Washington Attorney General Calls for Broader Privacy Laws, Stronger Consent and Data Broker Regulation

Table of Contents

Washington’s first-ever Attorney General Data Privacy Report could provide a roadmap for the state’s next wave of privacy legislation, calling for stronger consent requirements, data minimization, restrictions on sensitive data, data-broker registration and more effective enforcement.

 AG’s first-ever Data Privacy Report identifies policy priorities and recommendations

Washington Attorney General Nick Brown has released the state Attorney General’s first comprehensive Data Privacy Report, delivering one of the clearest signals yet that Washington could pursue substantially broader regulation of how businesses collect, use, retain and sell personal information.

Published August 14, 2026, the 35-page report examines what the Attorney General’s Office describes as structural problems within the modern “data economy” and recommends legislative, enforcement and educational responses.

For businesses, however, the most important takeaway is not simply that Washington officials are concerned about privacy.

It is what they want policymakers to do about it.

The Attorney General is recommending that Washington lawmakers consider:

  • meaningful and informed consent requirements;
  • limits on unnecessary data collection and retention;
  • restrictions on secondary uses of personal information;
  • stronger protections for biometric and precise geolocation information;
  • mandatory registration and additional requirements for data brokers;
  • centralized deletion and opt-out mechanisms;
  • stronger and better-funded privacy enforcement; and
  • clearer privacy and cybersecurity guidance for businesses.

The report does not itself impose those new requirements. But it could become an influential policy blueprint as Washington considers how to fill what the Attorney General describes as significant gaps in the state’s existing privacy regime.

Washington Says Its Existing Privacy Laws Are Too Fragmented

Washington is not starting from zero.

The state already has significant sector-specific and data-specific privacy laws, including the Washington My Health My Data Act, biometric protections, breach-notification requirements and specialized protections governing other categories of information.

The My Health My Data Act, for example, regulates consumer health information outside many traditional HIPAA contexts and makes violations actionable under Washington’s Consumer Protection Act. The Attorney General can enforce the law, and the statutory framework also allows private actions through the Consumer Protection Act.

But the Attorney General’s new report argues that Washington’s overall system remains fragmented.

According to the report, Washington does not currently have a generally applicable privacy framework establishing uniform requirements for consent, transparency, data minimization, retention and secondary uses of personal information across industries.

That distinction is crucial.

Washington has spent years regulating particular high-risk categories of data and particular situations. The new report suggests policymakers should increasingly consider baseline privacy rules that follow the personal information itself rather than relying almost entirely on the context in which the information happens to be collected.

If lawmakers follow that recommendation, Washington could move closer to states such as California, Colorado, Connecticut and Oregon, where broader consumer privacy frameworks regulate data processing across a much wider range of commercial activities.

Consent Is at the Center of Washington’s Proposed Privacy Model

One of the strongest themes in the report is consent.

The Attorney General recommends requiring data collectors to obtain meaningful and informed consent before collecting, using or sharing personal information beyond what is reasonably necessary to provide the product or service requested by the consumer.

That is considerably more consequential than simply requiring a privacy policy.

The report says consent mechanisms should be:

  • clear;
  • balanced;
  • easy to navigate;
  • written in plain language; and
  • designed to give consumers a genuine opportunity to decline unnecessary collection.

It specifically criticizes privacy terms buried inside lengthy policies or agreements and calls for lawmakers to prohibit deceptive interface designs that steer users toward surrendering more data than they otherwise would.

The report points to practices such as making an “accept” option easier or more prominent while forcing consumers through additional steps to reject tracking as examples of potentially problematic consent design.

For companies operating websites and mobile applications, that recommendation deserves attention.

A technically functioning consent-management platform may not be enough if the interface itself is designed in a manner regulators consider manipulative.

The emerging regulatory question is increasingly becoming:

Was the consumer presented with a real choice — and did the technology actually honor that choice?

That means button symmetry, banner configuration, tracking behavior before consent, withdrawal mechanisms and consent records may all become more important as regulators move beyond simply asking whether a privacy notice existed.

Washington Wants Businesses to Collect Less Data

The second major recommendation is data minimization.

The Attorney General proposes limiting the collection, use and retention of personal information to what is reasonably necessary to provide the product or service the consumer actually requested.

The report also recommends restricting secondary uses of information when those uses are unrelated to the original interaction.

Its message is straightforward: businesses should not collect or retain information merely because the data might become commercially useful later.

This represents a broader shift occurring across U.S. privacy regulation.

Traditional privacy compliance often focused heavily on disclosure:

Tell consumers what information you collect and what you do with it.

Data minimization changes the question:

Why are you collecting the information in the first place?

Under that approach, disclosing unnecessary processing may not cure the underlying problem.

Washington’s report specifically cites California, Colorado, Connecticut and Oregon as examples of states that have adopted broader data-minimization concepts.

For businesses, this makes data inventories and data-flow mapping increasingly important.

Companies need to know:

  • what personal information they collect;
  • which technologies collect it;
  • why it is needed;
  • which third parties receive it;
  • what secondary purposes it is used for; and
  • how long it is retained.

A company cannot meaningfully minimize data it does not know it is collecting.

Biometric and Precise Geolocation Data Could Face Tougher Rules

The Attorney General also recommends stronger protections for two particularly sensitive categories of information: biometric identifiers and precise geolocation data.

The report calls for clear informed consent before companies collect either category.

It further recommends limiting or prohibiting the sale and unnecessary commercial use of biometric and precise location information and establishing specific retention limits.

Washington already regulates biometric information in certain circumstances and protects geolocation information in some specialized contexts.

The Attorney General argues that those protections remain incomplete.

For example, precise geolocation information can expose where someone sleeps, works, worships, receives medical treatment or spends significant time. The report argues that such information warrants stronger protection regardless of the particular commercial context in which it was collected.

That recommendation could have consequences well beyond traditional location-data companies.

Mobile applications, advertising networks, analytics providers, retailers, connected-device operators and other organizations can all interact with precise location information depending on how their products are configured.

Data Brokers Are a Major Target

Perhaps the most concrete legislative proposal in the report concerns data brokers.

The Attorney General recommends requiring data brokers processing Washington residents’ personal information to register annually with the state and publicly disclose the categories of personal information they collect, sell or share.

Registration would only be the beginning.

The report also recommends requiring registered data brokers to:

  • maintain administrative, technical and physical security safeguards;
  • limit or prohibit sales of sensitive personal information;
  • honor requests to delete personal information;
  • honor requests to opt out of the sale or sharing of information; and
  • participate in a centralized mechanism allowing consumers to exercise privacy rights across multiple data brokers simultaneously.

Washington specifically identifies California’s Delete Request and Opt-Out Platform, commonly known as DROP, as one model policymakers can examine.

California, Oregon, Texas, Vermont and New Jersey are among the states the report identifies as having already adopted data-broker registration laws.

If Washington follows suit, another major state could join the accelerating effort to transform the data-broker industry from an ecosystem largely invisible to consumers into a publicly registered and directly regulated industry.

The Attorney General Wants Privacy Laws That Can Actually Be Enforced

The report’s enforcement section may ultimately prove as important as its substantive privacy recommendations.

The Attorney General argues that privacy rights have limited value when enforcement mechanisms are unclear, difficult to administer or too weak to change corporate behavior.

The report says effective enforcement should incorporate three principles:

Clarity: Businesses and consumers should know who can enforce the law and what penalties or remedies apply.

Practicality: Regulators need sufficient authority, tools, expertise and resources, while companies need requirements they can realistically understand and implement.

Accountability: Penalties and remedies must be significant enough to deter violations.

Importantly, the report does not endorse one universal enforcement model.

Instead, it says policymakers could use Washington’s existing Consumer Protection Act, establish dedicated funding for privacy enforcement, or create new frameworks providing authority for investigations, penalties, reporting, rulemaking and other compliance tools.

It also points lawmakers toward California and Colorado as examples of different regulatory structures.

California operates a dedicated privacy regulator in addition to Attorney General enforcement, while Colorado gives enforcement authority to the Attorney General and district attorneys.

The report also specifically highlights privacy risk assessments and cybersecurity audits as examples of regulatory mechanisms employed elsewhere.

That is an important signal for businesses.

Washington’s future debate may not be limited to creating additional consumer rights.

It could also encompass how companies prove they assessed and managed privacy risk before something went wrong.

Data Breaches Are Driving the Policy Push

The Attorney General supports the recommendations with stark breach statistics.

According to the report, the AGO received reports of 209 data breaches affecting more than 8 million Washington residents during 2025.

More than 80% of those reported breaches involved exposed Social Security numbers.

The office argues that extensive collection and retention magnify the damage when security incidents occur: the more sensitive information an organization accumulates, the more information exists to be stolen, misused or repurposed.

This is why privacy and cybersecurity increasingly cannot be treated as entirely separate disciplines.

Data minimization is a privacy principle, but it is also a security control.

Information that was never unnecessarily collected cannot later be exposed in a breach.

Washington Consumers Say They Feel They Have Little Control

The Attorney General also relies heavily on a 2025 privacy survey.

The office received responses from more than 700 Washington residents across 26 counties.

Among those respondents:

83% said they had little or no control over who could access their personal information.

95% said there was no circumstance in which they would be comfortable having their information collected, shared or sold without informed consent.

The survey also found significant difficulty exercising existing privacy choices: 62% reported difficulty opting out of targeted advertising and 65% reported difficulty requesting deletion from an application or service.

Those figures help explain why consent mechanics and consumer-request infrastructure feature so prominently in the Attorney General’s recommendations.

The policy direction is not merely toward more disclosures.

It is toward making privacy choices operationally usable.

Cookies Are Specifically on the Attorney General’s Radar

One detail businesses should not overlook is that the report specifically discusses website cookies and tracking.

As part of its public-education initiative, the Attorney General’s Tech Policy Team intends to develop materials explaining subjects including:

  • how personal information is collected, shared and sold;
  • how consumers can manage privacy settings;
  • how tracking cookies work;
  • how to recognize deceptive design; and
  • how data sharing can create privacy risks.

The report also recommends working with business associations to develop practical privacy and data-security resources for small businesses.

That creates an interesting dynamic.

Washington is simultaneously promising to help businesses understand privacy requirements while recommending stronger baseline laws and better enforcement.

Companies should view that as a warning against relying on ignorance or complexity as a long-term compliance strategy.

Privacy regulators increasingly expect organizations to understand what technologies are operating on their websites, what those technologies collect and where the resulting information goes.

What Businesses Should Do Now

Nothing in the August 14 report instantly creates a new statewide omnibus privacy law.

Businesses therefore should not treat the recommendations themselves as newly enforceable statutory obligations.

But they also should not ignore the report simply because legislation has not yet been enacted.

Attorney General reports of this type can influence legislative drafting, enforcement priorities and regulators’ interpretation of what responsible data practices look like.

Businesses operating in Washington should therefore evaluate whether their existing privacy programs would withstand the policy framework Brown is proposing.

That includes reviewing:

Consent architecture. Determine whether unnecessary tracking or data collection occurs before the consumer has been presented with an appropriate choice.

Website technologies. Identify cookies, pixels, analytics platforms, advertising technologies, session-replay tools, chat technologies and other third-party scripts transmitting information.

Data minimization. Document why each category of personal information is collected and whether it remains necessary.

Secondary uses. Determine whether information collected for one purpose is subsequently used for advertising, analytics, profiling or another unrelated purpose.

Sensitive data. Identify biometric, health, precise geolocation and other high-risk information and evaluate whether enhanced consent and retention controls apply.

Consumer requests. Ensure deletion, access and opt-out requests can actually be processed rather than merely described in a privacy policy.

Vendor relationships. Understand what third-party vendors receive personal information and what contractual and technical restrictions govern their use.

Retention. Establish defensible retention periods instead of maintaining personal information indefinitely.

The Bigger Story: Washington May Be Preparing for Its Next Privacy Chapter

Washington has debated comprehensive consumer privacy legislation for years without adopting the type of broad omnibus law now operating in numerous other states.

The Attorney General’s new report makes clear that the issue has not disappeared.

Instead, Washington now has a detailed set of recommendations from its chief legal officer identifying exactly where the current system is considered inadequate.

The report calls for a model built around several principles that are increasingly becoming common across U.S. privacy regulation:

collect less, obtain meaningful consent, give consumers usable rights, place stronger controls around sensitive information, increase transparency and make violations enforceable.

That does not mean every recommendation will become law.

The Legislature will ultimately determine whether — and how — Washington expands its privacy regime.

But for privacy officers, legal teams, marketers, developers and businesses collecting Washington residents’ information, the report provides something valuable before any bill is introduced:

a preview of what Washington’s Attorney General believes the state’s next privacy rules should look like.

And companies that begin addressing those issues now will be in a considerably better position if Washington lawmakers decide to turn that blueprint into law.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.