In recent years, privacy has gone from buzzword to business function, but despite that, it’s still too often treated like an exercise in documentation.

And that’s to a company’s detriment. 

Without infrastructure, privacy becomes something a business reacts to rather than something it runs, let alone something it turns into a competitive advantage. A polished privacy page in front of a program that doesn’t function is marketing, not trust.

A privacy program has many moving parts, including privacy notices, consumer privacy rights, consent management, vendor oversight, and data inventories. Instead, these six questions will tell you whether the pieces you have truly add up to infrastructure.

Question #1: Do our privacy notices align (with practice and/or laws)?

A privacy notice is only as good as how accurate it is when a customer reads it. It may be accurate the day it’s published, but it doesn’t take long for it to drift.

A notice has to stay true to two different things, both of which are changeable. 

  • Your business practices: A new vendor, a new tracking tool, a new product, a new state you sell into – any of them can change your practices, and the notice is usually the last thing anyone updates. 
  • What the law requires you to disclose: New state laws take effect, and existing ones get amended even in years when no new ones pass. These changes can influence what the notice has to say, even if your practices haven’t changed at all.

To keep this information in sync, your notice needs a review process, not just a publish date. Review it at least once a year, and also whenever your business practices or your legal obligations change.  

How to operationalize your privacy notices so they stay current

  • Review the notice at least annually, and again on each triggering change
  • Treat new vendors, tracking tools, products, and state entries as triggers, not routine
  • Reconcile the stated practices against what the systems and vendors are doing now
  • Keep a change log that records what changed, why, which disclosures were affected, and when the revised notice went live
  • Test the notice against the actual user experience, including cookie preferences, rights-request forms, and mobile views
  • Make sure any material changes are communicated as required by applicable laws and reflected in the notice’s effective date

Question #2: What does our data inventory tell us?

Most privacy teams already have a data inventory. What separates a working one from an inventory that merely exists is whether it shows how information flows into, through, and out of a business’s personal data ecosystem.

This is especially important in 2026, because the privacy landscape is complex with  intertangled tech stacks. In the past, your company’s data might have been limited to a handful of databases, but today it’s scattered across a CRM, a marketing platform, half a dozen SaaS tools, cloud storage, and whatever AI tool someone on the team started using last month. 

And locations are only part of the picture. Special categories of information, e.g., health data, financial account numbers, employee records, and children’s data, require specific handling on top of your general obligations. If your inventory doesn’t reflect these designations, meeting your obligations could be impossible.

But all this only counts as operational infrastructure if there’s a process to keep it current.  

How to operationalize your data inventory

  • Confirm the inventory maps flows and transfers between systems, not just where data sits
  • Record purpose, retention, and downstream recipients for each category, not just the fact of collection
  • Tag regulated categories (health, financial, employee, and children’s data) so their stricter rules can be applied
  • Check it against a live scenario, like scoping a deletion request or identifying what a breached vendor held

Question #3: Is privacy built into the systems and workflows our teams use every day?

For a lot of companies, privacy is a collection of activities under the banner of staying in regulatory good graces. A notice gets written, a cookie banner gets installed, and vendor agreements get signed. But a to-do list isn’t a program, and it keeps privacy reactive instead of a standardized, predictable process.

Privacy by design takes the opposite approach. Instead of tacking privacy features onto a product at the end, it considers privacy at the start of a project or change. Privacy gets built into products, campaigns, and systems by default. For example, if your marketing department is onboarding a new email platform, a privacy-by-design approach would determine what personal information is collected, why it is needed, how long it is retained, how consent is captured, and how opt-outs are honored before the platform goes live, not after.

How to operationalize privacy by design

  • Make privacy review part of procurement, product development, marketing launches, and IT change management so new tools do not simply join the compliance backlog
  • Review your data inventory (or conduct one if you do not have one) and identify privacy touchpoints in every new product, campaign, system, vendor onboarding, and material change
  • Configure systems to honor privacy choices by default, starting with the highest-risk processing activities
  • Define escalation triggers for higher-risk uses, such as sensitive data, children’s data, precise location, profiling, AI training, or a new data-sharing arrangement
  • For each processing activity, identify what personal data is involved, the business purpose, who can access it, where it will go, and how long it will be retained

Question #4: Do we (really) know which privacy regulations apply to us?

Most companies know GDPR and CCPA. Far fewer have mapped the full set of rules that might reach their business, and that set is bigger than it was even a year ago.

The US state landscape keeps shifting

States are continuously adding, expanding, and adjusting privacy laws; as of writing this article, there are 23 comprehensive laws signed and 19 that are effective. Each one sets its own applicability thresholds, consumer rights, and compliance requirements. 

The variations are as much an operational issue as they are a legal one. When you’re dealing with different obligations across multiple jurisdictions, you can’t easily standardize. 

(Although we’ll note, following privacy best practices is a great way to get ahead of any regulatory curve. When your baseline is industry best practice, it can limit the need to rebuild your program each time a new law takes effect. The goal is not to assume every law applies, but to build processes that can accommodate the stricter requirements that do apply to your business.)

The definition of sensitive data is expanding

The categories that trigger stricter handling are widening. Several states now require age assurance and stronger default protections for minors, and state legislatures are starting to address automated decision-making, AI transparency, and the use of personal information to train models.

Health data is one example of the trend. Washington’s My Health My Data Act was the first law in the country to protect consumer health data that falls outside HIPAA, and Nevada and Connecticut followed with their own approaches. 

What makes these laws significant is the breadth of the data they can reach. Take Washington’s My Health My Data Act, for example. Its definition of “consumer health data” can include personal information linked or reasonably linkable to a consumer that identifies physical or mental health status. 

This can extend beyond traditional medical records to information that infers health-related interests, conditions, care-seeking, or other health status. As such, a company doesn’t need to be a healthcare provider to find itself in a risky position. Information from an app, website, wearable, location dataset, purchase history, or advertising activity may fall within scope when it identifies or supports an inference about someone’s health status.     

More states are considering similar measures, so the safe assumption is that this list will keep growing.

Enforcement is getting coordinated

Beyond individual settlements, regulators are increasingly coordinating their work. In April 2025, the California Privacy Protection Agency announced the bipartisan Consortium of Privacy Regulators, which brings together the CPPA and state attorneys general to collaborate on privacy enforcement and information sharing.

It launched with eight members but has since grown to a dozen, with Vermont the most recent to join in August 2026, indicating that coordinated enforcement may become the norm. 

One early example of this coordination in action came in September 2025, when California, Colorado, and Connecticut launched a joint enforcement initiative targeting businesses that ignored GPC signals.

How to operationalize applying privacy regulations

  • Map where your customers are located and what data you collect
  • Check that map against every state law in effect, not just GDPR and CCPA
  • Account for sensitive-data rules, including the widening definition of consumer health data
  • Rerun the assessment whenever you enter a new state or start a new data use

Question #5: Can people exercise their privacy rights with us?

One of the key drivers behind privacy laws is to give people rights over their data, including the right to access it, delete it, correct it, and opt out of certain uses. 

Receiving requests is (often) the easy part. Fulfillment, though, is where programs often run aground. That’s because privacy requests aren’t a standalone task. For example, to delete a person’s data from your system, you would need to lean on:

  • Your data inventory to know every system their data lives in 
  • Your vendor oversight, because your vendors may have access to that data
  • Your verification process, to confirm the person is who they claim before you act
  • Your deadline tracking, to finish inside the legal window

The infrastructure version has a defined intake channel, a verification step calibrated to the request, a reliable way to locate data across every system, and tracking that keeps each request inside its deadline.

How to operationalize privacy rights

  • Run a request through your own process end to end, and time it
  • Confirm you can locate a requester’s data in every system, including vendors
  • Set verification that confirms identity without collecting more than you need
  • Track each request against its deadline, which many laws set at roughly 45 days

Question #6: Do we have a handle on the privacy risks our AI tools are creating?

Many existing privacy programs reflect a world where personal data moved through relatively well-traveled ecosystems. AI disrupts that assumption in two different ways.

The rise of shadow AI

The first is shadow AI, which refers to tools employees adopt without review. Shadow AI tools pose numerous issues, but as far as privacy goes, those problems center on what happens to data when it enters that tool. The vendor might use it to train their models; it might move across borders; or any number of other practices that don’t align with your own. 

But because the tool was never officially reviewed or approved, none of it appears in your data inventory, privacy notice, or any vendor assessment.  

Agentic AI and privacy

The second is agentic AI. An agentic tool can reach across your systems and run multi-step tasks without a human monitoring each step. If your systems hold personal information (and they likely do), that independence creates a new world of privacy risk. Because agentic AI tools act independently, privacy controls can no longer rely on periodic, manual reviews. Instead, you need dynamic, real-time governance, such as automated guardrails and continuous monitoring, that enforces compliance while the tool is actively running.

Neither of these requires reinventing your program, but they do require extending the controls you already run, review, inventory, notice, and vendor diligence, to a category of tool that behaves differently from the software they were designed around.  

How to operationalize AI governance

  • Review AI tools before adoption, and give employees a sanctioned option so shadow use has less pull
  • Set a clear policy on what can and can’t be entered into them
  • Capture AI data flows in the inventory and extend vendor diligence to AI vendors
  • Scope agentic tools specifically for what they can access and act on without review
Downloadable Resource

State Privacy Laws Comparison Guide

Ready to take a closer look at your privacy program?

These questions are a place to start, but they’re not a comprehensive assessment. If you’re not sure how to answer some of them, that’s where Red Clover Advisors can help. Schedule a consultation, and we’ll take it from there.