What changed — US state consumer data privacy laws: applicability thresholds by state
The change history of US state consumer data privacy laws: applicability thresholds by state: For each US state with a comprehensive consumer data privacy law, the thresholds a business must meet for the law to apply: consumer volume (number of state residents whose data is processed), revenue from data sales (percentage of gross revenue derived from selling personal data), revenue floor (minimum annual revenue), and whether these conditions are combined with AND or OR logic — sourced from the state's own statute. Answers 'does [state]'s privacy law apply to my business', 'what are the CCPA thresholds for 2026', 'which state privacy laws have no revenue threshold', 'how many consumers triggers the Virginia privacy law', 'which states changed their privacy law thresholds in 2026' (Connecticut lowers from 100k to 35k consumers on July 1, 2026, and adds a sensitive-data trigger with no volume floor; Indiana, Kentucky, and Rhode Island took effect January 1, 2026), 'which state has the lowest privacy law threshold' (Montana: 25k consumers), and 'does Utah require both a revenue AND consumer threshold' (yes — the only state using AND logic). As of mid-2026, 20 states have comprehensive consumer privacy laws in effect. No single authority publishes the thresholds for all states — each state's statute defines its own — which is why assembled versions come from compliance-software vendors (Feroot, IAPP, MultiState, PrivacyLawMap). The thresholds spread is wide: consumer volume from 25k (Montana) to 175k (Tennessee); revenue percentage from 0% (Texas, no numeric threshold) to 50% (Virginia model); revenue floor from $0 to $26.6M (California, inflation-adjusted). The AND/OR distinction matters: most states use OR (any threshold triggers the law), while Utah requires both revenue AND consumer volume, and Connecticut (CA) requires meeting one of three distinct paths.
No changes yet since the initial snapshot of . This register is re-checked against its sources on a schedule; a date appears below only when records were added or their values changed, so a quiet stretch means the register itself was quiet, not that nobody looked.
We keep the current verified state of each record, not the value it replaced — so each entry says which records changed and what they now state, never what they said before. Machine subscribers: poll changes.xml (Atom) or changes.json instead of re-fetching the dataset.
— Initial snapshot — 18 records
The first verified snapshot: every record was new on this date. The full register is on the dataset page.