The United States has no single comprehensive federal privacy statute. What it has instead, as of mid-2026, is a fast-expanding patchwork: California started with the CCPA in 2020, Virginia and Colorado followed in 2023, and a steady stream of states — Connecticut, Utah, Texas, Oregon, Montana, and many more — has since brought the total to roughly twenty comprehensive state privacy laws in effect or scheduled to take effect. More arrive nearly every legislative session.

The good news for anyone trying to comply: the laws rhyme. Most borrow from the same two templates — California's CCPA/CPRA model and the Virginia/Colorado "controller-processor" model — so a business that builds to the strictest common denominator covers most of the map. The trick is knowing where the laws agree, where they split, and which differences actually change what you build.

Step one: work out whether you are covered anywhere

Every comprehensive state law starts with an applicability test. California's, described on the Attorney General's CCPA page, applies to for-profit businesses that meet any of three prongs: annual gross revenue above a threshold (set at $25 million originally and adjusted over time), buying/selling/sharing personal information of a large number of California residents, or deriving half or more of revenue from selling or sharing personal information.

The Virginia/Colorado family instead keys mainly to processing volume — commonly, controlling or processing personal data of 100,000 or more state residents in a year, or 25,000 residents if the business also derives revenue from selling data. Texas took a different route: its law reaches nearly any business operating in the state that processes or sells personal data, exempting only "small businesses" as defined by the federal Small Business Administration, with a carve-back for sales of sensitive data. So a company too small for Colorado's thresholds may still be squarely inside Texas's law.

Then subtract exemptions. Nonprofits are exempt in some states and covered in others; employee and business-contact data is excluded almost everywhere outside California; and financial institutions under the GLBA or covered entities under HIPAA get entity-level exemptions in many states but only data-level exemptions in a few. Read the employee carve-out narrowly: it removes workforce data from the comprehensive statutes, not from regulation, since biometric consent laws, monitoring-notice statutes, and background-check rules still govern what an employer may collect about its own staff. Companies in regulated sectors — say, a fintech already mapping duties under CFPB open-banking data rules — need to check exemption language state by state rather than assuming a blanket pass.

The common core: rights and duties that recur

Despite different drafting, a stable core has emerged. If you honor the rights and duties below across your whole U.S. customer base, you are most of the way to compliance in nearly every state.

Features that recur across most comprehensive state privacy laws
FeatureTypical ruleNotable variation
Access / copyConsumers may confirm processing and get a copy of their dataResponse deadlines commonly 45 days, extendable
DeletionConsumers may request deletion, subject to exceptionsScope of exceptions (legal holds, transactions) varies
CorrectionRight to fix inaccurate dataAbsent from a few early or narrower laws
Opt-out of sale / targeted adsRight to opt out of data sales and cross-context targeted advertisingDefinitions of "sale" differ (money vs. any consideration)
Profiling opt-outOpt-out of profiling for decisions with legal or similarly significant effectsDetail supplied by rulemaking in some states
Sensitive dataExtra protection for health, biometric, precise location, kids' dataOpt-in consent (VA/CO/CT model) vs. notice and opt-out or use limits
Universal opt-out signalsMust honor browser-level signals like Global Privacy ControlRequired in California, Colorado, and a growing set; optional elsewhere
AssessmentsData protection assessments for higher-risk processingNot required by a few lighter-touch laws such as Utah's

On the obligation side, the recurring set includes: a compliant privacy notice describing categories collected, purposes, and rights; purpose limitation and data minimization; reasonable security; contracts with processors and service providers containing required clauses; a mechanism (often two) for submitting rights requests; an appeal process for denied requests in the Virginia-family states; and non-discrimination against consumers who exercise rights. Colorado's Attorney General maintains a resource page for the Colorado Privacy Act that illustrates the controller-model obligations well, including its universal opt-out mechanism rules.

Watch out: "We don't sell data" is one of the most common false statements in privacy notices. Many states define "sale" to include exchanging personal data for any valuable consideration — which can capture routine ad-tech data sharing. Audit your tags and SDKs before you make the claim.

Where the laws genuinely split

Four differences matter most in practice. First, California remains the outlier in scope: it covers employee and B2B data, has its own dedicated regulator (the California Privacy Protection Agency) alongside the Attorney General, and continues to generate detailed regulations, including on risk assessments and automated decision-making technology — an area that overlaps with the duties described in our guide to AI and automated-decision governance.

Second, consent models for sensitive data split the map: the Virginia/Colorado family requires opt-in consent before processing sensitive data, while California's approach centers on limiting use and Utah's on notice with opt-out. Third, universal opt-out preference signals are mandatory in some states and unaddressed in others, which effectively forces national businesses to honor them everywhere. Fourth, cure periods — grace windows to fix violations after regulator notice — were generous in early laws but have sunset or become discretionary in several states, raising the stakes of a first mistake.

Enforcement everywhere belongs to state attorneys general (plus the CPPA in California), with civil penalties typically in the low-to-mid four figures per violation and multipliers for intentional conduct. With one narrow exception — California's private right of action for certain data breaches involving unredacted, unencrypted personal information — consumers cannot sue directly under these statutes. That said, the FTC polices privacy misrepresentations nationally under its unfairness and deception authority, and its business guidance remains a floor under all of this. Sector statutes like the FCRA also continue to operate independently — a reminder that credit-report data has its own rights regime older than any of these laws.

A build sequence that survives new states

  1. Inventory. Map what personal data you collect, where it lives, which vendors touch it, and what you share with ad-tech. Every later step depends on this map being honest.
  2. Determine applicability. Apply each active state's thresholds to your customer counts and revenue. Recheck annually — both your numbers and the statute list move.
  3. Rebuild the privacy notice. Describe categories, purposes, retention, sharing, and rights in plain language, with state-specific disclosures where required.
  4. Stand up rights-request handling. Intake channels, identity verification, 45-day response clocks, appeal workflow, and a log that proves all of it.
  5. Fix contracts. Processor and service-provider agreements need the mandated clauses; your SaaS vendor contracts and DPAs are where most gaps hide.
  6. Handle opt-outs and signals. Implement sale/targeted-ads opt-outs and honor Global Privacy Control where required — which practically means everywhere.
  7. Run assessments. Document data protection assessments for targeted advertising, sensitive data, profiling, and sales, and keep them ready for regulators.

Practical step: Build once to the strictest requirement you face rather than maintaining per-state logic. Most national companies honor deletion, access, and opt-out rights for all U.S. consumers regardless of state — it is cheaper than geo-fencing rights and it eliminates a whole category of error.

Quick answers

Can consumers sue a company for violating these laws?

Almost never directly. Enforcement sits with state attorneys general and, in California, also the California Privacy Protection Agency. The main exception is California's private right of action for certain data breaches caused by failure to maintain reasonable security, which carries statutory damages per consumer per incident. Plaintiffs also sometimes repackage privacy harms under older statutes — wiretap laws, consumer-protection acts — so the absence of a private right is not the absence of litigation risk.

Do these laws apply to data about my employees?

Mostly no — with California as the big exception. The Virginia/Colorado-family statutes define "consumer" to exclude people acting in an employment or commercial context. California's CCPA/CPRA covers employee and job-applicant data, which means notices, rights handling, and vendor terms for HR data are effectively a California-specific workstream for national employers.

We are under every state's thresholds. Can we ignore privacy law?

No. Texas-style laws reach businesses below traditional thresholds, the FTC's deception authority applies to any privacy promise you make at any size, and sector rules — HIPAA, GLBA, COPPA for children's data, the FCRA — apply regardless of headcount. Small companies also grow into thresholds mid-year. Treat the thresholds as determining which extra obligations attach, not whether privacy practices matter.

How should we track new state laws as they pass?

Assign the job to someone specific, and anchor it to sources that update: state attorney general privacy pages, the CPPA's regulation announcements, and reputable legislative trackers. Do a formal applicability re-check once a year and whenever you enter a new market or launch a product that collects new data categories. Most new laws follow the existing templates, so each addition is usually an increment, not a rebuild.

Where this leaves you

Stop thinking in terms of individual statutes and start thinking in terms of the common core plus tracked exceptions. Inventory your data, test applicability honestly, build rights-handling and vendor contracts to the strictest standard you face, honor opt-out signals universally, and document assessments. Then put statute-watching on a calendar. The patchwork will keep growing — but a program built this way absorbs each new state as a delta, not a crisis.