US state privacy laws: which ones apply to you?

US state privacy laws each set their own applicability test, so the same business can be covered in one state and exempt in another. This hub explains who California's CCPA, Colorado's CPA, Connecticut's CTDPA, Texas's TDPSA, and Colorado's biometric law reach, using each statute's own thresholds rather than a single national rule.

Applies to: Businesses that handle the personal data of residents in one or more US states with a comprehensive or biometric privacy law.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

There is no single US privacy law. Instead, a growing group of states each passed its own statute with its own test for who is covered. That means the question "does a privacy law apply to me?" almost always has to be answered state by state, and a business that clears one state's threshold can still fall outside another's. This hub maps the laws we cover and points you to a focused page for each.

Why the state-by-state test matters

A company selling software across the country can touch residents of every state at once, yet the obligations that attach are not uniform. California measures scale through revenue, consumer volume, and how much of your revenue comes from selling data. Colorado and Connecticut count consumers and look at whether you sell data at all. Texas ignores numeric size entirely and asks whether you are a small business under a federal definition. Reading one law and assuming the rest match is the most common mistake we see. Start with the state whose residents you handle most, then work outward. For a side-by-side view of every state's cut-offs, see our comparison of privacy law thresholds by state and Texas TDPSA vs CCPA, and for what non-compliance can cost, read CCPA fines and penalties and what CCPA compliance costs. For the specific California duties and rights that follow, see the CCPA notice at collection, Do Not Sell or Share My Personal Information, the right to limit sensitive personal information, when you must honor Global Privacy Control, the consumer right to delete personal information, the right to know what a business collected, the right to correct inaccurate data, whether a business can charge more for opting out, whether the CCPA now covers employee and HR data, whether the CCPA still has a cure period, the difference between a service provider and a third party, and how long you may keep personal information. If you collect and resell data about people you have no direct relationship with, California data broker registration and the Delete Act explains the DROP platform and the annual filing.

The comprehensive state laws

For the comprehensive state laws, our detail pages walk through each applicability test in the statute's own words. See California's CCPA for the revenue and consumer thresholds (and CPRA vs CCPA for what the 2023 amendments changed), the Colorado Privacy Act for its consumer-volume and sale-of-data branches, the Connecticut Data Privacy Act for the triggers that took effect on July 1, 2026, and the Texas TDPSA for the small-business gate that replaces any numeric threshold, with whether Texas requires honoring browser opt-out signals covering the Section 541.055(e) authorized-agent route. Three more states run on the same consumer-count pattern with their own twist: Virginia's VCDPA, whose data protection assessment rules name five processing activities that trigger a written assessment, Utah's UCPA, which adds a $25 million revenue floor, and Oregon's OCPA, which triggers its data-sale branch at just 25 percent of revenue. Three newer additions round out the set: Iowa's Consumer Data Protection Act, which copies Virginia's thresholds, Montana's Consumer Data Privacy Act, which a 2025 amendment cut to some of the lowest thresholds in the country, and Delaware's Personal Data Privacy Act, which reaches many nonprofits and universities that other states exempt. Four more enacted states now have their own detail pages: Minnesota's Consumer Data Privacy Act, which triggers its data-sale branch at 25 percent of revenue; New Jersey's Data Privacy Act, whose 25,000-consumer branch fires on any data-sale revenue; Nebraska's Data Privacy Act, which copies the Texas small-business gate; and Indiana's Consumer Data Protection Act, effective January 1, 2026, which mirrors Virginia's thresholds. Five more enacted laws now have detail pages: Kentucky's Consumer Data Protection Act, effective January 1, 2026, on the same 100,000-consumer model; the Tennessee Information Protection Act, which reaches only businesses above $25 million in revenue; Maryland's Online Data Privacy Act, which drops the usual nonprofit and university exemptions; New Hampshire's Data Privacy Act; and Rhode Island's Data Transparency and Privacy Protection Act, effective January 1, 2026. Florida's Digital Bill of Rights sits apart, applying its core controller duties only to for-profits above $1 billion in global revenue that also run a qualifying tech business.

Data-type triggers that ignore your size

Some obligations do not depend on your revenue or how many people you serve at all. Colorado's biometric provisions turn purely on whether you collect, use, or store biometric identifiers of Colorado residents, so they can reach a small organization that sits well below the general Colorado Privacy Act thresholds. Connecticut works the same way from July 1, 2026: processing any sensitive data, or offering any personal data for sale, brings you in regardless of volume. If you use fingerprints, face scans, or similar identifiers, check those pages even when you think you are too small to worry about state privacy law. Texas's biometric law (CUBI) works the same way, with consent required before capture and enforcement left to the state attorney general. Health data has its own size-blind regime: Washington's My Health My Data Act reaches any regulated entity that handles consumer health data, with opt-in consent and a private right of action, and Nevada's consumer health data law does much the same with a 1,750-foot geofencing ban. Connecticut's consumer health data rules add the same 1,750-foot geofence ban and a consent-to-sell requirement inside its Data Privacy Act, and our consumer health data laws by state overview compares all three regimes side by side, and MHMDA vs HIPAA shows which health data HIPAA leaves uncovered. Our biometric privacy laws by state roundup compares how Illinois, Texas, Washington, and Colorado treat this data, Illinois BIPA explains the one law that lets individuals sue directly, the BIPA statute of limitations shows how far back those claims reach, and BIPA per-scan violations explains how damages multiply with every unlawful scan, while BIPA statutory damages breaks down the $1,000 and $5,000 amounts and the 2024 single-recovery cap, and the BIPA written retention policy requirement covers the Section 15(a) duty to publish a retention-and-destruction schedule. Whether BIPA applies to health care walks through the Section 10 carve-out for patient and worker biometrics, whether BIPA applies to employees covers the workplace fingerprint and face-scan timeclocks that drive most litigation, and BIPA written notice and consent sets out the Section 15(b) steps required before any scan.

Based outside a state you serve?

Location is rarely the test. If your company is based in one state but serves residents of another, read does the CCPA apply if you are based outside California for how the residency-plus-threshold logic works in practice. And if you run a nonprofit, does the CCPA apply to nonprofits explains why the for-profit definition of "business" usually leaves you out.

Next step

The fastest way to see which of these laws currently reaches your business is to run the free 2-minute Obligation Scan. It maps your data practices to each state's applicability test so you can focus your effort where a law actually applies, instead of guessing across fifty states.

Compliance checklist

  • Identify every US state whose residents' personal data you handle.
  • Check each state's own applicability test, because they differ on thresholds and triggers.
  • Note data-type triggers, such as Colorado's biometric rules, that apply with no numeric threshold.
  • Track effective dates and amendments, such as Connecticut's and Montana's lowered thresholds in 2025 and 2026.
  • Run an obligation scan to see which laws currently reach your business.

Sources

Last verified: 2026-08-14

Informational, not legal advice.