U.S. State Privacy Laws in 2026: A Compliance Reality Check
- Oso Data Privacy
- May 17
- 5 min read
Nineteen states. Three new ones this year. None of them agree. And the $12.75 million floor just got set.
In late 2025, California regulators announced a $12.75 million settlement with General Motors for allegedly selling driver data — including precise geolocation and driving behavior — to consumer reporting agencies without adequate disclosure. As of this writing, it is the largest enforcement action under the California Consumer Privacy Act to date.
The number is striking. The bigger shift is who was at the table when it happened. The California Privacy Protection Agency, the California Attorney General, local district attorneys, and the Federal Trade Commission all moved on the same fact pattern within months. Companies that built their CCPA program around "what does the CPPA care about?" suddenly have multiple regulators reading the same facts through different lenses, and the FTC is reading them through Section 5 (unfair and deceptive practices) in addition to whatever the state authorities are doing.
If your last serious look at U.S. state privacy compliance was 2023 or early 2024, this article is the reality check we'd give a client at our first meeting.
The landscape: 19 and counting
As of 2026, nineteen U.S. states have comprehensive consumer privacy laws on the books or in force:
California (CCPA/CPRA) — the foundational one, now seven years old
Virginia (VCDPA)
Colorado (CPA)
Connecticut (CTDPA)
Utah (UCPA)
Iowa, Indiana, Tennessee, Montana, Oregon, Texas
Delaware, New Hampshire, New Jersey
Maryland, Minnesota, Kentucky, Rhode Island
A growing cluster of "Year 4" laws now coming into force
Several more are in late-stage legislative consideration. Federal preemption discussions continue but a comprehensive federal privacy law is not imminent. Companies cannot wait it out.
What's similar across laws
There are real points of convergence. Most of the state laws share, in some form:
A consumer right to access personal information held by a business
A consumer right to deletion (with statutory exceptions)
A consumer right to correct inaccurate data
A consumer right to opt out of "sale" or "sharing" of personal information
A consumer right to opt out of certain forms of targeted advertising
Mandatory privacy disclosures at collection
Some form of data minimization or purpose limitation principle
Vendor / processor contract requirements
If your CCPA program is mature, you have the operational scaffolding for most of these requirements. You will not, however, be compliant by accident in any of the other nineteen states.
Where they diverge — and where companies get caught
This is where the reality check matters. The state laws differ on details that look minor on the surface but are operational landmines:
Definition of "sale" and "sharing." California's definition of "sale" is broader than several other states'. Texas, Colorado, and Connecticut each treat data broker–style relationships somewhat differently. A pipeline that is "CCPA compliant" because it falls within a specific carve-out can still be a "sale" under another state's law.
Sensitive data categories. What counts as sensitive personal information varies. Colorado's category of "sensitive data inferences" doesn't exist in most other state laws. Several states include precise geolocation as sensitive; some require opt-in consent before any processing.
Profiling and automated decision-making. Colorado, Texas, and several others have explicit rules around profiling that produces legal or similarly significant effects. California is rolling out its own rules in this area. The disclosure, opt-out, and human-review requirements are not uniform.
Data Protection Impact Assessments. Several states require DPIAs (or DPIA-like assessments) for high-risk processing. The thresholds differ. The required content differs. The retention rules differ. Companies frequently produce one assessment thinking it covers all states and find out otherwise.
Cure periods. Some states require regulators to offer a cure period before bringing an action. Others don't, or have sunsetted their cure provisions. The strategic implications for how companies respond to inquiries are different state to state.
Private rights of action. Most states limit enforcement to the attorney general. California allows private actions for certain breach claims. The litigation exposure profile differs accordingly.
The GM case as a cautionary tale
The General Motors settlement is worth reading in detail because it crystallizes several enforcement triggers at once:
Disclosure failures. GM allegedly did not clearly disclose that driver data would be sold to consumer reporting agencies or how it would be used downstream. Clear, prominent disclosure at collection is becoming non-negotiable.
Opt-out mechanism gaps. The absence of an effective opt-out from data sales was central to the claims. "We have an opt-out somewhere on the website" is no longer enough. Regulators are looking at whether the opt-out is findable, functional, and honored.
Data minimization and purpose limitation. Regulators framed the alleged conduct as a violation of purpose limitation rules — collecting data for one purpose, using it for another. This is one of the first major U.S. enforcement actions to do this. Expect more.
Coordinated regulatory pressure. The settlement was structured around a coordinated push from multiple regulators. Companies that scoped their program around a single regulator's expectations are exposed.
The required corrective actions are also worth noting: GM has to implement a robust privacy program, and they are barred from selling driver data to consumer reporting agencies for five years. The remedial scope tells you what regulators consider "robust" in 2026.
A practical compliance approach
For most companies operating across the U.S. — especially mid-market companies without a dedicated privacy team — the right approach in 2026 looks like this:
Build to the strictest state, with documented exceptions. Pick the most stringent applicable framework (typically California for most companies) and design your operational defaults to meet it. Where another state's law is more demanding on a specific point (e.g., Colorado on profiling, certain states on sensitive data opt-in), document the exception and operationalize it.
Treat the privacy disclosure as a regulator document. Your privacy notice is not marketing copy. It is the document the regulator will read first when something goes wrong. It needs to be accurate, specific, and updated whenever data flows change.
Audit your tag and data-sharing stack. A surprising amount of state-law exposure comes from marketing technology: Meta Pixel, GA, session replay, advertising pixels. Most companies have no real governance over what is firing on which page. Establish tag governance, especially on pages handling sensitive inputs.
Run a multi-regulator readiness review. Don't ask only "what would the CPPA say?" Ask what the FTC would say under Section 5. Ask what the New York AG would say if a New York consumer complained. Ask what plaintiffs' counsel would do with the same facts.
Maintain an opt-out signal program. Universal Opt-Out Mechanisms (Global Privacy Control, etc.) are required by an increasing number of states. Most companies are still not properly honoring them.
What's coming
Several patterns are clear in the legislative pipeline:
More states will adopt comprehensive privacy laws, with continued small-but-significant variations
AI-specific privacy rules are arriving alongside general privacy laws (see Colorado, Texas, California)
Sensitive data categories are expanding, particularly around health, location, and biometric data
The FTC continues to bring "unfair and deceptive practices" cases that mirror state privacy claims
Plaintiffs' counsel are increasingly weaponizing older statutes (CIPA, BIPA, etc.) against modern data practices
The compliance bar is rising every quarter, and the cost of catching up later compounds.
Oso Data Privacy helps U.S. organizations build privacy programs that survive contact with the actual regulators — not just the one they expected to deal with. If your CCPA program hasn't had a serious review since the GM settlement, that's the right next conversation.




Comments