Twenty. That's how many US states have a comprehensive consumer privacy law in effect as of 2026, and every one of them defines "sale" of data slightly differently.
There is still no federal privacy law. Instead, marketers operating nationally are stitching together compliance across a growing patchwork: California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and Washington all have laws live this year, according to MultiState's 2026 tracker. Indiana, Kentucky, and Rhode Island joined most recently, with Kentucky and Indiana both taking effect January 1, 2026.
Why "just comply with California" doesn't work anymore
For years, the shortcut was simple: meet CCPA/CPRA requirements and you're probably fine everywhere. That shortcut is dying.
Rhode Island's law applies to businesses controlling data of just 35,000 residents, a far lower bar than Indiana and Kentucky's 100,000-resident threshold (MultiState, 2026). That means a mid-size regional business that never triggered California's larger thresholds can still be squarely covered in Rhode Island.
The laws also disagree on what counts as a "sale." Some states, following Virginia's model, define sale narrowly as an exchange for money. Others, following California, include any exchange of data for "valuable consideration," which sweeps in most ad-tech data sharing and cross-device tracking deals.
If your ad tech stack shares data with third parties for targeting, "we don't sell data" is not automatically true across all 20 states even if it's true under a narrow, money-only definition. Check each state's sale definition before publishing that claim in a privacy policy.
Where the real differences show up for marketers
Four areas consistently trip up marketing teams operating across states.
- Opt-out rights for targeted advertising. Most of the 20 states require an opt-out for targeted ads and data sales; a handful (Colorado, Connecticut, and others building on it) also require honoring browser-level opt-out signals like Global Privacy Control automatically, not just a manual form.
- Sensitive data and consent. States increasingly require opt-in consent, not just opt-out, before processing sensitive categories like precise geolocation, health data, or data about minors, with Connecticut and Arkansas tightening minors' protections further in 2025-2026 updates (MultiState).
- Universal opt-out mechanisms. Some states mandate recognizing these signals starting on specific dates; missing the technical implementation is a compliance gap even if your privacy policy language is perfect.
- Right to cure. Several early laws gave companies a window to fix violations before facing penalties; newer laws increasingly drop that grace period entirely, meaning first offenses can now draw fines with no warning shot.
Each of these differences changes what your consent banner, ad pixel firing logic, and email preference center actually need to do, not just what your privacy policy says.
A practical approach: build to the strictest common denominator
Chasing 20 separate compliance configurations is how legal budgets and engineering sprints disappear. The workable approach most privacy counsel now recommends: build your consent infrastructure to the strictest applicable standard, then apply it nationwide.
That means opt-in consent for sensitive data by default, honoring Global Privacy Control signals everywhere, and a data subject request process that meets the shortest response deadline across all your applicable states (many cluster around 45 days, some allow 45+45 extensions, don't assume you get the longer window).
This costs more upfront than building state-by-state exceptions. It costs far less than 20 separate legal reviews every time a state amends its law, which is happening constantly.
Assign one person or a rotating quarterly owner to track state privacy law changes. New states and amendments are arriving multiple times a year now; a static compliance doc from 2024 is already out of date.
How this differs from GDPR and why that still matters
US state laws borrow GDPR's vocabulary, consent, purpose limitation, data minimization, but stay meaningfully weaker in enforcement teeth. GDPR gives regulators authority to fine up to 4% of global annual revenue; most US state laws cap civil penalties per violation, often in the thousands of dollars, with attorney general enforcement rather than a dedicated regulator (except California, which has the CPPA).
If your company already built GDPR-compliant consent flows for EU traffic, you're most of the way to US state compliance structurally. But do not assume GDPR compliance equals US state compliance; the definitions of "sale," "sensitive data," and required disclosures don't map one-to-one.
The takeaway
There is no federal floor yet, so "compliant" now means checking your data practices against a moving 20-state list, not a single national rulebook. Build your consent and data-rights infrastructure once, to the strictest common standard, and you convert 20 separate problems into one manageable system.