Back to BaseMonkeys Insights

Cyber Security · Marketing · Martech

The U.S. Privacy Patchwork: What Growing Businesses Need to Know About Customer Data

This is a business and operations guide, not legal advice. Which laws apply to your company and how to comply with them is a question for qualified counsel — this post is meant to help you have that conversation prepared, not replace it.

A corkboard with a paper U.S. map, colored pins, and hanging file folders

Privacy Compliance Is No Longer Just About California

For years, "privacy compliance" meant one law: California's CCPA. That era is over. Twenty states now have comprehensive consumer privacy laws on the books, with Indiana, Kentucky, and Rhode Island joining the list as recently as January 1 of this year.

Here's the part that catches growing businesses off guard: these laws generally apply based on where your customers live, not where your company is headquartered. A Raleigh-based business with customers in Colorado, Connecticut, and Virginia can find itself subject to three separate state frameworks without ever opening an office outside North Carolina.

Important Scope Questions

Before you can answer "are we compliant," you have to answer "does this even apply to us." That comes down to a handful of questions:

  • Where are your customers located? Each state law only covers residents of that state.
  • What personal data do you collect? Contact details, browsing behavior, and geolocation all count differently under different laws.
  • How much data do you process? Most state laws set a volume threshold — process below it, and the law may not apply to you at all.
  • Is data sold or shared? Several state laws define "sale" far more broadly than the plain-English meaning — more on that below.
  • Do you use targeted advertising? Retargeting pixels and ad platforms often trigger obligations businesses don't realize they've taken on.
  • Does an exemption apply? Nonprofits, certain financial and healthcare data already covered by federal law, and small-business thresholds vary by state.

Consumer Rights That Frequently Appear

The specific list varies state by state, but most of these frameworks give consumers some version of the same rights:

  • Access to the personal data a company holds about them.
  • Correction of inaccurate data.
  • Deletion of their data.
  • Portability — the ability to receive their data in a usable format.
  • Opt-out of the sale or sharing of their data.
  • Opt-out of targeted advertising specifically.
  • The right to appeal a denied request.

If your business can't currently fulfill all seven of those on request, that's the practical gap — regardless of what your privacy policy claims.

The Marketing and CRM Data at Issue

This is where privacy compliance stops being a legal department's problem and becomes a marketing and operations problem. The data categories these laws cover live directly inside the systems your team touches every day:

  • Contact information in your CRM.
  • Browsing activity tracked on your website.
  • Device identifiers collected by ad and analytics platforms.
  • Geolocation data — even approximate, IP-based location counts in many frameworks.
  • Purchase history.
  • Lead-source data showing how someone found you.
  • Behavioral profiles built from any of the above.

Why a Privacy Policy Alone Is Not Compliance

A privacy policy is a promise. Compliance is whether your systems actually keep it — and California's own enforcement record shows what happens when they don't. In May 2026, the California Attorney General secured a $12.75 million settlement from General Motors after finding the company sold driving and geolocation data collected through OnStar to data brokers Verisk Analytics and LexisNexis Risk Solutions — despite a privacy policy that specifically claimed it did not sell that data. The gap wasn't the policy's language. It was that GM's internal data practices didn't match what the policy promised.

That's the trap a document alone can't close. A request needs to actually propagate across your CRM, your email platform, your analytics tools, and every vendor holding a copy of that customer's data — and you need a real data inventory and retention policy to know where all those copies live in the first place.

Operational Capabilities Businesses Need

Turning a privacy policy into something you can actually operate requires:

  • A data inventory — knowing what personal data you collect and where it lives.
  • Consent and preference management — tracking what each individual has actually agreed to.
  • Request intake — a real process for consumers to submit access, correction, or deletion requests.
  • Identity verification — confirming a request is genuinely from the person it claims to be from.
  • Suppression and deletion workflows that reach every system, not just the primary database.
  • Vendor tracking — knowing every third party that receives your customer data.
  • Response documentation — a record proving you actually fulfilled the request, and when.

The Martech Vendor Problem

This is the piece most businesses underestimate. The average marketing technology environment runs 17 to 20 separate platforms, and each one that touches customer data is a separate place a deletion request has to reach. Removing a contact from your CRM does nothing for the copy sitting in your email platform, your ad retargeting audience, or a data enrichment vendor you signed up with two years ago and forgot about.

Sephora's 2022 CCPA settlement is the clearest illustration of how this trips businesses up. The company was penalized $1.2 million not for a data breach, but for allowing third-party tracking scripts on its website to collect shopping and location data — behavior California's Attorney General ruled constituted a "sale" of personal information under the law's broad definition, even though no money changed hands in the way most people picture a "sale." Sephora also hadn't honored Global Privacy Control opt-out signals browsers were already sending. A standard analytics or ad pixel most marketing teams install without a second thought can create exactly this exposure. Every vendor contract and data-processing agreement needs review with that broad definition in mind, not the narrow one most people assume.

A Practical Compliance Roadmap

  1. Work with counsel to identify which state laws actually apply to your business.
  2. Map your data and systems — every platform that touches customer data, listed out.
  3. Reduce unnecessary collection — the least risky data is the data you never collected.
  4. Update notices and choices to match what your systems actually do, not an aspirational version.
  5. Build request workflows that reach every connected system, not just the primary one.
  6. Test and document the process before a real request — or a regulator — tests it for you.

Common Mistakes

The patterns behind most enforcement actions are strikingly ordinary:

  • Copying another company's privacy policy without matching it to actual internal practices.
  • Treating a cookie banner as complete compliance, when it's one small piece of a much larger obligation.
  • Forgetting offline and CRM data — compliance efforts often focus entirely on the website and ignore the sales database.
  • Keeping information indefinitely with no retention policy, which expands your risk with every year of data you didn't need to keep.
  • Failing to monitor new states and rule changes — three more states added obligations this January alone, and that pace isn't slowing down.

Penalties aren't theoretical, either. California's per-violation civil penalties currently sit at up to $2,663 for a standard violation and $7,988 for an intentional one or one involving a minor's data — and that's before accounting for the kind of eight-figure settlements GM and others have faced.

Privacy Is a Data-Operations Requirement

The mistake we see most often is treating privacy compliance as a document to publish once and forget. It isn't. It's an ongoing data-operations discipline that touches your website, your CRM, your marketing platforms, and every vendor in between — and the growing number of state laws means that discipline only gets more complex from here, not less.

Legal counsel defines what you're obligated to do. Making that obligation actually operational — connecting your website, CRM, and marketing systems so a request or a deletion actually reaches everywhere your customer's data lives — is the technical and process work we help clients build at BaseMonkeys. If you can't currently answer "where does this customer's data live across our stack" in a day, that's the place to start.

Sources: MultiState (2026 State Privacy Law Tracker), California Attorney General's Office (General Motors settlement, May 2026; Sephora settlement, 2022), California Privacy Protection Agency (2025 penalty adjustment announcement), CaliberMind/BenchmarkIt 2025 State of B2B Marketing Attribution Report (martech stack sprawl data).