Commercial Data Monetization
The ongoing major issues seen in articles and topics over time.
The Drivers
54
Articles Related
1,154
The Big Picture

This theme covers the collection, profiling, tracking, sharing, and monetization of consumer behavior across platforms, retailers, streaming services, chatbots, loyalty systems, advertising networks, and data brokers. It includes dark patterns, hidden tracking, targeted pricing, third-party ad-tech sharing, and the commercial reuse of consumer data, but excludes ordinary breaches, credential theft, phishing, supply-chain compromise, passport exposures, and child-safety age-check issues unless tracking, profiling, monetization, targeted advertising, data brokerage, pricing, or secondary reuse is the main privacy mechanism.
Commercial privacy risk increasingly arises not from one visible transaction but from linked behavioral profiles used for advertising, personalization, pricing, fraud scoring, and product design. This issue will keep generating regulatory and litigation activity as companies seek monetization while consumers and regulators challenge consent, transparency, and fairness.
Categories
Corporate Data Practices & Accountability, Consumer Privacy & Digital Rights, Data Collection & Surveillance Practices, Regulation, Law & Enforcement
Keywords
ad tech, behavioral tracking, chatbot tracking, consumer profiling, customer dossier, dark patterns, data broker deletion mechanism, data broker registry, data brokers, data monetization, inferred sensitive attributes, loyalty data, personalized pricing, sensitive data transfer restrictions, sensitive trait profiling, sexual orientation data, streaming data, surveillance pricing, talent database, third-party sharing, tracking pixels, universal deletion request, VIP database
The Drivers
The Topics below, and their articles, all focus on, exemplify, or help to explain this theme.
Primary
- 97
State Data Broker Regulation Tightens

State privacy law is tightening around data brokers, with Texas and California expanding definitions, raising registration and transparency demands, and adding security and consumer-rights obligations. The current signal points to broader compliance scope, stronger disclosure rules, and more active state enforcement.
Articles: 9
Last Updated: 07/23/2026
- 97
FTC Tightens Location Data Sales

The FTC has moved to block Kochava and its subsidiary from selling or sharing precise location data without affirmative express consent. The action centers on data that can reveal visits to sensitive places such as health clinics, houses of worship, and shelters, and it reflects a broader push to impose stricter limits on location data brokers. The settlement also adds operational controls for consent verification, deletion, retention, and reporting, while California's Delete Act adds parallel pressure on the industry.
Articles: 4
Last Updated: 09/15/2026
- 96
The Fight Over Browser Fingerprints

Browser fingerprinting combines browser, device, network, and software signals to identify or distinguish users without relying on cookies. The technique remains useful for fraud prevention, advertising measurement, and bot detection, but it also enables difficult-to-clear tracking and has been adopted by phishing operators to evade automated review. Google’s advertising-policy shift and Mozilla’s expanding Firefox protections highlight an unresolved tension between commercial measurement, security functionality, privacy regulation, and web compatibility.
Articles: 14
Last Updated: 06/17/2026
- 96
California Puts Data Brokers On Notice

California is moving from company-by-company privacy requests to state-managed deletion of residents’ information held by registered data brokers. Through the Delete Request and Opt-out Platform, or DROP, one verified request can reach hundreds of brokers, which must process deletions, monitor for newly acquired data, and report compliance under California Privacy Protection Agency oversight. The development increases operational and enforcement obligations for brokers while highlighting California’s broader role in shaping privacy rules amid limited federal regulation and unsettled litigation over website tracking.
Articles: 72
Last Updated: 09/20/2026
- 96
Texas Targets Platforms Over Data Harvesting

Texas Attorney General Ken Paxton is pursuing privacy and deceptive-practices cases against Netflix and Temu, alleging that the companies harvest consumer data through tracking, app functionality, and misleading user practices. The Netflix case emphasizes viewing behavior, children's profiles, device information, location data, and alleged sharing with advertising and data-broker networks; the Temu case focuses on access to device data and alleged deceptive marketing. The cases illustrate Texas's broader use of state consumer-protection law to challenge data-collection practices, though the allegations remain contested and the litigation has not been resolved.
Articles: 4
Last Updated: 05/11/2026
- 96
Tiktok Privacy Policy And Tracking Changes

TikTok is revising its U.S. privacy framework while expanding or clarifying what it can collect, especially location signals, metadata, and AI interaction data. At the same time, reporting highlights cross-site tracking through advertising pixels and renewed scrutiny of how user data moves across the platform and ad ecosystem.
Articles: 4
Last Updated: 03/02/2026
- 95
Surveillance Pricing Faces State Limits

U.S. lawmakers and regulators are examining pricing systems that combine browsing, purchase, location, loyalty, device, and demographic data to estimate what individual customers may be willing to pay. The practice is drawing concerns about opaque pricing, discrimination, consent, and possible algorithmic coordination, while retailers and business groups argue that algorithmic pricing can improve efficiency or reduce prices. Maryland, Connecticut, and New Jersey have enacted differing restrictions, and federal lawmakers are considering broader safeguards, but the scope of covered practices and acceptable discounts remains unsettled.
Articles: 38
Last Updated: 09/07/2026
- 95
Meta-Whatsapp Data Sharing Scrutiny

Indian courts and regulators are pressing Meta and WhatsApp over how user data is shared for advertising, with penalties, compliance deadlines, and consent rules now shaping the dispute. The stable pattern is regulatory scrutiny of platform data practices rather than a general privacy debate.
Articles: 54
Last Updated: 03/01/2026
- 95
Malicious Extensions Hijack Browser Sessions

Malicious browser extensions are being used as a durable access layer for credential theft, session hijacking, ad fraud, remote code execution, and abuse of authenticated web services. Campaigns affecting Chrome and Edge have used legitimate-looking functionality, delayed or concealed payloads, shared infrastructure, and multiple publisher identities to reach large user populations. The pattern shows that browser add-ons can convert ordinary browsing access into persistent control over identity data, messaging sessions, enterprise credentials, and connected applications.
Articles: 7
Last Updated: 07/18/2026
- 95
Privacy-First Marketing And Shopping

Privacy practices are shifting toward first-party data, clearer consent, and lower-data consumer transactions. Marketers are adapting to cookie loss and privacy laws, while consumers are increasingly using masking tools, tokenized payments, and data-rights tools to reduce exposure.
Articles: 13
Last Updated: 07/02/2026
- 95
Cross-Site Tracking Pixel Scrutiny

Blacklight has expanded its tracking-pixel detection to include TikTok and X, adding visibility into how major platforms collect browsing, purchase, and search data across websites for profiling and advertising. The current signal is technically specific and coherent, with recurring attention on cross-site tracking, public scrutiny, and prior findings about data flows from government and other sites.
Articles: 4
Last Updated: 02/12/2026
- 95
Trackers Expose Health And Identity Data

Organizations are facing growing privacy and cybersecurity exposure from website trackers, third-party data sharing, weak access controls, and failures in privacy-focused products. Healthcare pixel tracking has produced substantial litigation exposure, while exposed identity documents and persistent email-address leakage show how difficult it can be to contain sensitive data once systems or vendors mishandle it. The material also points to a parallel shift in defensive pressure, including stronger scrutiny of tracking practices and malware designed to evade automated analysis.
Articles: 13
Last Updated: 07/03/2026
- 94
Third-Party Platforms Expose Customer Data

Organizations in the United States and Puerto Rico are reporting breaches involving cloud CRM systems, customer-support tools, and third-party financial service providers. Exposed information ranges from names and contact details to Social Security numbers, driver’s license data, health information, and debit card numbers. The pattern highlights how compromise of connected platforms or vendors can affect large customer populations even when an organization’s own core systems are not directly accessed.
Articles: 9
Last Updated: 07/23/2026
- 94
California Tightens Privacy Opt-Out Rules

California privacy regulators and courts are increasing scrutiny of how businesses collect, share, and track consumer data, particularly when opt-out mechanisms are difficult to use or require unnecessary information. The California Privacy Protection Agency’s $1.1 million PlayOn Sports settlement highlights heightened concern over student and family data on school-event platforms, while related enforcement against Ford and emerging adtech litigation extend the focus across industries. New CCPA/CPRA audit and risk-assessment requirements are also moving privacy controls toward formal executive and board oversight.
Articles: 45
Last Updated: 08/17/2026
- 94
Consumer Tracking And Privacy Controls

Apps, websites, smart devices, vehicles, and loyalty programs collect behavioral, location, identity, and interaction data across everyday activities. Privacy laws provide disclosure, access, deletion, and opt-out rights, but consent friction and fragmented controls limit practical user choice. Data brokers extend the life and reach of collected information, while AI-related data use adds a newer layer of uncertainty. Security guidance links exposed data to scams and account compromise.
Articles: 15
Last Updated: 07/29/2026
- 94
EU And India Whatsapp Privacy Enforcement

Recent privacy enforcement is concentrated on how WhatsApp and Meta can be challenged, sanctioned, and required to change data-sharing practices. In the EU, courts clarified that companies can directly contest binding EDPB decisions, while in India regulators and courts are tightening disclosure and consent rules for non-WhatsApp data uses, including advertising. The shared pattern is stronger procedural and substantive scrutiny of platform data processing, with cross-border enforcement and appeals still active.
Articles: 4
Last Updated: 03/13/2026
- 93
Colorado AI Pricing Rules

Colorado is advancing a set of laws aimed at limiting how companies use consumer and worker data in AI-driven pricing and wage decisions. The clearest thread is a ban on surveillance-based individualized pricing and pay, paired with broader AI rules that focus on notices, data access, correction rights, and state enforcement. The topic matters because it shows Colorado tightening oversight of data-driven discrimination while also testing the line between consumer protection and ordinary business software.
Articles: 12
Last Updated: 07/24/2026
- 93
Home Cameras Expand Surveillance Reach

Cloud-connected doorbells and home security cameras are becoming everyday tools for monitoring homes, while their footage can also enter provider systems, law-enforcement workflows and AI-based analysis. Reporting highlights uncertainty around retention, access and data sharing, alongside growing public concern over Ring partnerships, facial recognition and the use of surveillance imagery as social-media content. The central issue is how consumers can balance security benefits with control over recordings that may capture household activity and nearby public spaces.
Articles: 14
Last Updated: 07/18/2026
- 93
Connected Vehicle Data Sales Enforcement

Recent coverage is dominated by California enforcement against General Motors over OnStar data practices, especially the collection, retention, and sale of driving and precise location data to brokers without affirmative consent. The case has pushed data minimization, deletion, and broker-sale limits into the foreground of connected-vehicle privacy.
Articles: 7
Last Updated: 05/12/2026
- 93
Comcast Breach Settlement Moves Toward Payouts

The topic centers on the legal and consumer aftermath of the October 2023 Comcast Xfinity breach, including a reported $117.5 million class-action settlement, eligibility requirements, reimbursement limits, and identity-protection services. It also includes separate settlements involving Constar Financial Services and WaterStreet Company, showing a broader pattern of breach victims being offered capped payments, loss reimbursement, and monitoring services. The Comcast settlement has been described as proposed or pending in some reports and approved in a later report, while claim deadlines and payment amounts vary across accounts.
Articles: 75
Last Updated: 08/28/2026
- 92
Chick-Fil-A Warns Of Account Exposure
Chick-fil-A says attackers used credentials obtained from a third-party source to target Chick-fil-A One accounts through automated login attempts against its website and mobile app between June 17 and June 19, 2026. The company determined that some accounts may have been accessed, potentially exposing contact details, loyalty and payment-related information, and account balances. Chick-fil-A forced logouts, removed stored payment methods, restored affected balances, and reset passwords while advising customers to update credentials and monitor their accounts.
Articles: 68
Last Updated: 08/04/2026
- 92
AI Privacy Lawsuits And Probes

This topic centers on legal challenges accusing AI products and related platforms of collecting, sharing, or accessing user data without proper consent. The strongest threads involve privacy class actions against Perplexity, Otter.ai, and Google, alongside disputes over AI agents and platform authorization. It matters because these cases are testing how existing privacy, wiretapping, and unauthorized-access laws apply to AI interfaces that handle sensitive conversations and browsing activity.
Articles: 20
Last Updated: 07/06/2026
- 91
California Businesses Detail CCPA Rights

ASP-RCM Solutions, Northgate, and Rōti Modern Mediterranean publish California-specific notices describing the personal information they collect, how it is used and shared, and how residents can exercise CCPA/CPRA rights. All three describe identity verification and response timelines for consumer requests, while their disclosures differ on tracking and advertising: ASP-RCM and Northgate deny sale or cross-context behavioral advertising, whereas Rōti notes that cookies and tracking may qualify as sale or sharing under California law. The notices provide a practical view of how organizations are operationalizing California privacy transparency requirements across websites, customer services, and loyalty programs.
Articles: 3
Last Updated: 06/13/2026
- 91
Online Age Checks Raise Privacy Risks

Governments and platforms are advancing age checks and youth-safety restrictions for social media and online services, using methods that include government IDs, facial analysis, behavioral inference, and third-party verification. The measures are intended to limit minors' access to harmful or age-inappropriate experiences, but they also create risks involving sensitive-data breaches, surveillance, misclassification, exclusion, and circumvention. Privacy-preserving approaches such as tokenized age confirmation and zero-knowledge proofs are being tested, while policymakers and platforms continue to weigh them against enforcement and usability demands.
Articles: 25
Last Updated: 08/04/2026
- 90
EU Finds Tiktok Failed To Protect Minors

European regulators are intensifying scrutiny of TikTok over whether its account visibility settings adequately protect minors and whether EU user data can be accessed from China. The European Commission has identified potential Digital Services Act non-compliance over adult access to minors’ accounts, while Ireland’s Data Protection Commission previously fined TikTok €530 million over cross-border data access, a decision TikTok is challenging. The developments could lead to stronger safeguards, operational changes, and significant financial or legal consequences for the platform.
Articles: 12
Last Updated: 07/25/2026
- 88
Venice AI Bets On Private Chatbots

Venice AI is positioning its chatbot and developer API as a privacy-first alternative to mainstream AI services that collect user conversations for model improvement. The company says prompts and responses are encrypted and decrypted on users’ devices, routed through external infrastructure, and not retained on Venice’s own systems. Its $65 million funding round, reported $1 billion valuation, growing user base, and confidential-computing partnerships indicate that privacy is becoming a commercial differentiator, while regulatory obligations and the ability to verify its architecture remain open questions.
Articles: 14
Last Updated: 07/21/2026
- 88
AI Agent Breach And Toy Privacy

The topic centers on security, privacy, and safety failures linked to rapidly deployed AI systems. Hugging Face reported that an autonomous AI agent framework exploited code-execution paths in its data-processing pipeline, while separate reporting documented exposed children’s conversations and broader safety concerns involving AI-enabled toys. The developments highlight the need for stronger access controls, data minimization, product testing, incident response, and oversight of AI systems used in sensitive environments.
Articles: 9
Last Updated: 07/20/2026
- 88
Meta Removes Muse Image After Backlash

Meta launched Muse Image in July 2026 with a feature that allowed users to reference public Instagram accounts when generating or editing AI images. Reports said adult public-account users were included by default, were not directly notified when their photos were reused, and had to locate an opt-out setting; the feature was removed within days after criticism from privacy advocates and performer groups. The episode highlights continuing tension between Meta’s rapid AI product rollout and expectations for clear consent, notice, and control over publicly shared images and likenesses.
Articles: 25
Last Updated: 07/25/2026
- 88
Cloud Integrations And Identity Breaches

The topic centers on cyberattacks that abuse trusted cloud connections, exposed credentials, and convincing impersonation to reach enterprise or personal data. A Klue integration compromise enabled unauthorized access to connected Salesforce environments and led to extortion claims, while separate incidents involving Accenture and The Credit Pros raised concerns about source code, credentials, and sensitive personal information. Phishing campaigns targeting LastPass and Bitwarden users show the same broader reliance on identity and trust-based attack paths, although the incidents are not attributable to a single campaign.
Articles: 49
Last Updated: 07/22/2026
- 86
Regulators Probe Grok Deepfake Harms

xAI and X are facing lawsuits, regulatory investigations, and public pressure over allegations that Grok generated or distributed non-consensual sexualized images of identifiable people, including claims involving minors. Authorities in the UK, EU, France, and other jurisdictions are examining privacy, data protection, platform-risk, and online-safety obligations, while xAI has described account enforcement and pursued at least one user in court. The central unresolved issue is how responsibility should be divided among users, platform operators, and AI developers when safeguards fail to prevent foreseeable misuse.
Articles: 23
Last Updated: 07/28/2026
- 86
Email Tracking Privacy Compliance

Privacy rules are tightening around email tracking, consent, and disclosure. GDPR, US state privacy laws, and FTC enforcement are pushing organizations toward opt-in controls, clearer notices, stronger authentication, and reduced data collection.
Articles: 4
Last Updated: 05/18/2026
- 86
Package Registries Target Developer Secrets

Attackers are repeatedly compromising or impersonating packages on npm and PyPI to steal developer credentials, cloud secrets, CI/CD tokens, and cryptocurrency wallet data. Several campaigns use trusted publishing accounts, malicious installation hooks, typosquatted dependencies, or self-propagation to reach additional packages and repositories. The activity affects enterprise tooling, AI software, payment integrations, and widely downloaded development ecosystems, while attribution remains mixed between TeamPCP-linked malware, other threat actors using leaked code, and a Microsoft-attributed North Korean operation.
Articles: 17
Last Updated: 07/15/2026
- 84
Fidelity Settles 2024 Data Breach Claims

Fidelity Investments is resolving legal and regulatory claims tied to unauthorized access to systems in August 2024, with reported exposure of financial account data and other sensitive personal information. A $2.5 million class-action settlement provides compensation and monitoring benefits, while a separate Massachusetts agreement requires a $1.25 million payment and improvements to notification and cybersecurity practices. The matter highlights the financial and operational consequences of breach response, particularly when affected individuals extend beyond the company’s directly identified customers.
Articles: 65
Last Updated: 08/05/2026
- 83
VPN Privacy Limits And Tradeoffs

VPNs and browser-level privacy tools can reduce internet-service-provider visibility and IP-based location exposure, but they do not stop phishing, cookies, browser fingerprinting, malware, or device telemetry. Online banking systems may treat VPN-related location changes as anomalous and trigger additional checks or account locks. Separate reporting on children's trackers shows that location, messages, and device identifiers remain exposed when connected products use uneven authentication and encryption practices.
Articles: 11
Last Updated: 07/31/2026
- 83
Cross-Border Privacy Enforcement And Device Security

Privacy rules are increasingly being enforced through product design, device security, and cross-border litigation. The strongest signals are around embedded tracking tools, session replay and pixels, and new security obligations for connected products in the EU and UK.
Articles: 3
Last Updated: 03/16/2026
- 82
BIPA Damages Limited Retroactively

Recent Seventh Circuit rulings say Illinois BIPA's 2024 damages limit applies to pending cases, narrowing scan-based recovery and reducing class-action leverage in biometric privacy litigation.
Articles: 4
Last Updated: 07/13/2026
- 82
Blockchain Privacy And Compliance Controls

Blockchain privacy discussions are converging on a practical tradeoff: financial institutions want auditability and settlement transparency, while users and firms need selective disclosure, confidential transactions, and compliance-ready controls. The recurring pattern is layered privacy rather than full secrecy.
Articles: 4
Last Updated: 05/29/2026
- 82
Apple Siri AI Privacy Tradeoffs

Apple is turning Siri from a command-based assistant into a context-aware system that can search personal content, analyze screens, and act across applications. The design combines on-device processing with Private Cloud Compute and reported Google Gemini support, while fragmented controls, uncertain data-routing details, regulatory delays, and prompt-injection risks complicate Apple’s privacy assurances.
Articles: 21
Last Updated: 09/18/2026
- 79
Courts Tighten Data Breach Standing

U.S. federal courts are applying increasingly specific requirements for plaintiffs bringing data breach class actions, particularly on whether alleged fraud, mitigation costs, or future identity-theft risk can be traced to a defendant’s breach. Recent decisions have dismissed claims with speculative misuse allegations or weak temporal and factual links, while leaving in place a Fourth Circuit ruling recognizing standing where driver’s license numbers were posted on the dark web. The decisions make evidence of actual misuse, exposed-data matching, and forensic dark-web activity increasingly important to breach litigation.
Articles: 17
Last Updated: 07/28/2026
- 78
Youth Privacy Drives Chatbot Rules

U.S. lawmakers and regulators are developing a patchwork of rules for AI chatbots, especially services used by children and teenagers. Proposals include limits on profiling, training and advertising with minors’ data, age-assurance measures, disclosures, restrictions on harmful or sexualized interactions, and default limits on AI companions. The main unresolved tension is that age verification and safety requirements may improve protections while prompting services to collect more identifying information, with some state measures also facing constitutional challenges.
Articles: 17
Last Updated: 09/16/2026
- 77
AI Voice Training Faces Illinois BIPA Suits

Illinois journalists, podcasters, voice actors and other residents have filed class-action lawsuits alleging that major technology companies used recorded voices to develop AI systems without the notice and written consent required by the Illinois Biometric Information Privacy Act. The cases may test whether voiceprints extracted from recordings qualify as protected biometric identifiers and whether AI training constitutes regulated collection or use. Related Illinois disputes over facial recognition, automated transcription and proposed AI legislation show broader pressure on companies to disclose and limit biometric and personal-data practices.
Articles: 26
Last Updated: 08/05/2026
- 77
Oura Ring 5 Expands Health Monitoring

Oura is expanding its smart ring and app into a broader health platform with Ring 5, Health Radar, medical-record storage, hormone and GLP-1 insights, and optional AI and telehealth services. The company is positioning passive, continuous monitoring as a complement to conventional wearables while adding features that may help users identify patterns in cardiovascular, respiratory, sleep, and recovery data. As Oura handles increasingly sensitive health information, its privacy commitments, data-sharing controls, and time-based deletion tools become more consequential.
Articles: 7
Last Updated: 07/01/2026
- 74
Eurail Traveler Data Breach Fallout

Recent coverage is dominated by Eurail's disclosure of a December 2025 breach affecting roughly 308,777 travelers and exposing passport, contact, and other sensitive records. Reporting emphasizes dark-web resale, Telegram samples, regulator notifications, and advice to monitor for fraud and phishing.
Articles: 15
Last Updated: 07/01/2026
- 73
Healthcare Data Breaches Produce Multimillion-Dollar Settlements

U.S. healthcare providers and related service organizations are settling class actions arising from breaches that exposed personal, medical, Social Security, and financial information. The agreements generally combine cash or documented-loss reimbursements with credit, dark-web, or medical identity monitoring, while organizations deny liability or settle without admitting wrongdoing. The cases show how cyber incidents involving large patient populations are producing substantial litigation and remediation costs after the underlying breaches.
Articles: 12
Last Updated: 08/28/2026
- 73
Cyber Insurance Covers Breach Losses

This topic centers on cyber insurance claims and the kinds of losses most often driving payouts, especially data breaches, ransomware, and vendor-related incidents. The material shows insurance covering most average breach losses, while also highlighting that some events remain highly costly because of downtime, business interruption, and legal or settlement expenses. It also points to emerging pressure from AI-enabled social engineering and less traditional exposures such as pixel-tracking litigation.
Articles: 14
Last Updated: 07/30/2026
- 72
Treasury Reframes Crypto Privacy Tools

U.S. Treasury reporting has shifted toward recognizing crypto mixers as legitimate privacy tools for lawful users, while keeping strong emphasis on AML, sanctions enforcement, and new controls to slow illicit flows. The current pattern is a regulatory balancing act: preserve some financial privacy, but add hold, screening, and reporting mechanisms for suspicious activity.
Articles: 5
Last Updated: 03/15/2026
- 72
Meta Messaging Encryption Shift

Meta is pulling back from end-to-end encryption on Instagram direct messages while defending other privacy features, leaving messaging privacy shaped by adoption rates, safety enforcement demands, and regulatory pressure. The recurring pattern is a tradeoff between user confidentiality and platform visibility into harmful content.
Articles: 96
Last Updated: 07/02/2026
- 72
California Tightens Breach Notification Rules

The topic centers on California requirements for notifying residents after unauthorized access to covered personal information, including identifiers, financial credentials, health information, login data, and biometrics. The material also emphasizes related CCPA/CPRA litigation, Attorney General reporting for larger incidents, and overlapping healthcare obligations under HIPAA and California medical confidentiality law. A broader regulatory pattern is visible: organizations are expected to identify qualifying incidents quickly, preserve evidence, and notify affected people and authorities within jurisdiction-specific deadlines rather than waiting for investigations to fully conclude.
Articles: 11
Last Updated: 07/31/2026
- 71
Age Assurance Privacy Guidelines

Australian privacy regulators are setting rules for age assurance systems with a strong emphasis on data minimisation, transparency, proportionality, and vendor oversight as online age checks expand under new eSafety requirements.
Articles: 3
Last Updated: 05/04/2026
Secondary
- 88
States Tighten U.s. Privacy Rules

U.S. states are expanding the consumer privacy patchwork through new comprehensive laws and stricter amendments governing sensitive data, minors, geolocation, profiling, targeted advertising, and data sales. In the first half of 2026, Alabama, Louisiana, Oklahoma, and Vermont enacted laws, bringing the reported total to 24 state privacy regimes, while Connecticut, Arkansas, and Utah broadened existing protections. The changes increase obligations for businesses operating across states and create divergent requirements for consent, opt-out signals, assessments, disclosures, and enforcement.
Articles: 42
Last Updated: 08/18/2026
- 78
Global Privacy Control Enforcement

State privacy regulators are moving from written opt-out rights to technical enforcement of browser-based universal opt-out signals, with Global Privacy Control now a practical compliance requirement for many businesses. California leads the pattern, while several other states are aligning around the same standard.
Articles: 7
Last Updated: 07/13/2026
- 72
Connecticut Tightens Rules On Personal Data

Connecticut is expanding its privacy framework to regulate data brokers, restrict the sale and use of precise geolocation data, limit surveillance pricing, and give consumers greater control over genetic information and publicly available data used in profiles. Public Act No. 26-64 creates a data broker registry and a centralized deletion mechanism, while related amendments broaden sensitive-data, profiling, and transparency obligations. The phased implementation will create new operational requirements for companies that collect, sell, analyze, or use personal data in Connecticut.
Articles: 44
Last Updated: 09/16/2026
- 71
State Consumer Privacy Law Wave

Multiple U.S. states are enacting or advancing comprehensive consumer privacy laws with similar core rights: access, deletion, correction, portability, and opt-outs for targeted advertising and data sale. Oklahoma and Alabama are the main current examples, both using attorney general enforcement, cure periods, and broad exemptions that limit how disruptive the laws may be in practice. The cluster also shows ongoing debate over how strong these laws really are, especially around universal opt-out signals, private rights of action, and narrow sale definitions. A federal privacy bill has also been introduced, but the signal remains dominated by state-level lawmaking rather than national standard-setting.
Articles: 16
Last Updated: 06/16/2026
- 71
Vermont Enacts Broad Privacy Protections

Vermont enacted the Vermont Data Privacy and Online Surveillance Act together with measures addressing genetic data, data brokers, and education technology providers. The framework expands consumer rights, regulates sensitive health, biometric, neural, and genetic information, restricts certain sales and geofencing practices, and requires disclosures about personal-data use for large language model training. Most provisions of the comprehensive privacy act take effect in January 2028, while the genetic privacy measure takes effect earlier.
Articles: 28
Last Updated: 08/03/2026
