Skip to main content
Home/Blog/New US State Privacy Laws in 2026: Indiana, Kentucky and Rhode Island for Advertisers
Back to Intelligence Hub
regulationUnited StatesRisk Level: medium

New US State Privacy Laws in 2026: Indiana, Kentucky and Rhode Island for Advertisers

Three new state privacy laws took effect on January 1, 2026 — in Indiana, Kentucky and Rhode Island — each giving consumers a right to opt out of targeted advertising.

Updated July 8, 2026· Originally published July 8, 202613 min readAuditSocials Research
TweetShare
Quick Answer

On January 1, 2026, comprehensive consumer privacy laws took effect in three more US states: the Indiana Consumer Data Protection Act, the Kentucky Consumer Data Protection Act and the Rhode Island Data Transparency and Privacy Protection Act. All three follow the model established by earlier state laws and give consumers a set of rights that includes the right to opt out of the processing of their personal data for targeted advertising, the sale of personal data, and profiling — the rights most directly relevant to advertisers. The Indiana and Kentucky laws apply to businesses that control or process the personal data of 100,000 or more state consumers, or 25,000 or more while deriving over 50 percent of gross revenue from the sale of personal data; Rhode Island's thresholds are lower, applying at 35,000 consumers, or 10,000 consumers where more than 20 percent of revenue comes from selling personal data. All three require opt-in consent before processing sensitive data, a category that includes information such as racial or ethnic origin, religious beliefs, health conditions, genetic or biometric data and precise geolocation. Enforcement rests with each state's Attorney General: Indiana and Kentucky provide a 30-day period to cure violations with penalties up to $7,500 per violation, while Rhode Island provides no cure period and penalties up to $10,000 per violation. These laws bring the number of US states with comprehensive privacy laws in effect to twenty, within a larger group of enacted laws, so national advertisers face an expanding patchwork rather than a single federal rule. Map exposure across states with the Legal Compliance Scan, audit audience and consent practices with the AI Compliance Audit, and track new laws on the Policy Change Tracker.

New US State Privacy Laws in 2026: Indiana, Kentucky and Rhode Island for Advertisers

Three New State Privacy Laws in 2026

On January 1, 2026, three more US states brought comprehensive consumer privacy laws into effect: the Indiana Consumer Data Protection Act, the Kentucky Consumer Data Protection Act, and the Rhode Island Data Transparency and Privacy Protection Act. Each follows the general model established by earlier state privacy statutes, and each gives consumers a familiar set of rights — including, most relevantly for advertisers, the right to opt out of having their personal data processed for targeted advertising.

For advertisers and adtech teams, the practical significance is not that any one of these states introduces a novel concept, but that the map of where opt-out obligations apply keeps expanding. Each new state adds a population whose residents can require that their data not be used for targeted advertising, sold, or used for certain profiling, and each adds an enforcement authority. The result is a widening patchwork that national campaigns must accommodate.

"Right to access, correct, delete, obtain a copy, and opt out of data processing used for targeted advertising, the sale of personal data, or profiling.
— Kentucky Consumer Data Protection Act (consumer rights)"

This guide sets out who each law applies to, the rights they grant with a focus on the targeted-advertising opt-out, the sensitive-data consent rules, how each is enforced, and what advertisers should do. For the universal opt-out signal dimension see the US universal opt-out guide, and define terms in the compliance glossary.

Who Each Law Applies To

The first question for any business is whether these laws apply to it, and that turns on each state's applicability thresholds. Indiana and Kentucky share the more common threshold structure, while Rhode Island sets notably lower numbers, which brings smaller businesses into scope.

Applicability Thresholds

StateApplies if a business controls/processes...
Indiana (ICDPA)100,000+ Indiana consumers, or 25,000+ while deriving over 50% of revenue from the sale of personal data
Kentucky (KCDPA)100,000+ Kentucky consumers annually, or 25,000+ while deriving over 50% of gross revenue from the sale of personal data
Rhode Island (RIDTPPA)35,000+ Rhode Island consumers, or 10,000+ while deriving more than 20% of gross revenue from the sale of personal data

The Rhode Island thresholds are the ones most likely to surprise, because the 35,000-consumer floor and the 10,000-consumer-plus-20-percent-revenue alternative are lower than the 100,000/25,000 structure used in Indiana and Kentucky, meaning a business that falls below the threshold in Indiana or Kentucky could still be in scope in Rhode Island. For businesses operating nationally, the correct approach is to test applicability state by state rather than assume a single threshold. Map where a business is in scope across states with the Legal Compliance Scan, and for how these interact with platform data controls see the Meta limited data use guide.

Rights and the Targeted-Advertising Opt-Out

All three laws grant consumers a comparable bundle of rights, and the one that most directly shapes advertising practice is the right to opt out of the processing of personal data for targeted advertising, alongside opt-outs for the sale of personal data and for profiling.

The Common Rights

  • Access: the right to know about and access the personal data a business holds.
  • Correction: the right to correct inaccurate personal data.
  • Deletion: the right to delete personal data.
  • Portability: the right to obtain a copy of personal data in a portable form.
  • Opt-out: the right to opt out of processing for targeted advertising, the sale of personal data, and profiling in furtherance of certain decisions.

For advertisers, the opt-out right is the operational centre of gravity. When a consumer in one of these states exercises the right to opt out of targeted advertising, the business must stop processing that person's personal data for targeted advertising, which requires the systems and signals to recognise and honour the opt-out. Because the same right appears across many state laws, the efficient design is a consistent mechanism to capture and apply opt-outs rather than a separate build per state. The targeted-advertising and sale opt-outs also connect to universal opt-out signals, which several states require businesses to honour. Audit how audience-building and retargeting respect opt-outs with the AI Compliance Audit, and track how these obligations evolve on the Policy Change Tracker.

Sensitive Data, Enforcement and Penalties

Beyond the opt-out rights, the laws impose an opt-in consent requirement for sensitive data and back the whole framework with state enforcement, and here the three states differ in ways worth noting — particularly Rhode Island's approach to cure periods.

Consent and Enforcement

StateSensitive dataEnforcerCure periodPenalty (up to)
IndianaOpt-in consent requiredIndiana Attorney General30 days$7,500 per violation
KentuckyOpt-in consent requiredKentucky Attorney General30 days$7,500 per violation
Rhode IslandPrior consent requiredRhode Island Attorney GeneralNone provided$10,000 per violation

The sensitive-data rules require opt-in consent before processing categories such as racial or ethnic origin, religious beliefs, health conditions, genetic or biometric data, and precise geolocation, which is a higher bar than the opt-out model used for targeted advertising generally. On enforcement, Indiana and Kentucky each provide a 30-day window to cure a violation before penalties of up to $7,500 per violation, while Rhode Island provides no cure period and penalties of up to $10,000 per violation — a difference that makes proactive compliance in Rhode Island particularly important, since there is no built-in opportunity to fix a violation after the fact. All three are enforced by the state Attorney General rather than through a private right of action of general application. For the broader US framework see the US compliance reference, and screen data categories and copy with the Legal Compliance Scan.

What This Means for Advertisers

The addition of three states does not change the fundamental compliance approach, but it does reinforce the direction of travel and the practical need for a scalable opt-out mechanism. The advertiser priorities are consistent with the broader state-privacy landscape.

Advertiser Priorities

  • Test applicability: check the thresholds state by state, remembering Rhode Island's lower numbers can bring a business into scope where Indiana and Kentucky would not.
  • Honour targeted-advertising opt-outs: ensure systems recognise and apply opt-outs for targeted advertising, sale and profiling for residents of these states.
  • Manage sensitive data: obtain opt-in consent before processing sensitive-data categories.
  • Prioritise Rhode Island discipline: because Rhode Island provides no cure period, treat compliance there as requiring proactive rather than reactive correction.

The strategic message is that the expanding patchwork rewards a single, consistent compliance design over per-state improvisation: a mechanism that captures and honours opt-outs, a consent flow for sensitive data, and an applicability test that runs across states. Building to the common denominator of these state laws — the targeted-advertising, sale and profiling opt-outs, plus sensitive-data opt-in — positions an advertiser to absorb each new state with minimal incremental work. Because thresholds, rights and enforcement details differ and can change, confirm the specifics for each state against official sources. Map multi-state exposure with the Legal Compliance Scan, and track new and amended laws on the Policy Change Tracker.

State Privacy Compliance Checklist

  • [ ] Tested applicability against Indiana, Kentucky and Rhode Island thresholds
  • [ ] Noted that Rhode Island's lower thresholds may apply where Indiana and Kentucky do not
  • [ ] Implemented a mechanism to capture and honour targeted-advertising opt-outs
  • [ ] Extended opt-out handling to sale of personal data and profiling
  • [ ] Built opt-in consent flows for sensitive-data categories
  • [ ] Aligned universal opt-out signal handling with the targeted-advertising opt-out
  • [ ] Applied heightened, proactive compliance discipline for Rhode Island (no cure period)
  • [ ] Documented data-processing purposes to support access, correction and deletion requests
  • [ ] Designed a single cross-state compliance mechanism rather than per-state builds
  • [ ] Confirmed each state's thresholds, rights and enforcement against official sources

Frequently Asked Questions

Which new state privacy laws take effect in January 2026?
Three comprehensive state consumer privacy laws took effect on January 1, 2026: the Indiana Consumer Data Protection Act, the Kentucky Consumer Data Protection Act, and the Rhode Island Data Transparency and Privacy Protection Act. Each is a comprehensive privacy statute in the mould established by earlier state laws, and each grants consumers a bundle of rights that includes access, correction, deletion, portability and — the rights most relevant to advertisers — the ability to opt out of the processing of personal data for targeted advertising, the sale of personal data, and profiling. Their arrival on the same date is part of a larger trend of states adopting comprehensive privacy frameworks, and with these three in effect the number of US states with comprehensive privacy laws in force reaches twenty, within a still-larger group of enacted laws that will phase in later. For businesses, the significance of three states going live simultaneously is less about any single novel requirement and more about the cumulative expansion of the map. Each new state adds a population whose residents can exercise privacy rights, and each adds a state Attorney General with enforcement authority, so a national advertiser's compliance obligations grow incrementally with every addition. Because the three laws follow the common model, a business that has already built compliance for earlier state laws will find the core obligations familiar — the opt-out rights, the sensitive-data consent requirement, and the access/correction/deletion rights — but it still needs to confirm the specific thresholds and enforcement details for each new state, since those vary. The practical takeaway is that the compliance question is rarely 'is there something entirely new here' and more often 'does my existing state-privacy compliance design extend cleanly to these states,' which is why a scalable, common-denominator approach tends to work better than per-state improvisation. Because effective dates, thresholds and details can change, confirm the current status against official state sources rather than a summary. Track new and amended state laws and their effective dates on the Policy Change Tracker, and map cross-state exposure with the Legal Compliance Scan. The organizing principle is that Indiana, Kentucky and Rhode Island brought comprehensive privacy laws into effect on January 1, 2026, each granting a targeted-advertising opt-out, expanding the US patchwork to twenty states in force.
Who do the Indiana, Kentucky and Rhode Island laws apply to?
The Indiana and Kentucky laws apply to businesses that control or process the personal data of 100,000 or more of that state's consumers, or 25,000 or more while deriving over 50 percent of revenue from the sale of personal data, while Rhode Island applies at lower thresholds — 35,000 or more Rhode Island consumers, or 10,000 or more while deriving more than 20 percent of gross revenue from selling personal data. These applicability thresholds are the gate that determines whether a business must comply at all, so getting them right is the first step. Indiana and Kentucky share the more common structure: a primary threshold of 100,000 state consumers, and an alternative threshold of 25,000 state consumers combined with a revenue test — deriving over 50 percent of gross revenue from the sale of personal data — that captures data-centric businesses even if they touch fewer consumers. Rhode Island's thresholds are lower and therefore broader in reach: the primary threshold is 35,000 Rhode Island consumers, and the alternative is 10,000 consumers combined with deriving more than 20 percent of gross revenue from selling personal data. The practical consequence of the lower Rhode Island numbers is that a business could be below the threshold and out of scope in Indiana or Kentucky, yet above the threshold and in scope in Rhode Island, so applicability must be assessed state by state rather than assumed from one state's result. It is also worth noting that these thresholds are counted per state — the consumer counts are of that state's residents — so a business's total national footprint is not the test; what matters is its footprint in each specific state. For advertisers and data-driven businesses, the revenue-based alternative thresholds are particularly relevant, because a business whose model involves selling personal data can be captured at a lower consumer count than one that does not. The efficient approach for a national operation is to run an applicability assessment across all the states with comprehensive laws, using consistent definitions, rather than checking one state at a time in isolation. Because thresholds are defined by each statute and can be amended, confirm them against official state sources. Map where a business is in scope across states with the Legal Compliance Scan, and for the platform-data angle see the Meta limited data use guide. The organizing principle is that Indiana and Kentucky apply at 100,000 consumers or 25,000-plus-50%-revenue, while Rhode Island applies at lower thresholds of 35,000 or 10,000-plus-20%-revenue, so applicability must be tested per state.
What is the targeted-advertising opt-out and how does it affect advertisers?
The targeted-advertising opt-out is a consumer right, granted by all three 2026 laws, to require that a business stop processing the consumer's personal data for targeted advertising — and it affects advertisers directly, because once a resident of these states exercises it, the business must recognise and honour the opt-out and cease using that person's data for targeted advertising. Understanding what the right does, and what it does not do, is important for building the right response. The right is an opt-out, not an opt-in, for targeted advertising: a business can generally process personal data for targeted advertising unless and until the consumer opts out, at which point it must stop for that consumer. This sits alongside parallel opt-outs for the sale of personal data and for profiling in furtherance of decisions, which the laws also grant. The obligation the right creates is operational: the business needs systems that can capture an opt-out request, associate it with the right individual and their data, and then actually suppress targeted advertising for that person going forward. Because the same right appears across many state privacy laws, the efficient design is a single, consistent opt-out mechanism that applies the suppression regardless of which state the consumer is in, rather than a separate implementation per state. The targeted-advertising and sale opt-outs also connect to universal opt-out preference signals, which several states require businesses to recognise, so an advertiser's opt-out handling should account for both individual requests and signal-based opt-outs. For advertising operations specifically, the right means that audience-building, custom audiences, retargeting and similar practices must respect opt-outs for the individuals concerned, which in turn means the opt-out status has to flow through to the platforms and tools used to run campaigns. The reliable approach is to treat honouring opt-outs as a data-governance requirement that sits upstream of campaign execution, so that suppressed individuals are not reintroduced into targeted-advertising audiences through some other pathway. Because the precise scope and mechanics are defined by each statute, confirm the details against official sources. Audit how audience-building and retargeting respect opt-outs with the AI Compliance Audit, and for the signal dimension see the US universal opt-out guide. The organizing principle is that the targeted-advertising opt-out requires businesses to stop using a consumer's data for targeted advertising once they opt out, so advertisers need a consistent mechanism to capture and honour opt-outs across states.
What are the sensitive-data consent rules in these states?
All three 2026 laws require opt-in consent before a business processes sensitive data, which is a higher bar than the opt-out model that applies to targeted advertising generally, and the sensitive-data category includes information such as racial or ethnic origin, religious beliefs, health conditions, genetic or biometric data, and precise geolocation. The distinction between opt-in and opt-out is the key point. For targeted advertising, sale and profiling, the laws use an opt-out model: processing is generally permitted unless the consumer opts out. For sensitive data, the laws flip to an opt-in model: the business must obtain the consumer's consent before processing the sensitive data at all. That means sensitive data cannot be processed on a default-on basis and then switched off if the consumer objects; the consent must be obtained up front. The categories treated as sensitive are broadly consistent across the state-privacy landscape and, as reflected in these laws, include data revealing racial or ethnic origin, religious beliefs, and health conditions, as well as genetic and biometric data used to identify a person, and precise geolocation data. For advertisers and data-driven businesses, the sensitive-data rules have practical implications for both targeting and data collection. Any audience-building or personalisation that relies on sensitive-data categories requires opt-in consent, which is a meaningful constraint on, for example, targeting based on health or precise location without the consumer's affirmative agreement. It also means that data flows need to be mapped to identify where sensitive data is being collected or used, so that the appropriate consent can be obtained and documented. Because the consequences of processing sensitive data without consent can be significant — and because, in Rhode Island, there is no cure period to fix a violation after the fact — the sensitive-data rules are an area where proactive compliance is especially valuable. The efficient approach is to identify sensitive-data processing, build an opt-in consent flow for it, and document the consent, treating this as distinct from the opt-out mechanism used for general targeted advertising. Because the precise categories and consent requirements are defined by each statute and can vary, confirm them against official state sources. Screen data categories and copy with the Legal Compliance Scan, and define sensitive-data terms in the compliance glossary. The organizing principle is that the three laws require opt-in consent before processing sensitive data — including racial or ethnic origin, religious beliefs, health, genetic or biometric data and precise geolocation — which is a higher bar than the opt-out model for targeted advertising.
How are the laws enforced, and what are the penalties?
The Indiana, Kentucky and Rhode Island privacy laws are each enforced by the state's Attorney General, with Indiana and Kentucky providing a 30-day period to cure a violation and penalties of up to $7,500 per violation, while Rhode Island provides no cure period and penalties of up to $10,000 per violation — a difference that makes proactive compliance in Rhode Island particularly important. Enforcement structure matters because it determines both who can act and what opportunity a business has to correct a problem. In all three states, the enforcer is the state Attorney General rather than a broadly available private right of action, which means enforcement is a matter of state regulatory action. The cure-period difference is the most consequential distinction among the three. Indiana and Kentucky each provide a 30-day window to cure: if the Attorney General identifies a violation, the business generally has an opportunity to fix it within that window before a penalty is imposed, with penalties reaching up to $7,500 per violation. Rhode Island, by contrast, provides no cure period, and its penalties reach up to $10,000 per violation, which means a business cannot rely on a built-in opportunity to remedy a violation after it is identified — the compliance needs to be right in the first place. The practical implication is a difference in risk posture by state. In Indiana and Kentucky, the cure period offers a measure of tolerance for good-faith errors that are promptly fixed, though it is not a substitute for compliance. In Rhode Island, the absence of a cure period raises the stakes on getting compliance right proactively, since there is no defined chance to correct a violation before exposure to penalties. Because penalties are assessed per violation, the exposure can also scale with the number of affected consumers or instances, which reinforces the value of systematic rather than ad hoc compliance. For a business operating across all three states, the prudent approach is to design to the strictest standard — effectively treating Rhode Island's no-cure posture as the baseline — so that compliance holds up regardless of which state's enforcement applies. Because enforcement mechanics and penalty figures are set by each statute and can change, confirm them against official sources. Track enforcement developments on the Policy Change Tracker, and map multi-state exposure with the Legal Compliance Scan. The organizing principle is that all three laws are Attorney General-enforced, with Indiana and Kentucky offering a 30-day cure and up to $7,500 per violation, and Rhode Island offering no cure period and up to $10,000 per violation.
How do these three laws fit into the broader US state privacy landscape?
The Indiana, Kentucky and Rhode Island laws are three additions to a rapidly expanding US state privacy landscape: with them in effect, the number of states with comprehensive privacy laws in force reaches twenty, within a larger group of enacted laws — additional states have passed comprehensive frameworks that will phase in later — so the three are best understood as part of a continuing wave rather than as isolated events. This framing matters because it shapes the right compliance strategy. If a business treated each new state law as a distinct project, it would face an ever-growing backlog as more states enact and bring laws into force. But because these laws share a common model — the same core rights, the opt-out structure for targeted advertising, sale and profiling, the opt-in requirement for sensitive data, and Attorney General enforcement — the more efficient approach is to build a compliance framework around the common denominator and then accommodate each state's specific thresholds and enforcement details. The three 2026 laws reinforce that pattern: they do not introduce fundamentally new concepts so much as extend familiar ones to new populations. For national advertisers, the cumulative effect is a patchwork in which the reachable audience for targeted advertising is subject to opt-out rights in a growing number of states, and in which sensitive-data processing requires opt-in consent across those states. That argues for a single, scalable mechanism to capture and honour opt-outs and to manage sensitive-data consent, applied consistently, rather than per-state builds that multiply as the map grows. It also argues for ongoing monitoring, because the landscape is not static: more states are enacting laws, effective dates are staggered, and details differ, so a compliance design needs to be maintained as new states come online. The strategic message is that the expansion is predictable in shape even as it grows in scope, which means a business that builds to the common model and tracks the additions can absorb each new state with limited incremental effort. Because the number of states, their effective dates and their specific requirements all change over time, confirm the current landscape against official sources. Track new and amended state laws on the Policy Change Tracker, and map cross-state exposure with the Legal Compliance Scan. The organizing principle is that Indiana, Kentucky and Rhode Island are part of a continuing wave that brings comprehensive state privacy laws to twenty states in force, so advertisers should build to the common model and track each addition.

Don't miss the next policy change.

Create a free account — track every policy change across 8 platforms, get instant alerts, and access every free compliance tool. Or try our Meta Rejection Predictor first.

Create Free Account

Report Keywords — Run AI Compliance Audit

#State Privacy#Indiana CDPA#Kentucky CDPA#Rhode Island#Targeted Advertising#Opt-Out#Sensitive Data#Ad Compliance#US Regulation#2026 Policy#Advertisers#Compliance Guide 2026

Share This Report

TweetShare

Related Posts

Related Resources