Skip to content
Your Rights

New privacy laws in 2026: what changed for your data and inbox

Three new state privacy laws took effect on January 1, 2026, bringing the total near 20 states. Here is what changed for your data rights and your marketing email.

Email Unsubscriber Team 8 min read
Flat vector illustration of a 2026-stamped law booklet, a star-pinned map tile, an OPT OUT toggle switch, a crossed-out SOLD envelope, and a data-broker filing drawer.

You keep seeing headlines about new privacy laws, and you want to know the part that actually reaches you: does anything change for the marketing email piling up in your inbox, and for the data that put you on those lists in the first place. In 2026 the answer is yes, on both counts.

In 2026, new comprehensive privacy laws took effect in Indiana, Kentucky, and Rhode Island on January 1, bringing the US total near 20 states. They give residents the right to access, delete, and opt out of the sale of their personal data, including the email address that feeds marketing lists.

This is an educational overview of consumer privacy law, not legal advice. For a specific situation, check the regulator or statute linked in each section or consult a lawyer in your state.

Which new privacy laws took effect in 2026?

Three states switched on comprehensive privacy laws on January 1, 2026. Each one gives residents a fresh set of data rights and puts new duties on the companies that hold their information.

  • Indiana Consumer Data Protection Act. Indiana’s law tracks Virginia’s model. It covers businesses that handle the data of 100,000 or more Indiana residents, or 25,000 residents when half their revenue comes from selling data.
  • Kentucky Consumer Data Protection Act. Kentucky mirrors the same thresholds and rights. Its attorney general holds exclusive enforcement power and can seek up to $7,500 per violation.
  • Rhode Island Data Transparency and Privacy Protection Act. Rhode Island set the lowest bar of the three, reaching companies that handle 35,000 residents’ data, or 10,000 when a fifth of revenue comes from data sales. According to the IAPP’s 2026 overview, Rhode Island offers no cure period, so a company cannot fix a violation after the fact to escape penalty.

More arrive mid-year. According to MultiState’s 2026 tracker, Connecticut, Arkansas, and Utah all see privacy-law changes on July 1, 2026.

How many states now have a privacy law?

About 20 states now have a comprehensive consumer privacy law in effect. MultiState’s 2026 tracker counts 20 once Indiana, Kentucky, and Rhode Island join the group that already included California, Colorado, Virginia, Texas, and Oregon.

There is still no single federal privacy law covering everyone. Your rights depend on where you live and how much data the company handles. A resident of California or Kentucky can demand deletion; a resident of a state with no law has to rely on whatever the company offers voluntarily. Many national brands extend the same rights to all customers rather than run 20 separate systems, so you may get the options even outside a covered state, just without the legal force behind them.

What new rights do you actually get?

A comprehensive state privacy law gives residents a standard bundle of rights over their personal data. Your email address counts as personal data, so every right on this list applies to it.

RightWhat you can doWhy it touches your inbox
AccessAsk a company what data it holds on youSee if a sender bought or stored your address
CorrectFix inaccurate personal dataUpdate a wrong record tied to your email
DeleteRequire a company to erase your dataCut a sender’s record at the source, not just one list
PortabilityGet a copy of your dataTake proof of what a company held
Opt out of saleStop a company selling your dataKeep your address off new marketing lists
Opt out of targeted adsStop profiling for ad targetingReduce behavior-based marketing

Sensitive data, such as precise location or health details, generally needs your opt-in consent before a company can process it at all. The deletion right is the one that changes the email math most. Unsubscribing tells one sender to stop mailing a single list. A deletion request tells the company to erase the record entirely, which stops it from mailing you again from any list and from selling the address onward.

What is a universal opt-out signal, and why does it matter for your inbox?

A universal opt-out signal is a browser setting that opts you out of data sale and targeted advertising on every site at once, without visiting each one. The best-known version is Global Privacy Control, a signal your browser or a privacy extension sends automatically in the background.

According to the Oregon Department of Justice, Oregon began requiring covered businesses to honor a universal opt-out on January 1, 2026. Oregon joins roughly a dozen states, including California, Colorado, and Connecticut, that treat the signal as a binding opt-out request. You turn it on once and it works on every covered site you visit after that.

The inbox payoff is indirect but real. When a site honors the signal and stops selling or sharing your data, your email address stops flowing to new marketers, so fewer fresh lists ever acquire you. For the full walkthrough of turning it on, see our guide to Global Privacy Control.

What changed with California data brokers in 2026?

California went after the middlemen. Data brokers collect and resell personal information, including email addresses, which is how a company you never contacted ends up mailing you. Two 2026 changes tighten the rules on them.

First, California expanded what brokers must disclose when they register with the state, adding sensitive categories such as immigration status, union membership, and sexual orientation. Second, and more useful for you, California launched DROP, the Delete Request and Opt-out Platform.

According to the California Privacy Protection Agency, a California resident can file one DROP request and have it reach every registered data broker, more than 600 of them, instead of chasing each company separately. The platform opened to residents on January 1, 2026, and data brokers must begin processing those deletion requests by August 1, 2026, erasing matching records including the inferences built on top of them. Miss that, and a broker faces $200 per request per day in penalties. Deleting your address from the broker layer cuts off a major source of the promotional mail you never asked for.

How do these laws touch your marketing email specifically?

These laws work on the supply side of your inbox, upstream of the individual unsubscribe link. Three mechanisms matter for email.

Opt out of sale and sharing keeps your address from being passed to new marketers, so the flow of fresh senders slows. The deletion right lets you force a company to erase your record, which is stronger than unsubscribing because it removes you from every list the company runs, not just the one that mailed you. Data-broker deletion, through a tool like California’s DROP, pulls your address out of the resale market that seeds new lists in the first place.

None of this replaces the unsubscribe button for a sender you already hear from. The two systems cover different problems, and the fastest path still depends on which one you are facing. Our survey of unsubscribe laws by country maps the opt-out rules that sit alongside these privacy laws.

Do these laws replace the CAN-SPAM unsubscribe rule?

No. CAN-SPAM still governs the unsubscribe link on every commercial email sent to a US recipient, and it still gives a sender 10 business days to honor your opt-out. The new state privacy laws sit next to it, not on top of it.

The division is clean once you see it. You use the unsubscribe link when a specific sender keeps mailing you, and CAN-SPAM backs that request with FTC penalties. You use your privacy rights when you want to stop your data being sold, profiled, or held at all. If a sender ignores a clean unsubscribe, that is a CAN-SPAM problem, and our guide on your rights when unsubscribe fails walks through documenting and reporting it.

What should you do now?

Pick the tools that match your state and your goal. The steps below move from easiest to most thorough.

  1. Turn on Global Privacy Control. Enable it in your browser settings or add a privacy extension. In a covered state, every site that honors it treats your visit as an opt-out of sale and targeted advertising.
  2. Use California’s DROP if you are a resident. File one deletion request to reach every registered data broker at once.
  3. Exercise access and deletion rights with companies that hold too much of your data. Look for a “Do Not Sell or Share My Personal Information” or “Your Privacy Choices” link in the footer.
  4. Keep unsubscribing from senders you still hear from. Privacy rights slow new lists; the unsubscribe link stops the ones already reaching you.

That last step is where the pile-up lives, and doing it by hand across dozens of senders is the tedious part. The Email Unsubscriber app scans your inbox in your browser, so your email content never leaves your device, lists every subscription sender, and dispatches one-click unsubscribes while logging each one with its date. It flags any sender still mailing you after you opted out, which is the exact record you would need if you ever report a violation. It is a one-off payment, with nothing to cancel. We never read, analyze, or monetize your email content.

New privacy laws hand you the levers. Pulling them, and cleaning out the senders already in your inbox, is what turns the rights on paper into a quieter inbox.

Frequently asked questions

What new privacy laws went into effect in 2026?

Three comprehensive state privacy laws took effect on January 1, 2026: the Indiana Consumer Data Protection Act, the Kentucky Consumer Data Protection Act, and the Rhode Island Data Transparency and Privacy Protection Act. Connecticut, Arkansas, and Utah see further privacy changes on July 1, 2026. California expanded its data-broker rules and launched a single-request deletion platform the same year.

How many US states have a privacy law in 2026?

About 20 states now have a comprehensive consumer privacy law in effect, according to MultiState's 2026 tracker. Indiana, Kentucky, and Rhode Island joined the group on January 1, 2026. There is still no single federal privacy law, so your rights depend on which state you live in and how large the company handling your data is.

Do I have to live in a certain state to have privacy rights?

For these state laws, yes. Each one protects residents of that state, so an Indiana or Kentucky resident gains rights an Alabama resident does not. Many national companies extend the same options to everyone rather than build 20 separate systems. Federal CAN-SPAM rules on unsubscribing, by contrast, protect every US recipient regardless of state.

What is a universal opt-out mechanism?

It is a browser-level signal, such as Global Privacy Control, that tells every website you visit not to sell or share your personal data or use it for targeted advertising. You set it once and it applies everywhere automatically. Oregon began requiring businesses to honor it on January 1, 2026, joining roughly a dozen states with the same mandate.

Does opting out of data sale stop marketing emails?

Not directly, but it slows the pipeline. Opting out of sale and targeted advertising keeps your email address from being passed to new marketers, so fewer fresh lists acquire you. It does not stop a sender you already subscribed to. For that you still unsubscribe, and under CAN-SPAM the sender has 10 business days to stop.

How do I delete my data from data brokers in California?

California residents can use DROP, the state's Delete Request and Opt-out Platform, which launched on January 1, 2026. One request reaches every registered data broker, over 600 of them. Data brokers must begin processing those deletion requests by August 1, 2026, and delete matching records, including your email address and the inferences built from it.

Do 2026 privacy laws replace the CAN-SPAM unsubscribe rule?

No. They add a second layer. CAN-SPAM still governs the unsubscribe link and gives senders 10 business days to honor an opt-out. The new state privacy laws govern whether your data can be sold, shared, or used for targeted ads, and give you access and deletion rights. You use unsubscribe for one sender and privacy rights for the wider data trade.

What rights do state privacy laws give me over my email address?

Your email address is personal data, so these laws cover it. In a state with a comprehensive law you can request access to what a company holds, ask it to correct or delete your information, get a copy of it, and opt out of the sale of that data and of targeted advertising. Sensitive data generally requires your opt-in consent first.