Obtainer
Blog / Fundamentals 10 min read

Which State Privacy Laws Apply to My Business? The 2026 Threshold Guide

Last updated July 2026 · Obtainer

Request Studio
Requester
Compiled the manifest and drafted the response - illustrative sample request
0
records found
0
systems scanned
Data manifest
Response draft

Assembling the cover letter from the template...

You approve what is disclosed before anything ships

Helps you comply, not legal advice

Most companies are covered by more state privacy laws than they realize, and the trigger is rarely revenue. It is how many residents of a given state whose personal data you process in a year, whether you sell data, and in a few states whether you touch sensitive data at all. If you process the personal data of 100,000 people in most states, or as few as 35,000 in Connecticut as of July 2026, or literally anyone in Texas, you are likely in scope and must be ready to answer access, deletion, and opt-out requests on a 45-day clock.

General information, not legal advice. Thresholds, exemptions, and definitions vary by state and change, so confirm the rule that applies to your business before you rely on it.

Which state privacy laws apply to my business?

Twenty US states have a comprehensive consumer privacy law in effect in 2026. A law applies to you when you do business in that state or target its residents and you cross that state's threshold. Almost every state uses the same two-part test that Virginia set: a consumer-count trigger, plus a lower count trigger tied to selling data. Texas is the exception, with no numeric threshold at all. The table below is the fast way to see where you land.

State (law)Covered if you process data of...Or the smaller triggerHonor GPC?
California (CCPA/CPRA)Buy/sell/share data of 100,000+ consumers, or $26.625M+ revenue50%+ revenue from selling dataYes
Texas (TDPSA)Any business not an SBA small business (under ~500 employees)No numeric thresholdYes
Virginia (VCDPA)100,000+ consumers25,000+ consumers and 50%+ revenue from selling dataNo
Colorado (CPA)100,000+ consumers25,000+ consumers and any revenue from selling dataYes
Connecticut (CTDPA)35,000+ consumers (lowered July 1, 2026)Sell data or process sensitive data of any numberYes
Iowa (ICDPA)100,000+ consumers25,000+ consumers and 50%+ revenue from selling dataNo
Oregon, Montana, and most other states100,000+ consumers (35,000 in Montana, Delaware, New Hampshire)25,000+ consumers and revenue from selling dataYes (most)

Notice what is not on that list: for most states, your revenue does not matter. California is the outlier that keeps a revenue trigger, inflation-adjusted to $26,625,000 for the current period. Everywhere else, a mid-market company with modest revenue but a large customer or website-visitor base is squarely in scope, and a small company that sells data can be pulled in at a much lower count.

Do small businesses have to comply with state privacy laws?

Often yes, and the count that matters is broader than your paying customers. "Consumers" means residents of the state whose personal data you process, which includes website visitors you track with analytics and advertising pixels, email subscribers, leads, and app users, not just people who bought something. A company with 8,000 customers can easily process the data of well over 100,000 unique visitors in a year. Texas removes the question entirely: if you conduct business in Texas or serve Texas residents and you are not a federally defined small business, the TDPSA applies. Connecticut's July 2026 amendment cut its threshold to 35,000, so a company that was comfortably exempt in 2025 can be covered now without changing anything about its own operations.

How do I count consumers for the threshold?

Count unique residents of the state, not transactions or sessions, over a calendar year. One person who visits your site fifty times is one consumer. Households and devices are not separate consumers. Employees and business-to-business contacts count in states that no longer exempt that data, which now includes California. The practical problem is that almost no company can produce this number on demand, because the underlying data is scattered across a product database, a warehouse, an email platform, analytics, and an ad stack that each count people differently. If you cannot say how many state residents you process, assume you are over the line and prepare to answer requests, because that is the cheaper mistake. Tools that watch data across your warehouse, like continuous monitoring of your data pipelines, make the underlying counts far easier to trust than a once-a-year manual tally.

What do I have to do once a law applies?

The obligations rhyme across states because they all descend from the same template. Once you are in scope, you generally must:

  • Post a privacy notice describing what you collect, why, and how people exercise their rights.
  • Honor consumer rights: access, correct, delete, and obtain a portable copy of personal data.
  • Let consumers opt out of the sale of their data, targeted advertising, and certain profiling.
  • Respond to a verified request within 45 days, extendable once by another 45 days with notice.
  • In most states other than Virginia, honor a universal opt-out signal such as Global Privacy Control.

The response deadline is the part that turns a legal obligation into an operational one. A verified request starts a countdown, and 45 days plus a 45-day extension is the rule in 18 of the 20 states. Two are not: Iowa allows 90 days plus 45, and Florida allows 45 days plus only 15, a 60-day ceiling that is the tightest in the country. For a multi-state company the answer is to build one process to the strictest applicable clock rather than a different one per state. Our breakdown of data subject request deadlines by state covers when the clock starts and what can extend it.

One duty sits outside this framework entirely and catches companies that already decided they were compliant. If you sell or license personal information about people you have no direct relationship with, four states require you to register as a data broker regardless of your size: California, Vermont, Texas, and Oregon. Oregon sets no threshold at all. California charges $6,000 a year and, from August 1, 2026, requires registered brokers to pull deletion requests from a state platform every 45 days. The qualifying tests and deadlines are in data broker registration requirements.

Healthcare organizations need one extra step in this analysis, because the exemption they rely on is not written the same way twice. Connecticut, Florida, Indiana, Iowa, Montana, Tennessee, Texas, Utah, and Virginia exempt HIPAA covered entities and business associates at the entity level, so the comprehensive law does not reach them at all. California, Colorado, Delaware, Minnesota, New Jersey, and Oregon exempt only the protected health information, which means the thresholds above still apply to the organization and every non-PHI record it holds carries full consumer rights. The state-by-state split is in the guide to HIPAA exemptions from state privacy laws.

What happens if I ignore a request?

State attorneys general enforce these laws, and the penalties are per violation, so they add up fast when a mistake repeats across many consumers. Most states cap civil penalties around $7,500 per violation, though Colorado reaches $20,000 and Florida $50,000. California can reach $2,663 per violation, or $7,988 for intentional violations or those involving a consumer known to be under 16, both inflation-adjusted above the statute's original caps, and it is the only state with a limited private right of action, tied to data breaches rather than request handling. The penalty amounts for all twenty states are worth reading next to this table. Several states have removed or sunset their guaranteed cure periods, including Colorado and Connecticut, which means the attorney general no longer has to give you a chance to fix a problem before penalties attach. The enforcement risk is not evenly distributed, but the safe assumption is that a missed or botched request is a countable violation.

Which state pages should I read for my situation?

If you have identified the states you operate in, the per-state detail matters, because the thresholds, the cure periods, and the opt-out rules differ. Start with the states where you have the most residents or the most sensitive processing:

  • California (CCPA/CPRA), the strictest and the one with a private right of action.
  • Texas (TDPSA), with no numeric threshold, so nearly every mid-market business is covered.
  • Virginia (VCDPA), the template law and the one state that does not require honoring Global Privacy Control.
  • Colorado (CPA), which adds a formal appeal right and has no cure period since 2025.
  • Montana (MCDPA), which dropped to a 25,000-consumer trigger in October 2025, the lowest bar relative to state population in the country.
  • Oregon (OCPA), which covers nonprofits and lets a consumer demand the specific third parties that received their data.
  • Connecticut (CTDPA), whose July 2026 amendment lowered the threshold to 35,000 residents.
  • Delaware (DPDPA), at 35,000 consumers with no revenue floor, the lowest headcount threshold in the country, and it covers nonprofits.
  • New Jersey (NJDPA), where any revenue at all from a data sale drops the trigger to 25,000 consumers, and the cure period ended July 15, 2026.
  • Utah (UCPA), the narrowest of them, gated behind a $25 million revenue floor, and the newest to gain a right to correct.
  • Tennessee (TIPA), which needs more than $25 million in revenue AND 175,000 Tennessee consumers, the highest volume trigger in the country, and is the only state where a documented privacy program is an affirmative defense.
  • Minnesota (MCDPA), at 100,000 consumers or 25,000 while making more than 25 percent of revenue from data sales, and the only state where a consumer can question the result of a profiling decision and require it to be reevaluated on corrected data.

Getting from "we might be covered" to "we can answer"

Figuring out which laws apply is the easy half. The hard half is being able to actually answer a request when it lands, because a single person's data is spread across systems that were never built to be searched by name. That is the gap Obtainer closes: it intakes a request, runs personal data discovery to find where that person's data lives across your stack, compiles one reviewable manifest, drafts a deadline-safe response, and tracks the 45-day clock per request. Nothing is disclosed or deleted automatically; a human reviews, redacts, and approves at a gate. Obtainer helps you comply, self-serve from $49 a month, so being in scope in a dozen states does not mean building a dozen manual processes.

Run a data subject access request end to end

Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.