Does the US Have a Federal Data Privacy Law?
No. As of 2026, the United States still has no comprehensive federal data privacy law, nothing like Europe's GDPR that covers all consumer data across every industry. What exists instead is a patchwork: a handful of sector-specific federal laws, a growing set of state laws that vary widely, and a string of federal bills that keep stalling in Congress. The practical result is that your right to see, opt out of, and delete your personal data depends heavily on which state you live in, and even where those rights exist, actually exercising them is left up to you. Here is where things stand and what it means for protecting your information.
Is there any federal privacy law at all?
Only narrow, sector-specific ones. Federal law protects certain kinds of data in certain contexts: HIPAA covers some health information, FERPA covers student education records, the Gramm-Leach-Bliley Act covers some financial data, COPPA covers data collected from children under 13, and the Fair Credit Reporting Act governs credit and background reports. What is missing is any general law covering the broad commercial trade in your personal information, the buying and selling of your name, address, habits, and location by data brokers. That entire market operates without a dedicated federal privacy standard.
Why has a federal privacy law never passed?
Not for lack of trying. Congress has floated several comprehensive bills over the past decade. The American Data Privacy and Protection Act cleared a House committee in 2022 with a strong bipartisan vote but never made it through the full House or Senate. Later efforts, including the American Privacy Rights Act, stalled as well. Two disagreements keep sinking these bills: whether a federal law should override, or preempt, stronger state laws like California's, and whether individuals should be able to sue companies directly for violations. Until those are resolved, a national standard remains out of reach, and the states keep filling the gap on their own.
What privacy rights do I actually have?
It depends on your state. As of 2026, around 20 states have enacted comprehensive consumer privacy laws, and the number keeps climbing. California led the way with the CCPA and CPRA, followed by Virginia, Colorado, Connecticut, and many others, with new laws taking effect in states like Indiana, Kentucky, and Rhode Island. These laws generally give residents the right to access their data, opt out of its sale, and request deletion, with businesses typically required to respond within about 45 days. California went furthest of all, building a state platform that lets residents send a single request to delete their data from hundreds of registered brokers at once. If you live in one of these states, you have real, usable rights. If you do not, your legal footing is thinner.
What if my state has no privacy law?
You are not entirely without options. In practice, many large data brokers apply California-style privacy compliance across the whole country rather than build separate systems for each state, so residents of states without their own laws can often submit deletion or opt-out requests citing California's framework and have them honored. It is not guaranteed, and it is not a right you can enforce the way a Californian can, but it frequently works. The catch, as always, is that you have to send those requests yourself, to each broker, one at a time.
What does the patchwork mean for protecting my data?
It means the law is an uneven backstop, not a solution that works on your behalf. Even the strongest state laws put the burden on you to find every company holding your data and submit a request to each, and none of them stop people-search sites from rebuilding your listing from fresh public records afterward. The rights are worth using, but they do not do the work for you, which is where a removal service fits. It exercises those opt-out and deletion mechanisms across many sites regardless of which state you live in, and keeps doing it as listings return. Consumer Reports found that automated and do-it-yourself removals cleared only about 27 percent of exposed listings, while removals handled by real people who monitor and refile reached roughly 70 percent. The law gives you a lever. Someone still has to keep pulling it.
No federal law means the work falls on you. Or on us.
Wherever you live, exercising your data rights broker by broker is slow, and listings come back. A free scan shows which people-search sites expose you right now, and our team of real people files the removals across sites and keeps checking as they reappear.
Run my free scan Start free trialFrequently asked questions
Does the US have anything like the GDPR?
No. The GDPR is a single comprehensive law covering the whole European Union. The US has no national equivalent, only sector-specific federal laws and a growing collection of individual state laws, which is why compliance and consumer rights vary so much depending on where you are.
Is there a federal law regulating data brokers?
There is no comprehensive federal data broker law. Some brokers fall under narrow rules like the Fair Credit Reporting Act when their data is used for credit or employment, but the broad trade in consumer profiles is largely governed at the state level, where it is governed at all.
Will a federal privacy law pass soon?
It is uncertain. Bills continue to be introduced, but the long-running disputes over preempting state laws and allowing individuals to sue have repeatedly stalled them. In the meantime, states are the ones expanding privacy rights, so watching your own state's legislation is the more practical focus.
Can I delete my data if my state has no law?
Often yes, in practice. Many brokers apply California-style compliance nationwide, so a deletion request citing that framework is frequently honored even outside California. It is less certain than an enforceable right, and you still have to submit each request yourself, which is the tedious part a service can take over.