"Do state privacy laws apply to my business?" is not actually one question. It is twenty separate questions, one per state with a comprehensive privacy law on the books, and each state runs its own test with its own thresholds. A business can clear California's bar and miss Colorado's entirely, or the other way around, without changing anything about how it operates. Treating "state privacy law" as a single yes-or-no gate is the single most common mistake businesses make when they first try to figure out where they stand, and it is the reason so many companies end up either wildly overbuilding their compliance program or missing a state that genuinely applies to them.
This guide is not another list of which states have passed a law. See our full tracker of US state privacy laws for that. This is the decision framework: what actually determines whether a given state's law reaches your business, and why the answer can be different for two businesses that look nearly identical on paper.
Every state's test starts with the same first question
Before any threshold matters, every comprehensive state privacy law asks a version of the same gating question: does your business do business in that state, or target that state's residents. This is a lower bar than it sounds. Selling to consumers anywhere in the state, operating a website that residents can and do use, or otherwise conducting business that reaches state residents is generally enough to clear this first step. You do not need a physical office, a state-registered entity, or employees in the state.
This step rarely eliminates anyone. A business with any meaningful number of customers or website visitors from a given state almost always clears it. The real filtering happens at the next step, and that is where the laws stop looking alike.
The three variables that actually decide the rest
Once the "do you touch this state" question is answered yes, every comprehensive state privacy law narrows further using some combination of three variables. Which combination a state chose is what makes one state's law reach a business that another state's law does not.
Consumer or household count. How many residents of the state does your business control or process personal data for in a year. This is the backbone of the most common model, used by Virginia and most of the states that followed its template: a business is covered if it controls or processes the personal data of 100,000 or more state consumers, or of 25,000 or more consumers if it also derives over half its gross revenue from selling personal data. A handful of states, Utah among them, add a straight annual revenue floor on top of that consumer-count test, so a small business processing a large number of records still falls outside the law if its total revenue sits below that floor.
Revenue derived from selling data. Several states fold this into the consumer-count test as an alternate path in rather than a separate gate, the way Virginia's 25,000-consumer prong does. California's CCPA treats it as one of three fully independent thresholds instead, so a business can be covered purely because it sells or shares data heavily, regardless of its overall size.
A flat revenue floor, or no numeric test at all. California uses a straightforward revenue number, $26,625,000 in annual gross revenue as of the current inflation-adjusted figure, as one of its three independent thresholds. Texas takes a completely different approach: its Data Privacy and Security Act has no consumer-count or revenue-derived-from-sales threshold at all. Instead, it exempts businesses that qualify as a "small business" under the US Small Business Administration's own size standards for that business's industry, standards that vary by sector and are based on either revenue or employee count depending on the industry code. A Texas business can be covered by the law while processing far fewer than 100,000 residents' records, purely because it is not small enough to qualify for the SBA exemption.
Running the test as a flowchart
Because these are genuinely three different shapes of test, not one test with different numbers plugged in, it helps to treat "which model does this state use" as the first branch, before checking any specific figure.
Run this once per state where you have a meaningful number of residents as customers or users, not once for your business overall. The output is not a single answer, it is a state-by-state map, and that map is what your privacy policy actually needs to reflect.
Four states, four different tests
The three variables above combine into a handful of genuinely distinct models in practice. These four states illustrate the range.
How four states decide who is covered
| California (CCPA) | Virginia-style states | Texas (TDPSA) | Florida (FDBR) | |
|---|---|---|---|---|
| What triggers coverage | Any one of three thresholds | Consumer-count threshold | Not exempt as an SBA small business | Revenue plus specific activity |
| Revenue floor | $26.6M | None in most states | None, SBA standard applies instead | $1 billion |
| Consumer-count floor | 100K, or 50%+ revenue from sales | 100K, or 25K + 50%+ revenue from sales | None | None |
| Who it typically reaches | Large and many mid-size CA businesses | Most mid-size consumer businesses | Anything above small-business size | A handful of very large platforms |
Florida's Digital Bill of Rights is the extreme case worth naming directly. Its $1 billion revenue floor means it is, in practice, a law aimed at a small number of very large platforms rather than the broad mid-size-business base the other three models reach. A Florida-based business doing $50 million a year, well above CCPA's threshold, sits entirely outside its own state's privacy law because Florida's bar sits so much higher.
Why a business can be in scope in one state and out in its neighbor
Picture a subscription software company with 60,000 total customers spread across the country, $8 million in annual revenue, and no business model built around selling customer data to third parties.
Against California's test, that business clears none of the three thresholds. Revenue is well under $26.6 million, it is nowhere near 100,000 California consumers even if every customer were Californian, and it does not derive revenue from selling personal information. CCPA does not apply.
Against a typical Virginia-style state, the outcome depends entirely on how those 60,000 customers are distributed. If 15,000 of them are Colorado residents, that is below the 100,000-consumer threshold and below the 25,000-consumer alternate path, so Colorado's law does not reach this business either. But if the company's Colorado customer count were closer to 30,000 and even a modest share of its revenue came from a data-sharing arrangement with an ad network, it could cross the 25,000-consumer-plus-revenue-share path that California's test does not have an equivalent for at that size.
Against Texas, the analysis is not about consumer count at all. It is about whether this company qualifies as a small business under the SBA's size standard for its industry. A software company with $8 million in revenue could easily exceed the applicable SBA revenue-based size standard for its specific NAICS code, which would put it in scope for Texas residents regardless of how few of them it actually has, an outcome that looks unintuitive next to the consumer-count logic every other state in this example just used.
That is the entire reason a single "are we covered" answer does not exist. The same business can be squarely outside California's law, borderline in Colorado depending on customer distribution, and in scope in Texas for a reason that has nothing to do with how many Texans it actually serves.
The numbers that actually decide it
The carve-outs that narrow this further
Two more layers sit on top of the size and revenue tests above, and both differ by state in ways worth checking before assuming a threshold result is final.
Sector-specific data is exempted, sometimes entity-wide, in most of these laws. Personal data already regulated under HIPAA, or held by a HIPAA-covered entity or its business associates, is commonly excluded, as is data covered by the Gramm-Leach-Bliley Act's financial-institution rules. A healthcare provider or a bank is not automatically exempt from every state privacy law entirely, but the specific data covered by those federal schemes usually is, which narrows what a covered business actually has to disclose even when the law technically applies to it.
Nonprofit treatment is not consistent across states, and this is one of the more commonly assumed-wrong facts in this whole area. California's CCPA does not apply to genuine nonprofits at all, since the statute's definition of "business" requires an entity organized for profit. Several other states do not carry the same blanket exemption. Colorado's Privacy Act, notably, does not categorically exempt nonprofits the way CCPA does, so an organization that assumes its nonprofit status clears it everywhere can be wrong the moment it checks a state that does not share California's carve-out.
Turning this into a per-business checklist
The practical version of this whole framework is a short, repeatable process rather than a one-time lookup. Build a rough list of which states your customers or users actually come from, and how many in each. For any state with meaningful volume, identify which of the three test models that state uses, revenue-first like California, consumer-count like Virginia, or small-business-exemption like Texas, and run that state's specific figures against your own. Check whether the data in question falls under a sectoral carve-out like HIPAA or GLBA before assuming a threshold result settles the question. Then revisit the whole exercise on a schedule, not just once: revenue grows, customer bases shift geographically, and CCPA's own dollar thresholds are adjusted for inflation every two years, so a business that sat outside every state's law at launch can cross a line later without any change in what it actually does.
Once you know which states actually apply, our Privacy Policy Generator lets you select the jurisdictions your business operates in and assembles the CCPA and other state-specific disclosures those laws require, so the policy itself does not have to be drafted from scratch once the applicability question is settled. For the underlying scope test each individual law relies on in more depth, see our companion guides on GDPR for US companies and CCPA versus GDPR applicability.
The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.