Privacy & Security 9 min readBy Mehadi ShawonPublished

New US Data Privacy Laws in 2026: What Counts as "Sensitive Data" Now?

Indiana, Kentucky and Rhode Island privacy laws took effect January 1, 2026, and California now treats neural data as sensitive. Here is what changed, in plain English.

Glowing golden shield over a stack of legal documents with faint US state map outlines, representing new 2026 US state data privacy laws
Quick answer

New US Data Privacy Laws in 2026: What Counts as "Sensitive Data" Now?

On January 1, 2026, comprehensive consumer privacy laws took effect in Indiana, Kentucky and Rhode Island, giving residents rights to access, correct, delete and opt out of the sale of their data. California's updated CCPA regulations also took effect that day, and its definition of sensitive personal information now includes neural data.

On January 1, 2026, three more US states switched on comprehensive consumer privacy laws: Indiana, Kentucky and Rhode Island. Residents of those states now have the familiar set of rights — see your data, fix it, delete it, and tell companies to stop selling it or using it for targeted ads. The same day, California's updated CCPA regulations took effect, and California's definition of "sensitive personal information" now stretches all the way to neural data collected from brain-signal devices.

This is general information, not legal advice. Consult a privacy attorney for compliance guidance specific to your business.

The New State Laws Taking Effect

All three laws follow what lawyers call the Virginia model: the same core rights, enforced by the state Attorney General, with no ability for individuals to sue directly. The differences are in who they apply to and how forgiving they are.

Indiana Consumer Data Protection Act

Signed in May 2023 and effective January 1, 2026, Indiana's law applies to businesses that, in a calendar year, handle the personal data of at least 100,000 Indiana consumers — or at least 25,000 Indiana consumers if more than half of the company's gross revenue comes from selling personal data. It gives Indiana residents rights to access, correct, delete and port their data, plus opt-outs for targeted advertising, data sales and certain kinds of profiling. Businesses get a 30-day window to fix a problem after being notified before the Attorney General can pursue penalties of up to $7,500 per violation.

Kentucky Consumer Data Protection Act

Kentucky's law (HB 15, signed April 2024, later adjusted by 2025's HB 473) uses the same thresholds as Indiana: 100,000 Kentucky consumers, or 25,000 plus at least half of gross revenue from selling personal data. Rights are the same list, enforcement sits with the Kentucky Attorney General, there is a 30-day cure period, and the maximum penalty is $7,500 per violation.

Rhode Island Data Transparency and Privacy Protection Act

Rhode Island's law, signed June 29, 2024, is the strictest of the three in two ways. Its thresholds are lower — 35,000 Rhode Island customers, or more than 10,000 customers if over 20% of gross revenue comes from selling personal data — so smaller companies are pulled in. And it has no general right to cure, meaning there is no guaranteed grace period to fix a violation before enforcement. It is enforced by the Rhode Island Attorney General under the state's unfair trade practices framework, with penalties reaching up to $10,000 per violation.

For context, more than 20 states now have a comprehensive privacy law on the books, and more take effect through 2027 — Alabama's new law, for example, was enacted in 2026 but does not take effect until May 1, 2027.

Ad Space
Glowing icons for fingerprint, brainwave, location, heartbeat and DNA around a locked golden data vault, representing expanded sensitive data categories

What Now Counts as "Sensitive Data"

"Sensitive data" is a separate, higher tier. In most of these states, a company generally needs your consent before processing it at all, and mishandling it is treated more seriously than mishandling your email address.

  • Racial or ethnic origin.
  • Religious beliefs.
  • A mental or physical health condition or diagnosis (in the Virginia-model states, a diagnosis made by a health care provider).
  • Sexual orientation and sex life.
  • Citizenship or immigration status.
  • Genetic data — anything derived from analysing your biological samples.
  • Biometric data used to identify you uniquely: fingerprints, face and iris scans, voiceprints, and in California even keystroke and gait patterns.
  • Precise geolocation — typically defined as data that pins you inside a radius of about 1,750 feet.
  • Personal data of a child known to be under 13.

California goes further still. Its statutory list (Civil Code § 1798.140) also names Social Security, driver's licence and passport numbers, account login credentials, union membership, and the contents of your mail, email and text messages — and since January 1, 2025 it includes neural data.

Why neural data matters

SB 1223 defines neural data as information generated by measuring the activity of a consumer's central or peripheral nervous system that is not inferred from non-neural information. In plain terms: readings taken directly from your brain or nerves. Consumer EEG headbands, focus-tracking earbuds, sleep and meditation wearables and emerging brain-computer interfaces all produce it, and California now treats it with the same care as your fingerprints or your medical diagnosis. It is the clearest signal yet that privacy law is racing to catch up with body-sensing hardware.

What This Means for You as a Consumer

If you live in Indiana, Kentucky or Rhode Island, you can now send a request to companies that hold your data and expect an answer, usually within 45 days. Your rights cover:

  • Access — get confirmation that a company processes your data, and a copy of it.
  • Correction — have inaccurate personal data fixed.
  • Deletion — have your personal data erased, subject to legal exceptions like fraud prevention and record-keeping obligations.
  • Portability — receive your data in a usable, transferable format.
  • Opt out — of targeted advertising, the sale of your personal data, and profiling used for decisions with legal or similarly significant effects.
  • Consent for sensitive data — companies generally need your permission before processing the categories listed above.

Two practical notes. First, you cannot sue under these laws; if a business stonewalls you, the route is a complaint to your state Attorney General. Second, look for a "Do Not Sell or Share My Personal Information" or "Your Privacy Choices" link in site footers — that is usually the fastest way to exercise the opt-out. If you want a broader cleanup rather than one request at a time, our internet privacy guide walks through reducing what gets collected in the first place, and how to protect your online privacy in 2026 covers the day-to-day habits.

What This Means for Businesses and Site Owners

Most independent sites and small businesses sit under the thresholds — and remember that the counts are per state, so 100,000 means 100,000 Indiana residents, not 100,000 visitors overall. But if you run ads, use analytics that share identifiers, or sell or trade data, it is worth checking honestly rather than assuming. The practical basics look like this:

  1. Write down what you collect, why, where it goes, and how long you keep it. Almost every other requirement depends on knowing this.
  2. Publish a privacy notice that names the categories you collect, your purposes, who you share with, and how someone submits a request.
  3. Give a working opt-out for targeted advertising and data sales, and honour recognised opt-out signals such as Global Privacy Control.
  4. Ask for opt-in consent before processing sensitive data, and do not collect it at all if you do not need it.
  5. Have a request process: a monitored email or form, an identity check that is not itself invasive, and a 45-day response habit.
  6. Sign data processing terms with vendors that touch your users' data — the obligation follows the data.
  7. Collect less. Data you never gathered cannot be requested, breached, or fined over.

Rhode Island deserves specific attention because of its lower thresholds and lack of a cure period: a mistake there can go straight to enforcement. Again — this is general information, not legal advice, and a privacy attorney should review anything you rely on for compliance.

Tighten your own privacy footprint first.

Read the Internet Privacy Guide

The pattern across 2026 is clear enough: more states, lower thresholds, and a widening definition of what counts as sensitive. Whichever side of the request you are on, the safest assumption is that the data you collect today will be regulated more tightly tomorrow.

Frequently Asked Questions

Which new US privacy laws took effect in 2026?+

Three comprehensive state consumer privacy laws took effect on January 1, 2026: the Indiana Consumer Data Protection Act, the Kentucky Consumer Data Protection Act, and the Rhode Island Data Transparency and Privacy Protection Act. California's updated CCPA regulations covering risk assessments, cybersecurity audits and automated decision-making technology also became effective the same day.

What counts as sensitive data in 2026?+

Across these state laws, sensitive data typically means racial or ethnic origin, religious beliefs, a health diagnosis, sexual orientation, citizenship or immigration status, genetic data, biometric data used to identify you, precise geolocation, and the personal data of a known child. California's list is broader and, since January 1, 2025, also includes neural data.

Is neural data now legally protected?+

In California, yes. SB 1223 (Chapter 887, signed September 28, 2024, effective January 1, 2025) added neural data to the CCPA's definition of sensitive personal information, defining it as information generated by measuring the activity of a consumer's central or peripheral nervous system that is not inferred from non-neural information. That covers data from consumer brain-computer and neurotech devices.

Do these laws let me sue a company that misuses my data?+

Generally no. Indiana, Kentucky and Rhode Island all reserve enforcement to the state Attorney General and do not create a private right of action. You exercise your rights by submitting a request to the business, and you complain to your Attorney General if the business ignores it.

Does my small website have to comply with these laws?+

Most small sites fall below the thresholds. Indiana and Kentucky generally apply once you handle personal data of 100,000 residents of that state in a year, or 25,000 plus more than half your gross revenue from selling personal data. Rhode Island is lower at 35,000 customers, or 10,000 customers plus more than 20% of gross revenue from selling personal data. Thresholds are counted per state, and this is general information rather than legal advice.

Ad Space

Try the related free tools

Hands-on utilities from DigiMetrics Hub that go with this guide.

All tools