trusted by over 100 000 eCommerce stores

Empower your business and stay ahead of the latest US laws

Bring together all your US compliance needs with a single app solution

Cover All US State Laws with One Powerful App 🗲

US State Privacy Laws: CCPA, CPRA, CTDPA & More - 2025 Compliance Guide

Navigating US data privacy laws is critical for businesses handling personal data. The Consentmo Shopify app automates compliance tasks and streamlines privacy practices so you can focus on growing your business while protecting customer data.

Explore below which US data privacy laws are currently covered by Consentmo.

California state flag.
California

The California Privacy Rights Act

Read more
Colorado state flag.
Colorado

The Colorado Privacy Act

Read more
Connecticut

The Connecticut Data Privacy Act

Read more
Florida state flag.
Florida

The Florida Digital Bill of Rights

Read more
Montana state flag.
Montana

Minnesota Consumer Data Privacy Act

Read more
Oregon state flag.
Oregon

Oregon Consumer Privacy Act

Read more
Texas state flag.
Texas

Texas Data Privacy and Security Act

Read more
Utah state flag.
Utah

The Utah Consumer Privacy Act

Read more
Virginia state flag.
Virginia

The Virginia Consumer Data Protection Act

Read more
Delaware state flag.
Delaware

The Delaware Personal Data Privacy Act

Read more
Iowa state flag.
Iowa

The Iowa Consumer Data Protection Act

Read more
Iowa state flag.
Nebraska

The Nebraska Data Privacy Act

Read more
New Hampshire state flag.
New Hampshire

The New Hampshire Data Privacy Act

Read more
New Jersey state flag.
New Jersey

The New Jersey Data Privacy Act

Read more
Tennessee  state flag.
Tennessee

The Information Protection Act

Minesota state flag.
Minnesota

Minnesota Consumer Data Privacy Act

Become compliant with Consentmo

Learn about compliance in other countries:

Frequently Asked Questions

What is the main purpose of the CCPA, CPRA, and other state privacy laws?

These laws aim to protect the personal data of residents in states like California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and Utah (UCPA). They provide consumers with rights to access, control, and manage their personal information while establishing strict requirements for businesses handling such data. The goal is to increase transparency, improve data security, and enhance consumer trust in how personal data is managed.

Which businesses are subject to these state privacy laws?

Each law applies to businesses meeting specific thresholds, such as:
CCPA/CPRA: Annual revenue of $25M+, data of 100,000+ consumers/households/devices, or earning 50%+ revenue from selling/sharing personal data.
VCDPA: Data of 100,000+ consumers or data of 25,000+ consumers with 50%+ revenue from data sales.
CPA: Data of 100,000+ individuals or benefiting from data sales of 25,000+ individuals.
CTDPA: Data of 100,000+ individuals (excluding payments) or data of 25,000+ individuals with 25%+ revenue from data sales.
UCPA: Revenue of $25M+, data of 100,000+ residents, or 50%+ revenue from data sales.

What rights do consumers have under these privacy laws?

Consumers are granted rights such as:

Access: View their personal data.
Correction: Request inaccuracies in their data to be corrected.
Deletion: Request deletion of their personal data.
Opt-out: Opt out of targeted ads or the sale/sharing of personal data.
Data Transparency: Learn why and how their data is collected and used.

Some laws, like the CPRA, also include rights to limit the use of sensitive data and object to automated decision-making.

Are certain industries or businesses exempt from these laws?

Yes, exemptions exist for specific industries or data types covered by federal laws:

Health Data: Exempt under HIPAA.
Financial Data: Exempt under the Gramm-Leach-Bliley Act.
Educational Data: Exempt under FERPA.

Nonprofits, small businesses below the revenue or data thresholds, and government entities are often excluded.

How do businesses prepare for compliance with these laws?

To prepare for compliance, a business needs to:

- Appoint a privacy officer to oversee data practices.
- Conduct a data audit to understand what data is collected, stored, and shared.
- Implement a privacy policy that clearly outlines data practices.
- Provide consumer rights mechanisms, such as opt-out options and access request portals.
- Train employees on data protection best practices.
- Review contracts with vendors to ensure third-party compliance.
- Stay updated on new regulations and adjust practices accordingly.

How does Consentmo help?

Consentmo is a GDPR and privacy compliance app designed specifically for Shopify stores to simplify meeting requirements under laws like the CCPA, CPRA, and others. With features such as customizable cookie banners, automated consent tracking, and data request forms, Consentmo enables Shopify merchants to efficiently manage user consent while maintaining transparency. It also supports compliance with opt-out requests and consumer rights management, making it easier for Shopify stores to obey privacy regulations.

If you are a Shopify store owner, give us a try!

Start Now – Stay Ahead of 2025 Global Regulations

US State laws Compliance - including popular laws like CCPA, CPRA, with one easy to use app.
Global Compliance - cover international privacy regulations such as the GDPR (EU), and more.
Google CMP Certified - benefit from a CMP that's been validated by Google.
⭐ Built for Shopify app - designed specifically for Shopify, complete with a certified badge.