Verified as of August 2026: US privacy law changes every legislative session. This is operational translation, not legal advice. Get US privacy counsel for actual compliance decisions.
The US has no single federal consumer privacy law, so marketers operate under a patchwork of state statutes that differ on scope, consent model, and enforcement. The count of "US state privacy laws" varies wildly by source because some outlets count laws enacted and others count laws in effect on a given date: always check which, and always check the date. For day-to-day marketing, the practical breakage points are your Meta pixel, your GA4 configuration, your lead forms, and your retargeting lists.
I am a marketing strategist, not a lawyer, and I work with US brands from India: which means I've had to learn exactly where the operational line sits between "I can fix this in tag manager" and "this needs your counsel, today."
Key Takeaways
- Source counts of US state privacy laws differ because of the enacted-vs-in-effect distinction. Date-stamp every count you cite, including this one.
- The recurring marketing obligations across most comprehensive state laws: honour opt-outs of sale/sharing and targeted advertising, recognise universal opt-out signals like Global Privacy Control where required, get opt-in consent for sensitive data, and post an accurate privacy notice.
- TCPA "one-to-one consent" is widely misreported as in force. The FCC rule was vacated by the Eleventh Circuit in January 2025. Baseline TCPA prior-express-written-consent requirements still apply, and several state mini-TCPAs are stricter than federal law.
- Your highest-risk assets are usually the ones nobody owns: an old pixel on a landing page, a lead form with no consent language, and a lookalike audience built from a list with unclear provenance.
- Health, finance, education, and children's data carry heaviest exposure: edtech especially, because student data attracts additional regimes.
- Consent banners are not compliance. They are one control among several.
The patchwork is real, but the marketing-side obligations rhyme across states more than the headlines suggest.
Start with the honest framing
Most content ranking for this topic is written either by law firms for other lawyers, or by consent-management vendors who need you to conclude that you need a consent banner. Neither is dishonest, exactly. Neither is written for the person who has to decide on Tuesday whether to keep the Meta pixel firing on the pricing page.
This is the marketer translation. Where the answer is "ask a lawyer," I'll say so plainly rather than guessing.
The enacted vs in-effect trap
If you read that there are "twenty-something" comprehensive US state privacy laws, ask: enacted or in effect? A state can pass a law in 2025 with a 2027 effective date. Trackers count differently, so the same week can produce headline numbers several apart. The IAPP maintains a US state privacy legislation tracker that distinguishes these clearly: use a primary tracker with a date rather than a blog's number, and re-check it each quarter.
What the state laws actually ask of marketers
Across the comprehensive state consumer privacy laws now in effect, the marketing-relevant obligations cluster into a short list:
- Opt-out of "sale" or "sharing" of personal data. Several states define "sale" broadly enough to include passing data to ad platforms via pixels. This is the single most consequential definition for marketers.
- Opt-out of targeted advertising. Separate from sale in most states, and usually the one that touches retargeting directly.
- Universal opt-out signals. Some states require honouring browser-level signals such as Global Privacy Control. Whether your stack does this today is a testable question, go test it.
- Opt-in for sensitive data. Precise geolocation, health, biometric, immigration status, and in several states data revealing racial or ethnic origin, religion, or sexual orientation.
- Accurate privacy notice. Including categories collected, purposes, and how to exercise rights.
- Honouring deletion and access requests within statutory windows.
State-specific nuances matter and are exactly where counsel earns their fee. California, Colorado, Connecticut, Texas, Oregon, Virginia and others each have their own thresholds, definitions, and cure-period rules. Some state Attorney General offices publish marketer-readable guidance: the California AG's CCPA pages are a reasonable starting read, as is the Colorado AG's Universal Opt-Out Mechanism list.
Where it actually breaks: activity, risk, and what to check
This is the table I use in client kickoffs. Risk ratings are my operational judgment for a typical US-facing B2B or edtech brand, not a legal opinion.
| Marketing activity | Typical risk level | What actually breaks | What to check this week |
|---|---|---|---|
| Meta / TikTok / LinkedIn pixel firing on all pages | High | Pixel firing may constitute "sale" or "sharing" under several state definitions; firing before consent in opt-out states with UOOM requirements | Does the pixel respect your consent state? Does it suppress on Global Privacy Control? Is it on pages with sensitive context (health, finance, student status)? |
| GA4 with Google Signals / ads personalisation on | Medium-High | Signals enables ads-linked processing; default retention and IP handling may exceed your notice | Confirm Consent Mode is implemented and actually gating, not just present; review Signals on/off decision; verify retention setting matches your notice |
| Lead forms with no consent or notice language | High | No lawful basis story, no record of consent, and a downstream problem for every channel you use that data in | Add a notice link and a purpose statement at point of collection; store timestamp, IP, page URL, and exact language shown |
| Retargeting / custom audiences from CRM uploads | High | Uploading contacts who opted out of targeted advertising; provenance unclear on purchased or scraped lists | Can you prove where every contact came from? Is opt-out state synced to the ad platform before each upload? |
| Lookalike / seed audiences | Medium-High | Inherits every defect of the seed list, invisibly | Rebuild seeds from consented, first-party, opt-out-suppressed lists only |
| Session recording / heatmaps on forms | High | Can capture typed sensitive data; several states treat this harshly, and wiretapping-style claims have been a US litigation trend | Mask all inputs by default; exclude checkout, application, and account pages entirely |
| Chat widgets and third-party embeds | Medium | Vendor may process or retain visitor data outside your notice | Inventory every third-party script; get DPAs; remove anything unowned |
| Email marketing to purchased lists | High | CAN-SPAM plus state-law exposure plus deliverability collapse | Stop. Rebuild opt-in. This is rarely worth defending |
| SMS marketing | High | TCPA and stricter state mini-TCPAs; see the section below | Counsel review before any SMS programme launches or changes |
| Cookie banner present but non-functional | Medium-High | Banner records a choice that nothing downstream enforces: arguably worse than no banner | Set a preference to "reject," then watch the network tab. Do the tags actually stop? |
| Children's / student data (edtech) | High | COPPA, FERPA context, state student-privacy laws, and school-district contract terms all stack | Counsel, plus a data map, before any new collection |
| Privacy notice not matching actual stack | Medium-High | Every other control fails if the notice is inaccurate | Re-audit the notice against your live tag inventory quarterly |
The single most useful test
Set your consent preference to reject, load your five highest-traffic pages, and watch outbound network requests. Most teams discover at least one tag that ignores consent entirely. That finding is worth more than a month of policy reading.
The network tab is the honest auditor. What fires after "reject" is your actual compliance posture.
TCPA and the one-to-one consent misreporting
This deserves its own section because the misinformation is dense and persistent.
What is widely claimed: that "one-to-one consent" is required for telemarketing and lead-generation calls and texts in the US, meaning a consumer must consent separately to each individual seller.
What actually happened: the FCC adopted a rule that would have imposed a one-to-one consent requirement. The Eleventh Circuit vacated that rule in January 2025, before it took effect. Reporting and vendor marketing that treats one-to-one consent as current, binding federal law is inaccurate.
What still applies:
- Baseline TCPA requirements, including prior express written consent for autodialed or prerecorded telemarketing calls and texts, remain in force. Nothing about the vacatur removed those.
- State mini-TCPAs are in several cases stricter than federal law. Florida, Texas, Oklahoma and others have their own telephone solicitation statutes with their own consent, timing, and private-right-of-action provisions. A programme that satisfies federal TCPA can still violate a state statute.
- Litigation exposure in this area is substantial and driven heavily by private plaintiffs.
What to do: never write or accept a flat claim that "one-to-one consent is required." If you buy leads, do not rely on a vendor's compliance assertion: get counsel to review your consent capture, your disclosure language, and your state coverage before you dial or text. The FCC's own consumer and business guidance at fcc.gov, plus counsel, beat any agency blog post on this. Mine included.
What a marketer can fix without a lawyer
- Inventory every third-party script on the site. Delete what nobody owns.
- Mask form inputs in session recording tools; exclude sensitive pages.
- Implement and test consent gating rather than assuming the banner does it.
- Add point-of-collection notice and purpose language to every lead form, and log consent metadata.
- Sync opt-out status to ad platforms before every audience upload.
- Rebuild lookalike seeds from clean first-party data.
- Keep the privacy notice matched to the live stack, quarterly.
- Kill purchased email lists.
What genuinely needs US privacy counsel
- Whether your pixel usage constitutes "sale" or "sharing" in each state where you have consumers.
- Any SMS or outbound calling programme, and any purchased-lead arrangement.
- Anything involving health, financial, biometric, immigration status, children's, or student data.
- Your data processing agreements with vendors, including offshore ones, mine included.
- Your response process and timelines for consumer rights requests.
- Whether you meet applicability thresholds in each state at all. Many smaller B2B companies do not, and paying for controls you don't owe is its own waste.
A note on working with offshore teams
If you're a US brand working with a strategist or agency outside the US, again, that's me, build this into the contract rather than assuming it. Specify where data is processed and stored, who has access to CRM and ad accounts, what happens to data on termination, and that your privacy notice accurately reflects the arrangement. Have your counsel draft the DPA. A good offshore partner will sign a strict one without argument; that willingness is itself a useful screening signal.
FAQ
How many US state privacy laws are there in 2026? It depends entirely on whether the source is counting laws enacted or laws in effect, and on the date of the count. Use a primary tracker such as the IAPP's US state privacy legislation tracker and note the date you checked. Any number without that qualifier is unreliable.
Is one-to-one consent required under the TCPA? No: not as a flatly stated rule. The FCC rule that would have required it was vacated by the Eleventh Circuit in January 2025. Baseline TCPA prior-express-written-consent obligations still apply, and state mini-TCPAs in Florida, Texas, Oklahoma and elsewhere can be stricter. Get counsel before running any calling or texting programme.
Does running a Meta pixel count as selling data? Several state laws define "sale" or "sharing" broadly enough that it may. Whether it does in your specific configuration and states is a legal determination. This is a counsel question, and one worth asking early because the answer shapes your whole measurement stack.
Do I need a cookie banner in the US? It depends on your states, your thresholds, and what your tags do. A banner alone is not compliance; a banner whose choices nothing enforces is arguably worse than none. Test enforcement before you buy more banner.
What is Global Privacy Control and do I have to honour it? It's a browser-level opt-out signal. Some states require honouring universal opt-out mechanisms; requirements and recognised mechanisms vary by state and change over time. Colorado's AG publishes a list of recognised mechanisms. Verify with counsel whether it applies to you.
We're a B2B company, are we exempt? Sometimes partially, sometimes not at all. Several state laws have limited or no B2B exemptions, and California's approach has changed over time. Do not assume exemption; confirm it.
What about edtech and student data? Highest complexity tier. COPPA, FERPA context, state student-privacy statutes, and district contract terms can all apply simultaneously. Do not launch new collection without counsel and a data map.
Does GDPR compliance cover me for US states? No. It gives you useful infrastructure, data maps, DPAs, rights processes, but the US definitions of sale, sharing, and sensitive data, and the opt-out-first model, differ meaningfully from GDPR's opt-in model.
What's the fastest meaningful improvement? Run the reject-then-watch-the-network-tab test, delete unowned scripts, and add consent metadata logging to every lead form. That's a week of work and it removes a large share of the sloppiest exposure.
How often should we re-check all this? Quarterly at minimum for the tag inventory and privacy notice, and at every legislative session change for the legal picture. This post is verified as of August 2026 and will need re-checking by you before you rely on it.
If your growth stack has quietly outgrown your privacy notice, I can map what's firing, what's collecting, and what needs to go to your counsel: the operational half, honestly scoped. I'm a marketing strategist, not a lawyer, and I'll say so every time it matters. More at younusfardeen.com.