US state privacy laws: CCPA and what followed
The US still has no comprehensive federal privacy law, so consumer privacy is governed by a patchwork of state laws. California went first with the CCPA, and by the start of 2026 around 20 states had comprehensive privacy laws in force. Whether they apply to you depends mostly on how many residents’ data you handle and whether you sell or share it, not on where your business is based. A company in London can be covered, and some big US businesses are partly exempt.
Why it’s a patchwork
Before the state laws arrived, US privacy law worked sector by sector. Health data held by providers and insurers falls under HIPAA. Financial institutions have the Gramm-Leach-Bliley Act (GLBA). Online services aimed at children under 13 have COPPA. And the Federal Trade Commission can go after unfair or deceptive practices, including privacy promises a business doesn’t keep.
All of that still applies. The state laws sit on top, giving consumers general rights over their data and putting duties on businesses. Most of them exempt data or organizations already covered by HIPAA or GLBA, but the exemptions aren’t identical, so check each one.
California: the CCPA, as amended by the CPRA
The California Consumer Privacy Act took effect in 2020 and was expanded significantly by the California Privacy Rights Act from 2023. It’s enforced by the state attorney general and by a dedicated state privacy agency.
Who it covers
For-profit businesses that do business in California, collect California residents’ personal information, and meet at least one of these tests:
- Annual gross revenue above a threshold that started at $25 million and is adjusted for inflation (roughly $26.6 million as of 2025)
- Buying, selling or sharing the personal information of 100,000 or more California consumers or households a year
- Making 50% or more of annual revenue from selling or sharing personal information
Picture a fitness app run from London with 180,000 users in California and advertising SDKs built in. It has no US office and modest revenue. But if those SDKs pass California users’ data to ad networks, it’s probably “sharing” that data, and that alone could bring it within the law.
What it requires
- Notice at collection and a detailed privacy policy, updated at least once a year
- Rights to know, access, delete and correct personal information
- An opt-out from the sale of personal information and from sharing it for cross-context behavioral advertising, usually through a “Do Not Sell or Share My Personal Information” link
- Honoring opt-out preference signals such as Global Privacy Control sent by a browser
- A right to limit the use of sensitive personal information to what’s necessary
- Contracts with service providers, contractors and third parties that contain specific terms
California stands apart in two ways. It covers employee and business-contact data as well as consumer data. And it lets consumers sue for statutory damages when certain unencrypted personal information is exposed in a breach caused by a failure to keep reasonable security. The state also adopted new regulations in 2025 covering risk assessments, cybersecurity audits and automated decision-making, with requirements phasing in from 2026.
The states that followed
Virginia passed the second comprehensive law, and a steady stream followed. Most copy a common model with local twists.
| Feature | California | Most other states |
|---|---|---|
| Main test for who’s covered | Revenue, volume of data bought, sold or shared, or revenue from data sales | Number of state residents whose data you process (commonly 100,000 a year), or a lower number combined with income from selling data |
| Employee and B2B data | Covered | Generally excluded |
| Sensitive data | Right to limit use | Usually opt-in consent |
| Targeted advertising and sale | Opt-out | Opt-out |
| Risk assessments | Required for certain high-risk processing | Required for targeted advertising, sale, sensitive data and profiling |
| Private lawsuits | Only for certain data breaches | Generally none; the attorney general enforces |
A few states break the pattern. Texas and Nebraska have no numerical threshold. They apply to most businesses that aren’t small businesses under the federal definition, and even small businesses there need consent before selling sensitive data. Maryland goes further than most, with tight data minimization rules and a ban on selling sensitive data. Several states gave businesses a window to fix a violation after the regulator gets in touch, but in some of them that right has already expired. And Washington’s My Health My Data Act covers consumer health data broadly and allows private lawsuits, which makes it a big deal for wellness and fitness apps. Florida has a privacy law too, but it’s aimed at very large companies.
Working out which laws apply to you
- Map where your users live. Use analytics, billing addresses and your CRM to estimate how many residents of each state you process data about in a year.
- Compare against each state’s threshold. The count often includes website visitors identified by cookies or device IDs as well as paying customers, so the numbers can be higher than you’d guess.
- Check whether you sell or share data. Under several laws, running advertising pixels or third-party trackers can count as a sale or sharing, even though no money changes hands.
- Check the exemptions. Nonprofits, HIPAA-covered entities, GLBA-regulated institutions and certain types of data are exempt in some states and not others.
- Think about one national standard. Plenty of businesses apply the strictest common rules everywhere instead of running a different process per state.
What compliance looks like day to day
- Keep an inventory of the personal data you collect, why, where it’s stored and who receives it.
- Update your privacy policy to cover categories of data, purposes, recipients, retention and consumer rights.
- Set up a way for people to send requests, a process to verify who they are, and a response deadline (generally 45 days, with extensions allowed in some cases).
- Configure your site to honor opt-out signals such as Global Privacy Control where required.
- Get opt-in consent before processing sensitive data in the states that require it.
- Sign a data processing agreement with every vendor that handles personal data for you, with the terms state laws require.
- Document risk assessments for high-risk processing such as targeted advertising.
- Review your security, since weak security is what exposes you to breach lawsuits in California.
Vendor and customer contracts
Most state laws require a written contract between a business and each vendor processing data for it. The contract has to limit how the vendor uses the data, require confidentiality and let the business check compliance. Look for audit rights, clear deletion duties when the contract ends, and a requirement to pass the same terms down to subcontractors.
If you’re the vendor, expect bigger customers to send their own data terms. Check whether they push liability for privacy fines onto you through a broad indemnity, and whether the limitation of liability carves out data incidents with no cap at all. A $40,000-a-year contract with unlimited exposure for a breach isn’t a good trade.
Next steps
- Estimate your data volumes by state and list the laws that likely apply.
- Check whether your advertising and analytics tools count as selling or sharing data.
- Update your privacy notice and your process for handling requests.
- Review vendor contracts for the required data terms. LegalWolf can help you spot missing clauses and one-sided liability terms.
- Put a yearly review in the calendar. New state laws and amendments keep arriving.
This article is general information, not legal or tax advice. Laws differ between countries and states and change over time, so check the rules that apply to you or speak to a qualified professional.