September 27, 2026 · 8 min read

US State Privacy Laws 2026: Are You in Scope? (California, Virginia, Colorado, Texas)

The United States still has no single federal privacy law. Instead, a growing patchwork of roughly 20 state laws (in force in 2026) now governs how you handle personal data — each with its own thresholds, its own definitions, and its own regulator. The four below are the common core, but they are not the whole map: states like Connecticut (~35,000 consumers, plus triggers with no volume floor) and Montana (~50,000) reach smaller businesses. For an online business, the hard part isn't the rules themselves; it's figuring out which states apply to you in the first place.

The short version: most state laws only kick in once you do business in the state and cross a volume or revenue threshold. One big exception is Texas, whose law applies with essentially no size threshold. Below, the four laws that matter most in 2026.

The four laws most businesses hit first

State / LawApplies when you do business there AND…Regulator
California — CCPA / CPRA Gross revenue > ~$26.6M; OR buy/sell/share data of 100,000+ consumers/households; OR 50%+ of revenue from selling/sharing data CPPA + Attorney General
Virginia — VCDPA Process data of 100,000+ consumers; OR 25,000+ consumers and derive 50%+ of revenue from selling data Attorney General
Colorado — CPA Process data of 100,000+ consumers; OR derive revenue / a discount from selling data and process 25,000+ consumers Attorney General + DAs
Texas — TDPSA Essentially no size threshold — applies to anyone doing business in Texas and processing personal data, except SBA-defined small businesses Attorney General

California is the strictest — and now adds a cybersecurity audit

Beyond notice and opt-out rights, California layered on an annual cybersecurity audit obligation for larger, data-heavy businesses (in force since January 1, 2026). We break that down separately — see the linked article below — but the key point is that California keeps raising the bar the other states follow.

Virginia & Colorado — the "100,000 consumers" club

VCDPA and CPA share the same shape: a headline threshold of 100,000 consumers, or a lower 25,000-consumer bar if you make money from selling data. Both grant rights to access, correct, delete, and opt out of targeted advertising and sales, and both require recognizing universal opt-out signals.

Texas — the one that catches everyone

The TDPSA is the trap for smaller sellers: it has no revenue or volume threshold. If you do business in Texas or target Texas residents and process personal data, you're likely covered — unless you qualify as a small business under the SBA definition. And even then there's a catch: an exempt small business still must obtain consent before selling sensitive data. Many merchants who assume "we're too small for privacy laws" are wrong specifically because of Texas.

Don't confuse coverage with compliance. Being in scope is step one. Each law then demands specific things: a compliant privacy notice, honoring opt-out and universal signals (like Global Privacy Control), data-processing agreements with vendors, and — in California — a formal cybersecurity audit for qualifying businesses. A few traps worth knowing: GLBA/HIPAA exemptions can be entity-level (whole business out) or data-level (only the regulated data out, so your marketing and web-visitor data may still be covered); and rules for minors are stricter than COPPA — California needs consent to sell/share data of anyone under 16, and several states extend that further.

How to find out fast

You don't need to read four statutes. Start from two questions: where do your customers actually are, and do you sell or share their data. From there, an automated scan can flag the observable gaps — privacy notice, opt-out mechanics, universal-signal handling, disclosed data categories — and tell you which laws deserve a closer look. It won't replace legal advice, but it turns a vague worry into a concrete checklist.

Not sure which US laws apply to you?

Run a free scan. Our audit checks your site against CCPA/CPRA and other US state privacy frameworks, flags the observable gaps, and delivers a plain-language report — so you know exactly where to focus.

🔍 Check my site free

Related articles

This article is general information, not legal advice. Thresholds and definitions vary by state and change over time; confirm your obligations with a qualified professional.

← Back to the blog