United States · State consumer privacy laws

One configuration for the states that all copied the same template

Virginia, Colorado, Connecticut, Texas, Oregon and the rest of the state consumer privacy wave share a common shape — the same rights, the same 45+45-day clock, and a consumer appeal step California does not have. AccessPoint ships that shape as one pack.

United States — State Consumer Privacy at a glance

Rights deadline
45 days, extendable once by a further 45 days on notice
Appeal
An internal appeal of a refusal, answered within the statutory window
Rights covered
Access, deletion, correction, portability, and opt-out of targeted advertising, sale, and profiling
Assessments
Data protection assessments for higher-risk processing
Enforcement
State Attorneys General, most with a cure period
Languages
English

Built for United States — State Consumer Privacy

One platform for the whole access-and-privacy mandate, pre-configured for this regime and running in your own Microsoft 365 tenant.

One shape, many states

The state acts differ in their thresholds and their details, but they share a structure. One configuration runs them, with the applicable state recorded on each request rather than a separate system per jurisdiction.

The appeal step, built in

The feature that most distinguishes these acts from California's: a consumer may appeal a refusal, and the controller must respond within the statutory window. AccessPoint tracks the appeal as its own stage with its own clock and outcome.

Every right on the 45-day clock

Access, deletion, correction, and portability run on the common 45-day clock with the single 45-day extension, with the state that governs each request recorded.

Data protection assessments

Run the assessments these acts require for higher-risk processing — targeted advertising, sale, sensitive data, and profiling — as full cases with risks, mitigations, and sign-off.

Reporting across states

See volumes, timeliness, refusals, and appeals across every state you operate in at once, instead of assembling a picture from separate trackers.

In your own tenant

Consumer personal information stays inside your own Microsoft 365 and Azure tenant — no third-party privacy cloud holding the very data the requests are about.

The appeal nobody plans for

The state acts gave consumers a second bite. Most programs are built as though they didn't.

Virginia's act set the template and roughly twenty states have followed it, and one feature runs through nearly all of them: if a controller declines a request, the consumer may appeal, and the controller must respond within a defined window — and, if the appeal is denied, must tell the consumer how to complain to the Attorney General. That last step is why appeals matter out of proportion to their volume. They are the documented moment a refusal was tested internally, and they are the handoff point to a regulator. Programs that treat a refusal as the end of the matter discover the appeal window has run while the email sat unread. AccessPoint models the appeal as a real stage with its own clock, its own reviewer, and its own recorded outcome.

Two clocks The request window and the appeal window, both tracked.
Refusals tested An appeal reviewed by someone, with the outcome recorded.
State-aware The governing state recorded on every request.

Configured out of the box

Installing the us-state-privacy jurisdiction pack seeds your tenant with everything this regime needs — a starting point you can adjust, not a lock-in.

Related guide: FOI Workflow Quick Check
  • A rebindable state consumer privacy authority, set to the states you operate in
  • The 45-day rights clock with its single 45-day extension
  • Request types for access, deletion, correction, portability, and the opt-out rights
  • The consumer appeal stage with its own statutory window and recorded outcome
  • Attorney General complaint information where an appeal is denied
  • Data protection assessments for targeted advertising, sale, sensitive data, and profiling
  • Refusal grounds and exceptions, cited on the response
  • Cross-state reporting on volumes, timeliness, refusals, and appeals

United States — State Consumer Privacy Questions

Which states does this pack cover?

The comprehensive state consumer privacy acts that share the Virginia-derived structure — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Hampshire, New Jersey, Nebraska, Tennessee, Minnesota, Florida, Indiana, Kentucky and Rhode Island. It is one configuration of the common shape, with the governing state recorded per request; California is a separate pack because its regime genuinely differs.

Why is California separate?

Because California is the outlier rather than the template. It has a dedicated regulator in the CPPA, a different rights vocabulary, and no consumer appeal step. Folding it into a generic multi-state configuration would mean approximating both, so AccessPoint ships a California pack and a multi-state pack and lets an organization install either or both.

How are the differences between states handled?

The pack ships the common structure, and the governing state is recorded on each request so responses, exceptions, and reporting reflect it. Where a state's threshold, cure period, or assessment trigger differs, that is a configuration matter within the pack rather than a separate deployment.

Where does consumer personal information reside?

Entirely within your own Microsoft 365 and Azure tenant. Requests, the personal information gathered to answer them, and the audit history never leave your control — no third-party cloud and no vendor access.

Run Multi-State Consumer Privacy in Your Own Tenant

Try AccessPoint free for 30 days, configured for the states you operate in. No credit card required.

Start Free Trial