For most of the past decade, the development of U.S. privacy law has been measured by legislation.
California enacted the California Consumer Privacy Act in 2018. Other states followed with their own comprehensive privacy statutes. Legislatures then began adopting additional rules covering artificial intelligence, biometric information, consumer health data, children’s privacy, data brokers, genetic information, automated decision-making and online safety.
That legislative activity is continuing. But the next phase of American privacy law may be defined less by the number of bills passed and more by the cases regulators choose to bring.
More state privacy laws are now in effect. Temporary cure periods are expiring. Attorneys general are building specialized privacy teams. California has established a dedicated privacy regulator. States are sharing investigative resources and coordinating enforcement across jurisdictional lines.
As a result, businesses are beginning to learn what privacy laws mean through investigations, settlements, corrective orders and civil penalties.
The statutory text remains important. Enforcement, however, is increasingly showing companies how regulators expect that text to operate in the real world.
Privacy Law Is Moving From Enactment to Interpretation
The United States now has 23 enacted comprehensive state consumer privacy laws, in addition to a growing collection of sector-specific laws.
Four more comprehensive state privacy laws were enacted during 2026 alone.
For years, much of the business community’s attention remained focused on comparing the language of these statutes:
- Which businesses are covered?
- What counts as a sale of personal information?
- Which consumer rights must be offered?
- When is consent required?
- How should sensitive data be handled?
- Does the law include a cure period?
- Which exemptions apply?
Those questions still matter. But many of the most consequential compliance questions are now being answered through enforcement.
A law may require a business to offer consumers the right to opt out of targeted advertising. The statute may not explain every technical step necessary to honor that choice across websites, mobile applications, advertising platforms and downstream vendors.
Regulators fill that gap by investigating whether the company’s opt-out process actually works.
A law may permit a business to verify a privacy request. It may not establish exactly when a verification process becomes excessive or obstructive.
Regulators answer that question by examining whether consumers are being asked to provide unnecessary information or complete unreasonable steps before exercising their rights.
This is how enforcement begins to function as a form of practical rulemaking.
Regulators Are Testing Whether Privacy Rights Work
One of the clearest trends in recent enforcement is the movement away from checking whether a business has a privacy mechanism and toward determining whether that mechanism produces the legally required result.
It is no longer enough to place a “Do Not Sell or Share My Personal Information” link in a website footer.
Regulators may examine whether:
- The link is easy to locate
- The request is honored without unnecessary friction
- The preference is communicated to advertising technologies
- Tracking stops when legally required
- The decision is applied across relevant devices and accounts
- Service providers and third parties receive the instruction
- The business maintains evidence that the request was processed
The same operational standard applies to access, correction and deletion requests.
A company may publish an accurate privacy policy and still fail compliance testing if its internal systems cannot locate the information described in that policy.
A business may provide a request form but fail to search all relevant databases.
It may acknowledge an opt-out while continuing to transmit identifiers to advertising partners.
It may accept a deletion request but leave the information active in another system or with a vendor.
Enforcement is increasingly directed at these gaps between stated compliance and operational performance.
Technology-Neutral Laws Give Regulators Broad Reach
Many comprehensive privacy laws are deliberately technology-neutral.
They regulate the collection, use, disclosure and protection of personal information without limiting their application to a specific device, platform or business model.
That structure allows existing privacy laws to reach emerging technologies without requiring a new statute for every development.
A law governing sensitive information may apply whether that information is processed by a traditional database, a mobile application, an artificial intelligence model or an automated decision system.
A right to opt out of targeted advertising can apply even as advertising technology changes.
A requirement to provide meaningful notice can apply to new forms of data collection that did not exist when the statute was drafted.
This is one reason enforcement will increasingly shape technology policy.
Regulators can apply broadly written privacy obligations to new products and practices before legislatures enact technology-specific rules.
Companies should therefore avoid assuming that a new technology falls outside privacy law merely because the statute does not name it.
Targeted Advertising Remains a Major Enforcement Risk
The sale and sharing of personal information for targeted advertising have become recurring subjects of state privacy enforcement.
This is unsurprising. The right to opt out of these activities is one of the defining features of the modern state privacy framework.
The compliance problem is often not the absence of a policy. It is the disconnect between the policy and the technology operating on the website or application.
Regulators may examine:
- Whether tracking technologies activate before a consumer makes a choice
- Whether an opt-out signal is recognized
- Whether the company honors browser-based preference signals
- Whether advertising vendors are properly classified
- Whether personal information continues to be disclosed after an opt-out
- Whether mobile and web environments produce consistent results
- Whether the company can prove when and how consent was obtained
A privacy notice cannot cure a consent or opt-out mechanism that does not function as described.
That distinction is likely to remain central to privacy enforcement because tracking activity is relatively easy for regulators, researchers and plaintiffs to test.
Dark Patterns Are Becoming an Enforcement Issue
Regulators are also scrutinizing how privacy choices are presented.
A company may technically offer a privacy right while using design features that discourage people from exercising it.
Potentially problematic practices include:
- Making acceptance easier than rejection
- Using confusing button labels
- Requiring more steps to opt out than to opt in
- Using repeated prompts to reverse a privacy choice
- Requesting unnecessary personal information
- Hiding privacy settings within unrelated menus
- Presenting choices in a misleading or visually unequal manner
These design decisions can create exposure under both state privacy laws and consumer protection statutes.
The enforcement question is not simply whether a choice existed. It is whether the consumer could exercise that choice freely and understand its consequences.
Children’s Privacy Enforcement Extends Beyond Data Collection
Children and teenagers remain a major priority for state and federal regulators.
Traditional privacy inquiries focus on whether a business knowingly collected children’s information, obtained required consent or sold information without proper authorization.
Recent enforcement has expanded beyond those questions.
Regulators are also examining whether businesses:
- Ignored evidence that children were using a product
- Failed to implement effective age-gating
- Misrepresented known risks to young users
- Designed features that created unique harms for minors
- Provided inadequate notice about youth data practices
- Processed children’s information without appropriate consent
This broader approach allows regulators to combine privacy law, online safety rules and general consumer protection authority.
A company may therefore face scrutiny not only for how it collected a child’s information, but also for what its product design did with that information and whether the company accurately disclosed known risks.
Artificial Intelligence Claims Are Being Treated as Consumer Protection Issues
Privacy enforcement is also converging with artificial intelligence regulation.
Regulators do not always need an AI-specific law to pursue misleading claims about an AI product.
Federal and state consumer protection statutes already prohibit unfair or deceptive practices.
Those authorities can be applied when a business exaggerates the accuracy, reliability or capabilities of an AI system.
Potential enforcement theories may arise when companies claim that an AI tool:
- Produces consistently accurate results without sufficient evidence
- Eliminates bias when bias has not been adequately evaluated
- Protects personal information while retaining or disclosing it
- Makes decisions independently when significant human intervention remains
- Provides security guarantees that the technology cannot support
- Uses deidentified information when the data remains linkable to individuals
This illustrates the reach of technology-neutral enforcement.
A regulator may not need a statute titled “Artificial Intelligence Act” when existing privacy and consumer protection laws already address the underlying conduct.
Regulators Are Using Multiple Laws in the Same Cases
Another important enforcement trend is the variety of legal authorities being used.
Comprehensive privacy laws are becoming more prominent as additional statutes take effect. But regulators continue to rely heavily on older laws.
These may include:
- State unfair and deceptive practices statutes
- Section 5 of the Federal Trade Commission Act
- The Children’s Online Privacy Protection Act
- Biometric privacy laws
- Health data statutes
- Data broker requirements
- Breach notification laws
- Industry-specific security regulations
A single practice may create exposure under several of these authorities.
For example, a company that inaccurately describes its use of personal information could face a deception claim. If the same company fails to provide a legally required opt-out, it may also violate a comprehensive privacy statute. If children are involved, youth-specific laws may create additional exposure.
This means compliance programs cannot be designed around one statute at a time.
Businesses need a unified view of how their data practices intersect with privacy, consumer protection, cybersecurity and sector-specific obligations.
Texas and California Show That Privacy Enforcement Is Bipartisan
Privacy legislation is often discussed through a partisan lens.
Enforcement activity tells a more complicated story.
California and Texas were among the most active state privacy enforcers during 2025, despite their significant political differences.
Connecticut, Florida and Utah also pursued state privacy matters, while numerous states participated in actions involving youth privacy and online safety.
This matters for national businesses.
Privacy enforcement cannot be treated as a risk confined to California or other traditionally regulation-heavy states.
Republican and Democratic officials may emphasize different policy concerns, but both have shown a willingness to challenge data practices they consider deceptive, harmful or inconsistent with state law.
The enforcement theories may differ. The operational expectation is similar: businesses must understand their data practices and be prepared to justify them.
States Are Formalizing Cross-Border Enforcement
Multi-state privacy cooperation is also becoming more organized.
The Consortium of Privacy Regulators includes the California Privacy Protection Agency and attorneys general from states including California, Colorado, Connecticut, Delaware, Indiana, Minnesota, New Hampshire, New Jersey and Oregon.
The consortium was established to share expertise, combine resources and coordinate investigations involving potential privacy violations.
State cooperation is not new. Attorneys general have worked together on consumer protection and data breach matters for years.
The formal creation of a privacy-focused consortium is nevertheless significant.
It may allow regulators to:
- Share investigative methods
- Coordinate requests for information
- Compare company representations across states
- Develop more consistent interpretations
- Pursue companies operating in several jurisdictions
- Reduce duplication of technical expertise
- Increase leverage during settlement negotiations
For companies, this means a privacy issue discovered in one state may not remain isolated there.
An investigation can become a multi-jurisdictional matter, particularly when the underlying practice affects consumers nationwide.
Enforcement Can Create More Consistency Between State Laws
The growing patchwork of state privacy laws creates legitimate compliance challenges.
The statutes contain different thresholds, definitions, exemptions, consent requirements and consumer rights.
There is also a risk that regulators will interpret similar statutory language differently.
Coordinated enforcement may reduce some of that uncertainty.
When regulators collaborate, they can develop shared expectations around common requirements such as:
- Opt-out mechanisms
- Universal preference signals
- Data minimization
- Request verification
- Sensitive data consent
- Privacy notice disclosures
- Vendor oversight
- Consumer request response procedures
Enforcement will not eliminate differences between state statutes. But coordinated actions may create a more consistent operational baseline.
That baseline could eventually become as important to businesses as the language of the individual laws.
Public Settlements Are Becoming Informal Compliance Guidance
Each public enforcement action offers information to companies that were not involved in the case.
A settlement may reveal:
- Which practices regulators are prioritizing
- How a statutory term is being interpreted
- What evidence regulators expect businesses to maintain
- Which technical failures are considered serious
- How long corrective obligations may continue
- What remedial steps can reduce penalties
In that sense, enforcement actions function as informal guidance.
They show how regulators translate general legal standards into specific operational requirements.
This guidance is not always perfect. Companies may disagree with the regulator’s interpretation, and settlements do not necessarily establish binding precedent.
But ignoring enforcement activity creates risk.
When the same deficiencies appear repeatedly in public cases, businesses should assume that those issues will be examined in future investigations.
Privacy Enforcement Can Benefit Compliant Businesses
Increased enforcement creates obvious risks, but it can also benefit companies that have invested in mature privacy programs.
Businesses that spend money on consent systems, data mapping, request automation, legal review and privacy staffing compete with companies that do little more than publish a generic privacy policy.
Consistent enforcement reduces the advantage enjoyed by companies that avoid those investments.
It can also validate privacy budgets by showing executives and boards that operational compliance is not optional.
Regulators have repeatedly indicated that a company’s conduct before and during an investigation can affect the outcome.
A business that can demonstrate a functioning privacy program may receive more favorable treatment than one that ignored its obligations.
Relevant evidence may include:
- Documented policies and procedures
- Privacy impact assessments
- Data inventories
- Consent records
- Consumer request logs
- Vendor contracts
- Training records
- Internal testing
- Remediation plans
- Executive or board oversight
Cooperation does not eliminate liability. But documented good-faith compliance efforts may influence civil penalties, settlement terms and the duration of regulatory oversight.
Privacy Theater Is Becoming More Dangerous
The enforcement environment is particularly risky for companies engaged in privacy theater.
Privacy theater occurs when a business creates the appearance of compliance without changing the underlying data practice.
Examples include:
- Publishing a privacy notice that does not match actual data collection
- Displaying an opt-out link that does not stop disclosures
- Offering a request form that is not connected to internal systems
- Claiming to honor privacy signals without technically recognizing them
- Maintaining a consent banner that allows tracking before consent
- Calling data anonymous when it can still be linked to a person
- Listing vendors without monitoring how they use information
These failures are relatively easy for regulators to identify.
They also create damaging evidence because the company’s own policies and interfaces may contradict its technical practices.
Small Compliance Failures Can Invite Larger Investigations
Regulators do not need to begin with the most complex privacy issue.
Simple deficiencies can attract scrutiny.
An outdated privacy notice, missing opt-out link, unrecognized preference signal or incomplete disclosure of data sales may be easier to identify than a complicated internal governance failure.
Once an inquiry begins, regulators may examine much more than the original issue.
They may request information concerning:
- Data collection practices
- Consumer request procedures
- Advertising relationships
- Sensitive information
- Retention schedules
- Children’s data
- Security measures
- Vendor contracts
- Consent records
- Internal governance
This is why basic compliance failures should not be dismissed as technicalities.
They can become entry points into broader investigations.
Civil Penalties Are Becoming More Significant
Privacy penalties are also increasing.
A record civil penalty under the CCPA was established in 2025 and then surpassed twice during 2026, including settlements of $2.75 million and $12.75 million.
Regulators have made clear that penalties are intended to deter violations rather than become an ordinary cost of doing business.
The financial consequences may include more than a civil payment.
Settlement obligations can require:
- Independent assessments
- Executive certifications
- Regular compliance reporting
- Technical changes
- Consumer remediation
- Vendor reviews
- Employee training
- Long-term monitoring
For many businesses, these continuing obligations can create greater operational cost than the initial penalty.
Enforcement Will Influence Future Privacy Legislation
The relationship between enforcement and legislation runs in both directions.
Legislatures give regulators authority. Regulators then identify gaps, ambiguities and practical obstacles while enforcing the law.
Those findings return to lawmakers.
State attorneys general may tell legislators that a definition is too narrow, a cure period is being abused, an exemption creates an unexpected gap or a procedural requirement is difficult to enforce.
Lawmakers may respond by amending the statute.
Future state privacy bills will therefore be shaped partly by what regulators learn through investigations.
Enforcement may influence:
- Whether cure periods are retained
- How sensitive information is defined
- Which businesses qualify for exemptions
- How universal opt-out signals are treated
- Whether additional audit requirements are imposed
- What authority regulators receive
- How civil penalties are calculated
The next generation of privacy legislation will not be drafted in isolation from enforcement. It will be informed by the cases regulators bring and the compliance failures they uncover.
Businesses Should Build for Enforcement, Not Just Statutory Minimums
A privacy program designed only to satisfy the surface language of a statute may not withstand regulatory scrutiny.
Businesses should prepare to demonstrate how compliance works from beginning to end.
That requires more than policies.
Organizations should be able to show:
- What personal information they collect
- Why the information is needed
- Where it is stored
- Which vendors receive it
- How long it is retained
- How consumer requests are processed
- How consent and opt-outs are enforced
- How sensitive information is protected
- Who is accountable for compliance
- How the program is tested
The strongest privacy programs are designed around evidence.
When a regulator asks whether an opt-out was honored, the company should be able to produce a record.
When asked whether a request was completed, it should be able to show the workflow.
When asked why information was retained, it should be able to identify the business and legal basis.
When asked how a vendor was evaluated, it should be able to provide the assessment and contract terms.
Captain Compliance Helps Businesses Prepare for the Enforcement Era
Captain Compliance helps organizations operationalize state privacy requirements through consent management, cookie and tracking technology scanning, consumer request automation, data mapping, privacy assessments, vendor governance and compliance documentation.
As privacy enforcement increases, companies need more than a static privacy policy.
They need systems that can demonstrate that privacy choices are recognized, requests are fulfilled, data practices are documented and compliance controls operate as intended.
The center of U.S. privacy law is shifting.
Legislatures will continue to pass new laws. But investigations, settlements and regulatory coordination will increasingly determine what those laws require in practice.
Businesses that follow enforcement activity closely will be better positioned to anticipate those expectations.
Businesses that wait for a regulator to explain their obligations during an investigation may learn the same lessons at a much higher cost.
Frequently Asked Questions
Why is privacy enforcement increasing?
More state privacy laws have taken effect, temporary cure periods are expiring and regulators have had time to build enforcement teams and investigate business practices. States are also coordinating more closely across jurisdictions.
How does enforcement change the meaning of a privacy law?
Enforcement actions show how regulators interpret general statutory requirements in specific circumstances. Public settlements can clarify expectations concerning opt-outs, consumer requests, consent, disclosures, vendor oversight and other operational requirements.
Are privacy enforcement actions limited to California?
No. California remains an important enforcement jurisdiction, but Texas, Connecticut, Florida, Utah and other states have also pursued privacy matters. State enforcement activity crosses political and regional lines.
Can regulators use consumer protection laws for privacy cases?
Yes. State unfair and deceptive practices laws and Section 5 of the Federal Trade Commission Act remain important privacy enforcement tools, particularly when a business makes misleading statements or omits material information about its data practices.
What are regulators examining in opt-out mechanisms?
Regulators are looking beyond whether an opt-out link exists. They may test whether the mechanism is easy to use, whether tracking or data sharing actually stops and whether the business maintains evidence showing that the request was honored.
Can a mature privacy program reduce enforcement exposure?
A mature program does not guarantee that a business will avoid an investigation or penalty. However, documented good-faith compliance efforts, cooperation and prompt remediation may influence how regulators resolve alleged violations.
What should businesses do now?
Businesses should test their consent and opt-out systems, review privacy notices, confirm that consumer request workflows reach all relevant systems, assess vendors, document retention practices and maintain records demonstrating that their privacy controls function in practice.