Back to the hub

Privacy thresholds by state

US state privacy laws trigger on data volume rather than company size. Iowa and Indiana apply at 100,000 consumers in a calendar year, or 25,000 when over half of gross revenue comes from selling personal data. California is different: 100,000 consumers bought, sold or shared, or $26,625,000 in revenue.

Applies to: Businesses that handle the personal data of residents in one or more US states with a comprehensive privacy law and need to know which state thresholds they cross.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

The single most common mistake we see is a business reading one state's privacy law and assuming the rest work the same way. They do not. Each comprehensive state law sets its own applicability test, and the same company can be covered in one state and exempt next door. This page lays the thresholds side by side so you can see where you actually cross a line.

How the thresholds compare

Most laws use one of a few patterns: a headline consumer count, a lower branch that triggers when you sell data, and, in two states, a revenue floor you must clear first. The table below states each law's main trigger. Meeting any one branch is enough, except in Utah and Tennessee, where the revenue floor must also be met.

State (law) Main consumer threshold Data-sale branch Revenue floor
California (CCPA) 100,000 consumers/households 50%+ of revenue from selling/sharing $25M+ gross revenue (any one triggers)
Colorado (CPA) 100,000 25,000 + any data-sale revenue none
Connecticut (CTDPA) 35,000 any sale, or any sensitive data none
Virginia (VCDPA) 100,000 25,000 + >50% data-sale revenue none
Utah (UCPA) 100,000 25,000 + >50% data-sale revenue $25M+ required
Oregon (OCPA) 100,000 25,000 + >25% data-sale revenue none
Texas (TDPSA) none (small-business test) consent still needed to sell sensitive data none
Montana (MCDPA) 25,000 15,000 + >25% data-sale revenue none
Iowa (ICDPA) 100,000 25,000 + >50% data-sale revenue none
Delaware (DPDPA) 35,000 10,000 + >20% data-sale revenue none
Minnesota (MCDPA) 100,000 25,000 + >25% data-sale revenue none
Nebraska (NDPA) none (small-business test) consent still needed to sell sensitive data none
New Jersey (NJDPA) 100,000 25,000 + any data-sale revenue or discount none
Indiana (ICDPA) 100,000 25,000 + >50% data-sale revenue none
Kentucky (KCDPA) 100,000 25,000 + >50% data-sale revenue none
Tennessee (TIPA) 175,000 25,000 + >50% data-sale revenue $25M+ required
Maryland (MODPA) 35,000 10,000 + >20% data-sale revenue none
New Hampshire (NHDPA) 35,000 10,000 + >25% data-sale revenue none
Rhode Island (RIDTPPA) 35,000 10,000 + >20% data-sale revenue none

Most laws that count to 100,000 or 35,000 exclude data processed solely to complete a payment transaction from that count, so a high-volume payments business is not automatically in scope.

California's revenue gate is not $25 million any more

The statute still prints twenty-five million dollars at Cal. Civ. Code Section 1798.140(d)(1)(A), which is why most comparison pages quote that figure. It is superseded. Section 1798.199.95(d) requires the California Privacy Protection Agency to adjust the CCPA's monetary thresholds for inflation in January of every odd-numbered year, and the Agency's published adjustment sets the operative gross revenue trigger at $26,625,000, effective 1 January 2025. The same adjustment moved the administrative fine amounts to $2,663 per violation and $7,988 per intentional violation, and the private-action damages range to $107 to $799 per consumer per incident. If a business sits between $25 million and $26.6 million in revenue and meets no other trigger, the difference decides whether the CCPA applies at all.

California's three gates, quoted from the statute

California is the state most often summarized wrongly, because its test has three alternative limbs and a threshold figure that no longer matches the number printed in the code.

Civil Code section 1798.140(d)(1) covers an entity "organized or operated for the profit or financial benefit of its shareholders or other owners" that "collects consumers' personal information", alone or jointly determines the purposes and means of processing, does business in the State of California, and satisfies one or more of the following thresholds.

(A) "As of January 1 of the calendar year, had annual gross revenues in excess of twenty-five million dollars ($25,000,000) in the preceding calendar year, as adjusted pursuant to subdivision (d) of Section 1798.199.95."

(B) Alone or in combination, annually buys, sells, or shares the personal information of 100,000 or more consumers or households.

(C) Derives 50 percent or more of its annual revenues from selling or sharing consumers' personal information.

Three points follow from the wording that summaries tend to drop.

The limbs are alternatives, joined by "one or more of the following thresholds." A business with modest revenue that crosses 100,000 consumers or households is covered, and so is one that sells data for more than half its revenue at any size.

Limb (A) is measured twice over: as of January 1 of the calendar year, looking at the preceding calendar year. It is not a rolling figure.

And limb (A) is the only one that moves. The "as adjusted" clause routes to section 1798.199.95(d), which requires the California Privacy Protection Agency to revise the figure on January 1 of every odd-numbered year using the Consumer Price Index for California, All Items, All Urban Consumers, published by the Department of Industrial Relations, applying the August-to-August change over the prior two years and rounding to the nearest whole dollar. The current posted figure is $26,625,000, and because the cycle is biennial it stays operative through 2026, with the next adjustment due on January 1, 2027.

Limb (B) also counts households, not only consumers, which is a broader unit than the equivalent limb in any other state law on this page.

Why the data-sale branch catches smaller businesses

The headline number is not where most surprises happen. It is the second branch. A company well under 100,000 consumers can still be covered if it sells data and crosses a smaller count, often 25,000 or even 10,000. Colorado and New Jersey are the widest here, because their data-sale branch turns on any revenue from selling data rather than a percentage. If you share data with advertising or data partners, read that branch before assuming you are exempt.

The two states that gate on revenue

Utah and Tennessee are the outliers. Both require you to clear a $25 million revenue floor before any consumer threshold matters, which makes them the hardest of the comprehensive laws to fall under. Tennessee then adds an unusually high 175,000-consumer trigger. If your revenue is below $25 million, you can set those two aside and focus on the volume states.

Next step

Reading nineteen thresholds is exactly the kind of task worth automating. The free 2-minute Obligation Scan takes your consumer counts, revenue, and data-sale practices and tells you which state laws currently reach you, so you work from a list of the ones that apply instead of the whole map. Each state above links to a focused page, and the US state privacy laws hub ties them together.

Crossing a threshold is only the start. Maryland, for example, pairs an ordinary threshold with the strictest data minimization rule in the country.

Compliance checklist

  • List every US state whose residents' personal data you process, because the test is run state by state.
  • For each state, compare your annual consumer count to that state's main threshold: 100,000, 35,000, 25,000, or 175,000.
  • Check the data-sale branch, which triggers at a lower count (often 25,000 or 10,000) when you earn revenue from selling data.
  • Note the two revenue gates: Utah and Tennessee only apply once you exceed $25 million in revenue.
  • Note the small-business states: Texas and Nebraska drop numeric thresholds and turn on a federal small-business definition.
  • Recheck annually and whenever you grow, since every threshold is measured over a calendar year.

Sources

Last verified: 2026-09-18

Informational, not legal advice.