US State Privacy Laws for Customer Research: The Multi-State Compliance Guide (2026)
Twenty states now have comprehensive privacy laws and they do not agree with each other. Here is what actually applies to research interviews, why most B2B participants fall outside every law except California, and how to build one compliant process instead of twenty.
Two facts reshape most research teams' compliance work once they are understood. First, outside California, your B2B research participants are almost certainly not "consumers" under any state privacy law — every other comprehensive state law excludes individuals acting in a commercial or employment context. Second, when the laws do apply, the provisions that bite in research are narrow and predictable: opt-in consent for sensitive data, deletion and access rights over transcripts, data minimisation, and whether handing recordings to a vendor counts as a sale.
Everything else in the state privacy landscape — universal opt-out signals, targeted advertising opt-outs, data broker registration — is a website and adtech problem, not a research problem. Knowing which is which is what keeps a research programme from being reviewed as if it were a marketing pixel.
The 2026 landscape
Twenty states have comprehensive consumer privacy laws on the books as of early 2026, and the count keeps rising as each legislative session closes; some trackers already count higher after the mid-2026 wave. The dates that matter for anyone re-papering their process this year:
| Date | What changed |
|---|---|
| 1 Oct 2025 | Maryland Online Data Privacy Act in effect (enforceable from April 2026) |
| 1 Jan 2026 | Indiana, Kentucky and Rhode Island comprehensive laws take effect |
| 1 Jan 2026 | Oregon amendments (HB 2008); California expanded data broker and health data rules; Nebraska Age-Appropriate Design Code |
| 1 Jan 2026 | Texas Responsible AI Governance Act (HB 149) takes effect |
| 1 Jul 2026 | Further changes land in Connecticut, Arkansas and Utah |
| 1 Aug 2026 | New California data broker registration obligations |
Rhode Island is worth flagging because its applicability threshold is unusually low — processing the data of at least 35,000 consumers, or 10,000 if more than 20% of revenue comes from selling personal data. Maryland matches the 35,000 figure, against Oregon's 100,000. Threshold shopping is not a strategy; if you operate nationally you will cross a threshold somewhere.
Step 1 — Is your research participant a "consumer" at all?
This is the question to answer first, because it disposes of most B2B research entirely.
Every comprehensive state law except California's defines "consumer" as a resident acting in an individual or household context, and expressly excludes people acting in a commercial or employment context. Colorado, Connecticut, Utah and Virginia all take this approach, and the newer laws follow it.
California is the exception, and it is a total one. The CCPA as amended defines a consumer as any California resident — which includes employees, job applicants and B2B contacts. The partial exemptions for employee and B2B data expired on 1 January 2023 and have not returned.
What this means concretely:
- Interviewing a procurement manager at a customer account about your product, in her professional capacity: outside the scope of every state law except California's.
- Interviewing that same person about her personal banking app: a consumer, everywhere.
- Interviewing your own employees about an internal tool: outside every state law except California's.
- Interviewing a sole trader about the tools she uses to run her business: genuinely ambiguous, and worth treating as in-scope.
Two cautions before you relax. This analysis governs the state privacy laws only — recording consent laws, contractual obligations to your customers, sectoral rules like HIPAA, and GDPR for anyone in Europe all apply on their own terms. And if any of your participants are California residents, you are in scope regardless, which for most US-national research means designing to the California standard anyway.
Step 2 — Recognise the sensitive data you did not mean to collect
Nearly every state law requires opt-in consent before processing sensitive data, and Virginia, Connecticut, Colorado, Indiana, Kentucky and Rhode Island all take that approach. Sensitive categories typically include health conditions, racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, precise geolocation, and biometric data processed to identify someone.
The research problem is not that teams deliberately collect sensitive data. It is that open-ended interviews collect it accidentally. Ask a customer why she cancelled and she may tell you about a cancer diagnosis. Ask about a missed payment and you may hear about a divorce and an immigration status. None of that was on your discussion guide, and all of it is now in your transcript.
Three practical controls:
- Say so in the consent. State that the interview may touch on personal circumstances, that the participant should share only what they are comfortable with, and what happens to the recording.
- Redact on ingest, not at report time. Anonymisation applied when you write the summary leaves the raw transcript sitting in your system.
- Never let sensitive data leave in a "sale". Maryland goes furthest here: MODPA bans the sale of sensitive personal data outright, regardless of consent — the strictest sensitive-data rule in any US state law. If your process cannot guarantee that, design it so sensitive data never enters the flow that could be characterised as a sale.
On voice recordings specifically: most state definitions treat biometric data as data processed for the purpose of uniquely identifying an individual. A voice recording captured to be transcribed and analysed for content is not ordinarily biometric processing, because identification is not the purpose. That is a meaningful distinction for any team running voice interviews — but write the purpose down explicitly, keep voiceprint-style matching out of your stack, and check Maryland separately, since its biometric and consumer health data definitions are stricter than most.
Step 3 — Data minimisation is now a design constraint
Older state laws tied minimisation to disclosed purposes. Maryland changed the shape of the obligation: collection must be reasonably necessary and proportionate, and consent does not cure over-collection.
For research that argues against several common habits:
- Recording video when the analysis only ever uses audio and transcript.
- Retaining full recordings indefinitely because "we might re-analyse later."
- Importing an entire CRM export to personalise a study that needed three fields.
- Capturing demographics you never cross-tabulate.
The defensible pattern is the boring one: collect the fields the analysis actually uses, keep raw recordings for a defined window, and keep the de-identified transcript and structured answers for the longer term. That also happens to be a better research archive, because structured answers stay comparable across studies while recordings rot.
Step 4 — Consent that meets the statutory definition
State laws converge on the same consent standard: a clear affirmative act that is freely given, specific, informed and unambiguous. Consent obtained through dark patterns is not valid consent, and several laws say so explicitly.
Research consent is usually easier to get right than product consent because the context is transparent. Present the purpose, the recording, the retention period, who sees the data, and the withdrawal route on one screen before the interview begins, with a single affirmative action. Avoid pre-ticked boxes, bundled consents that mix research with marketing, and any design where declining is harder than accepting.
Where sensitive data is genuinely part of the study — health research, financial hardship research — take a separate, specific opt-in for that category rather than folding it into a general consent.
Step 5 — Rights requests reach into your transcripts
Access, correction, deletion and portability rights apply to research data held about an in-scope consumer, and a deletion request is the one that finds the weak point in most research operations. A transcript typically lives in more than one place: the platform, an export, a slide, a repository, a shared drive.
Before you need it, you should be able to answer: where does participant data live, how is a participant located across those stores, what is the deletion runbook, and what do you retain in de-identified form afterwards? De-identified data generally falls outside these laws — but only if it is genuinely de-identified, you commit not to re-identify it, and you bind recipients to the same.
Step 6 — Is sending transcripts to a vendor a "sale"?
"Sale" is defined broadly in most states — the exchange of personal data for monetary or other valuable consideration — and this is the provision that most often surprises research teams.
Disclosures to a processor or service provider acting on your documented instructions are not sales, provided the contract carries the required terms: process only on instructions, no use for the vendor's own purposes, no selling on, confidentiality, deletion or return at the end, and flow-down to sub-processors. Get those contract terms in place with every platform, transcription service and analysis tool that touches interview data, and the sale question resolves cleanly.
Two arrangements to look at carefully: any tool that trains its own models on your interview content for its own benefit, and any panel or data partner that receives participant data as part of a commercial exchange.
Universal opt-out mechanisms such as Global Privacy Control — now honoured under around a dozen state laws including California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, New Jersey, New Hampshire, Oregon and Texas — are a website obligation about sales and targeted advertising. They rarely touch a research programme directly, but they do matter if you recruit participants through advertising.
The pragmatic answer: build to the strictest standard once
Maintaining twenty variants of a research process is not viable. Build one, tuned to the strictest provision in each dimension:
| Dimension | Build to |
|---|---|
| Scope | Assume California applies (B2B and employment included) |
| Sensitive data | Opt-in consent, and never in a sale — Maryland standard |
| Minimisation | Reasonably necessary and proportionate — Maryland standard |
| Consent quality | Freely given, specific, informed, unambiguous; no dark patterns |
| Retention | Defined window for raw recordings; de-identified archive after |
| Vendors | Processor terms with every tool touching interview data |
| Rights | A documented, tested deletion runbook across every store |
A single process at that level satisfies all twenty and most of GDPR besides, and it costs far less than tracking divergence state by state.
Common mistakes
- Applying consumer privacy analysis to B2B interviews that are out of scope everywhere except California, and drowning the programme in unnecessary process.
- Assuming the reverse — that B2B is always exempt — and forgetting California entirely.
- Treating consent as the whole obligation, when minimisation, retention and rights carry equal weight.
- Recording video by default when the analysis never uses it.
- Sending transcripts to tools without processor terms in place.
- Calling data anonymised when it still contains names, employers and identifiable circumstances in the transcript body.
- Having no deletion runbook until a request arrives.
Frequently asked questions
Do US state privacy laws apply to B2B user research? Generally not, outside California. Every other comprehensive state law defines a consumer as a resident acting in an individual or household context and excludes people acting in a commercial or employment context. California is the exception: the CCPA covers B2B contacts and employees, and the partial exemptions for that data expired on 1 January 2023. Since most US-national research includes California residents, many teams design to the California standard regardless.
How many US states have comprehensive privacy laws in 2026? Twenty are on the books as of early 2026, with more added as each legislative session closes. Indiana, Kentucky and Rhode Island took effect on 1 January 2026, Maryland took effect on 1 October 2025 and became enforceable in April 2026, and further changes land in Connecticut, Arkansas and Utah on 1 July 2026.
Is a recorded research interview biometric data? Usually not. Most state definitions treat biometric data as data processed for the purpose of uniquely identifying an individual, and a recording captured to be transcribed and analysed for content is not being processed for identification. Write that purpose down explicitly, keep voiceprint matching out of your stack, and check Maryland separately because its biometric and consumer health data definitions are stricter than most states.
Does sharing interview transcripts with a research platform count as a sale of personal data? Not when the platform acts as a processor or service provider under a contract with the required terms: processing only on your documented instructions, no use for its own purposes, no onward selling, confidentiality, deletion or return at the end, and flow-down to sub-processors. Look carefully at any tool that trains its own models on your interview content, and at panel or data partners receiving participant data as part of a commercial exchange.
What is different about the Maryland Online Data Privacy Act? Three things matter for research. Data collection must be reasonably necessary and proportionate, and consent does not cure over-collection. The sale of sensitive personal data is banned outright regardless of consent, which is the strictest such rule in the country. And its definitions of biometric data, consumer health data and sensitive personal data are broader than most states, alongside a low 35,000-consumer applicability threshold.
Do we need a separate research process for every state? No, and it is not sustainable to try. Build one process to the strictest provision in each dimension — California scope, Maryland minimisation and sensitive-data handling, statutory consent quality, defined retention, processor terms with every vendor, and a tested deletion runbook. A single process at that level satisfies all of them and most of GDPR as well.
Related resources
- Structured Questions Guide — collecting countable answers without over-collecting personal data
- CCPA/CPRA Compliance for Customer Research — the California-specific detail behind the scope rule
- GDPR-Compliant AI User Research — the European equivalent of this analysis
- DSARs for Research Data — handling access, deletion and portability requests
- Anonymizing Customer Interview Data — what genuine de-identification requires
- Research Data Retention and Deletion — setting defensible retention windows
- Interview Recording Consent Laws — the separate one-party and two-party consent regime
Related Articles
Anonymizing Customer Interview Data: A Practical Guide for Privacy-Safe Research
Five operational techniques for handling PII in AI customer interviews — from intake-time anonymization to stakeholder-safe quote sharing — without sacrificing research signal.
CCPA/CPRA Compliance for Customer Research: The 2026 Practitioner Guide
Most US teams assume GDPR is the hard one and California takes care of itself. It does not. Here is what CCPA/CPRA actually requires for interviews, surveys, and voice research — the service provider contract that keeps your vendor out of "sale" territory, and the enforcement record that shows what regulators punish.
DSARs for Research Data: Handling Access, Deletion, and Portability Requests from Participants
A participant asks what you hold on them, or asks you to delete it. The clock is one month under GDPR and 45 days under CCPA. Here is what counts as their data in an interview study, why the research exemption rarely saves you, and a seven-step runbook.
GDPR-Compliant AI User Research: A Practical Guide
How to run AI-moderated customer interviews under GDPR. Lawful basis, consent flows, data minimization, retention, sub-processors, and how Koji handles each requirement.
User Research Privacy Laws Beyond GDPR and CCPA: Brazil, Canada, India, Japan, China and More
Most research compliance guidance stops at the EU and California. Here is what actually applies when you interview customers in Brazil, Canada, India, Japan, China, South Korea, Australia and South Africa — which law reaches you, what legal basis works, and the one design that satisfies all of them.
Interview Recording Consent Laws: One-Party, All-Party, and Biometric Rules (2026)
Federal law allows one-party consent recording, but roughly a dozen US states require all-party consent - and biometric laws like Illinois BIPA add a separate written-consent duty for voiceprints. Here is how research teams stay on the safe side of both.
Research Consent Form Templates: GDPR-Compliant Forms for Every Study
Ready-to-use consent form templates for user research, UX studies, and AI interviews. Covers GDPR compliance, informed consent best practices, and how to collect consent automatically with Koji.
Research Data Retention and Deletion: How Long Should You Keep Interview Data?
There is no universal legal number - which is exactly why having no retention schedule is itself the compliance failure. A tiered, per-artifact schedule for recordings, transcripts, quotes, and reports, plus how to handle deletion requests without losing your insights.
Structured Questions in AI Interviews
Mix quantitative data collection — scales, ratings, multiple choice, ranking — with AI-powered conversational follow-up in a single interview.