State Attorneys General Tighten Privacy Rules
Coverage from Kelley Drye & Warren LLP, Future of Privacy Forum, and others
Articles
31
Active Days
165
The Topic

U.S. state regulators and lawmakers are tightening privacy rules around consumer rights, sensitive data, children’s services, data brokers, consent interfaces, and breach notifications. Connecticut’s 2025 enforcement report provides the clearest current view of this shift, while New Jersey’s data broker registration law and related actions in other states show broader movement toward more detailed oversight and stronger penalties. The practical effect is greater pressure on businesses to align privacy disclosures, rights-request processes, tracking technologies, vendor relationships, and incident response with actual data practices.
First Article: 01/01/00
Latest Article: 07/13/26
Summary
- Connecticut’s attorney general is focusing on incomplete privacy notices, delayed data-rights responses, deceptive cookie banners, and failures to honor universal opt-out signals.
- Connecticut reported 1,830 breach notifications and issued 63 warning letters over alleged delays, including cases involving lengthy gaps between suspicious activity and notice.
- Children’s privacy investigations increasingly cover messaging apps, gaming platforms, tracking SDKs, precise geolocation, and AI chatbots.
- New Jersey enacted annual registration requirements for data brokers and certain direct-to-consumer data collectors, with disclosures covering opt-outs, purchasers, breaches, minors’ data, and processors.
- New Jersey separately prohibits the sale or licensing of sensitive data and provides substantial civil penalties for registration failures and sensitive-data violations.
- State activity remains fragmented, with different approaches emerging across Connecticut, New Jersey, Minnesota, Florida, South Carolina, and Massachusetts.
History
The story now broadens beyond Connecticut and New Jersey to show a wider multi-state privacy enforcement push, with the emphasis shifting toward fragmented but converging rules across several states. Connecticut’s enforcement focus is also more specific on deceptive cookie banners and universal opt-out failures, while New Jersey’s framework is framed more clearly as an operational registration-and-penalty regime.
The update is more concrete: Connecticut’s story now centers on documented enforcement activity, while New Jersey’s framework has moved from prospective legislation to enacted registration and sensitive-data restrictions. The framing also broadens from general privacy-law adoption to more active oversight of ads, opt-out mechanics, minors, and data-broker conduct.
