
US state-privacy patchwork
Fingerprinting under the US state laws.
13 US state laws regulate browser and device fingerprinting today, starting with CCPA and the Virginia template that 12 other states have copied with variations. This page compares them at a glance for multi-state controllers. Not legal advice.
How to read this page
California's CCPA stands apart, with broader sale-and-share opt-out, a private right of action for breaches, and the most active regulator. Every other state in the live set follows the Virginia template with named variations: cure-period sunset timing, Universal Opt-Out Mechanism recognition, DPA requirement, profiling opt-out scope, and consumer-count thresholds. Click any state row for the full per-state page.
The 13 live state laws
Sorted by effective date| State | Acronym | Effective | Max penalty | How the law treats fingerprinting | Updated |
|---|---|---|---|---|---|
| California, United States | CCPA | 1 January 2020 (CCPA), CPRA amendments effective 1 January 2023 | $2,500 per violation; $7,500 per intentional violation or violation involving a minor's data | Notice + the ability to opt out of 'sale' and 'sharing' of fingerprints; opt-in only for sensitive data and minors under 16. | 2026-06-06 |
| Oregon, USA | OCPA | 1 July 2024 (commercial controllers); 1 July 2025 (qualifying nonprofits) | Up to $7,500 per intentional violation (ORS 646A.589) | Opt-out regime for targeted advertising, sale, and profiling; opt-in required for sensitive-data inferences; UOOM recognition mandatory from 1 January 2026 and cure period sunsets on the same date. | 2026-06-06 |
| Virginia, USA | VCDPA | 1 January 2023 | Up to $7,500 per violation in civil penalties | No general consent requirement; opt-out rights for targeted advertising, sale, and profiling apply, and a Data Protection Assessment is mandatory before deploying fingerprinting for any of those purposes. | 2026-06-06 |
| Colorado, USA | CPA | 1 July 2023 | Up to $20,000 per violation in civil penalties (C.R.S. §6-1-112) | Universal Opt-Out Mechanism (GPC) is mandatory; controllers must honour it for targeted advertising and sale, and a Data Protection Assessment under 4 CCR 904-3 is required before deploying fingerprinting for those purposes. | 2026-06-06 |
| Connecticut, USA | CTDPA | 1 July 2023 | Civil penalties via the Connecticut Unfair Trade Practices Act (Conn. Gen. Stat. §42-110b): $5,000 base per wilful violation, plus restitution and injunctive relief | Opt-out via UOOM is mandatory; controllers must respect GPC for targeted advertising and sale; Data Protection Assessments are required; the 2023 consumer-health-data amendment expanded the opt-in regime. | 2026-06-06 |
| Utah, USA | UCPA | 31 December 2023 | Up to $7,500 per violation in civil penalties (Utah Code §13-61-402) | Opt-out rights for targeted advertising and sale apply, but UCPA has no Data Protection Assessment requirement, no profiling opt-out, no Universal Opt-Out Mechanism recognition, and a $25M revenue gate that excludes most mid-size controllers. | 2026-06-06 |
| Texas, USA | TDPSA | 1 July 2024 | Up to $7,500 per violation in civil penalties (Tex. Bus. & Com. Code §541.155) | No numeric consumer-count threshold; opt-out rights for targeted advertising, sale, and profiling apply once you're not a SBA-defined small business, with an explicit notice-at-collection rule on top of the standard VCDPA template. | 2026-06-06 |
| Montana, USA | MTCDPA | 1 October 2024 | Up to $7,500 per violation (Mont. Code Ann. §30-14-142) | Opt-out regime; Global Privacy Control is mandatory from 1 January 2025; DPA required before deploying fingerprinting for targeted advertising, sale, or covered profiling; cure period open until 1 April 2026. | 2026-06-06 |
| Delaware, USA | DPDPA | 1 January 2025 | Up to $10,000 per intentional violation (Del. Code §12D-111) | Opt-out regime with the lowest US-state applicability thresholds, mandatory UOOM recognition from 1 January 2026, and first-strike enforcement now that the cure period sunset at year-end 2025. | 2026-06-06 |
| Iowa, USA | ICDPA | 1 January 2025 | Up to $7,500 per violation in civil penalties | Opt-out rights for targeted advertising and sale only; no DPA requirement, no UOOM recognition, no profiling opt-out, and a 90-day cure period that is not scheduled to sunset. | 2026-06-06 |
| New Hampshire, USA | NHPA | 1 January 2025 | Up to $10,000 per violation under RSA 358-A, plus restitution, injunctive relief, and AG costs | Opt-out regime for targeted advertising, sale, and profiling; Universal Opt-Out Mechanism mandatory from 1 January 2026; enforcement runs through the NH Consumer Protection Act adding restitution and injunctive relief on top of per-violation penalties. | 2026-06-06 |
| New Jersey, USA | NJDPA | 15 January 2025 | Up to $10,000 per first offense, $20,000 per subsequent offense (NJ Consumer Fraud Act) | Opt-out regime for most purposes, but opt-in required for sensitive data and for any processing of known children up to age 17 - the broadest minor-protection rule of any US state law. | 2026-06-06 |
| Tennessee, USA | TIPA | 1 July 2025 | Up to $7,500 per violation; treble damages (up to $22,500) for wilful conduct under Tenn. Code Ann. §47-18-3214 | Opt-out regime for targeted advertising, sale, and covered profiling; unique NIST safe harbor provides an affirmative defense; treble damages apply for wilful violations, producing the highest effective per-violation cap in the Virginia cluster. | 2026-06-06 |
Tooling
One fingerprinting deployment, all 13 states.
Benny the Doorman is fingerprinting that defers to your CMP, supports the Universal Opt-Out Mechanism, and ships with per-state DPA addenda. If your deployment is VCDPA-compliant, it carries through most of the cluster with documented overlays.
