There Is No Single GDPR in the U.S.: How a Ukrainian Website or SaaS Can Identify Applicable Privacy Laws

Protection of personal data in accordance
4.9
Based on 700 reviews in Google

Reviews of our Clients

Your Ukrainian SaaS has just landed its first U.S. customer. Your lawyer (or you) thinks: “We already have a GDPR policy. We’ll just adapt it for the CCPA, and that should take care of it.”

But when you open California law, you realize that the logic is entirely different: instead of a single supranational framework like Europe has, there is a tangle of dozens of state laws, each with its own applicability thresholds, definitions of “data sale,” and exemptions. What works in Colorado may not apply in Texas at all, and vice versa.

There is no single general privacy law in the United States that applies to all companies. Ukrainian businesses need to review state laws, federal rules for specific sectors and types of data, and their own public privacy promises at the same time. The starting point should not be copying a CCPA policy, but mapping U.S. users, applicability thresholds, advertising technologies, and the company’s role in each data flow.

A European GDPR compliance program can provide a solid foundation: data mapping, vendor oversight, security, and request-handling procedures. But it does not automatically address state-law concepts of data “sale” and “sharing,” universal opt-out signals, local exemptions, employee data, or special federal regimes.

In this article, we explain how to systematically determine which laws apply to your product and what to do with the results of that analysis.

Why One “U.S. Privacy Policy” Does Not Work

Congress has not enacted a single comprehensive federal law comparable to the GDPR. Instead, the U.S. has:

  • comprehensive laws in individual states;
  • federal laws for certain sectors or types of data;
  • state laws on biometrics, consumer health data, call recording, breach notifications, and other specific issues;
  • Federal Trade Commission authority to address unfair or deceptive practices.

As a result, a single activity may be regulated by several regimes. For example, a wellness app is not necessarily subject to HIPAA, but it may fall under a state consumer health data law, a comprehensive privacy law, and Federal Trade Commission requirements. An advertising pixel may simultaneously affect privacy disclosures, the right to opt out of targeted advertising, and the contract with the advertising technology provider.

Five Steps for Determining Applicability

If you own or run a Ukrainian SaaS company, website, mobile app, or similar project and work with U.S. customers, users, or advertising platforms, you need to know how to determine which rules and requirements may apply to your business.

Step 1: Identify the States with Which You Have a Real Connection

Collect information about a user’s state of residence from sources the business already has a legitimate reason to use: a shipping or billing address, the selected country and state, and contractual information. An IP address can be a supplementary signal, but it does not always identify residence accurately.

Consumers, employees, applicants, and representatives of business customers should be considered separately. Most state laws focus on individuals acting in a personal or household context. California is an important exception: its regime also covers certain employee, applicant, and business-contact data.

What if the user’s state is unknown

If the company cannot reliably determine the state of residence for some users, this step should not be skipped. In the applicability matrix, those records should be marked as “state unknown,” with a separate note identifying which conclusions cannot yet be reached as a result.

First, review the data the business already has a legitimate reason to collect: the billing or shipping address, the state provided at registration, contractual information, and payment-profile data. An IP address should be used only as a supplementary signal. If the available data is insufficient, consider adding a minimally necessary state field and explaining why it is collected.

Until reliable statistics are available, the company should not claim that the laws of particular states do not apply to it. A practical interim approach is to establish a common baseline set of U.S. rules, flag states that remain unknown, and recalculate the thresholds once sufficient data has been collected.

Step 2: Check Each State’s Thresholds

The California CCPA applies to a for-profit entity that does business in California, determines the purposes and means of processing consumers’ personal information, and meets at least one of the prescribed criteria. These include:

  • annual gross revenue over USD 26,625,000—this threshold has applied since January 1, 2025 following indexation;
  • annually buying, selling, or sharing the personal information of at least 100,000 consumers or households;
  • deriving at least 50 percent of annual revenue from selling or sharing consumers’ personal information.

Other states use different models. In Colorado, the law covers entities that conduct business in the state or intentionally provide goods or services there and process the data of more than 100,000 consumers during a calendar year, or process the data of at least 25,000 consumers and receive compensation or a discount from the sale of data.

Texas law uses a different structure: it applies to persons that conduct business in Texas or produce a product or service consumed by Texas residents and process personal data. Small businesses as defined by the federal Small Business Administration are generally exempt, but even they are subject to a separate consent requirement before selling sensitive data.

These three examples show why a company’s revenue or total number of U.S. users cannot simply be plugged into a single test.

Step 3: Check the Sector and Type of Data

Even if a comprehensive state privacy law does not apply, special rules may still apply:

  • COPPA—for online services directed to children under 13, or services that knowingly collect their data;
  • HIPAA—for certain healthcare organizations and their business associates, not every product that contains health information;
  • Gramm-Leach-Bliley Act and the Federal Trade Commission Safeguards Rule—for certain financial institutions;
  • Fair Credit Reporting Act—for data and decisions in the consumer reporting context;
  • federal and state rules governing emails, text messages, calls, and recording communications.

Biometrics, precise geolocation, reproductive health, and children’s data require additional state-by-state analysis. A generic “sensitive data” label is not a substitute for analyzing the specific law.

Step 4: Determine Who Is the Controller, Processor, Contractor, or Service Provider

A U.S. SaaS customer may require contractual restrictions on data use, assistance with consumer requests, oversight of subprocessors, and evidence of security measures. California terminology and contract requirements do not fully align with the GDPR controller/processor model.

Advertising and analytics integrations require particular attention. Transmitting an identifier, browsing history, or a conversion event may be treated as a “sale” or “sharing” for targeted advertising even when the company does not receive money directly in exchange for a data file.

Step 5: Compare the Policy with How the Product Actually Operates

The Federal Trade Commission applies Section 5 of the Federal Trade Commission Act to unfair or deceptive practices. If a company promises not to disclose data, to delete it within a certain period, or to use encryption, but the product operates differently, the policy itself can become evidence of an unfulfilled promise.

Before publication, the company should technically review cookies, third-party software development kits, logs, backups, advertising accounts, and support services.

Do you need professional help with this matter?
Submit a request, and we will find the optimal solution for your situation.
Order a service

How the Five Steps Work in Practice

Let’s see how these steps work. Suppose a hypothetical Ukrainian company, TaskFlow UA, sells subscriptions to a project management service directly to users in the United States. According to payment-profile data, during the year the service had 110,000 users residing in Colorado, 75,000 in California, and 20,000 in Texas. The company’s annual gross revenue is USD 8 million. The website uses analytics tools and an advertising pixel. The company does not collect health, credit, or children’s data.

We apply Step 1. The company confirmed its connection with Colorado, California, and Texas using payment and account data. Users whose state cannot be determined remain in a separate group rather than being arbitrarily assigned to a particular state.

We apply Step 2. For Colorado, the quantitative threshold is potentially met because the service has more than 100,000 state residents. For California, the threshold has not yet been established under the assumptions given: the corporate group, the exact number of instances involving sale or sharing of data, and the nature of the advertising integrations require further review. For Texas, small-business status must be assessed separately.

We apply Step 3. Under the facts of the example, special regimes for health, children’s, or credit data are not the primary route. The conclusion should be revisited if the product begins collecting those categories of information.

We apply Step 4. For its own accounts, analytics, and advertising, TaskFlow UA determines the purposes for which data is used. If the company also processes end-user information solely on the instructions of a business customer, its role and contractual obligations for that data flow must be assessed separately.

We apply Step 5. The review shows that the advertising pixel transmits identifiers and events that are not disclosed in the current privacy notice, while the website does not process the GPC signal. The documents do not match how the product actually operates.

What conclusion should be drawn after the five steps: the company needs a Colorado module, an operational request and opt-out mechanism, GPC handling, an updated privacy notice, and a review of advertising integrations and vendor contracts. The applicability of California and Texas law cannot be determined conclusively without additional facts.

This is, of course, a hypothetical example, but it shows how our lawyers apply the five-step framework in practice.

Related: Business Registry Monitoring: How to Identify Financial Risks Early

What Should Be in Place After the Assessment

Privacy Notice

The notice should describe the actual categories of data, purposes, recipients, sale or sharing, retention periods or the criteria used to determine them, rights, and methods for submitting requests. Additional disclosures may be required for particular states or categories of data.

A notice could read as follows:

“When you register, we collect your email address, account identifier, the state you provide, and information required for payment. We use this data to create your account, provide the service, support you, and perform our contractual obligations. Information about disclosures to vendors, advertising technologies, retention periods, and available ways to exercise your rights is provided in our privacy notice. If applicable law gives you the right to opt out of the sale, sharing, or use of data for targeted advertising, use the “Privacy Settings” link.”

This text is displayed before or at the time of collection, for example next to the registration form. It is only an illustration: the data categories, purposes, recipients, retention periods, links, and rights must be adapted to how the product actually operates and to the applicable law.

Consumer Requests

The company must accept, verify, and fulfill requests for access, correction, deletion, portability, and opt-out rights to the extent required by applicable law. Some states also require a process for appealing a denial.

For an online service, this should be an operational workflow among support, legal, engineering, and security teams—not merely an email address listed in the policy.

Opting Out of Sale, Sharing, and Targeted Advertising

Prominent opt-out controls may be required on the website or in the app. Colorado recognizes Global Privacy Control as a universal mechanism through which a consumer automatically communicates an opt-out from the sale of data or its use for targeted advertising. Other states require similar signals, so a cookie banner that does not technically process the signal may be insufficient.

Sensitive Data and Risk Assessment

State laws may require prior consent to process sensitive data and a data protection assessment for targeted advertising, sale, certain profiling, or other high-risk processing. California has its own rules on limiting the use of sensitive personal information, and starting in 2026 updated rules on risk assessments, cybersecurity audits, and automated decision-making technologies apply to entities that meet the prescribed criteria.

Contracts and Security

Vendor agreements should define the purposes and limits of use, confidentiality, security measures, assistance with requests, conditions for engaging subsequent service providers, and the return or deletion of data. Technical measures should reflect the nature of the data and the company’s actual promises.

Why You Cannot Simply Rename GDPR as CCPA

The GDPR requires a legal basis for each processing activity and establishes a single supranational framework. Comprehensive U.S. state privacy laws more often structure control around transparency, consumer rights, opt-outs from sale or targeted advertising, sensitive data, and contractual restrictions.

Practical differences include:

  • applicability criteria and exemptions;
  • coverage of employees and business contacts;
  • definitions of sale, sharing, and targeted advertising;
  • universal opt-out signals;
  • response deadlines and appeal procedures;
  • a private right of action in specified cases;
  • sector-specific and special state laws.

For Ukrainian businesses, the best model is therefore a common operational core plus controlled state-specific addenda. The core covers data mapping, individual rights, security, retention periods, vendors, and incidents. The addenda set out thresholds, exemptions, special notices, opt-out mechanisms, and local deadlines. The matrix should be reviewed before entering a new state, launching a new category of data, or changing advertising technologies.

Where a Ukrainian Company Should Start

The first deliverable should be concise and verifiable:

  • a list of states and sectors that may apply;
  • threshold calculations;
  • a map of high-risk data flows;
  • a list of product gaps and a prioritized remediation plan.

Only then should the company prepare notices, contracts, and technical settings.

The lawyers at Pravova Dopomoga can assess the applicability of U.S. laws, audit a website or SaaS product, prepare a core package and state-specific addenda, and align the legal requirements with the technical team.

Contact us if you want to operate safely in Ukraine and abroad!

You can contact us through the service request form on the page “Personal Data Protection for Businesses” or by any other convenient method.

Publication date: 23/09/2026


Our clients



We are ready to help you!

Contact us by mail [email protected] or by filling out the form:
Edgar Simonyan

About author

Name: Edgar Simonyan

Position: Lead / Senior Attorney & Practice Development Lead

Education: Master’s Degree, East European University of Economics and Management

Knowledge of languages: Ukrainian, Russian, Armenian, English, Spanish

Email: [email protected]

Write to the author

Our other authors

Volodymyr Gurlov
Strategic Advisor
Marina Losenko
Associate
Edgar Simonyan
Lead / Senior Attorney & Practice Development Lead