US State Privacy Laws for Small Business Websites: What Applies and What to Do

A practical 2026 guide to US state privacy laws for small business websites: CCPA/CPRA thresholds, the other comprehensive state laws, Texas and Nebraska small-business rules, privacy notices, opt-out of sale and sharing, Global Privacy Control, pixels, forms, vendor contracts and CAN-SPAM.

US State Privacy Laws for Small Business Websites: What Applies and What to Do article cover image

Most small businesses are not directly covered by California's CCPA, because it applies only to for-profit businesses that have more than USD 26,625,000 in annual gross revenue (the 2025 inflation-adjusted figure), buy, sell or share the personal information of 100,000 or more California consumers or households, or earn at least half their revenue from selling or sharing personal information. As of 2026, 19 states have comprehensive consumer privacy laws in effect, most with volume thresholds that small sites will not reach, but Texas and Nebraska apply to almost any business that is not an SBA-defined small business and impose a consent rule on small businesses that sell sensitive data. Even when no state law applies, advertising pixels, lead forms and email marketing create obligations under consumer protection law and CAN-SPAM, so every business website needs an accurate privacy notice and a basic set of controls.

This guide sets out who is covered, what a covered website must do, and the practical steps that make sense for smaller businesses whether or not they cross a threshold today.

This article is general information, not legal advice. Thresholds and requirements change, and state laws differ in detail; confirm your obligations with a qualified privacy lawyer.

The CCPA and CPRA: Who Is Covered

The California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to a for-profit business that collects California residents' personal information, does business in California, and meets at least one of these tests:

TestThreshold
Annual gross revenue in the preceding calendar yearMore than USD 26,625,000 (adjusted from USD 25,000,000 on 1 January 2025)
Personal information bought, sold or shared100,000 or more California consumers or households per year
Revenue from selling or sharing personal information50% or more of annual revenue

The California Privacy Protection Agency adjusts the revenue threshold for inflation every two years; the current figure and its effective date are on the CPPA's monetary thresholds page. The next adjustment is due in January 2027.

The revenue test is global revenue, not California revenue. A company based in New York, London or anywhere else with revenue above the threshold that collects data from Californians is covered. The second test catches smaller sites with heavy traffic: 100,000 California visitors whose data is shared with advertising pixels can meet it even with modest revenue.

Two definitions matter most for websites:

  • Sale means disclosing personal information to a third party for money or other valuable consideration.
  • Sharing means disclosing personal information to a third party for cross-context behavioural advertising, whether or not money changes hands.

California's first public CCPA settlement shows how these apply to ordinary websites. In August 2022, the California Attorney General announced a USD 1.2 million settlement with Sephora, alleging that allowing third-party advertising and analytics trackers on its site was a sale that it failed to disclose, and that it did not honour Global Privacy Control signals.

The Other State Comprehensive Privacy Laws in 2026

According to the IAPP US State Privacy Legislation Tracker, comprehensive laws in Indiana, Kentucky and Rhode Island took effect on 1 January 2026, bringing the number of states with comprehensive privacy laws in effect to 19. Several more states have enacted laws that take effect later, so check the tracker for current dates.

The laws in effect as of 2026 are those of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island. Florida has a narrower law aimed at very large companies.

How thresholds work outside California

Most of these laws do not use a revenue test alone. They typically apply when a business controls or processes the personal data of a set number of state residents in a year, commonly 100,000, or a smaller number (commonly 25,000) combined with a share of revenue from selling personal data. Several states use lower numbers: Delaware, New Hampshire, Maryland and Rhode Island use 35,000. Some states exclude data processed solely to complete a payment transaction from the count, and Tennessee also requires revenue above USD 25 million. Check each state's exact wording before concluding you are out of scope.

Texas and Nebraska: no volume threshold

Texas and Nebraska take a different approach. Instead of counting consumers, they apply to businesses that operate in the state or target its residents, process personal data, and are not a small business as defined by the US Small Business Administration. The Texas Attorney General's TDPSA page summarises this. Two consequences follow:

  • A mid-size company with modest traffic can be covered in Texas or Nebraska even though it falls below every volume threshold elsewhere.
  • A business that does qualify as SBA-small is exempt from most obligations, but must still obtain consumer consent before selling sensitive data, such as precise geolocation or health information.

SBA size standards vary by industry (by employees or annual receipts), so determine your status from the SBA table for your industry code rather than assuming.

What a Small Business Website Must Actually Do

Whether you are covered by one state law or none, the practical workload on a website falls into six areas. If you are covered, these are legal requirements. If you are not, they are still the controls that keep you aligned with FTC expectations, platform policies and customer trust, and they put you in position when you grow.

1. Publish an accurate privacy notice

A privacy notice for a covered business generally needs to explain:

  • the categories of personal information collected (contact details, order history, device identifiers, browsing activity);
  • the sources and the purposes for each category;
  • the categories of third parties you disclose it to, and whether you sell or share it;
  • how long you keep each category;
  • consumer rights (access, correction, deletion, opt-out of sale, sharing and targeted advertising, and limits on sensitive data) and how to exercise them;
  • how you verify requests, how authorised agents can act, and how consumers can appeal a denied request where state law requires it;
  • the date the notice was last updated.

Write it for your actual data flows. A template copied from another site will describe processing you do not do and miss the pixels you actually run, which is itself a deceptive-practices risk.

2. Offer an opt-out of sale, sharing and targeted advertising

If you run advertising pixels or share data with ad networks, you are very likely "selling" or "sharing" under California law and engaging in "targeted advertising" under the other state laws. Covered businesses must give consumers an opt-out, and in California that means a clear "Do Not Sell or Share My Personal Information" link (or an alternative opt-out link permitted by the regulations). The opt-out must actually stop the relevant data flows, not just record a preference.

3. Honour Global Privacy Control

Global Privacy Control (GPC) is a browser signal that tells sites the visitor opts out of sale and sharing. California's regulations require businesses that sell or share personal information to treat a qualifying opt-out preference signal as a valid opt-out request, and from 1 January 2026 to display whether they have processed it (for example, "Opt-Out Request Honored"). The CPPA describes California as one of about a dozen states that require businesses to honour opt-out preference signals.

In practice, your consent or privacy tool should detect navigator.globalPrivacyControl, suppress advertising pixels and data sharing for that visitor, and, where the visitor is known (logged in), apply the opt-out to their account.

4. Treat cookies and pixels as potential sharing

US state laws are mostly opt-out rather than opt-in for ordinary tracking, which differs from the EU and UK. But the data flows are the same. Map every tag on your site:

Tag typeTypical status under state lawsAction
Strictly functional (cart, login, security)Not a sale or shareDisclose in the privacy notice
First-party analytics under a service-provider contractUsually not a sale if the vendor is contractually restrictedCheck the vendor terms; disclose
Advertising pixels (Meta, TikTok, Google Ads remarketing, Pinterest)Commonly sharing or targeted advertisingHonour opt-out and GPC; disclose
Session replay and chat toolsDepends on contract and data capturedMask form fields; review contract

Session replay and chat tools deserve a closer look, because they can capture form contents and have been the subject of wiretapping claims in some states. Mask inputs and restrict them on pages with sensitive information.

If you also serve visitors in the EU or UK, you need prior consent for non-essential cookies there, and Google requires Consent Mode signals for EEA ad measurement; see our Google Consent Mode v2 setup guide. Most consent platforms can apply opt-in rules to EU and UK visitors and opt-out rules plus GPC to US visitors from one configuration.

5. Minimise data in forms

Every field on a contact, quote or checkout form is data you have to protect, disclose and potentially delete on request. Collect what you need for the stated purpose and no more. Most state laws now include data minimisation principles, and several treat health, precise location, children's data, and racial or ethnic origin as sensitive data requiring opt-in consent.

Practical steps:

  • remove optional fields that nobody uses in follow-up;
  • do not ask for date of birth, government IDs or health details unless the service requires them;
  • set retention periods for form entries stored in WordPress, your form plugin and your CRM, and delete old submissions;
  • make sure form data sent to a CRM or email platform goes over HTTPS and is limited to the fields needed.

The WordPress forms to HubSpot integration guide and the lead management automation guide show where form data travels, which is the map you need for your privacy notice and deletion process.

6. Put contracts in place with vendors

State laws distinguish between vendors that process data on your behalf (service providers or processors) and third parties that use it for their own purposes. The distinction depends on the contract. Service provider or processor agreements must limit the vendor to processing for your specified purposes, prohibit selling or sharing the data, and require assistance with consumer requests and security. Most major vendors publish a data processing addendum; accept it and keep a record. For vendors without one, or whose terms allow them to use your data for their own advertising, treat the disclosure as a sale or share.

Handling Consumer Requests

Covered businesses must respond to requests to access, delete, correct and opt out, generally within 45 days (extendable in limited circumstances). A small business can handle this without special software:

  1. 1Provide at least the methods the applicable law requires (for many online-only businesses, an email address or web form).
  2. 2Verify identity proportionately: matching an email address and order number is often enough for low-risk requests.
  3. 3Search every system: website database, form plugin entries, CRM, email platform, payment processor, help desk and backups policy.
  4. 4Respond in writing, keep a log of the request and outcome, and provide an appeal route where state law requires it.

CAN-SPAM Basics for Email Marketing

The federal CAN-SPAM Act applies to all commercial email, regardless of business size and with no threshold. It is an opt-out law: you do not need prior consent to email US recipients, but you must follow the rules in the FTC's CAN-SPAM compliance guide:

  • do not use false or misleading header information (From, To, Reply-To, routing);
  • do not use deceptive subject lines;
  • identify the message as an advertisement where it is commercial content;
  • include a valid physical postal address;
  • include a clear way to opt out of future email, and keep it working for at least 30 days after sending;
  • honour opt-out requests within 10 business days, without charging a fee or asking for more than an email address;
  • monitor what agencies or platforms do on your behalf, because you remain responsible.

If you email people in the EU or UK, consent rules for marketing email are stricter and generally require opt-in. The email automation setup guide covers list hygiene, consent capture and unsubscribe handling.

A Practical Privacy Checklist

  • Determine which state laws apply using revenue, consumer counts and SBA size status
  • Inventory every tag, pixel, form, plugin and integration that touches personal data
  • Update the privacy notice to match the inventory, with a last-updated date
  • Add a "Do Not Sell or Share" or equivalent opt-out link if you run advertising pixels
  • Configure your consent tool to honour Global Privacy Control and show its status
  • Remove unnecessary form fields and set retention periods
  • Accept data processing addenda with analytics, email, CRM and hosting vendors
  • Set up a request inbox, a verification method and a request log
  • Check email templates for postal address and working unsubscribe
  • Review everything when you add a new tool or cross a threshold

Building Privacy into Your Website

For most small businesses, privacy compliance is less about the text of any single statute and more about knowing what data your website collects and where it goes. Once the tags, forms and vendors are mapped, the notice, opt-outs and request handling follow. If you want your WordPress, WooCommerce, Shopify or Next.js site audited for pixels, forms and consent handling, see our business consulting services or contact us to talk it through.

Related posts

European Accessibility Act for E-Commerce Websites: What Stores Must Do article cover image
Compliance & Accessibility••12 min read

European Accessibility Act for E-Commerce Websites: What Stores Must Do

A practical guide to the European Accessibility Act (Directive (EU) 2019/882) for e-commerce and consumer service websites: who is in scope, the microenterprise exemption, EN 301 549 and WCAG, accessibility information, enforcement and a remediation plan for WooCommerce and Shopify stores.

Read article →

ADA Website Compliance for Small Businesses: A WCAG 2.2 AA Guide article cover image
Compliance & Accessibility••10 min read

ADA Website Compliance for Small Businesses: A WCAG 2.2 AA Guide

A plain-English guide to ADA website compliance for US small businesses: Title III and websites, the DOJ Title II rule for governments, why demand letters happen, why overlays do not make a site compliant, a WCAG 2.2 AA checklist and what to put in an accessibility statement.

Read article →

Google Consent Mode v2 and Cookie Consent: A Setup Guide for Business Sites article cover image
Compliance & Accessibility••10 min read

Google Consent Mode v2 and Cookie Consent: A Setup Guide for Business Sites

How to set up Google Consent Mode v2 alongside a compliant cookie banner: ePrivacy and PECR consent rules, the GDPR consent standard, the four consent parameters, basic versus advanced mode, CMP requirements, WordPress and Shopify implementation, Tag Assistant testing and common mistakes.

Read article →

Author

Anushka Dahanayake

Anushka Dahanayake builds SEO-focused websites, e-commerce platforms, dashboards, and automation systems for businesses worldwide.