Wisconsin Data Privacy Act (SB 670)
Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Consumer Rights
Controllers must establish a process for consumers to appeal a denial of a rights request, with response and explanation within a defined window, and a referral path to the Attorney General.
- Appeals process documentation
- Appeals log with outcomes
- Standard appeal response templates
- Referral language pointing to the Attorney General
- Appeals process undocumented or not publicised
- Appeals decisions made by the same person who denied the initial request
- No referral pathway
Controllers must not discriminate against consumers for exercising their rights under the Act, including denial of goods or services, charging different prices, or providing a different level or quality of service.
- Non-discrimination policy
- Loyalty programme review
- Pricing differentials analysis tied to rights exercise
- Training records
- Loyalty programmes condition benefits on broad data uses
- Pricing differentials unmonitored
- Training not delivered to frontline staff
Controllers must provide consumers with confirmation of processing and access to their personal data within the statutory response window, free of charge for the first request in a 12-month period.
- Rights request intake channel
- Identity verification procedure
- Service level metrics for response within 45 days with allowed extension
- Sample disclosure response packs
- No tracking of statutory clock
- Verification disproportionate to request risk
- Disclosure pack omits processing purposes or recipient categories
Consumers may request correction of inaccurate personal data, with the controller required to correct, considering the nature of the data and the purposes of processing.
- Correction request workflow
- Evidence supporting accuracy determinations
- Downstream propagation log to recipients
- Records where correction was refused with rationale
- Correction limited to primary system, not propagated to downstream consumers of data
- Refusals lack documented basis
- No notification to consumer of correction outcome
Consumers may request deletion of personal data, including data the controller obtained from third parties as well as data provided by the consumer, subject to recognised exceptions.
- Deletion workflow covering primary, backup, archival, and recipient systems
- Exception register with legal basis
- Downstream recipient notification log
- Closure confirmation to the consumer
- Backups excluded without documented basis
- Third-party-sourced data ignored
- No log of downstream notification
Consumers may obtain a copy of personal data they provided to the controller in a portable, readily usable format that allows transfer to another controller, where technically feasible.
- Portable export format specification
- Sample exports demonstrating machine readability
- Documentation of technical feasibility assessments for refusals
- Security controls applied to portable exports
- Exports in non-portable PDF only
- No assessment for technical feasibility refusals
- Exports lack encryption or recipient verification
Consumers must be able to opt out of processing for purposes of targeted advertising, the sale of personal data, and profiling in furtherance of decisions producing legal or similarly significant effects.
- Opt-out mechanisms accessible from privacy notice and product surfaces
- Universal opt-out signal handling documentation
- Suppression lists propagated to ad-tech vendors
- Profiling inventory listing decisions and effects
- Universal opt-out signals ignored
- Opt-out limited to email rather than all channels
- Profiling inventory missing or limited to obvious cases
Controller Duties
Where controllers process de-identified data, they must take reasonable measures to ensure data cannot be associated with an individual, publicly commit to not re-identify the data, and contractually bind recipients to the same.
- De-identification methodology documentation
- Public statement of no re-identification
- Contracts with recipients of de-identified data
- Re-identification risk assessment
- Pseudonymised data treated as de-identified
- No public no-re-identify commitment
- Recipient contracts silent on re-identification
Controllers must limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which the data are processed, as disclosed to the consumer.
- Field-level necessity review for each processing activity
- Documented purposes per processing activity
- Periodic re-justification cadence
- Field deprecation backlog with target dates
- Necessity reviewed at design time only
- Purposes drift from disclosed purposes without re-notice
- Deprecated fields retained indefinitely
Controllers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices that protect confidentiality, integrity, and accessibility of personal data appropriate to the volume and nature of the data.
- Information security policy
- Risk assessment outputs
- Encryption and key management standards
- Access control reviews
- Incident response procedure
- Policy exists without evidence of operation
- Risk assessment outdated
- Encryption gaps for backups and analytics environments
Enforcement
Per Wisconsin Data Privacy Act (SB 670): Enforcement. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.
- Authoritative source-grounded evidence for WIPRIVACY-4
- see authoritative source for detailed gap analysis
Governance and Enforcement
The Wisconsin Department of Justice has exclusive enforcement authority, with a defined cure period for first-time violations and civil penalties for uncured or wilful violations.
- Procedure for receiving and responding to notice of violation
- Cure tracking system
- Internal escalation matrix to legal counsel
- Insurance review for regulatory penalties
- No procedure for handling regulator inquiries
- Cure activities not tracked centrally
- Insurance silent on regulatory penalties
Controllers should designate accountable owners, maintain processing records, and demonstrate the operation of the privacy programme through internal assessments, management review, and metrics.
- Privacy programme charter and accountable owner
- Processing register
- Internal assessment reports
- Management review minutes
- KPIs and KRIs for the programme
- No single accountable owner
- Processing register held in scattered sheets
- Management review absent or informal
Notice and Transparency
Controllers must publish a clear, accessible privacy notice that identifies categories of personal data processed, purposes, categories of recipients, sale and targeted advertising disclosures, and the rights process.
- Published privacy notice
- Notice content traceability matrix to processing inventory
- Accessibility conformance statement
- Notice version history
- Notice not updated after processing changes
- No traceability between notice content and processing inventory
- Notice not accessible to assistive technology
Processors and Assessments
Controllers must execute written contracts with processors specifying processing instructions, nature and purpose, types of personal data, duration, confidentiality, subprocessor authorisation, return or deletion obligations, and audit rights.
- Standard processor contract clauses
- Executed contracts inventory
- Subprocessor approval register
- Processor attestation or audit reports
- Subprocessor approvals retroactive
- Audit clauses present but never exercised
- Contracts lack return or deletion terms
Controllers must conduct and document data protection assessments for processing presenting heightened risk to consumers, including targeted advertising, sale of personal data, processing of sensitive data, and certain profiling.
- Data protection assessment template
- Completed assessments for in-scope processing
- Trigger criteria for new assessments
- Repository accessible to the Attorney General on request
- Assessments completed without independent review
- No trigger for reassessment when processing changes
- Assessments not available to legal counsel
Rights
Per Wisconsin Data Privacy Act (SB 670): Consumer Rights. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.
- Authoritative source-grounded evidence for WIPRIVACY-2
- see authoritative source for detailed gap analysis
Scope
Per Wisconsin Data Privacy Act (SB 670): Scope and Applicability. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.
- Authoritative source-grounded evidence for WIPRIVACY-1
- see authoritative source for detailed gap analysis
Scope and Applicability
Controllers must document whether they meet the proposed applicability thresholds for processing personal data of Wisconsin residents, including volume of consumers processed and percentage of revenue from data sales, on a defined cadence.
- Applicability assessment report
- Consumer volume metrics for Wisconsin residents
- Revenue analysis for data sales share
- Annual reassessment record
- Threshold assessed once at entry without periodic refresh
- No segregation of Wisconsin consumer counts from national base
- Revenue from data sales not separately tracked
Controllers must document reliance on statutory exemptions including public health, scientific or historical research, internal use compatible with consumer expectations, and other recognised carve-outs.
- Exemption decision register
- Research ethics or institutional review documentation
- Compatibility analysis for internal uses
- Periodic review of exemption reliance
- Research exemption claimed without ethical oversight
- Compatibility analyses absent
- Exemption use grows over time without governance
Sensitive
Per Wisconsin Data Privacy Act (SB 670): Sensitive Data and DPIA. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.
- Authoritative source-grounded evidence for WIPRIVACY-3
- see authoritative source for detailed gap analysis
Sensitive and Children Data
Where the controller knowingly processes personal data of a child as defined under COPPA, the controller must comply with COPPA verifiable parental consent and notice obligations as adopted by reference in the Act.
- Age screening on services likely to attract children
- Verifiable parental consent procedures
- Safe Harbor membership or equivalent attestation
- Documentation of knowledge determinations
- No age screening on consumer-facing apps
- Parental consent provided through unverified methods
- No documented analysis of knowledge thresholds
Processing of sensitive data requires the controller to obtain freely given, specific, informed, unambiguous, opt-in consent from the consumer, or for known children process in accordance with COPPA.
- Sensitive data consent capture screens
- Versioned consent records with timestamps
- Children's data flow documented against COPPA verifiable parental consent
- Revocation process documentation
- Consent combined with general terms
- No versioning of consent text
- Children's data handled without COPPA verifiable parental consent
Sensitive data categories such as racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data, children's data, and precise geolocation must be identified within processing inventories.
- Processing inventory tagging sensitive data categories
- Data classification standard
- Source-to-field mapping for sensitive categories
- Review of inferred data for sensitive classification
- Inferred sensitive data not classified
- Biometric data treated as ordinary identifier
- Precise geolocation processed without classification
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.