For years, "US privacy law" effectively meant California. That is no longer true. By 2026, roughly 20 states have enacted comprehensive consumer privacy laws, and new ones take effect almost every quarter. There is still no federal privacy statute to tie them together — so what businesses face instead is a growing patchwork of overlapping, similar-but-not-identical state regimes.
If you sell to US consumers, you are almost certainly in scope for more than one of these laws. Here is how the patchwork works and how to stay on top of it without building 20 separate compliance programmes.
How the Patchwork Grew
California started it with the CCPA, later strengthened by the CPRA. Virginia, Colorado, Connecticut, and Utah formed the next wave, each with its own model. Since then the list has expanded steadily — Texas, Oregon, Montana, Florida, Iowa, Delaware, New Jersey, New Hampshire, Nebraska, Tennessee, Minnesota, Maryland, and more — with effective dates spread across 2024, 2025, and 2026.
Because there is no federal law pre-empting them, each new statute adds another set of obligations rather than replacing the others. The trend is clearly toward more states, not consolidation.
What They Have in Common
The good news is that most of these laws rhyme. Build to the common core and you cover the bulk of your obligations everywhere:
- Consumer rights. Access, deletion, correction, and portability, plus the right to opt out of the "sale" of personal data and of targeted advertising.
- Sensitive data protections. Extra requirements — often opt-in consent — for sensitive categories like health, precise geolocation, and biometric data.
- Transparency. A detailed privacy notice describing what you collect, why, and who you share it with.
- Data processing agreements. Contracts required between controllers and their processors, echoing the structure GDPR made familiar.
- No general private right of action. Most of these laws are enforced by state attorneys general, not individual lawsuits — California's narrow data-breach provision being the main exception.
If your GDPR programme is mature, much of this will feel recognisable. The rights vocabulary and the controller/processor structure map closely — as our CCPA vs GDPR comparison sets out in detail.
Where They Diverge — and Where the Risk Lives
The danger of a patchwork is not the shared core; it is the edges, where the laws quietly differ:
- Thresholds. Each law applies based on revenue and/or the number of residents whose data you process. You can be in scope in one state and out in the neighbouring one.
- Response deadlines. Most give 45 days to respond to a consumer request, but extensions and specifics vary — and none of them match GDPR's one month. Treating them all as "about a month" is how deadlines get missed. Our DSAR deadline comparison by jurisdiction lays the differences out, and the DSAR Deadline Calculator works out an exact due date per request.
- Cure periods. Early laws gave businesses a window to fix violations before enforcement. Several of those cure periods are sunsetting, which raises the stakes for getting it right the first time.
- Sensitive data. Some states require opt-in consent before processing sensitive data; others let consumers opt out. The same data flow can be compliant in one state and not another.
- Universal opt-out signals. A number of states require businesses to honour browser-level opt-out signals — a technical obligation that is easy to overlook and increasingly enforced.
The edges are where enforcement actions come from, because they are where well-meaning businesses assume "we handle privacy" and stop checking.
How to Stay Compliant Without 20 Programmes
You do not need a separate programme per state. You need one strong baseline and a way to track the deltas:
- Build to the highest common standard. Design your rights-handling, notices, and consent flows to satisfy the strictest applicable state, then you are compliant nearly everywhere by default.
- Track scope by state. Maintain a simple record of which laws you are in scope for based on revenue and resident thresholds — and revisit it as you grow.
- Standardise request intake, vary the clock. Handle every consumer request through one process, but apply the correct per-state deadline. Do not average them.
- Honour opt-out signals technically. Make sure universal opt-out mechanisms actually work on your site, not just in your policy.
- Watch the calendar. New laws and expiring cure periods land every quarter. A recurring review keeps you from being surprised. Our roundup of the privacy laws set to impact business in 2026 is a starting point.
The Bottom Line
The US no longer has a single privacy law to point to — it has a widening patchwork of state regimes that share a core but diverge at the edges. The businesses that stay compliant are not the ones with 20 separate playbooks; they are the ones that built one strong baseline to the highest common standard and track the state-by-state differences that actually create risk — thresholds, deadlines, sensitive-data rules, and opt-out signals.
Start by knowing which laws you are in scope for, then standardise everything you can. To see how regulators treat privacy failures in practice, browse our enforcement monitor.




