LegisGate · privacy risk assessment · US states

One assessment for each state, opened from the same answers.

A growing number of states require a documented assessment before certain processing. They do not agree on what triggers one, what it must contain, or how long you keep it. In LegisGate the determination establishes which states your AI use case reaches, and an assessment is opened for each state whose statute calls for one.

Basis
State privacy statutes
Scope
The states the AI use case reaches
Included
With the AI use case that calls for it

How a state assessment is done in LegisGate

Five steps. You do not choose a number of states.

Obligations follow where the person is. If your AI use case reaches residents of four states whose statutes require an assessment, that is four assessments; if it reaches one, it is one.

Step 01

The determination finds the real footprint

From the jurisdictions you declare, it establishes which states the AI use case reaches and which of their statutes call for an assessment, with the provision that says so. Where none does, you have the dated record.

Step 02

A draft opens for each state

Each assessment is opened when the determination runs, titled with the term that state’s statute uses, and is included with the use case.

Step 03

Our half is written, state by state

The regulatory half is built from the provisions that state actually enacted: the triggering analysis, the required contents, and how long the assessment must be kept and when it can be demanded. Not a national summary with the state name inserted.

Step 04

You complete your half

For California, your half is laid out as guided questions drawn from the California regulations on risk assessments. Each question shows the section that requires it, and its Guidance block quotes the regulation. LegisGate prepares the regulatory half of each state assessment automatically and marks the sections your organisation completes; guided questions are added state by state (California first).

Step 05

You rate the risks, export, and record the review

The assessment register lists each risk the determination raised. No scale is prescribed for it; the register uses the ICO’s three-level scale and says so. The assessment can be exported at any point, with a status line on its cover saying how many questions are accepted and whether it has been reviewed. Mark reviewed records who reviewed it and when. It does not say the assessment is sufficient.

Monitoring is included and automatic: when the law behind a question changes, that question is flagged, and the activity log records who answered, accepted, assigned and exported.

Your first five AI use cases are free, with everything included: the laws, the obligations, the written assessments and monitoring. No card. More than five is a subscription.

What it looks like

The California assessment, section by section.

The sections follow the regulation’s own order, each showing how many of its questions are accepted. The first is open, with our half folded above your question.

A California risk assessment open in LegisGate: sections named for the parts of the regulation down the side, and the first section open with Our half summarised above the question in Your half

We bring the regulatory intelligence and the intake. You bring the privacy and legal judgment for your use case and organization. The document is built to hold both.

The division of labour, stated once

Why not one document for all of them

Because the differences are exactly where the exposure is.

The states converge on the idea of an assessment and diverge on nearly everything that determines whether yours counts. Averaging them produces a document that is plausible everywhere and correct nowhere.

01

The trigger differs

What kinds of processing require an assessment is not uniform — targeted advertising, sale of personal data, profiling with legal or similarly significant effects and sensitive-data processing appear in different combinations.

02

The contents differ

What has to be weighed, and against what, varies. Some statutes name the balancing test explicitly; others describe the factors and leave the framing open.

03

Retention and production differ

How long the assessment must be kept, and the circumstances in which an attorney general can demand it, are not the same statute to statute.

04

Confidentiality treatment differs

Whether producing an assessment waives privilege, and what protection attaches when it is disclosed to a regulator, is a state-level question with real consequences.

What this is not. LegisGate produces regulatory intelligence and assessment-preparation materials. Nothing we produce is legal advice, a legal opinion, a certification, or a determination of compliance, and no document we deliver satisfies a legal obligation on its own. Sufficiency is determined by your counsel. Sufficiency under any particular state statute is your counsel's judgement, not a property of the document we deliver.

Many statutes, one AI use case

Find the real footprint first.

Add the AI use case and the determination tells you which state assessments the law calls for. Those are the ones that are opened.

Talk to usWe're here to help
US State Privacy Risk Assessments, Prepared per State | LegisGate™