{"site":{"name":"Koji","description":"AI-native customer research platform that helps teams conduct, analyze, and synthesize customer interviews at scale.","url":"https://www.koji.so","contentTypes":["blog","documentation"],"lastUpdated":"2026-08-03T18:52:33.305Z"},"content":[{"type":"documentation","id":"f52c73f4-b762-45d7-bad9-f20cd8a18891","slug":"us-state-privacy-laws-research","title":"US State Privacy Laws for Customer Research: The Multi-State Compliance Guide (2026)","url":"https://www.koji.so/docs/us-state-privacy-laws-research","summary":"Twenty US states have comprehensive consumer privacy laws on the books as of early 2026. The decisive scope question for research is whether a participant is a consumer: every comprehensive state law except California defines a consumer as a resident acting in an individual or household context and excludes people acting in a commercial or employment context, so B2B research participants and employees fall outside those laws. California is the exception because the CCPA covers B2B contacts and employees after the partial exemptions expired on 1 January 2023. Key 2026 dates: Maryland MODPA in effect 1 October 2025 and enforceable April 2026; Indiana, Kentucky and Rhode Island effective 1 January 2026 along with Oregon amendments, expanded California data broker and health data rules, the Nebraska Age-Appropriate Design Code and the Texas Responsible AI Governance Act; further changes in Connecticut, Arkansas and Utah on 1 July 2026; new California data broker registration obligations on 1 August 2026. Rhode Island and Maryland apply at 35,000 consumers against Oregon 100,000. Most laws require opt-in consent for sensitive data including health, race, religion, sexual orientation, immigration status, precise geolocation and biometric data processed to identify someone, and open-ended interviews collect such data accidentally. Maryland bans the sale of sensitive personal data outright regardless of consent and requires collection to be reasonably necessary and proportionate, which consent cannot cure. Voice recordings analysed for content are not ordinarily biometric data because identification is not the purpose. Disclosures to a processor or service provider under contract terms covering documented instructions, no independent use, no onward sale, confidentiality, deletion or return and sub-processor flow-down are not sales. Universal opt-out mechanisms such as Global Privacy Control are honoured in around a dozen states but are a website and advertising obligation rather than a research one. The practical answer is a single research process built to the strictest provision in each dimension rather than twenty state variants.","content":"Two facts reshape most research teams' compliance work once they are understood. First, **outside California, your B2B research participants are almost certainly not \"consumers\" under any state privacy law** — every other comprehensive state law excludes individuals acting in a commercial or employment context. Second, when the laws do apply, the provisions that bite in research are narrow and predictable: opt-in consent for sensitive data, deletion and access rights over transcripts, data minimisation, and whether handing recordings to a vendor counts as a sale.\n\nEverything else in the state privacy landscape — universal opt-out signals, targeted advertising opt-outs, data broker registration — is a website and adtech problem, not a research problem. Knowing which is which is what keeps a research programme from being reviewed as if it were a marketing pixel.\n\n## The 2026 landscape\n\n**Twenty states have comprehensive consumer privacy laws on the books** as of early 2026, and the count keeps rising as each legislative session closes; some trackers already count higher after the mid-2026 wave. The dates that matter for anyone re-papering their process this year:\n\n| Date | What changed |\n|---|---|\n| 1 Oct 2025 | Maryland Online Data Privacy Act in effect (enforceable from April 2026) |\n| 1 Jan 2026 | Indiana, Kentucky and Rhode Island comprehensive laws take effect |\n| 1 Jan 2026 | Oregon amendments (HB 2008); California expanded data broker and health data rules; Nebraska Age-Appropriate Design Code |\n| 1 Jan 2026 | Texas Responsible AI Governance Act (HB 149) takes effect |\n| 1 Jul 2026 | Further changes land in Connecticut, Arkansas and Utah |\n| 1 Aug 2026 | New California data broker registration obligations |\n\nRhode Island is worth flagging because its applicability threshold is unusually low — processing the data of at least 35,000 consumers, or 10,000 if more than 20% of revenue comes from selling personal data. Maryland matches the 35,000 figure, against Oregon's 100,000. **Threshold shopping is not a strategy**; if you operate nationally you will cross a threshold somewhere.\n\n## Step 1 — Is your research participant a \"consumer\" at all?\n\nThis is the question to answer first, because it disposes of most B2B research entirely.\n\nEvery comprehensive state law except California's defines \"consumer\" as a resident **acting in an individual or household context**, and expressly excludes people acting in a commercial or employment context. Colorado, Connecticut, Utah and Virginia all take this approach, and the newer laws follow it.\n\nCalifornia is the exception, and it is a total one. The CCPA as amended defines a consumer as any California resident — which includes employees, job applicants and B2B contacts. The partial exemptions for employee and B2B data expired on **1 January 2023** and have not returned.\n\nWhat this means concretely:\n\n- Interviewing a procurement manager at a customer account about your product, in her professional capacity: outside the scope of every state law except California's.\n- Interviewing that same person about her personal banking app: a consumer, everywhere.\n- Interviewing your own employees about an internal tool: outside every state law except California's.\n- Interviewing a sole trader about the tools she uses to run her business: genuinely ambiguous, and worth treating as in-scope.\n\nTwo cautions before you relax. This analysis governs the **state privacy laws only** — recording consent laws, contractual obligations to your customers, sectoral rules like HIPAA, and GDPR for anyone in Europe all apply on their own terms. And if any of your participants are California residents, you are in scope regardless, which for most US-national research means designing to the California standard anyway.\n\n## Step 2 — Recognise the sensitive data you did not mean to collect\n\nNearly every state law requires **opt-in consent before processing sensitive data**, and Virginia, Connecticut, Colorado, Indiana, Kentucky and Rhode Island all take that approach. Sensitive categories typically include health conditions, racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, precise geolocation, and biometric data processed to identify someone.\n\nThe research problem is not that teams deliberately collect sensitive data. It is that **open-ended interviews collect it accidentally.** Ask a customer why she cancelled and she may tell you about a cancer diagnosis. Ask about a missed payment and you may hear about a divorce and an immigration status. None of that was on your discussion guide, and all of it is now in your transcript.\n\nThree practical controls:\n\n1. **Say so in the consent.** State that the interview may touch on personal circumstances, that the participant should share only what they are comfortable with, and what happens to the recording.\n2. **Redact on ingest, not at report time.** Anonymisation applied when you write the summary leaves the raw transcript sitting in your system.\n3. **Never let sensitive data leave in a \"sale\".** Maryland goes furthest here: MODPA **bans the sale of sensitive personal data outright, regardless of consent** — the strictest sensitive-data rule in any US state law. If your process cannot guarantee that, design it so sensitive data never enters the flow that could be characterised as a sale.\n\n**On voice recordings specifically:** most state definitions treat biometric data as data processed *for the purpose of uniquely identifying* an individual. A voice recording captured to be transcribed and analysed for content is not ordinarily biometric processing, because identification is not the purpose. That is a meaningful distinction for any team running voice interviews — but write the purpose down explicitly, keep voiceprint-style matching out of your stack, and check Maryland separately, since its biometric and consumer health data definitions are stricter than most.\n\n## Step 3 — Data minimisation is now a design constraint\n\nOlder state laws tied minimisation to disclosed purposes. Maryland changed the shape of the obligation: collection must be **reasonably necessary and proportionate**, and consent does not cure over-collection.\n\nFor research that argues against several common habits:\n\n- Recording video when the analysis only ever uses audio and transcript.\n- Retaining full recordings indefinitely because \"we might re-analyse later.\"\n- Importing an entire CRM export to personalise a study that needed three fields.\n- Capturing demographics you never cross-tabulate.\n\nThe defensible pattern is the boring one: collect the fields the analysis actually uses, keep raw recordings for a defined window, and keep the de-identified transcript and structured answers for the longer term. That also happens to be a better research archive, because structured answers stay comparable across studies while recordings rot.\n\n## Step 4 — Consent that meets the statutory definition\n\nState laws converge on the same consent standard: a clear affirmative act that is freely given, specific, informed and unambiguous. Consent obtained through dark patterns is not valid consent, and several laws say so explicitly.\n\nResearch consent is usually easier to get right than product consent because the context is transparent. Present the purpose, the recording, the retention period, who sees the data, and the withdrawal route on one screen before the interview begins, with a single affirmative action. Avoid pre-ticked boxes, bundled consents that mix research with marketing, and any design where declining is harder than accepting.\n\nWhere sensitive data is genuinely part of the study — health research, financial hardship research — take a separate, specific opt-in for that category rather than folding it into a general consent.\n\n## Step 5 — Rights requests reach into your transcripts\n\nAccess, correction, deletion and portability rights apply to research data held about an in-scope consumer, and a deletion request is the one that finds the weak point in most research operations. A transcript typically lives in more than one place: the platform, an export, a slide, a repository, a shared drive.\n\nBefore you need it, you should be able to answer: where does participant data live, how is a participant located across those stores, what is the deletion runbook, and what do you retain in de-identified form afterwards? De-identified data generally falls outside these laws — but only if it is genuinely de-identified, you commit not to re-identify it, and you bind recipients to the same.\n\n## Step 6 — Is sending transcripts to a vendor a \"sale\"?\n\n\"Sale\" is defined broadly in most states — the exchange of personal data for monetary or other valuable consideration — and this is the provision that most often surprises research teams.\n\nDisclosures to a **processor or service provider** acting on your documented instructions are not sales, provided the contract carries the required terms: process only on instructions, no use for the vendor's own purposes, no selling on, confidentiality, deletion or return at the end, and flow-down to sub-processors. Get those contract terms in place with every platform, transcription service and analysis tool that touches interview data, and the sale question resolves cleanly.\n\nTwo arrangements to look at carefully: any tool that trains its own models on your interview content for its own benefit, and any panel or data partner that receives participant data as part of a commercial exchange.\n\nUniversal opt-out mechanisms such as Global Privacy Control — now honoured under around a dozen state laws including California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, New Jersey, New Hampshire, Oregon and Texas — are a website obligation about sales and targeted advertising. They rarely touch a research programme directly, but they do matter if you recruit participants through advertising.\n\n## The pragmatic answer: build to the strictest standard once\n\nMaintaining twenty variants of a research process is not viable. Build one, tuned to the strictest provision in each dimension:\n\n| Dimension | Build to |\n|---|---|\n| Scope | Assume California applies (B2B and employment included) |\n| Sensitive data | Opt-in consent, and never in a sale — Maryland standard |\n| Minimisation | Reasonably necessary and proportionate — Maryland standard |\n| Consent quality | Freely given, specific, informed, unambiguous; no dark patterns |\n| Retention | Defined window for raw recordings; de-identified archive after |\n| Vendors | Processor terms with every tool touching interview data |\n| Rights | A documented, tested deletion runbook across every store |\n\nA single process at that level satisfies all twenty and most of GDPR besides, and it costs far less than tracking divergence state by state.\n\n## Common mistakes\n\n- Applying consumer privacy analysis to B2B interviews that are out of scope everywhere except California, and drowning the programme in unnecessary process.\n- Assuming the reverse — that B2B is always exempt — and forgetting California entirely.\n- Treating consent as the whole obligation, when minimisation, retention and rights carry equal weight.\n- Recording video by default when the analysis never uses it.\n- Sending transcripts to tools without processor terms in place.\n- Calling data anonymised when it still contains names, employers and identifiable circumstances in the transcript body.\n- Having no deletion runbook until a request arrives.\n\n## Frequently asked questions\n\n**Do US state privacy laws apply to B2B user research?**\nGenerally not, outside California. Every other comprehensive state law defines a consumer as a resident acting in an individual or household context and excludes people acting in a commercial or employment context. California is the exception: the CCPA covers B2B contacts and employees, and the partial exemptions for that data expired on 1 January 2023. Since most US-national research includes California residents, many teams design to the California standard regardless.\n\n**How many US states have comprehensive privacy laws in 2026?**\nTwenty are on the books as of early 2026, with more added as each legislative session closes. Indiana, Kentucky and Rhode Island took effect on 1 January 2026, Maryland took effect on 1 October 2025 and became enforceable in April 2026, and further changes land in Connecticut, Arkansas and Utah on 1 July 2026.\n\n**Is a recorded research interview biometric data?**\nUsually not. Most state definitions treat biometric data as data processed for the purpose of uniquely identifying an individual, and a recording captured to be transcribed and analysed for content is not being processed for identification. Write that purpose down explicitly, keep voiceprint matching out of your stack, and check Maryland separately because its biometric and consumer health data definitions are stricter than most states.\n\n**Does sharing interview transcripts with a research platform count as a sale of personal data?**\nNot when the platform acts as a processor or service provider under a contract with the required terms: processing only on your documented instructions, no use for its own purposes, no onward selling, confidentiality, deletion or return at the end, and flow-down to sub-processors. Look carefully at any tool that trains its own models on your interview content, and at panel or data partners receiving participant data as part of a commercial exchange.\n\n**What is different about the Maryland Online Data Privacy Act?**\nThree things matter for research. Data collection must be reasonably necessary and proportionate, and consent does not cure over-collection. The sale of sensitive personal data is banned outright regardless of consent, which is the strictest such rule in the country. And its definitions of biometric data, consumer health data and sensitive personal data are broader than most states, alongside a low 35,000-consumer applicability threshold.\n\n**Do we need a separate research process for every state?**\nNo, and it is not sustainable to try. Build one process to the strictest provision in each dimension — California scope, Maryland minimisation and sensitive-data handling, statutory consent quality, defined retention, processor terms with every vendor, and a tested deletion runbook. A single process at that level satisfies all of them and most of GDPR as well.\n\n## Related resources\n\n- [Structured Questions Guide](/docs/structured-questions-guide) — collecting countable answers without over-collecting personal data\n- [CCPA/CPRA Compliance for Customer Research](/docs/ccpa-user-research-compliance) — the California-specific detail behind the scope rule\n- [GDPR-Compliant AI User Research](/docs/gdpr-compliant-ai-user-research) — the European equivalent of this analysis\n- [DSARs for Research Data](/docs/dsar-research-data) — handling access, deletion and portability requests\n- [Anonymizing Customer Interview Data](/docs/anonymizing-customer-interview-data) — what genuine de-identification requires\n- [Research Data Retention and Deletion](/docs/research-data-retention-deletion) — setting defensible retention windows\n- [Interview Recording Consent Laws](/docs/interview-recording-consent-laws) — the separate one-party and two-party consent regime","category":"Research Operations","lastModified":"2026-08-01T03:21:55.717966+00:00","metaTitle":"US State Privacy Laws for Customer Research: 2026 Compliance Guide","metaDescription":"What twenty US state privacy laws require of research interviews: the B2B and employment scope rule, sensitive data opt-in, Maryland minimisation, deletion rights over transcripts, and processor terms.","keywords":["US state privacy laws customer research","VCDPA research compliance","Colorado Privacy Act research","Maryland Online Data Privacy Act","state privacy law research consent","sensitive data opt-in consent","B2B exemption state privacy law","research data deletion rights"],"aiSummary":"Twenty US states have comprehensive consumer privacy laws on the books as of early 2026. The decisive scope question for research is whether a participant is a consumer: every comprehensive state law except California defines a consumer as a resident acting in an individual or household context and excludes people acting in a commercial or employment context, so B2B research participants and employees fall outside those laws. California is the exception because the CCPA covers B2B contacts and employees after the partial exemptions expired on 1 January 2023. Key 2026 dates: Maryland MODPA in effect 1 October 2025 and enforceable April 2026; Indiana, Kentucky and Rhode Island effective 1 January 2026 along with Oregon amendments, expanded California data broker and health data rules, the Nebraska Age-Appropriate Design Code and the Texas Responsible AI Governance Act; further changes in Connecticut, Arkansas and Utah on 1 July 2026; new California data broker registration obligations on 1 August 2026. Rhode Island and Maryland apply at 35,000 consumers against Oregon 100,000. Most laws require opt-in consent for sensitive data including health, race, religion, sexual orientation, immigration status, precise geolocation and biometric data processed to identify someone, and open-ended interviews collect such data accidentally. Maryland bans the sale of sensitive personal data outright regardless of consent and requires collection to be reasonably necessary and proportionate, which consent cannot cure. Voice recordings analysed for content are not ordinarily biometric data because identification is not the purpose. Disclosures to a processor or service provider under contract terms covering documented instructions, no independent use, no onward sale, confidentiality, deletion or return and sub-processor flow-down are not sales. Universal opt-out mechanisms such as Global Privacy Control are honoured in around a dozen states but are a website and advertising obligation rather than a research one. The practical answer is a single research process built to the strictest provision in each dimension rather than twenty state variants.","aiPrerequisites":["Research participants who are US residents","A view of where interview recordings, transcripts and exports are stored","Vendor contracts for every tool that processes interview data"],"aiLearningOutcomes":["Determine whether a research participant is a consumer under state privacy law","Apply the B2B and employment scope rule correctly, including the California exception","Handle sensitive data that interviews collect unintentionally","Meet the Maryland data minimisation and sensitive-data sale standards","Distinguish processor disclosures from a sale of personal data","Build one multi-state research process instead of twenty state variants"],"aiDifficulty":"advanced","aiEstimatedTime":"13 min read"}],"pagination":{"total":1,"returned":1,"offset":0}}