Skip to content
SSDI Campaigns

Legal

Privacy policy (50-state)

Effective September 16, 2026. This policy explains how SSDI Campaigns collects, uses, shares, and protects personal information, including health-related disability data, from residents of every U.S. state and the District of Columbia.

Call +1 (561) 652-0362 · Start screening · [email protected]

Operator: SSDI Campaigns (“we,” “us”). Contact: [email protected]. Privacy requests: [email protected]. Phone: +1 (561) 652-0362. Website: ssdicampaigns.com.

1. Who we are — and who we are not

We are an independent private campaign. We are not the U.S. Social Security Administration, CMS, HHS, or any state DDS. We are not a covered entity under HIPAA merely by operating this website; if we later receive records from a covered entity we will handle them under a business-associate or comparable agreement. We are not a law firm.

2. Information we collect

  • Identifiers: name, phone, email, postal ZIP, state of residence.
  • Sensitive / health-related data: disability type and optional narrative about conditions, denials, or hearings.
  • Commercial / campaign data: that you requested a screening.
  • Internet activity: IP address, user agent, referring URL, pages viewed, GPC signal, cookie choices — used for TCPA consent logs, security, and (if you accept) analytics.
  • Inferences: possible SSDI issues (work credits, SGA, listing category) derived from what you tell us.
  • Audio: if you call us, we may record after notice, consistent with one-party / all-party consent laws.
We do not knowingly collect information from children under 16. SSDI worker claims are adult claims; minor auxiliary-beneficiary questions should be directed to SSA.

3. How we use information

To respond to your request; to screen eligibility at a high level; to send the communications you consented to (including autodialed/prerecorded calls and SMS if you gave PEWC); to refer you, with consent, to an SSA-registered representative; to keep required TCPA/E-SIGN records (disclosure text, timestamp, IP, URL); to secure the site; to comply with law; and to improve educational content. We do not use sensitive health data for cross-context behavioral advertising.

4. Sharing (and “sale” / “share” under state law)

We do not sell your information for money today. We may share identifiers and the disability information you submitted with:
  • SSA-registered attorneys or representatives, if you asked for hearing or case help.
  • Vendors who host this site, send SMS/voice, or provide security — bound by contract.
  • Professional advisors and authorities when required by law, fraud prevention, or safety.
Some state laws treat disclosure of personal information for leads or targeted ads as a “sale” or “share” even without cash. You may opt out here: Do Not Sell or Share My Personal Information. We honor Global Privacy Control (GPC) as an opt-out of sale/share.

5. Sensitive data consent

Disability type is health information. We collect it only after you check an affirmative box. Colorado, Virginia, Connecticut, Texas, Oregon, and similar laws require opt-in for sensitive data. Washington’s My Health My Data Act additionally regulates consumer health data — we treat Washington residents’ disability intake as MHMDA consumer health data: no geofencing of health facilities, no sale without separate consent.

6. TCPA, telemarketing, and DNC

Phone numbers are collected for campaign follow-up. Autodialed/prerecorded calls and texts require prior express written consent, captured with an unchecked checkbox, E-SIGN language, and the exact disclosure adjacent to submit. Consent is not a condition of receiving information — you may call us instead. We will maintain an internal do-not-call list and scrub against the National DNC Registry before outbound campaigns, as required by the FTC (refresh at least every 31 days). Reply STOP to texts. State mini-TCPA statutes (including Florida and Oklahoma) also apply.

7. Your rights

Depending on your state, you may have rights to: confirm processing; access; correct; delete; portability; opt out of sale, sharing, and targeted advertising; opt out of certain profiling; limit use of sensitive personal information (California); appeal a denied request; and non-discrimination. Submit a privacy request or email [email protected]. We will verify you (matching name + phone/email we already have) and respond within 45 days (or the shorter period your state requires), with one 45-day extension if reasonably necessary. Authorized agents: CA and several other states allow them; we will verify the agent and, where required, your signed permission.

8. Retention

Screening forms and TCPA consent logs: until the campaign follow-up is complete, then up to 5 years (TCPA limitations often run 4 years under 28 U.S.C. § 1658). Privacy requests: 2 years. Server logs: 13 months. If HubSpot or another CRM is connected later, that system’s retention schedule will be added here.

9. Security

TLS in transit, access limited to campaign staff and processors, and vendor diligence. No method is 100% secure. Massachusetts 201 CMR 17.00-style reasonable security is our baseline nationwide, plus NY SHIELD and similar “reasonable safeguards” statutes.

10. Federal overlay

TCPA (47 U.S.C. § 227) and FCC rules; CAN-SPAM for commercial email; E-SIGN / UETA for electronic signatures; COPPA (we do not target children); FTC Act § 5; Social Security Act § 1140 (no false SSA affiliation); 20 CFR Part 404 Subpart R if we or a partner acts as an appointed representative. There is no comprehensive federal consumer privacy statute as of 2026.

11. Cookies

See our Cookie Policy. Strictly necessary cookies run always. Analytics cookies wait for Accept or are skipped if GPC is present.

12. International

This site is directed at U.S. residents. If you access it from abroad, you understand we process in the United States.

13. Changes

We will post updates here and change the effective date. Material changes to sensitive-data uses will require a new consent where law demands it.

14. State-by-state addendum

Every U.S. state has a data-breach notification law. Twenty-plus states now have comprehensive consumer privacy codes; others rely on UDAP, sectoral, biometric, health, and recording statutes. The following is our 50-state + D.C. notice. Rights listed apply when statutory thresholds are met; we still accept requests from residents of every state as a matter of policy.

Alabama (AL)

Comprehensive law: Alabama Personal Data Protection Act (HB 351, 2026) — enacted; effective May 2027.

Breach notice: Ala. Code § 8-38-1 et seq. (data breach notification).

Other: Consumer protection via Alabama Deceptive Trade Practices Act; no private right of action under the forthcoming comprehensive law (AG enforcement).

Alaska (AK)

Comprehensive law: No comprehensive consumer privacy statute in effect.

Breach notice: Alaska Personal Information Protection Act (AS 45.48).

Other: UDAP: Alaska Unfair Trade Practices and Consumer Protection Act. Health and insurance data may be covered by sectoral rules.

Arizona (AZ)

Comprehensive law: No comprehensive consumer privacy statute in effect.

Breach notice: A.R.S. § 18-551 et seq. (breach notice, including AG notice for large incidents).

Other: Arizona Consumer Fraud Act. Telephone Solicitation and Do-Not-Call rules apply to outbound campaigns.

Arkansas (AR)

Comprehensive law: No comprehensive consumer privacy statute in effect.

Breach notice: Ark. Code § 4-110-101 et seq. (Personal Information Protection Act).

Other: Arkansas Deceptive Trade Practices Act. Biometric and student-data sectoral rules exist.

California (CA)

Comprehensive law: California Consumer Privacy Act as amended by the CPRA (Cal. Civ. Code § 1798.100 et seq.). In effect. Private right of action for certain breaches. CPPA + AG enforcement.

Breach notice: Civil Code § 1798.82 (among the nation’s first breach statutes).

Other: Rights: know, access, delete, correct, portability, opt out of sale/share and certain profiling, limit use of sensitive personal information. Global Privacy Control must be honored as an opt-out. Shine the Light. CalOPPA. Two-party call recording (Penal Code § 632). CCPA applies to disability/health data we collect as sensitive personal information.

Colorado (CO)

Comprehensive law: Colorado Privacy Act (C.R.S. § 6-1-1301 et seq.). In effect. AG + district attorneys. Cure period expired.

Breach notice: C.R.S. § 6-1-716.

Other: Opt-in for sensitive data (including health). Universal opt-out mechanism required. Biometric and children’s rules. Colorado Consumer Protection Act.

Connecticut (CT)

Comprehensive law: Connecticut Data Privacy Act (Conn. Gen. Stat. § 42-515 et seq.). In effect. Health-data amendments post-Dobbs.

Breach notice: Conn. Gen. Stat. § 36a-701b.

Other: Two-party call recording. Sensitive-data opt-in. Consumer health data duties. Connecticut Unfair Trade Practices Act.

Delaware (DE)

Comprehensive law: Delaware Personal Data Privacy Act (effective 2025). Lower consumer threshold (35,000).

Breach notice: 6 Del. C. § 12B-101 et seq.

Other: Two-party recording. Consumer Fraud Act. Health and nonprofit coverage is broader than in some peer states.

Florida (FL)

Comprehensive law: Florida Digital Bill of Rights (F.S. § 501.701 et seq.). High applicability threshold (including $1B global revenue) — we still honor FDBR-style rights for Florida residents as a matter of policy.

Breach notice: F.S. § 501.171.

Other: Florida Telemarketing Act; Florida Do-Not-Call; Florida Consumer Collection Practices Act (if collecting). Two-party consent for recorded calls (F.S. § 934.03). Florida Deceptive and Unfair Trade Practices Act.

Georgia (GA)

Comprehensive law: No comprehensive consumer privacy statute in effect.

Breach notice: O.C.G.A. § 10-1-910 et seq.

Other: Fair Business Practices Act. Georgia telemarketing and automatic-dialer restrictions.

Hawaii (HI)

Comprehensive law: No comprehensive consumer privacy statute in effect.

Breach notice: Haw. Rev. Stat. § 487N-1 et seq.

Other: Uniform Unfair and Deceptive Practices. Health information additionally protected by state medical-privacy norms and HIPAA when a covered entity is involved.

Idaho (ID)

Comprehensive law: No comprehensive consumer privacy statute in effect.

Breach notice: Idaho Code § 28-51-104 et seq.

Other: Idaho Consumer Protection Act.

Illinois (IL)

Comprehensive law: No comprehensive consumer privacy statute comparable to CCPA; Illinois Biometric Information Privacy Act (BIPA, 740 ILCS 14) is among the strictest biometric laws and carries a private right of action.

Breach notice: 815 ILCS 530.

Other: Two-party recording (720 ILCS 5/14). Illinois Personal Information Protection Act. Genetic Information Privacy Act. Consumer Fraud and Deceptive Business Practices Act.

Indiana (IN)

Comprehensive law: Indiana Consumer Data Protection Act (effective Jan. 1, 2026). Virginia-model; AG enforcement; 30-day cure.

Breach notice: Ind. Code § 24-4.9.

Other: Deceptive Consumer Sales Act. Sensitive-data consent required when the comprehensive law applies.

Iowa (IA)

Comprehensive law: Iowa Consumer Data Protection Act (effective 2025). 90-day cure. No private right of action.

Breach notice: Iowa Code § 715C.

Other: Iowa Consumer Fraud Act.

Kansas (KS)

Comprehensive law: No comprehensive consumer privacy statute in effect.

Breach notice: K.S.A. § 50-7a01 et seq.

Other: Kansas Consumer Protection Act.

Kentucky (KY)

Comprehensive law: Kentucky Consumer Data Protection Act (effective Jan. 1, 2026). Virginia-model; permanent 30-day cure.

Breach notice: KRS § 365.732.

Other: Kentucky Consumer Protection Act.

Louisiana (LA)

Comprehensive law: Louisiana Data Privacy Act (Act 502 / SB 386, 2026) — enacted; effective Jan. 1, 2027.

Breach notice: La. R.S. § 51:3071 et seq. (Database Security Breach Notification Law).

Other: Unfair Trade Practices and Consumer Protection Law. Database security duties already in force.

Maine (ME)

Comprehensive law: No comprehensive consumer privacy statute. Maine has a broadband ISP privacy law (35-A M.R.S. § 9301) and strong health/substance-use confidentiality rules.

Breach notice: 10 M.R.S. § 1346 et seq. (Notice of Risk to Personal Data Act).

Other: Unfair Trade Practices Act. Maine has strict confidentiality for behavioral-health records.

Maryland (MD)

Comprehensive law: Maryland Online Data Privacy Act (effective Oct. 1, 2025). Strong data-minimization; lower thresholds (35,000 consumers).

Breach notice: Md. Code, Com. Law § 14-3501 et seq.

Other: Two-party recording. Maryland Personal Information Protection Act. Consumer Protection Act. Health-data sensitivity recognized.

Massachusetts (MA)

Comprehensive law: No comprehensive consumer privacy statute. 201 CMR 17.00 imposes a written information-security program (WISP) duty — among the nation’s oldest data-security regs.

Breach notice: M.G.L. c. 93H.

Other: Two-party recording (M.G.L. c. 272, § 99). Chapter 93A consumer protection (private right of action). Attorney General data-security enforcement.

Michigan (MI)

Comprehensive law: No comprehensive consumer privacy statute in effect.

Breach notice: MCL § 445.63 et seq. (Identity Theft Protection Act, including notice).

Other: Michigan Consumer Protection Act. Social Security Number Privacy Act.

Minnesota (MN)

Comprehensive law: Minnesota Consumer Data Privacy Act (effective July 31, 2025). Includes profiling explanation rights and specific recipient disclosure.

Breach notice: Minn. Stat. § 325E.61.

Other: Minnesota Prevention of Consumer Fraud Act. Health Records Act for medical information.

Mississippi (MS)

Comprehensive law: No comprehensive consumer privacy statute in effect.

Breach notice: Miss. Code § 75-24-29.

Other: Mississippi Consumer Protection Act.

Missouri (MO)

Comprehensive law: No comprehensive consumer privacy statute in effect.

Breach notice: Mo. Rev. Stat. § 407.1500.

Other: Merchandising Practices Act (private right of action in many cases).

Montana (MT)

Comprehensive law: Montana Consumer Data Privacy Act (effective Oct. 1, 2024). 50,000-consumer threshold.

Breach notice: Mont. Code § 30-14-1701 et seq.

Other: Two-party recording. Montana Unfair Trade Practices and Consumer Protection Act.

Nebraska (NE)

Comprehensive law: Nebraska Data Privacy Act (effective 2025). No revenue threshold; small-business exclusion.

Breach notice: Neb. Rev. Stat. § 87-801 et seq.

Other: Consumer Protection Act. Telemarketing and automatic-dialer rules.

Nevada (NV)

Comprehensive law: No comprehensive law of the CCPA type; NRS 603A includes an online opt-out-of-sale right and covered-information duties. SB 370 added further internet privacy provisions.

Breach notice: NRS 603A.220 et seq.

Other: Two-party recording. Nevada Deceptive Trade Practices Act. Health and genetic sectoral rules.

New Hampshire (NH)

Comprehensive law: New Hampshire Privacy Act (effective Jan. 1, 2025). 35,000-consumer threshold.

Breach notice: N.H. Rev. Stat. § 359-C:19 et seq.

Other: Two-party recording. Consumer Protection Act. Notice of Security Breach.

New Jersey (NJ)

Comprehensive law: New Jersey Data Privacy Act (effective Jan. 15, 2025). Division of Consumer Affairs enforcement.

Breach notice: N.J.S.A. 56:8-161 et seq. (Identity Theft Prevention Act).

Other: Consumer Fraud Act (powerful private and AG remedies). Genetic Privacy Act.

New Mexico (NM)

Comprehensive law: No comprehensive consumer privacy statute in effect.

Breach notice: N.M. Stat. § 57-12C-1 et seq. (Data Breach Notification Act).

Other: Unfair Practices Act. Additional protections for student and health data.

New York (NY)

Comprehensive law: No comprehensive CCPA-style law in effect (SHIELD Act is a security/breach statute). NYC has a local AI/biometric ordinance for employers.

Breach notice: N.Y. Gen. Bus. Law § 899-aa; SHIELD Act (GBL § 899-bb) requires reasonable safeguards.

Other: General Business Law § 349 (deceptive acts, private right of action). Stop Hacks and Improve Electronic Data Security Act. Telemarketing and call-recording (one-party at the state level, but notice is our policy).

North Carolina (NC)

Comprehensive law: No comprehensive consumer privacy statute in effect.

Breach notice: N.C. Gen. Stat. § 75-60 et seq. (Identity Theft Protection Act).

Other: North Carolina Unfair and Deceptive Trade Practices Act (treble damages in many cases).

North Dakota (ND)

Comprehensive law: No comprehensive consumer privacy statute in effect.

Breach notice: N.D.C.C. § 51-30.

Other: Unlawful Sales or Advertising Practices. Consumer fraud AG enforcement.

Ohio (OH)

Comprehensive law: No comprehensive consumer privacy statute in effect. Ohio has a data-protection safe harbor (ORC 1354) for entities with a written cybersecurity program aligned to a recognized framework.

Breach notice: ORC § 1349.19.

Other: Ohio Consumer Sales Practices Act. Telephone Solicitation Sales Act.

Oklahoma (OK)

Comprehensive law: Oklahoma Consumer Data Protection Act (SB 546, 2026) — enacted; effective 2027. Virginia-model with a 30-day cure.

Breach notice: 24 O.S. § 161 et seq. (Security Breach Notification Act).

Other: Consumer Protection Act. Mini-TCPA / telemarketing restrictions.

Oregon (OR)

Comprehensive law: Oregon Consumer Privacy Act (effective July 1, 2024). Right to know specific third parties; 30-day cure.

Breach notice: ORS 646A.600 et seq. (Oregon Consumer Identity Theft Protection Act).

Other: Unlawful Trade Practices Act. Oregon Genetic Privacy. Consumer health data considered sensitive.

Pennsylvania (PA)

Comprehensive law: No comprehensive consumer privacy statute in effect.

Breach notice: 73 P.S. § 2301 et seq. (Breach of Personal Information Notification Act).

Other: Two-party recording (18 Pa.C.S. § 5703). Unfair Trade Practices and Consumer Protection Law (private right of action).

Rhode Island (RI)

Comprehensive law: Rhode Island Data Transparency and Privacy Protection Act (effective Jan. 1, 2026).

Breach notice: R.I. Gen. Laws § 11-49.3-1 et seq.

Other: Deceptive Trade Practices Act. Identity Theft Protection Act.

South Carolina (SC)

Comprehensive law: No comprehensive consumer privacy statute in effect. Insurance data security act applies to licensees.

Breach notice: S.C. Code § 39-1-90.

Other: South Carolina Unfair Trade Practices Act.

South Dakota (SD)

Comprehensive law: No comprehensive consumer privacy statute in effect.

Breach notice: SDCL § 22-40-19 et seq.

Other: Deceptive Trade Practices and Consumer Protection.

Tennessee (TN)

Comprehensive law: Tennessee Information Protection Act (effective July 1, 2025). $25M revenue + consumer thresholds; 60-day cure.

Breach notice: Tenn. Code § 47-18-2107.

Other: Tennessee Consumer Protection Act. Identity Theft Deterrence Act.

Texas (TX)

Comprehensive law: Texas Data Privacy and Security Act (effective July 1, 2024). No revenue threshold — applies to most for-profit entities that process personal data (small-business exclusion is narrow).

Breach notice: Tex. Bus. & Com. Code § 521.053.

Other: Texas Identity Theft Enforcement and Protection Act. Deceptive Trade Practices Act. Capture or Use of Biometric Identifier statute (CUBI). Telemarketing disclosure duties.

Utah (UT)

Comprehensive law: Utah Consumer Privacy Act (effective Dec. 31, 2023). $25M revenue threshold; 30-day cure; no private right of action.

Breach notice: Utah Code § 13-44-201 et seq.

Other: Utah Consumer Sales Practices Act. Genetic testing privacy.

Vermont (VT)

Comprehensive law: Vermont Data Privacy and Online Surveillance Act (S.71 / Act 145, 2026) — enacted; effective Jan. 1, 2028. Includes a private right of action (unusual among state privacy laws).

Breach notice: 9 V.S.A. § 2430 et seq. (Security Breach Notice Act). Data-broker registration already required.

Other: Consumer Protection Act. Data broker annual registration (9 V.S.A. § 2433). Student and health confidentiality.

Virginia (VA)

Comprehensive law: Virginia Consumer Data Protection Act (effective Jan. 1, 2023) — the model many later states copied. AG exclusive enforcement; 30-day cure; sensitive-data opt-in.

Breach notice: Va. Code § 18.2-186.6.

Other: Virginia Consumer Protection Act. Health records privacy (Va. Code § 32.1-127.1:03) when medical records are involved.

Washington (WA)

Comprehensive law: No comprehensive CCPA-style law. Washington My Health My Data Act (MHMDA) regulates consumer health data — including disability inferences — with a private right of action. Washington also has a biometric identifier statute.

Breach notice: RCW 19.255.

Other: Two-party recording (RCW 9.73). Consumer Protection Act (powerful private right of action). MHMDA consent and geofencing rules are treated as in-scope for this campaign’s health-related intake.

West Virginia (WV)

Comprehensive law: No comprehensive consumer privacy statute in effect.

Breach notice: W. Va. Code § 46A-2A-101 et seq.

Other: West Virginia Consumer Credit and Protection Act.

Wisconsin (WI)

Comprehensive law: No comprehensive consumer privacy statute in effect.

Breach notice: Wis. Stat. § 134.98.

Other: Wisconsin Deceptive Trade Practices. Student and health sectoral statutes.

Wyoming (WY)

Comprehensive law: No comprehensive consumer privacy statute in effect.

Breach notice: Wyo. Stat. § 40-12-501 et seq.

Other: Wyoming Consumer Protection Act.

District of Columbia (DC)

Comprehensive law: No comprehensive consumer privacy statute identical to CCPA. D.C. has a data-breach statute and strong consumer-protection law.

Breach notice: D.C. Code § 28-3851 et seq.

Other: D.C. Consumer Protection Procedures Act (private attorney general). Call-recording and telemarketing rules of the District apply to D.C. residents.

This addendum is educational compliance mapping, not a guarantee that every statutory threshold is triggered for our operation. When a law does not yet apply, we still offer access, deletion, and opt-out.

Call +1 (561) 652-0362 · Start screening · [email protected]

Call nowStart screening[email protected]