Skip to content
complianceofficer

CCPA compliance software and data privacy management software for every US state privacy law

CCPA compliance software is the system that answers three questions on demand: which state privacy laws you have crossed the threshold into, what personal data you hold about the people those laws protect, and whether you answered their requests inside the statutory clock. As of August 2026 that is 20 state statutes in force, or 21 counting Florida, and three more already signed.

The hard part stopped being California years ago. It is that the rules now move several times a year in states you already sell into, cure periods are expiring one by one, and nobody on the team is watching. Complianceofficer tracks the statutes themselves and points at the specific policy each change breaks.

Every threshold, date and penalty figure on this page was checked against the California Privacy Protection Agency and state enforcement sources on 17 August 2026. Where trackers disagree on a count, this page says why.

Find out which state privacy laws you have already triggered

Pick your industry and size. The scan returns the obligations that apply to an organization like yours, the regulatory movement behind each line over the last 12 months, and the primary source for every claim. No signup, nothing stored.

§ Live · Compliance scan

No signup. Nothing you pick is stored.

Frameworks you answer to

Sample register · fintech, US · what a scan returns

  • § 01 Written AML program with a named officer
  • § 02 KYC and customer due diligence
  • § 03 Sanctions screening lists Changed
  • § 04 PCI DSS v4.0 validation
§ 81 The map

Every US state privacy law in force, with the date it started

Published counts of state privacy laws range from 19 to 24 and all of them are defensible, which tells you the number is not the useful thing. The disagreement comes from two choices: whether you count laws that are enacted but not yet effective, and whether you count Florida, whose Digital Bill of Rights only applies above $1 billion in global gross revenue and so behaves nothing like the others. Here is the version that matters to a buyer, which is the date each one started biting.

State Statute In force since Note for buyers
California CCPA, as amended by the CPRA 1 Jan 2020, CPRA changes 1 Jan 2023 The only one covering employees and B2B contacts
Virginia VCDPA 1 Jan 2023 The template most later states copied
Colorado CPA 1 Jul 2023 Universal opt-out signal required, cure period gone
Connecticut CTDPA 1 Jul 2023 Amended again effective 1 Jul 2026
Utah UCPA 31 Dec 2023 Narrowest of the group, amended effective 1 Jul 2026
Texas TDPSA 1 Jul 2024 No revenue threshold, so small sellers are caught
Oregon OCPA 1 Jul 2024 Amendments effective 1 Jan 2026
Florida FDBR 1 Jul 2024 Only above $1bn revenue, which is why counts differ
Montana MCDPA 1 Oct 2024 Low thresholds, cure period expired 1 Apr 2026
Delaware DPDPA 1 Jan 2025 Cure period expired 1 Jan 2026
Iowa ICDPA 1 Jan 2025 Notably lighter obligations than its neighbors
Nebraska NDPA 1 Jan 2025 Follows the Texas model, no revenue threshold
New Hampshire NHDPA 1 Jan 2025 35,000 consumer threshold, low for a small state
New Jersey NJDPA 15 Jan 2025 Rulemaking authority, so expect more detail later
Tennessee TIPA 1 Jul 2025 Affirmative defense for an NIST-aligned program
Minnesota MCDPA 31 Jul 2025 Right to question profiling results, cure gone
Maryland MODPA 1 Oct 2025 Strictest in the country on data minimization
Indiana INCDPA 1 Jan 2026 Long runway, enacted 2023 and effective 2026
Kentucky KCDPA 1 Jan 2026 Close copy of Virginia
Rhode Island RIDTPPA 1 Jan 2026 Unusual public disclosure duty for third party sales
Arkansas ADRSTA 1 Jul 2026 Newest in force, adds profiling opt-out rights
Oklahoma OKCDPA 1 Jan 2027 Signed 20 Mar 2026, not yet in force
Alabama APDPA 1 May 2027 Signed 16 Apr 2026, not yet in force
Vermont VDPOSA 1 Jan 2028 Signed 16 Jun 2026, longest runway of any state

The last three rows are enacted and dated but not yet enforceable. If a vendor tells you their content library covers 24 states today, that is the number they are using, and it includes laws nobody can be fined under for another 16 months.

§ 82 Applicability

Do you have to comply with the CCPA?

You do if you are a for-profit business that does business in California and meets any one of three tests. The revenue test is the one most often quoted wrong, because the statute still prints $25,000,000 while the operative number has been higher since 1 January 2025. The California Privacy Protection Agency adjusts it for inflation every two years, and the current figure is $26,625,000 in annual gross revenue.

Test one

Revenue above $26,625,000

Annual gross revenue, global, not California revenue. This is the test that catches ordinary mid-market companies with a handful of California customers, and it is the reason so many businesses are in scope without ever having thought about it.

Test two

100,000 consumers or households

Buying, selling or sharing the personal information of 100,000 or more California consumers or households in a calendar year. Households count as units, so a consumer marketing list can cross this line faster than a headcount-based estimate suggests.

Test three

50 percent of revenue from data

Deriving 50 percent or more of annual revenue from selling or sharing personal information. No revenue floor applies here, so a small ad tech or lead generation business is fully in scope on day one.

The exemption people assume they have, and do not

California is the only state whose comprehensive privacy law covers employees, job applicants and business to business contacts. The temporary carve-outs for both expired on 1 January 2023 when the CPRA took full effect. That single difference changes the shape of a compliance program more than any other item on this page: your HR records, your applicant tracking system and your CRM all become in-scope systems, each with its own retention schedule, notice at collection and deletion path.

Every other state law on the table above applies only to consumers acting in a personal capacity. If you build a program to the California standard, the other 20 states are a narrowing exercise. If you build to Virginia and later cross into California, you are starting over on the hardest data you own.

§ 83 Enforcement

The cure period is disappearing, one state at a time

Most state privacy laws launched with a right to cure: the attorney general had to send a notice and give you 30 or 60 days to fix the problem before any penalty could attach. That was the single biggest reason a stretched team could rationally defer privacy work. It is now gone in five states, and the pattern is that these provisions were written with sunset dates from the start. Check this column before you plan a remediation schedule.

State Cure period status What it means now
Connecticut Sunset 31 Dec 2024 Cure is discretionary, the AG is not obliged to offer it
Colorado Expired 1 Jan 2025 Immediate enforcement authority
Delaware Expired 1 Jan 2026 Immediate enforcement authority
Minnesota Sunset 31 Jan 2026 Immediate enforcement authority
Montana Expired 1 Apr 2026 Immediate enforcement authority
California No mandatory cure since the CPRA The CPPA may allow time to cure, but need not

What a CCPA penalty actually costs

The inflation-adjusted figures effective 1 January 2025 are $2,663 per violation and $7,988 for each intentional violation and each violation involving a consumer under 16. Separately, the CCPA carries a private right of action for breaches of unencrypted, unredacted personal information, with statutory damages of $107 to $799 per consumer per incident and no requirement to prove actual harm.

The multiplier is what matters. Both figures are per consumer, so the size of your exposure is set by the size of your database rather than the seriousness of the mistake. A misconfigured opt-out link on a page seen by 50,000 Californians is arithmetically a different event from the same mistake at a company with 500 customers.

§ 84 Data brokers

If you are a data broker, the clock started on 1 August 2026

California's Delete Act created a single deletion channel called DROP, the Delete Request and Opt-out Platform. A California resident submits one request and it reaches every registered data broker at once. Consumers have been able to use it since 1 January 2026, and by spring more than 300,000 Californians had filed requests through it.

The obligation on the other side began on 1 August 2026. From that date a registered data broker must access DROP at least once every 45 days, retrieve the pending requests and process them. Two details catch companies out. First, access is restricted to the registered broker itself, so a consent or privacy management vendor cannot log in on your behalf, and any tool you buy has to fit around that. Second, SB 361 doubled the daily administrative fine for failing to register, so the penalty for the paperwork step now compounds faster than most teams assume.

The definition of data broker is broader than the phrase suggests. It reaches any business that knowingly collects and sells personal information about consumers with whom it has no direct relationship. Plenty of lead generation, ad tech, market research and enrichment businesses meet it without using the label internally.

§ 85 What to buy

What data privacy management software has to do

Privacy management software gets sold as one product and bought as four separate jobs. Teams routinely buy a cookie banner and believe they have bought a privacy program. Work out which of these you actually lack before you take a demo.

Data inventory and mapping

A record of what personal data you hold, in which system, for what purpose, shared with whom, kept for how long. Every other function depends on it. This is the part teams skip because it is the only part that cannot be bought as a finished artifact, and it is the reason deletion requests take four weeks instead of four minutes.

Consumer rights request handling

Intake, identity verification, routing to system owners, and a defensible record of what was returned or deleted, all against a 45 day clock that starts at receipt. Judge this feature on whether it reaches into your actual systems or just produces a ticket that a human then has to fulfil by hand.

Consent and universal opt-out signals

Several states now require you to honor a browser-level opt-out signal such as Global Privacy Control, not merely offer a link. That is a technical integration with your tag manager and ad stack, and it is the most common thing an attorney general finds broken when they look, because it silently stops working after a site change.

Assessments and change monitoring

Most state laws require a documented data protection assessment before higher risk processing such as targeted advertising, sale of data, or profiling with legal effects. And because the rulebook moves several times a year, something has to notice when a statute you rely on is amended. That is the layer almost nothing covers.

Privacy sits inside a wider obligation set for most regulated buyers, which is why teams that start here usually end up mapping it against the rest of their program. If you are building the register rather than just the request queue, our regulatory compliance software pillar covers the obligation and control layers, and regulatory change management covers the feed that keeps both current.

§ 86 CCPA vs GDPR

CCPA compliance and GDPR compliance are not the same program

The most expensive assumption in this category is that a GDPR program covers you in the United States. The two laws are built on opposite defaults, and the gaps run in both directions.

Dimension CCPA and US state laws GDPR
Default posture Process first, consumer opts out afterward Lawful basis required before processing at all
Who is covered Only businesses over revenue or volume thresholds Any organization processing EU personal data
Employee data Covered in California only, not in other states Fully covered everywhere
Response clock 45 days, one 45 day extension One month, extendable by two further months
Signature obligation Honor a browser opt-out signal automatically Collect and record valid consent before use
Private lawsuits Breach only, $107 to $799 per consumer Broad right to compensation for damage

If the European side is also in scope for you, our GDPR compliance software page covers that regime on its own terms, including transfers and the current status of the EU-US Data Privacy Framework. Health data has a third overlay again, which is handled on our HIPAA compliance software page, and a HIPAA covered entity is generally exempt from the state consumer laws for the data HIPAA already governs, but not for the rest of what it holds.

§ 87 Buying

What to ask a privacy management software vendor

Demos in this category are built around a request intake form, which is the easy part. These are the questions that separate a privacy platform from a ticketing queue with a cookie banner attached.

  1. When a state amends its law, what reaches me and how fast? Ask for the last three examples with dates. Connecticut, Utah and Oregon all changed in 2026. If the answer is a quarterly content refresh, you will learn about a change after your obligations already moved.
  2. Does deletion actually reach my systems? A request handled inside the tool but fulfilled by hand in your CRM, warehouse and backups is a workflow, not automation. Ask which of your systems it writes to, and what the record looks like afterward.
  3. How do you prove the opt-out signal is still working? Global Privacy Control handling breaks quietly during site changes. You want continuous verification with dated evidence, not a one-time implementation check.
  4. What happens to my price when the next state takes effect? Three more laws are already dated. If the contract prices per jurisdiction, you are signing up for increases in January 2027, May 2027 and January 2028.
  5. What is the total first-year cost with implementation? Implementation, integration and required training routinely add a meaningful share on top of subscription. Our compliance software pricing benchmark sets out what buyers have recorded paying across the wider category.
§ 88 Questions buyers ask

CCPA compliance software questions

What is CCPA compliance software?

CCPA compliance software is the system a business uses to meet the California Consumer Privacy Act and the state privacy statutes that copy it: a record of what personal data it holds and why, a way to receive and answer consumer rights requests on the statutory clock, opt-out signals honored across the site, and evidence that all of it happened. In practice most buyers need one system covering every state they trigger, not a California-only tool.

Who has to comply with the CCPA?

A for-profit business that does business in California and meets any one of three tests: annual gross revenue above $26,625,000, or buying, selling or sharing the personal information of 100,000 or more California consumers or households in a year, or deriving 50 percent or more of annual revenue from selling or sharing personal information. The revenue figure is the inflation-adjusted one the California Privacy Protection Agency set effective 1 January 2025. The statute text still prints $25,000,000.

How many states have data privacy laws?

As of August 2026, 20 states have a comprehensive consumer privacy law in force, or 21 if you count Florida, whose Digital Bill of Rights only reaches businesses above $1 billion in global gross revenue. That inconsistency is why published counts range from 19 to 24. Three more are enacted and waiting: Oklahoma on 1 January 2027, Alabama on 1 May 2027 and Vermont on 1 January 2028.

What is the difference between CCPA and GDPR?

The GDPR requires a lawful basis before you process personal data at all, so consent or legitimate interest comes first. The CCPA assumes you may process and gives the consumer rights afterward, chiefly the right to opt out of sale or sharing. The GDPR reaches every organization touching EU personal data regardless of size; the CCPA only reaches businesses over its thresholds. The CCPA is also the only US state law that covers employees and business contacts.

How much does CCPA compliance software cost?

Dedicated privacy management platforms are usually quoted on the number of consumer requests handled, the number of websites or properties scanned, and the number of state laws in scope, which is why a small business quote and an enterprise quote can differ by a factor of twenty. Almost nothing in the category publishes a price. Budget for a quoted annual contract and ask what happens to the price when the next state law takes effect.

What are the penalties for violating the CCPA?

Administrative fines run to $2,663 per violation, or $7,988 per intentional violation and per violation involving a minor, using the inflation-adjusted figures effective 1 January 2025. Separately, consumers can sue over a breach of unencrypted personal information for statutory damages of $107 to $799 per consumer per incident, without proving actual harm. Because the fine is per violation and per consumer, exposure scales with your record count.

Do I need separate software for each state privacy law?

No, and buying that way is the common expensive mistake. The state laws share most of their machinery: access, correction, deletion, portability, opt-out of targeted advertising and sale, universal opt-out signal recognition, and a data protection assessment for higher risk processing. Build one program to the strictest applicable standard, then track the state-specific deltas such as thresholds, response clocks and whether a cure period still exists.

How long do I have to respond to a CCPA request?

You must confirm receipt of a verifiable consumer request within 10 business days and respond substantively within 45 calendar days of receiving the request, counting from receipt rather than from verification. One further 45 day extension is available when reasonably necessary, provided you notify the consumer of the extension and the reason within the first 45 days. Other state laws generally use 45 days with a 45 day extension too.

Is there a cure period for state privacy law violations?

In a growing number of states, no. Connecticut let its cure period sunset on 31 December 2024, Colorado on 1 January 2025, Minnesota on 31 January 2026, Delaware on 1 January 2026 and Montana on 1 April 2026. In those states an attorney general can act on a violation immediately rather than sending a 30 day warning first. Several other states still keep a mandatory cure window written into the statute.

Last updated August 2026.

§ 99 · Final entry

Get on the early-access list

Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.

§ 90

Related registers