US State Privacy Laws Are Converging on Principles and Diverging on Everything Else

Twenty states have enacted comprehensive consumer privacy laws. More are in progress. The laws share a common conceptual architecture: consumer rights, controller and processor obligations, data protection assessments, and enforcement authority.

RCDr. Richard Chingombe · Founder, Verisq·4 min read·Practitioner perspective, not legal advice

They also differ in ways that make a single compliance program inadequate for the full state population: different thresholds for applicability, different definitions of sensitive data, different opt-out mechanisms, different enforcement structures, and different private rights of action. Converging on the architecture of privacy law and diverging on its specifics is the US state privacy landscape. Operating in it requires a governance approach that is more sophisticated than most organizations have built.

The Convergence That Creates the Illusion of Unity

The conceptual similarity across state privacy laws is genuine and significant. Every major state privacy law enacted since CCPA includes the right to know what personal data is collected, the right to delete, the right to opt out of the sale or sharing of personal data, and some form of data protection assessment requirement for high-risk processing. This convergence reflects deliberate policy choices by state legislators who were working from common templates and who were, in many cases, watching each other's legislation.

The convergence creates the impression that a compliance program designed for one state's law will transfer well to other states' laws with minor adaptation. This impression is partially correct and meaningfully misleading. The conceptual framework transfers. The operational requirements in each framework differ enough that the minor adaptation assumption consistently understates the compliance work required.

The state privacy laws agree on what rights consumers should have. They disagree on who those rights apply to, when they apply, how they are exercised, and what the consequences of non-compliance are. Compliance with one state's law does not produce compliance with another's.

Where the Divergence Creates Real Compliance Work

Applicability Thresholds

State privacy laws apply to organizations that meet specified thresholds — typically defined by consumer population served, revenue, and the volume of personal data processed. The thresholds differ. CCPA applies to organizations with annual gross revenues exceeding 25 million dollars, or organizations that buy, sell, or share the personal data of 100,000 or more consumers. Virginia's CDPA applies to organizations that control or process the personal data of 100,000 or more consumers, without a revenue threshold for most organizations. Texas's law applies to organizations that process the personal data of 100,000 or more consumers, or 25,000 or more consumers if the organization derives over 50 percent of gross revenue from selling personal data.

An organization that is subject to some but not all state laws faces a threshold mapping problem: which laws apply to the organization's operations in each state, based on the combination of revenue, consumer population, and processing volume that each law uses as its applicability trigger.

Sensitive Data Definitions

Each state law has its own definition of sensitive data that requires enhanced protection — typically requiring opt-in consent rather than opt-out. The categories included in sensitive data definitions are similar but not identical across state laws. California's sensitive personal information includes certain government-issued IDs, financial account numbers, precise geolocation, and health information, among others. Virginia's sensitive data definition is similar but not identical. Texas's sensitive data definition differs in specific inclusions. Processing a specific data category requires knowing whether it is sensitive under each law that applies to the specific consumers whose data is being processed.

Opt-Out Mechanisms and Universal Opt-Out Signals

California requires that organizations honor the Global Privacy Control browser signal as a valid opt-out request. Colorado requires that organizations honor universal opt-out mechanisms. Other states have varying requirements for how opt-out must be operationalized. An organization that has built an opt-out mechanism that satisfies California's requirements may not have built one that satisfies Colorado's. The technical implementation of opt-out across multiple states requires understanding each state's specific mechanism requirements.

See how your own vendors measure up.Security and privacy posture for any vendor, from the outside, free.
Check a vendor's scorecard

Building a Multi-State Compliance Architecture

Multi-state privacy compliance at scale requires a governance architecture that can accommodate the expanding population of applicable laws without requiring a separate compliance program for each state. The practical architecture has three components.

A highest-common-denominator baseline. Privacy practices that meet the most stringent requirements across applicable state laws — typically California's requirements — create a baseline that satisfies most other states' requirements where they are less stringent. This baseline reduces the marginal compliance work for each additional state law.

State-specific gap analysis and remediation. For each state law that applies, a gap analysis against the baseline identifies the specific requirements that exceed the baseline — Colorado's universal opt-out mechanism requirements, Virginia's data protection assessment specifics, Texas's disclosure requirements. Remediating the gaps produces compliance with the specific state law.

A monitoring process for new and amended state laws. The state privacy law landscape is evolving. New states are enacting laws. States with existing laws are amending them. A monitoring process that tracks legislative developments and assesses their impact on the existing compliance architecture prevents the organization from being surprised by laws that have already taken effect.

Build the architecture to accommodate the full state law population, not just the laws that were largest when the program was designed.

Map the applicable laws. Build to the highest-common-denominator baseline. Address the state-specific gaps. Monitor for changes. The landscape will keep expanding.

Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.