What increasing privacy enforcement activity means for US privacy legislation

The next phase of U.S. privacy law may be shaped as much by enforcement as legislation, as regulators increase oversight, coordinate across states and influence how privacy laws evolve.

Contributors:
Jordan Francis
CIPP/E, CIPP/US, CIPM, FIP
Senior Policy Counsel
Future of Privacy Forum
Editor's note
The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains.
For the last decade, U.S. privacy law has been defined in large part by legislative activity. California catalyzed a wave of new state laws when it enacted the California Consumer Privacy Act in 2018. There are now 23 state comprehensive consumer privacy laws enacted in addition to dozens of sectoral laws focusing on specific industries, technologies and practices, such as artificial intelligence, automated decision-making technology, biometric identification, consumer health data, data brokerage, data-driven pricing, genetic testing, and youth privacy and online safety.
As the privacy lead on the Future of Privacy Forum's U.S. Legislation team, I track hundreds of consumer privacy bills a year across these different subjects. That rapid pace of legislation shows no signs of abating, and 2026 has already seen four new comprehensive privacy laws enacted. This constant swirl of legislative activity remains important to the future of information privacy and data protection in this country, now and in the coming years.
New bills will continue to move. Regulations will continue to develop. But the center of gravity in the state privacy landscape may be shifting. Broadly applicable, technology-neutral privacy rules can address many of the pressing tech policy issues that drive new legislation — if these laws are enforced. As more of these new laws go into effect, cure periods expire and regulators build up their capacity to enforce the law, we will move into an era where the meaning of laws is shaped more by the outcome of enforcement activities than by the discussions in state legislatures. This shift may already be underway if the rise of enforcement activities in the past year is any indication of what is to come.
Lessons from last year's enforcement activity
As highlighted in the FPF's retrospective on privacy enforcement activity in 2025 and an ongoing enforcement series by the IAPP's former Westin Fellow David Botero, state authorities significantly ramped up privacy enforcement actions last year. Looking back at that regulatory activity, I have three high-level observations on the enforcement landscape. Rather than addressing the specifics of each enforcement action, these observations pertain to the direction of the enforcement landscape and the broader impact on state privacy law.
First, the enforcement actions themselves were varied in terms of their substantive focus. There was a significant jump in the enforcement of comprehensive consumer privacy laws last year. As one might expect for laws that are broadly applicable, nonsectoral and technology-neutral, no one issue predominated last year's activity. Several cases focused on the selling or sharing of personal data, especially for targeted advertising. The right to opt out of both data sales and targeted advertising is one of the key features of the new state privacy law regime, and that translates into constant scrutiny from regulators to ensure compliance. Regulators no longer check merely whether a business has an opt-out mechanism; they also want to ensure that it works. The same goes for consumer rights more generally. Regulators are checking if a business's rights mechanisms use manipulative design features or require an excessive amount of information from consumers.
Apart from the enforcement of state privacy laws, last year also saw significant enforcement activity on sectoral issues. When it comes to children, for example, regulators want to know if a business is obtaining opt-in consent for processing children's personal data, selling children's personal data without adequate notice or consent, or willfully disregarding the presence of children on the business's platform or using the business's product.
But youth-related enforcement activities extend well beyond privacy-focused harms. Regulators are also leveraging existing consumer protection laws and new youth safety requirements to enjoin and penalize practices that they see as being uniquely harmful to children and teenagers. These include things like deceiving the public about known risks of harm to children on a business's platform, either by omission or misrepresentation, and insufficient age-gating where required by law.
Existing consumer protection law also provides a basis for enforcement actions focused on AI. Last year, the Federal Trade Commission announced several settlements concerning deceptive AI claims. The FTC seemed particularly focused on whether businesses were misrepresenting the capabilities of their products, including by overstating the accuracy or reliability of their tools on offer.
My second observation about the enforcement landscape is that the legal authorities underlying these enforcement actions are also varied. Last year saw a significant increase in enforcement actions brought under state comprehensive privacy laws. This makes sense for a number of reasons — more laws have gone into effect, cure periods have expired, and businesses have had time to adjust their practices and establish compliance programs.
But, as mentioned above, established laws remain as relevant as ever. The federal Children’s Online Privacy Protection Act remains a key priority for the FTC. State and federal prohibitions on unfair and deceptive trade practices are also a constant source of privacy-focused lawsuits. Much of Texas' activity in the past year, for example, has been based on the Texas Deceptive Trade Practices Act. Likewise, the FTC continues to bring claims under Section 5 of the FTC Act.
There is nothing new about regulators bringing enforcement actions against companies that make deceptive statements or material omissions about their data practices, but those activities take on new significance when paired with a broader rise in privacy enforcement activity. Regulators have shown that they will not hesitate to use whatever levers are available to them if they think that a consumer's privacy is being violated.
My third observation on the current enforcement landscape is that this activity defies partisan lines. The two states that led the way in privacy enforcement last year were Texas and California. Last year also saw the enforcement of state privacy laws by Connecticut, Florida and Utah, not to mention the myriad states that brought actions focused on youth privacy and online safety.
One important enforcement milestone from last year was the establishment of a bipartisan Consortium of Privacy Regulators. The group consists of representatives from both red and blue states — the California Privacy Protection Agency and state attorneys general from California, Colorado, Connecticut, Delaware, Indiana, New Hampshire, New Jersey, Minnesota and Oregon. According to press releases, the consortium's stated purpose is to "share expertise and resources, as well as coordinate efforts to investigate potential violations of applicable laws." Cross-state collaboration on enforcement activity is nothing new, but the formal establishment of this group speaks to each state's public intent to enforce the law and uphold the privacy rights of their citizens.
Positive takeaways for consumers and businesses
So, it seems that enforcement activity is growing, but what does all of this activity mean for the people most affected by it? For consumers, first and foremost, it means justice and protection. Your privacy matters. You have rights and your data is subject to protection. But those rights and protections only exist insofar as they are operationalized. An enforcement action is the first step towards remedying harm to you and preventing future violations of your rights.
Increased enforcement activity also presents upsides for businesses. For the many companies out there trying to do the right thing, taking privacy seriously and trying to foster trust with their customers, enforcement levels the playing field. Regulators repeatedly stress that companies with a mature privacy program are able to show their work and demonstrate compliance efforts; organizations that take a collaborative and nonadversarial approach to an inquiry will benefit from greater latitude to mitigate alleged violations and, in some cases, less stringent settlement requirements. That process levels the playing field and penalizes companies that take short cuts or engage in privacy theater. Furthermore, enforcement actions validate the investments that companies make in robust privacy governance and in staffing to manage it; some regulators have identified this validation as an explicit goal. But doing so requires regulators to pursue an enforcement strategy that prioritizes meaningful violations of the law, offers clear guidance and rewards mature and well-run privacy programs as described above.
Enforcement activity also clarifies businesses' obligations under the law. Companies will undoubtedly disagree with regulators' interpretations of the law from time to time. Nevertheless, each new public enforcement action provides valuable insight into the law both for the entity subject to the action and the broader business community. An enforcement action can provide new insights into previously untested or undefined aspects of the law. Enforcement will be most effective, however, when it is founded on and produces clear guidance.
Enforcement can also be a route towards consistency across jurisdictions. There are meaningful distinctions between the various state privacy laws, and it remains a risk that regulators in different states could interpret the same language differently. But the reverse can be true as well. Efforts like the bipartisan Consortium of Privacy Regulators can foster uniformity in key definitions, rights or obligations that are similar across those state laws.
Looking ahead
As state and federal privacy enforcement grows, the businesses subject to these laws should keep one message front of mind: Be prepared. All indications suggest that this increase in enforcement activity is only the tip of the iceberg. Enforcement avenues have multiplied. The U.S. now has more than 20 state comprehensive privacy laws in effect, not to mention the many sectoral privacy laws and general consumer protection statutes under which privacy claims can be brought.
While those new laws take effect and state attorneys general build their enforcement capacity, privacy violations remain a constant fixture of the news cycle. We see time and time again how media scrutiny on a particular industry, technology or business practice translates into an investigatory sweep and, later, enforcement actions. One takeaway from these actions is that where there is smoke, there is fire. Failure to do the little things right, like having an up-to-date privacy notice, failing to disclose data sales or lacking opt-out mechanisms, invites scrutiny. These kinds of violations are low-hanging fruit to regulators.
And it is not just enforcement activity that is rising — fines are as well. Last year saw a new record civil penalty in a CCPA enforcement action. That record has already been broken twice this year in settlements for USD2.75 million and USD12.75 million, respectively. Regulators are clear that they want penalties for privacy violations to be a meaningful deterrent, not merely "a cost of doing business."
But, as discussed above, regulators repeatedly show that they are willing to engage with companies that are genuinely doing their best to comply with the law. Not every consumer complaint leads to an inquiry. Not every inquiry leads to an investigation. Not every investigation leads to a settlement. And not every settlement is equal in its severity — the size of a civil penalty and the obligations and duration of injunctive terms are shaped by the business's compliance efforts, both before and after they receive notice from a regulator. At the end of the day, regulators want their actions to shape behavior and meaningful privacy protections for consumers.
As enforcement activity increases in the coming months and years, it is important to bear in mind that all of this feeds back into legislative activity. State lawmakers are in constant dialogue with their respective attorneys general, and lawmakers have shown a willingness to amend their laws based on that feedback from regulators. Lawmakers are interested in the challenges that regulators face in enforcing the law, the gaps in protection for consumers and the obligations that are ambiguous or difficult to operationalize for businesses. For companies, this makes staying abreast of enforcement trends all the more critical. The next phase of U.S. privacy law will be written not only in state legislatures but through the cases regulators choose to bring and the lessons lawmakers draw from them.
This op-ed is based on remarks delivered at the Future of Privacy Forum's annual DC Privacy Forum 10 June.

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.
Submit for CPEsContributors:
Jordan Francis
CIPP/E, CIPP/US, CIPM, FIP
Senior Policy Counsel
Future of Privacy Forum



