Home
MTCDPA Montana and Cookies: All you need to know

MTCDPA Montana and Cookies: All you need to know

1 year ago
João Bruno Soares
1 minute

Montana's MTCDPA: Does It Apply to Your Website and Cookies?


Deciphering whether a new data privacy law applies to your business can feel like trying to solve a puzzle.

The Montana Consumer Data Privacy Act (MTCDPA) is no different, but it lays out clear rules. Let's break down exactly who needs to comply, the important deadlines, and who is exempt.



Who Must Comply: The Thresholds for Montana Businesses


Think of the MTCDPA's requirements as a checklist. If your business checks just one of the following two boxes, you need to bring your data handling practices into compliance.


The law applies to any company that conducts business in Montana or produces products or services targeted to Montana residents and:

  1. Controls or processes the personal data of at least 50,000 consumers.
  2. Controls or processes the personal data of at least 25,000 consumers and derives more than 25% of its gross revenue from the "sale" of personal data.

Let's quickly define those terms. A "consumer" here is simply a resident of Montana. "Personal data" is any information that can be linked to an identifiable person—from an email address to browsing history collected by cookies.

A "sale" isn't just a direct cash transaction; it's the exchange of personal data for money or "other valuable consideration."

This broad definition means many common digital marketing practices could be considered a sale.

Unlike some other state laws, Montana's act doesn't have a revenue threshold.

A small business could easily meet the 50,000-consumer mark, making it crucial not to ignore privacy regulations based on your company's size alone.

The focus is on the volume and use of data you handle.




Key Dates: When Does the MTCDPA Take Effect?


Mark your calendars. The Montana Consumer Data privacy Act goes into full effect on October 1, 2024.


This is the hard deadline by which your business must be fully compliant.

That means your ideal privacy policy should be updated, your mechanisms for handling consumer rights requests must be operational, and your cookie banner must function correctly.


There's a second key date to be aware of: January 1, 2025. By this date, businesses must recognize universal opt-out mechanisms.

This is a technical standard that allows users to signal their privacy preferences across all websites they visit through their browser settings, often known as the Global Privacy Control (GPC).

Getting this right requires a robust technical solution, which is where a certified CMP can be invaluable.




Exemptions: Who Is Off the Hook?


Not every organization is covered by the MTCDPA.

The law carves out several exemptions, largely to avoid creating redundant rules for industries that are already heavily regulated.

The following types of entities are generally exempt from the MTCDPA:

  • Government bodies and state agencies
  • Nonprofit organizations
  • Institutions of higher education
  • Financial institutions and data subject to the Gramm-Leach-Bliley Act (GLBA)
  • Covered entities and business associates governed by the Health Insurance Portability and Accountability Act (HIPAA)

Additionally, the law doesn't apply to certain types of data, such as health records governed by HIPAA or personal information used in an employment context (e.g., employee data).

For most for-profit businesses that meet the thresholds mentioned earlier, however, compliance will be mandatory.




The New Rules for Website Cookies & Consent: Opt-Out Explained


Montana's approach to consent fundamentally changes how your website can interact with visitor data.

Unlike the strict "opt-in" model of Europe's GDPR for cookies, the MTCDPA primarily uses an "opt-out" framework. Understanding this distinction is the key to compliance.



"Opt-Out" Model: What It Means for Your Cookie Banner


In an "opt-out" system, you can collect and process most types of personal data by default, but you must give consumers a clear and easy way to say "no."


Think of it this way: under this model, you don't have to ask for permission before placing most marketing or analytics cookies.

However, your visitors have the absolute right to refuse them.

Your responsibility is to make that choice readily available. This is where the modern cookie notice/banner becomes essential.

It’s no longer just a passive notice; it’s an active rights-management tool.

Your website’s banner must provide a conspicuous link for users to opt out of the sale of their data and targeted advertising.

The operation behind this banner needs to be robust, ensuring that when a user opts out, the corresponding scripts and tags are actually disabled.




Sensitive Data: When You Absolutely Need "Opt-In" Consent


The "opt-out" rule has one very important exception: sensitive data.

For this specific category of information, you must get explicit, affirmative consent before you collect or process it. This is known as an "opt-in" model.

Sensitive data under the MTCDPA includes information that reveals:

  • Racial or ethnic origin
  • Religious beliefs
  • A mental or physical health diagnosis
  • Sexual orientation or citizenship status
  • Genetic or biometric data used for identification
  • Precise geolocation data
  • Personal data from a known child (under 13)

For this information, silence does not equal consent. You must ask for a clear "yes" from the user.

This requires a much more specific function from your consent tool than a standard opt-out banner.

A comprehensive CMP is designed to handle these different legal basis requirements seamlessly.



Special Protections for Minors (Under 16): A Stricter Standard


The MTCDPA provides heightened protections for young people, creating a two-tiered system that businesses must respect.

  • For children under 13: The law aligns with the federal Children’s Online Privacy Protection Act (COPPA).

  • You must obtain verifiable consent from a parent or guardian before collecting any personal data from a known child.

  • This is a strict parental opt-in.

  • For minors between 13 and 16: This is a key difference from many other state laws.

  • You must obtain the minor's own "opt-in" consent before selling their personal data or using it for targeted advertising.

The operational challenge here is knowing a visitor's age.

This difficulty underscores the importance of adopting a "privacy by default" approach, a core principle of Privacy by Design, to minimize data collection risks.




Defining "Sale of Data" and "Targeted Advertising"


Since opting out of these two activities is a core consumer right, it's vital to understand what they mean in practical terms.

  • Targeted Advertising: This is defined as displaying ads to a consumer based on their personal data obtained from their activities over time and across non-affiliated websites.

  • In short, it’s the technology that makes ads "follow" you from site to site.

  • Sale of Personal Data: This isn't just selling a customer list for cash. The MTCDPA defines it as "the exchange of personal data for monetary or other valuable consideration."

  • This broad language can cover many common data-sharing agreements in the digital marketing ecosystem that provide a mutual benefit to the parties involved.

Understanding what you need is the first step when thinking about how to choose a CMP for your business.




Your 4-Step Action Plan for MTCDPA Cookie Compliance


Achieving compliance with a new privacy law can feel like a major project, but it doesn't have to be overwhelming.

By breaking it down into a clear, manageable action plan, you can ensure your website and business practices are ready. Here are four essential steps to take.




Step 1: Update Your Privacy Policy


Your privacy policy is the cornerstone of your transparency with customers.

It's the single most important document for explaining your data practices in plain language.

Under the MTCDPA, your privacy policy must be updated to clearly state:

  • The categories of personal data you collect (e.g., names, emails, cookie data).

  • Your purpose for processing that data.

  • The categories of data you share with or sell to third parties.

  • The rights consumers have under the new law (access, correction, deletion, opt-out).

  • Clear instructions on how consumers can exercise those rights.

Take the time to review your current policy. Is it easy to understand?

Does it accurately reflect all your data collection activities, including those from analytics and advertising cookies?

Creating the ideal privacy policy is about clarity and honesty, not just legal jargon.




Step 2: Implement a Compliant Cookie Management Tool


A policy is a promise; a consent management tool is how you keep it.

To comply with the MTCDPA's opt-out requirements, you need a technical solution that can manage user preferences and control the behavior of cookies and trackers on your site.


This is where a Consent Management Platform (CMP) becomes critical.

A professional CMP does much more than a basic WordPress cookie plugin. It handles the entire lifecycle of consent by:


  • Displaying a clear and compliant cookie banner.

  • Providing users with an easy-to-access way to opt out of targeted advertising and the sale of their data.

  • Automatically blocking or allowing tracking tags based on the user's choice.

  • Recording consent choices to provide an audit trail for your business.

Choosing a Google-certified CMP like AdOpt ensures the technical operation of your consent mechanism is robust and aligned with industry standards and legal requirements.




Step 3: Prepare for Consumer Rights Requests (DSRs)


The MTCDPA empowers consumers to take control of their data.

As a business, you must be ready to respond to their requests, often called Data Subject Requests or DSRs.

You need a reliable internal process for handling requests to:

  • Access: "Show me the personal data you have about me."

  • Correct: "Please fix the inaccurate information you hold on me."

  • Delete: "Erase my personal data from your systems."

  • Opt-Out: "Stop using my data for targeted ads or selling it."

To do this effectively, you need to know what data you have and where it is. This is why conducting a data mapping exercise is a foundational step.

You should also designate a person or team, like a Data Protection Officer, to oversee this process and ensure requests are handled within the legally required 45-day timeframe.




Step 4: Conduct a Data Protection Assessment


For certain activities, the MTCDPA requires you to perform a "Data Protection Assessment" (DPA).

Think of this as a formal risk assessment that you document internally.

You are required to conduct a DPA for processing activities that present a "heightened risk of harm" to a consumer.

Under the law, this includes:

  • Processing personal data for targeted advertising.

  • Selling personal data.

  • Processing sensitive data.

  • Using personal data for profiling that could produce significant legal or financial effects.

The assessment involves weighing the benefits of your data processing against the potential risks to consumer privacy and outlining the steps you're taking to mitigate those risks.

It’s a practical exercise in applying the principles of Privacy by Design and demonstrates that you are proactively managing your data responsibilities.



Consumer Rights You Must Honor Under the MTCDPA


The Montana Consumer Data Privacy Act is built on a foundation of consumer empowerment.

It grants Montana residents a specific set of rights to control their personal data, and it places a legal duty on your business to honor those rights promptly and efficiently.

Understanding these rights is fundamental to your compliance strategy.




Right to Access and Correct


Think of this as the right to "see and fix."

Consumers can ask you to confirm whether you are processing their data and request a copy of the exact personal information you hold about them.

If they find that information is inaccurate—a misspelled name, an old address—they have the right to request a correction.

For your business, this means you need to have a clear view of your data.

Fulfilling an access request is only possible if you’ve done the work of data mapping to know exactly what customer data you store and where you store it.




Right to Delete


This is the consumer's right to be forgotten.

A Montana resident can request that you erase the personal data you have collected from them.

This is one of the most significant rights and requires a robust internal process to execute properly.

When you receive a deletion request, you must remove that individual's personal data from your systems, from your CRM to your email marketing lists.

While there are some exceptions (for example, if you need the data to complete a transaction or comply with another legal obligation), the default expectation is deletion.




Right to Portability


The right to portability is the right for a consumer to take their data with them.

Upon request, you must provide them with a copy of their personal data in a common, easily usable, and machine-readable format (like a CSV file).

A simple analogy is getting your medical records from an old doctor to give to a new one.

The file must be structured and portable. This right ensures that consumers aren't locked into a service simply because their data is.

For your business, this requires the technical ability to export an individual's data cleanly from your systems.




Right to Opt-Out of Sale, Profiling, and Targeted Ads


This is the central right that directly impacts your website's use of cookies and your digital marketing efforts.

Consumers can direct your business to stop processing their data for three specific purposes:

  1. Sale of Personal Data: As a reminder, this is broadly defined as exchanging data for money or other valuable benefits.

  2. Targeted Advertising: Using data collected from a person’s activity across different websites to serve them personalized ads.

  3. Profiling: Any automated decision-making that has a legal or similarly significant effect on the consumer.

To honor these opt-out rights, especially for targeted advertising, you need a technical solution.

When a user opts out, your website must automatically disable the advertising tags and cookies.

This is precisely what a Consent Management Platform (CMP) is designed to do, making it an essential tool for MTCDPA compliance.

Knowing how to choose a CMP is a critical step in preparing your business.




What Happens If You Don't Comply? Enforcement and the Cure Period


Understanding the rules is half the battle; knowing the consequences of breaking them is the other half.

The Montana Consumer Data Privacy Act (MTCDPA) lays out a specific process for enforcement that every business should be aware of.

While it offers some initial flexibility, ignoring your privacy obligations is not a viable strategy.




The Attorney General's Role in Enforcement


Unlike some privacy laws, the MTCDPA does not allow for a "private right of action."

In simple terms, this means individual consumers cannot sue your business directly for a violation.

Instead, the Montana Attorney General has the sole and exclusive authority to enforce the law.

If a consumer believes a business has violated their rights, they can file a complaint with the Attorney General's office.

The AG's office will then review the complaint and decide whether to investigate and take action on behalf of the state.

While this may seem less direct, an official investigation from the state's top law enforcement office is a serious matter that can consume significant time and resources.




Understanding the 60-Day "Cure Period" (And Its 2026 Deadline)


The MTCDPA includes a business-friendly feature called a "right to cure," but it comes with an expiration date.


If the Attorney General determines that your business is in violation, they will provide you with a written notice.

From the moment you receive that notice, you have 60 days to "cure" the violation.

This means you must fix the issue and provide the Attorney General's office with a written statement confirming that the violation has been resolved and that you've put measures in place to prevent it from happening again.


However, this safety net is temporary. This right to cure expires on April 1, 2026.

After that date, the Attorney General is no longer required to offer a 60-day warning and can proceed directly to an enforcement action.

It’s crucial to treat compliance as a day-one priority, not something to be fixed only after you get caught.




Are There Fines Under the MTCDPA?


This is the question on every business owner's mind.

Interestingly, the MTCDPA does not specify exact dollar amounts for fines in the way that laws like the GDPR do.


However, a lack of a specific fine schedule does not mean there are no financial consequences.

If a business fails to cure a violation within the 60-day period (or if a violation occurs after the cure period expires), the Attorney General is authorized to bring a legal action against the company.

This action could result in a court-ordered injunction, forcing you to change your data practices, and could include civil penalties deemed appropriate by the court.


The key takeaway is that the financial and operational risks are real.

The most effective way to avoid penalties is to build a proactive compliance framework with a clear privacy policy and the right technology, like a professional CMP, to manage your obligations correctly from the start.




Frequently Asked Questions


When does the Montana Consumer Data Privacy Act go into effect?


The MTCDPA takes effect on October 1, 2024. Businesses have an additional deadline of January 1, 2025, to recognize universal opt-out signals like the Global Privacy Control (GPC).




Does my business need to comply with the MTCDPA?

Your business must comply if it operates in Montana or targets its residents and meets one of two conditions:

  • It controls or processes the personal data of at least 50,000 consumers.

  • It controls or processes the personal data of at least 25,000 consumers and derives over 25% of its gross revenue from selling personal data.




What is considered "sensitive data" under the MTCDPA?


Sensitive data is personal information that requires higher protection. Under the MTCDPA, this includes data revealing:

  • Racial or ethnic origin

  • Religious beliefs

  • A mental or physical health diagnosis

  • Sexual orientation or citizenship status

  • Genetic or biometric data

  • Precise geolocation data

  • Personal data from a known child under 13




How long does my business have to respond to consumer rights requests?


You have 45 days to respond to a consumer's request.

This period can be extended once by an additional 45 days when reasonably necessary, as long as you inform the consumer of the extension.




What happens if my business violates the MTCDPA?


The Montana Attorney General has the sole authority to enforce the law.

Initially, businesses are given a 60-day "cure period" to fix any violations. This grace period, however, expires on April 1, 2026.

After that date, or if a violation isn't fixed, the Attorney General can take legal action. The law does not specify exact fine amounts.




Do I need explicit consent to process sensitive data?


Yes. The MTCDPA requires you to obtain clear, affirmative "opt-in" consent from a consumer before you can collect or process any of their sensitive personal data.




Do I need to recognize Global Privacy Control (GPC)?


Yes. By January 1, 2025, your website must be able to recognize and honor universal opt-out mechanisms like the GPC, which allow users to signal their privacy choices through their browser settings.




Are there exemptions to the MTCDPA?


Yes. The law exempts certain types of entities and data, including:

  • Government agencies

  • Non-profit organizations

  • Institutions of higher education

  • Financial institutions covered by the Gramm-Leach-Bliley Act

  • Entities subject to federal health privacy law (HIPAA)


Platforms like AdOpt help you comply without complicating your site.


Schedule your call

The MTCDPA in practice: the three documents

Compliance with the MTCDPA rests on three documents that have to agree with each other: the cookies policy, which declares every tracker and its purpose; the privacy policy, which explains what you do with the data; and the privacy portal, where the consumer exercises their rights and you keep the record of it.

Tags

Privacy Policy
Cookie Banner

Related posts

AdOpt post

Why are cookie banners everywhere?

Want to understand why there are cookie banners on every website you visit today? This article is for you!

AdOpt post

How long can we ignore LGPD?

LGPD is in effect. Despite that, there are still many companies ignoring it, but is that possible? How long can we ignore LGPD?

AdOpt post

What is the ideal privacy policy for your company?

Is there an ideal and _foolproof_ Privacy Policy? This is one of the most difficult questions to answer nowadays. Especially considering all the jurisprudence already established in Europe with the GDPR, the extensive history of cases, and the numerous tips we see in the market. Not to mention the judicial decisions that are already emerging in Brazil with the LGPD.

AdOpt post

The Impact of Cookie Banners on Your E-commerce - LGPD

Having a cookie banner on your brand's website has become indispensable for many. However, for e-commerce websites, it has practically become an obligation to have one. This is because this type of website has a technological composition in which cookies are a structural part. Login flow, items in the shopping cart, recommendation showcases, remarketing... Most of them rely on cookies.

AdOpt post

What are Terms of Use and their importance for the LGPD?

Ignoring Terms of Use and their significance within a website, particularly now with LGPD, is a common mistake that both consumers and website owners frequently commit.

AdOpt post

How does a cookie banner operate?

Here is a step-by-step explanation of how consent registration works in AdOpt.

AdOpt post

ROPA in LGPD? Get to Know the Records of Processing Activities.

Brazilian LGPD - General Data Protection Law brought with it several acronyms and specific terms. Many of them are imported from other countries and regulations. One of them is ROPA (Record Of Processing Activities), adapted in Brazil to Registros das Atividades de Tratamento. An essential document for any DPO, Data Processor.

AdOpt post

What is a privacy policy?

A privacy policy is a document that outlines how an organization collects, uses, discloses, and manages a customer's data. It's essential for building trust with users and complying with legal requirements. However, if you're not familiar with it, don't worry as we're here to help you.

AdOpt post

We've created a cookie banner plugin.

The WordPress platform powers nearly 450 million websites globally, and it's estimated that 50% of Brazilian websites are on this platform. We are ready to help you, WP lovers!

AdOpt post

How to Choose a CMP (Consent Management Platform)?

Using a CMP (Consent Management Platform) is a great way to make efforts to adapt to new privacy regulations like GDPR, LGPD, DPDPA, CCPA and more...

AdOpt post

Why Give Consent on Every Website I Visit?

Have you ever noticed that every time you sign up for a service to access information or register on a website for purchases, you need to give consent? If you're wondering why you have to give consent on every website you visit, you'll find the answer here.

AdOpt post

Colorado CPA and Cookies: All You Need to Know

The Colorado Consumer Privacy Act went into effect July 1, 2023 (CPA). CPA is a vital piece of legislation designed to protect the privacy of residents in Colorado. Understanding its requirements is essential for any business operating in the state. This act is all about giving control back to the consumers regarding their personal data. But what does this mean for you and your business, especially when it comes to managing cookies on your website?

AdOpt post

5 Signs Your Website Needs an Cookie Consent Strategy

How does your website handle LGPD? What strategies does it use to comply with the General Data Protection Law? Have you thought about using a cookie notice but don't know if your site has cookies or if it's enough? If you can't answer these questions, be cautious! Your page may be exposed to fines and other sanctions.

AdOpt post

Texas TDPSA and Cookies: All You Need to Know

Your website have users accessing from Texas? So be ready… the Texas Data Privacy and Security Act is here to shake things up. Don't worry; we've got your back. This guide will walk you through everything you need to know to ensure your website complies with the new regulations.

AdOpt post

GDPR and Cookies all you need to know

Understanding the General Data Protection Regulation (GDPR) and its impact on cookies is essential. So, let's break it down, step by step.

AdOpt post

Florida FDBR and Cookies: All You Need to Know

Everything you need to know about the Florida Digital Bill of Rights (FDBR): who must comply, the $1 billion threshold, 7 consumer rights, FIPA vs FDBR explained, penalties, and cookies.

AdOpt post

Oregon OCPA and Cookies: All You Need to Know

Everything about the Oregon OCPA: who must comply, the payment transaction exclusion, 25% revenue threshold, derived data in scope, GPC requirement from January 2026, and elimination of the cure period.

AdOpt post

Google Consent Mode: Beginner to Advanced Guide.

Google Consent Mode (GCM) is nothing more than a way for you to integrate the consent you collect from your visitors into Google technologies. In this way, upon receiving this consent information, collection can only occur with authorization, thus complying with the legislation and having direct evidence of compliance as defense for both you and Google.

AdOpt post

Connecticut CTDPA and Cookies: All You Need to Know

The Connecticut Data Privacy Act (CTDPA) is a state regulation designed to protect the privacy of Connecticut residents. It also regards cookies, so in this article we will help you understand all about this new privacy regulation.

5 Common Cookie Consent Mistakes Hurting Your Compliance

Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.

AdOpt post

California CCPA and Cookies: All You Need to Know

Everything about the California CCPA and CPRA: who must comply, the $25M threshold, 7 consumer rights, CCPA vs CPRA explained, the Do Not Sell link, CPPA enforcement, and cookies.

AdOpt post

California CPRA and Cookies: All you need to know

California CPRA explained: CCPA vs CPRA timeline and key differences, sensitive personal information, sharing of data, CPPA enforcement, GPC requirement, and tripled penalties for minors.

AdOpt post

Tennessee TIPA and Cookies: All You Need to Know

If you're looking to understand how this law impacts businesses in Tennessee, especially those dealing with digital cookies, you're in the right place. This article will simplify the complexities of compliance and make them easy to grasp, even if you're just starting to learn about data privacy.

AdOpt post

IOWA ICDPA and Cookies: All you need to Know

Iowa ICDPA explained: the longest response deadline of all US state privacy laws (90 days), 90-day cure period, opt-out for sensitive data, limited deletion scope, no right to correct, and how it compares to UCPA, VCDPA, and OCPA.

AdOpt post

Texas TDPSA: Under the DSAR

Brings a new era of consumer rights—and at the heart of it is the Data Subject Access Request (DSAR). This article is your go-to guide for understanding what a DSAR is, how to handle it properly, and why your business needs a streamlined process to stay compliant and build trust with Texas consumers.

AdOpt post

California CPRA: Cookies Policy

What the California CPRA requires from your Cookies Policy: the sharing concept, GPC as valid opt-out, Do Not Sell or Share link, SPI geolocation, minor protections, and retention periods.

AdOpt post

New Hampshire NHDPA and Cookies: All you need to know

Discover what the New Hampshire Privacy Act (NHDPA) means for your business. Learn about compliance steps, consumer rights, penalties, and how to simplify it all with AdOpt, a Google-certified CMP.

AdOpt post

Virginia VCDPA and Cookies: All you need to know

Everything you need to know about the Virginia Consumer Data Protection Act (VCDPA): who must comply, consumer rights, cookie requirements, penalties, and how to get your site in compliance.

AdOpt post

California CPRA: Privacy Policy

What the California CPRA requires from your Privacy Policy: SPI category, two mandatory links, data retention periods, sharing disclosure, right to correct, GPC, and minor protections.

AdOpt post

Utah UCPA and Cookies: All you need to know

Utah UCPA explained: the most business-friendly US state privacy law, dual threshold requirement, opt-out for sensitive data, no right to correct, guaranteed 30-day cure period, and key differences from other state laws.

AdOpt post

Montana MTCDPA: DSAR Policy

Rights, Policy and how to understand about the DSAR Montana MTCDPA

AdOpt post

AdOpt CMP

AdOpt CMP: Google-certified consent platform with prior blocking, granular choices, encrypted logs, and GTM/Consent Mode

AdOpt post

How to choose a Cookie Banner for your website

What are the criteria for this choice, and what are the strengths and weaknesses of each option? Well, we're here to help you because this decision needs to be well thought out!

AdOpt post

Tenesse TIPA: Privacy Policy

Learn what your TIPA Privacy Policy must include to comply with the Tennessee Information Protection Act from consumer rights and targeted advertising disclosures to the NIST affirmative defense, appeal mechanisms, and how to keep your notice aligned with your operational program.

AdOpt post

Montana MTCDPA: Privacy Policy

Learn what your MTCDPA Privacy Policy must include after Montana's SB 297 amendments from the conspicuous "privacy" hyperlink and last-updated date requirements to sale disclosures, minor protections, and how to keep your notice operationally aligned with your stack.

AdOpt post

Florida FDBR: Cookies Policy

What the Florida FDBR requires from your Cookies Policy: targeted advertising across affiliated sites, opt-out for sensitive data and voice recognition, dark patterns, and tripled penalties.

AdOpt post

Texas TDPSA: Privacy Policy

The Texas Data Privacy and Security Act (TDPSA) introduces sweeping changes to how businesses collect, use, and disclose personal data—and your privacy policy is now a frontline compliance tool. This article is a comprehensive guide for any company serving Texas residents, explaining how to align your privacy practices with the new legal standards.

AdOpt post

Tenesse TIPA: DSAR Privacy Portal

Learn how to build a TIPA-compliant Privacy Portal for Tennessee. Understand DSAR deadlines, consumer rights, opt-out mechanisms, and the affirmative defense that sets TIPA apart from every other US state privacy law.

AdOpt post

New Hampshire NHDPA: Privacy Policy

Learn what your Privacy Policy must contain under the NHDPA. We break down the 8 mandatory elements and how to comply with New Hampshire's data privacy law.

AdOpt post

New Hampshire NHDPA: Cookies Policy

Cookies Policy under NHDPA explained. Discover what's mandatory, dark patterns to avoid, and how to implement legal cookie consent.

AdOpt post

New Hampshire NHDPA: DSAR Privacy Portal

What is a DSAR under NHDPA? Complete guide to consumer rights, response deadlines, and building a compliant Privacy Portal for your site.

AdOpt post

Virginia VCDPA: Privacy Policy

What the Virginia VCDPA requires from your Privacy Policy: the 5 mandatory content categories, sensitive data obligations, targeted advertising disclosure, and the appeal process explained.

AdOpt post

Virginia VCDPA: Cookies Policy

What the Virginia VCDPA requires from your Cookies Policy: targeted advertising disclosure, consent standards, tracker categories, opt-out mechanisms, and the 30-day cure period explained.

AdOpt post

Virginia VCDPA: DSAR Privacy Portal

How to handle DSARs under the Virginia VCDPA: consumer rights, 45-day response deadlines, the appeal process, free requests twice per year, and how to build a compliant Privacy Portal.

AdOpt post

Florida FDBR: Privacy Policy

What the Florida FDBR requires from your Privacy Policy: annual updates, 6 mandatory content categories, specific notices for sensitive and biometric data sales, and the 7 consumer rights.

AdOpt logoAdOpt logo

Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819

15 Rue du Général Campredon, 34000 Montpellier, France

207 Rue de Bercy, 75012 Paris, France

EIN: 86-3965064

Phone: +1 (407) 768-3792

AdOpt

Resources

Product

Certifications

Google CMP PartnerIAB Europe TCF Registered Vendor

© GO ADOPT, LLC since 2020 - Made by people who love🍪