some of these laws are pretty braindead though. here's a good one:
A California law passed in 2003 requires that any company that does business in California must notify their California customers if they discover or suspect that nonencrypted data has been accessed without authorization. This applies even if the business is not located in California, as long as you have customers there, and no exception is made for small businesses.
that's all very well, but how will California enforce this? If my business is in Edinburgh, and for some reason i have a large client base in California, then for some reason i fail to comply with this law, how is California going to prosecute me? Will it apply to Westminster for my extradition to the USA, a country i have never visited? Doubtful.
Pass as many laws as you like, if they're dumb laws, they won't help anybody.