The era in which US privacy compliance meant "do we need a cookie banner" is over. As of mid-2026, 20 comprehensive state privacy laws are in effect, and regulators have moved from publishing guidance to issuing penalties.
In California alone, CCPA-related fines now total more than $16 million. The organisations that faced regulatory action in the past year span automotive, retail and media: Ford, GM, Disney, PlayOn and Shein.
For a business operating a website that reaches consumers in multiple states, the practical question has shifted. It is no longer whether these laws apply to you. It is whether you can demonstrate what your site collects, who receives it, and how you honour a consumer's request to stop.
⚠️ Important: ⚖️ ENFORCEMENT IS ACTIVE: California CCPA-related fines now exceed $16 million in total, with Ford, GM, Disney, PlayOn and Shein among the organisations that faced regulatory action in the past year. The California Privacy Protection Agency can levy civil penalties of up to $2,500 per violation, rising to $7,988 per intentional violation — and because penalties are assessed per violation rather than per incident, a systematic failure across many consumer records compounds quickly.
What Changed in 2026
| When | What happened | Practical effect |
|---|---|---|
| 1 January 2026 | Indiana, Kentucky and Rhode Island laws took effect | Three more states with consumer rights and opt-out duties |
| 1 July 2026 | Connecticut, Utah and Maryland updated their existing laws | Changed obligations in states you may already have treated as done |
| 1 August 2026 | California's DELETE Act DROP platform milestone | Registered data brokers face a recurring 45-day deletion cycle |
| 1 January 2027 | California automated decision-making compliance date | Obligations attach to significant automated decisions |
What the Enforcement Actions Have in Common
• Global Privacy Control signals ignored — browser-level opt-out signals that the site does not detect or respect.
• Undisclosed third-party sharing — trackers and pixels sending data to parties not named in the privacy policy.
• Data broker registration gaps — businesses meeting the statutory definition without realising it.
• Retention beyond stated purpose — keeping data longer than the policy claims.
See Your Site the Way a Regulator Would
The gap between what your privacy policy claims and what your website actually does is where enforcement begins. Run a free privacy scan to see the trackers, cookies and third-party requests on your site. Scan your website now.
A Practical Multi-State Approach
• Know who receives it — every third party your pages load, and what each one gets.
• Honour opt-out signals automatically — including Global Privacy Control, not only your own banner.
• Make rights requests operable — access, deletion and correction routes that work end to end, including in backups and with downstream recipients.
• Say only what is true — align the privacy policy with observed behaviour, then keep them aligned. Most findings begin as a discrepancy between the two.
• Keep dated evidence — when you scanned, what you found, what you fixed.
Twenty state laws, more than $16 million in California fines alone, and an enforcement list that now includes household names. The pattern across those actions is not exotic legal interpretation — it is the ordinary gap between what a website says it does and what it actually does.
That gap is measurable. Start by finding out what your own site is doing, then align the policy to it, then keep evidence of both. Everything else in multi-state compliance is detail on top of that foundation.
Related reading: California's DELETE Act DROP platform • 2026 state privacy laws • GDPR fines hit €6 billion
Disclaimer: This article summarises publicly reported regulatory activity as of August 2026 and is general information, not legal advice. Consult qualified counsel about obligations specific to your business.