Privacy compliance guides

Plain-English guides, state comparisons, and actionable checklists for e-commerce businesses navigating state privacy laws.

Guide12 min read

The complete guide to California's CCPA/CPRA for e-commerce businesses in 2026

Everything e-commerce businesses need to know about California's CCPA/CPRA in 2026, including new ADMT rules, cybersecurity audit requirements, the DELETE Act DROP platform, and practical compliance steps.

Read article →
Guide10 min read

Texas Data Privacy and Security Act (TDPSA): what e-commerce businesses need to know

Texas's TDPSA applies broadly to e-commerce businesses with no revenue threshold. Learn about the $1B+ enforcement action, universal opt-out requirements, and compliance steps.

Read article →
Guide9 min read

Virginia Consumer Data Protection Act (VCDPA): compliance guide for online retailers

The VCDPA served as the model for most other state privacy laws. Learn about thresholds, consumer rights, data protection assessments, and the permanent 30-day cure period.

Read article →
Comparison15 min read

State privacy law comparison chart: all 20 states side by side (2026)

Comprehensive side-by-side comparison of all 20 state privacy laws, covering thresholds, cure periods, consumer rights, penalties, enforcement, and key differences.

Read article →
FAQ8 min read

Do I need a privacy policy for my Shopify store? (Yes — here's exactly why)

Yes, you need a privacy policy for your Shopify store. Learn which state laws apply even if you're not based in those states, what the policy must contain, and how to create one.

Read article →
Guide10 min read

What happens if you violate state privacy laws? Fines, penalties, and enforcement by state

State-by-state breakdown of privacy law penalties, from $2,663 to $50,000 per violation. Real enforcement examples including Texas's $1B+ settlement and California's CPPA actions.

Read article →
News8 min read

Three new state privacy laws took effect January 1, 2026 — here's what changed

Indiana, Kentucky, and Rhode Island privacy laws all went live January 1, 2026. Key differences include Rhode Island's low thresholds and unique third-party disclosure requirements.

Read article →
Guide9 min read

Universal opt-out mechanisms: which states require them and how to implement one

10 states now require recognition of universal opt-out signals like GPC. Learn which states require them, how they work, and step-by-step implementation guide.

Read article →
Checklist10 min read

Data protection impact assessments: when you need one and how to do it

Most state privacy laws require data protection assessments for targeted advertising, data sales, and profiling. Practical framework for e-commerce businesses.

Read article →
Checklist12 min read

The 2026 e-commerce privacy compliance checklist: 15 steps to get compliant across all states

15 concrete steps to achieve privacy compliance across all 20 state privacy laws. From data audits to vendor agreements, the complete action plan for online sellers.

Read article →
Guide12 min read

Indiana INCDPA Compliance Guide for E-Commerce Businesses

Indiana's Consumer Data Protection Act (INCDPA) applies to most e-commerce businesses. This guide covers applicability thresholds, consumer rights, compliance requirements, penalties, and actionable steps to avoid violations.

Read article →
Guide6 min read

Iowa ICDPA Compliance Guide for E-Commerce Businesses

A practical guide to Iowa's consumer data protection law (ICDPA), including applicability thresholds, consumer rights, key compliance requirements, and actionable steps to avoid penalties.

Read article →
Guide12 min read

Florida FDBR Compliance Guide for E-Commerce Businesses

Florida's Florida Data Breach Notification Act (FDBR) sets strict requirements for how e-commerce businesses handle consumer data. This guide breaks down who it applies to, what rights consumers have, key compliance requirements, penalties, and practical steps to avoid violations.

Read article →
Guide7 min read

Delaware DPDPA Compliance Guide for E-commerce Businesses

Delaware's Data Privacy and Protection Act (DPDPA) takes effect January 1, 2025, with enforcement beginning in 2026. This comprehensive guide covers thresholds, consumer rights, key requirements, and practical compliance steps for e-commerce businesses.

Read article →
Guide7 min read

Connecticut CTDPA Compliance Guide for E-commerce Businesses

Connecticut's CTDPA took effect July 1, 2023 and is now actively enforced. This guide covers thresholds, consumer rights, and practical compliance steps for e-commerce businesses in 2026.

Read article →
Guide7 min read

Cookie Consent Requirements for Online Stores

What cookie consent requirements apply to your online store? Understand opt-in vs opt-out rules, implementation best practices, and state-specific obligations.

Read article →
Guide8 min read

How to Handle a Data Breach: State Notification Requirements

A practical guide to data breach notification requirements across all 50 states, including timelines, what triggers notification, and how to respond.

Read article →
Analysis7 min read

Children's Privacy and E-Commerce: COPPA and State Laws

Understanding children's data protection requirements for online retailers, from federal COPPA rules to emerging state laws targeting kids' privacy.

Read article →
Guide8 min read

Privacy Compliance for Shopify and WooCommerce Stores

Platform-specific privacy compliance guidance for the two most popular e-commerce platforms, covering built-in tools, gaps, and recommended plugins.

Read article →
Analysis8 min read

What Happens If You Don't Comply? State Privacy Law Penalties

A detailed look at the fines, enforcement actions, and real consequences businesses face for violating state privacy laws.

Read article →
Comparison7 min read

CCPA vs CPRA: What Changed and What It Means for Your Store

California's privacy law evolved from CCPA to CPRA with significant changes. Here's what's different and what online retailers need to update.

Read article →
Guide6 min read

State Privacy Laws: What E-Commerce Businesses Need to Know in 2026

A comprehensive overview of the 20+ state privacy laws now in effect and which ones matter most for online retailers selling across state lines.

Read article →
FAQ7 min read

Do I Need a Privacy Policy? Requirements by State

Find out when your online business needs a privacy policy, what must be in it, and the specific thresholds that trigger requirements in each state.

Read article →
Checklist7 min read

The E-Commerce Privacy Compliance Checklist

A step-by-step privacy compliance checklist for online stores covering data mapping, policies, consent, DSARs, vendor management, and security.

Read article →
Guide8 min read

Understanding Data Subject Access Requests (DSARs)

Learn what DSARs are, how to handle them efficiently, and the response timelines required by each state privacy law.

Read article →

Get updates like these daily

BriefStack monitors all 20 state privacy laws and delivers what matters to your inbox.

Start free — no credit card required