Skip to content
PeekWellThe Rulebook
Join now

State privacy laws: opt-out and policy gaps

At a glance

US-11MediumVa. Code §§59.1-577, 59.1-578; Tex. Bus. & Com. Code §§541.051, 541.102; Conn. Gen. Stat. §42-516, §42-520(b)(1), (c)(1)(A); 4 CCR 904-3, Rules 5.02 and 6.03

Peeky checks whether visitors from states with their own privacy laws can opt out of targeted advertising and whether the policy explains how.

Last checked against the source:

I need to fix thisI need the rule

The rule

California is not the only state with a privacy statute. Several states have passed comprehensive laws on a shared pattern: a business that decides why and how personal data is processed, called a controller, owes consumers a privacy notice and a way to opt out of targeted advertising and the sale of their data. California is covered in US-04 and US-05. This article reads four others: Virginia, Colorado, Connecticut and Texas.

Virginia gives a consumer the right “to opt out of the processing of the personal data for purposes of (i) targeted advertising, (ii) the sale of personal data, or (iii) profiling in furtherance of decisions that produce legal or similarly significant effects.” Section 59.1-578(C) requires a privacy notice listing the categories of personal data processed, the purpose, how to exercise rights and appeal, and the categories shared with third parties and of those third parties. Section 59.1-578(D) adds: “If a controller sells personal data to third parties or processes personal data for targeted advertising, the controller shall clearly and conspicuously disclose such processing, as well as the manner in which a consumer may exercise the right to opt out.”

Connecticut’s text follows the same pattern. Connecticut applies from 1 July 2026 to businesses that process the personal data of 35,000 or more consumers, process sensitive data, or offer personal data for sale (§42-516 as amended by P.A. 25-113). Under §42-520(b)(1) the notice must be “reasonably accessible, clear and meaningful,” with “a clear and conspicuous disclosure” of any processing for targeted advertising or any sale for targeted advertising. Section 42-520(c)(1)(A) also asks for a clear and conspicuous hyperlink to a page where a consumer can opt out of targeted advertising or sale and for the ability to opt out through “an opt-out preference signal sent, with such consumer’s consent, by a platform, technology or mechanism.”

Colorado puts the signal in its rules. Rule 5.02(A) says consumers “may exercise their right to opt out of the Processing of Personal Data concerning the Consumer for purposes of Targeted Advertising or the Sale of Personal Data through a user-selected Universal Opt-Out Mechanism” that meets the technical specifications in Rule 5. Rule 6.03 says the privacy notice must state whether data “will be sold or used for Targeted Advertising,” and “Effective July 1, 2024,” must include “an explanation of how requests to opt out using Universal Opt-Out Mechanisms will be processed.”

Texas applies only to a person that is “not a small business as defined by the United States Small Business Administration,” with one exception: such a business “may not engage in the sale of personal data that is sensitive data without receiving prior consent from the consumer” (§541.107). A consumer may use “an Internet browser setting or extension, or a global setting on an electronic device” to appoint an agent to opt out of targeted advertising or sale, from 1 January 2025 (§541.055(e)). A controller that sells sensitive data must post, with the privacy notice, the words “NOTICE: We may sell your sensitive personal data” (§541.102(b)).

Virginia defines a sale as an exchange of personal data “for monetary consideration,” while Connecticut and Texas add “other valuable consideration,” which is the wording California uses. Thresholds differ: Virginia applies at 100,000 consumers, or 25,000 together with more than half of gross revenue from selling data (§59.1-576). The Connecticut text read here is the General Assembly’s 2026 supplement, with amended text effective 1 July 2026, and the Attorney General has announced further Connecticut privacy laws that take effect on 1 October 2026, so check the current text before relying on a threshold.

Enforcement is by the Attorney General in Virginia, Texas and Connecticut, with a cure period of 30 days in Virginia and Texas before an action can be brought. Both allow civil penalties of up to $7,500 “for each violation” (Va. Code §59.1-584; Tex. Bus. & Com. Code §541.155). In Connecticut the statute treats a failure to follow the Act as an unfair trade practice enforced solely by the Attorney General (§42-525).

What PeekWell checks and how

US-11 asks whether a visitor from a state with its own privacy law can opt out of targeted advertising and whether the policy describes how. Unlike the California checks, it is not limited to sites that name California, and the ruleset is keyed to the states a site is likely to serve. Detection is deterministic: code observes a mechanism or it does not.

The scan opens public pages in a fresh browser. It looks for an opt-out of targeted advertising, such as a link to a page where a visitor can switch it off. It reads the policy for what the state laws ask for: statements on sensitive data, targeted advertising and sale, and an explanation of the opt-out. And it looks at whether a browser opt-out signal is supported. The signal test works the way US-03 describes: a pass with the signal switched on is compared with one switched off, and advertising trackers that are unchanged between the two are what the report records.

The limits are the usual ones for a visit from outside: public pages only, no sign-in, no forms, and no view of data sent from your servers. It does not know a visitor’s state, check your threshold, or tell whether an opt-out request is honoured after the page closes. A Passed means the expected mechanisms were observed on the pages scanned. It does not say the business complies with any state’s law.

Why it matters for a company

The enforcement record under these statutes is shorter than California’s, and the cases that exist differ in kind. In the Texas matter filed on 13 January 2025, the Attorney General sued Allstate and its subsidiary Arity under the Texas Data Privacy and Security Act. The allegation was that they collected and sold location and movement data from phones through software embedded in third-party apps, without the notice and consent the Act requires for sensitive data such as precise geolocation. The Attorney General called it the first enforcement action filed by a state attorney general to enforce a comprehensive data privacy law. The page read reports no outcome.

Connecticut’s TicketNetwork settlement of 8 July 2025 is closer to what a site scan sees. The Attorney General sent a cure notice on 9 November 2023 saying the privacy notice was “largely unreadable, missing key data rights, and contained rights mechanisms that were misconfigured or inoperable.” The company had 60 days, until 8 January 2024, to fix each problem, and the Attorney General says it did not resolve them well beyond that period. It agreed to pay $85,000 and to report metrics on consumer requests. The release does not state the company’s size.

The Connecticut Attorney General’s February 2026 report By the end of 2025 the Connecticut Attorney General’s report counts dozens of notices of violation and warning letters, including over hidden consumer rights. Connecticut’s mandatory cure period expired on 1 January 2025, so a notice there may now lead to an action sooner.

For a company the lessons are practical. Cure periods, where they exist, are short: 30 days in Virginia and Texas, and 60 days in the notice Connecticut sent TicketNetwork. A warning letter has a deadline. A notice that is hard to read, or a rights link that does not work, is the kind of problem a visitor or a regulator can see without any inside information. And the statutes name opt-out signals and browser settings, so a mechanism that works only when someone finds a link may fall short in states that list the signal.

Smaller companies and larger companies

Size works differently in each state. Texas excludes small businesses as the SBA defines them, but not for selling sensitive data. Virginia sets its threshold on the number of consumers whose data is processed. Connecticut’s test counts consumers too, and since 1 July 2026 it also reaches any business that sells personal data or processes sensitive data. Colorado’s thresholds are set in C.R.S. §6-1-1304, which this article did not read at a primary source, so check them directly.

In a smaller company the site usually reaches several states without anyone choosing that. An online shop ships nationwide, and its policy was set up with one state’s law in mind or none. The opt-out link may be missing, or go to a page that does nothing. TicketNetwork shows that a notice can exist and still be unreadable or point to rights that do not function.

In a larger company the problem is spread. Different brands and apps run different policies, a legal team tracks a few states, and a signal that one team’s page honours is ignored by another’s. Large companies also hold sensitive data such as location, as in the Texas matter.

Enforcement cases

Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

The Officer, squinting at a file.

Larger companies

  • Allstate and Arity

    Texas Attorney General (United States), 2025Lawsuit filed, no outcome stated

    The Texas Attorney General sued Allstate and its subsidiary Arity, alleging that they collected, used and sold data about the location and movement of Texans' phones through software embedded in mobile apps. The Attorney General's release says the law requires clear notice and informed consent for sensitive data and says Allstate never gave notice or obtained consent. The Attorney General called it the first enforcement action filed by a state attorney general to enforce a comprehensive data privacy law.

    Read the Texas Attorney General (United States) publication about Allstate and Arity

Smaller companies

No enforcement action under a state comprehensive privacy law against a smaller company with a stated size could be confirmed at an authority's own page. The Connecticut TicketNetwork settlement is described below, but the Attorney General's release does not say how large the company is, so it is not listed as a smaller-company case.

How to fix it

Start by working out which states you serve, then make one opt-out experience that meets the strictest common ground.

  1. Decide where you have visitors. Check your analytics and shipping addresses for the states you reach. Then check each state’s threshold in its statute.
  2. Offer an opt-out of targeted advertising and sale. Add a clear link, in the footer or header, to a page where a visitor can switch both off, and make the switch stop the tags it names. If you also serve California, the same link can carry the “Do Not Sell or Share” title that US-02 covers.
  3. Honour the browser signal. Make your consent or tag setup read the opt-out signal and stop advertising tags for that visitor. US-03 describes how a scan tests this.
  4. Update the policy. State what you process, whether you sell or use targeted advertising, which categories go to third parties, how to opt out and appeal, and how signal requests are handled. Include the Texas sentence about selling sensitive data if you do that.
  5. Check sensitive data. If you collect precise location, health or similar data, ask your legal adviser which of the states you serve require consent before you collect or sell it.
  6. Test the notice as a visitor would. Read the policy on a phone and click each rights link. Unreadable notices and broken links are what Connecticut’s Attorney General pointed to.
  7. Re-scan. Run a scan after the changes. The finding should clear once the opt-out exists, the policy explains it and the signal changes what the page does.

Questions

Do states other than California require an opt-out of targeted advertising?

Yes. Virginia, Colorado, Connecticut and Texas each give consumers the right to opt out of targeted advertising and of the sale of personal data, and each expects the privacy notice to say how. Which law applies depends on where the visitor lives and whether the business meets that state's threshold.

Does the Texas Data Privacy and Security Act apply to small businesses?

Mostly no. The Act covers only businesses that are not small businesses as defined by the U.S. Small Business Administration. One exception is selling sensitive data: such a business needs the consumer's consent first.

Does the Colorado Privacy Act require honouring a universal opt-out signal?

Yes, for businesses the Act covers. The Colorado rules let consumers opt out of targeted advertising and sale through a user-selected universal opt-out mechanism that meets the technical specifications in the rules. From 1 July 2024 the privacy notice has to explain how those requests are processed.

Does Virginia define selling differently from California?

Yes, it is narrower. The Virginia Act defines a sale as the exchange of personal data for monetary consideration, while California, Connecticut and Texas also count other valuable consideration. Virginia still gives consumers a right to opt out of targeted advertising, a separate category defined by purpose.

How does Peeky check state privacy laws?

Peeky looks for a way to opt out of targeted advertising, checks what the privacy policy says about it, and sees whether a browser opt-out signal changes what the page does. It never signs in and never fills a form. How a scan works has the full path.

Filed with

The rule

Virginia Consumer Data Protection Act, Va. Code §§59.1-575 to 59.1-584

Read the rule (Virginia Consumer Data Protection Act, Va. Code §§59.1-575 to 59.1-584)

A case

Allstate and Arity

Texas Attorney General (United States), 2025

Read the decision (Allstate and Arity)

Your site

Is your website affected? Join now to find out.

Join now

Sources

  1. Virginia Code §§59.1-575, 59.1-576, 59.1-577, 59.1-578 and 59.1-584 (Virginia Law, current text)
  2. Texas H.B. 4, 88th Legislature, enrolled text (Business & Commerce Code ch. 541), effective 1 July 2024, §541.055(e) effective 1 January 2025; the codified chapter 541 at statutes.capitol.texas.gov could not be read, so later amendments are not ruled out
  3. Connecticut General Statutes ch. 743jj, 2026 supplement, with text amended by P.A. 25-113 effective 1 July 2026
  4. Colorado Privacy Act Rules, 4 CCR 904-3, Rule 5.02 (Rights exercised) (Cornell Legal Information Institute mirror of the Code of Colorado Regulations; the Colorado Department of Law or Secretary of State copy could not be read)
  5. Colorado Privacy Act Rules, 4 CCR 904-3, Rule 6.03 (Privacy notice content) (Cornell mirror, not the Colorado copy)
  6. Texas Attorney General, Allstate and Arity lawsuit, 13 January 2025
  7. Connecticut Attorney General, Settlement with TicketNetwork, 8 July 2025
  8. Connecticut Attorney General, Updated report on the Connecticut Data Privacy Act, 5 February 2026
  9. Connecticut Attorney General, Rights and requirements related to new and updated privacy laws, 16 September 2026

Last checked against the source:

For information only. Not legal advice.