Consent Resolve
Compliance & Privacy Blog

State Privacy Laws Are a Patchwork — Here's How to Stay Covered

The privacy law that applies to you isn't fixed — it grows as your service area does. Here's which laws can follow your customers home as you expand, and the one setup that covers them all.

By Andy Mentges, Chief Executive Officer at Consent Resolve 7 min readReviewed by Stefan Dimitrov, Head of Engineering

The map grows, and the rulebook grows with it

Here’s something most contractors never get told until it’s a problem: the privacy laws that apply to you aren’t fixed at your shop’s front door. They grow as your service area grows. The day you only worked one town, one state’s rules were in play. The day you start taking jobs across the county line, advertising into the next metro, or simply getting found by homeowners who moved in from out of state — the rulebook quietly expands.

The United States never passed a single national consumer-privacy law, so the states filled the gap themselves, one at a time, each a little different. That means there’s no federal referee. There’s a different statute waiting in every state you grow into.

Why expansion widens your exposure faster than you think

For a shop that’s scaling, this is the part that sneaks up on you. What matters for most of these laws is where your customers are, not where you are. So your exposure tracks your reach.

Pick up a few jobs in the next state over, and a homeowner there is covered by that state’s law the moment they land on your site and you collect their data. Run ads into a bordering metro that crosses a line, and you’ve invited another regime in. Even staying put isn’t static — an out-of-state homeowner checking your work brings their home state’s rules with them. The bigger your footprint, the more of the patchwork you’re standing on at once. A contractor who solves privacy for “my state” the year they start is signing up to re-solve it every time the trucks roll a little farther.

Which laws actually hit you as you grow?

The honest answer is “more of them, the wider you go” — but they aren’t fifty different ideas. They’re fifty versions of the same idea. Whether it’s Texas filing the first-ever enforcement suit under a comprehensive state privacy law over data sold without permission, California’s CIPA carrying $5,000 per violation for non-consented website tracking, or the federal TCPA’s $500 to $1,500 per unsolicited call or text that follows you into every state, each one turns on the same word: consent. Disclose what you collect, honor a no, get a yes before the sensitive stuff, and keep proof. None of these figures is a prediction for your shop — they’re evidence that the underlying rule doesn’t change from state to state.

How do I stay covered as I add new states?

Here’s the shortcut, and it’s the one engineers use for any moving-target problem: build to the highest standard, and everything below it is covered automatically — including states you haven’t even expanded into yet.

In privacy, the highest standard isn’t a U.S. state law at all — it’s GDPR, the European regime whose maximum fine reaches €20 million or 4% of global revenue. GDPR demands clear consent, plain-language transparency, honored opt-outs, and provable records. Those demands sit at or above what any U.S. state asks. So if your website already clears the GDPR bar, growing into a new market doesn’t trigger a compliance scramble — you were already over the line before you got there.

That’s the whole logic behind built-in compliance. Instead of mapping each new customer in each new market to that state’s rules, you meet one strict standard once and let it cover the patchwork beneath you as you scale. Open a new service area next quarter? You’re likely already compliant there, because the strictest regime in the world set your floor.

The patchwork only grows from here — and so will you

It’s worth being honest about the direction of travel. Every legislative session, more states pass privacy laws, and the existing ones get amended and sharpened. The trend line points one way: more rules, more enforcement, more states with a private right of action that lets residents sue directly. Now layer your own growth on top of that — more states you operate in, against more states passing laws — and statute-by-statute compliance becomes a permanent part-time job that gets worse the more successful you are.

Building to the strictest bar breaks that cycle. GDPR works as the benchmark because it was written years ahead of the U.S. wave and set the template most state laws now borrow from — consent, transparency, opt-out, provable records. When you cross into a new state, its law tends to ask for a subset of what you’re already doing, not something new. You confirm nothing major changed and get back to running jobs.

What “built to GDPR” looks like as you scale

In practice it’s three things working together, and they don’t change as your map does:

  • A clear consent banner. Identification only happens for visitors who say yes — satisfying the consent and transparency demands shared across every state you reach.
  • A timestamped consent log on a 7-year audit trail. That’s the provable record every regime expects, so “who agreed and when?” is one lookup, in any state your customers live in.
  • Email-grade follow-up only. You never get a phone number to cold-dial. Leads drop into the funnel you already run — Jobber, Housecall Pro, ServiceTitan, HubSpot, Klaviyo, GoHighLevel — by the channel that carries the least risk in every jurisdiction.

Done this way, consent-first capture isn’t a tax on growth. It’s the version that keeps working as your service area widens, while still turning the traffic you already pay for into real, defensible leads.

Grow the footprint, not the homework

You don’t need to become a fifty-state privacy expert before you expand. You need a website built to the strictest standard there is, so each new market is covered the day you enter it — no statute-chasing required. Capture leads on consent, follow up by email at a flat $7 per exclusive lead — never resold — and keep the receipt on every one.

See how built-in compliance covers the patchwork by design, read how the Texas TDPSA fits the same pattern, and weigh it against what your current lead channels actually cost — in fees and in exposure. Every figure here is sourced on our stats page. This article is general information, not legal advice — for how these laws apply to your specific business, talk to an attorney in your state.

FAQ

Frequently asked questions

Generally what matters is where your customers are, not where your shop is. Take jobs across a state line, advertise into a neighboring metro, or simply get found by an out-of-state homeowner, and that state's privacy law can reach you when you collect their data. Growth widens your exposure. This is general information, not legal advice.
Get Started — $7 Email Us