RegTech Reviews

State-Level Privacy Laws Beyond GDPR and CCPA

Reporter · · 11 min read
Cover illustration for “State-Level Privacy Laws Beyond GDPR and CCPA”
Industry Regulations · July 31, 2026 · 11 min read · 2,531 words

Twenty states have enacted comprehensive consumer privacy laws. The pace is accelerating, not plateauing. And the laws don't wait for compliance teams to finish implementing the last one. If your program is still calibrated to GDPR and CCPA alone, you are already behind, and the gap is widening every legislative session. Think of it like painting a house while someone keeps adding rooms — you're never quite done, and the ladder keeps moving.

California passed CCPA in 2018. For three years, it stood alone. Virginia and Colorado broke that in 2021. Utah and Connecticut followed in 2022. Seven more states enacted laws in 2023. Seven more in 2024. What once took years to replicate now takes a single session. The more important development from 2025 isn't new enactments; it's that roughly half of existing laws saw significant amendments. The patchwork doesn't just grow outward. It deepens.

Diagram: The State Privacy Law Explosion: From 1 to 20 in Six Years. Visualizes: Show the cumulative acceleration of U.S.

What GDPR and CCPA Established, and Where the State Laws Diverge From That Baseline

GDPR and CCPA gave compliance teams a shared vocabulary. Consumer rights to access, delete, and port their data. Required disclosures. Controller obligations. Opt-out mechanisms. Most state laws speak this same language, which is useful, but language similarity masks structural divergence.

The most consequential differences from CCPA are architectural. Most newer state laws use pure consumer-count thresholds to determine applicability; CCPA layered in a revenue trigger. Opt-in defaults for sensitive data categories vary significantly by state, as does the treatment of nonprofits and employment data. And the private right of action, which CCPA preserves for data breaches, is largely absent from the newer state frameworks.

The divergences from GDPR are just as meaningful, though they cut differently. There is no single supervisory authority in the U.S. state system. Enforcement runs through state attorneys general, and it varies considerably in aggression and priority. U.S. state laws generally don't require a lawful basis for every processing activity, which removes one of GDPR's more operationally demanding requirements. Cure periods, standard in most U.S. state laws, have no GDPR equivalent. Texas gives businesses 30 days to remediate a violation before fines attach, and that cure period doesn't sunset. Rhode Island gives businesses nothing.

The practical implication is this: GDPR compliance transfers concepts, not mechanics. CCPA compliance is a better starting foundation for U.S. expansion, but it still leaves significant gaps. Neither framework alone is sufficient.

Table: Key Divergences: GDPR vs. CCPA vs. U.S. State Laws. Compares Applicability Trigger, Lawful Basis Required, Supervisory Authority, Cure Period, and 2 more by GDPR, CCPA and Newer State Laws.

How Applicability Thresholds and Exemptions Determine Whether a Law Actually Covers a Business

Before a law creates obligations, it has to apply. That determination is more granular than most teams realize, and getting it wrong in either direction is costly. Over-compliance burns resources. Under-compliance creates regulatory exposure.

The two most common triggers are the number of consumers whose personal data a business processes and the percentage of gross revenue derived from selling that data. Most states set the primary consumer-processing threshold at 100,000. California, Colorado, Connecticut, Indiana, Iowa, Kentucky, Minnesota, New Jersey, Oregon, Tennessee, Utah, and Virginia all share this floor.

Maryland and New Hampshire sit meaningfully below it. Maryland's MODPA applies to businesses that process data on 35,000 consumers, or just 10,000 if more than 20 percent of gross revenue comes from data sales. New Hampshire mirrors this at 35,000 and 10,000, with a 25 percent revenue threshold. Those lower bars pull in mid-sized businesses that would be exempt in most other states.

Texas uses a different mechanism entirely. The TDPSA applies unless a business qualifies as a small business under the U.S. Small Business Administration definition, making it the first state to anchor applicability to a federal small-business standard rather than a consumer-count floor.

Florida is the sharpest outlier. Its Digital Bill of Rights applies only to companies with more than one billion dollars in gross annual revenue that derive more than half their revenue from online advertising. That scope is narrow enough that analysts frequently question whether it belongs in the comprehensive law count at all.

Exemptions compound this complexity. Most states exempt nonprofits. Oregon and Colorado do not. Minnesota includes a small business exemption; most states don't. Nearly every state excludes employment data from its scope. California is the only state whose comprehensive law reaches the employment context.

The practical implication is direct: a company is covered under Maryland and New Hampshire but exempt in Virginia and Colorado based solely on size. Applicability mapping is not a one-time exercise. It needs to be revisited as thresholds change and amendments pass.

The States Whose Laws Go Meaningfully Further Than the Mainstream Model

Some states are using privacy legislation as a policy instrument, not just a compliance framework. If your program is built to the median state law, it will be non-compliant in specific provisions across at least three states. These laws raise the bar and move the entire gymnasium.

Maryland's MODPA is currently the most demanding law in the country for consumer-side obligations. It doesn't merely require opt-in consent before selling sensitive data; it prohibits the sale outright. That's a categorical distinction. It also requires data protection assessments at the algorithm level for targeted advertising, profiling, and sensitive data processing. Most other states require assessments by category; Maryland requires them per algorithm. The law expressly includes gender-affirming care and reproductive or sexual health within its definition of consumer health data. Processing obligations begin April 1, 2026, which provides a runway, but the operational demands are heavier than what most teams have built for.

Oregon's OCPA is notable for its inclusivity and disclosure granularity. It is one of only two states, alongside Colorado, that refuses to exempt nonprofits. Its privacy notice requirements are more specific than most; businesses must describe how each third party receiving personal data will use it, not just that transfers occur.

Minnesota's MCDPA introduced something genuinely new: a requirement that controllers maintain a data inventory as part of their data security obligations. It also created a profiling right that no other state law matches. Consumers can question the result of a profiling decision, learn why it was reached, and correct the underlying data for reevaluation. That is a materially different obligation than a simple right to opt out of profiling.

Rhode Island's enforcement design is its differentiating feature. No cure period. Businesses found in violation face fines immediately. That changes the risk calculus in a way that most teams haven't priced in.

The States Whose Laws Are Narrower or More Business-Friendly, and Why That Still Matters

Utah's UCPA is consistently described by practitioners as more business-friendly than California's CPRA, Virginia's VCDPA, or Colorado's CPA. Consumer rights are narrower. Controller obligations are lighter. Iowa's ICDPA goes further in that direction; notably, it does not give consumers the right to delete or correct data held by third parties, which is a meaningful limitation relative to peer laws.

Florida's Digital Bill of Rights, as noted, is so narrowly scoped that it functions almost exclusively as a large-platform regulation.

The temptation is to treat these lighter laws as irrelevant to a serious compliance program. That's a mistake, for two reasons.

First, consumer rights still exist in all of them. Opt-out, access, and deletion rights are present even in Utah and Iowa. The floor is lower, but there is a floor.

Second, lighter laws don't stay that way. Montana's law saw amendments in 2025 that expanded scope, increased protections for minors, and narrowed exemptions. Laws that begin as business-friendly often become more demanding over time as legislatures respond to enforcement gaps and lobbying from consumer advocates. A program that treats Utah or Iowa as a minimum baseline is a program that will need to be rebuilt — which is a bit like buying the cheapest umbrella and acting surprised when it turns inside out.

Sector-Specific Laws That Sit Alongside Comprehensive Frameworks: Biometric and Health Data

The comprehensive law framework is not the whole picture. Two data categories have attracted distinct legislative attention at a level of rigor that exceeds what most comprehensive laws require: biometric identifiers and consumer health data.

Illinois BIPA remains the most consequential biometric statute in the country. Enacted in 2008, it requires written consent before collection of biometric data, mandates retention and destruction schedules, prohibits sale, and provides a private right of action with statutory damages of $1,000 per negligent violation and $5,000 per reckless or intentional violation, plus attorney fees. The Illinois Supreme Court held in Rosenbach v. Six Flags in 2019 that plaintiffs need not demonstrate actual harm to sue. That ruling turned BIPA into a class action engine. Texas and Washington have stand-alone biometric statutes; roughly twenty more states protect biometric data as a sensitive category under their comprehensive laws. Colorado amended its CPA, effective July 1, 2025, to add biometric protections that extend beyond consumers to employees, pushing past the consumer-only scope of most comprehensive frameworks.

Washington's My Health My Data Act, effective March 31, 2024, was designed explicitly to close the gap that allowed non-healthcare organizations to collect and monetize health information outside HIPAA's reach. Its definition of consumer health data is intentionally broad: any personal information reasonably linkable to past, present, or future physical or mental health status. The law bans geofencing within 2,000 feet of healthcare facilities to track or target consumers seeking health services, with no consent exception. It carries a private right of action, and two class actions were filed under it in 2025, one against Amazon in February and one against a cannabis retailer in November.

California amended CCPA to include neural data, meaning information generated by measuring nervous system activity, as sensitive personal information. Colorado followed. This is an early signal of where the next sensitive-data frontier is moving.

If your marketing stack uses facial recognition, or if your brand operates in health-adjacent categories in Washington, your obligations are entirely separate from and stricter than the comprehensive law framework.

Children's Privacy as the Fastest-Moving Front in State Legislation

Children's and teens' privacy has become a bipartisan legislative priority. The activity here is distinct from the comprehensive law wave, more intense in some ways, and more directly consequential for marketing operations.

The design code model is the more operationally demanding of the two approaches legislators are pursuing. Rather than requiring age verification alone, design code laws require that products serving minors default to the highest available privacy settings. Maryland's Age-Appropriate Design Code took effect October 1, 2024, and defines "child" as anyone under 18. Vermont enacted its own version in June 2025, effective January 1, 2027, with the same under-18 definition. California's version was enjoined as unconstitutional, and its fate remains unresolved, which creates meaningful uncertainty about how far these requirements will extend nationally.

Platform access laws are advancing in parallel. Florida's Social Media Safety Act, effective January 1, 2025, requires social media platforms to verify ages and terminate accounts for children under 14. Utah's App Store Accountability Act is the first state law requiring app store providers to verify all users' ages and obtain verifiable parental consent before minors can download apps or make in-app purchases. As of January 2025, 19 states have passed laws requiring age verification to access potentially harmful content.

The implication for marketers is specific. Audience targeting and retargeting programs that reach users under 18 are in scope across a growing number of states, even where the state's comprehensive privacy law would otherwise be inapplicable. More importantly, the under-18 threshold in Maryland and Vermont is broader than COPPA's under-13 definition. Ad tech assumptions built on the federal standard are insufficient. And in design code states, the unit of compliance is default settings, not consent flows. That's a different kind of obligation that requires product-level changes, not just policy updates.

The Enforcement Picture: Who Acts, What the Penalties Are, and Where Private Suits Are Possible

The enforcement architecture across U.S. state privacy laws is predominantly regulatory, not litigious. Almost every comprehensive state law vests enforcement exclusively in the state attorney general. No federal regulator. No private right of action for most violations. Most penalty structures cluster around $7,500 per violation, with cure periods of 30 to 60 days before fines attach.

The outliers are where the real exposure lives.

Illinois BIPA has a private right of action with statutory damages ranging from $1,000 to $5,000 per violation, no actual harm requirement, and a plaintiff-friendly precedent from the Illinois Supreme Court. It has generated substantial class action litigation. Washington's MHMDA has a private right of action and has already produced two class actions in 2025. CCPA preserves a private right of action for data breach scenarios specifically. Most other comprehensive state laws do not.

The staggered enforcement calendar creates a sequencing challenge. Several laws are already in enforcement, including those of Texas, Oregon, Montana, New Hampshire, and Minnesota. Indiana, Kentucky, and Rhode Island move into enforcement in 2026. Maryland's data processing obligations begin in April 2026.

Texas has already indicated enforcement is a priority. Rhode Island's absence of a cure period means first contact is also final notice. The laws most likely to generate early enforcement action are those with active attorneys general, no cure period, or private rights of action. Compliance teams that treat enforcement as a future problem are miscalibrating the timeline.

What a Working Compliance Approach Looks Like Across This Many Jurisdictions

The core challenge is that no single state law's compliance satisfies all others. This is a genuinely heterogeneous patchwork, and organizations that try to manage it as though one framework can cascade down to cover everything will find themselves continuously surprised.

The practical approach most compliance teams use is a tiered, lead-jurisdiction model. Build to the most demanding applicable law in each obligation category, then document where lighter-law jurisdictions permit a lower standard. Maryland sets the ceiling on sensitive data handling. Minnesota sets the ceiling on profiling rights. Rhode Island sets the risk calculus on cure-period assumptions. Illinois and Washington set the ceiling on litigation exposure for biometric and health data respectively.

Data inventory is non-negotiable. Minnesota now makes this a statutory requirement, but it was already operationally necessary. You cannot map applicability, satisfy consumer rights requests, or conduct data protection assessments without knowing what data you hold, where it came from, and where it goes.

Consumer rights workflows need to be state-aware. The rights themselves are similar across states, but the timelines, the scope of third-party obligations, and the verification requirements differ. Automation helps, but only if the logic underneath it reflects the actual variation.

Privacy notices need to be reviewed against Oregon's disclosure standard, which requires specificity about how third-party recipients will use data, not just that transfers occur. Most generic privacy policies fail this test.

Applicability assessments should be scheduled, not just completed once. Maryland and New Hampshire's lower thresholds, combined with the ongoing amendment cycle across states, mean that a company's coverage map can change without the company changing at all. Assign a calendar trigger to it.

The final point is the one most organizations resist accepting: this is not a finite project. The patchwork grows outward and deepens simultaneously. The organizations that manage it well are not the ones that complete implementation. They are the ones that build compliance infrastructure that can absorb change without requiring a full rebuild every legislative session. The goal isn't to finish. The goal is to stay current.

Sources

  1. iapp.org
  2. pro.bloomberglaw.com
  3. fpf.org
  4. americanbar.org
  5. mintz.com
  6. mayerbrown.com

More in Industry Regulations