Twenty state laws, one program: the arithmetic only works if the program is designed as a baseline plus configuration, not as twenty parallel efforts. The baseline is set by four anchor states whose requirements subsume the rest; the configuration layer handles the short list of genuine one-offs. Done this way, the twenty-first law is an afternoon’s gap analysis rather than a project.
Building the baseline
Set the spec from the anchors. California contributes the opt-out machinery and documentation depth, Colorado the consent and UOOM standards, Oregon the narrow-exemption scoping and recipient lists, Texas the assume-coverage posture. The comparison matrix shows why these four dominate.
Unify the operational layers. One DSAR intake routing all states; one sensitive-data consent flow built to the union list; one assessment template at Colorado/CPPA depth; one contract rider merging CCPA service-provider terms with Virginia-lineage processor duties.
Isolate the deltas. Verbatim notices, broker registrations, Maryland’s minimization rules, and children’s provisions live in a per-state configuration register with owners and effective dates, reviewed on the two-checkpoint calendar.
Audit what enforcers sample. The enforcement tracker shows sweeps start with the public surface: opt-out links, signal handling, notice-versus-practice consistency. The cure tracker shows why fixing findings before the letter matters more each year.
Start where the sweeps start: check your visible compliance surface with a free scan, or talk to BD Emerson about standing up the baseline.