes, third parties, how to exercise rights), a way to opt out of targeted advertising and sale, consent before processing sensitive data, and data protection assessments for high risk processing. The Attorney General must give you 30 days written notice to fix a problem before suing, and penalties reach $7,500 for each violation.

Louisiana: two sentences you may have to copy word for word

Louisiana is the only one of the four with a revenue test. Any business with more than $25 million in annual revenue that does business in the state is covered, however few Louisiana residents it serves.

Louisiana also has the most concrete notice rule. If you sell sensitive personal data, your privacy notice must carry this exact line:

NOTICE: We may sell your sensitive personal data.

And if you sell biometric data, this one:

NOTICE: We may sell your biometric personal data.

Texas uses almost the same wording, so one line can serve both states. Violations count as unfair and deceptive trade practices. Between 1 January and 31 July 2027 the Attorney General has to give 30 days written notice first, and a business that fixes the problem and says so in writing avoids an investigation. After July 2027 that grace period ends.

Alabama: low threshold, big penalty

Alabama is the one small and mid sized sellers should watch. The law covers anyone processing the data of more than 25,000 Alabama consumers, and data used only to complete a payment does not count toward that number. It also covers any business earning more than 25% of its gross revenue from selling personal data, whatever its size.

The penalty is up to $15,000 per violation, about double the common figure in other states. There is a permanent 45 day cure period, so a business that fixes an issue after notice and confirms it in writing cannot be sued for it.

Vermont: the strictest of the four

Vermont's Data Privacy and Online Surveillance Act takes effect last, on 1 January 2028, and asks the most. Its thresholds are low (35,000 consumers, or sensitive data of just 3,000). It limits collection to what is reasonably necessary and proportionate, requires consent before processing or selling sensitive data, and requires data protection and profiling assessments. Your privacy notice will need to say whether personal data is collected, used or sold to train large language models. Consumer health data rules apply more broadly than the main thresholds.

What to change in your privacy policy

  1. Check the thresholds first. Count consumers per state from your analytics or customer list. If you are below every threshold, you have nothing new to do for these four laws.
  2. Add the four states to your rights section if you are covered: access, correction, deletion, portability and opt out of targeted advertising and sale.
  3. Copy Louisiana's notice lines exactly if you sell sensitive or biometric data.
  4. Say whether data trains AI models. Vermont will require it from 2028, and it is already good practice.
  5. Offer an appeal process for refused requests, and answer requests within 45 days.

If you need a fresh policy, the free privacy policy generator writes one around your answers, and the CCPA privacy policy generator covers California. For the laws that took effect earlier, see new privacy laws 2026.

Frequently asked questions

Oklahoma (SB 546), Alabama (HB 351), Louisiana (SB 386, Act 502) and Vermont (Act 145). They take effect between 1 January 2027 and 1 January 2028.

Only if you process the data of more than 25,000 Alabama consumers, not counting data used only to complete a payment, or earn more than 25% of your revenue from selling personal data.

If you sell sensitive personal data you must post: NOTICE: We may sell your sensitive personal data. If you sell biometric data you must post: NOTICE: We may sell your biometric personal data.

On 1 January 2028. It covers businesses processing the data of 35,000 or more consumers, or the sensitive data of 3,000 or more, or selling the data of 3,000 or more.

No. All four are enforced only by the state Attorney General, and none creates a private right of action.

Up to $7,500 per violation, after a 30 day written notice that gives the business a chance to fix the problem.

The bottom line

Start with the thresholds. Most small sites sit below all four laws. If you are covered, add the four states to your rights section, copy Louisiana's notice lines if you sell sensitive or biometric data, and get ready to say whether personal data trains AI models before Vermont's law starts in 2028.

Update your privacy policy free

Tell us where your customers are and what your site does. We write the policy around it.

Open the generator

Sources

  1. Oklahoma SB 546 (enrolled), Oklahoma Legislature
  2. Oklahoma House: Major data privacy bill signed into law (23 March 2026)
  3. Alabama HB 351, Alabama Legislature
  4. Louisiana SB 386 (enrolled), Louisiana State Legislature
  5. Vermont Act 145 (S.71) act summary, Vermont General Assembly
  6. Mayer Brown: Vermont enacts comprehensive consumer privacy law
Cite this article

Shanti, A. (2026). 4 New State Privacy Laws of 2026: Oklahoma, Alabama, Louisiana and Vermont. FreeTOS.org. https://freetos.org/blog/new-state-privacy-laws-2026-oklahoma-alabama-louisiana-vermont

This article explains the rules in plain language. It is not legal advice. Last reviewed 27 September 2026.