By Lucy Thomas-Animashaun, Cyber Strategy & Governance, Risk, and Compliance (GRC)
U.S. privacy laws are fragmented and getting more complex. As of January 1, 2026, 19 states have enacted their own privacy regulations, with more on the way. There is still no federal privacy law, leaving businesses to navigate overlapping state requirements.
Many organizations assume privacy compliance is just a California issue or something they can “figure out later.” Then reality hits: a data subject request they can’t fulfill or a notice from a state attorney general asking questions they can’t answer.
What Are State Privacy Laws?
State privacy laws give individuals control over their personal data. These rights typically include:
- Asking companies what data they hold
- Requesting deletion or correction
- Opting out of data sales or targeted advertising
California started the trend in 2020 with the Consumer Privacy Act (CCPA). Since then, states like Virginia, Colorado, Connecticut, Utah, and 14 others have passed their own versions. Some laws are stricter than California’s; others are more business-friendly. Every state has its own approach with different compliance thresholds, definitions of “personal data,” consent rules, and enforcement mechanisms.
For businesses operating nationally, this means complying with all of them at once.
Three More States Coming in 2026
- Indiana: Follows the Colorado/Virginia model; no private right of action.
- Kentucky: Includes carve-outs for certain industries.
- Rhode Island: Applies to businesses processing data on 35,000 residents (about 3% of the state population).
Does This Apply to Your Business?
Most states set compliance thresholds based on data volume or revenue. For example:
- Processing data on 100,000+ residents
- Deriving significant revenue from data sales
Location doesn’t matter. If you sell to Virginia residents, Virginia’s law applies even if your headquarters is in Texas. Businesses can start the year under the threshold and cross it by Q3. Tracking is essential; guessing is risky.
What Rights Do Individuals Have?
Common rights include:
- Access: Know what data is collected, its source, and who it’s shared with
- Deletion & Correction
- Data Portability
- Opt-Out of sales or targeted advertising
Companies usually have 30–45 days to respond, requiring scalable processes:
- Verify identity
- Locate data across systems (CRM, marketing tools, analytics, backups)
- Fulfill the request
- Document everything
Example: An online retailer receives an email: “I want to know what data you have on me.” That triggers a 30-day clock to gather data from e-commerce, marketing automation, analytics, customer service, and advertising partners, then deliver it securely. If the follow-up says “Delete all of it,” the company must validate the request, remove data from systems, notify vendors, and prove compliance.
Manual processes break down when 10 requests arrive in one week.
Opt-In vs. Opt-Out: Why It Matters
- Opt-Out: Companies can collect and use data unless individuals say no. This is the U.S. default.
- Opt-In: Companies need explicit consent before collecting data. Required for sensitive data like health, biometrics, precise location, and children’s data.
For businesses, this means:
- Consent mechanisms must be built in
- Checkboxes not pre-checked
- Toggles default to “off”
- Clear language explaining what’s being asked
Opt-in rates are lower, but consent is more meaningful—people who opt in actually want what’s offered.
The Data Broker Problem
Data brokers compile extensive profiles—shopping habits, health issues, income, even pregnancy status—from public records, online activity, loyalty programs, and apps. They sell this data to advertisers, employers, insurers, and landlords.
Consumers aren’t the customer; they’re the product.
States are starting to regulate brokers:
- Vermont requires broker registration
- Some states allow one request to delete data across all registered brokers
If your business buys third-party data, vendor compliance matters. If the broker isn’t compliant, your business is exposed.
Vendor Relationships Create Obligations
Even with strong internal processes, non-compliant vendors create risk. Most state laws require Data Processing Agreements (DPAs) covering:
- What data is shared
- Permitted uses
- Retention periods
- Breach protocols
- Handling of data subject requests
Before onboarding new vendors or renewing contracts, address privacy obligations. Review existing agreements regularly.
The Consequences Are Real
- Fines: Thousands to tens of thousands per violation; violations add up fast
- Private rights of action: Some states allow class-action lawsuits
- Reputational damage: Privacy violations make headlines, erode trust, and impact recruiting and sales for years
- Operational costs: Investigations, remediation, PR crisis management, legal fees
It’s far cheaper to get this right upfront.
Where Businesses Go Off Course
- Waiting for a complaint before acting
- Treating compliance as a one-time project
- Ignoring vendor compliance
- Failing to document processes
- Assuming small size means exemption
How to Get on the Right Track
- Map customer locations against state thresholds
- Complete a data inventory: what’s collected, where it’s stored, who has access
- Update privacy policies in plain language
- Build systematic data subject request workflows
- Review and update vendor contracts
- Train all teams—sales, support, marketing, not just IT and legal
- Document everything: policies, procedures, training, fulfilled requests
Building a privacy program takes time—usually a few months to reach baseline. Start now, not during a crisis.
If SOC 2 or ISO 27001 Is Already in Place
Leverage existing frameworks:
- Data inventory, access controls, vendor management often overlap
- Expand vendor risk assessments to include privacy
- Integrate privacy into GRC programs, not as a standalone initiative
How Arcova Helps
At Arcova, we guide businesses across healthcare, finance, retail, tech, and manufacturing through this exact challenge.
- We start by understanding your business — data, systems, risk tolerance
- We prioritize investments for practical, sustainable compliance
- Our GRC team connects privacy to existing compliance work
- Our Security Architecture team builds privacy into systems
- Our Cyber Fusion Center and Incident Response teams support when issues arise
We know what works because we’ve seen what doesn’t.
Bottom Line
State privacy laws aren’t going away. More states are passing them, enforcement is intensifying, and international laws may add complexity. Businesses that act now can turn privacy into a competitive advantage.
Privacy is about trust and readiness. When something goes wrong — and it will — companies with strong privacy programs respond quickly and protect their reputation.
Unsure where you stand? That’s normal. The landscape is complex. Contact Arcova to assess your current privacy posture and build a roadmap that works.
