DPIA

What State Laws Require for Privacy Assessments

When are privacy assessments needed, and what must they cover?  State privacy laws have a lot to say about this, and state laws are taking different approaches for when assessments are needed and what they must cover. 

Why Organizations Do Privacy Assessments

Many privacy programs have processes to conduct privacy assessments of business activities.  These processes can be referred to by a lot of different names, like privacy threshold assessments, privacy impact assessments (PIAs), and data protection impact assessments (DPIAs).  Privacy programs may use the processes to serve different purposes, including to identify privacy requirements and risks, support data inventories and records of processing, or to document assessments when required by law. 

Having a privacy assessment process is a good starting point, but the process needs to be designed or tailored to address state law requirements if legal compliance is an objective.

What State Laws Require

In the U.S., state comprehensive privacy laws require a specific type of assessment to be conducted when certain triggers are met.  These triggers can include certain data processing activities, like those involving a "sale" of personal data, uses for targeted advertising, or certain profiling or automated processing.  Uses of certain types of personal data, like sensitive personal data or personal data relating to minors, can also trigger assessment requirements.  When they are required by state privacy laws, assessments generally need to be conducted and documented before the personal data processing starts--meaning before the product or feature goes live, advertising campaign launches, or vendor use starts.  They also must be updated before practices change.

State laws can also require assessments to cover specific questions or considerations that must be documented in the assessment.  There are some common elements that most states require, and there are unique requirements that only specific states require. 

For companies focused on privacy law compliance, it's important to conduct assessments when required, and to make sure the assessments address all required elements.  Documented assessments typically need to be provided to state regulators upon request, and companies subject to California's CCPA will ultimately need to make certifications to the state that assessments were conducted when required in 2026 (i.e., before in-scope personal data processing occurred).

The charts linked here have some high-level summaries of when assessments are required, and what they must cover, under state comprehensive privacy laws.  These include new assessment content requirements that Connecticut will require starting next month for certain profiling activities, and that Delaware's recently amended privacy law will require starting next year. 

How To Stay Compliant

If your organization hasn't reviewed and updated its privacy assessment processes in recent years, it may be time for a review.  Consider:

  • Validating policies and business processes require assessments before in-scope business activities launch

  • Refreshing training and guidance for business stakeholders on assessment processes

  • Tailoring assessment processes and platforms used so assessments are conducted (and not screened out) when state law triggers are met

  • Confirming all required questions and considerations are covered in the assessment

  • Sanitizing business stakeholder responses and information so documented assessments are ready for regulator review, and

  • Reviewing assessments and reassessing when activities change and when required by law.

Sam Castic is a Partner with Hintze Law, chair of the firm’s Retail Group, and co-chair of the Cybersecurity and Breach Response Group and FinTech + Financial Services Group. As a former chief privacy officer, he helps companies build, scale, and right-size privacy programs and strategies.

Hintze Law PLLC is a Chambers-ranked and Legal 500-recognized, boutique law firm that provides counseling exclusively on AI, privacy, and data security. Hintze attorneys and data consultants support technology, ecommerce, advertising, media, retail, healthcare, and mobile companies, organizations, and industry associations in all aspects of AI, privacy, and data security.