Multi-State Harmonized Compliance Program
Overview
As of 2026, over 20 US states have enacted comprehensive consumer privacy legislation. Organizations operating nationwide face a complex patchwork of requirements with significant overlap but important state-specific variations. A harmonized multi-state compliance program identifies the common baseline, maps state-specific deltas, and implements a unified privacy architecture that satisfies all applicable laws.
This skill covers the eight major enacted and effective state privacy laws: CCPA/CPRA (California), VCDPA (Virginia), CPA (Colorado), CTDPA (Connecticut), TDPSA (Texas), OCPA (Oregon), MTDPA (Montana), and KPPA (Kentucky).
Common Requirements Matrix
Consumer Rights — Universal Baseline
All eight laws provide these core rights:
| Right |
CA |
VA |
CO |
CT |
TX |
OR |
MT |
KY |
| Access/Know |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Correct |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Delete |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Portability |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Opt-out: targeted ads |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Opt-out: sale |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Opt-out: profiling |
No* |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
| Limit sensitive PI |
Yes |
N/A |
N/A |
N/A |
N/A |
N/A |
N/A |
N/A |
| Third-party list |
No |
No |
No |
No |
No |
Yes |
No |
No |
| Appeal |
No |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
*California provides opt-out of automated decision-making under pending CPPA regulations.
Controller Obligations — Universal Baseline
| Obligation |
All States |
| Privacy notice/policy |
Required |
| Data minimization |
Required |
| Purpose limitation |
Required |
| Data security |
Required |
| Non-discrimination |
Required |
| Response timeline |
45 days (all states) |
State-Specific Deltas
California (CCPA/CPRA) — Unique Requirements
- Revenue threshold: $25M alternative threshold (no other state has this)
- Sensitive PI limit right: Post-collection limit mechanism (other states require pre-collection consent)
- CPPA enforcement: Dedicated privacy agency (only state with one)
- Private right of action: For data breach claims (only state with any private right of action)
- Annual metrics: Required for businesses processing 10M+ consumers
- Data processing agreements: Explicit statutory requirement
- No cure period: Eliminated by CPRA
Virginia (VCDPA) — Unique Requirements
- 50% revenue threshold: Higher revenue percentage requirement than most states
Colorado (CPA) — Unique Requirements
- AG rulemaking: Most detailed implementing regulations (4 CCR 904-3)
- Universal opt-out: First mandated (effective July 2024)
- Profiling opt-out scope: Broadest definition covering 7+ decision categories
- $20,000 penalties: Higher per-violation penalties under Consumer Protection Act
Connecticut (CTDPA) — Unique Requirements
- Dark pattern prohibition: Explicit statutory definition and prohibition
- Loyalty program exemption: Bona fide loyalty programs exempt from sale opt-out
- 25% revenue threshold: Lower than Virginia's 50%
Texas (TDPSA) — Unique Requirements
- No revenue/consumer threshold: Applies to all non-SBA-small businesses
- Data broker registration: Secretary of State registration requirement
- CUBI interaction: Separate biometric data law (up to $25,000/violation)
- Broadest applicability: Largest state population, lowest effective threshold
Oregon (OCPA) — Unique Requirements
- Nonprofit coverage: Applies to nonprofit organizations
- Third-party list right: Specific entity names, not just categories
- De-identified data: Most detailed compliance requirements
- Employee data partial exemption: Unique treatment of employee data
- Transgender/nonbinary status: Explicit sensitive data category
- 14-day cure period: Shortest cure period among states
Montana (MTDPA) — Unique Requirements
- 50,000 consumer threshold: Lowest consumer count threshold
- 15-day extension only: Shorter extension than most states' 45 days
- Air carrier exemption: Unique industry exemption
Kentucky (KPPA) — Unique Requirements
- January 2026 effective date: Most recently effective among this group
- 50% revenue threshold: Matches Virginia
Unified Privacy Program Architecture
Tier 1: Common Baseline (Apply Everywhere)
These requirements are common across all states and form the foundation:
- Privacy notice with categories of PI, purposes, rights, third parties, contact info
- Consumer rights portal supporting access, correct, delete, portability, opt-out
- 45-day response SLA with tracking and metrics
- Data minimization and purpose limitation controls
- Reasonable data security measures
- Non-discrimination protections
Tier 2: High-Water Mark (Apply to Satisfy Strictest Requirement)
Where state requirements differ, apply the strictest standard universally:
| Area |
Strictest Standard |
Source State |
| Sensitive data consent |
Opt-in consent before collection |
VA, CO, CT, TX, OR, MT, KY |
| Dark pattern prohibition |
Consent via dark patterns invalid |
CT (explicit), all (implicit) |
| Response extension |
15-day extension only |
MT (strictest) or accept state-by-state |
| Universal opt-out |
Honor GPC signals |
CA, CO, CT, MT |
| Profiling opt-out |
Include 7+ decision categories |
CO (broadest scope) |
| De-identified data |
Full compliance program |
OR (most detailed) |
| Privacy notice retention periods |
Include per-category retention |
CA (CPRA requirement) |
Tier 3: State-Specific (Apply Only Where Required)
| Requirement |
State(s) |
Implementation |
| "Do Not Sell or Share" link |
CA |
Homepage footer |
| "Limit Sensitive PI" link |
CA |
Adjacent to opt-out link |
| Specific third-party list |
OR |
Additional disclosure in Oregon responses |
| Data broker registration |
TX |
Secretary of State registration (if applicable) |
| Annual metrics disclosure |
CA (10M+) |
Privacy notice metrics section |
| Loyalty program exemption |
CT |
Program-specific terms |
| Nonprofit compliance |
OR |
Full program for Oregon nonprofit operations |
Implementation Strategy for Liberty Commerce Inc.
Approach: High-Water Mark with State-Specific Overlays
Liberty Commerce Inc. implements a unified privacy program at the highest common standard, with state-specific modules activated based on the consumer's state of residence.
Consumer Request Received
│
├─► Determine Consumer's State
│
├─► Apply Tier 1 Common Baseline
│ (Same for all states)
│
├─► Apply Tier 2 High-Water Mark
│ (Strictest standard, applied universally)
│
└─► Apply Tier 3 State-Specific Module
├─ California module: CPRA-specific disclosures, sensitive PI limit
├─ Oregon module: Third-party specific list
├─ Texas module: Data broker check
└─ Connecticut module: Loyalty program exemption assessment
Harmonized Privacy Notice Template
A multi-state privacy notice should include these sections to satisfy all eight laws:
- Categories of PI/personal data collected (all states)
- Categories of sensitive PI/sensitive data collected (all states)
- Purposes for each category (all states)
- Retention period or criteria per category (CA required; best practice all)
- Sources of PI (CA required; best practice all)
- Categories of third parties receiving PI (all states)
- Whether PI is sold or shared (all states)
- Whether targeted advertising is conducted (all non-CA states)
- Whether profiling is conducted (all non-CA states)
- Consumer rights and how to exercise (all states)
- Appeal process (VA, CO, CT, TX, OR, MT, KY)
- Contact information (all states)
- "Do Not Sell or Share" link (CA)
- "Limit Sensitive PI" link (CA)
- Universal opt-out disclosure (CA, CO, CT, MT)
- Last updated date (CA required; best practice all)
- Annual metrics (CA, if 10M+ consumers)
Key Regulatory References
- IAPP US State Comprehensive Privacy Law Comparison Chart (updated quarterly)
- CPPA Regulations 11 CCR §7001-7102
- Colorado AG Regulations 4 CCR 904-3
- Global Privacy Control Specification v1.0
1---2name: multi-state-compliance3description: Multi-state harmonized privacy compliance program. Common requirements matrix across all US state privacy laws, state-specific deltas, unified privacy program architecture, and implementation strategy for operating across California, Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and Kentucky.4license: Apache-2.05---67# Multi-State Harmonized Compliance Program89## Overview1011As of 2026, over 20 US states have enacted comprehensive consumer privacy legislation. Organizations operating nationwide face a complex patchwork of requirements with significant overlap but important state-specific variations. A harmonized multi-state compliance program identifies the common baseline, maps state-specific deltas, and implements a unified privacy architecture that satisfies all applicable laws.1213This skill covers the eight major enacted and effective state privacy laws: CCPA/CPRA (California), VCDPA (Virginia), CPA (Colorado), CTDPA (Connecticut), TDPSA (Texas), OCPA (Oregon), MTDPA (Montana), and KPPA (Kentucky).1415## Common Requirements Matrix1617### Consumer Rights — Universal Baseline1819All eight laws provide these core rights:2021| Right | CA | VA | CO | CT | TX | OR | MT | KY |22|-------|----|----|----|----|----|----|----|----|23| Access/Know | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |24| Correct | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |25| Delete | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |26| Portability | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |27| Opt-out: targeted ads | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |28| Opt-out: sale | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |29| Opt-out: profiling | No* | Yes | Yes | Yes | Yes | Yes | Yes | Yes |30| Limit sensitive PI | Yes | N/A | N/A | N/A | N/A | N/A | N/A | N/A |31| Third-party list | No | No | No | No | No | Yes | No | No |32| Appeal | No | Yes | Yes | Yes | Yes | Yes | Yes | Yes |3334*California provides opt-out of automated decision-making under pending CPPA regulations.3536### Controller Obligations — Universal Baseline3738| Obligation | All States |39|-----------|-----------|40| Privacy notice/policy | Required |41| Data minimization | Required |42| Purpose limitation | Required |43| Data security | Required |44| Non-discrimination | Required |45| Response timeline | 45 days (all states) |4647## State-Specific Deltas4849### California (CCPA/CPRA) — Unique Requirements50- **Revenue threshold**: $25M alternative threshold (no other state has this)51- **Sensitive PI limit right**: Post-collection limit mechanism (other states require pre-collection consent)52- **CPPA enforcement**: Dedicated privacy agency (only state with one)53- **Private right of action**: For data breach claims (only state with any private right of action)54- **Annual metrics**: Required for businesses processing 10M+ consumers55- **Data processing agreements**: Explicit statutory requirement56- **No cure period**: Eliminated by CPRA5758### Virginia (VCDPA) — Unique Requirements59- **50% revenue threshold**: Higher revenue percentage requirement than most states6061### Colorado (CPA) — Unique Requirements62- **AG rulemaking**: Most detailed implementing regulations (4 CCR 904-3)63- **Universal opt-out**: First mandated (effective July 2024)64- **Profiling opt-out scope**: Broadest definition covering 7+ decision categories65- **$20,000 penalties**: Higher per-violation penalties under Consumer Protection Act6667### Connecticut (CTDPA) — Unique Requirements68- **Dark pattern prohibition**: Explicit statutory definition and prohibition69- **Loyalty program exemption**: Bona fide loyalty programs exempt from sale opt-out70- **25% revenue threshold**: Lower than Virginia's 50%7172### Texas (TDPSA) — Unique Requirements73- **No revenue/consumer threshold**: Applies to all non-SBA-small businesses74- **Data broker registration**: Secretary of State registration requirement75- **CUBI interaction**: Separate biometric data law (up to $25,000/violation)76- **Broadest applicability**: Largest state population, lowest effective threshold7778### Oregon (OCPA) — Unique Requirements79- **Nonprofit coverage**: Applies to nonprofit organizations80- **Third-party list right**: Specific entity names, not just categories81- **De-identified data**: Most detailed compliance requirements82- **Employee data partial exemption**: Unique treatment of employee data83- **Transgender/nonbinary status**: Explicit sensitive data category84- **14-day cure period**: Shortest cure period among states8586### Montana (MTDPA) — Unique Requirements87- **50,000 consumer threshold**: Lowest consumer count threshold88- **15-day extension only**: Shorter extension than most states' 45 days89- **Air carrier exemption**: Unique industry exemption9091### Kentucky (KPPA) — Unique Requirements92- **January 2026 effective date**: Most recently effective among this group93- **50% revenue threshold**: Matches Virginia9495## Unified Privacy Program Architecture9697### Tier 1: Common Baseline (Apply Everywhere)9899These requirements are common across all states and form the foundation:1001011. **Privacy notice** with categories of PI, purposes, rights, third parties, contact info1022. **Consumer rights portal** supporting access, correct, delete, portability, opt-out1033. **45-day response SLA** with tracking and metrics1044. **Data minimization** and purpose limitation controls1055. **Reasonable data security** measures1066. **Non-discrimination** protections107108### Tier 2: High-Water Mark (Apply to Satisfy Strictest Requirement)109110Where state requirements differ, apply the strictest standard universally:111112| Area | Strictest Standard | Source State |113|------|--------------------|-------------|114| Sensitive data consent | Opt-in consent before collection | VA, CO, CT, TX, OR, MT, KY |115| Dark pattern prohibition | Consent via dark patterns invalid | CT (explicit), all (implicit) |116| Response extension | 15-day extension only | MT (strictest) or accept state-by-state |117| Universal opt-out | Honor GPC signals | CA, CO, CT, MT |118| Profiling opt-out | Include 7+ decision categories | CO (broadest scope) |119| De-identified data | Full compliance program | OR (most detailed) |120| Privacy notice retention periods | Include per-category retention | CA (CPRA requirement) |121122### Tier 3: State-Specific (Apply Only Where Required)123124| Requirement | State(s) | Implementation |125|-------------|----------|---------------|126| "Do Not Sell or Share" link | CA | Homepage footer |127| "Limit Sensitive PI" link | CA | Adjacent to opt-out link |128| Specific third-party list | OR | Additional disclosure in Oregon responses |129| Data broker registration | TX | Secretary of State registration (if applicable) |130| Annual metrics disclosure | CA (10M+) | Privacy notice metrics section |131| Loyalty program exemption | CT | Program-specific terms |132| Nonprofit compliance | OR | Full program for Oregon nonprofit operations |133134### Implementation Strategy for Liberty Commerce Inc.135136**Approach: High-Water Mark with State-Specific Overlays**137138Liberty Commerce Inc. implements a unified privacy program at the highest common standard, with state-specific modules activated based on the consumer's state of residence.139140```141Consumer Request Received142 │143 ├─► Determine Consumer's State144 │145 ├─► Apply Tier 1 Common Baseline146 │ (Same for all states)147 │148 ├─► Apply Tier 2 High-Water Mark149 │ (Strictest standard, applied universally)150 │151 └─► Apply Tier 3 State-Specific Module152 ├─ California module: CPRA-specific disclosures, sensitive PI limit153 ├─ Oregon module: Third-party specific list154 ├─ Texas module: Data broker check155 └─ Connecticut module: Loyalty program exemption assessment156```157158## Harmonized Privacy Notice Template159160A multi-state privacy notice should include these sections to satisfy all eight laws:1611621. **Categories of PI/personal data collected** (all states)1632. **Categories of sensitive PI/sensitive data collected** (all states)1643. **Purposes for each category** (all states)1654. **Retention period or criteria per category** (CA required; best practice all)1665. **Sources of PI** (CA required; best practice all)1676. **Categories of third parties receiving PI** (all states)1687. **Whether PI is sold or shared** (all states)1698. **Whether targeted advertising is conducted** (all non-CA states)1709. **Whether profiling is conducted** (all non-CA states)17110. **Consumer rights and how to exercise** (all states)17211. **Appeal process** (VA, CO, CT, TX, OR, MT, KY)17312. **Contact information** (all states)17413. **"Do Not Sell or Share" link** (CA)17514. **"Limit Sensitive PI" link** (CA)17615. **Universal opt-out disclosure** (CA, CO, CT, MT)17716. **Last updated date** (CA required; best practice all)17817. **Annual metrics** (CA, if 10M+ consumers)179180## Key Regulatory References181182- IAPP US State Comprehensive Privacy Law Comparison Chart (updated quarterly)183- CPPA Regulations 11 CCR §7001-7102184- Colorado AG Regulations 4 CCR 904-3185- Global Privacy Control Specification v1.0