U.S. state privacy regulators are ramping up enforcement with a clear focus on data brokers, sensitive personal information, and transparency obligations. From mandatory registration sweeps to multimillion-dollar settlements, 2025 and so far in 2026 have delivered strong signals that accountability is no longer optional.
This in-depth analysis builds on recent enforcement trends, offering practical takeaways for businesses navigating the complex patchwork of state laws like the CCPA/CPRA, Oregon Consumer Privacy Act, Texas Data Privacy and Security Act, and others.
Data Broker Registration: The New Compliance Flashpoint
Several states now require data brokers to register annually, creating an easy entry point for investigations. Failure to register often triggers deeper scrutiny of broader data practices.
California’s Delete Act Enforcement: CalPrivacy has conducted investigative sweeps, leading to settlements with companies including Key Marketing Advantage, Jerico Pictures, and S&P Global Inc. The agency has forced several entities to register as data brokers. One notable case against Background Alert resulted in the company ceasing operations for three years.
Oregon Highlights: The state AG’s office received 62 data broker-related complaints out of 214 under the Oregon Consumer Privacy Act. “People search” sites that compile detailed profiles from public records are under particular scrutiny due to risks of inaccuracy and re-identification.
Emerging Laws: Connecticut’s new data broker law is expected to drive similar activity. Businesses that buy, sell, or compile personal information — even as a secondary activity — should evaluate registration obligations carefully.
Business Practices That Trigger Data Broker Status
Regulators are looking beyond formal titles to actual practices:
- Compiling and selling consumer profiles using public records and third-party data.
- Using pattern recognition and inferences (covered under CCPA as sensitive processing in some contexts).
- Nationwide data sales that include California (or other regulated state) residents without proper segmentation.
- Creating targeted advertising lists from behavioral data aggregated across sources.
Key Lesson: Even companies that do not self-identify as “data brokers” can fall under the definition if they engage in these activities. Proactive data flow mapping and legal review are essential.
Sensitive Data Enforcement Heats Up
States are cracking down on inadequate notice, consent, and safeguards for sensitive data (precise geolocation, biometrics, health inferences, etc.).
Texas Actions
Texas AG Ken Paxton has been particularly active:
- Allstate/Arity lawsuit: Alleged failure to clearly disclose sensitive data processing (precise geolocation from mobile apps) and obtain affirmative consent. Data was analyzed and sold to insurers.
- Google settlements: $1.375 billion across cases involving persistent geolocation tracking despite opt-outs, default permissions on Android, and biometric collection (facial recognition in Google Photos, voiceprints via Assistant).
Utah vs. Snap
Utah alleged violations involving My AI feature’s collection of geolocation and biometric data (speech patterns, voiceprints) without proper notice or consent — including from known minors.
Common Themes: Buried notices, multi-layered opt-outs, default-on tracking, and indefinite retention of sensitive data.
Privacy Notice Deficiencies and Symmetrical Choice
Connecticut has run multiple “privacy notice sweeps,” leading to settlements like the one with TicketNetwork over unclear notices and non-functional rights mechanisms.
In California, the Honda case highlighted “non-symmetrical” cookie banners: easy “Accept All” vs. multi-step opt-out. CalPrivacy views cookie banners as opt-out mechanisms that must offer symmetrical choice.
Third-Party Contract Compliance
Regulators are examining controller-processor/service provider contracts:
- Tractor Supply: Failure to contractually prohibit downstream selling/sharing.
- Healthline: Advertising partner contracts allowing broad internal use; required annual audits and new compliant agreements.
Practical Compliance Recommendations
- Registration Check: Map all data buying/selling/compiling activities against state definitions.
- Sensitive Data Audit: Inventory processing of geolocation, biometrics, etc. Implement clear notices and affirmative consent where required.
- Notice & Choice Overhaul: Ensure privacy policies and cookie banners are clear, accessible, and symmetrical.
- Contract Review Program: Annual audits of vendor agreements with strong flow-down protections and audit rights.
- Delete & Opt-Out Readiness: Streamline consumer rights fulfillment processes.
- Documentation & Governance: Maintain robust records for enforcement defense.
FAQs: Data Broker & Sensitive Data Enforcement
Q: Does my company need to register as a data broker?
A: If you buy, sell, or compile personal information for commercial purposes (especially in CA, OR, CT, etc.), conduct a formal assessment. Even secondary activities can trigger requirements.
Q: What counts as “sensitive data”?
A: Precise geolocation, biometrics, health inferences, children’s data, and more — definitions vary slightly by state but carry heightened obligations.
Q: How can businesses prepare for audits/sweeps?
A: Proactive mapping, policy updates, and mock exercises significantly reduce risk and demonstrate good faith.
Proactive Compliance Is the Best Defense
State privacy enforcement in 2025-2026 shows regulators using registration requirements as gateways to broader investigations, while zeroing in on sensitive data handling and transparency failures. The patchwork is challenging, but patterns are clear: clear notices, meaningful consent, robust contracts, and operational readiness are non-negotiable.