- What they do
- Privacy governance + ISO 27001
- Who they help
- XpertDPO is a privacy governance + ISO 27001 based in UK/Ireland. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Framework AI Governance & Privacy Frameworks
US State Privacy Laws
In the absence of a federal comprehensive privacy statute, US states have passed their own consumer privacy laws, beginning with California's CCPA (2018, amended by the CPRA) and followed by Virginia, Colorado, Connecticut, Utah, and a steady stream of others.
By early 2026 around twenty states had comprehensive laws in force, with Indiana, Kentucky, and Rhode Island taking effect on January 1, 2026 and further effective dates through the year; Alabama's law is reported to take effect May 1, 2027 (verify the current count and dates against a maintained tracker).
The laws share a common shape: consumer rights to access, delete, correct, and port data and to opt out of sale, targeted advertising, and profiling; duties on controllers to publish a privacy notice, minimize data, secure it, contract with processors, and assess high-risk processing; and enforcement by state attorneys general (and in California the California Privacy Protection Agency).
What these laws force into writing is a privacy notice that matches actual practice, a data inventory that supports rights requests, written processor and service provider contracts, data protection assessments for targeted advertising, sale, profiling, and sensitive data processing, a documented method for honoring opt-out signals such as Global Privacy Control, records of rights requests and responses, and (in California) recognized employee training.
Thresholds differ by state and are usually based on state resident counts or revenue from selling data, so many small businesses fall outside some laws and inside others.
Who has to comply
Businesses that process personal data of state residents and meet the state's threshold, typically a count of consumers (often 100,000, lower in smaller states such as 35,000 in Montana or Rhode Island) or a percentage of revenue from data sales. Exemptions commonly cover data already regulated under HIPAA, GLBA, and FCRA, and some states exempt nonprofits or higher education.
Texas has no volume threshold and applies to any non-small business that processes personal data.
What the assessor asks to see
When a regulator inquires or a customer performs due diligence: applicability analysis by state; privacy notice and notice at collection; data inventory and map; processor and service provider contracts; data protection assessments; opt-out mechanisms and GPC handling records; rights-request logs with response times and verification method; sensitive data consent records; data retention schedule; security program summary; training records; data broker registrations where applicable.
Where the requirement sits: CO, VA, CT, TX et al. comprehensive privacy acts
2026 effective dates
Reported effective dates in 2026 include Indiana, Kentucky, and Rhode Island on January 1; Connecticut amendments, Arkansas, and Utah amendments on July 1; and new California data broker registration duties on August 1. Alabama's act was signed April 17, 2026 with an effective date of May 1, 2027. Verify against the IAPP or MultiState trackers, which are updated as laws pass.
What AllyMatter does here
Policy and training-acknowledgment layer.
AllyMatter publishes this site.
Assessors
Who assesses US State Privacy Laws
None. Compliance is enforced by state attorneys general and the California Privacy Protection Agency through investigations and civil actions; there is no certification or licensed assessor.
California's regulations on cybersecurity audits and risk assessments, when in force, will require certain businesses to obtain an independent audit and file certifications with the agency (verify the current CPPA regulation status and effective dates).
No firm has claimed a US State Privacy Laws assessor listing yet. Claim yours →
Consultants
Who helps with US State Privacy Laws
A large ecosystem of privacy law firms, consultancies, and consent and rights-request platform vendors. Typical engagements map which states apply, build the data inventory, draft notices and processor contracts, stand up rights-request workflows, and prepare data protection assessments.
Engagements run from a few weeks for a single-state update to several months for a multi-state program.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
Software
Tools for US State Privacy Laws
Tools that name this framework in their own material.
Related reading
- US State Privacy Legislation TrackerThe reference chart and map for which states have comprehensive laws, tracking fourteen provisions that recur across them.IAPP
- New year, new rules: US state privacy requirements coming online as 2026 beginsExplains which obligations newly bite each January and how the requirements differ state to state.IAPP
- 20 state privacy laws in effect in 2026: key dates and changesDate-by-date view of when each state law takes effect and where amendments have shifted the goalposts.MultiState
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for US State Privacy Laws
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of US State Privacy Laws in AllyMatter
Approve the policies US State Privacy Laws asks for, keep every version, and record a named acknowledgment from each person who has to read them.