Skip to main content

On-demand webinar coming soon...

On-demand webinar coming soon...

Simplify US privacy law compliance

The United States privacy landscape is rapidly evolving, with more than a dozen states now enforcing comprehensive data privacy laws — many of which came into effect in 2025. Each law introduces different obligations around consumer rights, risk assessments, and opt-out mechanisms.

We’re here to simplify your compliance journey across all US jurisdictions and support you in protecting personal data while building trust with your customers. 

Government building with American flag outside

How OneTrust helps you operationalize US consumer privacy rights


Explore consumer rights and business requirements across enacted US privacy laws and see how our Privacy Automation can help.  

Automate access, correction, deletion, and portability requests

Fulfilling consumer requests all starts with having an appropriate intake method for consumers to make requests to access, correct, delete, or transmit their data. Explore the chart below to see which enacted US privacy laws require these rights. 


 
 Right to accessRight to correctRight to deleteRight to portability
California: CPRAXXXX
ColoradoXXXX
ConnecticutXXXX
DelawareXXXX
FloridaXXXX
IndianaXXXX
IowaX XX
KentuckyXXXX
MarylandXXXX
MinnesotaXXXX
MontanaXXXX
NebraskaXXXX
New HampshireXXXX
New JerseyXXXX
OregonXXXX
Rhode IslandXXXX
TennesseeXXXX
TexasXXXX
UtahX XX
VirginiaXXXX

Note: Cells with an 'X' indicate the corresponding law requires that particular right.

Processing personal rights requests can be time consuming for the business. Data Subject Request (DSR) Automation expedites the entire DSAR fulfillment process by:

  • Streamlining intake across your different touchpoints
  • Automating identity verification
  • Automating the redaction and response process
  • Automating the data discovery and deletion process


Honor opt-out requests and limit data use automatically 

Organizations that utilize the advertising ecosystem will have to pay particular attention to opt-out requests. Explore the chart below to see which enacted US privacy laws specify opt-out, right to use, and disclosure requirements. 


 
 Right to opt-outRight to limit use and disclosure
 SaleProfilingTargeted advertisingSensitive personal information 
California: CPRAXXXX
ColoradoXXXOpt-in required
ConnecticutXXXOpt-in required
DelawareXXXOpt-in required
FloridaXXXOpt-in required
IndianaXXXOpt-in required
IowaX X 
KentuckyXXXOpt-in required
MarylandXXXOpt-in required
MinnesotaXXXOpt-in required
MontanaXXXOpt-in required
NebraskaXXXOpt-in required
New HampshireXXXOpt-in required
New JerseyXXXOpt-in required
Rhode IslandXXXOpt-in required
OregonXXXOpt-in required
TennesseeXXXOpt-in required
TexasXXXOpt-in required
UtahX X 
VirginiaXXXOpt-in required

Note: Cells with an 'X' indicate the corresponding law requires that particular right.

Our Consent and Preferences solution operationalizes opt-outs by:

  • Automatically identifying third-party trackers
  • Delivering a consumer-first preference center where preferences can be changed at any time and applied across all touchpoints
  • Enforcing opt-outs and processing limitations based on preferences and opt-out requirements
  • Respect user preferences and support Global Privacy Controls (GPC)

Ensure transparency with dynamic policy management 


All enacted US privacy laws require notice and transparency be provided to those covered under the law. OneTrust Privacy Operations helps by enabling you to centrally manage policies across digital assets.  

  • Schedule automatic website and mobile app scans to trigger policy updates 
  • Use pre-built templates and sync the latest updates across your web and app properties 


Streamline risk assessments across states


All enacted US privacy laws (aside from Iowa and Utah) require formal risk assessments of privacy and/or security projects or procedures. OneTrust Privacy Operations integrates with your existing business processes, giving you real-time comprehensive risk discovery and actionable insights for risk mitigation.

In addition to streamlining the assessment process, our Privacy Automation solution also equips you with the tools to improve your privacy program. Privacy awareness training, third-party risk management, and privacy and security incident management are available to unify and optimize your data privacy program activities.



FAQs

We’re here to help demystify US data privacy regulations. Explore answers to frequently asked questions below.

Currently, unlike Europe’s General Data Protection Regulation (GDPR), there is no single comprehensive US privacy law. The enactment of the California Consumer Privacy Act of 2018 (CCPA) on January 1, 2020 marked the first comprehensive US state privacy law aimed to protect consumers’ personal data security. Since then, many states have followed suit with their own privacy legislation. 

More than 17 states have enacted comprehensive privacy laws. Other states have introduced bills for committee evaluation. In addition to comprehensive state-level laws, the US also has privacy laws that govern specific types of data. For example, HIPAA is a federal law that protects sensitive patient health information and COPPA protects children’s online privacy. 

 

Explore the DataGuidance US privacy tracker to learn more about emerging and new laws.

The EU’s General Data Protection Regulation (GDPR) focuses on a person’s right to privacy whereas much of the US legislation focuses on the data security safeguards of consumers and employees. Regardless of whether your business is in the EU or US, or other countries with data privacy laws, if data is processed across borders, relevant privacy and data protection laws apply. 

 

OneTrust Privacy Operations can simplify how you comply with the various requirements of privacy regulations. 


Ready to get started?

Request a free demo today to see how OneTrust can help you unlock the power of responsible data use.