Blog

2026 U.S. Privacy Compliance Trends: Business Guide

By
The Reform Team
Use AI to summarize text or ask questions

If you sell to people in the U.S., privacy compliance in 2026 is a location problem, a systems problem, and a leadership problem. As of September 26, 2026, 20 state privacy laws are live, and Oklahoma is set for January 1, 2027. I’d treat this as a workflow issue, not just a legal one.

Here’s the short version:

  • Your users’ state matters more than your company’s address
  • Connecticut now reaches businesses at 35,000 consumers, down from 100,000
  • California now ties risk assessments to executive sign-off
  • Oregon and Delaware require Global Privacy Control (GPC) handling
  • Indiana, Kentucky, and Rhode Island took effect on January 1, 2026
  • Automated decision-making, correction rights, deletion flow, and consent records need close review now
  • Forms, CRM syncs, enrichment tools, ad platforms, and routing rules are all part of compliance

If I were leading a B2B or SaaS team, I’d focus on four things first:

  1. Check which states put you in scope
  2. Fix notices, consent, and opt-out handling
  3. Test access, correction, deletion, and appeal workflows
  4. Review form-to-CRM data flow, including real-time enrichment and retention
U.S. State Privacy Laws 2026: Key Changes & Compliance Requirements

U.S. State Privacy Laws 2026: Key Changes & Compliance Requirements

January 1, 2026: New Privacy Laws, Amendments, and U.S. Privacy Compliance Obligations

Quick comparison

Area What changed in 2026 What I’d do now
Scope More laws are active; Connecticut dropped to 35,000 consumers Recheck thresholds by state
Consent Sensitive data often needs opt-in Review every form field and consent box
Opt-outs GPC handling matters more Make sure signals update user status across systems
Governance California now ties assessments to executive attestation Set owner names for legal, RevOps, IT, and marketing
Rights requests Correction, deletion, and appeals need tighter process Test requests end to end
Data flow Enrichment and sync tools can break compliance Stop corrected data from being overwritten

Bottom line: I’d set one internal privacy standard to the toughest rule that applies, then use the rest of 2026 to close gaps before 2027 rules add more pressure.

State Privacy Law Changes That Matter Most in 2026

Laws Taking Effect in 2026: Indiana, Kentucky, and Rhode Island

Indiana, Kentucky, and Rhode Island's laws took effect on January 1, 2026. Indiana and Kentucky mostly follow Virginia's model, while Rhode Island puts more focus on transparency and privacy-policy disclosures.

One detail stands out. Kentucky's first enforcement action came within a week of the law taking effect, which sends a pretty clear message: if you're collecting children's data, gating it at the point of collection can't be an afterthought.

If your forms collect sensitive data from residents of these states, you need explicit opt-in consent.

That change doesn't stop at the form itself. It affects how you capture consent, how you handle opt-outs, and how that data gets used later across your systems.

Rule Updates in California, Colorado, Connecticut, Maryland, Minnesota, Oregon, and Delaware

Several existing laws changed in 2026, and those updates expand both coverage and day-to-day duties. For B2B and SaaS teams, this shows up fast in forms, routing, enrichment, and CRM syncs.

Connecticut made one of the biggest moves. As of July 1, 2026, the CTDPA applies to businesses processing data on 35,000 or more consumers, down from 100,000. For a lot of mid-sized SaaS and B2B companies, that one change pulled them into scope.

A few other updates matter right away:

  • Oregon and Delaware now require GPC honors
  • California adds disclosure of whether the signal was honored
  • Colorado now treats precise geolocation as sensitive data
  • Oregon also bans the sale of precise geolocation data outright

California's executive attestation rule also changes the stakes. Privacy risk assessments are no longer just a legal or compliance task. They now sit with leadership too. In practice, that reaches into the forms, consent prompts, and automated scoring tied to acquisition.

Cure periods are also getting shorter or disappearing altogether, which means teams need to fix issues before enforcement starts - not after they get a warning.

What to Watch Next: 2026 Enactments and 2027 Preparation

The next planning target is 2027, but the work that matters in 2026 is happening now: mapping automated decisions and tightening notice workflows.

Two items deserve close attention:

  • Track Oklahoma's 2027 effective date
  • Map automated decision-making now for California's pre-use notice rules

For many teams, this is where privacy shifts from policy language to actual system design. If notices, scoring logic, and consent flows don't line up, problems tend to show up fast.

Once a state law applies, the next step is more practical: what do your forms, notices, and workflows need to do?

The basic rule is straightforward. Sensitive data usually needs opt-in consent. Sales, targeted advertising, and some automated decision-making activities need clear opt-out rights or advance notice.

For sensitive data, use an explicit opt-in mechanism. No vague wording. No pre-checked boxes. And if your lead flows involve Maryland residents and sensitive data, pay close attention: Maryland prohibits the sale of sensitive data. If that activity is part of your process, it needs to stop.

For targeted advertising and data sales, opt-out tools still matter a lot. Oregon requires businesses to honor Global Privacy Control (GPC) signals automatically. That means the signal can't just be logged somewhere and ignored. It should change the user’s status in your system, and that status should be easy to see.

Minors’ data needs tighter controls too. Several states now limit sale, targeted advertising, and profiling beyond COPPA. In plain terms, age-based gating in multi-step forms and ad tools can’t be an afterthought. California, Connecticut, and Montana also now treat neural data as sensitive data.

Data Category Notice Consent Opt-Out Minimization & Retention
General Personal Data Standard privacy policy Generally not required Required for sale or sharing Purpose-limited
Sensitive Data Specific disclosure Opt-in (most states) Restricted; Maryland prohibits sale Heightened scrutiny
Minors' Data (under 13) COPPA-compliant notice Verifiable parental consent Absolute for sale/targeted ads Strict deletion limits
Teen Data (13–16) Specific youth notice Opt-in or sale prohibition, depending on state Required for targeted ads in covered states Heightened assessment
Targeted Advertising Clear disclosure N/A Must honor GPC signals Risk assessment required
Profiling / Automated Decisions Pre-use notice N/A Opt-out for certain significant decisions Documented risk assessment

Handling Consumer Rights Requests: Access, Correction, Deletion, Portability, and Appeals

After consent rules, the next test is operational: can you find the data, verify the person, and respond on time?

Indiana, Kentucky, and Rhode Island each require a formal appeal process when a rights request is denied. So if your intake setup has no appeals path, you already have a problem for residents of those states.

California got more specific on correction requests this year. Businesses must notify the source of inaccurate data, and they must make sure corrected records are not later overwritten by fresh third-party data pulls. That can create friction for teams that use enrichment tools to auto-refresh CRM records. A correction that gets wiped out by the next sync is still a problem.

California’s request-to-know process also needs to support access to personal information collected on or after January 1, 2022, when a look-back limit applies.

There’s also a new item for California data brokers: the Delete Request and Opt-out Platform (DROP) is now live. Brokers in California must keep DROP synced on a regular schedule. More broadly, teams should focus on deletion propagation across the CRM and on making sure vendors carry out deletion requests all the way through, not just at the first system.

Request Type Intake Channel Verification Systems to Search Deadline Appeals Required
Access / Know Web form, toll-free # Identity verification CRM, analytics, data lake Typically 45 days Varies by state
Correction Web form, email Verify accuracy of new data CRM, vendor databases 45 days Varies by state
Deletion Web form, DROP (CA) Identity verification CRM, backups, processors 45 days Varies by state
Opt-Out (sale/ads) GPC, "Do Not Sell" link No verification required AdTech, CRM, DSPs 15 days (CA standard) N/A
Appeals Dedicated email/form Reference original request Legal/compliance review Varies by state (typically 45–60 days) IN, KY, RI required

Privacy Notices, Data Mapping, Retention, and Risk Assessments

These rules shouldn’t live in a policy doc and nowhere else. They should show up in your privacy notice, your retention schedule, and your review process.

Privacy notices need to do more in 2026. At a minimum, they should:

  • reflect rights for Indiana, Kentucky, and Rhode Island residents
  • disclose categories of data shared with contractors and service providers
  • explain how opt-out signals such as GPC are handled

California adds another layer here. Before using automated decision-making for major decisions like credit, employment, or housing, businesses must provide pre-use notices. Consumers also have the right to opt out of some automated decisions.

Risk assessments are also moving out of the legal silo. In California, a member of executive management must now personally attest to the accuracy of the business’s privacy risk assessments. That changes privacy from a back-office task into a governance issue with direct leadership responsibility.

This maturity model makes it easier to see where marketing, RevOps, and SaaS workflows may fall short.

Maturity Level What It Covers
Baseline Privacy notice updated for 2026 state laws; basic rights intake form live; data categories inventoried in CRM and forms
Operational GPC signals honored automatically; correction and deletion workflows tested end to end; DPAs in place with key vendors; appeal process documented
Advanced Executive attestation process for risk assessments; pre-use notices for automated decision-making deployed; enrichment and automation tools mapped to retention schedules; DROP sync configured (if applicable)

Retention needs to match purpose and deletion rules. Keep data only for as long as you need it for the stated purpose. The FTC’s 2025 COPPA updates also add prescriptive retention limits for children’s data.

Form and Lead-Flow Compliance Review for B2B and SaaS Teams

Privacy compliance doesn't stop at the policy page. It runs through every field your forms collect, every system that touches a lead record, and every vendor that handles data on your behalf.

For B2B and SaaS teams, this is where legal rules turn into form fields, routing logic, and retention settings. The next review is hands-on: first the form itself, then every system that handles the lead after someone hits submit.

Start with what you're collecting. Go through every live form and ask a simple question: do we need this field for the transaction? Collect only the fields required for that transaction.

Watch for any sensitive field. When one appears, apply the state-specific notice and consent required at the point of collection. Keep required fields to a minimum, and place the privacy notice link right beside the form so people can see it when they submit.

Then check your routing rules. If form logic sends submissions into third-party systems, look at each destination and ask whether that recipient needs the data. If sensitive submissions are routed into systems that don't need them, you create downstream risk that's tough to clean up later.

Add age-gating when youth data is even a possibility. Youth data gets extra scrutiny across several states.

What to Audit After Submission: Enrichment, CRM Sync, Automation, Analytics, and Retention

Once the data is collected, trace the record through your CRM, automation tools, analytics stack, and retention workflow. Make sure consent and opt-out status stay attached to the lead record the whole way through. If a consumer revokes consent, that signal needs to move across every connected channel.

Enrichment tools need a close look. Once a consumer's data is corrected, it cannot be overwritten by later third-party data. That sounds simple, but here's where teams get tripped up: if your CRM auto-refreshes records from enrichment sources, a corrected record could get replaced on the next sync. Review whether your enrichment vendors fall under the expanded data broker definitions in California and Texas, and confirm that deletion requests flow through to those vendors.

Partial-submission tracking is another easy miss. If partial entries include personal data, verify how long those entries are kept and whether they show up in access and deletion workflows.

Retention matters too. Old lead records that have outlived their stated purpose become a liability. Automated workflows that purge records on a set schedule can cut that risk.

Using Reform in a Privacy-by-Design Review

Use the same checklist when reviewing your form builder and connected automations. Look at Reform's multi-step forms, conditional routing, lead enrichment, spam prevention, email validation, and CRM integrations as part of the same privacy review.

Compliance comes down to configuration, routing, and retention.

2026 Implementation Priorities and Next Steps

The Highest-Risk Gaps to Fix First

After the form and lead-flow review, fix the issues that create the most immediate compliance exposure. Broken opt-out links, old privacy notices, and consent banners that don't honor Global Privacy Control signals are some of the first things regulators can spot.

A few internal gaps stand out right now:

  • Missing or stale privacy notices for Indiana, Kentucky, and Rhode Island leave businesses exposed under laws that are already in effect.
  • Consent revocation that doesn't carry across forms, CRM, automation, and ad platforms is a common breakdown.
  • Sensitive data handled without documented notice, consent, and risk review creates immediate exposure.
  • Inconsistent consent records become a documentation problem the moment a rights request comes in.
  • Profiling or automated decision-making without a pre-use notice is a gap that will get more serious as ADMT enforcement moves toward the January 1, 2027 deadline.

The fastest way to make progress is simple: assign each gap to one accountable team.

One team can't fix this alone. Clear ownership matters from day one, especially when work touches forms, CRM data, ad systems, and vendor tools at the same time.

Function 2026 Actions
Legal Confirm states in scope; update privacy notices for IN, KY, and RI; manage executive attestations for CA risk assessments; review vendor DPAs
Marketing Audit lead-gen consent language; deploy GPC-compliant banners; block youth data from targeted ads
RevOps Inventory connected systems; classify data; propagate opt-outs; protect corrected records from overwrite
IT / Security Complete risk assessments for high-risk processing before deployment; build technical workflows for access, deletion, and portability requests; prepare for California audit readiness
Sales Ops Review lead-flow forms for proper notice placement; ensure enrichment tools do not violate data broker registration rules; route correction requests into sales databases

Use the rest of 2026 to close notice, consent, GPC, and ADMT gaps before year-end. Then use late 2026 to get ready for the 2027 ADMT rules.

Key Takeaways for 2026 Privacy Compliance

Once owners are assigned, the work shifts to execution. In 2026, privacy compliance runs straight through marketing forms, CRM setup, enrichment logic, and sales workflows. Treat your high-converting lead forms and lead flows as compliance infrastructure, not just conversion tools.

As updates roll out, document consent and notice versions so there's a clear record of what changed and when. Build a repeatable process for rights requests, including access, correction, deletion, portability, and appeals, so responses don't depend on someone scrambling to remember the steps under pressure. State thresholds and enforcement priorities keep changing, so it's smart to recheck scope and deadlines throughout 2026.

FAQs

How do I know which state privacy laws apply to my business?

Check your business against each state law’s triggers. Most states look at annual gross revenue, how much consumer data you process, or whether you sell personal information.

Start by mapping your data flows and reviewing customer counts by state. The thresholds can be all over the map. California, for example, uses a $26,625,000 revenue trigger. Texas and Nebraska, by contrast, can apply to many businesses no matter how big or small they are.

What systems should I audit first for privacy compliance gaps?

Start with a full inventory of tags, pixels, SDKs, and session replay tools. Then map how consumer data is collected, stored, and shared.

Next, review public-facing features. Make sure your privacy policy is accurate, opt-out tools work, data rights request intake is centralized, and vendor agreements include required terms.

How should we handle GPC, deletion, and correction across connected tools?

Make sure Global Privacy Control (GPC), deletion, and correction requests are handled across your entire tech stack in practice, not just on the surface. A banner or form that looks right doesn't mean much if scripts behind the scenes still collect or pass along consumer data.

Start by auditing your tags and pixels. You need a clear view of every script that touches consumer data and where that data goes.

Then set up those tools so they can detect and honor GPC. For deletion and correction requests, use one centralized, branded intake form and route each request to the right team so you can respond within the 45-day window.

Related Blog Posts

Use AI to summarize text or ask questions

Discover proven form optimizations that drive real results for B2B, Lead/Demand Generation, and SaaS companies.

Lead Conversion Playbook

Get new content delivered straight to your inbox

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
The Playbook

Drive real results with form optimizations

Tested across hundreds of experiments, our strategies deliver a 215% lift in qualified leads for B2B and SaaS companies.