CODY KELLER

July 1 brought another wave of state privacy law changes into effect. If your compliance calendar had these flagged, this is the time to confirm your program is actually operational — not just documented. If you didn’t have them flagged, here’s what you need to know.

We covered the broader state privacy landscape in the June 2 post. This one focuses specifically on what changed July 1 and what the practical compliance implications are heading into the second half of 2026.

What Went Live July 1

Connecticut — Amended CTDPA Provisions

Connecticut’s updates are the most substantive of the July 1 changes. The amendments expand the definition of sensitive data and add enhanced protections for minors under 16, including tighter restrictions on processing their personal data for targeted advertising and stricter consent requirements. The cure period under Connecticut’s law is narrowing, and the AG’s office has been explicit that it will not extend grace for technical opt-out failures or inadequate privacy notices.

Connecticut has already demonstrated enforcement intent — their first CTDPA settlement in 2025 centered on a privacy notice that regulators described as “largely unreadable,” with absent consumer rights disclosures and broken opt-out mechanisms. That settlement established the template. Unreadable notices and inoperable opt-outs are documented violations, not informal warnings.

If Connecticut is on your coverage map, your privacy notice and opt-out mechanisms should have been tested before July 1. If they weren’t, test them now. The AG’s office isn’t waiting.

Arkansas — Data Privacy Act

Arkansas joins the active enforcement landscape with a comprehensive privacy law effective July 1. The Arkansas Personal Information Protection Act covers for-profit businesses that exceed applicability thresholds and establishes consumer rights around access, deletion, and opt-out of data sales and targeted advertising.

Arkansas’s law includes a 30-day right to cure, which provides some operational runway for organizations that receive a notice of violation before enforcement escalates. That runway is not a compliance strategy — it’s a remediation window. Organizations that haven’t assessed their Arkansas coverage shouldn’t treat the cure period as a substitute for preparation.

Utah — Updated Provisions

Utah’s amendments effective July 1 tighten existing requirements and add clarifications around data minimization and processing limitations. Utah’s law has generally been considered one of the more business-friendly state privacy frameworks, but the July 1 updates reflect the broader trend of states refining and tightening their initial frameworks as enforcement experience accumulates.

The Pattern Worth Noting

The July 1 changes aren’t isolated events. They’re part of a consistent pattern across 2026: states that enacted privacy laws in 2023 and 2024 are now amending those laws based on early enforcement experience, and new states continue to join the active enforcement map.

The practical effect is that the compliance posture your organization established at the beginning of the year may already need updating. Privacy laws are not static documents, and the organizations treating them as a one-time compliance checkbox are discovering that their documentation reflects requirements that have since changed.

Connecticut’s amendments alone require revisiting sensitive data classifications, minor data protections, and opt-out mechanism functionality for any organization with Connecticut exposure. If those reviews haven’t happened, they’re overdue.

The Six-Month Compliance Reality Check

We’re past the halfway point of 2026. The Indiana, Kentucky, and Rhode Island laws that went live January 1 have been in effect for six months. California’s automated decision-making regulations have been in effect for six months. If your organization had gaps in those frameworks at the start of the year and hasn’t addressed them, you’ve been carrying that exposure for two quarters.

State attorneys general are increasingly coordinating enforcement activity. The $1.4 billion in privacy fines and penalties in 2025 reflects a regulatory environment that has moved well past the warming-up phase. Enforcement isn’t a 2027 concern. It’s a current operating condition.

What to Do Right Now

  • Confirm Connecticut compliance if Connecticut is on your coverage map — specifically the opt-out mechanisms, minor data protections, and privacy notice readability. Test the opt-out flow yourself before assuming it works.
  • Assess Arkansas and Utah coverage using the same threshold analysis you applied to January 1 laws. Apply consistent methodology across all state laws rather than treating each one as a separate project.
  • Review your sensitive data classifications against Connecticut’s expanded definitions. If you haven’t updated your data inventory since January, it may not reflect current requirements.
  • Audit your January 1 compliance work for Indiana, Kentucky, Rhode Island, and California. Six months in, are the controls you put in place still operating as designed? Have business processes changed in ways that affect your compliance posture?
  • Document your coverage determinations. Regulators increasingly expect organizations to demonstrate that they assessed applicability and made informed compliance decisions — not just that they implemented controls. The determination is part of the compliance record.

The state privacy law stack is not a one-time project. It’s an ongoing compliance function that requires monitoring, updating, and periodic reassessment as laws change and business operations evolve.


Discussion Questions

  1. Has your organization completed a coverage determination for the July 1 laws — Connecticut amendments, Arkansas, and Utah? Is that determination documented?
  2. When did you last test your opt-out mechanisms across the platforms and jurisdictions where you have compliance obligations? Are they currently functional?
  3. Six months into 2026, have you reviewed whether your January 1 compliance work is still operating as designed? What’s the process for ongoing compliance monitoring versus point-in-time implementation?

Further Reading


Leave a Reply

Your email address will not be published. Required fields are marked *