California's CCPA was just the beginning. As of 2026, over a dozen US states have enacted comprehensive privacy laws — and more are on the way. If your business operates online, you may already need to comply with several of them simultaneously. This guide explains the key laws, how they differ, and what a single compliant Privacy Policy needs to cover.
The current US state privacy law landscape
The following states have enacted comprehensive consumer privacy laws that are currently in effect:
California — CCPA/CPRA
Effective: January 1, 2020 (CCPA); January 1, 2023 (CPRA amendments)
Threshold: Revenue over $25M, or 100,000+ consumers' data, or 50%+ revenue from data sales
Key rights: Know, delete, correct, opt-out of sale/sharing, limit sensitive data
Enforcer: California Privacy Protection Agency (CPPA)
Virginia — VCDPA
Effective: January 1, 2023
Threshold: Controls/processes data of 100,000+ Virginia consumers, or 25,000+ consumers if 50%+ revenue from data sales
Key rights: Access, correction, deletion, portability, opt-out of targeted advertising and data sales
Enforcer: Virginia Attorney General (no private right of action)
Colorado — CPA
Effective: July 1, 2023
Threshold: Controls/processes data of 100,000+ Colorado consumers, or 25,000+ if 50%+ revenue from data sales
Key rights: Access, correction, deletion, portability, opt-out of targeted advertising, profiling, and data sales
Enforcer: Colorado Attorney General
Connecticut — CTDPA
Effective: July 1, 2023
Threshold: Controls/processes data of 100,000+ Connecticut consumers, or 25,000+ if 50%+ revenue from data sales
Key rights: Similar to Colorado CPA, with additional opt-out rights for profiling
Enforcer: Connecticut Attorney General
Texas — TDPSA
Effective: July 1, 2024
Threshold: Conducts business in Texas or targets Texas residents, and processes personal data — no revenue or volume threshold
Key rights: Access, correction, deletion, portability, opt-out of sale and targeted advertising
Enforcer: Texas Attorney General
⚠ Texas's TDPSA is notably broad — it has no minimum revenue or consumer threshold, meaning almost any business that targets Texas residents and processes their data must comply. This is significantly different from CCPA's $25M revenue threshold.
Florida — FDBR
Effective: July 1, 2024
Threshold: Annual revenue over $1 billion (applies to very large businesses only)
Key rights: Access, correction, deletion, portability, opt-out of targeted advertising and data sales
Montana, Oregon, Delaware, Iowa, New Hampshire, New Jersey, Nebraska, Tennessee
All have passed privacy laws taking effect between 2024 and 2026, generally following the Virginia/Colorado model with similar rights and thresholds.
How do these laws differ from CCPA?
While CCPA was the template, state privacy laws vary in important ways:
- Thresholds — Texas has no minimum threshold; most others use 100,000 consumer threshold; California uses $25M revenue or 100,000 consumers
- Opt-in vs opt-out — Most states require opt-out (like CCPA). Some require opt-in consent for sensitive data categories
- Sensitive data — All states define sensitive data categories (health, financial, precise geolocation, children's data) requiring explicit consent
- Data Protection Assessments — Virginia, Colorado, Connecticut, and Texas all require Data Protection Impact Assessments for high-risk processing
- Private right of action — Only California allows individuals to sue. Other states limit enforcement to the Attorney General
- Cure periods — Many states give businesses 30–60 days to fix violations before facing penalties
What must a Privacy Policy cover to comply with all US state laws?
A Privacy Policy that complies with all current US state privacy laws needs to include:
- Categories of personal data collected — including identifiers, commercial information, geolocation, biometric data, and internet activity
- Purposes for processing — specific, not vague
- Categories of third parties data is shared with — including advertising networks, analytics providers, payment processors
- Whether data is sold or shared for targeted advertising — and how to opt out
- Consumer rights and how to exercise them — covering access, correction, deletion, portability, and opt-out
- Sensitive data processing — and how you obtain consent or honour opt-out requests
- Data retention periods
- Contact information for privacy requests
- Date last updated
Do I need separate policies for each state?
No — and this is important. A single, comprehensive Privacy Policy can satisfy all US state privacy laws simultaneously if it covers all the required disclosures. You don't need a separate California policy, a Virginia policy, and a Texas policy. You need one policy that addresses the requirements of all applicable laws.
The practical approach is to write a policy at the highest common standard — which broadly means meeting CCPA/CPRA requirements (the most detailed), adding Texas's broader applicability language, and ensuring opt-out mechanisms are visible and functional.
What are the penalties?
- California: $2,500 per unintentional violation, $7,500 per intentional violation
- Virginia: Up to $7,500 per violation
- Colorado: Up to $20,000 per violation
- Connecticut: Up to $5,000 per violation
- Texas: Up to $7,500 per violation, up to $150,000 per related series of violations
DataShark generates a single US Privacy Policy that covers CCPA, CPRA, Virginia's VCDPA, Colorado's CPA, Texas's TDPSA, Connecticut's CTDPA, and all other major US state privacy laws — in under 3 minutes, from $19.
Ready to generate your GDPR policy?
Answer a few questions about your business and get a personalised, legally-structured document in minutes.
Start free — from £29 →