Operator: SSDI Campaigns (“we,” “us”). Contact: [email protected]. Privacy requests: [email protected]. Phone: +1 (561) 652-0362. Website: ssdicampaigns.com.
1. Who we are — and who we are not
2. Information we collect
- Identifiers: name, phone, email, postal ZIP, state of residence.
- Sensitive / health-related data: disability type and optional narrative about conditions, denials, or hearings.
- Commercial / campaign data: that you requested a screening.
- Internet activity: IP address, user agent, referring URL, pages viewed, GPC signal, cookie choices — used for TCPA consent logs, security, and (if you accept) analytics.
- Inferences: possible SSDI issues (work credits, SGA, listing category) derived from what you tell us.
- Audio: if you call us, we may record after notice, consistent with one-party / all-party consent laws.
3. How we use information
4. Sharing (and “sale” / “share” under state law)
- SSA-registered attorneys or representatives, if you asked for hearing or case help.
- Vendors who host this site, send SMS/voice, or provide security — bound by contract.
- Professional advisors and authorities when required by law, fraud prevention, or safety.
5. Sensitive data consent
6. TCPA, telemarketing, and DNC
7. Your rights
8. Retention
9. Security
10. Federal overlay
11. Cookies
12. International
13. Changes
14. State-by-state addendum
Every U.S. state has a data-breach notification law. Twenty-plus states now have comprehensive consumer privacy codes; others rely on UDAP, sectoral, biometric, health, and recording statutes. The following is our 50-state + D.C. notice. Rights listed apply when statutory thresholds are met; we still accept requests from residents of every state as a matter of policy.
Alabama (AL)
Comprehensive law: Alabama Personal Data Protection Act (HB 351, 2026) — enacted; effective May 2027.
Breach notice: Ala. Code § 8-38-1 et seq. (data breach notification).
Other: Consumer protection via Alabama Deceptive Trade Practices Act; no private right of action under the forthcoming comprehensive law (AG enforcement).
Alaska (AK)
Comprehensive law: No comprehensive consumer privacy statute in effect.
Breach notice: Alaska Personal Information Protection Act (AS 45.48).
Other: UDAP: Alaska Unfair Trade Practices and Consumer Protection Act. Health and insurance data may be covered by sectoral rules.
Arizona (AZ)
Comprehensive law: No comprehensive consumer privacy statute in effect.
Breach notice: A.R.S. § 18-551 et seq. (breach notice, including AG notice for large incidents).
Other: Arizona Consumer Fraud Act. Telephone Solicitation and Do-Not-Call rules apply to outbound campaigns.
Arkansas (AR)
Comprehensive law: No comprehensive consumer privacy statute in effect.
Breach notice: Ark. Code § 4-110-101 et seq. (Personal Information Protection Act).
Other: Arkansas Deceptive Trade Practices Act. Biometric and student-data sectoral rules exist.
California (CA)
Comprehensive law: California Consumer Privacy Act as amended by the CPRA (Cal. Civ. Code § 1798.100 et seq.). In effect. Private right of action for certain breaches. CPPA + AG enforcement.
Breach notice: Civil Code § 1798.82 (among the nation’s first breach statutes).
Other: Rights: know, access, delete, correct, portability, opt out of sale/share and certain profiling, limit use of sensitive personal information. Global Privacy Control must be honored as an opt-out. Shine the Light. CalOPPA. Two-party call recording (Penal Code § 632). CCPA applies to disability/health data we collect as sensitive personal information.
Colorado (CO)
Comprehensive law: Colorado Privacy Act (C.R.S. § 6-1-1301 et seq.). In effect. AG + district attorneys. Cure period expired.
Breach notice: C.R.S. § 6-1-716.
Other: Opt-in for sensitive data (including health). Universal opt-out mechanism required. Biometric and children’s rules. Colorado Consumer Protection Act.
Connecticut (CT)
Comprehensive law: Connecticut Data Privacy Act (Conn. Gen. Stat. § 42-515 et seq.). In effect. Health-data amendments post-Dobbs.
Breach notice: Conn. Gen. Stat. § 36a-701b.
Other: Two-party call recording. Sensitive-data opt-in. Consumer health data duties. Connecticut Unfair Trade Practices Act.
Delaware (DE)
Comprehensive law: Delaware Personal Data Privacy Act (effective 2025). Lower consumer threshold (35,000).
Breach notice: 6 Del. C. § 12B-101 et seq.
Other: Two-party recording. Consumer Fraud Act. Health and nonprofit coverage is broader than in some peer states.
Florida (FL)
Comprehensive law: Florida Digital Bill of Rights (F.S. § 501.701 et seq.). High applicability threshold (including $1B global revenue) — we still honor FDBR-style rights for Florida residents as a matter of policy.
Breach notice: F.S. § 501.171.
Other: Florida Telemarketing Act; Florida Do-Not-Call; Florida Consumer Collection Practices Act (if collecting). Two-party consent for recorded calls (F.S. § 934.03). Florida Deceptive and Unfair Trade Practices Act.
Georgia (GA)
Comprehensive law: No comprehensive consumer privacy statute in effect.
Breach notice: O.C.G.A. § 10-1-910 et seq.
Other: Fair Business Practices Act. Georgia telemarketing and automatic-dialer restrictions.
Hawaii (HI)
Comprehensive law: No comprehensive consumer privacy statute in effect.
Breach notice: Haw. Rev. Stat. § 487N-1 et seq.
Other: Uniform Unfair and Deceptive Practices. Health information additionally protected by state medical-privacy norms and HIPAA when a covered entity is involved.
Idaho (ID)
Comprehensive law: No comprehensive consumer privacy statute in effect.
Breach notice: Idaho Code § 28-51-104 et seq.
Other: Idaho Consumer Protection Act.
Illinois (IL)
Comprehensive law: No comprehensive consumer privacy statute comparable to CCPA; Illinois Biometric Information Privacy Act (BIPA, 740 ILCS 14) is among the strictest biometric laws and carries a private right of action.
Breach notice: 815 ILCS 530.
Other: Two-party recording (720 ILCS 5/14). Illinois Personal Information Protection Act. Genetic Information Privacy Act. Consumer Fraud and Deceptive Business Practices Act.
Indiana (IN)
Comprehensive law: Indiana Consumer Data Protection Act (effective Jan. 1, 2026). Virginia-model; AG enforcement; 30-day cure.
Breach notice: Ind. Code § 24-4.9.
Other: Deceptive Consumer Sales Act. Sensitive-data consent required when the comprehensive law applies.
Iowa (IA)
Comprehensive law: Iowa Consumer Data Protection Act (effective 2025). 90-day cure. No private right of action.
Breach notice: Iowa Code § 715C.
Other: Iowa Consumer Fraud Act.
Kansas (KS)
Comprehensive law: No comprehensive consumer privacy statute in effect.
Breach notice: K.S.A. § 50-7a01 et seq.
Other: Kansas Consumer Protection Act.
Kentucky (KY)
Comprehensive law: Kentucky Consumer Data Protection Act (effective Jan. 1, 2026). Virginia-model; permanent 30-day cure.
Breach notice: KRS § 365.732.
Other: Kentucky Consumer Protection Act.
Louisiana (LA)
Comprehensive law: Louisiana Data Privacy Act (Act 502 / SB 386, 2026) — enacted; effective Jan. 1, 2027.
Breach notice: La. R.S. § 51:3071 et seq. (Database Security Breach Notification Law).
Other: Unfair Trade Practices and Consumer Protection Law. Database security duties already in force.
Maine (ME)
Comprehensive law: No comprehensive consumer privacy statute. Maine has a broadband ISP privacy law (35-A M.R.S. § 9301) and strong health/substance-use confidentiality rules.
Breach notice: 10 M.R.S. § 1346 et seq. (Notice of Risk to Personal Data Act).
Other: Unfair Trade Practices Act. Maine has strict confidentiality for behavioral-health records.
Maryland (MD)
Comprehensive law: Maryland Online Data Privacy Act (effective Oct. 1, 2025). Strong data-minimization; lower thresholds (35,000 consumers).
Breach notice: Md. Code, Com. Law § 14-3501 et seq.
Other: Two-party recording. Maryland Personal Information Protection Act. Consumer Protection Act. Health-data sensitivity recognized.
Massachusetts (MA)
Comprehensive law: No comprehensive consumer privacy statute. 201 CMR 17.00 imposes a written information-security program (WISP) duty — among the nation’s oldest data-security regs.
Breach notice: M.G.L. c. 93H.
Other: Two-party recording (M.G.L. c. 272, § 99). Chapter 93A consumer protection (private right of action). Attorney General data-security enforcement.
Michigan (MI)
Comprehensive law: No comprehensive consumer privacy statute in effect.
Breach notice: MCL § 445.63 et seq. (Identity Theft Protection Act, including notice).
Other: Michigan Consumer Protection Act. Social Security Number Privacy Act.
Minnesota (MN)
Comprehensive law: Minnesota Consumer Data Privacy Act (effective July 31, 2025). Includes profiling explanation rights and specific recipient disclosure.
Breach notice: Minn. Stat. § 325E.61.
Other: Minnesota Prevention of Consumer Fraud Act. Health Records Act for medical information.
Mississippi (MS)
Comprehensive law: No comprehensive consumer privacy statute in effect.
Breach notice: Miss. Code § 75-24-29.
Other: Mississippi Consumer Protection Act.
Missouri (MO)
Comprehensive law: No comprehensive consumer privacy statute in effect.
Breach notice: Mo. Rev. Stat. § 407.1500.
Other: Merchandising Practices Act (private right of action in many cases).
Montana (MT)
Comprehensive law: Montana Consumer Data Privacy Act (effective Oct. 1, 2024). 50,000-consumer threshold.
Breach notice: Mont. Code § 30-14-1701 et seq.
Other: Two-party recording. Montana Unfair Trade Practices and Consumer Protection Act.
Nebraska (NE)
Comprehensive law: Nebraska Data Privacy Act (effective 2025). No revenue threshold; small-business exclusion.
Breach notice: Neb. Rev. Stat. § 87-801 et seq.
Other: Consumer Protection Act. Telemarketing and automatic-dialer rules.
Nevada (NV)
Comprehensive law: No comprehensive law of the CCPA type; NRS 603A includes an online opt-out-of-sale right and covered-information duties. SB 370 added further internet privacy provisions.
Breach notice: NRS 603A.220 et seq.
Other: Two-party recording. Nevada Deceptive Trade Practices Act. Health and genetic sectoral rules.
New Hampshire (NH)
Comprehensive law: New Hampshire Privacy Act (effective Jan. 1, 2025). 35,000-consumer threshold.
Breach notice: N.H. Rev. Stat. § 359-C:19 et seq.
Other: Two-party recording. Consumer Protection Act. Notice of Security Breach.
New Jersey (NJ)
Comprehensive law: New Jersey Data Privacy Act (effective Jan. 15, 2025). Division of Consumer Affairs enforcement.
Breach notice: N.J.S.A. 56:8-161 et seq. (Identity Theft Prevention Act).
Other: Consumer Fraud Act (powerful private and AG remedies). Genetic Privacy Act.
New Mexico (NM)
Comprehensive law: No comprehensive consumer privacy statute in effect.
Breach notice: N.M. Stat. § 57-12C-1 et seq. (Data Breach Notification Act).
Other: Unfair Practices Act. Additional protections for student and health data.
New York (NY)
Comprehensive law: No comprehensive CCPA-style law in effect (SHIELD Act is a security/breach statute). NYC has a local AI/biometric ordinance for employers.
Breach notice: N.Y. Gen. Bus. Law § 899-aa; SHIELD Act (GBL § 899-bb) requires reasonable safeguards.
Other: General Business Law § 349 (deceptive acts, private right of action). Stop Hacks and Improve Electronic Data Security Act. Telemarketing and call-recording (one-party at the state level, but notice is our policy).
North Carolina (NC)
Comprehensive law: No comprehensive consumer privacy statute in effect.
Breach notice: N.C. Gen. Stat. § 75-60 et seq. (Identity Theft Protection Act).
Other: North Carolina Unfair and Deceptive Trade Practices Act (treble damages in many cases).
North Dakota (ND)
Comprehensive law: No comprehensive consumer privacy statute in effect.
Breach notice: N.D.C.C. § 51-30.
Other: Unlawful Sales or Advertising Practices. Consumer fraud AG enforcement.
Ohio (OH)
Comprehensive law: No comprehensive consumer privacy statute in effect. Ohio has a data-protection safe harbor (ORC 1354) for entities with a written cybersecurity program aligned to a recognized framework.
Breach notice: ORC § 1349.19.
Other: Ohio Consumer Sales Practices Act. Telephone Solicitation Sales Act.
Oklahoma (OK)
Comprehensive law: Oklahoma Consumer Data Protection Act (SB 546, 2026) — enacted; effective 2027. Virginia-model with a 30-day cure.
Breach notice: 24 O.S. § 161 et seq. (Security Breach Notification Act).
Other: Consumer Protection Act. Mini-TCPA / telemarketing restrictions.
Oregon (OR)
Comprehensive law: Oregon Consumer Privacy Act (effective July 1, 2024). Right to know specific third parties; 30-day cure.
Breach notice: ORS 646A.600 et seq. (Oregon Consumer Identity Theft Protection Act).
Other: Unlawful Trade Practices Act. Oregon Genetic Privacy. Consumer health data considered sensitive.
Pennsylvania (PA)
Comprehensive law: No comprehensive consumer privacy statute in effect.
Breach notice: 73 P.S. § 2301 et seq. (Breach of Personal Information Notification Act).
Other: Two-party recording (18 Pa.C.S. § 5703). Unfair Trade Practices and Consumer Protection Law (private right of action).
Rhode Island (RI)
Comprehensive law: Rhode Island Data Transparency and Privacy Protection Act (effective Jan. 1, 2026).
Breach notice: R.I. Gen. Laws § 11-49.3-1 et seq.
Other: Deceptive Trade Practices Act. Identity Theft Protection Act.
South Carolina (SC)
Comprehensive law: No comprehensive consumer privacy statute in effect. Insurance data security act applies to licensees.
Breach notice: S.C. Code § 39-1-90.
Other: South Carolina Unfair Trade Practices Act.
South Dakota (SD)
Comprehensive law: No comprehensive consumer privacy statute in effect.
Breach notice: SDCL § 22-40-19 et seq.
Other: Deceptive Trade Practices and Consumer Protection.
Tennessee (TN)
Comprehensive law: Tennessee Information Protection Act (effective July 1, 2025). $25M revenue + consumer thresholds; 60-day cure.
Breach notice: Tenn. Code § 47-18-2107.
Other: Tennessee Consumer Protection Act. Identity Theft Deterrence Act.
Texas (TX)
Comprehensive law: Texas Data Privacy and Security Act (effective July 1, 2024). No revenue threshold — applies to most for-profit entities that process personal data (small-business exclusion is narrow).
Breach notice: Tex. Bus. & Com. Code § 521.053.
Other: Texas Identity Theft Enforcement and Protection Act. Deceptive Trade Practices Act. Capture or Use of Biometric Identifier statute (CUBI). Telemarketing disclosure duties.
Utah (UT)
Comprehensive law: Utah Consumer Privacy Act (effective Dec. 31, 2023). $25M revenue threshold; 30-day cure; no private right of action.
Breach notice: Utah Code § 13-44-201 et seq.
Other: Utah Consumer Sales Practices Act. Genetic testing privacy.
Vermont (VT)
Comprehensive law: Vermont Data Privacy and Online Surveillance Act (S.71 / Act 145, 2026) — enacted; effective Jan. 1, 2028. Includes a private right of action (unusual among state privacy laws).
Breach notice: 9 V.S.A. § 2430 et seq. (Security Breach Notice Act). Data-broker registration already required.
Other: Consumer Protection Act. Data broker annual registration (9 V.S.A. § 2433). Student and health confidentiality.
Virginia (VA)
Comprehensive law: Virginia Consumer Data Protection Act (effective Jan. 1, 2023) — the model many later states copied. AG exclusive enforcement; 30-day cure; sensitive-data opt-in.
Breach notice: Va. Code § 18.2-186.6.
Other: Virginia Consumer Protection Act. Health records privacy (Va. Code § 32.1-127.1:03) when medical records are involved.
Washington (WA)
Comprehensive law: No comprehensive CCPA-style law. Washington My Health My Data Act (MHMDA) regulates consumer health data — including disability inferences — with a private right of action. Washington also has a biometric identifier statute.
Breach notice: RCW 19.255.
Other: Two-party recording (RCW 9.73). Consumer Protection Act (powerful private right of action). MHMDA consent and geofencing rules are treated as in-scope for this campaign’s health-related intake.
West Virginia (WV)
Comprehensive law: No comprehensive consumer privacy statute in effect.
Breach notice: W. Va. Code § 46A-2A-101 et seq.
Other: West Virginia Consumer Credit and Protection Act.
Wisconsin (WI)
Comprehensive law: No comprehensive consumer privacy statute in effect.
Breach notice: Wis. Stat. § 134.98.
Other: Wisconsin Deceptive Trade Practices. Student and health sectoral statutes.
Wyoming (WY)
Comprehensive law: No comprehensive consumer privacy statute in effect.
Breach notice: Wyo. Stat. § 40-12-501 et seq.
Other: Wyoming Consumer Protection Act.
District of Columbia (DC)
Comprehensive law: No comprehensive consumer privacy statute identical to CCPA. D.C. has a data-breach statute and strong consumer-protection law.
Breach notice: D.C. Code § 28-3851 et seq.
Other: D.C. Consumer Protection Procedures Act (private attorney general). Call-recording and telemarketing rules of the District apply to D.C. residents.
This addendum is educational compliance mapping, not a guarantee that every statutory threshold is triggered for our operation. When a law does not yet apply, we still offer access, deletion, and opt-out.
Call +1 (561) 652-0362 · Start screening · [email protected]