Last updated: August 2026
Please note this is a highlighted overview and not a complete overview of privacy laws for this state. If you would like a complete review of this state's privacy laws or a multi-state privacy compliance cheat sheet on specific topics, please contact Vivien Peaden at vpeaden@bakerdonelson.com.
Disclaimer: These materials do not constitute legal advice and should not be substituted for the advice of legal counsel.
The Louisiana Data Privacy Act (LDPA)
Effective Date: January 1, 2027.
1. Applicability Thresholds:
Subject to certain entity-level and data-level exemptions, the LDPA applies to any individual or legal entity doing business in Louisiana that meets any of the following criteria:
- Having $25 million or more in revenue;
- Annually buys, receives, sells, or shares for commercial purposes the personal information of more than 75,000 Louisiana consumers, households, or devices;
- Derives 50 percent or more of its annual revenue from selling consumer personal information.
2. Exemptions and Key Definitions:
- Entity-level Exemptions: Louisiana agencies or political subdivisions; entities subject to the Gramm-Leach-Bliley Act (GLBA) or HIPAA regulations; non-profit organizations; higher education institutions; electric public utilities; and registered public opinion poll conductors.
- Data-level Exemptions: Certain data types are also exempt, including data collected in commercial (B2B), employment, or benefits contexts; data covered by HIPAA and other health care statutes; and data governed by the GLBA, the Family Educational Rights and Privacy Act (FERPA), the Fair Credit Reporting Act (FCRA), or the Driver's Privacy Protection Act (DPPA), among other exemptions.
- Sales of Personal Data: Similar to California, "sales of personal data" is defined broadly as "the exchange of personal data for monetary or other valuable consideration by the Controller to a third party."
- Sensitive Data: Defined broadly under the LDPA to include:
- Personal data about an individual's ethnicity, religion, health diagnosis, sexuality, citizenship, etc.;
- Genetic or biometric data processed to uniquely identify an individual;
- Personal data of children under 13; and
- Precise geolocation data (i.e., within a radius of 1,750 feet).
The LDPA requires Controllers to obtain consumer consent before processing or selling sensitive data. Further, the Controller must conduct and document a data protection assessment for processing sensitive data.
3. Controller Obligations:
In addition to responding to Consumer rights requests, a Controller must meet the following obligations:
- Data Processing Agreement (DPA): A written contract (the DPA) between the Controller and Processor must govern processing activities. The DPA must include clear processing instructions, the nature and duration of processing, and the types of data processed, among other requirements.
- Data Protection Assessment: Yes, where processing presents a heightened risk of harm to Consumers, including targeted advertising, sales of personal data, processing sensitive data, data processing that presents a heightened risk of harm, or certain automated data processing that produces a significant effect concerning Consumers.
- Privacy Notice: A Controller must provide consumers with a privacy notice, including categories of personal data sold to third parties and the identity of those third parties. If a Controller sells sensitive personal data (such as biometric data), the Controller must provide specific disclosures in the Privacy Notice.
- Data Minimization and Purpose Limitation of Data Processing: The LDPA requires Controllers to: (i) limit the collection of personal data to what is "adequate, relevant, and reasonably necessary in relation to the purpose for which that personal data is processed, as disclosed to the consumer"; and (ii) not process personal data for purposes that are incompatible with the "disclosed purpose" without the consumer's consent.
4. Consumer Rights:
Subject to certain exceptions, Louisiana consumers have the right to:
- Confirm whether a Controller is processing their personal data and access it;
- Correct inaccuracies in the consumer's personal data;
- Delete personal data provided by or obtained about the consumer;
- Obtain a digital copy of their personal data processed by the Controller, if available (known as Data Portability);
- Opt out of data processing for targeted advertising, sales of personal data, and profiling in furtherance of "a decision that produces a legal or similarly significant effect concerning the consumer"; and
- Appeal a Controller's decision regarding the above request.
5. Enforcement and Penalties:
Private Right of Action: None
Penalties: Up to $5,000 per violation.
Cure Period: A 30-day cure period applies after receiving a notice of violation from the Louisiana Attorney General. This grace period is available only from January 1, 2027, through July 31, 2027.