← Back to blog
US Privacy Law

Virginia, Texas & Beyond: The New US State Privacy Laws Explained

By DataShark · 25 June 2026 · 8 min read
?>

California's CCPA was just the beginning. As of 2026, over a dozen US states have enacted comprehensive privacy laws — and more are on the way. If your business operates online, you may already need to comply with several of them simultaneously. This guide explains the key laws, how they differ, and what a single compliant Privacy Policy needs to cover.

The current US state privacy law landscape

The following states have enacted comprehensive consumer privacy laws that are currently in effect:

California — CCPA/CPRA

Effective: January 1, 2020 (CCPA); January 1, 2023 (CPRA amendments)
Threshold: Revenue over $25M, or 100,000+ consumers' data, or 50%+ revenue from data sales
Key rights: Know, delete, correct, opt-out of sale/sharing, limit sensitive data
Enforcer: California Privacy Protection Agency (CPPA)

Virginia — VCDPA

Effective: January 1, 2023
Threshold: Controls/processes data of 100,000+ Virginia consumers, or 25,000+ consumers if 50%+ revenue from data sales
Key rights: Access, correction, deletion, portability, opt-out of targeted advertising and data sales
Enforcer: Virginia Attorney General (no private right of action)

Unlike California, Virginia's VCDPA has no private right of action — meaning only the Attorney General can sue. However, businesses have a 30-day cure period to fix violations before enforcement action begins.

Colorado — CPA

Effective: July 1, 2023
Threshold: Controls/processes data of 100,000+ Colorado consumers, or 25,000+ if 50%+ revenue from data sales
Key rights: Access, correction, deletion, portability, opt-out of targeted advertising, profiling, and data sales
Enforcer: Colorado Attorney General

Connecticut — CTDPA

Effective: July 1, 2023
Threshold: Controls/processes data of 100,000+ Connecticut consumers, or 25,000+ if 50%+ revenue from data sales
Key rights: Similar to Colorado CPA, with additional opt-out rights for profiling
Enforcer: Connecticut Attorney General

Texas — TDPSA

Effective: July 1, 2024
Threshold: Conducts business in Texas or targets Texas residents, and processes personal data — no revenue or volume threshold
Key rights: Access, correction, deletion, portability, opt-out of sale and targeted advertising
Enforcer: Texas Attorney General

⚠ Texas's TDPSA is notably broad — it has no minimum revenue or consumer threshold, meaning almost any business that targets Texas residents and processes their data must comply. This is significantly different from CCPA's $25M revenue threshold.

Florida — FDBR

Effective: July 1, 2024
Threshold: Annual revenue over $1 billion (applies to very large businesses only)
Key rights: Access, correction, deletion, portability, opt-out of targeted advertising and data sales

Montana, Oregon, Delaware, Iowa, New Hampshire, New Jersey, Nebraska, Tennessee

All have passed privacy laws taking effect between 2024 and 2026, generally following the Virginia/Colorado model with similar rights and thresholds.

How do these laws differ from CCPA?

While CCPA was the template, state privacy laws vary in important ways:

What must a Privacy Policy cover to comply with all US state laws?

A Privacy Policy that complies with all current US state privacy laws needs to include:

  1. Categories of personal data collected — including identifiers, commercial information, geolocation, biometric data, and internet activity
  2. Purposes for processing — specific, not vague
  3. Categories of third parties data is shared with — including advertising networks, analytics providers, payment processors
  4. Whether data is sold or shared for targeted advertising — and how to opt out
  5. Consumer rights and how to exercise them — covering access, correction, deletion, portability, and opt-out
  6. Sensitive data processing — and how you obtain consent or honour opt-out requests
  7. Data retention periods
  8. Contact information for privacy requests
  9. Date last updated

Do I need separate policies for each state?

No — and this is important. A single, comprehensive Privacy Policy can satisfy all US state privacy laws simultaneously if it covers all the required disclosures. You don't need a separate California policy, a Virginia policy, and a Texas policy. You need one policy that addresses the requirements of all applicable laws.

The practical approach is to write a policy at the highest common standard — which broadly means meeting CCPA/CPRA requirements (the most detailed), adding Texas's broader applicability language, and ensuring opt-out mechanisms are visible and functional.

What are the penalties?

DataShark generates a single US Privacy Policy that covers CCPA, CPRA, Virginia's VCDPA, Colorado's CPA, Texas's TDPSA, Connecticut's CTDPA, and all other major US state privacy laws — in under 3 minutes, from $19.

Ready to generate your GDPR policy?

Answer a few questions about your business and get a personalised, legally-structured document in minutes.

Start free — from £29 →