Privacy Podcast Episode Three: State of Confusion: Navigating the U.S. Privacy Law Maze
Key Takeaways
- U.S. privacy compliance has become significantly more complex due to the rapid growth of state consumer privacy laws, each with unique thresholds, exemptions, rights, and definitions.
- California remains the most stringent and operationally impactful state, especially because it regulates businessātoābusiness and employee data, unlike most other states.
- Many states follow similar patterns, but critical distinctionsāsuch as the definition of āsale,ā applicability thresholds, and treatment of sensitive dataāsubstantially affect compliance programs.
- Two competing approaches have emerged: the āRace to the Topā (oneāsizeāfitsāall) model and the āDifferent Strokesā (jurisdictionāspecific) framework. Most companies will land somewhere between the two.
- Even perfect compliance with state privacy laws does not shield companies from litigation risks under older, repurposed laws such as the California Invasion of Privacy Act (CIPA) and the Video Privacy Protection Act (VPPA).
- Organizations should revisit their website tracking practices, cookie consent strategies, vendor contracts, and arbitration clauses to reduce exposure to these nonāprivacyālaw threats.
- The privacy landscape continues to evolve quickly, and businesses should continuously monitor developments, update internal processes, and refine compliance strategies.
- Link to Cover Page with Āé¶¹Ö±²„ās U.S. State Comprehensive Consumer Data Privacy Law Comparison Chart: /insights/publications/2026/01/us-state-consumer-data-privacy-laws/
Link to Āé¶¹Ö±²„ās U.S. State Comprehensive Consumer Data Privacy Law Comparison Chart: /wp-content/uploads/2026/01/U.S.-State-Comprehensive-Consumer-Privacy-Law-Comparison-Chart_V16.pdf
Introduction
If you are a company operating across the United States today, you are navigating one of the most complex privacy regulatory environments in the world. Unlike the European Union, which has a single, comprehensive privacy framework in the General Data Protection Regulation (GDPR), the U.S. has no federal privacy law governing the collection and use of personal information. Instead, states have taken the lead ā creating a fastāgrowing, often contradictory patchwork of rules that can create compliance challenges even for sophisticated businesses with strong privacy practices.
In the State of Confusion: Navigating the U.S. Privacy Law Maze episode of Āé¶¹Ö±²„ & Lardnerās Privacy podcast, attorneys Sam Goldstick and Alex Misakian from Āé¶¹Ö±²„ās Technology Transactions, Cybersecurity & Privacy Practice Group broke down this maze with clarity, humor, and practical insights. Their discussion covered the evolution of state privacy laws, the nuances that distinguish them, and the operational decisions companies must make to remain compliant. They also explored why, even when companies āget privacy right,ā they are still vulnerable to lawsuits under older statutes that predate the modern internet.
The Rise of the State-Based Privacy Regime
When the GDPR took effect in 2018, it redefined expectations worldwide for data protection. That same year, California passed the California Consumer Privacy Act (CCPA) ā the first comprehensive consumer privacy law in the U.S., later amended and expanded into the California Privacy Rights Act (CPRA). Californiaās law set the tone, and over the following years, more than 20 additional states enacted their own privacy statutes.
As Goldstick noted, the U.S. privacy landscape today is defined by similarity on the surface but divergence in the details. All these laws grant certain consumer rights ā like the right to access personal data and the right to delete it ā but they implement these rights differently. Each state uses its own definitions, exemptions, applicability thresholds, timelines, and obligations.
This divergence is not merely academic. It determines whether your business must comply, how operationally burdensome compliance will be, which data must be protected, and how companies must respond to consumer requests.
Despite calls for a federal privacy law, disagreements over preemption and private rights of action have stalled progress in Congress. In the absence of federal legislation, states continue to fill the void.
California: The Most Impactful State in the United States
California remains the heavyweight in U.S. privacy law. It enforces some of the strictest requirements and includes several features other states do not.
A Standalone Revenue Threshold
California is the only state whose privacy law applies when a business meets a standalone revenue threshold ā $26,625,000 (inflation-adjusted from the original $25M) in annual gross revenue ā regardless of how many consumersā data it processes. This threshold means many businessātoābusiness companies and nonāconsumerāfacing organizations are subject to the law.
Employment and B2B Data Coverage
Most states limit their consumer privacy laws strictly to āconsumers.ā California applies its law to:
- Employees
- Job applicants
- Contractors
- Business representatives/contacts
This dramatically expands compliance obligations for HR teams and sales operations, especially for national companies that meet Californiaās applicability threshold.
Opt-Out vs. Opt-In for Sensitive Data
Many states require optāin consent to process sensitive data. California instead generally restricts businesses from using or disclosing residentsā āsensitive personal informationā beyond those purposes specifically enumerated in the CPRA (and does not require covered businesses to obtain prior opt-in consent from individuals), making the CPRA surprisingly less stringent than the vast majority of other existing state consumer privacy laws in this respect. But in nearly every other regard ā enforcement, thresholds, rights, and scope ā California remains the most complex state to comply with.
For any business evaluating its privacy compliance program, understanding Californiaās operational impact is essential.
Baseline States: The Virginia Model and Its Variations
Outside of California, many states have enacted laws modeled on the Virginia Consumer Data Protection Act (VCDPA). These ābaseline statesā include:
- Virginia
- Indiana
- Kentucky
- Tennessee
- Texas
- Nebraska
- Rhode Island
These baseline states generally provide:
- Right to access
- Right to delete
- Right to correct
- Right to portability
- Right to opt out of sales
- Right to opt out of targeted advertising (or āsharingā under the CPRA)
- Right to opt out of profiling in certain contexts
But, as Misakian explained, even these āsimilarā states include differences that can create major compliance challenges.
Key Distinctions Among State Privacy Laws
Definition of āSaleā
Many states adopt Californiaās broad definition of āsale,ā which means sharing personal data for āvaluable considerationā, even if no money is exchanged. Under this definition:
- Thirdāparty analytics
- Targeting cookies
- Pixelābased ad tools
- Crossācontext behavioral advertising
ā¦may be considered a āsale,ā requiring specific disclosures and optāout rights.
Some states, however ā such as Virginia and Indiana ā take a narrower view, requiring monetary consideration for a sale to occur.
This single definitional difference can dramatically alter compliance strategies for cookies, pixels, and analytics tools.
Applicability Thresholds
States diverge sharply in when their laws apply.
- California: Standalone revenue threshold.
- Texas & Nebraska: No numerical thresholds; if you do business in the state and are not a small business under federal rules, the law applies.
- Others: Consumerācount thresholds ranging from 35,000 to 175,000 residents.
Connecticut is especially notable: starting July 1, 2026, its threshold is so low that many companies will qualify unexpectedly.
Exemptions
Differences in exemptions create significant compliance headaches, especially for financial services, healthcare, and utilities.
Examples:
- Some states exempt GLBAācovered financial institutions entirely.
- Others exempt only GLBAācovered data, not the entity.
- Some exempt utilities, while others do not.
- Some exempt nonprofits, while others regulate them.
A business subject to one stateās law may be exempt from anotherās, even if its operations are identical.
Consumer Rights & Timelines
Response timelines also vary:
- Some states require responses within 45 days
- Others require 30 days
- California requires a 10āday acknowledgment in all cases
Appeal timelines differ as well, creating additional burdens for companies with high request volumes.
Data Rights Variability
Even core privacy rights differ across states.
Examples:
- Iowa offers no correction right.
- Utah does not require optāouts for profiling.
- Oregon and Minnesota require businesses to disclose specific third parties with whom they share information.
These variations may seem small, but they meaningfully impact operations and consumer communications.
Compliance Approaches: One-Size-Fits-All vs. Tailored Models
Goldstick and Misakian debated two primary approaches companies can take when building privacy programs.
Both approaches offer strengths and weaknesses, and most organizations will eventually land somewhere between them.
Approach One: āRace to the Topā
(One-Size-Fits-All)
This approach applies the most stringent requirements from across all applicable states to all consumers, regardless of their state of residence.
Advantages
- Simplifies internal operations
- Reduces risk of misclassification
- Promotes consistency across systems
- Helps futureāproof against new state laws
- Allows companies to market strong privacy protections
- Creates potential legal risk:
By voluntarily applying California rights to all consumers, companies may expose themselves to enforcement if they miss deadlines or mishandle rights requests. - May impose unnecessary obligations:
For instance, treating all consumers as if they are subject to Washingtonās My Health My Data Act would require universal optāin consent for health data ā highly impractical for many businesses.
Employees are less likely to apply the wrong rule because there is only one rule.
Challenges
- Creates potential legal risk:
By voluntarily applying California rights to all consumers, companies may expose themselves to enforcement if they miss deadlines or mishandle rights requests. - May impose unnecessary obligations:
For instance, treating all consumers as if they are subject to Washingtonās My Health My Data Act would require universal optāin consent for health data ā highly impractical for many businesses.
Approach Two: āDifferent Strokes for Different Folksā (Jurisdiction-Specific)
This approach builds ²õ³Ł²¹³Ł±šās±č±š³¦¾±“ھ±³¦ workflows, often supported by geolocation tools, to apply the right rules to the right consumers.
Advantages
- Supports flexibility where it matters
- Avoids overācompliance
- Allows businesses in regulated industries to tailor rules for specific states
- Reduces operational burdens in states with fewer requirements
This method works well for organizations needing to preserve business agility ā for example, healthcare and financial services companies, or businesses whose success depends heavily on data analytics.
Challenges
- More operationally complex
- Requires branching logic
- Higher risk of employee or system error
- Requires rigorous training and internal oversight
Regulators may also perceive inconsistency across jurisdictions as a red flag if programs are not carefully implemented.
Finding the Middle Ground
As both agreed, most companies will adopt a hybrid approach.
For example:
- Apply a uniform set of rights across most states
- But tailor obligations for outlier states like Washington or Texas
- Use a common privacy notice with addendums
- Introduce ²õ³Ł²¹³Ł±šās±č±š³¦¾±“ھ±³¦ overlays only where absolutely necessary
- Preserve flexibility where it materially impacts business operations
This approach reduces overācompliance while avoiding the operational chaos of fully splintered programs.
The Hidden Thread: Non-Privacy-Law Lawsuits
Even perfect compliance with state privacy laws does not protect companies from exposure to an entirely separate and growing category of litigation: claims under older laws not written for modern technologies.
Two statutes in particular have become favorites of the plaintiffsā bar.
The California Invasion of Privacy Act (CIPA)
Originally enacted in 1967 as a wiretapping law, CIPA was never intended to regulate pixels, cookies, chatbots, or web analytics. Yet plaintiffs now argue that:
- When a website uses thirdāparty tools like the Meta Pixel
- And those tools collect browsing or interaction data
- The website operator is āaiding and abettingā thirdāparty eavesdropping
This theory has resulted in hundreds of lawsuits, with statutory damages up to $5,000 per violation or three times actual damages (whichever is greater), plus injunctive relief.
Even nuisance claims can be expensive to resolve.
Although legislative efforts to modernize CIPA exist, progress has stalled. Businesses must assume these lawsuits will continue.
The Video Privacy Protection Act (VPPA)
Passed in 1988, the VPPA was designed to protect video rental records in the era of Blockbuster. Today, plaintiffs argue that:
- A user watching a video clip on a website
- Combined with thirdāparty tracking tools
- Equals unlawful disclosure of āviewing historyā
Courts have entertained this theory, and several large settlements ā including $46 million in 2024 across six major cases ā show how serious the exposure can be.
Industries most at risk include:
- Media
- Retail
- Finance
- Healthcare
- Any website with embedded video and Meta Pixel installed
POST-PODCAST UPDATE: On January 26, 2026, the U.S. Supreme Court granted certiorari in Salazar v. Paramount Global, which may provide clarity on key questions about VPPA standing and scope; until then, VPPA litigation remains a major risk vector.
Risk-Reduction Strategies for These Non-Privacy Laws
To mitigate the risk of CIPA and VPPA lawsuits, Goldstick and Misakian recommend:
- Using YouTube AāFrame players with upfront disclosures
- Implementing robust cookie consent managers
- Conducting website tracking audits
- Reviewing contracts with vendors that receive personal data
- Ensuring arbitration clauses exist in Terms of Use
- Maintaining ongoing monitoring of legal developments
Many clients are surprised to learn what tracking tools are running on their websites. And because litigation theories shift quickly, businesses should treat this as an ongoing compliance area ā not a oneātime review.
The Privacy Compliance Bottom Line
The podcast concluded with three major takeaways for organizations evaluating or maturing their privacy programs:
1. The Privacy Landscape Is Only Getting More Complicated
With over 20 comprehensive state consumer privacy laws currently in effect and more on the way, the patchwork of state privacy laws across the U.S. will remain fragmented for the foreseeable future. Companies cannot rely on federal legislation to unify the rules anytime soon.
2. Your Compliance Approach Must Fit Your Business
Whether you choose a raceātoātheātop approach, a tailored jurisdictionāspecific model, or a hybrid solution, the right choice depends on:
- Your operations
- Your systems
- Your risk tolerance
- Your industry
- The nature of your data
- Your internal resources
3. Even Perfect Compliance Is Not Enough
CIPA and VPPA claims create additional litigation risk, which requires separate riskāreduction strategies beyond privacy law compliance.
Conclusion
State consumer privacy laws have created a dynamic, often dizzying patchwork of requirements that businesses must navigate carefully. Understanding each stateās unique thresholds, definitions, exemptions, and consumer rights is foundational ā but choosing the right approach for your companyās privacy program is equally important.
Whether your organization leans toward a oneāsizeāfitsāall strategy, a more tailored approach, or a hybrid model, thoughtful planning and consistent execution are essential. And because legal threats increasingly arise from older statutes not designed for modern technologies, companies must review their web tracking practices, vendor relationships, and disclosures with equal rigor.
For organizations navigating this complex terrain, Āé¶¹Ö±²„ās Technology Transactions, Cybersecurity & Privacy Practice Group is here to help ā offering practical, actionable guidance grounded in deep experience.
Interested in staying ahead of the latest privacy developments?
Listen to Āé¶¹Ö±²„ās Cybersecurity & Data Privacy Group podcast series, where our attorneys break down evolving regulations, emerging risks, and what they mean for your business.