The Scale of the Problem
Five years ago, the California Consumer Privacy Act (CCPA) was the only US data privacy law on the books. Today, figuring out “which laws apply to us” requires a spreadsheet—and it’s growing quickly.
Currently, twenty-three states have passed comprehensive privacy laws. Of these
- Three took effect January 1, 2026 (Indiana, Kentucky, Rhode Island).
- Connecticut's significant amendments take effect July 2026.
- California’s ADMT regulations, mandatory risk assessments, and cybersecurity audit requirements are all live.
- Alabama’s, Vermont’s, and Oklahoma’s laws were signed in 2026. Alabama and Oklahoma go into effect in 2027, and Vermont goes into effect in 2028.
All of these laws have different requirements to determine eligibility, exemptions, consumer rights, sensitive data requirements, and more. If history is any indication, more states will pass their own laws in the future, introducing additional caveats and complexity.
Companies need to keep pace with evolving regulatory requirements, especially as laws remove cure periods. To do so at scale, they need privacy solutions that go beyond the provision of tooling; businesses are instead seeking out privacy vendors that also provide guidance and maintain their solutions according to current regulatory best practices.
US State Privacy Laws: The 2026 Landscape
In 2026, twenty states have enacted comprehensive data privacy laws, and another three (Alabama, Oklahoma, and Vermont) have passed regulations that go into effect in early 2027. While these laws have significant overlap, each has its own unique features and requirements.
|
State |
Law Name |
Effective Date |
Revenue/data threshold |
Key distinctions |
|
Alabama |
APDPA |
May 1, 2027 |
≥25K consumers; or ≥25% revenue from data sales (no consumer floor) |
Revenue prong has no consumer-count minimum—unique; <500-employee exemption; permanent 45-day cure; $15K max penalty |
|
California |
CCPA/CPRA |
Jan 1, 2023 |
≥$25M revenue; or ≥100K consumers; or ≥50% revenue from selling/sharing data |
Only state with a fully developed employee and B2B data regime; dedicated CPPA enforcement agency; private right of action for data breaches |
|
Colorado |
CPA |
Jul 1, 2023 |
≥100K consumers; or ≥25K consumers plus any revenue from data sales |
Universal opt-out required; cure sunsetted Jan 2025; amended 2025: precise geolocation added as sensitive data (SB 276); biometric employer consent rules (Jul 2025); enhanced minors' protections (Oct 2025) |
|
Connecticut |
CTDPA |
Jul 1, 2023 |
≥35K consumers; or sells data to any resident; or processes any sensitive data (all effective Jul 2026) |
2026 amendments (SB 1295): threshold lowered from 100K to 35K, no-threshold triggers for any data sale or sensitive data processing, cure period eliminated; SB 4 (Oct 2026): LLM training disclosure required, data broker registry, surveillance pricing restrictions, facial recognition notice rules |
|
Delaware |
DPDPA |
Jan 1, 2025 |
≥35K consumers; or ≥10K consumers plus ≥20% revenue from data sales |
Covers nonprofits and most higher-ed institutions (unlike most states); opt-in for sensitive data; 60-day cure sunsetted Dec 2025 |
|
Florida |
FDBR |
Jul 1, 2024 |
≥$1B global revenue, plus additional platform criteria |
Narrowly scoped—effectively aimed at large online platforms only; AG-only enforcement; no private right of action; no cure period |
|
Indiana |
INCDPA |
Jan 1, 2026 |
≥100K consumers; or ≥25K consumers plus ≥50% revenue from data sales |
No specific protections for minors over 13; permanent 30-day cure; exempts nonprofits |
|
Iowa |
ICDPA |
Jan 1, 2025 |
≥100K consumers; or ≥25K consumers plus ≥50% revenue from data sales |
No data protection assessments; no right to correct; no profiling opt-out; opt-out (not opt-in) for sensitive data; permanent 90-day cure—longest of any state |
|
Kentucky |
KCDPA |
Jan 1, 2026 |
≥100K consumers; or ≥25K consumers plus ≥50% revenue from data sales |
Full nonprofit and GLBA entity-level exemptions; permanent 30-day cure; AG enforcement only |
|
Maryland |
MODPA |
Oct 1, 2025 |
≥35K consumers; or ≥10K consumers plus ≥20% revenue from data sales |
Mandatory data minimization; bans sale of sensitive data outright (no consent path); bans targeted ads and data sales to known under-18s; discretionary 60-day cure sunsets Apr 1, 2027 |
|
Minnesota |
MNDPA |
Jul 31, 2025 |
≥100K consumers; or ≥25K consumers plus ≥25% revenue from data sales; SBA small-biz exempt |
Unique right to question and receive explanation of automated profiling decisions; covers nonprofits; universal opt-out required; cure period sunsetted Jan 2026 |
|
Montana |
MCDPA |
Oct 1, 2024 |
≥25K consumers; or ≥15K consumers plus ≥25% revenue from data sales (amended Oct 2025) |
Opt-in for sensitive data; amended Oct 2025: GLBA entity exemption narrowed to data-level, nonprofit exemption limited to insurance-fraud orgs, cure period removed |
|
Nebraska |
NDPA |
Jan 1, 2025 |
No revenue or consumer-count threshold; SBA small-business exemption |
Broad applicability (like Texas); HIPAA entity-level exemption (not just data-level); opt-in for sensitive data; 30-day cure |
|
New Hampshire |
NHPA |
Jan 1, 2025 |
≥35K consumers; or ≥10K consumers plus ≥25% revenue from data sales |
Universal opt-out recognized; opt-in for sensitive data; 60-day cure |
|
New Jersey |
NJDPA |
Jan 15, 2025 |
≥100K consumers; or ≥25K consumers plus any revenue from data sales |
Covers nonprofits and higher ed; no FERPA exemption—unique among state privacy laws; universal opt-out required |
|
Oklahoma |
OKCDPA |
Jan 1, 2027 |
≥100K consumers; or ≥25K consumers plus ≥50% revenue from data sales |
"Sale" limited to monetary consideration only—narrower than most states; no GPC signal requirement; permanent 30-day cure; exempts nonprofits |
|
Oregon |
OCPA |
Jul 1, 2024 |
≥100K consumers; or ≥25K consumers plus any revenue from data sales |
Covers nonprofits (one of few states); amended Jan 2026: bans sale of under-16 data; bans sale of precise geolocation data for all consumers; universal opt-out required; cure period removed |
|
Rhode Island |
RIDTPPA |
Jan 1, 2026 |
≥35K consumers; or ≥10K consumers plus ≥20% revenue from data sales; separate website-operator tier |
No cure period; opt-in for sensitive data; unique future-looking third-party disclosure rule—requires disclosing parties to whom data may (not just does) get sold |
|
Tennessee |
TIPA |
Jul 1, 2025 |
≥$25M revenue and either ≥175K consumers or ≥25K consumers plus ≥50% revenue from data sales |
Dual threshold (revenue AND volume)—highest combined bar of any state; NIST Privacy Framework affirmative defense—unique to Tennessee; permanent 60-day cure |
|
Texas |
TDPSA |
Jul 1, 2024 |
No revenue or consumer-count threshold; SBA small-business exemption |
Broad applicability; active AG enforcement since Jan 2025; 2025 amendments (SB 2121 + SB 1343): data broker definition broadened, transparency obligations expanded |
|
Utah |
UCPA |
Dec 31, 2023 |
≥$25M revenue and either ≥100K consumers or ≥25K consumers plus ≥50% revenue from data sales |
No data protection assessments; opt-out (not opt-in) for sensitive data; permanent cure period; amended 2025–26: right to correct added (Jul 2026); social media data portability and interoperability required |
|
Vermont |
VDPOSA |
Jan 1, 2028 |
≥35,000 consumers ≥3,000 consumers’ sensitive data ≥3,000 consumers’ data sold/shared |
Neural data classified sensitive; dedicated treatment of consumer health data, no applicability threshold required; mandatory AI disclosures; expanded profiling rights |
Do These Laws Apply to Your Business?
While there are 20+ state-level privacy laws in effect, not all of them will apply to your business—though it’s likely that most will. The location of your customers, various built-in thresholds, and how you’re processing data are key to determining applicability.
Where are your visitors/customers?
The first step in determining applicability is figuring out where visitors and customers are located. Without a federal regulation, businesses are only subject to regulations in the states where they do business.
This is a bit more complicated for online businesses, since, in some cases, a single customer in a state might be enough to force compliance with the local laws. Some ways that a company can map out its customer base include:
- Account registration details
- Shipping addresses
- IP geolocation data
- Browser and device signals
Check thresholds
Most of the time, data privacy laws don’t automatically apply when the company gets its first customer in the state. Instead, regulations generally trigger based on three thresholds:
- Annual Revenue: Most data privacy laws have a minimum revenue cap designed to protect smaller businesses from being subject to costly compliance requirements. For example, California’s CCPA/CPRA applies to any company with annual gross revenues of at least $26,625,000.
- Volume of Customer Data: Companies can also be subject to a state’s data privacy law if they process a certain volume of customer data. For example, companies with at least 100,000 California residents as customers are subject to the CCPA/CPRA.
- Percentage of Sales: The final threshold used to determine eligibility is the percentage of revenue made from selling customers’ personal data. For the CCPA/CPRA, the threshold is 50%, but Nebraska and Texas have no minimum threshold.
In general, hitting any of these thresholds is enough to make a company subject to a state’s privacy laws. However, some states have exemptions for small businesses, non-profits, and entities regulated by other sector-specific laws like HIPAA, though requirements for eligibility can vary. Additionally, the processing of certain types of data, like sensitive data or consumer health data, may require certain controls even if these thresholds aren’t met.
Assess your data processing
For states where the company meets one or more eligibility thresholds, the final thing to consider is the types of data to be processed. Some states have broad privacy protections in place, while others focus on certain types of customer data. For example, a few states, like Connecticut, include neural data among their list of sensitive data.
The types of data that you collect and how you process them help determine whether you’re subject to various laws. To determine your responsibilities, do the following:
- Map Data Collection: Determine the types of potentially sensitive and identifiable data collected from customers, such as identifiers, behavioral data, purchase history, geolocation, and device data.
- Determine Data Sales and Sharing: Investigate whether your organization “sells” or “shares” customer data based on each state law’s definition. This includes the use of ad tech, analytics partnerships, and data brokers.
- Identify Sensitive Data Processing: While all data needs protection, some data is more restricted and controlled than others. Precise geolocation, health information, and financial data may have greater security obligations even at low volumes.
- Consider Third-Party Tool Usage: Third-party integrations, like participating in ad-tech networks or the use of software development kits , may access and process customer data that you collected. Under some state laws, this may be considered data sharing and trigger additional obligations. This is especially true with the rise of AI-enabled tools that may use provided data for model training or other purposes.
The bottom line
The reality is that, if you operate online with US customers, you’re likely subject to multiple data privacy laws. Texas and Nebraska have no revenue threshold at all, making them applicable to all businesses with at least one customer in the state unless the small business exemption applies. Additionally, Alabama’s APDPA, which goes into effect in 2027, has no customer floor if the business earns at least 25% of its revenue from sales of customer data.
Managing Multi-Jurisdiction Compliance
Multi-jurisdiction compliance is complex but manageable. An effective compliance strategy requires an understanding of how the laws work and a platform that supports adaptive compliance at scale.
Key Overlaps and Divergences
Each of the twenty-three state-level privacy laws is unique. That said, most of them share certain components and requirements, including:
- Privacy Notices: All major state-level privacy laws mandate that organizations disclose information about data collection and processing to their customers. This includes what types of data are collected, how and why it’s processed, how consumers can exercise their rights, and any sharing of data with third parties.
- Consumer Rights: Many modern privacy laws are inspired by the EU’s GDPR and provide a variety of rights to data subjects. This includes the right to know what data of theirs has been collected, access that data, correct any errors, request data deletion, and receive a copy of all collected data in a portable format. There are other consumer rights, but these are the common set between most state data privacy laws. Additionally, state laws mandate a timeframe for complying with requests, often 45 days, with the potential for a 45-day extension if needed.
- Opt-Outs: Data privacy laws also allow consumers to opt out of their data being sold, shared, or used for targeting advertising. Some jurisdictions require businesses to honor the Global Privacy Control (GPC) opt-out signal.
- Data Protection Assessments (DPAs): Many jurisdictions, including California, Virginia, Connecticut, Colorado, and Texas, mandate that organizations perform DPAs for high-risk data processing. Common triggers for a DPA include processing or sale of sensitive data, targeted advertising, and some profiling activities.
- Reasonable Security: Companies are expected to implement reasonable protections for sensitive data. While laws don’t define “reasonable,” compliance with frameworks like the NIST CSF, ISO 27001, or CIS Controls is generally understood to meet this requirement.
Despite their commonalities, every state law is unique. The major areas where they diverge include:
- Applicability Thresholds: Most state laws define applicability based on overall revenue, processing volumes, and percent of revenue derived from data sales. However, the exact numbers vary across jurisdictions.
- Sensitive Data Definitions: While certain types of data are broadly protected, definitions of sensitive data can vary. For example, Connecticut and Vermont explicitly include neural data in its list of protected categories.
- Cure Periods: Some regulations offer businesses a cure period where they are given a chance to address any issues before penalties are imposed. However, many states are eliminating cure periods as laws mature, assuming that businesses have had ample time to familiarize themselves with the requirements and achieve compliance.
- Private Right of Action: The CCPA is the only state privacy law with a limited private right of action, allowing individuals to sue businesses for statutory damages under certain circumstances. Most states only allow the state Attorney General to enforce the law. Notably, the statute of Vermont’s law asserts lawmakers will consider adding a private right of action if the state Attorney General isn’t adequately resourced to enforce the law.
- Opt-Out Mechanisms: Permitted opt-out mechanisms and requirements vary from state to state. California, for example, allows consumers to opt out of the sale or sharing of their data and to request businesses limit processing their sensitive data to strictly necessary activities. About a dozen states require businesses to honor GPC signals, while others have no such requirement. Check the individual states you must comply with, as failing to honor consumer opt-out requests is a major target for enforcement.
- ADMT/AI Regulations: Several states, like Colorado, California, and Vermont, explicitly regulate the use of AI and automated decision-making technologies (ADMT) with consumer data in their comprehensive data privacy laws. The majority of states have little or no guidance on AI/ADMT usage, though they may regulate AI and ADMT indirectly through requirements around profiling consumers.
A Practical Approach to Compliance
A practical approach to multi-jurisdiction compliance includes the following:
- Build to California standard. California’s CCPA/CPRA is among the most comprehensive and restrictive data privacy laws. Compliance with its requirements sets a strong foundation for compliance with the other 22 state-level laws as well.
- Use a platform that tracks regulatory changes. Data privacy laws are passed, enacted, and updated on a regular basis, meaning that compliance requirements are constantly changing. A platform like Osano, which is maintained by attorneys and privacy professionals, ensures that compliance efforts are up to date.
- Honor universal opt-out signals. Many state privacy laws require businesses to honor universal opt-out signals. Legislatures, regulators, and advocacy groups are pushing for the adoption of universal opt-out mechanisms, so expect for this requirement to become more common in the future.
- Automate DSAR fulfillment. All jurisdictions require companies to comply with data subject access rights, with average timelines of 45 days. With over twenty laws in effect, manual processing is untenable.
- Document everything. Multiple states require risk assessments for the processing of sensitive data. Centralized audit trails create defensibility that spreadsheets cannot.
Several jurisdictions have eliminated cure periods, meaning that companies need to achieve compliance as soon as possible. Solutions that offer out-of-the-box compliance configurations help avoid delays caused by wrestling with tooling that doesn’t always enable compliance outcomes. A platform should set you up for compliance by default, not just provide the infrastructure to build your own compliance program.
Key Takeaways
- 20+ states have active data privacy laws, with more on the way
- Companies are likely subject to several of these
- Build to California standard for broad compliance
- Use a platform that auto-tracks regulatory changes
- Osano covers 95+ privacy laws in 50+ countries backed by the only $500K compliance guarantee in the market
Achieve Multi-State Compliance with Osano
Book a consultation or see a demo. Osano's privacy team can help map your obligations.
FAQ
Do I need a separate privacy policy for each state?
No, many state privacy laws have overlapping requirements. However, certain states require specific information to be included in your privacy policy. For example, if you use consumer data to train AI models, Vermont requires you to disclose that in your privacy policy.
What if I'm not compliant with a law I didn't know about?
It’s the business’s responsibility to be aware of legal responsibilities and maintain compliance. Some states may have a cure period to fix compliance gaps, but many cure periods have expired.
Can one platform handle all these laws?
Yes, Osano offers out-of-the-box compliant configurations for all 20+ state privacy laws and is automatically updated when regulations are enacted or updated.
What's the most common mistake with multi-state compliance?
The most common mistake is treating compliance as a task rather than a process. Regulations change frequently, and companies need up-to-date visibility to ensure compliance with the latest requirements.
US Data Privacy Checklist
Follow our simple checklist to lay the foundation for US data privacy laws compliance.
Download Your Copy
Osano Staff
Osano Staff
Osano Staff is pseudonym used by team members when authorship may not be relevant. Osanians are a diverse team of free thinkers who enjoy working as part of a distributed team with the common goal of working to make a more transparent internet.