The US has no comprehensive federal privacy law, so compliance means satisfying a growing set of state statutes at once. Tracking them individually does not scale. The workable approach is to identify the shared architecture, build to the strictest common denominator, and keep a short register of the genuine state-specific differences.
The shared architecture
Despite different drafting, most state laws converge on the same structure:
- Applicability thresholds based on revenue and/or the number of residents whose data you process — so smaller businesses often fall outside several.
- Consumer rights to know, access, correct, delete and obtain a portable copy.
- Opt-out rights for sale of personal data, targeted advertising and certain profiling. This is the defining US pattern — an opt-out model, where GDPR-style regimes usually require a lawful basis up front.
- Sensitive data handled separately, typically requiring opt-in consent or a strict necessity test.
- Contracts with processors containing specified terms.
- Assessments for higher-risk processing such as targeted advertising, sale of data or profiling with significant effects.
- Non-discrimination for exercising rights.
Build the programme around this list and you will satisfy the substance of most states. What then remains is a manageable register of differences rather than a law-by-law implementation.
Where states genuinely differ
- Thresholds. A company in scope in one state may be out of scope in another, and thresholds change as laws are amended.
- Whether a cure period exists before enforcement — some states offer one, some have let theirs expire.
- Private right of action. Mostly absent, with California's narrow breach-related right the notable exception. This matters because it changes your litigation exposure, not just your regulatory exposure.
- Definition of "sale" — broad enough in places to capture data sharing for advertising that companies do not consider selling.
- Universal opt-out signals. Several states require honouring browser-level preference signals; this is a technical implementation, not a policy statement.
- Employee and B2B data. Most states exclude it; California does not, which is a significant scoping difference.
One privacy programme, many jurisdictions
GRC Copilot maps processing records, controls and evidence across privacy regimes together, so overlapping obligations are satisfied once.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
A practical build order
- Map your data — you cannot answer a rights request or complete an assessment without knowing what you hold and where.
- Determine applicability per state against current thresholds, and re-check annually as laws are amended and your volumes grow.
- Build one rights-handling process to the shortest deadline and broadest right set, rather than branching by state.
- Implement opt-outs properly, including universal preference signals, and verify they actually suppress downstream sharing — this is where audits find failures.
- Fix your ad-tech data flows. Most "sale" and "sharing" exposure sits in marketing tags, not in your product database.
- Paper your processors with the required contract terms.
- Run assessments for targeted advertising, sale and significant profiling.
The trap
Treating this as a legal documentation exercise. The obligations that fail in practice are technical: honouring an opt-out across every downstream system and tag, deleting data from analytics platforms and backups, and locating a consumer's data across an estate that was never designed to be searched by person.
Frequently asked questions
Does GDPR compliance cover US state laws?
It covers much of the substance and misses US-specific mechanics — opt-out signals, the breadth of "sale", and state-by-state applicability. It is a strong head start, not coverage.
Do we have to comply if we have no office in the state?
Generally yes if you meet the thresholds for residents of that state. These laws follow the consumer, not your premises.
Is a privacy policy update enough?
No. Notices are the visible part; rights handling, opt-out propagation and processor contracts are where obligations actually bite.
How do we keep up as new states pass laws?
Build to the common architecture and maintain a short difference register. Re-implementing per state is what becomes unsustainable.
Key takeaways
- Build to the shared architecture, then register only the genuine differences.
- The US model is opt-out led — implementing signals is technical work, not policy.
- Most "sale" exposure lives in marketing tags rather than your product data.
- California's inclusion of employee and B2B data is a major scoping difference.