Data protection in the USA

The United States has no single privacy law: every state writes its own test of who is covered, and federal rules sit on top by sector. We will count which ones reach you.

 

Consumer request

Ответ на запрос

45 days

45 дней

Notice before action

Окно на исправление

30 days

30 дней

Top state penalty

Потолок взыскания

USD 7,500

7 500 USD

Children's rule

Детское правило

under 13

младше 13 лет

When you need US data protection compliance

You started selling in a second state

Each state writes its own test for who is covered. Crossing one border can put you inside a law you have never read, with its own deadlines.

A letter arrived from an attorney general

Most states give a short window to fix the problem before anything is filed. That window is the cheapest part of the process, and it closes.

Children are using your product

The federal children's rule applies to services aimed at under-13s and to anyone who actually knows a user is that age. It asks for consent before collection, not after.

Your app sells or shares data

Selling data, targeted advertising and profiling are the three activities every state law singles out, and each demands its own opt-out route.

What you get

  • The states whose laws actually cover you
  • A privacy notice that survives all of them
  • Working opt-out routes, including browser signals
  • The children's and health rules mapped onto your product
  • A response procedure that fits the shortest deadline

What US state and federal rules require

There is no single federal privacy statute covering ordinary companies. Duties arrive from two directions: from the states, each with its own law, and from federal rules written for one sector or one audience.

That makes the first question a counting exercise. Every state law starts with a test of who is inside it, and the tests disagree with each other.

Four states, four different tests

Connecticut

You are covered if you handled the data of 100,000 consumers last year, or 25,000 while making more than a quarter of gross revenue from selling personal data.

Virginia

The same two doors, with the revenue one set at more than half rather than a quarter: 100,000 consumers, or 25,000 plus that revenue share.

Texas

No consumer count at all. You are in scope if you do business in the state or sell into it, process or sell personal data and are not a small business by the federal definition.

California

The only state with a regulator of its own for this: the California Privacy Protection Agency enforces, while everywhere else the work falls to the attorney general.

The deadlines and the second chance

Connecticut and California give a consumer 45 days for an answer, extendable by another 45 when the request is genuinely complex. Texas and Virginia hand the attorney general a 30-day notice to you before an action can start, and a cured violation ends the matter.

That second chance is not permanent everywhere. Connecticut's cure period was mandatory only until the end of 2024; since January 2025 the attorney general decides case by case whether to offer one at all.

Where the states do agree

The penalty ceiling is remarkably steady: 7,500 dollars per violation in Texas, in Virginia, and in California for an intentional violation or one involving a consumer under 16. The number that matters is not the ceiling but the count of violations, which is measured per consumer.

Since January 2025 both Texas and Connecticut require you to honour an opt-out sent by a browser setting or extension and not only one clicked on your site. Texas goes further and dictates the wording: a controller that sells sensitive data must post the sentence «NOTICE: We may sell your sensitive personal data», with a matching line for biometric data.

The federal rules that sit on top

The children's rule reaches any service aimed at under-13s, and it wants the parent's verified agreement before the first field is filled in. Since its 2025 amendment it also demands a written information security programme with a named coordinator and yearly risk assessments, and it caps retention: data lives only as long as the purpose it was collected for.

Health data at a covered entity and financial data at a bank sit under their own federal regimes, and every state law above carves them out by name. Other services we run in the country are listed on the USA page.

Sources: the Connecticut thresholds, 45 days and the 2025 signal duty — Public Act 22-15; the Texas scope, cure, penalty and notice wording — the Texas Data Privacy and Security Act; the Virginia thresholds and penalty — Chapter 35 of 2021; the amounts in California — section 1798.155 of its Civil Code; the under-13 duties — part 312 of title 16 of the Code of Federal Regulations.

Stages of work

Counting your way into the laws — 3–5 working days

Last year's numbers decide this, state by state: how many people's data you handled, what share of revenue came from selling it, and whether you clear the small-business line. The list of states follows from that.

Reading the product against the definitions

Selling, sharing for targeted advertising and profiling each have statutory definitions, and analytics or advertising tags often meet them without anyone deciding to sell anything.

Writing one notice that satisfies every state

Rather than four documents we will write one, built on the strictest requirement in each section, with the state-specific sentences where a statute dictates its own wording.

Building the opt-out routes

A link on the site, an email route for an authorised agent, and recognition of the browser signal that two of these states have required since January 2025.

Setting the response procedure to the shortest clock

Requests arrive undated and unlabelled. We will write who receives them, how identity is verified, when the extension is allowed and what the refusal letter says.

Mapping the sector rules onto the product

Children under 13, health data, financial data: we will check which of these your product touches and what each federal regime adds, including the written security programme the children's rule now requires.

This service belongs to our Licensing & Compliance practice.

Our case studies

No items found.

Leaders of the Area

Alexandra Kurdiumova

Alexandra

Kurdiumova

arrow_outward

FAQ

How many state privacy laws do we have to follow?
add
remove
Is one privacy policy enough for the whole country?
add
remove
How long do we have to answer a consumer request?
add
remove
Can a regulator fine us without warning?
add
remove
What changes if children use our product?
add
remove

Discuss
the Task

Speak to our team

Speak to our team. Tell us about your task –

we’ll help you with it in any jurisdiction.

Tell us about your task –
we’ll help you with it in any jurisdiction.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

We use cookies to improve your experience.