Ask most association leaders whether the new wave of state privacy laws applies to them, and you get a fast, confident answer. We are a nonprofit, so we are exempt. It is the most common thing I hear on this subject. In a growing number of states, it is also wrong. Not arguable. Wrong.

Start with the map. Roughly twenty states have a comprehensive consumer privacy law in force in 2026, and more than twenty have now passed one, up from a handful just two years ago.12 Most of those laws do carve out nonprofits, which is where the reflex comes from. But four of them do not carve nonprofits out at all. Colorado, Oregon, New Jersey, and Delaware extend no blanket nonprofit exemption.34 If you hold enough data on residents of those states, the law reaches your association the same way it reaches a company, tax status and mission included.

There is a second cut, and it lands hardest on trade and professional associations. Even among the states that do exempt nonprofits, several write that exemption for 501(c)(3) charities only. A 501(c)(6) business league or professional society is a nonprofit that many of those carve-outs were simply never drafted to cover.53 So the real question is not “are we a nonprofit.” It is two questions stacked: which state, and which kind of nonprofit. The single word on your tax filing answers neither one on its own.

What “nonprofit” actually buys you
Where your members liveWhat your nonprofit status gets you
Colorado, Oregon, New Jersey, DelawareNothing. No blanket nonprofit exemption. You are assessed on the same thresholds as any business.
States that exempt only 501(c)(3)Charities are covered by the exemption. 501(c)(6) trade and professional associations often are not.
Most of the remaining statesA broad nonprofit exemption, for now, though the drafting keeps narrowing with each new law.

Now the number that tells you whether any of this is yours to worry about. In the states where you are not exempt, the law applies once you cross a threshold, and the common one is the personal data of 100,000 residents in a single year, dropping to 25,000 if a large share of your revenue comes from selling that data.6 A national association with tens of thousands of members, plus everyone who ever registered for an event, downloaded a report, or landed on a mailing list, clears 100,000 records more easily than its leaders expect. The threshold counts people whose data you hold, not dues payers.

What changed this year is the safety net. For most of these laws’ short lives, a violation came with a cure period, a quiet window to fix the problem after a complaint before any penalty attached. In 2026 that window is closing. Delaware’s mandatory cure period expired on January 1. New Jersey’s ended July 1, so its attorney general can now move from inquiry to enforcement with no guaranteed chance to remediate. Colorado and Rhode Island never offered one at all.78 The thing that made this easy to defer, the quiet assumption that you would get a warning first, is being taken off the table.

The afternoon version

Here is the part you can do this week, with no budget, no vendor, and no help from IT. Open your AMS and your email platform and count your people by state of residence. You are after one number: how many records you hold on residents of the states that do not exempt you. Put Colorado, Oregon, New Jersey, and Delaware at the top of the list. If any single one of them clears roughly 100,000 records, treat yourself as in scope there and move on to what the law asks for. Your nonprofit status will not move that answer.

There is a wrong way to run this check, and it is the tempting one: email your AMS vendor, ask “are we compliant,” and file the reply. Every vendor says yes, because compliance is the association’s legal obligation and not the software’s, and “we are SOC 2 certified” answers a security question you did not ask. What you actually want out of this is a one-page count, by state, that you generated. If what comes back is a reassurance instead of a number, you have learned nothing. A real check produces a fact you did not have before.

That count leads straight to the one artifact every one of these laws quietly assumes you already keep: a data inventory. Every place you collect personal data, the join form, event registration, the AMS, the email tool, the website, and for each, what you collect and why.9 It is unglamorous, and it is the whole game. We have written before about the AI policy nobody could prove worked. This is the same shape. The document on the shelf is not the control. Knowing where the member data actually lives is the control.

The inventory also does something the statutes do not require but you will be glad for. It shows you the data you are keeping for no reason. Data minimization, collecting less and holding it for less time, is the cheapest compliance posture there is, because a field you never collected is one you never have to secure, explain, or delete when a member asks. And a member will ask. If you cannot produce a clean count of your own people by state, you also cannot answer the resident who writes to ask what you hold on them, which is the right most of these laws actually grant. That is the discipline we keep coming back to: member data you can actually see. The privacy laws just turned it from good practice into the kind of thing an attorney general can ask about, at the same moment your members have started asking machines what you know about them.

Quick takes

The signal you are probably ignoring lives on your public site, not in your AMS. As of January 2026, twelve states require businesses to honor the Global Privacy Control, a browser setting that tells every site “do not sell or share my data,” and California, Colorado, and Connecticut have been running a coordinated sweep for sites that ignore it.10 Most association websites have never been checked for whether they detect the signal at all. It is a five-minute question for whoever runs your web platform, and the answer is either yes or a finding.

California went furthest, and its direction of travel is the tell. The state’s privacy agency finalized rules, effective January 2026, on automated decision-making, risk assessments, and cybersecurity audits.11 Most associations sit under California’s size thresholds and will not be directly bound. But every requirement rests on the same foundation: documenting what you collect, why, and what you do with it. The states are converging on the data inventory whether or not any one of them catches you first.

The cheapest item on this whole list is collecting less. Every custom field on your join form, every “just in case” question on an event registration, is data you now have to secure, explain, and be able to delete on demand. Minimization is not a project. It is a decision to stop asking for things you never use, and it shrinks your risk and your inventory in the same stroke.

Worth a read

MultiState: the comprehensive privacy laws in effect in 2026. The clearest running map of which states are live and on what dates. Start here to see whether your biggest membership states are on it.

Wiley: New State Privacy Laws May Apply to Nonprofit Organizations. A plain-language legal read on exactly why “we are a nonprofit” is not the shield most associations assume it is.

CIPA World: the end of the cure period. Why 2026 is the year the warning-shot era of privacy enforcement closes, state by state.

Here is my prediction. The first association to land in a privacy complaint that makes the rounds will not be the one with the worst data practices. It will be the one that read the word nonprofit in a statute and stopped reading there.

Quick answers

Do state privacy laws apply to nonprofits?

Sometimes. Most state privacy laws exempt nonprofits, but Colorado, Oregon, New Jersey, and Delaware do not, and several other states exempt only 501(c)(3) charities rather than 501(c)(6) trade and professional associations. Whether you are covered depends on the state and your nonprofit type, not on the word nonprofit.

How do I know if my association has to comply?

In the states that do not exempt you, you comply if you cross that state’s threshold, commonly the personal data of 100,000 residents in a year, or 25,000 if a large share of your revenue comes from selling data. Count your members and contacts by state of residence, then compare those counts against the states with no nonprofit exemption. It is a spreadsheet exercise, not an IT project.

What is the single most useful first step?

Build a plain data inventory: every place you collect personal data, from web forms and event registration to the AMS and email tools, what you collect, and why. It answers the compliance questions directly, and it surfaces data you are storing for no reason, which is the cheapest risk to remove.