Twenty-Five State Privacy Laws: Thresholds-and-Exemptions Matrix

Share

Twenty-five US states have passed consumer data privacy laws – twenty-one are in force today and four more take effect between now and Jan. 1, 2028. Most of these are comprehensive, regulating consumer data privacy protection across (nearly) every industry – they don't only apply to online services.

These laws generally follow the same basic structure:

  • Providing individual rights of consumers with respect to their personal data
  • Placing obligations (such as disclosure, security, and data minimization requirements) on organizations that collect, process, and transfer consumers' personal data
  • Defining consent requirements around the processing of sensitive and children's data
  • Providing for enforcement, typically by the state's attorney general

We'll discuss the details of nationwide compliance in a later post. For now, we're focused on determining which of these laws -- if any -- apply to your activities.

Whereas the EU GDPR regulates essentially all processing of personal data, regardless of the scale, states have limited the scope of their data privacy laws to exclude smaller companies/services, and many have excluded nonprofit organizations entirely.

Why is this useful?

You might reasonably say to yourself, "This looks like a lot. Shouldn't I just assume they all apply and comply with all of it?"

Well, maybe. Even if you run an online service that's available everywhere, it's worth taking a closer look if you're subject to a common exemption (e.g. you're a nonprofit or deal mostly with HIPAA data), you're not selling data, and you have relatively low per-state user/data subject numbers.

And if you run a more traditional business that genuinely only serves customers or handles data about people in a handful of states, your obligations may be meaningfully limited compared to across-the-board compliance. Some of the more expensive requirements, like ongoing impact assessments of "high-risk" processing activities and universal opt-out compliance, vary by state.

The structure of state privacy law applicability thresholds

While the details vary in important ways between states, nearly every comprehensive state data privacy laws screen organizations according to some combination of the following thresholds:

  • Total annual revenue
  • The number of state residents whose personal data they process
  • The percentage of its revenue the organization makes from selling or sharing personal data of state residents

States mix and match these criteria in different ways. For example, California applies to an organization meeting any of three thresholds: (1) over $25M in total revenue (adjusted for inflation); (2) buying, selling, or sharing personal data of over 100,000 California consumers or households; or (3) deriving 50% of its annual revenue from selling or sharing personal data of California consumers. By contrast, several states (including Virginia, Indiana, and Iowa) have no "total revenue" threshold, but apply to organizations that either: (1) process personal data of over 100,000 state residents, or (2) process personal data of over 25,000 state residents and derive at least 50% of their revenue from selling that data. Other states, like Texas and Nebraska, have no such statutory thresholds, but exclude small businesses as defined by the federal Small Business Act (SBA) from most of their requirements.

Each state data privacy law also includes statutory exemptions for certain categories of (a) entities and (b) data. For example, many states exclude nonprofits or employment-related data (processed by employers) entirely, and make exceptions for HIPAA-regulated data (or entities) and financial institutions (or data regulated by the Gramm-Leach-Bliley Act). (Most laws also contain a fairly long list of exemptions for more niche entities and data, most of which are not applicable to the average company.)

Four questions to rule them all

To determine which laws (if any) are applicable to your organization, you first need to answer the following questions:

  1. What is your organization's total annual revenue?
  2. What sector is your organization in? (If the answer is nonprofit, healthcare, or financial services, you may be exempt from most requirements.)

And for each state where your data subjects reside:
3. How many people do you have personal data about in that state?
4. What share of your total revenue (if any) do you derive from selling or sharing personal data? (For most states, this analysis focuses on personal data of people in that state but some, including Virginia, do not make this distinction.)

Breakdown of main thresholds and exemptions by state

The table below contains information about the key thresholds and exemptions for every comprehensive (or near-comprehensive) US state data privacy law as of July 15, 2026. A detailed spreadsheet with more information about these laws can be found here or at the end of the post.

Statute (citation) Revenue threshold Volume threshold Sale-based alternative Nonprofits covered? Notable quirks
Alabama
Personal Data Protection Act (2026), codification pending
Takes effect 5/1/2027
None 25k (excl. personal data processed solely for payment) 25%+ gross revenue from sale Yes, except nonprofits with <100 employees that don't sell personal data Businesses with <500 employees exempted unless they sell personal data
California
CCPA/CPRA, Cal. Civ. Code 1798.100 et seq.
Effective 1/1/2020
>$25M (CPI-adjusted; ~$26.625M) 100k consumers/households (buy/sell/share) 50%+ of revenue from selling/sharing No (for-profit "businesses" only) Only dedicated agency; employee/B2B data; ADMT regs; thresholds are OR, not AND
Colorado
CPA, C.R.S. 6-1-1301 et seq.
Effective 7/1/2023
None 100k 25k + revenue/discount from sale Yes UOOM registry; 2025 biometric provisions apply regardless of thresholds
Connecticut
CTDPA, Conn. Gen. Stat. 42-515 et seq.
Effective 7/1/2023
None 35k (from 7/1/26) None (from 7/1/26) No Most-amended statute; often the leading edge
Delaware
DPDPA, 6 Del. C. 12D-101 et seq.
Effective 1/1/2025
None 35k 10k + 20% gross revenue from sale Yes Low thresholds; covers nonprofits and higher ed
Florida
Digital Bill of Rights, Fla. Stat. 501.701 et seq.
Effective 7/1/2024
$1B global revenue AND ad/app-store/smart-speaker criteria (but opt-in for data sales applies to all businesses) n/a n/a No Big-tech-only; arguably not "comprehensive"; sensitive-data sale consent applies more broadly
Iowa
ICDPA, Iowa Code 715D.1 et seq.
Effective 1/1/2025
None 100k 25k + 50% revenue from sale No Weakest tier with UT; longest cure period
Indiana
INCDPA, Ind. Code 24-15-1-1 et seq.
Effective 1/1/2026
None 100k 25k + 50% revenue from sale No Virginia clone
Kentucky
KCDPA, Ky. Rev. Stat. 367.3611 et seq.
Effective 1/1/2026
None 100k 25k + 50% revenue from sale No Virginia clone
Louisiana
Data Privacy Act (2026), codification pending
Takes effect 1/1/2027
$25M 75k consumers/households/devices (buy/receive/sell/share) 50%+ of annual revenue from selling LA consumers' PI No California-flavored threshold structure (households/devices; "sharing")
Maryland
MODPA, Md. Code, Com. Law 14-4601 et seq.
Effective 10/1/2025
None 35k 10k + 20% revenue from sale Yes Strictest: substantive data minimization for ALL personal data; no targeted ads to under-18s
Minnesota
MCDPA, Minn. Stat. 325O.01 et seq.
Effective 7/31/2025
None 100k 25k + 25% revenue from sale Yes, except nonprofits meeting SBA small-business definition Right to question profiling results; express data-inventory duty
Montana
MCDPA, Mont. Code Ann. 30-14-2801 et seq.
Effective 10/1/2024
None 25k 15k + 25% revenue from sale Yes Lowest-population state with a comprehensive law; watch amendments
Nebraska
NDPA, Neb. Rev. Stat. 87-1101 et seq.
Effective 1/1/2025
None None None No Texas clone: applies unless SBA small business (which still needs consent to sell sensitive data)
New Hampshire
NHPA, RSA 507-H
Effective 1/1/2025
None 35k 10k + 25% revenue from sale No Low thresholds for a small state
New Jersey
NJDPA, N.J.S.A. 56:8-166.4 et seq.
Effective 1/15/2025
None 100k (excl. personal data processed solely for payment) 25k + any revenue from sale Yes Only rulemaking authority outside CA/CO; financial info = sensitive
Nevada
Online Privacy Law (limited scope), NRS 603A.300-.360
Effective 10/1/2019
None None (operator definition, not volume, controls applicability) n/a Yes, if the nonprofit "owns or operates an Internet website or online service for commercial purposes" NOT comprehensive: notice + narrow sale opt-out only; no access/deletion/correction rights; applies to commercial website/online-service "operators"
Oklahoma
Consumer Data Privacy Act (2026), codification pending
Takes effect 1/1/2027
None 100k 25k + >50% gross revenue from sale No Virginia model
Oregon
OCPA, Or. Rev. Stat. 646A.570 et seq.
Effective 7/1/2024
None 100k 25k + 25% revenue from sale Yes Right to list of specific third parties; narrowest exemptions
Rhode Island
RIDTPPA, R.I. Gen. Laws 6-48.1-1 et seq.
Effective 1/1/2026
None 35k 10k + 20% revenue from sale No Must list third parties to whom controller has sold/may sell personal data in privacy notice; no cure period
Tennessee
TIPA, Tenn. Code Ann. 47-18-3201 et seq.
Effective 7/1/2025
>$25M AND volume or sales threshold 175k 25k + 50% revenue from sale No NIST Privacy Framework affirmative defense (unique); high volume threshold
Texas
TDPSA, Tex. Bus. & Com. Code 541.001 et seq.
Effective 7/1/2024
None None None No No numeric thresholds at all — SBA small-business status is the screen; active enforcer
Utah
UCPA, Utah Code 13-61-101 et seq.
Effective 12/31/2023
$25M AND volume or sales threshold 100k 25k + 50% revenue from sale No Weakest tier; revenue AND volume thresholds must both be met
Virginia
VCDPA, Va. Code 59.1-575 et seq.
Effective 1/1/2023
None 100k 25k + >50% revenue from sale No The template most states copied
Vermont
Data Privacy and Online Surveillance Act (2026), codification pending
Takes effect 1/1/2028
None 35k, OR 3k sensitive data (excl. personal data processed solely for payment) 3k consumers' personal data offered for sale Yes Lowest sensitive-data trigger of any state (3k) — a fitness or health-adjacent app hits this fast; longest runway (2028)

A handful of outliers

While the basic structure of thresholds and exemptions are pretty similar state-to-state, there are some distinct outliers worth mentioning. A few of particular note:

  • Texas and its copycat Nebraska have no revenue, volume, or data-sales thresholds at all. Instead, they exempt "small businesses" as defined by the SBA
  • Florida has such a high annual-revenue threshold ($1B in global revenue) that it basically only applies to big-tech companies. Even then, it only applies to companies that either (a) derive 50%+ of their annual revenue from online ad sales, (b) sell voice-operated smart speakers, or (c) operate app stores containing at least 250,000 apps.
  • California, always in its own category, is the only state that doesn't exempt processing of employment-related data by employers. It is also unique insofar as it established a new government agency (the California Privacy Protection Agency) to enforce its privacy law.
  • Maryland's thresholds are similar to other states, but its data protections are sharper than most: the law bans all sales of "sensitive data" and limits processing of all personal data to only what is strictly necessary.

Important: exemption doesn't mean unregulated

Keep in mind that, even if your activities are mostly exempted from state data privacy laws or don't meet the minimum thresholds, that doesn't mean they're totally unregulated. For one thing, some states regulate certain activities (such as sale of sensitive data) regardless of whether you meet the threshold.

There are also many other state and federal laws regulating data privacy to one degree or another, including:

  • The Illinois Biometric Information Privacy Act (BIPA), regulating the collection and sharing of biometric data.
  • The Washington My Health My Data Act (MHMDA), regulating the processing and sharing of personal health data that falls outside of HIPAA.
  • The federal Children's Online Privacy Protection Act (COPPA), strictly regulating the collection and use of children's personal data.
  • State breach-notification laws, which require disclosure and remediation of data breaches affecting personal data, without exemption.

And finally, the Federal Trade Commission has broad latitude under Section 5 of the FTC Act to regulate data processing and sharing activities to the extent they constitute unfair trade practices (though its reach does not extend to nonprofit organizations, banks and credit unions, common carriers, or most insurance companies).

Take action

This week, run down the answers to the four questions above, and identify which states' thresholds your organization meets. This will be a good first step in determining your compliance obligations in the US. Run the analysis again after any fund-raise, growth spurt, or expansion to a new state.