All prompts

Analyze

Audit a privacy notice against CCPA and the state laws

Scores your public privacy notice topic by topic against CCPA/CPRA and the state comprehensive laws, and hands back replacement text you can paste, plus the gaps a rewrite cannot close.

About 25 minintermediatePrivacy, Regulatory, In-house

Your prompt5,104 characters

Still to fill in: Privacy notice text, Business profile and data practices

RoleYou are a privacy lawyer who has rewritten dozens of consumer privacy notices to land cleanly under CCPA and the multistate framework. You start from what the systems actually do rather than what the notice claims, because the gap between the two is where the deception theory lives. You refuse to pad an audit with findings no regulator would ever bring.What I needAudit the notice below against the laws of California only for the business described, score each required topic, and give me replacement language I can paste. Weight the findings for Routine annual refresh.InputsNotice text: Privacy notice text Business and data practices: Business profile and data practices Ad tech posture: Pixels, SDKs, or conversion APIs deployed: identifiers leave the site States in scope: California only Review trigger: Routine annual refreshHow to work this1. Applicability first. One line per state: does the law reach this business, on which threshold? Do not score a state you exclude. 2. Compare the notice against what the business actually does per Business profile and data practices and Pixels, SDKs, or conversion APIs deployed: identifiers leave the site. Any divergence is a misrepresentation finding, not a disclosure gap, and it goes first. 3. One table row per required topic: Topic | Law | Present | Adequate | Gap | Replacement text. Cover categories, sources, purposes per category, recipients, sensitive data, retention per category, every right, submission methods, GPC, appeal, financial incentive, minors, contact. 4. Every redline is notice language the client can paste. Instructions to the drafter do not count. 5. Put state departures in their own section: consent model, universal opt-out signals, appeal timing, the minors' age line, assessments. 6. Rank the top five by enforcement exposure given Routine annual refresh, and say why a regulator opens on each rather than sending guidance. 7. Close with a separate list of what a rewrite cannot fix: intake, GPC honoring, opt-out propagation to ad platforms, vendor terms, assessments.Ask me firstYou have the notice, the business profile, and the states above. Ask me these four questions (what the published text cannot tell you), then stop and wait: 1. Does this business clear each state's applicability threshold: CCPA's revenue, consumer-count, and revenue-from-selling triggers, and the consumer-count and sale triggers in the Virginia-model states? I will not grade you against a statute that does not reach you. 2. Which sensitive categories do you actually collect, and do you use them beyond delivering the product the consumer asked for? That decides whether Colorado and Connecticut need opt-in consent and whether California needs a Limit the Use link. 3. What happens today when a consumer submits a request: how they submit it, who handles it, whether Global Privacy Control is honored at the browser, whether opt-outs reach the ad platforms, and whether an appeal path with a clock exists? 4. Am I fixing words or fixing the program? Tell me whether engineering capacity exists this quarter, or whether findings stay inside what a notice rewrite can close. Do not begin the audit until I answer. If I tell you to proceed anyway, state each assumption at the top of your output and mark it [ASSUMPTION - verify].Output formatA one-line GREEN / YELLOW / RED score with the reason, then the applicability lines, the topic audit table with paste-ready replacement text, the state-delta section, the top five ranked by exposure, and the operational gaps the notice cannot close. End with one line naming the two of my answers that changed this audit the most, and how you would have scored the notice without them. If an answer changed nothing, say so. That question did not earn its place.Never do this- If the audit would read the same for any consumer business in any state, it is too generic. Ground every finding in this company's data, this ad-tech posture, these states. - No hedging filler. Cut "arguably," "it should be noted," and "it depends." Do not tell me to consult privacy counsel. I am privacy counsel. - Never invent a statutory section, a regulation number, an effective date, or an enforcement action. Anything not in my inputs gets [UNVERIFIED - confirm against the current statute before publishing]. - Where you do not know whether a state amended a requirement or a rule has taken effect, say you do not know. These statutes change every session; do not smooth over the gap with fluent prose. - Do not pad the table with rows that are already clean. List those in one line and spend the space on the three that are not. Length is not value.Before you answer- Did I confirm applicability before scoring any state? - Is every gap paired with text the client could paste today? - Did I check the notice against actual practice, or only against the statute? - Would this audit be useless to a different company? It should be. - Is any citation or effective date unmarked and unverified?

Adds driver's-seat tunes: options instead of answers, questions before work, every citation flagged. Your values come with it.

2

Pressure-test it

Makes the AI switch hats and attack its own answer.

A consumer complaint about this company just landed on a state AG staff attorney's desk. Read your own audit as the staff attorney would. Name the two findings you would lead a civil investigative demand with, the one finding that produces an enforcement letter rather than an educational email, and the one that is a real gap you would never bother to charge. Then rewrite the ranking to match, and for each top finding write the one-sentence consumer-harm narrative the AG would put in the press release.
3

Go deeper

Pushes the work further once the basics are right.

Consumers never see the audit; what they see is the change log posted on the website with the revised notice. Draft it: the prior effective date, the substantive changes stated in plain English a consumer can follow, the reason for each change, and the date the new terms take effect. Then draft the two-paragraph internal note to the ad ops and engineering leads listing only the changes that require them to do something, with owners and dates.

Before you run it

What to gather first

  • The full notice, including any state-specific addendum and the cookie notice
  • What ad tech is actually deployed: pixels, SDKs, conversion APIs, data clean rooms
  • Consumer counts by state and total revenue, for applicability thresholds
  • How requests are received and handled today, and by whom
  • Whether engineering capacity exists this quarter or only copy changes are possible

Watch for

  • State privacy statutes and their regulations change every legislative session. Treat every section reference, effective date, and threshold the model gives you as unverified until you check the current text.
  • Deploying advertising pixels or SDKs is treated as a sale or share under CCPA even when no money changes hands. If the notice says otherwise, that is a misrepresentation exposure, not a technical gap.
  • A compliant notice describing operations that do not exist is worse than a thin one. Confirm with engineering that GPC is honored and that opt-outs actually reach the ad platforms before publishing the language.
  • Cure periods have sunset in several states. Do not budget for a warning letter before enforcement.
  • This audit does not cover sector regimes: HIPAA, GLBA, FERPA, COPPA, or state biometric and health-data statutes like Washington's My Health My Data. Run those separately.

What comes back

A GREEN / YELLOW / RED score with a one-line reason, applicability findings per state, a topic-by-topic audit table carrying paste-ready replacement notice language, a state-delta section for the states that depart from the model, the top five findings ranked by enforcement exposure, and a separate list of operational gaps a notice rewrite cannot close.

See an example of what you’ll get
*(After you answer the four questions, say, thresholds cleared in all states in scope, self-reported health conditions used for product recommendations and audience building, GPC not honored, no appeal path, and engineering has capacity next quarter.)* Score: RED. The notice states "we do not sell your personal information" while Meta and Google conversion tags transmit hashed email and browsing identifiers. Everything else in this audit is secondary to that sentence. Applicability. California: clears revenue threshold. Virginia, Colorado, Connecticut, Texas, Oregon: clear the 100,000-consumer trigger. Utah: does not apply; revenue below the threshold, not scored. Audit table (top rows). | Topic | Required by | Present | Adequate | Gap | Replacement text | |---|---|---|---|---|---| | Sale / share for cross-context advertising | CCPA § 1798.115, .120; VA/CO/CT/TX/OR analogues | Yes, and inaccurate | No | Notice denies selling while conversion tags fire | "We share identifiers, internet activity, and inferences with advertising partners including Meta and Google so they can deliver advertising to you across other sites and apps. Under California law this is a 'sale' and a 'share.' You may opt out using the 'Do Not Sell or Share My Personal Information' link or by enabling Global Privacy Control in your browser." | | Sensitive data | CCPA limit-use right; CO and CT opt-in consent | No | No | Self-reported health conditions are not identified as sensitive anywhere | "We collect health information you choose to give us, including self-reported conditions and wellness goals. We use it to recommend products and to build advertising audiences. California residents may direct us to limit its use; residents of Colorado and Connecticut will be asked to consent before we use it for anything other than filling your order." | | Retention | CPRA § 1798.100(a)(3) and most state laws | Generic | No | "As long as necessary" states no period or criteria per category | Add a Retention column to the categories table: contact information: life of account plus 6 years; order history: 7 years for tax; health self-reports: 24 months from last use; advertising identifiers: 13 months. | | Appeal | VA § 59.1-577(C), CO, CT, TX, OR | No | No | No appeal path or clock | "If we deny your request you may appeal by emailing privacy-appeal@northshorewellness.com. We will respond within 60 days and, if we deny the appeal, will give you a method to contact your state attorney general." | State deltas. Colorado and Connecticut require opt-in before the health data is used for advertising; Virginia and Texas run on opt-out. Colorado, Connecticut, Texas, and California all require honoring a universal opt-out signal; none is honored today. Colorado and Connecticut set the minors' line at 16 for targeted advertising, not 13. Top five by exposure, weighted for the AG letter. (1) The false "we do not sell" statement: this is the sentence a UCL or state AG action is built around. (2) No GPC honoring while the notice is silent about it. (3) Health data used for audience building with no consent flow in the opt-in states. (4) No appeal path in five states. (5) Loyalty program running without a financial-incentive notice. What a rewrite cannot fix. GPC detection at the edge and server-side propagation to Meta and Google; a consent gate for Colorado and Connecticut health-data use; a second request-submission method; the appeal queue and its 60-day clock; data-protection assessments for the profiling and sensitive-data processing; and updated processor terms with the two ad platforms. What your answers changed. Telling me the self-reported health conditions feed audience building and not just product recommendations is what turned the sensitive-data row from a disclosure gap into a consent failure. Without it, Colorado and Connecticut come off the opt-in list, the consent sentence comes out of that row's replacement text, and finding 3 drops off the top five entirely. Your answer that GPC is not honored and that no appeal path exists is what ranked findings 2 and 4 above the retention gap. The published text is silent on both, and silence reads as a drafting omission until you tell me it is an operational one. Neither answer moved the score: the “we do not sell” sentence earns RED on its own and would have earned it against a notice with perfect retention disclosures. Your answer about engineering capacity changed nothing. The operational list at the bottom runs the same length whether or not you can staff it next quarter, so that question did not earn its place here.
Why this prompt is built the way it is
## Framework 1. **Applicability before scoring.** Confirm each state law actually reaches this business before grading against it. Scoring a company against a statute that does not apply wastes the client's quarter. 2. **Accuracy outranks completeness.** A notice that says "we do not sell" while pixels fire is a misrepresentation, not a disclosure gap. That finding goes first. 3. **Topic-by-topic table.** Categories, sources, purposes mapped per category, recipients, sensitive data, retention per category, each right, submission methods, GPC, appeal, financial incentive, minors, contact. 4. **Redlines are text, not instructions.** "Add a retention disclosure" is not a redline. Notice language the client can paste is. 5. **State deltas separately.** Sensitive-data opt-in versus opt-out, universal opt-out signals, appeal clocks, minors' age lines, assessment obligations. 6. **Rank by enforcement exposure.** Which findings draw an AG letter versus a guidance email, and why. 7. **Name what the notice cannot fix.** Intake, GPC honoring, downstream opt-out propagation, vendor contracts, assessments. Otherwise the rewrite gets mistaken for compliance.