Skip to Main Content
Main Menu
Article

The Enforcement Era Is Here: A Mid-Year Privacy Reality Check

July 28, 2026

The first half of 2026 has been anything but quiet for privacy professionals. From record enforcement actions to new state laws taking effect, the regulatory landscape has shifted significantly, and the second half promises more of the same. Here’s what you need to know.

The Enforcement Era Is Real

If there was any lingering doubt that privacy enforcement had teeth, GDPR fines in the EU reached €1.27.1 billion last year, a 60% increase from 2023. So far 2026 is also putting those doubts to rest. In California alone, CCPA related fines total over $16M. And the targets aren’t just big tech anymore. Ford, GM, Disney, PlayOn, and Shein were among the organizations that faced regulatory action in the past year, spanning industries from automotive to retail to media.

“It’s a who’s who. This isn’t the days of Cambridge Analytica. You’re now seeing car makers, high school sports streamers, Disney — get fined.”

Val Ilchenko, TrustArc Chief Legal Strategy Officer

California’s CPPA continues to be especially active, and partners at privacy-focused law firms are seeing wiretap claim letters at a volume not seen in nearly a decade.

20 State Privacy Laws Are Now in Effect

The patchwork of U.S. state privacy legislation keeps expanding. As of mid-2026, 20 comprehensive state privacy laws are in effect. Indiana, Kentucky, and Rhode Island went live January 1st. Connecticut, Utah, and Maryland updated their laws on July 1st. California’s ADM (automated decision-making) compliance date is set for January 1, 2027.

For companies still treating state privacy as a “monitor and wait” issue, that approach is getting harder to defend.

California’s DROP System Goes Live August 1st

One of the most operationally significant privacy developments of 2026 will be California’s first major operational milestone for the DELETE Act’s Delete Request and Opt-Out Platform (DROP) on August 1. DROP became available earlier in the year, and more than 300,000 Californians had signed up by June. Beginning August 1, registered data brokers must access DROP at least every 45 days, process deletion requests, and delete covered personal information within 45 days. If a deletion request cannot be verified, the broker must generally treat it as an opt-out of the sale or sharing of the consumer’s personal information.

The catch: This is not a clean, one-to-one matching exercise. Beginning August 1, data brokers must access DROP at least every 45 days, standardize and compare the identifiers in consumer deletion lists against their own records, and direct relevant processors to delete matched information. For brokers and processors that have not prepared the necessary systems and workflows, operational readiness before August 1 is an immediate priority.

Consent Is Still the Front Door for Regulators

The enforcement actions from the first half of 2026 share a common thread: the public promise didn’t match the technical reality. Disney honored opt-outs on the device where they were submitted, but not across devices. PlayOn had layered consent mechanisms that the courts ultimately found insufficient. Honda used the same privacy-request form for verifiable CCPA requests and for opt-out and sensitive-personal-information “limit” requests, requiring consumers to provide more information than necessary, including their name, full address, email, phone number, and optionally the VIN or serial-number. The CPPA’s stipulated final order required Honda to stop effectively verifying opt-out and limit requests, which generally do not require verification.

“Consent isn’t just the moment somebody clicks a button,” Ilchenko said. “It’s the chain connecting the consent to the account, the device, the tag, the SDK, the vendor.”

The practical takeaway from the panel: go to your own website and walk through the opt-out experience. If it feels off, it probably is.

AI Governance Is Becoming a Sales Requirement

Panelists from Telly, OpenAP, and Mintz were aligned on this point: AI governance is no longer just an internal compliance exercise. Vendors and enterprise clients are now asking directly; what’s your AI policy, how are you using our data, and is it being used to train models?

“Get your AI governance house in order. You’re going to get asked those questions. If you don’t have answers, you risk delaying revenue.”

Andy Dale, OpenAP General Counsel and CPO

Julia Shullman, General Counsel and CPO at Telly, added that organizations shouldn’t wait for a regulatory standard to emerge before acting: “There’s the potential that people almost get paralyzed on this because AI is moving so fast. At least having a broad-based policy and an internal team of champions is the baseline.”

See How Organizations Are Keeping Up With AI Governance

What to Watch in H2 2026

A few items the panel flagged as priorities for the next six months:

  • The EU AI Act deadlines for high-risk systems under Annex I have been pushed back, but organizations shouldn’t treat delays as permission to deprioritize.
  • India’s DPDPA will have a significant implementation moment in November around its consent manager framework. 
  • The Kids Act package passed the House in June and, if it clears the Senate, would move COPPA toward a constructive knowledge standard. This is a meaningful shift for any service that doesn’t explicitly target minors but may reach them. 
  • Lastly, cure windows are expiring or disappearing in several states, meaning regulators may not be required to give you a chance to fix a violation before acting.

Stay Ahead of What’s Coming in H2

From state law deadlines to AI governance requirements, the second half of 2026 will move fast. TrustArc helps privacy teams stay compliant, audit-ready, and ahead of regulatory change so you’re not scrambling when the next enforcement wave hits.

Talk to a TrustArc Expert

Get the latest resources sent to your inbox

Subscribe
Back to Top