Sensitive data is where the state laws stop being harmonizable by paperwork. The categories differ, the handling models differ (consent, limit, ban), and the definitions reach inferences your ad stack generates automatically. The enforcement record, CPPA orders on SPI, the Texas location suits, Washington’s health-data class actions, shows regulators treat sensitive-data violations as the aggravated tier. One union-list consent architecture, plus honest minimization, is the only design that survives all twenty states.
Designing the consent architecture
Inventory by category, including inferences. Map declared data (forms, health fields), collected data (geolocation SDKs, biometrics), and derived data (segments, scores) against the union of state lists, California’s SPI categories plus the Virginia-lineage additions. The derived column is where audits find surprises.
Choose minimization before consent. Every category you stop collecting removes a consent flow, a Maryland problem, and a breach liability. Precision truncation for location, segment-taxonomy pruning, and retention limits do more than any banner.
Build one opt-in flow, layered for California. Affirmative, granular, revocable consent for the opt-in states; the limit-use link for California; notice language covering Utah and Iowa. Dark-pattern review is mandatory, Connecticut and Colorado void tainted consent.
Handle the special regimes separately. Children’s data follows the COPPA-plus state stack; health data outside HIPAA answers to Washington’s My Health My Data and its private right of action (see the HIPAA boundary guide); biometrics add BIPA’s litigation exposure.
Keep evidence. Consent records, assessment documentation (sensitive processing triggers assessments everywhere), and the audit trail regulators request first.
Sensitive-data leaks are usually visible in the tracker layer, health pages firing ad pixels, location SDKs in the tag manager: find yours with a free scan.