Data protection in the USA
The United States has no single privacy law: every state writes its own test of who is covered, and federal rules sit on top by sector. We will count which ones reach you.
Consumer request
Ответ на запрос
45 days
45 дней
Notice before action
Окно на исправление
30 days
30 дней
Top state penalty
Потолок взыскания
USD 7,500
7 500 USD
Children's rule
Детское правило
under 13
младше 13 лет
When you need US data protection compliance

You started selling in a second state
Each state writes its own test for who is covered. Crossing one border can put you inside a law you have never read, with its own deadlines.
A letter arrived from an attorney general
Most states give a short window to fix the problem before anything is filed. That window is the cheapest part of the process, and it closes.
Children are using your product
The federal children's rule applies to services aimed at under-13s and to anyone who actually knows a user is that age. It asks for consent before collection, not after.
Your app sells or shares data
Selling data, targeted advertising and profiling are the three activities every state law singles out, and each demands its own opt-out route.
What you get
- The states whose laws actually cover you
- A privacy notice that survives all of them
- Working opt-out routes, including browser signals
- The children's and health rules mapped onto your product
- A response procedure that fits the shortest deadline
What US state and federal rules require

There is no single federal privacy statute covering ordinary companies. Duties arrive from two directions: from the states, each with its own law, and from federal rules written for one sector or one audience.
That makes the first question a counting exercise. Every state law starts with a test of who is inside it, and the tests disagree with each other.
Four states, four different tests
Connecticut
You are covered if you handled the data of 100,000 consumers last year, or 25,000 while making more than a quarter of gross revenue from selling personal data.
Virginia
The same two doors, with the revenue one set at more than half rather than a quarter: 100,000 consumers, or 25,000 plus that revenue share.
Texas
No consumer count at all. You are in scope if you do business in the state or sell into it, process or sell personal data and are not a small business by the federal definition.
California
The only state with a regulator of its own for this: the California Privacy Protection Agency enforces, while everywhere else the work falls to the attorney general.
The deadlines and the second chance
Connecticut and California give a consumer 45 days for an answer, extendable by another 45 when the request is genuinely complex. Texas and Virginia hand the attorney general a 30-day notice to you before an action can start, and a cured violation ends the matter.
That second chance is not permanent everywhere. Connecticut's cure period was mandatory only until the end of 2024; since January 2025 the attorney general decides case by case whether to offer one at all.
Where the states do agree
The penalty ceiling is remarkably steady: 7,500 dollars per violation in Texas, in Virginia, and in California for an intentional violation or one involving a consumer under 16. The number that matters is not the ceiling but the count of violations, which is measured per consumer.
Since January 2025 both Texas and Connecticut require you to honour an opt-out sent by a browser setting or extension and not only one clicked on your site. Texas goes further and dictates the wording: a controller that sells sensitive data must post the sentence «NOTICE: We may sell your sensitive personal data», with a matching line for biometric data.
The federal rules that sit on top
The children's rule reaches any service aimed at under-13s, and it wants the parent's verified agreement before the first field is filled in. Since its 2025 amendment it also demands a written information security programme with a named coordinator and yearly risk assessments, and it caps retention: data lives only as long as the purpose it was collected for.
Health data at a covered entity and financial data at a bank sit under their own federal regimes, and every state law above carves them out by name. Other services we run in the country are listed on the USA page.
Sources: the Connecticut thresholds, 45 days and the 2025 signal duty — Public Act 22-15; the Texas scope, cure, penalty and notice wording — the Texas Data Privacy and Security Act; the Virginia thresholds and penalty — Chapter 35 of 2021; the amounts in California — section 1798.155 of its Civil Code; the under-13 duties — part 312 of title 16 of the Code of Federal Regulations.
Stages of work
Counting your way into the laws — 3–5 working days
Last year's numbers decide this, state by state: how many people's data you handled, what share of revenue came from selling it, and whether you clear the small-business line. The list of states follows from that.
Reading the product against the definitions
Selling, sharing for targeted advertising and profiling each have statutory definitions, and analytics or advertising tags often meet them without anyone deciding to sell anything.
Writing one notice that satisfies every state
Rather than four documents we will write one, built on the strictest requirement in each section, with the state-specific sentences where a statute dictates its own wording.
Building the opt-out routes
A link on the site, an email route for an authorised agent, and recognition of the browser signal that two of these states have required since January 2025.
Setting the response procedure to the shortest clock
Requests arrive undated and unlabelled. We will write who receives them, how identity is verified, when the extension is allowed and what the refusal letter says.
Mapping the sector rules onto the product
Children under 13, health data, financial data: we will check which of these your product touches and what each federal regime adds, including the written security programme the children's rule now requires.
This service belongs to our Licensing & Compliance practice.
Our case studies
FAQ
Only the ones whose test you meet, and that is a question of arithmetic rather than opinion. Connecticut and Virginia count consumers and revenue share; Texas counts neither and asks instead whether you are a small business by the federal definition. A product with modest traffic can be outside three laws and inside the fourth. We will run the count with last year's figures and name the states in writing.
One document is usually right, but it has to be built from the strictest version of each duty rather than the most convenient. Some sentences are dictated word for word: a Texas controller that sells sensitive data has to post a specific notice, and biometric data has its own line. A single notice that satisfies the strictest state and carries those exact sentences beats four documents that drift apart at the first update.
In California and Connecticut, 45 days from receipt, with one extension of another 45 days where the request is genuinely complex and you tell the person inside the first period. The practical constraint is not the length but the start: the clock runs from arrival, including requests that land in a support inbox rather than a privacy form. Build the intake first and the deadline stops being tight.
In Texas and Virginia the attorney general has to give you 30 days' written notice first, and a violation cured inside that window, with a written statement back, ends the matter. Connecticut worked the same way until the end of 2024; since January 2025 the cure period there is discretionary. California is the outlier in a different way: enforcement sits with a dedicated agency rather than with the attorney general.
The federal children's rule takes over for users under 13, and it asks for verifiable parental consent before collection rather than after. Since its 2025 amendment it also requires a written security programme with a named coordinator and yearly risk assessments, and it limits how long the data may be kept. Age-gating a product does not remove the duty if you actually know a user is under 13.
Discuss
the Task
Speak to our team
Speak to our team. Tell us about your task –
we’ll help you with it in any jurisdiction.
