Key Takeaways
- Louisiana became the 22nd U.S. state to enact an extensive consumer data privacy law, Senate Bill 386 (SB), to take effect January 1, 2027.
- The Louisiana Data Privacy Act (LDPA) provides Louisiana consumers who meet explicit thresholds with specific privacy rights.
- Businesses that meet the thresholds have the right to access, amend, delete, and opt out of data sales and certain profiling practices.
- Louisiana’s attorney general has sole enforcement authority.
What Happened
On May 29th, 2026, Louisiana enacted Senate Bill 386, the Louisiana Data Privacy Act (LDPA), becoming the 22nd and most recent state to implement an extensive, comprehensive consumer data privacy law. This law applies to businesses, also known as controllers or processors, that meet certain thresholds and those that buy, receive, or “sell” and share any personal data.
The bill’s purpose is to ensure that consumers have rights regarding their privacy and have more transparency about how their data is being used and gathered and if it will be shared. Additionally, if consumers submit privacy requests to controllers, the bill also states that requests must be responded to within 45 calendar days of receipt, with a single 45-day extension available. This also means that covered businesses must obtain consent before any processing of data takes place in order to comply with data minimization and transparency requirements.
Privacy and Governance Concerns
The LDPA applies to any person or entity that conducts business in Louisiana and meets one of the thresholds listed, such as having annual gross revenues exceeding $25 million, obtaining personal data, specifically 75,000 or more customers for commercial purposes, and obtaining 50% or more of its annual revenue from selling customers’ personal data. However, certain entities are exempt from LDPA, such as GLB-regulated financial institutions, HIPAA-covered entities and business associates, nonprofits, and institutions of higher education.
Further, the LDPA notes controllers must follow a set of requirements that include providing clear privacy notices, including sensitive data notices, data minimization, security safeguards, vendor contracts, and data protection assessments. These guidelines are adopted from the California Consumer Privacy Act (CCPA), including the use of the term “personal information,” rather than the LDPA’s defined term of “personal data.”
Why It Matters / Policy Considerations
The LDPA bill requires organizations, specifically those who collect, use, and share personal data, to ensure proper data protection measures are in place. Measures that will be in place include maintaining safeguards in place, following data protection assessments, and granting consumers transparent privacy notices. This allows consumers to have more control and transparency with their personal data.
Although this is beneficial for allowing more oversight and control, the question of whether these measures are sufficient enough still remains. The other part of the law states that the Louisiana Attorney General has exclusive enforcement authority, which prohibits a consumer from personally suing a company for violating the law.
Moreover, the law doesn’t take effect until January 1, 2027, which allows organizations to prepare by assessing their data collection practices and reviewing current procedures. Nevertheless, proper oversight will depend on regulatory enforcement and organizational compliance. With more efficient assessment techniques, regular audits, and regulatory practices, organizations can remain accountable.




