The first quarter of 2026 continued a familiar trajectory for U.S. state privacy law – new state consumer privacy laws; more amendments layered onto existing statutes; and a growing convergence among privacy, artificial intelligence and youth consumer protection. Privacy compliance now extends well beyond tracking state laws to understanding how overlapping statutes, enforcement priorities, judicial developments and consumer expectations interact to create real operational challenges and risk. In this environment, privacy compliance increasingly demands functioning operational controls, documented assessments, sound data governance and readiness for multistate scrutiny.
State Privacy Laws and Amendments
January 2026 marked another expansion of the U.S. state privacy law map, with the compliance bar continuing to rise. Three new comprehensive privacy laws became effective on January 1, 2026 – the Indiana Consumer Data Protection Act, the Kentucky Consumer Data Protection Act and the Rhode Island Data Transparency and Privacy Protection Act. Each closely follows the established state privacy law model and grants consumers core rights, including access, deletion, correction and opt-out rights. For companies already complying with other state consumer privacy laws, these new laws generally fit within existing compliance architectures, with some unique nuances (such as Rhode Island’s proactive requirement that companies disclose third parties they sell personal data to).
California remains a demanding jurisdiction. Amended California Consumer Privacy Act (CCPA) regulations took effect on January 1, 2026, refining compliance expectations and, in some cases, increasing operational complexity around privacy risk assessments, cybersecurity audits and automated decision-making. These changes coincide with the approaching launch of California’s centralized deletion mechanism for data brokers, reinforcing California’s role as both a substantive and enforcement bellwether.
The Maryland Online Data Privacy Act (MODPA) fully entered its enforcement phase as of April 1, 2026, following the expiration of a six‑month grace period. MODPA is among the nation’s strictest state privacy regimes, with substantive limits on personal data processing and reduced reliance on consent as a fallback, making Maryland a jurisdiction compliance teams should watch.
Several other states have refined their laws in ways that signal regulatory priorities. For example, effective January 1, 2026, Oregon amended its Consumer Privacy Act to prohibit the sale of precise geolocation data and the personal data of consumers under 16 in certain circumstances. Also in January, New Jersey enacted immediately effective amendments, expanding HIPAA‑related exemptions and the definition of de‑identified data.
Virginia’s governor has signed amendments to its Consumer Data Protection Act banning the sale (defined in that law as only for monetary consideration) of precise geolocation data, effective July 1, 2026. Kentucky also passed amendments that classify automatic content recognition data from smart TVs as sensitive data, with enforcement starting July 1, 2027, signaling heightened scrutiny of IoT and smart‑device analytics. Utah enacted targeted refinements, taking effect January 1, 2027, to the Utah Consumer Privacy Act to motor vehicle manufacturers and telematics providers regardless of traditional applicability thresholds.
March 2026 added Oklahoma to the comprehensive consumer privacy law map, although Oklahoma’s law does not take effect until January 1, 2027. Alabama soon followed. Signed on April 16, 2026, the Alabama Personal Data Protection Act takes effect May 1, 2027. Both laws closely align with existing state consumer privacy laws, granting residents the rights to access, correct and delete personal data, as well as to opt out of data sales and targeted advertising. For companies already complying with other state privacy laws, these additions do not introduce fundamentally new obligations, but they continue the steady expansion of multistate compliance expectations and reinforce the need for scalable, repeatable privacy programs.
Enforcement Shaping the State Privacy Landscape
Legislative activity was only part of the story in Q1. Enforcement actions during the quarter underscored that regulators are actively coordinating, increasingly assertive and focused on whether privacy rights function in practice rather than merely existing on paper. Across jurisdictions, regulators are converging on several enforcement priorities, including the protection of health data, location data and children’s and teens’ data, effective opt-out mechanisms, transparency around automated decision-making, and the monetization of sensitive data.
One of the clearest enforcement signals remains the expectation that opt-out rights be meaningful, low-friction and operative across devices and platforms. State regulators began coordinated investigations in late 2025 targeting companies that allegedly failed to honor universal opt-out preference signals, such as Global Privacy Control (GPC). By early 2026, at least a dozen state statutes required recognition of such signals. California, Colorado and Connecticut have each publicly emphasized that these signals must be honored consistently and without unnecessary friction. For companies, this means ensuring that websites, mobile apps and consent management platforms are properly configured to detect and process opt-out signals and that those mechanisms are tested end-to-end on a regular basis.
High‑profile enforcement actions continue to underscore this point. In parallel actions, California and federal regulators pursued a family entertainment and media conglomerate for alleged privacy and children’s data violations, resulting in a $2.75 million CCPA settlement related to honoring consumer rights requests (including GPC) across services and devices, and a separate $10 million civil penalty resolving Children’s Online Privacy Protection Act (COPPA) claims related to child‑directed content and data practices. Together, these actions reflect regulators’ willingness to tie technical opt‑out failures directly to monetary penalties, particularly where sensitive data is implicated.
Enforcement during Q1 also highlighted heightened scrutiny of how companies handle minors’ and student data. In March, the California Privacy Protection Agency announced a $1.1 million settlement with a youth sports media and ticketing platform for allegedly conditioning access to services on acceptance of tracking technologies, failing to provide compliant opt‑outs and failing to honor opt‑out preference signals. The agency emphasized that businesses cannot rely on industry opt‑out tools alone and must provide their own effective opt‑out mechanisms, particularly where student and youth data is involved.
As also reflected in various recent state-level amendments, regulators are treating precise geolocation and connected‑device data as high‑risk categories. In January, and consistent with trends we’ve been seeing at the state level, the Federal Trade Commission finalized a broad order against an automotive manufacturer over allegations that it collected and sold precise geolocation and driving behavior data without adequate disclosure or affirmative consumer consent. The order imposes long‑term restrictions on data sharing and mandates expanded consumer access, deletion and opt‑out rights, reinforcing that location data monetization will be closely scrutinized under unfair and deceptive practices theories, even outside comprehensive state privacy statutes.
Children’s and teens’ data protection also drove one of the most consequential enforcement and litigation developments of the quarter. In March, New Mexico secured a $375 million jury verdict against a social media company under the state’s consumer protection law, based on findings that the company misled consumers about the safety of its platforms and engaged in practices that endangered children. The verdict, one of the largest to date obtained by a state against a technology company, reflects a growing willingness by attorneys general to use existing consumer protection frameworks to challenge platform design and algorithmic features as well as representations about youth safety. That trend was reinforced the same month by a separate California jury verdict finding two social media companies liable for harms linked to the addictive designs of social media platforms and treating those platforms as defective products based on how their features were engineered to engage minors. Both companies have signaled their intent to appeal. Taken together, these cases indicate that regulators and courts are increasingly willing to look beyond content moderation and focus on product design and algorithmic engagement alongside the real‑world impacts of digital services on children and teens, significantly expanding enforcement and litigation risk for companies that serve or attract younger users.
Finally, enforcement attention expanded further into algorithmic decision‑making and pricing. In January, the New York Attorney General demanded extensive information from an online grocer regarding alleged algorithmic pricing practices, focusing on whether the company provided adequate disclosures about the use of personal data to affect prices under New York’s Algorithmic Pricing Disclosure Act. The inquiry highlights that algorithmic systems affecting consumers’ economic outcomes are rapidly becoming an enforcement priority, even where no dedicated AI statute is invoked.
Collectively, these actions reflect a clear enforcement shift toward testing operational privacy compliance. Regulators are examining whether opt‑out mechanisms function in practice, whether sensitive data use aligns with disclosures, and whether companies can demonstrate transparent, governable algorithmic systems across products and platforms.
App Age Assurance Laws
App store age assurance laws remain one of the more operationally complex privacy developments heading into mid‑2026. While much of the litigation posture remains unsettled, companies with consumer‑facing apps should not view these laws as theoretical.
Texas’ App Store Accountability Act was enjoined days before its January 1, 2026, effective date on First Amendment grounds and is currently on appeal. That decision has placed similar statutes under close judicial scrutiny, but it has not slowed legislative momentum.
Utah’s App Store Accountability Act is scheduled to take effect May 6, 2026, following a legal challenge and last‑minute legislative amendments addressing preinstalled apps, default safety settings and age‑verification flows. Importantly, those amendments defer substantive compliance obligations for app stores and developers until May 6, 2027. The amendments also eliminate enforcement authority by the Utah Attorney General while leaving a private right of action in place. Louisiana’s Online Protections for Minors law is scheduled for July 1, 2026, and California’s Digital Age Assurance Act is slated for January 1, 2027. In February 2026, Alabama became the latest state to adopt an app store accountability statute, extending common age‑verification, account categorization and parental consent requirements and also applying them to previously installed apps and existing accounts. Like California’s law, Alabama’s law takes effect January 1, 2027.
For private companies, these laws raise recurring issues, including determining whether particular apps or features are in scope, especially where minors may reasonably access them. Age‑verification and age‑estimation mechanisms themselves create sensitive data and data minimization concerns. Parental controls and teen‑specific defaults must be synchronized with state privacy rights and disclosures. Enforcement risk is unlikely to stay confined to app stores alone, particularly where developers, advertising practices or downstream data flows involving minors are implicated.
AI, Privacy and Emerging Best Practices
Q1 confirmed that AI governance is no longer separable from privacy compliance. In United States v. Heppner, for example, a federal court held that communications between a nonattorney employee and a public consumer AI tool were not privileged, focusing on how the tool was used and what the tool’s privacy notice explained to users about data uses and disclosures. Other courts have reached different conclusions on different facts, reinforcing that regulators and judges are scrutinizing transparency, notices, usage context and user expectations.
Although AI-specific legislation has encountered political headwinds, state regulators have made clear they will regulate AI through existing privacy, consumer protection, civil rights and antitrust laws. The Connecticut Attorney General’s February 2026 guidance explicitly emphasized this approach, warning that discrimination, deceptive practices and unlawful data use remain fully enforceable regardless of whether AI-specific statutes exist, particularly where consumers, children or essential services are affected.
AI compliance in 2026 resembles early-stage privacy compliance, with regulators moving from broad principles toward named risks, prohibited conduct and required governance documentation. Several state consumer privacy laws now include express rights related to profiling and automated decision-making. For companies, the takeaway is straightforward – if personal data is used to train models, power biometric systems or drive consequential decisions, regulators may ask not only whether models work but also whether consumer rights were honored, disclosures were accurate, opt-outs functioned, discriminatory effects were assessed and governance records exist.
Looking Ahead
Several significant requirements will take effect this summer, continuing the shift toward stricter oversight of minors’ data, automated processing, opt-out rights and compliance readiness. Amendments to the Connecticut Data Privacy Act will expand applicability thresholds, add to sensitive data definitions, enhance consumer automated decision-making rights and require new disclosures related to the use of personal data for training large language models. Utah’s Consumer Privacy Act will add a right to correct personal data and Arkansas’ Children and Teens’ Online Privacy Protection Act will impose COPPA-style obligations on companies collecting data from children and teens, including limits on targeted advertising and heightened consent requirements. Louisiana’s App Store Accountability Act is scheduled to take effect. Colorado’s delayed AI law may finally (or may not) come online with requirements tied to bias assessments, transparency and monitoring for discriminatory outcomes, although the Colorado Attorney General has in response to pending litigation signaled no intent to enforce the law until rulemaking is complete.