Skip to main content

US state privacy applicability tool

One workbook · twenty states · CAD $165

Which American state privacy laws actually catch you?

Not all twenty. Almost never all twenty. The useful question is which handful reach you on your real numbers, and the answer is rarely the one people expect — the states that catch a mid-sized Canadian firm first are usually the two nobody has heard of.

The thing most people get wrong

The common belief is that American state privacy laws work on thresholds: hold enough residents’ data and you are in, hold fewer and you are out. That is true of eighteen of them.

Texas and Nebraska set no number at all. Doing business there and processing personal data is enough, unless you are a small business under the US federal definition. We ran a realistic case through this tool — a Canadian SaaS at $8m revenue, no data sales, forty thousand Californians and a few thousand people in most other states. It came out in scope in exactly two states, and neither was California.

  1. Four numbers about your business, and a resident count per state. Estimates are fine — you are establishing which side of a line you fall on, not auditing a database.
  2. Every threshold calculated, not looked up. Each state’s test is built into the sheet, including the lower counts that only apply if you sell data, and the two states where revenue alone decides it.
  3. A reason for every answer. Not just in scope or out, but which limb of the test decided it, so you can check our working rather than trust it.
  4. Verified individually in August 2026. Not copied from a comparison table. Two thresholds in wide circulation are wrong: Montana’s fell in October 2025, and Tennessee’s is 175,000 rather than the 100,000 several trackers publish.
  5. What it does not tell you, said plainly — sectoral law, entity exemptions, how “consumer” is defined differently in California, and why being out of scope today is a measurement rather than a decision.
Available today

State applicability tool

One Excel workbook. Twenty state laws in force, plus the one enacted and waiting. Yours to keep, use and re-run as you grow.

  • Every threshold, every percentage test, every revenue floor, calculated from your own figures.
  • The two no-threshold states called out, because they are the ones that catch you first.
  • A tally of how many states reach you, and which ones need a human decision rather than a number.
  • Dated, so you know what it was current against, and cheap enough to re-run when it is not.

CAD $165

Buy the state applicability tool — $165

Secure checkout by Stripe · emailed within one working day

Read the free one first

If an American customer has asked you for a SOC 2 and you already hold ISO 27001, the crosswalk is published complete on this site and costs nothing.

  • All thirty-eight criteria mapped to ISO 27001, with what carries over and what does not.
  • The one criterion that is genuinely new work for an ISO shop.
  • Why the evidence, not the controls, is what makes a first SOC 2 take two or three quarters.
  • No email address, no form, no follow-up.

Free

Read the SOC 2 crosswalk

Published in full · nothing held back

Where the line falls

This tests applicability. It is not legal advice, and we do not practise United States state law.

The tool structures the question and records your answer to it. It does not model entity exemptions, it does not decide whether a GLBA or HIPAA carve-out takes you out of a state law, and it cannot tell you what to do once you are in scope. Where the answer is close, or where an exemption might apply, you need American counsel — and knowing when to make that call is most of what this is for.

A tool is not a management system, so buying this does not stop us carrying out an independent assessment of your organisation. The documentation packs are the purchase that would. We say which side of that line a purchase falls on before you buy, not after.

How to buy

Buy above and the workbook reaches you by email within one working day. No account to create, no subscription. Revisions are free for twelve months, which matters here more than usual: thresholds move, and one moved last October. The workbook is supplied in English; if you need it in French Canadian, ask before you buy and we will tell you what is possible.

What else attaches abroadThe free SOC 2 crosswalk

Standards we assess against

ISO/IEC 27001:2022 · ISO/IEC 27701:2025 · ISO 9001:2015 · ISO/IEC 42001:2023 · ISO/IEC 23894:2023 (guidance) · ISO/IEC 42005:2025 (guidance)

Français : La première heure — rédigé en français, pas une traduction automatique.

Canada Cyber-Safe is an independent assessment practice. We are not a certification body and we do not issue certificates.