Ask an American company which privacy law governs it and the honest answer is a spreadsheet. Since California's Consumer Privacy Act took effect in 2020, state legislatures have produced a steady procession of comprehensive privacy statutes — Virginia, Colorado, Connecticut, Utah, and then a wave that brought the count to roughly twenty states, with more bills moving each session.
This is what US privacy regulation looks like in the absence of a federal law: not a gap, but a patchwork. Congress has repeatedly come close — the American Data Privacy and Protection Act advanced further than any predecessor before stalling — and each failed federal attempt leaves the state regime more entrenched.
Why it matters
For businesses, the patchwork converts one compliance problem into many. The laws agree on the basics — consumers can access, correct and delete their data, and opt out of its sale and of targeted advertising — but diverge on nearly every operational detail: which companies are covered (revenue and volume thresholds differ), whether a cure period lets violators fix problems before penalties, how universal opt-out signals must be honored, and what sensitive-data consents require.
For consumers, the result is that privacy rights in the United States depend on a zip code. A Californian and a Texan hold statutory rights over the same data held by the same company; a resident of a state without a law holds none — beyond whatever the company grants voluntarily, which is often the California standard applied nationally because differentiation costs more than generosity.
How it works
Most of the state laws descend from the Washington Privacy Act template — controller/processor roles, consumer rights, opt-outs — rather than the more aggressive California model, which created a dedicated enforcement agency and a limited private right of action for data breaches. Enforcement otherwise sits with state attorneys general, and the early enforcement record shows a pattern: sweeps targeting industries (data brokers, connected vehicles, health-adjacent apps) rather than isolated complaints.
The operational keystone has become the Global Privacy Control signal: several states require businesses to honor this browser-level opt-out automatically, making a piece of browser plumbing the most consequential compliance surface in American privacy law.
Evidence
The IAPP's US state privacy legislation tracker maintains the running count and status of comprehensive state laws. The California Privacy Protection Agency publishes its regulations and enforcement advisories directly. The text of each statute — California's CCPA as amended by CPRA, Virginia's VCDPA, Colorado's CPA and the rest — is public through the respective legislatures, and state attorneys general, led publicly by California's, have announced investigative sweeps under these authorities.
The competing read
Industry groups argue the patchwork imposes real costs without proportional protection gains and have made federal preemption — one national law overriding the states — their top priority. Privacy advocates answer that the states moved only because Congress would not, that California-style floors have demonstrably improved national practice, and that any federal law weak enough to preempt the states would be a step backward. Both positions have enough support in Congress to keep the stalemate exactly where it is.
What happens next
Watch three fronts: new state laws in the 2027 sessions, which will push the count past twenty; attorney general enforcement maturing from sweeps into litigated precedent, especially around opt-out signals and sensitive data; and any revived federal bill, where the preemption question — whether a national law overrides California — remains the single issue on which every previous attempt has died.
