Handout · State AssessmentsThe Handbook
§Handout

State Data Protection and Privacy Risk Assessments

Also called: data protection assessments, privacy risk assessments, data privacy impact assessments — depending on the state.

Where they come from: US state comprehensive privacy laws. Virginia, Colorado, Connecticut, Texas, California and others each have their own version.

Mandatory since: 2023 in the earliest states, with more added each year.

Timing: before the triggering processing begins.


A Warning on Names

These instruments are not standardized, and the abbreviations collide.

  • Some states call it a data protection assessment
  • Some call it a privacy risk assessment
  • California's regulations use risk assessment language of their own

And separately: "DPA" is used for both a data protection assessment — this document — and a data processing agreement — a contract with a vendor. They are unrelated.

Read the statute, not the acronym. Write both out in full when you are talking to anyone.


When One Is Required

Triggered by processing that presents heightened risk. The specific triggers vary by state, but the common set is:

  • Targeted advertising
  • Sale of personal data
  • Profiling where it produces legal or similarly significant effects
  • Sensitive data processing
  • Any processing presenting a heightened risk of harm

The important consequence: these attach per state, per processing activity.

A deployment reaching consumers in four states with an assessment obligation may require an assessment in each — under each state's own rules.


What They Have to Cover

The structure is broadly consistent across states. Verify the specific requirements for each state in scope.

Identify the processing

  • What the activity is
  • What data is involved
  • Which consumers are affected

Weigh benefits against risks

This is the distinctive feature of the state assessments. They are explicitly a balancing exercise.

  • Benefits to your organization
  • Benefits to the consumer
  • Benefits to other stakeholders and the public
  • Risks to the rights of the consumer

Account for context

Several states direct you to consider:

  • Whether de-identified data could be used instead
  • What the consumer reasonably expects
  • The context in which the data was collected
  • The relationship between your organization and the consumer

Record the safeguards

  • What mitigations reduce the risk
  • Whether the benefits, as mitigated, outweigh the risks

Where the Information Probably Lives

What you needWhere to look
Which states are in scopeThe customer record system; HR for employees; billing
Whether processing is a "sale" or "share"Legal; the vendor contract; ad tech configuration
Whether targeted advertising is involvedMarketing; the ad platform configuration
Whether profiling produces significant effectsBusiness lead; what the output drives
Sensitive categories in scopeBusiness lead; IT; the data inventory
Benefits to the organizationThe business case; the approval request
Benefits to consumersBusiness lead; customer research
Consumer expectationsThe privacy notice; customer research; complaint records
Context of collectionThe privacy notice; the collection point
Whether de-identified data would workThe business lead and IT together
Existing safeguardsInformation security; the privacy team
Retention rulesRecords management; the retention schedule
Prior assessments for similar processingThe privacy team

Two Families, Not One Standard

This is what makes state assessments harder than they look.

There is no single US model. There are two — and then variation inside one of them.

The Virginia model

The landscape is dominated by what is usually called the Virginia model — a template set by the Virginia Consumer Data Protection Act in 2021 and since adopted by fifteen or more states.

Colorado, Connecticut, Utah, Indiana, Montana and many others followed Virginia rather than California — partly because Virginia used clear numeric thresholds a business can assess, and partly because it created no private right of action.

California is structurally different

California's framework diverges significantly. It created the only dedicated state privacy enforcement agency, the broadest consumer rights, a limited private right of action for breaches, and the most detailed implementing regulations of any state.

A California assessment is not a Virginia assessment with the state name changed.

And the Virginia-model states still differ from each other

Sharing a template is not sharing requirements.

Sensitive data is where the divergence is widest. Virginia, Colorado, Connecticut, Oregon, Maryland and most newer laws require opt-in consent. Utah and Iowa allow opt-out.

Thresholds vary just as much. Virginia applies at 100,000 consumers. Montana at 50,000. Texas has no revenue threshold and reaches any business not classified as small. Nebraska has no threshold at all.

Even the opt-out rights differ. Most Virginia-model states provide three — sale, targeted advertising, and profiling. Iowa omits the profiling opt-out.

None of that is visible from the fact that they share a lineage.


What This Means Arithmetically

One deployment. One tool, used one way, reaching people in several places.

RequirementApplies when
Data Protection Impact Assessment — EUAny EU residents affected
Data Protection Impact Assessment — UKAny UK residents affected
Fundamental Rights Impact AssessmentIf in scope, from December 2027
State assessment — VirginiaIf triggered
State assessment — ColoradoIf triggered
State assessment — ConnecticutIf triggered
State assessment — TexasIf triggered
State assessment — CaliforniaIf triggered

Eight documents for one deployment, and that list is not exhaustive. Twenty states have enacted comprehensive privacy laws as of 2026.

They are not copies of each other

  • The European assessment examines risk to data
  • The Fundamental Rights assessment examines risk to people's rights
  • The state assessments are a benefits-versus-risks balancing exercise
  • California differs structurally from the Virginia-model states
  • Virginia-model states differ from each other on sensitive data, thresholds, and opt-out scope

You cannot write one and adapt it seven times.

The factual sections overlap — what the tool does, what data it processes, who is affected. Reuse those.

The analysis does not. Each instrument asks a different question, and answering the wrong one produces a document that satisfies nothing.


Working Through It

The exclusions matter as much as the triggers. Several state privacy laws exclude individuals acting in an employment context from the definition of consumer. A deployment touching only employees may fall outside those states entirely — while remaining inside others.

Practical sequence:

  1. Establish which states are in scope, from where the people actually are
  2. Check the trigger for each state separately
  3. Record the states assessed and excluded, with the reason
  4. Do not assume requirements are interchangeable

Step three is the one people skip, and it is the one that makes the file defensible.


Who Supplies What

You or the privacy function:

  • Determining which states are in scope
  • Checking triggers per state
  • Structure and assembly
  • The balancing analysis

The business:

  • What the processing achieves
  • Benefits to the organization and to consumers
  • What the output drives

Marketing and ad operations:

  • Whether targeted advertising is involved
  • What data flows to advertising platforms

Legal or counsel:

  • Whether an exclusion applies
  • Whether a "sale" or "share" is occurring
  • Whether the assessment is sufficient

Common Gaps

  • Scoped from where the company operates rather than where the consumers are.
  • One assessment used for all states without checking whether the requirements match.
  • Benefits stated, risks not. It is a balancing exercise. Both sides have to be present.
  • Consumer benefit asserted without basis. "Consumers benefit from a better experience" is not an analysis.
  • De-identification never considered. Several states direct you to consider it. Record the conclusion either way.
  • Exclusions relied on but not documented. If a state is out of scope, write down why.
  • Never revisited when a new state law took effect. New states are added regularly.

One Practical Note

The state assessments are a balancing exercise, not a risk register.

An assessment that lists risks and mitigations but never states whether the benefits outweigh them has not answered the question the statute asks.


Triggering thresholds and content requirements vary by state and change regularly. Verify against the current text for each state in scope before relying on this handout.

Sources

Statutes referenced

  • Virginia Consumer Data Protection Act
  • Colorado Privacy Act
  • Connecticut Data Privacy Act
  • Texas Data Privacy and Security Act
  • California Consumer Privacy Act as amended, and the implementing regulations

On the comparative claims

The characterization of a dominant "Virginia model," the count of states with comprehensive privacy laws, the opt-in and opt-out split on sensitive data, and the threshold variations are drawn from published comparative analyses current to 2026. They are directional rather than definitive.

Verify each state's requirements against its own statute before relying on them. Thresholds, sensitive data definitions, exclusions, and cure periods all vary, and several have been amended since enactment.

A standing note

New state laws are enacted every legislative session, and existing ones are amended. Any list of states in this handout is a snapshot.


Use and reuse

Free to use, share, and adapt within your organization. Attribution appreciated, not required. No warranty of any kind — this is practitioner guidance, not legal advice, and sufficiency is determined by your counsel.

LegisGate · Regulatory Intelligence for AI Deployments · legisgate.com

Written by compliance and audit practitioners who spent decades on the other side of the table.

Version 1.0 · Current as of August 2026 · Verify time-sensitive claims against current sources before relying on them.

Contents
Talk to usWe're here to help
US State Privacy Risk Assessment Guide | LegisGate