What are the privacy law thresholds by state?
US state privacy laws use different applicability thresholds. Most apply at 100,000 consumers in a year; Connecticut, Delaware, Maryland, New Hampshire, and Rhode Island start at 35,000; Montana at 25,000. Texas and Nebraska drop numbers entirely and use a small-business test, while Utah and Tennessee add a $25 million revenue gate.
Applies to: Businesses that handle the personal data of residents in one or more US states with a comprehensive privacy law and need to know which state thresholds they cross.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanFounding 30% off with code FOUNDING until 15 August 2026
The single most common mistake we see is a business reading one state's privacy law and assuming the rest work the same way. They do not. Each comprehensive state law sets its own applicability test, and the same company can be covered in one state and exempt next door. This page lays the thresholds side by side so you can see where you actually cross a line.
How the thresholds compare
Most laws use one of a few patterns: a headline consumer count, a lower branch that triggers when you sell data, and, in two states, a revenue floor you must clear first. The table below states each law's main trigger. Meeting any one branch is enough, except in Utah and Tennessee, where the revenue floor must also be met.
| State (law) | Main consumer threshold | Data-sale branch | Revenue floor |
|---|---|---|---|
| California (CCPA) | 100,000 consumers/households | 50%+ of revenue from selling/sharing | $25M+ gross revenue (any one triggers) |
| Colorado (CPA) | 100,000 | 25,000 + any data-sale revenue | none |
| Connecticut (CTDPA) | 35,000 | any sale, or any sensitive data | none |
| Virginia (VCDPA) | 100,000 | 25,000 + >50% data-sale revenue | none |
| Utah (UCPA) | 100,000 | 25,000 + >50% data-sale revenue | $25M+ required |
| Oregon (OCPA) | 100,000 | 25,000 + >25% data-sale revenue | none |
| Texas (TDPSA) | none (small-business test) | consent still needed to sell sensitive data | none |
| Montana (MCDPA) | 25,000 | 15,000 + >25% data-sale revenue | none |
| Iowa (ICDPA) | 100,000 | 25,000 + >50% data-sale revenue | none |
| Delaware (DPDPA) | 35,000 | 10,000 + >20% data-sale revenue | none |
| Minnesota (MCDPA) | 100,000 | 25,000 + >25% data-sale revenue | none |
| Nebraska (NDPA) | none (small-business test) | consent still needed to sell sensitive data | none |
| New Jersey (NJDPA) | 100,000 | 25,000 + any data-sale revenue or discount | none |
| Indiana (ICDPA) | 100,000 | 25,000 + >50% data-sale revenue | none |
| Kentucky (KCDPA) | 100,000 | 25,000 + >50% data-sale revenue | none |
| Tennessee (TIPA) | 175,000 | 25,000 + >50% data-sale revenue | $25M+ required |
| Maryland (MODPA) | 35,000 | 10,000 + >20% data-sale revenue | none |
| New Hampshire (NHDPA) | 35,000 | 10,000 + >25% data-sale revenue | none |
| Rhode Island (RIDTPPA) | 35,000 | 10,000 + >20% data-sale revenue | none |
Most laws that count to 100,000 or 35,000 exclude data processed solely to complete a payment transaction from that count, so a high-volume payments business is not automatically in scope.
Why the data-sale branch catches smaller businesses
The headline number is not where most surprises happen. It is the second branch. A company well under 100,000 consumers can still be covered if it sells data and crosses a smaller count, often 25,000 or even 10,000. Colorado and New Jersey are the widest here, because their data-sale branch turns on any revenue from selling data rather than a percentage. If you share data with advertising or data partners, read that branch before assuming you are exempt.
The two states that gate on revenue
Utah and Tennessee are the outliers. Both require you to clear a $25 million revenue floor before any consumer threshold matters, which makes them the hardest of the comprehensive laws to fall under. Tennessee then adds an unusually high 175,000-consumer trigger. If your revenue is below $25 million, you can set those two aside and focus on the volume states.
Next step
Reading nineteen thresholds is exactly the kind of task worth automating. The free 2-minute Obligation Scan takes your consumer counts, revenue, and data-sale practices and tells you which state laws currently reach you, so you work from a list of the ones that apply instead of the whole map. Each state above links to a focused page, and the US state privacy laws hub ties them together.
Compliance checklist
- List every US state whose residents' personal data you process, because the test is run state by state.
- For each state, compare your annual consumer count to that state's main threshold: 100,000, 35,000, 25,000, or 175,000.
- Check the data-sale branch, which triggers at a lower count (often 25,000 or 10,000) when you earn revenue from selling data.
- Note the two revenue gates: Utah and Tennessee only apply once you exceed $25 million in revenue.
- Note the small-business states: Texas and Nebraska drop numeric thresholds and turn on a federal small-business definition.
- Recheck annually and whenever you grow, since every threshold is measured over a calendar year.
Sources
- Cal. Civ. Code Section 1798.140(d) (CCPA applicability thresholds)
- C.R.S. Section 6-1-1304 (Colorado Privacy Act applicability), Colorado Attorney General
- Conn. Gen. Stat. Section 42-516 as amended by P.A. 25-113 (effective July 1, 2026)
- Tex. Bus. & Com. Code Section 541.002 (Texas TDPSA applicability)
Last verified: 2026-07-27
Informational, not legal advice.