Law / United States / Louisiana

Louisiana Data Privacy Act (Act No. 502), applicability and controller duties

La. R.S. 51:1780.1, 1780.2, 1780.4

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force in 100 days, effective 1 January 2027.

A comprehensive regime rule binding private bodies.

As of 28 August 2026.

What it requires

  • Determine whether you do business in Louisiana and meet at least one of the LDPA's three independent thresholds ($25 million annual gross revenue, 75,000 or more consumers, households, or devices processed annually, or 50% or more of revenue from selling personal data) before relying on any exemption.
  • Confirm whether a sector exemption applies. The LDPA excludes state agencies and political subdivisions, Gramm-Leach-Bliley Act (GLBA)-regulated financial institutions, nonprofits, higher-education institutions, and Health Insurance Portability and Accountability Act (HIPAA)-covered entities and business associates.
  • Prepare to comply beginning January 1, 2027; the LDPA is enacted but not yet in force.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Louisiana Data Privacy Act, enacted as Act No. 502 of the 2026 Regular Session (formerly SB 386) and signed by Governor Landry on May 29, 2026, applies to a person or entity doing business in Louisiana that meets any one of three independent thresholds: annual gross revenue exceeding $25 million, annually buying, receiving, selling, or sharing for commercial purposes the personal data of 75,000 or more consumers, households, or devices, or deriving 50% or more of annual revenue from selling personal data.

Exemptions include state agencies and political subdivisions, Gramm-Leach-Bliley Act (GLBA)-regulated financial institutions, nonprofits, higher-education institutions, and Health Insurance Portability and Accountability Act (HIPAA)-covered entities and business associates, plus a separate household or personal-activity carve-out. Controllers and processors carry General Data Protection Regulation (GDPR) and VCDPA-style duties, including data protection assessments, processor contracts, and purpose limitation, under Sec. 1780.4. The Act takes effect January 1, 2027.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • processes_biometrics
  • processes_voice

Read the law

official Louisiana Act No. 502 (2026 Regular Session) text, as signed, Louisiana Legislature

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app