Regulatory radar / Data, Technology & Intangibles

US Privacy and Cyber in 2026: Build a Trigger Map, Not One Checklist

A business-owner map of selected U.S. federal and state privacy and cyber triggers, including California’s 2026 rules and DROP duties.

Status note — checked 12 August 2026. The examples below are current, specific authorities—not a claim that one U.S. national privacy or cyber rule covers every business. The correct map depends on people, states, data, sector, activity, thresholds and incident facts.

For an owner, “Are we compliant with U.S. privacy law?” is too broad to answer usefully. A better question is: which fact switches which duty on, for which legal entity and system?

Fact: different triggers produce different duties and dates

California’s completed 2025 rulemaking

The California Privacy Protection Agency’s final rulemaking page says regulations on CCPA updates, risk assessments, cybersecurity audits, automated decisionmaking technology (ADMT) and insurance were approved and took effect on 1 January 2026. These provisions apply to businesses and processing that meet their defined scope; they do not make every small U.S. company a CCPA business.

The Agency’s deadline summary states:

  • businesses subject to the risk-assessment requirements began compliance on 1 January 2026 and must submit an attestation and summary information by 1 April 2028 for the initial period;
  • businesses required to complete cybersecurity audits have first certifications due 1 April 2028, 2029 or 2030, phased by gross-revenue bands; and
  • covered uses of ADMT for significant decisions must meet the ADMT requirements from 1 January 2027.

The threshold and risk definitions in the approved text matter. A deadline table is not a substitute for deciding whether the business and processing are covered.

California DROP is a data-broker-specific 2026 operation

California’s DROP guidance for data brokers says the platform launched in January 2026 and that data brokers must begin processing requests on 1 August 2026. The processing instructions require a broker to access DROP at least every 45 calendar days, download the relevant lists, match them against its records, process requests and report status.

This duty turns on California’s data-broker definition and exemptions. A company is not a data broker merely because it uses analytics, and it does not escape the question merely because it calls a transfer a “partnership.”

Texas illustrates why the small-business answer changes by state

The Texas Attorney General’s Texas Data Privacy and Security Act overview says the Act took effect on 1 July 2024. It generally exempts a business qualifying as small under the federal Small Business Administration definition, but a small business must obtain consumer consent before selling sensitive data. The same page describes controller duties, including notices, consumer requests, security practices, processor contracts and assessments for specified high-risk processing.

California and Texas use different coverage tests and exceptions. “We are under the California revenue threshold” therefore is not a national small-business answer.

Federal and breach duties add another layer

The Federal Trade Commission’s Safeguards Rule guidance says a covered financial institution must notify the FTC as soon as possible and no later than 30 days after discovering a notification event involving unauthorised acquisition of at least 500 consumers’ unencrypted customer information, as defined by the Rule. That notification amendment has applied since 13 May 2024.

The FTC’s breach-response guide notes that all states, the District of Columbia, Puerto Rico and the Virgin Islands have breach-notification legislation, with other federal or sector rules potentially applying by data type. This is why an incident plan needs a jurisdiction-and-data analysis rather than one generic notice date.

Signal: the privacy inventory records vendors but not triggers

PARAVEILUX judgment. A vendor list is not a trigger map. The hidden risk sits in facts that change coverage: resident location, consumer relationship, sensitive-data category, data sale, targeted advertising, profiling, significant decisions, financial-service activity, data-broker status and incident scale.

Investigate when:

  • the company cannot say which legal entity controls each data set or where the people represented in it reside;
  • a “no sale” statement ignores transfers for valuable consideration, advertising arrangements or onward use;
  • an AI or scoring tool affects employment, lending, housing, insurance, education, healthcare or another significant decision without a state-by-state screen;
  • a data supplier promises that records are “compliant” but cannot support consumer rights, deletion propagation or provenance;
  • incident procedures contain one 72-hour or 30-day deadline for every event; or
  • small-business status is assumed once and never retested after growth, acquisition or a new data activity.

Counter-signals

  • A current processing register ties data categories, people, purpose, state, sector, controller/processor role and recipients to a named owner.
  • Each high-risk activity has a recorded coverage analysis and a contrary case explaining why a rule may not apply.
  • Contracts support rights requests, incident facts, deletion/return, assessments and onward-provider controls.
  • Incident counsel and technical responders can assemble affected people, states, data types, encryption status and acquisition evidence promptly.

Action: make a fact-to-duty matrix

Implementation checkpoints

  1. Map people and places. Record customers, prospects, employees, applicants, children and other groups by relevant U.S. state—not just company headquarters.
  2. Classify data and activity. Identify sensitive data, sale/sharing, targeted advertising, profiling, significant decisions, data brokerage and regulated financial or health activity.
  3. Test entity thresholds and exemptions. Keep the evidence and review after revenue, headcount, business model or ownership changes.
  4. Calendar the live California dates. For covered businesses, preserve 2026 risk-assessment evidence, prepare applicable audit work, scope ADMT before 2027 and operate DROP now if the data-broker definition applies.
  5. Build an incident overlay. The first facts should support state-residency counts, data categories, encryption/key status, evidence of access/acquisition, sector status and notification decision times.
  6. Flow duties through vendors. Require prompt incident evidence, consumer-request assistance, deletion propagation, subprocessor notice and return/destruction confirmation.

Limitations: selected examples are not a fifty-state survey

This page uses California, Texas and FTC authorities to show the trigger method. It does not catalogue every state comprehensive privacy statute, biometric law, consumer-health rule, children’s rule, sector regulator, cybersecurity requirement or breach-notification provision. It does not decide whether a particular business is a CCPA business, data broker, financial institution, controller or processor.

Rules and agency materials change, and federal pre-emption or sector interactions can be complex. This is general information, not legal, privacy, cybersecurity or incident-response advice. A live incident or material processing change requires qualified, fact-specific review.

Primary source

California Privacy Protection Agency — 2025 CCPA regulations. This source supports the identified facts; Paraveilux signals and recommendations remain interpretation.