Privacy vendors have a business model built on scaring you. ("Your website could cost you millions!" — from a company selling the solution.) This article does the opposite: the actual enforcement record, the actual lawsuit wave, and an honest map of when ignoring the law is fine, when it's a gamble, and when it's genuinely dangerous.
When ignoring it is fine: below the thresholds
Here's the baseline reality: every comprehensive state privacy law has applicability thresholds, and most true small businesses fall below them. A 15-person company with 4,000 customers isn't covered by California's, Virginia's, or Colorado's law. No coverage means no obligations — and no obligations means no penalties.
On top of that, enforcement of the comprehensive laws belongs exclusively to state attorneys general — consumers can't sue you directly under them. AGs have limited staff and tend to start with the biggest, most visible violators. A small business below the thresholds, with no complaints against it, is not where enforcement begins.
So if you've run the applicability test honestly and you're below every line: you're fine. Re-check yearly. That's the whole strategy.
When it stops being fine: the real risk vectors
1. The lawsuit shakedown (California's CIPA wave)
The biggest real-world danger to small businesses hasn't come from the comprehensive privacy laws at all — it's come from an old California wiretapping law being aimed at modern websites.
California's Invasion of Privacy Act (CIPA), a 1967 statute, was repurposed by plaintiffs' lawyers who argued that common website tools — Google Analytics, the Meta Pixel, session-replay software — "intercept" visitor communications. The statutory penalty: $5,000 per violation. Lawyers found California residents who'd visited small-business websites and filed putative class actions, with settlement demands from $50,000 to $200,000 per business. For a small company, settling was cheaper than fighting — which was the point.
Thousands of these lawsuits and demand letters were filed. Then, in October 2026, Governor Newsom signed SB 690, stripping the private right of action from the most-abused provision — explicitly calling out the "vexatious use of CIPA lawsuits and demand letters to extract settlement money from small businesses." The change applies retroactively to claims from the past two years.
2. Attorney-general enforcement (growing, and aimed upward)
State AGs are enforcing — and the numbers are real:
California: record fine against a national retailer
$1.35 million
In October 2025, California's privacy agency announced its largest fine ever against a national retailer — for failing to maintain a proper privacy policy, not notifying job applicants of their rights, and lacking an effective opt-out mechanism. The order also requires annual compliance certification by a corporate officer for four years.
California: data-broker enforcement
$62,000 and $56,600
S&P Global was fined $62,000 for operating 313 days as an unregistered data broker; a Nevada marketing firm paid $56,600 for the same violation. California's Delete Act carries $200-per-day penalties for registration failures.
Other states' headline figures: New Jersey allows up to $10,000 for a first violation and $20,000 for subsequent ones; New Hampshire up to $10,000 per violation; Texas up to $7,500 per violation after a 30-day cure period.
The pattern: enforcement starts with large, visible companies and data brokers — not 12-person shops. But the fines establish the ceiling, and AGs have shown they'll go downmarket once the big cases are done.
3. Crossing a threshold without noticing
The quietest risk: growth. A business at 60,000 consumers isn't covered anywhere; at 110,000, it's covered in a dozen states. Nobody sends you a letter when you cross the line — the obligation just attaches. This is the strongest argument for the yearly 30-minute applicability check: the risk isn't today's size, it's not noticing you've outgrown it.
4. The things that draw attention regardless of size
Certain practices raise your profile with regulators and plaintiffs' lawyers even below thresholds:
- No privacy policy at all — the single most common red flag, and the cheapest thing to fix.
- Ignoring opt-out requests you do receive — nothing turns a small issue into a big one faster.
- Selling or sharing sensitive data (health, precise location, children's data) — the category every law treats most seriously, and the one place even Texas's small-business exemption doesn't fully protect you.
- A data breach with no security basics — breach-notification laws in nearly every state apply regardless of the privacy-law thresholds.
The cure periods: your grace, if you need it
Almost every state gives first-time violators a right to cure — notice from the AG and 30 to 60 days to fix the problem before penalties attach. (Oklahoma and Louisiana: 30 days; Alabama: 45; New Hampshire: 60 days through 2025.) Some of these sunsets are already expiring, so don't treat cure periods as permanent — but they mean an honest mistake, promptly fixed, rarely becomes a fine on the first encounter.
Watch: the privacy traps businesses are missing
Video: "Your Website Could Get You Sued — The Privacy Traps Businesses Are Missing" (The Money Path podcast, with a compliance founder) — on outdated privacy policies, cookie tools, and why small businesses get hit. We haven't watched it end-to-end; verify anything you act on.
The bottom line
Ignoring state privacy laws is safe if you're below the thresholds and doing the basics (have a privacy policy, honor opt-outs, don't sell sensitive data). It becomes a gamble as you grow past thresholds without noticing, or if you draw attention through sloppy practices. And it's dangerous if you're covered and doing nothing — the fines are real, the AGs are active, and the cure periods won't last forever.
The good news: the fix for most small businesses is an afternoon's work, not a compliance department. Our free 20-question checklist tells you which category you're in; the $49 Starter Pack covers the full readiness system if you're covered.
The penalty landscape, state by state
| State / law | Per-violation figure | Cure period | Who enforces |
|---|---|---|---|
| California (CCPA) | Up to $7,500 | 30 days (limited) | AG + CPPA; $1.35M record fine Oct 2025 |
| Texas (TDPSA) | Up to $7,500 | 30 days | AG only; first action Jan 2025 |
| New Jersey | $10,000 first / $20,000 subsequent | 30 days until July 15, 2026 | AG (Division of Consumer Affairs) |
| New Hampshire | Up to $10,000 | 60 days until end of 2025, then discretionary | AG only |
| Oklahoma (eff. 2027) | Up to $7,500 | 30 days | AG only |
| Louisiana (eff. 2027) | Per-incident penalties (verify) | 30 days, sunsets July 2027 | AG only |
| Alabama (eff. 2027) | Verify against statute | 45 days | AG only |
| California (CIPA wiretapping) | $5,000 per violation — private lawsuits | None | Was plaintiffs' lawyers; defunded Oct 2026 (SB 690) |
Two patterns to notice. First: the comprehensive privacy laws are AG-enforced with cure periods — the system is designed to bring businesses into compliance, not to ambush them. Second: the real small-business pain came from outside the comprehensive laws (CIPA's private lawsuits), which is exactly why that wave's defunding matters more than any single fine.
The enforcement pyramid: who gets hit first
It helps to think of enforcement as a pyramid, widest at the bottom:
- Top — the giants: national retailers, data brokers, Big Tech. This is where every AG starts — visible wins, big fines, precedent-setting. The $1.35M California retailer fine lives here.
- Middle — the careless mid-size: companies with real consumer counts, no privacy program, and complaints on file. Data brokers operating unregistered ($62K and $56.6K fines) live here.
- Bottom — everyone else: small businesses below thresholds, or above them but making good-faith efforts. AGs have limited staff; they don't start here.
Your goal isn't to be invisible — it's to be boring: below the lines, or above them with the basics done. Boring businesses don't generate complaints, and complaints are what start investigations.
What to do if you get a demand letter
If a letter arrives alleging privacy violations, don't panic — and don't pay on reflex:
- Read what law it cites. CIPA-based demands sit in a very different (and now much weaker) legal position than an AG notice under a comprehensive privacy law. The October 2026 SB 690 change retroactively weakened pen-register CIPA claims from the past two years.
- Check the sender. AG notices come from the state; demand letters from plaintiffs' firms are settlement shakedowns until proven otherwise.
- Preserve, don't delete. Don't destroy logs, emails, or data related to the claim — spoliation makes everything worse.
- Call a lawyer before the deadline in the letter. Not after. Many of these letters count on the recipient missing the response window.
- Fix the underlying issue anyway. Whether or not the claim has merit, a missing privacy policy or broken opt-out is worth fixing on its own.
Know where you stand?
The $49 Starter Pack includes the 24-state threshold matrix, the 2027 readiness system, templates, and worksheets.
See the Starter PackStart free
The 20-question compliance checklist tells you where you stand in about ten minutes.
Get the free checklistImportant: this is not legal advice
This article is general educational information about privacy-law enforcement and penalties, not legal advice. Fine figures and case outcomes are dated as stated — verify against official sources. If you've received a demand letter or enforcement notice, talk to a licensed attorney before responding or paying anything.