State Data Protection and Privacy Risk Assessments
Also called: data protection assessments, privacy risk assessments, data privacy impact assessments — depending on the state.
Where they come from: US state comprehensive privacy laws. Virginia, Colorado, Connecticut, Texas, California and others each have their own version.
Mandatory since: 2023 in the earliest states, with more added each year.
Timing: before the triggering processing begins.
A Warning on Names
These instruments are not standardized, and the abbreviations collide.
- Some states call it a data protection assessment
- Some call it a privacy risk assessment
- California's regulations use risk assessment language of their own
And separately: "DPA" is used for both a data protection assessment — this document — and a data processing agreement — a contract with a vendor. They are unrelated.
Read the statute, not the acronym. Write both out in full when you are talking to anyone.
When One Is Required
Triggered by processing that presents heightened risk. The specific triggers vary by state, but the common set is:
- Targeted advertising
- Sale of personal data
- Profiling where it produces legal or similarly significant effects
- Sensitive data processing
- Any processing presenting a heightened risk of harm
The important consequence: these attach per state, per processing activity.
A deployment reaching consumers in four states with an assessment obligation may require an assessment in each — under each state's own rules.
What They Have to Cover
The structure is broadly consistent across states. Verify the specific requirements for each state in scope.
Identify the processing
- What the activity is
- What data is involved
- Which consumers are affected
Weigh benefits against risks
This is the distinctive feature of the state assessments. They are explicitly a balancing exercise.
- Benefits to your organization
- Benefits to the consumer
- Benefits to other stakeholders and the public
- Risks to the rights of the consumer
Account for context
Several states direct you to consider:
- Whether de-identified data could be used instead
- What the consumer reasonably expects
- The context in which the data was collected
- The relationship between your organization and the consumer
Record the safeguards
- What mitigations reduce the risk
- Whether the benefits, as mitigated, outweigh the risks
Where the Information Probably Lives
| What you need | Where to look |
|---|---|
| Which states are in scope | The customer record system; HR for employees; billing |
| Whether processing is a "sale" or "share" | Legal; the vendor contract; ad tech configuration |
| Whether targeted advertising is involved | Marketing; the ad platform configuration |
| Whether profiling produces significant effects | Business lead; what the output drives |
| Sensitive categories in scope | Business lead; IT; the data inventory |
| Benefits to the organization | The business case; the approval request |
| Benefits to consumers | Business lead; customer research |
| Consumer expectations | The privacy notice; customer research; complaint records |
| Context of collection | The privacy notice; the collection point |
| Whether de-identified data would work | The business lead and IT together |
| Existing safeguards | Information security; the privacy team |
| Retention rules | Records management; the retention schedule |
| Prior assessments for similar processing | The privacy team |
Two Families, Not One Standard
This is what makes state assessments harder than they look.
There is no single US model. There are two — and then variation inside one of them.
The Virginia model
The landscape is dominated by what is usually called the Virginia model — a template set by the Virginia Consumer Data Protection Act in 2021 and since adopted by fifteen or more states.
Colorado, Connecticut, Utah, Indiana, Montana and many others followed Virginia rather than California — partly because Virginia used clear numeric thresholds a business can assess, and partly because it created no private right of action.
California is structurally different
California's framework diverges significantly. It created the only dedicated state privacy enforcement agency, the broadest consumer rights, a limited private right of action for breaches, and the most detailed implementing regulations of any state.
A California assessment is not a Virginia assessment with the state name changed.
And the Virginia-model states still differ from each other
Sharing a template is not sharing requirements.
Sensitive data is where the divergence is widest. Virginia, Colorado, Connecticut, Oregon, Maryland and most newer laws require opt-in consent. Utah and Iowa allow opt-out.
Thresholds vary just as much. Virginia applies at 100,000 consumers. Montana at 50,000. Texas has no revenue threshold and reaches any business not classified as small. Nebraska has no threshold at all.
Even the opt-out rights differ. Most Virginia-model states provide three — sale, targeted advertising, and profiling. Iowa omits the profiling opt-out.
None of that is visible from the fact that they share a lineage.
What This Means Arithmetically
One deployment. One tool, used one way, reaching people in several places.
| Requirement | Applies when |
|---|---|
| Data Protection Impact Assessment — EU | Any EU residents affected |
| Data Protection Impact Assessment — UK | Any UK residents affected |
| Fundamental Rights Impact Assessment | If in scope, from December 2027 |
| State assessment — Virginia | If triggered |
| State assessment — Colorado | If triggered |
| State assessment — Connecticut | If triggered |
| State assessment — Texas | If triggered |
| State assessment — California | If triggered |
Eight documents for one deployment, and that list is not exhaustive. Twenty states have enacted comprehensive privacy laws as of 2026.
They are not copies of each other
- The European assessment examines risk to data
- The Fundamental Rights assessment examines risk to people's rights
- The state assessments are a benefits-versus-risks balancing exercise
- California differs structurally from the Virginia-model states
- Virginia-model states differ from each other on sensitive data, thresholds, and opt-out scope
You cannot write one and adapt it seven times.
The factual sections overlap — what the tool does, what data it processes, who is affected. Reuse those.
The analysis does not. Each instrument asks a different question, and answering the wrong one produces a document that satisfies nothing.
Working Through It
The exclusions matter as much as the triggers. Several state privacy laws exclude individuals acting in an employment context from the definition of consumer. A deployment touching only employees may fall outside those states entirely — while remaining inside others.
Practical sequence:
- Establish which states are in scope, from where the people actually are
- Check the trigger for each state separately
- Record the states assessed and excluded, with the reason
- Do not assume requirements are interchangeable
Step three is the one people skip, and it is the one that makes the file defensible.
Who Supplies What
You or the privacy function:
- Determining which states are in scope
- Checking triggers per state
- Structure and assembly
- The balancing analysis
The business:
- What the processing achieves
- Benefits to the organization and to consumers
- What the output drives
Marketing and ad operations:
- Whether targeted advertising is involved
- What data flows to advertising platforms
Legal or counsel:
- Whether an exclusion applies
- Whether a "sale" or "share" is occurring
- Whether the assessment is sufficient
Common Gaps
- Scoped from where the company operates rather than where the consumers are.
- One assessment used for all states without checking whether the requirements match.
- Benefits stated, risks not. It is a balancing exercise. Both sides have to be present.
- Consumer benefit asserted without basis. "Consumers benefit from a better experience" is not an analysis.
- De-identification never considered. Several states direct you to consider it. Record the conclusion either way.
- Exclusions relied on but not documented. If a state is out of scope, write down why.
- Never revisited when a new state law took effect. New states are added regularly.
One Practical Note
The state assessments are a balancing exercise, not a risk register.
An assessment that lists risks and mitigations but never states whether the benefits outweigh them has not answered the question the statute asks.
Triggering thresholds and content requirements vary by state and change regularly. Verify against the current text for each state in scope before relying on this handout.
Sources
Statutes referenced
- Virginia Consumer Data Protection Act
- Colorado Privacy Act
- Connecticut Data Privacy Act
- Texas Data Privacy and Security Act
- California Consumer Privacy Act as amended, and the implementing regulations
On the comparative claims
The characterization of a dominant "Virginia model," the count of states with comprehensive privacy laws, the opt-in and opt-out split on sensitive data, and the threshold variations are drawn from published comparative analyses current to 2026. They are directional rather than definitive.
Verify each state's requirements against its own statute before relying on them. Thresholds, sensitive data definitions, exclusions, and cure periods all vary, and several have been amended since enactment.
A standing note
New state laws are enacted every legislative session, and existing ones are amended. Any list of states in this handout is a snapshot.
Use and reuse
Free to use, share, and adapt within your organization. Attribution appreciated, not required. No warranty of any kind — this is practitioner guidance, not legal advice, and sufficiency is determined by your counsel.
LegisGate · Regulatory Intelligence for AI Deployments · legisgate.com
Written by compliance and audit practitioners who spent decades on the other side of the table.
Version 1.0 · Current as of August 2026 · Verify time-sensitive claims against current sources before relying on them.