California’s new deletion portal, DROP, now forces data brokers to process opt-out requests on a recurring cycle instead of a one-time basis. Connecticut and Vermont require companies to disclose whether they’re feeding personal data into an AI model. A multistate coalition just got Meta to agree to a $17.1 billion settlement over how it designed products aimed at kids. These aren’t three separate news items. They’re the same signal: privacy obligations are moving out of policy documents and into the way systems actually run, what data flows where, what ships on by default, what a product discloses about its own behavior.
That’s the shift worth building a program around. Tracking every bill as it drops isn’t a strategy, it’s a treadmill. What keeps a program ahead is the ability to take a regulatory change, decide quickly whether it applies, connect it to a control you already have, assign someone to own it, and produce evidence that the control actually works. Here are four signals from 2026 that make that case, followed by the operating model that turns signals into action.
1. Privacy rights are becoming infrastructure
California’s Delete Request and Opt-out Platform, DROP, had to be established by January 1, 2026. The obligation that actually kicked in this year landed August 1: data brokers had to start accessing the platform and processing deletion requests on a recurring 45-day cycle. That’s a different kind of compliance problem than a one-time policy update. It’s an operational commitment that repeats indefinitely.
CalPrivacy is already testing that commitment. LocateSmarter was fined for missing its data broker registration deadline and, separately, for conditioning a CCPA opt-out on unnecessary verification, including collecting partial Social Security numbers. Cybba and SalesIntel Research have also faced enforcement action this year. The message from the regulator is consistent: making an opt-out harder to exercise than it needs to be is itself a violation, not just bad practice.
CalPrivacy also opened its first formal sectoral audit, aimed at gig economy platforms and how they use personal data in decisions about job assignments, earnings, ratings, suspensions, and deactivations. If your organization touches data broker registration, or uses personal data to drive algorithmic decisions about workers, this is worth checking now rather than after an inquiry letter arrives.
2. Transparency is moving into products and business models
Connecticut’s amended privacy notice rules require a statement about whether a company collects, uses, or sells personal data to train large language models. Vermont’s privacy act includes a similar requirement, though it doesn’t take effect until January 1, 2028. Either way, the direction is clear: if your product touches AI training, “what does the privacy policy say” is becoming a technical question, not just a legal one, because someone has to know what the model actually does with the data before anyone can write an accurate disclosure.
Algorithmic pricing follows the same pattern applied to a different system. The Senate Judiciary Committee held a hearing on the practice in August, titled “Your Data, Their Profit: The Consumer Cost of AI Surveillance Pricing.” Three states have legislated, and the details differ more than the early headlines suggested. New Jersey bans grocery and foodstuff pricing based on personal data and adds a one-year moratorium on new electronic shelf labels while the technology gets studied; the general provision takes effect in 2027, and violations create civil-remedy exposure under the state’s Consumer Fraud Act rather than a standalone private right of action. Maryland’s rule is narrower, covering food retailers and third-party food delivery providers, effective October 1, 2026. Connecticut goes further for retail sellers and delivery services, prohibiting surveillance pricing outright, while requiring disclosure from other businesses that use a price-setting device; it explicitly rules out a private right of action.
The EU AI Act adds its own transparency layer. Providers and deployers of AI systems are now asked to support the development of AI literacy among their people, not guarantee a specific level of it. That’s a small wording change with a real effect on what a regulator can hold you to.
3. Children’s privacy is becoming a design and systems problem
There’s no single national age threshold for children’s privacy. COPPA sets a federal floor at under-13, and states are layering additional obligations on top, often with different age lines for different obligations inside the same law. New Jersey’s known-child rule tracks COPPA’s under-13 standard, but a separate consent requirement applies to processing involving 13-to-17-year-olds. Maryland runs a similar split.
A few specific developments deserve close tracking. New Jersey’s Kids Code Act, more precisely the Children’s Online Safety and Privacy Act, targets dark patterns and default account settings and takes effect September 1, 2027. Illinois passed a law requiring an age-bracket signal from devices, operating systems, and app stores, but those obligations don’t start until 2028, with additional platform requirements later that year. New York finalized its SAFE for Kids Act implementation rules in July 2026, with the framework itself taking effect January 25, 2027. At the federal level, KOSA remains a reintroduced bill working through the ordinary legislative process, not a bill stuck in formal conference.
The Meta story has also moved past the pending-trial stage. In August 2026, a multistate coalition of attorneys general reported a $17.1 billion settlement with the company over allegations of deliberately addictive design, harm to young users, misrepresentations about platform safety, and data-sharing practices involving children’s information.
Put together, these developments point to the same conclusion: children’s privacy compliance isn’t just an age gate and a consent form anymore. It’s default settings, recommendation logic, notification design, and deletion workflows, built to hold up under a design review, not just a notice review.
4. Regulatory status is itself a compliance risk
Four more US states enacted consumer privacy laws this year: Alabama, Oklahoma, Louisiana, and Vermont. None of them are in effect yet. Oklahoma and Louisiana take effect January 1, 2027; Alabama, May 1, 2027; Vermont, January 1, 2028. A program that treats “enacted” as “applicable” will build controls a year or earlier and still miss the window on something else that’s live today. The more accurate way to describe US privacy law right now isn’t “fifty states, zero consensus.” It’s one national market running more than twenty different state privacy regimes with no uniform control model behind them. Oklahoma’s law specifically doesn’t require recognition of universal opt-out signals, so check your coverage if you’ve built compliance around those signals as a given. Louisiana added an alternative applicability test based on $25 million in gross revenue, alongside separate consumer-volume and data-sale thresholds, not a straightforward threshold increase.
The EU’s Digital Omnibus is at an earlier stage than a lot of commentary suggests. It’s still a proposal covering changes to GDPR, ePrivacy, the Data Act, and cybersecurity reporting requirements, and it hasn’t replaced anything yet. Ireland holds the Council presidency through the end of 2026, and reports suggest they want the package closed by year-end, but there’s no confirmed deadline, and major issues, including the definitions of personal data and pseudonymization, remain open. The EDPB and EDPS have raised concerns and asked for clarification on several of the foundational changes on the table. A conditional legitimate-interest pathway for AI training and operation is in the draft, but it’s still subject to the full legislative process. Cybersecurity reporting is the item closest to a real simplification win, unifying overlapping reporting frameworks, though it isn’t final either. The practical rule: the current GDPR is the operative baseline until something specific is adopted and applicable. Don’t build controls around a provision that hasn’t cleared the process.
The AI Act moved on a different track. Regulation (EU) 2026/1744 was published in the Official Journal on July 24, 2026, and became generally applicable on August 2. The heavy compliance dates for high-risk systems got pushed out: systems under Article 6(2) and Annex III, covering uses like employment, education, and law enforcement, have until December 2, 2027. Systems embedded in regulated products, like medical devices or machinery covered by EU product-safety law, fall under Article 6(1) and Annex I and have until August 2, 2028. A new prohibition takes effect December 2, 2026, covering AI systems that generate or manipulate realistic non-consensual intimate imagery and child sexual abuse material, under the specific conditions the regulation sets out.
South Korea’s amended PIPA took effect September 11, 2026, and the headline everyone keeps repeating, cross-border transfer mechanisms that look more like GDPR and a right to challenge automated decisions, actually came out of the 2023 reforms. The real 2026 story is accountability: ultimate legal responsibility now sits explicitly with the business owner or representative, board-level involvement and reporting is required for certain chief privacy officer appointments, the breach-notification trigger moved earlier to cover the possibility of a breach rather than a confirmed one, and the rules around sensitive information, unique identifiers, CCTV, outsourcing, and pseudonymized data all tightened. The penalty ceiling moved to 10% of total revenue for aggravated cases: willful or grossly negligent repeat violations, breaches affecting ten million or more people, or failures tied to a corrective order. If your South Korea program hasn’t been reviewed since before 2023, this year’s amendment is the reason to do it now, not the 2023 changes most programs already built around.
A quick tour of the rest of the world:
- India’s DPDP consent manager registration requirements start November 2026, with the main operational obligations landing mid-2027, start building now.
- Japan’s amended APPI, promulgated in July, adds protections for biometric data and users under 16 and introduces the country’s first administrative surcharge regime, with an effective date still to be set by ordinance within two years.
- Australia’s automated decision transparency rules take effect December 10, 2026, while its Children’s Online Privacy Code is still being developed.
- Vietnam’s new Personal Data Protection Law took effect January 1, 2026, and works alongside its implementing decree as the current framework, with a 72-hour breach reporting requirement and AI processing transparency rules.
- Brazil’s ANPD, already technically and operationally independent, was elevated by 2026 legislation into a fully independent regulatory agency; more assertive enforcement is a reasonable bet, not yet a fact.
- And China’s 2025 Measures on Certification for the Export of Personal Information took effect January 1, 2026, adding certification as one transfer route alongside the existing contract and security-assessment mechanisms.
Turning signal into a program
Reading this list isn’t the point. The point is building a program that can absorb the next fifty items on it without a special project every time. That starts with a common control foundation: transparency, lawful processing, individual rights, data minimization and retention, security and breach response, and where applicable – consent, international transfers, and children’s data. Jurisdiction-specific rules then act as overlays, changing the thresholds, workflows, and evidence each control requires. From there, a program needs a repeatable sequence.
Detect
Continuous monitoring across jurisdictions, catching a change when it’s proposed and tracking it through enactment, rather than waiting until it’s already in effect.
Qualify
A fast, consistent way to decide whether a given change actually applies: to which products, which data, which vendors, which parts of the business model.
Map
Connecting a qualified change to an existing control rather than starting a new project from a blank page every time. Most changes are an overlay on something you already do.
Implement
Assigning an owner, a deadline, and a dependency list, so “we’re aware of it” turns into something that actually gets done.
Evidence
Testing the control, keeping proof it ran, and reporting status up the chain. A control nobody can prove operated isn’t a control regulators, or your own leadership, will take seriously.
Programs built this way don’t get faster at reading the news. They get faster at turning a regulatory change into a decision, a mapped control, an owner, and proof the control works.
Want to see how TrustArc helps privacy teams do exactly that, across jurisdictions?
Book a Demo