State Privacy Compliance Toolkit: Applicability, Rights, and Assessments
By Casey Scott McKay ·
The state privacy statutes look interchangeable in summary and differ in ways that decide compliance work, and building to a single strictest standard is usually cheaper than tracking each. This toolkit works applicability - the revenue, volume, and revenue-share thresholds, and the entity and data exemptions that remove more companies from scope than practitioners expect. It sets out the consumer rights and their operational requirements, the sensitive data rules that vary most between statutes, and the universal opt-out signal obligations. It covers data protection assessments, what triggers them and what they must contain, and the processor contract terms that every statute requires. It closes with enforcement, cure periods, and the private rights of action that exist in a small number of states.
IP and Technology > Privacy Data Security | Toolkit | Published 13 July 2024 - Updated 27 January 2025 | Casey Scott McKay - marksy.us
Summary. The state privacy statutes look interchangeable in summary and differ in ways that decide compliance work, and building to a single strictest standard is usually cheaper than tracking each. This toolkit works applicability — the revenue, volume, and revenue-share thresholds, and the entity and data exemptions that remove more companies from scope than practitioners expect. It sets out the consumer rights and their operational requirements, the sensitive data rules that vary most between statutes, and the universal opt-out signal obligations. It covers data protection assessments, what triggers them and what they must contain, and the processor contract terms that every statute requires. It closes with enforcement, cure periods, and the private rights of action that exist in a small number of states.
Keywords: state privacy statutes · applicability thresholds · controller and processor · personal data definitions · sensitive data · consumer rights · access deletion correction portability · opt out of targeted advertising · sale and sharing · universal opt out signals · data protection assessments · processor contract terms · privacy notice requirements · purpose limitation · data minimization · dark patterns and consent · cure periods · enforcement authorities · private rights of action
Start Here
A company reads that a new state privacy statute has taken effect and asks whether it applies.
The honest first answer is: possibly not. The thresholds are real, the exemptions are broad, and a substantial number of companies that spend money on state privacy compliance are outside the scope of every statute they are worried about.
The honest second answer is: if it applies in one state, build for all of them. The statutes share an architecture — controller and processor roles, a set of consumer rights, notice obligations, assessment requirements, and contract terms — and the differences, while real, are cheaper to over-comply with than to track.
The honest third answer is: the work is operational. Rights requests need a workflow. Opt-outs need to reach ad platforms. Assessments need to be written before processing begins. None of that is drafting.
This toolkit answers three questions.
- Does it apply? Thresholds and exemptions, run state by state and then collapsed.
- What must be built? Notices, a rights workflow, opt-out handling including signals, assessments, and contracts.
- What happens if it is wrong? Enforcement by attorneys general, cure periods in some states, and a private right of action in very few.
If you read only one thing, read The State Privacy Wave. It works the common architecture and the differences that actually change the build.
Applicability
Two questions. Does the entity meet a threshold, and is it or its data exempt?
The thresholds. Typically a combination of doing business in the state and either processing personal data of a stated number of consumers in a year, or processing a lower number while deriving a stated percentage of revenue from the sale of personal data. Some statutes add a revenue floor.
Consumers means residents acting in an individual context. Most statutes exclude individuals acting in a commercial or employment context, which removes business-to-business data and employee data from scope in several states — though not all, and the trend is toward including them.
Entity exemptions. Financial institutions subject to the framework at 15 U.S.C. § 6801 and following, covered entities and business associates under the health privacy framework at 42 U.S.C. § 1320d, non-profits in some states, higher education institutions in some states, and government entities.
Data exemptions. Protected health information, data subject to the consumer reporting framework at 15 U.S.C. § 1681, data subject to the children's privacy framework at 15 U.S.C. § 6501 and following, and data subject to several sectoral statutes.
Entity-level versus data-level exemptions matter enormously. An entity-level exemption removes the company entirely; a data-level exemption removes only the covered data, leaving the rest in scope.
Run it state by state and record the reasoning. A one-page applicability memorandum per state, with the threshold analysis and the exemptions considered, dated. It is the document that answers a regulator's first question and it is the document nobody has.
Re-run it annually and on any material change in volume, revenue mix, or business lines.
The Rights
Access. The right to confirm processing and to obtain the personal data. Response periods are typically forty-five days with an extension available.
Deletion. The right to delete personal data provided by or obtained about the consumer, subject to exceptions for legal obligations, security, internal uses reasonably aligned with expectations, and free speech.
Correction. The right to correct inaccuracies, taking into account the nature of the data and the purposes of processing.
Portability. A copy in a portable and readily usable format, where technically feasible, limited in frequency.
Opt out of targeted advertising. Advertising selected based on personal data obtained from the consumer's activities across non-affiliated websites or applications.
Opt out of sale. Definitions of sale vary — some statutes define it as exchange for monetary consideration, others for monetary or other valuable consideration, which is materially broader and captures many advertising arrangements.
Opt out of profiling in furtherance of decisions producing legal or similarly significant effects.
Sensitive data. Some statutes require opt-in consent before processing; others require an opt-out right. The categories typically include racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data processed to identify an individual, personal data of a known child, and precise geolocation.
Appeal. Most statutes require an internal appeal process for denied requests, with a response period and a route to contact the attorney general.
Non-discrimination. No denial of goods or services, differential pricing, or reduced quality for exercising rights, subject to loyalty programme provisions that vary.
Authorised agents. Requests submitted by agents must be honoured subject to verification.
Universal Opt-Out Signals
The obligation. Several statutes require controllers to recognise a browser or device signal indicating a consumer's intent to opt out of targeted advertising and sale.
Which is a technical obligation, not a policy one. The signal must be detected, the consumer's preference applied, and the application must persist.
Recognition requirements vary. Some statutes require recognition of specified mechanisms; others define characteristics a mechanism must have. Some make recognition mandatory and others permissive.
The frequent failure. A company honours the signal on its own site and continues sending the same consumer's data to advertising platforms through server-side integrations that never see the browser signal.
Which means the opt-out has to reach the platforms. Signals from the browser, preferences from the rights portal, and revocations from any channel must all converge on a single preference state that governs every downstream data flow.
Authenticated versus unauthenticated. A signal from an unauthenticated browser applies to that browser. Where the consumer is known, the preference should attach to the profile and follow them across devices.
Test it. Send the signal, and verify with network inspection that no data flows to advertising platforms afterwards. This test fails more often than it passes on first attempt.
Document the implementation and the test results, because the obligation is one regulators can verify from the outside in minutes.
Data Protection Assessments
The obligation. Most statutes require an assessment before conducting processing that presents a heightened risk of harm to consumers.
What triggers one. Targeted advertising. Sale of personal data. Processing sensitive data. Profiling where it presents a reasonably foreseeable risk of unfair or deceptive treatment, disparate impact, financial or physical injury, intrusion on solitude or private affairs, or other substantial injury.
What it must contain. Identification and weighing of the benefits to the controller, the consumer, other stakeholders, and the public, against the potential risks to consumer rights — as mitigated by safeguards.
Which is a balancing exercise, not a form. An assessment that lists processing and asserts it is low risk is not an assessment.
Practical structure. The processing described. The data categories and sources. The purposes and the benefits, stated concretely. The risks, identified specifically. The safeguards applied, mapped to the risks. The residual risk and the conclusion. And the sign-off with date and role.
Timing. Before the processing begins, and refreshed on material change.
Confidentiality. Assessments are generally confidential and exempt from public records requests when produced to a regulator, and producing one to an attorney general does not waive privilege under most statutes — but the statutory protection varies, so treat them as documents that may be read.
Which cuts both ways in drafting. Write them as if a regulator will read them, because one may; do not write them as if they will never be produced.
One assessment can cover comparable processing across similar activities, which makes a small number of well-drafted assessments better than dozens of thin ones.
Retention. For as long as the processing continues plus a reasonable period, and the statutes generally require production on request.
The gap most programmes have. Assessments written after the processing began, or not at all, discovered when a regulator asks. There is no cure for a retrospective assessment; the obligation was to assess first.
Contracts With Processors
Required by every statute. A controller must have a contract with each processor containing specified terms.
The required terms. Instructions for processing. The nature and purpose. The type of data and duration. The rights and obligations of both parties. A duty of confidentiality binding those processing the data. Deletion or return at the controller's direction at the end of provision of services. Provision of information necessary to demonstrate compliance on request. Cooperation with assessments. And engagement of subprocessors only under a written contract imposing the same obligations.
Audit rights. Several statutes require the processor to allow and cooperate with reasonable assessments, or to arrange a qualified independent assessment.
Assistance with rights requests. The processor must assist the controller in responding, by appropriate technical and organisational measures, insofar as reasonably practicable.
Security assistance. Cooperation in meeting the controller's security and breach obligations.
Role determination is substantive, not contractual. A party that determines the purposes and means of processing is a controller regardless of what the contract calls it, and a processor that uses data for its own purposes becomes a controller as to that use.
Which is where advertising and analytics vendors sit. Many arrangements labelled as processing are in substance sales or sharing, with the opt-out consequences that follow.
Flow-down. Subprocessors under equivalent terms, with notice or approval rights for the controller.
Practical approach. A standard data processing addendum covering the required terms across all applicable statutes, appended to every vendor agreement, with a register of who has signed it and when.
And check the substance. A signed addendum with a vendor whose actual data use exceeds the instructions is worse than no addendum, because it documents the instruction the vendor exceeded.
Notices
The privacy notice. Every statute requires a reasonably accessible, clear, and meaningful notice describing the categories of personal data processed, the purposes, how consumers exercise rights and appeal, the categories shared with third parties, the categories of third parties, and how consumers may opt out of targeted advertising and sale where applicable.
Layered notices work. A short summary with links to detail, provided the material information is not buried.
Just-in-time notice at the point of collection for unexpected uses, sensitive data, and precise geolocation.
Do not describe practices you do not have. A notice claiming safeguards or limitations the company does not implement is a deceptive practice under 15 U.S.C. § 45 independently of any privacy statute, and it is the most commonly enforced privacy failure.
Conversely, do not omit what you do. Undisclosed sharing with advertising platforms is the second most commonly enforced failure.
Financial incentive disclosures where loyalty programmes or discounts are tied to data, with the required good-faith estimate of value in the states that demand it.
Sensitive data notices and, where opt-in consent is required, a consent mechanism that meets the standard.
Do not use dark patterns for consent. Several statutes expressly provide that agreement obtained through a dark pattern does not constitute consent, which means a manipulative interface produces no valid consent at all. See Online Terms and Consumer Contracts Toolkit.
Update on change, with a revision date and an archive of prior versions.
Accessibility. Notices should be reachable from the site and app in the manner the statutes specify, including any required link text for opt-out mechanisms.
Translations where the company markets in other languages, because a notice a consumer cannot read is not meaningful.
Enforcement
Attorney general enforcement is the primary mechanism in nearly every state, with civil penalties per violation.
Cure periods. Several statutes provide a period to cure after notice of an alleged violation, some permanently and some sunsetting after an initial phase. Where a cure period exists, the practical consequence is that a company gets one warning — and the response to that notice determines everything that follows.
Which makes the notice response a priority matter. Cure within the period, document the cure, and provide a written statement that the violation is cured and will not recur where the statute requires it.
Rulemaking authority exists in some states, producing detailed regulations on top of the statutes.
Private rights of action are rare. Most comprehensive statutes have none. The significant exceptions are data breach provisions in a small number of states and sector-specific statutes — most consequentially the biometric statutes, where a private right of action with statutory damages has produced substantial class litigation. See Illinois Biometric Information Privacy Act.
Standing. TransUnion v. Ramirez and Spokeo v. Robins constrain federal court standing for bare procedural violations, which pushes some claims to state court where standing requirements differ.
Wiretapping claims. Session replay, chat transcription, and pixel-based tracking have generated substantial litigation under 18 U.S.C. § 2511 and state analogues, which is currently a larger practical exposure for many companies than the comprehensive statutes themselves.
Regulator priorities. Undisclosed sharing, non-functioning opt-outs, dark patterns in consent flows, sensitive data processing without a basis, and failure to honour universal opt-out signals. Every one of those is verifiable from outside the company.
Which is the practical point. A regulator can test the opt-out signal, inspect the network traffic, and read the notice, all in an afternoon and without contacting the company. Build for that.
Building the Programme
Start with the inventory. Processing activities, data categories, sources, purposes, recipients, retention, and legal basis. Everything else depends on it, and building it is most of the work.
Then the applicability analysis. State by state, with the reasoning recorded, and a single conclusion: which statutes apply and what the strictest combined standard requires.
Then the notice. Accurate to the inventory, layered, with the required links and disclosures.
Then the rights workflow. Intake channels, identity verification proportionate to the request and the data, routing to the systems holding the data, a response within the shortest applicable period, an appeal process, and a record of every request and its disposition.
Verification is where rights programmes fail. Too little and the company discloses data to the wrong person; too much and it constructs an obstacle. Match the verification to the sensitivity, and document the standard.
Then the opt-out infrastructure. A single preference state, fed by the rights portal, the universal opt-out signal, and any other revocation channel, and consulted by every downstream data flow including server-side integrations.
Then the assessments. For each triggering activity, written before processing begins, with the balancing done honestly.
Then the contracts. A standard data processing addendum, executed with every processor, with a register.
Then the governance. An owner, a review cadence, a change process that routes new processing through an assessment, and a training programme.
And then test it. Submit a rights request as a consumer and time it. Send a universal opt-out signal and inspect the network traffic. Read the notice against the inventory. Each test takes an hour and each finds something.
Worked Example: The Applicability Surprise
A software company with three hundred employees, business customers only, and a marketing website.
The assumption. Comprehensive state privacy compliance is required and expensive.
The analysis. Customer data is business contact information for individuals acting in a commercial context, which most statutes exclude from the definition of consumer. Employee data is excluded in several states, though not all. Website visitor data is consumer data and is in scope where thresholds are met.
The thresholds. The company processes personal data of fewer than the threshold number of consumers in every state except two, and derives no revenue from selling personal data.
The conclusion. Two statutes apply, both driven by website analytics and advertising rather than by the core business.
Which reframes the project entirely. The work is not an enterprise privacy programme; it is a notice, a rights workflow for website visitors, an opt-out that reaches the advertising platforms, and an assessment covering targeted advertising.
The finding that mattered. The advertising pixel on the marketing site sends visitor data to platforms in a way that constitutes sharing for targeted advertising under the applicable definitions, and the opt-out link on the site does not stop the server-side integration.
The remediation. Opt-out wired to the tag manager and to the server-side integration, tested by network inspection. Notice updated to disclose the sharing. Assessment written for the advertising activity. Processing addendum executed with the analytics vendor.
The cost. Three weeks, not three quarters.
The lesson. The applicability analysis is the highest-return hour in privacy compliance, and skipping it produces programmes sized for obligations the company does not have while missing the ones it does.
Sensitive Data
The category where the statutes diverge most and where the operational consequences are largest.
The categories. Typically racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, sex life or sexual orientation, citizenship or immigration status, genetic or biometric data processed for the purpose of uniquely identifying an individual, personal data collected from a known child, and precise geolocation.
The divergence. Some statutes require opt-in consent before processing. Others provide a right to limit use and disclosure. The difference determines whether the data can be processed at all by default.
Precise geolocation is the category that catches ordinary products, because a radius definition of a few thousand feet reaches most mobile location functionality.
Inference matters. Data from which a sensitive characteristic can be inferred is treated as sensitive under some statutes, which reaches purchase histories, content consumption, and app usage.
Biometric data carries separate exposure. Sector-specific biometric statutes impose notice, written consent, retention schedule, and destruction obligations, and at least one carries a private right of action with statutory damages that has produced very large settlements. See Illinois Biometric Information Privacy Act and Building a Biometric Compliance Program.
Health data beyond the federal framework. Consumer health data statutes in several states reach data outside 42 U.S.C. § 1320d, with consent requirements, and in one state a private right of action.
Children's data. Personal data of a known child is sensitive under most statutes and is separately governed by the federal children's privacy framework at 15 U.S.C. § 6501 and 16 C.F.R. § 312.2. See Children's and Youth Privacy Toolkit.
The practical approach. Identify sensitive data in the inventory explicitly. Where any applicable statute requires opt-in consent, build the consent flow and apply it universally rather than by state. And where the processing is not necessary, remove it — sensitive data is the category where minimisation pays for itself fastest.
Diligence Questions
Is there a data inventory, and is it current?
What is the applicability conclusion, state by state, with the reasoning?
Is the notice accurate to the inventory? Compare them line by line; the gap is the finding.
Is there a rights workflow? Volume received, median response time, appeal rate, and disposition records.
How is identity verified, and is the standard documented?
Does the opt-out reach every downstream flow, including server-side integrations? Test it with network inspection.
Are universal opt-out signals recognised, and does recognition persist?
Have assessments been completed for targeted advertising, sale, sensitive data, and profiling? Are they dated before the processing began?
Is a data processing addendum executed with every processor? Is there a register?
Are any vendors labelled processors actually acting as controllers? Advertising and analytics arrangements are the usual answer.
Is sensitive data processed? With what basis, and is precise geolocation involved?
Any biometric processing? With notice, written consent, and a retention schedule?
Any regulator inquiries, cure notices, or enforcement, and how were they handled?
Any session recording, chat transcription, or pixel tracking, and with what consent in two-party states?
What is the retention policy, and is it applied?
Common Mistakes
Building the programme before running the applicability analysis, and paying for obligations the company does not have while missing the ones it does.
A notice that describes aspirations rather than practices, which is a deceptive practice under 15 U.S.C. § 45 independent of any privacy statute.
Undisclosed sharing with advertising platforms, which is the most commonly enforced failure and the easiest to detect from outside.
An opt-out that stops the browser pixel and not the server-side integration.
Universal opt-out signals not recognised, or recognised and not persisted.
No data inventory, so rights requests cannot be fulfilled and assessments cannot be written.
Assessments written retrospectively, when the obligation was to assess before processing.
Assessments that are forms rather than balancing exercises.
Processor addenda executed with vendors who are in substance controllers, documenting an instruction the vendor exceeds.
Verification that is either too weak or too onerous, with no documented standard either way.
Ignoring the appeal obligation, which most statutes require and most programmes omit.
Dark patterns in consent flows, which several statutes provide produce no valid consent at all.
Treating sensitive data as ordinary data, particularly precise geolocation and inferred characteristics.
Missing the biometric statutes, which carry the private right of action that produces the largest settlements.
Session recording and pixel tracking without consent in two-party states, under 18 U.S.C. § 2511 and state analogues.
Failing to respond properly to a cure notice, which in states with cure periods is the one warning the company gets.
No retention policy, so deletion requests cannot be satisfied and minimisation never happens.
The One-Page Position
Privacy position — [company], [date]. Applicability: assessed [date]; statutes applying [list]; thresholds met by [criteria]; exemptions relied on [entity/data, with basis]. Data inventory: [N] processing activities, last refreshed [date]; sensitive categories processed [list]. Notice: version [N], effective [date], reconciled against the inventory on [date]; [N] discrepancies found and corrected. Rights: [N] requests in the period — access [N], deletion [N], correction [N], portability [N], opt-out [N]; median response [N] days against a [N]-day requirement; appeals [N], upheld [N]. Verification standard documented [date]. Opt-out infrastructure: single preference state [yes/no]; universal opt-out signal recognised [yes/no], tested [date] by network inspection, result [pass/fail]; server-side integrations covered [yes/no]. Assessments: [N] completed, [N] dated before processing began, [N] refreshed in the period. Processor addenda: executed with [N] of [N] processors; [N] vendors reclassified as controllers. Sensitive data: [categories], basis [consent/opt-out], consent flow reviewed for dark patterns [date]. Biometric processing: [none / details, with notice, consent, and retention schedule]. Session recording and tracking: [consent basis], two-party states assessed [date]. Enforcement: [N] inquiries, [N] cure notices, outcomes [summary]. Recommended actions: [wire the server-side opt-out / write the advertising assessment / reconcile the notice / execute addenda with the remaining vendors].
Questions Clients Ask
Does this apply to us? Run the thresholds state by state and check the exemptions. A substantial share of companies worrying about these statutes are outside all of them, and another share are inside only because of their marketing website.
Do employee records count? In several states, no — the definition of consumer excludes individuals acting in an employment context. In others, yes. The answer determines whether the programme is a marketing project or an enterprise one.
Do our business customers count? Individuals acting in a commercial context are excluded under several statutes, which removes most business-to-business contact data.
Do we sell data? Check the definition. Where a statute defines sale as exchange for monetary or other valuable consideration, many advertising arrangements qualify even though no money changes hands.
Do we have to honour a browser signal? In the states that require it, yes — and it must actually stop the data flows, including server-side ones.
How long do we have to respond to a rights request? Typically forty-five days with an extension, and the shortest applicable period should govern the workflow.
Can we charge for it? Generally not for the first request in a period; reasonable fees for excessive or repetitive requests are permitted in some statutes.
How do we verify who is asking? Proportionate to the sensitivity of the data and the risk of the request. Document the standard, apply it consistently, and do not collect new data solely to verify unless necessary.
Do we need an assessment? For targeted advertising, sale, sensitive data processing, and certain profiling. Before the processing starts.
Is our assessment privileged? The statutes generally protect it from waiver on production to a regulator, but the protection varies. Write it assuming it may be read.
Our vendor says it is a processor. Is it? Only if it processes on your instructions and for your purposes. If it uses the data for its own purposes, it is a controller as to that use, whatever the contract says.
What is the biggest risk? For most companies, not the comprehensive statutes — it is the biometric statutes with private rights of action, and the wiretapping claims arising from session recording and pixel tracking.
Where do we start? The inventory and the applicability analysis, in that order. Everything else is downstream.
Sector Notes
Retail and e-commerce. In scope almost universally through website analytics and advertising. The work concentrates on opt-out plumbing, loyalty programme financial incentive disclosures, and the marketing overlap. See Marketing Communications Toolkit.
Software and business services. Frequently out of scope for customer data through the commercial-context exclusion, and in scope for website data. The applicability analysis saves the most money here.
Healthcare and adjacent. The framework at 42 U.S.C. § 1320d and 45 C.F.R. § 164.502 exempts covered entities and protected health information, but consumer health data statutes reach wellness apps, fitness data, and adjacent products that fall outside it.
Financial services. The entity exemption under 15 U.S.C. § 6801 removes many institutions entirely; the data exemption removes only covered data for others. Determine which applies, because the difference is the whole programme.
Employers. Employee data is in scope in some states, which brings recruitment, monitoring, and human resources systems into a programme designed for consumers.
Advertising technology. Squarely in scope, with the sale and sharing definitions doing most of the work and the processor-versus-controller characterisation determining obligations.
Connected devices and mobility. Precise geolocation is sensitive data, and the radius definitions reach ordinary functionality.
Education technology. Children's data, sector-specific student privacy statutes, and the design code obligations. See Children's and Youth Privacy Toolkit.
Anything using facial recognition or fingerprints. Biometric statutes with private rights of action are the largest single exposure in this area for the companies they reach.
Working With Other Advisers
Engineering and data platform teams, who own the inventory in reality and who build the preference infrastructure. The opt-out that reaches server-side integrations is an engineering deliverable.
Marketing operations, whose tag manager, pixels, and platform integrations are the processing activities that put most companies in scope.
Security, because the safeguards obligations at 16 C.F.R. § 314.4 and the state equivalents share the vendor risk architecture. See Cybersecurity Governance and Disclosure Toolkit.
Procurement, for the processing addendum register and for the vendor classification question.
Human resources, where employee data is in scope.
Customer service, who receive rights requests through channels the programme did not anticipate.
Outside privacy counsel for the applicability analysis in unusual fact patterns, for assessments on novel processing, and for regulator engagement including cure notice responses.
Litigation counsel for biometric and wiretapping exposure, which is where the private claims are.
Cadence
At every new processing activity. Inventory updated, assessment written where triggered, notice reconciled, processor addendum executed.
At every new vendor. Classification determined, addendum executed, register updated.
Monthly. Rights request metrics reviewed — volume, response times, appeals, and any missed deadlines.
Quarterly. Opt-out testing by network inspection across the site, the app, and the server-side integrations. Notice reconciled against the inventory. Processor register reviewed against actual vendors.
Semi-annually. Applicability re-run against current volumes and revenue mix. Sensitive data processing reviewed for necessity.
Annually. Full inventory refresh, assessment refresh for continuing processing, retention policy review and enforcement, training for engineering, marketing, and service teams, and a board-level report.
On any statutory change. The strictest-standard analysis re-run, because a new state statute or a new regulation may raise the floor the programme is built to.
On any regulator contact. Immediate escalation, preservation, and a cure assessment where a cure period is available.
A Closing Note
Two things about this area are consistently misunderstood, and correcting both saves clients a great deal.
The first is that a substantial share of companies spending on comprehensive privacy compliance are not subject to the statutes they are complying with, or are subject only through their marketing website. The applicability analysis is an hour of work and it frequently reduces the project by an order of magnitude.
The second is that the obligations regulators actually enforce are the ones visible from outside the company. Whether the notice matches the practices. Whether the opt-out works. Whether the universal signal is honoured. Whether the consent flow uses dark patterns. A regulator can test every one of those in an afternoon without a subpoena, and those tests are what generate the inquiries.
Which suggests a straightforward priority order. Know whether you are in scope. Make the notice true. Make the opt-out work end to end. Everything else is important and none of it is first.
What This Costs
The applicability analysis. A day of counsel time, and it frequently determines whether the rest of the programme costs weeks or quarters.
The data inventory. The largest line item, because it requires interviewing every team that touches personal data. Weeks for a mid-sized company, and it is the asset the whole programme rests on.
The notice. Days, once the inventory exists. Impossible to do properly before it does.
The rights workflow. Either a purchased platform or an internal build, plus the routing to the systems that hold the data — which is engineering work proportional to how fragmented those systems are.
The opt-out infrastructure. Engineering, and the server-side integration work is the part that gets deferred and should not be.
Assessments. A day each for the first few, less thereafter once a template and a house style exist.
Processing addenda. A template plus the negotiation friction with vendors who resist audit and deletion terms.
Testing. An hour per quarter, and the highest-value hour in the programme because it finds the failures a regulator would find.
Against that: civil penalties per violation, calculated per consumer in some statutes; the biometric statutory damages that have produced nine-figure settlements; and the wiretapping class actions that arise from tracking technologies nobody in legal knew were deployed.
The programme's cost is dominated by the inventory. The programme's value is dominated by the tests. Companies routinely invert that, buying tooling before they know what data they hold and never checking whether the opt-out works.
The correction is unglamorous and it is the whole recommendation: build the inventory first, and test the opt-out every quarter for as long as the company exists.
Those two habits, sustained, outperform any amount of policy drafting — and they are what a regulator will actually look at.
A Suggested Reading Path
For applicability and rights:
- The State Privacy Wave
- Standing Up a Multi-State Privacy Compliance Program
- State Privacy Law Applicability and Readiness Checklist
For the marketing overlap:
For the security overlay:
Primary Authorities
| Authority | Proposition | |---|---| | 15 U.S.C. § 45 | Unfair or deceptive practices; baseline enforcement | | 15 U.S.C. § 6501 | Children's online privacy | | 16 C.F.R. § 312.2 | Children's privacy definitions | | 15 U.S.C. § 6801 | Financial privacy; entity exemption | | 16 C.F.R. § 314.4 | Safeguards requirements | | 42 U.S.C. § 1320d | Health information; exemption | | 45 C.F.R. § 164.502 | Uses and disclosures of protected health information | | 15 U.S.C. § 1681 | Consumer reporting; data exemption | | 15 U.S.C. § 6802 | Obligations with respect to disclosures | | 18 U.S.C. § 2511 | Interception; session recording | | 18 U.S.C. § 1030 | Computer fraud and abuse | | TransUnion v. Ramirez | Concrete injury for statutory claims | | Spokeo v. Robins | Injury in fact for procedural violations | | Van Buren v. United States | Exceeding authorised access | | hiQ Labs v. LinkedIn | Public data and access authorisation | | California Consumer Privacy Act | Rights, sale and sharing, sensitive data | | Virginia Consumer Data Protection Act | Controller and processor architecture | | Colorado Privacy Act | Universal opt-out mechanism | | Connecticut Data Privacy Act | Assessments and sensitive data consent | | Illinois Biometric Information Privacy Act | Private right of action for biometric data |
Forms and Templates
Privacy compliance produces a small number of documents that carry disproportionate weight, and the first is the data inventory — which the Portfolio Inventory Template adapts to directly: one row per processing activity, with the data categories, the sources, the purposes, the recipients, the retention period, the legal basis or exemption relied on, and the assessment reference where one is required. Every other privacy obligation is downstream of that table, and a programme without one is a programme that cannot answer a rights request, complete an assessment, or respond to a regulator. The License Agreement Template supplies the architecture for processor agreements, which every statute requires and which must contain the specified terms — processing instructions, confidentiality, deletion or return, subprocessor flow-down, audit cooperation, and assistance with rights requests. The Assignment Agreement Template matters in transactions, where personal data transfers are themselves a processing activity and where the buyer inherits the seller's notice representations.
Related Toolkits and Checklists
The Marketing Communications Toolkit covers the channel rules that apply to the same data and shares the consent and preference infrastructure, which is why the two programmes should be built together. The State Privacy Law Applicability and Readiness Checklist runs the threshold analysis and the build steps in order. The Children's and Youth Privacy Toolkit covers the heightened obligations for minors, which several state statutes now impose independently of the federal framework. And the Cybersecurity Governance and Disclosure Toolkit covers the safeguards obligations that sit alongside the privacy ones and that share the same vendor risk architecture.
Related Documents
Articles
Guides
- Standing Up a Multi-State Privacy Compliance Program
- Building a Marketing Communications Compliance Program
Checklists
Toolkits
- Marketing Communications Toolkit
- Children's and Youth Privacy Toolkit
- Cybersecurity Governance and Disclosure Toolkit
Templates & Forms
This document is general information about the law, not legal advice, and does not create an attorney-client relationship. Privacy obligations turn on the specific statutes, data, and processing activities. Marksy is not a law firm.