Compliance Guides

One page per law. What it requires, who it applies to, what changed.

Informational summaries of the privacy laws we test against most often. Not legal advice — start here to get oriented, then run a scan to see where your site actually stands.

California

California Consumer Privacy Act, as amended by the CPRA

CCPA / CPRA

The strictest US state law, and the one most actively enforced. Requires a working opt-out, not just a banner.

Read the guide →
Texas

Texas Data Privacy and Security Act

TDPSA

No revenue threshold like California's — a much broader set of businesses are in scope than most expect.

Read the guide →
Connecticut

Connecticut Data Privacy Act

CTDPA

One of the first state laws to require honoring universal opt-out signals like GPC, not just an on-site choice.

Read the guide →
New Jersey

New Jersey Data Privacy Act

NJDPA

The 30-day warning period for first-time violations ended in July 2026. Enforcement now starts with a penalty.

Read the guide →
European Union

General Data Protection Regulation

GDPR

Opt-in by default, not opt-out. Applies to any business selling to EU visitors, regardless of where it's based.

Read the guide →