Compliance

US state privacy and data security laws: the complete compliance map

Sienna VanceSienna VanceApril 30, 2026
Share:
US state privacy and data security laws: the complete compliance map

Key takeaways

  • 22 distinct US state frameworks in this group span four categories: comprehensive privacy rights laws (CCPA/CPRA, Virginia CDPA, Colorado CPA, Oregon CPA, Tennessee TIPA, Texas CDPA), breach notification laws (CA SB1386, IL PIPA, OR 646A, AK PIPA, NY SHIELD Act, TX BC521), sector-specific cybersecurity regulations (NY DFS 23 NYCRR 500, NV Gaming Regulation 5.260, IL IPA), IoT/device security law (CA SB327), data broker regulation (VT Act 171), and state government IT security frameworks (TX DIR Controls 2.0, TX SB 820, TX SB 2610, TX-RAMP Level 1, TX-RAMP Level 2).

  • Illinois BIPA is the highest litigation-risk framework in this group -- statutory damages of $1,000 to $5,000 per individual violation with a private right of action have produced class action settlements exceeding $650 million (Vulnox assessment data, 2024; BIPA litigation records).

  • The Texas data ecosystem alone contains six overlapping frameworks: TX BC521 (breach notification), TX CDPA (privacy rights), TX DIR Control Standards (state agency security), TX SB 820 (agency training/reporting), TX SB 2610 (local government cybersecurity), and TX-RAMP (cloud vendor certification) -- each with distinct scope, enforcement body, and obligations.

  • NY DFS 23 NYCRR 500 (2023 Amendment 2) is the most technically prescriptive framework in this group, requiring annual penetration testing, MFA for privileged access, CISO reporting directly to the board, and 72-hour incident notification -- obligations that go well beyond what any state breach notification law demands.

  • A written information security programme (WISP) satisfies the security safeguard requirement in Massachusetts 201 CMR 17.00 and the NY SHIELD Act simultaneously -- but does nothing to satisfy the consumer rights workflows, opt-out mechanisms, and data protection assessment requirements in CCPA/CPRA, Virginia CDPA, Colorado CPA, Oregon CPA, or Tennessee TIPA.

  • Nevada has two unrelated frameworks in this group that share a state but not an enforcement body: NV SB220 (online privacy opt-out, enforced by the AG) and NV Gaming Regulation 5.260 (casino cybersecurity, enforced by the Nevada Gaming Control Board) -- a distinction that casino operators routinely miss.

  • Vermont Act 171 is the only framework in this group that targets data brokers specifically -- companies with no direct consumer relationship. Organizations that aggregate and resell personal data frequently overlook Vermont registration because they do not see themselves as operating in Vermont.

TL;DR

The hard part of US state privacy compliance is not reading the laws. It is understanding that these 22 frameworks operate on three completely different logics: some create consumer rights that require operational workflows; some require security programmes that produce documentation; some mandate incident timelines that require detection infrastructure. A compliance programme that solves one of those problems does not automatically solve the others -- and the organizations that discover this during an investigation rather than before it pay the difference.

The 30-person SaaS company with five simultaneous obligations

A SaaS company based in Austin processes marketing analytics for US enterprise clients. It has 38 employees, annual revenue of $12 million, and a customer base spread across California, New York, Virginia, Colorado, and Texas. The legal team knew about CCPA. They had engaged a consultant to produce a privacy policy update in 2021 and considered the matter settled. When they began pursuing a contract with a Texas state agency in late 2024, the procurement team asked for TX-RAMP Level 2 certification. Nobody in the company had heard of it. A subsequent internal review found they were also processing biometric data through a facial recognition feature in their product -- a feature their Illinois-based enterprise customer had been using for 14 months without the company ever assessing BIPA exposure. The data protection assessment required under the Virginia CDPA for their profiling functionality had never been completed. And the written information security programme their legal team thought satisfied Massachusetts 201 CMR 17.00 had not been updated since 2020.

Turning point:

None of this was discovered through regulatory action. A single procurement question from one Texas state agency surfaced five distinct compliance gaps simultaneously. The problem was not that the company had ignored compliance -- it was that they had treated CCPA as representative of the entire landscape, when it is actually just one layer of a 22-framework system.

What this framework group covers and how it fits together

The 22 frameworks in this group represent the full spectrum of US state-level data privacy and security regulation as it currently exists. They are not a single system. They do not share an enforcement body. Many were drafted by different legislative committees responding to different political pressures, and several directly contradict each other on procedural details. Understanding the group as a unified whole requires recognizing that it contains four structurally different types of obligation.

The first type is comprehensive privacy rights laws. California CCPA/CPRA, Virginia CDPA, Colorado CPA, Oregon CPA, Tennessee TIPA, and Texas CDPA all follow the same basic architecture: they define categories of personal data, grant consumers enumerated rights (access, correction, deletion, portability, opt-out), and impose controller and processor obligations. They differ on thresholds, enforcement models, cure periods, and specific rights -- but a compliance programme that handles one of them transfers roughly 70% of its structure to the others.

The second type is breach notification laws. California SB1386 (the original, now superseded by updated Civil Code 1798.82), Illinois PIPA, Oregon 646A, Alaska PIPA, the New York SHIELD Act, and Texas BC521 all require notification to affected individuals and, in some cases, regulators when personal information is compromised. They differ on what constitutes personal information, notification timelines, regulator notification thresholds, and the security safeguard baseline they impose. A unified breach response programme satisfies most of them simultaneously -- but the specific timelines and notification content requirements still need to be managed per-jurisdiction.

The third type is sector-specific cybersecurity regulation. New York DFS 23 NYCRR 500 targets financial institutions licensed by the DFS. Nevada Gaming Regulation 5.260 targets casinos and gaming operators. Illinois IPA targets insurance licensees. These three frameworks are operationally intensive -- they require documented programmes, technical controls, and direct regulatory reporting -- and they are entirely invisible to organizations that do not operate in those sectors.

The fourth type is government IT and vendor frameworks. Texas DIR Control Standards 2.0, TX SB 820, TX SB 2610, and TX-RAMP Levels 1 and 2 apply to Texas state agencies and the cloud vendors serving them. If you are selling software to Texas government, TX-RAMP is not optional and not fast.

Outside those four types sit two specialists: California SB327, which imposes security requirements on IoT device manufacturers, and Vermont Act 171, which requires data brokers to register annually and disclose their practices. Both are frequently missed because neither fits neatly into the categories that compliance programmes are organized around.

Frameworks Covered
  • CA CCPA / CPRA (Nov 2022)

  • CA SB327

  • CA SB1386

  • CO Colorado Privacy Act

  • IL BIPA

  • IL IPA

  • IL PIPA

  • MA 201 CMR 17.00

  • NV SB220

  • NV NOGE Regulation 5.260

  • NY DFS 23 NYCRR500 2023 Amd 2

  • NY SHIELD Act S5575B

  • OR 646A

  • OR CPA

  • TN Tennessee Information Protection Act

  • TX BC521

  • TX CDPA

  • TX DIR Control Standards 2.0

  • TX SB 820

  • TX SB 2610

  • TX TX-RAMP Level 1

  • TX TX-RAMP Level 2

  • VA CDPA 2023

  • VT Act 171 of 2018

  • AK PIPA

Framework by framework: what each one actually requires

Frameworks

Name

California CCPA / CPRA (Nov 2022)

Who It Applies To

For-profit businesses meeting one of three thresholds: annual gross revenue over $25 million; buying, selling, or sharing personal information of 100,000 or more California consumers or households annually; or deriving 50% or more of annual revenue from selling personal information. Applies regardless of where the business is located if it serves California consumers.

Common Failure Mode

Organizations build a privacy notice and a deletion request workflow and call it done. The failures we see are in the backend: no data mapping to actually locate data subject to deletion requests; service provider contracts missing required CPRA provisions; sensitive personal information -- geolocation, health data, precise identifiers -- being processed without the additional opt-out mechanism. The CPPA''s enforcement investigations have focused on opt-out signal processing (Global Privacy Control compliance) and children''s data -- two areas many compliance programmes have not operationalized.

What It Actually Requires

Consumer rights to know, delete, correct, and opt out of sale or sharing. Opt-out must be accessible via a ''Do Not Sell or Share My Personal Information'' link. Data minimization and purpose limitation obligations under CPRA. Sensitive personal information carries additional opt-out rights. The California Privacy Protection Agency (CPPA) has rulemaking authority and has been issuing detailed regulations since 2022. Contracts with service providers and contractors must include specific CPRA language.

Enforcement And Consequences

The CPPA enforces CPRA with civil penalties up to $2,500 per unintentional violation and $7,500 per intentional violation. Consumers have a private right of action for data breaches involving their unencrypted personal information -- $100 to $750 per consumer per incident, or actual damages if higher. No cure period was retained under the CPRA amendments for CPPA-initiated enforcement.

Relationship To Others In Group

CCPA/CPRA is the most consumer-rights-oriented law in this group and the one with the most regulatory infrastructure behind it. Virginia CDPA, Colorado CPA, Oregon CPA, and Tennessee TIPA all follow CCPA''s basic architecture but with narrower scope and more business-friendly enforcement. CA SB1386 is the historical predecessor for breach notification -- California''s current breach notification obligation is now in Civil Code 1798.82, which CCPA/CPRA layered additional requirements on top of.

Name

CA SB1386

Who It Applies To

Any business or government agency that owns or licenses computerized personal information of California residents. No revenue or size threshold.

Common Failure Mode

Organizations treat it as a historical artifact superseded by CCPA. The breach notification obligation in Civil Code 1798.82 -- SB1386''s current form -- is still live, separate from CCPA, and covers a broader definition of personal information than the original 2003 law.

What It Actually Requires

Notification to affected California residents when their unencrypted personal information is acquired by an unauthorized person. The original SB1386 definition of personal information was narrow (name plus SSN, financial account, or driver''s license number). Subsequent amendments expanded the definition. Current California breach notification obligations are primarily governed by Civil Code Section 1798.82, which SB1386 became.

Enforcement And Consequences

Enforced by the California AG and local prosecutors. Civil penalties and consumer private right of action available. Historical significance: SB1386 passed in 2003 and directly triggered breach notification legislation in all 50 states over the following two decades.

Relationship To Others In Group

The direct ancestor of every breach notification law in this group. Oregon 646A, Illinois PIPA, Alaska PIPA, NY SHIELD Act, and Texas BC521 all follow the SB1386 model of notification-upon-breach plus reasonable security baseline.

Name

CA SB327

Who It Applies To

Manufacturers of connected devices -- IoT hardware -- sold or offered for sale in California. Device: any item capable of connecting to the internet, directly or indirectly, including via Bluetooth, Zigbee, or similar protocols.

Common Failure Mode

Manufacturers who sell B2B (devices deployed in enterprise or industrial settings) assume the law applies only to consumer IoT. It does not. A connected sensor sold to a Texas manufacturer that is used in a California facility falls within scope. The ''reasonable security feature'' standard is also deliberately vague -- manufacturers tend to interpret it narrowly until they face a product liability claim where SB327 non-compliance is cited.

What It Actually Requires

Each connected device must be equipped with a reasonable security feature appropriate to the nature and function of the device and the information it may collect. Critically: if the device uses a password as a means of authentication outside a local area network, it must either (a) have a unique pre-programmed password for each device, or (b) require the user to generate a new means of authentication before the device can be used.

Enforcement And Consequences

Enforced by the California AG. No private right of action.

Relationship To Others In Group

The only device security law in this group. It sits in a different compliance lane than all other frameworks here. Organizations building connected products face SB327 on the product side and CCPA/CPRA on the data side -- two separate legal obligations that share almost no control overlap.

Name

CO Colorado Privacy Act

Who It Applies To

Controllers processing personal data of 100,000 or more Colorado consumers per year, or 25,000 consumers where more than 25% of gross revenue derives from selling personal data. Effective July 2023.

Common Failure Mode

Confusion between ''selling'' personal data under the Colorado CPA (which requires consideration) and ''sharing'' under CCPA/CPRA (which includes no-consideration transfers for targeted advertising). An organization that has built CCPA opt-outs for ''sale or sharing'' may still be missing the Colorado definition. The mandatory universal opt-out mechanism -- specifically the technical implementation of honoring browser-level signals -- is also frequently incomplete.

What It Actually Requires

Consumer rights: access, correction, deletion, portability, opt-out of targeted advertising, data sale, and significant profiling. Mandatory data protection assessments for high-risk processing. Opt-out via universal opt-out mechanisms (similar to Global Privacy Control) required by July 2024. Controllers must respond to rights requests within 45 days, extendable by another 45 days.

Enforcement And Consequences

Colorado AG enforcement only, no private right of action. Civil penalties up to $20,000 per violation. No cure period after January 1, 2025.

Relationship To Others In Group

Part of the second wave of state privacy laws, structurally similar to Virginia CDPA. The data protection assessment requirement mirrors Virginia''s. The universal opt-out mechanism requirement is more specific than Virginia''s equivalent. Oregon CPA (effective July 2024) and Tennessee TIPA (effective July 2025) follow similar architectures.

Name

IL BIPA

Who It Applies To

Private entities -- not government agencies -- that collect, capture, purchase, receive through trade, or otherwise obtain biometric identifiers or biometric information from individuals in Illinois. Biometric identifiers: retina or iris scans, fingerprints, voiceprints, scans of hand or face geometry.

Common Failure Mode

Two distinct failure modes. First: employers using fingerprint time-and-attendance systems without BIPA-compliant consent forms. This is the most common BIPA lawsuit archetype. Second: technology companies building facial recognition or voiceprint features who assume BIPA only applies to the end employer deploying the feature, not to them as the vendor collecting the biometric data on behalf of the employer. Illinois courts have found both the employer and the technology vendor can be liable.

What It Actually Requires

Written policy with retention and destruction schedule, publicly available. Informed written consent before collection. Prohibition on selling, leasing, trading, or profiting from biometric data. Security standard: reasonable care consistent with the entity''s handling of other confidential and sensitive information, and at least the same standard as industry-wide norms.

Enforcement And Consequences

Private right of action with statutory damages: $1,000 per negligent violation, $5,000 per intentional or reckless violation. Attorneys'' fees available. This has made BIPA the source of the largest class action privacy settlements in US history -- the Facebook facial recognition settlement was $650 million, the TikTok settlement was $92 million. There is no cure period, no AG-first enforcement pathway. Litigation is the mechanism.

Relationship To Others In Group

Completely isolated from all other frameworks in this group in terms of enforcement mechanism. Every other framework here is enforced by an AG, a sector regulator, or a state agency. BIPA is enforced by class action plaintiffs and their attorneys. Virginia CDPA and Colorado CPA treat biometric data as sensitive and require consent -- but they impose no statutory damages and have no private right of action. The litigation risk profile of BIPA has no equivalent elsewhere in this group.

Name

IL IPA

Who It Applies To

Insurance companies, agents, brokers, and all other entities licensed by the Illinois Department of Insurance. Modeled on the NAIC Insurance Data Security Model Law MDL-668.

Common Failure Mode

Insurance licensees who have an enterprise-level security programme that technically satisfies the WISP requirement but lack the 72-hour notification mechanics. The 72-hour clock is a detection-and-escalation problem, not a documentation problem. Organizations with mature policies but immature monitoring have the gap in the wrong place.

What It Actually Requires

A formal written information security programme (WISP) covering administrative, technical, and physical safeguards. Annual risk assessment. Oversight of third-party service providers including written contracts with security requirements. Board oversight of the cybersecurity programme. 72-hour notification to the Illinois Director of Insurance following a cybersecurity event. Annual certification of compliance.

Enforcement And Consequences

Enforced by the Illinois Department of Insurance. Failure to notify within 72 hours or to maintain a programme can result in license action and civil penalties.

Relationship To Others In Group

Mirrors NY DFS 23 NYCRR 500 in its overall structure -- WISP, risk assessment, third-party oversight, board governance, 72-hour notification -- but applies to Illinois-licensed insurance entities rather than NY-licensed financial institutions. Both trace back to the NAIC model law. An organization licensed in both states can achieve significant control overlap but still faces separate certification obligations.

Name

IL PIPA

Who It Applies To

Data collectors that own or license personal information of Illinois residents. Applies regardless of business size or revenue.

Common Failure Mode

Organizations scope PIPA narrowly against the original definition of personal information and miss the expanded categories added through amendments. Medical information and health insurance information are now covered -- relevant to any employer, healthcare organization, or insurer handling Illinois residents'' data.

What It Actually Requires

Notification to affected Illinois residents following a qualifying breach of security involving their personal information. Illinois has progressively expanded the definition of personal information through amendments to include financial account information, medical information, health insurance information, unique biometric data, and other sensitive categories.

Enforcement And Consequences

Enforced by the Illinois AG. Civil penalties available. No private right of action for the breach notification obligation itself (unlike BIPA).

Relationship To Others In Group

Breach notification law structurally parallel to CA SB1386, OR 646A, AK PIPA, NY SHIELD Act, and TX BC521. The notification obligation is the primary requirement; the security baseline (reasonable security procedures) is secondary. Should not be confused with IL BIPA, which is a separate statute with separate obligations and an entirely different enforcement mechanism.

Name

MA 201 CMR 17.00

Who It Applies To

Any business that owns, licenses, stores, or maintains personal information of Massachusetts residents -- regardless of where the business is physically located. Personal information: Massachusetts resident name combined with SSN, driver''s license or state ID number, or financial account/credit card number.

Common Failure Mode

Organizations write a WISP policy document and treat it as done. The regulation''s portable device encryption requirement is the one that generates the most findings in our assessments. Laptops, USB drives, and mobile devices containing personal information must be encrypted -- not just subject to an encryption policy. We regularly find organizations that have the policy but not the enforcement. One assessment of a 90-person professional services firm found 12 unencrypted laptops with Massachusetts personal information, in direct violation of a WISP that explicitly required encryption.

What It Actually Requires

A comprehensive written information security programme (WISP) that includes risk assessment; employee training; vendor contract requirements; physical access controls; a system for monitoring, detecting, and responding to unauthorized access; encryption of personal information stored on portable devices and transmitted across public networks; up-to-date firewall and malware protection; and designated responsible employee(s).

Enforcement And Consequences

Enforced by the Massachusetts Office of Consumer Affairs and Business Regulation and the AG. Civil penalties and injunctive relief available.

Relationship To Others In Group

Massachusetts 201 CMR 17.00 was the first US regulation to mandate a WISP, which is why the NY SHIELD Act (2019) mirrors its structure. A WISP built to Massachusetts standards satisfies the security programme requirement of the SHIELD Act simultaneously. Neither law satisfies the consumer rights workflows required by CCPA/CPRA, Virginia CDPA, or Colorado CPA.

Name

NV SB220

Who It Applies To

Operators of websites and online services that collect covered information from Nevada consumers and sell that information to third parties for monetary consideration.

Common Failure Mode

Organizations that build CCPA opt-out mechanisms assume they also cover Nevada SB220. They do not, for a specific reason: Nevada SB220 applies to the ''sale'' of information for monetary consideration -- a narrower definition than CCPA/CPRA''s ''sale or sharing,'' which covers no-consideration transfers for targeted advertising. An organization could be fully compliant with CCPA opt-out requirements while still having an unfulfilled Nevada obligation if their data practices involve paid data transfers but not targeted advertising sharing.

What It Actually Requires

Operators must provide a mechanism for consumers to submit a verified request to opt out of the sale of their covered information. The operator must respond within 60 days (extendable by 30 days with notice).

Enforcement And Consequences

Enforced by the Nevada AG. Civil penalties available. No private right of action.

Relationship To Others In Group

Predates CCPA (Nevada SB220 passed in 2019, effective 2020). Much narrower than CCPA -- no access, correction, deletion, or portability rights. Narrower definition of ''sale'' than CCPA. Sits alongside Nevada Gaming Regulation 5.260 as a Nevada-specific obligation, but the two regulations address entirely different activities and are enforced by different bodies.

Name

NV NOGE Regulation 5.260

Who It Applies To

All Nevada-licensed gaming establishments -- resort casinos, standalone casinos, online gaming operators, and other entities regulated by the Nevada Gaming Control Board (NGCB). Requirements scale with size and complexity.

Common Failure Mode

Casino operators who have strong perimeter security but fragmented third-party risk management. The 2023 MGM Resorts and Caesars Entertainment incidents -- which directly precipitated this regulation -- both involved social engineering attacks through third-party service channels (identity verification vendors and IT support). Regulation 5.260 specifically requires operators to manage vendor risk, not just their own environment. Operators with mature internal security but a light-touch vendor assessment programme have the gap exactly where the regulation''s origin story sits.

What It Actually Requires

A written cybersecurity programme approved by senior management or the board. Risk assessments. Access controls including MFA for privileged access and least-privilege principles. Encryption of patron and financial data in transit and at rest. Documented incident response plan tested regularly. Third-party vendor risk management with contractual cybersecurity requirements. 72-hour incident reporting to the NGCB.

Enforcement And Consequences

Enforced by the Nevada Gaming Control Board. Non-compliance can result in regulatory action including fines and, in extreme cases, license suspension. The NGCB has real-time visibility into significant cyber events under the 72-hour reporting requirement.

Relationship To Others In Group

The only gaming-sector-specific framework in this group. Nevada is the first state to mandate detailed cybersecurity requirements specifically for gaming. Its structure -- written programme, risk assessment, access controls, incident reporting, third-party oversight -- mirrors NY DFS 23 NYCRR 500 in spirit, though gaming operators are not DFS-regulated. Aligns significantly with NIST CSF, which reduces implementation effort for operators already using that framework.

Name

NY DFS 23 NYCRR500 2023 Amd 2

Who It Applies To

Banks, insurance companies, money transmitters, and all other financial services entities licensed by the New York Department of Financial Services. Applies regardless of size, with limited exemptions for very small entities.

Common Failure Mode

The board governance requirement is the most frequently incomplete control we see. Organizations have a CISO. The CISO produces a report. The report exists on paper. Whether the board actually reviewed it, understood it, and took action based on it is a different question -- and DFS examiners ask exactly that question. Another persistent gap: the penetration test scope. Organizations conduct annual penetration tests but scope them narrowly, excluding cloud environments, third-party integrations, and recently acquired systems. DFS expects the test to cover the full environment.

What It Actually Requires

Mandatory annual penetration testing. Vulnerability scanning. MFA for remote access and privileged systems (no exceptions for covered entities above limited-entity thresholds). Encryption of nonpublic information in transit and at rest. CISO reporting obligations -- the CISO must report to the board annually, and the board must have sufficient expertise or advisors to understand the report. Annual certification of compliance filed with DFS. 72-hour notification for significant cybersecurity events. Written incident response plan. Third-party service provider cybersecurity requirements with annual monitoring. Asset inventory. Access management controls.

Enforcement And Consequences

DFS enforcement. The 2023 amendments strengthened penalties. DFS has already used NYCRR 500 to impose multi-million-dollar penalties and consent orders. Robinhood paid $30 million in 2022 for cybersecurity and anti-money-laundering failures partly under NYCRR 500.

Relationship To Others In Group

The most operationally demanding framework in this group for organizations it applies to. IL IPA follows the same structural pattern for insurance licensees. NV Gaming Regulation 5.260 follows a similar pattern for casinos. MA 201 CMR 17.00 and NY SHIELD Act overlap on the WISP requirement but are far less technically prescriptive. Texas DIR Control Standards are similarly detailed but apply to state agencies rather than private financial institutions.

Name

NY SHIELD Act S5575B

Who It Applies To

Any business that owns or licenses private information of New York residents, regardless of where the business operates. Small businesses (fewer than 50 employees, less than $3 million in gross revenue in each of the past three years, and less than $5 million in year-end total assets) have a scaled-down security programme requirement.

Common Failure Mode

The SHIELD Act''s small business carve-down is misapplied. Organizations at the threshold (say, 48 employees, $2.8 million revenue) assume they qualify for the scaled requirements. But the statute requires meeting all three thresholds simultaneously, and many businesses in the middle of a growth phase stop qualifying partway through a year. The data security programme they built to the ''small business'' standard may no longer satisfy the full standard once they cross a threshold.

What It Actually Requires

Expanded breach notification obligations: faster notification, updated definition of private information, and notification to the NY AG when breach affects more than 500 New York residents. Separately: ''reasonable safeguards'' requirement -- administrative, technical, and physical safeguards appropriate to the size and complexity of the business. The safeguards obligation is operationalized through a written data security programme.

Enforcement And Consequences

NY AG enforcement. Civil penalties up to $5,000 per violation for failure to notify. Civil penalties up to $250,000 total for failure to implement reasonable safeguards.

Relationship To Others In Group

A direct descendant of MA 201 CMR 17.00 in its data security programme requirement. A WISP built to Massachusetts standards satisfies NY SHIELD Act simultaneously. The breach notification component parallels CA SB1386/1798.82, OR 646A, IL PIPA, AK PIPA, and TX BC521 -- with New York-specific timelines and AG reporting thresholds.

Name

OR 646A

Who It Applies To

Businesses that own, maintain, or otherwise possess personal information of Oregon residents. Applies regardless of where the business is located.

Common Failure Mode

The AG notification threshold (250 Oregon residents) is missed. Organizations scope breach notification programmes for consumer notification but do not build the parallel workflow for AG notification when a larger population is involved. In a single assessment of a 200-person Oregon-headquartered employer, we found the incident response plan contained no step for assessing AG notification thresholds.

What It Actually Requires

Reasonable security measures for personal information. Breach notification to affected Oregon residents and -- when breach affects 250 or more Oregon residents -- to the Oregon AG. Oregon has progressively expanded its definition of personal information through legislative amendments.

Enforcement And Consequences

Oregon AG enforcement. Civil penalties available.

Relationship To Others In Group

Breach notification parallel to CA SB1386, IL PIPA, AK PIPA, NY SHIELD Act, TX BC521. Distinct from Oregon CPA (SB 619), which is a comprehensive privacy rights law effective July 2024. Oregon has both a breach notification law (ORS 646A) and a comprehensive privacy law (CPA). They are separate obligations requiring separate compliance work.

Name

OR CPA

Who It Applies To

Controllers processing personal data of 100,000 or more Oregon consumers annually, or 25,000 consumers where data selling accounts for 25% or more of gross revenue. Effective July 2024.

Common Failure Mode

Oregon''s broader definition of ''consumer health data'' -- which includes personal data that a controller has reason to believe could be used to infer health status -- catches organizations that do not consider themselves health companies. A fitness app, a grocery retailer with purchase data, or a life insurer holding application data may be processing ''consumer health data'' under Oregon''s definition without having identified themselves as doing so.

What It Actually Requires

Consumer rights: access, correction, deletion, portability, opt-out of targeted advertising, sale, and profiling for significant decisions. Data protection assessments for high-risk processing. 45-day response window for rights requests. Universal opt-out mechanism support. Sensitive data includes consumer health data -- a category that is more broadly defined under the Oregon CPA than under CCPA/CPRA.

Enforcement And Consequences

Oregon AG enforcement. 30-day cure period during initial phase. Civil penalties up to $25,000 per violation after the cure period.

Relationship To Others In Group

Third-wave state privacy law alongside Tennessee TIPA. Structurally similar to Virginia CDPA and Colorado CPA. The health data definition is broader than any other framework in this group except Washington''s My Health MY Data Act (not in this group). Oregon CPA and OR 646A are separate obligations for organizations operating in Oregon.

Name

TN Tennessee Information Protection Act

Who It Applies To

Controllers processing personal data of 175,000 or more Tennessee consumers annually, or 25,000 consumers where data selling generates 25% or more of gross revenue. Effective July 2025. The 175,000 threshold is the highest consumer-count threshold of any state privacy law in this group.

Common Failure Mode

Organizations in multi-state compliance programmes that have scoped TIPA out because they are below the 175,000-consumer threshold -- and then cross it during a period of growth without reassessing scope. TIPA became effective July 2025 and has not yet generated enforcement cases. The absence of enforcement history creates a false sense that the threshold question is theoretical.

What It Actually Requires

Consumer rights: access, correction, deletion, portability, opt-out of targeted advertising, sale, and profiling. 60-day cure period -- the most business-friendly cure period of any framework in this group. Sensitive data consent required. Data protection assessments for high-risk activities.

Enforcement And Consequences

Tennessee AG enforcement exclusively. No private right of action. Civil penalties up to $15,000 per violation.

Relationship To Others In Group

The most business-friendly comprehensive privacy law in this group: highest consumer-count threshold, longest cure period, AG-only enforcement. Structurally similar to Virginia CDPA and Colorado CPA but with fewer teeth. Organizations already CCPA/Virginia CDPA-compliant will find TIPA incremental.

Name

TX BC521

Who It Applies To

Individuals and organizations that conduct business in Texas and own or license personal information of Texas residents. No revenue or size threshold.

Common Failure Mode

''As quickly as possible'' is interpreted as more permissive than it actually is. Texas AG enforcement has treated delays of more than 60 days as unreasonable in documented cases. Organizations using 90-day timelines calibrated against less demanding laws are exposed under TX BC521.

What It Actually Requires

Breach notification to affected individuals ''as quickly as possible.'' When breach affects 250 or more Texans: notification to the Texas AG. Requires implementing reasonable security procedures and practices appropriate to the nature of personal information handled.

Enforcement And Consequences

Texas AG enforcement. Civil penalties available.

Relationship To Others In Group

Breach notification parallel in the Texas framework ecosystem. Distinct from -- and should not be confused with -- Texas CDPA (privacy rights) and TX DIR Control Standards (state agency IT security). Texas has three overlapping frameworks covering breach notification, consumer privacy rights, and state agency security standards, respectively.

Name

TX CDPA

Who It Applies To

Businesses that process personal data of Texas residents and are not a small business under SBA definitions. Notably, Texas CDPA has no revenue threshold and no consumer volume threshold -- the broadest applicability trigger of any state privacy rights law in this group. Effective July 2024.

Common Failure Mode

The SBA small business exclusion is misapplied. The SBA definition of small business varies by industry -- it is not a fixed headcount or revenue number. A professional services company with 500 employees may qualify as an SBA small business in its NAICS code; a manufacturing company with 100 employees may not. Organizations that assume they are excluded based on headcount alone frequently discover they are not when they check the actual SBA size standards table.

What It Actually Requires

Consumer rights: access, correction, deletion, portability, opt-out of targeted advertising, sale, and profiling. Sensitive data requires consent. Data protection assessments. Privacy notice. 45-day response window for rights requests. 30-day cure period.

Enforcement And Consequences

Texas AG enforcement exclusively. No private right of action. Civil penalties up to $7,500 per violation. 30-day cure period.

Relationship To Others In Group

The broadest-scope state privacy rights law in this group -- no volume or revenue threshold beyond the SBA small business exclusion. Sits in the same category as CCPA/CPRA, Virginia CDPA, Colorado CPA, Oregon CPA, and Tennessee TIPA. Also coexists with TX BC521 (breach notification) in the Texas regulatory landscape.

Name

TX DIR Control Standards 2.0

Who It Applies To

Texas state agencies and higher education institutions subject to DIR security requirements, and their technology vendors. Does not apply to private organizations unless they are contracting with a Texas state agency.

Common Failure Mode

Technology vendors scoping for TX-RAMP Level 1 or Level 2 who do not realize that DIR Control Standards 2.0 defines the baseline their TX-RAMP assessment is measured against. Understanding TX-RAMP without understanding DIR Control Standards is like studying for an exam without knowing the syllabus.

What It Actually Requires

A control catalogue derived from NIST SP 800-53 covering access management, configuration management, incident response, risk assessment, system and communications protection, and other control families. State agencies must implement these controls as a baseline and demonstrate compliance through DIR assessments and annual security plans.

Enforcement And Consequences

DIR oversight. Non-compliant agencies face DIR assessment findings, escalation to agency leadership, and ultimately to the Texas Legislature. Not directly applicable to private organizations -- but indirectly relevant to any vendor seeking state agency contracts.

Relationship To Others In Group

The foundational standard for all Texas state agency IT security. TX SB 820 and TX SB 2610 reference DIR authority and DIR-aligned controls. TX-RAMP Level 1 and Level 2 assess cloud vendors against DIR Control Standards-derived baselines.

Name

TX SB 820

Who It Applies To

Texas state agencies and their employees. Amended Texas Government Code Chapter 2054.

Common Failure Mode

Annual training is completed as a checkbox. The SB 820 training requirement is tied to DIR-approved training content -- agencies that deploy generic security awareness training not vetted by DIR are technically non-compliant. In our assessments of contractors supporting Texas state agencies, we find the training requirement is often well-documented but the DIR-approval status of the training content is unverified.

What It Actually Requires

Mandatory annual cybersecurity training for all state agency employees. Enhanced DIR oversight of agency cybersecurity programmes. Incident reporting obligations to DIR. Agency information security officers must report directly to agency leadership. DIR authority to conduct cybersecurity assessments of state agencies.

Enforcement And Consequences

DIR oversight and enforcement against state agencies. Agency heads are accountable for compliance.

Relationship To Others In Group

Operates alongside TX DIR Control Standards 2.0 as part of the Texas state agency cybersecurity infrastructure. TX SB 2610 extended similar requirements to local governments. TX-RAMP certifies the vendors serving these agencies. Together these four frameworks form a layered Texas government IT security ecosystem.

Name

TX SB 2610

Who It Applies To

Texas local governments: counties, municipalities, special districts, and public school districts. Passed in 2025.

Common Failure Mode

Small Texas municipalities and school districts with limited IT staff who do not know DIR-aligned policies exist or how to access DIR''s published policy templates. The gap is not willful non-compliance -- it is awareness. A 4,000-person school district with a two-person IT team typically has its hands full with operations; policy alignment with DIR standards is not on the radar until an incident forces the question.

What It Actually Requires

Adoption of cybersecurity policies aligned with DIR standards. Annual employee cybersecurity training. Reporting of cybersecurity incidents to the Texas Department of Information Resources.

Enforcement And Consequences

DIR oversight. Local government entities face DIR reporting requirements and potential audit.

Relationship To Others In Group

Extends the TX SB 820 framework to local government. Complementary to TX DIR Control Standards 2.0. Local governments are not subject to TX-RAMP (which is a cloud vendor certification programme), but they would be the buyers of TX-RAMP-certified cloud services.

Name

TX TX-RAMP Level 1

Who It Applies To

Cloud service providers seeking to sell low-impact cloud services to Texas state agencies. Specifically: cloud services that do not handle sensitive or confidential state data.

Common Failure Mode

Vendors who begin a Level 1 certification expecting it to be purely administrative (because it is self-attestation) and discover mid-process that the required security documentation does not exist. Self-attestation does not mean no controls are required -- it means the controls are documented and the vendor is asserting they exist. Vendors without a mature security documentation set cannot self-attest accurately.

What It Actually Requires

Self-attestation and basic security review against a NIST 800-53-derived control subset. DIR catalogue listing upon successful completion. Periodic recertification.

Enforcement And Consequences

DIR maintains the approved catalogue. Cloud services not on the catalogue cannot be procured by state agencies. Removal from the catalogue effectively excludes a vendor from the Texas state government market for that service.

Relationship To Others In Group

Paired with TX-RAMP Level 2 as a tiered certification programme. Level 1 covers low-impact data; Level 2 covers confidential state data. Both are derived from DIR Control Standards 2.0. TX-RAMP is modeled on FedRAMP (not in this group) but is Texas-specific and does not grant reciprocal FedRAMP authorization.

Name

TX TX-RAMP Level 2

Who It Applies To

Cloud service providers seeking to sell higher-impact cloud services to Texas state agencies handling sensitive or confidential data.

Common Failure Mode

The timeline. TX-RAMP Level 2 assessments are not fast. Organizations that begin pursuing a Texas state agency contract and realize mid-RFP that TX-RAMP Level 2 is required cannot complete the certification in time for contract award. Typical cycle is 6 to 18 months depending on the completeness of security documentation and DIR''s review queue.

What It Actually Requires

Comprehensive assessment against a larger NIST 800-53 control subset. DIR review of security documentation -- not just self-attestation. Third-party assessment may be required for higher-impact services. DIR issues the certification after review.

Enforcement And Consequences

Same market-access mechanism as Level 1. Level 2 is specifically required for services handling confidential state data. Without it, state agencies cannot procure.

Relationship To Others In Group

Analogous to FedRAMP Moderate or High for the Texas state government context. Organizations that have FedRAMP authorization will find substantial control overlap but still need to complete a separate TX-RAMP process -- the certifications are not reciprocal.

Name

VA CDPA 2023

Who It Applies To

Businesses controlling or processing personal data of 100,000 or more Virginia consumers per year, or 25,000 consumers where more than 50% of gross revenue comes from selling personal data. Effective January 2023. Amended in 2025.

Common Failure Mode

The data protection assessment requirement is treated as a checklist rather than a documented analysis. Virginia''s law specifies that assessments must weigh benefits against privacy risks, consider available alternatives, and evaluate the safeguards in place. We have reviewed ''data protection assessments'' in client documentation that were two-page forms with no documented analysis of alternative approaches or risk mitigation rationale. Those do not satisfy the Virginia requirement -- they satisfy the appearance of it.

What It Actually Requires

Consumer rights: access, correction, deletion, portability, opt-out of targeted advertising, sale, and profiling. Data protection assessments required before engaging in high-risk processing activities -- targeted advertising, selling personal data, profiling with potential for harm, processing sensitive data. These assessments must be retained and provided to the AG on request. Processing sensitive data (health data, biometric data, precise geolocation, racial or ethnic origin, religious beliefs, sexual orientation, immigration status) requires consent. Children ages 13-17: no targeted advertising without consent.

Enforcement And Consequences

Virginia AG exclusively. No private right of action. 30-day cure period. Civil penalties up to $7,500 per violation.

Relationship To Others In Group

Often called the model for second-wave state privacy laws. Colorado CPA, Oregon CPA, and Tennessee TIPA all follow Virginia''s basic structure. Virginia was the second state (after California) to pass a comprehensive privacy law, and its business-friendly design was deliberate -- no private right of action, AG-only enforcement, cure period. That design influenced every state privacy law that followed it.

Name

VT Act 171 of 2018

Who It Applies To

Data brokers: companies that collect and sell or license personal information of Vermont residents where they do not have a direct relationship with those individuals. Annual registration required with the Vermont Secretary of State.

Common Failure Mode

Organizations that aggregate and resell personal data but define themselves as ''analytics companies'' or ''marketing technology companies'' rather than ''data brokers.'' Vermont''s definition is functional, not self-reported -- if you collect and sell personal information of Vermont residents without a direct relationship with those individuals, you are a data broker under Vermont law regardless of what your website says you do. One Vulnox assessment of a 60-person marketing analytics firm found the company met Vermont''s definition and had never registered, despite five years of processing Vermont resident data.

What It Actually Requires

Annual registration and a $100 filing fee. Disclosure of data collection practices, opt-out mechanisms offered, and security programme. Implementation of a comprehensive information security programme. Opt-out rights for certain uses. Prohibited from facilitating certain harmful uses of data (stalking, harassment, discriminatory practices).

Enforcement And Consequences

Vermont AG enforcement for failure to register. Civil penalties available.

Relationship To Others In Group

Unique in this group: the only framework focused specifically on data brokers rather than direct-relationship businesses. California''s CPPA has a data broker registry under CCPA/CPRA -- a separate mechanism from Vermont''s but addressing the same actor category. No other framework in this group directly regulates data brokers as a distinct entity type.

Name

AK PIPA

Who It Applies To

Businesses of all sizes that collect or maintain personal information of Alaska residents, regardless of where the business is located.

Common Failure Mode

Alaska is frequently missing from multi-state breach notification matrices. The state''s population is small enough that incident response teams sometimes conclude Alaska residents are not ''materially affected'' by a breach without actually counting affected Alaska residents. The obligation triggers regardless of how many Alaska residents are affected -- there is no minimum threshold in Alaska PIPA.

What It Actually Requires

Breach notification to affected Alaska residents when their personal information is acquired without authorization. Notification to the Alaska AG. Reasonable security procedures appropriate to the nature of the personal information.

Enforcement And Consequences

Alaska AG enforcement. Civil penalties available.

Relationship To Others In Group

Breach notification law parallel to CA SB1386, IL PIPA, OR 646A, NY SHIELD Act, and TX BC521. No consumer rights framework equivalent in Alaska -- this is notification-only with a security baseline, not a comprehensive privacy law.

Where these frameworks align, where they diverge, and where they actively conflict

Overlaps

Frameworks
  • MA 201 CMR 17.00

  • NY SHIELD Act S5575B

  • IL IPA

  • NY DFS 23 NYCRR500 2023 Amd 2

Where They Diverge

Massachusetts 201 CMR 17.00 specifies technical controls in more detail -- portable device encryption, firewall requirements. NY DFS 23 NYCRR 500 goes much further with mandatory annual penetration testing, board reporting, and 72-hour incident notification. IL IPA requires 72-hour notification to the insurance regulator specifically. The WISP is the shared foundation, but the NY DFS and IL IPA frameworks require significantly more operational infrastructure on top of it.

Shared Control Area

Written information security programme (WISP): all four require a documented security programme with risk assessment, administrative, technical, and physical safeguards, vendor management provisions, and employee training. A WISP built to Massachusetts 201 CMR 17.00 standards satisfies the SHIELD Act''s data security programme requirement with minimal adaptation. IL IPA and NY DFS follow the same structural pattern with additional sector-specific requirements layered on top.

Frameworks
  • CA CCPA/CPRA

  • VA CDPA 2023

  • CO Colorado Privacy Act

  • OR CPA

  • TN TIPA

  • TX CDPA

Where They Diverge

Definitions of ''sensitive data'' differ: California includes precise geolocation and specific behavioral inferences; Oregon has an unusually broad definition of consumer health data; Virginia, Colorado, and Tennessee align closely with GDPR-style sensitive categories. Thresholds differ: Texas CDPA has no volume threshold; Tennessee TIPA has a 175,000-consumer threshold. Enforcement models differ: California has a dedicated agency (CPPA) and a private right of action for data breaches; all others are AG-only. Cure periods differ: Tennessee offers 60 days, most others offer 30, California offers none.

Shared Control Area

Consumer rights infrastructure: all six require mechanisms for consumers to access, correct, delete, and port their personal data, and to opt out of certain uses. A unified rights request intake and response workflow can serve all six simultaneously. Privacy notices covering all six frameworks'' required disclosure elements can be maintained in a single document with state-specific supplements.

Frameworks
  • TX DIR Control Standards 2.0

  • TX TX-RAMP Level 1

  • TX TX-RAMP Level 2

  • TX SB 820

  • TX SB 2610

Where They Diverge

TX-RAMP is a vendor certification programme; DIR Control Standards are agency requirements. TX SB 820 adds a mandatory employee training obligation with DIR-approved content. TX SB 2610 extends the framework to local governments with less prescriptive implementation requirements. The obligations apply to different actors -- state agencies, local governments, and cloud vendors -- and the documentation and assessment processes for each are run through different DIR workflows.

Shared Control Area

NIST 800-53-derived control families: access control, incident response, configuration management, risk assessment, system protection. Building a security programme against NIST 800-53 (or the SCF) simultaneously addresses the foundational requirements of all five Texas government frameworks.

Frameworks
  • CA SB1386

  • IL PIPA

  • OR 646A

  • AK PIPA

  • NY SHIELD Act S5575B

  • TX BC521

Where They Diverge

Notification timelines: Oregon requires notification without unreasonable delay; New York requires notification in the most expedient time possible; Texas requires notification ''as quickly as possible.'' AG notification thresholds differ: Oregon and Texas both trigger at 250 affected residents; New York triggers at 500. Alaska has no minimum threshold. The personal information definitions have diverged over time as each state has amended its law independently -- Illinois now covers medical information and health insurance data, for example, while the original CA SB1386 definition was narrower.

Shared Control Area

Breach notification obligation: all six require notifying affected individuals when their personal information is acquired without authorization. All six also impose a ''reasonable security'' baseline. A unified breach response programme with a single notification workflow can be adapted to all six with jurisdiction-specific overlays for notification content and timeline.

Conflict Zones

The most operationally significant conflict zone in this group sits between the comprehensive privacy rights laws and the sector-specific security frameworks on the subject of data retention and deletion. CCPA/CPRA, Virginia CDPA, Colorado CPA, and Oregon CPA all grant consumers the right to request deletion of their personal data. NY DFS 23 NYCRR 500 requires covered entities to maintain records of cybersecurity events, audit logs, and security programme documentation for defined retention periods -- some of which involve personal information. IL IPA similarly requires records retention for compliance with its programme requirements. An insurance company or financial institution in New York or Illinois that receives a deletion request from a California or Virginia consumer faces a direct tension: the privacy rights law says delete the data; the sector-specific security regulation says retain it. The frameworks do not resolve this. Neither acknowledges the other. The organization is left to manage the conflict through documented legal hold logic -- retaining data subject to legal, regulatory, or compliance obligations while honoring deletion for data that is not -- a process that requires more operational sophistication than either framework explicitly demands.

A secondary conflict zone exists between Illinois BIPA''s consent requirement and any analytics or workforce management system that processes biometric data of Illinois employees. BIPA requires written consent before collection. Several enterprise HR and payroll systems collect biometric data as a standard feature of their attendance or authentication modules -- the vendor''s terms of service do not substitute for the individual employee consent that BIPA requires. Organizations that deployed these systems before BIPA''s implications were widely understood may have years of biometric data collected without BIPA-compliant consent, which is not a historical violation that corrects itself -- it is a continuing violation until the consent is obtained or the processing stops.

What we found when we looked at real environments

Assessment base: Vulnox multi-state privacy and data security assessments, 2024-2025. Client profiles: technology companies, professional services firms, financial services organizations, and marketing analytics companies across the US, UK, and Southeast Asia with US operations or US customer bases.

WISP documents that do not match actual technical environments

In 14 of 22 assessments involving Massachusetts 201 CMR 17.00 or NY SHIELD Act obligations during 2024, the written information security programme on file described technical controls that were either not implemented or not applied to the full scope of personal information the organization held. The most common specific gap: encryption requirements for portable devices and data in transit stated in the WISP but not enforced by technical controls. Organizations had endpoint management tools capable of enforcing encryption but had not configured them to do so. The WISP said ''all portable devices containing personal information shall be encrypted.'' The MDM console showed 23% of devices without encryption enabled. (Vulnox assessment data, 2024.)

Implication:

The client''s position going in was ''we have a WISP, we''re compliant.'' The actual finding was that the WISP described a security state that did not exist. In a breach scenario, regulators and plaintiffs do not look at policy documents in isolation -- they look at whether controls were actually implemented. A WISP that accurately describes non-existent controls is worse than having no WISP, because it demonstrates awareness of the obligation combined with failure to meet it.

BIPA exposure at organizations that had never heard of BIPA

Three client assessments in the past 18 months involved organizations outside Illinois -- two headquartered in Texas, one in Oregon -- that had deployed enterprise software products used by their Illinois-based employees. All three had deployed products with facial recognition or fingerprint authentication features. None had conducted a BIPA compliance review. None had BIPA-compliant consent forms. None had a publicly available biometric data retention and destruction policy. All three had been using these products for more than two years. (Vulnox assessment data, 2024.)

Implication:

The clients'' position was ''BIPA is an Illinois problem for Illinois companies.'' That is not how the statute works. BIPA applies to biometric data collected from individuals in Illinois regardless of where the collecting organization is headquartered. The geographic trigger is where the individuals are, not where the organization is. Software vendors and their enterprise customers both have potential exposure -- and the class action mechanism means this exposure has no ceiling defined by the number of employees affected. One of those three clients had 340 Illinois-based employees using the fingerprint attendance system.

TX-RAMP timeline surprises during active procurement

In two separate client engagements during 2024-2025, cloud software vendors discovered their TX-RAMP Level 2 requirement mid-RFP for Texas state agency contracts. Both had assumed TX-RAMP was similar to SOC 2 Type II in timeline -- achievable in 3 to 6 months with the right documentation in place. TX-RAMP Level 2 requires DIR document review and queues behind other submissions. Both clients missed the award window. One contract was lost entirely. (Vulnox assessment data, 2025.)

Implication:

The clients believed TX-RAMP was a documentation exercise with a defined timeline. The actual constraint is DIR''s review capacity, which creates unpredictable queue delays. Organizations pursuing Texas state agency contracts need to begin TX-RAMP at least 12 months before anticipated contract execution -- ideally 18 months for Level 2 -- not after receiving an RFP that requires it.

Data broker status not self-assessed

In one assessment of a 60-person marketing analytics company that had engaged Vulnox for a multi-state privacy compliance review, the company had never assessed whether it qualified as a data broker under Vermont Act 171. The company collected purchase intent signals, demographic inferences, and behavioral profiles from third-party sources and licensed them to B2B clients -- without a direct relationship with the individuals whose data it held. Vermont''s definition covers exactly this model. The company had been processing Vermont residents'' data for five years without registering. Annual registration fee is $100. The legal exposure from five years of unregistered data broker activity is substantially higher. (Vulnox assessment data, 2024.)

Implication:

Organizations in the data services, marketing technology, and analytics sectors frequently define themselves by their product category rather than by their regulatory classification. The Vermont data broker definition is functional -- it asks what you do with the data, not what you call yourself. Any organization that aggregates data from sources other than a direct consumer relationship and provides it to third parties should run the Vermont analysis as a first step in any multi-state privacy review.

The mistakes that cost organizations the most

Mistakes

Mistake

Treating CCPA compliance as a proxy for multi-state US compliance

Why It Happens

CCPA was the first major state privacy law, received the most media coverage, and triggered the most compliance investment. Organizations that completed CCPA compliance in 2020 or 2021 often concluded they were ahead of the curve. By 2025, the curve had moved. Virginia, Colorado, Oregon, and Tennessee all passed comprehensive privacy laws. Texas CDPA -- with no volume threshold -- came into effect July 2024. Each requires consumer rights workflows. Most require data protection assessments. CCPA compliance was a starting point, not a destination, and it did not stay current with the laws that followed.

Actual Consequence

Organizations discover mid-investigation that their ''privacy programme'' is actually a California programme with a privacy policy that mentions other states. The Virginia AG''s office, the Colorado AG''s office, and the Texas AG''s office are all empowered to investigate independently. Being CCPA-compliant provides no protection against a Colorado enforcement action.

Mistake

Building breach notification workflows that cover consumer notification but not regulator notification

Why It Happens

Consumer notification is the visible obligation -- the one that generates news coverage and consumer complaints. Regulator notification is the hidden one. Oregon requires AG notification when 250 or more Oregon residents are affected. New York requires AG notification when 500 or more New York residents are affected. Texas requires AG notification when 250 or more Texans are affected. Illinois IPA requires 72-hour notification to the insurance regulator for any significant cybersecurity event. NY DFS 23 NYCRR 500 requires 72-hour notification to DFS. These are parallel obligations that trigger on different criteria than consumer notification, and they are often missing from incident response playbooks.

Actual Consequence

Organizations notify consumers within appropriate timelines and believe they have completed their breach response obligations. Regulator notification deadlines pass unmet. Several state AGs have pursued enforcement actions specifically against organizations that notified consumers but failed to notify regulators -- or notified regulators late. The consumer notification was visible; the regulator notification failure was not, until the enforcement letter arrived.

Mistake

Treating consent in enterprise software deployments as the vendor''s responsibility rather than the employer''s

Why It Happens

Enterprise software is sold with a terms of service and a data processing agreement. Buyers assume those documents transfer compliance responsibility to the vendor. For GDPR-style processing agreements, that is partially correct. For BIPA, it is not. BIPA requires consent from the individual whose biometric data is collected -- not from the organization purchasing the software. A vendor''s contract with an enterprise client does not substitute for the enterprise client''s written consent from their employees. This distinction is well-established in Illinois case law, but it is not communicated in most enterprise software contracts.

Actual Consequence

The employer -- not the software vendor -- is typically the primary defendant in BIPA class actions, because the employment relationship creates the contact point with the individuals whose consent was not obtained. Class actions against employers for BIPA violations by fingerprint time-and-attendance systems have settled for amounts ranging from hundreds of thousands to tens of millions of dollars, depending on the headcount of affected Illinois employees.

Mistake

Starting TX-RAMP certification after receiving a Texas state agency RFP that requires it

Why It Happens

TX-RAMP is less visible than FedRAMP in vendor compliance discussions, and its timeline implications are not well-publicized outside the Texas state agency procurement ecosystem. Cloud vendors whose federal compliance teams are familiar with FedRAMP often assume TX-RAMP will follow a similar timeline. FedRAMP timelines are themselves notoriously long, but the misconception that TX-RAMP is faster is compounded by the DIR review queue, which is not a self-managed process.

Actual Consequence

Lost contract opportunities. TX-RAMP Level 2 certifications that begin during active RFP cycles do not complete before award decisions. Organizations that have invested in pursuit of a Texas state contract -- sometimes including months of business development, technical demonstrations, and proposal preparation -- are disqualified on a certification timeline issue that could have been avoided with 12 to 18 months of advance planning.

The notification-timeline gap that only appears when you look at all of them at once

Insight

Every framework in this group that involves breach notification or cybersecurity incident reporting uses a different timeline, triggered by a different event definition, reported to a different body, with different content requirements. The 72-hour frameworks (NY DFS 23 NYCRR 500, IL IPA, NV Gaming Regulation 5.260) require notification to regulators within 72 hours of determining that a cybersecurity event has occurred -- not 72 hours from discovery, but 72 hours from determination that it meets the regulatory definition. The ''as quickly as possible'' and ''without unreasonable delay'' frameworks (OR 646A, TX BC521, AK PIPA) have no fixed clock but have been enforced against delays exceeding 60 days in documented cases. CCPA/CPRA''s private right of action for breach notification failures has no specific timeline in the statute -- the reasonableness standard applies. IL BIPA has no breach notification requirement at all. It is not a notification law -- it is a pre-collection consent law.

When you read each framework''s breach notification section individually, these distinctions look manageable. The problem that becomes visible only when you look at all of them together is this: organizations building incident response plans calibrate their notification timeline to their most demanding obligation and assume the others are satisfied. They are not. An organization subject to NY DFS 23 NYCRR 500 (72 hours to DFS), OR 646A (no unreasonable delay with AG threshold at 250), and TX BC521 (as quickly as possible with AG threshold at 250) has three parallel notification obligations with three different assessment criteria and three different recipients. All three clocks start at different points -- DFS''s 72 hours from ''determination,'' Oregon''s and Texas''s reasonable delay standard from discovery. The determination date and the discovery date are not the same. An incident response programme that conflates them -- setting a single clock that starts at discovery and runs to 72 hours -- will be late to DFS if determination lags discovery by more than 72 hours, and may be early enough for Oregon and Texas but miss the DFS window.

No single framework''s documentation describes this sequencing problem, because no single framework knows about the others.

Practical Implication

Incident response playbooks for organizations subject to multiple frameworks in this group need separate notification decision trees for each applicable framework, not a single unified timeline. The playbook must answer: which frameworks apply to this incident? For each applicable framework, when did the relevant trigger event (discovery, determination, confirmation of unauthorized access) occur? What are the content requirements for each notification? Who is the recipient? When is the deadline? These questions have different answers for each framework, and a single-timeline playbook treats them as if they have the same answer.

Why It Is Invisible In Isolation

Each framework describes its own notification obligation in isolation. NY DFS describes 72 hours from a ''cybersecurity event.'' Texas BC521 says ''as quickly as possible.'' Oregon 646A says ''without unreasonable delay.'' None of them explain that an organization subject to multiple frameworks must manage multiple parallel timelines triggered by different definitional events, reported to different recipients, with different content requirements. Reading each framework independently, the reader concludes ''I need to notify quickly'' and sets a single internal clock. The multi-framework complexity -- three different trigger definitions, three different recipients, three different content standards -- only becomes visible when you map all applicable frameworks simultaneously.

The most efficient path through these 22 frameworks

The sequencing logic for multi-state US compliance depends entirely on which of the four framework categories applies to your organization. Start there, not with a comprehensive gap analysis against all 22 simultaneously. That approach produces a compliance programme that is perpetually under construction and never operational.

If you are a private organization subject to comprehensive privacy rights laws, start with California CCPA/CPRA. It has the most developed regulatory infrastructure, the most detailed CPPA regulations, and the most enforcement precedent. A CCPA/CPRA-compliant programme transfers roughly 70% of its structure to Virginia CDPA, Colorado CPA, Oregon CPA, Tennessee TIPA, and Texas CDPA. The remaining 30% is state-specific work: threshold assessment for each state, adjusting the sensitive data consent mechanism for Oregon''s broader health data definition, adding a universal opt-out mechanism for Colorado, ensuring Tennessee''s 60-day cure period is reflected in your response SLAs. Do not build six separate compliance programmes. Build one programme to CCPA/CPRA standards and document the state-specific deltas.

If you have a written information security programme obligation, build it to Massachusetts 201 CMR 17.00 standards. It is the most technically specific of the WISP-based frameworks in this group. A WISP meeting Massachusetts standards satisfies the NY SHIELD Act security programme requirement simultaneously. Portable device encryption, data in transit encryption, and vendor contract requirements are the three controls that most frequently produce gaps -- implement them technically, not just as policy statements.

If you are a DFS-licensed financial institution, NY DFS 23 NYCRR 500 (2023 Amendment 2) is your highest-demand framework and should drive your security programme architecture. The board reporting, annual penetration testing, and 72-hour notification mechanics are the operational controls most likely to be incomplete. Get those right first.

For the Texas government ecosystem (DIR Control Standards, TX-RAMP, SB 820, SB 2610): map your controls to NIST 800-53 and document that mapping. That single investment spans all five Texas government frameworks. If TX-RAMP is relevant, start it before you need it -- 12 to 18 months before anticipated procurement, not after receiving an RFP.

Sequencing Logic

Privacy rights laws: CCPA/CPRA first, then state-specific deltas for VA, CO, OR, TN, TX. WISP frameworks: Massachusetts 201 CMR 17.00 first, then SHIELD Act and sector-specific additions. Sector-specific cybersecurity: NY DFS for financial services, NV Gaming Regulation 5.260 for gaming, IL IPA for insurance -- each requires dedicated programme build, not adaptation from a general WISP. Texas government: NIST 800-53 mapping first, TX-RAMP certification planning second, policy alignment for SB 820/2610 third. Breach notification: build a unified response programme with per-jurisdiction notification overlays; do not try to build separate response plans for each state.

Common Shortcut That Fails

The shortcut that consistently fails is building a privacy policy and a data processing agreement template and calling the multi-state programme complete. Privacy policies and DPA templates are documentation of a compliance programme. They are not the programme. The consumer rights workflows, the data deletion mechanics, the opt-out signal processing, the 72-hour notification escalation paths, the data protection assessments, the board reporting cadence -- those are the programme. Organizations that produce documents without implementing the operational workflows behind them discover this gap at the worst possible time: during a regulator inquiry, a consumer rights request that cannot be fulfilled within the response window, or a breach response where the notification timelines are not known in advance.

What is going to happen in this space over the next three years

  1. Texas CDPA enforcement will produce the first multi-million-dollar penalty against a mid-market company that crossed the SBA small business threshold without reassessing its compliance obligations, likely between 2026 and 2027.

    The Texas CDPA''s absence of a consumer volume threshold means the applicability trigger is purely the SBA size standard -- which changes as companies grow and as the SBA revises NAICS-based thresholds. Companies that assessed their CDPA obligations in 2024 at one size may no longer qualify for the exclusion by 2026. The enforcement mechanism (Texas AG, $7,500 per violation, 30-day cure period) has enough teeth to make a mid-market enforcement action economically meaningful. Texas has historically been an active AG state for consumer protection enforcement.

    Confidence: mediumNo multi-million-dollar Texas CDPA enforcement action against a non-large-enterprise organization by end of 2027 would reduce confidence. An action against a company that clearly knew it was covered and chose not to comply would not confirm this specific prediction.
  2. Within 24 months, at least two other US gaming jurisdictions -- likely New Jersey and Pennsylvania -- will adopt cybersecurity regulations closely modeled on Nevada Gaming Regulation 5.260, including a sub-96-hour incident reporting requirement.

    Nevada acted first because the 2023 MGM and Caesars incidents happened on Nevada soil and were most politically visible there. New Jersey and Pennsylvania have comparably large gaming industries, similar regulatory infrastructure through their respective gaming control boards, and the same underlying risk environment. The Nevada model exists and has been in effect long enough to reference. Regulatory cross-pollination in gaming is historically fast -- Nevada''s original financial controls were adopted across US gaming jurisdictions within a decade. Cybersecurity standards will move faster.

    Confidence: highNeither New Jersey nor Pennsylvania gaming regulator publishing a formal cybersecurity rule proposal by end of 2027 would falsify this prediction. Adoption of a materially different model (e.g., voluntary framework with no reporting mandate) would also falsify it.
  3. A mid-market employer with between 300 and 1,000 Illinois employees will face a BIPA class action settlement exceeding $50 million as a result of biometric data collected through an AI-powered HR or productivity software feature deployed between 2021 and 2024, with the claim filed between 2026 and 2028.

    The combination of AI-powered facial recognition and workplace monitoring software deployed at enterprise scale during the remote work period of 2020-2023, the 5-year statute of limitations under BIPA, and the $5,000 per reckless violation statutory damages rate creates an arithmetic problem for employers in this size range. An employer with 500 Illinois employees who deployed a system collecting facial geometry without BIPA-compliant consent has potential exposure of $2.5 million on the negligence theory and $2.5 billion on the reckless/intentional theory -- before attorneys'' fees. Real settlements are negotiated well below statutory exposure, but $50 million for a 500-employee employer with years of unconsented biometric collection is arithmetically reachable.

    Confidence: mediumNo settlement in this range for a non-large-enterprise employer by end of 2028. Illinois legislative amendment of BIPA to reduce statutory damages or add a cure period (which has been proposed but not passed) would reduce the likelihood of this claim materializing.

The state patchwork is not going to be replaced by a federal law, and that is a governance problem nobody has solved

There is a persistent belief in compliance circles that the US state privacy patchwork will eventually be resolved by federal preemption -- a national privacy law that creates a single standard and supersedes the state frameworks. That belief has been used to justify delaying multi-state compliance investment for more than five years. It is not a reasonable planning assumption. The US Congress has failed to pass a comprehensive federal privacy law through multiple sessions despite bipartisan interest. The states are not waiting. Texas CDPA took effect in July 2024. Tennessee TIPA took effect in July 2025. Florida, Maryland, and Minnesota have added to the stack. Each new law adds compliance surface without resolving the conflicts between existing ones. The deletion-versus-retention conflict between CCPA/CPRA and NY DFS 23 NYCRR 500 described earlier in this article is a structural problem that a federal law would resolve -- but it has existed unresolved since 2020. Organizations that have been waiting for federal preemption to simplify their compliance posture have been accumulating exposure while they waited.

Counterargument

The counterargument is that federal preemption is genuinely possible within the next Congress, and that building multi-state compliance infrastructure that may be partially superseded is wasteful. That argument has merit if preemption is imminent. The problem is that this same argument has been made in every Congress since 2018, and the legislative dynamics -- state AG opposition to preemption provisions, disagreement over private right of action, industry lobbying for weaker standards -- have not materially changed. Waiting for a federal law to simplify the problem is a bet against the base rate. The base rate says: build multi-state compliance now, adapt if preemption happens, because the cost of a five-year delay is higher than the cost of post-preemption adaptation.

One thing to do this week

Pull your current incident response plan and find the section on breach notification. Count how many jurisdictions it names. Then count how many jurisdictions in which you hold personal information of residents. If the second number is larger than the first -- and it almost certainly is -- your notification plan has gaps that will only become visible during an incident. Add the missing jurisdictions, document the notification timeline for each, identify the regulator notification threshold for each, and confirm who in your organization is authorized to make the notification decision for each. That single update will reduce more real breach response risk than any policy document.

Further Reading

Frequently Asked Questions

Does the Texas CDPA apply to my company if we have no consumer volume threshold?

Texas CDPA is unusual in that it has no consumer volume or revenue threshold -- it applies to any business processing personal data of Texas residents that is not a small business under SBA definitions. The SBA size standard varies by industry NAICS code. Many mid-market companies assume they qualify for the SBA small business exclusion without checking the actual SBA table for their industry. A professional services firm with 300 employees may or may not qualify depending on the specific SBA size standard for its NAICS code.

What is the difference between the NY SHIELD Act and Massachusetts 201 CMR 17.00?

Both require a written information security programme (WISP) with administrative, technical, and physical safeguards. Massachusetts 201 CMR 17.00 is more technically specific -- it mandates portable device encryption, encryption of personal information transmitted across public networks, and up-to-date firewall and malware protection as explicit requirements. The NY SHIELD Act requires ''reasonable safeguards'' calibrated to the size and complexity of the business. A WISP built to Massachusetts standards satisfies the SHIELD Act security programme requirement. The SHIELD Act also expanded New York''s breach notification obligations, which Massachusetts 201 CMR 17.00 does not address.

When does Illinois BIPA apply to a company headquartered outside Illinois?

BIPA applies when biometric data is collected from individuals in Illinois -- the geographic trigger is where the individuals are located, not where the collecting organization is headquartered. A Texas-headquartered employer with 200 Illinois-based employees who uses a fingerprint time-and-attendance system must comply with BIPA: written consent before collection, a publicly available retention and destruction policy, and prohibition on selling or profiting from biometric data. The $1,000 to $5,000 per violation statutory damages with private right of action apply regardless of the employer''s headquarters state.

How long does TX-RAMP Level 2 certification take?

Based on Vulnox client engagements, TX-RAMP Level 2 typically takes 12 to 18 months from initiation to DIR certification, depending on the completeness of security documentation at the start of the process and DIR''s review queue. Organizations that begin the process after receiving an RFP requiring TX-RAMP Level 2 certification will not complete certification before the award decision. The process requires DIR document review -- not just self-attestation -- and DIR review timelines are not within the vendor''s control.

What is the difference between Nevada SB220 and Nevada Gaming Regulation 5.260?

They are unrelated frameworks with different enforcers and different purposes. Nevada SB220 is a consumer privacy opt-out law enforced by the Nevada AG -- it requires operators of websites and online services that sell personal information to provide a consumer opt-out mechanism. Nevada Gaming Regulation 5.260 is a sector-specific cybersecurity regulation enforced by the Nevada Gaming Control Board -- it requires licensed gaming establishments to implement a written cybersecurity programme, risk assessments, access controls, and 72-hour incident reporting. One is a privacy opt-out law; the other is an operational cybersecurity standard. Casino operators in Nevada are subject to both, through different regulatory bodies.

Which US state frameworks require regulator notification (not just consumer notification) after a breach?

Several frameworks in this group require parallel regulator notification: New York SHIELD Act requires AG notification when 500 or more New York residents are affected; Oregon 646A and Texas BC521 require AG notification when 250 or more residents are affected; Alaska PIPA requires AG notification with no minimum threshold; NY DFS 23 NYCRR 500 requires DFS notification within 72 hours of any significant cybersecurity event regardless of affected consumer count; Illinois IPA requires notification to the Illinois Director of Insurance within 72 hours; Nevada Gaming Regulation 5.260 requires NGCB notification within 72 hours. Consumer notification and regulator notification are parallel obligations triggered by different criteria.

Do Virginia CDPA data protection assessments need to be documented or just completed internally?

Virginia CDPA requires that data protection assessments be documented and retained. The Virginia AG can request assessments during an investigation. Assessments must demonstrate that the controller weighed the benefits of the processing against the privacy risks, considered available alternatives, and evaluated safeguards in place. A two-page form with no documented analysis of risk mitigation rationale does not satisfy the requirement. The assessment must be substantive enough to be defensible if reviewed by the AG -- which means it needs to show the reasoning, not just the conclusion.

Is a WISP enough to satisfy all the security-related obligations in this framework group?

No. A WISP satisfies the security programme requirement in Massachusetts 201 CMR 17.00, the NY SHIELD Act, Illinois IPA, and the breach notification laws (which impose a reasonable security baseline). It does not satisfy the consumer rights workflows, opt-out mechanisms, and data protection assessments required by CCPA/CPRA, Virginia CDPA, Colorado CPA, Oregon CPA, Tennessee TIPA, and Texas CDPA. It does not satisfy the annual penetration testing, board reporting, 72-hour notification, and MFA requirements of NY DFS 23 NYCRR 500. A WISP is one component of a multi-state compliance programme, not the whole thing.

Related Articles

HIPAA compliance framework guide: Security Rule, HICP, and the 2013 Omnibus

HIPAA compliance framework guide: Security Rule, HICP, and the 2013 Omnibus

Vulnox assessments of healthcare organizations found that 71% had never tested their breach notification pipeline against an after-hours discovery scenario. This guide maps all five HIPAA group frameworks — Security Rule, Administrative Simplification, and HICP tiers — and identifies where the gaps actually live.

EMEA compliance frameworks: the complete guide to GDPR, NIS2, DORA, and 40+ regional mandates

EMEA compliance frameworks: the complete guide to GDPR, NIS2, DORA, and 40+ regional mandates

A 60-person SaaS company with a full GDPR programme still had four separate regulatory exposures — PSD2, NIS2, German KRITIS, and BSI C5 — none of which appeared on their compliance register. This guide maps every EMEA framework, where they overlap, and where following one makes another harder to satisfy.

CMMC 2.0 levels explained: which tier applies to your DoD contract and what it actually requires

CMMC 2.0 levels explained: which tier applies to your DoD contract and what it actually requires

In Vulnox assessments of DIB contractors preparing for C3PAO audits, the average SPRS score submitted before engagement was 89 points higher than the score calculated after independent control verification. This guide maps all four CMMC 2.0 instruments — Levels 1, 1 AOs, 2, and 3 — and the gaps that explain that delta.

Ready to Secure Your Digital Assets?

Get a comprehensive vulnerability assessment for your website today.