2026 U.S. Privacy Compliance Trends: Business Guide

If you sell to people in the U.S., privacy compliance in 2026 is a location problem, a systems problem, and a leadership problem. As of September 26, 2026, 20 state privacy laws are live, and Oklahoma is set for January 1, 2027. I’d treat this as a workflow issue, not just a legal one.
Here’s the short version:
- Your users’ state matters more than your company’s address
- Connecticut now reaches businesses at 35,000 consumers, down from 100,000
- California now ties risk assessments to executive sign-off
- Oregon and Delaware require Global Privacy Control (GPC) handling
- Indiana, Kentucky, and Rhode Island took effect on January 1, 2026
- Automated decision-making, correction rights, deletion flow, and consent records need close review now
- Forms, CRM syncs, enrichment tools, ad platforms, and routing rules are all part of compliance
If I were leading a B2B or SaaS team, I’d focus on four things first:
- Check which states put you in scope
- Fix notices, consent, and opt-out handling
- Test access, correction, deletion, and appeal workflows
- Review form-to-CRM data flow, including real-time enrichment and retention
U.S. State Privacy Laws 2026: Key Changes & Compliance Requirements
January 1, 2026: New Privacy Laws, Amendments, and U.S. Privacy Compliance Obligations
sbb-itb-5f36581
Quick comparison
| Area | What changed in 2026 | What I’d do now |
|---|---|---|
| Scope | More laws are active; Connecticut dropped to 35,000 consumers | Recheck thresholds by state |
| Consent | Sensitive data often needs opt-in | Review every form field and consent box |
| Opt-outs | GPC handling matters more | Make sure signals update user status across systems |
| Governance | California now ties assessments to executive attestation | Set owner names for legal, RevOps, IT, and marketing |
| Rights requests | Correction, deletion, and appeals need tighter process | Test requests end to end |
| Data flow | Enrichment and sync tools can break compliance | Stop corrected data from being overwritten |
Bottom line: I’d set one internal privacy standard to the toughest rule that applies, then use the rest of 2026 to close gaps before 2027 rules add more pressure.
State Privacy Law Changes That Matter Most in 2026
Laws Taking Effect in 2026: Indiana, Kentucky, and Rhode Island
Indiana, Kentucky, and Rhode Island's laws took effect on January 1, 2026. Indiana and Kentucky mostly follow Virginia's model, while Rhode Island puts more focus on transparency and privacy-policy disclosures.
One detail stands out. Kentucky's first enforcement action came within a week of the law taking effect, which sends a pretty clear message: if you're collecting children's data, gating it at the point of collection can't be an afterthought.
If your forms collect sensitive data from residents of these states, you need explicit opt-in consent.
That change doesn't stop at the form itself. It affects how you capture consent, how you handle opt-outs, and how that data gets used later across your systems.
Rule Updates in California, Colorado, Connecticut, Maryland, Minnesota, Oregon, and Delaware
Several existing laws changed in 2026, and those updates expand both coverage and day-to-day duties. For B2B and SaaS teams, this shows up fast in forms, routing, enrichment, and CRM syncs.
Connecticut made one of the biggest moves. As of July 1, 2026, the CTDPA applies to businesses processing data on 35,000 or more consumers, down from 100,000. For a lot of mid-sized SaaS and B2B companies, that one change pulled them into scope.
A few other updates matter right away:
- Oregon and Delaware now require GPC honors
- California adds disclosure of whether the signal was honored
- Colorado now treats precise geolocation as sensitive data
- Oregon also bans the sale of precise geolocation data outright
California's executive attestation rule also changes the stakes. Privacy risk assessments are no longer just a legal or compliance task. They now sit with leadership too. In practice, that reaches into the forms, consent prompts, and automated scoring tied to acquisition.
Cure periods are also getting shorter or disappearing altogether, which means teams need to fix issues before enforcement starts - not after they get a warning.
What to Watch Next: 2026 Enactments and 2027 Preparation
The next planning target is 2027, but the work that matters in 2026 is happening now: mapping automated decisions and tightening notice workflows.
Two items deserve close attention:
- Track Oklahoma's 2027 effective date
- Map automated decision-making now for California's pre-use notice rules
For many teams, this is where privacy shifts from policy language to actual system design. If notices, scoring logic, and consent flows don't line up, problems tend to show up fast.
Consent, Consumer Rights, and Data Governance Requirements
Once a state law applies, the next step is more practical: what do your forms, notices, and workflows need to do?
Consent and Opt-Out Rules for Sensitive Data, Minors, Targeted Advertising, and Profiling
The basic rule is straightforward. Sensitive data usually needs opt-in consent. Sales, targeted advertising, and some automated decision-making activities need clear opt-out rights or advance notice.
For sensitive data, use an explicit opt-in mechanism. No vague wording. No pre-checked boxes. And if your lead flows involve Maryland residents and sensitive data, pay close attention: Maryland prohibits the sale of sensitive data. If that activity is part of your process, it needs to stop.
For targeted advertising and data sales, opt-out tools still matter a lot. Oregon requires businesses to honor Global Privacy Control (GPC) signals automatically. That means the signal can't just be logged somewhere and ignored. It should change the user’s status in your system, and that status should be easy to see.
Minors’ data needs tighter controls too. Several states now limit sale, targeted advertising, and profiling beyond COPPA. In plain terms, age-based gating in multi-step forms and ad tools can’t be an afterthought. California, Connecticut, and Montana also now treat neural data as sensitive data.
| Data Category | Notice | Consent | Opt-Out | Minimization & Retention |
|---|---|---|---|---|
| General Personal Data | Standard privacy policy | Generally not required | Required for sale or sharing | Purpose-limited |
| Sensitive Data | Specific disclosure | Opt-in (most states) | Restricted; Maryland prohibits sale | Heightened scrutiny |
| Minors' Data (under 13) | COPPA-compliant notice | Verifiable parental consent | Absolute for sale/targeted ads | Strict deletion limits |
| Teen Data (13–16) | Specific youth notice | Opt-in or sale prohibition, depending on state | Required for targeted ads in covered states | Heightened assessment |
| Targeted Advertising | Clear disclosure | N/A | Must honor GPC signals | Risk assessment required |
| Profiling / Automated Decisions | Pre-use notice | N/A | Opt-out for certain significant decisions | Documented risk assessment |
Handling Consumer Rights Requests: Access, Correction, Deletion, Portability, and Appeals
After consent rules, the next test is operational: can you find the data, verify the person, and respond on time?
Indiana, Kentucky, and Rhode Island each require a formal appeal process when a rights request is denied. So if your intake setup has no appeals path, you already have a problem for residents of those states.
California got more specific on correction requests this year. Businesses must notify the source of inaccurate data, and they must make sure corrected records are not later overwritten by fresh third-party data pulls. That can create friction for teams that use enrichment tools to auto-refresh CRM records. A correction that gets wiped out by the next sync is still a problem.
California’s request-to-know process also needs to support access to personal information collected on or after January 1, 2022, when a look-back limit applies.
There’s also a new item for California data brokers: the Delete Request and Opt-out Platform (DROP) is now live. Brokers in California must keep DROP synced on a regular schedule. More broadly, teams should focus on deletion propagation across the CRM and on making sure vendors carry out deletion requests all the way through, not just at the first system.
| Request Type | Intake Channel | Verification | Systems to Search | Deadline | Appeals Required |
|---|---|---|---|---|---|
| Access / Know | Web form, toll-free # | Identity verification | CRM, analytics, data lake | Typically 45 days | Varies by state |
| Correction | Web form, email | Verify accuracy of new data | CRM, vendor databases | 45 days | Varies by state |
| Deletion | Web form, DROP (CA) | Identity verification | CRM, backups, processors | 45 days | Varies by state |
| Opt-Out (sale/ads) | GPC, "Do Not Sell" link | No verification required | AdTech, CRM, DSPs | 15 days (CA standard) | N/A |
| Appeals | Dedicated email/form | Reference original request | Legal/compliance review | Varies by state (typically 45–60 days) | IN, KY, RI required |
Privacy Notices, Data Mapping, Retention, and Risk Assessments
These rules shouldn’t live in a policy doc and nowhere else. They should show up in your privacy notice, your retention schedule, and your review process.
Privacy notices need to do more in 2026. At a minimum, they should:
- reflect rights for Indiana, Kentucky, and Rhode Island residents
- disclose categories of data shared with contractors and service providers
- explain how opt-out signals such as GPC are handled
California adds another layer here. Before using automated decision-making for major decisions like credit, employment, or housing, businesses must provide pre-use notices. Consumers also have the right to opt out of some automated decisions.
Risk assessments are also moving out of the legal silo. In California, a member of executive management must now personally attest to the accuracy of the business’s privacy risk assessments. That changes privacy from a back-office task into a governance issue with direct leadership responsibility.
This maturity model makes it easier to see where marketing, RevOps, and SaaS workflows may fall short.
| Maturity Level | What It Covers |
|---|---|
| Baseline | Privacy notice updated for 2026 state laws; basic rights intake form live; data categories inventoried in CRM and forms |
| Operational | GPC signals honored automatically; correction and deletion workflows tested end to end; DPAs in place with key vendors; appeal process documented |
| Advanced | Executive attestation process for risk assessments; pre-use notices for automated decision-making deployed; enrichment and automation tools mapped to retention schedules; DROP sync configured (if applicable) |
Retention needs to match purpose and deletion rules. Keep data only for as long as you need it for the stated purpose. The FTC’s 2025 COPPA updates also add prescriptive retention limits for children’s data.
Form and Lead-Flow Compliance Review for B2B and SaaS Teams
Privacy compliance doesn't stop at the policy page. It runs through every field your forms collect, every system that touches a lead record, and every vendor that handles data on your behalf.
For B2B and SaaS teams, this is where legal rules turn into form fields, routing logic, and retention settings. The next review is hands-on: first the form itself, then every system that handles the lead after someone hits submit.
What to Audit in Your Forms: Fields, Consent Language, Notice Placement, and Routing
Start with what you're collecting. Go through every live form and ask a simple question: do we need this field for the transaction? Collect only the fields required for that transaction.
Watch for any sensitive field. When one appears, apply the state-specific notice and consent required at the point of collection. Keep required fields to a minimum, and place the privacy notice link right beside the form so people can see it when they submit.
Then check your routing rules. If form logic sends submissions into third-party systems, look at each destination and ask whether that recipient needs the data. If sensitive submissions are routed into systems that don't need them, you create downstream risk that's tough to clean up later.
Add age-gating when youth data is even a possibility. Youth data gets extra scrutiny across several states.
What to Audit After Submission: Enrichment, CRM Sync, Automation, Analytics, and Retention
Once the data is collected, trace the record through your CRM, automation tools, analytics stack, and retention workflow. Make sure consent and opt-out status stay attached to the lead record the whole way through. If a consumer revokes consent, that signal needs to move across every connected channel.
Enrichment tools need a close look. Once a consumer's data is corrected, it cannot be overwritten by later third-party data. That sounds simple, but here's where teams get tripped up: if your CRM auto-refreshes records from enrichment sources, a corrected record could get replaced on the next sync. Review whether your enrichment vendors fall under the expanded data broker definitions in California and Texas, and confirm that deletion requests flow through to those vendors.
Partial-submission tracking is another easy miss. If partial entries include personal data, verify how long those entries are kept and whether they show up in access and deletion workflows.
Retention matters too. Old lead records that have outlived their stated purpose become a liability. Automated workflows that purge records on a set schedule can cut that risk.
Using Reform in a Privacy-by-Design Review
Use the same checklist when reviewing your form builder and connected automations. Look at Reform's multi-step forms, conditional routing, lead enrichment, spam prevention, email validation, and CRM integrations as part of the same privacy review.
Compliance comes down to configuration, routing, and retention.
2026 Implementation Priorities and Next Steps
The Highest-Risk Gaps to Fix First
After the form and lead-flow review, fix the issues that create the most immediate compliance exposure. Broken opt-out links, old privacy notices, and consent banners that don't honor Global Privacy Control signals are some of the first things regulators can spot.
A few internal gaps stand out right now:
- Missing or stale privacy notices for Indiana, Kentucky, and Rhode Island leave businesses exposed under laws that are already in effect.
- Consent revocation that doesn't carry across forms, CRM, automation, and ad platforms is a common breakdown.
- Sensitive data handled without documented notice, consent, and risk review creates immediate exposure.
- Inconsistent consent records become a documentation problem the moment a rights request comes in.
- Profiling or automated decision-making without a pre-use notice is a gap that will get more serious as ADMT enforcement moves toward the January 1, 2027 deadline.
The fastest way to make progress is simple: assign each gap to one accountable team.
Owner-Based Rollout Plan for Legal, Marketing, RevOps, IT, and Sales Operations
One team can't fix this alone. Clear ownership matters from day one, especially when work touches forms, CRM data, ad systems, and vendor tools at the same time.
| Function | 2026 Actions |
|---|---|
| Legal | Confirm states in scope; update privacy notices for IN, KY, and RI; manage executive attestations for CA risk assessments; review vendor DPAs |
| Marketing | Audit lead-gen consent language; deploy GPC-compliant banners; block youth data from targeted ads |
| RevOps | Inventory connected systems; classify data; propagate opt-outs; protect corrected records from overwrite |
| IT / Security | Complete risk assessments for high-risk processing before deployment; build technical workflows for access, deletion, and portability requests; prepare for California audit readiness |
| Sales Ops | Review lead-flow forms for proper notice placement; ensure enrichment tools do not violate data broker registration rules; route correction requests into sales databases |
Use the rest of 2026 to close notice, consent, GPC, and ADMT gaps before year-end. Then use late 2026 to get ready for the 2027 ADMT rules.
Key Takeaways for 2026 Privacy Compliance
Once owners are assigned, the work shifts to execution. In 2026, privacy compliance runs straight through marketing forms, CRM setup, enrichment logic, and sales workflows. Treat your high-converting lead forms and lead flows as compliance infrastructure, not just conversion tools.
As updates roll out, document consent and notice versions so there's a clear record of what changed and when. Build a repeatable process for rights requests, including access, correction, deletion, portability, and appeals, so responses don't depend on someone scrambling to remember the steps under pressure. State thresholds and enforcement priorities keep changing, so it's smart to recheck scope and deadlines throughout 2026.
FAQs
How do I know which state privacy laws apply to my business?
Check your business against each state law’s triggers. Most states look at annual gross revenue, how much consumer data you process, or whether you sell personal information.
Start by mapping your data flows and reviewing customer counts by state. The thresholds can be all over the map. California, for example, uses a $26,625,000 revenue trigger. Texas and Nebraska, by contrast, can apply to many businesses no matter how big or small they are.
What systems should I audit first for privacy compliance gaps?
Start with a full inventory of tags, pixels, SDKs, and session replay tools. Then map how consumer data is collected, stored, and shared.
Next, review public-facing features. Make sure your privacy policy is accurate, opt-out tools work, data rights request intake is centralized, and vendor agreements include required terms.
How should we handle GPC, deletion, and correction across connected tools?
Make sure Global Privacy Control (GPC), deletion, and correction requests are handled across your entire tech stack in practice, not just on the surface. A banner or form that looks right doesn't mean much if scripts behind the scenes still collect or pass along consumer data.
Start by auditing your tags and pixels. You need a clear view of every script that touches consumer data and where that data goes.
Then set up those tools so they can detect and honor GPC. For deletion and correction requests, use one centralized, branded intake form and route each request to the right team so you can respond within the 45-day window.
Related Blog Posts
Get new content delivered straight to your inbox
The Response
Updates on the Reform platform, insights on optimizing conversion rates, and tips to craft forms that convert.
Drive real results with form optimizations
Tested across hundreds of experiments, our strategies deliver a 215% lift in qualified leads for B2B and SaaS companies.

.webp)


