Privacy Laws by State: Data Rights, Biometrics & Recording Consent
No federal data law, no federal biometric law, and a recording standard eleven states overrode. American privacy is a patchwork with real holes - here is which one you live in.
On this page
There is no federal law giving Americans general control over their personal data, no federal law protecting their biometrics, and a federal recording standard so permissive that eleven states overrode it. Privacy in the United States is not a national floor with state variations on top. It is a patchwork with genuine holes, and which one you live in determines what rights you actually have.
This guide covers the three areas where state law does most of the work: comprehensive consumer data privacy, biometric protection, and recording-consent rules — the last of which is the one most likely to make an ordinary person accidentally commit a crime.
The short version
- 20 states have a comprehensive consumer data privacy law; 30 have none.
- Only Illinois, Texas, and Washington have standalone biometric statutes.
- Illinois's BIPA is the one companies actually fear — because individuals can sue directly.
- About 11 states require all-party consent to record a conversation; most require only one.
- When a call crosses state lines, follow the stricter rule.
- Comprehensive privacy law
- A state statute granting residents general rights over personal data held by businesses — access, correction, deletion, and opt-out.
- Private right of action
- The ability of an individual to sue a company directly for a violation, rather than relying on a state agency to enforce.
- Biometric data
- Information about unique physical traits — fingerprints, facial geometry, iris scans, voiceprints, hand geometry.
- One-party consent
- Only one participant must agree to a recording, and that participant can be you. The federal standard.
- All-party consent
- Every participant must agree before a conversation may lawfully be recorded.
- Global Privacy Control
- A browser signal that automatically communicates an opt-out request to sites, legally binding in some states.
Consumer data privacy: 20 states, and no federal backstop
Twenty states have enacted a comprehensive consumer data privacy law:
States with a comprehensive data privacy law
20 · June 2026States that have enacted a comprehensive consumer data privacy law, giving residents rights to access, delete, and opt out of the sale of their personal data.
- CACaliforniaCCPA/CPRA, first (2018)
- VAVirginia
- COColorado
- CTConnecticut
- UTUtah
- IAIowa
- INIndiana
- TNTennessee
- MTMontana
- OROregon
- TXTexas
- FLFloridanarrower scope
- DEDelaware
- NJNew Jersey
- NHNew Hampshire
- KYKentucky
- RIRhode Island
- MNMinnesota
- MDMaryland
- NENebraska
California was first (2018); 20 states have enacted one as of 2026. There is still no comprehensive federal privacy law.
California started it with the CCPA in 2018 and for years stood essentially alone. The pace changed sharply from 2023 onward, and more states debate bills every session.
The details differ, but the core rights are broadly consistent:
- Access — see what personal data a business holds about you.
- Correct — fix what is inaccurate.
- Delete — have it erased.
- Opt out — of the sale of your data and of targeted advertising.
- Portability — obtain a copy to take elsewhere.
Why Congress hasn't acted
A national standard has been debated for years without passing, and it is stuck on two specific questions rather than general disagreement. The first is preemption: whether a federal law should override stronger state laws, which California in particular resists. The second is the private right of action: whether individuals could sue companies directly, which industry resists. Until one of those breaks, the patchwork is what you have.
If your state has no law
Thirty states have none, but residents there are not entirely without options:
- Use the opt-outs anyway. Many companies extend privacy controls nationwide rather than maintain fifty versions of their systems — the same spillover effect that pay-transparency laws produce in hiring.
- Turn on Global Privacy Control. It is a browser signal that automatically communicates an opt-out, and it is legally binding in several states.
- Minimize. Limit what you share, review app permissions, and prefer tools that do not collect in the first place. This is the only approach that does not depend on someone else's compliance.
Biometric data: three states, and one that matters
Biometric data means your unique physical traits — fingerprints, facial geometry, iris scans, voiceprints, hand geometry. It is used to unlock phones, clock in at work, and tag photographs.
What makes it categorically different from other personal data is permanence. A leaked password is an inconvenience; you change it. You cannot change your face. A biometric breach is, functionally, permanent.
Three states have a dedicated biometric statute:
States with a dedicated biometric privacy law
3 · June 2026States with a standalone law governing biometric identifiers — fingerprints, face scans, voiceprints, and the like.
Illinois’s BIPA is the strictest — it lets individuals sue. Many of the 20 comprehensive-privacy states also regulate biometric data within those broader laws.
Many of the 20 comprehensive-privacy states also treat biometrics as a protected "sensitive" category within those broader laws, which is meaningful but generally weaker and less specific than a standalone statute.
Why BIPA is the one companies fear
Illinois's Biometric Information Privacy Act, passed in 2008, is watched more closely by corporate counsel than any other state privacy law in the country. Not because its requirements are unusually strict — inform the subject, obtain written consent, disclose the retention period, follow security and deletion rules — but because of one structural feature: it grants a private right of action.
Individuals can sue directly. They do not have to persuade a state attorney general to take an interest.
That single provision has produced class-action settlements reaching nine figures against major technology platforms, and it has made BIPA the de facto national standard for handling biometrics well outside Illinois — because a company operating nationally cannot easily build one biometric pipeline for Illinois and another for everywhere else.
It is the clearest demonstration in American privacy law that enforcement mechanism matters more than statutory text. Several states have biometric provisions on paper; one has consequences.
As facial recognition spreads through retail, policing, and venues, more states are weighing BIPA-style protections. The fight in each of them is over the private right of action, because everyone involved understands that is the part with teeth.
Recording consent: the rule that catches ordinary people
Federal law (18 U.S.C. § 2511) and most states follow one-party consent: you may record a conversation you are part of without telling anyone else. About eleven states require all-party consent — everyone must agree — and in those states getting it wrong can be a criminal offense as well as a civil liability.
The two-party (all-party) consent states
11 · June 2026States where everyone in a conversation must consent before it can legally be recorded — for phone calls and, usually, in-person talks.
- CACalifornia
- DEDelaware
- FLFlorida
- ILIllinois
- MDMaryland
- MAMassachusetts
- MTMontana
- NVNevada
- NHNew Hampshire
- PAPennsylvania
- WAWashington
Connecticut, Michigan, and Oregon have mixed rules; the other 37 states plus DC are one-party consent (only you need to agree).
Connecticut, Michigan, and Oregon sit in between, applying all-party rules to some kinds of communication, often in-person ones, but not to others.
The cross-border problem
This is where people genuinely get caught. If you are in a one-party state and the person you are recording is in an all-party state, which law governs is unsettled — courts have gone both ways, and there is no clean rule to rely on.
The safe practice is simple and costs nothing: if anyone on a call could be in an all-party state, get everyone's consent. "I'm recording this call — is that okay?" at the start resolves it almost everywhere, and a recorded yes is itself the evidence that you complied.
Given how much of American life now happens on calls between people who do not know each other's location, treating all-party consent as the default is the only defensible habit.
How states rank on privacy
Recording rules, data rights, and biometric protection all feed the Fourth Amendment score, alongside surveillance limits and civil-forfeiture protections:
- 1. Maine —9.5/10 (A+).
- 2. New Mexico —9.5/10 (A+).
- 3. Wisconsin —9.0/10 (A+).
- 4. Missouri —8.5/10 (A).
- 5. North Carolina —8.5/10 (A).
- 6. Maryland —8.5/10 (A).
- 7. Florida —6.5/10 (B-).
- 8. Colorado —6.5/10 (B-).
- 9. Connecticut —6.5/10 (B-).
- 10. Oregon —6.5/10 (B-).
See all 50 states ranked on privacy & the Fourth Amendment
Data privacy, biometrics, recording, surveillance, and forfeiture protections — the full ranking with a map.
Frequently asked questions
What is a two-party consent state?
In a two-party (more accurately, all-party) consent state, every person in a conversation must consent before it can legally be recorded. In one-party consent states, only one participant — which can be you — needs to agree.
Which states require all-party consent to record?
About eleven states require all-party consent: California, Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, Nevada, New Hampshire, Pennsylvania, and Washington. Connecticut, Michigan, and Oregon have mixed rules depending on the type of communication.
Is it illegal to record a phone call without consent?
It depends on the state. In one-party consent states (37 plus DC), you can record a call you’re part of without telling the other person. In all-party consent states, recording without everyone’s permission can be a crime.
Which law applies if the call crosses state lines?
It’s a gray area, and courts differ. The safest practice is to follow the stricter rule — if anyone on the call is in an all-party consent state, get everyone’s consent before recording.
How many states have comprehensive data privacy laws?
As of 2026, 20 states have enacted a comprehensive consumer data privacy law, starting with California’s CCPA in 2018. More are passing every legislative session.
What rights do state privacy laws give me?
Most grant residents the right to access the personal data a company holds, to correct or delete it, to opt out of its sale or of targeted advertising, and to data portability — though the specifics and enforcement vary by state.
Is there a federal data privacy law?
No. The US has no comprehensive federal consumer privacy law, which is exactly why a patchwork of state laws has emerged. Your data rights depend heavily on which state you live in.
Does California have the strongest privacy law?
California’s CCPA/CPRA is the oldest and among the most robust, with a dedicated enforcement agency. Several newer state laws are comparable in scope, but California remains the benchmark.
What counts as biometric data?
Biometric data is information about your unique physical characteristics — fingerprints, face scans, iris scans, voiceprints, and hand geometry. Because you can’t change them like a password, their misuse is uniquely hard to undo.
Which states have a dedicated biometric privacy law?
Illinois (BIPA), Texas (CUBI), and Washington have standalone biometric privacy laws. Many of the 20 states with comprehensive consumer privacy laws also regulate biometric data within those broader statutes.
Sources
See all 50 states ranked on privacy & the Fourth Amendment
Data privacy, biometrics, recording, surveillance, and forfeiture protections - the full ranking with a map.
Who represents you?
Enter your ZIP code to see your US House representative, senators, and governor — with their voting records, donors, and integrity scores.
