Reference Source

US state consumer data privacy laws: applicability thresholds by state

For each US state with a comprehensive consumer data privacy law, the thresholds a business must meet for the law to apply: consumer volume (number of state residents whose data is processed), revenue from data sales (percentage of gross revenue derived from selling personal data), revenue floor (minimum annual revenue), and whether these conditions are combined with AND or OR logic — sourced from the state's own statute. Answers 'does [state]'s privacy law apply to my business', 'what are the CCPA thresholds for 2026', 'which state privacy laws have no revenue threshold', 'how many consumers triggers the Virginia privacy law', 'which states changed their privacy law thresholds in 2026' (Connecticut lowers from 100k to 35k consumers on July 1, 2026, and adds a sensitive-data trigger with no volume floor; Indiana, Kentucky, and Rhode Island took effect January 1, 2026), 'which state has the lowest privacy law threshold' (Montana: 25k consumers), and 'does Utah require both a revenue AND consumer threshold' (yes — the only state using AND logic). As of mid-2026, 20 states have comprehensive consumer privacy laws in effect. No single authority publishes the thresholds for all states — each state's statute defines its own — which is why assembled versions come from compliance-software vendors (Feroot, IAPP, MultiState, PrivacyLawMap). The thresholds spread is wide: consumer volume from 25k (Montana) to 175k (Tennessee); revenue percentage from 0% (Texas, no numeric threshold) to 50% (Virginia model); revenue floor from $0 to $26.6M (California, inflation-adjusted). The AND/OR distinction matters: most states use OR (any threshold triggers the law), while Utah requires both revenue AND consumer volume, and Connecticut (CA) requires meeting one of three distinct paths.

Records18
Sources18
Verified
Review by
LicenceFacts and short attributed quotes taken from each state's own statute, linking back to the official code. Facts are not copyrightable (Feist, 1991); no source statute is reproduced wholesale.

The data

StateLaw name and abbreviationEffective dateConsumer volume thresholdRevenue-from-data-sales thresholdRevenue floorThreshold combination logicKey exemptionsEnforcement mechanismStatute citationNotes
CaliforniaCalifornia Consumer Privacy Act of 2018 / California Privacy Rights Act (CCPA/CPRA)January 1, 2020 (CCPA); January 1, 2023 (CPRA amendments)annually buys, sells, or shares the personal information of 100,000 or more consumers or householdsDerives 50 percent or more of its annual revenues from selling or sharing consumers' personal informationannual gross revenues in excess of twenty-five million dollars ($25,000,000), as adjusted pursuant to subdivision (d) of Section 1798.199.95OR — satisfies one or more of the following thresholdsNonprofits; government agencies; HIPAA-covered entities; GLBA-regulated financial institutions; FCRA consumer reporting agencies; entities complying with Driver's Privacy Protection ActState Attorney General and California Privacy Protection Agency (CPPA); limited private right of action for data breaches under Cal. Civ. Code § 1798.150Cal. Civ. Code §§ 1798.100–1798.199.100California is the only state with a standalone revenue threshold (no consumer volume required). The $25M threshold is inflation-adjusted annually per subdivision (d) of Section 1798.199.95. Definition of 'sale' is broad: includes renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating personal information for monetary or other valuable consideration. CPRA added 'sharing' as a separate trigger covering cross-context behavioral advertising.
ColoradoColorado Privacy Act (CPA)July 1, 2023Controls or processes the personal data of one hundred thousand consumers or more during a calendar yearDerives revenue or receives a discount on the price of goods or services from the sale of personal data and processes or controls the personal data of twenty-five thousand consumers or moreOR — satisfies one or both of the following thresholdsState and local government entities; financial institutions subject to GLBA; HIPAA-covered entities and business associates; nonprofit organizations; institutions of higher education; air carriersAttorney General and district attorneys; civil penalty of up to $20,000 per violation; no private right of actionC.R.S. §§ 6-1-1301 to 6-1-1313Colorado does not specify a minimum percentage of revenue from data sales — any revenue or discount from selling data combined with 25,000+ consumers triggers the law. As of October 1, 2025, the law also applies to any controller processing biometric identifiers or biometric data regardless of volume.
ConnecticutConnecticut Data Privacy Act (CTDPA)July 1, 2023Controlled or processed the personal data of not less than one hundred thousand consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transactioncontrolled or processed the personal data of not less than twenty-five thousand consumers and derived more than twenty-five per cent of their gross revenue from the sale of personal dataOR — during the preceding calendar year met either thresholdState and local government bodies; HIPAA-covered entities and business associates; GLBA-regulated financial institutions; nonprofit organizations; institutions of higher education; data processed solely for payment transactions excluded from consumer countAttorney General; cure period (expires December 31, 2024); civil penalty of up to $5,000 per violation under CUTPA; no private right of actionConn. Gen. Stat. §§ 42-515 to 42-525Connecticut SB 1295 (effective July 1, 2026) will lower the consumer threshold from 100,000 to 35,000, add a sensitive-data trigger with no volume floor, and add a trigger for selling consumer data at any scale regardless of volume or revenue percentage. Connecticut originally set the data sales revenue threshold at 25% (vs Virginia's 50%), making it easier for mid-sized data businesses to fall into scope.
DelawareDelaware Personal Data Privacy Act (DPDPA)January 1, 2025Controlled or processed the personal data of not less than 35,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transactionControlled or processed the personal data of not less than 10,000 consumers and derived more than 20% of their gross revenue from the sale of personal dataOR — during the preceding calendar year did any of the followingState and political subdivision bodies (excluding institutions of higher education); GLBA-regulated financial institutions; national securities associations; nonprofit organizations dedicated to preventing insurance crimeAttorney General (Department of Justice); 60-day cure period (expires December 31, 2025); no private right of actionDel. Code Ann. tit. 6, ch. 12DDelaware has relatively low thresholds: 35,000 consumers (excl. payment data) or 10,000 consumers with 20% revenue from data sales. Unlike many states, Delaware does not broadly exempt all nonprofits — only nonprofits dedicated to preventing insurance crime are exempt. Institutions of higher education are NOT exempt.
FloridaFlorida Digital Bill of Rights (FDBR)July 1, 2024Makes in excess of $1 billion in global gross annual revenuesAND — requires $1 billion+ in global gross annual revenues AND satisfies at least one additional criterion (50%+ revenue from online ads, operates a smart speaker with virtual assistant, or operates an app store with 250,000+ apps)State agencies and political subdivisions; GLBA-regulated financial institutions; HIPAA-covered entities and business associates; nonprofit organizations; postsecondary education institutionsDepartment of Legal Affairs (Attorney General); civil penalties of $50,000 per violation or treble damages; no private right of actionFla. Stat. §§ 501.701 to 501.721Florida has by far the highest revenue threshold of any state at $1 billion in global gross annual revenues, effectively limiting the law to large technology companies. Additionally, the business must satisfy at least one of three criteria: deriving 50%+ of global revenue from online advertising, operating a consumer smart speaker with a virtual assistant, or operating an app store with at least 250,000 apps. This narrow scope means the law applies to very few companies.
IowaIowa Consumer Data Protection Act (ICDPA)January 1, 2025Controls or processes personal data of at least one hundred thousand consumersControls or processes personal data of at least twenty-five thousand consumers and derives over fifty percent of gross revenue from the sale of personal dataOR — during a calendar year does either of the followingState and political subdivisions; GLBA-regulated financial institutions; HIPAA-covered entities and business associates; nonprofit organizations; institutions of higher educationAttorney General; 90-day cure period; no private right of actionIowa Code ch. 715DIowa follows the Virginia model closely. Unique feature: 90-day cure period (the longest among state privacy laws). Iowa does not include a right to correction of inaccurate personal data.
KentuckyKentucky Consumer Data Protection Act (KCDPA)January 1, 2026One hundred thousand (100,000) consumersTwenty-five thousand (25,000) consumers and derive over fifty percent (50%) of gross revenue from the sale of personal dataOR — control or process personal data of at least either thresholdCity, state agency, or political subdivision; GLBA-regulated financial institutions; HIPAA-covered entities and business associates; nonprofit organizations; institutions of higher education; small telephone utilities and Tier III CMRS providersAttorney General; 30-day cure period (non-expiring); no private right of actionKRS §§ 367.3611 to 367.3629Kentucky's 30-day cure period does not expire, making it one of the most business-friendly enforcement provisions. Kentucky follows the Virginia model closely. Small telephone utilities and municipal utilities that do not sell or share data are also exempt.
MarylandMaryland Online Data Privacy Act (MODPA)October 1, 2025CONTROLLED OR PROCESSED THE PERSONAL DATA OF AT LEAST 35,000 CONSUMERS, EXCLUDING PERSONAL DATA CONTROLLED OR PROCESSED SOLELY FOR THE PURPOSE OF COMPLETING A PAYMENT TRANSACTIONCONTROLLED OR PROCESSED THE PERSONAL DATA OF AT LEAST 10,000 CONSUMERS AND DERIVED MORE THAN 20% OF ITS GROSS REVENUE FROM THE SALE OF PERSONAL DATAOR — during the preceding calendar year met either thresholdState and local government bodies and instrumentalities; national securities associations; GLBA-regulated financial institutions and affiliates; nonprofit controllers assisting law enforcement with insurance crime or first responders with catastrophic eventsDivision of Consumer Protection (Attorney General); civil penalty; no private right of actionMd. Code Ann., Com. Law §§ 14-4601 to 14-4614Maryland bans the sale of sensitive data entirely (not just requiring consent). Maryland has relatively low thresholds (35,000/10,000 at 20%), matching Delaware and Rhode Island. Unlike many states, Maryland does not broadly exempt all nonprofits — only specific nonprofit controllers assisting law enforcement or first responders are exempt.
MinnesotaMinnesota Consumer Data Privacy Act (MCDPA)July 31, 2025during a calendar year, controls or processes personal data of 100,000 consumers or more, excluding personal data controlled or processed solely for the purpose of completing a payment transactionderives over 25 percent of gross revenue from the sale of personal data and processes or controls personal data of 25,000 consumers or moreOR — satisfies one or more of the following thresholdsState and local government entities; HIPAA-covered entities; GLBA-regulated financial institutions; nonprofit organizations; institutions of higher education (postsecondary institutions regulated by the Office of Higher Education not required to comply until July 31, 2029)Attorney General; no private right of actionMinn. Stat. §§ 325M.10 to 325M.21Minnesota uses a 25% revenue threshold (like Colorado and Oregon), lower than the 50% in Virginia-model states. Minnesota has stronger data minimization rules than most states. Postsecondary institutions regulated by the Office of Higher Education have a delayed compliance date of July 31, 2029.
MontanaMontana Consumer Data Privacy Act (MCDPA)October 1, 2024control or process the personal data of not less than 25,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transactioncontrol or process the personal data of not less than 15,000 consumers and derive more than 25% of gross revenue from the sale of personal dataOR — applies to persons that conduct business in this state and meet either thresholdGovernment bodies; HIPAA-covered entities; GLBA-regulated financial institutions; nonprofit organizations; institutions of higher educationAttorney General; 60-day cure period; no private right of actionMont. Code Ann. §§ 30-14-2801 to 30-14-2817Montana has the lowest consumer threshold in the country at 25,000 consumers, and the lowest data-sales threshold at 15,000 consumers with 25% revenue. Montana's small population (approximately 1.1 million) means these thresholds capture a proportionally larger share of businesses operating in the state.
NebraskaNebraska Data Privacy Act (NDPA)January 1, 2025No numeric consumer or revenue thresholds — applies to any non-small-business that processes or sells personal dataSmall businesses as determined under the federal Small Business Act; state agencies and political subdivisions; GLBA-regulated financial institutions; HIPAA-covered entities and business associates; nonprofit organizations; institutions of higher education; electric suppliers; natural gas public utilitiesAttorney General; 30-day cure period; civil penalty up to $7,500 per violation; no private right of actionNeb. Rev. Stat. §§ 87-1101 to 87-1118Nebraska follows the Texas model rather than the Virginia model, using the federal Small Business Act to determine applicability rather than fixed numeric thresholds. Nebraska is the only other state besides Texas to take this approach.
New JerseyNew Jersey Data Privacy Act (NJDPA)January 15, 2025control or process the personal data of at least 100,000 consumers, excluding personal data processed solely for the purpose of completing a payment transactioncontrol or process the personal data of at least 25,000 consumers and the controller derives revenue, or receives a discount on the price of any goods or services, from the sale of personal dataOR — during a calendar year either threshold is metHIPAA-covered entities and business associates; GLBA-regulated financial institutions and affiliates; secondary market institutions; insurance institutions; NJ Motor Vehicle Commission data sales under DPPAAttorney General (Division of Consumer Affairs); violations treated as unlawful practices under the Consumer Fraud Act; no private right of action for data privacy violations specificallyN.J. Stat. Ann. § 56:8-166.1 et seq.New Jersey is notable for not exempting nonprofit organizations — one of the few states where nonprofits must comply. Like Colorado, NJ does not specify a minimum percentage of revenue from data sales — any revenue or discount from selling data combined with 25,000+ consumers triggers the law.
OregonOregon Consumer Privacy Act (OCPA)July 1, 2024The personal data of 100,000 or more consumers, other than personal data controlled or processed solely for the purpose of completing a payment transactionThe personal data of 25,000 or more consumers, while deriving 25 percent or more of the person's annual gross revenue from selling personal dataOR — during a calendar year, controls or processes either thresholdPublic corporations and public bodies; HIPAA-covered entities; nonprofit organizations (exempt until July 1, 2025)Attorney General; exclusive authority; civil penalty; no private right of actionOr. Rev. Stat. §§ 646A.570 to 646A.589Oregon does not exclude payment-only data processing from the data-sales threshold — only from the volume threshold. As of the 2025 amendments, the law also applies to motor vehicle manufacturers regardless of consumer volume thresholds. Oregon had the latest nonprofit exemption expiration (July 1, 2025) and includes a universal opt-out mechanism requirement effective January 1, 2026.
Rhode IslandRhode Island Data Transparency and Privacy Protection Act (RIDTPPA)January 1, 2026Controlled or processed the personal data of not less than thirty-five thousand (35,000) customers, excluding personal data controlled or processed solely for the purpose of completing a payment transactionControlled or processed the personal data of not less than ten thousand (10,000) customers and derived more than twenty percent (20%) of their gross revenue from the sale of personal dataOR — during the preceding calendar year did any of the followingState and political subdivision bodies; nonprofit organizations; institutions of higher education; GLBA-regulated financial institutions; HIPAA-covered entities and business associates; national securities associationsAttorney General; no private right of actionR.I. Gen. Laws §§ 6-48.1-1 to 6-48.1-14Rhode Island uses the term 'customer' rather than 'consumer.' The thresholds (35,000 customers or 10,000 + 20% revenue) are identical to Delaware's and among the lowest in the country. The law applies only to for-profit entities.
TennesseeTennessee Information Protection Act (TIPA)July 1, 2025During a calendar year, control or process personal information of at least one hundred seventy-five thousand (175,000) consumersControl or process personal information of at least twenty-five thousand (25,000) consumers and derive more than fifty percent (50%) of gross revenue from the sale of personal informationExceed twenty-five million dollars ($25,000,000) in revenueAND — requires exceeding $25,000,000 in revenue AND one of the volume thresholdsState and local government entities; HIPAA-covered entities and business associates; GLBA-regulated financial institutions; nonprofit organizations; institutions of higher educationAttorney General; 60-day cure period; no private right of actionTenn. Code Ann. § 47-18-3201 et seq.Tennessee has the highest consumer volume threshold (175,000) of any state and requires both a $25M revenue floor AND volume thresholds (like Utah). This makes Tennessee's law one of the narrowest in scope. Tennessee uses the term 'personal information' rather than 'personal data.'
TexasTexas Data Privacy and Security Act (TDPSA)July 1, 2024No numeric consumer or revenue thresholds — applies to any non-small-business that processes or sells personal dataSmall businesses as defined by the United States Small Business Administration; state agencies and political subdivisions; GLBA-regulated financial institutions; HIPAA-covered entities and business associates; nonprofit organizations; institutions of higher educationAttorney General; 30-day cure period; civil penalty up to $7,500 per violation; no private right of actionTex. Bus. & Com. Code ch. 541Texas is unique among state privacy laws in having no specific numeric consumer or revenue thresholds. Instead, it exempts small businesses as defined by the U.S. Small Business Administration. This means the SBA size standards (which vary by industry) determine applicability rather than a fixed consumer count.
UtahUtah Consumer Privacy Act (UCPA)December 31, 2023during a calendar year, controls or processes personal data of 100,000 or more consumersderives over 50% of the entity's gross revenue from the sale of personal data and controls or processes personal data of 25,000 or more consumershas annual revenue of $25,000,000 or moreAND — requires annual revenue of $25,000,000 or more AND one of the volume thresholdsGovernmental entities; tribes; institutions of higher education; nonprofit corporations; HIPAA-covered entities and business associatesAttorney General; 30-day cure period; no private right of actionUtah Code §§ 13-61-101 to 13-61-404Utah is the only state that requires BOTH a revenue threshold AND consumer volume — using AND logic rather than OR. A business must have $25M+ in annual revenue and also meet one of the two volume thresholds. This makes Utah's law the narrowest in scope among all state privacy laws.
VirginiaVirginia Consumer Data Protection Act (VCDPA)January 1, 2023control or process personal data of at least 100,000 consumerscontrol or process personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal dataOR — applies to persons that (i) during a calendar year, control or process personal data of at least 100,000 consumers or (ii) control or process personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal dataState and local government bodies; financial institutions or data subject to GLBA; HIPAA-covered entities and business associates; nonprofit organizations; institutions of higher education; employment data and emergency contact informationAttorney General has exclusive authority to enforce; 30-day cure period; civil penalties up to $7,500 per violation; no private right of actionVa. Code Ann. §§ 59.1-575 to 59.1-585Virginia's law set the template for many subsequent state privacy laws (the 'Virginia model'). No independent revenue threshold — a business with over $150 million in annual revenue is not in scope unless it also meets the consumer volume thresholds. B2B contacts and employees are excluded from consumer counts per the exemption in § 59.1-576(C)(14).

Where this came from

Every record above links the page it was taken from and quotes the sentence that states it. These are the 18 sources this dataset was assembled from.

Machine-readable

18 records. last verified against source . due for re-check by .

Licence. Facts and short attributed quotes taken from each state's own statute, linking back to the official code. Facts are not copyrightable (Feist, 1991); no source statute is reproduced wholesale.