Skip to content

Getting started

New US state privacy laws in 2026: what changes for licensing data

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

New state privacy laws in 2026, including the comprehensive laws of Indiana, Kentucky and Rhode Island, matter for licensing data mainly through three definitions: what counts as a sale, how de-identified data is treated and which businesses are covered. Delivering properly de-identified records usually changes the analysis, which counsel confirms deal by deal.

Key takeaways

  • Each new state law is reviewed on its own definitions of personal data, sale, de-identified data and exemptions.
  • Licensing records that still identify people can count as a sale, depending on how the law defines consideration.
  • De-identified data is generally outside these laws when the business meets the statute's conditions, including a public commitment and recipient contracts.
  • Coverage depends mostly on how many state residents' data a company processes, not on employee headcount.
  • Business-contact and employee records are excluded under many state laws outside California, but the exemptions differ by state.

Which state privacy laws begin in 2026?#

The comprehensive consumer privacy laws of Indiana, Kentucky and Rhode Island took effect on January 1, 2026, bringing the number of states with such laws in effect to 20 by MultiState's count, which includes Florida's narrower law. Counts vary by tracker, so confirm each effective date, cure period and later amendment in the statute text or the state attorney general's guidance before relying on it.

For a company licensing records to AI developers, each new law adds definitions to check: who is covered, what counts as personal data, what counts as a sale, how de-identified data is treated and which exemptions apply. The laws share a common structure, but the details differ enough that each state is reviewed on its own.

A new law does not affect a company simply because it exists. It matters when the company's records contain personal data about that state's residents and the company meets the law's applicability test.

Which state privacy laws begin in 2026?
LawIn effect fromDefinitions to confirm for a licenseSourceX law page
Indiana Consumer Data Protection ActJanuary 1, 2026Applicability thresholds, sale (monetary only or broader), de-identified data conditions, B2B and employee exemptionsIndiana Consumer Data Protection Act page
Kentucky Consumer Data Protection ActJanuary 1, 2026Applicability thresholds, sale, de-identified and pseudonymous data, exemptionsKentucky Consumer Data Protection Act page
Rhode Island Data Transparency and Privacy Protection ActJanuary 1, 2026Applicability thresholds, sale and consideration, de-identified data, any disclosure duties about salesRhode Island Data Transparency and Privacy Protection Act page

Does licensing records count as a sale of personal data?#

Licensing records that still contain personal data can count as a sale under a state privacy law if the exchange fits that law's definition. Some state laws define a sale as an exchange of personal data for monetary consideration, while others also include other valuable consideration, which can reach arrangements such as credits or services.

When the records delivered are properly de-identified, the analysis usually changes, because de-identified data is generally excluded from the definition of personal data. That makes preparation central: what leaves the company determines which obligations attach to the license. Whether a specific license is a sale is assessed deal by deal with counsel.

How state laws generally treat de-identified data#

De-identified data is generally outside the scope of these laws when the business meets conditions written into the statute, and most comprehensive state laws use a similar set. The list describes the common pattern; the wording varies by state, so counsel reads each one.

Pseudonymous data, where identifiers are replaced but a key still exists, is defined separately in many of these laws and may still carry obligations. Replacing customer names with ticket numbers is not de-identification if the company keeps the mapping table.

  • The business takes reasonable measures to ensure the data cannot be linked to an identified or identifiable individual.
  • The business publicly commits to keep and use the data only in de-identified form and not to attempt to re-identify it.
  • The business contractually requires any recipient of the data to meet the same commitments.
  • In practice, the business also keeps a record of how de-identification was done, which helps show the measures were reasonable.

Do these laws reach a mid-size company?#

Whether a mid-size company is covered depends mainly on how many of a state's residents it holds personal data about and whether it earns revenue from selling personal data, not on headcount. A regional home services company with many residential customers in one state can cross a threshold that a larger B2B firm never reaches.

Exemptions matter as much as thresholds. Many state laws outside California exclude people acting in a commercial or employment context: Virginia's law generally does not apply to information about a person acting in a B2B or employment context, and the Colorado Attorney General says the Colorado Privacy Act does not cover data kept for employment records. That can take CRM contacts at business customers and internal employee records out of scope under those laws. Other laws, contracts and notices may still apply to the same records, and the exemptions differ by state.

What counsel checks in each new law#

Counsel checks each new law against the specific records in a proposed license, not against the company in general. The same five questions apply to every state, and the answers usually sit in the statute's definitions and exemptions sections or in attorney general guidance.

Recording the answers per state in one memo keeps the review consistent and gives the next license a starting point. When a law is amended, only the affected rows need updating.

What counsel checks in each new law
QuestionWhy it matters for a data licenseWhere the answer usually sits
Is the company covered?Thresholds decide whether the law applies at allApplicability section and any small-business test
Do the records contain personal data under this law?Business-contact and employee exemptions can remove whole record familiesDefinitions and exemptions
Would the license be a sale?Monetary-only and broader consideration tests give different answersDefinition of sale and its exceptions
Can the records qualify as de-identified?Meeting the conditions can take the delivery outside the lawDefinition of de-identified data and controller duties
Is sensitive data involved?Sensitive categories often need consent and an assessmentDefinition of sensitive data and assessment provisions

What the laws mean for common licensing scenarios#

The same new law can matter a great deal or barely at all depending on which records are licensed. The table maps common scenarios to the question each raises and the usual preparation response.

What the laws mean for common licensing scenarios
Licensing scenarioPrivacy-law question it raisesTypical preparation response
Help desk tickets from homeowners or consumersPersonal data of residents; a possible sale if identifiers remainRemove names, addresses, phone numbers and free-text identifiers before delivery
CRM histories with contacts at business customersWhether the state excludes people acting in a commercial contextConfirm the exemption state by state; remove contact details regardless
Internal chat and email between employeesWhether employee data is excluded under that state's lawCheck exemptions, employee notices and policies; remove personal details
Recorded service callsCall recording consent rules as well as privacy lawCheck consent at the time of recording; transcribe and de-identify
De-identified job or order historiesWhether the statute's de-identification conditions are metPublic commitment, no re-identification clause and recipient obligations

Illustrative: an HVAC company with customers in two of the new states#

Illustrative: a fictional HVAC and plumbing company serves homeowners in Indiana and Kentucky from several branches and runs every job through ServiceTitan. It wants to license job histories, from the first call to the invoice and any warranty visit, to a developer building dispatch and diagnosis tools.

Counsel checks each state's applicability test against the company's customer counts and concludes the laws are likely to apply. The company decides to deliver only de-identified records: names, street addresses, phone numbers and gate codes in technician notes are removed, the license bars re-identification and requires the buyer to bind any subcontractor, and the privacy notice is updated with a commitment on de-identified data. The result is a narrower package that counsel is comfortable approving.

How SourceX approaches state privacy review#

SourceX handles state privacy questions inside the Rights and Preparation steps of the SourceX five-step transaction, which runs Supply, Rights, Preparation, Approval and Delivery. Personal and confidential details are removed before delivery, and the supplier approves the final release.

The privacy record in each SourceX Evidence Packet documents what was removed, how and under which review, which gives counsel a written basis for the de-identification analysis. SourceX maintains a page for each state law, and the laws that may apply are assessed deal by deal with the supplier's counsel.

Frequently asked questions

Do we need to update our privacy notice before licensing data?

Possibly. If personal data leaves the company, notices may need to describe the disclosure or sale and any opt-out right. If only de-identified data is delivered, many state laws expect a public commitment not to re-identify it, which often sits in the privacy notice. Counsel should review the notice against each law that may apply.

How does California fit with the newer state laws?

California's law is the most detailed of the state privacy laws and, unlike most others, applies to employee and business-contact data. It also has its own rules on risk assessments. Companies with California residents in their records usually review California separately rather than assuming the newer laws set the standard.

Do we need a data protection assessment?

Many comprehensive state laws require a documented assessment for higher-risk processing, which can include selling personal data or processing sensitive data. If only de-identified data is licensed, the analysis may differ. Counsel can confirm whether an assessment is needed and what it should cover for a specific license.

Our records cover customers in many states. Which law applies?

Each law applies based on whose data is involved and on the business's own thresholds, so multi-state records can bring several laws into play at once. Many companies prepare data to meet the strictest relevant standard rather than tracking each state separately, then confirm the result with counsel.

Do the new laws change anything for records collected years ago?

They can. A new law generally governs what a business does with personal data once the law takes effect, including disclosures and sales, even if the records were collected earlier. That is why older archives are prepared to the current standard before delivery. How a specific law treats older records is a question for counsel.

Sources

  • Comprehensive consumer privacy laws in Indiana, Kentucky and Rhode Island took effect on January 1, 2026, bringing the number of states with such laws in effect to 20 by MultiState's count, including Florida's narrower law. Source
  • The Virginia Consumer Data Protection Act generally does not apply to information about a natural person acting in a commercial (B2B) or employment context. Source
  • The Colorado Attorney General states that the Colorado Privacy Act does not cover individuals acting in a commercial or employment context and does not apply to data maintained for employment records purposes. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify