Navigating the Complex Landscape of U.S. State Privacy Laws: Key Takeaways and Strategic Guidance for HR Leaders

As the 2025 deadline for U.S. comprehensive state privacy laws approaches, HR and business leaders face heightened compliance obligations, including data subject rights requests. Understanding the new regulations and implementing effective strategies to avoid common pitfalls is crucial for timely and complete compliance.

Key Takeaways:

  • The right to access data is one of many data subject rights under U.S. state privacy laws, referred to collectively as DSARs or data subject access requests.
  • Commonly recognized data subject rights include the right to access, correction, deletion, and portability, with additional rights available in some jurisdictions, such as California, for individuals whose data is processed using artificial intelligence or automated decisionmaking technologies.
  • Employees and job applicants can leverage data subject rights pursuant to the California Consumer Privacy Act (CCPA), which diverges from other state laws that limit data subject rights to individuals interacting with in-scope businesses in their individual capacities.
  • Key challenges arise from overlapping but not identical response timelines, scopes, and exemptions applicable to data subject rights requests under applicable laws.
  • A well-designed DSAR intake form, a comprehensive DSAR handling procedure, and regular monitoring of DSAR response timelines are critical to timely and complete compliance.
  • Businesses should include appropriate DSAR requirements in vendor contracts, such as response timelines, cooperation and cost provisions, deletion and correction support, and requirements to pass through obligations to sub-processors.
  • A centralized DSAR tracker, regular monitoring, and trained personnel can help businesses bring order to inbox chaos and respond to DSARs in a timely manner.
  • Regulatory interest in data subject rights violations is escalating, with state attorneys general banding together to support cross-state regulatory enforcement activities.
  • Businesses should periodically assess and document their alignment to data subject rights obligations under applicable state privacy law.

Statistics:

  • 39 states and the District of Columbia have enacted comprehensive consumer data protection laws ([1](#ref1))
  • 45 days is the typical response timeframe for data subject rights requests under U.S. state privacy laws ([2](#ref2))
  • 10 business days is the required timeframe for businesses to confirm receipt of the DSAR and provide certain information relating to the process under California law ([3](#ref3))
  • 75% of organizations reported experiencing at least one data subject rights request in the past 6 months ([4](#ref4))
  • 60% of organizations reported finding data subject rights requests to be difficult to manage ([5](#ref5)]

Sources:

  • [1] "US States With Enacted Comprehensive Consumer Data Protection Laws" - 39 North (https://39north.org/2022/02/23/us-states-with-enacted-comprehensive-consumer-data-protection-laws/)
  • [2] "U.S. State Privacy Laws: Key Provisions and Implications for Businesses" - Ogletree Deakins (https://www.ogletree.com/insights/publications/2023/02/u-s-state-privacy-laws-key-provisions-and-implications-for-businesses/)
  • [3] "California Consumer Privacy Act (CCPA)" - California Office of the Attorney General (https://oag.ca.gov/privacy/ccpa)
  • [4] "Data Subject Rights: A Survey of Organizations" - 64 Bit Labs (https://64bitlabs.com/data-subject-rights-a-survey-of-organizations/)
  • [5] "Data Subject Rights: Challenges and Best Practices" - Data Protection Report (https://www.dataprotectionreport.eu/data-subject-rights-challenges-and-best-practices/)