20+ States Have introduced Their Own Privacy Laws: A 2026 Compliance Roadmap for Businesses
- Jason Tucker

- Aug 12
- 8 min read
If your business collects, stores, or uses personal data from customers in the United States, the regulatory ground has shifted dramatically beneath your feet, and it's still moving. What began in 2018 with California's landmark privacy law has snowballed into a sprawling, state-by-state patchwork that now covers more than 20 states. There is still no single federal privacy law in the U.S., which means businesses face a genuine multi-jurisdictional compliance puzzle: a patient in Rhode Island, a customer in Kentucky, and a website visitor in California can each trigger different obligations for the exact same piece of data.
This article breaks down what's actually happening in the states right now, why it matters even if you're not headquartered in one of the covered states, and, most importantly, offers a practical roadmap your business can follow to get and stay compliant.

Why This Is Happening Now
Congress has tried and failed for years to pass a comprehensive federal privacy law. States have stepped in one after another, largely modeling their statutes on California's CCPA/CPRA and Virginia's Consumer Data Protection Act (VCDPA). The result is a wave that has moved from a handful of early-adopter states to a genuine majority of the country.
As of 2026, twenty states now have comprehensive privacy laws in effect, with Indiana, Kentucky, and Rhode Island joining the list on January 1, and additional laws and amendments phasing in throughout the year. Arkansas and Connecticut brought new obligations online in July, and California layered on yet another set of regulatory changes, including expanded data broker registration duties, automated decision-making disclosures, and mandatory risk assessments.
This isn't a one-time event you can handle and forget. It's an ongoing regulatory cycle. Lawmakers in dozens of additional states introduce privacy bills every legislative session, and states that already have laws frequently amend them to close loopholes, lower compliance thresholds, or eliminate the "cure periods" that used to give businesses a grace window before penalties kicked in.
Who Actually Has to Comply
A common misconception is that only businesses physically located in a regulated state need to worry about that state's law. In reality, nearly every comprehensive state privacy law applies based on where your customers or website visitors are located, not where your company is headquartered. If you have customers in Colorado, Connecticut, or Kentucky, regardless of whether you have an office, warehouse, or employee there, their state's law can apply to you.
Most of these laws use similar thresholds, generally triggered when a business:
Controls or processes the personal data of a set number of state residents annually (commonly 100,000, though some states set the bar far lower), or
Derives a significant share of revenue (commonly 25–50%) from selling personal data, often combined with a much lower consumer threshold in that case.
Rhode Island stands out as a cautionary example of how low these thresholds can go: its law applies to entities controlling or processing the data of just 35,000 consumers, or as few as 10,000 consumers if more than 20% of revenue comes from data sales. That threshold sweeps in businesses that would never have considered themselves "big data" companies. If you assumed your smaller customer base kept you out of scope, it's worth checking each state's specific numbers rather than relying on a general sense of your company's size.
What These State Privacy Laws Generally Require
Despite the growing divergence between states, most comprehensive privacy laws share a common backbone of consumer rights and business obligations:
Consumer rights: Residents typically gain the right to access the personal data a business holds about them, correct inaccuracies, delete their data, obtain a portable copy of it, and opt out of having their data sold, used for targeted advertising, or used in certain profiling and automated decision-making.
Privacy notices: Businesses must publish clear, accessible notices explaining what categories of personal data they collect, why they collect it, who they share it with, and how consumers can exercise their rights.
Sensitive data protections: Categories like health information, biometric data, precise geolocation, and data about children generally require opt-in consent before processing. A meaningfully higher bar than the opt-out model that applies to ordinary personal data.
Data protection impact assessments (DPIAs): For higher-risk processing, many laws require businesses to conduct and document formal risk assessments before proceeding. This covers activities like targeted advertising, sale of data, or profiling that could affect consumers in significant ways.
Vendor and processor obligations: Businesses that share data with third-party vendors are typically required to have data processing agreements in place that hold those vendors to the same standards.
Universal opt-out mechanism (UOOM) recognition: A growing number of states, including California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, New Hampshire, New Jersey, Oregon, and Texas, require websites to honor browser-based or device-based signals that let consumers opt out of data sales and targeted advertising across every site they visit, rather than making them click through a separate opt-out on each individual website.
Where the Laws Are Starting to Diverge
While the "Virginia model" still forms the backbone of most state laws, 2026 has brought real fragmentation that businesses need to track individually rather than assuming one compliance program fits every state:
Enforcement and cure periods are tightening. Several states are eliminating the 30-to-60-day "cure period" that historically gave businesses a chance to fix violations before facing fines. Delaware's cure period ended at the close of 2025; Montana's expires in April 2026; New Jersey's is set to expire mid-year. Rhode Island's law never had a cure period at all, meaning a violation can result in an immediate fine with no opportunity to remediate first. That changes the calculus significantly: a proactive compliance review now needs to happen before a complaint arrives, not after.
Penalty structures vary. Civil penalties for violations generally run from roughly $7,500 per violation in states like Indiana and Kentucky up to $10,000 per violation in Rhode Island. "Per violation" can add up fast when a single flawed process affects thousands of consumer records.
California continues to lead the landscape (and complicate it). California's Delete Act created the Delete Request and Opt-Out Platform (DROP), a centralized portal that lets California residents submit a single deletion or opt-out request that applies across every registered data broker at once. Brokers must now process these centralized requests within a defined window, adding a genuinely new operational burden beyond simply responding to individual consumer requests. California also finalized regulations requiring risk assessments for high-risk processing and new notice-and-opt-out rights for consumers subject to automated decision-making. the ADMT provisions don't take full effect until 2027, giving businesses a runway to prepare.
Children's and health data are the fastest-growing category of new obligations. States including Connecticut, Arkansas, Nebraska, and California have added or strengthened age-appropriate design code requirements, restrictions on selling or profiling minors' data.
Biometric data has its own separate legal track in some states. Illinois, Texas, and Washington maintain standalone biometric privacy statutes that operate independently of the comprehensive privacy laws. A business using facial recognition, fingerprint scanning, or voice authentication needs to check both regimes.
A Practical Compliance Roadmap
Given this complexity, treating privacy compliance as a one-time legal checklist is a recipe for falling behind. Below is a phased roadmap that scales to businesses of different sizes and levels of data exposure.
Phase 1: Map Your Exposure
Before you can comply with anything, you need to know which laws actually apply to you. Build (or update) a data map that identifies:
Which states your customers, website visitors, and app users are located in
How many consumers per state you control or process data for, and whether you're near any state's applicability threshold
What percentage of your revenue, if any, comes from selling or sharing personal data
What categories of data you collect, ordinary personal data, sensitive data (health, biometric, precise geolocation), and data belonging to minors
This exercise alone often surprises companies. A business that never thought of itself as "selling data" may discover that sharing data with ad-tech vendors in exchange for services counts as a sale under some states' broad definitions.
Phase 2: Update Your Privacy Notices and Internal Policies
Once you know which laws apply, audit your public-facing privacy notice against each state's specific disclosure requirements. Many businesses default to a single, generic notice, but a defensible program increasingly needs to reflect state-specific rights and definitions. Update internal data retention, security, and vendor management policies to match, and make sure every department that touches customer data (marketing, product, customer support, HR) understands what's changed.
Phase 3: Build (or Rebuild) Consumer Rights Workflows
Design a repeatable, auditable process for handling consumer requests to access, correct, delete, and port their data, along with opt-out requests for sales, targeted advertising, and profiling. This should include:
A verifiable intake channel (web form, email, or toll-free number) depending on state requirements
Define response timelines that meet the shortest deadline among the states you operate in, rather than tracking each state separately
An internal escalation path for requests involving sensitive data or data for minors, which often carry stricter standards
Recognition of universal opt-out signals on your website if you operate in any of the states that require it
Phase 4: Conduct and Document Risk Assessments
For any processing activity that qualifies as higher-risk (targeted advertising, data sales, sensitive data processing, profiling, or automated decision-making) conduct a documented data protection impact assessment before you begin that activity. Treat these assessments as living documents that get revised whenever the underlying processing changes, not static paperwork filed away and forgotten.
Phase 5: Tighten Vendor and Processor Contracts
Review every third-party vendor relationship where personal data changes hands (ad networks, analytics providers, cloud storage, customer service platforms) and confirm your data processing agreements include the specific contractual language most state laws now require, including audit rights, breach notification duties, and limits on the vendor's own use of the data.
Phase 6: Prepare for Continuous Monitoring, Not a One-Time Fix
Given how quickly cure periods are disappearing and new state laws are enacted or amended each year, build an ongoing governance process rather than treating this as a single project:
Assign clear internal ownership of privacy compliance, even if it's a part-time responsibility layered onto an existing legal or operations role
Set a recurring review of new and amended state laws relevant to your footprint
Track upcoming effective dates. 2027 alone is expected to bring additional comprehensive laws and expanded age-appropriate design code requirements in multiple states, plus California's automated decision-making disclosure rules taking full effect
Maintain an up-to-date inventory of AI and automated decision-making tools used in your business, since regulators are increasingly treating this as its own compliance category tied closely to privacy law
Phase 7: Train Your Team
Even the best-designed compliance program fails if the people handling customer data day-to-day don't understand it. Regular training for customer support, marketing, sales, and engineering teams on what counts as personal or sensitive data, how to route a consumer rights request, and what not to do with data (like using precise geolocation for advertising near a healthcare facility in California) closes the gap between policy and practice.
The Bottom Line
The days of treating U.S. privacy compliance as a California-only concern are over. With twenty states now enforcing comprehensive privacy statutes businesses of nearly every size need a real, maintained compliance program rather than a static policy written once and left untouched. The good news is that the underlying frameworks share enough common DNA, that a well-built program covering data mapping, consumer rights workflows, risk assessments, and vendor management, will get you most of the way across every state at once. The work now is making sure that program actually gets built, and that someone inside your organization owns the process of keeping it current.



