Tracked Regulations
69+
across 50 states + DC
Regulation Guide
How to navigate the patchwork of US state regulations across privacy, AI, employment, and food safety. Practical compliance strategies for businesses operating in multiple states.
This guide is for informational purposes only and does not constitute legal advice. Consult a qualified attorney for compliance guidance specific to your business.
Any business that sells products, employs workers, or processes personal data across state lines faces a growing compliance challenge. The United States has no comprehensive federal framework for data privacy, AI regulation, or food additive safety. States are filling the vacuum, and they are not coordinating with each other.
The result is a patchwork of requirements that can vary dramatically from state to state. A company with employees in California, New York, and Texas must navigate three different sets of employment laws. A food manufacturer selling nationally must track chemical bans that apply in some states but not others. A tech company using AI in hiring must comply with New York City's Local Law 144 requirements while monitoring Colorado's AI Act and emerging legislation in dozens of other states.
The simplest approach is to identify the strictest state standard for each regulatory category and comply with it universally. For data privacy, this typically means complying with California's CCPA/CPRA. For employment, it means meeting the highest minimum wage, broadest paid leave requirements, and strictest pay transparency rules.
Advantages: Simplicity, consistency, reduced risk of inadvertent non-compliance, simplified employee training, and future-proofing against new state laws that are likely to follow existing models.
Disadvantages: Potentially higher costs than necessary in less regulated states, possible over-investment in compliance infrastructure for markets that do not require it, and the challenge of determining which state is actually "strictest" when laws address different aspects of the same issue.
Larger organizations sometimes maintain separate compliance programs for each state, applying only the requirements that are legally mandated in each jurisdiction. This requires detailed tracking of which regulations apply where, which products are affected, and which employees or customers fall under which state's jurisdiction.
Advantages: Minimizes compliance costs in less regulated states, allows for market-specific approaches, and avoids applying restrictions that competitors in those states do not face.
Disadvantages: Higher administrative complexity, greater risk of non-compliance due to tracking errors, requires specialized legal expertise in each state, and ongoing monitoring as laws change.
Many businesses adopt a hybrid approach, applying the highest common denominator for some categories while maintaining state-specific programs for others. For example, a company might implement universal CCPA-level privacy protections (because privacy law affects all operations) while maintaining state-specific employment compliance (because employment costs vary significantly by jurisdiction).
Regardless of which strategy you choose, an effective multi-state compliance program should include:
With 20+ states now having privacy laws, universal CCPA compliance is increasingly the practical choice. Key areas: consent management, data subject request handling, privacy policy updates, and vendor management. See our State Privacy Laws Guide.
The AI regulatory landscape is still emerging but moving quickly. Colorado's AI Act is the most comprehensive model. Key areas: algorithmic impact assessments, transparency disclosures, and fairness testing for automated decision tools. See our AI Regulation Guide.
Employment compliance is inherently state-specific because it depends on where employees are physically located. Remote work has complicated this, an employee working from home in Colorado is subject to Colorado employment law regardless of where the employer is headquartered. See our Employment Law Guide.
Most businesses operating nationally adopt one of two strategies: comply with the strictest state standard universally (simpler but potentially more costly), or maintain separate compliance programs for each state (more complex but potentially less restrictive). Many companies find that universal compliance with the strictest standard is more cost-effective than managing state-by-state variations.
California consistently has the most comprehensive regulatory framework across multiple categories, data privacy (CCPA/CPRA), employment protections, food chemical bans, and AI transparency requirements. Colorado and Illinois are close runners-up, particularly in AI regulation and employment law. The strictest state varies by specific regulatory category.
It depends on the regulation. Many state data privacy laws include thresholds that exempt small businesses (e.g., processing data of fewer than 100,000 consumers). However, employment laws (minimum wage, paid leave, pay transparency) typically apply to all employers regardless of size. Food chemical bans apply to all food products sold in the state. Small businesses should review specific thresholds for each applicable regulation.
Federal preemption has been proposed for data privacy (the American Privacy Rights Act) and AI regulation, but as of 2026, no comprehensive federal legislation has been enacted in either area. Even if federal laws pass, they may set minimum standards while allowing states to maintain stricter requirements. The trend toward state-level regulation is accelerating, not slowing.
| Category | States with Laws | Avg Penalty (Max) | Compliance Deadline | Key Requirement |
|---|---|---|---|---|
| Data Privacy | 19 states | $7,500/violation | Enactment + 6-12mo | Opt-out consent, data deletion |
| AI Governance | 8 states | $20,000/violation | Enactment + 12mo | Fairness audits, transparency reports |
| Food Chemical Bans | 5 states | $5,000/violation | Enactment + 18-24mo | Reformulation or labeling |
| Right to Repair | 4 states | $1,000/day | Enactment + 12mo | Parts + manuals availability |
A SaaS company with users in California, Virginia, Colorado, and Connecticut must comply with four distinct privacy frameworks. California (CCPA/CPRA) requires opt-out sale buttons and 12 specific consumer rights. Virginia (VCDPA) mandates data protection assessments for targeted advertising. Colorado (CPA) adds a universal opt-out mechanism requirement. Connecticut (CTDPA) follows a similar model but with a shorter 45-day response window versus the standard 45 days. The compliance matrix shows 14 overlapping requirements across these four states, but 7 requirements are unique to individual states. Our tracker normalizes these into a side-by-side comparison so compliance teams can build to the highest common denominator.
Privacy regulation penalties scale with company revenue and violation volume. Under CCPA, the California AG can seek $2,500 per unintentional violation and $7,500 per intentional violation. For a mid-size company (50,000 consumer records), a single data breach without adequate safeguards could result in $100M+ in statutory damages. Our database tracks the maximum statutory penalty per state and per category, enabling businesses to prioritize compliance investments by risk exposure. Colorado and Connecticut additionally grant private right of action, extending the litigation risk beyond regulatory fines.
Companies operating nationally face a patchwork of effective dates. California's CCPA took effect January 2020, with CPRA amendments in January 2023. Virginia's VCDPA followed in January 2023, Colorado's CPA in July 2023. The food chemical ban timeline accelerates differently: California's SKMEA bans Red 3 and other additives starting January 2027, while Illinois follows in January 2028. Our tracker provides effective dates for all 69+ tracked regulations, allowing compliance teams to build a unified calendar that sequences work by urgency rather than by regulation category.
Most state privacy laws include revenue or data-volume thresholds that exempt small businesses. CCPA applies to businesses with >$25M annual revenue, or those buying/selling data of 100,000+ consumers, or deriving 50%+ of revenue from data sales. VCDPA applies to entities controlling 100,000+ consumer records or deriving 50%+ from targeted ad sales. However, no such exemptions exist for food chemical bans or right-to-repair laws, which apply equally regardless of business size. Our regulation detail pages clearly flag whether each law includes small business exemptions and at what thresholds.
Tracked Regulations
69+
across 50 states + DC
Regulatory Categories
5
privacy, AI, food, repair, employment
States with Privacy Laws
19
enacted or effective
8 states with enacted AI regulations
5 states banning specific additives
Every figure on PlainRegWatch is rendered directly from state source data, no number is typed in by an editor. This page draws directly on federal and state source data, no figure is typed in by an editor. See our editorial standards & corrections policy, the methodology behind these numbers, or report a data error.