US privacy law is a patchwork of state statutes — not one federal privacy act for all businesses. Most commercial websites must still address CalOPPA, CCPA/CPRA, and increasingly comprehensive state laws.
Federal baseline
- CalOPPA — privacy policy required if collecting PII from California residents (conspicuous link)
- COPPA — children under 13 online services
- HIPAA, GLBA, FCRA — sector-specific (health, finance, credit)
- FTC Act — unfair/deceptive practices including false privacy claims
Comprehensive state privacy laws (selected)
| State | Law | Effective | Notes |
|---|---|---|---|
| California | CCPA/CPRA | 2020/2023 | Broad rights, sale/sharing opt-out |
| Virginia | VCDPA | 2023 | Consumer rights similar to GDPR-lite |
| Colorado | CPA | 2023 | Universal opt-out mechanisms |
| Connecticut | CTDPA | 2023 | |
| Utah | UCPA | 2023 | Business-friendly thresholds |
| Texas | TDPSA | 2024 | Wide applicability |
| Oregon | OCPA | 2024 | |
| Montana | MCDPA | 2024 |
Thresholds vary — revenue, data volume, sale of data. Growing SaaS often triggers multiple states through nationwide user bases.
What publishers should do
- Publish strong master privacy policy covering major state rights
- Monitor state law updates (this page is educational snapshot — verify with counsel)
- Map PI categories and sharing for California first, then expand
- Use Privacy Policy Generator with US coverage
Consumer impact angle
State laws exist because customers lacked visibility into data use. Readable policies reduce support burden and build trust — Clerica certification scores clarity on verify pages.
Related: CCPA guide · US privacy requirements · Privacy laws by country · California requirements
Clerica is not a law firm and does not provide legal advice. This guide is educational. Consult qualified counsel for jurisdiction-specific requirements.