US State Law United States

Sensitive Data Consent Rules: State-by-State Guide

How US state privacy laws define sensitive data differently, where opt-in consent is required, Maryland's sale ban, inferred data, and building one national consent flow.

Regulation

Sensitive-data provisions of comprehensive state privacy laws (2023-2026)

Max Penalty

$2,500 to $20,000 per violation depending on state; sensitive-data violations feature in CPPA and Texas AG actions

Enforcing Authority

State attorneys general; California CPPA

Official Source

cppa.ca.gov

Executive Summary

  • Every comprehensive state law treats a core set of categories, race/ethnicity, religion, health, sexual orientation, genetic and biometric data, children's data, precise geolocation, as sensitive, but the handling models split: opt-in consent (most states), opt-out/limit rights (California, Utah, Iowa), and outright sale bans (Maryland).
  • The definitional edges diverge: New Jersey adds financial account data, Oregon adds crime-victim and transgender/nonbinary status, several states add immigration or national-origin status, and health-specific laws like Washington's My Health My Data sweep in inferences.
  • Inferred sensitive attributes count: a segment labeled 'diabetes interest' or 'LGBTQ+ audience' is sensitive data in the consent states even if no diagnosis or declaration was ever collected.
  • Precise geolocation (typically a 1,750-foot radius) is the sensitive category most businesses process without realizing it, through mobile SDKs, store locators, and ad platforms.
  • The maintainable architecture is one opt-in consent flow built to the union of all state lists, with California's 'Limit the Use of My Sensitive Personal Information' link layered on top.

Sensitive data is where the state laws stop being harmonizable by paperwork. The categories differ, the handling models differ (consent, limit, ban), and the definitions reach inferences your ad stack generates automatically. The enforcement record, CPPA orders on SPI, the Texas location suits, Washington’s health-data class actions, shows regulators treat sensitive-data violations as the aggravated tier. One union-list consent architecture, plus honest minimization, is the only design that survives all twenty states.

Inventory by category, including inferences. Map declared data (forms, health fields), collected data (geolocation SDKs, biometrics), and derived data (segments, scores) against the union of state lists, California’s SPI categories plus the Virginia-lineage additions. The derived column is where audits find surprises.

Choose minimization before consent. Every category you stop collecting removes a consent flow, a Maryland problem, and a breach liability. Precision truncation for location, segment-taxonomy pruning, and retention limits do more than any banner.

Build one opt-in flow, layered for California. Affirmative, granular, revocable consent for the opt-in states; the limit-use link for California; notice language covering Utah and Iowa. Dark-pattern review is mandatory, Connecticut and Colorado void tainted consent.

Handle the special regimes separately. Children’s data follows the COPPA-plus state stack; health data outside HIPAA answers to Washington’s My Health My Data and its private right of action (see the HIPAA boundary guide); biometrics add BIPA’s litigation exposure.

Keep evidence. Consent records, assessment documentation (sensitive processing triggers assessments everywhere), and the audit trail regulators request first.

Sensitive-data leaks are usually visible in the tracker layer, health pages firing ad pixels, location SDKs in the tag manager: find yours with a free scan.

Frequently Asked Questions

Which states require opt-in consent versus opt-out?

Opt-in consent before processing: Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Delaware, New Hampshire, New Jersey, Tennessee, Minnesota, Nebraska, Indiana, Kentucky, and the rest of the Virginia lineage. Opt-out models: California (right to limit use and disclosure of SPI via a dedicated link), Utah and Iowa (notice plus opportunity to opt out). The outlier: Maryland prohibits selling sensitive data entirely and permits collection only when strictly necessary for a requested service, consent cannot cure a Maryland violation.

What does valid consent look like in the opt-in states?

A clear affirmative act, freely given, specific, informed, and unambiguous: an unchecked box or explicit toggle tied to a plain-language description of the sensitive categories and purposes. Not valid: pre-checked boxes, consent bundled into terms of service, dark-pattern flows (Connecticut and Colorado expressly void consent obtained through them), or continued browsing. Colorado's rules add revocation as easy as granting, and consent refreshes when purposes change.

How do inferences become sensitive data?

Most definitions cover data 'revealing' the protected attribute, and regulators read that functionally: ad segments, health-condition audiences, purchase histories indicating religion or sexuality, and profiling outputs all reveal. California's CPPA has flagged inference-based SPI in enforcement, and Washington's My Health My Data defines consumer health data to include inferences and biometric-derived health signals, with a private right of action attached. Segment taxonomies are the place to audit first.

What are the geolocation traps?

Precise geolocation (usually within 1,750 feet) is sensitive nearly everywhere, and it enters through infrastructure: mobile SDKs collecting lat/long for ads or analytics, store-locator features retaining coordinates, and location-based push. The Texas AG's Allstate/Arity suit and the FTC's data-broker actions (X-Mode, InMarket) both center on location. Coarse location (city, ZIP) is generally not sensitive; truncating precision at collection is the cheapest compliance fix available.

How should one national consent flow handle all this?

Build to the union: one consent surface covering every state's categories (including New Jersey's financial data and Oregon's additions), triggered before any sensitive processing, with granular purpose descriptions, easy revocation, and consent records retained as evidence. Layer California's limit-use link for SPI, and treat Maryland's strictly-necessary standard as a data-minimization gate: if a sensitive category is not needed for the service, stop collecting it rather than papering it, minimization beats consent management.

Regulatory Crosswalk

GDPR Article 9CCPA/CPRA SPIWashington My Health My Data

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.