1---2name: state-privacy-law-compliance-timeline3description: Compliance gap analysis and remediation timeline for a newly enacted state consumer data privacy statute, identifying gaps in consumer rights procedures, sensitive data handling, data processor agreements, and enforcement risk analysis.4---56# Skill: State Consumer Data Privacy Law Compliance Timeline78## 1. Subject-matter triage (only if applicable)910- Confirm the statute’s applicability triggers before assessing controls: business scope, data volume, revenue, and any statutory carveouts.11- Map the privacy program documents against the statute’s operative definitions, with special attention to data inventory, processing purposes, and any representations in the privacy notice.12- Identify whether the statute is in force, whether any compliance grace period applies, and whether the remediation timeline must be staged before or after the effective date.13- If the source set includes multiple internal documents, first inventory them by function: notice, policy, rights workflow, vendor management, data inventory, and risk assessment materials.1415## 2. Failure modes the skill is correcting1617- Failing to test threshold applicability before analyzing controls, which can produce a false compliance roadmap.18- Misclassifying encoded, hashed, or pseudonymized biometric identifiers as outside the biometric category because of format rather than underlying substance.19- Collapsing all consumer-rights requests into one deadline and omitting the statute’s notice, extension, or response mechanics.20- Missing the distinction between mandatory cure language and discretionary cure language in enforcement provisions, which changes the risk timeline.21- Treating sensitive-data handling, consumer-rights operations, and vendor-contract controls as a single general privacy issue instead of distinct compliance workstreams.22- Omitting a severity rating, which makes the gap analysis hard to triage.23- Stating a problem without tying it to the controlling statutory section, the affected document, and the operational consequence.24- Providing diagnosis without a concrete remediation plan, owner, and timing anchor.2526## 3. Legal frameworks / domain conventions that apply2728- Start with the statute’s definitions and scope provisions; the analysis should track the statutory text section-by-section rather than rely on generic state-privacy assumptions.29- Consumer rights analysis should follow the statute’s specific rights architecture: access, correction, deletion, portability if recognized, and opt-out rights for targeted advertising, sale, or profiling if covered.30- Response timing must be read from the statute’s consumer-request procedure section, including any extension mechanics and notice obligations.31- Sensitive-data treatment must follow the statute’s definition and consent mechanics, including special rules for biometric, health, precise-location, and children’s data where applicable.32- Biometric classification should be based on the nature of the identifier or measurement, not on whether it is stored, transmitted, or hashed in a particular format.33- Data protection assessment obligations, if present, should be analyzed by processing purpose and risk profile, not merely by the label of the dataset.34- Processor or vendor agreements should be reviewed against the statute’s required contractual terms, including processing instructions, confidentiality, audit or inspection rights, subprocessors, and deletion/return obligations.35- If the statute contains a cure provision, determine whether the attorney general “must” offer the cure period or “may” offer it, and identify the point at which the enforcement posture changes.36- Enforcement analysis should cite the statute’s civil-penalty provision and any express exclusions or limits on private enforcement.3738## 4. Analytical scaffolds3940- Begin with a scope gate:41 - identify the statute section establishing applicability;42 - confirm whether Meridian falls within the covered entity definition;43 - note any uncertainty and state what additional fact would resolve it.44- Build the gap analysis by control family:45 - consumer notice and disclosures;46 - consumer-rights intake and response workflow;47 - sensitive-data and biometric handling;48 - data minimization and retention governance;49 - assessment or DPIA-style review;50 - vendor/processor contracting;51 - internal escalation and recordkeeping.52- For each gap, apply a consistent triage frame:53 - identify the governing statutory section;54 - compare the statute’s requirement to the current program artifact;55 - state whether the control is absent, partial, or misaligned;56 - explain the practical consequence if not remediated.57- For biometric or sensitive-data issues, trace the issue through the data lifecycle:58 - collection;59 - use;60 - sharing/disclosure;61 - storage and retention;62 - deletion or de-identification.63- For consumer-rights procedures, test each request type separately rather than using a generic “privacy requests” process.64- For vendor controls, review each processor relationship independently where the source materials show different scopes or purposes.65- For enforcement risk, separate legal exposure from operational exposure:66 - statutory violations;67 - response-time failures;68 - contracting deficiencies;69 - documentation gaps that undermine good-faith defense.70- When the statute includes multiple timing regimes, lay them out chronologically:71 - effective date;72 - any pre-enforcement period;73 - cure window;74 - post-cure enforcement phase;75 - internal target dates for remediation.7677## 5. Vertical / structural / temporal relationships (only if applicable)7879- If any product or workflow processes biometric or other sensitive data, that issue should be treated as upstream and cross-cutting because it can trigger notice, consent, assessment, and vendor-flowdown obligations at once.80- If the privacy program lacks a written minimization or retention rule, that omission may amplify multiple downstream failures, including request handling, deletion, and vendor oversight.81- If the source documents show that request intake, approvals, and fulfillment are split across teams, the timeline should reflect handoffs and escalation dependencies, not just a final due date.82- If the statute’s cure language changes from mandatory to discretionary after a trigger point, remediation completed before that transition deserves priority because it can materially reduce enforcement exposure.83- If vendor agreements are deficient, remediation should be sequenced early because contract amendments often depend on procurement, legal, and business-owner signoff.84- If the company’s data inventory is incomplete, treat inventory completion as a prerequisite to finalizing the rest of the roadmap.8586## 6. Output structure conventions8788- Write the memorandum as a professional advisory document with a brief executive summary, followed by a structured gap analysis and a dated remediation roadmap.89- Define one ordinal severity scale at the outset and apply it uniformly to every issue entry.90- Organize the body by compliance theme rather than by document name, but cite the specific source artifact reviewed for each issue.91- For each issue entry, include:92 - severity;93 - statutory authority;94 - source document(s) reviewed;95 - the gap;96 - why it matters;97 - recommended remediation;98 - responsible owner or function;99 - timing anchor or deadline;100 - any cross-reference to related controls or disclosures.101- If a control appears partially compliant, say what is already in place and what is still missing.102- Include a separate enforcement-risk section that explains the statute’s penalty mechanics and the practical enforcement posture, using the controlling statutory provisions.103- Include a remediation roadmap section that orders actions by urgency and dependency, with near-term, intermediate, and longer-term milestones.104- End with an explicit Recommended Actions block using imperative verbs, named owners, and timing anchors tied to the statute’s effective date, cure period, or other regulatory milestone.105- Preserve document-drafting discipline: conclusions should be tied to the source materials and the statute, not to general privacy-policy aspirations.