Skip to content

An Updated Template for State Law Processing Terms

The NAI is releasing Version 2.0 of its Template State Privacy Law Processing Addendum (the “Addendum”). The central design goal of this update was durability: terms that keep working as the statutory landscape keeps moving.

The template is available to members and non-members alike to use and draw from. It is intended to supplement whatever commercial agreement two companies already have, and addresses the contract terms that state privacy laws require for the personal data moving in connection with those agreements.

What’s new in Version 2.0

  • The terms governing disclosures of personal data to third parties are no longer written for California alone; they now attach wherever a state requires them (now including Delaware!).
  • A new provision keeps certain personal data from moving to a third party where a state bars the transfer to a third party outright.
  • The signal that turns a recipient into a processor is defined more carefully, and set apart from the opt-out signal a consumer sends to a business. Verification and remediation are written as rights the disclosing party holds rather than as promises to cooperate. The processor terms account for state-run request and deletion systems, California’s among them, and the parties are now asked to state how long data is kept.
  • The definition of covered laws is intended to reach any new state privacy laws as its provisions take effect, so the template does not need reissuing every time a legislature acts.
  • Parties who want NAI’s updates to flow through automatically can elect that, within limits.

What changed in the law

The last time the Addendum was updated, nine states had privacy laws addressing contract terms. Now, there are 24 state laws to grapple with, with more passing every year. Beyond addressing an increase in the number of states covered, several newer state law requirements were not addressed by the prior version of the Addendum.

First, contract requirements for disclosures of personal data to third parties are no longer a California-only issue. Version 2.0 answers this by untying those terms from California. They now attach whenever a state requires a contract containing specified terms for disclosures of personal data to third parties. Delaware also requires the contract to state whether the disclosed data may be used for decisions producing legal or similarly significant effects — a term with no CCPA counterpart. Version 2.0 addresses it by excluding that use from the advertising purposes the template covers.

Second, several states have adopted prohibitions on particular transfers that operate regardless of consent. Version 2.0 answers this with a new obligation on the disclosing party: do not send personal data where the applicable state law bars the transfer or the processing notwithstanding consent, or where a required consent or condition has not been met. It is keyed to the law rather than to a fixed list of data categories, so it keeps pace as states add restrictions.

Third, the signaling ecosystem has continued to mature and evolve. Version 1.1 referenced the IAB CCPA Compliance Framework, whose technical specifications were deprecated on January 31, 2024 and replaced by IAB Tech Lab’s more robust Global Privacy Protocol (GPP). Further, more states have separately adopted requirements for consumer-facing opt-out preference signals or universal opt-out mechanisms.

The updated Addendum addresses both. It updates the signaling reference while keeping any other format the parties agree to, and it states expressly that the Restricted Processing Signal is a business-to-business signal travelling with the data — not a consumer’s own opt-out preference signal — so the contractual signal is not read as standing in for a party’s independent obligations.

What if more state privacy laws are passed?

The definition of “State Privacy Laws” in the updated Addendum now names the current set and adds criteria-based language reaching any other state law of general application that grants consumers a right to opt out of targeted advertising, the sale of personal data, or both.

For parties who want updates to flow through automatically, the updated Addendum offers an optional provision under which NAI-published updates apply prospectively on at least 30 days’ notice.

What the template does not do

It is not intended to cover every purpose of processing (it is limited to advertising purposes), and it is not drafted for personal data subject to EU law or to other non-U.S. jurisdictions’ requirements. It does not address sensitive information, including how consent for sensitive information is obtained or passed. The one thing it does say is that a party will not transmit personal data where a state law prohibits the transmission or the processing notwithstanding consent, or where a required consent or condition has not been satisfied. It does not set pricing, indemnities, or liability caps; those belong in the underlying agreement, and the template is drafted to stay out of them.

Unlike the IAB Multi-State Privacy Agreement (MSPA), which forms a single agreement among all of its signatories and applies to the transactions they signal as covered, this template creates privity only between the two counterparties that execute it.

For companies that have signed the MSPA, the template can operate independently for transactions that are not covered under the MSPA.

Getting the template

Version 2.0 and the accompanying FAQ are available at https://thenai.org/nai-state-law-processing-addendum/

The FAQs also address questions that may arise in more detail.