US state consumer data privacy laws: applicability thresholds by state
For each US state with a comprehensive consumer data privacy law, the thresholds a business must meet for the law to apply: consumer volume (number of state residents whose data is processed), revenue from data sales (percentage of gross revenue derived from selling personal data), revenue floor (minimum annual revenue), and whether these conditions are combined with AND or OR logic — sourced from the state's own statute. Answers 'does [state]'s privacy law apply to my business', 'what are the CCPA thresholds for 2026', 'which state privacy laws have no revenue threshold', 'how many consumers triggers the Virginia privacy law', 'which states changed their privacy law thresholds in 2026' (Connecticut lowers from 100k to 35k consumers on July 1, 2026, and adds a sensitive-data trigger with no volume floor; Indiana, Kentucky, and Rhode Island took effect January 1, 2026), 'which state has the lowest privacy law threshold' (Montana: 25k consumers), and 'does Utah require both a revenue AND consumer threshold' (yes — the only state using AND logic). As of mid-2026, 20 states have comprehensive consumer privacy laws in effect. No single authority publishes the thresholds for all states — each state's statute defines its own — which is why assembled versions come from compliance-software vendors (Feroot, IAPP, MultiState, PrivacyLawMap). The thresholds spread is wide: consumer volume from 25k (Montana) to 175k (Tennessee); revenue percentage from 0% (Texas, no numeric threshold) to 50% (Virginia model); revenue floor from $0 to $26.6M (California, inflation-adjusted). The AND/OR distinction matters: most states use OR (any threshold triggers the law), while Utah requires both revenue AND consumer volume, and Connecticut (CA) requires meeting one of three distinct paths.
The data
| State | Law name and abbreviation | Effective date | Consumer volume threshold | Revenue-from-data-sales threshold | Revenue floor | Threshold combination logic | Key exemptions | Enforcement mechanism | Statute citation | Notes |
|---|---|---|---|---|---|---|---|---|---|---|
| California | California Consumer Privacy Act of 2018 / California Privacy Rights Act (CCPA/CPRA) | January 1, 2020 (CCPA); January 1, 2023 (CPRA amendments) | annually buys, sells, or shares the personal information of 100,000 or more consumers or households | Derives 50 percent or more of its annual revenues from selling or sharing consumers' personal information | annual gross revenues in excess of twenty-five million dollars ($25,000,000), as adjusted pursuant to subdivision (d) of Section 1798.199.95 | OR — satisfies one or more of the following thresholds | Nonprofits; government agencies; HIPAA-covered entities; GLBA-regulated financial institutions; FCRA consumer reporting agencies; entities complying with Driver's Privacy Protection Act | State Attorney General and California Privacy Protection Agency (CPPA); limited private right of action for data breaches under Cal. Civ. Code § 1798.150 | Cal. Civ. Code §§ 1798.100–1798.199.100 | California is the only state with a standalone revenue threshold (no consumer volume required). The $25M threshold is inflation-adjusted annually per subdivision (d) of Section 1798.199.95. Definition of 'sale' is broad: includes renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating personal information for monetary or other valuable consideration. CPRA added 'sharing' as a separate trigger covering cross-context behavioral advertising. |
| Colorado | Colorado Privacy Act (CPA) | July 1, 2023 | Controls or processes the personal data of one hundred thousand consumers or more during a calendar year | Derives revenue or receives a discount on the price of goods or services from the sale of personal data and processes or controls the personal data of twenty-five thousand consumers or more | OR — satisfies one or both of the following thresholds | State and local government entities; financial institutions subject to GLBA; HIPAA-covered entities and business associates; nonprofit organizations; institutions of higher education; air carriers | Attorney General and district attorneys; civil penalty of up to $20,000 per violation; no private right of action | C.R.S. §§ 6-1-1301 to 6-1-1313 | Colorado does not specify a minimum percentage of revenue from data sales — any revenue or discount from selling data combined with 25,000+ consumers triggers the law. As of October 1, 2025, the law also applies to any controller processing biometric identifiers or biometric data regardless of volume. | |
| Connecticut | Connecticut Data Privacy Act (CTDPA) | July 1, 2023 | Controlled or processed the personal data of not less than one hundred thousand consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction | controlled or processed the personal data of not less than twenty-five thousand consumers and derived more than twenty-five per cent of their gross revenue from the sale of personal data | OR — during the preceding calendar year met either threshold | State and local government bodies; HIPAA-covered entities and business associates; GLBA-regulated financial institutions; nonprofit organizations; institutions of higher education; data processed solely for payment transactions excluded from consumer count | Attorney General; cure period (expires December 31, 2024); civil penalty of up to $5,000 per violation under CUTPA; no private right of action | Conn. Gen. Stat. §§ 42-515 to 42-525 | Connecticut SB 1295 (effective July 1, 2026) will lower the consumer threshold from 100,000 to 35,000, add a sensitive-data trigger with no volume floor, and add a trigger for selling consumer data at any scale regardless of volume or revenue percentage. Connecticut originally set the data sales revenue threshold at 25% (vs Virginia's 50%), making it easier for mid-sized data businesses to fall into scope. | |
| Delaware | Delaware Personal Data Privacy Act (DPDPA) | January 1, 2025 | Controlled or processed the personal data of not less than 35,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction | Controlled or processed the personal data of not less than 10,000 consumers and derived more than 20% of their gross revenue from the sale of personal data | OR — during the preceding calendar year did any of the following | State and political subdivision bodies (excluding institutions of higher education); GLBA-regulated financial institutions; national securities associations; nonprofit organizations dedicated to preventing insurance crime | Attorney General (Department of Justice); 60-day cure period (expires December 31, 2025); no private right of action | Del. Code Ann. tit. 6, ch. 12D | Delaware has relatively low thresholds: 35,000 consumers (excl. payment data) or 10,000 consumers with 20% revenue from data sales. Unlike many states, Delaware does not broadly exempt all nonprofits — only nonprofits dedicated to preventing insurance crime are exempt. Institutions of higher education are NOT exempt. | |
| Florida | Florida Digital Bill of Rights (FDBR) | July 1, 2024 | Makes in excess of $1 billion in global gross annual revenues | AND — requires $1 billion+ in global gross annual revenues AND satisfies at least one additional criterion (50%+ revenue from online ads, operates a smart speaker with virtual assistant, or operates an app store with 250,000+ apps) | State agencies and political subdivisions; GLBA-regulated financial institutions; HIPAA-covered entities and business associates; nonprofit organizations; postsecondary education institutions | Department of Legal Affairs (Attorney General); civil penalties of $50,000 per violation or treble damages; no private right of action | Fla. Stat. §§ 501.701 to 501.721 | Florida has by far the highest revenue threshold of any state at $1 billion in global gross annual revenues, effectively limiting the law to large technology companies. Additionally, the business must satisfy at least one of three criteria: deriving 50%+ of global revenue from online advertising, operating a consumer smart speaker with a virtual assistant, or operating an app store with at least 250,000 apps. This narrow scope means the law applies to very few companies. | ||
| Iowa | Iowa Consumer Data Protection Act (ICDPA) | January 1, 2025 | Controls or processes personal data of at least one hundred thousand consumers | Controls or processes personal data of at least twenty-five thousand consumers and derives over fifty percent of gross revenue from the sale of personal data | OR — during a calendar year does either of the following | State and political subdivisions; GLBA-regulated financial institutions; HIPAA-covered entities and business associates; nonprofit organizations; institutions of higher education | Attorney General; 90-day cure period; no private right of action | Iowa Code ch. 715D | Iowa follows the Virginia model closely. Unique feature: 90-day cure period (the longest among state privacy laws). Iowa does not include a right to correction of inaccurate personal data. | |
| Kentucky | Kentucky Consumer Data Protection Act (KCDPA) | January 1, 2026 | One hundred thousand (100,000) consumers | Twenty-five thousand (25,000) consumers and derive over fifty percent (50%) of gross revenue from the sale of personal data | OR — control or process personal data of at least either threshold | City, state agency, or political subdivision; GLBA-regulated financial institutions; HIPAA-covered entities and business associates; nonprofit organizations; institutions of higher education; small telephone utilities and Tier III CMRS providers | Attorney General; 30-day cure period (non-expiring); no private right of action | KRS §§ 367.3611 to 367.3629 | Kentucky's 30-day cure period does not expire, making it one of the most business-friendly enforcement provisions. Kentucky follows the Virginia model closely. Small telephone utilities and municipal utilities that do not sell or share data are also exempt. | |
| Maryland | Maryland Online Data Privacy Act (MODPA) | October 1, 2025 | CONTROLLED OR PROCESSED THE PERSONAL DATA OF AT LEAST 35,000 CONSUMERS, EXCLUDING PERSONAL DATA CONTROLLED OR PROCESSED SOLELY FOR THE PURPOSE OF COMPLETING A PAYMENT TRANSACTION | CONTROLLED OR PROCESSED THE PERSONAL DATA OF AT LEAST 10,000 CONSUMERS AND DERIVED MORE THAN 20% OF ITS GROSS REVENUE FROM THE SALE OF PERSONAL DATA | OR — during the preceding calendar year met either threshold | State and local government bodies and instrumentalities; national securities associations; GLBA-regulated financial institutions and affiliates; nonprofit controllers assisting law enforcement with insurance crime or first responders with catastrophic events | Division of Consumer Protection (Attorney General); civil penalty; no private right of action | Md. Code Ann., Com. Law §§ 14-4601 to 14-4614 | Maryland bans the sale of sensitive data entirely (not just requiring consent). Maryland has relatively low thresholds (35,000/10,000 at 20%), matching Delaware and Rhode Island. Unlike many states, Maryland does not broadly exempt all nonprofits — only specific nonprofit controllers assisting law enforcement or first responders are exempt. | |
| Minnesota | Minnesota Consumer Data Privacy Act (MCDPA) | July 31, 2025 | during a calendar year, controls or processes personal data of 100,000 consumers or more, excluding personal data controlled or processed solely for the purpose of completing a payment transaction | derives over 25 percent of gross revenue from the sale of personal data and processes or controls personal data of 25,000 consumers or more | OR — satisfies one or more of the following thresholds | State and local government entities; HIPAA-covered entities; GLBA-regulated financial institutions; nonprofit organizations; institutions of higher education (postsecondary institutions regulated by the Office of Higher Education not required to comply until July 31, 2029) | Attorney General; no private right of action | Minn. Stat. §§ 325M.10 to 325M.21 | Minnesota uses a 25% revenue threshold (like Colorado and Oregon), lower than the 50% in Virginia-model states. Minnesota has stronger data minimization rules than most states. Postsecondary institutions regulated by the Office of Higher Education have a delayed compliance date of July 31, 2029. | |
| Montana | Montana Consumer Data Privacy Act (MCDPA) | October 1, 2024 | control or process the personal data of not less than 25,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction | control or process the personal data of not less than 15,000 consumers and derive more than 25% of gross revenue from the sale of personal data | OR — applies to persons that conduct business in this state and meet either threshold | Government bodies; HIPAA-covered entities; GLBA-regulated financial institutions; nonprofit organizations; institutions of higher education | Attorney General; 60-day cure period; no private right of action | Mont. Code Ann. §§ 30-14-2801 to 30-14-2817 | Montana has the lowest consumer threshold in the country at 25,000 consumers, and the lowest data-sales threshold at 15,000 consumers with 25% revenue. Montana's small population (approximately 1.1 million) means these thresholds capture a proportionally larger share of businesses operating in the state. | |
| Nebraska | Nebraska Data Privacy Act (NDPA) | January 1, 2025 | No numeric consumer or revenue thresholds — applies to any non-small-business that processes or sells personal data | Small businesses as determined under the federal Small Business Act; state agencies and political subdivisions; GLBA-regulated financial institutions; HIPAA-covered entities and business associates; nonprofit organizations; institutions of higher education; electric suppliers; natural gas public utilities | Attorney General; 30-day cure period; civil penalty up to $7,500 per violation; no private right of action | Neb. Rev. Stat. §§ 87-1101 to 87-1118 | Nebraska follows the Texas model rather than the Virginia model, using the federal Small Business Act to determine applicability rather than fixed numeric thresholds. Nebraska is the only other state besides Texas to take this approach. | |||
| New Jersey | New Jersey Data Privacy Act (NJDPA) | January 15, 2025 | control or process the personal data of at least 100,000 consumers, excluding personal data processed solely for the purpose of completing a payment transaction | control or process the personal data of at least 25,000 consumers and the controller derives revenue, or receives a discount on the price of any goods or services, from the sale of personal data | OR — during a calendar year either threshold is met | HIPAA-covered entities and business associates; GLBA-regulated financial institutions and affiliates; secondary market institutions; insurance institutions; NJ Motor Vehicle Commission data sales under DPPA | Attorney General (Division of Consumer Affairs); violations treated as unlawful practices under the Consumer Fraud Act; no private right of action for data privacy violations specifically | N.J. Stat. Ann. § 56:8-166.1 et seq. | New Jersey is notable for not exempting nonprofit organizations — one of the few states where nonprofits must comply. Like Colorado, NJ does not specify a minimum percentage of revenue from data sales — any revenue or discount from selling data combined with 25,000+ consumers triggers the law. | |
| Oregon | Oregon Consumer Privacy Act (OCPA) | July 1, 2024 | The personal data of 100,000 or more consumers, other than personal data controlled or processed solely for the purpose of completing a payment transaction | The personal data of 25,000 or more consumers, while deriving 25 percent or more of the person's annual gross revenue from selling personal data | OR — during a calendar year, controls or processes either threshold | Public corporations and public bodies; HIPAA-covered entities; nonprofit organizations (exempt until July 1, 2025) | Attorney General; exclusive authority; civil penalty; no private right of action | Or. Rev. Stat. §§ 646A.570 to 646A.589 | Oregon does not exclude payment-only data processing from the data-sales threshold — only from the volume threshold. As of the 2025 amendments, the law also applies to motor vehicle manufacturers regardless of consumer volume thresholds. Oregon had the latest nonprofit exemption expiration (July 1, 2025) and includes a universal opt-out mechanism requirement effective January 1, 2026. | |
| Rhode Island | Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) | January 1, 2026 | Controlled or processed the personal data of not less than thirty-five thousand (35,000) customers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction | Controlled or processed the personal data of not less than ten thousand (10,000) customers and derived more than twenty percent (20%) of their gross revenue from the sale of personal data | OR — during the preceding calendar year did any of the following | State and political subdivision bodies; nonprofit organizations; institutions of higher education; GLBA-regulated financial institutions; HIPAA-covered entities and business associates; national securities associations | Attorney General; no private right of action | R.I. Gen. Laws §§ 6-48.1-1 to 6-48.1-14 | Rhode Island uses the term 'customer' rather than 'consumer.' The thresholds (35,000 customers or 10,000 + 20% revenue) are identical to Delaware's and among the lowest in the country. The law applies only to for-profit entities. | |
| Tennessee | Tennessee Information Protection Act (TIPA) | July 1, 2025 | During a calendar year, control or process personal information of at least one hundred seventy-five thousand (175,000) consumers | Control or process personal information of at least twenty-five thousand (25,000) consumers and derive more than fifty percent (50%) of gross revenue from the sale of personal information | Exceed twenty-five million dollars ($25,000,000) in revenue | AND — requires exceeding $25,000,000 in revenue AND one of the volume thresholds | State and local government entities; HIPAA-covered entities and business associates; GLBA-regulated financial institutions; nonprofit organizations; institutions of higher education | Attorney General; 60-day cure period; no private right of action | Tenn. Code Ann. § 47-18-3201 et seq. | Tennessee has the highest consumer volume threshold (175,000) of any state and requires both a $25M revenue floor AND volume thresholds (like Utah). This makes Tennessee's law one of the narrowest in scope. Tennessee uses the term 'personal information' rather than 'personal data.' |
| Texas | Texas Data Privacy and Security Act (TDPSA) | July 1, 2024 | No numeric consumer or revenue thresholds — applies to any non-small-business that processes or sells personal data | Small businesses as defined by the United States Small Business Administration; state agencies and political subdivisions; GLBA-regulated financial institutions; HIPAA-covered entities and business associates; nonprofit organizations; institutions of higher education | Attorney General; 30-day cure period; civil penalty up to $7,500 per violation; no private right of action | Tex. Bus. & Com. Code ch. 541 | Texas is unique among state privacy laws in having no specific numeric consumer or revenue thresholds. Instead, it exempts small businesses as defined by the U.S. Small Business Administration. This means the SBA size standards (which vary by industry) determine applicability rather than a fixed consumer count. | |||
| Utah | Utah Consumer Privacy Act (UCPA) | December 31, 2023 | during a calendar year, controls or processes personal data of 100,000 or more consumers | derives over 50% of the entity's gross revenue from the sale of personal data and controls or processes personal data of 25,000 or more consumers | has annual revenue of $25,000,000 or more | AND — requires annual revenue of $25,000,000 or more AND one of the volume thresholds | Governmental entities; tribes; institutions of higher education; nonprofit corporations; HIPAA-covered entities and business associates | Attorney General; 30-day cure period; no private right of action | Utah Code §§ 13-61-101 to 13-61-404 | Utah is the only state that requires BOTH a revenue threshold AND consumer volume — using AND logic rather than OR. A business must have $25M+ in annual revenue and also meet one of the two volume thresholds. This makes Utah's law the narrowest in scope among all state privacy laws. |
| Virginia | Virginia Consumer Data Protection Act (VCDPA) | January 1, 2023 | control or process personal data of at least 100,000 consumers | control or process personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal data | OR — applies to persons that (i) during a calendar year, control or process personal data of at least 100,000 consumers or (ii) control or process personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal data | State and local government bodies; financial institutions or data subject to GLBA; HIPAA-covered entities and business associates; nonprofit organizations; institutions of higher education; employment data and emergency contact information | Attorney General has exclusive authority to enforce; 30-day cure period; civil penalties up to $7,500 per violation; no private right of action | Va. Code Ann. §§ 59.1-575 to 59.1-585 | Virginia's law set the template for many subsequent state privacy laws (the 'Virginia model'). No independent revenue threshold — a business with over $150 million in annual revenue is not in scope unless it also meets the consumer volume thresholds. B2B contacts and employees are excluded from consumer counts per the exemption in § 59.1-576(C)(14). |
Where this came from
Every record above links the page it was taken from and quotes the sentence that states it. These are the 18 sources this dataset was assembled from.
- leginfo.legislature.ca.govhttps://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?sectionNum=1798.140.&lawCode=CIV
- leg.colorado.govhttps://leg.colorado.gov/sites/default/files/images/olls/crs2024-title-06.pdf
- cga.ct.govhttps://web.archive.org/web/2024/https://www.cga.ct.gov/current/pub/chap_743jj.htm
- delcode.delaware.govhttps://delcode.delaware.gov/title6/c012d/index.html
- leg.state.fl.ushttps://www.leg.state.fl.us/statutes/index.cfm?App_mode=Display_Statute&Search_String=&URL=0500-0599/0501/Sections/0501.702.html
- legis.iowa.govhttps://www.legis.iowa.gov/docs/code/715D.pdf
- apps.legislature.ky.govhttps://apps.legislature.ky.gov/law/statutes/statute.aspx?id=56648
- mgaleg.maryland.govhttps://mgaleg.maryland.gov/2024RS/chapters_noln/Ch_455_sb0541E.pdf
- revisor.mn.govhttps://www.revisor.mn.gov/statutes/cite/325M/full
- leg.mt.govhttps://leg.mt.gov/bills/mca/title_0300/chapter_0140/part_0280/section_0030/0300-0140-0280-0030.html
- nebraskalegislature.govhttps://nebraskalegislature.gov/laws/statutes.php?statute=87-1103
- pub.njleg.state.nj.ushttps://pub.njleg.state.nj.us/Bills/2022/S0500/332_R5.PDF
- oregonlegislature.govhttps://www.oregonlegislature.gov/bills_laws/ors/ors646a.html
- webserver.rilegislature.govhttps://webserver.rilegislature.gov/Statutes/TITLE6/6-48.1/6-48.1-4.htm
- publications.tnsosfiles.comhttps://publications.tnsosfiles.com/acts/113/pub/pc0408.pdf
- capitol.texas.govhttps://capitol.texas.gov/tlodocs/88R/billtext/pdf/HB00004F.pdf
- le.utah.govhttps://le.utah.gov/xcode/Title13/Chapter61/C13-61_2022050420231231.pdf
- law.lis.virginia.govhttps://law.lis.virginia.gov/vacodefull/title59.1/chapter53/
Machine-readable
- data.jsonThe whole dataset — every record with its source URL and source quote.
- Open Knowledge Format bundleOne JSON object per line — every record's frontmatter and quoted span exactly as it is held here, in one fetch.
- changes.xmlAtom feed of what changed and when — poll this instead of re-fetching the dataset. Also as changes.json.
- What changedThe same change history as a readable page — each date, what moved, and the records' current state.
- How this is made and checkedWhat "verified against source" does and does not mean.