Understanding State Privacy Laws
Your data governance team is grappling with 12 different state privacy laws, each with its own rules for handling sensitive personal information. California wants a "Limit" link. Colorado demands opt-in consent. Utah requires a "clear notice" but doesn't define it. Iowa is similar to Utah but uses different language.
These questions arise from the gap between reading the law and actually configuring your systems. They're what people ask in implementation meetings when the compliance memo meets the CRM roadmap. Here's what you need to know.
California: Consent and Limitations
California doesn't require residents to opt in before you process their sensitive personal information. You can process it as long as your privacy policy discloses what you're doing.
However, California residents have the right to limit the use of their sensitive personal information (SPI) if you're using it to infer characteristics about them or for purposes outside the specific list in Section 7027(m) of the CCPA regulations.
Permitted purposes are narrow, covering things like processing location data for navigation features or running a medical search engine (as long as you're not inferring characteristics about the person). If your use case doesn't fit those categories, you must offer a "Limit the Use of My Sensitive Personal Information" link and honor requests within 15 business days. You can't ask someone who's limited their SPI use to reconsider for at least 12 months.
Opt-In Consent Requirements
Nine states, Colorado, Connecticut, Delaware, Indiana, Montana, Oregon, Tennessee, Texas, and Virginia, require you to obtain valid opt-in consent before processing SPI. Consent must be a clear affirmative act that's freely given, specific, informed, and unambiguous.
Here's what doesn't count as valid consent:
- Acceptance of broad terms bundled with unrelated agreements
- Hovering over, muting, or closing content
- Any agreement obtained through dark patterns
- Inaction (in Oregon's definition)
Colorado's rules specify that valid consent must be:
- Clear affirmative action: conduct or statements indicating acceptance
- Freely given: refusable or revocable without penalty
- Specific: separate consent for unrelated purposes
- Informed: accompanied by a clear notice with required details
- Unambiguous: not obtained through dark patterns
If someone withdraws consent in Colorado, you must delete the SPI or render it permanently anonymized or inaccessible within a reasonable timeframe.
Data Protection Assessments
If you're operating under Colorado, Connecticut, Delaware, Indiana, Montana, Oregon, Tennessee, Texas, or Virginia law, you must conduct a data protection assessment before processing SPI.
This assessment evaluates the risks your processing activities pose to individuals. You're documenting why you need the data, what safeguards you've implemented, and how you'll minimize risk. The assessment requirement runs parallel to the opt-in consent requirement. You need both before you start processing.
Notice and Opt-Out in Iowa and Utah
Iowa and Utah don't require opt-in consent. Instead, you must present residents with a clear notice and opportunity to opt out before processing their SPI.
Neither state defines what constitutes a "clear notice" or how to present the opt-out opportunity. Both laws say the notice must be "presented" to consumers, suggesting you can't just bury it in your privacy policy. You likely need a separate, active disclosure.
This approach creates a middle ground between California's "process first, offer a limit option" and Colorado's "get consent before processing" model. You're allowed to process unless someone opts out, but you must give them a meaningful chance to do so upfront.
Special Notices for Selling Sensitive Data in Texas
If you're selling sensitive data under Texas law, you must post this notice in the same manner and location as your privacy policy (typically your website footer):
"NOTICE: We may sell your sensitive personal data."
If you're selling biometric data specifically, the notice changes slightly:
"NOTICE: We may sell your biometric personal data."
This is separate from your general privacy policy. It's a direct, consumer-facing alert that must appear prominently.
Connecticut's Rules for Consumer Health Data
Connecticut treats consumer health data as a subset of sensitive data with additional restrictions. Consumer health data includes any personal data used to identify someone's physical or mental health condition or diagnosis, including gender-affirming health data and reproductive or sexual health data.
Two specific prohibitions:
- You cannot sell consumer health data without obtaining consent.
- You cannot use a geofence within 1,750 feet of mental health, reproductive, or sexual health facilities to identify, track, collect, or send notifications related to consumer health data.
If you're running location-based advertising or notification systems near healthcare facilities, this rule directly affects your technical configuration.
One Consent Mechanism for All States?
Not cleanly. You've got three different models:
California: Process without consent, but offer a "Limit" option and honor requests within 15 business days.
Nine states (CO, CT, DE, IN, MT, OR, TN, TX, VA): Obtain opt-in consent and complete a data protection assessment before processing.
Two states (IA, UT): Present a clear notice and opt-out opportunity before processing.
If you operate nationally, your most defensible approach is to implement the strictest standard (opt-in consent with data protection assessments) across all states. That satisfies Colorado's requirements and exceeds what California, Iowa, and Utah require.
The alternative is building state-specific consent flows, which increases complexity and introduces configuration risk.
Handling Data Considered Sensitive in Some States
Check the definitions carefully. While most states agree on categories like precise geolocation, racial or ethnic origin, and health diagnoses, California's definition is broader. It includes account credentials, government IDs, contents of communications (where you're not the recipient), philosophical beliefs, and union membership.
If you're processing any of these California-specific categories, you need California's "Limit" mechanism even if other states don't classify that data as sensitive.
Also remember: state privacy laws aren't the only regulations that apply. Illinois, Washington, and Texas have separate biometric data laws. Washington and Nevada have health data laws. New York City has its own biometric rules. Complying with state privacy laws doesn't exempt you from these sector-specific requirements.
Next Steps
Start with your state's regulations, not just the statute. Colorado's Rule 7.03 provides the clearest breakdown of what valid consent requires. Section 7027(m) of California's updated CCPA regulations lists the permitted purposes that don't trigger the right to limit.
If you're building consent flows, map your data types to each state's definition of SPI first. Then determine which states' laws apply based on where your users are located. Only then can you design a consent mechanism that actually works across jurisdictions.
And if you're using geofencing anywhere near healthcare facilities, review Connecticut's 1,750-foot rule before your next campaign goes live.





