Skip to main content
State Privacy Laws Collide: What the 2021 Legislative Wave Revealed About U.S. Compliance StrategyPrivacy Regulations
3 min readFor Privacy Officers

State Privacy Laws Collide: What the 2021 Legislative Wave Revealed About U.S. Compliance Strategy

The Legislative Wave

In early 2021, six U.S. states, Washington, Connecticut, Minnesota, New York, Oklahoma, and Virginia, introduced comprehensive privacy legislation almost simultaneously. Each state developed its own requirements, timelines, and enforcement mechanisms while Congress remained gridlocked on federal legislation. This left privacy teams at multi-state organizations scrambling to build multiple compliance programs at once, with no clear indication of which bills would pass or when federal preemption might occur.

This situation wasn't a traditional incident. There was no breach or regulatory fine. However, the strategic oversight was significant. Many organizations had treated state privacy laws as a California-specific issue, assuming federal legislation would arrive before other states acted. This assumption proved costly.

Key Events in 2021

January 2021: Washington reintroduced the Washington Privacy Act after previous failures. Connecticut, Minnesota, New York, Oklahoma, and Virginia also filed bills.

January 20, 2021: A new presidential administration took office with a Democrat-controlled Congress, raising hopes for federal action.

Q1 2021: Privacy teams rushed to map requirements across six proposed state frameworks while monitoring federal developments.

Throughout 2021: A federal bill never materialized. States continued drafting, amending, and sometimes passing their own laws.

Where Compliance Efforts Fell Short

Legislative Monitoring: Many organizations focused on California but didn't systematically monitor all 50 states. When multiple states acted, privacy teams often learned about new bills from news articles instead of structured processes.

Scalable Compliance Systems: Teams built solutions for the CCPA but not modular systems for varying state requirements. When New York proposed different consent standards than Virginia, engineering teams faced complete rebuilds.

Regulatory Engagement: Few organizations participated in comment periods or industry coalition efforts during the drafting phase. By the time bills reached final votes, requirements were set.

Federal Contingency Planning: Many compliance roadmaps assumed "federal law will preempt state action." When Congress stalled, those plans became obsolete, with no backup for a patchwork regime.

What the Standards Require

While no single standard governs U.S. state privacy legislation, the GDPR and ISO/IEC 29134 provide applicable principles:

Risk-Based Planning: ISO/IEC 29134 requires assessing privacy risks before new processing begins. This includes regulatory risk, the chance that new laws will impose requirements you haven't prepared for. Waiting for legislative certainty before planning is risky.

Accountability Documentation: GDPR Article 5(2) requires controllers to demonstrate compliance. In a multi-jurisdiction environment, document which state laws apply to which processing activities, the legal bases you're using, and how your controls meet each requirement.

Lawful Basis Clarity: GDPR Article 6 requires a specific legal basis for each processing purpose. U.S. state laws vary, some require Consent consent, others allow opt-out. Your data inventory must map legal bases at the state level.

Technical and Organisational Measures: GDPR Article 32 requires security appropriate to the risk. Operating under multiple state regimes with different breach notification timelines means your incident response procedures must accommodate the shortest deadline.

Action Items for Your Team

Implement a 50-State Monitoring Process: Assign someone to track privacy bills in every state. Use a structured intake form with bill number, sponsor, key requirements, hearing dates, and passage likelihood. Review monthly.

Design for Modularity: Your consent management platform should support state-specific configurations. Your DSAR workflow should accommodate different response timelines. Your privacy notice should generate state-specific disclosures based on user location.

Map Data Flows to State Jurisdictions: Identify which processing activities involve residents of specific states. Use your Article 30 records of processing as a starting framework, then add a jurisdiction column.

Engage in Drafting Processes: Join industry association privacy working groups. Submit comments during legislative hearings. Meet with staffers. Influencing requirements during drafting is easier than adapting to finalized laws.

Drop the Federal Preemption Assumption: Plan as if the patchwork is permanent. If federal legislation arrives, you can scale back. If it doesn't, you're ready.

Test Your Scalability: When the next state files a bill, assess applicability, identify gaps, and draft an implementation plan quickly. Run a tabletop exercise using a hypothetical state law to test your response time.

The 2021 legislative wave didn't produce a breach but highlighted the need for proactive compliance strategies. The challenge is to learn from this and prepare for future waves.

You Might Also Like