US State Privacy Laws Beyond CCPA: Virginia, Colorado, and the Growing Patchwork
California's CCPA isn't the only state privacy law US businesses need to comply with anymore. Here's what the growing multi-state patchwork actually requires technically.

Meerako — A Dallas-based technology partner building compliant data infrastructure for the multi-state US privacy landscape.
Introduction
For years, CCPA (California's privacy law) was the primary US state privacy regulation businesses needed to account for beyond federal sector-specific rules. That's no longer true — Virginia, Colorado, Connecticut, Utah, and a growing list of additional states have passed their own comprehensive privacy laws, each with real, if often overlapping, technical requirements. US businesses handling personal data now need to think about compliance across a genuine multi-state patchwork, not a single California-specific standard.
What You'll Learn
- Why the multi-state patchwork has grown, and where it's heading.
- What these laws share technically, and where they meaningfully differ.
- How to architect compliance for multiple state laws efficiently, not redundantly.
- What triggers apply for smaller businesses that might assume they're exempt.
Why the Patchwork Has Grown
In the absence of a comprehensive federal privacy law, individual states have moved to fill the gap independently — Virginia's Consumer Data Protection Act, Colorado's Privacy Act, and similar laws in Connecticut, Utah, and additional states passed since, each generally modeled loosely on GDPR and CCPA's core structure, but with genuinely different specific thresholds, requirements, and enforcement mechanisms. This trend shows no sign of slowing — more states are actively considering similar legislation, meaning the patchwork is very likely to keep growing.
Most of these state laws share a similar core structure: consumer rights to access, delete, and correct personal data; opt-out rights for data sales and, in several states, targeted advertising; and requirements around data processing agreements with third-party vendors. Building the core technical infrastructure for one comprehensive law — genuine data mapping, cascading deletion, granular consent management — largely transfers to compliance with the others, which is the practical silver lining in an otherwise fragmented landscape.
Where They Meaningfully Differ
Specific thresholds for which businesses the law applies to vary by state (based on revenue, data volume, or percentage of revenue from data sales), some states have stricter requirements around sensitive data categories or explicit opt-in consent for certain processing, and enforcement mechanisms differ — some states include a private right of action allowing individual consumers to sue directly, which meaningfully raises the practical stakes of non-compliance in those specific states.
Architecting for the Patchwork Efficiently
Rather than building separate compliance logic for each state, the practical approach builds one robust, comprehensive privacy infrastructure layer — covering the strictest common requirements across applicable states — and applies it broadly, rather than maintaining fragmented, state-specific logic that's harder to maintain correctly as more states pass new laws. This "build to the highest common bar" approach is both more maintainable and more genuinely protective than a minimal, state-by-state patchwork of narrow compliance logic.
Smaller Businesses Shouldn't Assume Exemption
Many of these laws have thresholds that smaller, growing businesses can cross without necessarily realizing it — revenue or data volume thresholds that don't require being a large enterprise to trigger. Businesses should actively evaluate their specific applicability under each state's threshold rather than assuming smaller scale automatically means exemption.
How Meerako Approaches Multi-State Privacy Compliance
We build the same robust data mapping, cascading deletion, and consent management infrastructure regardless of which specific state laws currently apply, since this "build to the highest common bar" approach both simplifies engineering and provides genuine protection as the multi-state patchwork continues expanding — working alongside legal counsel to confirm specific state-by-state applicability and any state-specific nuances.
Frequently Asked Questions
Do these state privacy laws apply only to businesses physically located in that state? No — like CCPA, most apply based on doing business with residents of that state or meeting specific data-volume or revenue thresholds tied to that state's residents, regardless of where the business itself is physically located.
Is a federal privacy law likely to replace this state-by-state patchwork soon? There's ongoing discussion and various proposals in Congress, but no comprehensive federal privacy law has passed as of now — businesses should plan for the current multi-state patchwork to persist for the foreseeable future, not assume imminent federal preemption.
How do private right of action provisions in some states change the practical risk? States allowing individual consumers to sue directly (rather than only state regulators enforcing) meaningfully raise practical litigation risk and should be weighed with real seriousness in prioritizing compliance work for businesses with exposure in those specific states.
Should a business build privacy compliance infrastructure even if it's currently below every state's applicability threshold? It's worth genuine consideration for a growing business — thresholds are often crossed before a company realizes it, and building the infrastructure proactively is meaningfully cheaper than retrofitting it urgently once a threshold is crossed or a complaint arrives.
Conclusion
The US privacy law landscape has genuinely fragmented into a growing multi-state patchwork beyond California's CCPA — the practical, efficient response is building robust privacy infrastructure to the highest common technical bar across applicable laws, rather than fragmented state-by-state compliance logic that's harder to maintain as more states pass their own laws.
Navigating the multi-state privacy compliance landscape? Let's build infrastructure that scales with it.
🧠 Meerako — Your Trusted Dallas Technology Partner.
From concept to scale, we deliver world-class SaaS, web, and AI solutions.
📞 Call us at +1 469-336-9968 or 💌 email hello@meerako.com for a free consultation.
Start Your Project →Tags
Share this article
Meerako Team
Editorial Team
Practical guidance from Meerako's delivery team on software strategy, product execution, SEO, SaaS, AI, and modern engineering best practices.
Continue Reading
Related Articles
Adjacent topics and deeper implementation guides hand-picked for this article.

Shadow AI: The Compliance Risk of Employees Using Unapproved AI Tools
Employees are pasting sensitive company data into consumer AI tools right now, with no governance and no visibility. Here's what shadow AI actually risks, and how to address it.

AI Red Teaming: Testing Your LLM Features for Jailbreaks Before Attackers Do
Every LLM feature has failure modes an attacker will eventually find. AI red teaming finds them first. Here's what a real red teaming process actually covers.

GDPR and CCPA Compliance for SaaS: A Technical Implementation Checklist
GDPR and CCPA compliance is as much a technical implementation problem as a legal one. Here's the concrete checklist of what your SaaS application actually needs to build.