You Were Too Small for Privacy Law. As of January, You Aren't.
Oct 7, 2026, 4:33:57 PM Richard Mendoza 13 min read
Privacy Rules Are Reaching Smaller Retailers.
For most of the last five years, state privacy laws were written with large companies in mind. A retailer with a few stores, an online shop, and a loyalty program could look at thresholds like 100,000 consumers and decide the law was aimed at someone else.
That decision is getting harder to defend. Oklahoma's new privacy law takes effect January 1, 2027. Alabama follows on May 1, 2027, with a threshold of more than 25,000 consumers. Delaware goes further than either state. On September 2, 2026, Delaware's governor signed House Bill 380, which cuts the state's threshold from 35,000 consumers to 10,000 Delaware consumers starting January 1, 2027, the lowest threshold of any state privacy law in the country. These changes, along with existing legislation in California and Virginia, create a significant compliance burden for small to mid-size organizations.
For small and mid-sized retailers, the old question was whether the business was big enough to be covered. The new question is how many customers the business has in each state, and most retailers have never counted.
In This Article
- Why the Thresholds Matter to Small Retailers
- What Delaware Changed
- Oklahoma and Alabama Join the List
- Why Your Ad Pixels Matter More Than You Think
- What Non-Compliance Costs
- Case Study: Todd Snyder
- A Note on Franchise and Multi-Location Retailers
- What Your Organization Needs to Have in Place
- The TL;DR
- FAQs
Why the Thresholds Matter to Small Retailers
Alabama's new law made it the 21st state to pass a comprehensive consumer privacy law, and more states have acted since. These laws apply based on whose data you hold, not where your business is located. An online retailer based in another state that ships to Oklahoma customers or runs Oklahoma-targeted marketing can fall under Oklahoma's law with no physical operations in the state.
State privacy laws define personal data broadly. A name, email address, phone number, shipping address, purchase history, loyalty account, or device identifier collected by your website can all count. A customer who bought once online, joined your email list, and scanned a loyalty card at the register is one consumer in your data, and those consumers add up faster than most owners expect.
A threshold of 10,000 consumers is within reach of a regional retailer with an active e-commerce site. A threshold of more than 25,000 is within reach of many small chains.
Delaware
10,000
State consumers
General threshold from January 1, 2027. Excludes data used solely to complete a payment.
Read the Delaware LawAlabama
>25,000
State consumers
General threshold from May 1, 2027. Data-sale rules and exemptions also affect coverage.
Review Alabama’s RulesOklahoma
100,000
State consumers
General threshold from January 1, 2027. A separate data-sale test starts at 25,000.
Review Oklahoma’s Rules.gif?width=940&height=788&name=Copy%20of%20Stats%20-%20Blog%20(29).gif)
What Delaware Changed
Delaware's amendment is the most aggressive of the three laws. For businesses that earn more than 20% of gross revenue from selling personal data, the threshold drops to 5,000 consumers. The IAPP noted that the lower thresholds pull a broader set of small and midsize businesses into scope.
Three other changes matter to retailers.
-
Third-Party Coverage
The first is a new category of covered business. From January 1, 2027, third parties that acquire personal data from a controller will face coverage with no minimum volume threshold, subject to statutory definitions and exemptions. If you buy or receive customer lists from partners, review whether this category applies to your business.
-
Vendor Oversight
The second is vendor oversight. From January 1, 2027, controllers must conduct reasonable due diligence on third parties that receive their data and sign new contract terms when data is sold or shared for targeted advertising. Consumers also gain the right to ask for a list of the third parties that received their data.
-
Sensitive Financial Data
The third is the definition of sensitive data. From January 1, 2027, Delaware will include certain payment card and financial account information that, alone or with required codes, passwords, or credentials, allows access to a consumer’s financial account. Sensitive data carries stricter handling rules than ordinary personal data. Retailers should review how this definition affects their payment, customer profile, and analytics systems.
The amendment also lowers the bar for formal risk reviews. The threshold for a required data protection assessment drops from 100,000 Delaware consumers to 50,000.
These amendments sit on top of a rule that already applies. Since January 1, 2026, Delaware has required businesses to treat universal opt-out signals as valid consumer requests. Once the threshold drops, far more retailers will need a website that recognizes those signals.
Primary source: Delaware Personal Data Privacy Act, effective January 1, 2027.
Oklahoma and Alabama Join the List
Oklahoma's law sets a higher bar. It applies to businesses that process data on at least 100,000 Oklahoma consumers per year, or 25,000 consumers where data sales make up more than half of gross revenue. Most small retailers will fall below that line. Regional chains and e-commerce brands with national reach should still run the numbers.
Alabama's law is the one to watch. It applies to businesses that process the personal data of more than 25,000 consumers, excluding data processed solely to complete a payment transaction, and it takes effect May 1, 2027. Small businesses with fewer than 500 employees are exempt, but only if they do not sell personal data.
That condition is where small retailers need to be careful. Alabama also covers businesses that derive more than 25% of gross revenue from personal data sales, regardless of consumer count. DLA Piper noted that Alabama's revenue-from-sales test could capture even small businesses that engage in sales of personal data. Whether your marketing tools count as a sale may decide whether the exemption protects you.
Why Your Ad Pixels Matter More Than You Think
Most retail websites run tracking tools from advertising and analytics platforms. These tools send information about visitors to outside companies, often to power retargeting ads. California regulators have treated this activity as the sale or sharing of personal information, which gives consumers the right to opt out of it.
Your privacy obligations and your payment security obligations overlap here. Under PCI-DSS v4.0.1, retailers must already keep a written inventory of every script on their payment pages, as we explained in PCI-DSS v4.0.1 Is Fully in Effect and Your Checkout Page May Already Be Non-Compliant. The same inventory shows which scripts send customer data to third parties. If you built it for PCI, extend it to your full website. If you have not built it, one project now serves two requirements.
What Non-Compliance Costs
Delaware, Oklahoma, and Alabama authorize their attorneys general to enforce these laws. Each law sets its own penalty rules.
Delaware
$10,000
Up to this amount per willful violation.
The mandatory 60-day cure period ended December 31, 2025.
Oklahoma
$7,500
Up to this amount per violation.
Written notice and a 30-day cure period.
Alabama
$15,000
Up to this amount per violation.
A 45-day cure period before enforcement.
Delaware has the least forgiving enforcement posture of the three. Its 60-day cure period expired on December 31, 2025, and courts can impose up to $10,000 for each willful violation. Any chance to fix a problem before penalties now depends on the attorney general's discretion.
In Oklahoma, the attorney general must give written notice and a 30-day cure period before acting, and penalties are capped at $7,500 per violation. In Alabama, the cure window is 45 days, and a court can assess up to $15,000 per violation if the business fails to fix the problem.
A cure period gives you a chance to fix a problem after regulators find it. It does not give you time to build a privacy program from scratch. A broken opt-out process that affects many customers can increase enforcement exposure; regulators apply the relevant law to determine violations and penalties.
A privacy enforcement action can start without a data breach. California's $1.35 million fine against retailer Tractor Supply grew out of basic compliance failures rather than a data breach. Regulators also give consumers ways to file complaints, and those complaints help them identify targets. One frustrated customer can start an investigation.
Case Study: Todd Snyder
California Enforcement Case
Todd Snyder
Broken Cookie Banner. Unprocessed Opt-Outs.
Todd Snyder is a clothing retailer, not a data company. Its website used cookies, pixels, and other tracking tools that sent data about shoppers' online behavior to third parties for analytics and cross-context behavioral advertising.
For 40 days in late 2023, when shoppers clicked the site's cookie preference link, the consent banner appeared and then disappeared, which made it impossible to submit an opt-out request. The same misconfiguration meant the site ignored Global Privacy Control signals. Regulators also found that the retailer asked for more personal information than necessary to process privacy requests and made consumers verify their identity before opting out.
The California Privacy Protection Agency found that the company relied on third-party privacy tools without understanding their limits or confirming that they worked. The agency imposed a $345,178 fine and required changes to the company's privacy practices.
Primary source: California Privacy Protection Agency enforcement announcement.
What Retailers Can Learn
The lesson for small retailers is that a privacy tool you install and never test is a liability. The fine came from a configuration error that lasted just over a month, and a smaller retailer with the same problem would have fewer resources to absorb the penalty.
A Note on Franchise and Multi-Location Retailers
Franchise and multi-location retailers should answer a question many have never asked: who owns the customer data? A franchisor may run the loyalty program, the website, and the email list, while individual locations collect names and phone numbers at the register. Depending on how those systems are set up, the franchisor, the franchisee, or both may carry obligations under state privacy laws.
Delaware's new third-party rules add another layer. When customer data moves between a franchisor and its locations, or between a retailer and its marketing vendors, Delaware’s amendments may require due diligence and written contract terms for qualifying transfers from January 1, 2027. Review the parties’ roles, any affiliate exclusions, and the terms that govern those data flows.
CompassMSP works with retail and franchise businesses on privacy, payment security, and compliance across multiple locations. You can learn more about our approach at compassmsp.com/industries/retail-franchise.
What Your Organization Needs to Have in Place
The following steps help a small or mid-sized retailer prepare for the January 1 and May 1, 2027 effective dates.
-
Count your Customers by State
Pull data from your e-commerce platform, point-of-sale system, loyalty program, and email marketing tool, then count unique consumers in Delaware, Oklahoma, and Alabama. Compare those numbers against each state's threshold.
-
Map Where Customer Data Goes
Document every system that stores customer data and every outside company that receives it, including ad platforms, analytics tools, and marketing vendors. Our guide to how compliance regulations shape data protection strategies explains why this asset inventory is the foundation of every privacy and security framework.
-
Inventory the Scripts on your Website
Identify every pixel, tag, and tracking tool, what data each one sends, and where that data goes. Start with the inventory you built for PCI-DSS Requirement 6.4.3 if you have one.
-
Test your Opt-out Process
Confirm that your cookie banner works, that opt-out requests are honored, and that your site responds to Global Privacy Control signals. Test it on a schedule, since a one-time check will not catch a later misconfiguration.
-
Review your Vendor Contracts
From January 1, 2027, Delaware will require specific contract terms for qualifying disclosures when you share data with third parties. Ask your marketing and technology vendors for their privacy terms and compare them against the new requirements.
-
Update your Privacy Notice
Your notice should accurately describe what you collect, why you collect it, who receives it, and how customers can exercise their rights.
-
Ask Counsel about Sensitive Data
Delaware’s amended definition covers financial and card information that enables account access. Confirm which data your business holds and how the sensitive-data requirements apply.
The TL;DR
YOU MAY NEED TO KNOW
Frequently Asked Questions
Does Delaware's privacy law apply to my business if we are not located in Delaware?
It can. The Delaware law applies to businesses that conduct business in Delaware or target products or services to Delaware residents, provided they meet the consumer thresholds. An online retailer that sells and ships to Delaware customers should count those customers.
What counts as personal data under these privacy laws?
State privacy laws generally define personal data as information linked or reasonably linkable to an identifiable person. For a retailer, that includes names, email addresses, phone numbers, shipping addresses, purchase histories, loyalty accounts, and the device identifiers and browsing data that website tracking tools collect.
How do we count consumers toward a state's threshold?
Count unique individuals who live in that state, across every system that holds customer data. A single customer who appears in your e-commerce platform, loyalty program, and email list counts once. Most retailers need to pull and deduplicate records from several systems to get an accurate number.
Is there a small business exemption?
It depends on the state. Delaware's law has no revenue test or employee-count exemption, so the consumer count alone decides coverage. Alabama exempts businesses with fewer than 500 employees, but only if they do not sell personal data. Oklahoma's thresholds are high enough that many small retailers will fall below them.
Does point-of-sale data count toward the thresholds?
Alabama's threshold excludes personal data processed solely to complete a payment transaction. Once a retailer uses that data for something else, such as linking a purchase to a loyalty account or adding a customer to a marketing list, the exclusion may no longer apply. Confirm how each state treats your specific data flows with counsel.
Do ad pixels and analytics tools count as selling personal data?
They can. California regulators have treated tracking tools that send visitor data to advertising platforms as the sale or sharing of personal information. Each state defines "sale" differently, so review how your pixels and tags are configured and what data they send before assuming you do not sell data.
What is Global Privacy Control, and do we have to honor it?
Global Privacy Control is a browser setting that automatically tells websites a visitor wants to opt out of the sale or sharing of their data. Delaware has required businesses to recognize universal opt-out signals like Global Privacy Control since January 1, 2026. In the Todd Snyder case, a misconfigured consent tool meant the site ignored these signals, which contributed to the fine.
What are the penalties for violating these laws?
Delaware allows civil penalties of up to $10,000 per willful violation and no longer guarantees a cure period. Oklahoma caps penalties at $7,500 per violation after a 30-day cure period. Alabama allows up to $15,000 per violation after a 45-day cure period. Because penalties apply per violation, a single broken process that affects many customers can multiply quickly.
If my business is PCI-DSS compliant, does that cover my privacy obligations?
PCI-DSS and state privacy laws cover different things. PCI-DSS governs how you protect payment card data. State privacy laws govern what customer data you collect, how you use it, who receives it, and what rights customers have over it. A retailer can pass a PCI assessment and still violate a state privacy law, although the script inventory PCI requires is a useful starting point for both.
What should a small retailer do first?
Count your customers by state. Pull unique customer records from every system that collects them, including e-commerce, point of sale, loyalty, and email marketing, and compare the Delaware, Oklahoma, and Alabama numbers against each law's threshold. That count tells you which laws apply and how much work is ahead.
Richard Mendoza
Richard is the Director of vCISO services with CompassMSP. He has over twenty-five years of experience as an Information Security professional with hands-on experience in engineering process and information security, and IT audit disciplines. With a wide-ranging knowledge as a Systems Engineer, Information Security Officer, and Senior Auditor, Richard has expertise in managing internal and external audits focused on reducing overall risk exposure and infrastructure redundancy for organizations.