🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
LA · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 9 sources retrieved model claude-sonnet-5 ·

Laos

LA schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 25 claims · 9 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
25Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive omnibus statute exists but is not yet effective (1 Jan 2027); regulator capacity/registration regime unconfirmed.

Primary frameworkLouisiana Data Privacy Act (SB 386, Title 51 Ch. 20-B)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberComprehensive omnibus statute exists but is not yet effective (1 Jan 2027); regulator capacity/registration regime unconfirmed.

Sub-modules (5)

Regulator And AuthorityGreen

Enforcement authority for the LDPA and for the state's breach-notification law is held exclusively by the Louisiana Attorney General.

Claims: CLM-LA-1a2b3c4d, CLM-LA-2b3c4d5e

Act And InstrumentsGreen

Primary instrument is SB 386 (LDPA), creating Chapter 20-B of Title 51; the pre-existing Database Security Breach Notification Law (La. R.S. 51:3071 et seq.) remains in force alongside it.

Claims: CLM-LA-3c4d5e6f, CLM-LA-4d5e6f7a

Material ScopeAmber

The LDPA regulates the collection, use, and sale of personal data by controllers/processors doing business in Louisiana that meet statutory thresholds.

Claims: CLM-LA-5e6f7a8b

Territorial ScopeAmber

Applies to controllers and processors that conduct business in Louisiana or produce products/services targeted to Louisiana residents and meet the revenue/volume thresholds, consistent with the extraterritorial approach of other US state comprehensive laws.

Claims: CLM-LA-5e6f7a8b

Regulator Registration And FilingRed

No controller/processor registration or filing obligation with the Attorney General has been identified in the LDPA or in secondary guidance reviewed.

Absence provenance: not recorded. Searched: not recorded.

Category narrative90 words

Louisiana has moved from an unregulated-gap consumer-privacy posture to a hybrid regime: the Louisiana Data Privacy Act (LDPA), enacted via Senate Bill 386 and signed into law on 29 May 2026, creates a new Chapter 20-B of Title 51 of the Louisiana Revised Statutes and establishes a comprehensive consumer data-privacy framework effective 1 January 2027, sitting alongside pre-existing sectoral instruments (breach notification law, student-data law, insurance data-security provisions, and children's online-safety acts). Enforcement of both the LDPA and the state's breach-notification statute is vested exclusively in the Louisiana Attorney General.

Sources and claims (5)
  1. ConfirmedDataGuidanceEnforcement of the Louisiana Data Privacy Act is granted exclusively to the Louisiana Attorney General, with violations classified as unfair or deceptive trade practices.
  2. ConfirmedDataGuidanceThe Louisiana Attorney General is responsible for enforcing the state's breach-notification requirements under La. R.S. 51:3071 et seq. and Title 16 of the Louisiana Administrative Code.
  3. ConfirmedDataGuidanceSenate Bill 386, signed on 29 May 2026, establishes the Louisiana Data Privacy Act, a comprehensive consumer data-privacy framework regulating collection, use and sale of personal data, effective 1 January 2027.
  4. ConfirmedDataGuidanceThe LDPA bill creates a new Chapter 20-B of Title 51 of the Louisiana Revised Statutes.
  5. ConfirmedInternational Association of Privacy ProfessionalsThe LDPA applies to businesses earning more than USD 25 million in revenue and those processing the personal data of more than 75,000 people, or deriving more than 50% of revenue from the sale of personal data.

#

Consent thresholds for sensitive data are documented; a GDPR-style enumerated lawful-bases regime and pseudonymisation/anonymisation safe-harbour provisions were not located in available sources.

Primary frameworkLouisiana Data Privacy Act (SB 386, Title 51 Ch. 20-B)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberConsent thresholds for sensitive data are documented; a GDPR-style enumerated lawful-bases regime and pseudonymisation/anonymisation safe-harbour provisions were not located in available sources.

Sub-modules (4)

Lawful BasesAmber

The LDPA does not use a GDPR-style enumerated lawful-bases list; general processing is permitted subject to consumer opt-out and notice obligations, with consent required only for sensitive categories.

Claims: CLM-LA-6f7a8b9c

Special CategoriesGreen

Sensitive data categories under the LDPA include health, biometric, genetic, and children's data, all of which require consumer consent to process.

Claims: CLM-LA-7a8b9c0d

Pseudonymisation And AnonymisationRed

No explicit pseudonymisation or anonymisation safe-harbour provisions were located for the LDPA in sources reviewed.

Absence provenance: not recorded. Searched: not recorded.

Category narrative39 words

The LDPA follows the notice-and-opt-out model typical of US state comprehensive privacy statutes rather than an enumerated GDPR-style lawful-bases list; however it imposes an affirmative consent requirement for processing of sensitive/special-category data, including health, biometric, genetic, and children's data.

Sources and claims (2)
  1. ProbableDataGuidanceThe LDPA establishes controller and processor obligations including data minimization and purpose limitation as general processing constraints, rather than an enumerated lawful-bases list.
  2. ConfirmedDataGuidanceThe LDPA requires consumer consent for processing sensitive data, including health, biometric, genetic, and children's data.

#

Core rights confirmed; deadline specifics unconfirmed pending primary statutory text review.

Primary frameworkLouisiana Data Privacy Act (SB 386, Title 51 Ch. 20-B)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberCore rights confirmed; deadline specifics unconfirmed pending primary statutory text review.

Sub-modules (5)

Access RightGreen

Consumers may access their personal data held by controllers under the LDPA.

Claims: CLM-LA-8b9c0d1e

Rectification And ErasureGreen

Consumers may correct and delete their personal data under the LDPA.

Claims: CLM-LA-8b9c0d1e

Restriction And ObjectionGreen

Consumers may opt out of targeted advertising and the sale of personal data under the LDPA.

Claims: CLM-LA-9c0d1e2f

Data PortabilityGreen

Consumers may obtain a portable copy of their personal data under the LDPA.

Claims: CLM-LA-8b9c0d1e

Deadlines And Response WindowsRed

No specific statutory response-window (e.g., number of days for controller response) was confirmed in the sources reviewed for the LDPA.

Absence provenance: not recorded. Searched: not recorded.

Category narrative40 words

The LDPA grants consumers rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising and sale of personal data. Specific statutory response-window lengths were not confirmed in sources reviewed.

Sources and claims (2)
  1. ConfirmedDataGuidanceIndividuals can access, correct, delete, and obtain a portable copy of their personal data under the Louisiana Data Privacy Act.
  2. ConfirmedDataGuidanceIndividuals can opt out of targeted advertising and data sales under the Louisiana Data Privacy Act.

#

Security and breach-notification duties well evidenced; DPIA trigger language is probable but truncated in sources; DPO/ROPA/retention specifics unconfirmed.

Primary frameworkLouisiana Data Privacy Act (SB 386, Title 51 Ch. 20-B); Database Security Breach Notification Law (La. R.S. 51:3071 et seq.)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberSecurity and breach-notification duties well evidenced; DPIA trigger language is probable but truncated in sources; DPO/ROPA/retention specifics unconfirmed.

Sub-modules (7)

Accountability And DpiaAmber

Higher-risk processing activities such as targeted advertising, sale of personal data, and profiling with foreseeable consumer harm are treated as heightened-risk under the LDPA, consistent with a data-protection-assessment trigger seen in peer state laws, though the exact assessment obligation text was truncated in sources reviewed.

Claims: CLM-LA-0d1e2f3a

Dpo RequirementsRed

No DPO appointment threshold was identified for the LDPA in sources reviewed.

Absence provenance: not recorded. Searched: not recorded.

Ropa RequirementsRed

No records-of-processing-activities obligation was identified for the LDPA in sources reviewed.

Absence provenance: not recorded. Searched: not recorded.

Joint Controller ArrangementsAmber

The LDPA imposes controller and processor obligations, but specific joint-controller contractual provisions were not detailed in sources reviewed.

Claims: CLM-LA-1e2f3a4b

Security MeasuresGreen

Controllers/processors must implement reasonable security safeguards under the LDPA.

Claims: CLM-LA-2f3a4b5c

Breach NotificationGreen

Louisiana's Database Security Breach Notification Law (La. R.S. 51:3071 et seq. and La. Admin. Code Title 16, Ch. 7) requires notification of data breaches, enforced by the Attorney General.

Claims: CLM-LA-3a4b5c6d

Retention And DisposalRed

No specific retention-limitation or disposal-duty provision was identified for the LDPA in sources reviewed.

Absence provenance: not recorded. Searched: not recorded.

Category narrative62 words

The LDPA imposes data minimization, purpose limitation, and reasonable security safeguard duties on controllers/processors, and higher-risk processing activities (targeted advertising, sale of personal data, profiling with foreseeable consumer harm, and sensitive-data processing) appear to trigger heightened obligations. Louisiana's pre-existing Database Security Breach Notification Law (La. R.S. 51:3071 et seq.) independently governs breach notification duties. DPO appointment and ROPA obligations were not confirmed.

Sources and claims (4)
  1. ProbableDataGuidanceHigher-risk processing activities such as targeted advertising, the sale of personal data, and profiling with foreseeable consumer harm are subject to heightened obligations under the Louisiana Data Privacy Act.
  2. ConfirmedDataGuidanceThe Louisiana Data Privacy Act includes controller and processor obligations covering data minimization, purpose limitation, security safeguards, and clear privacy notices.
  3. ConfirmedDataGuidanceBusiness obligations under the Louisiana Data Privacy Act require data minimization, purpose limitation, and reasonable security safeguards.
  4. ConfirmedDataGuidanceLouisiana requires breach notification pursuant to La. R.S. 51:3071 et seq. and Title 16, Chapter 7 of the Louisiana Administrative Code.

#

No comprehensive cross-border transfer regime exists in Louisiana or at US federal level for general commercial data.

Traffic-light rationale — RedNo comprehensive cross-border transfer regime exists in Louisiana or at US federal level for general commercial data.

Sub-modules (6)

Transfer MechanismsRed

No transfer-mechanism regime identified.

Absence provenance: not recorded. Searched: not recorded.

Adequacy ReceivedRed

Not applicable; no adequacy-determination framework exists for US states.

Absence provenance: not recorded. Searched: not recorded.

Adequacy GrantedRed

Not applicable; Louisiana does not grant adequacy determinations.

Absence provenance: not recorded. Searched: not recorded.

Sccs And BcrsRed

No SCC/BCR uptake or equivalent mechanism identified.

Absence provenance: not recorded. Searched: not recorded.

Transfer Impact AssessmentRed

No TIA requirement identified.

Absence provenance: not recorded. Searched: not recorded.

Data LocalisationRed

No data-localisation mandate identified for Louisiana.

Absence provenance: not recorded. Searched: not recorded.

Category narrative50 words

No cross-border transfer mechanism, adequacy determination, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate was identified for Louisiana. Consistent with the US federal/state patchwork, there is no US analogue to GDPR Chapter V transfer restrictions at the state level; the LDPA's scope is domestic personal-data processing rather than cross-border transfer governance.

#

Education and insurance overlays evidenced; other sectoral overlays unconfirmed at state level.

Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberEducation and insurance overlays evidenced; other sectoral overlays unconfirmed at state level.

Sub-modules (7)

Financial Sector OverlayRed

No Louisiana-specific financial-sector data-privacy overlay beyond federal GLBA was identified.

Absence provenance: not recorded. Searched: not recorded.

Health Sector OverlayRed

No Louisiana-specific health-sector overlay beyond federal HIPAA was identified.

Absence provenance: not recorded. Searched: not recorded.

Telecoms And EprivacyRed

No Louisiana-specific telecoms/eprivacy overlay identified.

Absence provenance: not recorded. Searched: not recorded.

Employment DataRed

No Louisiana-specific employment-data overlay identified.

Absence provenance: not recorded. Searched: not recorded.

Credit And ScoringRed

No Louisiana-specific credit-scoring overlay identified beyond federal FCRA.

Absence provenance: not recorded. Searched: not recorded.

EducationAmber

Louisiana previously passed a highly restrictive student-data-privacy law prohibiting districts from sharing student PII with any entity, including the state, without parental consent.

Claims: CLM-LA-4b5c6d7e

InsuranceAmber

A Louisiana Insurance Data Security Law reference (La. R.S. Title 22) was located in legal-research indices, but detailed substantive content was not retrievable from the sources reviewed.

Claims: CLM-LA-5c6d7e8f

Category narrative62 words

Louisiana layers sector-specific overlays atop the incoming LDPA: a legacy student-data-privacy law restricting district sharing of student PII without parental consent, and an insurance data-security statute referenced in Title 22 of the Louisiana Revised Statutes. Financial, health, telecoms/eprivacy, credit-scoring, and general employment-data overlays specific to Louisiana were not confirmed in sources reviewed (federal GLBA/HIPAA/FCRA overlays apply by default at the federal level).

Sources and claims (2)
  1. ProbableInternational Association of Privacy ProfessionalsLouisiana previously enacted a student data privacy law which prohibits districts from sharing PII with any entity, including the state, without parental consent.
  2. UncertainState of Louisiana / DataGuidance legal research repositoryLouisiana Revised Statutes Title 22 contains an insurance data security provision (referenced at La. R.S. §22:2504), though its full substantive scope could not be confirmed from available secondary sources.

#

Opt-out and cross-context advertising provisions confirmed; dark-patterns, cookies, clean-rooms, and direct-marketing specifics unconfirmed.

Primary frameworkLouisiana Data Privacy Act (SB 386, Title 51 Ch. 20-B)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberOpt-out and cross-context advertising provisions confirmed; dark-patterns, cookies, clean-rooms, and direct-marketing specifics unconfirmed.

Sub-modules (6)

Cookies And TrackersRed

No Louisiana-specific cookie/tracker consent regime distinct from the LDPA's general opt-out rights was identified.

Absence provenance: not recorded. Searched: not recorded.

Dark PatternsRed

No explicit dark-pattern prohibition specific to the LDPA was confirmed in sources reviewed, though such provisions are common in peer state laws.

Absence provenance: not recorded. Searched: not recorded.

Opt Out SignalsGreen

The LDPA includes a universal opt-out mechanism among its provisions.

Claims: CLM-LA-6d7e8f9a

Clean Rooms And DcrRed

No clean-room/data-collaboration-room provisions identified.

Absence provenance: not recorded. Searched: not recorded.

Cross Context AdvertisingGreen

Consumers may opt out of targeted advertising and the sale of personal data under the LDPA.

Claims: CLM-LA-7e8f9a0b

Direct MarketingAmber

No direct-marketing-specific consent/suppression regime distinct from the general opt-out right was identified.

Claims: CLM-LA-7e8f9a0b

Category narrative39 words

The LDPA requires a universal opt-out mechanism and grants consumers the right to opt out of targeted advertising and sale of personal data. Dark-pattern-specific prohibitions, cookie/tracker-specific rules, clean-room governance, and direct-marketing-specific suppression rules were not separately confirmed for Louisiana.

Sources and claims (2)
  1. ConfirmedInternational Association of Privacy ProfessionalsSensitive data limitations, universal opt-out mechanisms, and a sunsetting right to cure are included in the Louisiana Data Privacy Act.
  2. ConfirmedDataGuidanceConsumers can opt out of targeted advertising and data sales under the Louisiana Data Privacy Act.

#

Profiling and biometric/genetic consent confirmed; ADM transparency and AI-risk-assessment specifics unconfirmed.

Primary frameworkLouisiana Data Privacy Act (SB 386, Title 51 Ch. 20-B)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberProfiling and biometric/genetic consent confirmed; ADM transparency and AI-risk-assessment specifics unconfirmed.

Sub-modules (6)

Profiling RestrictionsAmber

Profiling with foreseeable consumer harm is identified as a higher-risk processing activity under the LDPA.

Claims: CLM-LA-8f9a0b1c

Automated Decision Making TransparencyRed

No explicit ADM transparency/explanation right distinct from general higher-risk-processing treatment was confirmed.

Absence provenance: not recorded. Searched: not recorded.

Ai Risk AssessmentsRed

No AI-specific risk-assessment regime (e.g., AI Act analogue) was identified for Louisiana.

Absence provenance: not recorded. Searched: not recorded.

Biometric RegimeGreen

Biometric data is classified as sensitive data requiring consumer consent under the LDPA.

Claims: CLM-LA-9a0b1c2d

Genetic DataGreen

Genetic data is classified as sensitive data requiring consumer consent under the LDPA.

Claims: CLM-LA-9a0b1c2d

State Surveillance CarveoutsRed

No state-surveillance/national-security carveout provisions specific to Louisiana were identified.

Absence provenance: not recorded. Searched: not recorded.

Category narrative38 words

The LDPA treats profiling with foreseeable consumer harm as a higher-risk processing activity and requires consent for processing biometric and genetic data as sensitive categories. Automated-decision-making transparency rights, AI-specific risk-assessment obligations, and state-surveillance carveouts were not separately confirmed.

Sources and claims (2)
  1. ProbableDataGuidanceHigher-risk processing activities under the Louisiana Data Privacy Act include profiling with foreseeable consumer harm.
  2. ConfirmedDataGuidanceThe Louisiana Data Privacy Act requires consumer consent for processing sensitive data including biometric and genetic data.

#

Multiple children's-data instruments confirmed at headline level; granular content of the 2025 Anti-Grooming Act and profiling bans specific to minors not independently confirmed.

Primary frameworkLouisiana Data Privacy Act (SB 386); Louisiana Kids Online Protection and Anti-Grooming Act (2025); HB 61 (2023)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberMultiple children's-data instruments confirmed at headline level; granular content of the 2025 Anti-Grooming Act and profiling bans specific to minors not independently confirmed.

Sub-modules (5)

Age VerificationAmber

Louisiana enacted a Kids Online Protection and Anti-Grooming Act in 2025; detailed age-verification mechanics were not retrievable from the sources reviewed.

Claims: CLM-LA-0b1c2d3e

Minor Profiling BansRed

No minor-specific profiling ban distinct from the LDPA's general 'profiling with foreseeable consumer harm' provision was identified.

Absence provenance: not recorded. Searched: not recorded.

Education SettingsAmber

Louisiana's legacy student-data-privacy law restricts sharing of student PII with any entity, including the state, without parental consent.

Claims: CLM-LA-4b5c6d7e

Dependent AdultsRed

No dependent-adult-specific data-protection provisions were identified for Louisiana.

Absence provenance: not recorded. Searched: not recorded.

Category narrative72 words

Louisiana has an active legislative cluster on minors' data and online safety: the LDPA requires consent for children's data and aligns parental-consent requirements with federal standards (COPPA); a 2023 enrolled bill (HB 61) addressed minors' consent for social-media platforms, effective 1 August 2024; and a Kids Online Protection and Anti-Grooming Act was enacted in 2025. A legacy student-data-privacy law restricts sharing of student PII without parental consent. No dependent-adult-specific provisions were identified.

Sources and claims (3)
  1. UncertainDataGuidanceLouisiana enacted a Kids Online Protection and Anti-Grooming Act in 2025 addressing online child interaction and age limitation.
  2. ConfirmedDataGuidanceThe Louisiana Data Privacy Act requires consent for processing children's data and aligns parental consent requirements with federal standards.
  3. ConfirmedLouisiana LegislatureA 2023 enrolled Louisiana House bill addressing minors' consent became effective on 1 August 2024, with the Louisiana State Law Institute directed to take implementing actions.

#

Enforcement powers and cure period confirmed; no enforcement track record exists yet as the law is not yet effective; PRA/class-action mechanisms unconfirmed.

Primary frameworkLouisiana Data Privacy Act (SB 386, Title 51 Ch. 20-B)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberEnforcement powers and cure period confirmed; no enforcement track record exists yet as the law is not yet effective; PRA/class-action mechanisms unconfirmed.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The Attorney General has exclusive enforcement authority; violations are classified as unfair or deceptive trade practices and subject to a 30-day cure period.

Claims: CLM-LA-3e4f5a6b, CLM-LA-4f5a6b7c

Enforcement Activity IndexRed

No enforcement actions exist yet, as the LDPA does not take effect until 1 January 2027.

Absence provenance: not recorded. Searched: not recorded.

Regulator Funding And CapacityRed

No specific funding or headcount signals for the Attorney General's privacy-enforcement function were identified.

Absence provenance: not recorded. Searched: not recorded.

Collective Redress And Class ActionsRed

No collective-redress or class-action mechanism specific to the LDPA was identified.

Absence provenance: not recorded. Searched: not recorded.

Private Right Of ActionAmber

The LDPA grants exclusive enforcement authority to the Attorney General, implying an absence of a private right of action, consistent with most peer US state comprehensive privacy laws.

Claims: CLM-LA-3e4f5a6b

Recent Developments 180DGreen

The Louisiana Data Privacy Act was signed into law on 29 May 2026, within the 180-day window preceding this run (5 August 2026).

Claims: CLM-LA-5a6b7c8d

Category narrative77 words

The Louisiana Attorney General holds exclusive enforcement authority over the LDPA, with violations treated as unfair or deceptive trade practices and subject to a 30-day cure period (reported as sunsetting). No private right of action or collective-redress mechanism was identified; regulator funding/capacity signals and a pre-enactment enforcement-activity track record are not yet available because the LDPA is not yet in force. The most recent development is the LDPA's enactment itself, within the 180-day window of this run.

Sources and claims (3)
  1. ConfirmedDataGuidanceEnforcement of the Louisiana Data Privacy Act is handled exclusively by the Attorney General, with a 30-day cure period for violations.
  2. ConfirmedDataGuidanceViolations of the Louisiana Data Privacy Act are classified as unfair or deceptive trade practices.
  3. ConfirmedDataGuidanceThe Governor of Louisiana signed Senate Bill 386, establishing the Louisiana Data Privacy Act, on 29 May 2026.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Laos
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 25 claim(s), 9 source(s) in the cumulative register.