Tech Law & AI Regulation Curator

US privacy regulation: state patchwork, federal financial privacy, enforcement surge

US privacy regulation: state patchwork, federal financial privacy, enforcement surge

Key Questions

What major CCPA enforcement action occurred recently?

California imposed a $12.75 million fine on GM under the CCPA for privacy violations. This reflects an ongoing surge in state enforcement activity.

How is Connecticut updating its data privacy law?

Connecticut overhauled the CTDPA with lower applicability thresholds, mandatory data broker registration, a geolocation data ban, and surveillance pricing disclosure rules. These changes significantly expand consumer protections.

What privacy law did Massachusetts recently pass?

Massachusetts passed a privacy law banning the sale of precise location data and granting a private right of action. The measure is viewed as particularly impactful for big tech companies.

Which new states enacted comprehensive privacy laws?

Louisiana became the 22nd state with a comprehensive privacy law. Alabama, Delaware, and Maryland also passed or advanced privacy and surveillance pricing legislation.

What Supreme Court ruling affects telecom data privacy enforcement?

The Supreme Court upheld the FCC’s authority to fine telecom companies for data privacy violations in an 8-1 decision. This strengthens federal enforcement powers in the sector.

What new biometric or facial recognition features are raising concerns?

Meta added facial recognition ‘NameTag’ functionality to its smart glasses. Amazon and Ring also face lawsuits over alleged privacy violations from their facial recognition tools.

What is the GUARD Financial Data Act?

The GUARD Financial Data Act proposes new federal rules for financial data privacy and security. It is part of broader efforts to address gaps in financial sector protections.

How are states addressing surveillance pricing and biometric data?

Maryland banned surveillance pricing practices while Erie County, New York introduced a biometric data ordinance. New Jersey has also issued cure letter guidance for privacy compliance.

CA $12.75M GM CCPA; FTC Take It Down Act; WA privacy laws (eff. Jul 1, 2026); Alabama HB 351; Maryland surveillance pricing ban; Delaware HB 380/381; Louisiana 22nd state; Erie County biometric law; GUARD Financial Data Act. New: Supreme Court upholds FCC's power to fine telecoms for data privacy violations (8-1). Meta adds facial recognition 'NameTag' to smart glasses. Connecticut overhauls CTDPA with lower thresholds, data broker registration, geolocation ban, surveillance pricing disclosure. Massachusetts passes privacy law banning sale of precise location data with private right of action. NJ cure letters, NY DFS cyber guidance.

Sources (11)
Updated Jun 9, 2026