2026 Mid-Year State Privacy Law Update: New Consumer Privacy Laws and Key Deadlines

5 min

State lawmakers continued to expand and add to consumer data privacy requirements during the first half of 2026. Four states passed new omnibus privacy laws, while other states continued the drumbeat of updated requirements under their existing laws. Below we highlight updates for states that enacted new omnibus laws and that adopted additional requirements for sensitive data, data brokers, and artificial intelligence (AI).

New State Consumer Privacy Laws

Louisiana and Oklahoma (January 1, 2027); Alabama (May 1, 2027); and Vermont (January 1, 2028) passed new privacy laws that are effective on the cited dates.

The new laws largely follow the familiar consensus state privacy framework, with key differences that companies should review, including the following:

  • Louisiana requires specific notice when a business sells sensitive personal information or biometric data and requires authentication for all consumer rights
  • Oklahoma treats "pseudonymous" data as personal data when it can reasonably be linked to an identifiable person and requires authentication for all consumer rights (including opt-outs)
  • Alabama generally does not treat disclosures or transfers of personal data for the purposes of providing analytics or certain marketing services as data "sales" and does not require formal data protection assessments
  • Vermont places added emphasis on AI and automated decision making. When profiling occurs to make a decision that produces a legal or similarly significant effect (e.g., housing), consumers may question the result, be informed of the reason for the profiling, review the data, and request correction of the data. Consumers may also request a list of specific third parties to which a business sold personal information. Privacy notices must also state whether personal information is collected, used, or sold to train large language models

Sensitive and Precise Geolocation Data

Maryland and Virginia enacted changes that took effect July 1, 2026.

  • Maryland expanded "precise geolocation" to cover information identifying a consumer, mobile device, or vehicle within a 1,750-foot radius. It also revised the treatment of information from government records and restricted certain sales to government units involved in civil immigration enforcement
  • Virginia now prohibits businesses from selling or offering to sell precise geolocation information

Connecticut's amendments will take effect October 1, 2026.

  • Connecticut's amendments address facial recognition technology, revise rules for publicly available information and related deletion requests, and prohibit businesses and third parties from selling precise geolocation data

New Jersey's amendments took effect immediately on June 30, 2026.

  • New Jersey's amendments prohibit any individual or legal entity—regardless of the number of consumers whose personal data they control or process—from selling sensitive data

Trends show that states are beginning to prohibit the sale or sharing of all sensitive data, or specific categories of sensitive data, like precise location, regardless of consent.

State Data Broker Laws

"Data broker" laws increasingly require covered businesses to register with states and to carry out deletion and opt-out requests across their systems and vendors. Definitions of "data broker" vary across the states, so registration obligations must be assessed on a state-by-state basis.

  • Connecticut will require covered data brokers to register before selling or licensing personal information beginning January 1, 2027. The annual fee is $2,500. The state must create a centralized deletion system by July 1, 2028. Beginning October 1, 2028, registered data brokers must access the system to effectuate deletion requests at least once every 45 days
  • New Jersey will require covered data brokers to register, pay high fees, and disclose certain information beginning in spring 2027. The mandatory registration fees can be up to $1.5 million. In addition, the bill applies to "data collectors," defined as a business that knowingly collects personal data of a consumer with whom it has a direct relationship and "sells or licenses" such data to a data broker. "Data collectors" will be required to register and pay a fee along with "data brokers"
  • Vermont expanded data broker disclosures to cover certain sensitive data practices and sharing with government bodies, law enforcement, foreign actors, and generative-AI developers. It also added a $20,000 bond requirement, requiring registered data brokers to maintain a bond for liabilities arising under the statute

This year showed an increasing focus on "data broker" transparency and consumer rights. The rest of this year's session and the upcoming 2027 session may see this trend continue.

State AI Laws

State AI laws are intersecting with privacy compliance.

  • Colorado's amended AI law takes effect January 1, 2027. The new law applies when automated technology materially influences consequential decisions involving employment, housing, education, lending, insurance, healthcare, or essential government services. Developers must provide technical documentation about covered systems. Deployers using them must provide consumer notices, keep compliance records for at least three years, support certain consumer rights, and offer meaningful human review following some adverse decisions
  • Illinois' AI Safety Measures Act takes effect January 1, 2027, and applies to the largest frontier AI developers (generally those with more than $500 million in annual revenue). By January 1, 2028, covered developers must publish AI safety and security frameworks, conduct annual independent third-party audits, report certain critical safety incidents (within 72 hours, or 24 hours for imminent threats), and maintain documentation demonstrating compliance with the law's transparency and risk management requirements.
  • Washington's generative AI disclosure law takes effect February 1, 2027. Covered providers must offer a free tool to help users determine whether content was generated or modified by their systems.

What Businesses Should Do Now to Operationalize New State Privacy Laws

  1. Prepare for New State Law Compliance: Identify which new state laws apply to your business, note how their requirements differ from those in other states, and prepare in advance of effective dates
  2. Map Sensitive and Location Data: Businesses should identify where sensitive and location data is in their systems and map obligations in certain states that prohibit or restrict certain activity related to such data
  3. Review Data Broker Obligations: Businesses should assess whether they qualify as data brokers (or "data collectors" in New Jersey) under the different definitions across the states, and work to ensure compliance with those obligations
  4. Inventory AI Systems: Businesses should review AI tools they develop or deploy, and should document what data each tool uses, who developed and operates it, what notices and records are required, and how a person can request human review

For state privacy law compliance assistance, including information about consumer privacy laws, sensitive data requirements, data brokers, and artificial intelligence, contact the authors or visit Venable's Privacy and Data Security center.