Skip to main content
State Privacy Laws Hit 15: Your Multi-Jurisdiction ChecklistLaws and Regulations
5 min readFor Privacy Officers

State Privacy Laws Hit 15: Your Multi-Jurisdiction Checklist

With Indiana, Kentucky, and Rhode Island now enforcing comprehensive privacy laws as of January 1, 2026, nearly half of US states require organizations to manage consumer rights, conduct Data Protection Impact Assessments, and handle cure provisions that vary by jurisdiction. This checklist helps you implement a flexible compliance framework that adapts to each state's requirements without rebuilding your program multiple times.

Prerequisites

Before working through this checklist, confirm:

  • You've mapped your consumer base by state. Accurate counts of residents whose data you process in each jurisdiction are essential to determine applicable thresholds (Rhode Island's 35,000-resident threshold is lower than most states).

  • You've identified your legal basis for processing. Each consumer right and DPIA trigger depends on your data activities (selling, targeted advertising, profiling, sensitive data processing).

  • You have a cross-functional team. Privacy compliance involves legal, engineering, product, marketing, and customer support. Assign owners now.

Good looks like: A spreadsheet showing resident counts by state, processing activities mapped to legal bases, and named owners for each compliance domain.

Compliance Checklist

1. Map your cure period exposure by state

Indiana and Kentucky provide an opportunity to cure violations before enforcement action, while Rhode Island does not. Seven other states with comprehensive privacy laws also offer cure periods.

Action: Create a matrix showing which states allow cure, the cure window, and your internal escalation process when you receive a notice.

Good looks like: Your legal team can answer "Do we have a cure period in this state?" in under 30 seconds, and your incident response plan reflects different timelines for cure vs. non-cure jurisdictions.

2. Implement consumer rights infrastructure for access, correction, deletion, and portability

All three states require you to honor these requests. Indiana limits correction obligations to information the consumer submitted (not inferred or derived data).

Action: Update your data subject request workflow to flag Indiana requests separately and route correction requests through a validation step that confirms the data type.

Good looks like: When an Indiana resident requests correction of their purchase history, your system accepts it. When they request correction of a credit score you calculated, your system explains the limitation and offers deletion instead.

3. Build controls for targeted advertising opt-outs

Residents in these states now have the right to opt out of targeted advertising. This isn't a consent requirement under most state laws, but you must honor the opt-out.

Action: Add state-specific opt-out signals to your Consent Management Platform. Ensure your ad tech stack respects these signals before serving behavioral ads.

Good looks like: A Kentucky resident who opts out of targeted advertising sees contextual ads only, and your ad server logs show the opt-out signal was processed before bid requests went out.

4. Implement sensitive data processing controls

Health information, religious beliefs, and other sensitive categories trigger heightened obligations. Consumers must be able to control how you process this data.

Action: Inventory where you collect or infer sensitive data. Build granular consent or opt-out mechanisms for each category.

Good looks like: Your health app asks separately for permission to process health data for product improvement vs. sharing with research partners, and users can toggle each purpose independently.

5. Conduct Data Protection Impact Assessments for high-risk activities

All three states require DPIAs when you engage in high-risk profiling, process sensitive information, sell data, or conduct targeted advertising. Iowa and Utah are the only state exceptions to this pattern.

Action: Document your DPIA triggers in a decision tree. For each trigger, assign a template and review cadence. DPIAs aren't one-time exercises; you'll need to refresh them as processing changes.

Good looks like: When your product team proposes a new profiling algorithm, the DPIA requirement is flagged automatically in your project management system, and the launch checklist includes "DPIA completed and reviewed by legal."

6. Configure your multi-state disclosure strategy

You can't write fifteen separate privacy notices. Build a layered disclosure that highlights state-specific rights and links to detailed information.

Action: Use geolocation to show state-specific consumer rights in your privacy notice. Maintain a single source of truth for each state's requirements and auto-populate your notice from that database.

Good looks like: A Rhode Island visitor sees their rights listed with a link to your request portal. An Indiana visitor sees identical rights with a note that correction is limited to submitted information. Both disclosures pull from the same backend system.

7. Test your request response timelines

Most state laws give you 45 days to respond to consumer requests, with a possible 45-day extension if the request is complex. Your systems need to track deadlines by state.

Action: Build automated deadline tracking into your request management system. Flag requests approaching their deadline seven days out.

Good looks like: Your support team sees a dashboard showing requests by state, days remaining, and escalation status. No request misses its deadline because someone forgot to check a spreadsheet.

Common Mistakes

Treating state laws as identical. Rhode Island's lack of a cure period and 35,000-resident threshold make it operationally different from Indiana and Kentucky. Your compliance program needs state-specific logic, not a one-size-fits-all approach.

Building state-by-state systems. The opposite mistake is creating fifteen separate compliance programs. Use a principles-based framework that handles common requirements (access, deletion, opt-outs) centrally, with configuration flags for state-specific nuances.

Ignoring amendment risk. California, Colorado, Connecticut, Montana, and Oregon have all amended their privacy laws after enactment. Your compliance program needs version control and a change management process.

Forgetting about vendors. Your data processors need to support state-specific consumer rights. If your CRM can't filter requests by state or your ad tech can't honor state-level opt-outs, you're not compliant no matter how good your internal systems are.

Assuming cure periods are safety nets. Indiana and Kentucky's cure provisions don't mean you can launch non-compliant and fix it later. Cure periods protect against good-faith mistakes, not systemic failures. Regulators notice patterns.

Next Steps

Month 1: Complete your state-by-state threshold analysis and confirm which laws apply to you. Map your processing activities to DPIA triggers.

Month 2: Implement consumer rights infrastructure with state-specific routing. Test your request workflow with synthetic requests from each state.

Month 3: Conduct DPIAs for triggered activities. Document your findings and mitigation measures. Schedule annual reviews.

Ongoing: Monitor state legislative activity. When a new state passes a privacy law (and they will), your principles-based framework should accommodate it with configuration changes, not a program rebuild.

The fragmentation isn't slowing down. Your compliance strategy needs to be more adaptive than the regulatory landscape is chaotic. Build systems that scale across jurisdictions, document your state-specific decisions, and treat cure periods as insurance rather than strategy.

You Might Also Like