You're operating under 20 state privacy laws, with two more arriving in 2027. There's still no federal baseline to simplify this. What you need isn't another law-by-law summary, it's a decision framework that tells you what to build once and where you need state-specific adjustments.
This checklist walks you through the common compliance elements that satisfy most state laws, then flags the handful of requirements that demand separate attention. It's built for teams managing consent across multiple jurisdictions without rebuilding your privacy program twenty times.
Prerequisites
Before you start this checklist, confirm:
You've mapped your coverage. You know which state laws apply based on your revenue, consumer counts, and business activities. Texas covers you if you're not an SBA-defined small business. Connecticut's 2026 amendments dropped the threshold to 35,000 consumers and added triggers for any volume of sensitive-data processing or data sales.
You have enforcement authority. Your privacy officer or legal team can make binding decisions about data-processing activities, vendor contracts, and consent-mechanism design.
Your CMP can segment by jurisdiction. You'll need different consent flows for California versus Utah, and Global Privacy Control (GPC) recognition in twelve states versus silence in eight others.
The Baseline Checklist
1. Privacy notice published and accessible
What to check: Your privacy policy discloses all processing purposes, data categories, third-party sharing, consumer rights, and contact information for requests.
Good looks like: A notice written in plain language, linked from every page footer, covering every state law you're subject to. You've disclosed sensitive-data processing separately, named the categories, and explained automated decision-making if you do profiling.
2. Consumer rights request mechanism in place
What to check: You accept and respond to requests for access, deletion, correction, and portability. You've built an intake form, assigned an internal owner, and documented your verification process.
Good looks like: A web form or email address published in your privacy notice, a 45-day response timeline, and a process that doesn't require account creation to submit a request.
3. Opt-out mechanisms for sale and targeted advertising
What to check: You offer a clear, conspicuous way to opt out of data sales and targeted advertising. This applies even if you call it "sharing for cross-context Behavioural Advertising" instead of a sale.
Good looks like: A "Do Not Sell or Share My Personal Information" link in your site footer, a preference center that doesn't require login, and a process that applies the opt-out within 15 business days.
4. Sensitive data handled under opt-in consent or notice-and-opt-out
What to check: If you process race, religion, health data, sexual orientation, biometric identifiers, precise geolocation, citizenship status, or data of known children, you've confirmed whether your applicable state laws require opt-in consent (most states) or notice-and-opt-out (Utah only).
Good looks like: A separate consent checkbox before processing sensitive data in California, Virginia, Colorado, Connecticut, and the other opt-in states. If you're Utah-only, a clear notice and an easy opt-out satisfies the requirement.
5. Global Privacy Control (GPC) recognized where required
What to check: Twelve states now require you to honor GPC signals: California, Colorado, Connecticut, Texas, Oregon, Montana, Delaware, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland. Your CMP detects the GPC header or JavaScript property and suppresses non-essential cookies automatically.
Good looks like: A technical implementation that reads navigator.globalPrivacyControl or the Sec-GPC: 1 HTTP header, treats it as a legally binding opt-out, and logs the signal in your consent records. You don't show a Consent Notice to GPC users; you block third-party cookies immediately.
6. Privacy impact assessments completed for high-risk processing
What to check: You've documented assessments for targeted advertising, data sales, profiling, sensitive-data processing, and automated decision-making. Nineteen states require these; only Utah doesn't.
Good looks like: A written assessment for each high-risk activity that identifies risks to consumers, describes safeguards, and explains why the processing is necessary. You update assessments when processing changes and store them where your AG can request them during an investigation.
7. Vendor contracts updated with data-processing terms
What to check: Every vendor that processes personal data on your behalf has signed a contract with processing instructions, confidentiality obligations, security requirements, and deletion duties.
Good looks like: A data-processing addendum (DPA) attached to every SaaS contract, every analytics provider, every ad-tech vendor. The DPA prohibits the vendor from selling your customers' data, requires breach notification, and survives contract termination for deletion obligations.
8. Data retention and deletion schedules documented
What to check: You've defined how long you keep each data category and why. You delete or anonymize data when the retention period expires or a consumer requests deletion.
Good looks like: A retention matrix that lists data types, legal basis for retention, and deletion triggers. Your systems execute scheduled deletions automatically, and you can prove compliance if a regulator asks.
State-Specific Adjustments
California: private right of action and CPPA rulemaking
What to check: You've implemented reasonable security for personal information (because consumers can sue you for breaches at $100 to $750 per person per incident), and you're tracking California Privacy Protection Agency rulemakings on risk assessments, automated decision-making, and AI.
Good looks like: Annual security audits, breach response plans, and a process for monitoring CPPA proposed rules before they finalize.
Connecticut: expanded sensitive-data list and no-threshold triggers
What to check: You've confirmed whether you process Connecticut's broadest-in-class sensitive-data definition (which includes financial account numbers with access credentials, government IDs, crime-victim status, and disability status). If you do, you're covered even if you process data for fewer than 35,000 Connecticut consumers.
Good looks like: A sensitive-data inventory that flags Connecticut-specific categories and a compliance confirmation that you're either under the threshold or you've implemented opt-in consent.
Texas: no small-business exemption and AG enforcement sweeps
What to check: If you're not an SBA-defined small business, you're covered regardless of revenue or consumer count. Texas's attorney general runs active privacy sweeps, so your compliance posture needs to be audit-ready.
Good looks like: Documentation proving you meet the small-business exemption or full TDPSA compliance, including impact assessments and GPC recognition.
Colorado: $20,000-per-violation fines and no cure period
What to check: Colorado's penalties run higher than most states, and the cure period expired in January 2025. You can't fix violations after the AG files suit.
Good looks like: Quarterly compliance audits, documented GPC implementation since July 2024, and a process that treats Colorado violations as zero-tolerance.
Common Mistakes
Treating "no GPC requirement" as permission to ignore GPC. Eight states don't require GPC recognition, but if a user enables it, you're still bound by their opt-out in the twelve states that do require it. Segment by jurisdiction; don't ignore the signal entirely.
Assuming the 30-day cure period buys you time. Virginia and Utah still offer perpetual cure periods, but most states sunset theirs or never offered one. California, Colorado (since January 2025), and Connecticut (since December 2024) enforce on first violation.
Using the same sensitive-data list across all states. Connecticut includes financial credentials and disability status. California adds neural data. Oregon covers reproductive health. Your CMP needs jurisdiction-specific sensitive-data handling, not a single global list.
Skipping impact assessments because "we're low-risk." If you run Behavioural Advertising, sell data, or process sensitive data, you're high-risk under nineteen state laws. The assessment isn't optional, and "we haven't been sued yet" isn't a defense.
Next Steps
Run this checklist quarterly, not once. State laws change mid-year (Connecticut's amendments took effect in July 2026), GPC requirements phase in on different timelines (Oregon and Delaware added GPC in January 2026), and your own processing activities shift as you add vendors or launch new products.
Assign a single owner to track state-law amendments. Subscribe to attorney general guidance updates in California, Colorado, and Texas, the three states publishing the most active enforcement positions.
If you're covered by ten or more state laws, build to the California standard and layer in the few stricter requirements (Connecticut's sensitive-data list, Colorado's fine structure, GPC in the twelve states that require it). You'll satisfy the baseline everywhere and avoid rebuilding your privacy program every time a new state goes live.



