Here's a number worth sitting with: in a Rippling survey of 408 small and midsize businesses, 52% said they didn't know whether state privacy laws applied to them at all. Not whether they were compliant — whether the laws even covered them.
That's the gap this guide exists to close. There is no single federal privacy law in the United States (and a federal one is considered highly unlikely in 2026, per StateScoop). Instead, around 20 states have comprehensive privacy laws on the books, more take effect in 2027 and 2028, and every one of them sets its own rules for who counts as "covered." The result is a patchwork — and figuring out where your business sits in it is genuinely confusing.
This article walks you through the three questions that determine whether any given state privacy law applies to your business. Work through them in order.
Question 1: Do you do business in the state — or target its residents?
State privacy laws don't care where your LLC is registered or where your laptop sits. They care whether you conduct business in the state or target products or services at its residents. That "targeting" language matters enormously for online businesses: if you run a Shopify store that ships anywhere in the US, you are, for practical purposes, targeting residents of every state.
A few specifics worth knowing:
- Physical presence isn't required. A Delaware company with no office anywhere can be covered by Indiana's or Kentucky's law if enough of those states' residents use its product.
- "Consumer" means residents acting in a personal capacity — not employees, not B2B contacts (most states carve those out).
- Texas is the odd one out. The Texas Data Privacy and Security Act covers businesses that conduct business in Texas or provide products or services consumed by Texas residents — "consumed," not "targeted." Legal analysts think that wording is designed to catch out-of-state sellers. But Texas also has a broad small-business exemption, which brings us to the next question. (Our full Texas small-business guide walks through it.)
If you only sell locally — a bakery serving one town, a plumber with a service area — your exposure is mostly your home state's law. If you sell online, keep reading: you're potentially in scope in many states at once.
Question 2: Do you hit the state's thresholds?
This is where most small businesses get their answer — and for most of them, the answer is no, not yet.
Almost every state privacy law only applies above certain thresholds. The standard model, borrowed from Virginia's 2021 law, looks like this:
A The consumer-count test
You control or process the personal data of at least 100,000 consumers in the state per year (excluding data used only to process payments). "Personal data" here means information tied to an identifiable person — names, emails, purchase histories, browsing behavior on your site. A customer list of 3,000 emails doesn't get you there. Neither does 40,000 site visitors if most are one-time browsers.
B The data-sales test
You control or process the data of at least 25,000 consumers and derive more than 50% of your gross revenue from selling personal data. Note the "and" — both have to be true. Most ordinary businesses don't sell personal data at all, so this prong rarely catches anyone by surprise. (One caution: "selling" is defined broadly in some states and can include sharing data for targeted advertising — check your ad-tech setup against the statute.)
The thresholds vary by state, and the variations matter:
| State pattern | Threshold | Notes |
|---|---|---|
| Most states (VA, CO, CT, IN, KY, and others) | 100,000 consumers or 25,000 + 50% revenue from data sales | The standard model |
| Rhode Island | 35,000 consumers or 10,000 + 20% revenue from data sales | Lower than standard |
| Tennessee | 175,000 consumers | Higher than standard |
| Montana | 25,000 / 15,000 | Lowered by 2025 amendment (SB 297) |
| Delaware | Dropping to 10,000 / 5,000 on Jan 1, 2027 (HB 380) | Watch this one — it gets stricter |
| Louisiana (eff. Jan 1, 2027) | $25M revenue or 75,000 consumers or 50% revenue from data sales | California-style triggers |
| Alabama (eff. May 1, 2027) | 25,000 consumers or 25% revenue from data sales (stand-alone) | Unusually low second prong |
| Nebraska | No numeric threshold | Applies more broadly — check the exemptions |
| Vermont (eff. Jan 1, 2028) | 3,000 sensitive-data / 3,000 sold-data triggers | Very low — the strictest incoming law |
| Texas | No volume threshold — but exempts SBA small businesses | See our Texas guide |
The honest read: if you're a 12-person company with a few thousand customers, you're below the thresholds in nearly every state. That's not a loophole — it's how the laws were designed. But thresholds are falling (Delaware, Montana, Vermont), new states keep joining, and a growing business can cross a line without noticing. Which is why the smart move isn't panic — it's a yearly 30-minute check.
Question 3: Are you exempt anyway?
Even above the thresholds, whole categories of businesses and data sit outside these laws:
- Texas's small-business exemption — the big one. Businesses qualifying as small under U.S. Small Business Administration size standards (generally fewer than 500 employees, with revenue caps varying by industry) are exempt from most of the Texas law. One exception: even exempt small businesses need consent before selling someone's sensitive data.
- Nonprofits and higher education — exempt in many states (though not all; New Hampshire and Delaware notably don't broadly exempt them).
- Regulated data — health information covered by HIPAA, financial data under GLBA, and similar sectoral coverage is carved out of most state laws.
- Employment and B2B data — your employees' and business contacts' information is generally excluded.
So what do I actually do with this?
Here's the practical version, in priority order:
- Run the three questions once a year. Thresholds change, your business grows, new states come online. Thirty minutes, once a year, beats a panic later.
- Count your consumers honestly. Not site visitors — identifiable people whose personal data you control or process, per state. Your email list, customer database, and analytics are the inputs.
- If you're below every threshold: you're fine for now. Keep the free compliance checklist on file and re-check yearly — especially before the January 2027 wave.
- If you're above a threshold in any state: that's when the obligations kick in — privacy notices, honoring opt-outs, responding to consumer rights requests within 45 days, vendor contracts. Our Starter Pack walks through the full readiness system.
- If you sell online across state lines: read our Shopify store guide — multi-state selling makes applicability messier, and e-commerce has specific trip-wires.
Watch: how this actually plays out for small businesses
Video: "Small Businesses Are Next — 19 States Just Changed the Rules on Customer Data" (COMNEXIA / Mike Wilson). A small-business-focused walkthrough of why state privacy enforcement is reaching smaller companies. We haven't watched it end-to-end; verify anything you act on.
The 2027 wave: four new laws, one calendar
The patchwork isn't finished growing. Four more comprehensive laws are already on the calendar:
- Oklahoma — effective January 1, 2027 (30-day cure period, AG enforcement). Our Oklahoma guide has the full breakdown and a prep timeline.
- Louisiana — effective January 1, 2027 (California-style $25M / 75,000-consumer / 50%-revenue triggers; 30-day cure sunsetting July 2027). See our Louisiana guide.
- Alabama — effective May 1, 2027 (unusually low 25,000-consumer / 25%-revenue triggers; 45-day cure). See our Alabama guide.
- Vermont — effective January 1, 2028 (3,000 sensitive-data / 3,000 sold-data triggers — the strictest incoming thresholds in the country).
Each new law re-runs the three-question test for every business touching that state. That's the treadmill: the patchwork doesn't just sit there, it grows, and every growth spurt re-confuses everyone. The businesses that stay calm are the ones that re-check yearly instead of panicking at each deadline.
How to count your consumers: a worked example
The threshold math is where most owners get stuck, so here's a concrete walkthrough. Imagine Maria's online candle shop: 22,000 email subscribers, 31,000 orders last year, website analytics showing 90,000 unique visitors.
Her per-state counts (from shipping addresses): California 8,200 customers, Texas 5,100, Florida 4,400, New York 3,900, every other state under 2,000.
- California (100,000-consumer threshold): 8,200 — not covered.
- Texas: SBA small business — exempt from most of the TDPSA regardless.
- Every other state: under 2,000 — not covered.
- Data sales prong: she doesn't sell personal data — the second prong doesn't trigger anywhere.
Result: Maria is below every threshold today. Her honest answer is "not covered" — with a calendar reminder to re-run the numbers next year, because at her growth rate she'll cross 100,000 total customers in about three years, and that's when California starts mattering.
Notice what the example shows: the question was never "am I a good person about privacy." It was arithmetic. Do the arithmetic.
Why vendor content will mislead you
A word of warning about where most "privacy law guides" come from: companies selling compliance software. Their business model needs you to feel covered and scared. So their content systematically:
- Leads with the scariest possible reading of every threshold ("no revenue threshold in Texas!" — without mentioning the small-business exemption);
- Buries the exemptions three scrolls down, if at all;
- Concludes, coincidentally, that you need their product.
We're vendor-neutral — we don't sell software, and our only product is plain-English guides. That doesn't make us unbiased about everything, but it does mean we have no reason to make the rules sound scarier than they are. When we say "you're probably fine," it's because the math says so, not because we're upselling you.
Frequently asked questions
Do I need to follow the strictest state's law everywhere?
No — and this is a common and expensive misconception. Each state's law applies to that state's residents. You don't need to apply California's rules to your Texas customers. What you do need is to know which states' residents you're covered for, and meet each one's requirements for those residents. In practice, many businesses adopt the strictest applicable standard across the board for simplicity — that's a business decision, not a legal requirement.
I'm below every threshold. Do I need a privacy policy?
Strictly for state privacy-law purposes: probably not required. Practically: yes, have one anyway. A basic privacy policy costs nothing, answers customer questions, and is the first thing anyone — regulator, partner, or plaintiff's lawyer — looks for. It's also required by some platforms and payment processors regardless of privacy law.
What counts as "selling" personal data?
More than you'd think. Beyond literal data-broker sales, several states' definitions capture sharing data for targeted advertising — including common setups like the Meta Pixel feeding purchase data back for ad targeting. If you run targeted ads, check whether your setup trips the "sale" definition in states where you're near thresholds. This is one of the highest-value questions to put to a privacy attorney.
How often should I re-check?
Once a year, plus whenever something material changes: a funding round, a big hiring push, crossing 50,000 total customers, launching targeted advertising, or a new state law taking effect where you have customers. Put it on the calendar next to your insurance renewal.
Is there really no federal law coming?
Correct as of October 2026. The last serious attempt (APRA) died with the 118th Congress in January 2025 and was never reintroduced; three 2026 bills exist but are considered highly unlikely to pass amid midterms. The realistic safety window for the state-led patchwork runs through 2028. We'll update this guide if that changes.
Want the full system?
The $49 Starter Pack includes the 24-state threshold matrix as a sortable spreadsheet, the 2027 readiness system, templates, and worksheets.
See the Starter PackStart free
The 20-question compliance checklist tells you where you stand in about ten minutes.
Get the free checklistImportant: this is not legal advice
This article is general educational information about US state privacy laws, not legal advice. Thresholds, exemptions, and effective dates change — verify against the statute or your state attorney general's guidance, and consult a licensed privacy attorney in your state before making compliance decisions based on your specific facts.