How Regulens Calculates Your Readiness Score
Transparency is the product. Here is exactly how every Regulens score is calculated — the data sources, the formulas, and the limits of what we cover.
1. Our Data Sources
Every data point in Regulens traces to an official government source. Regulens Version 4.0 covers 39 U.S. jurisdictions across two data categories — sales tax economic nexus rules and consumer privacy laws.
For each jurisdiction, data is sourced directly from the state revenue department (for sales tax) or the state attorney general office (for privacy law). We do not use third-party summaries as primary sources.
Every record in our database includes:
- The authority name and official government URL
- The enacted statute or regulation citation
- The date the data was last verified
- The date of the next scheduled review
The 8 highest-priority sources for weekly monitoring are: Florida DOR, Texas Comptroller, New York Dept of Tax and Finance, DC OTR, Florida Dept of Legal Affairs, Texas Attorney General, New York Attorney General, and California CDTFA.
For the live verification status of all 39 jurisdictions including last-verified dates and clickable source links, see:
2. The Scoring Formula
Final Score = (Nexus × 35%) + (Privacy × 30%) + (Policy × 20%) + (Awareness × 15%)Highest weight because unregistered sales-tax nexus carries the largest back-liability risk. Per-state tier weights below. Hard penalty: −12 pts per triggered-but-unregistered state.
| State | Tax Weight |
|---|---|
| CA | 1.8x |
| TX | 1.5x |
| NY | 1.5x |
| WA | 1.5x |
| IL | 1.4x |
| DC | 1.25x |
| CO | 1.25x |
| VA | 1.25x |
| AK | 0.0x (no state sales tax) |
| All others | 1.0x |
Four consumer rights per applicable state (Policy, Opt-Out, Delete, Access), 25 pts each. TX TDPSA missing-opt-out incurs a −10 pt penalty. FL exempt if revenue < $1B. DC scored as N/A. NY scored on SHIELD Act only.
| State | Privacy Weight |
|---|---|
| CA | 2.0x |
| CO | 1.5x |
| TX | 1.3x |
| IL | 1.3x |
| VA | 1.3x |
| WA | 1.2x |
| IN | 1.1x |
| TN | 1.1x |
| FL, KY, IA, NE, MN | 1.0x |
| NV | 0.8x (opt-out of sale only) |
| Others (no enacted law) | 0.5x |
Sum of weighted policy items (see "What We Check" table below). Max 100 pts.
Operational maturity — jurisdictions identified (40), nexus documented (30), active monitoring (30). Max 100 pts.
Global −15 pt penalty applies if overall awareness criteria are completely unmet.
3. What We Check in Your Policy Documents
| Item | Max Points | Why it matters |
|---|---|---|
| Privacy Policy present | 22 | TX TDPSA, best-practice all states |
| Privacy Policy covers data sharing | 18 | TX TDPSA |
| Terms of Service | 15 | Best-practice for Shopify merchants |
| Cookie consent banner | 13 | TX TDPSA, EU/UK best-practice |
| Refund policy | 12 | FTC best-practice, all states |
| Privacy contact in policy | 12 | TX TDPSA opt-out infrastructure |
| Data retention disclosure | 8 | TX TDPSA best-practice |
4. Readiness Score Bands
5. Our Limitations
Regulens covers 39 U.S. jurisdictions. Not all U.S. states are included in the current edition. It is not a substitute for licensed legal counsel. Scores are informational only.
View full coverage scope and limitations →