Skip to content

Stratgik — technology strategy and business systems engineering.
Delivery across the USA, UK, UAE and India.

Talk about a problem

US state privacy lawsAbout 20 states with comprehensive laws in 2026

US privacy compliance for the states you actually sell into. Fixed fees from $1,900.

There is no single US privacy law. California’s new rules on risk assessments, cybersecurity audits and automated decision-making took effect in January 2026, and roughly 20 states now have comprehensive privacy laws. We work out which apply to you and build opt-outs, rights requests and assessments into your systems.

  • Fixed fees in $
  • Implemented in your systems, not just a policy
  • Engineers, working alongside your lawyers

What is at stake

Enforcement under CCPA/CPRA and the other US state consumer privacy laws

Enforcement is active: regulators have focused on opt-out links, Global Privacy Control signals, dark patterns and data broker obligations.

  1. Per violation

    CCPA administrative fines and civil penalties, higher for intentional violations and minors’ data

  2. AG actions

    State attorneys general in other states enforce their own laws and can seek penalties

  3. Private action

    Californians can sue over data breaches caused by unreasonable security

What the law asks, in plain words

Eight things to get right in United States

  • Know your thresholds

    Each state sets thresholds by revenue, number of consumers or revenue from selling data. Map where you cross them.

  • Privacy notice

    State-specific disclosures on categories collected, purposes, sale or sharing and retention.

  • Opt-outs and Global Privacy Control

    Honour opt-outs of sale, sharing and targeted advertising, including browser signals where required.

  • Consumer rights requests

    Access, deletion, correction and portability, typically answered within 45 days with verification.

  • Sensitive data

    Many states require opt-in consent for sensitive data such as health, precise location and children’s data.

  • Risk assessments

    Data protection assessments for high-risk processing, now with detailed California requirements.

  • Automated decision-making

    New California rules cover notices, opt-outs and access for significant automated decisions.

  • Vendor and service provider terms

    Contracts that restrict how vendors use the data you share with them.

Free self-check

How ready is your organisation?

Ten questions, two minutes. Nothing is sent anywhere unless you ask for help.

0/ 100

Answer the questions to see your score

0 of 10 answered

  1. 1Do you know which state privacy laws you meet the thresholds for?
  2. 2Do you have an inventory of consumer personal data?
  3. 3Does your website honour Global Privacy Control signals?
  4. 4Is there a working opt-out of sale, sharing and targeted advertising?
  5. 5Can you verify and answer rights requests within 45 days?
  6. 6Do you get opt-in consent for sensitive data where required?
  7. 7Have high-risk activities had a documented risk assessment?
  8. 8Do automated decisions about consumers have notice and opt-out?
  9. 9Do vendor contracts include the required service provider terms?
  10. 10Would you meet reasonable security standards if breached?

How we get you compliant

Four steps, done with your team

  1. 1

    Discover

    Find every copy of personal data

    Website, apps, CRM, ERP, spreadsheets, messaging tools and vendors.

  2. 2

    Decide

    Rank the gaps by risk

    Each gap scored against enforcement exposure and effort, so the serious ones get fixed first.

  3. 3

    Implement

    Fix it in your systems

    Notices, consent, request workflows, access controls, retention and vendor terms.

  4. 4

    Hand over

    Train people, rehearse a breach

    A live session for the staff who handle data and a practice run of breach reporting.

Pricing

Fixed fees. No surprises.

For organisations with one website or product and up to five systems holding personal data. Larger scope is quoted in writing before you pay anything.

Readiness Audit

Know which state laws apply and where you fall short.

$1,900one-time

Report in 7 working days

Choose Readiness Audit
  • Discovery session with an engineer
  • State threshold mapping
  • Data map across website, product, CRM and vendors (up to 5 systems)
  • Gap report ranked by enforcement risk
  • 90-day action plan

Recommended

Compliance Setup

We implement opt-outs, requests and assessments.

$5,900one-time

Typically 3 to 5 weeks

Choose Compliance Setup
  • Everything in Readiness Audit
  • State-specific privacy notice
  • Opt-out flows and Global Privacy Control handling
  • Rights request intake, verification and tracking
  • Risk assessment templates
  • Vendor terms checklist
  • Live staff training session

Privacy Care

Keep up as new state laws take effect.

$790per month

Cancel any month

Choose Privacy Care
  • Rights request handling support
  • Quarterly review of systems, vendors and new state laws
  • Breach support during US business hours
  • Updates when regulations change
  • Annual refresher training

Free readiness call

Talk to an engineer, not a salesperson

An engineer replies within one working day with a suggested approach and a fixed quote.

  1. 1
    You send the formTwo minutes. Tell us the problem, not the solution.
  2. 2
    We talk it throughA short call at a time that suits your working hours.
  3. 3
    You get a fixed quoteIn writing, in $. Nothing is billed until you approve it.

Book your free readiness call

Interested in

See our privacy policy.

Questions

US state privacy laws questions we get asked

Also see how Stratgik works with United States businesses.

Is there a federal privacy law in the US?

Not a comprehensive one. Sector laws such as HIPAA, GLBA and COPPA apply to specific data, and around 20 states have their own comprehensive consumer privacy laws.

Does CCPA apply to companies outside California?

Yes, if you do business with California residents and meet one of its thresholds, such as annual gross revenue above about US$26 million (adjusted for inflation) or buying, selling or sharing the data of 100,000 or more consumers or households.

What changed in California in 2026?

Regulations on risk assessments, cybersecurity audits and automated decision-making technology took effect on 1 January 2026, with compliance deadlines phased over the following years.

What is Global Privacy Control?

A browser signal that tells websites a user wants to opt out of the sale or sharing of their data. California and several other states require businesses to honour it.

Is this legal advice?

No. Stratgik is a technology firm. We implement notices, opt-outs, requests and assessments in your systems and work alongside your counsel for legal opinions.

Are prices fixed?

Yes, for businesses with one website or product and up to five systems holding personal data. Larger scope is quoted in writing before work starts.

Find the gaps before a regulator does.

A readiness audit takes 7 working days and gives you a ranked, costed plan.

The Stratgik model

Strategy first. Technology that follows through.

Four stages, in order. Most businesses need them one at a time.