California is the outlier and the drafting anchor. 11 CCR section 7051 is the most prescriptive processor contract rule in the country, the CCPA alone reaches employee and job applicant data, and Civil Code section 1798.150 gives consumers a private right of action for breaches of unencrypted personal information caused by unreasonable security. That statutory damages exposure is why California vendors negotiate hardest over the security schedule. Draft to California first and the rest of the country generally follows.
Texas applies the Texas Data Privacy and Security Act with no revenue threshold, so small companies fall in unless they qualify under section 541.107. Section 541.104(b) mandates the contract terms and 541.104(c) lets a vendor substitute a qualified independent assessor's report for a customer audit. House Bill 149, the Texas Responsible Artificial Intelligence Governance Act, amended section 541.104 to reach personal data processed by an artificial intelligence system, so AI vendors selling into Texas must say so in the processing description.
Virginia is the model most other states copied. Virginia Code section 59.1-579 requires processing instructions, confidentiality duties, deletion or return at the customer's election, and cooperation with assessments. It exempts employee and business to business data, so a Virginia only analysis understates your California obligations.
Colorado adds detail through the Attorney General's rules at 4 CCR 904-3, read with section 6-1-1305(5) of the Colorado Privacy Act, and says plainly that a processor becomes a controller once it decides purposes and means on its own. Connecticut tracks the same structure at section 42-520, and its cure period has now sunset, so the Attorney General can act on a first violation without giving you a window to fix it. Related paperwork sits in the US business contracts and incorporation documents catalog.