Blog / US compliance
US compliance
State Privacy Laws in 2026: Which of the 20 Actually Apply to a Business Your Size
State privacy laws 2026: 20 are in force, three started in January, and Texas has no consumer-count threshold. How to tell which ones apply to your business.
The email that says "under Texas law"
The founder of a Texas skincare brand, nine employees and about 60,000 customers, gets a customer email on a Tuesday. It is short. The customer wants every piece of data the brand holds on her deleted, and she wants written confirmation, "under Texas law".
The founder forwards it to the customer service lead with a note: "We're too small for this, right?" The customer service lead does not know. The founder texts a lawyer friend.
The lawyer friend calls back in ten minutes, which is never a good sign. Texas, she says, does not count consumers. The Texas law applies to any business operating in the state that is not a small business under the federal SBA size standards, and there is no revenue floor. The founder asks what her size standard is. The lawyer says it depends on the industry code, and at her growth rate she should assume she will cross it.
Then the lawyer asks where else the brand ships. Everywhere, of course. Rhode Island, since January, at a 35,000-consumer threshold. Connecticut, since July, with no threshold at all if you sell personal data or process sensitive data. Skin conditions, the lawyer points out, are health data. The founder has a quiz on her website that asks about them.
Twenty state laws, twenty thresholds, one nine-person company. The founder stops saying "too small" and starts counting.
What the heck does this mean
A comprehensive state privacy law gives residents rights over their personal data and gives businesses duties. The rights are the ones you see in the customer's email: know what you hold, delete it, correct it, opt out of its sale or use for targeted advertising. The duties are a privacy notice that is true, contracts with the vendors who process the data, and a written risk review for the risky stuff.
A threshold is the test that decides whether a law applies to you. Most states use a consumer count, commonly 100,000 or 35,000 residents a year. Some add a revenue test. Texas uses the SBA size standards instead of a count. Connecticut, since 1 July 2026, drops the count entirely for any business that sells personal data or processes sensitive data.
Sensitive data is the category with the sharpest rules: health, precise location, biometrics, children's data, and details like race or religion. A skincare quiz that asks about eczema collects health data.
Sale is broader than cash. Handing customer data to an advertising platform so it can target better is a sale under most of these laws.
A data protection assessment is the written risk review, required before you start targeted advertising, selling data, or handling sensitive data.
The numbers that matter
Indiana, Kentucky and Rhode Island's comprehensive privacy laws took effect on 1 January 2026, and Rhode Island's applicability threshold is 35,000 consumers, according to the 2026 state statutes as tracked by MultiState. Three new sets of rights in one morning, for any brand that ships to those states.
Connecticut's amendment, in force since 1 July 2026 under SB 1295 passed in 2025, covers any business that sells personal data or processes sensitive data, with no consumer-count threshold. The advertising pixel on a checkout page is enough to pull a nine-person company in.
Texas's Data Privacy and Security Act, in force since 2024, covers any business operating in the state that is not a small business under SBA size standards, with no revenue floor. The question is not how many customers you have; it is which industry code you fall under and if the business has outgrown it.
What to do this week
- Count customers by state from the order system, for the last twelve months. Mark every state where you cross 35,000 or 100,000, and look up your SBA size standard for the Texas test. That list is your map of which laws apply. (CIS 3 Data Protection)
- Inventory the personal data: what you collect at checkout, in the quiz, in the newsletter signup, and where each field goes afterward, including the pixels and the email platform. Flag anything that counts as sensitive. (CIS 3 Data Protection)
- List every vendor that receives customer data, from the email tool to the ad platforms to the fulfillment warehouse, and check whether each contract says what they can do with it. Most state laws require those terms in writing. (CIS 15 Service Provider Management)
- Set up one mailbox for privacy requests and a log with the date received, what was asked, what you did, and the date you replied. Every state sets a response clock, and the log is your evidence that you met it. (CIS 8 Audit Log Management)
- Cut the sensitive data you do not need. If the quiz can recommend a product without storing the skin condition against the customer's name, change it so it does not. Consent is the fallback, deletion is the fix. (CIS 3 Data Protection)
- Write the data protection assessment for the targeted advertising you already run, update the privacy notice to match reality, and add the opt-out link. Then answer the customer's email, on time. (CIS 3 Data Protection)
Where AccuSights fits
Our assessment starts with the data map, not the statute: where personal data enters, where it lives, which vendors get it, and which state thresholds you have crossed. Our team then implements the controls at a reasonable rate, from data loss prevention that keeps the customer export out of personal inboxes to scanning and protection of the systems holding the data, so the privacy notice you publish describes something true. The Cyber Hygiene Test takes three minutes, and 15 minutes with an engineer will tell you which of the twenty you need to worry about.
Questions people ask
Does the California privacy law apply to out-of-state businesses? Yes, if you do business in California and meet its thresholds, which are based on annual revenue, the number of California consumers whose data you handle, or the share of revenue you earn from selling personal data. A Texas brand shipping to Los Angeles is doing business in California. Whether it crosses a threshold is a counting exercise, and the count changes every year you grow.
What is a data protection assessment? A written review of a specific kind of processing that the law considers risky: targeted advertising, selling personal data, profiling, or handling sensitive data. It records what you collect, why, what could go wrong for the consumer, and what you do to reduce that. Most state laws require one before you start the processing and let the attorney general ask for it, so it is a document you keep, not one you write when the letter arrives.
Do I need a Do Not Sell link? If you are covered by a state law and you sell personal data or use it for targeted advertising, you need a clear way for consumers to opt out, and several states name the link. The catch is the word sell. Sharing customer data with an advertising platform in exchange for better targeting counts as a sale under most of these laws, even though no invoice changes hands. If a pixel on your site feeds an ad network, assume you sell.
"Too small" is a threshold, and thresholds are numbers. Go find yours before a customer finds it for you.
Controls this post maps to
CIS Controls v8.1. These are the same controls our assessment scores and the console watches.
Sources
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
The 2027 Cybersecurity Calendar for US Small Business: The Dates That Are Real, and the One Everybody Is Guessing About
A US cybersecurity regulatory calendar for 2027: the confirmed dates from January to December, which ones apply to a 40-person company, and what to do first.
US complianceFTC Safeguards Rule: The CPA, the Car Dealer and the Tax Preparer Are All Financial Institutions Now
The FTC Safeguards Rule covers CPAs, dealers with in-house financing and tax preparers. What a WISP is, who the qualified individual is, and the 30-day notice.
US complianceSOC 2 for a 20-Person Company: Type 1, Type 2, the Cost, and When You Actually Need It
SOC 2 for small business, explained plainly: Type 1 vs Type 2, what drives the cost, who really needs a report, and how a founder loses a deal without one.
