13 of the 20 US state comprehensive privacy laws in effect or enacted as of January 2026 fully exempt nonprofit organizations, according to Foley & Lardner's U.S. State Comprehensive Consumer Data Privacy Law Comparison chart, current as of January 15, 2026 and updated quarterly by the firm's Cybersecurity & Data Privacy team. The other 7 states split between a narrow, activity-specific carve-out and, in Colorado and New Jersey's case, no nonprofit exemption whatsoever.

Exemptions are where these 20 laws diverge the most. Every state agrees on the broad strokes, a threshold based on residents' data or revenue, consumer rights to access and delete, an opt-out of sale. But which organizations and which categories of data fall outside the law entirely differs state by state, and getting it wrong is the single most common way a business assumes it is covered when it is not, or assumes it is exempt when it is not. Below is what 20 state privacy laws actually say about nonprofits, financial institutions, HIPAA-covered entities and B2B data, side by side.

States that fully exempt nonprofits from their privacy law 65% 35% of 20 state privacy lawsfully exempt nonprofits,versus partial or none

Figure: 13 of 20 state privacy laws fully exempt nonprofit organizations; the other 7 offer a limited carve-out or none. Source: Foley & Lardner, U.S. State Comprehensive Consumer Data Privacy Law Comparison, current as of January 15, 2026.

How many state privacy laws exempt nonprofit organizations?

13 of the 20 states, California, Connecticut, Florida, Indiana, Iowa, Kentucky, Nebraska, New Hampshire, Rhode Island, Tennessee, Texas, Utah and Virginia, give nonprofit organizations a full exemption from their privacy law. California's exemption comes with a documented catch: the CPRA defines a "business" broadly enough that a nonprofit owned by, or that owns, a for-profit entity meeting the revenue threshold can still fall within scope.

Five states, Delaware, Maryland, Minnesota, Montana and Oregon, exempt nonprofits only for narrow activities, such as fraud prevention tied to insurance, or intermingled HIPAA-protected health data. Colorado and New Jersey stand apart: neither statute exempts nonprofits at all. Colorado's attorney general states plainly that the Colorado Privacy Act "applies to entities, including nonprofits, that conduct business in Colorado" once the consumer thresholds are met.

Figure 1: 13 states fully exempt nonprofits, 5 offer a limited carve-out, and 2 offer none. Source: Foley & Lardner, U.S. State Comprehensive Consumer Data Privacy Law Comparison (January 2026).

A nonprofit fundraising or running membership programs across state lines cannot assume the same exemption follows it everywhere. The safest read is state by state, not a blanket assumption either way.

Which entity types get the broadest exemptions overall?

GLBA-regulated financial institutions get the widest berth of any entity type tracked: 15 of the 20 states fully exempt them, and 4 more (Connecticut, Minnesota, Montana, Oregon) exempt them in a limited form tied to the institution's financial activities. California is the sole holdout, with no GLBA-specific exemption in the CCPA or CPRA at all.

Nonprofits, HIPAA-covered entities and higher education institutions each land at the same 65% mark, 13 of 20 states granting a full exemption. National securities associations and state-licensed insurance producers are the rarest carve-outs by far, present in only 7 and 6 states respectively.

Figure 2: GLBA-regulated financial institutions are exempt in more states than any other entity type tracked. Source: Foley & Lardner, U.S. State Comprehensive Consumer Data Privacy Law Comparison (January 2026).

The pattern holds across nearly every state: federally regulated industries, already subject to GLBA, HIPAA, or securities law, get carved out first, and general-purpose organizations like nonprofits and higher education institutions get carved out second, if at all.

Do state privacy laws treat HIPAA-covered entities the same way?

Not even close. 13 of the 20 states give HIPAA-covered entities and their business associates a full entity-level exemption, meaning the organization itself sits outside the state law's scope for all its data, not just the health records it holds. The other 7, California, Colorado, Maryland, Minnesota, New Jersey and Oregon on a data-level basis, plus Delaware on a narrower combined basis, exempt only the specific data already protected as HIPAA information, leaving the rest of the organization's data subject to the state law.

That distinction matters for a hospital system's marketing arm, a health plan's member-engagement platform, or any HIPAA-adjacent business that also collects data HIPAA does not reach. An entity-level exemption clears the whole organization; a data-level exemption clears only the protected health information itself, and everything else, loyalty program data, website analytics, appointment-reminder opt-ins, stays in scope. A privacy policy generator built for state-by-state compliance can help map which disclosures apply once you know which exemption tier your organization actually falls into.

Is B2B data exempt from state privacy laws?

In 19 of the 20 states, yes, business-to-business data, information collected in the course of a business relationship rather than a consumer one, is exempt outright. California is the single exception. The CCPA originally exempted B2B and employment-related personal information too, but those exemptions were always written as temporary and expired on December 31, 2022, according to the California Attorney General's official CCPA guidance, which confirms the carve-outs were never renewed.

That makes California's law the strictest of the 20 on this specific point: a business collecting a vendor contact's name, title and email address for a commercial relationship is handling regulated personal information under the CCPA in a way it would not be in Texas, Virginia, or any of the other 19 states. Companies operating nationally sometimes build their B2B data handling around the other 19 states' exemption and get caught out by California's narrower rule.

How fast is the map of state privacy exemptions growing?

The number of states with a comprehensive privacy law in effect has nearly quadrupled in three years. Five states, California, Colorado, Connecticut, Utah and Virginia, had a law in effect by the end of 2023. That grew to 9 by the end of 2024, 17 by the end of 2025, and reached 20 with Indiana, Kentucky and Rhode Island taking effect in January 2026.

Figure 3: The count of states with an effective comprehensive privacy law nearly quadrupled between 2023 and 2026. Source: Foley & Lardner, U.S. State Comprehensive Consumer Data Privacy Law Comparison (January 2026), effective dates by state.

2025 alone accounted for 8 of the 20 laws taking effect, the single largest wave to date, which is also why exemption language has kept shifting: later statutes borrow heavily from earlier ones, but each legislature has adjusted the entity list slightly, which is exactly why Colorado and New Jersey ended up as outliers on nonprofits rather than following the majority pattern.

What is the timeline of major exemption changes?

The story of state privacy exemptions is really the story of five legislative waves, each one refining what the last state got wrong or left ambiguous.

Figure 4: Five waves of state privacy legislation, each refining entity and data exemptions. Source: Foley & Lardner, U.S. State Comprehensive Consumer Data Privacy Law Comparison (January 2026).

The 2022 sunset of California's own B2B exemption is the outlier event on this timeline. Every other state that followed built B2B and employee-data exemptions in as permanent features rather than temporary ones, precisely because California's experience made the alternative look risky to legislators drafting later bills.

How do you know if your organization is exempt?

Because the answer depends on entity type and state at the same time, a simple decision test catches most of the confusion companies run into.

Figure 5: A state-by-state decision test for the most commonly claimed exemptions. Source: Foley & Lardner, U.S. State Comprehensive Consumer Data Privacy Law Comparison (January 2026).

None of these five outcomes are a substitute for reading the specific statute a business is subject to, since thresholds around revenue and consumer counts (covered in our full list and tracker of US state privacy laws) still apply on top of any entity-type exemption.

State-by-state exemption snapshot

The table below summarizes the three exemption categories most businesses ask about first: nonprofits, GLBA-regulated financial institutions, and HIPAA-covered entities.

StateNonprofitsGLBA entitiesHIPAA entities
CaliforniaFull (with caveat)NoneData-level only
ColoradoNoneFullData-level only
ConnecticutFullLimitedFull
DelawareLimitedFullPartial
FloridaFullFullFull
IndianaFullFullFull
IowaFullFullFull
KentuckyFullFullFull
MarylandLimitedFullData-level only
MinnesotaLimitedLimitedData-level only
MontanaLimitedLimitedFull
NebraskaFullFullFull
New HampshireFullFullFull
New JerseyNoneFullData-level only
OregonLimitedLimitedData-level only
Rhode IslandFullFullFull
TennesseeFullFullFull
TexasFullFullFull
UtahFullFullFull
VirginiaFullFullFull
Totals (of 20)13 Full / 5 Limited / 2 None15 Full / 4 Limited / 1 None13 Full / 6 Data-level / 1 Partial

Source: Foley & Lardner, U.S. State Comprehensive Consumer Data Privacy Law Comparison, current as of January 15, 2026. This mirrors the same divide our Minnesota and Maryland deep dive covers for two of the five "limited" nonprofit states, and the Oregon and Delaware scope comparison covers for two more.

The rarer professional exemptions follow a similar pattern to GLBA and HIPAA: already-regulated industries get carved out first.

Exemption typeStates granting itShare of 20
Higher education institutions13 full, 1 limited70%
National securities associations735%
State-licensed insurance producers630%

Source: Foley & Lardner, U.S. State Comprehensive Consumer Data Privacy Law Comparison, current as of January 15, 2026.

The Bottom Line

20 states now have a comprehensive privacy law, and the exemption differences between them are not a footnote, they decide whether an organization is regulated at all. 13 of 20 fully exempt nonprofits, but Colorado and New Jersey do not, and a nonprofit operating in both states cannot rely on the majority rule. GLBA-covered financial institutions get the broadest pass, exempt in 15 of 20 states, while California stands alone in exempting neither GLBA entities nor B2B data. For any organization deciding which state laws actually apply to it, checking exemptions first, entity type by entity type and state by state, catches more compliance gaps than checking thresholds alone. To see which of the 20 laws apply to a specific business before drafting a policy, our guide to which state privacy laws apply to your business walks through the same entity and threshold questions this comparison is built from.

Frequently Asked Questions

How many state privacy laws exempt nonprofit organizations? 13 of the 20 US state comprehensive privacy laws in effect or enacted as of January 2026 fully exempt nonprofit organizations, per Foley & Lardner's state privacy law comparison chart. Five states offer only a limited nonprofit carve-out, and Colorado and New Jersey exempt nonprofits not at all.

Which state privacy law does not exempt B2B data? California is the only one of the 20 states whose privacy law does not exempt business-to-business data. The CCPA's original B2B and employment-related personal information exemptions expired on December 31, 2022, and were never renewed.

Do all state privacy laws exempt HIPAA-covered entities the same way? No. 13 of the 20 states give HIPAA-covered entities and their business associates a full entity-level exemption, meaning the organization itself is out of scope. The other 7, including California and Colorado, exempt only the specific health data already regulated by HIPAA, not the entity that holds it.

Which states give nonprofits no privacy law exemption at all? Colorado and New Jersey are the only 2 of the 20 states with a comprehensive privacy law that apply their statute to nonprofit organizations with no dedicated exemption, subject to the same thresholds and obligations as for-profit entities.

Where the Numbers Come From

  1. Foley & Lardner LLP. (2026). "U.S. State Comprehensive Consumer Data Privacy Law Comparison." Chart current as of January 15, 2026, updated quarterly; entity and data-category exemption tables for the 20 states with an enacted comprehensive privacy law.
  2. California Office of the Attorney General. "California Consumer Privacy Act (CCPA)." Official guidance confirming the CCPA's business-to-business and employment-related personal information exemptions expired December 31, 2022.
  3. Colorado Attorney General. "Colorado Privacy Act" resource page. Confirms the GLBA entity exemption and that the statute applies to nonprofit organizations with no dedicated exemption.
  4. IAPP. "US State Privacy Legislation Tracker." Ongoing tracker of enacted and pending state comprehensive privacy bills, referenced to corroborate the 20-state count.

Note: All figures verified as of August 2026, sourced primarily from Foley & Lardner's comparison chart current as of January 15, 2026 and updated quarterly by the firm. Exemption interpretations for the newest 2026 laws (Indiana, Kentucky, Rhode Island) may be refined as state regulators issue further guidance; this post is scheduled for its own refresh alongside the next quarterly chart update.