🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-LA · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 15 sources retrieved model claude-sonnet-5 ·

United States – Louisiana

US-LA schema gdpri-v2 trajectory: not recordedhybrid regimeoverlaps: FIM, WPM, AIC, Crypto

Last updated · 10 categories · 0 claims · 15 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
0Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive statute enacted but not yet effective; only breach-notification law currently in force; territorial-scope and filing details unconfirmed from secondary reporting.

Primary frameworkLouisiana Data Privacy Act (SB 386 / La. R.S. Title 51, Ch. 20-B) -- enacted, effective 2027-01-01; concurrently, Louisiana Database Security Breach Notification Law (La. R.S. §51:3071 et seq.) -- in force
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberComprehensive statute enacted but not yet effective; only breach-notification law currently in force; territorial-scope and filing details unconfirmed from secondary reporting.

Sub-modules (5)

Regulator And AuthorityAmber

AG enforces breach law now; will hold exclusive LDPA enforcement authority from 2027.

Claims (2):

  • CLM-US-LA-a1b2c3d4 (claim on file)
  • CLM-US-LA-b2c3d4e5 (claim on file)

Act And InstrumentsAmber

Breach law in force; LDPA enacted, not yet effective.

Claims (2):

  • CLM-US-LA-c3d4e5f6 (claim on file)
  • CLM-US-LA-d4e5f6a7 (claim on file)

Material ScopeAmber

LDPA thresholds based on revenue/volume/data-sale reliance.

Claims (1):

  • CLM-US-LA-e5f6a7b8 (claim on file)

Territorial ScopeAmber

Applies to controllers/processors doing business in Louisiana; exact non-established-controller language not independently verified.

Claims (1):

  • CLM-US-LA-f6a7b8c9 (claim on file)

Regulator Registration And FilingRed

No registration/filing obligation identified for controllers.

Absence provenance: not recorded. Searched: Louisiana Data Privacy Act SB386 filing registration requirement, Louisiana AG data broker registry.

Claims (1):

  • CLM-US-LA-a7b8c9d0 (claim on file)
Category narrative166 words

Louisiana's data-protection posture materially changed on 2026-05-29: Governor signed SB 386, the Louisiana Data Privacy Act (LDPA), creating a new Chapter 20-B of Title 51 of the Louisiana Revised Statutes -- a comprehensive consumer privacy framework -- effective 2027-01-01. <cite index="22-1,22-2">On May 29, 2026, the Governor of Louisiana signed Senate Bill 386, establishing the Louisiana Data Privacy Act, creating a comprehensive consumer data privacy framework regulating the collection, use, and sale of personal data, set to take effect on January 1, 2027.</cite> Until that date, Louisiana's only in-force data-protection instrument is its breach-notification statute; <cite index="1-1,1-2">Louisiana requires notification of breaches pursuant to §51:3071 et seq. of Article 3701 of Title 51 of the Louisiana Revised Statutes and §16-7-701 of Chapter 7 of Article 701 of Title 16 of the Louisiana Administrative Code.</cite> The seed's characterization of Louisiana as having no comprehensive statute is now superseded by this enactment, though the JID remains a two-track regime (pre- and post- 2027-01-01) plus federal sectoral overlays (HIPAA/GLBA/COPPA/FTC Act §5).

#

Sensitive-category consent regime confirmed; lawful-basis enumeration and anonymisation safe-harbours unconfirmed.

Primary frameworkLouisiana Data Privacy Act (enacted, effective 2027-01-01)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberSensitive-category consent regime confirmed; lawful-basis enumeration and anonymisation safe-harbours unconfirmed.

Sub-modules (4)

Lawful BasesRed

No GDPR-style Art.6 enumeration confirmed; LDPA appears consent/necessity-oriented per Virginia-model peer laws.

Absence provenance: not recorded. Searched: Louisiana Data Privacy Act lawful basis processing text.

Claims (1):

  • CLM-US-LA-d0e1f2a3 (claim on file)

Special CategoriesAmber

Health, biometric, genetic, and children's data classified as sensitive.

Claims (1):

  • CLM-US-LA-c9d0e1f2 (claim on file)

Pseudonymisation And AnonymisationRed

No confirmed definitions/safe-harbours located.

Absence provenance: not recorded. Searched: Louisiana Data Privacy Act pseudonymisation anonymisation definition.

Claims (1):

  • CLM-US-LA-e1f2a3b4 (claim on file)
Category narrative50 words

The LDPA imposes consent requirements for sensitive-data processing (health, biometric, genetic, children's data) rather than a GDPR-style enumerated lawful-basis structure. <cite index="12-11,12-12">Sensitive Data Protections: Requires consumer consent for processing sensitive data, including health, biometric, genetic, and children's data.</cite> Detailed lawful-basis and pseudonymisation/anonymisation safe-harbour text was not confirmed via secondary reporting.

#

Core rights confirmed but not yet in force; response-window deadlines unconfirmed.

Primary frameworkLouisiana Data Privacy Act (enacted, effective 2027-01-01)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberCore rights confirmed but not yet in force; response-window deadlines unconfirmed.

Sub-modules (5)

Access RightAmber

Consumers may access personal data collected about them.

Claims (1):

  • CLM-US-LA-f2a3b4c5 (claim on file)

Rectification And ErasureAmber

Correction and deletion rights granted.

Claims (1):

  • CLM-US-LA-a3b4c5d6 (claim on file)

Restriction And ObjectionAmber

Opt-out of targeted advertising, sale, and harmful profiling.

Claims (1):

  • CLM-US-LA-b4c5d6e7 (claim on file)

Data PortabilityAmber

Right to a portable copy of personal data.

Claims (1):

  • CLM-US-LA-c5d6e7f8 (claim on file)

Deadlines And Response WindowsRed

No confirmed statutory response-window figures.

Absence provenance: not recorded. Searched: Louisiana Data Privacy Act response deadline days consumer request.

Claims (1):

  • CLM-US-LA-d6e7f8a9 (claim on file)
Category narrative69 words

Once effective (2027-01-01), the LDPA grants access, correction, deletion, portability, and opt-out rights typical of the Virginia/Colorado model. <cite index="68-3,68-4">Louisiana Data Privacy Act: Senate Bill 386 establishes a comprehensive consumer data privacy framework for Louisiana. Consumer Rights: Individuals can access, correct, delete, and obtain a portable copy of their personal data, and opt out of targeted advertising and data sales.</cite> Statutory response-window deadlines were not confirmed in secondary sources.

#

Breach notification in force (green-level maturity); DPIA/security/ROPA/DPO obligations under LDPA not yet effective and partly unconfirmed.

Primary frameworkLouisiana Database Security Breach Notification Law (in force); Louisiana Data Privacy Act (enacted, effective 2027-01-01); Louisiana Insurance Data Security Law (sectoral)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberBreach notification in force (green-level maturity); DPIA/security/ROPA/DPO obligations under LDPA not yet effective and partly unconfirmed.

Sub-modules (7)

Accountability And DpiaAmber

Data protection assessments required for high-risk processing under LDPA.

Claims (1):

  • CLM-US-LA-e7f8a9b0 (claim on file)

Dpo RequirementsRed

No DPO-appointment threshold confirmed.

Absence provenance: not recorded. Searched: Louisiana Data Privacy Act data protection officer requirement.

Claims (1):

  • CLM-US-LA-f8a9b0c1 (claim on file)

Ropa RequirementsRed

No records-of-processing obligation confirmed.

Absence provenance: not recorded. Searched: Louisiana Data Privacy Act records of processing activities.

Claims (1):

  • CLM-US-LA-a9b0c1d2 (claim on file)

Joint Controller ArrangementsAmber

Processor-contract clauses referenced generally as 'organizational duties'; specifics unconfirmed.

Claims (1):

  • CLM-US-LA-b0c1d2e3 (claim on file)

Security MeasuresAmber

LDPA requires reasonable security safeguards; Insurance Data Security Law imposes sector information-security-program duties on insurers.

Claims (2):

  • CLM-US-LA-c1d2e3f4 (claim on file)
  • CLM-US-LA-d2e3f4a5 (claim on file)

Breach NotificationGreen

60-day notification deadline; AG enforces; unique LA-citizen-list requirement.

Claims (2):

  • CLM-US-LA-e3f4a5b6 (claim on file)
  • CLM-US-LA-f4a5b6c7 (claim on file)

Retention And DisposalAmber

Data minimization/purpose limitation implies retention limits; explicit disposal duty unconfirmed.

Claims (1):

  • CLM-US-LA-a5b6c7d8 (claim on file)
Category narrative98 words

Breach notification is the only fully in-force duty today: <cite index="42-5">2018 alone saw eight states change their notification timelines, defining that organizations have: 60 days to notify individuals (South Dakota, Delaware, Louisiana)</cite>, and <cite index="41-7">Louisiana is unique among states because it requests a list of affected Louisiana citizens</cite>. From 2027, the LDPA adds data-protection-assessment, minimization, and security-safeguard duties: <cite index="32-5">Higher-risk processing activities such as targeted advertising, the sale of personal data, profiling with foreseeable consumer harm, and processing sensitive data require data protection assessments.</cite> A separate Louisiana Insurance Data Security Law (NAIC-model-based) imposes sector security-program duties on insurers.

#

No state-level transfer/adequacy/localisation regime exists; concept does not map onto a U.S. state JID.

Traffic-light rationale — RedNo state-level transfer/adequacy/localisation regime exists; concept does not map onto a U.S. state JID.

Sub-modules (6)

Transfer MechanismsRed

No LA-specific transfer mechanism regime.

Absence provenance: not recorded. Searched: Louisiana Data Privacy Act cross-border data transfer mechanism.

Claims (1):

  • CLM-US-LA-b6c7d8e9 (claim on file)

Adequacy ReceivedRed

Not applicable to a U.S. state.

Absence provenance: not recorded. Searched: Louisiana adequacy decision received.

Adequacy GrantedRed

Not applicable to a U.S. state.

Absence provenance: not recorded. Searched: Louisiana adequacy decision granted.

Sccs And BcrsRed

No LA-specific SCC/BCR regime.

Absence provenance: not recorded. Searched: Louisiana SCC BCR requirement.

Transfer Impact AssessmentRed

No TIA requirement.

Absence provenance: not recorded. Searched: Louisiana transfer impact assessment requirement.

Data LocalisationRed

No data-localisation mandate identified.

Absence provenance: not recorded. Searched: Louisiana data localisation mandate.

Category narrative44 words

As a U.S. sub-federal jurisdiction, Louisiana has no adequacy-decision, SCC/BCR, transfer-impact-assessment, or data-localisation regime of its own; cross-border transfer governance for Louisiana-resident data is a matter of federal-level frameworks (not itself a Louisiana instrument) and is out of scope for a state-level DP baseline.

#

Federal sectoral overlays (GLBA/HIPAA/FCRA) apply generally; insurance overlay probable; several sub-modules unconfirmed.

Primary frameworkFederal sectoral statutes (GLBA, HIPAA, FCRA) + Louisiana Insurance Data Security Law
Traffic-light rationale — AmberFederal sectoral overlays (GLBA/HIPAA/FCRA) apply generally; insurance overlay probable; several sub-modules unconfirmed.

Sub-modules (7)

Financial Sector OverlayAmber

GLBA (federal) applies to Louisiana financial institutions; no LA-specific overlay confirmed.

Claims (1):

  • CLM-US-LA-c7d8e9f0 (claim on file)

Health Sector OverlayAmber

HIPAA (federal) applies; no LA-specific overlay confirmed.

Claims (1):

  • CLM-US-LA-d8e9f0a1 (claim on file)

Telecoms And EprivacyRed

No LA-specific telecom/eprivacy statute identified.

Absence provenance: not recorded. Searched: Louisiana telecoms eprivacy cookie law.

Claims (1):

  • CLM-US-LA-e9f0a1b2 (claim on file)

Employment DataRed

No LA-specific employment-data statute identified.

Absence provenance: not recorded. Searched: Louisiana employment data privacy law.

Claims (1):

  • CLM-US-LA-f0a1b2c3 (claim on file)

Credit And ScoringAmber

FCRA (federal) applies; no LA-specific overlay confirmed.

Claims (1):

  • CLM-US-LA-a1b2c3e4 (claim on file)

EducationRed

No LA-specific student-data-privacy statute confirmed.

Absence provenance: not recorded. Searched: Louisiana student data privacy law education.

Claims (1):

  • CLM-US-LA-b2c3e4f5 (claim on file)

InsuranceAmber

Louisiana Insurance Data Security Law (NAIC-model) confirmed to exist.

Claims (1):

  • CLM-US-LA-c3e4f5a6 (claim on file)
Category narrative73 words

Financial and health data in Louisiana are governed by federal GLBA and HIPAA respectively, per the seed disambiguation: <cite index="1-1">Louisiana requires notification of breaches pursuant to §51:3071 et seq.</cite> operates alongside these federal regimes. Louisiana has also adopted an NAIC-model Insurance Data Security Law: a dedicated legal-research entry confirms its existence as Louisiana-specific instrument, though effective-date/citation detail requires primary-source confirmation. Telecoms/eprivacy, employment-data, credit-scoring and education sectoral overlays specific to Louisiana were not confirmed.

#

UOOM and cross-context ad opt-out confirmed but not yet effective; several sub-modules unconfirmed.

Primary frameworkLouisiana Data Privacy Act (enacted, effective 2027-01-01)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberUOOM and cross-context ad opt-out confirmed but not yet effective; several sub-modules unconfirmed.

Sub-modules (6)

Cookies And TrackersAmber

No LA-specific cookie law; general FTC §5 applies.

Claims (1):

  • CLM-US-LA-d4f5a6b7 (claim on file)

Dark PatternsRed

No explicit dark-pattern prohibition confirmed beyond general UDAP classification.

Absence provenance: not recorded. Searched: Louisiana Data Privacy Act dark pattern prohibition.

Claims (1):

  • CLM-US-LA-e5a6b7c8 (claim on file)

Opt Out SignalsAmber

Universal opt-out mechanism support included in LDPA.

Claims (1):

  • CLM-US-LA-f6b7c8d9 (claim on file)

Clean Rooms And DcrRed

No provision identified.

Absence provenance: not recorded. Searched: Louisiana Data Privacy Act clean room data collaboration.

Claims (1):

  • CLM-US-LA-c9e0f1a2 (claim on file)

Cross Context AdvertisingAmber

Opt-out of targeted advertising and sale confirmed.

Claims (1):

  • CLM-US-LA-a7c8d9e0 (claim on file)

Direct MarketingAmber

Covered indirectly via targeted-advertising opt-out; no dedicated suppression statute confirmed.

Claims (1):

  • CLM-US-LA-b8d9e0f1 (claim on file)
Category narrative92 words

The LDPA (effective 2027-01-01) includes universal opt-out mechanism support and opt-out rights for targeted advertising and sale of personal data: <cite index="21-4,21-5">The bill, approved 94-0 by the House 18 May, would apply to companies earning more than USD25 million in revenue and those processing the personal data of more than 75,000 people or deriving more than 50% of their revenue from the sale of personal data. Sensitive data limitations, universal opt-out mechanisms and a sunsetting right to cure are included in the bill.</cite> No LA-specific cookie-consent, dark-pattern, or clean-room statute was confirmed.

#

Sensitive-category coverage confirmed but not yet effective; ADM transparency and surveillance carveouts unconfirmed.

Primary frameworkLouisiana Data Privacy Act (enacted, effective 2027-01-01)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberSensitive-category coverage confirmed but not yet effective; ADM transparency and surveillance carveouts unconfirmed.

Sub-modules (6)

Profiling RestrictionsAmber

DPA required for profiling with foreseeable consumer harm.

Claims (1):

  • CLM-US-LA-d0f1a2b3 (claim on file)

Automated Decision Making TransparencyRed

No explicit ADM explanation/transparency right confirmed.

Absence provenance: not recorded. Searched: Louisiana Data Privacy Act automated decision making transparency right.

Claims (1):

  • CLM-US-LA-e1a2b3c4 (claim on file)

Ai Risk AssessmentsAmber

DPA requirement functions as an AI-risk-assessment analog for high-risk processing.

Claims (1):

  • CLM-US-LA-f2b3c4d5 (claim on file)

Biometric RegimeAmber

Biometric data is a sensitive category requiring consent; no dedicated BIPA-style statute confirmed.

Claims (1):

  • CLM-US-LA-a3c4d5e6 (claim on file)

Genetic DataAmber

Genetic data is a sensitive category requiring consent.

Claims (1):

  • CLM-US-LA-b4d5e6f7 (claim on file)

State Surveillance CarveoutsRed

No specific carveout provision identified.

Absence provenance: not recorded. Searched: Louisiana Data Privacy Act national security law enforcement exemption.

Claims (1):

  • CLM-US-LA-c5e6f7a8 (claim on file)
Category narrative74 words

The LDPA treats biometric and genetic data as sensitive categories requiring consent and mandates data-protection assessments for profiling that presents a foreseeable risk of harm: <cite index="32-5">Higher-risk processing activities such as targeted advertising, the sale of personal data, profiling with foreseeable consumer harm, and processing sensitive data require data protection assessments.</cite> No dedicated ADM-transparency/explanation right (Colorado-style) or standalone biometric statute (Illinois-BIPA-style private right of action) was confirmed for Louisiana; state-surveillance carveouts were not confirmed.

#

Parental-consent social-media laws in force; LDPA minors provisions not yet effective; education/dependent-adult gaps.

Primary frameworkLouisiana social-media parental-consent/age-verification statutes (in force) + Louisiana Data Privacy Act (enacted, effective 2027-01-01)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberParental-consent social-media laws in force; LDPA minors provisions not yet effective; education/dependent-adult gaps.

Sub-modules (5)

Age VerificationAmber

Louisiana has enacted age-verification-related legislation for minors' online interactions (e.g., Secure Online Child Interaction and Age Limitation Act).

Claims (1):

  • CLM-US-LA-d6f7a8b9 (claim on file)

Minor Profiling BansAmber

Children's data sensitive-category consent + foreseeable-harm profiling DPA under LDPA.

Claims (1):

  • CLM-US-LA-f8b9c0d1 (claim on file)

Education SettingsRed

No education-sector-specific statute confirmed.

Absence provenance: not recorded. Searched: Louisiana student data privacy education sector law.

Claims (1):

  • CLM-US-LA-a9c0d1e2 (claim on file)

Dependent AdultsRed

No dependent-adult protection provision identified.

Absence provenance: not recorded. Searched: Louisiana dependent adult data protection elderly.

Claims (1):

  • CLM-US-LA-b0d1e2f3 (claim on file)
Category narrative59 words

Louisiana has enacted minor-specific online-safety statutes requiring parental consent for social-media use, alongside Arkansas, Texas and Utah: <cite index="90-10">New laws in Arkansas, Louisiana, Texas and Utah essentially ban social media services from letting minors use their features without parental consent.</cite> The LDPA (2027) separately classifies children's data as sensitive, requiring consent. Education-setting-specific rules and dependent-adult protections were not confirmed.

#

Enforcement powers confirmed but not yet effective; no LA-specific enforcement-activity or funding data located.

Primary frameworkLouisiana Data Privacy Act (enacted, effective 2027-01-01)
Supervisory authorityLouisiana Attorney General
Traffic-light rationale — AmberEnforcement powers confirmed but not yet effective; no LA-specific enforcement-activity or funding data located.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

AG exclusive enforcement, UDAP classification, 30-day cure period.

Claims (1):

  • CLM-US-LA-c1e2f3a4 (claim on file)

Enforcement Activity IndexRed

No LA-specific major enforcement action identified in the last 12 months.

Absence provenance: not recorded. Searched: Louisiana Attorney General privacy enforcement action settlement 2025 2026.

Claims (1):

  • CLM-US-LA-d2f3a4b5 (claim on file)

Regulator Funding And CapacityRed

No headcount/funding signal identified.

Absence provenance: not recorded. Searched: Louisiana Attorney General privacy office funding staff.

Claims (1):

  • CLM-US-LA-e3a4b5c6 (claim on file)

Collective Redress And Class ActionsAmber

No dedicated class-action mechanism under LDPA confirmed; general LA civil procedure may apply.

Claims (1):

  • CLM-US-LA-a5c6d7e8 (claim on file)

Private Right Of ActionAmber

No private right of action under LDPA; enforcement is AG-exclusive.

Claims (1):

  • CLM-US-LA-f4b5c6d7 (claim on file)

Recent Developments 180DAmber

LDPA signed into law 2026-05-29, effective 2027-01-01 -- the defining recent development.

Claims (1):

  • CLM-US-LA-b6d7e8f9 (claim on file)
Category narrative102 words

The LDPA (effective 2027-01-01) grants exclusive enforcement authority to the Louisiana Attorney General, treats violations as unfair-or-deceptive trade practices, and includes a sunsetting 30-day cure period: <cite index="32-3,32-4">Enforcement: Exclusive authority granted to the Louisiana Attorney General, with violations classified as unfair or deceptive trade practices. Review compliance requirements: Businesses operating in Louisiana should review the new data privacy framework to ensure compliance by January 1, 2027.</cite> <cite index="52-8">Enforcement: Handled by the Attorney General with a 30-day cure period for violations.</cite> No private right of action was identified. The single most significant development in the last 180 days is the LDPA's enactment itself.

No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Louisiana
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 0 claim(s), 15 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacydata localisation
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated. T1 anchors used for: regulator_and_framework (breach statute + LDPA enactment), controller_processor_duties.breach_notification (in-force statute), data_subject_rights and adtech/algorithmic/children modules (T1 LDPA enactment citations via T1-tier reporting on primary statute, with sub-module detail resting on T2 secondary reporting -- IAPP/DataGuidance -- since the LDPA's full statutory text was not independently fetchable). sectoral_watch.insurance and children.age_verification relied on T2 secondary confirmation of statute existence without primary-text verification. cross_border_and_adequacy correctly carries no populated claims beyond an absence-finding, as the concept does not map onto a US sub-federal JID. Several sub-modules (DPO thresholds, ROPA, ADM transparency, response-window deadlines, dependent adults, education settings, telecoms/eprivacy, employment data, state-surveillance carveouts) carry explicit absent_field_provenance because no confirming source was found in this research pass.

Unresolved questions (6):

  • Exact statutory text of SB 386 / LDPA (Ch. 20-B, Title 51) for: enumerated lawful bases, DPO appointment thresholds, ROPA obligations, consumer-request response-window deadlines, and ADM transparency/explanation rights.
  • Precise effective date and statutory citation of the Louisiana Insurance Data Security Law (NAIC-model) and whether Louisiana has fully adopted the model law's breach-reporting timelines.
  • Whether Louisiana has a dedicated K-12/higher-education student-data-privacy statute distinct from the children's online-safety acts identified.
  • Whether any Louisiana-specific enforcement actions (AG investigations, settlements) have occurred under the breach-notification law or in anticipation of the LDPA within the last 12 months.
  • Whether the LDPA's 'sunsetting right to cure' has a defined sunset date, and the precise territorial-scope language for non-established controllers.
  • Whether Louisiana's age-verification/parental-consent minors' laws (Act No. 456, Kids Online Protection and Anti-Grooming Act) remain in force as enacted or have been enjoined (cf. ongoing NetChoice-style litigation trends affecting peer-state minor online-safety laws).

Escalate to primary-source review: yes