Technology Resources for Cybersecurity, IT, + Cloud | CompassMSP

You Were Too Small for Privacy Law. As of January, You Aren't.

Written by Richard Mendoza | Oct 7, 2026, 8:33:57 PM

Privacy Rules Are Reaching Smaller Retailers.

For most of the last five years, state privacy laws were written with large companies in mind. A retailer with a few stores, an online shop, and a loyalty program could look at thresholds like 100,000 consumers and decide the law was aimed at someone else.

That decision is getting harder to defend. Oklahoma's new privacy law takes effect January 1, 2027. Alabama follows on May 1, 2027, with a threshold of more than 25,000 consumers. Delaware goes further than either state. On September 2, 2026, Delaware's governor signed House Bill 380, which cuts the state's threshold from 35,000 consumers to 10,000 Delaware consumers starting January 1, 2027, the lowest threshold of any state privacy law in the country. These changes, along with existing legislation in California and Virginia, create a significant compliance burden for small to mid-size organizations.

For small and mid-sized retailers, the old question was whether the business was big enough to be covered. The new question is how many customers the business has in each state, and most retailers have never counted.

In This Article

Why the Thresholds Matter to Small Retailers

Alabama's new law made it the 21st state to pass a comprehensive consumer privacy law, and more states have acted since. These laws apply based on whose data you hold, not where your business is located. An online retailer based in another state that ships to Oklahoma customers or runs Oklahoma-targeted marketing can fall under Oklahoma's law with no physical operations in the state.

State privacy laws define personal data broadly. A name, email address, phone number, shipping address, purchase history, loyalty account, or device identifier collected by your website can all count. A customer who bought once online, joined your email list, and scanned a loyalty card at the register is one consumer in your data, and those consumers add up faster than most owners expect.

A threshold of 10,000 consumers is within reach of a regional retailer with an active e-commerce site. A threshold of more than 25,000 is within reach of many small chains.

Delaware

10,000

State consumers

General threshold from January 1, 2027. Excludes data used solely to complete a payment.

Read the Delaware Law

Alabama

>25,000

State consumers

General threshold from May 1, 2027. Data-sale rules and exemptions also affect coverage.

Review Alabama’s Rules

Oklahoma

100,000

State consumers

General threshold from January 1, 2027. A separate data-sale test starts at 25,000.

Review Oklahoma’s Rules

What Delaware Changed

Delaware's amendment is the most aggressive of the three laws. For businesses that earn more than 20% of gross revenue from selling personal data, the threshold drops to 5,000 consumers. The IAPP noted that the lower thresholds pull a broader set of small and midsize businesses into scope.

Three other changes matter to retailers.

  1. Third-Party Coverage

    The first is a new category of covered business. From January 1, 2027, third parties that acquire personal data from a controller will face coverage with no minimum volume threshold, subject to statutory definitions and exemptions. If you buy or receive customer lists from partners, review whether this category applies to your business.

  2. Vendor Oversight

    The second is vendor oversight. From January 1, 2027, controllers must conduct reasonable due diligence on third parties that receive their data and sign new contract terms when data is sold or shared for targeted advertising. Consumers also gain the right to ask for a list of the third parties that received their data.

  3. Sensitive Financial Data

    The third is the definition of sensitive data. From January 1, 2027, Delaware will include certain payment card and financial account information that, alone or with required codes, passwords, or credentials, allows access to a consumer’s financial account. Sensitive data carries stricter handling rules than ordinary personal data. Retailers should review how this definition affects their payment, customer profile, and analytics systems.

The amendment also lowers the bar for formal risk reviews. The threshold for a required data protection assessment drops from 100,000 Delaware consumers to 50,000.

These amendments sit on top of a rule that already applies. Since January 1, 2026, Delaware has required businesses to treat universal opt-out signals as valid consumer requests. Once the threshold drops, far more retailers will need a website that recognizes those signals.

Primary source: Delaware Personal Data Privacy Act, effective January 1, 2027.

Oklahoma and Alabama Join the List

Oklahoma's law sets a higher bar. It applies to businesses that process data on at least 100,000 Oklahoma consumers per year, or 25,000 consumers where data sales make up more than half of gross revenue. Most small retailers will fall below that line. Regional chains and e-commerce brands with national reach should still run the numbers.

Alabama's law is the one to watch. It applies to businesses that process the personal data of more than 25,000 consumers, excluding data processed solely to complete a payment transaction, and it takes effect May 1, 2027. Small businesses with fewer than 500 employees are exempt, but only if they do not sell personal data.

That condition is where small retailers need to be careful. Alabama also covers businesses that derive more than 25% of gross revenue from personal data sales, regardless of consumer count. DLA Piper noted that Alabama's revenue-from-sales test could capture even small businesses that engage in sales of personal data. Whether your marketing tools count as a sale may decide whether the exemption protects you.

Why Your Ad Pixels Matter More Than You Think

Most retail websites run tracking tools from advertising and analytics platforms. These tools send information about visitors to outside companies, often to power retargeting ads. California regulators have treated this activity as the sale or sharing of personal information, which gives consumers the right to opt out of it.

Your privacy obligations and your payment security obligations overlap here. Under PCI-DSS v4.0.1, retailers must already keep a written inventory of every script on their payment pages, as we explained in PCI-DSS v4.0.1 Is Fully in Effect and Your Checkout Page May Already Be Non-Compliant. The same inventory shows which scripts send customer data to third parties. If you built it for PCI, extend it to your full website. If you have not built it, one project now serves two requirements.

One Inventory, Two Uses

Follow the Data Behind Every Tag.

Your payment-page script inventory can be the starting point for a wider review of website tracking, customer data transfers, and privacy controls.

What Non-Compliance Costs

Delaware, Oklahoma, and Alabama authorize their attorneys general to enforce these laws. Each law sets its own penalty rules.

Delaware

$10,000

Up to this amount per willful violation.

The mandatory 60-day cure period ended December 31, 2025.

Oklahoma

$7,500

Up to this amount per violation.

Written notice and a 30-day cure period.

Alabama

$15,000

Up to this amount per violation.

A 45-day cure period before enforcement.

Delaware has the least forgiving enforcement posture of the three. Its 60-day cure period expired on December 31, 2025, and courts can impose up to $10,000 for each willful violation. Any chance to fix a problem before penalties now depends on the attorney general's discretion.

In Oklahoma, the attorney general must give written notice and a 30-day cure period before acting, and penalties are capped at $7,500 per violation. In Alabama, the cure window is 45 days, and a court can assess up to $15,000 per violation if the business fails to fix the problem.

A cure period gives you a chance to fix a problem after regulators find it. It does not give you time to build a privacy program from scratch. A broken opt-out process that affects many customers can increase enforcement exposure; regulators apply the relevant law to determine violations and penalties.

A privacy enforcement action can start without a data breach. California's $1.35 million fine against retailer Tractor Supply grew out of basic compliance failures rather than a data breach. Regulators also give consumers ways to file complaints, and those complaints help them identify targets. One frustrated customer can start an investigation.

Case Study: Todd Snyder

California Enforcement Case

Todd Snyder

Broken Cookie Banner. Unprocessed Opt-Outs.

40Days of failed opt-out processing
$345,178CCPA fine

Todd Snyder is a clothing retailer, not a data company. Its website used cookies, pixels, and other tracking tools that sent data about shoppers' online behavior to third parties for analytics and cross-context behavioral advertising.

For 40 days in late 2023, when shoppers clicked the site's cookie preference link, the consent banner appeared and then disappeared, which made it impossible to submit an opt-out request. The same misconfiguration meant the site ignored Global Privacy Control signals. Regulators also found that the retailer asked for more personal information than necessary to process privacy requests and made consumers verify their identity before opting out.

The California Privacy Protection Agency found that the company relied on third-party privacy tools without understanding their limits or confirming that they worked. The agency imposed a $345,178 fine and required changes to the company's privacy practices.

Primary source: California Privacy Protection Agency enforcement announcement.

What Retailers Can Learn

The lesson for small retailers is that a privacy tool you install and never test is a liability. The fine came from a configuration error that lasted just over a month, and a smaller retailer with the same problem would have fewer resources to absorb the penalty.

A Note on Franchise and Multi-Location Retailers

Franchise and multi-location retailers should answer a question many have never asked: who owns the customer data? A franchisor may run the loyalty program, the website, and the email list, while individual locations collect names and phone numbers at the register. Depending on how those systems are set up, the franchisor, the franchisee, or both may carry obligations under state privacy laws.

Delaware's new third-party rules add another layer. When customer data moves between a franchisor and its locations, or between a retailer and its marketing vendors, Delaware’s amendments may require due diligence and written contract terms for qualifying transfers from January 1, 2027. Review the parties’ roles, any affiliate exclusions, and the terms that govern those data flows.

CompassMSP works with retail and franchise businesses on privacy, payment security, and compliance across multiple locations. You can learn more about our approach at compassmsp.com/industries/retail-franchise.

What Your Organization Needs to Have in Place

The following steps help a small or mid-sized retailer prepare for the January 1 and May 1, 2027 effective dates.

  1. Count your Customers by State

    Pull data from your e-commerce platform, point-of-sale system, loyalty program, and email marketing tool, then count unique consumers in Delaware, Oklahoma, and Alabama. Compare those numbers against each state's threshold.

  2. Map Where Customer Data Goes

    Document every system that stores customer data and every outside company that receives it, including ad platforms, analytics tools, and marketing vendors. Our guide to how compliance regulations shape data protection strategies explains why this asset inventory is the foundation of every privacy and security framework.

  3. Inventory the Scripts on your Website

    Identify every pixel, tag, and tracking tool, what data each one sends, and where that data goes. Start with the inventory you built for PCI-DSS Requirement 6.4.3 if you have one.

  4. Test your Opt-out Process

    Confirm that your cookie banner works, that opt-out requests are honored, and that your site responds to Global Privacy Control signals. Test it on a schedule, since a one-time check will not catch a later misconfiguration.

  5. Review your Vendor Contracts

    From January 1, 2027, Delaware will require specific contract terms for qualifying disclosures when you share data with third parties. Ask your marketing and technology vendors for their privacy terms and compare them against the new requirements.

  6. Update your Privacy Notice

    Your notice should accurately describe what you collect, why you collect it, who receives it, and how customers can exercise their rights.

  7. Ask Counsel about Sensitive Data

    Delaware’s amended definition covers financial and card information that enables account access. Confirm which data your business holds and how the sensitive-data requirements apply.

The TL;DR

Delaware's privacy law will apply to businesses that hold data on 10,000 Delaware consumers starting January 1, 2027, and third parties that acquire personal data will be covered with no minimum volume threshold, subject to statutory definitions and exemptions. Oklahoma's law takes effect the same day. Alabama's law follows on May 1 with a general threshold of more than 25,000 consumers and penalties of up to $15,000 per violation.

The retailers most exposed are the ones who never counted their customers by state because they assumed privacy law applied to bigger companies. Loyalty programs, email lists, and ad pixels can put a small retailer in scope, and a broken cookie banner can turn into a six-figure fine. The time to find out where you stand is before January, not after a customer complaint.

Your Next Move

Ready to Assess Your
Privacy Compliance Posture?

Delaware’s amended law and Oklahoma’s new law take effect on January 1, 2027. Alabama’s law follows on May 1, 2027. If your organization has not counted its customers by state or tested its opt-out process, a privacy gap assessment is where this work starts.

CompassMSP works with small and mid-sized retail and franchise businesses on privacy compliance, PCI-DSS, payment security, and the broader cybersecurity programs that keep customer data protected.