Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherBrowse by ChannelAbout the NetworkJoin the NetworkProductsSub-MenuProducts OverviewBlog ProBlog PlusBlog PremierMicrositeSyndication PortalsAbout UsContactSubscribeSupport
Book a Demo
Search
Close

Reminder: Data Protection Impact Assessments May Be Required Under New State Privacy Laws

By Greenberg Traurig, LLP on February 13, 2025
Email this postTweet this postLike this postShare this post on LinkedIn
data privacy 2

As we settle in to 2025, and five additional state privacy laws have or are about to go into effect, we wanted to put on your radar the obligation to conduct data protection impact assessments (DPIAs). In general, a DPIA should contain:

  • a systematic description of potential processing operations and the purpose of the processing, including where applicable, the legitimate interest pursued by the controller;
  • an assessment of the necessity and proportionality of the processing operations in relation to the purpose;
  • an assessment of the risks to the rights and freedoms of consumers; and
  • potential measures to address the risks, including safeguards, security measures, and mechanisms to ensure the protection of personal data.

As a reminder, most of the new state privacy laws require businesses to complete DPIAs if you do any of the following:

  1. Cookies and pixels (i.e., browser-based targeted advertising)
  2. Custom and lookalike audience (i.e., CRM-based targeted advertising)
  3. CAPI (i.e., server-based targeted advertising)
  4. App advertising (i.e., SDK-based targeted advertising)
  5. Find-a-store (i.e., precise geolocation collection)
  6. Other sensitive information collection (e.g., race, ethnicity, health, etc.)
  7. Selling of personal data
  8. Adaptive pricing (i.e., profiling that may cause financial injury)
  9. Collecting credit cards number (New Jersey privacy statute only)

We have seen states begin to request that companies produce DPIAs in response to consumer complaints and attorney general investigations. GT can help prepare DPIAs to meet the state requirements. If you have questions about conducting DPIAs, please reach out to our Data Privacy & Cybersecurity Practice contacts below.


Gretchen A. Ramos
Shareholder
San Francisco
+1 415.655.1319
ramosg@gtlaw.com
Greenberg Traurig Attorney Viola Bensinger
Dr. Viola Bensinger
Partner/Shareholder
Berlin
+49 30.700.171.150
viola.bensinger@gtlaw.com

Jena M. Valdetero
Shareholder
Chicago
+1 312.456.1025
Jena.Valdetero@gtlaw.com

David A. Zetoony
Shareholder
Denver
+1 303.685.7425
David.Zetoony@gtlaw.com
  • Posted in:
    Privacy & Data Security
  • Blog:
    Data Privacy Dish
  • Organization:
    Greenberg Traurig, LLP
  • Article: View Original Source

LexBlog, Inc. logo
Facebook LinkedIn Twitter RSS
Real Lawyers
99 Park Row
  • About LexBlog
  • Careers
  • Press
  • Contact LexBlog
  • Privacy Policy
  • Editorial Policy
  • Disclaimer
  • Terms of Service
  • RSS Terms of Service
  • Products
  • Blog Pro
  • Blog Plus
  • Blog Premier
  • Microsite
  • Syndication Portals
  • LexBlog Community
  • Resource Center
  • 1-800-913-0988
  • Submit a Request
  • Support Center
  • System Status
  • Resource Center
  • Blogging 101

New to the Network

  • Tennessee Insurance Litigation Blog
  • Claims & Sustains
  • New Jersey Restraining Order Lawyers
  • New Jersey Gun Lawyers
  • Blog of Reason
Copyright © 2025, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo