State Privacy Laws Beyond Texas for Businesses That Sell Nationwide
As of July 30, 2026, 20 state consumer privacy laws have taken effect, including Florida's narrower Digital Bill of Rights. Alabama, Louisiana, Oklahoma, and Vermont have enacted four more laws with future effective dates, bringing the enacted total to 24 under that counting method, and some trackers exclude Florida from the comprehensive category, so published counts disagree with each other more than with the underlying facts.
If your Texas business sells nationwide, you first need to determine which laws govern the data and then identify which law supplies the strictest requirement for each part of the privacy program. A sound coverage analysis prevents unnecessary implementation and identifies the states that require separate controls.
Coverage Comes First
You should test coverage before copying another company's privacy notice. Most comprehensive state laws use consumer volume, revenue from data sales, or both, while Connecticut can now cover a nonexempt person that processes even one Connecticut consumer's sensitive data or offers Connecticut consumers' personal data for sale.
Exemptions can change the result as much as thresholds. Entity exemptions and data exemptions for financial services, health care, nonprofits, higher education, employment data, business contact data, and information governed by federal law all require review, since a company may qualify for an exemption in one state while remaining covered elsewhere.
Your use of advertising pixels, loyalty programs, precise location tools, health inferences, age signals, artificial intelligence training, and vendor disclosures can trigger duties that a revenue-only analysis would miss entirely.
California
California often supplies the first national operating standard because it combines broad rights, detailed regulations, a dedicated privacy regulator, active enforcement, and a limited private claim for certain security breaches. A for-profit business may qualify through annual gross revenue, data volume, or revenue derived from selling or sharing personal information.
The adjusted revenue threshold has been $26,625,000 since January 1, 2025. Two other statutory tests cover businesses that annually buy, sell, or share personal information of at least 100,000 California consumers or households, or derive at least 50% of annual revenue from selling or sharing personal information, and Section 1798.140 states all three tests.
California treats sharing for cross-context behavioral advertising as a regulated transfer even when no money changes hands. A business that sells or shares personal information, or uses or discloses sensitive personal information beyond authorized purposes, must provide the applicable choice, and the homepage link statute permits either the prescribed links or compliance through an opt-out preference signal under its alternative method, so a blanket statement that every covered business requires every link goes too far.
Regulations effective January 1, 2026 added staggered compliance dates for risk assessments, cybersecurity audits, and automated decisionmaking technology. Covered risk assessment activity began on January 1, 2026, automated decisionmaking duties begin on January 1, 2027, and initial cybersecurity audit certifications run from April 1, 2028 through April 1, 2030 based on revenue, so the California Privacy Protection Agency's schedule should control the implementation calendar.
Connecticut
Connecticut became a low-threshold jurisdiction on July 1, 2026. The law now applies when a covered business processes personal data of at least 35,000 Connecticut consumers, processes sensitive data in any volume other than data handled solely to complete a payment transaction, or offers personal data for sale in any volume. The current applicability provision removes the former revenue-based alternative and leaves two triggers without a numerical floor.
The same amendments require collection that is reasonably necessary and proportionate to disclosed purposes, expand sensitive data, require consent before the sale of sensitive data, require privacy notice disclosure when personal data trains large language models, and impose impact assessments on covered processing created on or after August 1, 2026. Connecticut replaced its former general financial institution exemption with exemptions for specified regulated entities and data governed by Title V of the Gramm-Leach-Bliley Act. A financial business outside those entity exemptions may have marketing, website, or other data subject to the Connecticut statute when the federal data exemption doesn't apply.
Connecticut's youth rules apply to controllers that offer an online service, product, or feature to consumers they know or willfully disregard are minors. The amended law prohibits targeted advertising and personal data sales involving a minor's data. Specified profiling that produces legal or similarly significant effects follows a separate rule, which requires the processing to be reasonably necessary and requires the minor's consent, or parental consent for a child under 13.
Public Act 26-64 adds another round of requirements. The governor signed the act on May 27, 2026, introducing restrictions on the sale, sharing, transfer, or allowance of access to precise geolocation data and facial recognition requirements beginning October 1, 2026, followed by a data broker registration and deletion program beginning in 2027. Businesses using location data, loss prevention tools, or consumer profiling should review the enacted act before the first operative date.
Maryland
Maryland applies at 35,000 consumers, or at 10,000 consumers when more than 20% of gross revenue comes from personal data sales. Its coverage provision makes the state relevant to businesses that remain far below California's revenue threshold.
The Maryland Online Data Privacy Act took effect October 1, 2025, and its obligations generally cover processing that occurred on or after April 1, 2026, which is more precise than describing April 1 as the law's effective date. Maryland limits collection to data reasonably necessary and proportionate to provide or maintain a product or service requested by the consumer. Sensitive data receives a stricter rule, collection, processing, and sharing must be strictly necessary for that requested product or service, and consent can't authorize a sale of sensitive data, so businesses using health data, biometrics, precise location, or children's data should run a Maryland review even when another state permits the activity with consent.
A 2026 amendment, effective July 1, 2026, prohibits knowingly selling personal data to a federal, state, or local governmental unit that engaged in or supported civil immigration enforcement within the preceding six months, subject to a valid-warrant exception, and it expands sensitive data to include categories a controller infers from other personal data. Both changes deserve a contract and recipient review for data brokers and other companies that sell information to public agencies.
Colorado, Oregon, and Virginia
Colorado requires covered controllers to honor qualifying universal opt-out mechanisms for sales and targeted advertising. Global Privacy Control became mandatory there on July 1, 2024, the former mandatory cure period expired on January 1, 2025, and the state's business guidance explains both coverage and consumer rights.
Oregon requires universal opt-out recognition beginning January 1, 2026. It also defines sale to include monetary or other valuable consideration and prohibits sales of precise geolocation data and personal data of consumers under 16 when the controller has actual knowledge or willfully disregards the consumer's age, and the current Oregon statutes use a 1,750-foot radius for precise geolocation.
Virginia retains the familiar 100,000-consumer test and the 25,000-consumer-plus-50% data sale revenue test, its attorney general holds exclusive enforcement authority, and the law keeps a 30-day cure period without requiring recognition of a universal opt-out mechanism. Among the laws in force, it remains the template the others vary from.
Virginia added a separate location rule on July 1, 2026. Controllers may not sell or offer to sell precise geolocation data, so location analytics, advertising transfers, and data licenses deserve review under the current controller duties.
Delaware, New Hampshire, Rhode Island, and New Jersey
Lower thresholds bring these states into the analysis early. Delaware and Rhode Island apply at 35,000 consumers, or at 10,000 consumers when data sale revenue exceeds 20%, and New Hampshire uses 35,000 consumers, or 10,000 consumers with more than 25% of revenue from personal data sales.
Cure rights now depend on enforcement discretion in Delaware and New Hampshire. Delaware's mandatory 60-day opportunity ended on December 31, 2025, and its Department of Justice may consider statutory factors when deciding whether to offer one, while New Hampshire's mandatory period ended the same date, after which its attorney general may offer 60 days based on listed factors.
Rhode Island provides no statutory cure right. It also imposes a separate notice duty on commercial websites or internet service providers that collect, store, and sell personally identifiable information, while the broader controller duties apply at the law's numerical thresholds, and the Rhode Island enforcement provision assigns enforcement to the attorney general and rejects a private claim under the statute.
New Jersey requires a universal opt-out mechanism for covered sales and targeted advertising, and its temporary cure period expired on July 15, 2026, 18 months after the law took effect. A business that recognizes Global Privacy Control only for California, Colorado, Connecticut, Oregon, and Texas has omitted New Jersey.
Minnesota and the Other Laws in Force
Minnesota's law took effect July 31, 2025. Covered controllers must maintain a data inventory, the law gives consumers added rights involving profiling that produces legal or similarly significant effects, its general 30-day cure period expired January 31, 2026, and the enforcement statute authorizes civil penalties of up to $7,500 per violation.
A nationwide inventory also includes Iowa, Indiana, Kentucky, Montana, Nebraska, Tennessee, and Utah. Those laws may resemble the Virginia model, yet their thresholds, exemptions, cure provisions, and definitions differ, and omitting them from an applicability chart can produce a wrong coverage answer even when another state supplies the stricter operating rule.
For many sellers, these states won't require a new site design after the strongest controls are in place. The documentation should record whether each law applies and which exemption, threshold, or existing control resolves it.
Florida
Florida's Digital Bill of Rights uses a much narrower threshold. It generally applies to controllers with more than $1 billion in global gross annual revenue that also derive at least 50% of global revenue from online advertising, operate a qualifying smart speaker service, or operate an app store or digital distribution platform offering at least 250,000 applications, and the Florida scope provision states those business-model tests.
Most small and middle-market Texas companies won't qualify. Large advertising businesses, app distribution platforms, and smart device operators should run a separate Florida analysis because coverage depends on revenue and business model rather than consumer volume.
Washington Health Data
Washington's My Health My Data Act operates outside the comprehensive state law count. It covers consumer health data beyond HIPAA and can apply to websites, retailers, wellness services, fitness tools, supplement sellers, and other companies that collect data or inferences linked to physical or mental health.
Coverage turns on regulated activity rather than revenue. The statute provides small businesses with different compliance timing and defines regulated entities broadly, and its consumer health data definition includes information that identifies past, present, or future health status and inferences drawn from nonhealth data.
Violations qualify as unfair or deceptive acts under the Washington Consumer Protection Act. A consumer may bring a claim through that statute while remaining responsible for its private-claim elements, including injury to business or property and causation, so describing the law as an automatic privacy damages claim skips those requirements.
Four Enacted Laws With Future Dates
Oklahoma and Louisiana take effect January 1, 2027, Alabama follows on May 1, 2027, and Vermont takes effect January 1, 2028. The January 2027 effective dates leave about five months for product changes, contract amendments, and vendor coordination.
The enrolled Oklahoma act uses the familiar 100,000-consumer threshold or 25,000 consumers plus more than 50% of revenue from personal data sales. It provides a continuing 30-day cure process and authorizes penalties of up to $7,500 per violation after an uncured violation or breach of the required written statement.
Alabama provides a 45-day cure process and penalties of up to $15,000 per violation after a failure to correct, with a duty to honor opt-out preference signals beginning January 1, 2028. Vermont provides a temporary 60-day cure period through June 30, 2029, with civil penalties of up to $10,000 per violation. All four states belong on the implementation calendar now, because product work, contract amendments, and vendor changes often take longer than the statutory lead time suggests.
Build One Program With State Controls
You should build the program around recurring duties and maintain a decision table for the differences. The recurring duties include a data inventory, privacy notices, consumer request intake, identity verification, appeals, consent records, opt-out signals, risk assessments, retention rules, security controls, and processor contracts.
The inventory should identify each data category, source, purpose, recipient, retention period, governing system, and applicable sensitive classification. It should also show health inferences, precise location, minor data, advertising identifiers, and inputs used for automated decisions or model training.
The website can transmit opt-out choices to every relevant tag, software development kit, advertising partner, and downstream system. Testing can expose an implementation that fails on one platform while working on another. A complete Global Privacy Control test covers logged-in and logged-out sessions, mobile and desktop devices, and changes to the consent manager or tag manager.
Separate controls apply where state law diverges. Maryland requires strict necessity for sensitive data and prohibits its sale, Connecticut can apply at any volume of sensitive data or offered sale, Virginia and Oregon restrict precise location sales, and Washington requires its own health data analysis.
You should use a national baseline for vendor contracts. California's service provider and contractor rules, the state processor statutes, and product-specific data flows should align on instructions, permitted purposes, confidentiality, security, subcontractors, consumer requests, audits, incident response, deletion, and return.
Applicability deserves review after each legislative session and whenever the business changes its advertising stack, launches in a new state, adds a data-driven product, or acquires another company. The documentation should record why each law applies, which control satisfies it, who owns the control, and when someone last tested it.
Related practice area: Privacy Law
This article is general information about the law, not legal advice, and reading it does not create an attorney-client relationship. Laws change and how they apply depends on your specific facts. For advice on your situation, consult a qualified attorney.
Need advice tied to your business issue?
Share the issue. Get direct attorney review. Receive a concrete recommendation.
Submit an Inquiry