Data privacy used to be a legal question you answered once a year. In 2026 it is an operating question you answer every quarter. Twenty US states now enforce a comprehensive privacy law, the EU has begun applying its AI transparency rules, and regulators have moved from warning letters to seven-figure penalties.
This guide covers what changed, what applies right now, and what you can safely postpone. It is written for the people who implement it: founders, marketing leads, IT managers and operations teams, not privacy lawyers. Every date and figure below points to a rule that exists or an enforcement action that happened.
Read it once, then use the checklist at the end to set priorities.
Key Takeaways
- Twenty US state privacy laws are in force in 2026; 24 states have enacted one.
- EU AI Act transparency duties apply from 2 August 2026; the high-risk rules moved to December 2027.
- Enforcement means real money: California issued penalties of $1.35 million and $1.55 million in 2025.
- The amended children’s privacy rule (COPPA) has been fully binding since 22 April 2026.
- Website tracking lawsuits remain the likeliest way an ordinary company gets sued over privacy.
Why your privacy strategy needs a reset in 2026
Most privacy programs were built for a single law. That approach broke over the last two years, because the rules applying to one ordinary business multiplied faster than anyone re-staffed for.
Consider a mid-sized online retailer that ships to 20 states, runs a chat widget, uses an advertising pixel, and has an AI assistant answering support questions. It is now touched by state laws with different definitions of sensitive data. A federal children’s rule applies if any customers are under 13. EU transparency duties apply if it serves European users. And tracking lawsuits turn on how its website is wired.
The practical shift: treat compliance as a running operation, not a project with an end date. A project produces a policy document. An operation produces a repeatable process for consumer requests, vendor reviews, and checking what your website sends where.
- Write down where personal data lives, including spreadsheets and unapproved SaaS tools.
- Set a review cadence for notices, consent flows and vendor contracts.
- Assign one named owner per obligation, so deadlines have a person attached, not a department.
If you are starting from scratch, our privacy compliance framework gives you the scaffolding, and this guide to digital trust and operating models covers how privacy work connects to the rest of the business.
The data privacy trends shaping your next moves
Four things changed the picture. State rules multiplied and then got enforced. AI rules split into duties that apply now and duties that were pushed back. Enforcement became measurable in dollars: cumulative fines under the EU’s General Data Protection Regulation (GDPR) passed €7.1 billion by early 2026, according to DLA Piper’s January survey. And litigation moved to the website layer.
“Fix the two or three things that create real exposure before polishing the policy document.”
The state patchwork: 20 laws in force
Twenty comprehensive state privacy laws are active in 2026, and 24 states have enacted one. Indiana, Kentucky and Rhode Island joined on 1 January 2026, all three following the Virginia template. That is good news: the core duties look similar across most states.
“Comprehensive” here means the law covers personal data generally rather than one sector like health or finance. It gives residents rights to access, correct and delete their data, and to opt out of targeted advertising and the sale of their data.
The differences that actually cost you time
The states agree on the basics and disagree on the details. Those details are where compliance work hides.
- Thresholds: some laws apply only above a set number of residents, others catch smaller firms.
- Sensitive data: definitions vary, and some states require opt-in consent while others allow opt-out.
- Cure periods: Texas gives 30 days to fix a violation before enforcement. Several states have let their cure periods expire.
- Minimization: Maryland limits collection to what is strictly necessary, stricter than the usual standard.
Adopt a national baseline, then layer outliers
Building 20 separate compliance regimes is not realistic. The workable pattern is one baseline satisfying the strictest common requirement, plus narrow state exceptions.
The baseline: one privacy notice, one rights request process, one consent mechanism that honors browser-based opt-out signals, and one set of vendor contract clauses. Then track the genuine outliers, such as Maryland’s minimization rule, in a short exception list your team will actually read. Solid data governance makes this cheaper, because you cannot apply a rule to data you cannot find.
State enforcers stepped up
California has been the most visible. The California Privacy Protection Agency (CPPA) fined American Honda $632,500 in March 2025 over broken access and opt-out processes. Todd Snyder paid over $345,000 in May 2025 for mishandled opt-outs. Tractor Supply paid $1.35 million in September 2025 for ignoring browser opt-out signals, among other failures. California’s Attorney General separately settled with Healthline for $1.55 million in July 2025 over tracking technology and health data sharing.
Texas has been equally active. Its Attorney General secured a $1.375 billion settlement with Google in 2025 over biometric and location data, and notified more than 100 companies that had missed the state’s broker registration requirement.
None of these turned on an exotic legal theory. They turned on opt-out mechanisms that did not work, notices that did not match reality, and registrations nobody filed.
The federal picture: FTC priorities and children’s privacy
The Federal Trade Commission (FTC) is the main federal privacy enforcer in the US. Under Chair Andrew Ferguson it has favored targeted cases over sweeping new rules, using existing authority against practices it considers unfair or deceptive. That makes the risk concrete: if your privacy notice says one thing and your systems do another, that gap is the case.
The amended COPPA rule is now fully binding
The Children’s Online Privacy Protection Act (COPPA) governs data collected from children under 13. Its amended rule became fully binding on 22 April 2026 and changed several things that catch companies out.
- Separate consent: one bundled parental consent no longer covers both collection and sharing with third parties. Targeted advertising and AI training need their own consent.
- Written retention policy: publish what you collect, why you keep it, and when you delete it. Indefinite retention is expressly prohibited.
- Security program: documented, with a named owner, annual risk assessments and regular testing.
- Biometric identifiers: voiceprints and faceprints now count as personal information, so parental access requests must cover them.
Separately, FTC enforcement of the TAKE IT DOWN Act began on 19 May 2026, requiring covered platforms to remove non-consensual intimate imagery within 48 hours of notice.
If your product could attract under-13 users, audit age gating now. Mixed-audience services are exactly where the FTC has been looking.
AI rules: what applies in 2026 and what got delayed
This is where 2025 forecasts aged worst. Several headline deadlines moved, and planning against the old dates wastes money.
EU AI Act: transparency now, high-risk rules later
The EU AI Act phases in over several years. The important 2026 split:
- On schedule: the Article 50 transparency duties apply from 2 August 2026. You must tell people when they are interacting with an AI system, and label synthetic content such as deepfakes.
- Delayed: the heavy obligations for high-risk systems in Annex III moved from August 2026 to 2 December 2027. High-risk AI embedded in regulated products (Annex I) moved to August 2028.
The delay came through the EU’s digital omnibus package, provisionally agreed on 6 May 2026 and confirmed by member states on 13 May 2026. One caution: the new dates only bind once the omnibus is published in the Official Journal, so check the status before rebuilding a roadmap. Our guide to EU AI Act compliance breaks the risk tiers down further.
In practice: the disclosure work is due now, the conformity paperwork has breathing room. Do the labeling and keep building governance, but do not spend a year of budget on Annex III documentation due in late 2027.
Colorado’s AI law was frozen and rewritten
Colorado passed the first broad US AI anti-discrimination law in 2024, and it never took effect. Its date slipped to 30 June 2026, then a federal magistrate judge stayed enforcement on 27 April 2026. The legislature passed SB 26-189 to replace it with a narrower notice-and-transparency regime for automated decision-making technology, with employer duties starting 1 January 2027. US AI rules are being narrowed and postponed, not abandoned. Build governance that survives either outcome.
California’s ADMT rules have a 2027 deadline
California finalized rules on automated decision-making technology (ADMT), privacy risk assessments and cybersecurity audits in September 2025. Risk assessments have been required for higher-risk processing since 1 January 2026, with documentation due to the regulator by 1 April 2028. ADMT notices, opt-outs and access rights must be in place by 1 January 2027 where the technology drives significant decisions about people. Cybersecurity audits are staggered by revenue, starting 1 April 2028 for the largest businesses.
Common ground across these regimes: an inventory of your AI systems, documentation of what each decides, and a human review path. Build that once and it satisfies most of them. If AI decisions touch your staff rather than customers, see our guides on AI in employee monitoring and emotion recognition at work, and the wider picture in AI regulation in 2026.
A documented AI governance model is what auditors ask for first, and larger organizations increasingly hand ownership of it to an AI ethics officer.
Consumer rights requests: the operational bottleneck
Subject rights requests, or SRRs, are the requests people send asking to see, correct, delete or stop the sale of their data. As more state laws take effect, more people gain the right to send them and volumes rise.
Here is the gap most companies have. The cookie banner on the front end is usually fine. The back end, where a deletion request has to reach a CRM, a warehouse, an email tool and three vendors, usually is not. That gap produced the California fines.
Building a process that scales
- Verify identity without creating friction. Ask enough to prevent fraud, no more. A passport scan to delete an email address creates its own problem.
- Know where the data is first. You cannot delete from systems you have not inventoried, and shared drives are where requests stall.
- Connect consent records to fulfillment. An opt-out that stops at your website but not at your ad platform is not an opt-out.
- Honor browser signals. Ignoring global opt-out signals was a named failure in the Tractor Supply case.
- Measure cycle time and backlog. If you cannot show timely handling, you cannot defend it.
Then feed the findings back into product. If most requests concern one data set, ask whether you need it at all. Reducing collection is the only fix that lowers volume permanently. Zero-party data, where customers tell you things directly, and a deliberate first-party data strategy reduce this load rather than add to it, and a well-run customer data platform makes fulfillment far less manual.
Biometrics and consumer health data
Two categories carry outsized legal risk because both come with a private right of action, meaning individuals can sue you directly rather than waiting for a regulator.
Biometrics. Illinois’ Biometric Information Privacy Act (BIPA) set the pattern: written consent before collecting fingerprints, face scans or voiceprints, a published retention schedule, and no sale of biometric data. Texas and Washington impose comparable duties. Review anywhere you capture or derive biometrics: time clocks, cameras with face matching, voice authentication. Our guide to biometric authentication at work covers the trade-offs.
Consumer health data. Washington’s My Health My Data Act defines consumer health information broadly, including inferences drawn from other data, and allows private lawsuits. The first class action under it was filed against Amazon in February 2025. Nevada and Connecticut take narrower approaches tied to identifying a diagnosis.
The trap is inference. You do not need medical records to be in scope. A retailer that infers a pregnancy from purchase history, or an app that infers a condition from search behavior, can fall under these definitions. Test whether health inferences flow into advertising or profiling, and cut those flows. Employee wellness data raises the same question, which is why a written wearable tech policy is worth having before the devices arrive.
Data brokers under the microscope
Scrutiny of broker networks has sharpened, and it reaches further than pure brokers. If your company buys or sells contact lists, you may qualify as one without thinking of yourself that way.

Registration is the first thing enforcers check
Registration duties are easy to miss and easy for regulators to spot, the most common trigger. Texas’ broker registration law took effect in March 2024, and its Attorney General notified over 100 companies of apparent non-compliance. California’s regulator brought registration actions under the Delete Act in 2025 and a further round in January 2026, and expanded its registration requirements during 2026.
The FTC has separately pursued brokers over sales of precise location data tied to sensitive places such as health clinics, where consent checks were weak.
Managing broker relationships
- Check the broker definition in each state where you operate, then register where required.
- Ask partners how consent was obtained, and require proof rather than an assurance.
- Put source disclosure, collection method and deletion duties into the contract itself.
- Sample what you receive for sensitive categories you did not ask for, and be able to stop the flow quickly.
- Keep a written record of each diligence decision, because it is your defense.
Cross-border transfers and the DOJ rule
Transfers that used to be routine now carry serious exposure. Two US rules matter most.
PADFA, the Protecting Americans’ Data from Foreign Adversaries Act, took effect in June 2024. It bars data brokers from transferring Americans’ sensitive personal data to China, Russia, Iran or North Korea, or to entities they substantially control. The FTC enforces it.
The DOJ bulk data rule (28 CFR Part 202) took effect on 8 April 2025, with full compliance phased in through October 2025. It restricts or prohibits transactions giving countries of concern access to bulk US personal data or government-related data, and it reaches beyond outright sales into vendor, employment and investment agreements. Penalties for willful violations are severe.
- Map where your data sits and who can access it, including offshore teams and contractors.
- Screen ownership and control of vendors before deals close, not after.
- Add approval gates for analytics, licensing and model-training deals that move data abroad.
- Brief executives, because these decisions change deal structure, not just paperwork.
Where you may store data is a separate question, covered in our guide to data localization laws.
Website tracking and outreach: where companies get sued
For a typical business the likeliest privacy claim is not a breach. It is a lawsuit about how the website collects data.
Tracking pixel and chat tool litigation
Plaintiffs have used decades-old wiretapping statutes, particularly the California Invasion of Privacy Act (CIPA), to challenge chat tools, session recording and advertising pixels. Roughly 4,000 CIPA suits had been filed in California by July 2026.
One important development: the California legislature unanimously passed SB 690 on 28 August 2026, removing the private right to sue over “pen register” theories for website and app tracking and leaving enforcement to the Attorney General. It was expected to become operative on 1 January 2027 if signed, applying retroactively to claims filed from 1 January 2025.
Do not read that as an all-clear. SB 690 leaves the core wiretapping and eavesdropping provisions of CIPA untouched, along with federal wiretapping law and common law claims.
Practical audit: list every tag on your site, check what each transmits, and separate flows that touch health, finance or precise location. Tools installed without review are a common source of surprise, the same problem covered in our guides to shadow IT and employee-chosen apps.
Outreach rules under the TCPA
The Telephone Consumer Protection Act (TCPA) governs marketing calls and texts. Here the 2025 forecasts were simply wrong.
The FCC’s much-discussed “one-to-one consent” rule, which would have required separate consent for each seller, was vacated by the Eleventh Circuit in January 2025 and never took effect. Prior express written consent is still required for marketing calls and texts, but the stricter one-to-one standard is not law. The revocation rules, which oblige you to honor an opt-out promptly and across channels, are the practical compliance point.
Action: log consent with a timestamp and source, honor revocation everywhere within the required window, and be able to produce that evidence quickly. How you then use this data is covered in our guide to AI in marketing.
What to do first
Most teams cannot do everything, so sequence by exposure.
This quarter. Audit your website tracking and fix any mismatch between what you disclose and what you send. Test that opt-outs propagate, including browser signals. Register if you might qualify as a data broker. Check your COPPA position if you serve children.
This year. Inventory your AI systems and document what each decides. Complete privacy risk assessments where California requires them. Ship the EU AI Act transparency disclosures if you serve EU users. Tighten vendor contracts around deletion and cross-border access.
Plan, but do not rush. Annex III conformity work, California’s ADMT opt-outs and the cybersecurity audits all have 2027 or 2028 deadlines.
Privacy and security work overlap heavily, so plan them together. Our overview of cybersecurity trends covers that side, and data privacy at work covers the employee-facing half.
Found this useful?
Make SmartKeys a preferred source on Google, and our articles will surface more often in your Top Stories, AI Overviews, and AI Mode.
Add as Preferred Source







