🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
US-LA v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing15 sources retrieved model claude-sonnet-5 · 2026-08-05

Louisiana, USA

US-LA schema gdpri-v2 trajectory: not yet assessedhybrid regimeoverlaps: FIM, WPM, AIC, Crypto

Last updated · 10 categories · 56 claims · 27 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
56Claimsbaseline..claims[]
1Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Louisiana enacted its first comprehensive consumer privacy law this session. The Louisiana Data Privacy Act (SB 386) was signed by Governor Jeff Landry on May 29, 2026, and is codified at La. R.S. 51:1780.1 through 1780.5. The Act applies to entities doing business in Louisiana that have annual gross revenue exceeding $25 million, or that annually buy, receive, sell, or share personal data of 75,000 or more consumers, households, or devices, or that derive 50 percent or more of annual revenue from selling personal data. It takes effect January 1, 2027, moving Louisiana from a purely sectoral and breach-notification regime to a hybrid omnibus-plus-sectoral framework.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive statute enacted but not yet effective; only breach-notification law currently in force; territorial-scope and filing details unconfirmed from secondary reporting.

Primary frameworkLouisiana Data Privacy Act (SB 386 / La. R.S. Title 51, Ch. 20-B) -- enacted, effective 2027-01-01; concurrently, Louisiana Database Security Breach Notification Law (La. R.S. §51:3071 et seq.) -- in force
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberComprehensive statute enacted but not yet effective; only breach-notification law currently in force; territorial-scope and filing details unconfirmed from secondary reporting.

Sub-modules (5)

Regulator And AuthorityAmber

AG enforces breach law now; will hold exclusive LDPA enforcement authority from 2027.

Claims (2):

  • The Louisiana Attorney General is responsible for enforcing the state's breach-notification requirements under La. R.S. and the La. Admin. Code.
  • Under the Louisiana Data Privacy Act, exclusive enforcement authority is granted to the Louisiana Attorney General.

Act And InstrumentsAmber

Breach law in force; LDPA enacted, not yet effective.

Claims (2):

  • Louisiana's Database Security Breach Notification Law (La. R.S. §51:3071 et seq. and La. Admin. Code tit.16 §701) is currently in force and is the only fully operative data-protection-adjacent statute predating the LDPA.
  • SB 386, the Louisiana Data Privacy Act, was signed into law on 2026-05-29, creating a new Chapter 20-B of Title 51 of the Louisiana Revised Statutes, effective 2027-01-01.

Material ScopeAmber

LDPA thresholds based on revenue/volume/data-sale reliance.

Claims (1):

  • The LDPA applies to controllers/processors earning more than USD 25 million in revenue, or processing personal data of more than 75,000 Louisiana consumers, or deriving more than 50% of revenue from the sale of personal data.

Territorial ScopeAmber

Applies to controllers/processors doing business in Louisiana; exact non-established-controller language not independently verified.

Claims (1):

  • The LDPA applies to controllers and processors that conduct business in Louisiana and meet the statutory thresholds.

Regulator Registration And FilingRed

No registration/filing obligation identified for controllers.

Absence provenance: unavailable. Searched: Louisiana Data Privacy Act SB386 filing registration requirement, Louisiana AG data broker registry.

Claims (1):

  • No controller registration or filing obligation with the Louisiana Attorney General has been identified under the LDPA or breach-notification law.
Category narrative166 words

Louisiana's data-protection posture materially changed on 2026-05-29: Governor signed SB 386, the Louisiana Data Privacy Act (LDPA), creating a new Chapter 20-B of Title 51 of the Louisiana Revised Statutes -- a comprehensive consumer privacy framework -- effective 2027-01-01. <cite index="22-1,22-2">On May 29, 2026, the Governor of Louisiana signed Senate Bill 386, establishing the Louisiana Data Privacy Act, creating a comprehensive consumer data privacy framework regulating the collection, use, and sale of personal data, set to take effect on January 1, 2027.</cite> Until that date, Louisiana's only in-force data-protection instrument is its breach-notification statute; <cite index="1-1,1-2">Louisiana requires notification of breaches pursuant to §51:3071 et seq. of Article 3701 of Title 51 of the Louisiana Revised Statutes and §16-7-701 of Chapter 7 of Article 701 of Title 16 of the Louisiana Administrative Code.</cite> The seed's characterization of Louisiana as having no comprehensive statute is now superseded by this enactment, though the JID remains a two-track regime (pre- and post- 2027-01-01) plus federal sectoral overlays (HIPAA/GLBA/COPPA/FTC Act §5).

Periodic update · new data 2026-09-28

Regulator & Framework

Louisiana enacted its first comprehensive consumer privacy statute this session: the Louisiana Data Privacy Act, SB 386, signed by Governor Jeff Landry on May 29, 2026, and codified at La. R.S. 51:1780.1 through 1780.5. This moves the state from a regime previously limited to sectoral rules and breach-notification obligations to a hybrid omnibus-plus-sectoral consumer-privacy framework. The Act has not yet taken effect: its provisions are enacted but not yet effective, with the operative date set for January 1, 2027.

The LDPA's material scope thresholds follow the now-common tiered-trigger model: it applies to entities doing business in Louisiana with annual gross revenue exceeding $25 million, or that annually buy, receive, sell, or share personal data of 75,000 or more consumers, households, or devices, or that derive 50 percent or more of annual revenue from selling personal data. These thresholds determine which entities fall within scope from the January 1, 2027 effective date.

Enforcement authority sits exclusively with the Louisiana Attorney General. Violations of the LDPA are treated as unfair or deceptive trade practices under the state's Unfair Trade Practices and Consumer Protection Law, and the statute provides no private right of action, meaning individual consumers cannot bring their own civil claims for violations; enforcement runs solely through the Attorney General's office.

Outlook

The January 1, 2027 effective date is the operative marker for this framework: entities meeting the revenue or data-volume thresholds must have compliance programs in place by that date. A statutory cure period, addressed further under Enforcement & Redress, runs through the law's first several months in force.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (7)
  1. ConfirmedDataGuidance (secondary reporting) — The Louisiana Attorney General is responsible for enforcing the state's breach-notification requirements under La. R.S. and the La. Admin. Code.observed
  2. ConfirmedDataGuidance — Under the Louisiana Data Privacy Act, exclusive enforcement authority is granted to the Louisiana Attorney General.observed
  3. ConfirmedDataGuidance (secondary reporting of statute) — Louisiana's Database Security Breach Notification Law (La. R.S. §51:3071 et seq. and La. Admin. Code tit.16 §701) is currently in force and is the only fully operative data-protection-adjacent statute predating the LDPA.observed
  4. ConfirmedDataGuidance — SB 386, the Louisiana Data Privacy Act, was signed into law on 2026-05-29, creating a new Chapter 20-B of Title 51 of the Louisiana Revised Statutes, effective 2027-01-01.observed
  5. ConfirmedIAPP — The LDPA applies to controllers/processors earning more than USD 25 million in revenue, or processing personal data of more than 75,000 Louisiana consumers, or deriving more than 50% of revenue from the sale of personal data.observed
  6. ProbableDataGuidance — The LDPA applies to controllers and processors that conduct business in Louisiana and meet the statutory thresholds.observed
  7. UncertainDataGuidance — No controller registration or filing obligation with the Louisiana Attorney General has been identified under the LDPA or breach-notification law.observed

#

Sensitive-category consent regime confirmed; lawful-basis enumeration and anonymisation safe-harbours unconfirmed.

Primary frameworkLouisiana Data Privacy Act (enacted, effective 2027-01-01)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberSensitive-category consent regime confirmed; lawful-basis enumeration and anonymisation safe-harbours unconfirmed.

Sub-modules (4)

Lawful BasesRed

No GDPR-style Art.6 enumeration confirmed; LDPA appears consent/necessity-oriented per Virginia-model peer laws.

Absence provenance: unavailable. Searched: Louisiana Data Privacy Act lawful basis processing text.

Claims (1):

  • The LDPA does not appear to enumerate a GDPR-Article-6-style list of lawful bases; the statutory text confirming this was not independently verified.

Special CategoriesAmber

Health, biometric, genetic, and children's data classified as sensitive.

Claims (1):

  • Sensitive data under the LDPA includes health, biometric, genetic, and children's data, all requiring consumer consent to process.

Pseudonymisation And AnonymisationRed

No confirmed definitions/safe-harbours located.

Absence provenance: unavailable. Searched: Louisiana Data Privacy Act pseudonymisation anonymisation definition.

Claims (1):

  • No pseudonymisation or anonymisation safe-harbour definitions were located for the LDPA.
Category narrative50 words

The LDPA imposes consent requirements for sensitive-data processing (health, biometric, genetic, children's data) rather than a GDPR-style enumerated lawful-basis structure. <cite index="12-11,12-12">Sensitive Data Protections: Requires consumer consent for processing sensitive data, including health, biometric, genetic, and children's data.</cite> Detailed lawful-basis and pseudonymisation/anonymisation safe-harbour text was not confirmed via secondary reporting.

Periodic update · new data 2026-09-28

Lawful Processing & Special Data

The Louisiana Data Privacy Act imposes a distinctive separate-consent requirement on the sale of sensitive or biometric personal data. Controllers deriving 50 percent or more of their annual revenue from selling personal data must obtain consumers' separate consent before selling sensitive or biometric personal data specifically, layered on top of any general processing basis that might otherwise apply. These same high-revenue-from-sale controllers must also post a conspicuous notice stating that they may sell such sensitive or biometric data, giving consumers an upfront disclosure independent of the separate-consent mechanism itself.

This provision is enacted but not yet effective, reaching its operative date on January 1, 2027 alongside the rest of the LDPA's substantive obligations. The separate-consent trigger is narrower than a blanket sensitive-data consent requirement: it applies specifically to the subset of controllers whose business model depends heavily on data sales, rather than to all controllers processing sensitive or biometric data generally, meaning entities that process sensitive data without a revenue-from-sale profile above the 50 percent threshold face a different, less stringent compliance posture under this specific provision.

Outlook

As the January 1, 2027 effective date approaches, high-revenue-from-sale controllers processing sensitive or biometric data in Louisiana should expect the separate-consent and conspicuous-notice requirements to become a discrete compliance workstream distinct from the LDPA's general consumer-rights obligations.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (4)
  1. ConfirmedIAPP — The LDPA requires consumer consent before processing sensitive data categories.observed
  2. ConfirmedDataGuidance — Sensitive data under the LDPA includes health, biometric, genetic, and children's data, all requiring consumer consent to process.observed
  3. UncertainDataGuidance — The LDPA does not appear to enumerate a GDPR-Article-6-style list of lawful bases; the statutory text confirming this was not independently verified.observed
  4. UncertainDataGuidance — No pseudonymisation or anonymisation safe-harbour definitions were located for the LDPA.observed

#

Core rights confirmed but not yet in force; response-window deadlines unconfirmed.

Primary frameworkLouisiana Data Privacy Act (enacted, effective 2027-01-01)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberCore rights confirmed but not yet in force; response-window deadlines unconfirmed.

Sub-modules (5)

Access RightAmber

Consumers may access personal data collected about them.

Claims (1):

  • Consumers may access personal data collected about them under the LDPA.

Rectification And ErasureAmber

Correction and deletion rights granted.

Claims (1):

  • Consumers may correct and delete their personal data under the LDPA.

Restriction And ObjectionAmber

Opt-out of targeted advertising, sale, and harmful profiling.

Claims (1):

  • Consumers may opt out of targeted advertising, sale of personal data, and profiling that presents a foreseeable risk of harm.

Data PortabilityAmber

Right to a portable copy of personal data.

Claims (1):

  • Consumers may obtain a portable copy of their personal data under the LDPA.

Deadlines And Response WindowsRed

No confirmed statutory response-window figures.

Absence provenance: unavailable. Searched: Louisiana Data Privacy Act response deadline days consumer request.

Claims (1):

  • No specific statutory response-window (days) for consumer-rights requests was located.
Category narrative69 words

Once effective (2027-01-01), the LDPA grants access, correction, deletion, portability, and opt-out rights typical of the Virginia/Colorado model. <cite index="68-3,68-4">Louisiana Data Privacy Act: Senate Bill 386 establishes a comprehensive consumer data privacy framework for Louisiana. Consumer Rights: Individuals can access, correct, delete, and obtain a portable copy of their personal data, and opt out of targeted advertising and data sales.</cite> Statutory response-window deadlines were not confirmed in secondary sources.

Periodic update · new data 2026-09-28

Data Subject Rights

The Louisiana Data Privacy Act grants Louisiana consumers a now-standard bundle of omnibus consumer-privacy rights: the right to confirm whether a controller is processing their personal data, the right to access that data, the right to correct it, the right to delete it, the right to port it, and the right to opt out of both targeted advertising and the sale of personal data. This rights bundle is enacted but not yet effective, reaching its operative date on January 1, 2027 together with the rest of the Act's substantive provisions.

The rights structure follows the pattern established by the broader 2026 wave of state comprehensive privacy laws rather than introducing a materially novel rights category. What distinguishes Louisiana's implementation from some peer states, addressed further under AdTech & Commercial Privacy, is the accompanying requirement that controllers honor universal opt-out signals, meaning consumers can exercise at least the opt-out subset of these rights through a browser-based mechanism rather than navigating individual controller opt-out interfaces one at a time.

Outlook

Controllers subject to the LDPA should expect consumer rights requests, particularly access, deletion, and opt-out requests, to become operative from January 1, 2027, and should have request-intake and verification processes in place ahead of that date.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ConfirmedDataGuidance — Consumers may access personal data collected about them under the LDPA.observed
  2. ConfirmedDataGuidance — Consumers may correct and delete their personal data under the LDPA.observed
  3. ConfirmedDataGuidance — Consumers may opt out of targeted advertising, sale of personal data, and profiling that presents a foreseeable risk of harm.observed
  4. ConfirmedDataGuidance — Consumers may obtain a portable copy of their personal data under the LDPA.observed
  5. UncertainDataGuidance — No specific statutory response-window (days) for consumer-rights requests was located.observed

#

Breach notification in force (green-level maturity); DPIA/security/ROPA/DPO obligations under LDPA not yet effective and partly unconfirmed.

Primary frameworkLouisiana Database Security Breach Notification Law (in force); Louisiana Data Privacy Act (enacted, effective 2027-01-01); Louisiana Insurance Data Security Law (sectoral)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberBreach notification in force (green-level maturity); DPIA/security/ROPA/DPO obligations under LDPA not yet effective and partly unconfirmed.

Sub-modules (7)

Accountability And DpiaAmber

Data protection assessments required for high-risk processing under LDPA.

Claims (1):

  • Data protection assessments are required under the LDPA for targeted advertising, sale of personal data, profiling with foreseeable consumer harm, and sensitive-data processing.

Dpo RequirementsRed

No DPO-appointment threshold confirmed.

Absence provenance: unavailable. Searched: Louisiana Data Privacy Act data protection officer requirement.

Claims (1):

  • No DPO-appointment threshold was located under the LDPA.

Ropa RequirementsRed

No records-of-processing obligation confirmed.

Absence provenance: unavailable. Searched: Louisiana Data Privacy Act records of processing activities.

Claims (1):

  • No records-of-processing-activities obligation was located under the LDPA.

Joint Controller ArrangementsAmber

Processor-contract clauses referenced generally as 'organizational duties'; specifics unconfirmed.

Claims (1):

  • The LDPA establishes organizational duties for controllers and processors, though specific processor-contract clause requirements were not independently confirmed.

Security MeasuresAmber

LDPA requires reasonable security safeguards; Insurance Data Security Law imposes sector information-security-program duties on insurers.

Claims (2):

  • The LDPA requires implementation of reasonable security safeguards by controllers and processors.
  • Louisiana has adopted an Insurance Data Security Law requiring insurers to implement an information-security program consistent with the NAIC Insurance Data Security Model Law.

Breach NotificationGreen

60-day notification deadline; AG enforces; unique LA-citizen-list requirement.

Claims (2):

  • Louisiana requires breach notification to affected individuals within 60 days, and its regulator notice is unique among states in requesting a list of affected Louisiana citizens.
  • The Louisiana Attorney General enforces breach-notification requirements under La. R.S. and La. Admin. Code, per citation §3074(J).

Retention And DisposalAmber

Data minimization/purpose limitation implies retention limits; explicit disposal duty unconfirmed.

Claims (1):

  • The LDPA's data-minimization and purpose-limitation obligations imply retention limits, though an explicit disposal duty was not independently confirmed.
Category narrative98 words

Breach notification is the only fully in-force duty today: <cite index="42-5">2018 alone saw eight states change their notification timelines, defining that organizations have: 60 days to notify individuals (South Dakota, Delaware, Louisiana)</cite>, and <cite index="41-7">Louisiana is unique among states because it requests a list of affected Louisiana citizens</cite>. From 2027, the LDPA adds data-protection-assessment, minimization, and security-safeguard duties: <cite index="32-5">Higher-risk processing activities such as targeted advertising, the sale of personal data, profiling with foreseeable consumer harm, and processing sensitive data require data protection assessments.</cite> A separate Louisiana Insurance Data Security Law (NAIC-model-based) imposes sector security-program duties on insurers.

Periodic update · new data 2026-09-28

Controller/Processor Duties

The Louisiana Data Privacy Act imposes two distinct categories of controller obligation this cycle. First, controllers must conduct data protection assessments, functionally equivalent to a DPIA, for targeted advertising, sensitive-data processing, certain profiling carrying a foreseeable risk of substantial injury to consumers, and other heightened-risk processing activities. This assessment requirement applies as of January 1, 2027 and is explicitly not retroactive, meaning processing activities that occurred before that date are not subject to after-the-fact assessment.

Second, the LDPA requires reasonable security measures, a requirement that multiple law-firm analyses reviewing the statute describe as a distinctive feature largely absent from other state comprehensive privacy laws; this framing should be read as reflecting the practice of legal commentators comparing Louisiana against its peer-state cohort, rather than as an independently verified regulatory first for the sector.

These controller-facing duties sit alongside Louisiana's pre-existing, separate data-breach-notification statute, which addresses breach notification obligations only and remains in force independent of the LDPA's broader consumer-privacy-rights framework; the breach statute is a narrower, longer-standing instrument that the LDPA supplements rather than replaces.

Outlook

Controllers should treat the January 1, 2027 effective date as the deadline for having data protection assessment processes and reasonable security programs operational, recognizing that the assessment obligation is prospective only and does not reach prior processing activity.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (9)
  1. ConfirmedDataGuidance — Data protection assessments are required under the LDPA for targeted advertising, sale of personal data, profiling with foreseeable consumer harm, and sensitive-data processing.observed
  2. UncertainDataGuidance — No DPO-appointment threshold was located under the LDPA.observed
  3. UncertainDataGuidance — No records-of-processing-activities obligation was located under the LDPA.observed
  4. UncertainDataGuidance — The LDPA establishes organizational duties for controllers and processors, though specific processor-contract clause requirements were not independently confirmed.observed
  5. ConfirmedDataGuidance — The LDPA requires implementation of reasonable security safeguards by controllers and processors.observed
  6. ProbableDataGuidance (legacy) — Louisiana has adopted an Insurance Data Security Law requiring insurers to implement an information-security program consistent with the NAIC Insurance Data Security Model Law.observed
  7. ConfirmedIAPP — Louisiana requires breach notification to affected individuals within 60 days, and its regulator notice is unique among states in requesting a list of affected Louisiana citizens.observed
  8. ConfirmedDataGuidance (secondary reporting) — The Louisiana Attorney General enforces breach-notification requirements under La. R.S. and La. Admin. Code, per citation §3074(J).observed
  9. ProbableDataGuidance — The LDPA's data-minimization and purpose-limitation obligations imply retention limits, though an explicit disposal duty was not independently confirmed.observed

#

No state-level transfer/adequacy/localisation regime exists; concept does not map onto a U.S. state JID.

Traffic-light rationale — RedNo state-level transfer/adequacy/localisation regime exists; concept does not map onto a U.S. state JID.

Sub-modules (6)

Transfer MechanismsRed

No LA-specific transfer mechanism regime.

Absence provenance: unavailable. Searched: Louisiana Data Privacy Act cross-border data transfer mechanism.

Claims (1):

  • Louisiana, as a U.S. state, has no adequacy-decision, SCC/BCR, transfer-impact-assessment, or data-localisation regime of its own.

Adequacy ReceivedRed

Not applicable to a U.S. state.

Absence provenance: unavailable. Searched: Louisiana adequacy decision received.

Adequacy GrantedRed

Not applicable to a U.S. state.

Absence provenance: unavailable. Searched: Louisiana adequacy decision granted.

Sccs And BcrsRed

No LA-specific SCC/BCR regime.

Absence provenance: unavailable. Searched: Louisiana SCC BCR requirement.

Transfer Impact AssessmentRed

No TIA requirement.

Absence provenance: unavailable. Searched: Louisiana transfer impact assessment requirement.

Data LocalisationRed

No data-localisation mandate identified.

Absence provenance: unavailable. Searched: Louisiana data localisation mandate.

Category narrative44 words

As a U.S. sub-federal jurisdiction, Louisiana has no adequacy-decision, SCC/BCR, transfer-impact-assessment, or data-localisation regime of its own; cross-border transfer governance for Louisiana-resident data is a matter of federal-level frameworks (not itself a Louisiana instrument) and is out of scope for a state-level DP baseline.

Sources and claims (1)
  1. ConfirmedDataGuidance — Louisiana, as a U.S. state, has no adequacy-decision, SCC/BCR, transfer-impact-assessment, or data-localisation regime of its own.observed

#

Federal sectoral overlays (GLBA/HIPAA/FCRA) apply generally; insurance overlay probable; several sub-modules unconfirmed.

Primary frameworkFederal sectoral statutes (GLBA, HIPAA, FCRA) + Louisiana Insurance Data Security Law
Traffic-light rationale — AmberFederal sectoral overlays (GLBA/HIPAA/FCRA) apply generally; insurance overlay probable; several sub-modules unconfirmed.

Sub-modules (7)

Financial Sector OverlayAmber

GLBA (federal) applies to Louisiana financial institutions; no LA-specific overlay confirmed.

Claims (1):

  • Financial institutions operating in Louisiana are subject to the federal Gramm-Leach-Bliley Act privacy and safeguards regime; no Louisiana-specific overlay was confirmed.

Health Sector OverlayAmber

HIPAA (federal) applies; no LA-specific overlay confirmed.

Claims (1):

  • Health data in Louisiana is governed by the federal HIPAA regime; no Louisiana-specific overlay was confirmed.

Telecoms And EprivacyRed

No LA-specific telecom/eprivacy statute identified.

Absence provenance: unavailable. Searched: Louisiana telecoms eprivacy cookie law.

Claims (1):

  • No Louisiana-specific telecoms/eprivacy overlay was identified.

Employment DataRed

No LA-specific employment-data statute identified.

Absence provenance: unavailable. Searched: Louisiana employment data privacy law.

Claims (1):

  • No Louisiana-specific employment-data privacy overlay was identified.

Credit And ScoringAmber

FCRA (federal) applies; no LA-specific overlay confirmed.

Claims (1):

  • Credit-scoring practices in Louisiana are governed by the federal Fair Credit Reporting Act; no Louisiana-specific overlay was confirmed.

EducationRed

No LA-specific student-data-privacy statute confirmed.

Absence provenance: unavailable. Searched: Louisiana student data privacy law education.

Claims (1):

  • No Louisiana-specific student-data-privacy statute was confirmed.

InsuranceAmber

Louisiana Insurance Data Security Law (NAIC-model) confirmed to exist.

Claims (1):

  • Louisiana has adopted an Insurance Data Security Law modeled on the NAIC Insurance Data Security Model Law, imposing information-security and breach-reporting duties on licensees.
Category narrative73 words

Financial and health data in Louisiana are governed by federal GLBA and HIPAA respectively, per the seed disambiguation: <cite index="1-1">Louisiana requires notification of breaches pursuant to §51:3071 et seq.</cite> operates alongside these federal regimes. Louisiana has also adopted an NAIC-model Insurance Data Security Law: a dedicated legal-research entry confirms its existence as Louisiana-specific instrument, though effective-date/citation detail requires primary-source confirmation. Telecoms/eprivacy, employment-data, credit-scoring and education sectoral overlays specific to Louisiana were not confirmed.

Periodic update · new data 2026-09-28

Sectoral Watch

The Louisiana Data Privacy Act contains customary data-level exemptions for information already governed by established federal sectoral frameworks: health-related data covered by HIPAA, financial data covered by the Gramm-Leach-Bliley Act, credit data covered by the Fair Credit Reporting Act, education data covered by FERPA, and employee data. This is a probable-confidence finding, sourced from secondary law-firm analysis rather than independently verified against the specific exemption clauses of the enrolled statutory text this cycle, so the precise boundaries of each exemption should be treated as provisional pending primary-text confirmation.

These exemptions follow the standard pattern seen across the 2026 wave of state comprehensive privacy laws, under which data already subject to a specific federal regulatory regime is carved out of the state omnibus framework to avoid duplicative or conflicting compliance obligations for entities such as banks, health-data handlers, credit bureaus, and educational institutions operating in Louisiana.

Outlook

Primary-text verification of the LDPA's specific exemption clauses is the key open item for this sub-module; until confirmed, entities relying on a sectoral exemption should treat their exempt status as probable rather than certain ahead of the January 1, 2027 effective date.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (7)
  1. ProbableFederal Trade Commission — Financial institutions operating in Louisiana are subject to the federal Gramm-Leach-Bliley Act privacy and safeguards regime; no Louisiana-specific overlay was confirmed.observed
  2. ProbableFederal Trade Commission — Health data in Louisiana is governed by the federal HIPAA regime; no Louisiana-specific overlay was confirmed.observed
  3. UncertainFederal Trade Commission — No Louisiana-specific telecoms/eprivacy overlay was identified.observed
  4. UncertainFederal Trade Commission — No Louisiana-specific employment-data privacy overlay was identified.observed
  5. ProbableFederal Trade Commission — Credit-scoring practices in Louisiana are governed by the federal Fair Credit Reporting Act; no Louisiana-specific overlay was confirmed.observed
  6. UncertainFederal Trade Commission — No Louisiana-specific student-data-privacy statute was confirmed.observed
  7. ProbableDataGuidance (legacy) — Louisiana has adopted an Insurance Data Security Law modeled on the NAIC Insurance Data Security Model Law, imposing information-security and breach-reporting duties on licensees.observed

#

UOOM and cross-context ad opt-out confirmed but not yet effective; several sub-modules unconfirmed.

Primary frameworkLouisiana Data Privacy Act (enacted, effective 2027-01-01)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberUOOM and cross-context ad opt-out confirmed but not yet effective; several sub-modules unconfirmed.

Sub-modules (6)

Cookies And TrackersAmber

No LA-specific cookie law; general FTC §5 applies.

Claims (1):

  • No Louisiana-specific cookie/tracker consent statute was identified; general FTC Act §5 deceptive-practices authority applies to misleading tracking disclosures.

Dark PatternsRed

No explicit dark-pattern prohibition confirmed beyond general UDAP classification.

Absence provenance: unavailable. Searched: Louisiana Data Privacy Act dark pattern prohibition.

Claims (1):

  • No explicit dark-pattern prohibition specific to Louisiana was confirmed.

Opt Out SignalsAmber

Universal opt-out mechanism support included in LDPA.

Claims (1):

  • The LDPA includes support for universal opt-out mechanisms alongside a sunsetting right-to-cure provision.

Clean Rooms And DcrRed

No provision identified.

Absence provenance: unavailable. Searched: Louisiana Data Privacy Act clean room data collaboration.

Claims (1):

  • No clean-room/data-collaboration-room provision was identified under the LDPA.

Cross Context AdvertisingAmber

Opt-out of targeted advertising and sale confirmed.

Claims (1):

  • Consumers may opt out of targeted advertising and the sale of personal data under the LDPA.

Direct MarketingAmber

Covered indirectly via targeted-advertising opt-out; no dedicated suppression statute confirmed.

Claims (1):

  • Direct-marketing suppression is addressed indirectly via the LDPA's targeted-advertising opt-out right; no dedicated direct-marketing suppression statute was confirmed.
Category narrative92 words

The LDPA (effective 2027-01-01) includes universal opt-out mechanism support and opt-out rights for targeted advertising and sale of personal data: <cite index="21-4,21-5">The bill, approved 94-0 by the House 18 May, would apply to companies earning more than USD25 million in revenue and those processing the personal data of more than 75,000 people or deriving more than 50% of their revenue from the sale of personal data. Sensitive data limitations, universal opt-out mechanisms and a sunsetting right to cure are included in the bill.</cite> No LA-specific cookie-consent, dark-pattern, or clean-room statute was confirmed.

Periodic update · new data 2026-09-28

AdTech & Commercial Privacy

The Louisiana Data Privacy Act requires controllers to honor universal opt-out signals, a browser- or device-based mechanism through which a consumer can communicate an opt-out preference for targeted advertising and data sales without contacting each controller individually. This requirement places Louisiana alongside Colorado and California among the state comprehensive privacy laws that mandate recognition of such signals, distinguishing it from peer states that permit but do not require universal opt-out recognition. This finding carries probable rather than confirmed confidence, sourced from secondary law-firm analysis.

The universal opt-out obligation operates alongside the LDPA's individual consumer right to opt out of targeted advertising and data sales directly, addressed under Data Subject Rights: together, these two mechanisms give Louisiana consumers both a per-controller opt-out right and a signal-based mechanism intended to operate across multiple controllers simultaneously. Both become operative from the Act's January 1, 2027 effective date.

Outlook

Controllers engaged in targeted advertising or data sales involving Louisiana consumers should plan for universal opt-out signal recognition capability to be operational by January 1, 2027, alongside individual per-controller opt-out request handling.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (6)
  1. ProbableFederal Trade Commission — No Louisiana-specific cookie/tracker consent statute was identified; general FTC Act §5 deceptive-practices authority applies to misleading tracking disclosures.observed
  2. UncertainDataGuidance — No explicit dark-pattern prohibition specific to Louisiana was confirmed.observed
  3. ConfirmedIAPP — The LDPA includes support for universal opt-out mechanisms alongside a sunsetting right-to-cure provision.observed
  4. ConfirmedDataGuidance — Consumers may opt out of targeted advertising and the sale of personal data under the LDPA.observed
  5. ProbableDataGuidance — Direct-marketing suppression is addressed indirectly via the LDPA's targeted-advertising opt-out right; no dedicated direct-marketing suppression statute was confirmed.observed
  6. UncertainDataGuidance — No clean-room/data-collaboration-room provision was identified under the LDPA.observed

#

Sensitive-category coverage confirmed but not yet effective; ADM transparency and surveillance carveouts unconfirmed.

Primary frameworkLouisiana Data Privacy Act (enacted, effective 2027-01-01)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberSensitive-category coverage confirmed but not yet effective; ADM transparency and surveillance carveouts unconfirmed.

Sub-modules (6)

Profiling RestrictionsAmber

DPA required for profiling with foreseeable consumer harm.

Claims (1):

  • Profiling that presents a foreseeable risk of harm to consumers requires a data protection assessment under the LDPA.

Automated Decision Making TransparencyRed

No explicit ADM explanation/transparency right confirmed.

Absence provenance: unavailable. Searched: Louisiana Data Privacy Act automated decision making transparency right.

Claims (1):

  • No explicit ADM transparency or explanation right was confirmed under the LDPA.

Ai Risk AssessmentsAmber

DPA requirement functions as an AI-risk-assessment analog for high-risk processing.

Claims (1):

  • The LDPA's data-protection-assessment requirement for high-risk processing functions as an AI-risk-assessment analog, though no dedicated AI statute exists in Louisiana.

Biometric RegimeAmber

Biometric data is a sensitive category requiring consent; no dedicated BIPA-style statute confirmed.

Claims (1):

  • Biometric data is classified as a sensitive category requiring consumer consent under the LDPA; no dedicated Illinois-BIPA-style private-right-of-action biometric statute was confirmed for Louisiana.

Genetic DataAmber

Genetic data is a sensitive category requiring consent.

Claims (1):

  • Genetic data is classified as a sensitive category requiring consumer consent under the LDPA.

State Surveillance CarveoutsRed

No specific carveout provision identified.

Absence provenance: unavailable. Searched: Louisiana Data Privacy Act national security law enforcement exemption.

Claims (1):

  • No state-surveillance carveout provision was confirmed for the LDPA.
Category narrative74 words

The LDPA treats biometric and genetic data as sensitive categories requiring consent and mandates data-protection assessments for profiling that presents a foreseeable risk of harm: <cite index="32-5">Higher-risk processing activities such as targeted advertising, the sale of personal data, profiling with foreseeable consumer harm, and processing sensitive data require data protection assessments.</cite> No dedicated ADM-transparency/explanation right (Colorado-style) or standalone biometric statute (Illinois-BIPA-style private right of action) was confirmed for Louisiana; state-surveillance carveouts were not confirmed.

Periodic update · new data 2026-09-28

Algorithmic, Biometric & Surveillance Governance

The Louisiana Data Privacy Act's confirmed biometric-data provision is the separate-consent requirement addressed under Lawful Processing & Special Data: controllers deriving 50 percent or more of annual revenue from selling personal data must obtain separate consumer consent before selling biometric personal data specifically, alongside sensitive data generally, and must post a conspicuous notice of that possibility.

Secondary legal commentary reports that Louisiana came close to embedding AI-specific obligations into the LDPA's processor-duty provisions before the bill's final passage, describing the state as having 'almost' become the second US state to do so. This claim carries uncertain confidence: it has not been confirmed against the final enrolled statutory text this cycle, and the specific nature of the near-miss AI provision, what it would have required, and why it did not survive into the final Act, remains unclear from the available secondary sourcing. Readers should treat this as an open research question rather than a settled feature of the enacted law.

Outlook

Confirming whether any AI-specific processor-duty language survived into the LDPA's final enrolled text, and if not, what if anything was substituted in its place, is the key open item for this module in a future cycle.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (6)
  1. ConfirmedDataGuidance — Profiling that presents a foreseeable risk of harm to consumers requires a data protection assessment under the LDPA.observed
  2. UncertainDataGuidance — No explicit ADM transparency or explanation right was confirmed under the LDPA.observed
  3. ProbableDataGuidance — The LDPA's data-protection-assessment requirement for high-risk processing functions as an AI-risk-assessment analog, though no dedicated AI statute exists in Louisiana.observed
  4. ConfirmedDataGuidance — Biometric data is classified as a sensitive category requiring consumer consent under the LDPA; no dedicated Illinois-BIPA-style private-right-of-action biometric statute was confirmed for Louisiana.observed
  5. ConfirmedDataGuidance — Genetic data is classified as a sensitive category requiring consumer consent under the LDPA.observed
  6. UncertainDataGuidance — No state-surveillance carveout provision was confirmed for the LDPA.observed

#

Parental-consent social-media laws in force; LDPA minors provisions not yet effective; education/dependent-adult gaps.

Primary frameworkLouisiana social-media parental-consent/age-verification statutes (in force) + Louisiana Data Privacy Act (enacted, effective 2027-01-01)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberParental-consent social-media laws in force; LDPA minors provisions not yet effective; education/dependent-adult gaps.

Sub-modules (5)

Age VerificationAmber

Louisiana has enacted age-verification-related legislation for minors' online interactions (e.g., Secure Online Child Interaction and Age Limitation Act).

Claims (1):

  • Louisiana has enacted online age-verification-related legislation for minors' interactions, including the Secure Online Child Interaction and Age Limitation Act.

Minor Profiling BansAmber

Children's data sensitive-category consent + foreseeable-harm profiling DPA under LDPA.

Claims (1):

  • Children's data is a sensitive category requiring consent under the LDPA, and profiling with foreseeable harm (which may include minors) triggers a data-protection-assessment obligation.

Education SettingsRed

No education-sector-specific statute confirmed.

Absence provenance: unavailable. Searched: Louisiana student data privacy education sector law.

Claims (1):

  • No education-setting-specific children's-data provision was confirmed for Louisiana.

Dependent AdultsRed

No dependent-adult protection provision identified.

Absence provenance: unavailable. Searched: Louisiana dependent adult data protection elderly.

Claims (1):

  • No dependent-adult data-protection provision was identified for Louisiana.
Category narrative59 words

Louisiana has enacted minor-specific online-safety statutes requiring parental consent for social-media use, alongside Arkansas, Texas and Utah: <cite index="90-10">New laws in Arkansas, Louisiana, Texas and Utah essentially ban social media services from letting minors use their features without parental consent.</cite> The LDPA (2027) separately classifies children's data as sensitive, requiring consent. Education-setting-specific rules and dependent-adult protections were not confirmed.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ProbableDataGuidance — Louisiana has enacted online age-verification-related legislation for minors' interactions, including the Secure Online Child Interaction and Age Limitation Act.observed
  2. ConfirmedIAPP — Louisiana is among states (with Arkansas, Texas, and Utah) that require parental consent before minors may use social-media platform features.observed
  3. ProbableDataGuidance — Children's data is a sensitive category requiring consent under the LDPA, and profiling with foreseeable harm (which may include minors) triggers a data-protection-assessment obligation.observed
  4. UncertainDataGuidance — No education-setting-specific children's-data provision was confirmed for Louisiana.observed
  5. UncertainDataGuidance — No dependent-adult data-protection provision was identified for Louisiana.observed

#

Enforcement powers confirmed but not yet effective; no LA-specific enforcement-activity or funding data located.

Primary frameworkLouisiana Data Privacy Act (enacted, effective 2027-01-01)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberEnforcement powers confirmed but not yet effective; no LA-specific enforcement-activity or funding data located.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

AG exclusive enforcement, UDAP classification, 30-day cure period.

Claims (1):

  • The LDPA grants exclusive enforcement authority to the Louisiana Attorney General, classifies violations as unfair-or-deceptive trade practices, and provides a 30-day cure period.

Enforcement Activity IndexRed

No LA-specific major enforcement action identified in the last 12 months.

Absence provenance: unavailable. Searched: Louisiana Attorney General privacy enforcement action settlement 2025 2026.

Claims (1):

  • No Louisiana-specific major privacy enforcement action or settlement in the last 12 months was located.

Regulator Funding And CapacityRed

No headcount/funding signal identified.

Absence provenance: unavailable. Searched: Louisiana Attorney General privacy office funding staff.

Claims (1):

  • No funding or headcount signal for the Louisiana AG's privacy-enforcement capacity was located.

Collective Redress And Class ActionsAmber

No dedicated class-action mechanism under LDPA confirmed; general LA civil procedure may apply.

Claims (1):

  • No dedicated class-action mechanism specific to LDPA violations was confirmed; general Louisiana civil procedure may still permit class actions on other legal theories.

Private Right Of ActionAmber

No private right of action under LDPA; enforcement is AG-exclusive.

Claims (1):

  • The LDPA does not provide a private right of action; enforcement is exclusive to the Louisiana Attorney General.

Recent Developments 180DAmber

LDPA signed into law 2026-05-29, effective 2027-01-01 -- the defining recent development.

Claims (1):

  • Within the last 180 days, Louisiana enacted its first comprehensive consumer data privacy statute, the Louisiana Data Privacy Act (SB 386), signed 2026-05-29 and effective 2027-01-01.
Category narrative102 words

The LDPA (effective 2027-01-01) grants exclusive enforcement authority to the Louisiana Attorney General, treats violations as unfair-or-deceptive trade practices, and includes a sunsetting 30-day cure period: <cite index="32-3,32-4">Enforcement: Exclusive authority granted to the Louisiana Attorney General, with violations classified as unfair or deceptive trade practices. Review compliance requirements: Businesses operating in Louisiana should review the new data privacy framework to ensure compliance by January 1, 2027.</cite> <cite index="52-8">Enforcement: Handled by the Attorney General with a 30-day cure period for violations.</cite> No private right of action was identified. The single most significant development in the last 180 days is the LDPA's enactment itself.

Periodic update · new data 2026-09-28

Enforcement & Redress

The Louisiana Attorney General holds exclusive enforcement authority over the LDPA. Violations constitute unfair or deceptive trade practices under the state's Unfair Trade Practices and Consumer Protection Law, and the statute provides no private right of action, meaning consumers cannot pursue their own civil claims for LDPA violations; all enforcement runs through the Attorney General's office.

A transitional statutory cure period applies for the law's first several months in force. From January 1, 2027 through July 31, 2027, the Attorney General must provide 30 calendar days' written notice before investigating a suspected violation, and may not proceed with an investigation if the controller cures the violation within that period and provides written confirmation and supportive documentation of the cure to the Attorney General. This gives controllers a defined grace mechanism during the law's initial months in force, after which the notice-and-cure protection lapses and the Attorney General may pursue enforcement without a mandatory cure opportunity.

Outlook

The cure period's expiration on July 31, 2027 is the key marker: enforcement risk for controllers rises materially from August 1, 2027 onward, once the mandatory notice-and-cure mechanism is no longer available and the Attorney General's exclusive enforcement authority operates without that transitional protection.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (6)
  1. ConfirmedDataGuidance — The LDPA grants exclusive enforcement authority to the Louisiana Attorney General, classifies violations as unfair-or-deceptive trade practices, and provides a 30-day cure period.observed
  2. UncertainNAAG — No Louisiana-specific major privacy enforcement action or settlement in the last 12 months was located.observed
  3. UncertainNAAG — No funding or headcount signal for the Louisiana AG's privacy-enforcement capacity was located.observed
  4. ProbableDataGuidance — No dedicated class-action mechanism specific to LDPA violations was confirmed; general Louisiana civil procedure may still permit class actions on other legal theories.observed
  5. ConfirmedDataGuidance — The LDPA does not provide a private right of action; enforcement is exclusive to the Louisiana Attorney General.observed
  6. ConfirmedDataGuidance — Within the last 180 days, Louisiana enacted its first comprehensive consumer data privacy statute, the Louisiana Data Privacy Act (SB 386), signed 2026-05-29 and effective 2027-01-01.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metpass
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct7.14
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Louisiana, USA
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 56 claim(s) (56 category placement(s)), 27 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacydata localisation
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated. T1 anchors used for: regulator_and_framework (breach statute + LDPA enactment), controller_processor_duties.breach_notification (in-force statute), data_subject_rights and adtech/algorithmic/children modules (T1 LDPA enactment citations via T1-tier reporting on primary statute, with sub-module detail resting on T2 secondary reporting -- IAPP/DataGuidance -- since the LDPA's full statutory text was not independently fetchable). sectoral_watch.insurance and children.age_verification relied on T2 secondary confirmation of statute existence without primary-text verification. cross_border_and_adequacy correctly carries no populated claims beyond an absence-finding, as the concept does not map onto a US sub-federal JID. Several sub-modules (DPO thresholds, ROPA, ADM transparency, response-window deadlines, dependent adults, education settings, telecoms/eprivacy, employment data, state-surveillance carveouts) carry explicit absent_field_provenance because no confirming source was found in this research pass.

Unresolved questions (6):

  • Exact statutory text of SB 386 / LDPA (Ch. 20-B, Title 51) for: enumerated lawful bases, DPO appointment thresholds, ROPA obligations, consumer-request response-window deadlines, and ADM transparency/explanation rights.
  • Precise effective date and statutory citation of the Louisiana Insurance Data Security Law (NAIC-model) and whether Louisiana has fully adopted the model law's breach-reporting timelines.
  • Whether Louisiana has a dedicated K-12/higher-education student-data-privacy statute distinct from the children's online-safety acts identified.
  • Whether any Louisiana-specific enforcement actions (AG investigations, settlements) have occurred under the breach-notification law or in anticipation of the LDPA within the last 12 months.
  • Whether the LDPA's 'sunsetting right to cure' has a defined sunset date, and the precise territorial-scope language for non-established controllers.
  • Whether Louisiana's age-verification/parental-consent minors' laws (Act No. 456, Kids Online Protection and Anti-Grooming Act) remain in force as enacted or have been enjoined (cf. ongoing NetChoice-style litigation trends affecting peer-state minor online-safety laws).

Escalate to primary-source review: yes