California gets most of the attention when it comes to data privacy law. But as of mid-2026, at least seven states have enacted laws that specifically require data brokers to register with a state agency, and more than 20 states have broad consumer privacy laws that give you opt-out rights over the sale of your personal data. This article surveys what exists outside California so you can take advantage of protections you may not know about.
This article is for informational purposes only and does not constitute legal advice. Consult an attorney for guidance specific to your situation.
States with Data Broker Registration Laws
A data broker registration law requires companies that buy and sell personal data to register with a state agency, pay a fee, and disclose information about their practices. Some of these states maintain searchable public registries, meaning you can look up exactly which companies are trading in personal information.
Vermont: The Pioneer (2018)
Vermont was the first state in the country to require data broker registration. Enacted in 2018, the Vermont Data Broker Act (9 V.S.A. Section 2446) requires data brokers to register annually with the Secretary of State by January 31 and pay a $100 fee. The state maintains a searchable public registry at the Secretary of State’s website, where you can look up registered brokers and find information about their opt-out procedures. As of 2026, roughly 283 data brokers are listed. Vermont’s registry revealed the true scale of the data broker industry and directly inspired other states to follow.
Texas: Registry with Attorney General Enforcement (2023)
Texas Governor Greg Abbott signed SB 2105 into law on June 18, 2023, creating a data broker registration requirement administered by the Secretary of State. Data brokers must register before conducting business in Texas and pay a $300 annual fee. The state maintains a searchable central registry on the Secretary of State’s website. The registry includes contact information, security breach history, and categories of data each broker collects. Non-compliance carries penalties of $100 per day, up to $10,000 annually. The Attorney General handles enforcement of violations.
Oregon: Financial Regulator Oversight (2023)
Oregon’s HB 2052, signed by Governor Tina Kotek on July 27, 2023, requires data brokers to register with the Division of Financial Regulation before collecting, selling, or licensing personal data in Oregon. Registration has been required since January 1, 2024. The annual renewal fee is $600. Oregon’s registry is publicly searchable through the Division’s website, where consumers can look up registered brokers and find opt-out information. Non-compliance penalties run $500 per day, up to $10,000 annually. One notable detail: Oregon requires a registered agent in the state and an entity number from the Secretary of State to register.
Connecticut: The Newest Registry State (2026)
On May 27, 2026, Governor Ned Lamont signed Public Act No. 26-64, making Connecticut the fifth state to require data broker registration. Data brokers must register with the Department of Consumer Protection by January 1, 2027, and pay a $2,500 annual fee. The law also includes a centralized deletion mechanism, similar to California’s Delete Act, scheduled to go live by July 1, 2028. This would let Connecticut residents submit a single request to have all registered data brokers delete their data. The law also bans the sale of precise geolocation data, effective October 1, 2026.
New Jersey: Broadest Scope, Highest Fees (2026)
New Jersey’s A.5328, signed on June 30, 2026, stands out for two reasons. First, its scope extends beyond traditional data brokers to cover “data collectors,” meaning companies that have a direct relationship with consumers but sell their data to brokers. Second, its fees are the steepest in the nation, ranging from $5,000 to $1.5 million annually depending on the volume of consumer data sold. The public registry is expected to launch around spring 2027, with the first registration period running from April 1 through June 30, 2027. The law also bans the sale of sensitive data entirely and imposes penalties of up to $50,000 per record for violations.
States with General Consumer Privacy Laws (No Dedicated Registry)
Several states have enacted comprehensive consumer privacy laws that include opt-out rights over data sales and targeted advertising, even though they do not require data brokers to register with a state agency. These laws still give you meaningful tools to protect your personal information.
Virginia (VCDPA, effective January 2023)
Virginia’s Consumer Data Protection Act gives residents the right to access, correct, delete, and obtain a copy of their personal data. You can opt out of the sale of your data, targeted advertising, and certain automated profiling. Virginia uses an opt-out model, meaning you need to proactively request that companies stop selling your data. One gap: Virginia does not require companies to honor Global Privacy Control (GPC) browser signals, so you need to submit opt-out requests directly. The Attorney General enforces the law, with penalties of up to $7,500 per violation.
Colorado (CPA, effective July 2023)
The Colorado Privacy Act is one of the stronger general privacy laws in the country. It requires businesses to honor universal opt-out mechanisms like Global Privacy Control, meaning you can enable a single browser setting to automatically opt out of data sales and targeted advertising across covered websites. Colorado also requires businesses to obtain fresh consent if they want to use previously collected data for a new purpose, such as selling it to a data broker. The right-to-cure window closed on January 1, 2025, so the Attorney General can now pursue enforcement directly for most violations. Penalties can reach $20,000 per violation.
Other States with Opt-Out Rights
As of 2026, more than 20 states have enacted some form of consumer privacy law. While the specifics vary, most follow a similar framework that includes the right to know what data a company has collected, the right to delete it, and the right to opt out of data sales. States in this group include Delaware, Montana, New Hampshire, Iowa, Indiana, Tennessee, and others. Delaware’s Personal Data Privacy Act, which took effect January 1, 2025, is notable for requiring companies to honor opt-out preference signals as of January 1, 2026. Delaware has also been considering a separate data broker registration bill (HB 262), but it has not been enacted as of mid-2026.
How to Use These Laws
- Check the registries. Vermont, Texas, and Oregon all have searchable public databases of registered data brokers. Look up the companies that have your data and use their listed opt-out procedures.
- Enable Global Privacy Control. If you live in Colorado, Connecticut, Delaware, or another state that requires it, enabling GPC in your browser (Firefox, Brave, and DuckDuckGo support it natively) gives you automatic opt-out coverage across many sites.
- Submit deletion requests directly. In states like Virginia where GPC is not required, use the privacy links on company websites to request data deletion and opt out of sales.
- File complaints when companies ignore you. Every state with a privacy law designates an enforcer, usually the Attorney General. If a company does not respond to your request within the required timeframe, file a complaint.
What Is Coming Next
The landscape is expanding quickly. Connecticut’s centralized deletion platform is scheduled for July 2028. New Jersey’s registry is expected to launch in spring 2027. Several other states, including Michigan and Alaska, have data broker bills in various stages of development. Meanwhile, states that already have general privacy laws continue to strengthen them with new amendments covering minors, biometric data, and algorithmic pricing.
The trend is clear: data broker regulation is no longer a California-only story. Wherever you live, it is worth checking what your state offers and using whatever tools are available to you.