Louisiana Legislative Session Yields Cyber, Privacy Laws
During Louisiana’s 2026 legislative session, which adjourned June 1, lawmakers focused on two questions: What happens when local governments are hit by cyber attacks, and how much control should residents have over their personal information?
Answers emerged through a series of technology measures that address cybersecurity, data sharing and consumer privacy and have been signed into law. One places new cybersecurity expectations on local governments that turn to the state for help after a cyber incident. Another creates new privacy rights for consumers and limits how some businesses can collect and use personal information. And a third seeks to standardize how state agencies exchange information through a framework designed to support privacy-compliant data sharing.
Of the three, state Senate Bill 75 may have the biggest impact on local governments.
The legislation, sponsored by state Sen. Valarie Hodges, directs the Governor’s Office of Homeland Security and Emergency Preparedness to develop cybersecurity standards for local governments seeking state assistance after a cyber attack or other cybersecurity incident.
Specifically, the law requires the agency to create rules “establishing cybersecurity standards applicable to local governmental subdivisions and political subdivisions that seek state assistance in response to a cybersecurity incident.”
Those standards must include “technical management practices that assure cybersecurity compliance with national cybersecurity standards” and spell out what local governments must do if they want state assistance.
The bill does not prevent the state from helping communities that fall short of those standards. But it does create financial consequences. Under the law, state officials may still provide assistance during an incident. However, “reimbursement of costs associated with these services shall be the obligation of the noncompliant local governmental subdivision or political subdivision.”
In other words, local governments that do not meet the state’s cybersecurity requirements could end up paying the costs tied to response and recovery services. The bill was officially enacted back in May.
It gives the Governor’s Office of Homeland Security and Emergency Preparedness authority to write the rules that local governments will eventually follow, placing the agency at the center of the state’s cybersecurity effort.
The session also produced legislation targeting how government agencies share information. Senate Bill 386, known as the Louisiana Data Privacy Act and sponsored by state Sen. Patrick Connick, addresses how certain private-sector companies collect, use and process consumer information.
It will give consumers several new rights. They can ask businesses for access to their information, request corrections, seek deletion of certain data, obtain copies of their information and opt out of some uses of personal data, much as with a recent law passed in Vermont.
The Louisiana bill also limits how much information businesses it covers can gather. Controllers, according to the legislation, “shall limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which that personal data is processed, as disclosed to the consumer.” And companies that sell sensitive personal information must provide notice to consumers.
The state attorney general will enforce the law, which treats violations as unfair or deceptive trade practices under state law. The act has been signed by the governor and takes effect Jan. 1.
In May, lawmakers also enacted Senate Bill 233, sponsored by state Sen. Beth Mizell, which established the Louisiana Statewide Data Exchange Compact. According to the bill text, the compact will establish “a single legal and technical framework for secure, privacy-compliant interagency data sharing” among participating agencies.
The bill is intended to create a more consistent approach to data sharing across state government, facilitating the sharing of confidential information and defining the responsibilities of participating agencies including the purposes for which data may be accessed and used.
The Office of Technology Services will serve as the compact administrator and develop a standardized agreement for participating agencies. The law also calls for a committee of participating agencies to advise the office, review the framework as laws and security requirements evolve, and recommend updates when necessary.
Participation in the compact is voluntary, and agencies may withdraw or pursue another approach if they determine the framework is no longer appropriate for specific data-sharing needs. Agencies will retain ownership of any information they choose to share through the program.
Louisiana is not alone in asking local governments to strengthen their cyber defenses and overall privacy governance. Other states have adopted requirements, standards or assistance programs aimed at helping local agencies prepare for an attack.
In Florida, lawmakers recently moved to formalize a state program that provides local governments with cybersecurity tools, services, and support resources through a statewide assistance initiative. In New York, a 2025 law established reporting requirements for cyber incidents and ransom payments while also requiring cybersecurity training for government employees. Ohio has also required local governments to adopt cybersecurity programs, provide employee training, and publicly approve any ransomware payments before they are made.