Skip to main content
State Privacy Notice Compliance AuditLaws and Regulations
5 min readFor DPOs (Data Protection Officers)

State Privacy Notice Compliance Audit

Connecticut's $85,000 enforcement action against TicketNetwork marks a turning point: state attorneys general are no longer issuing warnings. They're issuing fines. The violations weren't exotic edge cases; they were privacy notice configuration errors that exist on thousands of websites right now.

This checklist translates the Connecticut AG's enforcement priorities into actionable audit items. Use it to verify your privacy notice meets state-specific requirements before a regulator does it for you.

Prerequisites

Before starting this audit:

  • Confirm which state privacy laws apply to your organization (CTDPA, CCPA/CPRA, VCDPA, CPA, UCPA, or others).
  • Locate your current privacy notice and all state-specific addenda.
  • Identify the email addresses or web forms consumers use to submit rights requests.
  • Gather a copy of your consumer rights request handling procedures.

If you're relying on a single "omnibus" privacy notice to cover multiple state laws, flag that now. The Connecticut enforcement action shows this approach creates compliance gaps.

Privacy Notice Structure and Accessibility

1. Font Size and Readability

Requirement: Your privacy notice must use legible font sizes and avoid dense, unbroken text blocks.

How to verify: Print your privacy notice. If you squint to read it or lose your place in paragraph blocks longer than 6-7 lines, it fails.

What good looks like: 12-point or larger font, paragraph breaks every 4-6 sentences, clear section headings that let readers scan for specific rights.

2. Placement and Isolation

Requirement: Privacy disclosures must be distinguishable from unrelated legal policies.

How to verify: Does your privacy notice appear on the same page as your Terms of Service, Acceptable Use Policy, or Copyright Notice without clear visual separation?

What good looks like: A dedicated privacy notice page, or if combined with other policies, clear visual dividers (headings, spacing, or separate expandable sections) that prevent readers from mistaking one policy for another.

State-Specific Consumer Rights Disclosure

3. Right to Correct Inaccurate Data

Requirement: Connecticut consumers have the right to correct inaccurate personal data. Your notice must state this explicitly in your Connecticut-specific section.

How to verify: Search your privacy notice for "correct" or "rectify" within your CTDPA disclosures. If it's missing or only mentioned in your GDPR section, you're non-compliant.

What good looks like: "Connecticut consumers have the right to correct inaccuracies in their personal data" with clear instructions on how to submit a correction request.

4. Right to Opt Out of Targeted Advertising

Requirement: CTDPA requires disclosure of the right to opt out of targeted advertising (not just "sale" of data).

How to verify: Check whether your Connecticut section mentions both sale opt-out AND targeted advertising opt-out as separate rights. The TicketNetwork case flagged the omission of targeted advertising opt-out as a specific deficiency.

What good looks like: Separate bullet points for "opt out of sale of personal data" and "opt out of targeted advertising," each with its own mechanism or a single mechanism that addresses both.

5. Right to Appeal and Appeal Procedures

Requirement: Connecticut consumers must be informed they can appeal a decision regarding their rights request and how to do so.

How to verify: Does your privacy notice explain what happens if you deny a consumer's request? Does it provide an email address or process for appeals?

What good looks like: "If we deny your request, you may appeal our decision by emailing [appeal-specific address] within 30 days. We will respond to your appeal within 45 days."

Request Handling and Limitations

6. Lookback Period Restrictions

Requirement: Do not impose a 12-month lookback limit on access requests unless the specific state law permits it. The CTDPA does not.

How to verify: Review your privacy notice and internal request-handling procedures. If you state "we will provide data from the past 12 months," verify that Connecticut law authorizes this limitation. It doesn't.

What good looks like: "We will provide the personal data we maintain about you" without an arbitrary time restriction, or a restriction explicitly authorized by the applicable state statute.

7. Request Frequency Caps

Requirement: Do not limit how many times per year a consumer can submit a valid rights request unless the state law explicitly permits it.

How to verify: Search your privacy notice for phrases like "twice per year" or "no more than X requests." The CTDPA contains no such limit.

What good looks like: Either no mention of request frequency limits, or a statement that clarifies: "We may decline requests that are manifestly unfounded or excessive, particularly if repetitive, as permitted under [cite specific statute section]."

8. State-Specific Contact Mechanisms

Requirement: Do not use email addresses or web forms that imply rights are limited to one state's residents (e.g., "californiaconsumerrights@...").

How to verify: Review all email addresses and web form URLs listed in your privacy notice. Do any reference a single state by name?

What good looks like: "[email protected]" or "Submit a Privacy Rights Request" without state-specific branding, paired with clear instructions that the mechanism serves residents of all applicable states.

9. Functional Opt-Out Links

Requirement: Any hyperlink to opt out of sale or targeted advertising must be operational.

How to verify: Click every opt-out link in your privacy notice from an incognito browser. Does it load? Does it present a functional interface?

What good looks like: The link loads within 3 seconds, presents clear opt-out choices, and confirms the opt-out action with a confirmation message or email.

Common Mistakes

Copying California disclosures verbatim. Connecticut's rights differ from California's. Your CTDPA section must reflect Connecticut's specific requirements, not just duplicate your CCPA section with "Connecticut" substituted for "California."

Assuming one cure notice buys unlimited time. The CTDPA's 60-day cure period (which expired December 31, 2024) required businesses to remedy deficiencies to the AG's satisfaction. Incomplete fixes triggered further enforcement. Going forward, there is no cure period.

Ignoring regulator follow-up. The Connecticut AG sent multiple letters before filing the enforcement action. Non-responsiveness signals to regulators that you're not taking compliance seriously.

Relying on your CMP vendor's default templates. Most Consent Management Platform templates are written for GDPR or CCPA. They don't automatically incorporate CTDPA-specific rights like correction or appeal procedures.

Next Steps

Run this audit quarterly, or whenever you update your privacy notice or expand into a new state. Document each audit with screenshots and dated notes. If a regulator asks what steps you took to ensure compliance, "we reviewed it" isn't sufficient. "We completed a checklist audit on [date], identified three gaps, and remediated them within 14 days" is.

If you discover deficiencies, fix them immediately. The Connecticut case shows that partial fixes or delayed responses don't satisfy regulators. Set internal deadlines shorter than any statutory cure period, and treat every regulator inquiry as if enforcement is the alternative, because it is.

You Might Also Like