20 State Privacy Laws Are Now in Force — and Enforcement Has Started

The era in which US privacy compliance meant "do we need a cookie banner" is over. As of mid-2026, 20 comprehensive state privacy laws are in effect, and regulators have moved from publishing guidance to issuing penalties.

In California alone, CCPA-related fines now total more than $16 million. The organisations that faced regulatory action in the past year span automotive, retail and media: Ford, GM, Disney, PlayOn and Shein.

For a business operating a website that reaches consumers in multiple states, the practical question has shifted. It is no longer whether these laws apply to you. It is whether you can demonstrate what your site collects, who receives it, and how you honour a consumer's request to stop.

⚠️ Important: ⚖️ ENFORCEMENT IS ACTIVE: California CCPA-related fines now exceed $16 million in total, with Ford, GM, Disney, PlayOn and Shein among the organisations that faced regulatory action in the past year. The California Privacy Protection Agency can levy civil penalties of up to $2,500 per violation, rising to $7,988 per intentional violation — and because penalties are assessed per violation rather than per incident, a systematic failure across many consumer records compounds quickly.

What Changed in 2026

📅 The 2026 additions and updates
When What happened Practical effect
1 January 2026 Indiana, Kentucky and Rhode Island laws took effect Three more states with consumer rights and opt-out duties
1 July 2026 Connecticut, Utah and Maryland updated their existing laws Changed obligations in states you may already have treated as done
1 August 2026 California's DELETE Act DROP platform milestone Registered data brokers face a recurring 45-day deletion cycle
1 January 2027 California automated decision-making compliance date Obligations attach to significant automated decisions
The July updates deserve particular attention. Connecticut, Utah and Maryland were already on most compliance checklists, which means a business that mapped them in 2024 or 2025 and moved on may now be out of date without any new state having been added.

What the Enforcement Actions Have in Common

🔍 The recurring failure patterns
Looking across the organisations that have faced action, the same issues repeat:
Opt-out requests not actually honoured — a preference centre that records a choice but does not stop the downstream data sharing.
Global Privacy Control signals ignored — browser-level opt-out signals that the site does not detect or respect.
Undisclosed third-party sharing — trackers and pixels sending data to parties not named in the privacy policy.
Data broker registration gaps — businesses meeting the statutory definition without realising it.
Retention beyond stated purpose — keeping data longer than the policy claims.
Every item on that list is detectable from outside your organisation. That is precisely how regulators and plaintiffs' firms build cases: they load your website, watch what it does, and compare that to what your policy says.

See Your Site the Way a Regulator Would

The gap between what your privacy policy claims and what your website actually does is where enforcement begins. Run a free privacy scan to see the trackers, cookies and third-party requests on your site. Scan your website now.

A Practical Multi-State Approach

✅ How to cover twenty laws without twenty projects
The state laws differ in thresholds and detail but converge on a common core. Build to the strictest common denominator and the rest largely follows:
Know what your site collects — a current inventory of cookies, trackers, pixels and form fields, refreshed when the site changes rather than annually.
Know who receives it — every third party your pages load, and what each one gets.
Honour opt-out signals automatically — including Global Privacy Control, not only your own banner.
Make rights requests operable — access, deletion and correction routes that work end to end, including in backups and with downstream recipients.
Say only what is true — align the privacy policy with observed behaviour, then keep them aligned. Most findings begin as a discrepancy between the two.
Keep dated evidence — when you scanned, what you found, what you fixed.
A business that can produce that inventory on request is in a fundamentally different position from one that cannot, regardless of which state is asking. Our comparison of compliance tooling covers the options.

Twenty state laws, more than $16 million in California fines alone, and an enforcement list that now includes household names. The pattern across those actions is not exotic legal interpretation — it is the ordinary gap between what a website says it does and what it actually does.

That gap is measurable. Start by finding out what your own site is doing, then align the policy to it, then keep evidence of both. Everything else in multi-state compliance is detail on top of that foundation.

Related reading: California's DELETE Act DROP platform2026 state privacy lawsGDPR fines hit €6 billion

Disclaimer: This article summarises publicly reported regulatory activity as of August 2026 and is general information, not legal advice. Consult qualified counsel about obligations specific to your business.

Stay Updated on Privacy & Security Compliance

Get the latest updates on privacy laws, security threats, and compliance requirements.

Read More Articles Test Your Site