Home › Topics › data retention
U.S. AI Laws: data retention
As of 2026-08-12, AI Laws USA tracks 26 U.S. AI rules on data retention across federal, state, county, and city government. Each entry links to its official source.
Federal data retention rules (2)
-
In effect
COPPA + 2025 Rule (childrens data)
United States · Effective 2025-06-23 · 15 U.S.C. §§ 6501–6506; 16 C.F.R. Part 312
COPPA requires online services aimed at children under 13 to get verifiable parental consent before collecting kids' personal data. The 2025 rule update — fully in effect since April 22, 2026 — adds biometric identifiers (like face templates and voiceprints, which matter for AI tools), requires separate parental consent before sharing children's data for targeted advertising, and tightens data retention limits.
-
In effect
FTC HBNR Rule (AI health apps)
United States · Effective 2024-07-29 · 16 C.F.R. Part 318; 89 Fed. Reg. 47028
Health apps and connected devices — including AI-powered mental health and fitness tools — must notify users, the FTC, and (in some cases) the media within 60 days of a breach of identifiable health information. The 2024 amendments confirm that AI-generated inferences about health are covered.
State data retention rules (17)
-
In effect
CCPA/CPRA + ADMT Regulations
California · Effective 2026-01-01 · Cal. Civ. Code § 1798.100 et seq.; Cal. Code Regs. tit. 11, div. 6
California's main privacy law gives consumers rights to know, delete, correct, and opt out of the sale or sharing of their personal information. New regulations finalized in 2025 add rights around automated decision-making technology (ADMT): businesses using ADMT for significant decisions (jobs, housing, credit, healthcare) must give pre-use notice, let people opt out, and provide access to how decisions were made.
-
In effect
BIPA
Illinois · Effective 2008-10-03 · 740 ILCS 14/1 et seq.
The strongest US biometric privacy law: companies must get written consent before collecting fingerprints, face scans, voiceprints, or other biometrics, publish retention/destruction policies, and cannot sell biometric data. Individuals can sue directly and recover $1,000–$5,000 per violation, which has produced major settlements against facial recognition and AI companies.
-
In effect
Kentucky Consumer Data Protection Act
Kentucky · Effective 2026-01-01 · 2024 Ky. Acts (HB 15); KRS ch. 367
Kentucky's privacy law took effect January 1, 2026, giving residents rights to access, correct, delete, and copy their personal data, and to opt out of data sales and targeted advertising. Businesses need opt-in consent for sensitive data including biometrics.
-
In effect
RI Privacy Law (RIDTPPA)
Rhode Island · Effective 2026-01-01 · R.I. Gen. Laws § 6-48.1 (2024)
Rhode Island residents can access, correct, delete, and port their data, and opt out of targeted advertising, data sales, and profiling. The Attorney General enforces with fines up to $10,000 per violation and — unusually — no cure period.
-
In effect
Indiana Consumer Data Protection Act
Indiana · Effective 2026-01-01 · 2023 Ind. Acts P.L. 94-2023 (SB 5); I.C. 24-15-1 et seq.
Indiana's privacy law, effective January 1, 2026, gives residents rights to access, correct, delete, and port personal data, and to opt out of targeted advertising, data sales, and profiling. Enforced exclusively by the Attorney General with a permanent 30-day cure period.
-
In effect
Montana MCDPA
Montana · Effective 2025-10-01 · Mont. Code Ann. §§ 30-14-2901 et seq. (SB 384, 2023; as amended by SB 297, 2025, eff. Oct. 1, 2025)
Montana's comprehensive consumer privacy law, strengthened by 2025 amendments, gives residents rights to access, correct, delete, and opt out of data processing. The SB 297 amendment removed the 'solely automated' qualifier for profiling opt-out, meaning consumers can now opt out of any automated decision-making that involves profiling with significant effects — not just fully automated decisions.
-
In effect
Maryland Online Data Privacy Act
Maryland · Effective 2025-10-01 · 2024 Md. Laws ch. 440 (SB 541); Md. Code Ann., Com. Law §§ 14-4601–14-4626
Maryland's privacy law is stricter than most: it prohibits processing sensitive personal data unless strictly necessary for the requested service. Consumers can access, correct, delete, and port their data, and opt out of automated profiling and targeted advertising. AG enforcement began April 2026.
-
In effect
Minnesota Consumer Data Privacy Act
Minnesota · Effective 2025-07-31 · 2024 Minn. Laws ch. 123 (HF 4757); Minn. Stat. §§ 325M.01–.21
Minnesota's privacy law gives residents data rights plus something unique: the right to question automated profiling decisions with significant effects — including the right to know why the decision was made and what would change the outcome. Full AG enforcement began February 2026.
-
In effect
New Jersey Data Protection Act
New Jersey · Effective 2025-01-15 · P.L.2024, c.9 (N.J. SB 332)
New Jersey's comprehensive privacy law grants residents rights to access, correct, delete, and port personal data and to opt out of data sales and targeted advertising. Controllers must get opt-in consent for sensitive data (health, biometric, precise location) and honor universal opt-out signals since July 2025.
-
In effect
Iowa Consumer Data Protection Act
Iowa · Effective 2025-01-01 · Iowa SF 262 (2023), Iowa Code ch. 715D
Iowa's privacy law gives consumers rights to access, delete, copy, and opt out of the sale of their personal data and targeted advertising. Notably it does NOT include a profiling opt-out, making it one of the more business-friendly state privacy laws.
-
In effect
Nebraska NDPA
Nebraska · Effective 2025-01-01 · Neb. Rev. Stat. §§ 87-901 et seq. (LB 1074, 108th Leg., 2024), eff. Jan. 1, 2025
Nebraska's comprehensive consumer privacy law gives residents the right to access, correct, delete, and port their personal data and to opt out of targeted advertising, data sales, and automated profiling used in decisions with significant legal or financial effects. The Attorney General enforces with fines up to $7,500 per violation with no private right of action.
-
In effect
NH Consumer Privacy Act
New Hampshire · Effective 2025-01-01 · RSA 507-H (2024 NH SB 255)
New Hampshire residents can access, correct, delete, and port their personal data, and opt out of targeted advertising, data sales, and profiling used in solely automated decisions. Applies at low thresholds (35,000 residents), so it covers many businesses.
-
In effect
Delaware Privacy Law (DPDPA)
Delaware · Effective 2025-01-01 · 6 Del. C. § 12D-101 et seq. (2023 DE HB 154)
Delaware residents can access, correct, delete, and port their personal data, and opt out of targeted advertising, data sales, and profiling used in solely automated decisions with legal effects. Applies at low thresholds (35,000 consumers).
-
In effect
TDPSA
Texas · Effective 2024-07-01 · Tex. Bus. & Com. Code ch. 541 (HB 4, 2023)
Texans can access, correct, delete, and obtain copies of personal data held by covered businesses, and can opt out of targeted advertising, data sales, and profiling used for decisions with significant effects (like jobs, housing, or credit). Businesses must get consent for sensitive data, including biometrics.
-
In effect
My Health My Data Act
Washington · Effective 2024-03-31 · RCW ch. 19.373
A sweeping health-data privacy law covering 'consumer health data' far beyond HIPAA — including biometric data, health inferences drawn by algorithms, and reproductive health information. Companies need consent to collect or share such data, must honor deletion requests, and cannot geofence health facilities. Consumers can sue under Washington's Consumer Protection Act.
-
In effect
Guam EDPA (5 GCA Ch. 14)
Guam · Effective 2012-01-01 · 5 G.C.A. ch. 14
Guam's baseline statute on government use of personal data — predates the AI wave but is the foundation any AI system using citizen data must comply with. Governs collection, use, and protection of personal data by Guam executive-branch agencies.
-
In effect
Guam Breach Notification (9 GCA Ch. 48)
Guam · Effective 2009-01-01 · 9 G.C.A. ch. 48
Guam's data breach notification statute. Requires entities holding personal information to notify affected residents of breaches. Relevant to AI systems processing personal data because any compromise must trigger notice.
County data retention rules (6)
-
In effect
Riverside County CA Sheriff ALPR Policy & Retention
Riverside County, CA · Effective 2025-07-22 · RCSD ALPR Policy (2025) (2025-07-22)
Riverside County Sheriff's Department adopted ALPR policy aligning with California Civil Code §1798.90.5 et seq.: 90-day retention cap, documented investigative purpose for queries, audit logging, and quarterly reporting to the Board of Supervisors.
-
In effect
Ventura County CA Sheriff ALPR Policy
Ventura County, CA · Effective 2025-05-20 · VCSO ALPR Policy (2025) (2025-05-20)
Ventura County Sheriff's Office adopted ALPR policy with 90-day retention, documented investigative purpose required for queries, audit logging, and prohibition on sharing data with commercial brokers, per California Civil Code §1798.90.5.
-
In effect
Orange County CA Sheriff ALPR Use & Retention Policy
Orange County, CA · Effective 2025-04-15 · OCSD ALPR Policy (2025) (2025-04-15)
Orange County (CA) Sheriff's Department adopted ALPR governance policy with 90-day retention cap, documented investigative purpose requirement, audit logging, and quarterly reporting to the Board of Supervisors per California Civil Code §1798.90.5 et seq.
-
In effect
Loudoun County Sheriff's Office ALPR General Order 401.8
Loudoun County, VA · Effective 2025-03-24 · LCSO General Order 401
Loudoun County Sheriff's Office General Order 401.8 (Operations) governs Automated License Plate Recognition (ALPR / Flock Safety) use by LCSO personnel. Last reviewed March 24, 2025 with the next review scheduled for November 1, 2027. The order requires data-sharing among other agencies to be governed by MOUs, states that ALPR data is owned by LCSO and is not sold to third parties, and is updated to reflect VA legislative changes effective July 1, 2025.
-
In effect
Arlington County VA ACPD Automated License Plate Reader
Arlington County, VA · Effective 2024-04-01 · ACPD General Order 605 (ALPR policy) (2024-04-01)
Arlington County Police Department adopted formal ALPR governance policy with 30-day data retention limit, restricted access, audit trails, and required reasonable-suspicion or investigative purpose for queries; aligns with Virginia Code §15.2-1723.1.
-
In effect
Santa Clara County Surveillance Ordinance
Santa Clara County, CA · Santa Clara County, Cal., Ordinance Code div. A40 (NS-300.897, 2016)
Santa Clara County passed the nation's first county-level surveillance oversight law in 2016. County departments must get Board of Supervisors approval, publish a surveillance use policy, and file an impact report before acquiring surveillance technology, plus annual reports afterward. Still actively administered by the County Privacy Office.
City / local data retention rules (1)
-
In effect
New Orleans Surveillance/FR Rules
New Orleans, LA · New Orleans, La., Code ch. 147, as amended July 21, 2022
New Orleans banned facial recognition, predictive policing, and cell-site simulators in December 2020, but the council partially repealed the ban in July 2022, letting police use facial recognition (with human review and reporting) for serious violent crimes. In 2025 it emerged NOPD had received real-time facial recognition alerts from a private camera network in violation of these rules; alerts were paused in April 2025 and a proposal to authorize real-time FR was withdrawn, leaving the 2022 rules in place.