If you run a website with a contact form, an email list, or a CRM that stores customer phone numbers, you are collecting personal data. As of January 1, 2026, that simple fact is enough to pull you under a comprehensive privacy law in at least one U.S. state — possibly several at once, if you sell to customers across state lines.
Twenty states now have comprehensive consumer privacy laws on the books, and three of them — Indiana, Kentucky, and Rhode Island — flipped the switch on January 1, 2026. Texas, whose Data Privacy and Security Act (TDPSA) has been active since mid-2024, layered in an AI-specific amendment the same day. For years, small business owners could reasonably assume these laws were a "big company problem" — California's CCPA, after all, only applies to businesses with $25 million or more in revenue. That assumption no longer holds everywhere. Two of the three new 2026 laws have no revenue threshold at all, and Texas never had one to begin with.
This isn't a compliance checklist you can outsource entirely to a lawyer and forget. Whether these laws apply to you often comes down to numbers you should already be tracking in your books: how many customer records you hold, and — critically — what share of your revenue comes from selling or sharing personal data. If your bookkeeping can't answer that second question cleanly, you have a bigger problem than privacy law.
The Three New 2026 Laws, in Plain English
Indiana Consumer Data Protection Act (INCDPA) applies to for-profit businesses that either:
- Control or process personal data of 100,000+ Indiana residents in a calendar year, or
- Derive more than 50% of gross revenue from selling personal data and process data of 25,000+ Indiana residents.
Kentucky Consumer Data Protection Act (KCDPA) mirrors Indiana's thresholds almost exactly — same 100,000-consumer floor, same 50%-of-revenue-from-data-sales alternative test at 25,000 consumers. Both statutes are close cousins of Virginia's 2023 law, so if you've already built compliance for Virginia or Colorado, most of the groundwork carries over.
Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) sets a noticeably lower bar:
- Controls or processes data of 35,000+ Rhode Island residents, or
- Controls or processes data of 10,000+ residents and derives 20% or more of gross revenue from selling personal data.
Rhode Island also skips the 30-day cure period that Indiana and Kentucky grant violators — a first offense there can go straight to an Attorney General enforcement action, with penalties up to $10,000 per violation (versus $7,500 in Indiana and Kentucky).
Texas Data Privacy and Security Act (TDPSA) is the outlier worth flagging separately: it has no consumer-count or revenue threshold whatsoever. Instead it uses a small business exemption tied to the U.S. Small Business Administration's size standards (which vary by industry — a software company qualifies at a different headcount than a manufacturer). The catch: that exemption evaporates the moment a "small" business sells sensitive personal data — health information, precise geolocation, biometric identifiers, and similar categories. A lot of small e-commerce and marketing-tech businesses trip this wire without realizing it, because "selling data" under these laws is defined broadly enough to capture some ad-tech and analytics integrations, not just literal data brokering.
Why the Revenue Threshold Is the Part Most Owners Get Wrong
The most common way small businesses miscalculate their exposure isn't the consumer count — it's the revenue percentage. "50% of gross revenue from selling personal data" sounds like it only applies to data brokers. But the legal definition of a "sale" in most of these statutes includes sharing personal data for monetary or other valuable consideration — which can sweep in ad-network revenue shares, co-marketing arrangements, and even some affiliate structures where customer data flows alongside the transaction.
Here's the practical problem: if your chart of accounts lumps "ad revenue," "affiliate revenue," and "product revenue" into one undifferentiated income line, you cannot answer the question these laws are asking you. You need your books to separate revenue streams cleanly enough to say, with a number, whether any category tied to data-sharing arrangements crosses 20% (Rhode Island) or 50% (Indiana, Kentucky) of total revenue. Waiting until an Attorney General's office asks is the wrong time to find out your bookkeeping can't produce that breakdown.
This is a case where "helpful to know" and "helpful to prove" are the same exercise. A plain-text, version-controlled ledger where every revenue account is tagged by source — Income:Advertising, Income:AffiliateShare, Income:ProductSales — lets you run that percentage in minutes instead of reconstructing it from a year of bank statements and invoices.
A Practical Compliance Checklist
You don't need a general counsel on retainer to get the basics right. Work through these in order:
- Count your records, not your customers. Pull a rough count of unique individuals whose personal data you store or process in a calendar year — website visitors with tracking cookies, email subscribers, CRM contacts, and transaction records all count in most states' definitions, not just paying customers.
- Check where those people live. These laws are triggered by state residency of the consumer, not where your business is headquartered. A Delaware-incorporated, remote-first business selling nationally can be subject to Indiana's law even with zero employees in Indiana.
- Break out any data-sharing revenue. If any part of your income involves sharing customer data with an ad network, data co-op, or partner — even indirectly — isolate that revenue in its own account and calculate it as a percentage of gross.
- Publish a real privacy notice. All four states require a clear, accessible notice describing what data you collect, why, and how consumers can exercise rights (access, correction, deletion, and opt-out of targeted advertising or data sales). A generic template copied from another site with the wrong effective date or wrong company name is worse than nothing — regulators have specifically flagged stale privacy notices as an easy first-glance violation.
- Build the opt-out mechanism before you need it. Consumers in all three new states get the right to opt out of targeted advertising, data sales, and certain profiling. If your website doesn't have a working "Do Not Sell or Share My Personal Information" link or equivalent preference center, that's the fastest fix on this list and the one most likely to get flagged first.
- Use the cure period if you get one. Indiana and Kentucky give 30 days to fix a violation after notice from the Attorney General before penalties apply. Rhode Island doesn't — which makes getting steps 1–5 right before January 1 traffic ramped up considerably more valuable there than in the other two states.
- Re-run the calculation annually. Thresholds are evaluated on an ongoing basis, typically by calendar year. A business that was exempt in 2025 because it stayed under 100,000 records can cross into coverage the moment growth (or a data-sharing deal) pushes it over the line — this is a recurring bookkeeping check, not a one-time audit.
Where Small Businesses Get Caught Off Guard
Two blind spots come up repeatedly in early guidance on the 2026 laws:
- "We're too small" isn't a universal defense. Texas has no floor at all, and its small-business exemption disappears the instant sensitive data is sold — a common trap for businesses using third-party analytics or ad pixels without auditing what data those tools actually transmit.
- Enforcement is state Attorney General-driven, not private lawsuits (mostly). None of the three new 2026 laws include a broad private right of action, which is genuinely good news — it means an individual consumer generally can't sue your business directly over a privacy violation. But it also means enforcement discretion sits with a state AG's office that has every incentive to make an early, visible example out of a business that ignored a clearly-dated new law.
How the Four Laws Stack Up
| Indiana | Kentucky | Rhode Island | Texas | |
|---|---|---|---|---|
| Effective date | Jan. 1, 2026 | Jan. 1, 2026 | Jan. 1, 2026 | Active since 2024; AI amendment Jan. 1, 2026 |
| Applies at | 100,000+ residents, or 25,000+ with 50%+ revenue from data sales | 100,000+ residents, or 25,000+ with 50%+ revenue from data sales | 35,000+ residents, or 10,000+ with 20%+ revenue from data sales | No floor — SBA-size small businesses exempt unless they sell sensitive data |
| Cure period | 30 days | 30 days | None | 30 days |
| Max penalty | $7,500/violation | $7,500/violation | $10,000/violation | Up to $7,500/violation |
| Private lawsuits | No — AG only | No — AG only | No — AG only | No — AG only |
The pattern worth noticing: Rhode Island's combination of a low consumer floor, a low revenue-percentage trigger, and zero cure period makes it the least forgiving of the four for a fast-growing small business that crosses the line without noticing. Texas is the opposite shape of risk — most small businesses start out exempt, but a single new ad-tech integration that shares sensitive data can erase that exemption overnight.
Frequently Asked Questions
Does this apply to my business if I'm not physically located in any of these states? Yes. All four laws are triggered by where your customers or website visitors live, not where your business is registered or headquartered. A business with no employees or offices in Indiana can still be subject to the INCDPA if it processes data belonging to 100,000+ Indiana residents.
I use Google Analytics and a Facebook ad pixel — does that count as "selling" data? Potentially. Most of these statutes define a "sale" broadly enough to include sharing data for something of value, not just a direct cash transaction. Ad-tech integrations that pass customer data to third parties for targeted advertising are exactly the kind of arrangement regulators have flagged as within scope — worth an honest audit of what your tracking pixels actually transmit, rather than assuming "we don't sell a list" settles the question.
What happens if I do nothing? In Indiana and Kentucky, the Attorney General must typically notify you and give 30 days to cure a violation before penalties apply — so a good-faith business that fixes issues promptly after notice has a real safety net. Rhode Island offers no such grace period, so waiting to act is a materially riskier bet there than in the other two 2026 states.
Do I need a lawyer to comply? For a straightforward small business — a services company, an online store, a SaaS product with a normal customer list — the checklist above (privacy notice, opt-out link, data inventory, revenue-source tracking) covers the majority of practical exposure without custom legal drafting. If your business shares data with ad networks, data brokers, or partners in ways that are hard to describe in one sentence, that complexity is exactly when outside counsel earns its fee.
Keep Your Records Clean Enough to Answer the Hard Questions
Privacy compliance and financial record-keeping turn out to be more connected than most owners expect: both come down to whether your data — customer data on one side, revenue data on the other — is organized well enough to produce a clear answer under scrutiny. If your books can't currently tell you what percentage of revenue comes from a specific source, that's worth fixing regardless of which state's privacy law applies to you.
Beancount.io offers plain-text accounting that gives you full transparency and control over your financial data — every revenue stream tagged, version-controlled, and queryable, with no black-box software standing between you and the numbers regulators (or your own due diligence) might ask for. Get started for free and see why developers and finance-minded business owners are switching to plain-text accounting.