Help us improve
Share bugs, ideas, or general feedback.
Provides common requirements matrix, state-specific deltas, and unified architecture for US state privacy laws across CA, VA, CO, CT, TX, OR, MT, KY. Useful for multi-state compliance programs.
npx claudepluginhub mukul975/privacy-data-protection-skills --plugin privacy-skills-completeHow this skill is triggered — by the user, by Claude, or both
Slash command
/privacy-skills-complete:multi-state-complianceThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
As of 2026, over 20 US states have enacted comprehensive consumer privacy legislation. Organizations operating nationwide face a complex patchwork of requirements with significant overlap but important state-specific variations. A harmonized multi-state compliance program identifies the common baseline, maps state-specific deltas, and implements a unified privacy architecture that satisfies all...
Provides common requirements matrix, state-specific deltas, and unified architecture for US state privacy laws across CA, VA, CO, CT, TX, OR, MT, KY. Useful for multi-state compliance programs.
Tracks US state privacy laws across 50 states, DC, territories: enacted laws (CCPA/CPRA, VCDPA, CPA, etc.), pending bills, effective dates, enforcers, thresholds, rights differences. For multi-state compliance.
Explains U.S. state-by-state consumer data-privacy law (CCPA, CPRA, VCDPA, CPA, etc.) — applicability thresholds, consumer rights, enforcement, and privacy-policy requirements, using bundled source-cited snapshots.
Share bugs, ideas, or general feedback.
As of 2026, over 20 US states have enacted comprehensive consumer privacy legislation. Organizations operating nationwide face a complex patchwork of requirements with significant overlap but important state-specific variations. A harmonized multi-state compliance program identifies the common baseline, maps state-specific deltas, and implements a unified privacy architecture that satisfies all applicable laws.
This skill covers the eight major enacted and effective state privacy laws: CCPA/CPRA (California), VCDPA (Virginia), CPA (Colorado), CTDPA (Connecticut), TDPSA (Texas), OCPA (Oregon), MTDPA (Montana), and KPPA (Kentucky).
All eight laws provide these core rights:
| Right | CA | VA | CO | CT | TX | OR | MT | KY |
|---|---|---|---|---|---|---|---|---|
| Access/Know | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Correct | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Delete | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Portability | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Opt-out: targeted ads | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Opt-out: sale | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Opt-out: profiling | No* | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Limit sensitive PI | Yes | N/A | N/A | N/A | N/A | N/A | N/A | N/A |
| Third-party list | No | No | No | No | No | Yes | No | No |
| Appeal | No | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
*California provides opt-out of automated decision-making under pending CPPA regulations.
| Obligation | All States |
|---|---|
| Privacy notice/policy | Required |
| Data minimization | Required |
| Purpose limitation | Required |
| Data security | Required |
| Non-discrimination | Required |
| Response timeline | 45 days (all states) |
These requirements are common across all states and form the foundation:
Where state requirements differ, apply the strictest standard universally:
| Area | Strictest Standard | Source State |
|---|---|---|
| Sensitive data consent | Opt-in consent before collection | VA, CO, CT, TX, OR, MT, KY |
| Dark pattern prohibition | Consent via dark patterns invalid | CT (explicit), all (implicit) |
| Response extension | 15-day extension only | MT (strictest) or accept state-by-state |
| Universal opt-out | Honor GPC signals | CA, CO, CT, MT |
| Profiling opt-out | Include 7+ decision categories | CO (broadest scope) |
| De-identified data | Full compliance program | OR (most detailed) |
| Privacy notice retention periods | Include per-category retention | CA (CPRA requirement) |
| Requirement | State(s) | Implementation |
|---|---|---|
| "Do Not Sell or Share" link | CA | Homepage footer |
| "Limit Sensitive PI" link | CA | Adjacent to opt-out link |
| Specific third-party list | OR | Additional disclosure in Oregon responses |
| Data broker registration | TX | Secretary of State registration (if applicable) |
| Annual metrics disclosure | CA (10M+) | Privacy notice metrics section |
| Loyalty program exemption | CT | Program-specific terms |
| Nonprofit compliance | OR | Full program for Oregon nonprofit operations |
Approach: High-Water Mark with State-Specific Overlays
Liberty Commerce Inc. implements a unified privacy program at the highest common standard, with state-specific modules activated based on the consumer's state of residence.
Consumer Request Received
│
├─► Determine Consumer's State
│
├─► Apply Tier 1 Common Baseline
│ (Same for all states)
│
├─► Apply Tier 2 High-Water Mark
│ (Strictest standard, applied universally)
│
└─► Apply Tier 3 State-Specific Module
├─ California module: CPRA-specific disclosures, sensitive PI limit
├─ Oregon module: Third-party specific list
├─ Texas module: Data broker check
└─ Connecticut module: Loyalty program exemption assessment
A multi-state privacy notice should include these sections to satisfy all eight laws: