Back to Blog
CCPA

The US State Privacy Patchwork in September 2026: 20+ Laws, One Operational Problem

Twenty-plus comprehensive state privacy laws are now in force, and the 'one banner, all states' pitch has broken. This piece maps the September 2026 state of play — applicability thresholds, opt-out signals (GPC + GPP), sensitive-data definition drift, the right-to-correct gap, minors' data rules, and enforcement priorities — and flags where the patchwork has become a real operational hazard.

KaviyaAugust 28, 202614 min read
The US State Privacy Patchwork in September 2026: 20+ Laws, One Operational Problem

Twenty States, Four Opt-Out Signals, One Operational Problem

The 'one banner, all US states' pitch that carried consent management sales through 2023 and 2024 has been rendered obsolete by the twenty-plus comprehensive state privacy laws now in force. September 2026 is a useful moment to take inventory: which laws are live, how their rights and definitions differ, and where the divergence has broken compliance stacks that were promised to be portable.

The complexity is not just quantitative — more states means more forms to fill out, and that is manageable — but qualitative: the laws differ on which processing triggers rights, how sensitive data is defined, which opt-out signals must be honoured, whether the right to correct exists, and what age gates apply. Programmes that treated CCPA as the compliance floor and expected everything else to fall inside it are now failing in Texas and Colorado where the ceiling is higher, and in New Jersey where the health-data definition is broader. This piece maps the September 2026 state of play and highlights where the patchwork has become a real operational hazard.

The Live-Laws Matrix (September 2026)

As of September 2026 the following comprehensive state privacy laws are in force: California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Iowa (ICDPA), Indiana (INCDPA), Tennessee (TIPA), Montana (MCDPA), Oregon (OCPA), Texas (TDPSA), Delaware (DPDPA), New Hampshire (NHDPA), New Jersey (NJDPA), Kentucky (KCDPA), Maryland (MODPA), Minnesota (MCDPA — different from Montana), Rhode Island (RIDPA), Nebraska (NDPA), and additional laws that took effect through 2025 and 2026.

Each law has its own applicability thresholds (typically revenue or number of consumers processed), its own set of rights, and its own enforcement authority. Some (Colorado, California) empower rulemaking authorities that have been active. Others (Virginia, Utah) enforce entirely through the state Attorney General. Cure periods vary from immediate enforceability (California) to fixed periods that have started to expire in Colorado and Connecticut. The compliance floor is now higher than any single law — and the ceiling in Colorado, California, and (arguably) Maryland is meaningfully higher than the average.

Applicability Thresholds Have Consequences

The revenue and consumer-count thresholds each state chose determine which businesses are covered, and the divergence has practical consequences. A mid-market SaaS with $20M annual revenue and 40,000 US consumers is in scope in California, Colorado, Connecticut, Virginia, Texas, Oregon, New Jersey, Delaware, and New Hampshire — but not necessarily in Utah (higher revenue floor) or Iowa (higher consumer count).

Multistate applicability determination is now non-trivial. The pragmatic model is to treat any state with a threshold your business exceeds as in scope for that state's residents, with residency determination based on billing address or IP-based inference for anonymous surfaces. Programmes that scoped to CCPA alone missed the Colorado and Texas obligations for their non-Californian US users. The corollary: a data inventory that does not include jurisdiction (residency) as an attribute of the data subject cannot answer the applicability question at all. See our complete data inventory guide for the base structure.

Opt-Out Signals: The GPC + State-Signal Reality

The obligation to honour a browser-level opt-out signal has become a real compliance requirement in California, Colorado, Connecticut, Oregon, Delaware, New Jersey, Texas, and others. The dominant signal is Global Privacy Control (GPC). California's regulations effectively require it. Colorado's rules recognise it. Others have adopted or are converging on GPC-compatible signals.

The operational reality is messier. GPC is not universally implemented by browsers in ways that make it reliably detectable. IAB Global Privacy Platform (GPP) strings are the industry response and add another layer of complexity. Some states have suggested willingness to accept state-specific signals in the future. The current best pattern: honour GPC as an opt-out for sale, sharing, and targeted advertising (where recognised by the state law); update the CMP to write both a stored consent decision and a GPP string that downstream vendors read; and log the receipt of the opt-out signal per request with timestamp, source, and effective purpose scope. Enforcement actions in California have already targeted businesses that recorded no evidence of receiving or honouring GPC.

Sensitive Data Definition Drift

'Sensitive data' is not a uniform category across state laws, and the drift has created real ambiguity for businesses that assumed a common definition. California treats precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, contents of communications, genetic data, biometric information processed for unique identification, health data, sex life or sexual orientation as sensitive. Colorado's list is close but not identical.

Maryland's law significantly expands the sensitive-data category, particularly around consumer health data, financial account data, and immigration or citizenship status. New Jersey similarly expanded the health-data definition beyond the traditional 'derived from HIPAA-covered treatment' scope. Texas treats certain categories differently and has an unusual small-business exemption structure. The practical fix is a sensitive-data tag on personal data attributes in the inventory, with the tag defined by the strictest applicable state — treat as sensitive under all laws if any applicable state calls it sensitive. This over-classifies for some laws, but the alternative (state-conditional tagging) is unworkable at scale.

The Right-to-Correct Gap

Not every state law includes a right to correct inaccurate personal data. California, Colorado, Connecticut, Virginia, Oregon, Delaware, New Jersey, Maryland, and others do. Utah, Iowa, Tennessee, Indiana, and a few others do not — or make it discretionary.

For the businesses that built DSR intake surfaces before this variance was well understood, the effect is a routing problem: a correction request from a Utah resident does not obligate you the way a correction request from a Colorado resident does, but if your intake form does not detect the state, you either process every correction (over-serving Utah, potentially reducing data integrity for others) or process none (under-serving Colorado, creating enforcement exposure). The clean fix is a state-aware DSR router that resolves the applicable rights per request based on the resident's state, and returns a valid response — including 'this jurisdiction does not grant this right' where accurate — with reasoning that would survive an AG's read.

Verified vs Non-Verified Request Thresholds

Every state law requires businesses to verify the identity of a DSR requester with reasonable certainty scaled to the sensitivity of the data. What 'reasonable' means varies. California's regulations set out specific criteria including how many data points to match, when to require sworn declarations, and how to handle authorised agents. Colorado similarly has specific rules. Others rely on more general standards enforced by AG interpretation.

The operational reality is that a verified-request threshold that satisfies California is generally defensible across states, but the reverse is not true. A weak verification standard tuned to Iowa may create an over-disclosure risk in California — releasing personal data to the wrong requester is potentially worse than declining a legitimate request. Standardise the verification workflow to the strictest applicable rules and document the criteria met per request; the audit trail is what defends the decision, not the abstract policy. See our DSR automation guide for the process pattern.

Universal Opt-Out and the CMP Rework

California's Universal Opt-Out Mechanism (UOOM) rules, expanded through subsequent CPPA regulations, have effectively created a floor: businesses must honour the opt-out via a machine-readable signal, and the CMP must reflect the signal in its UI so consumers can see their choice was received. Colorado, Connecticut, and others have adopted or are converging on the same expectation.

Many CMPs deployed in 2023 and 2024 did not honour GPC by default and did not surface the received-signal state in the UI. Retrofitting has been more work than expected: the CMP needs to detect the signal before rendering the banner, suppress the 'accept' path for signal-covered purposes, reflect the signal state in the preference centre, and persist an event log that shows both the signal receipt and the resulting consent state. See our cookie consent what changed and consent fatigue banner design pieces for the design pattern. The businesses still shipping a 'first accept, then honour GPC' pattern are exposed; the AG has been asking.

Minors' Data and the Age-Gate Trap

Age-related rules diverge significantly. California requires opt-in consent for the sale or sharing of personal information of consumers aged 13-15, and parental consent for under-13s. Connecticut similarly. Some states extend affirmative consent requirements to targeted advertising for minors. Maryland, New Jersey, and others include specific minor-data restrictions with slightly different age thresholds.

Any business with users who might be minors — which is most consumer-facing businesses — now needs an age-gate that produces evidence, not just a checkbox. The age-inference model (using signals from the account) is fragile if not backed by an actual attestation. Verifiable parental consent workflows built for COPPA (under-13) do not necessarily satisfy state-law requirements for 13-15-year-olds. This is one of the harder areas of the patchwork, and honestly best handled by an over-inclusive design: if any signal suggests a user may be a minor, engage the age-gate and evidence path proactively.

Enforcement Reality: Who Is Actually Fining Whom

Enforcement has been most active in California, where both the AG's office and the CPPA have brought cases with published settlements, and increasingly in Colorado, Connecticut, and Texas. Common enforcement patterns: failure to provide required disclosures on the website, failure to honour opt-out signals, dark patterns in consent flows, inadequate response to DSRs, and inadequate contracts with service providers.

Fine sizes have varied but the trend is up. The reputational cost of a public settlement in a state that publishes them typically exceeds the fine amount. Businesses that treat enforcement as a diffuse threat, betting on being ignored, are increasingly wrong — state AGs share intelligence, and a filing in one state often precedes similar filings elsewhere. The pragmatic risk assessment now weighs enforcement probability by state, and California, Colorado, Texas, and Connecticut sit at the top of the probability list for most sectors.

The Contracts Reality: Service Provider vs Processor

State laws differ on the exact terms required in contracts with service providers or processors. California's specific service-provider contract terms include restrictions on retention, use, and disclosure. Colorado has similar requirements plus specific processor terms. Virginia, Connecticut, and others largely follow the same shape but with terminology variances.

The practical consequence is that a single processor addendum has to satisfy the union of state requirements — the strictest terms apply. Contracts drafted only against California's rules typically miss Virginia's processor obligations. Contracts drafted only against Virginia miss California's specific service-provider restrictions. The clean fix is a multi-state processor addendum template that is the union of applicable requirements, revised twice a year as new state laws take effect. See our vendor risk management guide for the base pattern.

The Case for Federal Preemption (and Why It Won't Save You)

The argument for federal preemption of state privacy laws has been made repeatedly, most recently around comprehensive proposals that would supersede state laws in favour of a single national standard. Even in the best case, federal preemption would take years to enact and years more to implement, and the state laws currently in force will remain in force during any transition.

More importantly, a federal law that meaningfully preempts state law is unlikely to please the states with the strictest regimes (California, Colorado, Maryland), which have consistently opposed weaker preemption proposals. The operational reality: assume the patchwork is permanent for at least the medium term. Build systems that treat state applicability as data, resolve rights and definitions per state, and stay flexible against year-on-year additions. Betting on federal preemption to simplify the compliance burden is a losing bet.

Where to Focus Your Q4 2026 Programme

For the fourth quarter of 2026, prioritise four things. First, verify your CMP honours GPC and any state-specific signals with logged evidence — this is where enforcement is heaviest. Second, close the state-aware DSR router gap so requests get the rights their jurisdiction actually grants. Third, review the sensitive-data classification against the strictest applicable state list and re-tag inventory. Fourth, roll updated processor addendums with any US-facing vendor that has not been through a contract refresh in the last twelve months.

Beyond these, keep an eye on the states with 2027 effective dates (bills that have passed but not yet come into force), and pre-plan the applicability review. The patchwork will keep growing — Rhode Island, Kentucky, and Nebraska are recent additions; more will follow. The businesses that will run this cleanest are the ones that treat multistate compliance as a data problem and instrument accordingly, not the ones trying to keep a mental map.

Automate your privacy compliance

See how TruePrivacy can handle DSRs, consent, and breach response — all in one platform.

Free 14-day trial · No credit card required · Setup in minutes