By 2026, nearly half the U.S. states had enacted consumer privacy laws. What began with California's Consumer Privacy Act in 2018 has become a compliance challenge that crosses state lines and affects businesses beyond their home jurisdictions.
You don't need to track 25 separate frameworks. The state privacy laws share more similarities than their different names suggest. Here's what the data shows and what your team should do about it.
What Changed
The state privacy law landscape expanded from California-only to nationwide coverage in under eight years. Every law enacted since 2018 applies extraterritorially. If you process data about residents in a state with a privacy law, that law applies to you regardless of where your headquarters is located.
The laws use revenue thresholds and resident data volume thresholds to exempt small businesses. Some explicitly exempt organizations that meet U.S. Small Business Administration size definitions. Most exempt nonprofits and higher education institutions, though not all. Every law carves out data already covered by federal statutes: Health Insurance Portability and Accountability Act, Family Educational Rights and Privacy Act, and Gramm-Leach-Bliley Act.
Key Findings
Extraterritorial reach is universal. Every state privacy law applies to out-of-state entities doing business in that state or collecting data about its residents. Your physical location doesn't shield you from compliance obligations. If you serve customers in states with privacy laws, you're in scope.
Notice-and-choice dominates the regulatory model. Nearly all laws allow you to determine your data processing activities, provided you disclose them and give individuals opt-out rights. Most require opt-in consent for sensitive data. The laws define personal data using General Data Protection Regulation-style language: identified or identifiable individuals. Most exempt publicly available information.
Sensitive data triggers heightened requirements. All laws require special handling for sensitive data, though they differ on what qualifies as sensitive. Common categories include:
- Precise geolocation data
- Health information
- Financial account credentials
- Biometric data
- Genetic data
- Social Security numbers
- Children's data
- Sexual orientation
- Racial or ethnic origin
- Religious beliefs
- Citizenship status
Most laws require opt-in consent and a privacy impact assessment before you can process sensitive data.
Individual rights converge on five core requests. Nearly every law grants residents the right to know what data you hold, access that data, correct inaccuracies, delete their information, and receive portable copies. Iowa is the outlier, omitting the correction right. Most laws also require you to honor opt-out requests for targeted advertising, profiling, and data sales. A few states include Automated Individual Decision-Making and Profiling decision rights that let individuals question profiling results and request human review.
Enforcement sits with state attorneys general, with one exception. California designated a specific agency to enforce its law. Other states assign enforcement to their attorneys general. Violation penalties typically range from $5,000 to $10,000 per incident, though some states authorize fines up to $50,000. Most laws lack a private right of action. California is the exception again, allowing private lawsuits for data security violations specifically. Many laws include a 30-to-60-day cure period before penalties attach. Some cure rights sunset over time; others remain permanent.
What This Means for Your Team
You're managing compliance across jurisdictions that share a common structure but diverge on details that matter. The notice-and-choice model gives you processing flexibility, but it requires you to maintain current privacy notices and functional preference management systems across all the states where you operate.
Sensitive data definitions vary by state. Maryland imposes strict Data Minimisation requirements, especially for sensitive categories. Some states invalidate consent obtained through dark patterns. Children's data faces additional restrictions in several jurisdictions. You can't build one sensitive data inventory and apply it everywhere.
The enforcement picture matters for risk prioritization. State attorneys general vary in their privacy enforcement aggressiveness and resource allocation. California's dedicated enforcement agency and private right of action for security violations create materially different risk exposure than states with attorney general enforcement only.
Action Items by Priority
Map your state exposure immediately. Document which states your customers, employees, and service users reside in. Calculate whether you meet revenue and data volume thresholds in each state with a privacy law. Don't assume small business exemptions apply without checking each state's specific thresholds.
Build a unified sensitive data taxonomy that covers the superset. Identify every category of sensitive data recognized by any state law you're subject to. Tag data in your inventory with all applicable state-specific sensitivity flags. When you process data that qualifies as sensitive in any jurisdiction, apply the most restrictive requirements across all states. This approach prevents gaps when state definitions don't align.
Implement a preference management system that handles opt-in and opt-out by state. Your system must track which states require opt-in for sensitive data processing and which allow opt-out for targeted advertising, profiling, and sales. You need state-specific consent records, not a single global preference.
Standardize on privacy impact assessments for sensitive data processing. Most state laws require assessments before you process sensitive categories. Document your assessment methodology once, then apply it consistently. Include Data Minimisation analysis, purpose limitation review, and security control validation in every assessment.
Create state-specific privacy notices or a layered disclosure approach. If you serve residents in multiple states, either maintain separate notices that address each state's requirements or build a comprehensive notice that covers the superset and uses layered disclosure to highlight state-specific rights. Test your notices against each state's disclosure requirements annually.
Track cure period provisions and attorney general enforcement patterns. Document which states offer cure periods and which sunset those rights over time. Monitor attorney general enforcement actions in your industry. Adjust your compliance investment based on demonstrated enforcement priorities, not theoretical maximum penalties.
Audit your children's data practices separately. Several states impose restrictions beyond the baseline individual rights framework. If you knowingly process data about minors, map state-specific age thresholds and prohibited processing activities.





