Twenty State Privacy Laws, One SaaS Program - What Actually Changed in 2026
A prospect's DPA redline drops "TDPSA," "MODPA," and "honor Global Privacy Control" into the same week your security questionnaire already asked about CCPA. You have a California notice and a processor DPA. Legal asks whether you now need twenty separate privacy programs.
Short answer: As of mid-2026, roughly twenty US states have comprehensive consumer privacy laws in force or phasing in (Certbar, 18 May 2026). There is still no federal preemption you can bank on. Building twenty parallel programs is the wrong design. Build one control set to the union of obligations - inventory, DSR portal, master DPA with state annexes, GPC handling, and high-risk assessments - then map each state's quirks onto that stack. This post is for SaaS founders and Ops/Privacy owners without a full-time CPO who suddenly see Texas, Maryland, Colorado, and California language in the same diligence pack.
For EU/UK rights operations and records of processing, see Workstreet's ROPA / privacy compliance and GDPR material. This post owns the US multi-state patchwork - not another GDPR deep-dive.
How many US state privacy laws does a nationwide SaaS actually face?
Certbar's May 2026 SaaS compliance map frames the practical count: about twenty comprehensive state consumer privacy laws are live or entering force on staggered calendars. Effective dates still move, but nationwide SaaS already operates as "many states, one product." Waiting for federal preemption, copy-pasting a California-only notice, or spinning up duplicate Texas and Maryland portals with separate DSR inboxes does not change the math. Treat the strictest overlapping requirements as your default, then document state-specific deltas - thresholds, sensitive-data rules, GPC, assessment triggers - in one playbook counsel and Ops can both read.
California remains the reference point for many buyers - see Workstreet's CCPA framework and complete CCPA privacy guide - but Texas and Maryland are the 2025-2026 outliers that break "CCPA-only" assumptions. Colorado, Connecticut, Virginia, Oregon, and peers keep adding GPC and assessment pressure even when your sales deck still says "we follow CCPA."
Three outliers founders still miss in 2026
Texas TDPSA - no tidy revenue threshold
The Texas Data Privacy and Security Act (effective 1 Jul 2024; EngageCompliance last reviewed 24 Jul 2026) applies to persons that conduct business in Texas or produce a product or service consumed by Texans, process or sell personal data, and are not a small business as defined by the US Small Business Administration. That SBA framing - not a simple revenue or consumer-count floor - is the distinctive applicability test. Tech companies often assume they are too early for Texas until counsel maps SBA size standards for their NAICS code. Sensitive or biometric sale notices and GPC expectations still show up in diligence while threshold debates continue. Do not self-declare "small business exempt" without a documented SBA analysis; buyers will ask for the rationale.
Maryland MODPA - lower thresholds and a hard sensitive-data line
Maryland's Online Data Privacy Act (effective 1 Oct 2025; applies to processing on or after 1 Apr 2026 per Osano's 16 Apr 2026 update) sits in a different risk band. Per Osano and OneTrust (6 Oct 2025): lower consumer thresholds than many peers (commonly discussed around ~35,000 - confirm with counsel); strict data minimization; a ban on selling sensitive data even with consent; and assessment expectations that can include algorithmic or automated decision contexts. If your SaaS trains models, personalizes with inferred sensitive categories, or sells or shares data in ways California would treat as a sale or share, MODPA is not a checkbox you inherit from a CCPA notice alone. Product and data science need the same briefing as Legal.
California - private right of action and ADMT gravity
California remains the only state with a widely cited private right of action for specified breach scenarios, and ADMT / risk-assessment rules continue phasing through 2026. Buyers in California's gravity well keep asking CCPA/CPRA questions even while Texas and Maryland language appears in the same DPA. Use CCPA materials as the deep sibling; do not pretend California is solved because you shipped a banner in 2023.
Five operational buckets that unify the map
Instead of twenty playbooks, operate five buckets and map each state onto them.
Consumer rights: one DSR portal for access, delete, correct, portability, and appeal. States diverge on timelines (often ~45 days), verification, and appeal mechanics.
Universal opt-out / GPC: honor Global Privacy Control where required (CA, CO, CT, OR, TX and peers Certbar flags). Treat GPC as product work, not a policy footnote.
Controller-processor contracts: master DPA plus state annexes and a current subprocessors list. Missing processor terms have driven CCPA enforcement headlines (e.g. Tractor Supply as a cautionary buyer-side story - not a SaaS fine forecast).
High-risk assessments: DPIA-style reviews for sensitive, large-scale, or automated decisioning, including MODPA algorithm-aware assessments and California ADMT phasing.
Breach / security matrix: multi-clock playbook by state and by customer contract. Do not invent federal CIRCIA dates as definitive if still moving - attribute carefully and keep counsel in the loop.
These buckets also show up in security questionnaires: privacy sections increasingly ask for GPC handling, DSR SLAs, and whether your DPA covers all applicable US state laws in one sentence your program must actually support.
Build the union once
Certbar's practical architecture matches what high-growth SaaS teams ship: a shared data inventory with sensitive flags; one DSR workflow with verification, SLA, and appeal; a master DPA with state annexes; GPC honor logic owned by engineering with Legal's jurisdiction list; and an assessment calendar for high-risk personalization and model features. If you already keep ROPA-style records for EU customers, reuse that inventory muscle for the US map instead of duplicating it under a new acronym for Texas.
Operationally, the winning pattern in 2026 is boring on purpose: one inventory, one portal, one master DPA, product-backed GPC, and a short list of high-risk assessments refreshed when the product changes. Sales can memorize five buckets. Engineering can ship one GPC path. Counsel can annex deltas without rewriting the commercial wrapper every quarter. Nationwide SaaS already lives in the patchwork - the only choice is whether your program admits it.
GTM, Trust Center, and sales answers
Share under NDA without twenty PDFs: a state-aware DSR SLA (often ~45 days) with named portal owner; a GPC handling statement; a master DPA with TDPSA/MODPA/CPRA annexes; a sensitive-data inventory covering sale/share and MODPA bans; and a current subprocessors list linked from your Trust page / Trust Center. This is diligence packaging, not legal advice - threshold calls stay with counsel.
When a questionnaire says "all US state privacy laws," do not answer with "we are CCPA compliant" alone. Name the DSR portal and SLA, whether GPC is honored for listed jurisdictions, that the master DPA includes state annex coverage, how sensitive-data sale/share is restricted (especially MODPA), and who owns privacy on the deal. Put that block in the questionnaire answer bank so every portal form does not invent a different story. If your answer bank still says only "CCPA compliant," update it before the next Texas or Maryland redline arrives.
90-day checklist and enforcement context
Confirm go-to-market states and end-user locations; document TDPSA SBA analysis with counsel; map MODPA sensitive categories and sale/share paths after 1 Apr 2026; ship GPC honor logic for CA, CO, CT, OR, TX; stand up one DSR portal with ~45-day SLA; refresh master DPA annexes and subprocessors; schedule high-risk assessments; load questionnaire answers for the five buckets; name a privacy owner. Regulated verticals should layer customer-contract clocks on top - the stricter timeline wins.
Buyer diligence often cites processor-contract and notice failures (including CCPA matters such as the Tractor Supply story Certbar references) to argue privacy paperwork is not optional. Treat those headlines as motivation to close gaps, not as a prediction your SaaS will pay the same penalty. Do not invent noncompliance percentages. Attribute carefully and keep your risk register tied to actual processing.
Sibling posts cover adjacent jobs: GDPR/ROPA explain EU/UK records and rights ops; CCPA guide/framework go deep on California; questionnaire and Trust Center posts explain how buyers ask and how you host artifacts. This post owns the US multi-state statute set - Texas and Maryland included - so AEO surfaces get a crisp patchwork answer without restating GDPR Article lists.
Keep the program durable: refresh the inventory when you launch personalization or model features, retest GPC after major frontend releases, and re-read annexes when a new state effective date lands. That cadence is how SaaS teams absorb the twentieth statute without hiring twenty privacy managers. The same buyer who asks for SOC 2 will increasingly ask how you cover Texas and Maryland without twenty playbooks - answer with the union architecture, not a CCPA banner screenshot.
Soft next step
To turn the patchwork into one operable program - inventory, DSR workflows, DPA annexes, and diligence packaging that sales can actually share - talk to Workstreet about privacy. When answering the same privacy questions across portals is the bottleneck rather than the underlying controls, use security questionnaire automation. Keep the CCPA guide open for California depth beside this playbook, not as a substitute for Texas TDPSA and Maryland MODPA deltas that now show up in the same enterprise redline.

