Provides common requirements matrix, state-specific deltas, and unified architecture for US state privacy laws across CA, VA, CO, CT, TX, OR, MT, KY. Useful for multi-state compliance programs.
npx claudepluginhub mukul975/privacy-data-protection-skills --plugin us-state-privacy-skillsThis skill uses the workspace's default tool permissions.
As of 2026, over 20 US states have enacted comprehensive consumer privacy legislation. Organizations operating nationwide face a complex patchwork of requirements with significant overlap but important state-specific variations. A harmonized multi-state compliance program identifies the common baseline, maps state-specific deltas, and implements a unified privacy architecture that satisfies all...
Generates design tokens/docs from CSS/Tailwind/styled-components codebases, audits visual consistency across 10 dimensions, detects AI slop in UI.
Records polished WebM UI demo videos of web apps using Playwright with cursor overlay, natural pacing, and three-phase scripting. Activates for demo, walkthrough, screen recording, or tutorial requests.
Delivers idiomatic Kotlin patterns for null safety, immutability, sealed classes, coroutines, Flows, extensions, DSL builders, and Gradle DSL. Use when writing, reviewing, refactoring, or designing Kotlin code.
As of 2026, over 20 US states have enacted comprehensive consumer privacy legislation. Organizations operating nationwide face a complex patchwork of requirements with significant overlap but important state-specific variations. A harmonized multi-state compliance program identifies the common baseline, maps state-specific deltas, and implements a unified privacy architecture that satisfies all applicable laws.
This skill covers the eight major enacted and effective state privacy laws: CCPA/CPRA (California), VCDPA (Virginia), CPA (Colorado), CTDPA (Connecticut), TDPSA (Texas), OCPA (Oregon), MTDPA (Montana), and KPPA (Kentucky).
All eight laws provide these core rights:
| Right | CA | VA | CO | CT | TX | OR | MT | KY |
|---|---|---|---|---|---|---|---|---|
| Access/Know | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Correct | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Delete | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Portability | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Opt-out: targeted ads | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Opt-out: sale | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Opt-out: profiling | No* | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Limit sensitive PI | Yes | N/A | N/A | N/A | N/A | N/A | N/A | N/A |
| Third-party list | No | No | No | No | No | Yes | No | No |
| Appeal | No | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
*California provides opt-out of automated decision-making under pending CPPA regulations.
| Obligation | All States |
|---|---|
| Privacy notice/policy | Required |
| Data minimization | Required |
| Purpose limitation | Required |
| Data security | Required |
| Non-discrimination | Required |
| Response timeline | 45 days (all states) |
These requirements are common across all states and form the foundation:
Where state requirements differ, apply the strictest standard universally:
| Area | Strictest Standard | Source State |
|---|---|---|
| Sensitive data consent | Opt-in consent before collection | VA, CO, CT, TX, OR, MT, KY |
| Dark pattern prohibition | Consent via dark patterns invalid | CT (explicit), all (implicit) |
| Response extension | 15-day extension only | MT (strictest) or accept state-by-state |
| Universal opt-out | Honor GPC signals | CA, CO, CT, MT |
| Profiling opt-out | Include 7+ decision categories | CO (broadest scope) |
| De-identified data | Full compliance program | OR (most detailed) |
| Privacy notice retention periods | Include per-category retention | CA (CPRA requirement) |
| Requirement | State(s) | Implementation |
|---|---|---|
| "Do Not Sell or Share" link | CA | Homepage footer |
| "Limit Sensitive PI" link | CA | Adjacent to opt-out link |
| Specific third-party list | OR | Additional disclosure in Oregon responses |
| Data broker registration | TX | Secretary of State registration (if applicable) |
| Annual metrics disclosure | CA (10M+) | Privacy notice metrics section |
| Loyalty program exemption | CT | Program-specific terms |
| Nonprofit compliance | OR | Full program for Oregon nonprofit operations |
Approach: High-Water Mark with State-Specific Overlays
Liberty Commerce Inc. implements a unified privacy program at the highest common standard, with state-specific modules activated based on the consumer's state of residence.
Consumer Request Received
│
├─► Determine Consumer's State
│
├─► Apply Tier 1 Common Baseline
│ (Same for all states)
│
├─► Apply Tier 2 High-Water Mark
│ (Strictest standard, applied universally)
│
└─► Apply Tier 3 State-Specific Module
├─ California module: CPRA-specific disclosures, sensitive PI limit
├─ Oregon module: Third-party specific list
├─ Texas module: Data broker check
└─ Connecticut module: Loyalty program exemption assessment
A multi-state privacy notice should include these sections to satisfy all eight laws: