Which State Privacy Laws Apply to Your Business?

The one question every small business owner asks about privacy law — and the one almost nobody answers in plain English. Here's the applicability decision tree, the honest thresholds, and why "it depends" is actually a useful answer.

Updated October 2026 · 12-minute read

The honest answer first: most true small businesses fall below state privacy law thresholds today. If that's you, this article will tell you so — and tell you what to watch for as the patchwork grows. We'd rather give you a clear "you're probably fine" than sell you fear.

Here's a number worth sitting with: in a Rippling survey of 408 small and midsize businesses, 52% said they didn't know whether state privacy laws applied to them at all. Not whether they were compliant — whether the laws even covered them.

That's the gap this guide exists to close. There is no single federal privacy law in the United States (and a federal one is considered highly unlikely in 2026, per StateScoop). Instead, around 20 states have comprehensive privacy laws on the books, more take effect in 2027 and 2028, and every one of them sets its own rules for who counts as "covered." The result is a patchwork — and figuring out where your business sits in it is genuinely confusing.

This article walks you through the three questions that determine whether any given state privacy law applies to your business. Work through them in order.

Question 1: Do you do business in the state — or target its residents?

State privacy laws don't care where your LLC is registered or where your laptop sits. They care whether you conduct business in the state or target products or services at its residents. That "targeting" language matters enormously for online businesses: if you run a Shopify store that ships anywhere in the US, you are, for practical purposes, targeting residents of every state.

A few specifics worth knowing:

If you only sell locally — a bakery serving one town, a plumber with a service area — your exposure is mostly your home state's law. If you sell online, keep reading: you're potentially in scope in many states at once.

Question 2: Do you hit the state's thresholds?

This is where most small businesses get their answer — and for most of them, the answer is no, not yet.

Almost every state privacy law only applies above certain thresholds. The standard model, borrowed from Virginia's 2021 law, looks like this:

A The consumer-count test

You control or process the personal data of at least 100,000 consumers in the state per year (excluding data used only to process payments). "Personal data" here means information tied to an identifiable person — names, emails, purchase histories, browsing behavior on your site. A customer list of 3,000 emails doesn't get you there. Neither does 40,000 site visitors if most are one-time browsers.

B The data-sales test

You control or process the data of at least 25,000 consumers and derive more than 50% of your gross revenue from selling personal data. Note the "and" — both have to be true. Most ordinary businesses don't sell personal data at all, so this prong rarely catches anyone by surprise. (One caution: "selling" is defined broadly in some states and can include sharing data for targeted advertising — check your ad-tech setup against the statute.)

The thresholds vary by state, and the variations matter:

State patternThresholdNotes
Most states (VA, CO, CT, IN, KY, and others)100,000 consumers or 25,000 + 50% revenue from data salesThe standard model
Rhode Island35,000 consumers or 10,000 + 20% revenue from data salesLower than standard
Tennessee175,000 consumersHigher than standard
Montana25,000 / 15,000Lowered by 2025 amendment (SB 297)
DelawareDropping to 10,000 / 5,000 on Jan 1, 2027 (HB 380)Watch this one — it gets stricter
Louisiana (eff. Jan 1, 2027)$25M revenue or 75,000 consumers or 50% revenue from data salesCalifornia-style triggers
Alabama (eff. May 1, 2027)25,000 consumers or 25% revenue from data sales (stand-alone)Unusually low second prong
NebraskaNo numeric thresholdApplies more broadly — check the exemptions
Vermont (eff. Jan 1, 2028)3,000 sensitive-data / 3,000 sold-data triggersVery low — the strictest incoming law
TexasNo volume threshold — but exempts SBA small businessesSee our Texas guide

The honest read: if you're a 12-person company with a few thousand customers, you're below the thresholds in nearly every state. That's not a loophole — it's how the laws were designed. But thresholds are falling (Delaware, Montana, Vermont), new states keep joining, and a growing business can cross a line without noticing. Which is why the smart move isn't panic — it's a yearly 30-minute check.

Question 3: Are you exempt anyway?

Even above the thresholds, whole categories of businesses and data sit outside these laws:

Don't DIY the exemptions. They're the most misread part of every privacy statute — including by vendors selling you compliance tools. If an exemption is load-bearing for your business (like the Texas small-business exemption), confirm your reading with a licensed privacy attorney in your state. This article is education, not advice.

So what do I actually do with this?

Here's the practical version, in priority order:

  1. Run the three questions once a year. Thresholds change, your business grows, new states come online. Thirty minutes, once a year, beats a panic later.
  2. Count your consumers honestly. Not site visitors — identifiable people whose personal data you control or process, per state. Your email list, customer database, and analytics are the inputs.
  3. If you're below every threshold: you're fine for now. Keep the free compliance checklist on file and re-check yearly — especially before the January 2027 wave.
  4. If you're above a threshold in any state: that's when the obligations kick in — privacy notices, honoring opt-outs, responding to consumer rights requests within 45 days, vendor contracts. Our Starter Pack walks through the full readiness system.
  5. If you sell online across state lines: read our Shopify store guide — multi-state selling makes applicability messier, and e-commerce has specific trip-wires.

Watch: how this actually plays out for small businesses

Video: "Small Businesses Are Next — 19 States Just Changed the Rules on Customer Data" (COMNEXIA / Mike Wilson). A small-business-focused walkthrough of why state privacy enforcement is reaching smaller companies. We haven't watched it end-to-end; verify anything you act on.

The 2027 wave: four new laws, one calendar

The patchwork isn't finished growing. Four more comprehensive laws are already on the calendar:

Each new law re-runs the three-question test for every business touching that state. That's the treadmill: the patchwork doesn't just sit there, it grows, and every growth spurt re-confuses everyone. The businesses that stay calm are the ones that re-check yearly instead of panicking at each deadline.

How to count your consumers: a worked example

The threshold math is where most owners get stuck, so here's a concrete walkthrough. Imagine Maria's online candle shop: 22,000 email subscribers, 31,000 orders last year, website analytics showing 90,000 unique visitors.

Her per-state counts (from shipping addresses): California 8,200 customers, Texas 5,100, Florida 4,400, New York 3,900, every other state under 2,000.

Result: Maria is below every threshold today. Her honest answer is "not covered" — with a calendar reminder to re-run the numbers next year, because at her growth rate she'll cross 100,000 total customers in about three years, and that's when California starts mattering.

Notice what the example shows: the question was never "am I a good person about privacy." It was arithmetic. Do the arithmetic.

Why vendor content will mislead you

A word of warning about where most "privacy law guides" come from: companies selling compliance software. Their business model needs you to feel covered and scared. So their content systematically:

We're vendor-neutral — we don't sell software, and our only product is plain-English guides. That doesn't make us unbiased about everything, but it does mean we have no reason to make the rules sound scarier than they are. When we say "you're probably fine," it's because the math says so, not because we're upselling you.

Frequently asked questions

Do I need to follow the strictest state's law everywhere?

No — and this is a common and expensive misconception. Each state's law applies to that state's residents. You don't need to apply California's rules to your Texas customers. What you do need is to know which states' residents you're covered for, and meet each one's requirements for those residents. In practice, many businesses adopt the strictest applicable standard across the board for simplicity — that's a business decision, not a legal requirement.

I'm below every threshold. Do I need a privacy policy?

Strictly for state privacy-law purposes: probably not required. Practically: yes, have one anyway. A basic privacy policy costs nothing, answers customer questions, and is the first thing anyone — regulator, partner, or plaintiff's lawyer — looks for. It's also required by some platforms and payment processors regardless of privacy law.

What counts as "selling" personal data?

More than you'd think. Beyond literal data-broker sales, several states' definitions capture sharing data for targeted advertising — including common setups like the Meta Pixel feeding purchase data back for ad targeting. If you run targeted ads, check whether your setup trips the "sale" definition in states where you're near thresholds. This is one of the highest-value questions to put to a privacy attorney.

How often should I re-check?

Once a year, plus whenever something material changes: a funding round, a big hiring push, crossing 50,000 total customers, launching targeted advertising, or a new state law taking effect where you have customers. Put it on the calendar next to your insurance renewal.

Is there really no federal law coming?

Correct as of October 2026. The last serious attempt (APRA) died with the 118th Congress in January 2025 and was never reintroduced; three 2026 bills exist but are considered highly unlikely to pass amid midterms. The realistic safety window for the state-led patchwork runs through 2028. We'll update this guide if that changes.

Want the full system?

The $49 Starter Pack includes the 24-state threshold matrix as a sortable spreadsheet, the 2027 readiness system, templates, and worksheets.

See the Starter Pack

Start free

The 20-question compliance checklist tells you where you stand in about ten minutes.

Get the free checklist

Important: this is not legal advice

This article is general educational information about US state privacy laws, not legal advice. Thresholds, exemptions, and effective dates change — verify against the statute or your state attorney general's guidance, and consult a licensed privacy attorney in your state before making compliance decisions based on your specific facts.