Orange textured background

US state-privacy patchwork

Fingerprinting under the US state laws.

13 US state laws regulate browser and device fingerprinting today, starting with CCPA and the Virginia template that 12 other states have copied with variations. This page compares them at a glance for multi-state controllers. Not legal advice.

How to read this page

California's CCPA stands apart, with broader sale-and-share opt-out, a private right of action for breaches, and the most active regulator. Every other state in the live set follows the Virginia template with named variations: cure-period sunset timing, Universal Opt-Out Mechanism recognition, DPA requirement, profiling opt-out scope, and consumer-count thresholds. Click any state row for the full per-state page.

The 13 live state laws

Sorted by effective date
StateAcronymEffectiveMax penaltyHow the law treats fingerprintingUpdated
California, United StatesCCPA1 January 2020 (CCPA), CPRA amendments effective 1 January 2023$2,500 per violation; $7,500 per intentional violation or violation involving a minor's dataNotice + the ability to opt out of 'sale' and 'sharing' of fingerprints; opt-in only for sensitive data and minors under 16.2026-06-06
Oregon, USAOCPA1 July 2024 (commercial controllers); 1 July 2025 (qualifying nonprofits)Up to $7,500 per intentional violation (ORS 646A.589)Opt-out regime for targeted advertising, sale, and profiling; opt-in required for sensitive-data inferences; UOOM recognition mandatory from 1 January 2026 and cure period sunsets on the same date.2026-06-06
Virginia, USAVCDPA1 January 2023Up to $7,500 per violation in civil penaltiesNo general consent requirement; opt-out rights for targeted advertising, sale, and profiling apply, and a Data Protection Assessment is mandatory before deploying fingerprinting for any of those purposes.2026-06-06
Colorado, USACPA1 July 2023Up to $20,000 per violation in civil penalties (C.R.S. §6-1-112)Universal Opt-Out Mechanism (GPC) is mandatory; controllers must honour it for targeted advertising and sale, and a Data Protection Assessment under 4 CCR 904-3 is required before deploying fingerprinting for those purposes.2026-06-06
Connecticut, USACTDPA1 July 2023Civil penalties via the Connecticut Unfair Trade Practices Act (Conn. Gen. Stat. §42-110b): $5,000 base per wilful violation, plus restitution and injunctive reliefOpt-out via UOOM is mandatory; controllers must respect GPC for targeted advertising and sale; Data Protection Assessments are required; the 2023 consumer-health-data amendment expanded the opt-in regime.2026-06-06
Utah, USAUCPA31 December 2023Up to $7,500 per violation in civil penalties (Utah Code §13-61-402)Opt-out rights for targeted advertising and sale apply, but UCPA has no Data Protection Assessment requirement, no profiling opt-out, no Universal Opt-Out Mechanism recognition, and a $25M revenue gate that excludes most mid-size controllers.2026-06-06
Texas, USATDPSA1 July 2024Up to $7,500 per violation in civil penalties (Tex. Bus. & Com. Code §541.155)No numeric consumer-count threshold; opt-out rights for targeted advertising, sale, and profiling apply once you're not a SBA-defined small business, with an explicit notice-at-collection rule on top of the standard VCDPA template.2026-06-06
Montana, USAMTCDPA1 October 2024Up to $7,500 per violation (Mont. Code Ann. §30-14-142)Opt-out regime; Global Privacy Control is mandatory from 1 January 2025; DPA required before deploying fingerprinting for targeted advertising, sale, or covered profiling; cure period open until 1 April 2026.2026-06-06
Delaware, USADPDPA1 January 2025Up to $10,000 per intentional violation (Del. Code §12D-111)Opt-out regime with the lowest US-state applicability thresholds, mandatory UOOM recognition from 1 January 2026, and first-strike enforcement now that the cure period sunset at year-end 2025.2026-06-06
Iowa, USAICDPA1 January 2025Up to $7,500 per violation in civil penaltiesOpt-out rights for targeted advertising and sale only; no DPA requirement, no UOOM recognition, no profiling opt-out, and a 90-day cure period that is not scheduled to sunset.2026-06-06
New Hampshire, USANHPA1 January 2025Up to $10,000 per violation under RSA 358-A, plus restitution, injunctive relief, and AG costsOpt-out regime for targeted advertising, sale, and profiling; Universal Opt-Out Mechanism mandatory from 1 January 2026; enforcement runs through the NH Consumer Protection Act adding restitution and injunctive relief on top of per-violation penalties.2026-06-06
New Jersey, USANJDPA15 January 2025Up to $10,000 per first offense, $20,000 per subsequent offense (NJ Consumer Fraud Act)Opt-out regime for most purposes, but opt-in required for sensitive data and for any processing of known children up to age 17 - the broadest minor-protection rule of any US state law.2026-06-06
Tennessee, USATIPA1 July 2025Up to $7,500 per violation; treble damages (up to $22,500) for wilful conduct under Tenn. Code Ann. §47-18-3214Opt-out regime for targeted advertising, sale, and covered profiling; unique NIST safe harbor provides an affirmative defense; treble damages apply for wilful violations, producing the highest effective per-violation cap in the Virginia cluster.2026-06-06

Tooling

One fingerprinting deployment, all 13 states.

Benny the Doorman is fingerprinting that defers to your CMP, supports the Universal Opt-Out Mechanism, and ships with per-state DPA addenda. If your deployment is VCDPA-compliant, it carries through most of the cluster with documented overlays.