Skip to content

Usercentrics blog

Dive into our blog articles for insights on data privacy, product news, and regulatory updates. Discover trends in privacy-led marketing, and explore tools and strategies to optimize user consent and increase revenue.
Article
GDPR exemptions are specific circumstances in which organizations may be excused from certain requirements under the law. This guide explains what those scenarios are, which obligations may still apply, and when an organization may be able to rely on its legitimate interests.
Read more
Article
The Vermont Data Privacy and Online Surveillance Act (VDPOSA) makes Vermont the 23rd U.S. state with a comprehensive privacy law. This guide covers applicability thresholds, consumer rights, the AI training disclosure requirement, opt-out preference signals, and enforcement, with comparisons to the models in effect in other states.
Read more
Article
The Connecticut Data Privacy Act (CTDPA) governs how businesses collect, process, and sell Connecticut residents’ personal data. This guide covers applicability thresholds, sensitive data categories, consumer rights, and enforcement, including the July 2026 amendments (Public Act 25-113) and SB 4, which add profiling rights, a geolocation sale ban, and new disclosure requirements for businesses.
Read more
Article
Read more
Article
Read more
Article
For companies doing business with residents of California, CCPA and CPRA compliance are required. Here’s how to protect your business.
Read more
Article
The Alabama Personal Data Protection Act (APDPA), enacted through HB 351 in April 2026, establishes consumer rights over personal data and corresponding obligations for businesses processing data of Alabama residents. The law takes effect May 1, 2027 and includes notable distinctions around its applicability thresholds, sale definition, consent revocation, teen data protections, and cure period.
Read more
Article
The Virginia Consumer Data Protection Act was the second US state-level privacy law passed, in effect from January 1, 2023. It establishes consumers’ rights and companies’ responsibilities, and has been influential over subsequent data privacy laws passed in other states.
Read more
Article
The Oklahoma Consumer Data Privacy Act takes effect January 1, 2027, bringing opt-out requirements for data sales and targeted advertising, affirmative consent for sensitive data, and AG-only enforcement with a permanent cure period. Oklahoma’s obligations closely track Virginia and Texas frameworks—but its narrower “sale” definition and absence of GPC support create specific operational considerations to address before the effective date.
Read more
Article
The California Privacy Protection Agency, now publicly known as CalPrivacy, is California’s privacy watchdog. The Agency has broad powers to audit businesses, enforce privacy law, and shape regulations. This article explains what it does, why it matters, and what businesses need to know to avoid penalties and fines as enforcement ramps up.
Read more
Article
California’s privacy laws set a high bar with obligations for businesses that handle consumer data. This guide covers everything your CCPA/CPRA privacy policy must include, making sure it stays up to date, and what it takes to stay on the right side of the enforcement.
Read more
Article
California’s Age-Appropriate Design Code Act (CAADC) brings core obligations that include privacy by default, data minimization, dark pattern restrictions, and impact assessments for children’s data. Businesses that handle data from minors need to understand what the CAADC requires, where it stands legally, and what companion obligations are already in force.
Read more
Stay in the loop

Join our growing community of data privacy enthusiasts now. Subscribe to the Usercentrics newsletter and get the latest updates right in your inbox.