More U.S. States Pass Privacy Laws That Companies Need to Incorporate into Their Privacy Strategy
While the American Data Privacy Protection Act (“ADPPA”), the proposed federal comprehensive personal data privacy law, sits in committee in the U.S. Congress, State legislatures continue to be active and pass personal data privacy laws, forcing companies to continuously update their privacy strategies to incorporate these new laws. In 2023, four states (Virginia, Connecticut, Colorado, and Utah) have comprehensive data privacy laws coming into effect, joining California’s consumer data privacy law (“CCPA” and “CPRA”). So far in 2023, seven additional states (Iowa, Montana, Tennessee, Indiana, Florida, Texas, and Washington) have enacted data privacy laws, which become effective at various times between 2024 and 2026. With multiple other states having introduced data privacy legislation, it is expected that these seven states will be joined by others before the end of the year.
Given the various timeframes for when the seven new state privacy laws become effective, companies need to develop a comprehensive compliance strategy timeline and framework. One significant factor to consider in developing a strategy is the similarities and differences between the various state laws, which can help identify areas where compliance can be streamlined, helping to reduce associated costs.
Although certain “standards” or “norms” are starting to develop in the various U.S. state privacy laws, there are important differences between these laws. To ensure a comprehensive and compliant privacy program, it is important to identify and understand these differences. Below, we discuss some of the more important differences in these various state laws that companies should know and understand to efficiently strategize their personal data privacy implementation and compliance efforts.
Effective Dates
Just as important to understanding if a company is subject to these new laws is when a company must comply. Below is a summary of the various effective dates for these seven new laws.
- Montana – Montana Consumer Data Privacy Act (“MCDPA”) takes effect on October 1, 2024.
- Washington – My Health My Data Act (“MHMDA”) takes effect on March 31, 2024, for “regulated entities.” and on June 30, 2024, for “small businesses.”
- Texas – Texas Data Privacy and Security Act (“TDPSA”) takes effect on March 1, 2024.
- Florida – Florida Digital Bill of Rights (“FDBR”) takes effect on July 1, 2024.
- Iowa – Senate File 262 (“SF 262”) takes effect on January 1, 2025.
- Tennessee – Tennessee Information Protection Act (“TIPA”) takes effect on July 1, 2025.
- Indiana – Indiana Consumer Data Protection Act (“InCDPA”) takes effect on January 1, 2026.
As companies update their privacy compliance program, one important consideration will be how to stagger implementing compliance with the various state privacy laws, particularly where certain states have differences in compliance obligations. Despite the significant overlap and consistency of the various state laws, companies need to ensure that where there are differences, they understand those differences and have a plan to implement the respective state obligations by the effective date of the applicable state law.
Overview of Applicability and Covered Data
Before undertaking the task of updating a privacy program, a company should first determine whether it meets certain thresholds that make the new laws applicable to its operations and, if so, the scope and type of personal data the company may be collecting that is subject to those laws, especially since many of the new laws create additional burdens and obligations for particular subsets of personal data.
Regarding applicability, other than Texas, the new state privacy laws adopt either a processing volume approach, a revenue approach, or both, which is consistent with the current privacy laws.
In particular, the MCDPA and InCDPA take similar approaches to applicability as those under Virginia, Colorado, and Connecticut laws in that they only include a processing volume threshold and no revenue threshold. Notably, MCDPA has the lowest processing volume threshold of not less than 50,000 consumers, or of not less than 25,000 consumers if a covered company derives more than 25% of revenue from the sale of personal data processed. InCDPA applies to a company that processes personal data of at least 100,000 Indiana residents, or of at least 25,000 Indiana residents when deriving more than 50% of its gross revenue from the sale of personal data. TIPA and FDBR take California’s and Utah’s approaches to applicability: they include both a revenue threshold and a processing volume threshold. While TIPA, like California’s law, sets its revenue threshold to $25 million, FDBR has the highest revenue threshold among all state privacy laws—$1 billion in global gross annual revenues. Texas is unique amongst its peers in that it falls into neither camp in its approach to applicability and instead has a broad applicability. TDPSA applies to companies that conduct business in the state or target their products or services to Texans, regardless of revenue threshold or processing volume threshold, process or engage in the sale of personal data, but are not considered a “small business” as defined by the U.S. Small Business Administration. Small businesses, however, cannot sell sensitive personal data without obtaining consumer consent even though such entities are not otherwise subject to TDPSA.
All the new state data privacy laws regulate “personal data” and certain subsets of personal data, such as “sensitive data”, with heightened obligations. The definitions and scope of personal data and sensitive data under the new state privacy laws are generally consistent with the definitions for those terms under the existing laws, but a company needs to understand based on its collection practices if it is collecting “personal data” and/or “sensitive data” under each of the new laws. It is worth noting that the new laws generally exclude data collected in the commercial (business) or employment context from their definition of covered “personal data”. Thus, California remains the only state privacy law to cover such data as protected “personal data” since the CCPA business-to-business and human resources data exemptions sunset on January 1, 2023.
The Washington MHMDA is unique among its peers in that it specifically applies to “consumer health data”. This client alert does not explore the Washington MHMDA; instead it focuses on the new state privacy laws that apply to consumers’ “personal data”.
Consumer Privacy Rights
Each of the new laws, except Washington’s MHMDA, provides what the industry now considers the “standard” set of consumer rights—the right to access; correct; delete; data portability; and opt-out of sale of personal data, processing for purpose of targeted advertising, and profiling (which can implicate the use of automated decision making or AI systems).
The new state privacy laws diverge on the scope of these “standard” rights as well as other additional rights. For example, in the context of the right to opt-out, MCDPA is the only new state privacy law that follows an emerging trend of granting consumers the ability to exercise opt-out rights using a universal opt-out preference signal (also referred to as global privacy control). Specifically, MCDPA requires covered businesses to implement the use of global privacy controls by January 1, 2025, as does the Connecticut privacy law. It remains to be seen whether the use of such global privacy controls to grant consumers their right to opt-out will be adopted by other states that have already enacted their laws as well as those with proposed privacy bills.
MCDPA, FDBR, and TDPSA adopt the broader definition of what constitutes a “sale” of personal data as do the laws of California, Colorado, and Connecticut, which all include both monetary and other valuable considerations. This would require companies operating in Montana, Florida, and Texas to more thoroughly review what they receive from vendors and third parties in exchange for sharing or the disclosure of the personal data they collect. In contrast, InCDPA and TIPA adopt a narrow definition of “sale”, which includes only monetary consideration.
Consent Requirements
InCDPA, MCDPA, FDBR, TDPSA, and TIPA all require a covered business to obtain affirmative consent from individuals for certain processing activities (e.g., processing sensitive personal data). But MCDPA is unique among the new state privacy laws because it includes specific provisions for collection and use of a teens’ (i.e., ages 13 to 15) personal data, requiring businesses to obtain affirmative consent (e.g., an opt-in) of that teenager prior to processing the teens’ personal data for targeted advertising towards teens or selling that teen’s consumer data, where the business has actual knowledge that the teenager is between 13-15 years of age. Only California and Connecticut laws have similar provisions concerning privacy protections for a subset of minors. MCDPA also requires covered businesses to provide individuals, teen or otherwise, a mechanism to revoke their consent, an obligation only found in Connecticut law.
Data Protection Impact Assessment
Each of the existing state privacy laws, except for Utah, require businesses to conduct a data protection impact assessment (“DPIA”) for certain activities. Of the new state privacy laws, only Iowa follows Utah’s approach. In other words, InCDPA, MCDPA, FDBR, TDPSA, and TIPA all require businesses to conduct a DPIA for each of the following activities: (1) processing of sensitive data; (2) sale; (3) processing for targeted advertising; (4) profiling (automated decision-making that could have significant legal effects such as related to housing, drinking water, credit, etc.); and (5) processing activities that present a “heightened risk of harm” to consumers.
Notably, only Montana enumerates what is considered as processing activities that pose a “heightened risk of harm” to consumers. With only MCDPA and the Colorado Privacy Act defining this concept, it remains to be seen whether there will be any deviation in what activities will subject various businesses to the DPIA obligations under the growing state privacy regimes. In an effort to streamline compliance obligations, each of the new state privacy laws that include DPIA obligations allows companies to use DPIAs performed by the company to comply with other state laws, as long as they are reasonably comparable in scope and effect, in order to satisfy the DPIA requirement. Companies subject to the new state privacy laws will need to look to DPIA regulatory guidance under Colorado Privacy Act and MCDPA for clarity on what processing activities present a “heightened risk of harm” to consumers and develop a DPIA policy and procedure based on Colorado’s and Montana’s requirements.
Enforcement and Cure Periods
Iowa’s SF 262, InCDPA, MCDPA, FDBR, TDPSA, and TIPA do not provide a private right of action for violations; in contrast, Washington’s MHMDA grants consumers a private right of action for violations. Unlike MHMDA, each of the other six new laws grants exclusive enforcement authority to the respective state Attorney General, who must provide companies with a right to cure. The cure periods under each are:
- Iowa: 90-day cure period
- Indiana: 30-day cure period
- Montana: 60-day cure period
- Florida: 45-day cure period
- Texas: 30-day cure period
- Tennessee: 60-day cure period
Interestingly, MCDPA is the first of these new state privacy laws that will sunset the cure period, which expires after April 1, 2026, creating a heightened potential for enforcement activity in Montana after that date.
Companies that fail to cure their alleged violations will face injunction and civil penalties up to $7,500 per violation. Distinguished from its peers, TIPA, like California’s law, imposes not only civil penalties of $7,500 for each uncured violation, but also allows treble damages for willful or knowing violations, raising the potential civil penalty cap. Thus, total civil penalty under TIPA for willful or knowing violations would be comparable to those under California’s law. Notably, TIPA also includes a potential safe harbor against enforcement action for violations that further distinguishes it from not only the newly enacted state privacy laws, but also from the existing state privacy laws. Under TIPA, companies that adopt privacy programs that (A) “reasonably conform” to the NIST privacy framework, (2) are updated regularly, and (3) afford Tennessee consumers their TIPA rights may enjoy the safe harbor for their “alleged violations.”
FDBR is unique from all other state privacy laws in that it allows civil penalties for each violation up to $50,000. FDBR civil penalty may be tripled for certain violations, including those involving a known child and continuing to sell or share a consumer’s “personal data” against the consumer’s choice to opt-out.
Conclusion
The recently enacted new state privacy laws are similar to many of the existing five state privacy laws. There are some notable differences we’ve described here that businesses covered by these existing privacy laws need to understand to update their existing privacy compliance programs, including updating privacy policies/notices; revising their cybersecurity policies, practices, and controls; incorporating NIST standards to their policies and processes; updating consumer rights notifications and responses; and updating internal training programs regarding consumers’ personal data.

