Three New State Privacy Laws Start January 1: An Ad Ops Checklist
Indiana, Kentucky and Rhode Island privacy laws take effect January 1, alongside new CCPA risk assessment rules. What changes for ad-supported sites, with extra care for health publishers.
On January 1, three more US states join the list with comprehensive consumer privacy laws in force: Indiana, Kentucky and Rhode Island. On the same day, amended California regulations kick in that add formal risk assessment obligations for businesses that sell or share personal information. None of this is a cliff for publishers who have been keeping up. But each new law is another place where a stale consent setup can turn into a compliance gap, and the patchwork keeps getting harder to manage by hand.
This is not legal advice. Talk to your counsel about your specific obligations. What follows is the ad operations view: what these laws touch in your stack and what to check before the calendar flips.
What takes effect
Indiana and Kentucky
Both follow the familiar Virginia-style model. They apply to businesses that control or process personal data of at least 100,000 state consumers a year, or 25,000 consumers if more than half of gross revenue comes from selling personal data. Consumers get rights to access, correct, delete and port their data, plus the right to opt out of targeted advertising, the sale of personal data and certain profiling. Processing sensitive data requires opt-in consent. Enforcement sits with the state attorney general, and both laws include a 30-day cure period, according to a summary from TrustArc.
Rhode Island
Rhode Island's thresholds are lower: 35,000 consumers, or 10,000 consumers if more than 20 percent of revenue comes from data sales. That brings more mid-sized publishers into scope than the Indiana and Kentucky laws do. The same core rights apply, including opt-outs for targeted advertising and sales, and the law calls for data protection assessments for high-risk processing. Penalties can reach $10,000 per violation.
California's new regulations
The California Privacy Protection Agency's amended regulations take effect January 1, 2026. The piece most relevant to ad-supported sites is the risk assessment requirement. The regulations were finalized in September, and selling or sharing personal information is one of the triggers. Assessments conducted in 2026 and 2027 are due to the agency by April 1, 2028. Separate rules on automated decision-making technology carry a January 1, 2027 compliance date, and cybersecurity audit submissions are phased in from 2028 based on company revenue.
In practical terms: if your site shares data with ad tech partners for cross-context behavioral advertising, which describes most header bidding setups, you should expect to document that processing in a risk assessment during 2026.
What this means inside the ad stack
Most of the work is making sure the signals you already send are correct for more states.
1. Your consent platform's geo list
Check whether your consent management platform treats Indiana, Kentucky and Rhode Island visitors as opt-out jurisdictions starting January 1. Many platforms update automatically; some require you to enable new regions. Load your site from each state (a VPN or your CMP's preview tool) and confirm the right notice and "do not sell or share" or "opt out of targeted advertising" link appears.
2. The privacy signal your wrapper passes
If you use the IAB Tech Lab Global Privacy Platform, confirm your CMP is emitting the right section strings for the new states, and that Prebid's consent management module is configured to read GPP and pass it to bidders. A correct banner with a broken signal is the worst of both worlds: the user opted out, but your bid requests say otherwise.
3. Universal opt-out signals
California, Colorado and several other states require businesses to honor browser-level opt-out preference signals such as Global Privacy Control. Make sure GPC is detected and translated into an opt-out in the signals you send to partners, and test it with a browser that has GPC enabled.
4. Vendor list and contracts
Every new law is a prompt to review who receives data from your pages. Remove bidders and pixels that no longer earn their place. Each extra partner is extra processing you have to justify, disclose and, in California, assess.
5. Privacy policy language
Update your privacy notice to list the rights available to residents of the new states and how to exercise them. Make sure the opt-out request path actually works and that someone owns responding to requests within the statutory windows.
Extra care for health and wellness publishers
Health content raises the stakes. Several state laws treat health-related data as sensitive, which means opt-in consent rather than opt-out. What counts as health data varies by state, and some laws reach inferences drawn from browsing, not just information a user types in. Washington's My Health My Data Act, in force since 2024, is the most expansive example.
Maryland is next on the horizon. Its law has been in effect since October 1, 2025, but it applies to processing activities from April 1, 2026. It sets a lower applicability threshold than most states, adds strict data minimization rules, and prohibits the sale of sensitive data.
For health and wellness sites, practical steps include:
- Reviewing whether page-level contextual categories passed in bid requests could reveal sensitive conditions when combined with user identifiers
- Limiting or disabling user ID modules on sensitive sections of the site
- Leaning on contextual targeting for condition-specific content rather than audience segments
- Asking each demand partner how they handle sensitive-category inventory
A simple January 1 checklist
- Confirm your CMP covers Indiana, Kentucky and Rhode Island.
- Test opt-out flows and GPC handling end to end, from banner to bid request.
- Verify your Prebid consent configuration reads and forwards GPP.
- Prune vendors you do not need.
- Update your privacy policy.
- Start a written inventory of your ad-related data sharing to support 2026 risk assessments.
- Flag sensitive content sections for special handling.
The bigger picture
The US still has no federal privacy law, so publishers are managing a growing list of state rules with overlapping but not identical requirements. The sustainable approach is to design for the strictest common denominator, keep the signal chain from consent banner to bid request tested, and treat each new effective date as a checkpoint rather than a fire drill.
A well-run header bidding setup makes this easier: fewer partners, clean consent modules, and logs that show exactly what signal went out with each request.
Related Articles
July's Privacy Law Changes: A Checklist for Health and Finance Publishers
Connecticut, Arkansas and Virginia changes took effect July 1, and IAB Tech Lab just proposed GPP updates. What health, finance and other sensitive-content publishers should check.
Privacy Sandbox Is Winding Down in Chrome. Time to Clean Up Your Wrapper
Chrome 150 is now rejecting Protected Audience calls as Google retires most Privacy Sandbox APIs. Here is what to remove from your ad stack and what stays the same.
July 1 Privacy Deadlines: Connecticut and Arkansas Tighten Teen Ad Rules
On July 1, Connecticut's amended privacy law and Arkansas's children's and teens' privacy law take effect, both restricting targeted ads to minors. What publishers should change first.