Privacy thresholds by state
US state privacy laws trigger on data volume rather than company size. Iowa and Indiana apply at 100,000 consumers in a calendar year, or 25,000 when over half of gross revenue comes from selling personal data. California is different: 100,000 consumers bought, sold or shared, or $26,625,000 in revenue.
Applies to: Businesses that handle the personal data of residents in one or more US states with a comprehensive privacy law and need to know which state thresholds they cross.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanThe single most common mistake we see is a business reading one state's privacy law and assuming the rest work the same way. They do not. Each comprehensive state law sets its own applicability test, and the same company can be covered in one state and exempt next door. This page lays the thresholds side by side so you can see where you actually cross a line.
How the thresholds compare
Most laws use one of a few patterns: a headline consumer count, a lower branch that triggers when you sell data, and, in two states, a revenue floor you must clear first. The table below states each law's main trigger. Meeting any one branch is enough, except in Utah and Tennessee, where the revenue floor must also be met.
| State (law) | Main consumer threshold | Data-sale branch | Revenue floor |
|---|---|---|---|
| California (CCPA) | 100,000 consumers/households | 50%+ of revenue from selling/sharing | $25M+ gross revenue (any one triggers) |
| Colorado (CPA) | 100,000 | 25,000 + any data-sale revenue | none |
| Connecticut (CTDPA) | 35,000 | any sale, or any sensitive data | none |
| Virginia (VCDPA) | 100,000 | 25,000 + >50% data-sale revenue | none |
| Utah (UCPA) | 100,000 | 25,000 + >50% data-sale revenue | $25M+ required |
| Oregon (OCPA) | 100,000 | 25,000 + >25% data-sale revenue | none |
| Texas (TDPSA) | none (small-business test) | consent still needed to sell sensitive data | none |
| Montana (MCDPA) | 25,000 | 15,000 + >25% data-sale revenue | none |
| Iowa (ICDPA) | 100,000 | 25,000 + >50% data-sale revenue | none |
| Delaware (DPDPA) | 35,000 | 10,000 + >20% data-sale revenue | none |
| Minnesota (MCDPA) | 100,000 | 25,000 + >25% data-sale revenue | none |
| Nebraska (NDPA) | none (small-business test) | consent still needed to sell sensitive data | none |
| New Jersey (NJDPA) | 100,000 | 25,000 + any data-sale revenue or discount | none |
| Indiana (ICDPA) | 100,000 | 25,000 + >50% data-sale revenue | none |
| Kentucky (KCDPA) | 100,000 | 25,000 + >50% data-sale revenue | none |
| Tennessee (TIPA) | 175,000 | 25,000 + >50% data-sale revenue | $25M+ required |
| Maryland (MODPA) | 35,000 | 10,000 + >20% data-sale revenue | none |
| New Hampshire (NHDPA) | 35,000 | 10,000 + >25% data-sale revenue | none |
| Rhode Island (RIDTPPA) | 35,000 | 10,000 + >20% data-sale revenue | none |
Most laws that count to 100,000 or 35,000 exclude data processed solely to complete a payment transaction from that count, so a high-volume payments business is not automatically in scope.
California's revenue gate is not $25 million any more
The statute still prints twenty-five million dollars at Cal. Civ. Code Section 1798.140(d)(1)(A), which is why most comparison pages quote that figure. It is superseded. Section 1798.199.95(d) requires the California Privacy Protection Agency to adjust the CCPA's monetary thresholds for inflation in January of every odd-numbered year, and the Agency's published adjustment sets the operative gross revenue trigger at $26,625,000, effective 1 January 2025. The same adjustment moved the administrative fine amounts to $2,663 per violation and $7,988 per intentional violation, and the private-action damages range to $107 to $799 per consumer per incident. If a business sits between $25 million and $26.6 million in revenue and meets no other trigger, the difference decides whether the CCPA applies at all.
California's three gates, quoted from the statute
California is the state most often summarized wrongly, because its test has three alternative limbs and a threshold figure that no longer matches the number printed in the code.
Civil Code section 1798.140(d)(1) covers an entity "organized or operated for the profit or financial benefit of its shareholders or other owners" that "collects consumers' personal information", alone or jointly determines the purposes and means of processing, does business in the State of California, and satisfies one or more of the following thresholds.
(A) "As of January 1 of the calendar year, had annual gross revenues in excess of twenty-five million dollars ($25,000,000) in the preceding calendar year, as adjusted pursuant to subdivision (d) of Section 1798.199.95."
(B) Alone or in combination, annually buys, sells, or shares the personal information of 100,000 or more consumers or households.
(C) Derives 50 percent or more of its annual revenues from selling or sharing consumers' personal information.
Three points follow from the wording that summaries tend to drop.
The limbs are alternatives, joined by "one or more of the following thresholds." A business with modest revenue that crosses 100,000 consumers or households is covered, and so is one that sells data for more than half its revenue at any size.
Limb (A) is measured twice over: as of January 1 of the calendar year, looking at the preceding calendar year. It is not a rolling figure.
And limb (A) is the only one that moves. The "as adjusted" clause routes to section 1798.199.95(d), which requires the California Privacy Protection Agency to revise the figure on January 1 of every odd-numbered year using the Consumer Price Index for California, All Items, All Urban Consumers, published by the Department of Industrial Relations, applying the August-to-August change over the prior two years and rounding to the nearest whole dollar. The current posted figure is $26,625,000, and because the cycle is biennial it stays operative through 2026, with the next adjustment due on January 1, 2027.
Limb (B) also counts households, not only consumers, which is a broader unit than the equivalent limb in any other state law on this page.
Why the data-sale branch catches smaller businesses
The headline number is not where most surprises happen. It is the second branch. A company well under 100,000 consumers can still be covered if it sells data and crosses a smaller count, often 25,000 or even 10,000. Colorado and New Jersey are the widest here, because their data-sale branch turns on any revenue from selling data rather than a percentage. If you share data with advertising or data partners, read that branch before assuming you are exempt.
The two states that gate on revenue
Utah and Tennessee are the outliers. Both require you to clear a $25 million revenue floor before any consumer threshold matters, which makes them the hardest of the comprehensive laws to fall under. Tennessee then adds an unusually high 175,000-consumer trigger. If your revenue is below $25 million, you can set those two aside and focus on the volume states.
Next step
Reading nineteen thresholds is exactly the kind of task worth automating. The free 2-minute Obligation Scan takes your consumer counts, revenue, and data-sale practices and tells you which state laws currently reach you, so you work from a list of the ones that apply instead of the whole map. Each state above links to a focused page, and the US state privacy laws hub ties them together.
Crossing a threshold is only the start. Maryland, for example, pairs an ordinary threshold with the strictest data minimization rule in the country.
Compliance checklist
- List every US state whose residents' personal data you process, because the test is run state by state.
- For each state, compare your annual consumer count to that state's main threshold: 100,000, 35,000, 25,000, or 175,000.
- Check the data-sale branch, which triggers at a lower count (often 25,000 or 10,000) when you earn revenue from selling data.
- Note the two revenue gates: Utah and Tennessee only apply once you exceed $25 million in revenue.
- Note the small-business states: Texas and Nebraska drop numeric thresholds and turn on a federal small-business definition.
- Recheck annually and whenever you grow, since every threshold is measured over a calendar year.
Sources
- Cal. Civ. Code Section 1798.140(d) (CCPA applicability thresholds)
- C.R.S. Section 6-1-1304 (Colorado Privacy Act applicability), Colorado Attorney General
- Conn. Gen. Stat. Section 42-516 as amended by P.A. 25-113 (effective July 1, 2026)
- Tex. Bus. & Com. Code Section 541.002 (Texas TDPSA applicability)
- Updated Monetary Thresholds in CCPA, California Privacy Protection Agency (CPI adjustment effective January 1, 2025; $26,625,000 revenue gate)
- Cal. Civ. Code Section 1798.199.95(d) (Consumer Price Index adjustment mechanism and method), California Legislative Information
Last verified: 2026-09-18
Informational, not legal advice.