Scrutineer · By framework
Data privacy compliance software for every US state privacy law
Around twenty US states now run comprehensive consumer privacy laws, and they are similar enough that one control set covers most of the work. The expensive part is not the controls. It is knowing which laws reach you at all.
Scrutineer holds your data inventory, your deletion and opt-out handling and your processor contracts once, then shows every regime each control satisfies and every threshold that puts you in scope.
Control-mapped findings · linked evidence · you decide what to remediate
›
Illustrative sample · not an audit attestation
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with data privacy compliance
The laws are similar. The scope tests are not.
Nearly every state after California copied the Virginia template, so the obligations converge: a data inventory, consumer rights handling, opt-outs for targeted advertising and sale, contracts with processors, and assessments for higher risk processing. What does not converge is who has to do any of it. California turns on at roughly 26.6 million dollars of gross revenue or 100,000 California consumers. Texas has no revenue or consumer threshold at all and instead exempts small businesses by SBA size standard. Florida reaches almost nobody, needing over a billion dollars in revenue plus half of it from online advertising. Maryland and Rhode Island start at 35,000 consumers with no revenue test. Scrutineer runs your revenue, your consumer counts by state and your processing activities against each test, so you prepare for the laws that actually bind you.
Your GLBA or HIPAA exemption is narrower than you think
Most published trackers still say financial institutions are exempt from state privacy law. That is no longer reliably true. Every one of these laws exempts GLBA-covered data, but the broader entity-level exemption, which excuses the whole company, is now missing in California, Colorado, Connecticut, Minnesota, Montana and Oregon. Montana removed its entity-level exemption on October 1, 2025 under SB 297. Connecticut replaced its broad exemption with one available only to depository institutions under SB 1295, with most changes effective July 1, 2026. A lender or fintech running GLBA and non-GLBA lines can no longer treat the whole business as out of scope. Scrutineer tracks the exemption at both levels and flags the data that fell outside it.
One control, mapped to every regime it satisfies
A deletion workflow that meets the CCPA also answers Virginia, Texas, Colorado and the rest, and much of it answers a GDPR erasure request too. Maintaining separate programs per state is how privacy teams end up with twenty spreadsheets and no confidence in any of them. Scrutineer maps a control once and shows every law it satisfies, so the marginal cost of the twenty-first state is the delta rather than a fresh program. Where a state genuinely diverges, which is mostly Maryland on data minimization and sensitive data, it shows up as a gap against that state rather than being averaged away.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Runs your revenue and per-state consumer counts against each applicability threshold, so you know which laws reach you before you build for them
- Tracks GLBA and HIPAA exemptions at both entity level and data level, and flags the states where the entity-level exemption no longer exists
- Holds the data inventory and records of processing once, then maps each element to every state law, GDPR and CCPA obligation it satisfies
- Keeps consumer rights handling on the clock, including the differing response and appeal windows each state sets
- Records processor and sub-processor contracts and flags the ones missing the terms a state law requires
- Tracks universal opt-out signal handling, including Global Privacy Control, across the states that now mandate recognition
- Surfaces where a data protection assessment is owed, which turns on the processing activity rather than on company size
- Separates California employee and applicant data, which no other state law covers, so HR records are not quietly left out of scope
- Shows the delta when a new state law takes effect, rather than restarting the program
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Scope reference
Which US state privacy laws reach your business, and whether the exemption you are relying on still exists
Almost every published state privacy tracker is organized by state, which is the wrong axis for deciding what to build. The question that decides your program is what kind of organization you are, because that is what determines whether an exemption applies and how much of your data it actually covers. Two rows here contradict guidance that is still widely republished: financial institutions are no longer broadly exempt in six states, and a small business in Texas is not exempt at all once it sells sensitive data.
| Your organization | Which state laws reach you | Does an exemption cover you | What you still owe | Where it goes wrong |
|---|---|---|---|---|
| SaaS or technology company selling nationwide | Every state where you clear the threshold. Texas needs no threshold at all, so any business above SBA small business size that serves Texas residents is in scope. | No sectoral exemption exists for you. Scope is decided purely by the thresholds. | Data inventory, consumer rights handling with per-state deadlines, sale and targeted advertising opt-outs, universal opt-out signal recognition, processor contracts, and assessments for higher risk processing | Building for California and assuming the rest follow. Texas has no threshold, Maryland and Rhode Island start at 35,000 consumers, and Maryland data minimization rule is substantively stricter than anything California requires. |
| Bank, credit union or other depository institution | Fewer than most. An entity-level GLBA exemption still applies in the large majority of states. | Usually yes, at entity level. California, Colorado, Minnesota and Oregon are the exceptions, and Connecticut now limits its exemption to depository institutions specifically. | Compliance in the states with no entity-level exemption, plus GLBA and the Safeguards Rule everywhere regardless | Assuming GLBA settles it nationally. It does not in California, Colorado, Minnesota or Oregon, and the trackers that say otherwise are usually out of date. |
| Fintech, non-depository lender or mortgage servicer | More than a bank. The entity-level exemption is gone in six states, and Connecticut narrower exemption reaches depository institutions only. | Only at data level in California, Colorado, Connecticut, Minnesota, Montana and Oregon. GLBA-covered data is exempt; the company is not. | Full program for every non-GLBA data set: marketing lists, prospects, website analytics, and any product line outside GLBA scope | Treating a GLBA exemption as a company-wide switch. Montana removed its entity-level exemption on October 1, 2025 and Connecticut narrowed its own effective July 1, 2026. |
| Healthcare provider, health plan or business associate | Partially. HIPAA-covered entities and protected health information are exempt to varying degrees in every state. | Yes for PHI, and often at entity level for covered entities. The exemption rarely reaches your marketing site, wellness apps or non-PHI consumer data. | HIPAA for PHI, plus the state law for everything outside it, plus Washington My Health My Data if you touch consumer health data of Washington residents | Reading a HIPAA exemption as total. Consumer health data outside HIPAA is exactly what the newer state health privacy statutes were written to reach. |
| Small business under the SBA size standard | Texas exempts you by size. Most other states exempt you in practice by threshold rather than by an explicit small business carve-out. | In Texas, yes, and only until you sell sensitive personal data. Elsewhere you are out of scope because you are under the thresholds, which is not the same thing. | Consent before selling sensitive personal data in Texas regardless of size, and full compliance in any state whose threshold you cross as you grow | Relying on being small. Thresholds are counted on consumers processed, so a consumer app can cross 100,000 consumers long before it is a large company. |
| Adtech company, data broker or publisher | All of them, and earliest. Selling data triggers the lower threshold tier, commonly 25,000 consumers where more than half of revenue comes from data sales. | None. Data brokers are the category these laws were written for, and several states run separate broker registration regimes on top. | Everything above, plus registration where required, plus the deletion mechanisms some states now operate centrally | Waiting for the 100,000 consumer threshold. If over half your revenue comes from selling data, the trigger is far lower and Florida separate regime targets large ad-funded platforms directly. |
| Employer with staff or applicants in California | California only, for this data. No other state comprehensive privacy law covers employment context data. | No. The California employee, applicant and business-to-business exemptions expired on January 1, 2023. | Full consumer rights for employees, applicants and contractors: notice at collection, access, deletion, correction, and limits on sensitive data use | Scoping the program to customer data. HR systems, applicant tracking and payroll hold California employee data that has carried consumer rights since 2023. |
Reflects laws in force as at August 2026. Around twenty states run comprehensive consumer privacy laws, with Indiana, Kentucky and Rhode Island effective January 1, 2026; published counts vary between nineteen and twenty depending on how mid-year effective dates are treated. Thresholds, exemptions and penalty figures are amended frequently, so confirm the current text for your states with counsel. Scrutineer maps controls and maintains evidence. It does not provide legal advice, and no software can determine that you are compliant.
Good questions
Questions about data privacy compliance
Keep reading
Guides that go deeper on privacy compliance
Best data privacy management software
What the privacy tooling categories actually do, where consent platforms stop, and how to tell scope work from control work before you buy.
Read the guideGDPR compliance checklist for US companies
When GDPR reaches a US business, what the representative requirement means, and which controls carry straight over to US state law.
Read the guideWhat is GLBA compliance
The Safeguards Rule, the Privacy Rule and who each one binds, which is where the state privacy exemption question starts.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification