US State Privacy Laws — DSAR Requirements by State

Compare DSAR response deadlines, consumer rights, identity verification, and penalties across all 19 US state privacy laws.

Last updated: 2026-03-01

The United States has no single federal privacy law. Instead, individual states have passed their own comprehensive privacy laws — 19 and counting. Each creates data subject access request obligations with different deadlines, consumer rights, and penalties.

If your business processes personal data of US residents, you may need to comply with multiple state laws simultaneously. This page gives you the quick-reference comparison. Click any state for the full DSAR requirements breakdown.

Disclaimer: This content is for informational purposes only and does not constitute legal advice. Consult a qualified attorney for guidance specific to your business.

DSAR Response Deadlines and Penalties

JurisdictionLawResponse DeadlineExtensionMax PenaltyCure Period
CaliforniaCCPA/CPRA45 days+45 days$7,500/violationNone
VirginiaVCDPA45 days+45 days$7,500/violation30 days
ColoradoCPA45 days+45 days$20,000/violationExpired
ConnecticutCTDPA45 days+45 days$5,000/violationExpired
UtahUCPA45 days+45 days$7,500/violation30 days (permanent)
OregonOCPA45 days+45 days$7,500/violationExpired
TexasTDPSA45 days+45 days$7,500/violationExpired
MontanaMTCDPA45 days+45 days$7,500/violation60 days (exp. Apr 2026)
DelawareDPDPA45 days+45 days$10,000/violationExpired
IowaICDPA90 daysNone$7,500/violation90 days (permanent)
NebraskaNDPA30 days+30 days$7,500/violation30 days (permanent)
New HampshireNHPA45 days+45 days$10,000/violationExpired
New JerseyNJDPA45 days+45 days$10K/$20K per violation30 days (exp. Jul 2026)
TennesseeTIPA45 days+45 days$7,500/violation60 days (exp. Jul 2027)
MinnesotaMCDPA45 days+45 days$7,500/violation30 days (exp. Jul 2026)
MarylandMODPA45 days+15 days only$10K/$25K per violation60 days (exp. Apr 2027)
IndianaINCDPA45 days+45 days$7,500/violation30 days (exp. Jan 2028)
KentuckyKCDPA45 days+45 days$7,500/violation30 days
Rhode IslandRIDTPPA45 days+45 days$10,000/violation30 days (exp. Jan 2027)

For comparison with international privacy laws, see our GDPR guide (30-day deadline, EUR 20M or 4% revenue penalty) and UK GDPR guide (30-day deadline, GBP 17.5M or 4% revenue penalty).

Key Patterns

Response deadlines: Most US states give you 45 days. Iowa is the most generous at 90 days. Nebraska is the tightest US state at 30 days.

Extensions: Most states allow a 45-day extension. Maryland only allows 15 days. Iowa allows no extension at all.

Cure periods: Many states had cure periods that have now expired. Utah, Iowa, and Nebraska have permanent cure periods. California has no cure period.

Private right of action: Only California (for data breaches) allows individuals to sue directly. All other US state laws are enforced only by the Attorney General.

Consumer Rights by State

Not every state grants the same DSAR rights. Most grant access, deletion, and portability. Correction and profiling opt-out vary.

RightMost US StatesIowa/Utah
AccessYesYes
CorrectionYesNo
DeletionYesYes
PortabilityYesYes
Opt out of saleYesYes
Opt out of targeted advertisingYesYes
Opt out of profilingYesNo
Appeal denied requestsYesNo

Identity Verification

Every state requires identity verification before fulfilling a DSAR, but none prescribe a specific method. See our DSAR identity verification guide for practical approaches.

Related Guides