Quick answer
The US has no federal GDPR equivalent, so states legislate individually: California's CCPA/CPRA led, and Virginia, Colorado, Connecticut, Utah, Texas, and more than a dozen others followed. Over 19 state privacy laws now exist, each with its own thresholds, consumer rights, and enforcement. If you sell to US consumers across states, you comply with all of them, and new ones keep arriving. The workable strategy is one centralized privacy program mapped to every applicable law, not 19 parallel projects.
What the laws have in common
Despite different texts, the state laws converge on a recognizable core:
- Consumer rights: access, deletion, correction, portability, and opt-out of sale or targeted advertising.
- Notice obligations: privacy policies describing collection, purposes, and sharing.
- Contracts with processors and service providers.
- Risk assessments for higher-risk processing (profiling, sensitive data) in several states.
- Universal opt-out signals (like Global Privacy Control) honored in a growing subset.
The differences are in thresholds (revenue, record counts), cure periods, sensitive-data definitions, and enforcement style. That's exactly the kind of variance a cross-mapped requirement catalog absorbs: one control, many statutory citations.
Why this matters for non-US companies too
European companies selling into the US often assume GDPR compliance covers them. It helps enormously (the rights machinery and records exist), but the state laws differ in scope: they cover consumer data more broadly than employment context, define "sale" of data expansively, and require specific opt-out mechanics GDPR doesn't. A GDPR program is the right foundation and roughly 70 percent of the work; the state-law delta still needs mapping. See how OptiTech handles the delta.
The trajectory
More states pass laws every legislative season, and requirements tighten over time. A centralized program treats each new law as a delta analysis against existing controls rather than a fresh scramble, the same way framework version updates arrive as managed diffs.

Get a personalized walkthrough of automated compliance for your team. No commitment required.