Skip to the main content.

Featured resource

Ban the Box Guide

Our new Ban the Box Guide makes it easier than ever to decipher the patchwork of fair chance laws across the country. Check the map to quickly identify what laws apply to you.

Visit the guide ›

PBSA Accredited

Verified Credentials is proud to be accredited by PBSA and an original founding member. Our accreditation confirms that our policies, processes, and team member training meet rigorous industry compliance standards.

3 min read

Louisiana's SB386: What Employers Need to Know Before 2027

As more states pass extensive data privacy laws, Louisiana lawmakers have decided it’s time for the state to establish its own. On May 29, 2026, Governor Jeff Landry signed the Louisiana Data Privacy Act, Senate Bill 386 (SB386).

 

Who does the Louisiana Data Privacy Act apply to?

Starting January 1, 2027, the Louisiana Data Privacy Act (LDPA) applies to any person or entity conducting business in Louisiana that meets at least one of the following thresholds:

  • General revenue: A total annual revenue of over $25 million
  • Consumer data volume: Annually buys, receives, sells, or shares for commercial purposes the personal information of 75,000 or more consumers, households, or devices
  • Revenue from data sales threshold: Derives 50% or more annual revenue from selling consumer personal information

Like several other recent data privacy laws, enforcement for organizations falls into two main categories: processors and controllers. Controllers under Louisiana’s SB386 are defined as an “individual or other person that, alone or jointly with others, determines the purpose and means of processing personal data.” A processor is defined as a “person that processes personal data on behalf of a controller.”

Organization types exempt from SB386

Louisiana’s SB386 privacy law does not apply to:

  • State agencies and/or political subdivisions of Louisiana
  • Financial institutions and affiliates already regulated by Title V, Gramm-Leach-Bliley Act, 15 U.S.C. 6801 et seq.
  • Covered entities or business associates governed by the privacy, security, and breach notification rules under the Health Insurance Portability and Accountability Act of 1996, 42 U.S.C.11 1320d et seq.

Information exempt from SB386

Multiple types of information already regulated by other entities or pre-existing laws are listed in detail. For more details, see the full list of exempted entities and information starting on page 9 of SB386 here.

 

Overview for organizations regulated by SB386

Controllers of covered entities are required to take several measures to help consumers exercise rights and protect their data.

1: Privacy notice obligations

Controllers are required to provide consumers with a privacy notice that is clear, accessible, and compliant with LDPA requirements, including:

  • Categories of personal data processed
  • Purposes for processing
  • Consumer rights
  • Methods for submitting requests
  • Categories of third parties with whom data is shared

2: Consent for sensitive data

Processing sensitive data requires affirmative consent, including:

  • Precise geolocation
  • Biometric identifiers
  • Children’s data
  • Racial or ethnic origin
  • Health information

3: Honor consumer requests

Controllers must respond to consumer requests, including requests to:

  • Confirm whether the controller is processing the consumer’s personal data and accessing that data
  • Correct inaccuracies in consumer data
  • Delete personal data
  • Provide a consumer copy of data that allows the consumer to transmit the data to another controller without hindrance

4: Data protection assessments

Controllers must conduct assessments for higher-risk processing, such as:

  • Targeted advertising
  • Profiling
  • Sensitive-data processing
  • Activities presenting an increased risk of harm

5: Controller and processor compliance requirements

Controllers must implement compliance actions for processors to help support consumer rights, including:

  • Contractual requirements
  • Data-security safeguards

Processor responsibilities

While most direct responsibilities are placed on controllers, processors are required to process personal data solely as directed by the controller, assist controllers in complying with contractual requirements, and maintain appropriate data-security safeguards.

For full details of organizational responsibilities under SB386, see the full text of the law here.

 

Consumer rights

Under the LDPA, consumers gain rights regarding their personal information, including the ability to request access, correction, or deletion, as well as information about data processing activities. Like many other recent data privacy consumer laws, consumers may opt out of:

  • Targeted advertising
  • Sale of personal data
  • Processing of sensitive data
  • Processing that presents an increased risk of harm

 

What’s next?

On January 1, 2027, SB386 goes into effect for applicable employers and organizations, with exclusive enforcement authority granted to the Louisiana Attorney General.

Cure Period

Following January 1, 2027, there is a 30-day cure period to give employers a buffer to correct violations. The cure period ends on July 31, 2027, meaning that violations can be pursued upon finding.

It is also important to note that the cure period comes with stipulations. In order to cure an alleged violation within the 30-day period, businesses that fall under SB386 regulations must:

  1. Give the attorney general a written statement that the violation was cured
  2. Provide supporting documentation showing how it was cured
  3. Make changes to internal policies, if necessary, to ensure the violation does not occur again

Organizations hiring and operating in Louisiana should review SB386 and consult their legal counsel to see how the law applies to them before taking any action.

 

This content is for informational purposes only and shall not constitute legal opinion or advice. Consult your legal counsel to ensure compliance.