Analysis

Analysis of U.S. state privacy and AI laws

Consumer privacy23

The Alabama Personal Data Protection Act is very business-friendly, including lacking a data protection impact assessment requirement and not requiring recognition of opt-out preference signals.

The California Consumer Privacy Act (CCPA) was the nation's first broad consumer data privacy law. It is the only state consumer data privacy law to broadly apply to employee and business-to-business data. The CCPA is vigorously enforced through the California Attorney General's office and the California Privacy Protection Agency (CalPrivacy). The CCPA's statutory provisions must be read in…

Read the full analysis →

Colorado was the third state to pass a consumer data privacy law, and the first to require controllers to recognize universal opt-out mechanisms and to decline to exempt nonprofits and HIPAA-covered entities. The law required the Colorado Attorney General's office to promulgate interpretive rules, which are important to review when analyzing the law's requirements. The law has been amended…

Read the full analysis →

Originally passed in 2022, the Connecticut Data Privacy Act has been amended three times since and is one of the strongest in the country. The 2023 amendment added children's privacy and consumer health data privacy provisions. The 2025 amendment modified the law's applicability standard, exemptions, definitions, consumer rights, data minimization provisions, and minors' privacy sections, and…

Read the full analysis →

The law is one of the more consumer-friendly laws passed to date. It applies to entities that process the personal data of 35,000 consumers. The law also applies to nonprofits, with a couple of exceptions. There is no HIPAA-covered entity exemption, but there are data-level health data exemptions. The law adds the right to obtain a list of categories of third parties to which the controller has…

Read the full analysis →

Indiana's law is based on Virginia's law, with some notable variations. There is a right to correct inaccurate information, but only information that the consumer previously provided to the controller — not all information the controller possesses about the consumer. The right to access also contains language giving the controller the option to provide a copy of the personal data or a…

Read the full analysis →

Iowa's law rivals Utah's as the most business-friendly in the country. The law does not contain a right to correction or a right to opt out of profiling, and it is unclear whether there is a right to opt out of targeted advertising. It also uses a narrow definition of sale. It is one of two laws that relies on notice and an opportunity to object to process sensitive data instead of consent. The…

Read the full analysis →

Kentucky's law largely tracks the Virginia Consumer Data Protection Act. In 2026, the law was amended to add “automatic content recognition” as a category of sensitive data.

Louisiana is the 22nd state to enact a broad consumer privacy law, and it generally follows the Texas model. The important difference is applicability: the standard appears borrowed from the CCPA and turns on revenue and volume without reference to whether you process personal data — so it may reach businesses that would not expect to be covered, including business-to-business companies.

Maryland's law sets a low applicability threshold of 35,000 consumers. Its core feature is data minimization: controllers must limit personal data collection to what is reasonably necessary and proportionate to provide the requested product or service, and limit sensitive data collection, processing, and sharing to what is "strictly necessary" for that purpose. Selling sensitive data is…

Read the full analysis →

The law applies the standard 100,000-consumer threshold, exempting small businesses (though even they cannot sell sensitive data without consent). Consumer rights include a right to obtain a list of third parties to whom personal data was transferred. The law creates a first-in-the-nation right to question profiling results and receive information about the profiling process. Privacy policy…

Read the full analysis →

Montana's law is one of the more consumer-friendly laws in the country. Montana was the first state to lower the applicability threshold from 100,000 to 50,000 consumers. It was also the first Republican state to require controllers to recognize universal opt-out mechanisms, and one of the first to include heightened protections for children's data. Montana's law was amended in 2025 to add…

Read the full analysis →

Nebraska's law largely tracks the Texas Data Privacy and Security Act. Like Texas, applicability is not based on a consumer-count threshold – instead, it turns on whether an entity sells personal data and qualifies as a small business.

New Hampshire's law largely tracks the Connecticut law as originally passed in 2022, without the 2023 amendments (e.g., adding consumer health data to the definition of sensitive data). The law applies to controllers that process the personal data of 35,000 consumers. In 2026, the law was amended to prohibit the sale of personal data belonging to children under 13.

The law generally follows the Virginia structure, but there are entire paragraphs and provisions found in laws like Connecticut's that are missing from this law. The definition of sensitive personal data broadly includes financial information. The law also has unique definitions of biometric data and processing, and omits a key exception in the definition of sale. The law has narrower exemptions…

Read the full analysis →

Oklahoma's law is a more business friendly law that is based on the laws in Virginia and Texas. It does not require controllers to recognize universal opt out mechanisms.

Oregon's law is one of the more consumer-friendly privacy laws enacted to date. The law does not have a HIPAA-covered entity exemption, and its GLBA entity-level exemption language is narrower. The law applies to non-profits with a couple of exceptions. The definitions of personal data, biometric data, and sensitive data are unique and are intended to be broader and cover more information than in…

Read the full analysis →

Enacted in 2024, the law is notable for privacy policy provisions that apply more broadly than those in other state laws. However, it fails to define "personally identifiable information," the term those provisions turn on, leaving their scope ambiguous. Where they apply, controllers must name every third party to whom they sell or "may sell" PII. Beyond that, the law omits much of what is now…

Read the full analysis →

Tennessee's law is one of the more business-friendly laws enacted to date. It has a high standard for applicability (a revenue and processing requirement) and provides limited consumer rights.

The bill is based on the Virginia law, with some notable variations. The most significant variation is the applicability standard. The bill applies to persons that (1) conduct business in Texas or produce products or services consumed by Texas residents, (2) process or engage in the sale of personal data, and (3) are not small businesses as defined by the United States Small Business…

Read the full analysis →

Utah's law is one of the most business-friendly laws passed to date. The law lacks many of the hallmarks of recent laws, including a data protection impact assessment requirement. It also relies on notice and opportunity to object for the processing of sensitive data. The law was amended to add the right to correct, effective July 1, 2026.

Vermont is the 23rd state to enact a broad consumer privacy law, following the 2025 version of Connecticut’s. Its definitions run broader than most — personal data reaches derived and device-linked information, publicly available information is defined narrowly, and biometric data covers information collected or used to identify someone, so collection alone can trigger coverage. The rights are…

Read the full analysis →

Virginia was the second state to enact a broad consumer privacy law. The law served as the baseline model for all other non-California state consumer data privacy laws. It has been amended several times, including to add an exemption for political organizations and additional provisions protecting children under 13. In 2026, the law was amended to prohibit controllers from selling or offering to…

Read the full analysis →

Data broker7

California's legislature first passed the state's data broker registration law in 2019. In 2023, the California legislature amended the law through passage of the Delete Act. Among other things, the 2023 amendment transferred oversight authority for the data broker registry to CalPrivacy, required data brokers to provide significantly more information when registering, and increased penalties for…

Read the full analysis →

Connecticut's law was enacted in 2026 and will require data brokers to register and pay an annual fee starting in 2027. The law also creates a California-style one-stop shop deletion mechanism.

Nevada's data broker law does not require covered entities to register with the state or pay a registration fee. The law requires data brokers to establish a designated request address for the submission of verified requests to opt out of sales.

New Jersey's data broker law creates requirements not only for data brokers, but also for data collectors, which are entities that have a direct relationship with individuals but sell their personal data to data brokers. The law also creates a tiered – and costly – structure for annual registration fees, requiring the largest data brokers and data collectors to pay a $1.5 million annual…

Read the full analysis →

Oregon's data broker law requires covered entities to annually register with the state and pay a registration fee. The law contains unique definitions that impact its applicability.

Texas' data broker law requires entities to annually register with the state, pay a registration fee, and post a disclosure on their websites and mobile applications. The law was amended in 2025 to modify its definitions of "data broker" and its applicability provision.

Vermont's law requires data brokers to annually register with the state and pay a registration fee. The law was significantly amended in 2026 with those changes effective January 1, 2027. The amendments include a new requirement for data brokers to post a bond.

Frontier AI Laws2

Among other things, the law requires a large frontier developer to write, implement, and clearly and conspicuously publish on its website a frontier AI framework that applies to the large frontier developer's frontier models and describes how the large frontier developer approaches, among other things, incorporating national standards, international standards, and industry-consensus best…

Read the full analysis →

In Frontier AI Laws

The law regulates frontier developers and large frontier developers. Frontier developers are persons doing business in Connecticut who intend to train, initiate the training of, or train a foundation model, and who in doing so use or intend to use a quantity of computing power greater than 10^26 integer or floating-point operations — inclusive of any computing power used for the original training…

Read the full analysis →

In Frontier AI Laws
Transparency Laws4

The California AI Transparency Act applies to "covered providers," defined as "a person that creates, codes, or otherwise produces a generative artificial intelligence system that has over 1,000,000 monthly visitors or users and is publicly accessible within the geographic boundaries of" California. Among other things, covered providers are required to make an AI detection tool available to users…

Read the full analysis →

In Transparency Laws

The law requires that whenever a developer makes a generative artificial intelligence ("AI") system or service — or a substantial modification to a generative AI system or service released after January 1, 2022 — available for use by Californians, the developer must post on its website documentation regarding the data used to train the AI system or service. The law defines developer as "a person…

Read the full analysis →

In Transparency Laws

The Utah Digital Content Provenance Standards Act creates obligations for "covered providers," defined as a "person that creates, codes, or otherwise produces a generative artificial intelligence system that: (i) has over 1,000,000 monthly visitors or users; and (ii) is publicly accessible within the geographic boundaries of" Utah. Covered providers must include a latent disclosure in image…

Read the full analysis →

In Transparency Laws

The law applies to covered providers, defined as “a person or entity that creates, codes, or otherwise produces a generative artificial intelligence system that has over 1,000,000 monthly users and is publicly accessible within the geographic boundaries of the state to consumers for personal use.” To the extent commercially and technically reasonable, covered providers must include provenance…

Read the full analysis →

In Transparency Laws
General AI Governance1

The law contains provisions specific to government entities and companies. With respect to companies, the law requires persons that make AI systems available for interacting with consumers to disclose to the consumer that they are interacting with an AI system. If the AI system is used in relation to a health care service or treatment, the provider must make the disclosure not later than the date…

Read the full analysis →

In General AI Governance
Employment / ADMT Laws8

Among other things, the regulations make it unlawful for an employer or other covered entity to use an automated-decision system or selection criteria (including a qualification standard, employment test, or proxy) that discriminates against an applicant or employee or a class of applicants or employees on a basis protected by law. Relevant to any such claim or available defense is evidence or…

Read the full analysis →

In Employment / ADMT Laws

The CCPA’s automated decisionmaking technology (ADMT) regulations apply when a business uses “ADMT to make a significant decision concerning a consumer.” The regulations define ADMT to mean “any technology that processes personal information and uses computation to replace human decisionmaking or substantially replace human decisionmaking.” The regulations define “substantially replace human…

Read the full analysis →

In Employment / ADMT Laws

SB 189 repeals and replaces the 2024 Colorado AI Act with a disclosure-based regime — no duty of care, no risk management programs, no impact assessments. What remains for deployers is a pre-use notice, a 30-day post-adverse-outcome disclosure, three-year recordkeeping, and access, correction and human review rights that trigger only after an adverse decision. But whether you are covered at all…

Read the full analysis →

Effective October 1, 2027, Connecticut's AI employment law requires deployers/employers that use automated employment decision tools (AEDT) to provide disclosures to job applicants and employees. Deployers/employers using an AEDT to interact with job applicants or employees must disclose that they are dealing with an AEDT unless it would be obvious to a reasonable person that they are interacting…

Read the full analysis →

The law applies to employers that ask applicants to record video interviews to allow the employer to use AI to analyze the applicant-submitted videos. Employers must notify applicants of the employer’s use of AI, provide applicants with information as to how the AI works and what general types of characteristics it uses to evaluate applicants, and obtain consent from applicants.

In Employment / ADMT Laws
Illinois HB 3773Jul 30, 2026

In 2024, Illinois amended the Illinois Human Rights Act to make it a civil rights violation for an employer to use artificial intelligence in a way that results in unlawful discrimination, or to fail to notify employees that the employer is using artificial intelligence for certain purposes. The law took effect January 1, 2026, but the Department of Human Rights has yet to finalize rulemaking on…

Read the full analysis →

In Employment / ADMT Laws

The law prohibits an employer from using a facial recognition service for the purpose of creating a facial template during an applicant’s interview for employment unless the applicant consents.

In Employment / ADMT Laws
NYC Local Law 144Jul 28, 2026

The law requires New York City employers using automated employment decision tools to notify job applicants and employees and conduct bias audits.

In Employment / ADMT Laws
Chatbot Laws13

In effect since 2019, California's bot disclosure law makes it unlawful for any person to use a bot to communicate or interact online with another person in California, with the intent to mislead the person about the bot's artificial identity in order to knowingly deceive the person about the content of the communication for the purpose of incentivizing a purchase or sale of goods or services in…

Read the full analysis →

In Chatbot Laws
California SB 243Aug 18, 2026

The law requires an operator of a companion chatbot platform to issue a clear and conspicuous notification indicating that the companion chatbot is artificially generated and not human, if a reasonable person interacting with the companion chatbot would be misled into believing that they are interacting with a human. The law also requires an operator to take certain actions with respect to a user…

Read the full analysis →

In Chatbot Laws

The law applies to operators of publicly available conversational AI services. Operators must use commercially reasonable or generally accepted methods to estimate the age of consumers who create or open an account or profile to use a conversational AI service, as well as the age of other users of the service. If an operator knows that an account holder or user is a minor, the operator must (1)…

Read the full analysis →

In Chatbot Laws

The law applies to AI companions, defined as any form of AI with a natural language interface that provides adaptive, human-like responses to user inputs — including, but not limited to, by exhibiting anthropomorphic features — and that is able to sustain a relationship across multiple interactions. The law excludes certain chatbots, including, but not limited to, chatbots used only for a…

Read the full analysis →

In Chatbot Laws
Georgia SB 540Aug 26, 2026

Among other things, the law requires operators of AI companions to clearly and conspicuously disclose to users that they are interacting with an AI companion chatbot, as opposed to a natural person, at the beginning of each interaction or session and at least every three hours during continued interaction. If the operator knows the user is a minor, or if the AI companion is directed or marketed…

Read the full analysis →

In Chatbot Laws
Hawaii SB 3001Jul 28, 2026

The law requires AI companion operators to disclose when individuals are interacting with AI, provide crisis resources, and implement additional safeguards for minors. It also prohibits AI companions from posing as licensed mental health professionals or encouraging harmful behavior. The state’s consumer protection laws govern violations.

In Chatbot Laws
Maine LD 1727Aug 9, 2026

The law prohibits a person from using an AI chatbot or other computer technology to engage in trade and commerce with a consumer in a manner that may mislead or deceive a reasonable consumer into believing they are engaging with a human, unless the consumer is notified in a clear and conspicuous manner that they are not.

In Chatbot Laws

The law prohibits persons from using online bots to communicate or interact with a person in New Jersey in connection with the sale or advertisement of any merchandise or real estate or to solicit support for any candidate, party or public question in an election unless the person discloses at the outset of the communication or interaction, in clear and conspicuous fashion, that the communication…

Read the full analysis →

In Chatbot Laws

The law makes it unlawful for an operator to operate for or provide an AI companion to a user unless the AI companion contains a protocol to take reasonable efforts for detecting and addressing suicidal ideation or expressions of self-harm expressed by a user. The AI companion must provide a notification to the user that refers them to crisis service providers, a crisis text line, or other…

Read the full analysis →

In Chatbot Laws
Oregon SB 1546Jul 27, 2026

The law is directed at AI companions, but contains ambiguous, undefined terms that could cause businesses to unintentionally trigger its provisions. It includes a private right of action with statutory damages of $1,000 per violation.

In Chatbot Laws

The law contains provisions specific to government entities and companies. With respect to companies, the law requires persons that make AI systems available for interacting with consumers to disclose to the consumer that they are interacting with an AI system. If the AI system is used in relation to a health care service or treatment, the provider must make the disclosure not later than the date…

Read the full analysis →

In Chatbot Laws
Utah 13-77-101Aug 9, 2026

The law requires disclosures in two situations where entities are using generative AI to interact with individuals. First, suppliers that use generative AI to interact with individuals in consumer transactions must disclose that fact if the individual asks or otherwise prompts the supplier to do so. Second, individuals providing services in a regulated occupation must prominently disclose when…

Read the full analysis →

In Chatbot Laws
Washington HB 2225Jul 28, 2026

Washington's AI companion chatbot law arguably applies more broadly than intended. The law requires operators to disclose that the chatbot is AI and to implement a protocol for detecting and addressing users' suicidal ideation or expressions of self-harm. The law includes a private right of action modeled on the private right of action in Washington's My Health My Data Act. It does not include…

Read the full analysis →

In Chatbot Laws
Healthcare / Mental Health12

The law requires certain healthcare providers to disclose to patients if they use generative AI for written or verbal patient communications pertaining to patient clinical information. The disclosure must include instructions for how patients can contact a human health care provider, employee of the health facility, clinic, physician's office, or office of a group provider, or other appropriate…

Read the full analysis →

In Healthcare / Mental Health

The law regulates the use of AI in providing psychotherapy services. Among other things, regulated professionals are prohibited from allowing AI systems to interact with clients in any form of therapeutic communication without synchronous, real-time interaction between the regulated professional, the AI system, and the client. AI systems also cannot be used to generate therapeutic recommendations…

Read the full analysis →

In Healthcare / Mental Health

The law prohibits individuals, corporations, and entities from providing, advertising, or otherwise offering therapy or psychotherapy services, including through the use of AI, unless the therapy or psychotherapy services are conducted by an individual who is a licensed professional. Licensed professionals cannot allow AI to (1) make independent therapeutic decisions; (2) directly interact with…

Read the full analysis →

In Healthcare / Mental Health

The law requires licensed healthcare professionals to verbally disclose the use of any recording device, software, or service to a patient before recording any part of an appointment or treatment to be transcribed by AI.

In Healthcare / Mental Health

The law prohibits any person from providing, advertising, or otherwise offering therapy or psychotherapy services, including through the use of AI, to the public unless the services are provided by a licensed professional.

In Healthcare / Mental Health

AI system providers cannot make representations or statements that explicitly or implicitly indicate that (a) the AI system is capable of providing professional mental or behavioral health care; (b) a user of an AI system may interact with any feature of the system which simulates human conversation to obtain professional mental or behavioral health care; or (c) the system, or any component…

Read the full analysis →

In Healthcare / Mental Health

The Use of AI by Healthcare Providers Notification Act requires healthcare providers and facilities that use AI to document in-person or telehealth visits to notify patients of that use and to review the AI-generated documentation for accuracy.

In Healthcare / Mental Health

Licensed professionals or providers cannot use AI designed to simulate emotional attachment, bonding, or dependency (or AI companions for mental health/emotional support) to assist with supplementary support or therapeutic communication where the session is recorded or transcribed, unless the patient (or their parent, guardian, or other legally authorized representative) is informed in writing…

Read the full analysis →

In Healthcare / Mental Health

Tennessee's law prohibits a person who develops or deploys an AI system in the state from advertising or representing to the public that the system is or is able to act as a qualified mental health professional.

In Healthcare / Mental Health

A health care practitioner may use AI for diagnostic purposes, including using AI to generate recommendations on a diagnosis or course of treatment based on a patient's medical record, if the use (1) complies with law, (2) is within the practitioner's scope of authorization to practice, (3) is reviewed by the practitioner as to all outputs, and (4) is disclosed to patients.

In Healthcare / Mental Health

The law does three things. First, mental health chatbot suppliers must clearly and conspicuously disclose to Utah users that the mental health chatbot is an AI technology and not a human. Second, subject to exceptions, mental health chatbot suppliers cannot sell to or share with any third party any individually identifiable health information of a Utah user or the user input of a Utah user…

Read the full analysis →

In Healthcare / Mental Health

The law prohibits a corporation or entity from providing, advertising, other otherwise offering mental health services, including through the use of AI, to the public unless the mental health services are either provided by a mental health professional or part of an approved institutional review board or privacy board study. It does not preclude a mental health professional who is operating…

Read the full analysis →

In Healthcare / Mental Health
Pricing Algorithm Laws5
Connecticut SB 4Jul 28, 2026

Effective October 1, 2026, the law requires persons doing business in the state that use a price setting device for certain purposes to provide a disclosure stating that the price was increased by a price setting device using the individual's personal data. Subject to certain exemptions, the law also prohibits retail sellers and third-party delivery services from engaging in surveillance pricing…

Read the full analysis →

In Pricing Algorithm Laws

The law imposes restrictions on price-setting by food retailers and third-party delivery service providers.

In Pricing Algorithm Laws

The law prohibits grocery stores from using personal information – such as online activity, location, purchasing history, or other collected data – to charge different prices for identical products based on what an algorithm predicts a shopper is willing or able to pay.

In Pricing Algorithm Laws

The law makes it unlawful for a person or entity to knowingly, or with reckless disregard, facilitate an agreement between or among two or more residential rental property owners or managers not to compete with respect to residential rental dwelling units, including by operating or licensing software, a data analytics service, or an algorithmic device that performs a coordinating function on…

Read the full analysis →

In Pricing Algorithm Laws

The law requires any entity that sets the price of a good or service using personalized algorithmic pricing, and that directly or indirectly advertises, promotes, labels, or publishes a statement, display, image, offer, or announcement of that personalized algorithmic pricing to a New York consumer using personal data specific to that consumer, to include a clear and conspicuous disclosure…

Read the full analysis →

In Pricing Algorithm Laws
Other AI Laws6
Arkansas HB 1876Jul 28, 2026

The law provides that the person who provides the input to a generative artificial intelligence tool is the owner of the generated content, provided that the content does not infringe on existing copyrights or intellectual property rights. It further provides that the person who provides data or input to train a generative AI model is the owner of the resulting trained model, unless that person…

Read the full analysis →

In Other AI Laws

The law requires real estate brokers and salespersons to include a disclosure whenever an advertisement or other promotional material for the sale of real property contains a digitally altered image. If the advertisement or promotional material is posted on a website, it must also include the same, unaltered image.

In Other AI Laws

Connecticut SB 1295 amended Connecticut's consumer data privacy law to add profiling and AI provisions.

In Other AI Laws

The law requires disclaimers when an advertisement contains a synthetic performer. "Synthetic performer" is defined as "a digitally created asset created, reproduced, or modified by computer, using generative artificial intelligence or a software algorithm, that is intended to create the impression that the asset is engaging in an audiovisual and/or visual performance of a human performer who is…

Read the full analysis →

In Other AI Laws

The law provides that a licensee is responsible for all work product produced by the licensee or with the assistance of artificial intelligence, machine learning, or similar technology.

In Other AI Laws

In 2025, the Texas legislature passed HB 149, which amended Texas' biometric law to address the use of biometric identifiers to train AI models or systems.

In Other AI Laws
Biometric Privacy2

This amendment to the Colorado Privacy Act (CPA) requires controllers to obtain consent before processing biometric identifiers. It applies to more organizations than the main provisions of the CPA cover and extends to the collection of employees' biometric identifiers. The amendment also requires controllers to adopt a written policy that (1) establishes a retention schedule for biometric…

Read the full analysis →

In Biometric Privacy

Washington's My Health My Data Act (MHMD) was the nation's first privacy law focused on regulating the collection and processing of consumer health data. The law strictly regulates the processing of consumer health data and is enforceable by the state attorney general and a private right of action.

In Biometric Privacy
Children's Privacy1

New Jersey's Kids Code Act imposes strict design and data-handling requirements on "covered online service providers" — businesses conducting business in New Jersey with either $25 million+ in annual gross revenue or 25,000+ consumers/households processed, that own or control an online service reasonably likely to be accessed by a minor (with a 2%-of-audience-under-18 threshold as one trigger)…

Read the full analysis →

In Children's Privacy
Consumer Health Data3

Passed in 2023, Nevada's law regulates the collection and use of consumer health data and biometric data. The law is similar in kind to Washington's My Health My Data Act but contains narrower definitions and does not have a private right of action. The law requires regulated entities to develop and maintain on their website a consumer health privacy notice. Regulated entities can collect…

Read the full analysis →

In Consumer Health Data

This 2025 amendment to Virginia's consumer protection act (as distinguished from its consumer privacy law) prohibits obtaining, disclosing, selling, or disseminating any personally identifiable reproductive or sexual health information without the consent of the consumer in connection with a consumer transaction. The law is enforceable through a private right of action.

In Consumer Health Data

Washington's My Health My Data Act (MHMD) was the nation's first privacy law focused on regulating the collection and processing of consumer health data. The law strictly regulates the processing of consumer health data and is enforceable by the state attorney general and a private right of action.

In Consumer Health Data

Tracking state privacy and AI laws? We write about it as the law changes.

Questions about state privacy and AI laws?

Stauss PLLC advises companies on state privacy, AI, and data broker compliance.

Contact Stauss PLLC

Follow state privacy and AI laws

Our analysis, by email, as the law moves.

This page is provided for general informational purposes only, is not legal advice, and does not create an attorney-client relationship. State laws change frequently; coverage reflects this tool’s most recent update. Contact Stauss PLLC to confirm how these requirements apply to your organization.