AccuSights
PartnersBlogAbout
Book my 30-minute demo

Privacy · State attorneys general

US state privacy laws (20 in force in 2026)

Indiana, Kentucky and Rhode Island joined January 1, 2026. California adds cybersecurity audits and risk assessments under the CPPA rules.

One control set, every frameworkPractitioner-led, CRISC and CISAPublic pricing

Who it applies to

The businesses that carry State privacy, and the pages written for them.

Each industry page names the regulation, the obligation and the clock, tells the story of an owner in that trade, and shows what we protect for them.

Which packages satisfy it

Cyber and Data Protection Assessment

Any business of 10 to 500 people that has never had a real assessment, or has not had one in a year

Fixed feescoped in 30 minutes
Details →

SOC 2 Readiness: Type 1 and Type 2

SaaS, AI and technology companies of 5 to 300 people, and professional firms whose clients require it

Fixed feescoped in 30 minutes
Details →

Practice Cybersecurity, Data Protection and HIPAA Package

Medical and dental practices, clinics, surgery centers, hospital departments and the business associates that serve them

Fixed feescoped in 30 minutes
Details →

What it asks for

In plain English, what State privacy expects you to have in place.

  • A data mapWhat personal data you collect, why, where it goes and how long you keep it.
  • A lawful basis and a noticeA reason for each use and a privacy notice that says so in plain language.
  • Rights handlingA process to answer access, correction, deletion and opt-out requests within the required time.
  • Security appropriate to the riskTechnical and organizational measures that match the sensitivity of the data.
  • Processor and vendor termsContracts that bind the companies processing data on your behalf.
  • Breach notificationA tested process to assess a breach and notify the authority and the people affected on the clock the law sets.

A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.

Or start with the 3-minute test

Questions we get about State privacy

Do you certify State privacy compliance?
No. State attorneys general and the auditors or assessors it recognizes have the final say. We interpret the requirements for your business, scope what applies, close the gaps and keep the evidence current so the assessment or examination is a formality.
Where do we start with State privacy?
With the 3-minute Cyber Hygiene Test if you want a number today, or with the 30-minute call if you want a written scope and a fixed fee. Either way the first deliverable is a gap list ranked by what would fail and what would hurt.
We also need other frameworks. Do we do State privacy separately?
No. We build one control set and map it to every framework you carry, so evidence is produced once and reused. Adding a framework later is a mapping exercise, not a second program.

Also in privacy: GDPR · NIS2 · every framework by industry

Next step

Thirty minutes, an engineer, a written scope for State privacy.

Book the demo and see how one control set carries State privacy and everything else you owe. Or leave your details and an engineer replies within one business day.

3-min test