DxtraBETA
Back to blog
GuidesUnited StatesSmall Business July 2026 6 min read

The Small Business Guide to the United States in 2026

There is no single United States privacy law. There is a federal patchwork, a growing set of state laws, and one rule that reaches every business regardless of size: what your privacy policy says, you have to actually do.

Why the United States is confusing on purpose

Most privacy guides start by naming the law. For the United States there is no law to name. There is no comprehensive federal privacy statute. What exists instead is two layers that behave very differently.

The federal layer is sectoral. It covers particular kinds of data rather than data in general: HIPAA for health information, GLBA for financial institutions, COPPA for children under 13, FERPA for education records. If you are not a clinic, a lender, a school or a children's service, most of that layer passes over you. What does not pass over you is the Federal Trade Commission's authority over unfair and deceptive practices. That is the general-purpose backstop, and it applies to businesses of any size.

The second layer is the states. A growing number have passed comprehensive consumer privacy laws that look broadly similar to each other. They come with thresholds, and for many small businesses those thresholds are out of reach. This is the part owners fixate on, and usually the part that matters least to them.

The honest headline is the reverse of what most articles tell you. The state laws may not reach you. Your own published promises bind you either way.

Who this applies to

If you sell online to people in the United States, or collect data from them, you are in scope for something. The question is which layer.

You are in scope for the FTC's authority the moment you publish a privacy policy, a cookie notice, or any other statement about how you handle customer information. No revenue threshold or employee count exempts you. A two-person store is as capable of making a false statement as a public company.

You are in scope for a state comprehensive law only if you cross that state's applicability threshold, normally expressed as the number of that state's residents whose personal data you process in a year. You are in scope for a breach notification law in every state where your affected customers live, without any threshold at all.

Most small businesses land in the same place: fully exposed on the FTC and breach notification side, below the line on most or all state comprehensive laws. That is a workable position, but only if you know it is where you are.

What you actually have to do

Make sure your privacy policy is true. This is the single highest-value hour you will spend. If your policy says you do not sell personal information while your site runs an advertising pixel that shares identifiers with an ad network, your policy is not accurate. If it says data is encrypted and it is not, the same problem applies. Saying something you do not do is a deceptive practice, enforceable against a business of any size. Read your own policy as a stranger would and strike anything you cannot demonstrate.

Work out which state laws actually reach you, using real numbers. State comprehensive laws set applicability thresholds based on how many of that state's residents you process data about. A common figure is 100,000 residents in a year, with a lower figure such as 25,000 where you derive revenue from selling personal data. Thresholds vary by state, so do not assume one number applies everywhere. Pull your customer list, sort by state, and count. Most owners find in twenty minutes that they are nowhere near the line, and that beats any amount of speculation.

Publish a privacy notice that describes the business you actually run. Every state comprehensive law requires one, and the FTC point above makes it worth having regardless. It should say what data you collect, why, who you share it with, how long you keep it, and how someone contacts you. A notice that says "we may share data with partners" tells your customer nothing and gives you nothing to stand behind.

Be able to answer a rights request without panic. Where a state law applies, consumers can ask to access their data, delete it, correct it, and receive a portable copy. The obligation is not really the response; it is the plumbing behind it. Decide now who receives these requests, how you verify the person, and which systems you would have to search.

Offer real opt-outs, including the automated kind. State laws generally give people the right to opt out of targeted advertising, the sale of their data, and certain profiling. A growing number of states also require you to recognise universal opt-out mechanisms, browser-level signals that broadcast a person's choice automatically rather than making them click through every site. If you honour a click on your own page but ignore the signal, you have done half the job. Higher-risk processing may also require a data protection assessment, a written analysis weighing what you gain against the risk to the person.

Treat sensitive data and children's data as separate problems. Most states require opt-in consent before you process sensitive categories such as health, precise location, biometric data or information revealing race or religion. Children are stricter again. COPPA applies regardless of your size where a service is directed to children under 13, or where you have actual knowledge that under-13 users are on it. This is not only for toy companies. A gaming community, a tutoring service or a craft shop with a young audience can all be caught.

Have a breach plan before you need one. All 50 states have breach notification laws and they apply to small businesses without revenue thresholds. The failure is almost never unwillingness to notify. It is that on the day it happens nobody knows who decides, who writes the notice, or where the list of affected people lives. Write those three answers down now.

What changed for 2026

The state map keeps moving. The fair way to describe it today is 20 comprehensive state privacy laws in force and 23 enacted, and that gap is the point: some laws are on the books with future effective dates. The number changes as new laws are passed and phased in, so treat any single count you read, including this one, as a snapshot. Indiana, Kentucky and Rhode Island's comprehensive laws took effect on 1 January 2026.

Two enforcement themes are live this year. The first is minors and age-appropriate design, where several states have added or strengthened provisions covering how services treat younger users. The second is the use of personal data to train AI systems, where regulators have signalled interest in whether privacy notices actually disclose that use. If you have started feeding customer content into an AI tool and your policy has not changed, that is exactly the gap being looked at.

Separately, the FTC amended the COPPA Rule, and the amendments phase in across 2025 and 2026. If children could plausibly be using your service, that deserves a proper look.

Common mistakes

The biggest one is reading "100,000 residents" and concluding you have no obligations. The thresholds are real, but they only switch off the state comprehensive laws. They do nothing about the FTC, breach notification, or COPPA.

The second is borrowing a privacy policy from a larger company. It will describe practices, vendors and procedures that are not yours. You have now published a detailed set of promises about a business you do not run, which is worse than publishing nothing.

The third is treating California as the whole country. It was first and it is the most discussed, but states differ on thresholds, definitions and which opt-out signals you must honour. Meeting one state's rules is a strong start, not a finish.

The fourth is waiting. Owners hear that a federal law would simplify everything and sit still until it arrives. There is no comprehensive federal privacy law, and building your plan around one appearing is not a plan.

How Dxtra helps

Dxtra generates a privacy program from a questionnaire about how your business actually works: a privacy policy, a cookie notice, consent records, processing records, a public Transparency Center and a way to handle data subject access requests. It covers more than 500 obligations across 140-plus countries, and starts at $10 a month. It will not replace a lawyer on a hard question, and it is not meant to.

If you want a starting point that costs nothing, Dxtra's free scan reads your site's public pages in about two minutes with no signup and returns a risk band along with findings mapped to named sources, so you can see which gaps deserve your attention first. It is a diagnostic, not a determination of compliance.

Where to start

Read your own privacy policy first, before you read a single statute. Mark every sentence you cannot prove is true today. That list is your real compliance backlog, and it is enforceable against you no matter how small you are.

Then count. Sort your customers by state and find out whether any comprehensive law genuinely reaches you. If none does, you have narrowed the problem enormously, and you can stop worrying about thresholds and start maintaining accuracy.

After that, write down every tool that touches customer data. Your rights-request answer, your breach answer and your AI-training answer all depend on that list, and nothing else gets easier until it exists.

That is an afternoon, not a quarter. And it puts you ahead of most businesses your size.

This article is general information, not legal advice. Rules change; confirm anything that matters with the Federal Trade Commission (ftc.gov), your state attorney general, or a qualified adviser before you rely on it.

Ready to get compliant?

Start your privacy program today — from $10/month.