Salta al contenuto principale

The Mid-2026 State Privacy Law Wave: What Small Businesses Need to Know

7 minuti di letturaMike ThriftMike Thrift
The Mid-2026 State Privacy Law Wave: What Small Businesses Need to Know

If your business collects customer emails, runs a loyalty program, or drops a single tracking pixel on your website, July 1, 2026 quietly changed your legal obligations — even if you've never heard of Connecticut's, Arkansas's, or Utah's privacy statutes. What started as a handful of state privacy laws aimed at Big Tech has, in the span of two years, become a 20-plus-state patchwork that increasingly reaches ordinary small businesses, not just data-broker giants.

The mid-2026 wave is different from earlier rounds in one important way: the thresholds for who counts as "covered" keep dropping, and the categories of "sensitive" data keep expanding. A business that was safely below the radar in 2024 may find itself squarely inside the law today. Here's what actually changed, who it applies to, and what to do about it.

What Changed on July 1, 2026

Three states — Connecticut, Arkansas, and Utah — had major privacy law provisions take effect on July 1, 2026, layering on top of California's expanded data broker rules that began rolling out earlier in the year. Together they represent the most consequential mid-year privacy update since states started passing comprehensive privacy legislation. None of these laws are identical, and none use the same thresholds or definitions, which is exactly why compliance has gotten harder rather than easier as more states pile on.

Connecticut: The Threshold Just Got a Lot Lower

Connecticut's Data Privacy Act (CTDPA) was amended by SB 1295, and the headline change is the applicability threshold. Previously, the law only covered businesses that processed personal data for at least 100,000 Connecticut residents in a year. As of July 1, that number drops to 35,000 residents — a nearly two-thirds reduction that pulls a meaningful number of regional and multi-state small businesses into scope for the first time.

There's a second, more aggressive trigger: if your business processes any "sensitive data" or engages in any sale of personal data, you're covered regardless of volume. That means a five-person company processing sensitive information for even a few hundred Connecticut customers can be subject to the law.

Connecticut also expanded its definition of sensitive data to include government-issued IDs, financial account numbers, Social Security numbers, and — notably — neural data (information generated by brain-computer interface devices). Sensitive data now requires opt-in consent before collection and can't be sold without explicit consumer approval.

The most novel piece of the amendment is a new AI transparency requirement: businesses must disclose in their privacy notices whether they collect, use, or sell personal data for the purpose of training large language models. If you've licensed customer data to a vendor, used a chatbot platform that trains on your inputs, or signed a contract with "model improvement" language buried in the terms, you now need to say so publicly. This is the first state mandate of its kind, and other states are expected to follow.

Arkansas: A Flat Ban on Targeted Ads to Minors

Arkansas's Children and Teens' Online Privacy Protection Act (ACTOPPA), also effective July 1, takes a harder line than any comparable law on the books. For children age 12 and under, the law requires verifiable parental consent before collecting personal data. For teens 13 through 16, either the teen or a parent can provide consent.

The part that catches businesses off guard is the advertising rule: targeted advertising to minors under the law is flatly prohibited, with no consent exception, no opt-in path, and no parental workaround. If your business runs any kind of retargeting, lookalike audience, or interest-based ad campaign and your audience includes users under 17, you need age-appropriate guardrails in your ad stack — not just a checkbox in your terms of service.

Data collection from minors is also limited to what's "reasonably necessary" to provide the service, echoing the data-minimization language showing up across the newer wave of state laws. One piece of relief: only the Arkansas Attorney General can enforce ACTOPPA — there's no private right of action, which lowers (but doesn't eliminate) litigation exposure.

Utah: Correction Rights and Social Media Portability

Utah's contribution, HB 418, amends the state's Digital Choice Act with two new consumer rights. First, a right to correct inaccurate personal data — consumers can now ask a business to fix wrong information about them, not just delete it or opt out of its sale. Second, and more specific to platforms, new data portability and interoperability requirements for social media services, meant to let users move their data between competing platforms.

For most small businesses, the correction right is the one that matters. If you maintain customer records — a CRM, an email list, a membership database — you'll need an intake and verification workflow for correction requests, similar to what many businesses already built for deletion requests under earlier privacy laws.

California: Data Brokers Now Have to Name Names

California's data broker rules, tightened by SB 361 and rolling out through 2026, require registered data brokers to disclose not just what categories of data they collect, but whether they've shared or sold that data to foreign actors, government entities, law enforcement, or generative AI developers. "Foreign actor" specifically captures entities tied to adversary nations including China, Russia, Iran, and North Korea.

This mostly affects businesses that meet California's legal definition of a data broker — companies that sell consumer data to third parties they have no direct relationship with. But if your business works with a data broker as a vendor, or resells enriched customer data as part of your revenue model, it's worth checking whether the label applies to you before the next annual CPPA registration deadline.

Do These Laws Actually Apply to You?

This is the question that trips up most small business owners, because the honest answer is "it depends on where your customers live, not where your business is." State privacy laws generally apply based on the residency of the people whose data you process, not your company's home state or size in the traditional sense.

A few practical signals that you may be in scope somewhere:

  • You have customers, email subscribers, or website visitors in Connecticut, and you process any of the newly expanded sensitive data categories (financial info, government IDs, health data).
  • Your marketing touches users under 17 in Arkansas — including via third-party ad platforms you didn't build yourself.
  • You maintain customer records for Utah residents and haven't built a correction-request process.
  • You use any data broker, ad network, or list-rental vendor and haven't asked what they do with the information.

If none of those apply, you may genuinely be out of scope for now — but "for now" is doing a lot of work in that sentence, given how fast thresholds have been falling.

A Practical Compliance Checklist

You don't need a compliance department to get the basics right. Start here:

  1. Inventory what you collect. You can't comply with data-category rules you haven't mapped. List every place customer data enters your business — website forms, POS systems, email signups, ad pixels.
  2. Check your vendor contracts for AI training language. If you use a CRM, chatbot, or analytics tool, look for clauses about using your data to "improve" or "train" models. Connecticut now requires you to disclose this publicly.
  3. Update your privacy policy. Add LLM-training disclosure language if applicable, and make sure your policy actually reflects what you do — regulators increasingly compare policy language against real practice.
  4. Build a lightweight request process. A single email address or form where customers can ask to correct, delete, or opt out of the sale of their data covers most obligations across states.
  5. Segment ad targeting for minors if relevant. If your audience skews young, disable interest-based and retargeted ads for that segment rather than trying to build a state-by-state exception.

Keep Your Financial Records as Clean as Your Data Policy

Privacy compliance and financial recordkeeping share the same underlying discipline: know exactly what you're collecting, where it lives, and who can see it. Beancount.io brings that same transparency to your books with plain-text accounting that's version-controlled, auditable, and free of vendor lock-in — no black box, no guessing what changed or when. Get started for free and keep your financial data as well-organized as your compliance program.

Condividi questo articolo