Your 6-Step Checklist for US Privacy Compliance

Resource CDPA CPRA Privacy Management Privacy Rights

The US has four comprehensive state privacy laws set to enter into effect in 2023. California, Virginia, Colorado, and Utah have all passed new state privacy bills over the past 18 months, and while there are some similarities to be found in the requirements of all four, there are also several key differences that organizations should be paying attention to.


Organizations that have already built compliant privacy programs for the California Consumer Privacy Act (CCPA) will be one step ahead when the provisions of the California Privacy Rights Act (CPRA) enter into effect on January 1, 2023. However, the Virginia Consumer Data Protection Act (CDPA), the Colorado Privacy Act (CPA), and the Utah Consumer Privacy Act (UCPA) all have their own varying requirements for covered businesses (the definition of which is also different across all four state laws) to meet. As a result, organizations should be looking to develop a benchmark for cross-state compliance by finding common ground while accounting for the nuances of each law.


A Checklist for Compliance with US Privacy Laws

This six-step checklist provides you with foundational processes that organizations should take into account when working towards compliance with the CPRA, CDPA, CPA, and UCPA, from the initial discovery of personal data to developing and enforcing robust data policies such as retention, minimization, and access.


By following the steps outlined in this checklist, organizations will be able to understand what personal data they have, where that data lives, and what privacy laws apply. Organizations will also understand the steps necessary to attribute consent preferences to personal information and ensure these are communicated with third parties to avoid unauthorized disclosure. This US privacy law compliance checklist also highlights the processes that organizations should be developing for handling privacy rights requests (DSARs) and performing privacy impact assessments (PIAs), where applicable.


Download the checklist and start taking the six steps towards US privacy compliance now, or follow OneTrust on LinkedInTwitter, or YouTube for the latest updates on US privacy.

Get Resource

Note: All fields marked with * are required

I’d like email updates on local events, news, resources and products to stay connected with the OneTrust community. Unsubscribe at any time.

I’d like a solution expert to provide product information or show me a custom demo of the OneTrust platform

How would you like us to contact you?

Privacy Notice

You can learn more about how we handle your personal data and your rights by reviewing our privacy notice.

Onetrust All Rights Reserved