Generate state-compliant privacy impact assessment templates for US state privacy laws. Identify DPIA triggers, assess risk levels, and download pre-filled PIA templates for each state where you operate.
Select all states where you collect or process personal data from consumers.
Last verified: June 23, 2026
A data privacy impact assessment template is a written benefits-vs-risks record for high-risk processing. In 2026, the most common US state-law triggers are targeted advertising, sale of personal data, sensitive-data processing, high-risk profiling, children's data, and California ADMT use.
Processing purpose, data recipients, opt-out method, and benefits-vs-risks rationale
Virginia VCDPA and Colorado CPA both treat these activities as DPA triggers.
Sensitive-category inventory, consent basis, minimization controls, and retention limit
Colorado AG guidance lists sensitive-data processing as a required assessment scenario.
Decision logic, affected rights, foreseeable harms, safeguards, and human-review path
California risk-assessment and ADMT rules add 2026-2027 compliance dates.
Age signal, service purpose, data categories, parental-consent path, and minor-specific safeguards
Virginia Code section 59.1-580 calls out known children online services, products, and features.
Keep one record per processing activity: purpose, data categories, sources, recipients, processor roles, retention, safeguards, benefits, consumer risks, residual-risk approval, and review date. Virginia expressly allows one assessment to cover comparable processing operations with similar activities, so grouped templates should still explain why the activities are comparable.
Sources checked date_retrieved 2026-06-23: Virginia Code section 59.1-580, Colorado Attorney General CPA guidance, and CalPrivacy risk assessment and ADMT regulations announcement.