US Data Privacy & Compliance Laws Every Software Buyer Should Know (2026)

US Data Privacy & Compliance Laws Every Software Buyer Should Know (2026)

Short Answer:

As of 2026, 20 US states have comprehensive consumer privacy laws in effect — up from just five in 2023 — alongside federal and sector-specific rules like HIPAA, Illinois' Biometric Information Privacy Act (BIPA), and Massachusetts' data security regulation (201 CMR 17.00). There is still no single federal privacy law, so compliance requirements depend on where your users live, what kind of data you collect, and which industry you're in — not just where your company is headquartered. Enforcement has gotten real: California alone issued a record $12.75 million CCPA settlement in 2026, and BIPA lawsuits have produced verdicts exceeding $200 million. If you're building or buying software that touches personal data, understanding which of these rules applies to you is no longer optional legal homework — it's a cost and architecture decision that should shape your project from day one.

Most compliance content online is written for lawyers. This isn't that. It's written for the founder, product manager, or CTO who needs to know, in plain terms, which rules actually apply to their project, what they cost to ignore, and what to ask a development partner before writing a single line of code. If you're also scoping the actual dollar cost of your build, our software development cost in the USA guide breaks down how compliance requirements specifically move that number.

The US State Privacy Law Landscape in 2026

There is no comprehensive federal privacy law in the United States. Instead, states have built their own patchwork, and that patchwork has grown fast: from five states with comprehensive privacy laws in 2023 to 20 states with laws in effect as of 2026, according to the IAPP's US State Privacy Legislation Tracker and legal roundups from MultiState and Venable LLP. Indiana, Kentucky, and Rhode Island became the newest additions on January 1, 2026. A further four states — Alabama, Louisiana, Oklahoma, and Vermont — enacted new comprehensive privacy laws in 2026 that take effect between 2027 and 2028, meaning the list will keep growing.

States with comprehensive privacy laws in effect (2026): California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and Washington.

What this means practically: if your software collects personal data from residents of any of these states — regardless of where your company is based — you're likely subject to that state's rules on consumer rights (access, deletion, opt-out of sale), data minimization, and, increasingly, specific obligations around sensitive data categories and automated decision-making. Most of these laws follow a similar opt-out model rather than the GDPR's opt-in consent standard, but the details differ enough between states that "compliant in California" doesn't automatically mean "compliant in Colorado."

Two 2026 developments worth flagging specifically:

  1. California's automated decision-making technology (ADMT) regulations took effect January 1, 2026, adding new obligations around AI-driven decisions that affect consumers — directly relevant if your product uses AI for anything from content personalization to credit or hiring decisions. If you're building AI features, this is worth reading alongside our guide on AI-powered software development costs, since ADMT compliance adds real scoping time to those builds.

  2. A growing number of states now require honoring Global Privacy Control (GPC) — a browser-level opt-out signal — which is a technical implementation requirement, not just a policy one. If your development team hasn't built GPC detection into your site or app, that's an active compliance gap in at least 11 states as of 2026.

If you operate in California, Illinois, or New Jersey specifically, state-level requirements should be part of your project scoping conversation from the first discovery call — not a compliance review bolted on before launch.

HIPAA: What It Actually Requires From Software Buyers

HIPAA (the Health Insurance Portability and Accountability Act) applies to "covered entities" (healthcare providers, insurers, clearinghouses) and their "business associates" — which includes almost any software vendor that stores, processes, or transmits protected health information (PHI) on their behalf. If you're building a healthtech product, a wellness app that handles health data, or even an internal tool that touches patient records, HIPAA likely applies to your development vendor, not just your organization.

The stakes are real and current. According to HIPAA Journal's analysis of the HHS Office for Civil Rights breach reporting portal, healthcare data breaches affected more than 289 million individuals in 2024 — a single-year figure inflated substantially by the Change Healthcare ransomware attack (192.7 million individuals alone). In 2025, that number fell sharply to roughly 61 million individuals affected, a 78.9% year-over-year decline, though still a historically high total. The trend line matters more than any single year's headline number: healthcare remains one of the most breached sectors in the US economy, and regulators have not slowed enforcement in response.

What this means for a software buyer, practically:

  • If your vendor will touch PHI, you need a signed Business Associate Agreement (BAA) before development starts — not after. Any vendor unfamiliar with this term or reluctant to sign one is a serious red flag.

  • HIPAA doesn't mandate specific technology, but it does require documented administrative, physical, and technical safeguards — encryption at rest and in transit, access logging, and breach notification procedures are the baseline, not optional extras.

  • Interoperability standards (HL7/FHIR) for EHR/EMR integration add real scoping time that a generic development quote often won't anticipate — this is one of the most common sources of healthtech budget overruns.

CCPA/CPRA: California's Privacy Law and Why It Matters Outside California

The California Consumer Privacy Act, as amended by the California Privacy Rights Act (CPRA), is the most actively enforced state privacy law in the country — and enforcement in 2025 and 2026 has made clear that "we're not based in California" is not a defense if you have California users.

CCPA fines run up to $2,663 per unintentional violation and $7,988 per intentional violation (2025 figures, adjusted biennially for inflation), with no overall cap — since each affected consumer can count as a separate violation, penalties scale with your user base, not your intent. Real 2025–2026 enforcement actions show exactly how this plays out:

Company

Settlement

Year

Core Allegation

General Motors

$12.75 million

2026

Selling OnStar driving/geolocation data to data brokers without proper consent

Disney

$2.75 million

2025

Failing to honor consumer opt-out signals

Healthline Media

$1.55 million

2025

Sharing sensitive health-related browsing data with advertisers

Jam City (mobile gaming)

$1.4 million

2025

Selling minors' personal information without consent

Tractor Supply Co.

$1.35 million

2025

Privacy notice, opt-out, and vendor contract failures

PlayOn Sports

$1.1 million

2025

Student data privacy violations

American Honda Motor Co.

$632,500

2025

Excessive identity verification burden on opt-out requests

The GM settlement is the largest CCPA penalty issued to date and the first tied specifically to a "data minimization" theory — meaning California regulators are now scrutinizing not just how data is protected, but whether it should have been collected at all. That's a meaningfully different compliance bar than most software teams are used to designing for, and it has direct implications for anything involving connected-device data, location tracking, or behavioral analytics.

What this means practically: if your product has California users (which, for most consumer or B2B SaaS products, it does), your development team needs to build in real opt-out mechanisms — including GPC signal detection — data minimization by design, and clear vendor contracts for any third-party data sharing, from day one.

BIPA: Illinois' Biometric Privacy Law and Its Outsized Litigation Risk

The Illinois Biometric Information Privacy Act (BIPA), passed in 2008, remains the strictest biometric privacy law in the country, and it carries a private right of action — meaning individuals, not just regulators, can sue directly. This has produced some of the largest privacy verdicts in US history.

In 2022, a federal jury handed down the first BIPA trial verdict: $228 million against BNSF Railway, based on 45,600 separate violations from a fingerprint-based timekeeping system used by truck drivers. Since then, companies including Meta and Google have paid out a combined $800 million-plus in BIPA settlements, and smaller but still significant judgments continue to land regularly — a $28.5 million settlement against an ID-verification provider, a $4 million settlement against Incode Technologies, and numerous multi-million-dollar employer settlements tied to fingerprint time-clock systems.

Illinois lawmakers amended BIPA in 2024 to reduce some of the "per-scan" damage exposure that drove these massive verdicts (courts had previously treated each individual scan as a separate violation), but the law's core requirement — written consent before collecting fingerprints, facial geometry, retina scans, or voiceprints — remains intact and remains a serious risk for any software that uses biometric authentication, facial recognition, or similar features, regardless of whether your company is based in Illinois.

If you're building anything with biometric login, facial recognition-based features, or voice authentication and you have any Illinois user base, this needs to be flagged during your project's discovery phase — not discovered after a feature ships. A software development company in Chicago working locally will typically already build this into their scoping process by default, but any vendor, anywhere, needs to account for it if Illinois users are in scope.

Washington's My Health My Data Act (MHMDA)

Washington's My Health My Data Act took effect March 31, 2024, and represents a newer category of state law: consumer health data protection that applies regardless of whether HIPAA covers you. It defines "consumer health data" broadly enough to include information inferred from behavior — fitness tracking, location data near healthcare facilities, and reproductive or mental health-related app usage all potentially qualify, even for apps that aren't traditionally "healthcare" products.

The law also includes a private right of action, and the first lawsuit under MHMDA was filed against Amazon on February 10, 2025 — nearly a year after the law took effect, signaling that litigation under this statute is now actively ramping up rather than remaining theoretical. Legal analysts have specifically flagged MHMDA as a likely new frontier for biometric and health-adjacent privacy litigation, given its broad definitions and private enforcement mechanism.

If your product touches fitness, wellness, mental health, or reproductive health data in any form — even as a secondary feature — and you have Washington users, this law almost certainly applies, whether or not you'd describe your product as "healthcare software."

Massachusetts 201 CMR 17.00: A Data Security Regulation Buyers Often Miss

Unlike the consumer-rights-focused laws above, Massachusetts' 201 CMR 17.00 is a data security regulation — it specifies minimum technical requirements for protecting personal information about Massachusetts residents, including encryption standards, access controls, and a written information security program (WISP). It's older than most of the newer state privacy laws (in effect since 2010) but remains actively enforced and is frequently underestimated by out-of-state development teams who aren't familiar with it.

If your software handles personal information (Social Security numbers, financial account numbers, driver's license numbers) about Massachusetts residents, your vendor should be able to speak specifically to how their architecture satisfies 201 CMR 17.00's encryption and access-control requirements — not just generic "we use industry-standard security."

SOC 2, PCI-DSS, and Other Standards Buyers Often Confuse With "Compliance"

A quick but important distinction: SOC 2 and PCI-DSS are not government privacy laws — they're auditing frameworks and industry standards, respectively, and they solve a different problem than the laws above.

  • SOC 2 is a voluntary audit standard (via the AICPA) that demonstrates a vendor has adequate controls around security, availability, and confidentiality. Many B2B software buyers require SOC 2 Type II certification from vendors before signing a contract — but SOC 2 compliance doesn't automatically satisfy state privacy law obligations, which govern consumer rights rather than internal security controls.

  • PCI-DSS applies specifically to anyone handling credit card data, and it's enforced by the payment card industry (Visa, Mastercard, etc.), not a government body. If your software processes payments directly rather than through a compliant third-party processor like Stripe, PCI-DSS scope expands significantly.

A development company that conflates these with state privacy law compliance, or treats one as a substitute for the other, hasn't scoped your compliance requirements correctly.

A Practical Compliance Checklist for Software Buyers

Before development starts, confirm your project addresses:

  • Which states your users are in, and which comprehensive privacy laws apply as a result — not just where your business is headquartered

  • Whether you handle PHI, requiring a signed BAA and HIPAA-compliant architecture

  • Whether you use biometric authentication or facial recognition, triggering BIPA (Illinois) or similar state biometric laws

  • Whether you handle health-adjacent data (fitness, wellness, reproductive health) even outside a traditional healthcare product, triggering Washington's MHMDA

  • Whether your data collection could be characterized as excessive relative to your stated purpose — the GM settlement shows this is now an active enforcement theory, not a theoretical risk

  • Global Privacy Control (GPC) signal detection, now required in 11+ states

  • Encryption and access-control standards matching the strictest applicable state requirement (Massachusetts' 201 CMR 17.00 is a useful baseline)

  • Vendor and third-party data-sharing contracts, which several of the 2025 CCPA settlements specifically flagged as inadequate

How to Vet a Development Partner's Compliance Practices

Compliance isn't something you bolt onto a finished product — it needs to be part of how a vendor scopes and architects from day one. When evaluating a software development company, ask directly:

  • Have you built HIPAA-compliant systems before, and can you describe your BAA and audit-logging approach specifically?

  • How do you handle Global Privacy Control detection and multi-state opt-out requirements?

  • What's your approach to biometric data if our product uses facial recognition or fingerprint authentication?

  • Do you document data flows and third-party data sharing as part of your architecture process?

  • How do you decide what data actually needs to be collected, versus what's convenient to collect?

A vendor who can answer these specifically — not generically — has actually built compliance-sensitive software before. This is exactly the kind of question we'd recommend adding to the vendor evaluation process in our guide to hiring a software development company in the USA, which covers the full hiring and contract process in more depth.

Frequently Asked Questions

How many US states have data privacy laws in 2026?
20 states have comprehensive consumer privacy laws in effect as of 2026, with four more (Alabama, Louisiana, Oklahoma, Vermont) enacted but not yet effective.

Is there a federal data privacy law in the United States?
No. The US has no comprehensive federal privacy law; compliance depends on a patchwork of state laws plus sector-specific federal rules like HIPAA.

Does HIPAA apply to my software company if we're not a healthcare provider?
Yes, if you're a "business associate" that stores, processes, or transmits protected health information on behalf of a covered entity — this includes most software vendors serving healthcare clients.

What is BIPA and why does it matter outside Illinois?
BIPA is Illinois' biometric privacy law, and it applies to any company collecting biometric data (fingerprints, facial geometry, voiceprints) from Illinois residents, regardless of where the company itself is based.

What's the largest CCPA fine issued so far?
General Motors' $12.75 million settlement in 2026, over selling OnStar driving and geolocation data to data brokers without proper consumer consent.

Does CCPA apply to my business if I'm not based in California?
Yes — CCPA applies based on whether you have California consumers and meet the law's revenue or data-volume thresholds, not on where your company is headquartered.

What is Washington's My Health My Data Act?
A 2024 Washington state law protecting "consumer health data" broadly — including data inferred from behavior like fitness tracking or location near healthcare facilities — that applies even to companies not covered by HIPAA.

What's the difference between SOC 2 and state privacy law compliance?
SOC 2 is a voluntary security-controls audit standard; state privacy laws govern consumer rights (access, deletion, opt-out) and carry legal penalties for non-compliance. Meeting one doesn't automatically satisfy the other.

Do I need a Business Associate Agreement (BAA) with my software vendor?
Yes, if your vendor will handle protected health information on your behalf — this should be signed before development starts, not after.

What is Global Privacy Control (GPC) and do I need to support it?
GPC is a browser-level signal indicating a user's opt-out preference; 11+ states now require businesses to recognize and honor it as a valid opt-out request.

How much can a company be fined for a CCPA violation?
Up to $2,663 per unintentional violation and $7,988 per intentional violation, with no overall cap — penalties can scale into the millions for large user bases.

Does Massachusetts have its own data security law?
Yes — 201 CMR 17.00 requires specific technical safeguards (encryption, access controls, a written information security program) for anyone handling personal information about Massachusetts residents.

Can individuals sue directly under these privacy laws?
It depends on the law — BIPA and Washington's MHMDA both include a private right of action allowing individual lawsuits; most other state privacy laws only allow enforcement by a state attorney general or privacy agency.

How do I know which state privacy laws apply to my software?
It depends on where your users are located, not where your company is based — a product with users across multiple states may need to comply with several different state laws simultaneously.

Should compliance be part of my initial software development quote?
Yes — compliance requirements should be identified during project discovery and factored into architecture decisions from the start, since retrofitting compliance after launch is significantly more expensive than designing for it upfront.


Akoode Technologies builds software for clients across the US, UK, Canada , UAE and India, with a coordination office in Jenks, Oklahoma. The team holds a 4.9 rating from 125 reviews on Google and a 5.0 rating on GoodFirms. If you're scoping a project with compliance requirements you're not sure how to address, book a time on our calendar and we'll walk through what applies to your specific situation.

Note: This article is provided for informational purposes only and does not constitute legal advice.

Tags
#US Data Privacy#Software Buyers 2026#HIPAA

Get In Touch Now

= ?

Stay Informed with Thoughtful Innovation

Subscribe to the Akoode newsletter for carefully curated insights on AI, digital intelligence, and real-world innovation. Just perspectives that help you think, plan, and build better.