惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
博客园 - 司徒正美
博客园 - 【当耐特】
爱范儿
爱范儿
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
人人都是产品经理
人人都是产品经理
雷峰网
雷峰网
酷 壳 – CoolShell
酷 壳 – CoolShell
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
大猫的无限游戏
大猫的无限游戏
月光博客
月光博客
宝玉的分享
宝玉的分享
V
V2EX
S
SegmentFault 最新的问题
V
Visual Studio Blog
阮一峰的网络日志
阮一峰的网络日志
Martin Fowler
Martin Fowler
Jina AI
Jina AI
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园_首页
L
LangChain Blog
D
Docker
腾讯CDC

Privacy & Cybersecurity Law Blog

EU Cyber Resilience Act Reporting Obligations Take Effect for Manufacturers Delaware Expands State Privacy Law Dutch DPA Fines Uber Over Automated Decisions Affecting Drivers European Commission Designates ChatGPT, Reddit, and Roblox Under the Digital Services Act China Issues New Rules on Cyberspace Security Inspection Court Approves Meta Settlement With 29 States Over Alleged Harms to Children and Teens FTC Proposes Enforcement Policy Statement on Personalized Pricing New Jersey Enacts the Kids Code Act with Privacy-by-Default and Safety-by-Design Obligations White House Memorandum Establishes Framework for Government-Directed Private-Sector Cyber Operations FTC, California and Utah Sue Telehealth Company Hims & Hers for Deceptive and Unlawful Privacy Practices CalPrivacy Settles with Two Data Brokers over Registration Failures and Privacy Violations New York Attorney General Releases Final Rules for SAFE for Kids Act EDPB Adopts Guidelines on Anonymous Data, Web Scraping, and Blockchain China Publishes Official Q&A on Administrative Policies for Cross-Border Data Transfers Hawaii Enacts AI Companion Disclosure and Safety Law EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence CNIL Issues FAQs on Recommendation for Tracking Pixels in Emails European Commission Issues Guidance on the Cyber Resilience Act European Commission Issues EU AI Act Transparency Guidelines EU Digital Omnibus on AI Enters Into Force Connecticut AG Leads Multistate Settlement With 23andMe Over 2023 Data Breach CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale and Licensing Restrictions CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026 Illinois Governor Signs Frontier AI Model Law New Hampshire Amends the NHDPA to Prohibit the Sale of Children’s Personal Data Canada’s Proposed Social Media Ban for Children and Chatbot Regulation: Bill C-34’s Impact on Platforms European Commission Unveils Cybersecurity and AI Action Plan European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays EDPB Opens Public Consultation on New Personal Data Breach Notification Template
Louisiana Enacts Comprehensive Consumer Privacy Law
2026-06-12 · via Privacy & Cybersecurity Law Blog

Louisiana recently enacted Senate Bill 386, the Louisiana Data Privacy Act (“LDPA”), becoming the 22nd U.S. state to adopt a comprehensive consumer data privacy law. The LDPA follows the now-familiar controller/processor and consumer-rights framework seen in many state comprehensive data privacy laws, with certain distinctions.

Scope

The LDPA applies to any person or entity that does business in Louisiana and satisfies at least one of the following thresholds:

  • has annual gross revenues exceeding $25 million;
  • annually buys, receives, “sells” (for monetary or other valuable consideration), or shares for commercial purposes the personal data of 75,000 or more consumers, households, or devices; or
  • derives 50% or more of its annual revenues from selling consumers’ personal data.

Notably, unlike many other state comprehensive data privacy laws, the LDPA does not apply to entities that merely “target” Louisiana residents with their products and services. Rather, it applies to entities that ”do business” in the state, which may narrow the law's reach.

Like other state comprehensive data privacy laws, the LDPA exempts certain entities and data from its scope. Exempt entities include state agencies, GLB-regulated financial institutions, HIPAA-covered entities and business associates, nonprofits and institutions of higher education. Data-level exemptions include HR-related data, PHI and NPI.

Key Obligations

The LDPA imposes several obligations on controllers, including:

  • Privacy Notice: Controllers must provide a reasonably accessible and clear privacy notice that discloses the categories of personal data (including sensitive data) processed; the purposes of processing; the categories of personal data sold to third parties; the categories of third parties receiving the data; and the methods for submitting consumer rights requests.
  • Data Minimization: Controllers must limit the collection of personal data to what is adequate, relevant and reasonably necessary for the disclosed purposes.
  • Security Safeguards: Controllers must implement and maintain reasonable administrative, technical and physical safeguards appropriate to the volume and nature of the data.
  • Vendor Contracts: Contracts between controllers and processors must include the nature and purpose(s) of processing; the types of personal data subject to processing; the duration of processing; the rights and obligations of both parties; and requirements for confidentiality, data return/deletion, audit cooperation and sub-processor oversight.
  • Data Protection Assessments: Controllers must conduct and document data protection assessments for higher-risk processing activities, including targeted advertising, the sale of personal data, profiling that presents a foreseeable risk of harm and the processing of sensitive data.
  • Sensitive Data: Controllers must obtain prior consent to process sensitive data.
    • Notably, unlike other state privacy laws, controllers that derive 50% or more of their annual revenues from the sale of personal data must obtain consumers’ separate consent to sell sensitive data.
  • Sale of Sensitive or Biometric Data Notice:
    • Controllers that sell sensitive personal data or biometric data must post a conspicuous notice stating “NOTICE: We may sell your sensitive personal data” or “NOTICE: We may sell your biometric personal data,” as applicable.

Consumer Rights

The LDPA provides Louisiana consumers the right to:

  • confirm whether the controller is processing their personal data;
  • access their personal data, including in a portable copy (if available in a digital format);
  • correct inaccuracies in their personal data;
  • delete their personal data;
  • opt out of (i) targeted advertising, (ii) the sale of personal data, and (iii) profiling that produces a legal or similarly significant effect (consumers may designate an authorized agent, including through a technology-based opt-out signal that complies with the law’s requirements (e.g., Global Privacy Control)); and
  • appeal the denial of a privacy request.

Controllers must respond to privacy requests within 45 calendar days of receipt, with a single 45-day extension available.

Effective Date and Enforcement

The LDPA will take effect January 1, 2027. The Louisiana Attorney General has exclusive enforcement authority. Violations of the law constitute unfair and deceptive trade practices. A 30-day cure period applies from January 1, 2027 through July 31, 2027, after which the cure period expires.