Definition
Beyond the California Consumer Privacy Act (CCPA) and its amendment, the California Privacy Rights Act (CPRA), a growing patchwork of US state privacy laws imposes email-specific compliance requirements. These include the Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), Utah Consumer Privacy Act (UCPA), and newer laws in Iowa, Texas, and Oregon. While these laws share common consumer rights — access, deletion, correction, data portability, and the right to opt out of targeted advertising and data sales — each contains state-specific nuances that affect how email marketers collect, process, and store subscriber data. The lack of a comprehensive federal privacy law in the United States means organisations sending emails nationally must comply with the most restrictive applicable state law.
For email marketing specifically, these laws primarily affect how subscriber data is collected at sign-up, how email engagement data is processed for personalisation and profiling, and how these data are shared with third-party platforms. The definition of sale or sharing of data varies notably between states: California broadly defines sale to include sharing for cross-context behavioural advertising, while Utah and Iowa provide narrower definitions. Targeted advertising restrictions in Colorado and Connecticut directly impact email segmentation based on inferred subscriber characteristics. Additionally, sensitive data classifications in Virginia and Colorado affect how demographic and behavioural data used for email personalisation must be handled, requiring explicit opt-in consent rather than opt-out.
Best Practices
Map all subscriber data flows across your email programme, identifying what data is collected, where it is stored, which third-party processors have access, and how each data element is used for personalisation or profiling. This data mapping exercise is the foundation for determining which state privacy laws apply and what obligations are triggered for each data processing activity in your email programme.
Implement a privacy preference centre that allows subscribers to exercise their rights under applicable state laws from a single interface, including the right to access collected data, request deletion, correct inaccuracies, opt out of data sales or targeted advertising, and manage consent for specific processing activities. The preference centre should detect the subscriber's state of residence and surface the appropriate rights under that state's law.
Apply geo-detection at the point of data collection to determine which state privacy law governs each subscriber relationship, and maintain a dynamic compliance matrix that tracks evolving state requirements. Consider complying with the most restrictive applicable law (such as the CPRA or CPA) as a baseline across all US subscribers to simplify operational complexity, a common approach for organisations with multistate audiences.
Update email privacy notices to include state-specific disclosures required by each applicable law, including categories of personal data collected, purposes of processing, categories of third parties with whom data is shared, and the specific rights available to residents of each state. Privacy notices must be conspicuously accessible at or before the point of data collection and updated at least annually.
Audit third-party data-sharing arrangements with email service providers, analytics platforms, personalisation engines, and advertising networks to determine whether these relationships constitute data sales or targeted advertising under each applicable state law. Execute data processing agreements (DPAs) with all third-party processors and implement contractual restrictions on secondary use of subscriber data.
Frequently Asked Questions
The primary laws are California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Iowa (ICDPA), Texas (TDPSA), and Oregon (OCPA). Additional states including Montana, Tennessee, Delaware, and New Jersey have passed laws with staggered effective dates through 2026, creating a continuously expanding compliance landscape.
Common rights include: right to know what personal data is collected and how it is used; right to access collected data; right to request deletion of personal data; right to correct inaccurate data; right to data portability in a commonly used format; right to opt out of data sales and targeted advertising; and right to non-discrimination for exercising privacy rights.
Email-specific requirements include: providing clear notice of data collection at sign-up point; obtaining consent for use of sensitive data in email personalisation (Virginia and Colorado); enabling opt-out mechanisms for profiling-based email segmentation; maintaining records of processing activities for email data; and ensuring service agreements with email platforms include privacy law-mandated contractual provisions.
California defines sale broadly to include sharing for cross-context behavioural advertising. Colorado considers data sharing for targeted advertising as a sale. Utah and Iowa provide narrower definitions that exclude certain common data-sharing practices. These definitional differences mean the same email data-sharing activity may trigger opt-out requirements in California and Colorado but not in Utah or Iowa.
Most organisations adopt a compliance approach based on the most restrictive applicable law as a baseline for all US subscribers, operationalised through a centralised preference centre, universal data mapping, standardised contractual protections with processors, and documented compliance policies that can be adapted as new state laws take effect. Legal counsel should review state-specific nuances annually as new laws are enacted and existing laws are amended.