Louisiana’s Data Privacy Act (LDPA) takes effect on January 1, 2027. If the person or entity operating your website does business in Louisiana and meets at least one statutory threshold, you may need to change how your website handles cookies, tracking technologies, targeted advertising, sales of personal data and visitor privacy choices.
The LDPA does not impose blanket cookie consent for every non-essential cookie. What matters is what cookies, pixels, scripts and other tracking technologies actually do with personal data.
Targeted advertising, sales of personal data and certain profiling can trigger opt-out rights, while sensitive-data processing generally requires consent. personal data collected from a known child is subject to the Act’s COPPA-based rule.
If your site falls within scope, use the time before January 1 to inventory trackers, map data flows, update privacy notices and controls, test visitor choices and complete any required data protection assessments.
What Is the LDPA and Does It Apply to Your Website?
Senate Bill 386 was signed on May 29, 2026, becoming Act No. 502.
The law applies to a person or entity doing business in Louisiana that meets one or more of these thresholds:
- Revenue: annual gross revenues exceed $25 million.
- Data volume: it annually buys, receives for commercial purposes, sells or shares for commercial purposes the Personal Information of at least 75,000 consumers, households or devices.
- Revenue from sales: it derives 50% or more of annual revenue from selling consumers’ Personal Information.
A “consumer” is a Louisiana resident acting in an individual or household context. Commercial and employment contexts are excluded.
The Act also contains entity- and data-level exemptions involving areas such as government bodies, GLBA-regulated financial institutions, HIPAA covered entities and business associates, nonprofits, higher education and specified healthcare, research, employment and FCRA-regulated information.
The $25 million annual gross-revenue threshold is a standalone test. A website operator can fall within the law’s scope even if it does not meet the 75,000-consumer, household or device threshold.
What Rights Will Louisiana Consumers Have?
Covered controllers will need to provide rights to:
- Confirm and access personal data being processed.
- Correct inaccuracies.
- Delete personal data.
- Obtain certain personal data in a portable format.
- Opt out of targeted advertising, the sale of personal data and certain profiling producing legal or similarly significant effects.
Controllers generally have 45 calendar days to respond to an authenticated request, with one additional 45-day extension available when reasonably necessary and properly communicated.
Before the law takes effect, make sure privacy-request workflows can receive, authenticate and respond to these requests within the required timeframe.
What Website Tracking Should Be Reviewed?
Start with the technologies actually running on the site, including:
- Advertising and first-party cookies.
- Pixels, analytics and remarketing tags.
- Social-media embeds.
- Session-recording and heatmap tools.
- Forms, chat widgets and customer-data platforms.
- Conversion tools and other third-party scripts.
For each technology, identify the personal data involved, who receives it, why it is processed and whether the activity could involve targeted advertising, a sale or sensitive data.
Cookie categories used by a Consent Management Platform are implementation tools, not statutory definitions. A “marketing cookie” is not automatically targeted advertising, and an “analytics cookie” is not automatically outside the Act.
How the LDPA Treats Targeted Advertising and Sales
Targeted advertising involves advertisements selected using personal data obtained or inferred from a consumer’s activities over time and across non-affiliated websites or applications to predict preferences or interests.
The definition excludes advertising based on:
- Activity within the controller’s own website or application.
- The context of the consumer’s current search or visit.
- A consumer request.
- Processing performed solely to measure or report advertising performance, reach or frequency.
An advertising pixel or analytics platform can support several uses, so the legal treatment depends on its configuration and data flow rather than the vendor name.
A sale of personal data generally involves exchanging personal data with a third party for monetary or other valuable consideration.
The definition contains exclusions for certain processor and affiliate disclosures, disclosures needed for requested products or services, consumer-directed disclosures and specified business transactions.
For both activities, review what data is disclosed, who receives it, what the recipient can do with it and whether an opt-out must change or stop the relevant processing.
Prepare for Browser-Level Privacy Signals and GPC
The Act allows consumers to designate an authorised agent to exercise opt-out rights relating to targeted advertising and sales. The designation may use technologies including a website link, browser setting, browser extension or global electronic-device setting.
The controller may use commercially reasonable efforts to verify the consumer’s identity and the agent’s authority. The technology must also satisfy statutory conditions, including that it:
- Does not rely on a default setting.
- Reflects an affirmative, freely given and unambiguous choice.
- Is consumer-friendly and easy to use.
Global Privacy Control (GPC) is a technical signal for communicating a privacy preference, but the statute does not automatically treat every GPC implementation as a valid Louisiana authorised-agent request.
The LDPA does not name GPC. Its authorised-agent provisions refer to technologies such as browser settings, browser extensions and global device settings, subject to statutory conditions.
Identify Where Consent Will Be Required
The Act generally uses an opt-out model for targeted advertising, sales and qualifying profiling. Sensitive-data processing generally requires consent, with a separate rule for personal data collected from a known child.
Sensitive data includes specified information relating to:
- Racial or ethnic origin.
- Religious beliefs.
- Mental or physical health diagnoses.
- Sexuality.
- Citizenship or immigration status.
- Genetic or biometric data used for unique identification.
- Personal data from a known child.
- Precise geolocation data.
For personal data collected from a known child, the Act requires processing in accordance with the rules, regulations and exceptions of COPPA.
Where consent is required, it must be a clear affirmative act showing a freely given, specific, informed and unambiguous agreement. Broad terms, inactivity, merely hovering over content, closing or pausing content, and dark patterns do not satisfy that standard.
The Act also restricts processing for purposes that are neither reasonably necessary to nor compatible with disclosed purposes unless consent is obtained.
Where the LDPA requires consent, inaction is not consent.
What Should Be Updated in Privacy Notices?
A covered controller’s privacy notice should describe:
- Categories of personal data processed, including sensitive data where applicable.
- Processing purposes.
- Consumer rights and how to exercise them.
- The appeal process.
- Categories of personal data sold and relevant third parties, where applicable.
- Methods for submitting privacy requests.
If personal data is sold or processed for targeted advertising, the controller must clearly disclose that activity and explain how consumers can opt out.
The Act also prescribes notices in certain sensitive-data sales situations:
- “NOTICE: We may sell your sensitive personal data.”
- “NOTICE: We may sell your biometric personal data.”
Before January 1, 2027, compare the privacy notice with the site’s actual data flows so disclosures and technical behaviour match.
When Does the LDPA Require a Data Protection Assessment?
Controllers will need data protection assessments for specified activities including:
- Targeted advertising.
- Sales of personal data.
- Sensitive-data processing.
- Certain higher-risk profiling.
- Other processing presenting a heightened risk of harm.
Assessments apply to relevant processing activities as of January 1, 2027 and are not retroactive. A comparable assessment completed under another law may satisfy Louisiana’s requirement if its scope and effect are reasonably comparable.
What Websites Should Do Before January 1, 2027
- Check scope: confirm whether the operator meets a statutory threshold and whether an exemption applies.
- Inventory and map: identify cookies, pixels, scripts, personal data, recipients and downstream uses.
- Classify advertising and sales: determine which data flows fall within the relevant definitions.
- Review consent requirements: identify sensitive data, known-child data and incompatible secondary purposes.
- Update controls and disclosures: review privacy notices, opt-outs, consent choices and browser-level signals.
- Assess and test: complete required assessments and confirm that privacy choices change the relevant scripts and data flows.
BEFORE JANUARY 1, 2027: Confirm scope, map tracking and data flows, configure applicable privacy choices, test the implementation and complete required data protection assessments.
LDPA vs. GDPR: Does Louisiana Require GDPR-Style Cookie Consent?
The main difference is what triggers the privacy control. Under Article 5(3) of the ePrivacy Directive, storing information on or accessing information from a user’s device generally requires consent unless an exception applies. The GDPR then governs resulting processing of personal data, with GDPR Article 6 providing several possible lawful bases.
| Topic | Louisiana LDPA | GDPR and eprivacy |
|---|---|---|
| Cookies and trackers | No equivalent general device-storage rule. Treatment depends on the processing performed with personal data. | Article 5(3) of the ePrivacy Directive generally requires consent for storing or accessing information on a device unless an exception applies. |
| Personal-data processing | Uses specific rights, duties, opt-outs and consent requirements rather than the GDPR lawful-basis framework. | GDPR Article 6 provides several lawful bases, so consent is not required for every processing activity. |
| Targeted advertising | Consumers may opt out of this processing as defined by the Act. | eprivacy consent requirements may apply to device access before the GDPR lawful basis for later processing is considered. |
| Sensitive data | Processing generally requires consent; known-child data follows Louisiana’s COPPA-based rule. | Special-category data is governed by GDPR Article 9. explicit consent is one possible condition, but not the only one. |
| Browser-level signals | Authorised-agent requests may use browser settings, extensions and global device settings, subject to statutory conditions. | A browser-level opt-out signal does not replace consent where Article 5(3) requires it. |
An EU GDPR/ePrivacy banner should therefore not simply be copied into a Louisiana configuration.
How the LDPA Differs From Other U.S. State Privacy Laws
Existing California, Colorado, Texas or Virginia privacy controls can provide useful infrastructure, but they should not automatically be treated as sufficient for Louisiana.
| Jurisdiction | Key difference from Louisiana | Website impact |
|---|---|---|
| California | California separately defines “sale” and “sharing” under California Civil Code §1798.140, with sharing covering cross-context behavioural advertising. Its opt-out framework appears in §1798.135. Louisiana regulates sales and targeted advertising as separate concepts. | Do not automatically copy a California “Do Not Sell or Share” classification into Louisiana. |
| Colorado | Colorado provides qualifying Universal Opt-Out Mechanisms under C.R.S. §6-1-1306(1)(a)(IV). The Colorado Attorney General maintains guidance on recognised opt-out mechanisms. Louisiana instead uses an authorised-agent framework subject to specific conditions. | Similar technical infrastructure may be reusable, but the legal test differs. |
| Texas | The Texas Data Privacy and Security Act, Business & Commerce Code Chapter 541, covers sensitive-data consent, targeted advertising, privacy notices and assessments. Scope appears in §541.002 and controller duties in §541.101. | Existing Texas controls may help, but Louisiana requires its own scope and notice analysis. |
| Virginia | Virginia defines a sale as an exchange for monetary consideration in Va. Code §59.1-575. Louisiana uses monetary or other valuable consideration. | A data flow not treated as a Virginia sale may still require separate Louisiana analysis. |
For a multi-state site, map the underlying data flows first, then apply each state’s definitions and regional controls.
Enforcement and the 2027 Cure Period
The Louisiana Attorney General enforces the Act. Under Act No. 502, violations are treated as unfair or deceptive trade practices under Louisiana’s Unfair Trade Practices and Consumer Protection Law.
From January 1 through July 31, 2027, the Act provides a temporary cure procedure. Before initiating an investigation, the Attorney General must provide written notice and allow 30 calendar days to cure the alleged violation, provide a written statement and supporting documentation, and make necessary policy changes.
The Act does not set a flat fine for every privacy violation.
Under R.S. 51:1407(A), a court may impose up to $5,000 per violation where it finds intent to defraud. R.S. 51:1416 separately allows up to $5,000 per violation for violating an injunction or assurance of voluntary compliance.
The LDPA excludes the private rights of action provided by R.S. 51:1409 and R.S. 51:1409.1.
How a CMP Can Help Manage Privacy Choices Under the LDPA
A Consent Management Platform (CMP) can help turn these privacy decisions into working controls, including opt-outs, consent choices, regional configurations and technical control of scripts and trackers.
Features particularly relevant to this preparation work include:
- Cookie Scanner: identifies cookies and related technologies, helping build the tracker inventory needed for the legal review.
- User consents recording: records visitor choices where consent is required and can support internal documentation.
- Third-party cookie blocking: helps enforce privacy choices by controlling relevant third-party technologies.
- Geo targeting: can apply different configurations across jurisdictions. Location detection should not be treated as proof of legal residency.
CMPs can also provide additional privacy-management capabilities, including:
- Automatic script blocking
- Consent events
- Global privacy regulation support
- 42 languages
- Google Consent Mode v2
- Google Tag Manager integration
- Automatic monthly scans
- Advanced reporting
- Cookie Banner sharing
- IAB TCF 2.3 integration
- Privacy Policy Generator
- Cookie Policy Generator
CookieScript is a Consent Management Platform (CMP) that Google includes among the CMP partners available for Consent Mode setup. It is also a Google-certified CMP with Gold tier status.
A 14-day free trial of the Plus plan is available without requiring a credit card.
A CMP can support scanning, configuration and technical enforcement, but it does not determine the legal classification of a particular data flow.
Conclusion
Preparing for January 1, 2027 should start with the site’s actual data flows so privacy notices, visitor choices and technical behaviour all match the processing taking place behind it.

