You keep seeing headlines about new privacy laws, and you want to know the part that actually reaches you: does anything change for the marketing email piling up in your inbox, and for the data that put you on those lists in the first place. In 2026 the answer is yes, on both counts.
In 2026, new comprehensive privacy laws took effect in Indiana, Kentucky, and Rhode Island on January 1, bringing the US total near 20 states. They give residents the right to access, delete, and opt out of the sale of their personal data, including the email address that feeds marketing lists.
This is an educational overview of consumer privacy law, not legal advice. For a specific situation, check the regulator or statute linked in each section or consult a lawyer in your state.
Which new privacy laws took effect in 2026?
Three states switched on comprehensive privacy laws on January 1, 2026. Each one gives residents a fresh set of data rights and puts new duties on the companies that hold their information.
- Indiana Consumer Data Protection Act. Indiana’s law tracks Virginia’s model. It covers businesses that handle the data of 100,000 or more Indiana residents, or 25,000 residents when half their revenue comes from selling data.
- Kentucky Consumer Data Protection Act. Kentucky mirrors the same thresholds and rights. Its attorney general holds exclusive enforcement power and can seek up to $7,500 per violation.
- Rhode Island Data Transparency and Privacy Protection Act. Rhode Island set the lowest bar of the three, reaching companies that handle 35,000 residents’ data, or 10,000 when a fifth of revenue comes from data sales. According to the IAPP’s 2026 overview, Rhode Island offers no cure period, so a company cannot fix a violation after the fact to escape penalty.
More arrive mid-year. According to MultiState’s 2026 tracker, Connecticut, Arkansas, and Utah all see privacy-law changes on July 1, 2026.
How many states now have a privacy law?
About 20 states now have a comprehensive consumer privacy law in effect. MultiState’s 2026 tracker counts 20 once Indiana, Kentucky, and Rhode Island join the group that already included California, Colorado, Virginia, Texas, and Oregon.
There is still no single federal privacy law covering everyone. Your rights depend on where you live and how much data the company handles. A resident of California or Kentucky can demand deletion; a resident of a state with no law has to rely on whatever the company offers voluntarily. Many national brands extend the same rights to all customers rather than run 20 separate systems, so you may get the options even outside a covered state, just without the legal force behind them.
What new rights do you actually get?
A comprehensive state privacy law gives residents a standard bundle of rights over their personal data. Your email address counts as personal data, so every right on this list applies to it.
| Right | What you can do | Why it touches your inbox |
|---|---|---|
| Access | Ask a company what data it holds on you | See if a sender bought or stored your address |
| Correct | Fix inaccurate personal data | Update a wrong record tied to your email |
| Delete | Require a company to erase your data | Cut a sender’s record at the source, not just one list |
| Portability | Get a copy of your data | Take proof of what a company held |
| Opt out of sale | Stop a company selling your data | Keep your address off new marketing lists |
| Opt out of targeted ads | Stop profiling for ad targeting | Reduce behavior-based marketing |
Sensitive data, such as precise location or health details, generally needs your opt-in consent before a company can process it at all. The deletion right is the one that changes the email math most. Unsubscribing tells one sender to stop mailing a single list. A deletion request tells the company to erase the record entirely, which stops it from mailing you again from any list and from selling the address onward.
What is a universal opt-out signal, and why does it matter for your inbox?
A universal opt-out signal is a browser setting that opts you out of data sale and targeted advertising on every site at once, without visiting each one. The best-known version is Global Privacy Control, a signal your browser or a privacy extension sends automatically in the background.
According to the Oregon Department of Justice, Oregon began requiring covered businesses to honor a universal opt-out on January 1, 2026. Oregon joins roughly a dozen states, including California, Colorado, and Connecticut, that treat the signal as a binding opt-out request. You turn it on once and it works on every covered site you visit after that.
The inbox payoff is indirect but real. When a site honors the signal and stops selling or sharing your data, your email address stops flowing to new marketers, so fewer fresh lists ever acquire you. For the full walkthrough of turning it on, see our guide to Global Privacy Control.
What changed with California data brokers in 2026?
California went after the middlemen. Data brokers collect and resell personal information, including email addresses, which is how a company you never contacted ends up mailing you. Two 2026 changes tighten the rules on them.
First, California expanded what brokers must disclose when they register with the state, adding sensitive categories such as immigration status, union membership, and sexual orientation. Second, and more useful for you, California launched DROP, the Delete Request and Opt-out Platform.
According to the California Privacy Protection Agency, a California resident can file one DROP request and have it reach every registered data broker, more than 600 of them, instead of chasing each company separately. The platform opened to residents on January 1, 2026, and data brokers must begin processing those deletion requests by August 1, 2026, erasing matching records including the inferences built on top of them. Miss that, and a broker faces $200 per request per day in penalties. Deleting your address from the broker layer cuts off a major source of the promotional mail you never asked for.
How do these laws touch your marketing email specifically?
These laws work on the supply side of your inbox, upstream of the individual unsubscribe link. Three mechanisms matter for email.
Opt out of sale and sharing keeps your address from being passed to new marketers, so the flow of fresh senders slows. The deletion right lets you force a company to erase your record, which is stronger than unsubscribing because it removes you from every list the company runs, not just the one that mailed you. Data-broker deletion, through a tool like California’s DROP, pulls your address out of the resale market that seeds new lists in the first place.
None of this replaces the unsubscribe button for a sender you already hear from. The two systems cover different problems, and the fastest path still depends on which one you are facing. Our survey of unsubscribe laws by country maps the opt-out rules that sit alongside these privacy laws.
Do these laws replace the CAN-SPAM unsubscribe rule?
No. CAN-SPAM still governs the unsubscribe link on every commercial email sent to a US recipient, and it still gives a sender 10 business days to honor your opt-out. The new state privacy laws sit next to it, not on top of it.
The division is clean once you see it. You use the unsubscribe link when a specific sender keeps mailing you, and CAN-SPAM backs that request with FTC penalties. You use your privacy rights when you want to stop your data being sold, profiled, or held at all. If a sender ignores a clean unsubscribe, that is a CAN-SPAM problem, and our guide on your rights when unsubscribe fails walks through documenting and reporting it.
What should you do now?
Pick the tools that match your state and your goal. The steps below move from easiest to most thorough.
- Turn on Global Privacy Control. Enable it in your browser settings or add a privacy extension. In a covered state, every site that honors it treats your visit as an opt-out of sale and targeted advertising.
- Use California’s DROP if you are a resident. File one deletion request to reach every registered data broker at once.
- Exercise access and deletion rights with companies that hold too much of your data. Look for a “Do Not Sell or Share My Personal Information” or “Your Privacy Choices” link in the footer.
- Keep unsubscribing from senders you still hear from. Privacy rights slow new lists; the unsubscribe link stops the ones already reaching you.
That last step is where the pile-up lives, and doing it by hand across dozens of senders is the tedious part. The Email Unsubscriber app scans your inbox in your browser, so your email content never leaves your device, lists every subscription sender, and dispatches one-click unsubscribes while logging each one with its date. It flags any sender still mailing you after you opted out, which is the exact record you would need if you ever report a violation. It is a one-off payment, with nothing to cancel. We never read, analyze, or monetize your email content.
New privacy laws hand you the levers. Pulling them, and cleaning out the senders already in your inbox, is what turns the rights on paper into a quieter inbox.
