TwinEthosRequest access

Law

US State Privacy Laws — Profiling Opt-Out (Virginia-model)

State Attorneys General (multiple) · Colorado (US-CO), Connecticut (US-CT), Delaware (US-DE), Florida (US-FL), Indiana (US-IN), Kentucky (US-KY), Maryland (US-MD), Minnesota (US-MN), Montana (US-MT), Nebraska (US-NE), New Hampshire (US-NH), New Jersey (US-NJ), Oregon (US-OR), Rhode Island (US-RI), Tennessee (US-TN), Texas (US-TX), Virginia (US-VA) · 1 provision encoded · verified against the official source as of 2026-09-03.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Official text: apps.legislature.ky.gov, coag.gov, content.leg.colorado.gov, delcode.delaware.gov, iga.in.gov, law.lis.virginia.gov, mca.legmt.gov, mgaleg.maryland.gov, nebraskalegislature.gov, pub.njleg.state.nj.us, publications.tnsosfiles.com, statutes.capitol.texas.gov, tcss.legis.texas.gov, webserver.rilegislature.gov, www.cga.ct.gov, www.flsenate.gov, www.gencourt.state.nh.us, www.oregonlegislature.gov, www.revisor.mn.gov.

Binding law — in force

Consumers can opt out of profiling for significant-effects decisions (17 US state privacy laws, Virginia-model)

Va. Code 59.1-577(A)(5) (VCDPA) — canonical text · official text · In force: applies since 1 Jan 2023 · Colorado (US-CO), Connecticut (US-CT), Delaware (US-DE), Florida (US-FL), Indiana (US-IN), Kentucky (US-KY), Maryland (US-MD), Minnesota (US-MN), Montana (US-MT), Nebraska (US-NE), New Hampshire (US-NH), New Jersey (US-NJ), Oregon (US-OR), Rhode Island (US-RI), Tennessee (US-TN), Texas (US-TX), Virginia (US-VA)

Under the 17 encoded Virginia-model comprehensive privacy laws, a consumer has the right to opt out of profiling — automated processing used to evaluate/analyze/predict personal aspects — in furtherance of decisions that produce legal or similarly significant effects (financial/lending, housing, insurance, education, criminal justice, employment, health care, and access to basic necessities or essential goods/services). Many states additionally require honoring a universal opt-out signal (GPC). Detect a profiling/automated-decision path for consequential decisions with no consumer opt-out mechanism (or no GPC honoring where required). The primary-source-derived variants are VA §59.1-577, CO §6-1-1306, CT, IN, TN, MT, OR, TX, FL, DE, NH, NJ, KY, NE, MN, MD, and RI. GPC/universal-opt-out is mandatory in CO, CT, DE, MD, MN, MT, NE, NH, NJ, OR, and TX. California's equivalent is the CCPA ADMT regulations, tracked separately as ccpa-admt. Iowa and Utah are excluded from this family because they do not provide the encoded significant-effects profiling opt-out.

Who it applies to

  • Duty falls on: controller
  • Systems covered: automated decision, consequential decision
  • Sectors: lending, insurance, employment, housing, healthcare, education, essential services
  • Virginia-model consumer right to opt out of profiling in furtherance of decisions producing legal or similarly significant effects. The right belongs to a 'consumer' (Rhode Island: 'customer'), which every encoded law limits to a state resident and excludes people acting in a commercial or employment context; each variant anchors its own official definition, and excluded_uses lists the exclusions with citations. Per-jurisdiction citation, GPC/universal-opt-out duty, correction right, thresholds, effective date, provenance, and official source anchors are in jurisdiction_variants[]. All 17 encoded variants are primary-source-derived. Iowa and Utah are excluded because they do not provide this significant-effects profiling opt-out in the encoded form.
  • Not covered:
    • Individuals acting in a commercial or employment context: they are not 'consumers' under any of the 17 encoded laws (Va. Code 59.1-575; C.R.S. 6-1-1303(6)(b); Conn. Gen. Stat. 42-515(8); Ind. Code 24-15-2-8(b); Tenn. Code Ann. 47-18-3201(7)(B); Mont. Code Ann. 30-14-2802(7)(b); ORS 646A.570(7); Tex. Bus. & Com. Code 541.001(7); Fla. Stat. 501.702(8); 6 Del. C. 12D-102(8); N.H. RSA 507-H:1, VIII; N.J.S.A. 56:8-166.4; KRS 367.3611(7); Neb. Rev. Stat. 87-1102(7)(b); Minn. Stat. 325M.11(g); Md. Code, Com. Law 14-4701(h)(2)(i); R.I. Gen. Laws 6-48.1-2(10), where the protected person is a 'customer')
    • Business contacts: an employee, owner, director, officer, or contractor of a company, partnership, sole proprietorship, nonprofit, or government agency whose communications or transactions with the controller occur solely within that role (named expressly in Conn. Gen. Stat. 42-515(8); Mont. Code Ann. 30-14-2802(7)(b); 6 Del. C. 12D-102(8); N.H. RSA 507-H:1, VIII; Md. Code, Com. Law 14-4701(h)(2)(ii); R.I. Gen. Laws 6-48.1-2(10); in the other states they act in a commercial or employment context)
    • Job applicants and beneficiaries of someone acting in an employment context, in Colorado only (C.R.S. 6-1-1303(6)(b)); elsewhere whether an applicant acts 'in an employment context' is not settled by the text (legal-review queue)

The guard to add

Store a consumer's profiling opt-out (and a Global Privacy Control signal where honored) and check it before profiling outputs feed any significant-effects decision.

An opt-out surface (privacy settings toggle, POST /privacy/opt-out) that persists a do_not_profile preference; request middleware that reads the Sec-GPC header (or navigator.globalPrivacyControl on the client) and sets the same preference for that consumer; and a gate in the decision service before profile features, segments, or propensity scores reach approve, deny, or underwrite. Opted-out consumers are decided without profiling-derived inputs or by a person, and the gate records that the opt-out was applied. The check belongs in the server-side decision path, because that is where the profiling takes effect.

Where it goes: 1 application source code, 2 data models, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Honor a universal opt-out signal such as GPC where mandatory: CO, CT, DE, MD, MN, MT, NE, NH, NJ, OR, and TX.
  • Cover profiling for decisions in financial or lending services, housing, insurance, education, criminal justice, employment, health care, and access to basic necessities or essential goods and services.

Example (FastAPI middleware + decision route), before:

@app.post('/credit/decision')
def credit_decision(req: CreditRequest):
    feats = behavioral_features(req.user_id) | credit_features(req.user_id)
    return underwrite(req, propensity_score(feats))

After:

@app.middleware('http')
async def honor_gpc(request: Request, call_next):
    uid = current_user_id(request)
    if uid and request.headers.get('Sec-GPC') == '1':
        prefs.set(uid, 'do_not_profile', True)
    return await call_next(request)

@app.post('/credit/decision')
def credit_decision(req: CreditRequest):
    if prefs.get(req.user_id, 'do_not_profile'):
        return route_to_human(req, reason='profiling_opt_out')
    feats = behavioral_features(req.user_id) | credit_features(req.user_id)
    return underwrite(req, propensity_score(feats))

Control: Profiling for significant-effects decisions with no opt-out. The same guard addresses 1 item with binding law in 17 jurisdictions. Engineering guidance, not legal advice.

Rule id us-state-privacy-admt.profiling-optout · review status: primary source derived