17.1 Other Major Comprehensive State Privacy Laws

Key Takeaways

  • IAPP’s 5 January 2026 roundup is the official 2026 checkpoint: Indiana, Kentucky, and Rhode Island comprehensive laws became applicable 1 January 2026; IAPP’s companion report then tracked 19 enacted comprehensive state laws — not a single official “20-state” statute
  • Indiana and Kentucky copy Virginia’s 100,000-consumer or 25,000-consumer-plus-over-50-percent-of-revenue-from-sale pair, a 30-day attorney-general cure, and about $7,500 per violation; Rhode Island uses low 35,000 / 10,000-plus-20-percent-sale thresholds and, per IAPP, has no statutory cure and no universal-opt-out mandate
  • Oregon HB 2008, in force 1 January 2026, bans sale of personal data if the controller has actual knowledge or willfully disregards that the consumer is under 16, bans sale of precise geolocation that identifies a present or past location within a 1,750-foot radius, and coincides with the expiration of Oregon’s 30-day cure
  • Compare archetypes, do not dump states: Virginia-style (AG, 100k/25k+50%, cure-or-not), California (CPPA plus limited security PRA plus “share”), Colorado (rulemaking, universal opt-out, assessments), Maryland (stricter minimization and no sale of sensitive data), Texas (no Virginia-style volume threshold; SBA small-business gate), Iowa/Utah (more business-friendly duties and longer or stacked gates)
  • Texas Bus. & Com. Code § 541.002 applies to a person that conducts business in Texas or produces a product or service consumed by Texas residents, processes or sells personal data, and is not an SBA small business — there is no 100,000-consumer volume test
Last updated: August 2026

There Is No Official “20-State” Statute

Body of Knowledge V.B PI11 asks you to compare other major comprehensive state privacy laws, not to recite a blog’s running count. IAPP’s 5 January 2026 news item — New year, new rules: US state privacy requirements coming online as 2026 begins — is the official 2026 checkpoint: https://iapp.org/news/a/new-year-new-rules-us-state-privacy-requirements-coming-online-as-2026-begins. That piece names the three comprehensive laws that became applicable on 1 January 2026 — the Indiana Consumer Data Protection Act (ICDPA), the Kentucky Consumer Data Protection Act (KCDPA), and the Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) — and it points readers to IAPP’s U.S. State Comprehensive Privacy Laws Report, which at that date described 19 enacted comprehensive state laws. Third-party “20 states in effect in 2026” charts are study aids. They are not a statute. Name the law you are applying.

The exam rewards archetypes. Once you can place a new statute next to Virginia, California, Colorado, Maryland, Texas, or Iowa/Utah, you can answer a scenario without listing every chapter and section.

1 January 2026: Indiana, Kentucky, Rhode Island

IAPP is explicit that Indiana and Kentucky mirror Virginia’s Consumer Data Protection Act coverage math. A controller is in if it conducts business in the state or targets residents and, during a calendar year, controls or processes personal data of at least 100,000 consumers or controls or processes personal data of at least 25,000 consumers and derives over 50 percent of gross revenue from the sale of personal data. Both statutes require data-protection assessments for high-risk processing, contracts with processors, opt-outs of targeted advertising, sale, and significant profiling, and opt-in consent before processing sensitive data. Both keep a standing 30-day attorney-general cure. Both authorize the attorney general — and only the attorney general — to seek an injunction and about $7,500 per violation. Indiana’s Attorney General published a Consumer Data Bill of Rights before the effective date; that guidance restates rights and definitions, it does not rewrite the statute.

Rhode Island is the contrast case in the same IAPP article. RIDTPPA (R.I. Gen. Laws ch. 6-48.1) applies full customer rights to a controller that, in a calendar year, controls or processes personal data of at least 35,000 Rhode Island consumers — excluding personal data controlled or processed solely to complete a payment transactionor at least 10,000 consumers while deriving more than 20 percent of gross revenue from the sale of personal data. That is Maryland-low, not Virginia-high. IAPP flags the “most glaring items not included”: recognition of a universal opt-out mechanism (UOOM), enhanced children’s extras, a standalone “personally identifiable information” definition (the statute uses personal data), and a right to cure. The Rhode Island Attorney General enforces. Do not import Indiana’s 30-day cure or Colorado’s UOOM duty into Providence.

Scenario. A $9 million fitness-app company processes 40,000 Indiana consumers, 40,000 Kentucky consumers, and 12,000 Rhode Island consumers, and it derives 22 percent of revenue from selling personal data. Indiana: 40,000 is below 100,000 and the sale prong needs 25,000 and over 50 percentout. Kentucky: same math — out. Rhode Island: 12,000 plus more than 20 percent from sales — in for full rights. The same company can be outside two Virginia clones and inside Rhode Island on one spreadsheet.

Oregon HB 2008 — Official Text, 1 January 2026

The Oregon Consumer Privacy Act (OCPA), ORS 646A.570–646A.589, has been applicable to most for-profit controllers since 1 July 2024. Enrolled House Bill 2008 (2025) amended ORS 646A.578 and took effect 1 January 2026. Official enrolled measure: https://olis.oregonlegislature.gov/liz/2025R1/Downloads/MeasureDocument/HB2008/Enrolled. The Oregon Department of Justice consumer FAQ restates the same rules: https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/privacy-law-faqs-for-consumers/.

Three exam facts live in the enrolled text.

First — under-16 processing and sale. A controller may not process a consumer’s personal data for targeted advertising or for profiling in furtherance of decisions that produce legal or similarly significant effects if the controller has actual knowledge that, or willfully disregards whether, the consumer is under 16. A controller may not sell personal data that pertains to a consumer if it has that same actual knowledge or willful disregard that the consumer is under 16. The old 13-to-15 consent-to-sell construct is gone. Oregon DOJ tells consumers it is now unlawful to sell a known or willfully disregarded under-16 consumer’s personal data or to use it for targeted advertising or profiling.

Second — the 1,750-foot geolocation sale ban. A controller may not sell personal data that “accurately identifies within a radius of 1,750 feet a consumer’s present or past location, or the present or past location of a device that links or is linkable to a consumer,” including by GPS latitude and longitude. The enrolled text carves out the content of communications and data generated by or connected to advanced utility metering systems. This is a sale ban for precise location of any Oregon consumer. It is not Washington’s My Health My Data Act geofence-around-a-clinic ban, even though both use a footage number.

Third — the 30-day cure expired 1 January 2026. That sunset is a separate legal event from HB 2008’s sale bans, and Chapter 15 already taught the enforcement consequence: the Attorney General may proceed directly to a civil investigative demand or a lawsuit. HB 2008 also requires a controller to honor a consumer’s revocation of consent as soon as practicable and not later than 15 days, and the OCPA’s UOOM-recognition machinery is in force. Do not collapse “Oregon 2026” into a single slogan.

Archetypes the Exam Actually Tests

Do not list every remaining state. Sort.

ArchetypeSignature design (as of August 2026)Exam hook
Virginia-style100,000 consumers or 25,000 + over 50% revenue from sale; AG-only; standing 30-day cure (unless the statute sunsets it); about $7,500/violation; consent for sensitive data; assessmentsIndiana and Kentucky (1 Jan 2026) sit here
CaliforniaCalifornia Privacy Protection Agency (CPPA) plus the California Attorney General; share (cross-context behavioral advertising) is not the same as sale; limited § 1798.150 security private right of action (PRA)Agency + share + PRA. Not “just another AG statute”
ColoradoAttorney General rulemaking; mandatory UOOM; data-protection assessments; many nonprofits inRules and signals, not just the statute PDF
MarylandMaryland Online Data Privacy Act (MODPA) (applicable 1 October 2025): 35,000 or 10,000 + more than 20% from sale; cannot sell sensitive data; collect/process/share sensitive data only when strictly necessaryMinimization and a sale ban, not a consent toggle
TexasTexas Data Privacy and Security Act (TDPSA), Tex. Bus. & Com. Code ch. 541 (effective 1 July 2024): no 100,000-consumer volume test; the gate is “not an SBA small business,” except a small business still needs consent to sell sensitive dataOfficial AG page: https://www.texasattorneygeneral.gov/consumer-protection/file-consumer-complaint/consumer-privacy-rights/texas-data-privacy-and-security-act
Iowa / Utah (business-friendlier)Iowa: Virginia-like volume math but a 90-day cure and thinner extra duties (no UOOM mandate, no original assessment mandate). Utah Consumer Privacy Act: stacks a $25 million revenue test on top of a volume or sale test; AG-only; standing 30-day cure; lighter assessment packageA company can be in Texas and out of Utah on the same headcount

Texas, in official words. Section 541.002 applies only to a person that (1) conducts business in Texas or produces a product or service consumed by residents of this state, (2) processes or engages in the sale of personal data, and (3) is not a small business as defined by the U.S. Small Business Administration, except that § 541.107 still forbids that small business from selling sensitive data without prior consent. There is no “100,000 Texans” line. A mid-size software firm that processes 8,000 Texas consumers can be in TDPSA and still outside ICDPA, KCDPA, and UCPA.

Maryland versus Virginia. Chapter 14 already taught MODPA’s 35,000 / 10,000-plus-20-percent pair. The PI11 point is the duty, not the threshold. Virginia lets a controller process sensitive data with consent. Maryland’s Attorney General states that a business cannot sell sensitive data and may collect, process, or share it only where strictly necessary to provide or maintain a requested product or service. Treating Maryland as “Virginia with smaller numbers” fails.

California versus everyone else. California is the only comprehensive-law archetype with a dedicated privacy agency, a statutory share concept, and a consumer security PRA. A Virginia-style question that asks “who sues for a missed deletion request?” is still “the attorney general.” A California question about an unencrypted driver’s-license exfiltration is a § 1798.150 problem.

Worked comparison. A 40-person analytics vendor has $18 million worldwide revenue, processes 80,000 consumers in each of Texas, Indiana, Utah, and Maryland, sells none of their data, and is above the SBA size standard for its NAICS code. Texas: processes personal data and is not a small business — in TDPSA. Indiana: 80,000 is below 100,000 and there is no 50-percent-sale prong — out. Utah: the $25 million revenue stack fails — out. Maryland: 80,000 exceeds 35,000 — in MODPA, and it still cannot sell those consumers’ precise geolocation or health inferences. Same vendor, four different answers. That is the skill PI11 tests.

Exam traps

  • Do not treat a consultant’s “20 states” slide as an official count. IAPP’s January 2026 report named 19 enacted comprehensive laws and three newly applicable ones.
  • Indiana and Kentucky are Virginia math. Rhode Island is 35,000 / 10,000+20%, no IAPP-listed cure, no UOOM mandate.
  • Oregon HB 2008’s 1,750-foot figure is a sale restriction on precise geolocation, not a license to geofence a clinic.
  • Texas has no 100,000-consumer threshold. The SBA small-business gate is the limit — and it does not authorize unconsented sales of sensitive data.
  • Maryland’s sensitive-data rule is a ban on sale, not Virginia’s consent-and-proceed model.
Loading diagram...
2026 Comprehensive-Law Comparison Map
Test Your Knowledge

A controller sells precise GPS coordinates of Oregon consumers and, with actual knowledge that a user is 15, also sells that user’s profile to an advertiser. Oregon’s 30-day OCPA cure is invoked as a complete defense. Which statement matches enrolled HB 2008 and the 1 January 2026 OCPA landscape?

A
B
C
D
Test Your Knowledge

A company processes personal data of 12,000 consumers in Indiana, 12,000 in Kentucky, and 12,000 in Rhode Island, and it derives 22 percent of gross revenue from selling personal data. Payment-only processing is not in the Rhode Island count. Which coverage result is correct for 2026?

A
B
C
D
Test Your Knowledge

A mid-size software firm processes 8,000 consumers in Texas and 8,000 in Indiana, sells none of their data, and is above the SBA size standard for its industry. Counsel claims Texas cannot apply because the firm is under Virginia’s 100,000-consumer test. Which statement is correct?

A
B
C
D