For growing digital businesses. General guidance, not legal advice.
If you sell to US consumers, privacy law stopped being a "someday" problem. Twenty states now have comprehensive laws, fines hit $3.4 billion in 2025, and the grace periods that let you fix things quietly are disappearing. Here's the plain-English version of what matters.
Thresholds are lower than most founders assume. California (CCPA/CPRA): $25M+ revenue, OR data on 100,000+ consumers, OR 50%+ of revenue from selling/sharing data. A site with ~275 California visitors a day running Google Analytics or the Meta Pixel can cross the 100,000 line in a year. Texas (TDPSA): no revenue or volume threshold at all. Virginia-model states (CO, CT, VA and more): typically 100,000+ residents' data, or 25,000+ plus data-sale revenue.
Enforcement patterns point to the same operational failures, not breaches:
1. Opt-outs that don't work end to end — the "Do Not Sell/Share" link doesn't reach your ad and analytics vendors. The most common trigger.
2. Global Privacy Control ignored — 11+ states require honoring the browser opt-out signal automatically. Sephora's case turned on this.
3. Vendor contracts out of date — Tractor Supply and Healthline turned on inadequate third-party contracts.
4. DSARs not handled on time — access/deletion requests have legal deadlines.
5. No evidence — when a regulator asks you to prove it, "we're pretty sure" isn't an answer.
Map what personal data you collect and which vendors touch it. Make sure your opt-out reaches your ad/analytics stack and you honor GPC. Get a current DPA with every processor. Set a real process (deadline + owner) for DSARs. Keep a dated evidence trail.
Compliance drifts. People change roles, vendors get swapped, new trackers get added, and a year later the paperwork no longer matches reality. Cure periods are sunsetting, so there's less room to fix it after the fact. The businesses that stay safe treat compliance as something they run, with clear owners and current records.
Keep compliance true over time, without a legal team. ComplyFine tracks your obligations, handles DSARs, keeps vendor records current, and stores audit-ready evidence. GDPR and UK GDPR today, US state privacy law now live. Start with ComplyFine →
ComplyFine provides compliance tracking and guidance, not legal advice. Thresholds and laws change; confirm your obligations with qualified counsel.