{"asset": "state-data-privacy-applicability-thresholds", "asset_type": "applicability-threshold", "body": "For each US state with a comprehensive consumer data privacy law, the thresholds a business must meet for the law to apply: consumer volume (number of state residents whose data is processed), revenue from data sales (percentage of gross revenue derived from selling personal data), revenue floor (minimum annual revenue), and whether these conditions are combined with AND or OR logic \u2014 sourced from the state's own statute. Answers 'does [state]'s privacy law apply to my business', 'what are the CCPA thresholds for 2026', 'which state privacy laws have no revenue threshold', 'how many consumers triggers the Virginia privacy law', 'which states changed their privacy law thresholds in 2026' (Connecticut lowers from 100k to 35k consumers on July 1, 2026, and adds a sensitive-data trigger with no volume floor; Indiana, Kentucky, and Rhode Island took effect January 1, 2026), 'which state has the lowest privacy law threshold' (Montana: 25k consumers), and 'does Utah require both a revenue AND consumer threshold' (yes \u2014 the only state using AND logic). As of mid-2026, 20 states have comprehensive consumer privacy laws in effect. No single authority publishes the thresholds for all states \u2014 each state's statute defines its own \u2014 which is why assembled versions come from compliance-software vendors (Feroot, IAPP, MultiState, PrivacyLawMap). The thresholds spread is wide: consumer volume from 25k (Montana) to 175k (Tennessee); revenue percentage from 0% (Texas, no numeric threshold) to 50% (Virginia model); revenue floor from $0 to $26.6M (California, inflation-adjusted). The AND/OR distinction matters: most states use OR (any threshold triggers the law), while Utah requires both revenue AND consumer volume, and Connecticut (CA) requires meeting one of three distinct paths.\n", "description": "For each US state with a comprehensive consumer data privacy law, the thresholds a business must meet for the law to apply: consumer volume (number of state residents whose data is processed), revenue from data sales (percentage of gross revenue derived from selling personal data), revenue floor (minimum annual revenue), and whether these conditions are combined with AND or OR logic \u2014 sourced from the state's own statute. Answers 'does [state]'s privacy law apply to my business', 'what are the CCPA thresholds for 2026', 'which state privacy laws have no revenue threshold', 'how many consumers triggers the Virginia privacy law', 'which states changed their privacy law thresholds in 2026' (Connecticut lowers from 100k to 35k consumers on July 1, 2026, and adds a sensitive-data trigger with no volume floor; Indiana, Kentucky, and Rhode Island took effect January 1, 2026), 'which state has the lowest privacy law threshold' (Montana: 25k consumers), and 'does Utah require both a revenue AND consumer threshold' (yes \u2014 the only state using AND logic). As of mid-2026, 20 states have comprehensive consumer privacy laws in effect. No single authority publishes the thresholds for all states \u2014 each state's statute defines its own \u2014 which is why assembled versions come from compliance-software vendors (Feroot, IAPP, MultiState, PrivacyLawMap). The thresholds spread is wide: consumer volume from 25k (Montana) to 175k (Tennessee); revenue percentage from 0% (Texas, no numeric threshold) to 50% (Virginia model); revenue floor from $0 to $26.6M (California, inflation-adjusted). The AND/OR distinction matters: most states use OR (any threshold triggers the law), while Utah requires both revenue AND consumer volume, and Connecticut (CA) requires meeting one of three distinct paths.", "file": "index.md", "generated": true, "harvested": "2026-08-12", "key_field": "state", "licence": "Facts and short attributed quotes taken from each state's own statute, linking back to the official code. Facts are not copyrightable (Feist, 1991); no source statute is reproduced wholesale.", "sources": ["https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?sectionNum=1798.140.&lawCode=CIV", "https://leg.colorado.gov/sites/default/files/images/olls/crs2024-title-06.pdf", "https://web.archive.org/web/2024/https://www.cga.ct.gov/current/pub/chap_743jj.htm", "https://delcode.delaware.gov/title6/c012d/index.html", "https://www.leg.state.fl.us/statutes/index.cfm?App_mode=Display_Statute&Search_String=&URL=0500-0599/0501/Sections/0501.702.html", "https://www.legis.iowa.gov/docs/code/715D.pdf", "https://apps.legislature.ky.gov/law/statutes/statute.aspx?id=56648", "https://mgaleg.maryland.gov/2024RS/chapters_noln/Ch_455_sb0541E.pdf", "https://www.revisor.mn.gov/statutes/cite/325M/full", "https://leg.mt.gov/bills/mca/title_0300/chapter_0140/part_0280/section_0030/0300-0140-0280-0030.html", "https://nebraskalegislature.gov/laws/statutes.php?statute=87-1103", "https://pub.njleg.state.nj.us/Bills/2022/S0500/332_R5.PDF", "https://www.oregonlegislature.gov/bills_laws/ors/ors646a.html", "https://webserver.rilegislature.gov/Statutes/TITLE6/6-48.1/6-48.1-4.htm", "https://publications.tnsosfiles.com/acts/113/pub/pc0408.pdf", "https://capitol.texas.gov/tlodocs/88R/billtext/pdf/HB00004F.pdf", "https://le.utah.gov/xcode/Title13/Chapter61/C13-61_2022050420231231.pdf", "https://law.lis.virginia.gov/vacodefull/title59.1/chapter53/"], "stale_after": "2026-11-10", "title": "US state consumer data privacy laws: applicability thresholds by state", "type": "dataset", "verified": false}
{"asset": "state-data-privacy-applicability-thresholds", "body": "**State:** California\n\n**Law name and abbreviation:** California Consumer Privacy Act of 2018 / California Privacy Rights Act (CCPA/CPRA)\n\n**Effective date:** January 1, 2020 (CCPA); January 1, 2023 (CPRA amendments)\n\n**Consumer volume threshold:** annually buys, sells, or shares the personal information of 100,000 or more consumers or households\n\n**Revenue-from-data-sales threshold:** Derives 50 percent or more of its annual revenues from selling or sharing consumers' personal information\n\n**Revenue floor:** annual gross revenues in excess of twenty-five million dollars ($25,000,000), as adjusted pursuant to subdivision (d) of Section 1798.199.95\n\n**Threshold combination logic:** OR \u2014 satisfies one or more of the following thresholds\n\n**Key exemptions:** Nonprofits; government agencies; HIPAA-covered entities; GLBA-regulated financial institutions; FCRA consumer reporting agencies; entities complying with Driver's Privacy Protection Act\n\n**Enforcement mechanism:** State Attorney General and California Privacy Protection Agency (CPPA); limited private right of action for data breaches under Cal. Civ. Code \u00a7 1798.150\n\n**Statute citation:** Cal. Civ. Code \u00a7\u00a7 1798.100\u20131798.199.100\n\n**Notes:** California is the only state with a standalone revenue threshold (no consumer volume required). The $25M threshold is inflation-adjusted annually per subdivision (d) of Section 1798.199.95. Definition of 'sale' is broad: includes renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating personal information for monetary or other valuable consideration. CPRA added 'sharing' as a separate trigger covering cross-context behavioral advertising.\n\n> California, and that satisfies one or more of the following thresholds: (A) As of January 1 of the calendar year, had annual gross revenues in excess of twenty-five million dollars ($25,000,000) in the preceding calendar year, as adjusted pursuant to subdivision (d) of Section 1798.199.95. (B) Alone or in combination, annually buys, sells, or shares the personal information of 100,000 or more consumers or households.\n\nSource: <https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?sectionNum=1798.140.&lawCode=CIV>\n", "consumer_volume_threshold": "annually buys, sells, or shares the personal information of 100,000 or more consumers or households", "data_sales_revenue_threshold": "Derives 50 percent or more of its annual revenues from selling or sharing consumers' personal information", "effective_date": "January 1, 2020 (CCPA); January 1, 2023 (CPRA amendments)", "enforcement": "State Attorney General and California Privacy Protection Agency (CPPA); limited private right of action for data breaches under Cal. Civ. Code \u00a7 1798.150", "file": "california.md", "generated": true, "harvested": "2026-08-12", "id": "california", "key_exemptions": "Nonprofits; government agencies; HIPAA-covered entities; GLBA-regulated financial institutions; FCRA consumer reporting agencies; entities complying with Driver's Privacy Protection Act", "law_name": "California Consumer Privacy Act of 2018 / California Privacy Rights Act (CCPA/CPRA)", "notes": "California is the only state with a standalone revenue threshold (no consumer volume required). The $25M threshold is inflation-adjusted annually per subdivision (d) of Section 1798.199.95. Definition of 'sale' is broad: includes renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating personal information for monetary or other valuable consideration. CPRA added 'sharing' as a separate trigger covering cross-context behavioral advertising.", "revenue_floor": "annual gross revenues in excess of twenty-five million dollars ($25,000,000), as adjusted pursuant to subdivision (d) of Section 1798.199.95", "source_quote": "California, and that satisfies one or more of the following thresholds: (A) As of January 1 of the calendar year, had annual gross revenues in excess of twenty-five million dollars ($25,000,000) in the preceding calendar year, as adjusted pursuant to subdivision (d) of Section 1798.199.95. (B) Alone or in combination, annually buys, sells, or shares the personal information of 100,000 or more consumers or households.", "sources": ["https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?sectionNum=1798.140.&lawCode=CIV"], "stale_after": "2026-11-10", "state": "California", "statute_citation": "Cal. Civ. Code \u00a7\u00a7 1798.100\u20131798.199.100", "threshold_logic": "OR \u2014 satisfies one or more of the following thresholds", "title": "California \u2014 US state consumer data privacy laws: applicability thresholds by state", "type": "applicability-threshold", "unverified_fields": "data_sales_revenue_threshold, effective_date, enforcement, key_exemptions, law_name, notes, statute_citation", "verified": true}
{"asset": "state-data-privacy-applicability-thresholds", "body": "**State:** Colorado\n\n**Law name and abbreviation:** Colorado Privacy Act (CPA)\n\n**Effective date:** July 1, 2023\n\n**Consumer volume threshold:** Controls or processes the personal data of one hundred thousand consumers or more during a calendar year\n\n**Revenue-from-data-sales threshold:** Derives revenue or receives a discount on the price of goods or services from the sale of personal data and processes or controls the personal data of twenty-five thousand consumers or more\n\n**Threshold combination logic:** OR \u2014 satisfies one or both of the following thresholds\n\n**Key exemptions:** State and local government entities; financial institutions subject to GLBA; HIPAA-covered entities and business associates; nonprofit organizations; institutions of higher education; air carriers\n\n**Enforcement mechanism:** Attorney General and district attorneys; civil penalty of up to $20,000 per violation; no private right of action\n\n**Statute citation:** C.R.S. \u00a7\u00a7 6-1-1301 to 6-1-1313\n\n**Notes:** Colorado does not specify a minimum percentage of revenue from data sales \u2014 any revenue or discount from selling data combined with 25,000+ consumers triggers the law. As of October 1, 2025, the law also applies to any controller processing biometric identifiers or biometric data regardless of volume.\n\n> (I) Controls or processes the personal data of one hundred thousand consumers or more during a calendar year; or Colorado Revised Statutes 2024 Page 142 of 320 Uncertified Printout (II) Derives revenue or receives a discount on the price of goods or services from the sale of personal data and processes or controls the personal data of twenty-five thousand consumers or more.\n\nSource: <https://leg.colorado.gov/sites/default/files/images/olls/crs2024-title-06.pdf>\n", "consumer_volume_threshold": "Controls or processes the personal data of one hundred thousand consumers or more during a calendar year", "data_sales_revenue_threshold": "Derives revenue or receives a discount on the price of goods or services from the sale of personal data and processes or controls the personal data of twenty-five thousand consumers or more", "effective_date": "July 1, 2023", "enforcement": "Attorney General and district attorneys; civil penalty of up to $20,000 per violation; no private right of action", "file": "colorado.md", "generated": true, "harvested": "2026-08-12", "id": "colorado", "key_exemptions": "State and local government entities; financial institutions subject to GLBA; HIPAA-covered entities and business associates; nonprofit organizations; institutions of higher education; air carriers", "law_name": "Colorado Privacy Act (CPA)", "notes": "Colorado does not specify a minimum percentage of revenue from data sales \u2014 any revenue or discount from selling data combined with 25,000+ consumers triggers the law. As of October 1, 2025, the law also applies to any controller processing biometric identifiers or biometric data regardless of volume.", "source_quote": "(I) Controls or processes the personal data of one hundred thousand consumers or more during a calendar year; or Colorado Revised Statutes 2024 Page 142 of 320 Uncertified Printout (II) Derives revenue or receives a discount on the price of goods or services from the sale of personal data and processes or controls the personal data of twenty-five thousand consumers or more.", "sources": ["https://leg.colorado.gov/sites/default/files/images/olls/crs2024-title-06.pdf"], "stale_after": "2026-11-10", "state": "Colorado", "statute_citation": "C.R.S. \u00a7\u00a7 6-1-1301 to 6-1-1313", "threshold_logic": "OR \u2014 satisfies one or both of the following thresholds", "title": "Colorado \u2014 US state consumer data privacy laws: applicability thresholds by state", "type": "applicability-threshold", "unverified_fields": "effective_date, enforcement, key_exemptions, law_name, notes, statute_citation", "verified": true}
{"asset": "state-data-privacy-applicability-thresholds", "body": "**State:** Connecticut\n\n**Law name and abbreviation:** Connecticut Data Privacy Act (CTDPA)\n\n**Effective date:** July 1, 2023\n\n**Consumer volume threshold:** Controlled or processed the personal data of not less than one hundred thousand consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction\n\n**Revenue-from-data-sales threshold:** controlled or processed the personal data of not less than twenty-five thousand consumers and derived more than twenty-five per cent of their gross revenue from the sale of personal data\n\n**Threshold combination logic:** OR \u2014 during the preceding calendar year met either threshold\n\n**Key exemptions:** State and local government bodies; HIPAA-covered entities and business associates; GLBA-regulated financial institutions; nonprofit organizations; institutions of higher education; data processed solely for payment transactions excluded from consumer count\n\n**Enforcement mechanism:** Attorney General; cure period (expires December 31, 2024); civil penalty of up to $5,000 per violation under CUTPA; no private right of action\n\n**Statute citation:** Conn. Gen. Stat. \u00a7\u00a7 42-515 to 42-525\n\n**Notes:** Connecticut SB 1295 (effective July 1, 2026) will lower the consumer threshold from 100,000 to 35,000, add a sensitive-data trigger with no volume floor, and add a trigger for selling consumer data at any scale regardless of volume or revenue percentage. Connecticut originally set the data sales revenue threshold at 25% (vs Virginia's 50%), making it easier for mid-sized data businesses to fall into scope.\n\n> apply to persons that conduct business in this state or persons that produce products or services that are targeted to residents of this state and that during the preceding calendar year: (1) Controlled or processed the personal data of not less than one hundred thousand consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or (2) controlled or processed the personal data of not less than twenty-five thousand consumers and derived more than twenty-five per cent of their gross revenue from the sale of personal data.\n\nSource: <https://web.archive.org/web/2024/https://www.cga.ct.gov/current/pub/chap_743jj.htm>\n", "consumer_volume_threshold": "Controlled or processed the personal data of not less than one hundred thousand consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction", "data_sales_revenue_threshold": "controlled or processed the personal data of not less than twenty-five thousand consumers and derived more than twenty-five per cent of their gross revenue from the sale of personal data", "effective_date": "July 1, 2023", "enforcement": "Attorney General; cure period (expires December 31, 2024); civil penalty of up to $5,000 per violation under CUTPA; no private right of action", "file": "connecticut.md", "generated": true, "harvested": "2026-08-12", "id": "connecticut", "key_exemptions": "State and local government bodies; HIPAA-covered entities and business associates; GLBA-regulated financial institutions; nonprofit organizations; institutions of higher education; data processed solely for payment transactions excluded from consumer count", "law_name": "Connecticut Data Privacy Act (CTDPA)", "notes": "Connecticut SB 1295 (effective July 1, 2026) will lower the consumer threshold from 100,000 to 35,000, add a sensitive-data trigger with no volume floor, and add a trigger for selling consumer data at any scale regardless of volume or revenue percentage. Connecticut originally set the data sales revenue threshold at 25% (vs Virginia's 50%), making it easier for mid-sized data businesses to fall into scope.", "source_quote": "apply to persons that conduct business in this state or persons that produce products or services that are targeted to residents of this state and that during the preceding calendar year: (1) Controlled or processed the personal data of not less than one hundred thousand consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or (2) controlled or processed the personal data of not less than twenty-five thousand consumers and derived more than twenty-five per cent of their gross revenue from the sale of personal data.", "sources": ["https://web.archive.org/web/2024/https://www.cga.ct.gov/current/pub/chap_743jj.htm"], "stale_after": "2026-11-10", "state": "Connecticut", "statute_citation": "Conn. Gen. Stat. \u00a7\u00a7 42-515 to 42-525", "threshold_logic": "OR \u2014 during the preceding calendar year met either threshold", "title": "Connecticut \u2014 US state consumer data privacy laws: applicability thresholds by state", "type": "applicability-threshold", "unverified_fields": "effective_date, enforcement, key_exemptions, law_name, notes, statute_citation", "verified": true}
{"asset": "state-data-privacy-applicability-thresholds", "body": "**State:** Delaware\n\n**Law name and abbreviation:** Delaware Personal Data Privacy Act (DPDPA)\n\n**Effective date:** January 1, 2025\n\n**Consumer volume threshold:** Controlled or processed the personal data of not less than 35,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction\n\n**Revenue-from-data-sales threshold:** Controlled or processed the personal data of not less than 10,000 consumers and derived more than 20% of their gross revenue from the sale of personal data\n\n**Threshold combination logic:** OR \u2014 during the preceding calendar year did any of the following\n\n**Key exemptions:** State and political subdivision bodies (excluding institutions of higher education); GLBA-regulated financial institutions; national securities associations; nonprofit organizations dedicated to preventing insurance crime\n\n**Enforcement mechanism:** Attorney General (Department of Justice); 60-day cure period (expires December 31, 2025); no private right of action\n\n**Statute citation:** Del. Code Ann. tit. 6, ch. 12D\n\n**Notes:** Delaware has relatively low thresholds: 35,000 consumers (excl. payment data) or 10,000 consumers with 20% revenue from data sales. Unlike many states, Delaware does not broadly exempt all nonprofits \u2014 only nonprofits dedicated to preventing insurance crime are exempt. Institutions of higher education are NOT exempt.\n\n> This chapter applies to persons that conduct business in the State or persons that produce products or services that are targeted to residents of the State and that during the preceding calendar year did any of the following: (1) Controlled or processed the personal data of not less than 35,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction. (2) Controlled or processed the personal data of not less than 10,000 consumers and derived more than 20% of their gross revenue from the sale of personal data.\n\nSource: <https://delcode.delaware.gov/title6/c012d/index.html>\n", "consumer_volume_threshold": "Controlled or processed the personal data of not less than 35,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction", "data_sales_revenue_threshold": "Controlled or processed the personal data of not less than 10,000 consumers and derived more than 20% of their gross revenue from the sale of personal data", "effective_date": "January 1, 2025", "enforcement": "Attorney General (Department of Justice); 60-day cure period (expires December 31, 2025); no private right of action", "file": "delaware.md", "generated": true, "harvested": "2026-08-12", "id": "delaware", "key_exemptions": "State and political subdivision bodies (excluding institutions of higher education); GLBA-regulated financial institutions; national securities associations; nonprofit organizations dedicated to preventing insurance crime", "law_name": "Delaware Personal Data Privacy Act (DPDPA)", "notes": "Delaware has relatively low thresholds: 35,000 consumers (excl. payment data) or 10,000 consumers with 20% revenue from data sales. Unlike many states, Delaware does not broadly exempt all nonprofits \u2014 only nonprofits dedicated to preventing insurance crime are exempt. Institutions of higher education are NOT exempt.", "source_quote": "This chapter applies to persons that conduct business in the State or persons that produce products or services that are targeted to residents of the State and that during the preceding calendar year did any of the following: (1) Controlled or processed the personal data of not less than 35,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction. (2) Controlled or processed the personal data of not less than 10,000 consumers and derived more than 20% of their gross revenue from the sale of personal data.", "sources": ["https://delcode.delaware.gov/title6/c012d/index.html"], "stale_after": "2026-11-10", "state": "Delaware", "statute_citation": "Del. Code Ann. tit. 6, ch. 12D", "threshold_logic": "OR \u2014 during the preceding calendar year did any of the following", "title": "Delaware \u2014 US state consumer data privacy laws: applicability thresholds by state", "type": "applicability-threshold", "unverified_fields": "effective_date, enforcement, key_exemptions, law_name, notes, statute_citation", "verified": true}
{"asset": "state-data-privacy-applicability-thresholds", "body": "**State:** Florida\n\n**Law name and abbreviation:** Florida Digital Bill of Rights (FDBR)\n\n**Effective date:** July 1, 2024\n\n**Revenue floor:** Makes in excess of $1 billion in global gross annual revenues\n\n**Threshold combination logic:** AND \u2014 requires $1 billion+ in global gross annual revenues AND satisfies at least one additional criterion (50%+ revenue from online ads, operates a smart speaker with virtual assistant, or operates an app store with 250,000+ apps)\n\n**Key exemptions:** State agencies and political subdivisions; GLBA-regulated financial institutions; HIPAA-covered entities and business associates; nonprofit organizations; postsecondary education institutions\n\n**Enforcement mechanism:** Department of Legal Affairs (Attorney General); civil penalties of $50,000 per violation or treble damages; no private right of action\n\n**Statute citation:** Fla. Stat. \u00a7\u00a7 501.701 to 501.721\n\n**Notes:** Florida has by far the highest revenue threshold of any state at $1 billion in global gross annual revenues, effectively limiting the law to large technology companies. Additionally, the business must satisfy at least one of three criteria: deriving 50%+ of global revenue from online advertising, operating a consumer smart speaker with a virtual assistant, or operating an app store with at least 250,000 apps. This narrow scope means the law applies to very few companies.\n\n> Makes in excess of $1 billion in global gross annual revenues; and 6.&#x2003; Satisfies at least one of the following: a.&#x2003; Derives 50 percent or more of its global gross annual revenues from the sale of advertisements online, including providing targeted advertising or the sale of ads online; b.&#x2003; Operates a consumer smart speaker and voice command component service with an integrated virtual assistant connected to a cloud computing service that uses hands-free verbal activation.\n\nSource: <https://www.leg.state.fl.us/statutes/index.cfm?App_mode=Display_Statute&Search_String=&URL=0500-0599/0501/Sections/0501.702.html>\n", "effective_date": "July 1, 2024", "enforcement": "Department of Legal Affairs (Attorney General); civil penalties of $50,000 per violation or treble damages; no private right of action", "file": "florida.md", "generated": true, "harvested": "2026-08-12", "id": "florida", "key_exemptions": "State agencies and political subdivisions; GLBA-regulated financial institutions; HIPAA-covered entities and business associates; nonprofit organizations; postsecondary education institutions", "law_name": "Florida Digital Bill of Rights (FDBR)", "notes": "Florida has by far the highest revenue threshold of any state at $1 billion in global gross annual revenues, effectively limiting the law to large technology companies. Additionally, the business must satisfy at least one of three criteria: deriving 50%+ of global revenue from online advertising, operating a consumer smart speaker with a virtual assistant, or operating an app store with at least 250,000 apps. This narrow scope means the law applies to very few companies.", "revenue_floor": "Makes in excess of $1 billion in global gross annual revenues", "source_quote": "Makes in excess of $1 billion in global gross annual revenues; and 6.&#x2003; Satisfies at least one of the following: a.&#x2003; Derives 50 percent or more of its global gross annual revenues from the sale of advertisements online, including providing targeted advertising or the sale of ads online; b.&#x2003; Operates a consumer smart speaker and voice command component service with an integrated virtual assistant connected to a cloud computing service that uses hands-free verbal activation.", "sources": ["https://www.leg.state.fl.us/statutes/index.cfm?App_mode=Display_Statute&Search_String=&URL=0500-0599/0501/Sections/0501.702.html"], "stale_after": "2026-11-10", "state": "Florida", "statute_citation": "Fla. Stat. \u00a7\u00a7 501.701 to 501.721", "threshold_logic": "AND \u2014 requires $1 billion+ in global gross annual revenues AND satisfies at least one additional criterion (50%+ revenue from online ads, operates a smart speaker with virtual assistant, or operates an app store with 250,000+ apps)", "title": "Florida \u2014 US state consumer data privacy laws: applicability thresholds by state", "type": "applicability-threshold", "unverified_fields": "effective_date, enforcement, key_exemptions, law_name, notes, statute_citation, threshold_logic", "verified": true}
{"asset": "state-data-privacy-applicability-thresholds", "body": "**State:** Iowa\n\n**Law name and abbreviation:** Iowa Consumer Data Protection Act (ICDPA)\n\n**Effective date:** January 1, 2025\n\n**Consumer volume threshold:** Controls or processes personal data of at least one hundred thousand consumers\n\n**Revenue-from-data-sales threshold:** Controls or processes personal data of at least twenty-five thousand consumers and derives over fifty percent of gross revenue from the sale of personal data\n\n**Threshold combination logic:** OR \u2014 during a calendar year does either of the following\n\n**Key exemptions:** State and political subdivisions; GLBA-regulated financial institutions; HIPAA-covered entities and business associates; nonprofit organizations; institutions of higher education\n\n**Enforcement mechanism:** Attorney General; 90-day cure period; no private right of action\n\n**Statute citation:** Iowa Code ch. 715D\n\n**Notes:** Iowa follows the Virginia model closely. Unique feature: 90-day cure period (the longest among state privacy laws). Iowa does not include a right to correction of inaccurate personal data.\n\n> This chapter applies to a person conducting business in the state or producing products or services that are targeted to consumers who are residents of the state and that during a calendar year does either of the following: a. Controls or processes personal data of at least one hundred thousand consumers. b. Controls or processes personal data of at least twenty-five thousand consumers and derives over fifty percent of gross revenue from the sale of personal data.\n\nSource: <https://www.legis.iowa.gov/docs/code/715D.pdf>\n", "consumer_volume_threshold": "Controls or processes personal data of at least one hundred thousand consumers", "data_sales_revenue_threshold": "Controls or processes personal data of at least twenty-five thousand consumers and derives over fifty percent of gross revenue from the sale of personal data", "effective_date": "January 1, 2025", "enforcement": "Attorney General; 90-day cure period; no private right of action", "file": "iowa.md", "generated": true, "harvested": "2026-08-12", "id": "iowa", "key_exemptions": "State and political subdivisions; GLBA-regulated financial institutions; HIPAA-covered entities and business associates; nonprofit organizations; institutions of higher education", "law_name": "Iowa Consumer Data Protection Act (ICDPA)", "notes": "Iowa follows the Virginia model closely. Unique feature: 90-day cure period (the longest among state privacy laws). Iowa does not include a right to correction of inaccurate personal data.", "source_quote": "This chapter applies to a person conducting business in the state or producing products or services that are targeted to consumers who are residents of the state and that during a calendar year does either of the following: a. Controls or processes personal data of at least one hundred thousand consumers. b. Controls or processes personal data of at least twenty-five thousand consumers and derives over fifty percent of gross revenue from the sale of personal data.", "sources": ["https://www.legis.iowa.gov/docs/code/715D.pdf"], "stale_after": "2026-11-10", "state": "Iowa", "statute_citation": "Iowa Code ch. 715D", "threshold_logic": "OR \u2014 during a calendar year does either of the following", "title": "Iowa \u2014 US state consumer data privacy laws: applicability thresholds by state", "type": "applicability-threshold", "unverified_fields": "effective_date, enforcement, key_exemptions, law_name, notes, statute_citation", "verified": true}
{"asset": "state-data-privacy-applicability-thresholds", "body": "**State:** Kentucky\n\n**Law name and abbreviation:** Kentucky Consumer Data Protection Act (KCDPA)\n\n**Effective date:** January 1, 2026\n\n**Consumer volume threshold:** One hundred thousand (100,000) consumers\n\n**Revenue-from-data-sales threshold:** Twenty-five thousand (25,000) consumers and derive over fifty percent (50%) of gross revenue from the sale of personal data\n\n**Threshold combination logic:** OR \u2014 control or process personal data of at least either threshold\n\n**Key exemptions:** City, state agency, or political subdivision; GLBA-regulated financial institutions; HIPAA-covered entities and business associates; nonprofit organizations; institutions of higher education; small telephone utilities and Tier III CMRS providers\n\n**Enforcement mechanism:** Attorney General; 30-day cure period (non-expiring); no private right of action\n\n**Statute citation:** KRS \u00a7\u00a7 367.3611 to 367.3629\n\n**Notes:** Kentucky's 30-day cure period does not expire, making it one of the most business-friendly enforcement provisions. Kentucky follows the Virginia model closely. Small telephone utilities and municipal utilities that do not sell or share data are also exempt.\n\n> KRS 367.3611 to 367.3629 apply to persons that conduct business in the Commonwealth or produce products or services that are targeted to residents of the Commonwealth and that during a calendar year control or process personal data of at least: (a) One hundred thousand (100,000) consumers; or (b) Twenty-five thousand (25,000) consumers and derive over fifty percent (50%) of gross revenue from the sale of personal data.\n\nSource: <https://apps.legislature.ky.gov/law/statutes/statute.aspx?id=56648>\n", "consumer_volume_threshold": "One hundred thousand (100,000) consumers", "data_sales_revenue_threshold": "Twenty-five thousand (25,000) consumers and derive over fifty percent (50%) of gross revenue from the sale of personal data", "effective_date": "January 1, 2026", "enforcement": "Attorney General; 30-day cure period (non-expiring); no private right of action", "file": "kentucky.md", "generated": true, "harvested": "2026-08-12", "id": "kentucky", "key_exemptions": "City, state agency, or political subdivision; GLBA-regulated financial institutions; HIPAA-covered entities and business associates; nonprofit organizations; institutions of higher education; small telephone utilities and Tier III CMRS providers", "law_name": "Kentucky Consumer Data Protection Act (KCDPA)", "notes": "Kentucky's 30-day cure period does not expire, making it one of the most business-friendly enforcement provisions. Kentucky follows the Virginia model closely. Small telephone utilities and municipal utilities that do not sell or share data are also exempt.", "source_quote": "KRS 367.3611 to 367.3629 apply to persons that conduct business in the Commonwealth or produce products or services that are targeted to residents of the Commonwealth and that during a calendar year control or process personal data of at least: (a) One hundred thousand (100,000) consumers; or (b) Twenty-five thousand (25,000) consumers and derive over fifty percent (50%) of gross revenue from the sale of personal data.", "sources": ["https://apps.legislature.ky.gov/law/statutes/statute.aspx?id=56648"], "stale_after": "2026-11-10", "state": "Kentucky", "statute_citation": "KRS \u00a7\u00a7 367.3611 to 367.3629", "threshold_logic": "OR \u2014 control or process personal data of at least either threshold", "title": "Kentucky \u2014 US state consumer data privacy laws: applicability thresholds by state", "type": "applicability-threshold", "unverified_fields": "effective_date, enforcement, key_exemptions, law_name, notes, statute_citation", "verified": true}
{"asset": "state-data-privacy-applicability-thresholds", "body": "**State:** Maryland\n\n**Law name and abbreviation:** Maryland Online Data Privacy Act (MODPA)\n\n**Effective date:** October 1, 2025\n\n**Consumer volume threshold:** CONTROLLED OR PROCESSED THE PERSONAL DATA OF AT LEAST 35,000 CONSUMERS, EXCLUDING PERSONAL DATA CONTROLLED OR PROCESSED SOLELY FOR THE PURPOSE OF COMPLETING A PAYMENT TRANSACTION\n\n**Revenue-from-data-sales threshold:** CONTROLLED OR PROCESSED THE PERSONAL DATA OF AT LEAST 10,000 CONSUMERS AND DERIVED MORE THAN 20% OF ITS GROSS REVENUE FROM THE SALE OF PERSONAL DATA\n\n**Threshold combination logic:** OR \u2014 during the preceding calendar year met either threshold\n\n**Key exemptions:** State and local government bodies and instrumentalities; national securities associations; GLBA-regulated financial institutions and affiliates; nonprofit controllers assisting law enforcement with insurance crime or first responders with catastrophic events\n\n**Enforcement mechanism:** Division of Consumer Protection (Attorney General); civil penalty; no private right of action\n\n**Statute citation:** Md. Code Ann., Com. Law \u00a7\u00a7 14-4601 to 14-4614\n\n**Notes:** Maryland bans the sale of sensitive data entirely (not just requiring consent). Maryland has relatively low thresholds (35,000/10,000 at 20%), matching Delaware and Rhode Island. Unlike many states, Maryland does not broadly exempt all nonprofits \u2014 only specific nonprofit controllers assisting law enforcement or first responders are exempt.\n\n> CONDUCTS BUSINESS IN THE STATE OR PROVIDES PRODUCTS OR SERVICES THAT ARE TARGETED TO RESIDENTS OF THE STATE, AND THAT DURING THE PRECEDING CALENDAR YEAR DID ANY OF THE FOLLOWING: (1) CONTROLLED OR PROCESSED THE PERSONAL DATA OF AT LEAST 35,000 CONSUMERS, EXCLUDING PERSONAL DATA CONTROLLED OR PROCESSED SOLELY FOR THE PURPOSE OF COMPLETING A PAYMENT TRANSACTION; OR 2. (II) (2) CONTROLLED OR PROCESSED THE PERSONAL DATA OF AT LEAST 10,000 CONSUMERS AND DERIVED MORE THAN 20% OF ITS GROSS REVENUE FROM THE SALE OF PERSONAL DATA.\n\nSource: <https://mgaleg.maryland.gov/2024RS/chapters_noln/Ch_455_sb0541E.pdf>\n", "consumer_volume_threshold": "CONTROLLED OR PROCESSED THE PERSONAL DATA OF AT LEAST 35,000 CONSUMERS, EXCLUDING PERSONAL DATA CONTROLLED OR PROCESSED SOLELY FOR THE PURPOSE OF COMPLETING A PAYMENT TRANSACTION", "data_sales_revenue_threshold": "CONTROLLED OR PROCESSED THE PERSONAL DATA OF AT LEAST 10,000 CONSUMERS AND DERIVED MORE THAN 20% OF ITS GROSS REVENUE FROM THE SALE OF PERSONAL DATA", "effective_date": "October 1, 2025", "enforcement": "Division of Consumer Protection (Attorney General); civil penalty; no private right of action", "file": "maryland.md", "generated": true, "harvested": "2026-08-12", "id": "maryland", "key_exemptions": "State and local government bodies and instrumentalities; national securities associations; GLBA-regulated financial institutions and affiliates; nonprofit controllers assisting law enforcement with insurance crime or first responders with catastrophic events", "law_name": "Maryland Online Data Privacy Act (MODPA)", "notes": "Maryland bans the sale of sensitive data entirely (not just requiring consent). Maryland has relatively low thresholds (35,000/10,000 at 20%), matching Delaware and Rhode Island. Unlike many states, Maryland does not broadly exempt all nonprofits \u2014 only specific nonprofit controllers assisting law enforcement or first responders are exempt.", "source_quote": "CONDUCTS BUSINESS IN THE STATE OR PROVIDES PRODUCTS OR SERVICES THAT ARE TARGETED TO RESIDENTS OF THE STATE, AND THAT DURING THE PRECEDING CALENDAR YEAR DID ANY OF THE FOLLOWING: (1) CONTROLLED OR PROCESSED THE PERSONAL DATA OF AT LEAST 35,000 CONSUMERS, EXCLUDING PERSONAL DATA CONTROLLED OR PROCESSED SOLELY FOR THE PURPOSE OF COMPLETING A PAYMENT TRANSACTION; OR 2. (II) (2) CONTROLLED OR PROCESSED THE PERSONAL DATA OF AT LEAST 10,000 CONSUMERS AND DERIVED MORE THAN 20% OF ITS GROSS REVENUE FROM THE SALE OF PERSONAL DATA.", "sources": ["https://mgaleg.maryland.gov/2024RS/chapters_noln/Ch_455_sb0541E.pdf"], "stale_after": "2026-11-10", "state": "Maryland", "statute_citation": "Md. Code Ann., Com. Law \u00a7\u00a7 14-4601 to 14-4614", "threshold_logic": "OR \u2014 during the preceding calendar year met either threshold", "title": "Maryland \u2014 US state consumer data privacy laws: applicability thresholds by state", "type": "applicability-threshold", "unverified_fields": "effective_date, enforcement, key_exemptions, law_name, notes, statute_citation", "verified": true}
{"asset": "state-data-privacy-applicability-thresholds", "body": "**State:** Minnesota\n\n**Law name and abbreviation:** Minnesota Consumer Data Privacy Act (MCDPA)\n\n**Effective date:** July 31, 2025\n\n**Consumer volume threshold:** during a calendar year, controls or processes personal data of 100,000 consumers or more, excluding personal data controlled or processed solely for the purpose of completing a payment transaction\n\n**Revenue-from-data-sales threshold:** derives over 25 percent of gross revenue from the sale of personal data and processes or controls personal data of 25,000 consumers or more\n\n**Threshold combination logic:** OR \u2014 satisfies one or more of the following thresholds\n\n**Key exemptions:** State and local government entities; HIPAA-covered entities; GLBA-regulated financial institutions; nonprofit organizations; institutions of higher education (postsecondary institutions regulated by the Office of Higher Education not required to comply until July 31, 2029)\n\n**Enforcement mechanism:** Attorney General; no private right of action\n\n**Statute citation:** Minn. Stat. \u00a7\u00a7 325M.10 to 325M.21\n\n**Notes:** Minnesota uses a 25% revenue threshold (like Colorado and Oregon), lower than the 50% in Virginia-model states. Minnesota has stronger data minimization rules than most states. Postsecondary institutions regulated by the Office of Higher Education have a delayed compliance date of July 31, 2029.\n\n> This section, as added by Laws 2024, chapter 121, article 5, section 3, is effective July 31, 2025, except that postsecondary institutions regulated by the Office of Higher Education are not required to comply until July 31, 2029. Laws 2024, chapter 121, article 5, section 14. 325M.12 SCOPE; EXCLUSIONS. \u00a7 Subdivision 1. Scope. (a) Sections <https://www.revisor.mn.gov/statutes/cite/325M.10> 325M.10 to <https://www.revisor.mn.gov/statutes/cite/325M.21> 325M.21 apply to legal entities that conduct business in Minnesota or produce products or services that are targeted to residents of Minnesota, and that satisfy one or more of the following thresholds: (1) during a calendar year, controls or processes personal data of 100,000 consumers or more, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or (2) derives over 25 percent of gross revenue from the sale of personal data and processes or controls personal data of 25,000 consumers or more.\n\nSource: <https://www.revisor.mn.gov/statutes/cite/325M/full>\n", "consumer_volume_threshold": "during a calendar year, controls or processes personal data of 100,000 consumers or more, excluding personal data controlled or processed solely for the purpose of completing a payment transaction", "data_sales_revenue_threshold": "derives over 25 percent of gross revenue from the sale of personal data and processes or controls personal data of 25,000 consumers or more", "effective_date": "July 31, 2025", "enforcement": "Attorney General; no private right of action", "file": "minnesota.md", "generated": true, "harvested": "2026-08-12", "id": "minnesota", "key_exemptions": "State and local government entities; HIPAA-covered entities; GLBA-regulated financial institutions; nonprofit organizations; institutions of higher education (postsecondary institutions regulated by the Office of Higher Education not required to comply until July 31, 2029)", "law_name": "Minnesota Consumer Data Privacy Act (MCDPA)", "notes": "Minnesota uses a 25% revenue threshold (like Colorado and Oregon), lower than the 50% in Virginia-model states. Minnesota has stronger data minimization rules than most states. Postsecondary institutions regulated by the Office of Higher Education have a delayed compliance date of July 31, 2029.", "source_quote": "This section, as added by Laws 2024, chapter 121, article 5, section 3, is effective July 31, 2025, except that postsecondary institutions regulated by the Office of Higher Education are not required to comply until July 31, 2029. Laws 2024, chapter 121, article 5, section 14. 325M.12 SCOPE; EXCLUSIONS. \u00a7 Subdivision 1. Scope. (a) Sections <https://www.revisor.mn.gov/statutes/cite/325M.10> 325M.10 to <https://www.revisor.mn.gov/statutes/cite/325M.21> 325M.21 apply to legal entities that conduct business in Minnesota or produce products or services that are targeted to residents of Minnesota, and that satisfy one or more of the following thresholds: (1) during a calendar year, controls or processes personal data of 100,000 consumers or more, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or (2) derives over 25 percent of gross revenue from the sale of personal data and processes or controls personal data of 25,000 consumers or more.", "sources": ["https://www.revisor.mn.gov/statutes/cite/325M/full"], "stale_after": "2026-11-10", "state": "Minnesota", "statute_citation": "Minn. Stat. \u00a7\u00a7 325M.10 to 325M.21", "threshold_logic": "OR \u2014 satisfies one or more of the following thresholds", "title": "Minnesota \u2014 US state consumer data privacy laws: applicability thresholds by state", "type": "applicability-threshold", "unverified_fields": "enforcement, key_exemptions, law_name, statute_citation", "verified": true}
{"asset": "state-data-privacy-applicability-thresholds", "body": "**State:** Montana\n\n**Law name and abbreviation:** Montana Consumer Data Privacy Act (MCDPA)\n\n**Effective date:** October 1, 2024\n\n**Consumer volume threshold:** control or process the personal data of not less than 25,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction\n\n**Revenue-from-data-sales threshold:** control or process the personal data of not less than 15,000 consumers and derive more than 25% of gross revenue from the sale of personal data\n\n**Threshold combination logic:** OR \u2014 applies to persons that conduct business in this state and meet either threshold\n\n**Key exemptions:** Government bodies; HIPAA-covered entities; GLBA-regulated financial institutions; nonprofit organizations; institutions of higher education\n\n**Enforcement mechanism:** Attorney General; 60-day cure period; no private right of action\n\n**Statute citation:** Mont. Code Ann. \u00a7\u00a7 30-14-2801 to 30-14-2817\n\n**Notes:** Montana has the lowest consumer threshold in the country at 25,000 consumers, and the lowest data-sales threshold at 15,000 consumers with 25% revenue. Montana's small population (approximately 1.1 million) means these thresholds capture a proportionally larger share of businesses operating in the state.\n\n> apply to persons that conduct business in this state or persons that produce products or services that are targeted to residents of this state and: (a) control or process the personal data of not less than 25,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or (b) control or process the personal data of not less than 15,000 consumers and derive more than 25% of gross revenue from the sale of personal data.\n\nSource: <https://leg.mt.gov/bills/mca/title_0300/chapter_0140/part_0280/section_0030/0300-0140-0280-0030.html>\n", "consumer_volume_threshold": "control or process the personal data of not less than 25,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction", "data_sales_revenue_threshold": "control or process the personal data of not less than 15,000 consumers and derive more than 25% of gross revenue from the sale of personal data", "effective_date": "October 1, 2024", "enforcement": "Attorney General; 60-day cure period; no private right of action", "file": "montana.md", "generated": true, "harvested": "2026-08-12", "id": "montana", "key_exemptions": "Government bodies; HIPAA-covered entities; GLBA-regulated financial institutions; nonprofit organizations; institutions of higher education", "law_name": "Montana Consumer Data Privacy Act (MCDPA)", "notes": "Montana has the lowest consumer threshold in the country at 25,000 consumers, and the lowest data-sales threshold at 15,000 consumers with 25% revenue. Montana's small population (approximately 1.1 million) means these thresholds capture a proportionally larger share of businesses operating in the state.", "source_quote": "apply to persons that conduct business in this state or persons that produce products or services that are targeted to residents of this state and: (a) control or process the personal data of not less than 25,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or (b) control or process the personal data of not less than 15,000 consumers and derive more than 25% of gross revenue from the sale of personal data.", "sources": ["https://leg.mt.gov/bills/mca/title_0300/chapter_0140/part_0280/section_0030/0300-0140-0280-0030.html"], "stale_after": "2026-11-10", "state": "Montana", "statute_citation": "Mont. Code Ann. \u00a7\u00a7 30-14-2801 to 30-14-2817", "threshold_logic": "OR \u2014 applies to persons that conduct business in this state and meet either threshold", "title": "Montana \u2014 US state consumer data privacy laws: applicability thresholds by state", "type": "applicability-threshold", "unverified_fields": "effective_date, enforcement, key_exemptions, law_name, notes, statute_citation", "verified": true}
{"asset": "state-data-privacy-applicability-thresholds", "body": "**State:** Nebraska\n\n**Law name and abbreviation:** Nebraska Data Privacy Act (NDPA)\n\n**Effective date:** January 1, 2025\n\n**Threshold combination logic:** No numeric consumer or revenue thresholds \u2014 applies to any non-small-business that processes or sells personal data\n\n**Key exemptions:** Small businesses as determined under the federal Small Business Act; state agencies and political subdivisions; GLBA-regulated financial institutions; HIPAA-covered entities and business associates; nonprofit organizations; institutions of higher education; electric suppliers; natural gas public utilities\n\n**Enforcement mechanism:** Attorney General; 30-day cure period; civil penalty up to $7,500 per violation; no private right of action\n\n**Statute citation:** Neb. Rev. Stat. \u00a7\u00a7 87-1101 to 87-1118\n\n**Notes:** Nebraska follows the Texas model rather than the Virginia model, using the federal Small Business Act to determine applicability rather than fixed numeric thresholds. Nebraska is the only other state besides Texas to take this approach.\n\n> Data Privacy Act applies only to a person that: (a) Conducts business in this state or produces a product or service consumed by residents of this state; (b) Processes or engages in the sale of personal data; and (c) Is not a small business as determined under the federal Small Business Act, as such act existed on January 1, 2024, except to the extent that section\n\nSource: <https://nebraskalegislature.gov/laws/statutes.php?statute=87-1103>\n", "effective_date": "January 1, 2025", "enforcement": "Attorney General; 30-day cure period; civil penalty up to $7,500 per violation; no private right of action", "file": "nebraska.md", "generated": true, "harvested": "2026-08-12", "id": "nebraska", "key_exemptions": "Small businesses as determined under the federal Small Business Act; state agencies and political subdivisions; GLBA-regulated financial institutions; HIPAA-covered entities and business associates; nonprofit organizations; institutions of higher education; electric suppliers; natural gas public utilities", "law_name": "Nebraska Data Privacy Act (NDPA)", "notes": "Nebraska follows the Texas model rather than the Virginia model, using the federal Small Business Act to determine applicability rather than fixed numeric thresholds. Nebraska is the only other state besides Texas to take this approach.", "source_quote": "Data Privacy Act applies only to a person that: (a) Conducts business in this state or produces a product or service consumed by residents of this state; (b) Processes or engages in the sale of personal data; and (c) Is not a small business as determined under the federal Small Business Act, as such act existed on January 1, 2024, except to the extent that section", "sources": ["https://nebraskalegislature.gov/laws/statutes.php?statute=87-1103"], "stale_after": "2026-11-10", "state": "Nebraska", "statute_citation": "Neb. Rev. Stat. \u00a7\u00a7 87-1101 to 87-1118", "threshold_logic": "No numeric consumer or revenue thresholds \u2014 applies to any non-small-business that processes or sells personal data", "title": "Nebraska \u2014 US state consumer data privacy laws: applicability thresholds by state", "type": "applicability-threshold", "unverified_fields": "effective_date, enforcement, key_exemptions, law_name, notes, statute_citation, threshold_logic", "verified": true}
{"asset": "state-data-privacy-applicability-thresholds", "body": "**State:** New Jersey\n\n**Law name and abbreviation:** New Jersey Data Privacy Act (NJDPA)\n\n**Effective date:** January 15, 2025\n\n**Consumer volume threshold:** control or process the personal data of at least 100,000 consumers, excluding personal data processed solely for the purpose of completing a payment transaction\n\n**Revenue-from-data-sales threshold:** control or process the personal data of at least 25,000 consumers and the controller derives revenue, or receives a discount on the price of any goods or services, from the sale of personal data\n\n**Threshold combination logic:** OR \u2014 during a calendar year either threshold is met\n\n**Key exemptions:** HIPAA-covered entities and business associates; GLBA-regulated financial institutions and affiliates; secondary market institutions; insurance institutions; NJ Motor Vehicle Commission data sales under DPPA\n\n**Enforcement mechanism:** Attorney General (Division of Consumer Affairs); violations treated as unlawful practices under the Consumer Fraud Act; no private right of action for data privacy violations specifically\n\n**Statute citation:** N.J. Stat. Ann. \u00a7 56:8-166.1 et seq.\n\n**Notes:** New Jersey is notable for not exempting nonprofit organizations \u2014 one of the few states where nonprofits must comply. Like Colorado, NJ does not specify a minimum percentage of revenue from data sales \u2014 any revenue or discount from selling data combined with 25,000+ consumers triggers the law.\n\n> that during a calendar 44 year either: 45 a. control or process the personal data of at least 100,000 46 consumers, excluding personal data processed solely for the 47 purpose of completing a payment transaction; or S332 [5R] SINGLETON, CODEY 12 1 b. control or process the personal data of at least 25,000 2 consumers and the controller derives revenue, or receives a discount 3 on the price of any goods or services, from the sale of personal 4 data.\n\nSource: <https://pub.njleg.state.nj.us/Bills/2022/S0500/332_R5.PDF>\n", "consumer_volume_threshold": "control or process the personal data of at least 100,000 consumers, excluding personal data processed solely for the purpose of completing a payment transaction", "data_sales_revenue_threshold": "control or process the personal data of at least 25,000 consumers and the controller derives revenue, or receives a discount on the price of any goods or services, from the sale of personal data", "effective_date": "January 15, 2025", "enforcement": "Attorney General (Division of Consumer Affairs); violations treated as unlawful practices under the Consumer Fraud Act; no private right of action for data privacy violations specifically", "file": "new-jersey.md", "generated": true, "harvested": "2026-08-12", "id": "new-jersey", "key_exemptions": "HIPAA-covered entities and business associates; GLBA-regulated financial institutions and affiliates; secondary market institutions; insurance institutions; NJ Motor Vehicle Commission data sales under DPPA", "law_name": "New Jersey Data Privacy Act (NJDPA)", "notes": "New Jersey is notable for not exempting nonprofit organizations \u2014 one of the few states where nonprofits must comply. Like Colorado, NJ does not specify a minimum percentage of revenue from data sales \u2014 any revenue or discount from selling data combined with 25,000+ consumers triggers the law.", "source_quote": "that during a calendar 44 year either: 45 a. control or process the personal data of at least 100,000 46 consumers, excluding personal data processed solely for the 47 purpose of completing a payment transaction; or S332 [5R] SINGLETON, CODEY 12 1 b. control or process the personal data of at least 25,000 2 consumers and the controller derives revenue, or receives a discount 3 on the price of any goods or services, from the sale of personal 4 data.", "sources": ["https://pub.njleg.state.nj.us/Bills/2022/S0500/332_R5.PDF"], "stale_after": "2026-11-10", "state": "New Jersey", "statute_citation": "N.J. Stat. Ann. \u00a7 56:8-166.1 et seq.", "threshold_logic": "OR \u2014 during a calendar year either threshold is met", "title": "New Jersey \u2014 US state consumer data privacy laws: applicability thresholds by state", "type": "applicability-threshold", "unverified_fields": "effective_date, enforcement, key_exemptions, law_name, notes, statute_citation", "verified": true}
{"asset": "state-data-privacy-applicability-thresholds", "body": "**State:** Oregon\n\n**Law name and abbreviation:** Oregon Consumer Privacy Act (OCPA)\n\n**Effective date:** July 1, 2024\n\n**Consumer volume threshold:** The personal data of 100,000 or more consumers, other than personal data controlled or processed solely for the purpose of completing a payment transaction\n\n**Revenue-from-data-sales threshold:** The personal data of 25,000 or more consumers, while deriving 25 percent or more of the person's annual gross revenue from selling personal data\n\n**Threshold combination logic:** OR \u2014 during a calendar year, controls or processes either threshold\n\n**Key exemptions:** Public corporations and public bodies; HIPAA-covered entities; nonprofit organizations (exempt until July 1, 2025)\n\n**Enforcement mechanism:** Attorney General; exclusive authority; civil penalty; no private right of action\n\n**Statute citation:** Or. Rev. Stat. \u00a7\u00a7 646A.570 to 646A.589\n\n**Notes:** Oregon does not exclude payment-only data processing from the data-sales threshold \u2014 only from the volume threshold. As of the 2025 amendments, the law also applies to motor vehicle manufacturers regardless of consumer volume thresholds. Oregon had the latest nonprofit exemption expiration (July 1, 2025) and includes a universal opt-out mechanism requirement effective January 1, 2026.\n\n> \ufffd\ufffd\ufffd\ufffd\ufffd (20) \ufffdThird party\ufffd means a person, a public corporation, including the Oregon Health and Science University and the Oregon State Bar, or a public body, as defined in ORS 174.109, other than a consumer, a controller, a processor or an affiliate of a controller or processor. [2023 c.369 \ufffd1] \ufffd\ufffd\ufffd\ufffd\ufffd 646A.572 Scope and application; exclusions. (1)(a) ORS 646A.570 to 646A.589 apply to any person that conducts business in this state, or that provides products or services to residents of this state, and that during a calendar year, controls or processes: \ufffd\ufffd\ufffd\ufffd\ufffd (A) The personal data of 100,000 or more consumers, other than personal data controlled or processed solely for the purpose of completing a payment transaction;\n\nSource: <https://www.oregonlegislature.gov/bills_laws/ors/ors646a.html>\n", "consumer_volume_threshold": "The personal data of 100,000 or more consumers, other than personal data controlled or processed solely for the purpose of completing a payment transaction", "data_sales_revenue_threshold": "The personal data of 25,000 or more consumers, while deriving 25 percent or more of the person's annual gross revenue from selling personal data", "effective_date": "July 1, 2024", "enforcement": "Attorney General; exclusive authority; civil penalty; no private right of action", "file": "oregon.md", "generated": true, "harvested": "2026-08-12", "id": "oregon", "key_exemptions": "Public corporations and public bodies; HIPAA-covered entities; nonprofit organizations (exempt until July 1, 2025)", "law_name": "Oregon Consumer Privacy Act (OCPA)", "notes": "Oregon does not exclude payment-only data processing from the data-sales threshold \u2014 only from the volume threshold. As of the 2025 amendments, the law also applies to motor vehicle manufacturers regardless of consumer volume thresholds. Oregon had the latest nonprofit exemption expiration (July 1, 2025) and includes a universal opt-out mechanism requirement effective January 1, 2026.", "source_quote": "\ufffd\ufffd\ufffd\ufffd\ufffd (20) \ufffdThird party\ufffd means a person, a public corporation, including the Oregon Health and Science University and the Oregon State Bar, or a public body, as defined in ORS 174.109, other than a consumer, a controller, a processor or an affiliate of a controller or processor. [2023 c.369 \ufffd1] \ufffd\ufffd\ufffd\ufffd\ufffd 646A.572 Scope and application; exclusions. (1)(a) ORS 646A.570 to 646A.589 apply to any person that conducts business in this state, or that provides products or services to residents of this state, and that during a calendar year, controls or processes: \ufffd\ufffd\ufffd\ufffd\ufffd (A) The personal data of 100,000 or more consumers, other than personal data controlled or processed solely for the purpose of completing a payment transaction;", "sources": ["https://www.oregonlegislature.gov/bills_laws/ors/ors646a.html"], "stale_after": "2026-11-10", "state": "Oregon", "statute_citation": "Or. Rev. Stat. \u00a7\u00a7 646A.570 to 646A.589", "threshold_logic": "OR \u2014 during a calendar year, controls or processes either threshold", "title": "Oregon \u2014 US state consumer data privacy laws: applicability thresholds by state", "type": "applicability-threshold", "unverified_fields": "data_sales_revenue_threshold, effective_date, enforcement, key_exemptions, law_name, notes, statute_citation, threshold_logic", "verified": true}
{"asset": "state-data-privacy-applicability-thresholds", "body": "**State:** Rhode Island\n\n**Law name and abbreviation:** Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)\n\n**Effective date:** January 1, 2026\n\n**Consumer volume threshold:** Controlled or processed the personal data of not less than thirty-five thousand (35,000) customers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction\n\n**Revenue-from-data-sales threshold:** Controlled or processed the personal data of not less than ten thousand (10,000) customers and derived more than twenty percent (20%) of their gross revenue from the sale of personal data\n\n**Threshold combination logic:** OR \u2014 during the preceding calendar year did any of the following\n\n**Key exemptions:** State and political subdivision bodies; nonprofit organizations; institutions of higher education; GLBA-regulated financial institutions; HIPAA-covered entities and business associates; national securities associations\n\n**Enforcement mechanism:** Attorney General; no private right of action\n\n**Statute citation:** R.I. Gen. Laws \u00a7\u00a7 6-48.1-1 to 6-48.1-14\n\n**Notes:** Rhode Island uses the term 'customer' rather than 'consumer.' The thresholds (35,000 customers or 10,000 + 20% revenue) are identical to Delaware's and among the lowest in the country. The law applies only to for-profit entities.\n\n> entities that conduct business in the state or for-profit entities that produce products or services that are targeted to residents of the state and that during the preceding calendar year did any of the following: (1) Controlled or processed the personal data of not less than thirty-five thousand (35,000) customers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction. (2) Controlled or processed the personal data of not less than ten thousand (10,000) customers and derived more than twenty percent (20%) of their gross revenue from the sale of personal data.\n\nSource: <https://webserver.rilegislature.gov/Statutes/TITLE6/6-48.1/6-48.1-4.htm>\n", "consumer_volume_threshold": "Controlled or processed the personal data of not less than thirty-five thousand (35,000) customers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction", "data_sales_revenue_threshold": "Controlled or processed the personal data of not less than ten thousand (10,000) customers and derived more than twenty percent (20%) of their gross revenue from the sale of personal data", "effective_date": "January 1, 2026", "enforcement": "Attorney General; no private right of action", "file": "rhode-island.md", "generated": true, "harvested": "2026-08-12", "id": "rhode-island", "key_exemptions": "State and political subdivision bodies; nonprofit organizations; institutions of higher education; GLBA-regulated financial institutions; HIPAA-covered entities and business associates; national securities associations", "law_name": "Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)", "notes": "Rhode Island uses the term 'customer' rather than 'consumer.' The thresholds (35,000 customers or 10,000 + 20% revenue) are identical to Delaware's and among the lowest in the country. The law applies only to for-profit entities.", "source_quote": "entities that conduct business in the state or for-profit entities that produce products or services that are targeted to residents of the state and that during the preceding calendar year did any of the following: (1) Controlled or processed the personal data of not less than thirty-five thousand (35,000) customers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction. (2) Controlled or processed the personal data of not less than ten thousand (10,000) customers and derived more than twenty percent (20%) of their gross revenue from the sale of personal data.", "sources": ["https://webserver.rilegislature.gov/Statutes/TITLE6/6-48.1/6-48.1-4.htm"], "stale_after": "2026-11-10", "state": "Rhode Island", "statute_citation": "R.I. Gen. Laws \u00a7\u00a7 6-48.1-1 to 6-48.1-14", "threshold_logic": "OR \u2014 during the preceding calendar year did any of the following", "title": "Rhode Island \u2014 US state consumer data privacy laws: applicability thresholds by state", "type": "applicability-threshold", "unverified_fields": "effective_date, enforcement, key_exemptions, law_name, notes, statute_citation", "verified": true}
{"asset": "state-data-privacy-applicability-thresholds", "body": "**State:** Tennessee\n\n**Law name and abbreviation:** Tennessee Information Protection Act (TIPA)\n\n**Effective date:** July 1, 2025\n\n**Consumer volume threshold:** During a calendar year, control or process personal information of at least one hundred seventy-five thousand (175,000) consumers\n\n**Revenue-from-data-sales threshold:** Control or process personal information of at least twenty-five thousand (25,000) consumers and derive more than fifty percent (50%) of gross revenue from the sale of personal information\n\n**Revenue floor:** Exceed twenty-five million dollars ($25,000,000) in revenue\n\n**Threshold combination logic:** AND \u2014 requires exceeding $25,000,000 in revenue AND one of the volume thresholds\n\n**Key exemptions:** State and local government entities; HIPAA-covered entities and business associates; GLBA-regulated financial institutions; nonprofit organizations; institutions of higher education\n\n**Enforcement mechanism:** Attorney General; 60-day cure period; no private right of action\n\n**Statute citation:** Tenn. Code Ann. \u00a7 47-18-3201 et seq.\n\n**Notes:** Tennessee has the highest consumer volume threshold (175,000) of any state and requires both a $25M revenue floor AND volume thresholds (like Utah). This makes Tennessee's law one of the narrowest in scope. Tennessee uses the term 'personal information' rather than 'personal data.'\n\n> However, the Tennessee Code Commission is requested to include the headings in any compilation or publication containing this act. SECTION 6. This act takes effect July 1, 2025, the public welfare requiring it.\n\nSource: <https://publications.tnsosfiles.com/acts/113/pub/pc0408.pdf>\n", "consumer_volume_threshold": "During a calendar year, control or process personal information of at least one hundred seventy-five thousand (175,000) consumers", "data_sales_revenue_threshold": "Control or process personal information of at least twenty-five thousand (25,000) consumers and derive more than fifty percent (50%) of gross revenue from the sale of personal information", "effective_date": "July 1, 2025", "enforcement": "Attorney General; 60-day cure period; no private right of action", "file": "tennessee.md", "generated": true, "harvested": "2026-08-12", "id": "tennessee", "key_exemptions": "State and local government entities; HIPAA-covered entities and business associates; GLBA-regulated financial institutions; nonprofit organizations; institutions of higher education", "law_name": "Tennessee Information Protection Act (TIPA)", "notes": "Tennessee has the highest consumer volume threshold (175,000) of any state and requires both a $25M revenue floor AND volume thresholds (like Utah). This makes Tennessee's law one of the narrowest in scope. Tennessee uses the term 'personal information' rather than 'personal data.'", "revenue_floor": "Exceed twenty-five million dollars ($25,000,000) in revenue", "source_quote": "However, the Tennessee Code Commission is requested to include the headings in any compilation or publication containing this act. SECTION 6. This act takes effect July 1, 2025, the public welfare requiring it.", "sources": ["https://publications.tnsosfiles.com/acts/113/pub/pc0408.pdf"], "stale_after": "2026-11-10", "state": "Tennessee", "statute_citation": "Tenn. Code Ann. \u00a7 47-18-3201 et seq.", "threshold_logic": "AND \u2014 requires exceeding $25,000,000 in revenue AND one of the volume thresholds", "title": "Tennessee \u2014 US state consumer data privacy laws: applicability thresholds by state", "type": "applicability-threshold", "unverified_fields": "consumer_volume_threshold, data_sales_revenue_threshold, enforcement, key_exemptions, law_name, notes, revenue_floor, statute_citation, threshold_logic", "verified": true}
{"asset": "state-data-privacy-applicability-thresholds", "body": "**State:** Texas\n\n**Law name and abbreviation:** Texas Data Privacy and Security Act (TDPSA)\n\n**Effective date:** July 1, 2024\n\n**Threshold combination logic:** No numeric consumer or revenue thresholds \u2014 applies to any non-small-business that processes or sells personal data\n\n**Key exemptions:** Small businesses as defined by the United States Small Business Administration; state agencies and political subdivisions; GLBA-regulated financial institutions; HIPAA-covered entities and business associates; nonprofit organizations; institutions of higher education\n\n**Enforcement mechanism:** Attorney General; 30-day cure period; civil penalty up to $7,500 per violation; no private right of action\n\n**Statute citation:** Tex. Bus. & Com. Code ch. 541\n\n**Notes:** Texas is unique among state privacy laws in having no specific numeric consumer or revenue thresholds. Instead, it exempts small businesses as defined by the U.S. Small Business Administration. This means the SBA size standards (which vary by industry) determine applicability rather than a fixed consumer count.\n\n> APPLICABILITY OF CHAPTER. (a) This chapter 16 applies only to a person that: 17 (1)AAconducts business in this state or produces a 18 product or service consumed by residents of this state; 19 (2)AAprocesses or engages in the sale of personal data; 20 and 21 (3)AAis not a small business as defined by the United 22 States Small Business Administration, except to the extent that 23 Section 541.107 applies to a person described by this subdivision.\n\nSource: <https://capitol.texas.gov/tlodocs/88R/billtext/pdf/HB00004F.pdf>\n", "effective_date": "July 1, 2024", "enforcement": "Attorney General; 30-day cure period; civil penalty up to $7,500 per violation; no private right of action", "file": "texas.md", "generated": true, "harvested": "2026-08-12", "id": "texas", "key_exemptions": "Small businesses as defined by the United States Small Business Administration; state agencies and political subdivisions; GLBA-regulated financial institutions; HIPAA-covered entities and business associates; nonprofit organizations; institutions of higher education", "law_name": "Texas Data Privacy and Security Act (TDPSA)", "notes": "Texas is unique among state privacy laws in having no specific numeric consumer or revenue thresholds. Instead, it exempts small businesses as defined by the U.S. Small Business Administration. This means the SBA size standards (which vary by industry) determine applicability rather than a fixed consumer count.", "source_quote": "APPLICABILITY OF CHAPTER. (a) This chapter 16 applies only to a person that: 17 (1)AAconducts business in this state or produces a 18 product or service consumed by residents of this state; 19 (2)AAprocesses or engages in the sale of personal data; 20 and 21 (3)AAis not a small business as defined by the United 22 States Small Business Administration, except to the extent that 23 Section 541.107 applies to a person described by this subdivision.", "sources": ["https://capitol.texas.gov/tlodocs/88R/billtext/pdf/HB00004F.pdf"], "stale_after": "2026-11-10", "state": "Texas", "statute_citation": "Tex. Bus. & Com. Code ch. 541", "threshold_logic": "No numeric consumer or revenue thresholds \u2014 applies to any non-small-business that processes or sells personal data", "title": "Texas \u2014 US state consumer data privacy laws: applicability thresholds by state", "type": "applicability-threshold", "unverified_fields": "effective_date, enforcement, key_exemptions, law_name, notes, statute_citation, threshold_logic", "verified": true}
{"asset": "state-data-privacy-applicability-thresholds", "body": "**State:** Utah\n\n**Law name and abbreviation:** Utah Consumer Privacy Act (UCPA)\n\n**Effective date:** December 31, 2023\n\n**Consumer volume threshold:** during a calendar year, controls or processes personal data of 100,000 or more consumers\n\n**Revenue-from-data-sales threshold:** derives over 50% of the entity's gross revenue from the sale of personal data and controls or processes personal data of 25,000 or more consumers\n\n**Revenue floor:** has annual revenue of $25,000,000 or more\n\n**Threshold combination logic:** AND \u2014 requires annual revenue of $25,000,000 or more AND one of the volume thresholds\n\n**Key exemptions:** Governmental entities; tribes; institutions of higher education; nonprofit corporations; HIPAA-covered entities and business associates\n\n**Enforcement mechanism:** Attorney General; 30-day cure period; no private right of action\n\n**Statute citation:** Utah Code \u00a7\u00a7 13-61-101 to 13-61-404\n\n**Notes:** Utah is the only state that requires BOTH a revenue threshold AND consumer volume \u2014 using AND logic rather than OR. A business must have $25M+ in annual revenue and also meet one of the two volume thresholds. This makes Utah's law the narrowest in scope among all state privacy laws.\n\n> This chapter applies to any controller or processor who: (a) (i) conducts business in the state; or (ii) produces a product or service that is targeted to consumers who are residents of the state; (b) has annual revenue of $25,000,000 or more; and (c) satisfies one or more of the following thresholds: (i) during a calendar year, controls or processes personal data of 100,000 or more consumers; or (ii) derives over 50% of the entity's gross revenue from the sale of personal data and controls or processes personal data of 25,000 or more consumers.\n\nSource: <https://le.utah.gov/xcode/Title13/Chapter61/C13-61_2022050420231231.pdf>\n", "consumer_volume_threshold": "during a calendar year, controls or processes personal data of 100,000 or more consumers", "data_sales_revenue_threshold": "derives over 50% of the entity's gross revenue from the sale of personal data and controls or processes personal data of 25,000 or more consumers", "effective_date": "December 31, 2023", "enforcement": "Attorney General; 30-day cure period; no private right of action", "file": "utah.md", "generated": true, "harvested": "2026-08-12", "id": "utah", "key_exemptions": "Governmental entities; tribes; institutions of higher education; nonprofit corporations; HIPAA-covered entities and business associates", "law_name": "Utah Consumer Privacy Act (UCPA)", "notes": "Utah is the only state that requires BOTH a revenue threshold AND consumer volume \u2014 using AND logic rather than OR. A business must have $25M+ in annual revenue and also meet one of the two volume thresholds. This makes Utah's law the narrowest in scope among all state privacy laws.", "revenue_floor": "has annual revenue of $25,000,000 or more", "source_quote": "This chapter applies to any controller or processor who: (a) (i) conducts business in the state; or (ii) produces a product or service that is targeted to consumers who are residents of the state; (b) has annual revenue of $25,000,000 or more; and (c) satisfies one or more of the following thresholds: (i) during a calendar year, controls or processes personal data of 100,000 or more consumers; or (ii) derives over 50% of the entity's gross revenue from the sale of personal data and controls or processes personal data of 25,000 or more consumers.", "sources": ["https://le.utah.gov/xcode/Title13/Chapter61/C13-61_2022050420231231.pdf"], "stale_after": "2026-11-10", "state": "Utah", "statute_citation": "Utah Code \u00a7\u00a7 13-61-101 to 13-61-404", "threshold_logic": "AND \u2014 requires annual revenue of $25,000,000 or more AND one of the volume thresholds", "title": "Utah \u2014 US state consumer data privacy laws: applicability thresholds by state", "type": "applicability-threshold", "unverified_fields": "effective_date, enforcement, key_exemptions, law_name, notes, statute_citation", "verified": true}
{"asset": "state-data-privacy-applicability-thresholds", "body": "**State:** Virginia\n\n**Law name and abbreviation:** Virginia Consumer Data Protection Act (VCDPA)\n\n**Effective date:** January 1, 2023\n\n**Consumer volume threshold:** control or process personal data of at least 100,000 consumers\n\n**Revenue-from-data-sales threshold:** control or process personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal data\n\n**Threshold combination logic:** OR \u2014 applies to persons that (i) during a calendar year, control or process personal data of at least 100,000 consumers or (ii) control or process personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal data\n\n**Key exemptions:** State and local government bodies; financial institutions or data subject to GLBA; HIPAA-covered entities and business associates; nonprofit organizations; institutions of higher education; employment data and emergency contact information\n\n**Enforcement mechanism:** Attorney General has exclusive authority to enforce; 30-day cure period; civil penalties up to $7,500 per violation; no private right of action\n\n**Statute citation:** Va. Code Ann. \u00a7\u00a7 59.1-575 to 59.1-585\n\n**Notes:** Virginia's law set the template for many subsequent state privacy laws (the 'Virginia model'). No independent revenue threshold \u2014 a business with over $150 million in annual revenue is not in scope unless it also meets the consumer volume thresholds. B2B contacts and employees are excluded from consumer counts per the exemption in \u00a7 59.1-576(C)(14).\n\n> This chapter applies to persons that conduct business in the Commonwealth or produce products or services that are targeted to residents of the Commonwealth and that (i) during a calendar year, control or process personal data of at least 100,000 consumers or (ii) control or process personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal data.\n\nSource: <https://law.lis.virginia.gov/vacodefull/title59.1/chapter53/>\n", "consumer_volume_threshold": "control or process personal data of at least 100,000 consumers", "data_sales_revenue_threshold": "control or process personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal data", "effective_date": "January 1, 2023", "enforcement": "Attorney General has exclusive authority to enforce; 30-day cure period; civil penalties up to $7,500 per violation; no private right of action", "file": "virginia.md", "generated": true, "harvested": "2026-08-12", "id": "virginia", "key_exemptions": "State and local government bodies; financial institutions or data subject to GLBA; HIPAA-covered entities and business associates; nonprofit organizations; institutions of higher education; employment data and emergency contact information", "law_name": "Virginia Consumer Data Protection Act (VCDPA)", "notes": "Virginia's law set the template for many subsequent state privacy laws (the 'Virginia model'). No independent revenue threshold \u2014 a business with over $150 million in annual revenue is not in scope unless it also meets the consumer volume thresholds. B2B contacts and employees are excluded from consumer counts per the exemption in \u00a7 59.1-576(C)(14).", "source_quote": "This chapter applies to persons that conduct business in the Commonwealth or produce products or services that are targeted to residents of the Commonwealth and that (i) during a calendar year, control or process personal data of at least 100,000 consumers or (ii) control or process personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal data.", "sources": ["https://law.lis.virginia.gov/vacodefull/title59.1/chapter53/"], "stale_after": "2026-11-10", "state": "Virginia", "statute_citation": "Va. Code Ann. \u00a7\u00a7 59.1-575 to 59.1-585", "threshold_logic": "OR \u2014 applies to persons that (i) during a calendar year, control or process personal data of at least 100,000 consumers or (ii) control or process personal data of at least 25,000 consumers and derive over 50 percent of gross revenue from the sale of personal data", "title": "Virginia \u2014 US state consumer data privacy laws: applicability thresholds by state", "type": "applicability-threshold", "unverified_fields": "effective_date, enforcement, key_exemptions, law_name, notes, statute_citation", "verified": true}
