Skip to content

Evidence request lists

Wisconsin Data Privacy Act (SB 670)

Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Consumer Rights

WI-DPA-APP.2
Appeals process for denied rights requests

Controllers must establish a process for consumers to appeal a denial of a rights request, with response and explanation within a defined window, and a referral path to the Attorney General.

Artefacts an auditor will ask for
  • Appeals process documentation
  • Appeals log with outcomes
  • Standard appeal response templates
  • Referral language pointing to the Attorney General
Where this commonly fails
  • Appeals process undocumented or not publicised
  • Appeals decisions made by the same person who denied the initial request
  • No referral pathway
WI-DPA-NDR.1
Non-discrimination for exercising rights

Controllers must not discriminate against consumers for exercising their rights under the Act, including denial of goods or services, charging different prices, or providing a different level or quality of service.

Artefacts an auditor will ask for
  • Non-discrimination policy
  • Loyalty programme review
  • Pricing differentials analysis tied to rights exercise
  • Training records
Where this commonly fails
  • Loyalty programmes condition benefits on broad data uses
  • Pricing differentials unmonitored
  • Training not delivered to frontline staff
WI-DPA-RTS.1
Consumer right to access personal data

Controllers must provide consumers with confirmation of processing and access to their personal data within the statutory response window, free of charge for the first request in a 12-month period.

Artefacts an auditor will ask for
  • Rights request intake channel
  • Identity verification procedure
  • Service level metrics for response within 45 days with allowed extension
  • Sample disclosure response packs
Where this commonly fails
  • No tracking of statutory clock
  • Verification disproportionate to request risk
  • Disclosure pack omits processing purposes or recipient categories
WI-DPA-RTS.2
Consumer right to correct inaccurate personal data

Consumers may request correction of inaccurate personal data, with the controller required to correct, considering the nature of the data and the purposes of processing.

Artefacts an auditor will ask for
  • Correction request workflow
  • Evidence supporting accuracy determinations
  • Downstream propagation log to recipients
  • Records where correction was refused with rationale
Where this commonly fails
  • Correction limited to primary system, not propagated to downstream consumers of data
  • Refusals lack documented basis
  • No notification to consumer of correction outcome
WI-DPA-RTS.3
Consumer right to delete personal data

Consumers may request deletion of personal data, including data the controller obtained from third parties as well as data provided by the consumer, subject to recognised exceptions.

Artefacts an auditor will ask for
  • Deletion workflow covering primary, backup, archival, and recipient systems
  • Exception register with legal basis
  • Downstream recipient notification log
  • Closure confirmation to the consumer
Where this commonly fails
  • Backups excluded without documented basis
  • Third-party-sourced data ignored
  • No log of downstream notification
WI-DPA-RTS.4
Consumer right to data portability

Consumers may obtain a copy of personal data they provided to the controller in a portable, readily usable format that allows transfer to another controller, where technically feasible.

Artefacts an auditor will ask for
  • Portable export format specification
  • Sample exports demonstrating machine readability
  • Documentation of technical feasibility assessments for refusals
  • Security controls applied to portable exports
Where this commonly fails
  • Exports in non-portable PDF only
  • No assessment for technical feasibility refusals
  • Exports lack encryption or recipient verification
WI-DPA-RTS.5
Right to opt out of sale, targeted advertising, and profiling

Consumers must be able to opt out of processing for purposes of targeted advertising, the sale of personal data, and profiling in furtherance of decisions producing legal or similarly significant effects.

Artefacts an auditor will ask for
  • Opt-out mechanisms accessible from privacy notice and product surfaces
  • Universal opt-out signal handling documentation
  • Suppression lists propagated to ad-tech vendors
  • Profiling inventory listing decisions and effects
Where this commonly fails
  • Universal opt-out signals ignored
  • Opt-out limited to email rather than all channels
  • Profiling inventory missing or limited to obvious cases

Controller Duties

WI-DPA-DAR.1
De-identified data safeguards

Where controllers process de-identified data, they must take reasonable measures to ensure data cannot be associated with an individual, publicly commit to not re-identify the data, and contractually bind recipients to the same.

Artefacts an auditor will ask for
  • De-identification methodology documentation
  • Public statement of no re-identification
  • Contracts with recipients of de-identified data
  • Re-identification risk assessment
Where this commonly fails
  • Pseudonymised data treated as de-identified
  • No public no-re-identify commitment
  • Recipient contracts silent on re-identification
WI-DPA-PUR.1
Purpose limitation and data minimisation

Controllers must limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which the data are processed, as disclosed to the consumer.

Artefacts an auditor will ask for
  • Field-level necessity review for each processing activity
  • Documented purposes per processing activity
  • Periodic re-justification cadence
  • Field deprecation backlog with target dates
Where this commonly fails
  • Necessity reviewed at design time only
  • Purposes drift from disclosed purposes without re-notice
  • Deprecated fields retained indefinitely
WI-DPA-SEC.1
Reasonable administrative, technical, and physical security

Controllers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices that protect confidentiality, integrity, and accessibility of personal data appropriate to the volume and nature of the data.

Artefacts an auditor will ask for
  • Information security policy
  • Risk assessment outputs
  • Encryption and key management standards
  • Access control reviews
  • Incident response procedure
Where this commonly fails
  • Policy exists without evidence of operation
  • Risk assessment outdated
  • Encryption gaps for backups and analytics environments

Enforcement

WIPRIVACY-4
Enforcement

Per Wisconsin Data Privacy Act (SB 670): Enforcement. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.

Artefacts an auditor will ask for
  • Authoritative source-grounded evidence for WIPRIVACY-4
Where this commonly fails
  • see authoritative source for detailed gap analysis

Governance and Enforcement

WI-DPA-ENF.1
Attorney General enforcement and cure period

The Wisconsin Department of Justice has exclusive enforcement authority, with a defined cure period for first-time violations and civil penalties for uncured or wilful violations.

Artefacts an auditor will ask for
  • Procedure for receiving and responding to notice of violation
  • Cure tracking system
  • Internal escalation matrix to legal counsel
  • Insurance review for regulatory penalties
Where this commonly fails
  • No procedure for handling regulator inquiries
  • Cure activities not tracked centrally
  • Insurance silent on regulatory penalties
WI-DPA-REC.1
Programme governance and accountability

Controllers should designate accountable owners, maintain processing records, and demonstrate the operation of the privacy programme through internal assessments, management review, and metrics.

Artefacts an auditor will ask for
  • Privacy programme charter and accountable owner
  • Processing register
  • Internal assessment reports
  • Management review minutes
  • KPIs and KRIs for the programme
Where this commonly fails
  • No single accountable owner
  • Processing register held in scattered sheets
  • Management review absent or informal

Notice and Transparency

WI-DPA-NOT.1
Privacy notice content and accessibility

Controllers must publish a clear, accessible privacy notice that identifies categories of personal data processed, purposes, categories of recipients, sale and targeted advertising disclosures, and the rights process.

Artefacts an auditor will ask for
  • Published privacy notice
  • Notice content traceability matrix to processing inventory
  • Accessibility conformance statement
  • Notice version history
Where this commonly fails
  • Notice not updated after processing changes
  • No traceability between notice content and processing inventory
  • Notice not accessible to assistive technology

Processors and Assessments

WI-DPA-CON.2
Processor contractual obligations

Controllers must execute written contracts with processors specifying processing instructions, nature and purpose, types of personal data, duration, confidentiality, subprocessor authorisation, return or deletion obligations, and audit rights.

Artefacts an auditor will ask for
  • Standard processor contract clauses
  • Executed contracts inventory
  • Subprocessor approval register
  • Processor attestation or audit reports
Where this commonly fails
  • Subprocessor approvals retroactive
  • Audit clauses present but never exercised
  • Contracts lack return or deletion terms
WI-DPA-DPA.1
Data protection assessments for higher-risk processing

Controllers must conduct and document data protection assessments for processing presenting heightened risk to consumers, including targeted advertising, sale of personal data, processing of sensitive data, and certain profiling.

Artefacts an auditor will ask for
  • Data protection assessment template
  • Completed assessments for in-scope processing
  • Trigger criteria for new assessments
  • Repository accessible to the Attorney General on request
Where this commonly fails
  • Assessments completed without independent review
  • No trigger for reassessment when processing changes
  • Assessments not available to legal counsel

Rights

WIPRIVACY-2
Consumer Rights

Per Wisconsin Data Privacy Act (SB 670): Consumer Rights. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.

Artefacts an auditor will ask for
  • Authoritative source-grounded evidence for WIPRIVACY-2
Where this commonly fails
  • see authoritative source for detailed gap analysis

Scope

WIPRIVACY-1
Scope and Applicability

Per Wisconsin Data Privacy Act (SB 670): Scope and Applicability. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.

Artefacts an auditor will ask for
  • Authoritative source-grounded evidence for WIPRIVACY-1
Where this commonly fails
  • see authoritative source for detailed gap analysis

Scope and Applicability

WI-DPA-APP.1
Applicability threshold determination

Controllers must document whether they meet the proposed applicability thresholds for processing personal data of Wisconsin residents, including volume of consumers processed and percentage of revenue from data sales, on a defined cadence.

Artefacts an auditor will ask for
  • Applicability assessment report
  • Consumer volume metrics for Wisconsin residents
  • Revenue analysis for data sales share
  • Annual reassessment record
Where this commonly fails
  • Threshold assessed once at entry without periodic refresh
  • No segregation of Wisconsin consumer counts from national base
  • Revenue from data sales not separately tracked
WI-DPA-PUB.1
Public-interest, research, and exempt processing

Controllers must document reliance on statutory exemptions including public health, scientific or historical research, internal use compatible with consumer expectations, and other recognised carve-outs.

Artefacts an auditor will ask for
  • Exemption decision register
  • Research ethics or institutional review documentation
  • Compatibility analysis for internal uses
  • Periodic review of exemption reliance
Where this commonly fails
  • Research exemption claimed without ethical oversight
  • Compatibility analyses absent
  • Exemption use grows over time without governance

Sensitive

WIPRIVACY-3
Sensitive Data and DPIA

Per Wisconsin Data Privacy Act (SB 670): Sensitive Data and DPIA. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.

Artefacts an auditor will ask for
  • Authoritative source-grounded evidence for WIPRIVACY-3
Where this commonly fails
  • see authoritative source for detailed gap analysis

Sensitive and Children Data

WI-DPA-CHI.1
Processing of children's personal data

Where the controller knowingly processes personal data of a child as defined under COPPA, the controller must comply with COPPA verifiable parental consent and notice obligations as adopted by reference in the Act.

Artefacts an auditor will ask for
  • Age screening on services likely to attract children
  • Verifiable parental consent procedures
  • Safe Harbor membership or equivalent attestation
  • Documentation of knowledge determinations
Where this commonly fails
  • No age screening on consumer-facing apps
  • Parental consent provided through unverified methods
  • No documented analysis of knowledge thresholds
WI-DPA-CON.1
Opt-in consent for processing of sensitive data

Processing of sensitive data requires the controller to obtain freely given, specific, informed, unambiguous, opt-in consent from the consumer, or for known children process in accordance with COPPA.

Artefacts an auditor will ask for
  • Sensitive data consent capture screens
  • Versioned consent records with timestamps
  • Children's data flow documented against COPPA verifiable parental consent
  • Revocation process documentation
Where this commonly fails
  • Consent combined with general terms
  • No versioning of consent text
  • Children's data handled without COPPA verifiable parental consent
WI-DPA-DEF.1
Identification of sensitive personal data

Sensitive data categories such as racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data, children's data, and precise geolocation must be identified within processing inventories.

Artefacts an auditor will ask for
  • Processing inventory tagging sensitive data categories
  • Data classification standard
  • Source-to-field mapping for sensitive categories
  • Review of inferred data for sensitive classification
Where this commonly fails
  • Inferred sensitive data not classified
  • Biometric data treated as ordinary identifier
  • Precise geolocation processed without classification
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.