The rules for your business regarding the use of data about people in the United States are not one-size-fits-all. Instead, you face a growing patchwork of state laws, each with its own rights, thresholds, and penalties. As of 2026, twenty US states have passed comprehensive consumer privacy laws, and more are on the way.

For any company selling into the US, that makes compliance a real puzzle, and getting it wrong can mean heavy fines and lost trust. This guide clears up the confusion. It walks through how US state privacy laws work, what the CCPA requires, the newer rules landing in 2026, and how these laws compare with GDPR.

KewData helps UK and international businesses understand rules like these and build compliance that stands up to scrutiny, wherever their customers are.

Table of Contents

  1. Why the US Has No Single Privacy Law
  2. What Are US State Privacy Laws?
  3. The CCPA: California’s Privacy Law
  4. Who Must Comply With the CCPA?
  5. CCPA Consumer Rights and Data Privacy
  6. Opt-In vs Opt-Out: How Consent Works Across US States
  7. CCPA New Regulations for 2026
  8. Other Key US State Privacy Laws
  9. How US State Privacy Laws Compare With GDPR
  10. How Businesses Can Approach Multi-State Compliance
  11. Conclusion

Why the US Has No Single Privacy Law

Unlike Europe, the United States has no single, overarching privacy law that covers everyone. For years, efforts to pass a federal privacy bill have stalled, and none has made it into law. That gap is why individual states have stepped in to write their own rules.

What the US does have at the national level are sector-specific laws. HIPAA covers health information, GLBA covers financial data, and COPPA protects children’s data online. These are important, but each only applies to a narrow slice of activity. They leave most everyday business data, the kind collected through websites, apps, and marketing, without federal protection.

Into that space, the states have moved. The result is a patchwork of United States data protection laws that changes from one state line to the next, which is what makes solid privacy compliance so tricky for businesses operating nationally.

What Are US State Privacy Laws?

US state privacy laws are comprehensive consumer data laws passed at the state level. As of 2026, twenty states have enacted them, starting with California and followed by Virginia, Colorado, Connecticut, Utah, Texas, and many more. Several further states are expected to join over the next couple of years.

The good news is that most of these laws share a common template. Almost all of them give consumers a similar set of rights: the right to know what data a business holds, the right to delete it, the right to correct it, and the right to opt out of having it sold or shared. Most also require businesses to protect sensitive data more carefully and to be open about their data practices, which comes down to solid data protection at the core.

Where they differ is in the detail. Each law sets its own thresholds for which businesses it applies to, its own penalties, and its own enforcement approach. California is the strictest and the broadest, which is why it usually sets the standard the others are measured against. If you build your compliance around California, you are most of the way toward meeting the rest.

The CCPA: California’s Privacy Law

The CCPA, or California Consumer Privacy Act, is the most well-known and far-reaching of all the state laws. California passed it in 2018, and it took effect on 1 January 2020, making it the first broad consumer privacy law in the country. It drew heavily on the ideas behind Europe’s GDPR.

California then strengthened it. A follow-up law, the California Privacy Rights Act, took full effect on 1 January 2023. It did not replace the CCPA but expanded it, adding new rights, a category for sensitive personal information, and rules around data sharing rather than just selling. It also created a dedicated regulator, the California Privacy Protection Agency, to write and enforce the rules. When people talk about California privacy laws today, they usually mean this combined framework.

That regulator matters. California is the only state with a privacy agency whose sole job is enforcement, and it has been active, which is a big reason CCPA compliance carries real weight.

Who Must Comply With the CCPA?

The CCPA does not apply to every business. It targets for-profit companies that do business in California and meet at least one of three tests. The first is annual gross revenue above 25 million dollars, a figure now adjusted for inflation. The second is buying, selling, or sharing the personal information of 100,000 or more California consumers or households. The third is making half or more of your revenue from selling or sharing personal information.

The part that catches many businesses out is reach. You do not need an office in California, or even a presence in the US, for these rules to apply. If you handle enough Californian data and meet a threshold, CCPA privacy duties can land on you wherever you are based. This extraterritorial reach works much like GDPR’s, which is why so many international companies find themselves in scope.

For a UK or global business, the safest move is to check your numbers early, ideally through a GDPR and privacy audit that shows exactly where you stand. If you are close to any threshold, it is worth acting before you cross it rather than after.

CCPA Consumer Rights and Data Privacy

At the heart of the law sits a set of rights that give people real control over their information. Under the CCPA, Californians can ask to know what personal data you hold and how you use it. They can ask you to delete it. They can correct it if it is wrong. They can opt out of having it sold or shared. And they can limit how you use their sensitive information, such as precise location or health details.

For a business, respecting these rights means work behind the scenes. You need to know exactly what data you hold and where it lives, so you can answer a request properly and on time. You need a clear way to receive and act on requests, which is where a reliable data subject access request process earns its place. And you cannot treat someone worse, for example with a higher price or a lesser service, simply because they used a right.

Strong CCPA data privacy also depends on a clear privacy policy. The law requires you to publish one that explains what you collect, why, who you share it with, and how people can use their rights, and to keep it current.

Opt-In vs Opt-Out: How Consent Works Across US States

One of the biggest sources of confusion in US privacy law is how consent actually works, because it is not the same from state to state. The mechanics change depending on the type of data and the state you are dealing with.

The Opt-Out Default

Most US state privacy laws follow an opt-out model, which is the opposite of GDPR. Under opt-out, you are generally allowed to process someone’s data unless they tell you to stop. People have the right to opt out of three things in particular: the sale of their data, targeted advertising, and certain types of profiling.

Sensitive Data Needs Opt-In

Sensitive data is where the rules flip. For information like health details, biometrics, precise location, or race, most states require opt-in consent, meaning you must get clear permission before you process it at all. California handles this slightly differently, giving people the right to limit how their sensitive data is used rather than demanding upfront opt-in, but the direction of travel across the country is toward stronger protection for sensitive information.

The Universal Opt-Out Signal

A growing number of states now require businesses to detect and honour the Global Privacy Control, a browser setting that broadcasts a person’s “do not sell or share” choice automatically. As of 2026, twelve states make this mandatory, including California, Colorado, Connecticut, Texas, New Jersey, and Oregon. States built on the Virginia model, such as Virginia itself, Utah, Iowa, and Indiana, generally do not require it. For a business, the safest bet is to recognise the signal everywhere rather than trying to track which states demand it.

Extra Rules for Minors

There is also a growing set of rules around minors. Several states, including New Jersey and Connecticut, now require opt-in consent before using the data of teenagers for targeted ads, sale, or profiling. If your audience includes young people, this deserves particular care, and a data protection impact assessment is a sensible way to check those activities before they go live.

CCPA New Regulations for 2026

California keeps adding to the rulebook, and the newest set of CCPA new regulations is significant. The California Privacy Protection Agency finalised them in September 2025, and they took effect on 1 January 2026, though many of the heavier duties phase in over the following years.

The new rules focus on three areas. The first is automated decision-making technology, meaning tools, often powered by AI, that make significant decisions about people, such as in hiring or lending. Businesses using it will need to give notice and let people opt out, with compliance required by January 2027.

The second is mandatory risk assessments for high-risk data activities, with the first submissions to the regulator due by April 2028. The third is annual cybersecurity audits for businesses whose processing poses a significant risk to consumers, phased in by company size from 2028 onward. The message for any business is that CCPA compliance is not a fixed target. If you use AI or handle sensitive data at scale, these newer rules deserve close attention now, not later.

Other Key US State Privacy Laws

California may lead, but it is far from alone. As of 2026, twenty states have comprehensive privacy laws in effect: California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and Washington. More are working through their legislatures.

The Virginia Model: Business-Friendly

Virginia’s Consumer Data Protection Act set the first major template. It gives people opt-out rights for ordinary data and requires opt-in consent for sensitive data, with enforcement handled by the state attorney general rather than a dedicated agency. Several states copied this business-friendly approach closely, including Iowa, Indiana, Kentucky, and Tennessee.

The Colorado Model: Stricter Enforcement

Colorado’s Privacy Act, often shortened to CPA, set the second template. It grants similar rights to Virginia’s law but comes with sharper enforcement, a duty to honour universal opt-out signals, and an official list of recognised opt-out tools. Connecticut, Oregon, and others lean toward this stricter approach.

The Standout States

A handful of laws break from the usual pattern and deserve extra attention:

  • Texas has no revenue threshold under its Data Privacy and Security Act, so it applies to almost any business operating in the state that is not classed as a small business.
  • Maryland has the strictest law since California. It bans the sale of sensitive data outright and asks businesses to collect only what they genuinely need.
  • Oregon lets people ask for a list of the specific third parties their data was shared with, which goes further than most states.
  • New Jersey, Indiana, Kentucky, and Rhode Island all brought their laws into effect around the start of 2026, and more states, including Wisconsin, have privacy bills in progress.

What This Means for Your Business

Each law has its own thresholds, cure periods, and penalties, which is what makes multi-state compliance a genuine challenge. Most, though, share enough with California that a solid foundation in data security and consumer rights gives you a strong head start on all of them.

How US State Privacy Laws Compare With GDPR

If you already know GDPR, US state laws will feel familiar in places and different in others. The shared ground is real. Both give people rights over their data, both expect transparency, and both reach beyond their own borders to catch businesses that handle residents’ data from abroad.

The differences matter, though. GDPR applies a single standard across the EU and the UK, while the US operates under state-by-state rules with no single baseline. GDPR requires a lawful basis before you process data at all, whereas US laws lean more on giving people the right to opt out after the fact. GDPR also tends to carry larger potential fines, based on a percentage of global turnover, while US penalties are usually charged per violation. If you want the fuller European picture, our complete guide to [GDPR compliance blog] explains how UK and EU GDPR work alongside the Data Protection Act 2018 and what businesses must do to meet them.

The practical takeaway is reassuring. A business that already meets GDPR is usually well placed to meet US state laws, because it has done the hard work of mapping data and respecting rights. You are adjusting for local detail, not starting over.

How Businesses Can Approach Multi-State Compliance

Facing twenty different laws sounds overwhelming, but a sensible strategy makes it manageable. The most practical approach is to build your compliance around the strictest standard, which usually means California, and then adjust for the specific states where you have the most customers.

A workable plan looks like this:

  • Check where you stand: Work out which state laws apply to you based on your revenue and how many residents’ data you handle in each state.
  • Map your data: Know what personal information you collect, where it lives, and who you share it with. You cannot protect what you have not mapped.
  • Set up rights handling: Put a clear process in place to answer consumer requests to know, delete, correct, and opt out, within each state’s deadlines.
  • Honour opt-out signals: Many states now expect you to recognise universal opt-out tools like the Global Privacy Control, so build that in.
  • Keep it current: New state laws keep arriving, and existing ones keep changing, so review your approach regularly.

Getting this right across states is where strong data governance and expert support pay off, saving you from rebuilding your compliance every time a new law lands. And since the US and Europe are only part of the picture, our guide to [global data protection laws blog] covers the major frameworks beyond them, from Brazil and India to Singapore, Australia, and Canada, showing how each compares with GDPR.

Conclusion

US state privacy laws are a moving target, but they do not have to overwhelm you. The key is to understand the landscape, treat California and the CCPA as your baseline, and build one strong compliance programme that adapts to each state where you do business. Handled well, privacy becomes something that builds trust with your US customers rather than a risk that keeps you up at night.

KewData helps businesses turn that challenge into a clear, managed process. Our team understands global privacy rules and builds practical compliance that fits how you actually work, backed by ongoing support as the requirements change. If you want to know where you stand with US and international privacy rules, our compliance services are a straightforward place to start.

Book your free consultation: https://kewdata.ai/contact-us/

Leave A Comment

Receive the latest news in your email
Table of content
Related articles