State Privacy Law Applicability and Readiness Checklist: Thresholds, Notices, Rights Workflow, Assessments, and Processor Terms

By ·

This checklist establishes whether a company is actually subject to the comprehensive state privacy statutes, then builds the capability to comply with them, in the order the work has to happen rather than the order the statutes are written in. It opens with the pixel inventory, because the wiretap and video-privacy theories are the live litigation exposure while the privacy statutes are enforced slowly. It then builds the data map and identity resolution that every downstream obligation depends on, runs the applicability and exemption analysis per state, and forces the residency decision that determines whether the program is national or segmented. It specifies the rights workflow with proportionate verification, the deletion policy reconciled against records needed to defend other claims, the consent and tag layer where universal opt-out signals actually live, and the processor rider. Gates mark items that should clear before any new system receives personal data.

IP and Technology > Privacy Data Security | Checklist | Published 10 November 2025 - Updated 18 March 2026 | Casey Scott McKay - marksy.us

Summary. This checklist establishes whether a company is actually subject to the comprehensive state privacy statutes, then builds the capability to comply with them, in the order the work has to happen rather than the order the statutes are written in. It opens with the pixel inventory, because the wiretap and video-privacy theories are the live litigation exposure while the privacy statutes are enforced slowly. It then builds the data map and identity resolution that every downstream obligation depends on, runs the applicability and exemption analysis per state, and forces the residency decision that determines whether the program is national or segmented. It specifies the rights workflow with proportionate verification, the deletion policy reconciled against records needed to defend other claims, the consent and tag layer where universal opt-out signals actually live, and the processor rider. Gates mark items that should clear before any new system receives personal data.

Keywords: pixel inventory · tag ownership · data map · identity resolution · applicability thresholds · exemption analysis · residency determination · rights intake · verification proportionality · deletion and backups · retention conflict · consent gating · universal opt-out signals · sensitive data controls · data protection assessments · processor register · statutory rider · subprocessor evidence · notice versioning · regulator readiness


How to use this checklist

| Phase | What it covers | |---|---| | 1 | The pixel inventory, first | | 2 | Tag ownership and gating | | 3 | The data map | | 4 | Identity resolution | | 5 | Applicability thresholds | | 6 | Exemption analysis | | 7 | The residency decision | | 8 | Rights intake | | 9 | Verification proportionality | | 10 | Deletion execution | | 11 | The retention conflict | | 12 | Consent gating | | 13 | Universal opt-out signals | | 14 | Sensitive data controls | | 15 | Data protection assessments | | 16 | The processor register | | 17 | The statutory rider | | 18 | The notice, written last | | 19 | Regulator readiness | | 20 | Special situations | | 21 | Metrics and the annual cycle | | 22 | Ownership |

Boxes marked [Gate] should clear before any new system, vendor, or tag receives personal data.

The matter. A retailer with eleven million customer records and no data map found forty-one systems where twenty-six had been listed, sixty-eight tags of which nineteen were unaccounted for, and four systems that could not be searched by person at all.


Phase 1. The pixel inventory, first


Phase 2. Tag ownership and gating


Phase 3. The data map


Phase 4. Identity resolution


Phase 5. Applicability thresholds


Phase 6. Exemption analysis


Phase 7. The residency decision


Phase 8. Rights intake


Phase 9. Verification proportionality


Phase 10. Deletion execution


Phase 11. The retention conflict


Phase 12. Consent gating


Phase 13. Universal opt-out signals


Phase 14. Sensitive data controls


Phase 15. Data protection assessments


Phase 16. The processor register


Phase 17. The statutory rider


Phase 18. The notice, written last


Phase 19. Regulator readiness


Phase 20. Special situations


Phase 21. Metrics and the annual cycle


Phase 22. Ownership

Phase 23. The seven divergences, as a working table

Everything that differs between these statutes collapses into seven items. Confirm each against the states in scope and record the answer.

| # | Divergence | What it changes | Build response | |---|---|---|---| | 1 | Whose data is covered | California reaches employees, applicants, and business contacts; other states cover consumers only | Separate employee-data workstream with an HR owner | | 2 | Sensitive data treatment | Opt-in consent in most states; a right to limit in California under Cal. Civ. Code § 1798.121 | Build both a pre-collection consent flow and a post-collection limit control | | 3 | Universal opt-out signals | Required in Colorado, Connecticut, California, Texas, Montana and others on varying timelines | Implement once, nationally, in the tag layer | | 4 | Minimization standard | Disclosure-based in most states; tied to the requested product or service in Maryland under Md. Code, Com. Law § 14-4607 | The real segmentation decision — national strict, or residency-based | | 5 | Cure periods | Present in some states, absent in others, sunsetting in several | A dated table in the applicability memo, refreshed annually | | 6 | Exemption structure | Entity-level versus data-level; nonprofit treatment | Per-state written analysis, not a single conclusion | | 7 | Thresholds | Consumer counts, revenue, sale proportion, and the Texas small-business route under Tex. Bus. & Com. Code § 541.101 | Prioritization input, not a decision about whether to have a program |


Phase 24. A worked assessment

Use this as the pattern for Phase 15. The fact pattern is the most common one that requires an assessment.

The processing. Uploading hashed email addresses of high-value customers to an advertising platform to build lookalike audiences.


Phase 25. Evidence request, written in advance

Draft it once so it can be sent unchanged when a letter arrives. Name the system and the owner for each item.

Why this belongs in the checklist rather than a litigation memo. Several of these items do not exist in retrievable form at most companies, and the first week of a regulatory inquiry — or, worse, of a cure window that is already running — is a much worse time to discover that than a quarterly review.

Phase 26. Business-model boxes

Run the base checklist, then the boxes for the model in play.

Retail and ecommerce.

Media and publishing.

Software and SaaS.

Healthcare-adjacent and wellness.

Financial services.

Employers of any size.

Companies with an acquisition history.


Phase 27. The ninety-day plan

What is deliberately not in the first ninety days. Backfilling riders across the whole vendor estate, and full identity resolution across every system. Both are long tails, and neither should delay the items above — a program that waits for completeness ships nothing, and the externally testable failures are the ones that get cited.

Phase 28. Diligence questions for an acquisition

Ask for artifacts, not assurances. A compliance certificate tells you nothing; these ten answers price the integration.

Then price three things. The cost of building what does not exist. The exposure from tags that have been running unmonitored, calculated per violation rather than per person. And the cost of migrating the acquired user base onto the acquirer's notice, which requires notice rather than a silent swap.

Outcome. The pixel inventory found sixty-eight tags with nineteen unaccounted for; eleven were removed in the first month and two on video pages were gated immediately. The data map, built from vendor payments, outbound integrations, and tool lists, produced forty-one systems where twenty-six had been listed, six of them spreadsheets. Identity resolution covered the eleven systems holding most of the data; four systems could not be searched by person and were disclosed as gaps in the response language. The applicability memo found the company in scope in fourteen states, with employee data in scope only in California, which brought HR into the program. The residency decision was hybrid, documented, with billing address primary and IP as fallback. Riders went to one hundred and twelve vendors; nine refused, and three of those were reclassified as sales, which changed the opt-out obligations. The notice was rewritten from the map in week thirty. The first external test, in week thirty-four, met the response window in two of three states and exposed a routing gap fixed within a week.


Key Authorities at a Glance

| Authority | Proposition | |---|---| | Cal. Civ. Code § 1798.100 | Collection and notice duties | | Cal. Civ. Code § 1798.105 | Right to delete | | Cal. Civ. Code § 1798.106 | Right to correct | | Cal. Civ. Code § 1798.120 | Opt out of sale or sharing | | Cal. Civ. Code § 1798.121 | Limit sensitive data use | | Cal. Civ. Code § 1798.140 | Definitions of sale and sharing | | Cal. Civ. Code § 1798.150 | Private right of action for breaches | | Va. Code § 59.1-577 | Controller duties | | Va. Code § 59.1-580 | Assessments and confidentiality | | Colo. Rev. Stat. § 6-1-1306 | Rights and universal opt-out signals | | Colo. Rev. Stat. § 6-1-1308 | Duties including consent | | Conn. Gen. Stat. § 42-520 | Connecticut duties | | Tex. Bus. & Com. Code § 541.101 | Texas duties and threshold structure | | Utah Code § 13-61-302 | A lighter-touch model | | Md. Code, Com. Law § 14-4607 | Strict minimization | | Wash. Rev. Code § 19.373.010 | Consumer health data | | 15 U.S.C. § 6801 | Financial institution exemption | | 15 U.S.C. § 1681b | Consumer report exemption | | 45 C.F.R. § 164.502 | Health information exemption | | 15 U.S.C. § 6502 | Children's data | | 15 U.S.C. § 45 | Notice as an enforceable representation | | 18 U.S.C. § 2511 | Wiretap theory | | Cal. Penal Code § 631 | Session replay claims | | Cal. Penal Code § 638.51 | Pen register theory | | 18 U.S.C. § 2710 | Video privacy; pixel claims | | 47 U.S.C. § 227 | Retention conflict with deletion | | TransUnion v. Ramirez | Concrete harm | | Spokeo v. Robins | Concrete injury |


The five things people get wrong

Writing the notice first. A privacy notice drafted before the data map describes a company nobody works at, and it converts a documentation gap into an enforceable misrepresentation under 15 U.S.C. § 45.

Buying a rights-management tool without a data map. The tool submits requests into a void, and the audit log then documents that the company received requests it could not actually fulfil.

A consent banner that nothing downstream consumes. Tags fire before the choice is evaluated, server-side tagging bypasses the gate entirely, and the recorded preference never reaches the platforms that already have the data.

Failing to honor universal opt-out signals. The requirement most companies miss, and the one a regulator can test from a browser without contacting anyone — which is exactly why it is among the most commonly cited.

Deleting the records needed to defend other claims. Consent evidence under 47 U.S.C. § 227 carries per-message statutory damages, and purging it to satisfy a deletion request trades a modest privacy obligation for a much larger exposure. Resolve the conflict in writing before the first request.


Related Documents

Articles

Guides

Checklists

Toolkits

Templates & Forms


This document is general information about the law, not legal advice, and does not create an attorney-client relationship. State privacy obligations differ by statute and by effective date. Marksy is not a law firm.

Read this article on Marksy