US State Laws
US State Privacy Laws (VCDPA, CTDPA, UCPA & more)
Beyond California: Virginia, Connecticut, Colorado, Utah, and other states now enforce their own privacy rules for cookies and personal data.
Quick navigation
US State Laws
What it means
The United States has no single federal privacy law for all websites. California led with CCPA and CPRA, but Virginia (VCDPA), Connecticut (CTDPA), Utah (UCPA), Colorado (CPA), and other states followed with their own requirements.
For agencies selling to US clients, saying you support 'US state privacy laws' - not only CCPA - signals that you understand the full American compliance landscape.
United States · multi-state
Who must comply
- You do business in Virginia, Connecticut, Colorado, Utah, or other states with active privacy laws.
- You meet state-specific thresholds for revenue, data volume, or data sales/sharing.
- You use advertising, analytics, or profiling technologies on US visitors from covered states.
US State Laws
What you need to do
- Provide state-appropriate privacy notices and opt-out rights.
- Honor 'Do Not Sell or Share' and targeted advertising opt-outs where applicable.
- Respond to access, deletion, and correction requests from covered residents.
- Map which states your traffic and clients trigger based on thresholds.
- Maintain vendor contracts aligned with service provider rules.
Plain language
What it is not
US State Laws
FAQ
What are VCDPA, CTDPA, and UCPA?
They are comprehensive state privacy laws in Virginia, Connecticut, and Utah. Colorado's CPA is another major example in the same generation of US state laws.
Do I need separate banners per state?
Most sites use one US-oriented consent experience that satisfies the strictest applicable state requirements for their traffic.
Why mention state laws on a marketing page?
US agencies and legal teams immediately recognize that you understand compliance beyond California alone - that builds trust.