US state privacy law is a patchwork of consumer-rights frameworks that each defines what personal data businesses must protect, who qualifies as a covered consumer, and which agency holds enforcement authority. Three states have moved furthest: California with the California Consumer Privacy Act (CCPA) and its successor ballot measure, Virginia with the Virginia Consumer Data Protection Act (VCDPA), and Colorado with the Colorado Privacy Act (CPA). Each statute reflects local political priorities and drafting choices, producing a fragmented landscape that businesses operating across state lines must navigate simultaneously.
The California Consumer Privacy Act, the Virginia Consumer Data Protection Act, and the Colorado Privacy Act share a common lineage, each borrowing vocabulary from the EU's General Data Protection Regulation, but they diverged on applicability thresholds, enforcement architecture, and the mechanics consumers use to exercise control. Understanding those divergences, not just the surface similarities, is what shapes a compliant multi-state program. Background on how GDPR principles influenced these domestic frameworks appears in the GDPR enforcement mechanisms and their influence on US privacy law.
What State Privacy Laws Actually Regulate
Each US state privacy law shares a common vocabulary but defines its core terms differently, and those definitional gaps determine which businesses comply and which consumers have standing. Each law centers on the relationship between a controller (the entity that determines the purposes and means of processing) and a processor (a vendor that processes data on the controller's behalf). The consumer is the individual whose rights the law protects, and personal data is the category of information those rights attach to.
- Personal data (California)
- Information that identifies, relates to, describes, or is reasonably capable of being associated with a particular consumer or household. This is a broader definition than Virginia's or Colorado's formulations, encompassing household-level data.
- Personal data (Virginia)
- Any information linked or reasonably linkable to an identified or identifiable natural person. The Virginia Consumer Data Protection Act explicitly excludes de-identified data and publicly available information from this definition (law.lis.virginia.gov §59.1-575).
- Consumer (Virginia)
- A natural person who is a resident of the Commonwealth acting only in an individual or household context. Persons acting in a commercial or employment context are excluded from VCDPA coverage (law.lis.virginia.gov §59.1-575).
- Precise geolocation data (Virginia)
- Location information derived from technology, such as GPS coordinates, that identifies a person's location within a radius of 1,750 feet. This places it in the sensitive data category requiring explicit consent under the VCDPA (law.lis.virginia.gov §59.1-575).
- Consent (Virginia)
- A clear affirmative act signifying a consumer's freely given, specific, informed, and unambiguous agreement to process personal data. This tracks GDPR's consent standard more closely than California's framework (law.lis.virginia.gov §59.1-575).
Sensitive data categories span all three statutes but vary in their exact lists. Biometric identifiers, precise geolocation, and health data appear across each law, though the coverage thresholds for biometric data protection legal frameworks differ by state. The definitional architecture sets the foundation for every obligation that follows.
Consumer Rights: How the Three Laws Compare
US state privacy law grants consumers a core set of access and control rights, but the scope of those rights and which businesses must honor them varies by state. California's framework, codified through the California Consumer Privacy Act and expanded by the CPRA amendment (the California Privacy Rights Act of 2020), provides the most comprehensive set of consumer rights among the three states, as documented by the California Attorney General (oag.ca.gov/privacy/ccpa). Virginia and Colorado grant comparable core rights, though each carries its own scope conditions and exceptions.
| Right | CCPA (California) | VCDPA (Virginia) | CPA (Colorado) |
|---|---|---|---|
| Right to Know / Access | Consumers may request disclosure of categories and specific pieces of personal data collected, the sources, purposes, and third parties with whom data is shared. | Consumers may confirm whether a controller is processing their personal data and request a copy in portable format. | Consumers may access personal data a controller holds about them and receive it in a portable, usable format. |
| Right to Delete | Consumers may request deletion of personal data the business collected, subject to enumerated exceptions for completing transactions or legal obligations. | Consumers may request deletion of personal data provided by or obtained about them, subject to exceptions. | Consumers may request deletion of personal data a controller collected, with exceptions for legal obligations and certain processing purposes. |
| Right to Correct | Added by CPRA, effective January 1, 2023: consumers may correct inaccurate personal data a business holds about them (oag.ca.gov). | Consumers may correct inaccuracies in personal data, accounting for the nature and purpose of processing. | Consumers may correct inaccurate personal data a controller holds about them. |
| Opt-Out of Sale / Sharing | Consumers may opt out of the sale or sharing of their personal data, including via the global privacy control signal, per California AG guidance (oag.ca.gov). | Consumers may opt out of processing for targeted advertising, sale of personal data, or profiling that produces legal or similarly significant effects. | Consumers may opt out of processing for targeted advertising, sale of personal data, or profiling with legal or similarly significant effects. |
| Limit Sensitive Data Use | Effective January 1, 2023: consumers may limit the use and disclosure of sensitive personal information to the purposes listed in the CPRA (oag.ca.gov). | Controllers must obtain consumer consent before processing sensitive data; the consent requirement applies at the point of collection rather than via a separate limiting right. | Controllers must obtain consent before processing sensitive data; consumers may withdraw consent at any time. |
| Non-Discrimination | Businesses may not discriminate against consumers for exercising their CCPA rights, including by denying goods or services or charging different prices (oag.ca.gov). | Controllers may not retaliate against consumers for exercising their VCDPA rights. | Controllers may not discriminate against consumers for exercising their CPA rights. |
| Private Right of Action | Limited: applies to certain data breaches involving unencrypted, unredacted personal data. No broad private cause of action for general CCPA violations. | None. Enforcement is exclusively with the Virginia Attorney General. | None. Enforcement is exclusively with the Colorado Attorney General. |
Applicability Thresholds and Business Scope
Whether a business falls under a US state privacy law depends on a combination of revenue size, data-processing volume, and the percentage of revenue derived from data sales. The California Consumer Privacy Act sets its applicability conditions in terms the California Attorney General's office has published directly: the CCPA applies to for-profit businesses that do business in California and meet at least one of three thresholds, buying or selling the personal data of 100,000 or more consumers or households per year, or deriving 50 percent or more of annual revenues from selling or sharing personal data, or meeting a specified annual gross revenue level. The CCPA also explicitly covers data brokers (oag.ca.gov/privacy/ccpa).
Virginia and Colorado both apply comparable revenue and data-volume thresholds for defining which controllers fall under their respective laws, though the specific figures should be confirmed against current statute text. The Virginia Consumer Data Protection Act and the Colorado Privacy Act are oriented around controllers rather than businesses, meaning the legal obligations attach to any entity that determines the purpose and means of processing. The CPA was enacted as Colorado Senate Bill 21-190, establishing the framework that later amendments have updated (leg.colorado.gov/bills/sb21-190).
Several structural differences in scope are worth noting for cross-state compliance planning:
- Employee and B2B data. California's CCPA, as amended by the CPRA, extended full consumer rights to employees and business contacts. Virginia's VCDPA limits coverage to consumers acting in individual or household contexts, leaving employment data largely outside the statute's reach.
- Household data. California's definition of personal data encompasses household-level data, not just individual-level records. Virginia and Colorado tie their definitions to identifiable natural persons, excluding household aggregations.
- Data brokers. California explicitly names data brokers as a covered category with additional registration obligations. Virginia and Colorado address data broker activities through the controller and processor framework without a separate registration regime.
- Nonprofit and government exemptions. Both Virginia and Colorado exempt nonprofit organizations and government entities from their statutes. California's law applies primarily to for-profit entities, though the boundaries of certain exemptions differ by context.
- Entity-level versus data-level coverage. California's CCPA applies at the entity level once a threshold is crossed; Virginia and Colorado apply at the level of processing activity, so a company could be a controller under some activities and a processor under others simultaneously.
Sensitive Data and Opt-Out Mechanics
Each law carves out a category of sensitive personal data requiring stronger protections, and each establishes a distinct mechanism for consumers to signal their opt-out preferences. California's CCPA, as updated by the CPRA, lists sensitive personal information as a defined subcategory covering Social Security numbers, financial account data, precise geolocation, racial or ethnic origin, religious beliefs, union membership, health information, and certain communications content. Consumers gained the right to limit the use of sensitive personal information effective January 1, 2023, per California AG guidance (oag.ca.gov/privacy/ccpa).
Virginia's VCDPA treats sensitive data as a consent-gated category: controllers must obtain explicit consumer consent before processing data in any of the sensitive categories, which include personal data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnoses, sexual orientation, immigration status, and biometric or genetic data. Precise geolocation data, defined under the VCDPA as location information accurate within 1,750 feet, also requires consent (law.lis.virginia.gov §59.1-575). Colorado's CPA uses a similar consent-first approach for sensitive data processing.
The opt-out architectures diverge most visibly in how each state handles automated signals. Key differences include:
- California and the global privacy control (GPC). The CCPA framework explicitly requires businesses to honor the global privacy control as a valid opt-out mechanism under official California AG guidance. A consumer who configures a GPC-enabled browser communicates an automatic opt-out of sale and sharing to every site visited, without submitting individual requests. This is a legally binding obligation for covered California businesses. The cookie-based advertising opt-out mechanics article explains how GPC interacts with consent-management platforms in practice.
- Colorado and universal opt-out signals. The Colorado Privacy Act similarly requires controllers to recognize universal opt-out mechanisms, including GPC-compatible signals. Colorado sets a compliance timeline for honoring these signals, making it one of two states with a mandatory automated opt-out recognition requirement.
- Virginia and request-based opt-out. The VCDPA requires controllers to respond to consumer opt-out requests for targeted advertising, data sales, and certain profiling, but the statute does not mandate recognition of automated signals such as GPC. Consumers must submit individual opt-out requests through a controller's designated channels.
- Data protection assessments. Both Virginia and Colorado require controllers to conduct data protection assessments before undertaking processing activities that present heightened risk, including processing sensitive data and processing for targeted advertising or profiling. California imposes comparable risk assessment obligations under CPRA rulemaking.
- Opt-in consent for minors. All three statutes impose stricter standards for processing personal data of children or minors. California's CCPA prohibits the sale or sharing of data of consumers under 16 without opt-in consent. Virginia and Colorado require opt-in consent for sensitive data processing of minors under their respective thresholds.
Enforcement Architecture and Cure Periods
Enforcement design is where the three laws diverge most sharply: California created a dedicated rulemaking agency, while Virginia and Colorado place enforcement exclusively with their state attorneys general. California established the California Privacy Protection Agency (CPPA) through a 2020 ballot measure. The CPPA assumed rulemaking and enforcement authority from the California AG for the CCPA framework, making California the only US state with a standalone data protection regulator. Civil penalties under the CCPA can reach up to $7,500 per intentional violation (oag.ca.gov/privacy/ccpa; oag.ca.gov/privacy/ccpa/regs).
Virginia and Colorado vest enforcement authority exclusively in their respective attorneys general. Neither state created a parallel regulatory agency. The GDPR enforcement mechanisms and their influence on US privacy law provides useful comparative context for understanding why the agency model emerged in California but not in other states. Key structural differences in enforcement include:
- California CPPA. The California Privacy Protection Agency has independent rulemaking authority, can issue regulations, and investigates and prosecutes violations. The California AG retains concurrent enforcement authority in some areas, and consumers retain a limited private right of action for certain data breaches involving unredacted personal data.
- Virginia Attorney General. The Virginia AG holds exclusive enforcement authority. There is no private right of action under the Virginia Consumer Data Protection Act, and consumers cannot sue controllers directly. The AG may bring civil actions and seek civil penalties. Virginia's statute included a cure period allowing controllers to remedy violations before penalty enforcement, though amendments have modified its application.
- Colorado Attorney General. The Colorado AG similarly holds exclusive enforcement authority under the CPA, with no private right of action available to consumers. Colorado's original statute included a cure period during which controllers notified of a violation had a defined window to remediate. A subsequent amendment set a sunset date for the automatic cure period, requiring the AG to exercise discretion on a case-by-case basis after that date.
- Rulemaking authority. California's CPPA can issue binding regulations independent of the AG. Virginia's AG has no separate rulemaking authority under the VCDPA, and the statute itself governs. Colorado's AG has rulemaking authority to issue regulations clarifying the CPA, similar in scope to California's original pre-CPPA arrangement.
- Cure period status. All three states initially included cure periods. California's CPPA operates under a discretionary approach rather than a mandatory cure period. Virginia and Colorado originally provided mandatory cure windows; both have moved toward or completed transitions to discretionary cure determinations as their statutes matured.
Compliance Checklist for Businesses Operating Across States
A business operating in California, Virginia, and Colorado simultaneously faces overlapping but non-identical obligations, and a unified compliance program must satisfy the strictest requirement in each category. The Federal Trade Commission's guidance on privacy and security provides a federal-baseline reference point alongside the state statutes (ftc.gov/business-guidance/privacy-security). A multi-state program built to California's CCPA standards will satisfy the core rights obligations in Virginia and Colorado, but gaps remain in opt-out signal mechanics, consent requirements for sensitive data, and data protection assessment documentation.
The following steps form the foundation of a unified multi-state data protection program:
- Conduct a data inventory. Map all categories of personal data the organization collects, the sources of that data, the purposes for processing, and any third parties with whom data is shared. The data inventory is the prerequisite for every downstream compliance obligation under all three statutes.
- Determine applicability. Verify whether the organization meets any of California's three applicability thresholds and whether it qualifies as a controller under Virginia's or Colorado's frameworks. Document the legal basis for any conclusion that a given statute does not apply.
- Update privacy notices. Each statute requires a privacy notice disclosing categories of personal data collected, the purposes of processing, consumer rights, and how to submit requests. California's CCPA requires more granular disclosure than Virginia or Colorado, so a California-compliant notice generally satisfies the other two states' notice requirements.
- Build a consumer request response workflow. All three statutes require a response mechanism for consumer rights requests, typically within 45 days with a possible single extension. The workflow must handle access, deletion, correction, and opt-out requests. For California, it must also handle GPC signals as opt-out requests.
- Implement opt-out links and GPC recognition. California mandates a "Do Not Sell or Share My Personal Information" link on the homepage. Colorado requires recognition of universal opt-out mechanisms including GPC-compatible signals. Virginia requires an accessible opt-out mechanism but not automated signal recognition. A single technical implementation honoring GPC and providing a visible opt-out link satisfies all three requirements.
- Draft data protection assessments. Virginia and Colorado require data protection assessments before initiating high-risk processing, including sensitive data processing and targeted advertising. Document and retain these assessments for potential regulatory inquiry.
- Establish processor agreements. All three statutes require written contracts with processors that impose data protection obligations. California's CCPA requires service provider agreements; Virginia and Colorado use processor contract requirements modeled on the GDPR's processor-contract requirements.
- Review sensitive data handling. Identify all sensitive personal information the organization processes. For California, ensure the use-limitation mechanism is in place for consumers who invoke it. For Virginia and Colorado, confirm that consent is obtained before processing begins.
References
- California Attorney General: California Consumer Privacy Act: oag.ca.gov/privacy/ccpa
- California Attorney General: CCPA Regulations: oag.ca.gov/privacy/ccpa/regs
- Virginia Law: VCDPA Definitions, §59.1-575: law.lis.virginia.gov
- Colorado General Assembly: Senate Bill 21-190 (Colorado Privacy Act): leg.colorado.gov/bills/sb21-190
- Federal Trade Commission: Business Guidance on Privacy and Security: ftc.gov/business-guidance/privacy-security
Further reading
Frequently Asked Questions
Does the CCPA apply to small businesses?
CCPA applies to for-profit businesses that meet at least one of three thresholds. Those thresholds are generating annual gross revenues above a specified level, buying or selling personal data of 100,000 or more consumers or households annually, or deriving 50 percent or more of annual revenue from selling or sharing personal data. Businesses below all three thresholds are generally exempt, though service providers that process data on behalf of a covered business still carry contractual obligations.
Does Virginia's VCDPA give consumers a private right of action?
No. The Virginia Consumer Data Protection Act is enforced exclusively by the Virginia Attorney General; consumers cannot sue a controller directly. This is a key structural difference from California's framework, where the California Privacy Protection Agency handles enforcement and a limited private right of action exists for certain data breaches.
What is a universal opt-out signal and which states recognize it?
A universal opt-out signal is a browser- or device-level preference that automatically communicates a consumer's opt-out request to every site visited, without requiring individual form submissions. California's CCPA framework explicitly recognizes the global privacy control (GPC) as a valid opt-out mechanism under official Attorney General guidance. Colorado's CPA similarly requires controllers to honor universal opt-out mechanisms. Virginia's VCDPA requires controllers to respond to opt-out requests but does not mandate recognition of automated signals.









