Twenty-Five State Privacy Laws: Thresholds-and-Exemptions Matrix
Twenty-five US states have passed consumer data privacy laws – twenty-one are in force today and four more take effect between now and Jan. 1, 2028. Most of these are comprehensive, regulating consumer data privacy protection across (nearly) every industry – they don't only apply to online services.
These laws generally follow the same basic structure:
- Providing individual rights of consumers with respect to their personal data
- Placing obligations (such as disclosure, security, and data minimization requirements) on organizations that collect, process, and transfer consumers' personal data
- Defining consent requirements around the processing of sensitive and children's data
- Providing for enforcement, typically by the state's attorney general
We'll discuss the details of nationwide compliance in a later post. For now, we're focused on determining which of these laws -- if any -- apply to your activities.
Whereas the EU GDPR regulates essentially all processing of personal data, regardless of the scale, states have limited the scope of their data privacy laws to exclude smaller companies/services, and many have excluded nonprofit organizations entirely.
Why is this useful?
You might reasonably say to yourself, "This looks like a lot. Shouldn't I just assume they all apply and comply with all of it?"
Well, maybe. Even if you run an online service that's available everywhere, it's worth taking a closer look if you're subject to a common exemption (e.g. you're a nonprofit or deal mostly with HIPAA data), you're not selling data, and you have relatively low per-state user/data subject numbers.
And if you run a more traditional business that genuinely only serves customers or handles data about people in a handful of states, your obligations may be meaningfully limited compared to across-the-board compliance. Some of the more expensive requirements, like ongoing impact assessments of "high-risk" processing activities and universal opt-out compliance, vary by state.
The structure of state privacy law applicability thresholds
While the details vary in important ways between states, nearly every comprehensive state data privacy laws screen organizations according to some combination of the following thresholds:
- Total annual revenue
- The number of state residents whose personal data they process
- The percentage of its revenue the organization makes from selling or sharing personal data of state residents
States mix and match these criteria in different ways. For example, California applies to an organization meeting any of three thresholds: (1) over $25M in total revenue (adjusted for inflation); (2) buying, selling, or sharing personal data of over 100,000 California consumers or households; or (3) deriving 50% of its annual revenue from selling or sharing personal data of California consumers. By contrast, several states (including Virginia, Indiana, and Iowa) have no "total revenue" threshold, but apply to organizations that either: (1) process personal data of over 100,000 state residents, or (2) process personal data of over 25,000 state residents and derive at least 50% of their revenue from selling that data. Other states, like Texas and Nebraska, have no such statutory thresholds, but exclude small businesses as defined by the federal Small Business Act (SBA) from most of their requirements.
Each state data privacy law also includes statutory exemptions for certain categories of (a) entities and (b) data. For example, many states exclude nonprofits or employment-related data (processed by employers) entirely, and make exceptions for HIPAA-regulated data (or entities) and financial institutions (or data regulated by the Gramm-Leach-Bliley Act). (Most laws also contain a fairly long list of exemptions for more niche entities and data, most of which are not applicable to the average company.)
Four questions to rule them all
To determine which laws (if any) are applicable to your organization, you first need to answer the following questions:
- What is your organization's total annual revenue?
- What sector is your organization in? (If the answer is nonprofit, healthcare, or financial services, you may be exempt from most requirements.)
And for each state where your data subjects reside:
3. How many people do you have personal data about in that state?
4. What share of your total revenue (if any) do you derive from selling or sharing personal data? (For most states, this analysis focuses on personal data of people in that state but some, including Virginia, do not make this distinction.)
Breakdown of main thresholds and exemptions by state
The table below contains information about the key thresholds and exemptions for every comprehensive (or near-comprehensive) US state data privacy law as of July 15, 2026. A detailed spreadsheet with more information about these laws can be found here or at the end of the post.
| Statute (citation) | Revenue threshold | Volume threshold | Sale-based alternative | Nonprofits covered? | Notable quirks |
|---|---|---|---|---|---|
| Alabama Personal Data Protection Act (2026), codification pending Takes effect 5/1/2027 |
None | 25k (excl. personal data processed solely for payment) | 25%+ gross revenue from sale | Yes, except nonprofits with <100 employees that don't sell personal data | Businesses with <500 employees exempted unless they sell personal data |
| California CCPA/CPRA, Cal. Civ. Code 1798.100 et seq. Effective 1/1/2020 |
>$25M (CPI-adjusted; ~$26.625M) | 100k consumers/households (buy/sell/share) | 50%+ of revenue from selling/sharing | No (for-profit "businesses" only) | Only dedicated agency; employee/B2B data; ADMT regs; thresholds are OR, not AND |
| Colorado CPA, C.R.S. 6-1-1301 et seq. Effective 7/1/2023 |
None | 100k | 25k + revenue/discount from sale | Yes | UOOM registry; 2025 biometric provisions apply regardless of thresholds |
| Connecticut CTDPA, Conn. Gen. Stat. 42-515 et seq. Effective 7/1/2023 |
None | 35k (from 7/1/26) | None (from 7/1/26) | No | Most-amended statute; often the leading edge |
| Delaware DPDPA, 6 Del. C. 12D-101 et seq. Effective 1/1/2025 |
None | 35k | 10k + 20% gross revenue from sale | Yes | Low thresholds; covers nonprofits and higher ed |
| Florida Digital Bill of Rights, Fla. Stat. 501.701 et seq. Effective 7/1/2024 |
$1B global revenue AND ad/app-store/smart-speaker criteria (but opt-in for data sales applies to all businesses) | n/a | n/a | No | Big-tech-only; arguably not "comprehensive"; sensitive-data sale consent applies more broadly |
| Iowa ICDPA, Iowa Code 715D.1 et seq. Effective 1/1/2025 |
None | 100k | 25k + 50% revenue from sale | No | Weakest tier with UT; longest cure period |
| Indiana INCDPA, Ind. Code 24-15-1-1 et seq. Effective 1/1/2026 |
None | 100k | 25k + 50% revenue from sale | No | Virginia clone |
| Kentucky KCDPA, Ky. Rev. Stat. 367.3611 et seq. Effective 1/1/2026 |
None | 100k | 25k + 50% revenue from sale | No | Virginia clone |
| Louisiana Data Privacy Act (2026), codification pending Takes effect 1/1/2027 |
$25M | 75k consumers/households/devices (buy/receive/sell/share) | 50%+ of annual revenue from selling LA consumers' PI | No | California-flavored threshold structure (households/devices; "sharing") |
| Maryland MODPA, Md. Code, Com. Law 14-4601 et seq. Effective 10/1/2025 |
None | 35k | 10k + 20% revenue from sale | Yes | Strictest: substantive data minimization for ALL personal data; no targeted ads to under-18s |
| Minnesota MCDPA, Minn. Stat. 325O.01 et seq. Effective 7/31/2025 |
None | 100k | 25k + 25% revenue from sale | Yes, except nonprofits meeting SBA small-business definition | Right to question profiling results; express data-inventory duty |
| Montana MCDPA, Mont. Code Ann. 30-14-2801 et seq. Effective 10/1/2024 |
None | 25k | 15k + 25% revenue from sale | Yes | Lowest-population state with a comprehensive law; watch amendments |
| Nebraska NDPA, Neb. Rev. Stat. 87-1101 et seq. Effective 1/1/2025 |
None | None | None | No | Texas clone: applies unless SBA small business (which still needs consent to sell sensitive data) |
| New Hampshire NHPA, RSA 507-H Effective 1/1/2025 |
None | 35k | 10k + 25% revenue from sale | No | Low thresholds for a small state |
| New Jersey NJDPA, N.J.S.A. 56:8-166.4 et seq. Effective 1/15/2025 |
None | 100k (excl. personal data processed solely for payment) | 25k + any revenue from sale | Yes | Only rulemaking authority outside CA/CO; financial info = sensitive |
| Nevada Online Privacy Law (limited scope), NRS 603A.300-.360 Effective 10/1/2019 |
None | None (operator definition, not volume, controls applicability) | n/a | Yes, if the nonprofit "owns or operates an Internet website or online service for commercial purposes" | NOT comprehensive: notice + narrow sale opt-out only; no access/deletion/correction rights; applies to commercial website/online-service "operators" |
| Oklahoma Consumer Data Privacy Act (2026), codification pending Takes effect 1/1/2027 |
None | 100k | 25k + >50% gross revenue from sale | No | Virginia model |
| Oregon OCPA, Or. Rev. Stat. 646A.570 et seq. Effective 7/1/2024 |
None | 100k | 25k + 25% revenue from sale | Yes | Right to list of specific third parties; narrowest exemptions |
| Rhode Island RIDTPPA, R.I. Gen. Laws 6-48.1-1 et seq. Effective 1/1/2026 |
None | 35k | 10k + 20% revenue from sale | No | Must list third parties to whom controller has sold/may sell personal data in privacy notice; no cure period |
| Tennessee TIPA, Tenn. Code Ann. 47-18-3201 et seq. Effective 7/1/2025 |
>$25M AND volume or sales threshold | 175k | 25k + 50% revenue from sale | No | NIST Privacy Framework affirmative defense (unique); high volume threshold |
| Texas TDPSA, Tex. Bus. & Com. Code 541.001 et seq. Effective 7/1/2024 |
None | None | None | No | No numeric thresholds at all — SBA small-business status is the screen; active enforcer |
| Utah UCPA, Utah Code 13-61-101 et seq. Effective 12/31/2023 |
$25M AND volume or sales threshold | 100k | 25k + 50% revenue from sale | No | Weakest tier; revenue AND volume thresholds must both be met |
| Virginia VCDPA, Va. Code 59.1-575 et seq. Effective 1/1/2023 |
None | 100k | 25k + >50% revenue from sale | No | The template most states copied |
| Vermont Data Privacy and Online Surveillance Act (2026), codification pending Takes effect 1/1/2028 |
None | 35k, OR 3k sensitive data (excl. personal data processed solely for payment) | 3k consumers' personal data offered for sale | Yes | Lowest sensitive-data trigger of any state (3k) — a fitness or health-adjacent app hits this fast; longest runway (2028) |
A handful of outliers
While the basic structure of thresholds and exemptions are pretty similar state-to-state, there are some distinct outliers worth mentioning. A few of particular note:
- Texas and its copycat Nebraska have no revenue, volume, or data-sales thresholds at all. Instead, they exempt "small businesses" as defined by the SBA
- Florida has such a high annual-revenue threshold ($1B in global revenue) that it basically only applies to big-tech companies. Even then, it only applies to companies that either (a) derive 50%+ of their annual revenue from online ad sales, (b) sell voice-operated smart speakers, or (c) operate app stores containing at least 250,000 apps.
- California, always in its own category, is the only state that doesn't exempt processing of employment-related data by employers. It is also unique insofar as it established a new government agency (the California Privacy Protection Agency) to enforce its privacy law.
- Maryland's thresholds are similar to other states, but its data protections are sharper than most: the law bans all sales of "sensitive data" and limits processing of all personal data to only what is strictly necessary.
Important: exemption doesn't mean unregulated
Keep in mind that, even if your activities are mostly exempted from state data privacy laws or don't meet the minimum thresholds, that doesn't mean they're totally unregulated. For one thing, some states regulate certain activities (such as sale of sensitive data) regardless of whether you meet the threshold.
There are also many other state and federal laws regulating data privacy to one degree or another, including:
- The Illinois Biometric Information Privacy Act (BIPA), regulating the collection and sharing of biometric data.
- The Washington My Health My Data Act (MHMDA), regulating the processing and sharing of personal health data that falls outside of HIPAA.
- The federal Children's Online Privacy Protection Act (COPPA), strictly regulating the collection and use of children's personal data.
- State breach-notification laws, which require disclosure and remediation of data breaches affecting personal data, without exemption.
And finally, the Federal Trade Commission has broad latitude under Section 5 of the FTC Act to regulate data processing and sharing activities to the extent they constitute unfair trade practices (though its reach does not extend to nonprofit organizations, banks and credit unions, common carriers, or most insurance companies).
Take action
This week, run down the answers to the four questions above, and identify which states' thresholds your organization meets. This will be a good first step in determining your compliance obligations in the US. Run the analysis again after any fund-raise, growth spurt, or expansion to a new state.