AccuSights
PartnersBlogAbout
Book my 30-minute demo

Blog / US compliance

US compliance

State Privacy Laws in 2026: Which of the 20 Actually Apply to a Business Your Size

State privacy laws 2026: 20 are in force, three started in January, and Texas has no consumer-count threshold. How to tell which ones apply to your business.

Sam KhanSam Khan The Cyber ExpertFounder and CEOSeptember 2, 2026 · 6 min read

The email that says "under Texas law"

The founder of a Texas skincare brand, nine employees and about 60,000 customers, gets a customer email on a Tuesday. It is short. The customer wants every piece of data the brand holds on her deleted, and she wants written confirmation, "under Texas law".

The founder forwards it to the customer service lead with a note: "We're too small for this, right?" The customer service lead does not know. The founder texts a lawyer friend.

The lawyer friend calls back in ten minutes, which is never a good sign. Texas, she says, does not count consumers. The Texas law applies to any business operating in the state that is not a small business under the federal SBA size standards, and there is no revenue floor. The founder asks what her size standard is. The lawyer says it depends on the industry code, and at her growth rate she should assume she will cross it.

Then the lawyer asks where else the brand ships. Everywhere, of course. Rhode Island, since January, at a 35,000-consumer threshold. Connecticut, since July, with no threshold at all if you sell personal data or process sensitive data. Skin conditions, the lawyer points out, are health data. The founder has a quiz on her website that asks about them.

Twenty state laws, twenty thresholds, one nine-person company. The founder stops saying "too small" and starts counting.

What the heck does this mean

A comprehensive state privacy law gives residents rights over their personal data and gives businesses duties. The rights are the ones you see in the customer's email: know what you hold, delete it, correct it, opt out of its sale or use for targeted advertising. The duties are a privacy notice that is true, contracts with the vendors who process the data, and a written risk review for the risky stuff.

A threshold is the test that decides whether a law applies to you. Most states use a consumer count, commonly 100,000 or 35,000 residents a year. Some add a revenue test. Texas uses the SBA size standards instead of a count. Connecticut, since 1 July 2026, drops the count entirely for any business that sells personal data or processes sensitive data.

Sensitive data is the category with the sharpest rules: health, precise location, biometrics, children's data, and details like race or religion. A skincare quiz that asks about eczema collects health data.

Sale is broader than cash. Handing customer data to an advertising platform so it can target better is a sale under most of these laws.

A data protection assessment is the written risk review, required before you start targeted advertising, selling data, or handling sensitive data.

The numbers that matter

Indiana, Kentucky and Rhode Island's comprehensive privacy laws took effect on 1 January 2026, and Rhode Island's applicability threshold is 35,000 consumers, according to the 2026 state statutes as tracked by MultiState. Three new sets of rights in one morning, for any brand that ships to those states.

Connecticut's amendment, in force since 1 July 2026 under SB 1295 passed in 2025, covers any business that sells personal data or processes sensitive data, with no consumer-count threshold. The advertising pixel on a checkout page is enough to pull a nine-person company in.

Texas's Data Privacy and Security Act, in force since 2024, covers any business operating in the state that is not a small business under SBA size standards, with no revenue floor. The question is not how many customers you have; it is which industry code you fall under and if the business has outgrown it.

What to do this week

  1. Count customers by state from the order system, for the last twelve months. Mark every state where you cross 35,000 or 100,000, and look up your SBA size standard for the Texas test. That list is your map of which laws apply. (CIS 3 Data Protection)
  2. Inventory the personal data: what you collect at checkout, in the quiz, in the newsletter signup, and where each field goes afterward, including the pixels and the email platform. Flag anything that counts as sensitive. (CIS 3 Data Protection)
  3. List every vendor that receives customer data, from the email tool to the ad platforms to the fulfillment warehouse, and check whether each contract says what they can do with it. Most state laws require those terms in writing. (CIS 15 Service Provider Management)
  4. Set up one mailbox for privacy requests and a log with the date received, what was asked, what you did, and the date you replied. Every state sets a response clock, and the log is your evidence that you met it. (CIS 8 Audit Log Management)
  5. Cut the sensitive data you do not need. If the quiz can recommend a product without storing the skin condition against the customer's name, change it so it does not. Consent is the fallback, deletion is the fix. (CIS 3 Data Protection)
  6. Write the data protection assessment for the targeted advertising you already run, update the privacy notice to match reality, and add the opt-out link. Then answer the customer's email, on time. (CIS 3 Data Protection)

Where AccuSights fits

Our assessment starts with the data map, not the statute: where personal data enters, where it lives, which vendors get it, and which state thresholds you have crossed. Our team then implements the controls at a reasonable rate, from data loss prevention that keeps the customer export out of personal inboxes to scanning and protection of the systems holding the data, so the privacy notice you publish describes something true. The Cyber Hygiene Test takes three minutes, and 15 minutes with an engineer will tell you which of the twenty you need to worry about.

Questions people ask

Does the California privacy law apply to out-of-state businesses? Yes, if you do business in California and meet its thresholds, which are based on annual revenue, the number of California consumers whose data you handle, or the share of revenue you earn from selling personal data. A Texas brand shipping to Los Angeles is doing business in California. Whether it crosses a threshold is a counting exercise, and the count changes every year you grow.

What is a data protection assessment? A written review of a specific kind of processing that the law considers risky: targeted advertising, selling personal data, profiling, or handling sensitive data. It records what you collect, why, what could go wrong for the consumer, and what you do to reduce that. Most state laws require one before you start the processing and let the attorney general ask for it, so it is a document you keep, not one you write when the letter arrives.

Do I need a Do Not Sell link? If you are covered by a state law and you sell personal data or use it for targeted advertising, you need a clear way for consumers to opt out, and several states name the link. The catch is the word sell. Sharing customer data with an advertising platform in exchange for better targeting counts as a sale under most of these laws, even though no invoice changes hands. If a pixel on your site feeds an ad network, assume you sell.

"Too small" is a threshold, and thresholds are numbers. Go find yours before a customer finds it for you.

Controls this post maps to

CIS 3 Data ProtectionCIS 8 Audit Log ManagementCIS 15 Service Provider Management

CIS Controls v8.1. These are the same controls our assessment scores and the console watches.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Our team implements these controls at a reasonable rate, from DLP to scanning to protection of assets.

Thirty minutes with an engineer, your environment on the screen, and a fixed-fee scope before the call ends. Prefer to see where you stand first? The hygiene test takes three minutes.

Compliance is not security. The audit is not the exam; the attacker is.