State Privacy Law Applicability and Readiness Checklist: Thresholds, Notices, Rights Workflow, Assessments, and Processor Terms
By Casey Scott McKay ·
This checklist establishes whether a company is actually subject to the comprehensive state privacy statutes, then builds the capability to comply with them, in the order the work has to happen rather than the order the statutes are written in. It opens with the pixel inventory, because the wiretap and video-privacy theories are the live litigation exposure while the privacy statutes are enforced slowly. It then builds the data map and identity resolution that every downstream obligation depends on, runs the applicability and exemption analysis per state, and forces the residency decision that determines whether the program is national or segmented. It specifies the rights workflow with proportionate verification, the deletion policy reconciled against records needed to defend other claims, the consent and tag layer where universal opt-out signals actually live, and the processor rider. Gates mark items that should clear before any new system receives personal data.
IP and Technology > Privacy Data Security | Checklist | Published 10 November 2025 - Updated 18 March 2026 | Casey Scott McKay - marksy.us
Summary. This checklist establishes whether a company is actually subject to the comprehensive state privacy statutes, then builds the capability to comply with them, in the order the work has to happen rather than the order the statutes are written in. It opens with the pixel inventory, because the wiretap and video-privacy theories are the live litigation exposure while the privacy statutes are enforced slowly. It then builds the data map and identity resolution that every downstream obligation depends on, runs the applicability and exemption analysis per state, and forces the residency decision that determines whether the program is national or segmented. It specifies the rights workflow with proportionate verification, the deletion policy reconciled against records needed to defend other claims, the consent and tag layer where universal opt-out signals actually live, and the processor rider. Gates mark items that should clear before any new system receives personal data.
Keywords: pixel inventory · tag ownership · data map · identity resolution · applicability thresholds · exemption analysis · residency determination · rights intake · verification proportionality · deletion and backups · retention conflict · consent gating · universal opt-out signals · sensitive data controls · data protection assessments · processor register · statutory rider · subprocessor evidence · notice versioning · regulator readiness
How to use this checklist
| Phase | What it covers | |---|---| | 1 | The pixel inventory, first | | 2 | Tag ownership and gating | | 3 | The data map | | 4 | Identity resolution | | 5 | Applicability thresholds | | 6 | Exemption analysis | | 7 | The residency decision | | 8 | Rights intake | | 9 | Verification proportionality | | 10 | Deletion execution | | 11 | The retention conflict | | 12 | Consent gating | | 13 | Universal opt-out signals | | 14 | Sensitive data controls | | 15 | Data protection assessments | | 16 | The processor register | | 17 | The statutory rider | | 18 | The notice, written last | | 19 | Regulator readiness | | 20 | Special situations | | 21 | Metrics and the annual cycle | | 22 | Ownership |
Boxes marked [Gate] should clear before any new system, vendor, or tag receives personal data.
The matter. A retailer with eleven million customer records and no data map found forty-one systems where twenty-six had been listed, sixty-eight tags of which nineteen were unaccounted for, and four systems that could not be searched by person at all.
Phase 1. The pixel inventory, first
-
[ ] [Gate] Inventory every tag on every customer-facing page, including tags injected by tag managers, partners, embedded widgets, and server-side integrations.
- Why. The comprehensive statutes are enforced by regulators over months. The wiretap and video-privacy theories generate class actions in weeks with per-violation statutory damages.
- Trap. Most companies find scripts nobody can account for, several added by a contractor who has left.
-
[ ] Classify each tag by what it transmits and to whom — page URL, referrer, form field contents, video titles, search terms, identifiers, and any content of a communication.
-
[ ] [Gate] Flag video pages. 18 U.S.C. § 2710 provides liquidated damages of twenty-five hundred dollars per violation for disclosing video-viewing information to a third party.
-
[ ] [Gate] Flag anything capturing form contents or keystrokes. This is the 18 U.S.C. § 2511 and Cal. Penal Code § 631 fact pattern.
-
[ ] Flag device fingerprinting, which supports the Cal. Penal Code § 638.51 theory.
-
[ ] Remove what is not earning its place. Usually a third of the inventory, and the cheapest risk reduction available.
Phase 2. Tag ownership and gating
-
[ ] [Gate] Assign a named owner and a stated purpose to every surviving tag.
-
[ ] Adopt the rule that no tag ships without both.
-
[ ] Bring server-side tagging inside the consent layer.
- Trap. Server-side integrations routinely bypass client-side consent entirely, and this is the most common technical gap in an otherwise good program.
-
[ ] Review the tag inventory quarterly, since new pixels appear with every campaign.
-
[ ] Attend the campaign calendar review, where new tags are visible weeks before they ship.
Phase 3. The data map
-
[ ] [Gate] One row per system, with: name and owner; hosting and region; data categories; sensitive categories present; source of data; purposes; linking keys available; searchable by person; deletable per person; retention period and basis; disposal method; downstream recipients; consent dependency; last verified.
-
[ ] Build it from three independent lists — vendor payments from finance, outbound integrations from engineering, tool inventories from marketing and HR — and reconcile.
- Why. Systems appearing on only one list are the discoveries. Questionnaires return the systems people already knew about.
-
[ ] Interview each system owner for fifteen minutes rather than sending a form.
-
[ ] Include the unglamorous systems — shared-drive spreadsheets, support ticketing, call recordings, camera footage, HR systems, and the analytics warehouse where everything is copied.
-
[ ] Record "searchable by person" and "deletable per person" honestly. These two columns determine what the rights workflow can promise.
-
[ ] Rank by risk — sensitive categories, volume, external exposure — and do detailed work in that order.
-
[ ] Refresh on trigger, not schedule: new system, vendor, integration, or data category.
Phase 4. Identity resolution
-
[ ] [Gate] Decide the linking keys — email, phone, account identifier, device identifier, household — and normalize them, or joins fail silently.
-
[ ] Build or buy the resolution layer, and test it on five real people by producing every record.
-
[ ] Record the known gaps: systems not searchable by person, pseudonymous data that cannot be linked, unindexed archives.
-
[ ] Put those gaps in the rights-response language, honestly.
-
[ ] Expect this to be the most expensive item in the program, and the one that makes everything else possible.
Phase 5. Applicability thresholds
-
[ ] Count residents processed by state, using the Phase 7 residency method.
-
[ ] Assess revenue and sale-proportion alternatives where a statute uses them, noting that Texas keys to federal small-business criteria rather than a consumer count under Tex. Bus. & Com. Code § 541.101.
-
[ ] Include website visitors with cookie identifiers, prospects, applicants, and data received from partners.
- Trap. Counting only customer records understates the number badly.
-
[ ] Determine whether adtech arrangements are sales, which affects the lower sale-proportion threshold. See Cal. Civ. Code § 1798.140.
-
[ ] Accept that most companies of any size cross the threshold in the large states. The count matters for prioritization, not for whether to have a program.
Phase 6. Exemption analysis
-
[ ] [Gate] Do it per state, in writing.
-
[ ] Financial institutions under 15 U.S.C. § 6801 — entity-level in some states, data-level in others.
-
[ ] Health-regulated organizations under 45 C.F.R. § 164.502 — same divergence.
-
[ ] Consumer report data under 15 U.S.C. § 1681b.
-
[ ] [Gate] Employee, applicant, and business-contact data — exempt in nearly every state, in scope in California.
- Why. This single divergence brings HR, payroll, benefits, background screening, and monitoring systems into the program for any employer.
-
[ ] Nonprofits, covered in some states and not others.
-
[ ] Record cure periods and their sunset dates, because whether a warning shot exists is state-specific and expiring.
Phase 7. The residency decision
-
[ ] [Gate] Choose the strategy explicitly and document it.
- Strictest standard nationally. Simplest, most defensible, forecloses misclassification arguments; costs whatever the strictest requirement costs.
- Segment by best-available signal. Cheaper in data, costlier in engineering, and creates an unmeasurable failure rate.
- Hybrid. Strict where universal application is cheap; segmented where cost is material — usually minimization and retention.
-
[ ] Understand how each proxy fails. Billing address is reliable and often absent; shipping address may be a gift recipient; IP geolocation reflects where the device is now; area code says nothing; self-declaration is accurate and rarely given.
-
[ ] Note that the Maryland standard changes the stakes. Md. Code, Com. Law § 14-4607 ties collection to the specific product or service requested, so disclosure does not cure over-collection.
-
[ ] Write down the determination method, its failure modes, and the accepted error tolerance.
Phase 8. Rights intake
-
[ ] [Gate] Accept requests through every required channel — webform, email address, and a toll-free number where a statute requires one.
-
[ ] Never require an account to exercise a right.
-
[ ] Accommodate authorized agents with a defined proof standard.
-
[ ] Route to systems from the data map, with per-system confirmation rather than a global assumption.
-
[ ] Run a response clock — typically forty-five days, extendable once by forty-five with notice — with an alarm before expiry.
-
[ ] Provide an appeal path with its own window and, where required, a route to the attorney general.
-
[ ] [Gate] Keep a complete audit log: request, type, verification performed, systems touched, disposition, and dates. This is the second thing a regulator asks for.
-
[ ] Test quarterly by submitting a request as a consumer, from outside, and timing it.
Phase 9. Verification proportionality
-
[ ] Match the standard to the request.
- Categories collected — low: match an identifier and confirm to it.
- Specific pieces — higher: two known data points or an authenticated session.
- Deletion — higher still, because wrongful deletion is irreversible.
- Sensitive data or a minor's record — highest, with manual review.
-
[ ] [Gate] Do not over-verify. Demanding identity documents for a categories request is itself a violation in several states.
-
[ ] Handle non-account holders by matching on the identifier supplied and disclosing only data tied to it, saying so in the response.
-
[ ] Use verification data only for verification, then delete it.
-
[ ] Log the verification performed. "We could not verify" is only an answer if the attempt is documented.
Phase 10. Deletion execution
-
[ ] Production systems immediately, across every system the map identifies.
-
[ ] Backups on the normal rotation, with a documented commitment not to restore deleted data.
-
[ ] Processors on instruction, with confirmation recorded.
-
[ ] [Gate] Analytics and warehouse copies, which is where deletion most often fails silently.
-
[ ] Confirm per system rather than assuming propagation.
-
[ ] Test deletion end to end on a seeded test record before the first real request.
Phase 11. The retention conflict
-
[ ] [Gate] Identify what must be kept after a deletion request — tax records, employment records, and consent evidence defending claims.
-
[ ] Resolve the messaging conflict in writing. Consent evidence defends a claim under 47 U.S.C. § 227 carrying per-message statutory damages, and deleting it trades a privacy obligation for a much larger exposure.
-
[ ] Segregate retained records and use them for no other purpose.
-
[ ] Tell the consumer what was retained and why, which most statutes contemplate.
-
[ ] Write the policy before the first request, not during it.
Phase 12. Consent gating
-
[ ] [Gate] Evaluate consent before tags fire, not after.
- Trap. A banner that records a preference after the pixel transmitted is documentation of a violation.
-
[ ] Propagate downstream to the marketing platform, advertising platforms that already received data, the analytics stack, and every processor.
-
[ ] Log the preference with timestamp, language shown, and version.
-
[ ] Provide the required links — California's conspicuous opt-out of sale and sharing under Cal. Civ. Code § 1798.120, plus the sensitive-data limit; other states require a clear mechanism without prescribed wording.
-
[ ] Test from a clean browser and confirm nothing fires before a choice is made.
Phase 13. Universal opt-out signals
-
[ ] [Gate] Detect the signal. Required in Colorado under Colo. Rev. Stat. § 6-1-1306, and in Connecticut, California, Texas, Montana and others on varying timelines.
-
[ ] Map it to the right processing categories — sale, sharing, targeted advertising — per state.
-
[ ] Apply it before anything fires.
-
[ ] Persist it against the identifier, so it survives the session.
-
[ ] Re-test after every front-end release.
- Why. This is the requirement most companies fail and the easiest for a regulator to test from a browser, which is why it is among the most commonly cited.
Phase 14. Sensitive data controls
-
[ ] [Gate] Build both mechanisms: an opt-in consent flow for the states requiring it, and a limit control for California's right to limit under Cal. Civ. Code § 1798.121.
-
[ ] Inventory precise geolocation. Store locators, delivery, and fraud checks collect it casually, and the statutory radius definitions are narrow enough to capture ordinary mobile location.
-
[ ] Screen for inference. Data revealing a sensitive characteristic can be sensitive even where the field is not labelled that way — purchase history revealing a health condition is the recurring example.
-
[ ] Treat health-adjacent inference as sensitive everywhere, given Washington's statute at Wash. Rev. Code § 19.373.010 and its private right of action.
-
[ ] Route biometrics to the separate regime, which is more dangerous than these statutes. See the Biometric Data Checklist.
-
[ ] Screen for known child users, triggering 15 U.S.C. § 6502 and the sensitive-data provisions simultaneously.
Phase 15. Data protection assessments
-
[ ] [Gate] Trigger at design time, inside the existing intake form.
-
[ ] Required for targeted advertising, sale, sensitive data processing, and profiling with legal or similarly significant effects — Va. Code § 59.1-580 and analogues.
-
[ ] Keep to two pages: the processing; benefits to controller, consumer, and public, stated without inflation; risks; safeguards actually adopted; residual risk and balance; named decision-maker and date.
-
[ ] [Gate] Record at least one adopted mitigation. An assessment that changed nothing is evidence the process is theatre.
-
[ ] Identify contract sections relied upon rather than gesturing at "contractual protections."
-
[ ] Check the confidentiality provision in the governing statute, since protection against waiver is not uniform.
Phase 16. The processor register
-
[ ] [Gate] One register: every vendor receiving personal data, its role, rider status, subprocessors, deletion-on-termination status, and any assessment reference.
-
[ ] Reconcile against vendor payments semi-annually, which reliably surfaces vendors nobody registered.
-
[ ] [Gate] Classify adtech honestly. Papering an advertising platform as a processor when the arrangement is a sale or share removes the opt-out the statute requires.
-
[ ] Escalate any vendor asking to use data for its own purposes — model improvement, benchmarking, its own analytics. That vendor is a controller, whatever the contract says.
-
[ ] Exercise one audit right per year on someone. A right never used is a right the vendor has learned to ignore.
-
[ ] Confirm deletion actually happened on termination. The clause exists everywhere; the performance almost nowhere.
Phase 17. The statutory rider
- [ ] Roles, with processing only on documented instructions.
- [ ] Scope — nature, purpose, data categories, data subject categories, and duration, stated specifically rather than by cross-reference.
- [ ] Confidentiality of personnel with access.
- [ ] Security, by reference to a named standard rather than "industry standard."
- [ ] [Gate] Subprocessors only under flow-down contract, with notice and objection rights — and ask to see one flow-down contract at signature.
- [ ] Assistance with rights requests, security, breach notification within a stated period, and assessments.
- [ ] Deletion or return on direction, with written confirmation and a deadline.
- [ ] [Gate] No independent use — not for product improvement, model training, benchmarking, or the vendor's own analytics.
- [ ] Audit and information rights.
- [ ] A no-sale representation, where the relationship is intended to be processor-only.
- [ ] A jurisdiction annex for California employee data and consumer health data.
- [ ] Attach it to the standard vendor packet so it travels by default.
Phase 18. The notice, written last
-
[ ] [Gate] Write it from the data map, not from a template.
-
[ ] Cover categories collected and sources; purposes; categories disclosed and to whom; whether data is sold or shared and which categories; sensitive data handling; retention periods or criteria; rights and how to exercise them; the appeal process; and a contact.
-
[ ] Use state-specific supplements rather than one document straining to satisfy every state in every sentence.
-
[ ] Version and date it, with an archive.
-
[ ] Check it against reality quarterly.
- Why. The notice is a set of representations enforceable under 15 U.S.C. § 45 and state consumer statutes, and the fastest route to enforcement is a notice describing a program the company does not run.
Phase 19. Regulator readiness
-
[ ] Keep seven documents retrievable within a week: the notice as published on stated dates; the rights request log with response times; the data map; the processor register with riders; assessments for targeted advertising, sale, and sensitive data; evidence that opt-outs propagate; and the retention schedule with evidence of execution.
-
[ ] Know the external entry points. A regulator can load the site, test the universal opt-out signal, look for required links, and submit a rights request — all without contacting the company.
-
[ ] Diary any deadline immediately and request extensions in the first week, not on the due date.
-
[ ] Answer factually and narrowly, supplying records rather than characterizations, and without volunteering a compliance conclusion.
-
[ ] Fix what the inquiry reveals, with dates, since where a cure period exists, speed is the whole game.
-
[ ] Preserve, treating the letter as a hold trigger because a plaintiff's firm may follow the publicity.
-
[ ] Keep the regulator response consistent with any wiretap-case position on how data flows to third parties.
Phase 20. Special situations
-
[ ] Employers. Run the California employee-data workstream as its own project with an HR owner; the systems, vendors, and retention drivers differ entirely from the consumer side.
-
[ ] Groups with a regulated entity. Draw the exemption line entity by entity and state by state, and examine the data flowing between the regulated entity and unregulated affiliates, which is where the exemption stops.
-
[ ] Business-to-business companies. Lightly regulated almost everywhere, materially regulated in California — a manageable outcome only if the memo says so rather than assuming exemption.
-
[ ] Health-adjacent products. Treat health inference as sensitive everywhere.
-
[ ] Products with minors. Actual knowledge triggers two regimes at once. See the Children's Privacy Compliance Checklist.
-
[ ] Acquisitions. Ask in diligence for the seven readiness documents rather than a compliance certificate.
-
[ ] Companies that also process for customers. Two obligation sets in the same systems; the boundary must be architectural rather than contractual.
Phase 21. Metrics and the annual cycle
-
[ ] Quarterly: tag review with owners confirmed; rights volume, median response time, and missed windows; an external timed request; universal opt-out signal re-tested after front-end releases.
-
[ ] Semi-annually: processor register reconciled to vendor payments; retention execution sampled; notice checked against practice.
-
[ ] Annually: applicability memo refreshed; exemption analysis re-run; residency decision re-assessed; one vendor audit exercised; data map last-verified column refreshed; assessments reviewed for adopted mitigations; insurance re-read at renewal.
-
[ ] Four numbers for the board: tags with a named owner as a proportion of all tags; systems reachable by identity resolution; rights answered within the window; vendors with an executed rider.
-
[ ] The metric that predicts everything: time to produce the seven readiness documents, measured cold, once a year.
Phase 22. Ownership
-
[ ] [Gate] Name one owner with authority across marketing, product, engineering, and procurement.
- Why. The failures in this area are almost always seams between functions rather than errors within one.
-
[ ] Publish four triggers on one slide: a new system or vendor receiving personal data; a new data category; a new purpose for existing data; and any new tag or integration on a customer-facing surface.
-
[ ] Give legal review a service level. Two weeks gets routed around; two days gets used.
-
[ ] Put the annual cycle on a shared calendar with named owners per item.
Phase 23. The seven divergences, as a working table
Everything that differs between these statutes collapses into seven items. Confirm each against the states in scope and record the answer.
| # | Divergence | What it changes | Build response | |---|---|---|---| | 1 | Whose data is covered | California reaches employees, applicants, and business contacts; other states cover consumers only | Separate employee-data workstream with an HR owner | | 2 | Sensitive data treatment | Opt-in consent in most states; a right to limit in California under Cal. Civ. Code § 1798.121 | Build both a pre-collection consent flow and a post-collection limit control | | 3 | Universal opt-out signals | Required in Colorado, Connecticut, California, Texas, Montana and others on varying timelines | Implement once, nationally, in the tag layer | | 4 | Minimization standard | Disclosure-based in most states; tied to the requested product or service in Maryland under Md. Code, Com. Law § 14-4607 | The real segmentation decision — national strict, or residency-based | | 5 | Cure periods | Present in some states, absent in others, sunsetting in several | A dated table in the applicability memo, refreshed annually | | 6 | Exemption structure | Entity-level versus data-level; nonprofit treatment | Per-state written analysis, not a single conclusion | | 7 | Thresholds | Consumer counts, revenue, sale proportion, and the Texas small-business route under Tex. Bus. & Com. Code § 541.101 | Prioritization input, not a decision about whether to have a program |
- [ ] Record the answer for each divergence, per state in scope.
- [ ] Note that items 1 through 3 are handled by building to the strictest requirement, which is cheaper than segmenting.
- [ ] Note that item 4 is the one forcing a genuine choice.
- [ ] Note that items 5 through 7 are legal analysis rather than engineering, and belong in a memo refreshed annually.
Phase 24. A worked assessment
Use this as the pattern for Phase 15. The fact pattern is the most common one that requires an assessment.
The processing. Uploading hashed email addresses of high-value customers to an advertising platform to build lookalike audiences.
-
[ ] Classify it. A sale or share in most states — personal data disclosed to a third party for valuable consideration and used for cross-context behavioral advertising — and targeted advertising in every state in the family. An assessment is required.
-
[ ] State benefits without inflation. To the controller: acquisition efficiency, with a figure. To the consumer: more relevant advertising, a real but modest benefit. To the public: none material, said plainly.
-
[ ] State risks. Disclosure of the customer relationship to a platform that may retain and reuse it; loss of control after matching; potential inference of sensitive characteristics if the high-value segment correlates with one; consumer surprise.
-
[ ] Record safeguards actually adopted. Hashing before transmission; contractual prohibition on the platform's own use, identified by contract section; exclusion of any segment derived from sensitive signals; suppression of opt-outs applied before upload rather than after; a retention limit with a stated deletion date.
-
[ ] [Gate] Record the mitigation that changed the processing. In this example, a proposed pregnancy-prediction segment was dropped. That single line is what distinguishes an assessment from a memo written to satisfy a checklist.
-
[ ] State residual risk and the balance in two sentences.
-
[ ] Name the decision-maker and date it.
Phase 25. Evidence request, written in advance
Draft it once so it can be sent unchanged when a letter arrives. Name the system and the owner for each item.
- [ ] Privacy notice as published on each date in the inquiry period, from the archive.
- [ ] Rights request log with type, verification, systems touched, disposition, and dates.
- [ ] Data map, current version and the version in force during the inquiry period.
- [ ] Identity resolution coverage report — which systems are reachable, which are not.
- [ ] Processor register with rider status, subprocessors, and deletion confirmations.
- [ ] Executed riders for the vendors named in the inquiry.
- [ ] Assessments for targeted advertising, sale, and sensitive data processing in the period.
- [ ] Opt-out propagation trace — a single consumer's preference followed from capture through to each downstream system.
- [ ] Universal opt-out signal test results, dated, from the quarterly re-tests.
- [ ] Tag inventory with owners and purposes, plus the removal history.
- [ ] Retention schedule and evidence of execution on a sample of systems.
- [ ] Consent and preference logs for any consumer named.
- [ ] Breach notifications made in the period, if any.
Why this belongs in the checklist rather than a litigation memo. Several of these items do not exist in retrievable form at most companies, and the first week of a regulatory inquiry — or, worse, of a cure window that is already running — is a much worse time to discover that than a quarterly review.
Phase 26. Business-model boxes
Run the base checklist, then the boxes for the model in play.
Retail and ecommerce.
- [ ] Loyalty programs generate the richest inference data and are rarely in the data map.
- [ ] Store wifi, beacons, and camera analytics collect data nobody thinks of as personal.
- [ ] Financial-incentive rules apply to loyalty discounts tied to data collection; disclose the incentive and its good-faith relationship to the data's value.
- [ ] Precise geolocation from store locators and delivery is sensitive data in most states.
Media and publishing.
- [ ] Video pages are the highest-priority item in Phase 1, given 18 U.S.C. § 2710.
- [ ] Subscriber data and reading history support inference of sensitive characteristics.
- [ ] Advertising relationships are almost always sales or shares, not processor arrangements.
Software and SaaS.
- [ ] Controller for the company's own data and processor for customer data, in the same systems — the boundary must be architectural.
- [ ] Product telemetry used for the vendor's own improvement converts the vendor into a controller as to that use.
- [ ] Customer-facing rider requests will arrive; have a standard position rather than negotiating each one.
Healthcare-adjacent and wellness.
- [ ] Confirm whether the exemption is entity-level or data-level in each state.
- [ ] Treat health inference as sensitive everywhere, given Wash. Rev. Code § 19.373.010.
- [ ] Advertising pixels on symptom, condition, or appointment pages are the highest-risk configuration in this practice.
Financial services.
- [ ] Entity-level exemption under 15 U.S.C. § 6801 in some states only, and it does not reach affiliated marketing entities.
- [ ] Consumer report data under 15 U.S.C. § 1681b has its own regime layered on top.
Employers of any size.
- [ ] California employee data brings HR, payroll, benefits, background screening, and monitoring into scope.
- [ ] Monitoring tools raise wiretap questions independent of the privacy statutes.
- [ ] Applicant data retention is driven by employment law, not by minimization.
Companies with an acquisition history.
- [ ] Each acquired product arrives with its own systems, vendors, and notice history.
- [ ] Migrating acquired users to the acquirer's notice requires notice, not a silent swap.
- [ ] Run Phases 1, 3, and 16 on the acquired estate before integrating data.
Phase 27. The ninety-day plan
-
[ ] Days 1-10. Pixel inventory. Remove unaccounted-for tags. Gate video-page tags immediately.
-
[ ] Days 11-25. Data map from three independent lists. Identify the systems nobody listed.
-
[ ] Days 26-35. Applicability memo, exemption analysis, and the residency decision, all written and dated.
-
[ ] Days 36-55. Identity resolution on the highest-volume systems. Record the gaps.
-
[ ] Days 56-70. Rights workflow live: intake, proportionate verification, routing from the map, response clock, appeal path, audit log. Deletion tested on a seeded record.
-
[ ] Days 71-80. Consent gate evaluating before tags fire; server-side tagging brought inside; universal opt-out signal detection shipped and tested from a clean browser.
-
[ ] Days 81-85. Rider attached to the standard vendor packet; processor register started; assessment trigger added to the existing intake form.
-
[ ] Days 86-90. Notice rewritten from the map, versioned and archived. Owner named. Annual cycle calendared. Seven readiness documents assembled and the retrieval time measured.
What is deliberately not in the first ninety days. Backfilling riders across the whole vendor estate, and full identity resolution across every system. Both are long tails, and neither should delay the items above — a program that waits for completeness ships nothing, and the externally testable failures are the ones that get cited.
Phase 28. Diligence questions for an acquisition
Ask for artifacts, not assurances. A compliance certificate tells you nothing; these ten answers price the integration.
- [ ] Produce the data map. If none exists, the integration cost is the whole of Phase 3.
- [ ] Produce the rights request log for the last twenty-four months, with response times.
- [ ] Produce the tag inventory with owners, and the list of tags on any page with video content.
- [ ] Produce the processor register and three executed riders chosen at random.
- [ ] Produce every version of the privacy notice for the last three years, with dates.
- [ ] Produce the assessments for any targeted advertising or sale.
- [ ] Name the residency determination method and its documented error tolerance.
- [ ] Identify any regulatory correspondence on privacy in the last five years, and any cure notice received.
- [ ] Identify pending or threatened wiretap, pen-register, or video-privacy claims, which are the ones most likely to be omitted from a standard litigation schedule because counsel classified them as consumer claims rather than privacy claims.
- [ ] Confirm what the target promised its own customers in processor riders it signed, since those obligations transfer and may conflict with the acquirer's practices.
Then price three things. The cost of building what does not exist. The exposure from tags that have been running unmonitored, calculated per violation rather than per person. And the cost of migrating the acquired user base onto the acquirer's notice, which requires notice rather than a silent swap.
Outcome. The pixel inventory found sixty-eight tags with nineteen unaccounted for; eleven were removed in the first month and two on video pages were gated immediately. The data map, built from vendor payments, outbound integrations, and tool lists, produced forty-one systems where twenty-six had been listed, six of them spreadsheets. Identity resolution covered the eleven systems holding most of the data; four systems could not be searched by person and were disclosed as gaps in the response language. The applicability memo found the company in scope in fourteen states, with employee data in scope only in California, which brought HR into the program. The residency decision was hybrid, documented, with billing address primary and IP as fallback. Riders went to one hundred and twelve vendors; nine refused, and three of those were reclassified as sales, which changed the opt-out obligations. The notice was rewritten from the map in week thirty. The first external test, in week thirty-four, met the response window in two of three states and exposed a routing gap fixed within a week.
Key Authorities at a Glance
| Authority | Proposition | |---|---| | Cal. Civ. Code § 1798.100 | Collection and notice duties | | Cal. Civ. Code § 1798.105 | Right to delete | | Cal. Civ. Code § 1798.106 | Right to correct | | Cal. Civ. Code § 1798.120 | Opt out of sale or sharing | | Cal. Civ. Code § 1798.121 | Limit sensitive data use | | Cal. Civ. Code § 1798.140 | Definitions of sale and sharing | | Cal. Civ. Code § 1798.150 | Private right of action for breaches | | Va. Code § 59.1-577 | Controller duties | | Va. Code § 59.1-580 | Assessments and confidentiality | | Colo. Rev. Stat. § 6-1-1306 | Rights and universal opt-out signals | | Colo. Rev. Stat. § 6-1-1308 | Duties including consent | | Conn. Gen. Stat. § 42-520 | Connecticut duties | | Tex. Bus. & Com. Code § 541.101 | Texas duties and threshold structure | | Utah Code § 13-61-302 | A lighter-touch model | | Md. Code, Com. Law § 14-4607 | Strict minimization | | Wash. Rev. Code § 19.373.010 | Consumer health data | | 15 U.S.C. § 6801 | Financial institution exemption | | 15 U.S.C. § 1681b | Consumer report exemption | | 45 C.F.R. § 164.502 | Health information exemption | | 15 U.S.C. § 6502 | Children's data | | 15 U.S.C. § 45 | Notice as an enforceable representation | | 18 U.S.C. § 2511 | Wiretap theory | | Cal. Penal Code § 631 | Session replay claims | | Cal. Penal Code § 638.51 | Pen register theory | | 18 U.S.C. § 2710 | Video privacy; pixel claims | | 47 U.S.C. § 227 | Retention conflict with deletion | | TransUnion v. Ramirez | Concrete harm | | Spokeo v. Robins | Concrete injury |
The five things people get wrong
Writing the notice first. A privacy notice drafted before the data map describes a company nobody works at, and it converts a documentation gap into an enforceable misrepresentation under 15 U.S.C. § 45.
Buying a rights-management tool without a data map. The tool submits requests into a void, and the audit log then documents that the company received requests it could not actually fulfil.
A consent banner that nothing downstream consumes. Tags fire before the choice is evaluated, server-side tagging bypasses the gate entirely, and the recorded preference never reaches the platforms that already have the data.
Failing to honor universal opt-out signals. The requirement most companies miss, and the one a regulator can test from a browser without contacting anyone — which is exactly why it is among the most commonly cited.
Deleting the records needed to defend other claims. Consent evidence under 47 U.S.C. § 227 carries per-message statutory damages, and purging it to satisfy a deletion request trades a modest privacy obligation for a much larger exposure. Resolve the conflict in writing before the first request.
Related Documents
Articles
- The State Privacy Wave
- The Data Behind the Marketing: Privacy Law for Brands
- Permission to Reach Someone
- Your Face as Data
Guides
- Standing Up a Multi-State Privacy Compliance Program
- Building a Privacy Compliance Program for a Consumer Brand
- Building a Marketing Communications Compliance Program
- Running a Data Breach Response
Checklists
- Marketing Privacy Compliance Checklist
- Outbound Marketing Compliance Checklist
- Biometric Data Checklist
- Incident Response Checklist
Toolkits
- State Privacy Compliance Toolkit
- Privacy and Marketing Data Toolkit
- Biometric and Sensitive Data Toolkit
- Incident Response and Breach Notification Toolkit
Templates & Forms
This document is general information about the law, not legal advice, and does not create an attorney-client relationship. State privacy obligations differ by statute and by effective date. Marksy is not a law firm.