US State Law United States

State Privacy Cure Periods: Tracker and Expiration Map

Which state privacy laws still offer cure periods, how long the windows run, which sunsets have expired, and how AGs actually use cure notices in enforcement.

Regulation

Cure provisions of comprehensive state privacy laws (2023-2026)

Max Penalty

Post-cure (or where none applies): $2,500-$50,000 per violation depending on state

Enforcing Authority

State attorneys general; California CPPA

Official Source

cppa.ca.gov

Executive Summary

  • Cure periods, statutory windows to fix violations before enforcement, are splitting into three groups: permanent (Virginia, Utah, Iowa, Tennessee, Texas), expired (California's original CCPA cure, Colorado, Connecticut), and sunsetting through 2025-2026 (Oregon, Delaware, New Hampshire, New Jersey, Montana, Minnesota).
  • Permanent cure rights vary in length and condition: Virginia and Utah give 30 days, Iowa 90, Tennessee 60, and Texas 30 with a required written statement that violations were cured and will not recur.
  • Where cure has expired or never existed, AGs and the CPPA move directly to investigation and penalties, weighing good faith and violation history as discretion factors instead.
  • Enforcement practice matters more than the statute: cure notices function as evidence-gathering (the response documents your practices), and 'cured' violations resurface as aggravating history in later actions.
  • The design implication: build compliance as if no cure period exists, because in the largest markets (California, Colorado, Connecticut) none does.

Cure periods were the state legislatures’ training wheels, and they are coming off on schedule. The laws’ drafters traded business support for grace windows, sunset most of them, and the sunsets are now arriving: Colorado’s and Connecticut’s expired in 2025, the January-2025 cohort’s expire through 2026, and California never rebuilt the one the CPRA removed. What remains is a patchwork where the strictest enforcers owe you nothing and the friendliest owe you 30 to 90 days, once.

The current map

StatusStatesWindow
PermanentVirginia, Utah, Indiana, Kentucky, Texas*30 days (*with no-recurrence statement)
Permanent, longerTennessee (60), Iowa (90)60-90 days
ExpiredCalifornia, Colorado, ConnecticutNone (discretionary factors only)
Sunsetting/sunsetOregon, Delaware, New Hampshire, New Jersey, Montana, MinnesotaCheck current date vs. statute

What this means operationally

Design for zero. The CPPA’s enforcement actions and Texas’s litigation posture define the real standard: violations found in a sweep proceed on the regulator’s discretion, not your statutory grace. The multi-state baseline should assume immediate enforceability everywhere.

Keep a notice-response runbook. Named owner, 48-hour assessment, evidence-preserving response drafting, and pre-approved fix paths for the common findings (opt-out links, GPC handling, notice mismatches). The response is discovery; legal reviews it as such.

Track the sunsets with dates, not vibes. Each expiration shifts a state from cure-first to discretion-first; the enforcement tracker logs how each AG behaves after its window closes, and amendment cycles (Montana 2025) can move dates mid-life.

Fix before they find. The findings AGs cure-notice most, broken opt-outs, missing rights mechanisms, notices contradicting practice, are externally visible and cheap to self-audit: run a free scan before a regulator runs theirs.

Frequently Asked Questions

Which states still have mandatory cure periods, and how long?

Permanent: Virginia (30 days), Utah (30), Iowa (90), Tennessee (60), Indiana (30), Kentucky (30), and Texas (30, conditioned on a written no-recurrence statement). Time-limited windows still open into 2025-2026 in several January-2025 states (Oregon's 30-day right ran to January 1, 2026; Delaware's 60-day to December 31, 2025; New Hampshire's 60-day through 2025; New Jersey's 30-day for its first 18 months; Montana's restructured by its 2025 amendments). Always verify the current date against the statute, this is the fastest-moving variable in state privacy law.

Where has cure already ended?

California: the CCPA's original 30-day cure was removed by the CPRA in 2023; the CPPA and AG may consider cure efforts but owe no window (Sephora, Honda, and Todd Snyder all proceeded to penalties). Colorado: the 60-day right expired January 1, 2025. Connecticut: its cure right converted to discretionary January 1, 2025. These three plus Texas's conditional regime cover the most active enforcers, which is why cure-dependent compliance strategies are obsolete.

What actually happens when an AG sends a cure notice?

The notice identifies alleged violations and starts the clock; your response, describing practices, fixes, and evidence, becomes part of the investigative record. Oregon's enforcement reports show most matters closing after cure, but the closures are logged: a second notice on the same subject meets less patience. Texas pairs notices with sweep letters and has sued where responses were inadequate (the GM and Allstate matters began with investigation, not cure closure). Treat every notice as pre-litigation discovery.

Does curing erase the violation?

It bars the enforcement action for that violation where the statute says so, nothing more. The conduct remains known to the regulator, informs discretion in future matters, and in Texas the written no-recurrence statement converts any repeat into an aggravated, documented breach of your own representation. Where private rights exist (CCPA's breach provision), the consumer's 30-day cure notice cannot cure an actual breach's statutory damages exposure, courts have read the cure right narrowly there.

How should cure periods figure in compliance planning?

As margin, not strategy. Build to the no-cure states' standard (California, Colorado, Connecticut), keep externally visible controls, opt-out links, GPC handling, notices, continuously correct since sweeps sample them without warning, and maintain a rapid-response capability for notices: 30 days is short for fixes involving ad-stack changes or vendor renegotiation. The one strategic use is prioritization: a genuine gap discovered internally in a permanent-cure state can be scheduled behind no-cure-state work.

Regulatory Crosswalk

CCPA/CPRA (discretionary)VCDPA (permanent 30-day)Colorado CPA (expired)

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.