Twenty U.S. states now have comprehensive consumer data privacy laws on the books. There is no federal equivalent. Congress has discussed one for years and hasn't passed one, and the current administration has shown no indication that federal privacy legislation is a near-term priority. The result is a patchwork: twenty different sets of rules, each with its own applicability thresholds, consumer rights, enforcement mechanisms, and cure periods, governing how businesses collect, process, and protect personal information.

Most small businesses have responded to this in one of two ways. Some assume they're too small to be covered. Others assume they need to comply with everything, panic, and either overspend on compliance tools or ignore the problem entirely because it feels unmanageable. Both responses are wrong, and for the same reason: neither starts with understanding what actually triggers compliance and what the realistic risk looks like at their scale.

Which States Have Laws, and Why It Matters Where Your Customers Are

The states with comprehensive privacy laws in effect as of mid-2026 include California, Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Tennessee, Oregon, Montana, Texas, Delaware, New Hampshire, New Jersey, Nebraska, Kentucky, Rhode Island, Maryland, Minnesota, and Oklahoma — with several more enacted and approaching effective dates. Each state's law applies based on where the consumer is, not where the business is. If you sell products or services to residents of a state with a privacy law, or if you process their personal data above certain thresholds, that state's law may apply to you regardless of where you're incorporated or physically located.

This is the detail that catches most small businesses off guard. A five-person company in Florida selling online to customers across the country may be subject to California's, Virginia's, and Texas's privacy laws simultaneously — not because the business is large, but because its customers are distributed across those states.

The Threshold Question

Not every state's law applies to every business. Most include applicability thresholds based on revenue, volume of consumer data processed, or both. Utah, for example, only applies to businesses with $25 million or more in annual revenue that also meet a consumer-data-volume threshold. California's threshold is $25 million in revenue, or processing data of 100,000 or more consumers annually, or deriving 50% or more of revenue from selling personal information.

Texas is the notable exception — and the one most likely to catch small businesses. The Texas Data Privacy and Security Act has no revenue threshold and no minimum consumer count for most provisions. If you do business in Texas, produce goods or services consumed by Texas residents, and are not classified as a small business under the SBA definition, you're likely covered. And Texas isn't just writing laws: the state attorney general has run dedicated enforcement sweeps targeting data privacy violations since 2024 — a level of proactive enforcement most states haven't attempted.

For small businesses that fall below most states' thresholds, the practical exposure comes from a different direction. Even if you're not subject to a comprehensive state privacy law, the FTC retains authority under Section 5 to pursue businesses that engage in unfair or deceptive practices related to consumer data — including making privacy promises you don't keep, failing to secure data you've collected, or sharing data in ways your privacy policy doesn't disclose.

What the Laws Actually Require

Despite their differences, the twenty state laws share a common core of obligations. Covered businesses must generally provide consumers with the right to know what personal data is being collected, the right to delete their data, the right to opt out of the sale of their data (where “sale” is defined broadly to include many data-sharing arrangements), and the right to correct inaccurate data. Many also require data protection assessments for certain high-risk processing activities.

From a practical standpoint, compliance starts with four things that most small businesses lack: a privacy policy that accurately describes what data you collect and what you do with it, a mechanism for consumers to exercise their rights (even a dedicated email address counts), an inventory of what personal data you actually collect and where it goes, and documentation showing that you've thought about these obligations rather than ignored them.

The Realistic Risk for Small Businesses

If you're a five-person company with modest web traffic and you sell physical products, you're unlikely to be the target of a state attorney general's privacy enforcement sweep. The realistic risk at that scale is narrower: a consumer who submits a data subject request that you can't fulfill because you have no process for it, a data breach that triggers notification obligations you didn't know existed, or an FTC inquiry prompted by a privacy policy that claims protections you don't actually provide.

The cost of addressing these risks is low relative to the cost of discovering them in a crisis. A real privacy policy, a monitored privacy email address, a basic inventory of what data you collect and who processes it, and a documented process for responding to consumer requests cover the realistic risk for most small businesses at a fraction of what panic compliance would cost.

What to Do Now

Check whether you meet the applicability threshold for any state where you have significant customers. If you do, you have specific obligations under that state's law and should review them — or have them reviewed — before your next fiscal quarter. If you don't, you still need a privacy policy that accurately describes your actual practices, a way for consumers to contact you about their data, and reasonable security for the data you hold.

The privacy landscape will continue to add states and tighten requirements. Building a defensible baseline now — not a perfect program, but an honest one — is cheaper and more durable than waiting until a specific regulation forces your hand.

This article is for educational purposes only and does not constitute legal, tax, or financial advice. Consult a qualified professional for guidance specific to your situation.