What data privacy rights do I have in the US?
short answer
The US has no single federal privacy law, so your rights depend mainly on your state. Roughly twenty states now have comprehensive privacy laws giving residents the right to know what data a company holds, to correct it, to delete it, to obtain a copy, and to opt out of sale or targeted advertising. If you live in a state without one, you still have sector-specific protections — health, financial, credit, children's data — and the practical option of asking anyway, since many companies apply one process nationwide.
The rights that recur
State laws differ in detail, but the same rights appear in nearly all of them:
| Right | What you can ask for |
|---|---|
| Know / access | What personal data is held about you, and often its sources |
| Correct | Fix inaccurate data |
| Delete | Remove data, subject to exemptions |
| Portability | A copy in a usable format |
| Opt out of sale or sharing | Stop it being sold or used for targeted advertising |
| Limit sensitive data use | Restrict processing of precise location, health, biometrics and similar |
| Non-discrimination | Not be charged more or given worse service for exercising a right |
California adds the right to correct and to limit sensitive personal information. Several states add an appeal right if a request is refused.
If your state has no comprehensive law
You are not without protection:
- Health data — HIPAA where a covered entity holds it (what PHI is), and the FTC’s Health Breach Notification Rule for many apps that fall outside HIPAA
- Financial data — the Gramm-Leach-Bliley Act
- Credit data — the Fair Credit Reporting Act, including a right to dispute
- Children’s data — COPPA
- Calls and texts — the TCPA
- Unfair or deceptive practices — Section 5 of the FTC Act, which the FTC has used extensively in privacy enforcement
And a practical point that gets overlooked: many national companies operate one privacy process for everyone, because maintaining fifty is harder than maintaining one. Ask, even if you cannot compel. A surprising proportion comply.
How to actually exercise a right
- Find the privacy contact in the company’s privacy policy — usually a form, an email, or a toll-free number.
- Be specific. “Please delete all personal data you hold about me and confirm when this is complete.”
- Verify proportionately. They may reasonably ask you to prove who you are. They should not need your passport for a request tied to an account email.
- Record the date. Deadlines are typically 45 days in US states, one month under GDPR. See what a DSAR is.
- Escalate. Your state attorney general takes complaints. So does the FTC.
What deletion does not do
A deletion request removes data the company holds going forward. It does not:
- Retrieve data already sold or shared with third parties — you generally have to ask each of them separately
- Erase records the company must keep by law, such as transaction or tax records
- Undo a disclosure that already happened
This is why the moment of collection matters more than any later request. The most effective privacy decision is the one made before you hand something over, not the one made afterwards.
General information, not legal advice. State laws change frequently; check current requirements for your state.
people also ask this as
- Do I have privacy rights if my state has no privacy law?
- How do I stop companies selling my data?
- What rights does the CCPA give me?
- Can I make a company delete my data?
keep reading
Last updated August 2026. This is general information, not legal advice — privacy law changes often and turns on specifics. For your own situation, talk to counsel.