Comprehensive omnibus statute exists but is not yet effective (1 Jan 2027); regulator capacity/registration regime unconfirmed.
Primary frameworkLouisiana Data Privacy Act (SB 386, Title 51 Ch. 20-B)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberComprehensive omnibus statute exists but is not yet effective (1 Jan 2027); regulator capacity/registration regime unconfirmed.
Sub-modules (5)
Regulator And AuthorityGreen
Enforcement authority for the LDPA and for the state's breach-notification law is held exclusively by the Louisiana Attorney General.
Claims: CLM-LA-1a2b3c4d, CLM-LA-2b3c4d5e
Act And InstrumentsGreen
Primary instrument is SB 386 (LDPA), creating Chapter 20-B of Title 51; the pre-existing Database Security Breach Notification Law (La. R.S. 51:3071 et seq.) remains in force alongside it.
Claims: CLM-LA-3c4d5e6f, CLM-LA-4d5e6f7a
Material ScopeAmber
The LDPA regulates the collection, use, and sale of personal data by controllers/processors doing business in Louisiana that meet statutory thresholds.
Claims: CLM-LA-5e6f7a8b
Territorial ScopeAmber
Applies to controllers and processors that conduct business in Louisiana or produce products/services targeted to Louisiana residents and meet the revenue/volume thresholds, consistent with the extraterritorial approach of other US state comprehensive laws.
Claims: CLM-LA-5e6f7a8b
Regulator Registration And FilingRed
No controller/processor registration or filing obligation with the Attorney General has been identified in the LDPA or in secondary guidance reviewed.
Absence provenance: not recorded. Searched: not recorded.
Category narrative90 words
Louisiana has moved from an unregulated-gap consumer-privacy posture to a hybrid regime: the Louisiana Data Privacy Act (LDPA), enacted via Senate Bill 386 and signed into law on 29 May 2026, creates a new Chapter 20-B of Title 51 of the Louisiana Revised Statutes and establishes a comprehensive consumer data-privacy framework effective 1 January 2027, sitting alongside pre-existing sectoral instruments (breach notification law, student-data law, insurance data-security provisions, and children's online-safety acts). Enforcement of both the LDPA and the state's breach-notification statute is vested exclusively in the Louisiana Attorney General.
Sources and claims (5)
ConfirmedDataGuidance — Enforcement of the Louisiana Data Privacy Act is granted exclusively to the Louisiana Attorney General, with violations classified as unfair or deceptive trade practices.
ConfirmedDataGuidance — The Louisiana Attorney General is responsible for enforcing the state's breach-notification requirements under La. R.S. 51:3071 et seq. and Title 16 of the Louisiana Administrative Code.
ConfirmedDataGuidance — Senate Bill 386, signed on 29 May 2026, establishes the Louisiana Data Privacy Act, a comprehensive consumer data-privacy framework regulating collection, use and sale of personal data, effective 1 January 2027.
ConfirmedDataGuidance — The LDPA bill creates a new Chapter 20-B of Title 51 of the Louisiana Revised Statutes.
ConfirmedInternational Association of Privacy Professionals — The LDPA applies to businesses earning more than USD 25 million in revenue and those processing the personal data of more than 75,000 people, or deriving more than 50% of revenue from the sale of personal data.
Consent thresholds for sensitive data are documented; a GDPR-style enumerated lawful-bases regime and pseudonymisation/anonymisation safe-harbour provisions were not located in available sources.
Primary frameworkLouisiana Data Privacy Act (SB 386, Title 51 Ch. 20-B)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberConsent thresholds for sensitive data are documented; a GDPR-style enumerated lawful-bases regime and pseudonymisation/anonymisation safe-harbour provisions were not located in available sources.
Sub-modules (4)
Lawful BasesAmber
The LDPA does not use a GDPR-style enumerated lawful-bases list; general processing is permitted subject to consumer opt-out and notice obligations, with consent required only for sensitive categories.
Claims: CLM-LA-6f7a8b9c
Consent ThresholdsGreen
Consumer consent is required before processing sensitive personal data, including health, biometric, genetic, and children's data.
Claims: CLM-LA-7a8b9c0d
Special CategoriesGreen
Sensitive data categories under the LDPA include health, biometric, genetic, and children's data, all of which require consumer consent to process.
Claims: CLM-LA-7a8b9c0d
Pseudonymisation And AnonymisationRed
No explicit pseudonymisation or anonymisation safe-harbour provisions were located for the LDPA in sources reviewed.
Absence provenance: not recorded. Searched: not recorded.
Category narrative39 words
The LDPA follows the notice-and-opt-out model typical of US state comprehensive privacy statutes rather than an enumerated GDPR-style lawful-bases list; however it imposes an affirmative consent requirement for processing of sensitive/special-category data, including health, biometric, genetic, and children's data.
Sources and claims (2)
ProbableDataGuidance — The LDPA establishes controller and processor obligations including data minimization and purpose limitation as general processing constraints, rather than an enumerated lawful-bases list.
ConfirmedDataGuidance — The LDPA requires consumer consent for processing sensitive data, including health, biometric, genetic, and children's data.
Core rights confirmed; deadline specifics unconfirmed pending primary statutory text review.
Primary frameworkLouisiana Data Privacy Act (SB 386, Title 51 Ch. 20-B)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberCore rights confirmed; deadline specifics unconfirmed pending primary statutory text review.
Sub-modules (5)
Access RightGreen
Consumers may access their personal data held by controllers under the LDPA.
Claims: CLM-LA-8b9c0d1e
Rectification And ErasureGreen
Consumers may correct and delete their personal data under the LDPA.
Claims: CLM-LA-8b9c0d1e
Restriction And ObjectionGreen
Consumers may opt out of targeted advertising and the sale of personal data under the LDPA.
Claims: CLM-LA-9c0d1e2f
Data PortabilityGreen
Consumers may obtain a portable copy of their personal data under the LDPA.
Claims: CLM-LA-8b9c0d1e
Deadlines And Response WindowsRed
No specific statutory response-window (e.g., number of days for controller response) was confirmed in the sources reviewed for the LDPA.
Absence provenance: not recorded. Searched: not recorded.
Category narrative40 words
The LDPA grants consumers rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising and sale of personal data. Specific statutory response-window lengths were not confirmed in sources reviewed.
Sources and claims (2)
ConfirmedDataGuidance — Individuals can access, correct, delete, and obtain a portable copy of their personal data under the Louisiana Data Privacy Act.
ConfirmedDataGuidance — Individuals can opt out of targeted advertising and data sales under the Louisiana Data Privacy Act.
Security and breach-notification duties well evidenced; DPIA trigger language is probable but truncated in sources; DPO/ROPA/retention specifics unconfirmed.
Primary frameworkLouisiana Data Privacy Act (SB 386, Title 51 Ch. 20-B); Database Security Breach Notification Law (La. R.S. 51:3071 et seq.)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberSecurity and breach-notification duties well evidenced; DPIA trigger language is probable but truncated in sources; DPO/ROPA/retention specifics unconfirmed.
Sub-modules (7)
Accountability And DpiaAmber
Higher-risk processing activities such as targeted advertising, sale of personal data, and profiling with foreseeable consumer harm are treated as heightened-risk under the LDPA, consistent with a data-protection-assessment trigger seen in peer state laws, though the exact assessment obligation text was truncated in sources reviewed.
Claims: CLM-LA-0d1e2f3a
Dpo RequirementsRed
No DPO appointment threshold was identified for the LDPA in sources reviewed.
Absence provenance: not recorded. Searched: not recorded.
Ropa RequirementsRed
No records-of-processing-activities obligation was identified for the LDPA in sources reviewed.
Absence provenance: not recorded. Searched: not recorded.
Joint Controller ArrangementsAmber
The LDPA imposes controller and processor obligations, but specific joint-controller contractual provisions were not detailed in sources reviewed.
Claims: CLM-LA-1e2f3a4b
Security MeasuresGreen
Controllers/processors must implement reasonable security safeguards under the LDPA.
Claims: CLM-LA-2f3a4b5c
Breach NotificationGreen
Louisiana's Database Security Breach Notification Law (La. R.S. 51:3071 et seq. and La. Admin. Code Title 16, Ch. 7) requires notification of data breaches, enforced by the Attorney General.
Claims: CLM-LA-3a4b5c6d
Retention And DisposalRed
No specific retention-limitation or disposal-duty provision was identified for the LDPA in sources reviewed.
Absence provenance: not recorded. Searched: not recorded.
Category narrative62 words
The LDPA imposes data minimization, purpose limitation, and reasonable security safeguard duties on controllers/processors, and higher-risk processing activities (targeted advertising, sale of personal data, profiling with foreseeable consumer harm, and sensitive-data processing) appear to trigger heightened obligations. Louisiana's pre-existing Database Security Breach Notification Law (La. R.S. 51:3071 et seq.) independently governs breach notification duties. DPO appointment and ROPA obligations were not confirmed.
Sources and claims (4)
ProbableDataGuidance — Higher-risk processing activities such as targeted advertising, the sale of personal data, and profiling with foreseeable consumer harm are subject to heightened obligations under the Louisiana Data Privacy Act.
ConfirmedDataGuidance — The Louisiana Data Privacy Act includes controller and processor obligations covering data minimization, purpose limitation, security safeguards, and clear privacy notices.
ConfirmedDataGuidance — Business obligations under the Louisiana Data Privacy Act require data minimization, purpose limitation, and reasonable security safeguards.
ConfirmedDataGuidance — Louisiana requires breach notification pursuant to La. R.S. 51:3071 et seq. and Title 16, Chapter 7 of the Louisiana Administrative Code.
No comprehensive cross-border transfer regime exists in Louisiana or at US federal level for general commercial data.
Traffic-light rationale — RedNo comprehensive cross-border transfer regime exists in Louisiana or at US federal level for general commercial data.
Sub-modules (6)
Transfer MechanismsRed
No transfer-mechanism regime identified.
Absence provenance: not recorded. Searched: not recorded.
Adequacy ReceivedRed
Not applicable; no adequacy-determination framework exists for US states.
Absence provenance: not recorded. Searched: not recorded.
Adequacy GrantedRed
Not applicable; Louisiana does not grant adequacy determinations.
Absence provenance: not recorded. Searched: not recorded.
Sccs And BcrsRed
No SCC/BCR uptake or equivalent mechanism identified.
Absence provenance: not recorded. Searched: not recorded.
Transfer Impact AssessmentRed
No TIA requirement identified.
Absence provenance: not recorded. Searched: not recorded.
Data LocalisationRed
No data-localisation mandate identified for Louisiana.
Absence provenance: not recorded. Searched: not recorded.
Category narrative50 words
No cross-border transfer mechanism, adequacy determination, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate was identified for Louisiana. Consistent with the US federal/state patchwork, there is no US analogue to GDPR Chapter V transfer restrictions at the state level; the LDPA's scope is domestic personal-data processing rather than cross-border transfer governance.
Education and insurance overlays evidenced; other sectoral overlays unconfirmed at state level.
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberEducation and insurance overlays evidenced; other sectoral overlays unconfirmed at state level.
Sub-modules (7)
Financial Sector OverlayRed
No Louisiana-specific financial-sector data-privacy overlay beyond federal GLBA was identified.
Absence provenance: not recorded. Searched: not recorded.
Health Sector OverlayRed
No Louisiana-specific health-sector overlay beyond federal HIPAA was identified.
Absence provenance: not recorded. Searched: not recorded.
Telecoms And EprivacyRed
No Louisiana-specific telecoms/eprivacy overlay identified.
Absence provenance: not recorded. Searched: not recorded.
Employment DataRed
No Louisiana-specific employment-data overlay identified.
Absence provenance: not recorded. Searched: not recorded.
Credit And ScoringRed
No Louisiana-specific credit-scoring overlay identified beyond federal FCRA.
Absence provenance: not recorded. Searched: not recorded.
EducationAmber
Louisiana previously passed a highly restrictive student-data-privacy law prohibiting districts from sharing student PII with any entity, including the state, without parental consent.
Claims: CLM-LA-4b5c6d7e
InsuranceAmber
A Louisiana Insurance Data Security Law reference (La. R.S. Title 22) was located in legal-research indices, but detailed substantive content was not retrievable from the sources reviewed.
Claims: CLM-LA-5c6d7e8f
Category narrative62 words
Louisiana layers sector-specific overlays atop the incoming LDPA: a legacy student-data-privacy law restricting district sharing of student PII without parental consent, and an insurance data-security statute referenced in Title 22 of the Louisiana Revised Statutes. Financial, health, telecoms/eprivacy, credit-scoring, and general employment-data overlays specific to Louisiana were not confirmed in sources reviewed (federal GLBA/HIPAA/FCRA overlays apply by default at the federal level).
Sources and claims (2)
ProbableInternational Association of Privacy Professionals — Louisiana previously enacted a student data privacy law which prohibits districts from sharing PII with any entity, including the state, without parental consent.
UncertainState of Louisiana / DataGuidance legal research repository — Louisiana Revised Statutes Title 22 contains an insurance data security provision (referenced at La. R.S. §22:2504), though its full substantive scope could not be confirmed from available secondary sources.
Opt-out and cross-context advertising provisions confirmed; dark-patterns, cookies, clean-rooms, and direct-marketing specifics unconfirmed.
Primary frameworkLouisiana Data Privacy Act (SB 386, Title 51 Ch. 20-B)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberOpt-out and cross-context advertising provisions confirmed; dark-patterns, cookies, clean-rooms, and direct-marketing specifics unconfirmed.
Sub-modules (6)
Cookies And TrackersRed
No Louisiana-specific cookie/tracker consent regime distinct from the LDPA's general opt-out rights was identified.
Absence provenance: not recorded. Searched: not recorded.
Dark PatternsRed
No explicit dark-pattern prohibition specific to the LDPA was confirmed in sources reviewed, though such provisions are common in peer state laws.
Absence provenance: not recorded. Searched: not recorded.
Opt Out SignalsGreen
The LDPA includes a universal opt-out mechanism among its provisions.
Claims: CLM-LA-6d7e8f9a
Clean Rooms And DcrRed
No clean-room/data-collaboration-room provisions identified.
Absence provenance: not recorded. Searched: not recorded.
Cross Context AdvertisingGreen
Consumers may opt out of targeted advertising and the sale of personal data under the LDPA.
Claims: CLM-LA-7e8f9a0b
Direct MarketingAmber
No direct-marketing-specific consent/suppression regime distinct from the general opt-out right was identified.
Claims: CLM-LA-7e8f9a0b
Category narrative39 words
The LDPA requires a universal opt-out mechanism and grants consumers the right to opt out of targeted advertising and sale of personal data. Dark-pattern-specific prohibitions, cookie/tracker-specific rules, clean-room governance, and direct-marketing-specific suppression rules were not separately confirmed for Louisiana.
Profiling and biometric/genetic consent confirmed; ADM transparency and AI-risk-assessment specifics unconfirmed.
Primary frameworkLouisiana Data Privacy Act (SB 386, Title 51 Ch. 20-B)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberProfiling and biometric/genetic consent confirmed; ADM transparency and AI-risk-assessment specifics unconfirmed.
Sub-modules (6)
Profiling RestrictionsAmber
Profiling with foreseeable consumer harm is identified as a higher-risk processing activity under the LDPA.
Claims: CLM-LA-8f9a0b1c
Automated Decision Making TransparencyRed
No explicit ADM transparency/explanation right distinct from general higher-risk-processing treatment was confirmed.
Absence provenance: not recorded. Searched: not recorded.
Ai Risk AssessmentsRed
No AI-specific risk-assessment regime (e.g., AI Act analogue) was identified for Louisiana.
Absence provenance: not recorded. Searched: not recorded.
Biometric RegimeGreen
Biometric data is classified as sensitive data requiring consumer consent under the LDPA.
Claims: CLM-LA-9a0b1c2d
Genetic DataGreen
Genetic data is classified as sensitive data requiring consumer consent under the LDPA.
Claims: CLM-LA-9a0b1c2d
State Surveillance CarveoutsRed
No state-surveillance/national-security carveout provisions specific to Louisiana were identified.
Absence provenance: not recorded. Searched: not recorded.
Category narrative38 words
The LDPA treats profiling with foreseeable consumer harm as a higher-risk processing activity and requires consent for processing biometric and genetic data as sensitive categories. Automated-decision-making transparency rights, AI-specific risk-assessment obligations, and state-surveillance carveouts were not separately confirmed.
Sources and claims (2)
ProbableDataGuidance — Higher-risk processing activities under the Louisiana Data Privacy Act include profiling with foreseeable consumer harm.
ConfirmedDataGuidance — The Louisiana Data Privacy Act requires consumer consent for processing sensitive data including biometric and genetic data.
Multiple children's-data instruments confirmed at headline level; granular content of the 2025 Anti-Grooming Act and profiling bans specific to minors not independently confirmed.
Primary frameworkLouisiana Data Privacy Act (SB 386); Louisiana Kids Online Protection and Anti-Grooming Act (2025); HB 61 (2023)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberMultiple children's-data instruments confirmed at headline level; granular content of the 2025 Anti-Grooming Act and profiling bans specific to minors not independently confirmed.
Sub-modules (5)
Age VerificationAmber
Louisiana enacted a Kids Online Protection and Anti-Grooming Act in 2025; detailed age-verification mechanics were not retrievable from the sources reviewed.
Claims: CLM-LA-0b1c2d3e
Parental ConsentGreen
The LDPA requires consent for processing children's data and aligns its parental-consent requirements with federal standards (i.e., COPPA); a separate 2023 enrolled bill (HB 61) addressed minors' consent obligations for social media, effective 1 August 2024.
Claims: CLM-LA-1c2d3e4f, CLM-LA-2d3e4f5a
Minor Profiling BansRed
No minor-specific profiling ban distinct from the LDPA's general 'profiling with foreseeable consumer harm' provision was identified.
Absence provenance: not recorded. Searched: not recorded.
Education SettingsAmber
Louisiana's legacy student-data-privacy law restricts sharing of student PII with any entity, including the state, without parental consent.
Claims: CLM-LA-4b5c6d7e
Dependent AdultsRed
No dependent-adult-specific data-protection provisions were identified for Louisiana.
Absence provenance: not recorded. Searched: not recorded.
Category narrative72 words
Louisiana has an active legislative cluster on minors' data and online safety: the LDPA requires consent for children's data and aligns parental-consent requirements with federal standards (COPPA); a 2023 enrolled bill (HB 61) addressed minors' consent for social-media platforms, effective 1 August 2024; and a Kids Online Protection and Anti-Grooming Act was enacted in 2025. A legacy student-data-privacy law restricts sharing of student PII without parental consent. No dependent-adult-specific provisions were identified.
Sources and claims (3)
UncertainDataGuidance — Louisiana enacted a Kids Online Protection and Anti-Grooming Act in 2025 addressing online child interaction and age limitation.
ConfirmedDataGuidance — The Louisiana Data Privacy Act requires consent for processing children's data and aligns parental consent requirements with federal standards.
ConfirmedLouisiana Legislature — A 2023 enrolled Louisiana House bill addressing minors' consent became effective on 1 August 2024, with the Louisiana State Law Institute directed to take implementing actions.
Enforcement powers and cure period confirmed; no enforcement track record exists yet as the law is not yet effective; PRA/class-action mechanisms unconfirmed.
Primary frameworkLouisiana Data Privacy Act (SB 386, Title 51 Ch. 20-B)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberEnforcement powers and cure period confirmed; no enforcement track record exists yet as the law is not yet effective; PRA/class-action mechanisms unconfirmed.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
The Attorney General has exclusive enforcement authority; violations are classified as unfair or deceptive trade practices and subject to a 30-day cure period.
Claims: CLM-LA-3e4f5a6b, CLM-LA-4f5a6b7c
Enforcement Activity IndexRed
No enforcement actions exist yet, as the LDPA does not take effect until 1 January 2027.
Absence provenance: not recorded. Searched: not recorded.
Regulator Funding And CapacityRed
No specific funding or headcount signals for the Attorney General's privacy-enforcement function were identified.
Absence provenance: not recorded. Searched: not recorded.
Collective Redress And Class ActionsRed
No collective-redress or class-action mechanism specific to the LDPA was identified.
Absence provenance: not recorded. Searched: not recorded.
Private Right Of ActionAmber
The LDPA grants exclusive enforcement authority to the Attorney General, implying an absence of a private right of action, consistent with most peer US state comprehensive privacy laws.
Claims: CLM-LA-3e4f5a6b
Recent Developments 180DGreen
The Louisiana Data Privacy Act was signed into law on 29 May 2026, within the 180-day window preceding this run (5 August 2026).
Claims: CLM-LA-5a6b7c8d
Category narrative77 words
The Louisiana Attorney General holds exclusive enforcement authority over the LDPA, with violations treated as unfair or deceptive trade practices and subject to a 30-day cure period (reported as sunsetting). No private right of action or collective-redress mechanism was identified; regulator funding/capacity signals and a pre-enactment enforcement-activity track record are not yet available because the LDPA is not yet in force. The most recent development is the LDPA's enactment itself, within the 180-day window of this run.
Sources and claims (3)
ConfirmedDataGuidance — Enforcement of the Louisiana Data Privacy Act is handled exclusively by the Attorney General, with a 30-day cure period for violations.
ConfirmedDataGuidance — Violations of the Louisiana Data Privacy Act are classified as unfair or deceptive trade practices.
ConfirmedDataGuidance — The Governor of Louisiana signed Senate Bill 386, establishing the Louisiana Data Privacy Act, on 29 May 2026.
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Laos
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 25 claim(s), 9 source(s) in the cumulative register.