State Penalties
Privacy Regulatory Penalties — All 50 States

Privacy Regulatory Penalties — All 50 States

State privacy laws: CCPA-style consumer rights, breach notification, biometric data regulations, and enforcement notes.

Color-coded by maximum imprisonment severity

Risk tier:HighMediumLow
StateTierLawCivil FineCriminal FineImprisonmentNotes
AlabamaLowData Breach Notification Act$7,500$500,000 cap/breachN/AAG exclusive; $5K/day breach notice failure
AlaskaHighAPIPA / SB 134$25,000$2,0001 yearGovt employee disclosure = misdemeanor
ArizonaLowA.R.S. § 18-552$10,000/individualN/AN/A$500K cap per breach
ArkansasLowPIPA / Deceptive Trade Practices$10,000N/AN/AAG enforcement under DTPA
CaliforniaMediumCMIA / CCPA / AB 2013$25,000 (willful)$250,0001 yearPrivate right of action; $1K nominal damages
ColoradoMediumCPA$20,000N/AN/A$500K aggregate cap; AG exclusive
ConnecticutLowCTDPA$5,000 (willful)N/AN/APer-consumer violations can be massive
DelawareLowDPDPA$10,000 (willful)N/AN/ANo cure period as of Jan 2026
FloridaMediumFLDBR$50,000N/AN/ATrebled to $150K for children
GeorgiaHighSB 473 (eff. July 2026)$7,500$50,000 (computer)15 years (felony)60-day cure period
HawaiiMediumSB 3017 / SB 1163$10,000/dayN/AN/ATreble damages for consumers
IdahoMediumID Code § 28-51-105$25,000/breach$2,0001 yearGovt employee disclosure = misdemeanor
IllinoisLowBIPA$5,000 (intentional)N/AN/AOne recovery per person per biometric type
IndianaHighICDPA (eff. Jan 2026)$7,500$5,000 (privacy invasion)2.5 years (Level 6 Felony)30-day cure; no private right of action
IowaLowICDPA$7,500N/AN/A90-day mandatory cure; AG exclusive
KansasLowKCPA$10,000N/AN/A$20K for willful court order violations
KentuckyLowKCDPA$7,500N/AN/A30-day cure period
LouisianaHighData Breach Notification$5,000/day$250,00010 yearsCriminal for wrongful health info disclosure
MaineMediumLD 1088$10 million (initial)N/AN/A$30M for subsequent; 30-day cure
MarylandMediumMODPA / MCPA$25,000 (repeat)$1,0001 year60-day cure until April 2027
MassachusettsHighMDPA (eff. July 2026)$5,000$250,000 (health data)10 years60-day cure July 2026–Dec 2027
MichiganHighHIPAA/State$50,000/violation$250,00010 yearsFederal HIPAA tiers apply
MinnesotaLowMCDPA$7,500N/AN/AAG exclusive; no private right of action
MississippiLowHB 1051$7,500N/AN/A$100–$750 per consumer for breaches
MissouriHighHIPAA (federal)$50,000$250,00010 yearsFederal HIPAA enforcement
MontanaHighMTCDPA$7,500$10,0005 yearsCure period sunsets April 2026
NebraskaMediumNDPA / LB 504$50,000 (minors)N/AN/A$7,500 general; 30-day cure
NevadaLowNRS 603A$5,000N/AN/AAG sole enforcement; no private right
New HampshireMediumNHPA / SB 255$10,000$100,000 (entity felony)Felony possibleCure discretionary as of Jan 2026
New JerseyMediumNJDPA$20,000 (subsequent)N/AN/A30-day cure until July 2026
New MexicoHighCHISPA / SB 53$1,000 (health data)N/A18 months (2nd offense)Opt-in standard for data collection
New YorkMediumSHIELD Act$20,000 (notification)N/AN/A$5K/violation security failures
North CarolinaMediumNC Personal Data Privacy Act$2,500Misdemeanor60 days (Class 2)$50K cap for breach notification
North DakotaHighHB 1127$100,000$10,000 (financial)5 years (Class C Felony)$5K/offense breach notice
OhioHighORC 1349.19$10,000/day (after 90 days)N/A5 years (tampering)Tiered daily fines for breach notice
OklahomaMediumSB 626 (2026)$150,000/breachN/AN/AAffirmative defense for safeguards
OregonMediumOCPA$7,500Class C felony possibleFelony possibleNo cure period as of Jan 2026
PennsylvaniaLowBPINA / UTPCPL$5,000 (injunction)N/AN/A$3K/violation for senior victims
Rhode IslandLowRIDTPPA$10,000N/AN/ANo cure period; no private right of action
South CarolinaLowHB 3431 (Social Media)Treble damagesN/AN/APersonal liability for officers
South DakotaMediumSB 49 (Genetic) / DTPA$10,000/dayN/AN/A$5K/violation genetic data
TennesseeLowTIPA$7,500 ($22,500 willful)N/AN/A60-day cure; NIST safe harbor
TexasLowTDPSA$7,500N/AN/A30-day cure; AG exclusive
UtahLowUCPAAG enforcementN/AN/ARight to correct eff. July 2026
VermontLowVDPA$10,000 ($25K filings)N/AN/APrivate right of action 2026–2028
VirginiaLowVCDPA$7,500 ($2.5M cap continuing)N/AN/A30-day cure; no private right of action
WashingtonHighMHMDA / CPA$7,500 (AG) / $25K treble$250,000 (HIPAA)10 years (HIPAA)Private right of action under MHMDA
West VirginiaHighHB 4868 (proposed 2026)$10,000/violation$10,00010 years (felony)AG exclusive enforcement
WisconsinHighAB-172 (proposed)$10,000/infraction$100,000 (for profit)3.5 yearsPending legislation for 2027
WyomingHighSF0065 / HIPAA$250,000 (malicious)$250,00010 yearsGovt data restrictions eff. July 2026