CIPP-US - State Privacy Laws - Section 5.3

Identify the key requirements of comprehensive state privacy laws enacted beyond California, including consumer rights, data minimisation, and consent obligations.

Identify the shared consumer rights, including access, correction, deletion, portability, and opt-out of targeted advertising, across the Virginia CDPA, Colorado Privacy Act, and Connecticut Data Privacy Act, and how their data minimisation and purpose limitation duties align. Distinguish where they diverge on universal opt-out and data protection assessments for high-risk processing.

Virginia CDPAColorado Privacy ActConnecticut Data Privacy ActUniversal opt-out mechanism

Practice question for this objective

Free sampleState Privacy Lawshard

A controller subject to the Virginia, Colorado, and Connecticut comprehensive privacy laws is mapping when it must conduct and keep a data protection assessment for its processing activities. The compliance lead wants to identify the processing categories that trigger this assessment duty under all three statutes. Which two processing activities trigger the data protection assessment duty across the Virginia, Colorado, and Connecticut laws? (Select TWO.)

  • ARoutine processing of personal data the consumer provided in order to complete a transaction the consumer specifically requested from the controller.
  • BProcessing personal data for the purpose of targeted advertising or for the sale of that consumer's personal data to a third party. Correct
  • CAny processing for which a consumer is able to sue the controller directly to compel completion of an outstanding assessment.
  • DProcessing of a consumer's sensitive data, such as data revealing health conditions, racial or ethnic origin, or precise geolocation. Correct
  • EProcessing that the controller may begin only after it files the completed assessment with the state regulator for prior approval.
Across Virginia, Colorado, and Connecticut, processing for targeted advertising or sale and processing of sensitive data are heightened-risk activities that require a documented data protection assessment. Options B and D capture two heightened-risk categories that all three statutes flag for a mandatory data protection assessment: targeted advertising and sale, and the processing of sensitive data. Routine fulfilment of a requested transaction is not heightened-risk, no consumer private action exists to compel assessments, and the assessments are kept for disclosure to the attorney general on request rather than pre-filed with a regulator.

Why A is wrong: Processing limited to fulfilling a transaction the consumer requested is not heightened-risk processing, so it does not trigger the assessment duty and is wrong.

Why B is correct: All three laws expressly list processing for targeted advertising and sale as activities that require a documented data protection assessment, so this is correct.

Why C is wrong: Tempting as an enforcement hook, but none of the three laws gives consumers a private right of action to compel assessments; the attorney general enforces, so this is wrong.

Why D is correct: Each statute treats the processing of sensitive data as heightened-risk processing that requires a data protection assessment, so this is correct.

Why E is wrong: These laws require assessments to be retained and disclosed to the attorney general on request, not pre-filed with a regulator before processing, so this mischaracterises the duty.

See more CIPP-US practice questions, answers explained.

More in this domain

Back to all State Privacy Laws objectives, or the CIPP-US cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.