Privacy Range | Privacy Readiness
Know what you collect. Know where it goes.
Privacy laws may begin with an acronym, but privacy readiness begins inside the operation.
A growing business should be able to explain what personal information it collects, why it is needed, which systems receive it, who can access it, how long it is retained, and what happens when someone asks to access, correct, or delete it.
GDPR, CCPA, CPRA, TDPSA, COPPA, and the growing number of state privacy laws all approach the issue differently. The operational foundation is the same: understand the data trail before the business grows beyond it.
01 | The shift
Data privacy is no longer a footer issue.
A modern website is no longer just a brochure.
It may collect names, email addresses, telephone numbers, payment information, appointment details, form responses, device information, location information, analytics activity, advertising behavior, CRM history, consent records, and information created through AI or automated workflows.
If a business uses forms, email marketing, CRM software, cookies, pixels, analytics, online scheduling, payment systems, chat tools, or automation platforms, personal data is moving through the business, even when no one has formally mapped it.
Privacy readiness is not about fear. It is about stewardship.
A privacy policy is the sign on the gate. Privacy practice is everything happening across the property behind it.
02 | The data trail
Before choosing a policy, map the operation.
-
01
Collection
Website forms, calls, email, booking, checkout, events, applications, and direct messages.
-
02
Movement
Integrations, automations, APIs, email forwarding, imports, and synchronization.
-
03
Storage
CRM, inboxes, cloud drives, spreadsheets, payment tools, scheduling systems, and backups.
-
04
Use
Customer service, fulfillment, analytics, advertising, profiling, AI, and reporting.
-
05
Access
Employees, contractors, vendors, service providers, processors, and third parties.
-
06
Retention or deletion
How long information remains, why it remains, and how it is securely removed.
A business cannot accurately explain, protect, retain, or delete information it has never located.
Privacy readiness starts with a practical inventory of the tools already in use and the information flowing through them.
03 | Privacy frameworks
The names businesses hear most, in plain English.
Privacy laws are not interchangeable. Some apply because of where a person lives. Some depend on the size or data activity of the business. Others apply because a company collects information from children, processes health data, handles sensitive information, or transfers data internationally.
A business may be subject to several requirements at the same time. It may also fall outside a law’s formal threshold today and move closer as its audience, revenue, advertising activity, technology, or data volume grows.
Filter by category
European Union General Data Protection Regulation (GDPR)
The GDPR is the European Union’s primary data-protection law. It governs how covered organizations collect, use, store, organize, disclose, transfer, secure, and delete personal data.
GDPR can reach organizations outside Europe when the circumstances bring their activities within the regulation, including certain offers of goods or services to people in the EU, or monitoring of their behavior there. Being based in Texas does not by itself place a business outside its reach, and it does not by itself place a business inside it either.
What covered organizations should generally be able to demonstrate
- A lawful reason for processing personal data (consent is one of several lawful bases, not the only one)
- Clear and accurate transparency
- Data minimization
- Purpose limitation
- Accuracy
- Appropriate retention
- Security
- Procedures for applicable individual rights
- Documentation and accountability
- Appropriate international-transfer safeguards
Plain-English takeawayYou should be able to explain what personal data you collect, why you are permitted to use it, where it goes, who can access it, how long it remains, how it is protected, and how an individual can exercise applicable rights.
Official resources
- Regulation (EU) 2016/679, full text (EUR-Lex) (opens in a new tab)
- European Commission: data protection guidance for business and organisations (opens in a new tab)
General educational information, not legal advice. Applicability depends on the organization, jurisdiction, audience, industry, revenue, data volume, technology, contracts, and specific processing activities.
California California Consumer Privacy Act (CCPA), as amended by the CPRA
CCPA
The California Consumer Privacy Act gives qualifying California consumers rights involving personal information collected by covered businesses. Depending on the circumstances, those rights may include:
- Knowing what information is collected and how it is used or shared
- Access
- Deletion, subject to exceptions
- Correction
- Opting out of qualifying sales or sharing
- Limiting certain uses or disclosures of sensitive personal information
- Non-discrimination
- Use of opt-out preference signals
Not every business serving a California resident is automatically covered. A business may fall within scope where it meets one of several applicability concepts, including:
- Annual gross revenue above the current adjusted threshold of $26.625 million
- Processing the personal information of at least 100,000 consumers or households
- Receiving at least half of annual revenue from selling or sharing consumers’ personal information
These thresholds are a starting point for a conversation, not legal advice, and they are not the only applicability considerations.
CPRA
CPRA did not replace the CCPA. It amended and expanded it.
- Added and strengthened consumer rights
- Added sensitive-personal-information protections
- Expanded qualifying “sharing” concepts
- Strengthened data-minimization and purpose-limitation expectations
- Strengthened vendor and contractor responsibilities
- Created the California Privacy Protection Agency
- Made privacy more connected to operational systems and technology
California’s updated CCPA regulations became effective January 1, 2026 and include requirements involving risk assessments, cybersecurity audits, and automated decision-making technology, with some deadlines phased in. Which of those requirements reaches a particular business depends on its size and processing activity.
Plain-English takeawayA Texas business can move closer to California applicability as its revenue, California audience, advertising activity, or data volume grows. The privacy policy, cookie controls, website, CRM, analytics, advertising pixels, and vendor agreements should tell the same story.
Official resources
- California Attorney General: CCPA (opens in a new tab)
- California Privacy Protection Agency: regulations (opens in a new tab)
- California Privacy Protection Agency: FAQ (opens in a new tab)
General educational information, not legal advice. Applicability depends on the organization, jurisdiction, audience, industry, revenue, data volume, technology, contracts, and specific processing activities.
Texas Texas Data Privacy and Security Act (TDPSA)
The TDPSA creates privacy rights for Texas residents and obligations for qualifying businesses that conduct business in Texas or provide products or services consumed by Texas residents, and that process or sell personal data.
Consumer rights may include
- Confirmation and access
- Correction
- Deletion
- Portability
- Opting out of targeted advertising
- Opting out of sales
- Opting out of certain profiling
- Appeals
Covered controllers may need
- A clear privacy notice
- Data minimization
- Reasonable administrative, technical, and physical security
- Consent before processing sensitive data
- Consumer-request methods
- Processor contracts
- Data-protection assessments for designated high-risk processing
- Opt-out disclosures
Small businesses are generally exempt from most of the TDPSA. The law still restricts a small business from selling sensitive personal data without prior consumer consent.
The Texas Attorney General has exclusive enforcement authority. There is a 30-day notice-and-cure process, and civil penalties may reach up to $7,500 per violation when an identified violation is not properly cured. The TDPSA does not create a private right of action.
Plain-English takeawayA small-business exemption is not permission to ignore data privacy. Texas businesses may still encounter separate requirements involving breaches, biometrics, data brokers, children, artificial intelligence, advertising, and sensitive information.
Official resources
- Texas Attorney General: Texas Data Privacy and Security Act (opens in a new tab)
- Texas Business and Commerce Code, Chapter 541 (opens in a new tab)
General educational information, not legal advice. Applicability depends on the organization, jurisdiction, audience, industry, revenue, data volume, technology, contracts, and specific processing activities.
United States | Children Children’s Online Privacy Protection Act (COPPA)
COPPA protects personal information collected online from children under 13. Depending on the circumstances it may apply to:
- Commercial websites or online services directed to children
- General-audience services with actual knowledge they collect personal information from a child under 13
- Operators benefiting from another party collecting children’s information on their behalf
Personal information can include
- Names
- Addresses
- Email addresses
- Telephone numbers
- Persistent identifiers
- IP addresses
- Device identifiers
- Photographs
- Audio containing a child’s voice
- Geolocation
- Biometric identifiers
- Other linked information
Covered operators generally must
- Provide clear notices
- Obtain verifiable parental consent
- Give parents review and deletion rights
- Avoid collecting more than reasonably necessary
- Protect confidentiality, security, and integrity
- Maintain a written information-security program
- Review vendors
- Maintain a written retention policy
- Delete data when it is no longer reasonably necessary
The current COPPA Rule includes amendments made in 2025.
Plain-English takeawayYouth programs, camps, lessons, livestock organizations, sports programs, scholarship services, educational platforms, contests, and family-oriented websites should evaluate whether they knowingly collect information from children under 13.
Official resources
- FTC: Children’s Online Privacy Protection Rule (opens in a new tab)
- eCFR: 16 CFR Part 312 (opens in a new tab)
General educational information, not legal advice. Applicability depends on the organization, jurisdiction, audience, industry, revenue, data volume, technology, contracts, and specific processing activities.
Connecticut Connecticut Data Privacy Act (CTDPA)
Under current Connecticut Attorney General guidance, the CTDPA applies to qualifying businesses that conduct business in Connecticut or target products or services to Connecticut residents and that:
- Process the personal data of at least 35,000 consumers, excluding data processed solely for payment transactions
- Process consumers’ sensitive data, outside the payment exclusion
- Offer consumers’ personal data for sale in trade or commerce
Connecticut consumer-health-data controllers may be covered regardless of size.
Consumer rights may include
- Access
- Inferences
- Profiling disclosures
- Correction
- Deletion, including qualifying third-party data
- Portability
- Information about parties receiving sold data
- Opt-outs
- Appeals
Covered controllers must honor qualifying universal opt-out signals.
Business responsibilities may include
- Sensitive-data consent
- Data minimization
- Security
- Data-protection and impact assessments
- Profiling requirements
- Children’s and teenagers’ protections
- Consumer-health-data obligations
- AI and large-language-model disclosures where applicable
The Connecticut Attorney General has exclusive enforcement authority. The CTDPA does not create a private cause of action.
Plain-English takeawayConnecticut now reaches some businesses because of the type of information processed, not only the total volume.
Official resources
General educational information, not legal advice. Applicability depends on the organization, jurisdiction, audience, industry, revenue, data volume, technology, contracts, and specific processing activities.
New York New York privacy landscape
New York Privacy Act
The New York Privacy Act remains proposed legislation. It is not enacted law. The current 2025 to 2026 proposals are Senate Bill S3044 and Assembly Bill A4947.
If enacted in some form, the proposals would seek rights and obligations involving access, correction, deletion, portability, transparency, data sharing, and related safeguards. Until then, they would not create obligations for a business.
Requirements that already apply in New York
The absence of an enacted comprehensive privacy act does not mean New York has no privacy requirements.
- The SHIELD Act
- Reasonable administrative, technical, and physical safeguards
- Breach-notification responsibilities
- Consumer-protection rules addressing misleading privacy claims
- The need for cookie banners and opt-out controls to function as represented
Plain-English takeawayA proposed law can signal where regulation may be heading, but existing security and consumer-protection laws already matter.
Official resources
- New York Senate Bill S3044 (2025) (opens in a new tab)
- New York Assembly Bill A4947 (2025) (opens in a new tab)
- New York Attorney General: SHIELD Act (opens in a new tab)
- New York Attorney General: website privacy controls (opens in a new tab)
General educational information, not legal advice. Applicability depends on the organization, jurisdiction, audience, industry, revenue, data volume, technology, contracts, and specific processing activities.
Utah Utah Consumer Privacy Act (UCPA)
The UCPA generally applies to qualifying controllers or processors that conduct business in Utah or target Utah residents, have at least $25 million in annual revenue, and meet one of these conditions:
- Process at least 100,000 consumers’ personal data during a calendar year; or
- Receive more than 50% of gross revenue from selling personal data and process at least 25,000 consumers’ data
Consumer rights may include
- Confirmation and access
- Deletion of information the consumer provided
- Portability
- Correction
- Opting out of sales
- Opting out of targeted advertising
Business responsibilities may include
- Clear privacy notice
- Reasonable security
- Processor contracts
- Targeted-advertising and sale disclosures
- Sensitive-data notice and opt-out
- COPPA handling for known children
Plain-English takeawayUtah’s law focuses primarily on larger operations, but its thresholds and rights should not be copied into a national privacy process without accounting for state differences.
Official resources
- Utah Code Title 13, Chapter 61 (opens in a new tab)
- Utah Division of Consumer Protection: UCPA (opens in a new tab)
General educational information, not legal advice. Applicability depends on the organization, jurisdiction, audience, industry, revenue, data volume, technology, contracts, and specific processing activities.
United States + European Union EU-U.S. Data Privacy Framework
The EU-U.S. Data Privacy Framework is not a general consumer privacy law. It is a mechanism supporting certain transfers of personal data from the European Union to participating U.S. organizations.
- The European Commission adopted its adequacy decision on July 10, 2023
- A U.S. business is not covered merely because it is located in the United States
- The receiving organization must participate and remain active on the official Data Privacy Framework List
- Participation involves public commitments, annual recertification, appropriate notice, choice, security, access, recourse, accountability, and onward-transfer requirements
- Other transfer mechanisms, such as Standard Contractual Clauses, may be needed when the recipient is not an active participant
- The framework does not replace GDPR compliance
Redress operates on two levels: the Civil Liberties Protection Officer within the Office of the Director of National Intelligence, and the Data Protection Review Court.
Plain-English takeawayA transfer mechanism may open the gate, but it does not manage the entire data operation.
Official resources
- European Commission: EU-US data transfers (opens in a new tab)
- Data Privacy Framework program (opens in a new tab)
- Data Privacy Framework List (opens in a new tab)
- U.S. Department of Justice: Data Protection Review Court (opens in a new tab)
General educational information, not legal advice. Applicability depends on the organization, jurisdiction, audience, industry, revenue, data volume, technology, contracts, and specific processing activities.
Virginia Virginia Consumer Data Protection Act (VCDPA)
The VCDPA generally applies to qualifying organizations conducting business in Virginia or targeting Virginia residents that:
- Process at least 100,000 consumers’ personal data during a calendar year; or
- Process at least 25,000 consumers’ personal data and receive more than 50% of gross revenue from selling personal data
Virginia does not use Utah’s separate $25 million revenue threshold.
Consumer rights may include
- Confirmation
- Access
- Correction
- Deletion
- Portability
- Opting out of sales
- Opting out of targeted advertising
- Opting out of qualifying profiling
- Appeals
Business responsibilities may include
- Data minimization
- Purpose limitation
- Reasonable security
- Sensitive-data consent
- Clear privacy notices
- Secure consumer-request methods
- Processor contracts
- Data-protection assessments
- Children’s-data assessments where applicable
The Virginia Attorney General has exclusive enforcement authority. The law generally provides a 30-day cure process, and civil penalties may reach $7,500 per violation. The VCDPA does not create a private right of action.
Plain-English takeawayA business can become covered because of its data volume even without meeting a separate large-revenue threshold.
Official resources
- Virginia Code Title 59.1, Chapter 53 (opens in a new tab)
- Virginia Attorney General: laws and cases (opens in a new tab)
General educational information, not legal advice. Applicability depends on the organization, jurisdiction, audience, industry, revenue, data volume, technology, contracts, and specific processing activities.
Washington Washington privacy landscape
Washington Privacy Act
The proposed Washington Privacy Act did not become an enacted comprehensive privacy law. SB 5062 from the 2021 to 2022 biennium is a historical proposal. Its applicability thresholds should not be treated as current Washington law.
My Health My Data Act
Washington enacted the My Health My Data Act to protect consumer health data outside traditional HIPAA settings. It can reach businesses of many sizes and covers broadly defined consumer health data, including certain inferred information.
- A separate consumer-health-data privacy policy
- Consent for collection
- Separate consent for sharing
- Written authorization for sales
- Access
- Withdrawal
- Deletion
- Processor and downstream deletion obligations
- Security
- Access controls
- Geofencing restrictions around health-care locations
- Enforcement under the Washington Consumer Protection Act, including the potential availability of private claims under that existing enforcement structure
Plain-English takeawayA company does not need to be a hospital or clinic to collect health-related information. A form, search feature, wellness platform, location tool, chatbot, or algorithm may collect or infer health data.
Official resources
- RCW 19.373: My Health My Data Act (opens in a new tab)
- Washington Attorney General: data privacy (opens in a new tab)
- Washington Attorney General: personal health data and privacy (opens in a new tab)
- Washington SB 5062 (2021), historical proposal (opens in a new tab)
General educational information, not legal advice. Applicability depends on the organization, jurisdiction, audience, industry, revenue, data volume, technology, contracts, and specific processing activities.
United States | Federal ADPPA and COPRA
American Data Privacy and Protection Act (ADPPA)
Introduced as H.R. 8152 during the 117th Congress. It proposed a national framework involving data minimization, consumer rights, privacy by design, service-provider responsibilities, security, algorithmic accountability, and enforcement. It did not become law.
Consumer Online Privacy Rights Act (COPRA)
Introduced as S. 2968 during the 116th Congress. It proposed rights involving access, correction, deletion, portability, consent, data minimization, security, algorithmic decision-making, civil rights, and enforcement. It did not become law.
Plain-English takeawayBills may influence later laws and industry practices, but a proposed bill should never be presented as an active compliance statute.
Official resources
- Congress.gov: H.R. 8152 (117th Congress) (opens in a new tab)
- Congress.gov: S. 2968 (116th Congress) (opens in a new tab)
General educational information, not legal advice. Applicability depends on the organization, jurisdiction, audience, industry, revenue, data volume, technology, contracts, and specific processing activities.
04 | The common ground
The statutes differ. The operational questions repeat.
- Know what personal information you collect
- Collect only what is reasonably needed
- Explain the purpose in understandable language
- Use information consistently with the stated purpose
- Identify sensitive and children’s data
- Protect information with reasonable safeguards
- Govern vendors and service providers
- Give consumers meaningful choices where required
- Prepare for access, correction, portability, and deletion requests
- Establish retention and disposal practices
- Assess high-risk processing
- Keep policies aligned with actual technology
- Document decisions and responsibilities
That is why privacy cannot be handled as a footer-only project.
A policy describes the fence line. Operations determine whether the fence is standing.
05 | Policy vs. reality
A privacy policy is not the same as a privacy practice.
A policy may say one thing while the website, forms, cookies, CRM, email platform, analytics, advertising pixels, payment processor, scheduling tools, AI systems, and automations do something else.
That disconnect is where risk, confusion, and broken trust quietly grow.
Privacy readiness closes the gap between what the business says and what its systems actually do.
Questions the business should be able to answer
- What personal information are we collecting?
- Why do we need each category?
- Where does it go after a form is submitted?
- Does it enter a CRM, inbox, spreadsheet, or cloud drive?
- Is it shared with analytics, advertising, payment, scheduling, or AI platforms?
- Which employees and contractors can access it?
- Which vendors and subprocessors receive it?
- How long is it kept?
- What happens when someone withdraws consent?
- What happens when someone asks for access, correction, portability, or deletion?
- Can the request be completed across backups and integrations?
- What changes when a new campaign, form, funnel, or automation is added?
06 | Blind spots
Where privacy quietly drifts as a business grows.
- Contact forms sending information to multiple inboxes
- Newsletter forms without clear consent language
- Analytics activating before a visitor’s choice is applied
- Advertising pixels collecting visitor behavior
- Cookie banners that do not actually control the tags
- CRM fields storing unnecessary information
- Old lead lists with no retention plan
- Scheduling tools collecting detailed notes
- Payment platforms connected to customer profiles
- Automations moving data between unrelated systems
- Former employees retaining access
- Shared passwords or accounts in another person’s name
- Vendors without written processing expectations
- AI tools receiving customer or client information without a clear rule
- Privacy policies that do not match the current technology
- Deletion requests completed in one system but not the others
- Sensitive information collected because a form template included the field
- Health or location information inferred through analytics or advertising
These problems usually do not begin because a business was careless. They begin because the business grew one tool at a time.
07 | Even in Texas
A Texas address does not keep data inside Texas.
A business does not have to be located in California, Connecticut, Virginia, Washington, Utah, or Europe for privacy readiness to matter.
Modern websites reach across state and national lines. Customers, students, clients, donors, applicants, patients, members, and visitors may live in different jurisdictions. The tools serving them may process information through companies and infrastructure located across the country or around the world.
Not every law applies to every business in the same way. Every serious business should still understand its data practices before growth creates larger exposure.
For Texas businesses, the digital operation can scale faster than the documentation. A simple website can become a connected system of forms, CRM records, email marketing, scheduling, payments, analytics, retargeting, AI, and automations.
At that point, privacy is operational.
Build the foundation. Protect the perimeter.
08 | The review
What a Privacy Range review looks at.
We walk the digital property with the business and map where information enters, where it travels, where it rests, and what should be tightened first.
We do not review only the policy. We review the system supporting it.
Privacy Range provides operational privacy-readiness support. It does not determine final legal applicability or provide legal representation.
- Website forms and inquiry flows
- Privacy-notice alignment
- Cookie and tracking disclosures
- Consent-management behavior
- Analytics
- Advertising pixels
- Global Privacy Control and opt-out signals
- CRM and lead routing
- Email-marketing consent
- Scheduling systems
- Payment tools
- Vendor and processor connections
- Data retention
- User access
- Former-user access
- Consumer-request pathways
- Unsubscribe processes
- Deletion procedures
- Sensitive-data collection
- Children’s and youth data
- Health and location data
- AI and automation handling
- Cross-border data movement
- Policy-to-system inconsistencies
- Documentation needed for legal review
09 | The boundary
Privacy Range does not replace legal counsel.
Results Ranch and Privacy Range do not provide legal representation, regulatory defense, or guarantees of compliance with every law in every jurisdiction.
The work focuses on the operational side of privacy:
- Websites
- Technology
- Forms
- Tracking
- CRM systems
- Workflows
- Vendors
- Data movement
- Access
- Retention
- Documentation
- Consumer-request processes
For legal interpretation, formal opinions, contract drafting, or regulatory defense, the business should consult a qualified attorney.
Our role is to help make sure the digital house is in order before, during, and after that legal review.
Last reviewed July 28, 2026
This page links to official statutes, government agencies, and regulatory resources wherever possible. Laws, thresholds, regulations, and enforcement priorities can change.
This material provides general educational information and is not legal advice. Applicability depends on the organization, jurisdiction, audience, industry, revenue, data volume, technology, contracts, and specific processing activities. Consult qualified legal counsel regarding individual obligations.

