Data Privacy Trends 2026: The Rules That Actually Apply

Infographic splitting the 2026 privacy landscape from the strategic response, with state law, AI and litigation panels


Data privacy used to be a legal question you answered once a year. In 2026 it is an operating question you answer every quarter. Twenty US states now enforce a comprehensive privacy law, the EU has begun applying its AI transparency rules, and regulators have moved from warning letters to seven-figure penalties.

This guide covers what changed, what applies right now, and what you can safely postpone. It is written for the people who implement it: founders, marketing leads, IT managers and operations teams, not privacy lawyers. Every date and figure below points to a rule that exists or an enforcement action that happened.

Read it once, then use the checklist at the end to set priorities.

Key Takeaways

  • Twenty US state privacy laws are in force in 2026; 24 states have enacted one.
  • EU AI Act transparency duties apply from 2 August 2026; the high-risk rules moved to December 2027.
  • Enforcement means real money: California issued penalties of $1.35 million and $1.55 million in 2025.
  • The amended children’s privacy rule (COPPA) has been fully binding since 22 April 2026.
  • Website tracking lawsuits remain the likeliest way an ordinary company gets sued over privacy.

Why your privacy strategy needs a reset in 2026

Most privacy programs were built for a single law. That approach broke over the last two years, because the rules applying to one ordinary business multiplied faster than anyone re-staffed for.

Consider a mid-sized online retailer that ships to 20 states, runs a chat widget, uses an advertising pixel, and has an AI assistant answering support questions. It is now touched by state laws with different definitions of sensitive data. A federal children’s rule applies if any customers are under 13. EU transparency duties apply if it serves European users. And tracking lawsuits turn on how its website is wired.

The practical shift: treat compliance as a running operation, not a project with an end date. A project produces a policy document. An operation produces a repeatable process for consumer requests, vendor reviews, and checking what your website sends where.

  • Write down where personal data lives, including spreadsheets and unapproved SaaS tools.
  • Set a review cadence for notices, consent flows and vendor contracts.
  • Assign one named owner per obligation, so deadlines have a person attached, not a department.

If you are starting from scratch, our privacy compliance framework gives you the scaffolding, and this guide to digital trust and operating models covers how privacy work connects to the rest of the business.

The data privacy trends shaping your next moves

Four things changed the picture. State rules multiplied and then got enforced. AI rules split into duties that apply now and duties that were pushed back. Enforcement became measurable in dollars: cumulative fines under the EU’s General Data Protection Regulation (GDPR) passed €7.1 billion by early 2026, according to DLA Piper’s January survey. And litigation moved to the website layer.

“Fix the two or three things that create real exposure before polishing the policy document.”

The state patchwork: 20 laws in force

Twenty comprehensive state privacy laws are active in 2026, and 24 states have enacted one. Indiana, Kentucky and Rhode Island joined on 1 January 2026, all three following the Virginia template. That is good news: the core duties look similar across most states.

“Comprehensive” here means the law covers personal data generally rather than one sector like health or finance. It gives residents rights to access, correct and delete their data, and to opt out of targeted advertising and the sale of their data.

The differences that actually cost you time

The states agree on the basics and disagree on the details. Those details are where compliance work hides.

  • Thresholds: some laws apply only above a set number of residents, others catch smaller firms.
  • Sensitive data: definitions vary, and some states require opt-in consent while others allow opt-out.
  • Cure periods: Texas gives 30 days to fix a violation before enforcement. Several states have let their cure periods expire.
  • Minimization: Maryland limits collection to what is strictly necessary, stricter than the usual standard.

Adopt a national baseline, then layer outliers

Building 20 separate compliance regimes is not realistic. The workable pattern is one baseline satisfying the strictest common requirement, plus narrow state exceptions.

The baseline: one privacy notice, one rights request process, one consent mechanism that honors browser-based opt-out signals, and one set of vendor contract clauses. Then track the genuine outliers, such as Maryland’s minimization rule, in a short exception list your team will actually read. Solid data governance makes this cheaper, because you cannot apply a rule to data you cannot find.

State enforcers stepped up

California has been the most visible. The California Privacy Protection Agency (CPPA) fined American Honda $632,500 in March 2025 over broken access and opt-out processes. Todd Snyder paid over $345,000 in May 2025 for mishandled opt-outs. Tractor Supply paid $1.35 million in September 2025 for ignoring browser opt-out signals, among other failures. California’s Attorney General separately settled with Healthline for $1.55 million in July 2025 over tracking technology and health data sharing.

Texas has been equally active. Its Attorney General secured a $1.375 billion settlement with Google in 2025 over biometric and location data, and notified more than 100 companies that had missed the state’s broker registration requirement.

None of these turned on an exotic legal theory. They turned on opt-out mechanisms that did not work, notices that did not match reality, and registrations nobody filed.

The federal picture: FTC priorities and children’s privacy

The Federal Trade Commission (FTC) is the main federal privacy enforcer in the US. Under Chair Andrew Ferguson it has favored targeted cases over sweeping new rules, using existing authority against practices it considers unfair or deceptive. That makes the risk concrete: if your privacy notice says one thing and your systems do another, that gap is the case.

The amended COPPA rule is now fully binding

The Children’s Online Privacy Protection Act (COPPA) governs data collected from children under 13. Its amended rule became fully binding on 22 April 2026 and changed several things that catch companies out.

  • Separate consent: one bundled parental consent no longer covers both collection and sharing with third parties. Targeted advertising and AI training need their own consent.
  • Written retention policy: publish what you collect, why you keep it, and when you delete it. Indefinite retention is expressly prohibited.
  • Security program: documented, with a named owner, annual risk assessments and regular testing.
  • Biometric identifiers: voiceprints and faceprints now count as personal information, so parental access requests must cover them.

Separately, FTC enforcement of the TAKE IT DOWN Act began on 19 May 2026, requiring covered platforms to remove non-consensual intimate imagery within 48 hours of notice.

If your product could attract under-13 users, audit age gating now. Mixed-audience services are exactly where the FTC has been looking.

AI rules: what applies in 2026 and what got delayed

This is where 2025 forecasts aged worst. Several headline deadlines moved, and planning against the old dates wastes money.

EU AI Act: transparency now, high-risk rules later

The EU AI Act phases in over several years. The important 2026 split:

  • On schedule: the Article 50 transparency duties apply from 2 August 2026. You must tell people when they are interacting with an AI system, and label synthetic content such as deepfakes.
  • Delayed: the heavy obligations for high-risk systems in Annex III moved from August 2026 to 2 December 2027. High-risk AI embedded in regulated products (Annex I) moved to August 2028.

The delay came through the EU’s digital omnibus package, provisionally agreed on 6 May 2026 and confirmed by member states on 13 May 2026. One caution: the new dates only bind once the omnibus is published in the Official Journal, so check the status before rebuilding a roadmap. Our guide to EU AI Act compliance breaks the risk tiers down further.

In practice: the disclosure work is due now, the conformity paperwork has breathing room. Do the labeling and keep building governance, but do not spend a year of budget on Annex III documentation due in late 2027.

Colorado’s AI law was frozen and rewritten

Colorado passed the first broad US AI anti-discrimination law in 2024, and it never took effect. Its date slipped to 30 June 2026, then a federal magistrate judge stayed enforcement on 27 April 2026. The legislature passed SB 26-189 to replace it with a narrower notice-and-transparency regime for automated decision-making technology, with employer duties starting 1 January 2027. US AI rules are being narrowed and postponed, not abandoned. Build governance that survives either outcome.

California’s ADMT rules have a 2027 deadline

California finalized rules on automated decision-making technology (ADMT), privacy risk assessments and cybersecurity audits in September 2025. Risk assessments have been required for higher-risk processing since 1 January 2026, with documentation due to the regulator by 1 April 2028. ADMT notices, opt-outs and access rights must be in place by 1 January 2027 where the technology drives significant decisions about people. Cybersecurity audits are staggered by revenue, starting 1 April 2028 for the largest businesses.

Common ground across these regimes: an inventory of your AI systems, documentation of what each decides, and a human review path. Build that once and it satisfies most of them. If AI decisions touch your staff rather than customers, see our guides on AI in employee monitoring and emotion recognition at work, and the wider picture in AI regulation in 2026.

A documented AI governance model is what auditors ask for first, and larger organizations increasingly hand ownership of it to an AI ethics officer.

Consumer rights requests: the operational bottleneck

Subject rights requests, or SRRs, are the requests people send asking to see, correct, delete or stop the sale of their data. As more state laws take effect, more people gain the right to send them and volumes rise.

Here is the gap most companies have. The cookie banner on the front end is usually fine. The back end, where a deletion request has to reach a CRM, a warehouse, an email tool and three vendors, usually is not. That gap produced the California fines.

Building a process that scales

  • Verify identity without creating friction. Ask enough to prevent fraud, no more. A passport scan to delete an email address creates its own problem.
  • Know where the data is first. You cannot delete from systems you have not inventoried, and shared drives are where requests stall.
  • Connect consent records to fulfillment. An opt-out that stops at your website but not at your ad platform is not an opt-out.
  • Honor browser signals. Ignoring global opt-out signals was a named failure in the Tractor Supply case.
  • Measure cycle time and backlog. If you cannot show timely handling, you cannot defend it.

Then feed the findings back into product. If most requests concern one data set, ask whether you need it at all. Reducing collection is the only fix that lowers volume permanently. Zero-party data, where customers tell you things directly, and a deliberate first-party data strategy reduce this load rather than add to it, and a well-run customer data platform makes fulfillment far less manual.

Biometrics and consumer health data

Two categories carry outsized legal risk because both come with a private right of action, meaning individuals can sue you directly rather than waiting for a regulator.

Biometrics. Illinois’ Biometric Information Privacy Act (BIPA) set the pattern: written consent before collecting fingerprints, face scans or voiceprints, a published retention schedule, and no sale of biometric data. Texas and Washington impose comparable duties. Review anywhere you capture or derive biometrics: time clocks, cameras with face matching, voice authentication. Our guide to biometric authentication at work covers the trade-offs.

Consumer health data. Washington’s My Health My Data Act defines consumer health information broadly, including inferences drawn from other data, and allows private lawsuits. The first class action under it was filed against Amazon in February 2025. Nevada and Connecticut take narrower approaches tied to identifying a diagnosis.

The trap is inference. You do not need medical records to be in scope. A retailer that infers a pregnancy from purchase history, or an app that infers a condition from search behavior, can fall under these definitions. Test whether health inferences flow into advertising or profiling, and cut those flows. Employee wellness data raises the same question, which is why a written wearable tech policy is worth having before the devices arrive.

Data brokers under the microscope

Scrutiny of broker networks has sharpened, and it reaches further than pure brokers. If your company buys or sells contact lists, you may qualify as one without thinking of yourself that way.

Microscope positioned over a circular circuit board sample in a blue-lit laboratory filled with server racks

Registration is the first thing enforcers check

Registration duties are easy to miss and easy for regulators to spot, the most common trigger. Texas’ broker registration law took effect in March 2024, and its Attorney General notified over 100 companies of apparent non-compliance. California’s regulator brought registration actions under the Delete Act in 2025 and a further round in January 2026, and expanded its registration requirements during 2026.

The FTC has separately pursued brokers over sales of precise location data tied to sensitive places such as health clinics, where consent checks were weak.

Managing broker relationships

  • Check the broker definition in each state where you operate, then register where required.
  • Ask partners how consent was obtained, and require proof rather than an assurance.
  • Put source disclosure, collection method and deletion duties into the contract itself.
  • Sample what you receive for sensitive categories you did not ask for, and be able to stop the flow quickly.
  • Keep a written record of each diligence decision, because it is your defense.

Cross-border transfers and the DOJ rule

Transfers that used to be routine now carry serious exposure. Two US rules matter most.

PADFA, the Protecting Americans’ Data from Foreign Adversaries Act, took effect in June 2024. It bars data brokers from transferring Americans’ sensitive personal data to China, Russia, Iran or North Korea, or to entities they substantially control. The FTC enforces it.

The DOJ bulk data rule (28 CFR Part 202) took effect on 8 April 2025, with full compliance phased in through October 2025. It restricts or prohibits transactions giving countries of concern access to bulk US personal data or government-related data, and it reaches beyond outright sales into vendor, employment and investment agreements. Penalties for willful violations are severe.

  • Map where your data sits and who can access it, including offshore teams and contractors.
  • Screen ownership and control of vendors before deals close, not after.
  • Add approval gates for analytics, licensing and model-training deals that move data abroad.
  • Brief executives, because these decisions change deal structure, not just paperwork.

Where you may store data is a separate question, covered in our guide to data localization laws.

Website tracking and outreach: where companies get sued

For a typical business the likeliest privacy claim is not a breach. It is a lawsuit about how the website collects data.

Tracking pixel and chat tool litigation

Plaintiffs have used decades-old wiretapping statutes, particularly the California Invasion of Privacy Act (CIPA), to challenge chat tools, session recording and advertising pixels. Roughly 4,000 CIPA suits had been filed in California by July 2026.

One important development: the California legislature unanimously passed SB 690 on 28 August 2026, removing the private right to sue over “pen register” theories for website and app tracking and leaving enforcement to the Attorney General. It was expected to become operative on 1 January 2027 if signed, applying retroactively to claims filed from 1 January 2025.

Do not read that as an all-clear. SB 690 leaves the core wiretapping and eavesdropping provisions of CIPA untouched, along with federal wiretapping law and common law claims.

Practical audit: list every tag on your site, check what each transmits, and separate flows that touch health, finance or precise location. Tools installed without review are a common source of surprise, the same problem covered in our guides to shadow IT and employee-chosen apps.

Outreach rules under the TCPA

The Telephone Consumer Protection Act (TCPA) governs marketing calls and texts. Here the 2025 forecasts were simply wrong.

The FCC’s much-discussed “one-to-one consent” rule, which would have required separate consent for each seller, was vacated by the Eleventh Circuit in January 2025 and never took effect. Prior express written consent is still required for marketing calls and texts, but the stricter one-to-one standard is not law. The revocation rules, which oblige you to honor an opt-out promptly and across channels, are the practical compliance point.

Action: log consent with a timestamp and source, honor revocation everywhere within the required window, and be able to produce that evidence quickly. How you then use this data is covered in our guide to AI in marketing.

What to do first

Most teams cannot do everything, so sequence by exposure.

This quarter. Audit your website tracking and fix any mismatch between what you disclose and what you send. Test that opt-outs propagate, including browser signals. Register if you might qualify as a data broker. Check your COPPA position if you serve children.

This year. Inventory your AI systems and document what each decides. Complete privacy risk assessments where California requires them. Ship the EU AI Act transparency disclosures if you serve EU users. Tighten vendor contracts around deletion and cross-border access.

Plan, but do not rush. Annex III conformity work, California’s ADMT opt-outs and the cybersecurity audits all have 2027 or 2028 deadlines.

Privacy and security work overlap heavily, so plan them together. Our overview of cybersecurity trends covers that side, and data privacy at work covers the employee-facing half.

Found this useful?

Make SmartKeys a preferred source on Google, and our articles will surface more often in your Top Stories, AI Overviews, and AI Mode.

Add as Preferred Source

FAQ

How many US states have a comprehensive privacy law in 2026?

Twenty state comprehensive privacy laws are in force during 2026, and 24 states have enacted one. Indiana, Kentucky and Rhode Island joined on 1 January 2026. Most follow a similar template: residents can access, correct and delete their data, and opt out of targeted advertising and the sale of their data. The differences sit in the details, such as which businesses are covered, whether sensitive data needs opt-in consent, and whether you get a cure period before enforcement. The practical answer is one national baseline meeting the strictest common requirement, plus a short exception list.

What does the EU AI Act actually require from August 2026?

From 2 August 2026 the transparency duties in Article 50 apply. You must tell people when they are interacting with an AI system rather than a human, and mark synthetic content such as AI-generated images or video. The heavier obligations for high-risk systems, meaning conformity assessments, technical documentation and registration, were postponed by the EU’s digital omnibus package: Annex III systems moved to 2 December 2027, and AI embedded in regulated products to August 2028. Those dates bind only once the omnibus is published in the Official Journal, so confirm the status first.

What are regulators actually fining companies for?

For practical failures, not exotic legal theories. California’s privacy regulator fined American Honda $632,500 in March 2025 over access and opt-out processes, Todd Snyder over $345,000 in May 2025 for mishandled opt-outs, and Tractor Supply $1.35 million in September 2025 for failures including ignoring browser-based opt-out signals. California’s Attorney General settled with Healthline for $1.55 million in July 2025 over tracking technology. The recurring themes are opt-outs that did not work, notices that did not match reality, and registrations nobody filed.

What changed in the COPPA rule for children’s data?

The amended Children’s Online Privacy Protection Act rule became fully binding on 22 April 2026. Four changes catch companies out. A single bundled parental consent no longer covers both collecting a child’s data and sharing it with third parties; targeted advertising and AI training need separate consent. You must publish a written retention policy, because indefinite retention is now prohibited. You need a documented security program with a named owner and annual risk assessments. And voiceprints and faceprints now count as personal information. If your service could reach under-13 users, audit your age gating.

Is the TCPA one-to-one consent rule still coming?

No. The FCC rule that would have required separate consent for each individual seller was vacated by the Eleventh Circuit in January 2025 and never took effect. Much 2025 planning advice assumed it would, so this is worth checking against your internal guidance. What still applies is prior express written consent for marketing calls and texts, plus the revocation rules, which require you to honor an opt-out promptly and across every channel rather than only the one it arrived in. Record consent with a timestamp and source, propagate revocation everywhere, and be able to produce that evidence quickly.

Why are website tracking lawsuits such a common risk?

Because the claim needs no data breach, only a mismatch between what your website does and what you tell visitors. Plaintiffs have used decades-old wiretapping statutes, particularly the California Invasion of Privacy Act, against chat widgets, session recording and advertising pixels. Roughly 4,000 such suits had been filed in California by July 2026. California’s SB 690, passed unanimously on 28 August 2026, would remove the private right to sue over “pen register” theories and hand enforcement to the Attorney General, operative from 1 January 2027 if signed. It leaves core wiretapping claims intact, so the audit still matters.

What counts as consumer health data, and why does it matter?

Much more than medical records. Washington’s My Health My Data Act defines consumer health information broadly enough to include inferences drawn from other data, and it lets individuals sue directly rather than wait for a regulator. The first class action under it was filed against Amazon in February 2025. Nevada and Connecticut take narrower approaches tied to identifying a diagnosis. The trap is inference: a retailer that deduces a health condition from purchase history is in scope without ever handling a medical file. Test whether health inferences flow into advertising, and cut those flows.

Could my company count as a data broker without realizing it?

Yes, and it is a common blind spot. State broker definitions generally cover businesses that sell or share personal data about people they have no direct relationship with, which catches companies that trade contact lists as a side activity. Registration is easy for regulators to check, making it a frequent enforcement trigger: Texas notified more than 100 companies of apparent non-compliance, and California’s regulator brought registration actions in 2025 and again in January 2026. Check the definition in each state where you operate, register where required, and keep diligence records for the brokers you buy from.

Author

  • Felix Römer

    Felix is the founder of SmartKeys.org, where he explores the future of work, SaaS innovation, and productivity strategies. With over 15 years of experience in e-commerce and digital marketing, he combines hands-on expertise with a passion for emerging technologies. Through SmartKeys, Felix shares actionable insights designed to help professionals and businesses work smarter, adapt to change, and stay ahead in a fast-moving digital world. Connect with him on LinkedIn