Skip to main content
Should You Build Compliance Around This State Bill?Privacy Regulations
5 min readFor Data Governance Teams

Should You Build Compliance Around This State Bill?

The Washington Privacy Act returned for a public hearing on January 15, 2020, with bipartisan support and endorsements from several privacy advocates. However, experts Jevan Hutson and Jennifer Lee testified that the bill contains gaps that undermine its consumer protection goals.

This puts you in a familiar position: A state privacy bill is moving forward with political momentum, but the technical details suggest it won't deliver the protection its sponsors promise. Do you allocate resources to build compliance infrastructure now, or wait to see if amendments address the substantive gaps?

Here's how to decide.

The Decision You're Facing

You need to determine whether to begin implementation work on a state privacy bill that has legislative support but faces technical criticism from subject matter experts. This decision affects your team's roadmap, technology investments, and ability to deliver meaningful data protection.

Choosing wrong means either scrambling to retrofit systems when the bill passes with unexpected requirements or investing months of engineering time on a framework that gets amended or fails entirely.

Key Factors That Affect Your Choice

Legislative trajectory matters more than hearing testimony. A bill with bipartisan support in committee has cleared a significant hurdle. The Washington Privacy Act's reintroduction after a previous failure signals that sponsors have addressed at least some objections. Track whether amendments are being proposed in response to expert testimony, not just whether criticism exists.

Gap severity determines risk exposure. Not all legislative shortcomings create equal compliance risk. If experts identify missing enforcement mechanisms, that's a political problem but not necessarily your operational problem. If they identify ambiguous definitions of personal data or unclear processor obligations, that directly affects your system design.

Your existing controls provide a baseline. If you've already implemented GDPR or CCPA compliance, evaluate whether the criticized bill requires net-new capabilities or just configuration changes. A bill with gaps might still raise your baseline if you're currently operating without comprehensive privacy controls.

Regulatory interpretation will fill some gaps. State attorneys general and newly created privacy authorities will issue guidance after passage. If the bill establishes a supervisory authority with rulemaking power, some technical ambiguities will resolve through administrative process. If it relies solely on private right of action, you're working without that safety net.

Path A: Begin Implementation Now

Choose this path when:

The bill addresses your current gap areas. If you operate without comprehensive consent management, data subject rights fulfillment, or processing records, even an imperfect bill raises your protection baseline. The Washington Privacy Act's reintroduction suggests it includes core requirements around access, deletion, and opt-out rights. If you lack these capabilities today, build them regardless of whether this specific bill passes.

You can modularize the work. Design your implementation so that components remain useful even if the bill changes. A consent preference center serves GDPR, CCPA, and most proposed state bills. A data mapping tool supports any disclosure or assessment requirement. An automated DSAR workflow adapts to different response timelines. If your architecture remains framework-agnostic, early investment isn't wasted.

You have multi-state exposure. If you're already tracking Virginia, Colorado, and other state bills, the incremental cost of preparing for Washington is lower. You're building a compliance engine that handles variation, not a point solution for one jurisdiction.

Your development cycle is long. If implementing consent management or subject rights automation takes your team nine months, you can't wait for legislative certainty. Start with the requirements that appear in every bill (transparency, access, deletion) and defer the contested provisions until the bill language stabilizes.

Path B: Monitor and Prepare, Don't Build

Choose this path when:

Expert criticism targets core definitions. If testimony identifies ambiguity in what constitutes personal data, sensitive data, or sale, you can't design technical controls until those terms stabilize. Hutson and Lee's concerns about comprehensive protection suggest definitional or scope issues. Wait for amendments before committing to a data classification scheme.

The bill lacks enforcement clarity. Without knowing whether enforcement comes through a supervisory authority, attorney general action, or private litigation, you can't assess your true compliance risk. A bill with weak enforcement might warrant minimal investment even if it passes.

You're already compliant with a stricter framework. If you've implemented GDPR across your organization, a state bill with gaps might not require additional work. Evaluate whether the bill's requirements are a subset of your existing controls. If so, your preparation work is documentation and legal review, not engineering.

The bill is still in early committee. The Washington Privacy Act's hearing was its first public appearance after reintroduction. Bills change substantially between committee and floor votes. If you're monitoring five state bills and three are in early committee stage, you can't resource all of them speculatively.

Path C: Implement the Uncontroversial Subset

Choose this path when:

You can separate consensus requirements from contested provisions. Most state privacy bills include common elements: transparency obligations, access rights, deletion rights, and opt-out mechanisms for certain processing. Even bills that face criticism for gaps typically include these baseline requirements. Build those capabilities first.

You need to demonstrate progress to leadership. If your executive team is asking about state privacy compliance, delivering a working DSAR portal or updated privacy notice shows tangible progress while you wait for legislative clarity on contested provisions.

You want to test your implementation approach. Use the uncontroversial requirements as a pilot. If you're evaluating consent management platforms or data mapping tools, implement them against the stable requirements in the bill. You'll learn whether your chosen vendors and architecture work before the full requirement set is final.

Summary Matrix

Factor Implement Now Monitor Only Partial Implementation
Bill status Committee passage, bipartisan support Early committee, significant amendments expected First hearing, core provisions stable
Your current state No comprehensive privacy program Already GDPR or CCPA compliant Some controls, significant gaps
Expert criticism Focuses on enforcement or scope Identifies ambiguous core definitions Targets specific provisions, not foundations
Development timeline 6+ months for core capabilities Can implement in 8-12 weeks Modular approach possible
Multi-state exposure Operating in 10+ states Single-state or regional operation 3-5 state exposure
Risk tolerance Low; need to lead compliance High; can retrofit quickly Moderate; want optionality

The Washington Privacy Act's trajectory illustrates a broader pattern: State privacy bills gain momentum through political compromise, not technical perfection. Your job isn't to wait for the perfect bill. It's to build controls that protect data regardless of whether the legislation that prompted them survives intact.

You Might Also Like