Louisiana’s Comprehensive Data Privacy Law to Head to the Governor’s Desk—What Businesses Need to Know About Senate Bill 386
Louisiana’s Comprehensive Data Privacy Law to Head to the Governor’s Desk—What Businesses Need to Know About Senate Bill 386
Louisiana is poised to join the growing roster of states with comprehensive consumer data privacy legislation. Senate Bill 386 (“SB 386”), the Louisiana Data Privacy Act, has passed the Louisiana Legislature and will soon be sent to Governor Jeff Landry for signature. Governor Landry will have 10 days to veto or sign the bill; if he does neither, the bill is adopted automatically. The bill passed unanimously in both the Senate and House, so enactment is expected.
If enacted, the Act will take effect on January 1, 2027, giving covered businesses approximately seven months to prepare to comply. Businesses that have already worked to comply with existing state laws, such as the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) and the Texas Data Privacy and Security Act (TDPSA), will find SB 386 broadly familiar. But, there are meaningful differences in scope and enforcement posture, so businesses already complying with other state’s laws should not assume the current compliance programs fully conform with the Louisiana requirements.
Who Is Covered by the LDPA
SB 386 applies to any person or entity that does business in Louisiana and meets at least one of three thresholds: (1) annual gross revenues exceeding $25 million; (2) annually buying, receiving for the business’ commercial purposes, selling, or sharing the personal information of 75,000 or more consumers, households, or devices for commercial purposes; or (3) deriving 50% or more of annual revenues from the sale of consumers’ personal information. A “consumer” is defined as a Louisiana resident acting in an individual or household context, expressly excluding individuals acting in a commercial or employment capacity.
Selling personal information is broader than the traditional sense. “Sale of personal data” means “the exchange of personal data for monetary or other valuable consideration by the controller to a third party.” It does not include: (a) disclosing personal information to a processor who processes the data on the controller’s behalf; (b) disclosing personal data to a third party for the purpose of providing a product or service requested by the consumer; (c) disclosure or transfer to an affiliate of the controller; (d) disclosing information that the consumer intentionally made available to the general public through a mass media channel that was not restricted to a specific audience; (e) disclosing information at the direction of a consumer or when the consumer uses the controller to interact with a third party; or (f) disclosure to a third party as part of an actual or proposed merger, acquisition, or similar activity.
SB 386 adopts common understandings of controllers and processors in other data protection laws. The “controller” is a person that, in whole or in part, determines the purposes and means of processing personal data; meanwhile, a processor means a person that processes personal data on behalf of a controller, and is not making decisions about the purposes or means.
Who Is Exempted From the LDPA
The most significant exemption from the LDPA is personal information processed in either the employment context or the business-to-business context. So, if a business does not sell or market to individuals, and its goods and services are strictly business to business products and services, then the LDPA is unlikely to apply. However, if the business sells to both businesses and individuals, then closer evaluation is required to determine exemptions.
The LDPA also includes exemptions common in other state privacy laws for entities and data already regulated by other federal or state law. Exempt entities include state agencies, political subdivisions, financial institutions subject to the Gramm-Leach-Bliley Act, covered entities and business associates governed by HIPAA, nonprofit organizations, institutions of higher education, and electric public utilities. Exempt data categories include protected health information, health records, patient identifying information, data regulated by the Fair Credit Reporting Act, the Driver’s Privacy Protection Act, and the Family Educational Rights and Privacy Act. Where an entity claims an exemption, the entity bears the burden of demonstrating the processing qualifies for an exemption, is reasonably necessary and proportionate to the business case, and is adequate, relevant and limited to what is necessary.
OK, So I Am Likely Covered. What Is Required?
The LDPA requires implementation of data minimization practices, data transparency, and respect for consents (or lack thereof) to process personal information.
Controllers must limit personal information collection to what is adequate, relevant, and reasonably necessary for processing personal information and disclose that processing and purpose to the consumer. Controllers must also implement and maintain sufficient administrative, technical, and physical data security practices to protect confidentiality, integrity, and accessibility of personal information. Controllers are prohibited from: (1) processing personal information for a reason now compatible with the reason provided to the consumer when the consumer provided the personal information unless the consumer provided consent; (2) processing personal information in a discriminatory way; (3) discriminating against consumers who exercise their consumer rights under the Act (e.g., denying goods or services, charging different prices, or providing lesser quality of goods and services); (4) processing “sensitive data” of a consumer without obtaining a consumer’s consent; or (5) processing the sensitive data of a child in violation of the Children’s Online Privacy Protection Act of 1998, 15 U.S.C. § 6501, et seq. “Sensitive data” includes personal data concerning racial or ethnic origins, religious beliefs, mental or physical health diagnosis, sexuality, citizenship or immigration status, genetic or biometric data, children’s data, or precise geolocation. No sensitive data can be processed or sold without affirmative consumer consent.
Controllers must provide consumers (typically through a privacy policy) notice concerning the categories of personal data processed, the purpose for processing, how consumers may exercise their rights, the categories of data shared with third parties, and the methods available for submitting requests. If a controller sells sensitive data or biometric data, it must post a conspicuous notice stating as much. If the controller maintains a website, the controller must provide a mechanism on the website for the consumer to submit requests to exercise their data rights.
Processing relationships must be governed by a written contract specifying the nature and purpose of processing, the types of data subject to processing, the duration of processing, and the rights and obligations of both parties. Processors must ensure confidentiality, delete or return data at the controller’s direction upon completion of services, and allow reasonable compliance assessments.
If a controller possesses deidentified data, the controller must take reasonable measures to ensure the data cannot be associated with an individual, publicly commit to maintaining and using deidentified data without attempting to reidentify the data, and contractually obligate any recipient of the deidentified data to do the same.
We Have a New Potential Use for Personal Information Not Yet Implemented—Any Requirements Before We Implement?
Yes. Controllers are required to conduct and document data protection assessments for specified high-risk processing activities, including processing personal data for targeted advertising, sales of personal data, profiling that presents foreseeable risks of harm, and the processing of sensitive data. These assessments must weigh the benefits of processing against potential risks to consumer rights and factor in the use of deidentified data, the reasonable expectations of consumers, the context of processing, and the controller-consumer relationship. Data protection assessments are confidential, exempt from public records disclosure, and their production to the attorney general in connection with a civil investigation demand does not waive attorney-client privilege or work product protection.
Controllers are not required to conduct data protection assessments for processing that occurred prior to January 1, 2027, but assessments are required for activities that started before January 1, 2027 and will continue.
What Rights Does a Consumer Have Concerning Their Data?
SB 386 grants Louisiana consumers a robust suite of rights. Consumers may submit authenticated requests to a controller to: confirm whether the controller is processing their personal data and access that data; correct inaccuracies; delete personal data provided by or obtained about the consumer; obtain a portable copy of data previously provided to the controller in a readily usable digital format; and opt out of the processing of personal data for targeted advertising, the sale of personal data, or profiling that produces a legal or similarly significant effect. Parents or legal guardians may exercise these rights on behalf of a known child (defined as an individual younger than thirteen years of age).
Like other state privacy laws, controllers must respond to consumer requests within 45 calendar days, with a single 45-day extension available when reasonably necessary. If a request is denied, the controller must provide notice of the justification and instructions on how to appeal. Controllers must also establish a formal appeal process and respond to appeals within 60 days; if the appeal is denied, the controller must provide a mechanism for the consumer to submit a complaint to the attorney general.
Consumers may exercise their rights themselves or through an authorized agent. This authorized agent can include technology-based opt-out signals such as a browser setting, extension, or device-level global setting, so covered businesses must recognize universal opt-out signals such as Global Privacy Controls. However, the Act specifies that such technology must not rely on a default setting and must require an affirmative, freely given, and unambiguous consumer choice.
Enforcement
The attorney general has exclusive enforcement authority; the Act does not provide a private right of action for consumers. Violations constitute unfair and deceptive trade practices under Louisiana’s Unfair Trade Practices and Consumer Protection Law, which can carry civil penalties per violation, attorney fees, costs, and treble damages if the violation is found to be willful. Importantly, the Act includes a temporary cure period: from January 1, 2027 through July 31, 2027, the attorney general must provide written notice of an alleged violation at least 30 days before initiating an investigation, and the business may avoid enforcement by curing the violation, certifying the cure in writing, notifying affected consumers, and implementing internal policy changes to prevent recurrence. After July 31, 2027, this mandatory cure period expires.
Practical Considerations for Covered Businesses
Organizations that do business in Louisiana—or that process the personal data of Louisiana residents—should begin compliance planning now, even while the bill awaits the governor’s signature. Key action items include:
- Assess applicability. Determine whether your organization meets the $25 million revenue threshold, processes data of 75,000 or more Louisiana consumers or households, or derives 50% or more revenue from data sales. Organizations should also evaluate whether any entity-level exemption (e.g., HIPAA-covered entity, financial institution, nonprofit) applies to your organization.
- Map your data. Inventory the personal data and sensitive data your organization collects, processes, and shares with third parties. The Act’s definition of “sensitive data” encompasses categories—including precise geolocation data, biometric data processed for identification, and data collected from known children—that may not be addressed by existing privacy programs.
- Update privacy notices. Ensure your privacy notice meets the Act’s disclosure requirements: categories of data processed, purposes of processing, consumer rights and how to exercise them, categories of third parties receiving data, and the methods available for submitting requests. If you sell sensitive or biometric personal data, plan for the required conspicuous notices.
- Establish consumer request mechanisms. The Act requires at least two secure and reliable methods for consumers to submit rights requests, considering how consumers normally interact with your business. If you maintain a website, you must provide an online submission mechanism.
- Review processor contracts. Contracts with processors must include clear processing instructions, the nature and purpose of processing, data types, duration, confidentiality obligations, data return/deletion procedures, audit rights, and subcontractor flow-down requirements.
- Conduct data protection assessments. If you engage in targeted advertising, sell personal data, process sensitive data, or perform profiling that could produce legal or similarly significant effects, you will need documented assessments weighing benefits against consumer risks.
- Evaluate opt-out signal compliance. Determine how your organization will respond to technology-based opt-out requests (e.g., browser signals, device settings) while respecting the Act’s requirement that such signals reflect affirmative, non-default consumer choices.
What Comes Next
The bill now requires the governor’s signature to become law. Assuming signature or no action by June 1, the Louisiana Data Privacy Act will take effect on January 1, 2027 and enforcement will begin on August 1, 2027. Organizations should use the period between now and January 1, 2027, to build or adapt their compliance infrastructure. Those already subject to similar state privacy laws will have a head start but should not assume that existing programs satisfy all of Louisiana’s requirements, particularly with respect to the consent-based framework for sensitive data, the specific privacy notice mandates, and the nuanced approach to universal opt-out signals.
Kean Miller’s Support
Our Data Privacy & Cybersecurity team is actively monitoring SB 386 and its impact. If you have questions about how the Louisiana Data Privacy Act may affect your organization, or if you would like assistance conducting a compliance gap analysis, please reach out to your primary firm contact or any member of our team. We are here to help you navigate Louisiana’s evolving data privacy landscape and ensure your business is prepared well ahead of the January 2027 effective date.
Jessica Engler, PLS, CIPP/US, CIPM is Chair of Kean Miller’s Data Privacy & Cybersecurity practice, advising businesses on data governance, privacy compliance, cybersecurity risk, and incident response. She helps organizations navigate evolving state and federal privacy laws and build practical compliance strategies tailored to their operations.