Scrutineer.ai

Scrutineer · By framework

Data privacy compliance software for every US state privacy law

Around twenty US states now run comprehensive consumer privacy laws, and they are similar enough that one control set covers most of the work. The expensive part is not the controls. It is knowing which laws reach you at all.

Scrutineer holds your data inventory, your deletion and opt-out handling and your processor contracts once, then shows every regime each control satisfies and every threshold that puts you in scope.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Illustrative sample · not an audit attestation

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with data privacy compliance

The laws are similar. The scope tests are not.

Nearly every state after California copied the Virginia template, so the obligations converge: a data inventory, consumer rights handling, opt-outs for targeted advertising and sale, contracts with processors, and assessments for higher risk processing. What does not converge is who has to do any of it. California turns on at roughly 26.6 million dollars of gross revenue or 100,000 California consumers. Texas has no revenue or consumer threshold at all and instead exempts small businesses by SBA size standard. Florida reaches almost nobody, needing over a billion dollars in revenue plus half of it from online advertising. Maryland and Rhode Island start at 35,000 consumers with no revenue test. Scrutineer runs your revenue, your consumer counts by state and your processing activities against each test, so you prepare for the laws that actually bind you.

Your GLBA or HIPAA exemption is narrower than you think

Most published trackers still say financial institutions are exempt from state privacy law. That is no longer reliably true. Every one of these laws exempts GLBA-covered data, but the broader entity-level exemption, which excuses the whole company, is now missing in California, Colorado, Connecticut, Minnesota, Montana and Oregon. Montana removed its entity-level exemption on October 1, 2025 under SB 297. Connecticut replaced its broad exemption with one available only to depository institutions under SB 1295, with most changes effective July 1, 2026. A lender or fintech running GLBA and non-GLBA lines can no longer treat the whole business as out of scope. Scrutineer tracks the exemption at both levels and flags the data that fell outside it.

One control, mapped to every regime it satisfies

A deletion workflow that meets the CCPA also answers Virginia, Texas, Colorado and the rest, and much of it answers a GDPR erasure request too. Maintaining separate programs per state is how privacy teams end up with twenty spreadsheets and no confidence in any of them. Scrutineer maps a control once and shows every law it satisfies, so the marginal cost of the twenty-first state is the delta rather than a fresh program. Where a state genuinely diverges, which is mostly Maryland on data minimization and sensitive data, it shows up as a gap against that state rather than being averaged away.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Runs your revenue and per-state consumer counts against each applicability threshold, so you know which laws reach you before you build for them
  • Tracks GLBA and HIPAA exemptions at both entity level and data level, and flags the states where the entity-level exemption no longer exists
  • Holds the data inventory and records of processing once, then maps each element to every state law, GDPR and CCPA obligation it satisfies
  • Keeps consumer rights handling on the clock, including the differing response and appeal windows each state sets
  • Records processor and sub-processor contracts and flags the ones missing the terms a state law requires
  • Tracks universal opt-out signal handling, including Global Privacy Control, across the states that now mandate recognition
  • Surfaces where a data protection assessment is owed, which turns on the processing activity rather than on company size
  • Separates California employee and applicant data, which no other state law covers, so HR records are not quietly left out of scope
  • Shows the delta when a new state law takes effect, rather than restarting the program
DATA PRIVACY COMPLIANCE readiness_report
READINESS · 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Example report layout, not customer data

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Scope reference

Which US state privacy laws reach your business, and whether the exemption you are relying on still exists

Almost every published state privacy tracker is organized by state, which is the wrong axis for deciding what to build. The question that decides your program is what kind of organization you are, because that is what determines whether an exemption applies and how much of your data it actually covers. Two rows here contradict guidance that is still widely republished: financial institutions are no longer broadly exempt in six states, and a small business in Texas is not exempt at all once it sells sensitive data.

Your organization Which state laws reach you Does an exemption cover you What you still owe Where it goes wrong
SaaS or technology company selling nationwide Every state where you clear the threshold. Texas needs no threshold at all, so any business above SBA small business size that serves Texas residents is in scope. No sectoral exemption exists for you. Scope is decided purely by the thresholds. Data inventory, consumer rights handling with per-state deadlines, sale and targeted advertising opt-outs, universal opt-out signal recognition, processor contracts, and assessments for higher risk processing Building for California and assuming the rest follow. Texas has no threshold, Maryland and Rhode Island start at 35,000 consumers, and Maryland data minimization rule is substantively stricter than anything California requires.
Bank, credit union or other depository institution Fewer than most. An entity-level GLBA exemption still applies in the large majority of states. Usually yes, at entity level. California, Colorado, Minnesota and Oregon are the exceptions, and Connecticut now limits its exemption to depository institutions specifically. Compliance in the states with no entity-level exemption, plus GLBA and the Safeguards Rule everywhere regardless Assuming GLBA settles it nationally. It does not in California, Colorado, Minnesota or Oregon, and the trackers that say otherwise are usually out of date.
Fintech, non-depository lender or mortgage servicer More than a bank. The entity-level exemption is gone in six states, and Connecticut narrower exemption reaches depository institutions only. Only at data level in California, Colorado, Connecticut, Minnesota, Montana and Oregon. GLBA-covered data is exempt; the company is not. Full program for every non-GLBA data set: marketing lists, prospects, website analytics, and any product line outside GLBA scope Treating a GLBA exemption as a company-wide switch. Montana removed its entity-level exemption on October 1, 2025 and Connecticut narrowed its own effective July 1, 2026.
Healthcare provider, health plan or business associate Partially. HIPAA-covered entities and protected health information are exempt to varying degrees in every state. Yes for PHI, and often at entity level for covered entities. The exemption rarely reaches your marketing site, wellness apps or non-PHI consumer data. HIPAA for PHI, plus the state law for everything outside it, plus Washington My Health My Data if you touch consumer health data of Washington residents Reading a HIPAA exemption as total. Consumer health data outside HIPAA is exactly what the newer state health privacy statutes were written to reach.
Small business under the SBA size standard Texas exempts you by size. Most other states exempt you in practice by threshold rather than by an explicit small business carve-out. In Texas, yes, and only until you sell sensitive personal data. Elsewhere you are out of scope because you are under the thresholds, which is not the same thing. Consent before selling sensitive personal data in Texas regardless of size, and full compliance in any state whose threshold you cross as you grow Relying on being small. Thresholds are counted on consumers processed, so a consumer app can cross 100,000 consumers long before it is a large company.
Adtech company, data broker or publisher All of them, and earliest. Selling data triggers the lower threshold tier, commonly 25,000 consumers where more than half of revenue comes from data sales. None. Data brokers are the category these laws were written for, and several states run separate broker registration regimes on top. Everything above, plus registration where required, plus the deletion mechanisms some states now operate centrally Waiting for the 100,000 consumer threshold. If over half your revenue comes from selling data, the trigger is far lower and Florida separate regime targets large ad-funded platforms directly.
Employer with staff or applicants in California California only, for this data. No other state comprehensive privacy law covers employment context data. No. The California employee, applicant and business-to-business exemptions expired on January 1, 2023. Full consumer rights for employees, applicants and contractors: notice at collection, access, deletion, correction, and limits on sensitive data use Scoping the program to customer data. HR systems, applicant tracking and payroll hold California employee data that has carried consumer rights since 2023.

Reflects laws in force as at August 2026. Around twenty states run comprehensive consumer privacy laws, with Indiana, Kentucky and Rhode Island effective January 1, 2026; published counts vary between nineteen and twenty depending on how mid-year effective dates are treated. Thresholds, exemptions and penalty figures are amended frequently, so confirm the current text for your states with counsel. Scrutineer maps controls and maintains evidence. It does not provide legal advice, and no software can determine that you are compliant.

Good questions

Questions about data privacy compliance

Data privacy compliance software holds your data inventory, consumer rights workflows, processor contracts and risk assessments in one place, and maps each control to the privacy laws it satisfies. The useful ones do scope work as well as control work: they tell you which of the roughly twenty US state privacy laws actually apply to your business before you spend a quarter building for all of them.
Around twenty states have comprehensive consumer privacy laws in force during 2026, and published counts differ between nineteen and twenty depending on whether a law that takes effect later in the year is counted as in force. Indiana, Kentucky and Rhode Island joined on January 1, 2026. Counting sectoral laws such as biometric and health privacy statutes raises the number considerably.
It depends on where your consumers are and on each law separate threshold, not on where you are incorporated. Most states use a consumer count, commonly 100,000, with a lower tier around 25,000 if you make over half your revenue from selling data. California adds a revenue test. Texas has no threshold and exempts small businesses instead. Check state by state rather than assuming a single national trigger.
A for-profit business doing business in California is covered if it exceeds 26,625,000 dollars in annual gross revenue, or buys, sells or shares the personal information of 100,000 or more California consumers, households or devices, or derives more than half its annual revenue from selling or sharing personal information. The revenue figure is inflation adjusted by the California Privacy Protection Agency and changes periodically.
No, and this is the trap that catches the most companies. The Texas Data Privacy and Security Act has no revenue threshold and no consumer count threshold. It applies to any entity that does business in Texas or offers products or services to Texas residents and processes personal data, unless the entity is a small business under the SBA size standard for its NAICS code. That exemption disappears if you sell sensitive personal data.
Not reliably, and this is the most commonly repeated error in published guidance. All of these laws exempt data already covered by the Gramm-Leach-Bliley Act. The broader entity-level exemption that excuses the whole company is absent in California, Colorado, Connecticut, Minnesota, Montana and Oregon. Montana removed its entity-level exemption in October 2025 and Connecticut narrowed its own to depository institutions only.
An entity-level exemption puts the whole institution outside the law, whatever data it holds. A data-level exemption covers only the data that GLBA itself regulates. The difference matters most to companies with mixed business lines: under a data-level exemption, marketing lists, website analytics, prospect data and any non-GLBA product line stay fully in scope, so the compliance program cannot simply be switched off.
Maryland, on the substance. The Maryland Online Data Privacy Act limits collection to what is reasonably necessary and proportionate to provide the product the consumer asked for, which is a genuine data minimization standard rather than a notice requirement, and it is closer to GDPR than to the Virginia template every other state copied. It pairs that with a 35,000 consumer threshold and broad restrictions on sensitive data.
Only California. The CCPA exemptions for employee, applicant and business-to-business data expired on January 1, 2023, so California employees and job applicants have the same rights as consumers. Every other state comprehensive privacy law excludes data processed in an employment context. Companies that built their program around consumer data alone routinely discover their HR and recruiting systems were never in scope anywhere else, and are fully in scope in California.
It is a browser or device signal, most commonly Global Privacy Control, that tells every site a consumer visits not to sell or share their data or use it for targeted advertising. A growing set of states now require controllers to honor it rather than only offering an on-site link. Recognizing a signal approved in one state generally satisfies the others, so this is one control built once.
No, and buying per-state tooling is a common and expensive mistake. The operational work is largely shared: a data inventory, consumer rights handling, opt-out mechanics, processor contracts and risk assessments. What differs is the scope test, a handful of response deadlines and a few substantive rules such as Maryland data minimization. One program with per-state deltas is far cheaper to run than twenty programs.
It gets you most of the way and leaves real gaps. GDPR gives you the data inventory, the rights workflows and the processor contracts, which is the bulk of the effort. What it does not give you is the US-specific machinery: sale and share opt-outs, universal opt-out signal recognition, the California notice at collection, and the finance and health sector exemptions that decide whether a US law applies to you at all.
It is a documented weighing of the benefits and risks of a processing activity, required before you begin higher risk processing such as targeted advertising, selling personal data, profiling with legal or similarly significant effects, and handling sensitive data. The trigger is the activity, not your company size, so a small business that is otherwise in scope can owe assessments while a much larger one that does none of these does not.
Most states enforce through the attorney general with civil penalties per violation, often in the range of 7,500 dollars, and many still grant a cure period before action. California enforces through both the attorney general and the California Privacy Protection Agency and has no general cure right. Private lawsuits are rare under these laws, with California data breach claims the main exception. Confirm current figures for your states, since amendments are frequent.
Not for these laws. No regulator or auditor issues a CCPA certificate or a state privacy law certificate, and nobody is CCPA certified. Compliance is a continuing state you demonstrate through documented practice, not a badge you hold. ISO 27701 and the EU certification schemes are separate voluntary standards that do not discharge any US state obligation.
No. Scrutineer maps your controls, keeps evidence current, works out which laws reach you and shows where coverage is thin. Whether you are compliant is a legal conclusion that depends on facts and on counsel, and no software can issue it. We are explicit about that line rather than implying a subscription closes the obligation.

Keep reading

Guides that go deeper on privacy compliance

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification