The era of a unified U.S. state privacy law has ended. In 2024, seven states passed new privacy laws, bringing the total to 19. These laws diverged from the Washington State Privacy Act framework that previously shaped legislation. This shift, known as the end of "Pax Washingtonia," means your compliance program can no longer rely on a single playbook.
What Changed in 2024
Until 2023, the Washington State Privacy Act served as a template for most state privacy laws. States copied its structure for data subject rights, processing restrictions, and enforcement mechanisms. This consistency allowed you to build one compliance framework and make minor adjustments across jurisdictions.
In 2024, this pattern broke. The seven new state laws introduced variations in scope, rights, exemptions, and enforcement triggers. Keir Lamont of the Future of Privacy Forum and David Stauss of Husch Blackwell highlight this as a fundamental change in state privacy regulation.
Key Findings
1. Compliance mapping now requires jurisdiction-by-jurisdiction analysis
Your California Privacy Rights Act controls won't necessarily satisfy requirements in Kentucky or Montana. Each of the 19 state laws includes distinct provisions for:
- Revenue and data volume thresholds
- Categories of sensitive data requiring Consent consent
- Exemptions for specific industries or data types
- Timelines for responding to data subject access requests
- Requirements for privacy notices and consent mechanisms
2. Enforcement priorities vary by state attorney general
State attorneys general are signaling different enforcement priorities. Some focus on consent mechanisms and opt-out rights, while others prioritize data security practices or vendor management. This fragmentation means your risk profile changes based on where you operate and what data you process.
3. Rulemaking timelines are unpredictable
Unlike the GDPR, U.S. state privacy laws lack a central coordination mechanism. Each state's attorney general or designated agency writes rules on their own schedule. You're now tracking 19 separate rulemaking processes with different public comment periods, effective dates, and revision cycles.
4. Standardized contract language no longer covers all jurisdictions
The data processing addenda you negotiated with vendors likely reference "applicable state privacy laws" in general terms. Now you need jurisdiction-specific provisions for:
- Processor obligations that vary by state
- Data retention requirements
- Audit rights
- Sub-processor notification requirements
5. Multi-state operations face compounding complexity
If you process data from residents in multiple states, you're managing overlapping but non-identical requirements. For example, a SaaS platform with users in California, Virginia, Colorado, Connecticut, and Utah faces different definitions of "sensitive data" and rules for processing children's data.
What This Means for Your Team
The fragmented landscape requires a shift from a compliance checklist to a risk-based framework. Here's what that looks like:
Map your data flows by state jurisdiction. You need visibility into where your data subjects are located and which state laws apply to each processing activity.
Build state-specific control variations. Your consent management platform needs to serve different Consent and opt-out mechanisms based on user location. Your DSAR workflow needs conditional timelines. Your vendor contracts need jurisdiction-specific clauses.
Monitor rulemaking in every state where you operate. Subscribe to attorney general announcements. Track proposed rules through public comment periods. Adjust your controls before enforcement dates.
Document your compliance decisions by jurisdiction. When implementing a requirement that's ambiguous or undefined, document your reasoning. If an attorney general later issues guidance that contradicts your approach, you'll need to show you made a good-faith interpretation.
Action Items by Priority
Immediate (next 30 days):
- Audit which of the 19 state laws apply to your organization
- Identify gaps between your current controls and state-specific requirements
- Update your privacy notice to reflect the most restrictive disclosure requirements
Short-term (60-90 days):
- Revise data processing agreements to include state-specific processor obligations
- Configure your consent management and DSAR tools for jurisdiction-specific variations
- Establish a rulemaking monitoring process with assigned owners for each applicable state
Medium-term (6 months):
- Build a compliance matrix mapping each state's requirements to your controls
- Conduct vendor assessments focused on multi-state compliance
- Train your privacy team on jurisdiction-specific requirements
Ongoing:
- Review new state legislation quarterly
- Track enforcement actions and adjust your risk assessment
- Update your compliance matrix as states issue new rules or guidance
The end of Pax Washingtonia doesn't make state privacy law unmanageable. It requires more granular visibility into your data practices and flexible controls. Organizations that adapt their compliance programs now will be better positioned for future changes.



