A practical guide to US privacy laws for small and growing businesses

American flags waving among New York skyscrapers

Understanding privacy law in the United States can feel unusually difficult. Instead of one clear law that applies across the country, businesses may encounter a mixture of federal rules, state privacy laws, industry requirements and customer expectations.

For a small or growing business, the challenge is rarely a lack of information. There is plenty of guidance available, but it can be difficult to work out which parts apply to your business and what should be addressed first.

A clearer starting point comes from understanding where your customers are located, what personal information your business handles and how that information is used. From there, the legal landscape becomes much more manageable.

The United States has a patchwork of privacy laws

The United States does not currently have one comprehensive federal privacy law that applies in the same way to every private business. Federal privacy requirements tend to focus on particular industries, activities or types of information, while an increasing number of states have introduced broader consumer privacy laws.

The International Association of Privacy Professionals reported 19 enacted comprehensive state privacy laws as the United States entered 2026. These laws share some common principles, but they differ in important areas such as coverage thresholds, exemptions, consumer rights, consent requirements and enforcement.

This means that two businesses carrying out similar activities may have different obligations depending on where their customers live, how much information they process and whether they operate in a regulated industry.

It also means that a national privacy policy copied from another business may not accurately reflect what your own business does or which laws apply.

A business does not always need a US office to be affected

Being based outside the United States does not automatically place a business outside US privacy law. Some state laws apply to organisations that conduct business in a state or offer products and services to people who live there, provided the organisation also meets the relevant coverage thresholds.

For example, the Colorado Privacy Act can apply to an organisation that conducts business in Colorado or targets products or services at Colorado residents. Coverage then depends on factors such as the number of Colorado consumers whose information the organisation processes or whether it receives value from selling personal data.

The Texas Data Privacy and Security Act similarly applies to certain organisations that conduct business in Texas or produce products or services consumed by Texas residents. Texas also provides a broad exemption for businesses that meet the federal definition of a small business, although a specific rule still applies when a small business sells sensitive data.

California’s law applies to qualifying for-profit businesses that do business in California and meet one or more of its coverage thresholds. A business therefore needs to consider its connection with the state and its activities, rather than looking only at where it is incorporated or where its staff work.

For an Australian, New Zealand, UK or other international business, the practical question is usually not simply whether it has a US office. It helps to look at whether the business actively serves people in particular states and whether its data practices bring it within a law’s thresholds.

Start with where your business has connections

Before comparing individual laws, it helps to build a simple picture of the business. This gives you the information needed to narrow down which requirements deserve closer attention.

A useful initial review should consider the following areas:

  • Customer locations: Identify the US states where your customers, users, employees and other relevant individuals live.
  • Business activities: Consider whether you actively market, sell or deliver services to people in those states.
  • Volume of personal information: Estimate how many individuals’ information you collect or process during a year.
  • Types of information: Record whether you handle contact details, account information, financial data, health information, precise location information, children’s data or other sensitive information.
  • Use of advertising and analytics: Understand whether personal information is used for targeted advertising, profiling, audience matching or similar activities.
  • Data sharing: Identify information given to software providers, contractors, advertising platforms, analytics services and business partners.
  • Commercial use of information: Check whether your business sells personal information or receives another benefit in exchange for providing it.
  • Contractual commitments: Review whether larger customers require you to follow particular state privacy laws or support them with their own compliance.

This does not need to begin as a large legal or technical project. A basic spreadsheet showing the information held, the people it relates to, where it is stored and who receives it can provide a strong foundation.

Not every state law will apply to every small business

The growing number of US privacy laws can make it seem as though a business must immediately comply with every state regime. In practice, each law contains its own scope, thresholds and exemptions.

Some states use the number of residents whose personal information a business processes. Others consider revenue, involvement in the sale of personal data, the type of organisation or a combination of these factors.

Colorado, for example, generally uses thresholds based on processing the personal data of 100,000 consumers or processing the data of 25,000 consumers while receiving revenue or a discount from selling personal information. Texas takes a different approach and generally exempts federally defined small businesses, subject to its rule about selling sensitive information.

Some laws also exempt particular organisations or information already regulated under other legislation. These exemptions are not consistent between states, so it is important to check the exact law rather than assuming that an exemption found in one jurisdiction will apply everywhere.

A smaller business may also encounter privacy requirements indirectly. A customer that is covered by a state law may require its suppliers and service providers to sign privacy terms, maintain safeguards, help respond to consumer requests or place limits on how customer information is used.

The result is often a narrower and more practical compliance task than the number of laws initially suggests. The first objective is to identify the laws and contractual requirements with a realistic connection to the business.

Many state laws follow similar principles

Although state privacy laws are not identical, many are built around a recognisable set of privacy principles. Understanding these recurring themes makes it easier to create a common foundation before dealing with state-specific differences.

Common requirements may include:

  • Providing clear privacy information: Businesses may need to explain what personal information they collect, why they use it, who they disclose it to and how people can exercise their rights.
  • Supporting individual rights: Depending on the state, people may have rights to access, correct, delete or obtain a copy of their personal information.
  • Providing opt-out choices: Some laws allow people to opt out of the sale of their information, targeted advertising or certain forms of profiling.
  • Handling sensitive information carefully: A business may need consent or additional controls before processing information such as health data, precise location information or information about children.
  • Limiting unnecessary collection: Businesses may be expected to collect information that is reasonably necessary for a stated purpose and avoid using it for unrelated purposes without appropriate notice or consent.
  • Protecting the information held: State laws commonly expect businesses to use reasonable administrative, technical and physical safeguards.
  • Managing service providers: Contracts may be required when another organisation processes personal information on the business’s behalf.
  • Assessing higher-risk activities: Some laws require documented assessments before using information in ways that present a heightened privacy risk.

Colorado’s official guidance, for example, describes duties involving transparent privacy notices, consumer requests, data minimisation, sensitive data, security and assessments for higher-risk processing.

These common themes make it possible to build a practical privacy baseline. State-specific work can then focus on genuine differences such as wording, response periods, opt-out mechanisms, exemptions and consent requirements.

California has an important place in the wider picture

California is often the first state people associate with US privacy law. Its privacy regime is influential, and businesses with a meaningful connection to California should consider it carefully.

The California Privacy Rights Act, usually shortened to CPRA, amended and expanded the California Consumer Privacy Act. They are not two separate compliance frameworks that a business must implement independently. The current law is generally referred to as the CCPA or the CCPA as amended by the CPRA.

The CCPA applies to qualifying for-profit businesses that do business in California and meet at least one threshold. The thresholds currently include annual gross revenue above US$26.625 million, buying, selling or sharing the personal information of 100,000 or more California consumers or households, or receiving at least half of annual revenue from selling or sharing California consumers’ personal information.

This means many small businesses will fall outside the CCPA’s direct coverage. However, a smaller company may still need to support a covered customer as a service provider or contractor, particularly when it stores, accesses or processes personal information on that customer’s behalf.

California also has privacy requirements outside the CCPA. For example, the California Online Privacy Protection Act can require operators of commercial websites that collect personally identifiable information from California consumers to conspicuously display a privacy policy.

California therefore deserves careful attention, but it should be considered as one part of a wider US privacy review. A separate CCPA assessment is most useful once the business has confirmed that it has a meaningful connection to California.

Federal requirements may also apply

State consumer privacy laws are only one part of the US privacy landscape. Federal laws may apply when a business operates in a particular industry, performs a regulated activity or handles certain types of information.

Some of the more widely encountered federal requirements include:

  • The Health Insurance Portability and Accountability Act: HIPAA applies to health plans, healthcare clearinghouses, certain healthcare providers and their business associates. It does not automatically apply to every business that holds health-related information.
  • The Gramm-Leach-Bliley Act: GLBA applies to financial institutions, a category that can include businesses providing loans, financial advice, insurance and other financial products or services. Its requirements include explaining certain information-sharing practices and safeguarding customer information.
  • The Children’s Online Privacy Protection Act: COPPA applies to operators of websites and online services directed to children under 13, as well as operators that have actual knowledge that they are collecting personal information from a child under 13.
  • The FTC Health Breach Notification Rule: This rule can apply to certain health apps, connected devices and personal health record services that are not covered by HIPAA.

The Federal Trade Commission also takes action when businesses make misleading privacy or security claims or engage in unfair practices involving consumer information. A privacy policy should therefore describe what the business actually does, rather than presenting an idealised version of its practices.

Sector-specific rules can sometimes be more important than the comprehensive state laws. A business working with healthcare providers, financial organisations or children’s services should include these requirements in its initial privacy review.

Privacy compliance depends on good cybersecurity

Privacy documents are important, but they are only one part of protecting personal information. The practices described in a privacy notice need to be supported by the way information is collected, accessed, stored, shared, retained and deleted.

At least 25 states have private-sector data security laws, with many requiring reasonable security procedures appropriate to the nature of the information held. These requirements can apply separately from the newer comprehensive consumer privacy laws.

The FTC’s practical guidance recommends that businesses take stock of the personal information they hold, keep only what they need, protect it, dispose of it securely and prepare for security incidents. These are useful principles for businesses of almost any size, even before a detailed legal assessment has been completed.

In practical terms, this often means reviewing:

  • Who has access to personal information and whether that access is still appropriate.
  • Whether important accounts are protected with multi-factor authentication.
  • Whether business devices, cloud platforms and applications are configured securely.
  • Whether sensitive information is encrypted when appropriate.
  • Whether old records are retained longer than the business requires.
  • Whether software providers have suitable privacy and security commitments.
  • Whether the business can identify, investigate and respond to a data incident.

A business is in a much stronger position when its privacy commitments and its everyday security practices reflect each other. This also makes it easier to answer customer questionnaires and demonstrate that personal information is being handled responsibly.

A sensible first privacy action

Trying to build a separate compliance program for every US state is unlikely to be the best starting point for most smaller businesses. A more manageable approach is to establish what is relevant and create a shared foundation that addresses the common requirements.

This can be approached in five stages:

  1. Understand the information you hold. Record the main categories of personal information, whose information it is, where it comes from and where it is stored.
  2. Identify your US connections. Note where customers, users and employees live and which markets the business actively targets.
  3. Check likely laws and thresholds. Review the state and federal requirements that have a realistic connection to your activities, including any exemptions.
  4. Build a common privacy baseline. Create accurate privacy notices, reasonable security controls, retention practices, service-provider arrangements and a way to respond to privacy requests.
  5. Address specific differences. Add state-specific wording, opt-out tools, consent processes or assessments where they are genuinely required.

This sequence keeps the work connected to the business rather than to a long list of laws. It also provides a clearer basis for deciding when specialist privacy legal advice would be useful.

How BrightShield can help

BrightShield helps small and growing businesses turn broad privacy requirements into a practical and prioritised improvement plan. The work begins with understanding the business, the information it holds and the jurisdictions that may be relevant.

Depending on the support selected, BrightShield can help you:

  • Identify the personal information held across business systems, files and service providers.
  • Map where that information comes from, why it is used and who it is shared with.
  • Review which US privacy jurisdictions may have a meaningful connection to the business.
  • Assess privacy notices, retention practices, access controls and incident readiness.
  • Identify gaps between documented privacy commitments and actual business practices.
  • Prepare practical policies, procedures and templates.
  • Improve the cybersecurity safeguards that support privacy compliance.
  • Build a prioritised Cyber Action Plan showing what should be addressed first.

With Guided, your business works through the improvements using a tailored plan, practical resources and expert support. This suits businesses that are comfortable making the changes but would value clarity about what applies and how to approach it.

With Complete, BrightShield manages the improvement work through to completion, coordinating with your team, technology providers and legal advisers where needed. This provides a more hands-on path for businesses that do not have the time or internal resources to manage the work themselves.

BrightShield does not replace specialist legal advice where a definitive interpretation of US law is required. It helps make that advice easier to use by clarifying the business’s data, systems, current practices and practical compliance gaps.

A clearer path through the US privacy landscape

US privacy law is complex because several layers of regulation may apply at the same time. Once those layers are connected to the business’s actual customers, information and activities, the work becomes easier to prioritise.

Most small businesses can begin with a modest exercise: understand what personal information is held, identify where the people behind that information live and check which legal thresholds or contractual requirements are relevant.

From there, the aim is steady improvement. A sound privacy foundation, supported by practical cybersecurity and accurate documentation, gives the business a clearer way to respond as its customers, services and legal obligations develop.

This article provides general information and should not be treated as legal advice. Privacy law applicability depends on the circumstances of each business and should be confirmed with a suitably qualified adviser where necessary.

Subscribe to our newsletter

Every week we publish a short email on a topic we think you'll find interesting. We know you're busy, so we keep it short, snappy, and relevant.

Let's Begin

Ready to understand your security risks?

Get a clear, practical view of your risks and a plan to fix them with a BrightShield Security Audit.