What shifting privacy laws actually mean for business owners in 2026
Google has a behavioral profile on you. It knows what you searched at 2 a.m., where your phone spent the night, which videos you finished, and roughly what is sitting in your inbox.
Meta has a social graph on you. Even if you have never once signed up for Facebook, it likely built a shadow profile out of the contacts of everyone who did. Data brokers and analytics firms buy, blend, and resell dossiers on ordinary people that would make a 1970s intelligence agency jealous.
The government, for its part, buys commercial data to fill in the gaps it cannot legally collect on its own.
Your phone is a sensor package that reports home all day: location, app usage, advertising identifiers. And your most sensitive identifiers are already loose in the wild. The Equifax breach exposed the names, birth dates, and Social Security numbers of roughly 147 million people back in 2017. The National Public Data breach in 2024 spilled billions of records, Social Security numbers included.
Now everyone has started pasting contracts, health questions, and half-finished business plans into AI (artificial intelligence) tools that ingest every word.
So is the cat out of the bag? Are we all just playing pretend?
Yes and no. Your personal privacy is pretty much a lost cause, but your company has real and growing privacy obligations to your customers.
“Privacy is Dead” is Not a Legal Defense
It helps here to separate two ideas that get lumped together. Cybersecurity is about keeping attackers out and limiting the damage when they get in: the firewalls, encryption, and incident response plans.
Privacy is a different and more legal concern. Are you even allowed to collect and use someone’s data the way you do, and did you tell them the truth about it? Privacy is more of a compliance obligation than a technical discipline. Cybersecurity breaches are just one potential cause of privacy lawsuits.
“Everyone’s data is already leaked anyway” has a zero percent success rate as a defense in a breach lawsuit or a regulatory action. Your customers’ privacy nihilism does not transfer to you. The legal duty to protect your customers (and even free website visitors) belongs to your company specifically, and it is growing.
Reported United States privacy fines and penalties reached roughly $1.4 billion in 2025. A large share of that came from a single settlement: Texas collected more than $1 billion from a major technology company under the Texas Data Privacy and Security Act (TDPSA), the largest data privacy recovery any single state has ever won.
If you are reading that and thinking “fine, but I am not Google,” don’t relax yet. California’s privacy regulator reached a $1.55 million settlement with a health information publisher over a broken cookie banner and ignored opt-out requests. Connecticut settled with a ticket seller for $85,000 over an unreadable privacy notice and opt-out mechanisms that did not work. In February 2026, California’s Privacy Protection Agency broke its own record with a $2.75 million settlement against a streaming company for failing to honor opt-outs.
None of these cases involved a cybersecurity breach. They came down to sloppy basics: a cookie banner that misled visitors and opt-out buttons that did nothing.
Even if none of us should expect much personal privacy anymore, that does not mean the law as it exists will sit idly forever. In fact, privacy legislation and case law is moving faster than ever.
The Supreme Court Just Said Privacy Still Exists
On June 29, 2026, the Supreme Court decided Chatrie v. United States, and it changed the legal outlook on privacy.
Here are the facts of the case: Police investigating a 2019 bank robbery could not find a suspect, so they got a geofence warrant: a court order compelling Google to hand over data on every phone that passed through a virtual perimeter around the crime scene.
The question for the Court was whether pulling that location history counts as a search under the Fourth Amendment, which protects you from unreasonable government searches.
In a 6-3 decision, the Court said yes. In the majority’s words, “An individual has a reasonable expectation of privacy in records about his cell phone’s location.”
That reasonable expectation exists even though the data was sitting on Google’s servers, provided by you (thanks to a likely-unread End User License Agreement).
That holding matters because of an old rule called the third-party doctrine, a 1970s idea that you surrender your privacy in anything you voluntarily share with a company. For decades, that doctrine was the government’s trump card. Chatrie continues to chip away at it, building directly on Carpenter v. United States from 2018, where the Court extended similar protection to cell-tower location records. The trajectory is unmistakable: the more revealing the data, the more protection courts are willing to extend to it.
Two caveats:
- The Court did not outlaw geofence warrants; it sent the case back to the lower court to sort out whether this particular warrant passed muster.
- The ruling is about the government searching you, not about a private company’s marketing stack.
For many years, privacy was eroded by new technology that behaved on a “collect first, ask questions later” process. Now, the legal system is expanding privacy expectations, not shrinking them. Plan accordingly, because the next set of lawsuits is aimed squarely at businesses.
The Wiretapping Lawsuits Are Aimed at Your Website
Most business owners have no idea that the hottest privacy litigation in the country right now targets ordinary company websites. Not data breaches. Websites.
Plaintiffs’ firms are filing waves of lawsuits arguing that website analytics pixels, session replay tools, and chatbots “wiretap” your visitors. The theories run under two laws: the California Invasion of Privacy Act (CIPA), a wiretapping statute from 1967, and the federal Electronic Communications Privacy Act (ECPA). CIPA carries statutory damages of $5,000 per violation, and when a plaintiff multiplies that across every visitor to a site, the numbers get frightening fast. The volume of these decisions is climbing sharply, and the theories are spreading to courts well outside California.
The encouraging news is that the case law is forming a picture about what is required.
A consent mechanism that requires an affirmative action from the visitor, checking a box or clicking a button, paired with a privacy policy that specifically names the tracking tools you actually use, is usually enough to defend against these lawsuits.
Vague boilerplate, the “we collect information about how you interact with the Site” language that came free with your website template, is not.
There is a related trap worth knowing about. The Video Privacy Protection Act (VPPA), a 1988 law originally passed because a newspaper published a Supreme Court nominee’s video-rental records, is being aimed at any business that puts video on its website and runs a Meta pixel. It carries $2,500 in damages per violation and a private right to sue. The Supreme Court granted review of a VPPA case, Salazar v. Paramount Global, on January 26, 2026, to settle exactly how far the law reaches, with a decision expected in early 2027.
Put this plainly. If your marketing team installed a Facebook pixel a few years ago and your privacy policy is boilerplate from 2019, you may already be a defendant waiting to be served.
Europe Led, America (Sort of) Followed
Modern privacy legislation in the United States is downstream of Europe’s landmark privacy law, the General Data Protection Regulation, or GDPR.
GDPR set the template in 2018: real consumer rights to access, delete, correct, and port your data, opt-in consent before tracking, and punishing fines of up to 4 percent of a company’s global revenue. It was one law for one market.
America, meanwhile, has developed a tapestry of state laws with broad similarities to the GDPR and lots of little differences to each other. California led the pack with its Consumer Privacy Act (CCPA) in 2020. As of 2026, twenty states have enacted comprehensive privacy laws. Indiana, Kentucky, and Rhode Island took effect on January 1, 2026. Oklahoma signed on as the twentieth in March 2026, effective in 2027. Together these laws now cover more than half the population of the United States.
There is a philosophical split between the nations’ laws. GDPR is opt-in: get consent before you track. Most American state laws are opt-out: track by default, honor requests to stop. That gap is closing, though. Maryland’s new data minimization requirement, which limits collection to what you actually need, is a distinctly GDPR-style move.
Eventually, the U.S. may get a national law that supersedes all these state laws. In the meantime, plan to comply with the patchwork of similar-but-different laws that apply to your business.
Only Some of These Laws Actually Apply to You
Before you spend any time building a privacy compliance program, you need to make sure you understand which privacy laws actually apply to your business.
- Volume of data. Most state laws switch on at 100,000 residents’ worth of personal data, but the thresholds vary wildly. Rhode Island’s kicks in at 35,000. Texas set effectively no minimum, so a small company selling to Texans can be fully on the hook.
- Revenue from data. Thresholds drop, often to around 25,000 consumers, if you derive a meaningful share of revenue from selling data. Important wrinkle: “selling” in these laws frequently includes sharing data with advertising platforms.
- Your sector. Health data brings in HIPAA (the Health Insurance Portability and Accountability Act), financial data brings in GLBA (the Gramm-Leach-Bliley Act), and education records bring in FERPA (the Family Educational Rights and Privacy Act). These may exempt you from a state’s comprehensive law, or they may stack on top of it.
- Where your customers live, not where your office is. A Massachusetts company with Texas customers is subject to Texas law. Geography follows the customer.
There are also breach notification laws, which exist in all fifty states, comprehensive privacy law or not. (Plan on notifying all of your affected customers of a breach regardless of where they live.)
Plus, eleven states now require your website to technically recognize and honor the Global Privacy Control (GPC), a browser signal that tells you a visitor is opting out.
Privacy compliance is not just something for the biggest players anymore!
Picture a forty-person e-commerce company, T-Shirt Co. It sells t-shirts to customers in all fifty states, holds data on about 200,000 of them, and runs Meta and Google ads. That single profile pulls T-Shirt Co. under most of the twenty state laws, into GPC obligations, and into the pixel-litigation crosshairs. That’s a lot of laws to comply with for a 40-person company!
So What You Can Do About It?
Some good news. Privacy compliance is not just for Fortune 500 companies, so it doesn’t require a Fortune 500 program budget. Here are actionable steps you can take to control your privacy program.
- Know what you have. Build a basic data inventory: what personal data you collect, where it lives, who you share it with, and why. You cannot protect or lawfully process what you cannot find.
- Minimize. The cheapest compliance strategy in existence is holding less data. Delete what you do not need and stop collecting what you do not use. Data you do not have cannot be breached, subpoenaed, or litigated.
- Fix your consent mechanics. A cookie banner that requires an affirmative click, a privacy policy that names your actual tracking tools by name (pixels, session replay, chat widgets), and honored opt-outs including GPC. This is the precise fact pattern deciding the wiretapping cases right now.
- Audit your marketing stack. Every pixel, tag, and analytics tool is a potential data “sale” under state law and a potential wiretapping claim. Marketing installed them; legal never reviewed them. Reconcile those two facts before a plaintiff’s firm does it for you.
- Paper your vendors. State laws require data processing agreements with the service providers who touch customer data. Review those contracts with everyone in that category, and yes, that includes your AI tools.
- Treat AI as a data flow, not a magic box. Set a policy on what employee and customer data can go into which AI tools. Prefer enterprise agreements with no-training commitments over free consumer tiers, where your inputs may become someone else’s training data.
- Prepare for the breach before it happens. Have an incident response plan, map your breach notification obligations state by state, review your cyber insurance for privacy-litigation coverage specifically, and run a tabletop exercise so leadership is not improvising at 2 a.m.
- Assign ownership. Someone has to own privacy as an ongoing operational function, not a one-time project. Nine states amended their privacy laws in 2025 alone. Whoever owns this needs a standing review cadence, not a checkbox.
Privacy isn’t dead?
Yes, your personal data is already everywhere, and no amount of caution fully claws it back. It’s easy to be fatalistic about privacy, but it’s a trap!
Your business does not get to inherit that fatalism, because your legal privacy obligations are moving in the opposite direction. They are expanding and increasingly enforced, and plaintiffs’ firms have figured out that stale privacy policies = paydays.
Privacy isn’t dead. Now, it’s undead!
Want to get great cybersecurity content delivered to your inbox? Click here to sign up for our monthly newsletter, Tales from the Click!