Binding law — in force
Consumers can opt out of profiling for significant-effects decisions (17 US state privacy laws, Virginia-model)
Under the 17 encoded Virginia-model comprehensive privacy laws, a consumer has the right to opt out of profiling — automated processing used to evaluate/analyze/predict personal aspects — in furtherance of decisions that produce legal or similarly significant effects (financial/lending, housing, insurance, education, criminal justice, employment, health care, and access to basic necessities or essential goods/services). Many states additionally require honoring a universal opt-out signal (GPC). Detect a profiling/automated-decision path for consequential decisions with no consumer opt-out mechanism (or no GPC honoring where required). The primary-source-derived variants are VA §59.1-577, CO §6-1-1306, CT, IN, TN, MT, OR, TX, FL, DE, NH, NJ, KY, NE, MN, MD, and RI. GPC/universal-opt-out is mandatory in CO, CT, DE, MD, MN, MT, NE, NH, NJ, OR, and TX. California's equivalent is the CCPA ADMT regulations, tracked separately as ccpa-admt. Iowa and Utah are excluded from this family because they do not provide the encoded significant-effects profiling opt-out.
Who it applies to
- Duty falls on: controller
- Systems covered: automated decision, consequential decision
- Sectors: lending, insurance, employment, housing, healthcare, education, essential services
- Virginia-model consumer right to opt out of profiling in furtherance of decisions producing legal or similarly significant effects. The right belongs to a 'consumer' (Rhode Island: 'customer'), which every encoded law limits to a state resident and excludes people acting in a commercial or employment context; each variant anchors its own official definition, and excluded_uses lists the exclusions with citations. Per-jurisdiction citation, GPC/universal-opt-out duty, correction right, thresholds, effective date, provenance, and official source anchors are in jurisdiction_variants[]. All 17 encoded variants are primary-source-derived. Iowa and Utah are excluded because they do not provide this significant-effects profiling opt-out in the encoded form.
- Not covered:
- Individuals acting in a commercial or employment context: they are not 'consumers' under any of the 17 encoded laws (Va. Code 59.1-575; C.R.S. 6-1-1303(6)(b); Conn. Gen. Stat. 42-515(8); Ind. Code 24-15-2-8(b); Tenn. Code Ann. 47-18-3201(7)(B); Mont. Code Ann. 30-14-2802(7)(b); ORS 646A.570(7); Tex. Bus. & Com. Code 541.001(7); Fla. Stat. 501.702(8); 6 Del. C. 12D-102(8); N.H. RSA 507-H:1, VIII; N.J.S.A. 56:8-166.4; KRS 367.3611(7); Neb. Rev. Stat. 87-1102(7)(b); Minn. Stat. 325M.11(g); Md. Code, Com. Law 14-4701(h)(2)(i); R.I. Gen. Laws 6-48.1-2(10), where the protected person is a 'customer')
- Business contacts: an employee, owner, director, officer, or contractor of a company, partnership, sole proprietorship, nonprofit, or government agency whose communications or transactions with the controller occur solely within that role (named expressly in Conn. Gen. Stat. 42-515(8); Mont. Code Ann. 30-14-2802(7)(b); 6 Del. C. 12D-102(8); N.H. RSA 507-H:1, VIII; Md. Code, Com. Law 14-4701(h)(2)(ii); R.I. Gen. Laws 6-48.1-2(10); in the other states they act in a commercial or employment context)
- Job applicants and beneficiaries of someone acting in an employment context, in Colorado only (C.R.S. 6-1-1303(6)(b)); elsewhere whether an applicant acts 'in an employment context' is not settled by the text (legal-review queue)
The guard to add
Store a consumer's profiling opt-out (and a Global Privacy Control signal where honored) and check it before profiling outputs feed any significant-effects decision.
An opt-out surface (privacy settings toggle, POST /privacy/opt-out) that persists a do_not_profile preference; request middleware that reads the Sec-GPC header (or navigator.globalPrivacyControl on the client) and sets the same preference for that consumer; and a gate in the decision service before profile features, segments, or propensity scores reach approve, deny, or underwrite. Opted-out consumers are decided without profiling-derived inputs or by a person, and the gate records that the opt-out was applied. The check belongs in the server-side decision path, because that is where the profiling takes effect.
Where it goes: 1 application source code, 2 data models, 9 AI output handling, 14 user-facing text.
What this provision adds:
- Honor a universal opt-out signal such as GPC where mandatory: CO, CT, DE, MD, MN, MT, NE, NH, NJ, OR, and TX.
- Cover profiling for decisions in financial or lending services, housing, insurance, education, criminal justice, employment, health care, and access to basic necessities or essential goods and services.
Example (FastAPI middleware + decision route), before:
@app.post('/credit/decision')
def credit_decision(req: CreditRequest):
feats = behavioral_features(req.user_id) | credit_features(req.user_id)
return underwrite(req, propensity_score(feats))After:
@app.middleware('http')
async def honor_gpc(request: Request, call_next):
uid = current_user_id(request)
if uid and request.headers.get('Sec-GPC') == '1':
prefs.set(uid, 'do_not_profile', True)
return await call_next(request)
@app.post('/credit/decision')
def credit_decision(req: CreditRequest):
if prefs.get(req.user_id, 'do_not_profile'):
return route_to_human(req, reason='profiling_opt_out')
feats = behavioral_features(req.user_id) | credit_features(req.user_id)
return underwrite(req, propensity_score(feats))Control: Profiling for significant-effects decisions with no opt-out. The same guard addresses 1 item with binding law in 17 jurisdictions. Engineering guidance, not legal advice.
Rule id us-state-privacy-admt.profiling-optout · review status: primary source derived