On January 1, 2026, three new comprehensive state privacy laws took effect — the Indiana Consumer Data Protection Act, the Kentucky Consumer Data Privacy Act, and the Rhode Island Data Transparency and Privacy Protection Act. If you live in any of these states, you now have enforceable rights to see, correct, delete, and stop the sale of your personal data. Here is exactly what changed and how to exercise your new rights.
Why These Laws Matter
Twenty U.S. states now have comprehensive consumer privacy laws in effect. In the absence of a federal privacy law, this state-by-state expansion is the primary way ordinary Americans gain enforceable rights over how companies collect, use, and share their personal information.
The three laws that took effect on January 1, 2026 generally follow the model established by Virginia and Connecticut: they give residents new rights, put obligations on businesses over certain revenue and data thresholds, and are enforced exclusively by each state's Attorney General — there is no private right for consumers to sue directly.
Your New Rights Under Each Law
All three states give consumers a broadly similar package of rights. If you are an Indiana, Kentucky, or Rhode Island resident, you now have the right to:
- Access — confirm whether a business is processing your personal data and get a copy of it
- Correct — request that inaccurate personal data be corrected
- Delete — request deletion of personal data a business holds about you
- Portability — obtain a copy of your data in a portable, readily usable format
- Opt out of sale — direct businesses to stop selling your personal data
- Opt out of targeted advertising — stop the use of your data to serve you targeted ads
- Opt out of profiling — stop automated decisions that produce legal or similarly significant effects
Sensitive data — including biometric identifiers, precise geolocation, health information, immigration status, sexual orientation, and data about children under 13 — requires opt-in consent before collection. Companies must give you a clear notice and let you say yes or no.
How Each State's Law Differs
Indiana Consumer Data Protection Act (INCDPA)
Indiana's law is the most business-friendly of the three and closely mirrors Virginia's Consumer Data Protection Act. Businesses have a 30-day cure period to fix violations before the Attorney General can pursue enforcement. Penalties reach up to $7,500 per violation. The law applies to businesses that either process the personal data of 100,000+ Indiana residents annually, or process 25,000+ residents' data and derive more than 50% of revenue from selling that data.
Kentucky Consumer Data Privacy Act (KCDPA)
Kentucky's law closely tracks Virginia's model. It provides a 30-day cure period and caps penalties at $7,500 per violation. Applicability thresholds match Indiana's: 100,000 residents, or 25,000 residents with 50% revenue from data sales. Kentucky's Attorney General has exclusive enforcement authority.
Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
Rhode Island's law is the strictest of the three. It provides no cure period for violations — a company that violates a Rhode Island resident's rights can face immediate enforcement action. Penalties reach $10,000 per violation. Rhode Island also requires companies to disclose the specific third-party categories with whom they have sold personal data, which is more transparent than most other state laws.
Rhode Island Is the Strongest of the Three
Rhode Island's no-cure enforcement and higher $10,000 per-violation penalty make it the toughest new law of 2026. If you live in Rhode Island, companies are more incentivized to respond to your requests correctly the first time.
How to Exercise Your New Rights
Step 1: Identify Which Companies Have Your Data
Start with the obvious: your bank, credit card issuers, insurance providers, streaming services, e-commerce accounts, and social platforms. Also think about who might have indirectly received your data — advertising networks, data brokers, and marketing analytics firms.
Step 2: Find the Company's Privacy Notice
Under all three new laws, businesses must publish a reasonably accessible privacy notice explaining what data they collect, why, and how you can exercise your rights. Look for a "Privacy Policy" or "Your Privacy Choices" link in the website footer or app settings.
Step 3: Submit Your Request
Most companies now offer a web form or dedicated email address for privacy requests. Include: your full name, the state you reside in, the specific right you are exercising (access / delete / opt out of sale / opt out of targeted advertising), and enough information for them to verify your identity.
Step 4: Track the Response Deadline
Companies generally have 45 days to respond, with an option to extend once for another 45 days if reasonably necessary. If they refuse or ignore your request, keep records.
Step 5: Complain to Your Attorney General
If a company fails to honor a valid request, file a complaint with your state Attorney General's consumer protection division:
- Indiana: Indiana Attorney General Consumer Protection Division
- Kentucky: Kentucky Attorney General Office of Consumer Protection
- Rhode Island: Rhode Island Attorney General Consumer Protection Unit
Data Brokers Are Often Excluded From Your Reach
None of these three laws include a Delete Act-style universal deletion mechanism for data brokers. To remove your info from the 100+ people-search and data-broker sites that expose your home address, phone number, relatives, and property records, you either need to opt out at each site individually or use an automated service.
Skip the manual work
PrivacyOn removes your personal information from 100+ data broker sites and keeps it removed — automatically.
Start your free scan★★★★★ 4.8/5 · Trusted by thousands of families
What These Laws Do NOT Cover
- No private lawsuits. Only the state Attorney General can bring enforcement actions. You cannot sue a company yourself for a privacy violation under these laws.
- Small businesses are exempt. The laws apply only above the resident thresholds, so many small operators are outside their scope.
- Employee data is exempt. Data your employer collects about you in an employment context generally falls outside these laws.
- HIPAA, GLBA, and FCRA data is exempt. Health, financial, and credit reporting data covered by federal laws is not covered again by the state law.
- Data brokers are only partially reached. You can opt out of sale — but only broker-by-broker where you are already listed.
How to Get the Most Protection After These Laws
These state privacy laws are a floor, not a ceiling. To meaningfully reduce your data exposure, combine your legal rights with proactive removal:
- Submit sale opt-outs to the largest data brokers and adtech companies (LiveRamp, Acxiom, Oracle Data Cloud, Epsilon).
- Freeze your credit at Equifax, Experian, and TransUnion — a separate right that predates these laws.
- Remove yourself from people-search sites like Spokeo, BeenVerified, WhitePages, and Radaris. These fall outside most state-law removal rights and require site-by-site opt-out.
- Use dark web monitoring to catch when your exposed data appears in breach dumps.
How PrivacyOn Helps
State privacy laws give you the right to opt out — but exercising those rights company-by-company across 100+ data brokers is a full-time job. PrivacyOn does the work for you:
- Automated data broker removal from 100+ people-search sites
- Continuous monitoring with automatic re-removal when your data reappears
- Dark web monitoring for compromised passwords, SSNs, and financial data
- Family plans covering up to 5 people from $8.33/month
Turn Your New Rights Into Real Protection
The Indiana, Kentucky, and Rhode Island privacy laws are a great start — but the biggest exposure most people have is the 100+ data broker sites that publish your address, phone, and family relationships. Run a free PrivacyOn scan to see where your data appears and start removing it today.
Frequently Asked Questions
Which states have new privacy laws effective in 2026?
Three new comprehensive state privacy laws took effect on January 1, 2026: the Indiana Consumer Data Protection Act, the Kentucky Consumer Data Privacy Act, and the Rhode Island Data Transparency and Privacy Protection Act. Arkansas's Personal Information Protection Act follows on July 1, 2026, bringing the total to 20 states with active comprehensive privacy laws.
Can I sue a company under Indiana's, Kentucky's, or Rhode Island's privacy law?
No. Enforcement is handled exclusively by each state's Attorney General. Consumers cannot bring their own private lawsuits under any of the three 2026 laws. If a company violates your rights, file a complaint with your state's Attorney General consumer protection division.
How long does a business have to respond to a privacy request?
Companies generally have 45 days to respond to consumer requests to access, delete, correct, or opt out. They can extend the deadline once by another 45 days if reasonably necessary, and they must notify you of the extension before the original deadline.
What's the difference between opt-out and opt-in consent under these laws?
For regular personal data, companies can process by default and you must opt out of sale or targeted advertising. For sensitive data — biometrics, precise geolocation, health, sexual orientation, immigration status, and data about children under 13 — companies must get your explicit opt-in consent before collecting or processing that data.
Do these laws cover data brokers and people-search sites?
Partially. You can submit an opt-out-of-sale request to any broker that is subject to the law, but you must do it broker-by-broker. None of the 2026 laws include a universal one-stop deletion mechanism for data brokers. Services like PrivacyOn automate broker-by-broker removal across 100+ sites so you don't have to.
What are the penalties for a company that violates these laws?
Indiana and Kentucky allow up to $7,500 per violation with a 30-day cure period. Rhode Island's law is the strictest — up to $10,000 per violation with no cure period. The state Attorney General decides whether to pursue action based on complaints and its own investigations.