When a customer clicks "Submit a privacy request," it's tempting to assume you owe every one of them the same set of options. You don't. The rights a person can actually exercise — see their data, delete it, correct it, opt out of its sale — depend entirely on where they live. An Iowa resident is legally entitled to fewer choices than someone in Oregon, who in turn gets fewer than someone in Germany.
For anyone running a data subject request (DSR, sometimes DSAR) process, that variation isn't a footnote. It's the whole design problem. Here it is, mapped.
The US isn't one privacy law — it's twenty-four
There is no national US privacy law. States have passed their own, and as of August 2026, twenty-four states have enacted comprehensive consumer privacy laws — though only twenty are in effect. Four more (Oklahoma, Louisiana, Alabama, and Vermont) are signed but don't take effect until 2027–2028.
That patchwork alone makes a single "national form" a fiction. But it goes deeper than whether a state has a law.
Same country, different rights
Even among states with a law, the rights differ. Most grant a broad set: access, deletion, correction, portability, and opt-outs for sale, targeted advertising, and profiling — plus the right to appeal a denial. A couple don't. Utah and Iowa, the narrowest, drop correction and profiling opt-outs, and Utah drops the appeal right entirely.
The practical result: an Iowa resident should see roughly three request types; an Oregon resident sees five or more. Show the Iowa resident every option and you invite requests you aren't required to honor. Show the Oregon resident Iowa's shorter list and you've under-served someone legally entitled to more — exactly the kind of gap regulators and plaintiffs' attorneys look for.
Globally, it's not simpler — but it clusters
Zoom out and the pattern repeats at world scale. Around 140 countries now have a privacy law. The good news: they don't each reinvent the wheel. Most follow a recognizable GDPR-style model — access, correct, erase, portability, object, and rights around automated decisions. The EU and UK, Brazil, South Korea, Thailand, Indonesia, the Gulf states, and much of Africa all sit in that family.
The outliers are what demand attention. Canada and much of Latin America use a narrower "ARCO" model. Australia, Japan, and Singapore lean on access and correction with weak or no deletion and portability. China's rights look complete on paper but sit under a heavy cross-border-transfer regime. India's new law is consent-and-notice with no data portability at all. One profile covers the majority; a handful of exceptions cover the rest.
What this means for your DSR form
Two design consequences fall out of these maps.
First, rights follow residency, not IP address. Where someone's device happens to be — a VPN, a business trip — tells you nothing about which law protects them. GeoIP is a fine convenience to pre-fill a field, but the person's confirmed state or country is what should decide the rights they see. Gating rights on geolocation is both less accurate and harder to defend.
Second, the map keeps moving. Four US states enacted laws in 2026 alone; three others — Indiana, Kentucky, and Rhode Island — only went live this January. A DSR intake form that was correct last year isn't necessarily correct today. Keeping a jurisdiction-to-rights mapping current is a standing job, not a one-time build.
How PieEye handles it
This is exactly what PieEye's data subject request platform is built for. Instead of one static form, the intake adapts to the requester's confirmed residency. It shows only the request types that jurisdiction grants, surfaces the right notices — an EU resident sees their right to complain to a supervisory authority; a Texan doesn't — and draws from a jurisdiction ruleset we maintain along with you. We keep it current as laws take effect; you stay in control of how it applies to your brands. Your team doesn't have to track two dozen state statutes and their amendments on its own — but nothing about your compliance leaves your hands.
You don't have to choose between over-serving and under-serving. Each person sees exactly what the law where they live entitles them to — and the mapping stays current, maintained with you and under your control, not handed off.
See where your business actually has obligations today. Try the PieEye state privacy law checker to map your exposure in a couple of minutes — or book a walkthrough of PieEye's jurisdiction-aware DSR intake.
