Questions
Frequently asked questions
How many US state privacy laws are actually in effect?
Around twenty-four states have enacted comprehensive consumer privacy laws and roughly twenty are operative as at September 2026. Indiana, Kentucky and Rhode Island joined on 1 January 2026. Oklahoma follows on 1 January 2027, and Delaware’s amended threshold takes effect on the same date. The count moves every legislative session, so treat any fixed number as a snapshot rather than a constant.
What did Delaware change in 2026?
House Bill 380 was signed on 2 September 2026 and lowers Delaware’s applicability threshold from 35,000 consumers to 10,000 consumers with effect from 1 January 2027. That is a meaningful expansion: organisations that sat below the original threshold on a small Delaware footprint may be pulled into scope without any change in their own processing.
Do I have to honour Global Privacy Control?
In a growing number of states, yes. California, Colorado, Connecticut, Texas, Montana, Oregon, Delaware, New Jersey, Minnesota, Maryland, Nebraska and New Hampshire, among others, require controllers to recognise universal opt-out mechanisms for sales and targeted advertising. Because the signal is browser-level and the requirement is now widespread, the practical answer for most organisations is to honour it everywhere rather than attempt state-by-state conditional logic.
Which state is the strictest?
It depends on the dimension. California is broadest in coverage because it uniquely extends to employee and business-to-business personal information and has a dedicated regulator in the California Privacy Protection Agency. Maryland is strictest substantively: its Online Data Privacy Act bans the sale of sensitive personal data outright, a prohibition consent cannot cure, and applies strict data minimisation tied to what is reasonably necessary to provide the requested product or service. Minnesota adds a right to question the result of profiling that no other state matches.
Are cure periods disappearing?
Yes. Right-to-cure provisions were common in the first wave of laws but were mostly drafted to sunset. California’s expired, as did Colorado’s and Connecticut’s. Several later laws grant discretionary rather than mandatory cure, and a few have no cure period at all. Planning on a guaranteed thirty or sixty day fix window is no longer safe.
What thresholds bring my organisation into scope?
Most states use a processing-volume test, commonly 100,000 consumers, or a lower volume such as 25,000 combined with deriving a significant share of revenue from selling personal data. But several states break the pattern. Texas and Nebraska apply the law to any entity that is not a small business under the Small Business Administration definition, with no numeric threshold. Florida targets very large entities with more than one billion dollars in global revenue plus additional criteria. California uses a revenue test alongside volume and revenue-share tests. Run the analysis state by state rather than assuming a uniform number.