State Data Protection and Privacy Risk Assessments
Also called: data protection assessments, privacy risk assessments, data privacy impact assessments — depending on the state.
Where they come from: US state comprehensive privacy laws. Virginia, Colorado, Connecticut, Texas, California and others each have their own version.
Mandatory since: 2023 in the earliest states, with more added each year. Connecticut added a dedicated profiling impact assessment, separate from its general data protection assessment, from August 1, 2026.
Timing: before the triggering processing begins.
A Warning on Names
These instruments are not standardized, and the abbreviations collide.
- Some states call it a data protection assessment
- Some call it a privacy risk assessment
- California's regulations use risk assessment language of their own
And separately: "DPA" is used for both a data protection assessment — this document — and a data processing agreement — a contract with a vendor. They are unrelated.
Read the statute, not the acronym. Write both out in full when you are talking to anyone.
When One Is Required
Triggered by processing that presents heightened risk. The specific triggers vary by state, but the common set is:
- Targeted advertising
- Sale of personal data
- Profiling where it produces legal or similarly significant effects
- Sensitive data processing
- Any processing presenting a heightened risk of harm
The important consequence: these attach per state, per processing activity.
A deployment reaching consumers in four states with an assessment obligation may require an assessment in each — under each state's own rules.
What They Have to Cover
The structure is broadly consistent across states. Verify the specific requirements for each state in scope.
Identify the processing
- What the activity is
- What data is involved
- Which consumers are affected
Weigh benefits against risks
This is the distinctive feature of the state assessments. They are explicitly a balancing exercise.
- Benefits to your organization
- Benefits to the consumer
- Benefits to other stakeholders and the public
- Risks to the rights of the consumer
Account for context
Several states direct you to consider:
- Whether de-identified data could be used instead
- What the consumer reasonably expects
- The context in which the data was collected
- The relationship between your organization and the consumer
Record the safeguards
- What mitigations reduce the risk
- Whether the benefits, as mitigated, outweigh the risks
Where the Information Probably Lives
| What you need | Where to look |
|---|---|
| Which states are in scope | The customer record system; HR for employees; billing |
| Whether processing is a "sale" or "share" | Legal; the vendor contract; ad tech configuration |
| Whether targeted advertising is involved | Marketing; the ad platform configuration |
| Whether profiling produces significant effects | Business lead; what the output drives |
| Sensitive categories in scope | Business lead; IT; the data inventory |
| Benefits to the organization | The business case; the approval request |
| Benefits to consumers | Business lead; customer research |
| Consumer expectations | The privacy notice; customer research; complaint records |
| Context of collection | The privacy notice; the collection point |
| Whether de-identified data would work | The business lead and IT together |
| Existing safeguards | Information security; the privacy team |
| Retention rules | Records management; the retention schedule |
| Prior assessments for similar processing | The privacy team |
Two Families, Not One Standard
This is what makes state assessments harder than they look.
There is no single US model. There are two — and then variation inside one of them.
The Virginia model
The landscape is dominated by what is usually called the Virginia model — a template set by the Virginia Consumer Data Protection Act in 2021 and since followed, with variations, by most of the states that legislated after it.
Colorado, Connecticut, Utah, Indiana, Montana and many others followed Virginia rather than California — partly because Virginia used clear numeric thresholds a business can assess, and partly because it created no private right of action.
Utah is the exception on the one duty this handout is about. It borrowed Virginia's opt-out structure, but it did not adopt Virginia's assessment requirement — the Utah Consumer Privacy Act imposes no data protection assessment obligation at all. Where Utah appears later in this handout, on sensitive data and opt-out rights, that is a comparison of its other consumer-rights provisions, not of an assessment duty. There is none to compare.
California is structurally different
California's framework diverges significantly. It created the only dedicated state privacy enforcement agency, the broadest consumer rights, a limited private right of action for breaches, and the most detailed implementing regulations of any state.
A California assessment is not a Virginia assessment with the state name changed.
And the Virginia-model states still differ from each other
Sharing a template is not sharing requirements.
Sensitive data is where the divergence is widest. Virginia, Colorado, Connecticut, Oregon and most newer laws require opt-in consent. Utah and Iowa require only clear notice and an opportunity to opt out. Maryland goes further than consent: it limits collecting, processing or sharing sensitive data to what is strictly necessary for a product or service the consumer asked for, and bans selling it.
Thresholds vary just as much, and most states set two of them rather than one. Virginia applies at 100,000 consumers, or at 25,000 where more than half of gross revenue comes from selling personal data. Montana, since its 2025 amendments, applies at 25,000 consumers, or at 15,000 where more than 25% of gross revenue comes from selling personal data. Texas and Nebraska use no consumer count at all — they reach businesses that are not small businesses under federal small-business standards, and both still require consent before a small business sells sensitive data.
Check the second tier before concluding you are out of scope. A business under the headline consumer count can still be caught by the revenue-share limb, and that is the limb organizations skip.
Even the opt-out rights differ. Most Virginia-model states provide three — sale, targeted advertising, and profiling. Utah provides two: sale and targeted advertising. Iowa's list of consumer rights includes only a sale opt-out — though a controller that engages in targeted advertising must still disclose how a consumer can opt out of it.
None of that is visible from the fact that they share a lineage.
What This Means Arithmetically
One deployment. One tool, used one way, reaching people in several places.
| Requirement | Applies when |
|---|---|
| Data Protection Impact Assessment — EU | Any EU residents affected |
| Data Protection Impact Assessment — UK | Any UK residents affected |
| Fundamental Rights Impact Assessment | If in scope, from December 2027 |
| State assessment — Virginia | If triggered |
| State assessment — Colorado | If triggered |
| State assessment — Connecticut | If triggered |
| State assessment — Texas | If triggered |
| State assessment — California | If triggered |
Eight documents for one deployment, and that list is not exhaustive. Twenty-one US states now carry a named assessment duty of their own — eighteen of them already in force, with Louisiana and Oklahoma joining on January 1, 2027 and Vermont on January 1, 2028. New York City adds a bias audit, which is a different instrument again.
They are not copies of each other
- The European assessment examines risk to data
- The Fundamental Rights assessment examines risk to people's rights
- The state assessments are a benefits-versus-risks balancing exercise
- California differs structurally from the Virginia-model states
- Virginia-model states differ from each other on sensitive data, thresholds, and opt-out scope
You cannot write one and adapt it seven times.
The factual sections overlap — what the tool does, what data it processes, who is affected. Reuse those.
The analysis does not. Each instrument asks a different question, and answering the wrong one produces a document that satisfies nothing.
Working Through It
The exclusions matter as much as the triggers. Several state privacy laws exclude individuals acting in an employment context from the definition of consumer. A deployment touching only employees may fall outside those states entirely — while remaining inside others.
Practical sequence:
- Establish which states are in scope, from where the people actually are
- Check the trigger for each state separately
- Record the states assessed and excluded, with the reason
- Do not assume requirements are interchangeable
Step three is the one people skip, and it is the one that makes the file defensible.
Who Supplies What
You or the privacy function:
- Determining which states are in scope
- Checking triggers per state
- Structure and assembly
- The balancing analysis
The business:
- What the processing achieves
- Benefits to the organization and to consumers
- What the output drives
Marketing and ad operations:
- Whether targeted advertising is involved
- What data flows to advertising platforms
Legal or counsel:
- Whether an exclusion applies
- Whether a "sale" or "share" is occurring
- Whether the assessment is sufficient
Common Gaps
- Scoped from where the company operates rather than where the consumers are.
- One assessment used for all states without checking whether the requirements match.
- Benefits stated, risks not. It is a balancing exercise. Both sides have to be present.
- Consumer benefit asserted without basis. "Consumers benefit from a better experience" is not an analysis.
- De-identification never considered. Several states direct you to consider it. Record the conclusion either way.
- Exclusions relied on but not documented. If a state is out of scope, write down why.
- Never revisited when a new state law took effect. New states are added regularly.
One Practical Note
The state assessments are a balancing exercise, not a ranking of risks.
An assessment that lists risks and mitigations but never states whether the benefits outweigh them has not answered the question the statute asks.
Triggering thresholds and content requirements vary by state and change regularly. Verify against the current text for each state in scope before relying on this handout.
Sources
Statutes referenced
- Virginia Consumer Data Protection Act
- Colorado Privacy Act
- Connecticut Data Privacy Act
- Texas Data Privacy and Security Act
- California Consumer Privacy Act as amended, and the implementing regulations
On the comparative claims
Each specific comparison above was checked against the state's own code:
| Claim | Provision |
|---|---|
| Virginia applies at 100,000 consumers, or 25,000 with over 50% of gross revenue from the sale of personal data | Va. Code Ann. § 59.1-576(A) |
| Montana applies at 25,000 consumers, or 15,000 with more than 25% of gross revenue from the sale of personal data | Mont. Code Ann. § 30-14-2803(1), as amended 2025 |
| Texas reaches businesses that are not small businesses as defined by the U.S. Small Business Administration; consent for small-business sale of sensitive data | Tex. Bus. & Com. Code §§ 541.002(a)(3), 541.107 |
| Nebraska reaches businesses that are not small businesses under the federal Small Business Act; consent for small-business sale of sensitive data | Neb. Rev. Stat. §§ 87-1103, 87-1118 |
| Utah: notice and opt-out for sensitive data; opt-outs of sale and targeted advertising only | Utah Code §§ 13-61-302(3), 13-61-201(5) (version effective July 1, 2026) |
| Iowa: notice and opt-out for sensitive data; enumerated opt-out of sale only; disclosure of a targeted-advertising opt-out | Iowa Code §§ 715D.4(2), 715D.3(1)(d), 715D.4(6) |
| Maryland: collecting, processing or sharing sensitive data limited to what is strictly necessary; sale banned | Md. Code, Com. Law § 14-4707(a)(1)–(2) |
The state count is our own, taken from the assessment duty recorded against each jurisdiction in the LegisGate corpus at the version date on this handout, and it counts states carrying a named assessment duty rather than states with a comprehensive privacy law — the two sets overlap but are not identical. The characterization of a dominant "Virginia model" is descriptive rather than statutory.
Verify each state's requirements against its own statute before relying on them. Thresholds, sensitive data definitions, exclusions, and cure periods all vary, and several have been amended since enactment.
A standing note
New state laws are enacted every legislative session, and existing ones are amended. Any list of states in this handout is a snapshot.
Use and reuse
Free to use, share, and adapt within your organization. Attribution appreciated, not required. No warranty of any kind — this is practitioner guidance, not legal advice, and sufficiency is determined by your counsel.
LegisGate · Regulatory Intelligence for AI Deployments · legisgate.com
Written by compliance and audit practitioners who spent decades on the other side of the table.
Version 1.1 · Current as of September 2026 · Verify time-sensitive claims against current sources before relying on them.