Back to the hub

What are the privacy law thresholds by state?

US state privacy laws use different applicability thresholds. Most apply at 100,000 consumers in a year; Connecticut, Delaware, Maryland, New Hampshire, and Rhode Island start at 35,000; Montana at 25,000. Texas and Nebraska drop numbers entirely and use a small-business test, while Utah and Tennessee add a $25 million revenue gate.

Applies to: Businesses that handle the personal data of residents in one or more US states with a comprehensive privacy law and need to know which state thresholds they cross.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

The single most common mistake we see is a business reading one state's privacy law and assuming the rest work the same way. They do not. Each comprehensive state law sets its own applicability test, and the same company can be covered in one state and exempt next door. This page lays the thresholds side by side so you can see where you actually cross a line.

How the thresholds compare

Most laws use one of a few patterns: a headline consumer count, a lower branch that triggers when you sell data, and, in two states, a revenue floor you must clear first. The table below states each law's main trigger. Meeting any one branch is enough, except in Utah and Tennessee, where the revenue floor must also be met.

State (law) Main consumer threshold Data-sale branch Revenue floor
California (CCPA) 100,000 consumers/households 50%+ of revenue from selling/sharing $25M+ gross revenue (any one triggers)
Colorado (CPA) 100,000 25,000 + any data-sale revenue none
Connecticut (CTDPA) 35,000 any sale, or any sensitive data none
Virginia (VCDPA) 100,000 25,000 + >50% data-sale revenue none
Utah (UCPA) 100,000 25,000 + >50% data-sale revenue $25M+ required
Oregon (OCPA) 100,000 25,000 + >25% data-sale revenue none
Texas (TDPSA) none (small-business test) consent still needed to sell sensitive data none
Montana (MCDPA) 25,000 15,000 + >25% data-sale revenue none
Iowa (ICDPA) 100,000 25,000 + >50% data-sale revenue none
Delaware (DPDPA) 35,000 10,000 + >20% data-sale revenue none
Minnesota (MCDPA) 100,000 25,000 + >25% data-sale revenue none
Nebraska (NDPA) none (small-business test) consent still needed to sell sensitive data none
New Jersey (NJDPA) 100,000 25,000 + any data-sale revenue or discount none
Indiana (ICDPA) 100,000 25,000 + >50% data-sale revenue none
Kentucky (KCDPA) 100,000 25,000 + >50% data-sale revenue none
Tennessee (TIPA) 175,000 25,000 + >50% data-sale revenue $25M+ required
Maryland (MODPA) 35,000 10,000 + >20% data-sale revenue none
New Hampshire (NHDPA) 35,000 10,000 + >25% data-sale revenue none
Rhode Island (RIDTPPA) 35,000 10,000 + >20% data-sale revenue none

Most laws that count to 100,000 or 35,000 exclude data processed solely to complete a payment transaction from that count, so a high-volume payments business is not automatically in scope.

Why the data-sale branch catches smaller businesses

The headline number is not where most surprises happen. It is the second branch. A company well under 100,000 consumers can still be covered if it sells data and crosses a smaller count, often 25,000 or even 10,000. Colorado and New Jersey are the widest here, because their data-sale branch turns on any revenue from selling data rather than a percentage. If you share data with advertising or data partners, read that branch before assuming you are exempt.

The two states that gate on revenue

Utah and Tennessee are the outliers. Both require you to clear a $25 million revenue floor before any consumer threshold matters, which makes them the hardest of the comprehensive laws to fall under. Tennessee then adds an unusually high 175,000-consumer trigger. If your revenue is below $25 million, you can set those two aside and focus on the volume states.

Next step

Reading nineteen thresholds is exactly the kind of task worth automating. The free 2-minute Obligation Scan takes your consumer counts, revenue, and data-sale practices and tells you which state laws currently reach you, so you work from a list of the ones that apply instead of the whole map. Each state above links to a focused page, and the US state privacy laws hub ties them together.

Compliance checklist

  • List every US state whose residents' personal data you process, because the test is run state by state.
  • For each state, compare your annual consumer count to that state's main threshold: 100,000, 35,000, 25,000, or 175,000.
  • Check the data-sale branch, which triggers at a lower count (often 25,000 or 10,000) when you earn revenue from selling data.
  • Note the two revenue gates: Utah and Tennessee only apply once you exceed $25 million in revenue.
  • Note the small-business states: Texas and Nebraska drop numeric thresholds and turn on a federal small-business definition.
  • Recheck annually and whenever you grow, since every threshold is measured over a calendar year.

Sources

Last verified: 2026-07-27

Informational, not legal advice.