Comparing State Privacy Laws

Staying on top of the ever-evolving landscape of state privacy laws continues to get more challenging. Legislatures across the country have debated their own versions of a privacy law. To date, five states have passed a law:

The five state laws that are on the books are not carbon copies of each other. There are significant differences involving cure times, private right of action, applicability thresholds, and more. To help you better understand your organization’s obligations and risks in each state, we are providing this side-by-side comparison of the laws.

Effective dates

StateEffective data
CaliforniaOperative January 1, 2023, Enforceable July 1, 2023
ColoradoJuly 1, 2023
ConnecticutJuly 1, 2023
UtahDecember 31, 2023
VirginiaJanuary 1, 2023

Fines

StateFines
California$2,500-$7,500 per violation
ColoradoUp to $20,000 per violation
ConnecticutUp to $5,000 per violation
UtahUp to $7,500 per violation
VirginiaUp to $7,500 per violation

Cure Period

A cure period is the amount of time to remedy a violation after its discovery before a fine is issued. California is the only state without a cure period, increasing the risk of a fine.

StateCure Period
CaliforniaNo right to cure
Colorado60 days (expires in 2025)
Connecticut60 days (expires in 2025)
Utah30 days
Virginia30 days

Applicability Thresholds

The thresholds that determine if the privacy laws apply to your organization vary by state.

StateApplicability Thresholds
California
  • Has annual revenue of $25 million or more
  • Controls or possesses the data of 100,000 or more California residents
  • Derives 50% or more of its revenue from the sale of personal data
Colorado
  • Controls or possesses the data of 100,000 or more Colorado residents
  • Derives any revenue from the sale of data for 25,000 or more Colorado residents
Connecticut
  • Controls or possesses the data of 100,000 or more Connecticut residents
  • Derives 25% of its revenue from the sale of data for 25,000 or more Connecticut residents
UtahHas more than $25 million in annual revenue and meets one or more of the following criteria:
  • Controls or possesses the data of 100,000 or more Utah residents
  • Derives 50% or more of its revenue from the sale of data for more than 25,000 Utah residents
Virginia
  • Controls or possesses the data of 100,000 or more Virginia residents
  • Derives 50% or more of its revenue from the sale of data for more than 25,000 Virginia residents

Exemptions

There are some key exemptions that apply to state privacy laws, most notably for the Gramm-Leach-Biley-Act (GLBA) and HIPAA. For all existing state laws, data that is covered under GLBA or HIPAA is exempt. In certain cases, an entire entity that falls under the GLBA or HIPAA umbrella is exempt.

StateGLBAHIPAA
CaliforniaDataData
ColoradoData & EntityData
ConnecticutData & EntityData & Entity
UtahData & EntityData & Entity
VirginiaData & EntityData & Entity

Sale Definitions and Opt-out Considerations

What is considered a “sale” of data varies between the states. States with a broad definition consider the exchange of monetary or other valuable consideration a “sale.” States with a traditional definition consider a “sale” to be the exchange of data for money.

In all 5 states, organizations must allow people to opt out of targeted advertising. In California, organizations must also provide the option to opt out of having their data shared.

StateSale DefinitionOpt-out
CaliforniaBroadSale and Sharing
ColoradoBroadSale and Targeted Advertising
ConnecticutBroadSale and Targeted Advertising
UtahTraditionalSale and Targeted Advertising
VirginiaTraditionalSale and Targeted Advertising

Other California Considerations

The CPRA does not exempt business-to-business or employee data, the other state laws do.

Also included in the CPRA is the private right of action which authorizes consumers to file lawsuits for breaches. Damages from a private right of action suite can range from $100-$750 per consumer per incident. Breaches often include hundreds or thousands of personal records, so the private right of action exposes organizations to large financial risks.

For a more in-depth exploration of state privacy laws watch our Current State of Privacy Laws webinar.

CompliancePoint has a team of privacy professionals that can help your organization stay in compliance with all state laws and avoid risk. Contact us today at connect@compliancepoint.com to learn more about how we can help you.

Finding a credible expert with the appropriate background, expertise, and credentials can be difficult. CompliancePoint is here to help.