For the complete documentation index, see llms.txt. This page is also available as Markdown.

United States (U.S.) privacy regulations

Expand the accordions below for support information and recommendations for each U.S. state privacy regulation currently supported by Didomi.

If your consent notice utilizes the IAB Global Privacy Protocol (GPP) to support U.S. privacy regulations, click here for more information.

California: California Privacy Rights Act (CPRA)

Refer to the table below regarding default and recommended settings when configuring the California Privacy Rights Act (CPRA) on a consent notice:

Description

Default territories

Automatically set for California, United States

Recommended purposes

  • Sell my personal information

  • Share my personal information

Recommended sensitive personal information (SPI) purposes

  • Use information that reveal my data for social security, driver's license, state identification card, or passport number

  • Use information that reveal account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account

  • Use information that reveal mental or physical health condition or diagnosis

  • Use information that reveal precise geolocation

  • Use information that reveal sex life or sexual orientation

  • Use information that reveal racial or ethnic origin, religious or philosophical beliefs, or union membership

  • Use information that reveal mail, email, and text messages unless I am the intended recipient of the communication

  • Use information that reveal my genetic data

  • Use information that reveal my biometric data for the purpose of uniquely identifying an individual

Refer to the table below for information on popular integrations with the California Privacy Rights Act (CPRA):

Integration
Availability

IAB Transparency and Consent Framework (TCF)

No

Google Consent Mode v2

No

IAB Global Privacy Protocol (GPP)

Yes. Supported via the National section or state-specific section of the GPP String.

Global Privacy Control (GPC)

GPC is a privacy signal supported by several browsers for end-users to specify at the browser level that they do not want their data to be processed. When a GPC signal is detected, your CPRA configured consent notice is adjusted to respect the end-user choice via GPC:

  • A "GPC signal detected" icon is displayed in the notice.

  • All personal information will be set to Do not sell / Do not share.

  • Instead of Agree and Close there will be a Close button.

Consent notices configured for the California Privacy Rights Act will support the GPC signal automatically. Currently, it is not possible to deactivate GPC support for the consent notice.

Colorado: Colorado Privacy Act (CPA)

Refer to the table below regarding default and recommended settings when configuring the Colorado Privacy Act (CPA) on a consent notice:

Description

Default territories

Automatically set for Colorado, United States

Recommended purposes

  • Sell my personal information

  • Use my personal information for targeted advertising

Recommended sensitive personal information (SPI) purposes

  • Use information that reveal my racial or ethnic origin

  • Use information that reveal religious beliefs

  • Use information that reveal mental or physical health condition or diagnosis

  • Use information that reveal sex lift or sexual orientation

  • Use information that reveal citizenship or immigration status

  • Use information that reveal my genetic data

  • Use information that reveal my biometric data for the purpose of uniquely identifying an individual

Refer to the table below for information on popular integrations with the Colorado Privacy Act (CPA):

Integration
Availability

IAB Transparency and Consent Framework (TCF)

No

Google Consent Mode v2

No

IAB Global Privacy Protocol (GPP)

Yes. Supported via the National section or state-specific section of the GPP String.

Global Privacy Control (GPC)

GPC is a privacy signal supported by several browsers for end-users to specify at the browser level that they do not want their data to be processed. When a GPC signal is detected, your CPA configured consent notice is adjusted to respect the end-user choice via GPC:

  • A "GPC signal detected" icon is displayed in the notice.

  • All personal information will be set to Do not sell / Do not share.

  • Instead of Agree and Close there will be a Close button.

Consent notices configured for the Colorado Privacy Act will support the GPC signal automatically. Currently, it is not possible to deactivate GPC support for the consent notice.

Connecticut: Connecticut Data Privacy Act (CTDPA)

Refer to the table below regarding default and recommended settings when configuring the Connecticut Data Privacy Act (CTDPA) on a consent notice:

Description

Default territories

Automatically set for Connecticut, United States

Recommended purposes

  • Sell my personal information

  • Use my personal information for targeted advertising

Recommended sensitive personal information (SPI) purposes

  • Use information that reveal my racial or ethnic origin,

  • Use information that reveal religious beliefs

  • Use information that reveal mental or physical health condition or diagnosis

  • Use information that reveal precise geolocation

  • Use information that reveal sex life or sexual orientation

  • Use information that reveal citizenship or immigration status

  • Use information that reveal my genetic data

  • Use information that reveal my biometric data for the purpose of uniquely identifying an individual

Refer to the table below for information on popular integrations with the Connecticut Data Privacy Act (CTDPA):

Integration
Availability

IAB Transparency and Consent Framework (TCF)

No

Google Consent Mode v2

No

IAB Global Privacy Protocol (GPP)

Yes. Supported via the National section or state-specific section of the GPP String.

Global Privacy Control (GPC)

GPC is a privacy signal supported by several browsers for end-users to specify at the browser level that they do not want their data to be processed. When a GPC signal is detected, your CTDPA configured consent notice is adjusted to respect the end-user choice via GPC:

  • A "GPC signal detected" icon is displayed in the notice.

  • All personal information will be set to Do not sell / Do not share.

  • Instead of Agree and Close there will be a Close button.

Consent notices configured for the Connecticut Data Privacy Act will support the GPC signal automatically. Currently, it is not possible to deactivate GPC support for the consent notice.

Delaware: Delaware Personal Data Privacy Act (DPDPA)

Refer to the table below regarding default and recommended settings when configuring the Delaware Personal Data Privacy Act (DPDPA) on a consent notice:

Description

Default territories

Automatically set for Delaware, United States

Recommended purposes

  • Sell my personal information

  • Use my personal information for targeted advertising

Recommended sensitive personal information (SPI) purposes

  • Use information that reveal my racial or ethnic origin,

  • Use information that reveal religious beliefs

  • Use information that reveal mental or physical health condition or diagnosis

  • Use information that reveal sex life or sexual orientation

  • Use information that reveal citizenship or immigration status

  • Use information that reveal my genetic data

  • Use information that reveal my biometric data for the purpose of uniquely identifying an individual

  • Use information that reveal precise geolocation

  • Use information that reveal my status as transgender or nonbinary

Refer to the table below for information on popular integrations with the Delaware Personal Data Privacy Act (DPDPA):

Integration
Availability

IAB Transparency and Consent Framework (TCF)

No

Google Consent Mode v2

No

IAB Global Privacy Protocol (GPP)

Yes. Supported via the National section or state-specific section of the GPP String.

Global Privacy Control (GPC)

GPC is a privacy signal supported by several browsers for end-users to specify at the browser level that they do not want their data to be processed. When a GPC signal is detected, your DPDPA configured consent notice is adjusted to respect the end-user choice via GPC:

  • A "GPC signal detected" icon is displayed in the notice.

  • All personal information will be set to Do not sell / Do not share.

  • Instead of Agree and Close there will be a Close button.

Consent notices configured for the Delaware Personal Data Privacy Act will support the GPC signal automatically. Currently, it is not possible to deactivate GPC support for the consent notice.

Florida: Florida Digital Bill of Rights (FDBR)

Refer to the table below regarding default and recommended settings when configuring the Florida Digital Bill of Rights (FDBR) on a consent notice:

Description

Default territories

Automatically set for Florida, United States

Recommended purposes

  • Sell my personal information

  • Use my personal information for targeted advertising

Recommended sensitive personal information (SPI) purposes

  • Use information that reveal my racial or ethnic origin,

  • Use information that reveal religious beliefs

  • Use information that reveal mental or physical health condition or diagnosis

  • Use information that reveal precise geolocation

  • Use information that reveal sex life or sexual orientation

  • Use information that reveal citizenship or immigration status

  • Use information that reveal my genetic data

  • Use information that reveal my biometric data for the purpose of uniquely identifying an individual

Refer to the table below for information on popular integrations with the Florida Digital Bill of Rights (FDBR):

Integration
Availability

IAB Transparency and Consent Framework (TCF)

No

Google Consent Mode v2

No

IAB Global Privacy Protocol (GPP)

Yes. Supported via the National section or state-specific section of the GPP String.

Global Privacy Control (GPC)

GPC is a privacy signal supported by several browsers for end-users to specify at the browser level that they do not want their data to be processed. When a GPC signal is detected, your FDBR configured consent notice is adjusted to respect the end-user choice via GPC:

  • A "GPC signal detected" icon is displayed in the notice.

  • All personal information will be set to Do not sell / Do not share.

  • Instead of Agree and Close there will be a Close button.

Consent notices configured for the Florida Digital Bill of Rights will support the GPC signal automatically. Currently, it is not possible to deactivate GPC support for the consent notice.

Indiana: Indiana Consumer Data Protection Act (INCDPA)

Refer to the table below regarding default and recommended settings when configuring the Indiana Consumer Data Protection Act (INCDPA) on a consent notice:

Description

Default territories

Automatically set for Indiana, United States

Recommended purposes

  • Sell my personal information

  • Use my personal information for targeted advertising

Recommended sensitive personal information (SPI) purposes

  • Use information that reveal my racial or ethnic origin,

  • Use information that reveal religious beliefs

  • Use information that reveal mental or physical health condition or diagnosis

  • Use information that reveal sex life or sexual orientation

  • Use information that reveal citizenship or immigration status

  • Use information that reveal my genetic data

  • Use information that reveal my biometric data for the purpose of uniquely identifying an individual

  • Use information that reveal precise geolocation

Refer to the table below for information on popular integrations with the Indiana Consumer Data Protection Act (INCDPA):

Integration
Availability

IAB Transparency and Consent Framework (TCF)

No

Google Consent Mode v2

No

IAB Global Privacy Protocol (GPP)

Yes. Supported via the National section of the GPP String.

Global Privacy Control (GPC)

GPC is a privacy signal supported by several browsers for end-users to specify at the browser level that they do not want their data to be processed. When a GPC signal is detected, your INCDPA configured consent notice is adjusted to respect the end-user choice via GPC:

  • A "GPC signal detected" icon is displayed in the notice.

  • All personal information will be set to Do not sell / Do not share.

  • Instead of Agree and Close there will be a Close button.

Consent notices configured for the Indiana Consumer Data Privacy Act will support the GPC signal automatically. Currently, it is not possible to deactivate GPC support for the consent notice.

Iowa: Iowa Consumer Data Protection Act (ICDPA)

Refer to the table below regarding default and recommended settings when configuring the Iowa Consumer Data Protection Act (ICDPA) on a consent notice:

Description

Default territories

Automatically set for Iowa, United States

Recommended purposes

  • Sell my personal information

  • Use my personal information for targeted advertising

Recommended sensitive personal information (SPI) purposes

  • Use information that reveal my racial or ethnic origin,

  • Use information that reveal religious beliefs

  • Use information that reveal mental or physical health condition or diagnosis

  • Use information that reveal sex life or sexual orientation

  • Use information that reveal citizenship or immigration status

  • Use information that reveal my genetic data

  • Use information that reveal my biometric data for the purpose of uniquely identifying an individual

  • Use information that reveal precise geolocation

Refer to the table below for information on popular integrations with the Iowa Consumer Data Protection Act (ICDPA):

Integration
Availability

IAB Transparency and Consent Framework (TCF)

No

Google Consent Mode v2

No

IAB Global Privacy Protocol (GPP)

Yes. Supported via the National section or state-specific section of the GPP String.

Global Privacy Control (GPC)

GPC is a privacy signal supported by several browsers for end-users to specify at the browser level that they do not want their data to be processed. When a GPC signal is detected, your INCDPA configured consent notice is adjusted to respect the end-user choice via GPC:

  • A "GPC signal detected" icon is displayed in the notice.

  • All personal information will be set to Do not sell / Do not share.

  • Instead of Agree and Close there will be a Close button.

Consent notices configured for the Iowa Consumer Data Privacy Act will support the GPC signal automatically. Currently, it is not possible to deactivate GPC support for the consent notice.

Kentucky: Kentucky Consumer Data Protection Act (KCDPA)

Refer to the table below regarding default and recommended settings when configuring the Kentucky Consumer Data Protection Act (KCDPA) on a consent notice:

Description

Default territories

Automatically set for Kentucky, United States

Recommended purposes

  • Sell my personal information

  • Use my personal information for targeted advertising

Recommended sensitive personal information (SPI) purposes

  • Use information that reveal my racial or ethnic origin,

  • Use information that reveal religious beliefs

  • Use information that reveal mental or physical health condition or diagnosis

  • Use information that reveal sex life or sexual orientation

  • Use information that reveal citizenship or immigration status

  • Use information that reveal my genetic data

  • Use information that reveal my biometric data for the purpose of uniquely identifying an individual

  • Use information that reveal precise geolocation

Refer to the table below for information on popular integrations with the Kentucky Consumer Data Protection Act (KCDPA):

Integration
Availability

IAB Transparency and Consent Framework (TCF)

No

Google Consent Mode v2

No

IAB Global Privacy Protocol (GPP)

Yes. Supported via the National section of the GPP String.

Global Privacy Control (GPC)

GPC is a privacy signal supported by several browsers for end-users to specify at the browser level that they do not want their data to be processed. When a GPC signal is detected, your KCDPA configured consent notice is adjusted to respect the end-user choice via GPC:

  • A "GPC signal detected" icon is displayed in the notice.

  • All personal information will be set to Do not sell / Do not share.

  • Instead of Agree and Close there will be a Close button.

Consent notices configured for the Kentucky Consumer Data Privacy Act will support the GPC signal automatically. Currently, it is not possible to deactivate GPC support for the consent notice.

Maryland: Maryland Online Data Privacy Act (MODPA)

Refer to the table below regarding default and recommended settings when configuring the Maryland Online Data Privacy Act (MODPA) on a consent notice:

Description

Default territories

Automatically set for Maryland, United States

Recommended purposes

  • Sell my personal information

  • Use my personal information for targeted advertising

Recommended sensitive personal information (SPI) purposes

Refer to the table below for information on popular integrations with the Maryland Online Data Privacy Act (MODPA):

Integration
Availability

IAB Transparency and Consent Framework (TCF)

No

Google Consent Mode v2

No

IAB Global Privacy Protocol (GPP)

Yes. Supported via the National section of the GPP String.

Global Privacy Control (GPC)

GPC is a privacy signal supported by several browsers for end-users to specify at the browser level that they do not want their data to be processed. When a GPC signal is detected, your MODPA configured consent notice is adjusted to respect the end-user choice via GPC:

  • A "GPC signal detected" icon is displayed in the notice.

  • All personal information will be set to Do not sell / Do not share.

  • Instead of Agree and Close there will be a Close button.

Consent notices configured for the Maryland Online Data Privacy Act will support the GPC signal automatically. Currently, it is not possible to deactivate GPC support for the consent notice.

Minnesota: Minnesota Consumer Data Privacy Act (MNCDPA)

Refer to the table below regarding default and recommended settings when configuring the Minnesota Consumer Data Privacy Act (MNCDPA) on a consent notice:

Description

Default territories

Automatically set for Minnesota, United States

Recommended purposes

  • Sell my personal information

  • Use my personal information for targeted advertising

Recommended sensitive personal information (SPI) purposes

  • Use information that reveal my racial or ethnic origin,

  • Use information that reveal religious beliefs

  • Use information that reveal mental or physical health condition or diagnosis

  • Use information that reveal precise geolocation

  • Use information that reveal sex life or sexual orientation

  • Use information that reveal citizenship or immigration status

  • Use information that reveal my genetic data

  • Use information that reveal my biometric data for the purpose of uniquely identifying an individual

Refer to the table below for information on popular integrations with the Minnesota Consumer Data Privacy Act (MNCDPA):

Integration
Availability

IAB Transparency and Consent Framework (TCF)

No

Google Consent Mode v2

No

IAB Global Privacy Protocol (GPP)

Yes. Supported via the National section or state-specific section of the GPP String.

Global Privacy Control (GPC)

GPC is a privacy signal supported by several browsers for end-users to specify at the browser level that they do not want their data to be processed. When a GPC signal is detected, your MNCDPA configured consent notice is adjusted to respect the end-user choice via GPC:

  • A "GPC signal detected" icon is displayed in the notice.

  • All personal information will be set to Do not sell / Do not share.

  • Instead of Agree and Close there will be a Close button.

Consent notices configured for the Minnesota Consumer Data Privacy Act will support the GPC signal automatically. Currently, it is not possible to deactivate GPC support for the consent notice.

Montana: Montana Consumer Data Privacy Act (MCDPA)

Refer to the table below regarding default and recommended settings when configuring the Montana Consumer Data Privacy Act (MCDPA) on a consent notice:

Description

Default territories

Automatically set for Montana, United States

Recommended purposes

  • Sell my personal information

  • Use my personal information for targeted advertising

Recommended sensitive personal information (SPI) purposes

  • Use information that reveal my racial or ethnic origin,

  • Use information that reveal religious beliefs

  • Use information that reveal mental or physical health condition or diagnosis

  • Use information that reveal precise geolocation

  • Use information that reveal sex life or sexual orientation

  • Use information that reveal citizenship or immigration status

  • Use information that reveal my genetic data

  • Use information that reveal my biometric data for the purpose of uniquely identifying an individual

Refer to the table below for information on popular integrations with the Montana Consumer Data Privacy Act (MCDPA):

Integration
Availability

IAB Transparency and Consent Framework (TCF)

No

Google Consent Mode v2

No

IAB Global Privacy Protocol (GPP)

Yes. Supported via the National section or state-specific section of the GPP String.

Global Privacy Control (GPC)

GPC is a privacy signal supported by several browsers for end-users to specify at the browser level that they do not want their data to be processed. When a GPC signal is detected, your MCDPA configured consent notice is adjusted to respect the end-user choice via GPC:

  • A "GPC signal detected" icon is displayed in the notice.

  • All personal information will be set to Do not sell / Do not share.

  • Instead of Agree and Close there will be a Close button.

Consent notices configured for the Montana Consumer Data Privacy Act will support the GPC signal automatically. Currently, it is not possible to deactivate GPC support for the consent notice.

Nebraska: Nebraska Data Privacy Act (NDPA)

Refer to the table below regarding default and recommended settings when configuring the Nebraska Data Privacy Act (NDPA) on a consent notice:

Description

Default territories

Automatically set for Nebraska, United States

Recommended purposes

  • Sell my personal information

  • Use my personal information for targeted advertising

Recommended sensitive personal information (SPI) purposes

  • Use information that reveal my racial or ethnic origin,

  • Use information that reveal religious beliefs

  • Use information that reveal mental or physical health condition or diagnosis

  • Use information that reveal sex life or sexual orientation

  • Use information that reveal citizenship or immigration status

  • Use information that reveal my genetic data

  • Use information that reveal my biometric data for the purpose of uniquely identifying an individual

  • Use information that reveal precise geolocation

Refer to the table below for information on popular integrations with the Nebraska Data Privacy Act (NDPA):

Integration
Availability

IAB Transparency and Consent Framework (TCF)

No

Google Consent Mode v2

No

IAB Global Privacy Protocol (GPP)

Yes. Supported via the National section or state-specific section of the GPP String.

Global Privacy Control (GPC)

GPC is a privacy signal supported by several browsers for end-users to specify at the browser level that they do not want their data to be processed. When a GPC signal is detected, your NDPA configured consent notice is adjusted to respect the end-user choice via GPC:

  • A "GPC signal detected" icon is displayed in the notice.

  • All personal information will be set to Do not sell / Do not share.

  • Instead of Agree and Close there will be a Close button.

Consent notices configured for the Nebraska Data Privacy Act will support the GPC signal automatically. Currently, it is not possible to deactivate GPC support for the consent notice.

New Hampshire: New Hampshire Privacy Act (NHPA)

Refer to the table below regarding default and recommended settings when configuring the New Hampshire Privacy Act (NHPA) on a consent notice:

Description

Default territories

Automatically set for New Hampshire, United States

Recommended purposes

  • Sell my personal information

  • Use my personal information for targeted advertising

Recommended sensitive personal information (SPI) purposes

  • Use information that reveal my racial or ethnic origin,

  • Use information that reveal religious beliefs

  • Use information that reveal mental or physical health condition or diagnosis

  • Use information that reveal sex life or sexual orientation

  • Use information that reveal citizenship or immigration status

  • Use information that reveal my genetic data

  • Use information that reveal my biometric data for the purpose of uniquely identifying an individual

  • Use information that reveal precise geolocation

Refer to the table below for information on popular integrations with the New Hampshire Privacy Act (NHPA):

Integration
Availability

IAB Transparency and Consent Framework (TCF)

No

Google Consent Mode v2

No

IAB Global Privacy Protocol (GPP)

Yes. Supported via the National section or state-specific section of the GPP String.

Global Privacy Control (GPC)

GPC is a privacy signal supported by several browsers for end-users to specify at the browser level that they do not want their data to be processed. When a GPC signal is detected, your NHPA configured consent notice is adjusted to respect the end-user choice via GPC:

  • A "GPC signal detected" icon is displayed in the notice.

  • All personal information will be set to Do not sell / Do not share.

  • Instead of Agree and Close there will be a Close button.

Consent notices configured for the New Hampshire Privacy Act will support the GPC signal automatically. Currently, it is not possible to deactivate GPC support for the consent notice.

New Jersey: New Jersey Data Privacy Act (NJDPA)

Refer to the table below regarding default and recommended settings when configuring the New Jersey Data Privacy Act (NJDPA) on a consent notice:

Description

Default territories

Automatically set for New Jersey, United States

Recommended purposes

  • Sell my personal information

  • Use my personal information for targeted advertising

Recommended sensitive personal information (SPI) purposes

  • Use information that reveal my racial or ethnic origin,

  • Use information that reveal religious beliefs

  • Use information that reveal mental or physical health condition or diagnosis

  • Use information that reveal sex life or sexual orientation

  • Use information that reveal citizenship or immigration status

  • Use information that reveal my genetic data

  • Use information that reveal my biometric data for the purpose of uniquely identifying an individual

  • Use information that reveal precise geolocation

  • Use information that reveal my status as transgender or nonbinary

  • Use information that reveal account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account

Refer to the table below for information on popular integrations with the New Jersey Data Privacy Act (NJDPA):

Integration
Availability

IAB Transparency and Consent Framework (TCF)

No

Google Consent Mode v2

No

IAB Global Privacy Protocol (GPP)

Yes. Supported via the National section or state-specific section of the GPP String.

Global Privacy Control (GPC)

GPC is a privacy signal supported by several browsers for end-users to specify at the browser level that they do not want their data to be processed. When a GPC signal is detected, your NJDPA configured consent notice is adjusted to respect the end-user choice via GPC:

  • A "GPC signal detected" icon is displayed in the notice.

  • All personal information will be set to Do not sell / Do not share.

  • Instead of Agree and Close there will be a Close button.

Consent notices configured for the New Jersey Data Privacy Act will support the GPC signal automatically. Currently, it is not possible to deactivate GPC support for the consent notice.

Oregon: Oregon Consumer Privacy Act (OCPA)

Refer to the table below regarding default and recommended settings when configuring the Oregon Consumer Privacy Act (OCPA) on a consent notice:

Description

Default territories

Automatically set for Oregon, United States

Recommended purposes

  • Sell my personal information

  • Use my personal information for targeted advertising

Recommended sensitive personal information (SPI) purposes

  • Use information that reveal my racial or ethnic origin,

  • Use information that reveal religious beliefs

  • Use information that reveal mental or physical health condition or diagnosis

  • Use information that reveal precise geolocation

  • Use information that reveal sex life or sexual orientation

  • Use information that reveal citizenship or immigration status

  • Use information that reveal my genetic data

  • Use information that reveal my biometric data for the purpose of uniquely identifying an individual

  • Use information that reveal my status as transgender or nonbinary

  • Use information that reveal national origin

  • Use information that reveal my status as a victim of a crime

Refer to the table below for information on popular integrations with the Oregon Consumer Privacy Act (OCPA):

Integration
Availability

IAB Transparency and Consent Framework (TCF)

No

Google Consent Mode v2

No

IAB Global Privacy Protocol (GPP)

Yes. Supported via the National section or state-specific section of the GPP String.

Global Privacy Control (GPC)

GPC is a privacy signal supported by several browsers for end-users to specify at the browser level that they do not want their data to be processed. When a GPC signal is detected, your OCPA configured consent notice is adjusted to respect the end-user choice via GPC:

  • A "GPC signal detected" icon is displayed in the notice.

  • All personal information will be set to Do not sell / Do not share.

  • Instead of Agree and Close there will be a Close button.

Consent notices configured for the Oregon Consumer Privacy Act will support the GPC signal automatically. Currently, it is not possible to deactivate GPC support for the consent notice.

Rhode Island: Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)

Refer to the table below regarding default and recommended settings when configuring the Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) on a consent notice:

Description

Default territories

Automatically set for Rhode Island, United States

Recommended purposes

  • Sell my personal information

  • Use my personal information for targeted advertising

Recommended sensitive personal information (SPI) purposes

  • Use information that reveal my racial or ethnic origin,

  • Use information that reveal religious beliefs

  • Use information that reveal mental or physical health condition or diagnosis

  • Use information that reveal sex life or sexual orientation

  • Use information that reveal citizenship or immigration status

  • Use information that reveal my genetic data

  • Use information that reveal my biometric data for the purpose of uniquely identifying an individual

  • Use information that reveal precise geolocation

Refer to the table below for information on popular integrations with the Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA):

Integration
Availability

IAB Transparency and Consent Framework (TCF)

No

Google Consent Mode v2

No

IAB Global Privacy Protocol (GPP)

Yes. Supported via the National section of the GPP String.

Tennessee: Tennessee Information Protection Act (TIPA)

Refer to the table below regarding default and recommended settings when configuring the Tennessee Information Privacy Act (TIPA) on a consent notice:

Description

Default territories

Automatically set for Tennessee, United States

Recommended purposes

  • Sell my personal information

  • Use my personal information for targeted advertising

Recommended sensitive personal information (SPI) purposes

  • Use information that reveal my racial or ethnic origin,

  • Use information that reveal religious beliefs

  • Use information that reveal mental or physical health condition or diagnosis

  • Use information that reveal sex life or sexual orientation

  • Use information that reveal citizenship or immigration status

  • Use information that reveal my genetic data

  • Use information that reveal my biometric data for the purpose of uniquely identifying an individual

  • Use information that reveal precise geolocation

Refer to the table below for information on popular integrations with the Tennessee Information Privacy Act (TIPA):

Integration
Availability

IAB Transparency and Consent Framework (TCF)

No

Google Consent Mode v2

No

IAB Global Privacy Protocol (GPP)

Yes. Supported via the National section or state-specific section of the GPP String.

Global Privacy Control (GPC)

GPC is a privacy signal supported by several browsers for end-users to specify at the browser level that they do not want their data to be processed. When a GPC signal is detected, your TIPA configured consent notice is adjusted to respect the end-user choice via GPC:

  • A "GPC signal detected" icon is displayed in the notice.

  • All personal information will be set to Do not sell / Do not share.

  • Instead of Agree and Close there will be a Close button.

Consent notices configured for the Tennessee Information Privacy Act will support the GPC signal automatically. Currently, it is not possible to deactivate GPC support for the consent notice.

Texas: Texas Data Privacy and Security Act (TDPSA)

Refer to the table below regarding default and recommended settings when configuring the Texas Data Privacy and Security Act (TDPSA) on a consent notice:

Description

Default territories

Automatically set for Texas, United States

Recommended purposes

  • Sell my personal information

  • Use my personal information for targeted advertising

Recommended sensitive personal information (SPI) purposes

  • Use information that reveal my racial or ethnic origin,

  • Use information that reveal religious beliefs

  • Use information that reveal mental or physical health condition or diagnosis

  • Use information that reveal precise geolocation

  • Use information that reveal sex life or sexual orientation

  • Use information that reveal citizenship or immigration status

  • Use information that reveal my genetic data

  • Use information that reveal my biometric data for the purpose of uniquely identifying an individual

Refer to the table below for information on popular integrations with the Texas Data Privacy and Security Act (TDPSA):

Integration
Availability

IAB Transparency and Consent Framework (TCF)

No

Google Consent Mode v2

No

IAB Global Privacy Protocol (GPP)

Yes. Supported via the National section or state-specific section of the GPP String.

Global Privacy Control (GPC)

GPC is a privacy signal supported by several browsers for end-users to specify at the browser level that they do not want their data to be processed. When a GPC signal is detected, your TDPSA configured consent notice is adjusted to respect the end-user choice via GPC:

  • A "GPC signal detected" icon is displayed in the notice.

  • All personal information will be set to Do not sell / Do not share.

  • Instead of Agree and Close there will be a Close button.

Consent notices configured for the Texas Data Privacy and Security Act will support the GPC signal automatically. Currently, it is not possible to deactivate GPC support for the consent notice.

Utah: Utah Consumer Privacy Act (UCPA)

Refer to the table below regarding default and recommended settings when configuring the Utah Consumer Privacy Act (UCPA) on a consent notice:

Description

Default territories

Automatically set for Utah, United States

Recommended purposes

  • Sell my personal information

  • Use my personal information for targeted advertising

Recommended sensitive personal information (SPI) purposes

  • Use information that reveal my racial or ethnic origin,

  • Use information that reveal religious beliefs

  • Use information that reveal mental or physical health condition or diagnosis

  • Use information that reveal precise geolocation

  • Use information that reveal sex life or sexual orientation

  • Use information that reveal citizenship or immigration status

  • Use information that reveal my genetic data

  • Use information that reveal my biometric data for the purpose of uniquely identifying an individual

Refer to the table below for information on popular integrations with the Utah Consumer Privacy Act (UCPA):

Integration
Availability

IAB Transparency and Consent Framework (TCF)

No

Google Consent Mode v2

No

IAB Global Privacy Protocol (GPP)

Yes. Supported via the National section or state-specific section of the GPP String.

Global Privacy Control (GPC)

GPC is a privacy signal supported by several browsers for end-users to specify at the browser level that they do not want their data to be processed. When a GPC signal is detected, your UCPA configured consent notice is adjusted to respect the end-user choice via GPC:

  • A "GPC signal detected" icon is displayed in the notice.

  • All personal information will be set to Do not sell / Do not share.

  • Instead of Agree and Close there will be a Close button.

Consent notices configured for the Utah Consumer Privacy Act will support the GPC signal automatically. Currently, it is not possible to deactivate GPC support for the consent notice.

Virginia: Virginia Consumer Data Protection Act (VCDPA)

Refer to the table below regarding default and recommended settings when configuring the Virginia Consumer Data Privacy Act (VCDPA) on a consent notice:

Description

Default territories

Automatically set for Virginia, United States

Recommended purposes

  • Sell my personal information

  • Use my personal information for targeted advertising

Recommended sensitive personal information (SPI) purposes

  • Use information that reveal my racial or ethnic origin,

  • Use information that reveal religious beliefs

  • Use information that reveal mental or physical health condition or diagnosis

  • Use information that reveal precise geolocation

  • Use information that reveal sex life or sexual orientation

  • Use information that reveal citizenship or immigration status

  • Use information that reveal my genetic data

  • Use information that reveal my biometric data for the purpose of uniquely identifying an individual

Refer to the table below for information on popular integrations with the Virginia Consumer Data Privacy Act (VCDPA):

Integration
Availability

IAB Transparency and Consent Framework (TCF)

No

Google Consent Mode v2

No

IAB Global Privacy Protocol (GPP)

Yes. Supported via the National section or state-specific section of the GPP String.

Global Privacy Control (GPC)

GPC is a privacy signal supported by several browsers for end-users to specify at the browser level that they do not want their data to be processed. When a GPC signal is detected, your VCDPA configured consent notice is adjusted to respect the end-user choice via GPC:

  • A "GPC signal detected" icon is displayed in the notice.

  • All personal information will be set to Do not sell / Do not share.

  • Instead of Agree and Close there will be a Close button.

Consent notices configured for the Virginia Consumer Data Privacy Act will support the GPC signal automatically. Currently, it is not possible to deactivate GPC support for the consent notice.

Last updated