Privacy, security and AI governance across 50+ jurisdictionsTalk to us
Featured jurisdictionIndia, DPDP Act 2023

Notice, consent, Data Fiduciary duties, SDF obligations and breach intimation, explained.

Open the guide
Where most engagements startA readiness assessment, then a plan

We scope against the laws that actually apply to you, then sequence the work by risk.

Start the assessment
Featured whitepaperThe DPDP implementation clock

What must be operational before the substantive obligations commence in 2027.

Read the briefing
Free, no sign-upCheck your readiness in 10 minutes

Answer 18 questions and get a prioritised control roadmap instantly.

Start the assessment
Free, alwaysZero to practitioner

Track 01 assumes no prior knowledge of governance, risk and compliance.

Start Track 01
United States · State-by-state · No federal law

Twenty-four laws, one programme, if you build it right.

In the absence of a federal statute, US privacy compliance is a patchwork of state consumer privacy laws that agree on most of the architecture and diverge on the details that cost money: thresholds, sensitive data, universal opt-out signals and whether you get a chance to fix things before enforcement.

Overview

A patchwork that is converging on structure, not detail

There is no general federal consumer privacy statute in the United States. Sectoral federal laws cover health, financial, credit, children’s and communications data, and the Federal Trade Commission polices unfair and deceptive practices, but the comprehensive obligations come from the states. California opened the field with the CCPA in 2018, amended by the CPRA, and the model has spread steadily since.

Shared architecture

Almost every state law uses the same skeleton: controller and processor roles, applicability thresholds, a set of consumer rights, opt-outs for sale and targeted advertising, consent for sensitive data, contractual flow-down to processors and data protection assessments for higher-risk processing.

Divergent detail

Thresholds, the definition of sale, whether sensitive data needs opt-in or opt-out, whether universal opt-out signals are mandatory, whether cure periods exist and how profiling is treated all vary. The detail is where compliance cost concentrates.

California is the outlier

It is the only state that covers employee and business-to-business personal information, the only one with a dedicated privacy regulator in the CPPA, and the only one with a limited private right of action, available for certain data breaches rather than for general violations.

Moving target

Laws are enacted, amended and brought into effect every legislative session, and amendments such as Delaware’s 2026 threshold reduction can pull organisations into scope without any change to their own processing. Build a review cadence, not a one-off assessment.

Applicability

Thresholds that do not follow one pattern

Applicability models across the states
ModelStates using itHow it works
Standard volume testMost states including Virginia, Colorado, Connecticut, Utah, Oregon, Montana, New Jersey, Indiana, Kentucky, Rhode IslandApplies where the entity controls or processes the personal data of at least 100,000 consumers in a year, or a lower number such as 25,000 while deriving a defined share of gross revenue from the sale of personal data. The revenue-share percentage differs by state, commonly 25 or 50 percent.
California compositeCaliforniaApplies where the business exceeds an annually adjusted gross revenue threshold, or buys, sells or shares the personal information of 100,000 or more consumers or households, or derives 50 percent or more of annual revenue from selling or sharing personal information. Uniquely extends to employee and business-to-business data.
Small business testTexas, NebraskaNo numeric consumer threshold. The law applies to any person conducting business in the state that processes or sells personal data and is not a small business as defined by the Small Business Administration, which pulls in far more mid-sized entities than the volume states.
Large-entity testFloridaTargets entities with more than one billion dollars in global annual revenue that also meet additional criteria tied to digital advertising, smart speaker services or app stores.
Lowered thresholdDelaware from 1 January 2027House Bill 380, signed 2 September 2026, reduces the threshold from 35,000 to 10,000 consumers, materially expanding coverage.
Non-profit inclusionColorado, Delaware, New Jersey, Oregon and othersSeveral states extend coverage to non-profit organisations, which the California model generally excludes. Check this before assuming exemption.

Entity and data-level exemptions differ. Some states exempt entities regulated by HIPAA or the Gramm-Leach-Bliley Act outright, while others exempt only the regulated data itself. An entity-level exemption in one state does not carry to the next.

Timeline

When each state took or takes effect

Effective dates for comprehensive state privacy laws
EffectiveStatesNote
2020 to 2023California, Virginia, Colorado, Connecticut, UtahThe first wave. California January 2020 with CPRA amendments from January 2023; Virginia January 2023; Colorado and Connecticut July 2023; Utah December 2023.
2024Texas, Oregon, Florida, MontanaTexas and Oregon July 2024, Florida July 2024, Montana October 2024.
2025Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, MarylandA dense year. Delaware, Iowa, Nebraska and New Hampshire in January 2025, New Jersey in January 2025, Tennessee in July 2025, Minnesota in July 2025 and Maryland in October 2025.
1 January 2026Indiana, Kentucky, Rhode IslandNow in effect. Indiana had an unusually long runway from its 2023 enactment.
1 January 2027Oklahoma; Delaware amended thresholdOklahoma takes effect and Delaware’s reduced 10,000-consumer threshold applies from the same date.

Consumers

The rights set, and where states add to it

Core rights

Access and confirmation, correction, deletion, portability, and opt-out of sale and of targeted advertising appear in substantially every state law. Response deadlines are typically 45 days with a 45-day extension, and an appeal mechanism is required in most states outside California.

Opt-out of profiling

Most states allow consumers to opt out of profiling in furtherance of decisions producing legal or similarly significant effects. The definition of significant effect varies and commonly covers lending, housing, insurance, education, employment and healthcare access.

Minnesota’s addition

Minnesota gives consumers a right to question the result of profiling, to be informed of the reason the profiling resulted in the decision, and to be informed of what actions might have produced a different outcome. No other state currently matches it.

California’s extras

Right to limit use and disclosure of sensitive personal information, right to know about automated decision-making under CPPA regulations, and coverage of employee and applicant data, which turns HR systems into in-scope systems.

Authorised agents

Most states permit an authorised agent to submit opt-out requests on a consumer’s behalf, and California permits agents for other request types with proof of authorisation. Build agent handling into the intake process.

Non-discrimination

Consumers cannot be penalised for exercising rights, though financial incentive and loyalty programmes are permitted where properly disclosed and, in several states, consented to.

Sensitive data

Opt-in is the norm, Maryland goes further

Sensitive data typically covers racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic and biometric data processed to identify an individual, personal data of a known child, and precise geolocation. Several states add union membership, national origin, transgender or non-binary status, and status as a victim of crime.

Opt-in consent

Most states require affirmative opt-in consent before processing sensitive data, in contrast with California, which instead grants a right to limit its use and disclosure.

Maryland’s prohibition

The Maryland Online Data Privacy Act bans the sale of sensitive personal data outright. Consent does not cure it. Maryland also requires that collection be limited to what is reasonably necessary to provide the specific product or service requested, a stricter minimisation standard than elsewhere.

Precise geolocation

Commonly defined by a radius, frequently 1,750 feet, and treated as sensitive in most states. Mobile SDKs and advertising partners are the usual source of unplanned exposure.

Children and teens

Processing data of a known child follows federal COPPA consent rules. Several states add targeted advertising and sale restrictions for teenagers, commonly ages 13 to 16 or 13 to 17, with knowledge standards that differ by state.

Signals

Universal opt-out mechanisms

A growing majority of states require controllers to recognise browser or device-level opt-out signals, of which Global Privacy Control is the principal implementation. California, Colorado, Connecticut, Texas, Montana, Oregon, Delaware, New Jersey, Minnesota, Maryland, Nebraska and New Hampshire are among those with a mandatory recognition duty, and Colorado maintains a published list of approved mechanisms.

Treat it as universal

Conditional logic that honours the signal only for residents of mandating states is fragile, hard to test and hard to defend. Honouring the signal for all traffic is simpler, cheaper to maintain and lower risk.

Scope of the signal

The signal must be treated as a valid opt-out of sale and of targeted advertising. It does not, of itself, constitute a deletion or correction request, and in most states it does not override an authenticated consumer’s explicit contrary preference.

Tag and vendor reality

Honouring the signal means suppressing the downstream transfer, not just recording a preference. Consent management platform configuration, tag sequencing and server-side integrations all need testing, and pixels firing before the signal is evaluated are a frequent finding.

Evidence

Keep logs demonstrating that signals were received and acted upon. Attorneys general in California and Colorado have both focused enforcement sweeps on this exact gap between stated policy and observed network behaviour.

Enforcement

Who acts, and whether you get to cure

Attorneys general

State attorneys general hold exclusive enforcement authority in nearly every state, with civil penalties commonly set per violation, frequently 7,500 dollars, and higher amounts in some states for violations involving children.

California’s CPPA

The California Privacy Protection Agency has rulemaking, audit and enforcement authority alongside the Attorney General, and has issued regulations on risk assessments, cybersecurity audits and automated decision-making technology.

Cure periods sunsetting

California’s cure period expired, and Colorado’s and Connecticut’s have also lapsed. Later statutes increasingly grant discretionary rather than mandatory cure, and some grant none. Do not build a remediation plan that assumes a guaranteed fix window.

Private right of action

Only California, and only for certain data breaches involving defined categories of unencrypted and unredacted personal information, with statutory damages. General violations are not privately actionable, though plaintiffs increasingly use wiretapping and session-recording theories under older statutes instead.

Data protection assessments

Required in most states for targeted advertising, sale, sensitive data processing, certain profiling and any processing presenting heightened risk. Assessments must be produced to the attorney general on request, so write them to be read by a regulator.

Enforcement themes so far

Published actions and sweeps have focused on defective opt-out mechanics, failure to honour universal signals, inadequate notice, dark patterns in consent interfaces, and unhonoured deletion requests flowing to data brokers.

Approach

Building one programme across the patchwork

1

Apply the highest common standard

Design to the strictest requirement and deploy it everywhere. State-by-state conditional experiences cost more to build, far more to maintain, and fail in ways that are visible to regulators testing your site.

2

Run applicability annually

Thresholds change, amendments such as Delaware’s pull new organisations in, and your own consumer counts move. Re-run the analysis each year and after any material product or acquisition change.

3

Honour GPC globally

Implement universal opt-out recognition for all traffic, verify the downstream suppression actually happens in the network layer, and log the evidence.

4

Treat sensitive data as opt-in and unsaleable

Default to affirmative consent before processing and never sell it. That posture satisfies the opt-in states and Maryland’s outright prohibition simultaneously.

5

Industrialise rights handling

One intake route, identity verification proportionate to the request, 45-day clock with tracked extensions, an appeal path, authorised agent handling, and flow-down of deletion to processors and downstream recipients.

6

Write assessments for regulators

Document targeted advertising, sale, sensitive data, profiling and any heightened-risk processing in a form you would be content to hand to an attorney general without rewriting.

Questions

Frequently asked questions

How many US state privacy laws are actually in effect?

Around twenty-four states have enacted comprehensive consumer privacy laws and roughly twenty are operative as at September 2026. Indiana, Kentucky and Rhode Island joined on 1 January 2026. Oklahoma follows on 1 January 2027, and Delaware’s amended threshold takes effect on the same date. The count moves every legislative session, so treat any fixed number as a snapshot rather than a constant.

What did Delaware change in 2026?

House Bill 380 was signed on 2 September 2026 and lowers Delaware’s applicability threshold from 35,000 consumers to 10,000 consumers with effect from 1 January 2027. That is a meaningful expansion: organisations that sat below the original threshold on a small Delaware footprint may be pulled into scope without any change in their own processing.

Do I have to honour Global Privacy Control?

In a growing number of states, yes. California, Colorado, Connecticut, Texas, Montana, Oregon, Delaware, New Jersey, Minnesota, Maryland, Nebraska and New Hampshire, among others, require controllers to recognise universal opt-out mechanisms for sales and targeted advertising. Because the signal is browser-level and the requirement is now widespread, the practical answer for most organisations is to honour it everywhere rather than attempt state-by-state conditional logic.

Which state is the strictest?

It depends on the dimension. California is broadest in coverage because it uniquely extends to employee and business-to-business personal information and has a dedicated regulator in the California Privacy Protection Agency. Maryland is strictest substantively: its Online Data Privacy Act bans the sale of sensitive personal data outright, a prohibition consent cannot cure, and applies strict data minimisation tied to what is reasonably necessary to provide the requested product or service. Minnesota adds a right to question the result of profiling that no other state matches.

Are cure periods disappearing?

Yes. Right-to-cure provisions were common in the first wave of laws but were mostly drafted to sunset. California’s expired, as did Colorado’s and Connecticut’s. Several later laws grant discretionary rather than mandatory cure, and a few have no cure period at all. Planning on a guaranteed thirty or sixty day fix window is no longer safe.

What thresholds bring my organisation into scope?

Most states use a processing-volume test, commonly 100,000 consumers, or a lower volume such as 25,000 combined with deriving a significant share of revenue from selling personal data. But several states break the pattern. Texas and Nebraska apply the law to any entity that is not a small business under the Small Business Administration definition, with no numeric threshold. Florida targets very large entities with more than one billion dollars in global revenue plus additional criteria. California uses a revenue test alongside volume and revenue-share tests. Run the analysis state by state rather than assuming a uniform number.

Verify

Primary sources

General information, not legal advice. State laws are enacted and amended every legislative session, effective dates shift, and attorney general guidance and CPPA regulations continue to develop. Verify the current statute and regulations for each state before relying on this page. Researched 21 September 2026.

Facing the US patchwork?

We run applicability analysis across all enacted states, design a single highest-common-standard programme, and build the opt-out, rights and assessment evidence attorneys general are testing for.

Talk to Vedhacon