---------------------------
Title: State Privacy Regulators Are Teaming Up: Here's What It Means for Your Website
URL: https://www.cookiebot.com/us/state-privacy-enforcement-coordination/
---------------------------

# State Privacy Regulators Are Teaming Up: Here's What It Means for Your Website

State privacy enforcement is changing fast. More than 20 states now enforce their own privacy laws, and eleven state attorneys general plus California's privacy agency are coordinating investigations across borders. Private lawsuits under laws like CIPA are climbing too, with no need to prove harm. Here's why companies need to have a privacy compliance strategy bigger than going state-by-state, and what it means for your website.

## At a Glance

- More than 20 U.S. states now have privacy laws in effect, with four more enacted but not yet active (Oklahoma, Alabama, Louisiana, Vermont), bringing the total to 24.
- 11 state attorneys general and California's privacy agency have joined the Consortium of Privacy Regulators since it formed in April 2025, most recently Vermont in August 2026.
- The group has already acted together: a joint GPC investigation across three states, and a $5.1 million multistate settlement with an ed-tech company.
- 12 states already require honoring GPC opt-out signals, and a U.S. senator has asked regulators in 10 states, plus the CPPA, to build a dedicated task force for GPC enforcement.
- There's still no federal privacy law. The SECURE Data Act would create one and preempt most state laws, but it's been stalled since a contentious June 2026 hearing, with no markup scheduled.
- Private lawsuits are a separate, growing risk: California's decades-old CIPA wiretapping law is now widely used to sue over website tracking tech, with damages of $5,000 per violation and no need to prove actual harm.

If you run a website that collects data from U.S. visitors, you already know the privacy compliance picture is complex. More than 20 different state laws, additional federal laws for specific industries but no overarching federal privacy rulebook, new requirements arriving every year, and rising litigation risks. That patchwork isn't going away.

What's changing is how it's enforced, and where the pressure is coming from. State regulators have stopped working in isolation, and private lawsuits under old state laws are climbing on a completely separate track.

A compliance gap spotted in one state can draw attention from another, and a technical detail your site got wrong can just as easily draw a demand letter with no regulator involved at all. Here's what's driving both, and what it means for keeping your site out of trouble.

## How We Got Here: A Fast-Growing Patchwork of State Laws

California kicked things off in 2018 with the [CCPA](https://www.cookiebot.com/us/what-is-ccpa/), the first comprehensive state privacy law in the U.S. Other states took their time joining in, then picked up speed fast.

Delaware, Iowa, Minnesota, Nebraska, New Hampshire, New Jersey, Tennessee, and Maryland all became enforceable in 2025 alone — eight states in a single year, more than any prior year combined. Indiana, Kentucky, and Rhode Island followed on January 1, 2026.

As of August 2026, that's 20 states with active laws and four more enacted but not yet in force (Oklahoma, Alabama, Louisiana, Vermont), for 24 total.

For a small or mid-sized business, this adds up fast, with different thresholds, different definitions of sensitive data, different consumer rights, and a legislative calendar that never really stops.

## Enter the Consortium of Privacy Regulators

The biggest shift in how these laws get enforced arrived on April 16, 2025, when the [California Privacy Protection Agency (CPPA)](https://www.cookiebot.com/en/escalating-cppa-enforcement/), now publicly known as CalPrivacy, launched the [Consortium of Privacy Regulators](https://cppa.ca.gov/announcements/2025/20250416.html), a coalition built to coordinate enforcement across state lines.

The founding group was the CPPA plus the attorneys general of California, Colorado, Connecticut, Delaware, Indiana, New Jersey, and Oregon, working from a memorandum of understanding covering regular meetings, shared priorities, and joint investigations.

Minnesota and New Hampshire joined by October 2025, Maryland came next, and Vermont signed on in August 2026, notably before its own [VDPOSA](https://usercentrics.com/us/knowledge-hub/vermont-data-privacy-online-surveillance-act-vdposa/) privacy law even takes effect in 2028. That puts membership at eleven state attorneys general plus the CPPA.

For your website, the practical upshot is this: a privacy compliance issue that draws attention in one Consortium state is now more likely to get noticed by the others too.

## Active Coordination: A Joint GPC Sweep and a Multimillion-Dollar Settlement

Two cases show what this coordination looks like on the ground. On September 9, 2025, California, Colorado, and Connecticut jointly went after [businesses that weren't honoring GPC opt-out signals](https://cppa.ca.gov/announcements/2025/20250909.html), sending coordinated compliance letters and building on California's earlier [USD 1.2 million Sephora settlement](https://oag.ca.gov/news/press-releases/attorney-general-bonta-announces-settlement-sephora-part-ongoing-enforcement). It was the Consortium's first joint enforcement action.

Separately, in November 2025, California, Connecticut, and New York recovered [USD 5.1 million combined from ed-tech company Illuminate Education](https://oag.ca.gov/news/press-releases/attorney-general-bonta-joins-states-securing-51-million-settlements-education) over a 2021 student data breach. New York isn't a Consortium member, so this is better described as multistate cooperation, though it reflects the same trend toward coordination.

## Where Regulators Are Focusing Their Attention

These patterns were forming before the Consortium even existed, and they've only sharpened since.

[Opt-out](https://www.cookiebot.com/en/opt-in-vs-opt-out-consent-website/) compliance is a consistent target, especially around GPC. Twelve states, California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas, now require sites to recognize [Global Privacy Control (GPC)](https://www.cookiebot.com/en/global-privacy-control/) or a comparable universal opt-out mechanism (UOOM).

Children's and teens' data is squarely in focus too. Privacy laws across U.S. states consistently treat it as sensitive; Connecticut, Colorado, and Maryland have added protections for 13-to-17-year-olds, and both the FTC and Congress have stepped up scrutiny.

[Sensitive categories](https://www.cookiebot.com/en/pii-vs-personal-data-sensitive-data/) like health, location, and biometric data are also drawing attention, as shown by the FTC's finalized [January 2026 order against General Motors and OnStar](https://www.ftc.gov/news-events/news/press-releases/2026/01/ftc-finalizes-order-settling-allegations-gm-onstar-collected-sold-geolocation-data-without-consumers) over undisclosed geolocation and driving data sales. Consent needs to come before collection, not after.

Data brokers face added scrutiny under California's [Delete Act](https://privacy.ca.gov/drop/about-drop-and-the-delete-act/), with the CPPA following up multiple sweeps with real actions. Texas runs its own separate, active enforcement track. Third-party transparency is growing too: Minnesota, Oregon, and Connecticut all now require disclosure of which third parties get consumer data.

## Where the Pressure Is Building Next

On August 3, 2026, [Senator Ron Wyden wrote to attorneys general](https://www.wyden.senate.gov/imo/media/doc/wyden_letter_to_ags_on_gpc.pdf) in ten states, California, Colorado, Connecticut, Delaware, Maryland, Montana, Nebraska, New Hampshire, New Jersey, and Texas, plus the chair of the California Privacy Protection Agency Board, asking for public guidance that GPC signals be honored no matter a visitor's apparent location or VPN use, and for a dedicated multistate task force for GPC enforcement.

None of this has been adopted, and no state has formally committed. But it points the same direction the Consortium already has: more coordination ahead, with location-based workarounds for opt-out compliance drawing direct scrutiny.

## Do you know what your website is collecting?

Scan your website for free and learn what cookies and trackers are active. Get a customized report of your privacy compliance risk for U.S. requirements in minutes.

[Start Scan](https://www.cookiebot.com/us/cookie-checker/)

## Enforcement Keeps Climbing, Even as New Laws Slow Down

Interestingly, 2025 was the first year since 2020 without a brand-new comprehensive state privacy law, yet enforcement activity went up as states shifted from writing laws to enforcing the ones already on the books.

California's AG announced its largest CCPA penalty to date in July 2025, [USD 1.55 million against Healthline Media](https://oag.ca.gov/news/press-releases/attorney-general-bonta-announces-largest-ccpa-settlement-date-secures-155), for continuing to share sensitive health browsing data with advertisers after visitors opted out, including via GPC.

Connecticut's AG landed its first [CTDPA](https://www.cookiebot.com/en/connecticut-data-privacy-act-ctdpa/) settlement that same month, [USD 85,000 with TicketNetwork](https://portal.ct.gov/ag/press-releases/2025-press-releases/attorney-general-tong-announces-settlement-with-ticketnetwork). Separately, the CPPA issued its own [record settlement against Tractor Supply](https://cppa.ca.gov/announcements/2025/20250930.html), and California's AG set another record in February 2026 with a [USD 2.75 million settlement against Disney](https://oag.ca.gov/news/press-releases/california-wont-let-it-go-attorney-general-bonta-announces-275-million) over inconsistent opt-out handling across its streaming services.

Across all of these, the common thread isn't just the fine. It's the corrective-action requirements: operational fixes, added resourcing, and ongoing monitoring.

Learn more: CCPA vs CPRA: Understanding the Differences

## The Litigation Risk: Private Lawsuits Under CIPA and Similar Laws

Regulators aren't the only ones bringing cases. A California law from 1967 is quietly becoming one of the biggest website-compliance risks around, and it has nothing to do with any AG or the Consortium.

The [California Invasion of Privacy Act (CIPA)](https://www.cookiebot.com/us/cipa-california-invasion-of-privacy-act/) was written to stop illegal phone wiretapping. Plaintiffs' firms now apply it to ordinary website technology instead, arguing that session-replay tools, tracking pixels, live chat, and AI chatbots "intercept" a visitor's communications before they've consented.

Anyone can sue directly under CIPA, with statutory damages of USD 5,000 per violation (or three times actual damages, whichever is greater), and a plaintiff doesn't have to prove real harm to ask for it.

Case law is still a mixed bag. A federal court approved a [USD 3.85 million class settlement against the Los Angeles Times](https://www.spencerfane.com/insight/cipa-website-tracking-lawsuits-where-the-law-stands-where-its-going-and-what-your-business-should-do-now/) in June 2026, while a nearly identical claim was thrown out with prejudice by a state court just three weeks earlier.

The legislative fix is in, but it is a narrow one. [SB 690](https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB690), signed by Governor Newsom on September 30, 2026, strips the private right of action for one specific CIPA theory, pen register and trap-and-trace claims over website and app conduct, and hands enforcement to the California Attorney General instead. It takes effect January 1, 2027. It does not touch the wiretapping and eavesdropping theories that many CIPA website suits rely on today.

It has spread past California too. Plaintiffs are increasingly pairing CIPA claims with similar wiretap theories under [Florida](https://www.leg.state.fl.us/statutes/index.cfm?App_mode=Display_Statute&URL=0900-0999%2F0934%2F0934.html) and [Pennsylvania](https://www.palegis.us/statutes/consolidated/view-statute?txtType=HTM&ttl=18&div=0&chpt=57) law, as well as the [VPPA](https://usercentrics.com/us/knowledge-hub/video-privacy-protection-act-vppa/) or [ECPA](https://www.cookiebot.com/us/electronic-communications-privacy-act-ecpa/), which are federal. The takeaway is that a site with visitors across multiple states can't treat this as a California-only problem.

A tidy [privacy policy](https://www.cookiebot.com/us/how-to-write-privacy-policy-guide/) and a state-law checklist don't cover this. It's a separate legal theory, and it doesn't wait on any regulator to act.

Learn more: CIPA Demand Letters: What It Means and What to Do About It

## What This Multistate Coordination Means for Your Website

A violation flagged in one state can now trigger scrutiny in others. With Consortium states sharing information under their MOU, and non-Consortium states like New York and Texas increasingly coordinating on their own, treating each state's requirements as a separate, isolated problem is no longer a safe bet.

Having a privacy policy on file isn't the finish line. Regulators check whether things actually work in practice. Non-functional [consent banners](https://www.cookiebot.com/en/legal-requirements-for-websites/), opt-outs that are hard to find or use, and policies that don't match real data practices have all drawn enforcement action.

Universal opt-out signals are now required in 12 states. As sweeps continue and momentum builds for a dedicated task force, sites that don't properly honor these signals face growing exposure.

Third-party and vendor relationships matter too. Data sharing with ad tech, analytics, and data brokers is a live enforcement focus, so it's worth checking that vendor contracts reflect current requirements and that you actually know how your third parties use visitor data.

Learn more: Cookie Consent Management Platform Guide

## Meanwhile in Washington: Still No Federal Privacy Law

Federal privacy legislation remains stuck, though there's more visible motion than in past years. The House Energy & Commerce Committee's Privacy Working Group spent over a year gathering input, and in April 2026 that effort produced the [SECURE Data Act (H.R. 8413)](https://www.congress.gov/bill/119th-congress/house-bill/8413), the most serious attempt at a comprehensive federal privacy law in years.

It would set a single national standard and broadly preempt state privacy laws, and cleared a subcommittee hearing in June 2026, but split along party lines there and hasn't advanced to a markup vote since.

The federal government is still active in narrower areas. The DOJ's Bulk Data Rule, limiting sensitive data transfers to countries of concern, took effect April 8, 2025 (full enforcement from July 8, 2025). The FTC continues enforcing [COPPA](https://www.cookiebot.com/en/coppa-compliance-requirements-checklist/) and has signaled it intends to pursue the Protecting Americans' Data from Foreign Adversaries Act; and sector rules like [HIPAA](https://www.cookiebot.com/us/hipaa-compliance-healthcare-websites/) and the [GLBA](https://www.cookiebot.com/us/gramm-leach-bliley-act-glba/) remain in force regardless.

Without a federal law to unify things, expect the Consortium model to keep growing in influence, at least for as long as the SECURE Data Act stays stalled.

## A Practical Compliance Checklist for This New Reality

Privacy compliance isn't a set-it-and-forget-it project anymore, especially if your site draws visitors from multiple states. Here's a starting point:

- **Check your consent setup** — Does your site actually honor GPC signals? Are opt-outs easy to find and use, no matter where a visitor appears to be located?
- **Map out your third-party data flows** — Do your vendor contracts reflect current requirements? Do you know what your third parties are doing with visitor data?
- **Take a hard look at sensitive data** — Health, location, biometric, and children's data draw outsized attention, so document how you handle each clearly.
- **Automate what you can** — Manually tracking 20-plus state laws by hand isn't realistic for most teams, but a CMP built for U.S. compliance can handle opt-in or opt-out signals as required, and keep an audit trail for you.
- **Watch enforcement and litigation, not just legislation** — Settlements and lawsuits often tell you more about real-world risk than the statute text does.

## The Bottom Line for Your Website Privacy Compliance Strategy

U.S. privacy enforcement is getting more coordinated and more active, not less. 11 states plus the CPPA and counting, record numbers of enforceable laws, and a rising tide of joint enforcement actions all point the same way — cross-state enforcement is becoming the norm, and Washington wants more of it, not less.

Regulators aren't your only exposure either. Private litigation under laws like CIPA is running on its own track, with its own damages and its own timeline, and doesn't wait for any AG to act.

A privacy compliance approach built around a single state's rules, or around regulators alone, is unlikely to hold up. Consistent, well-documented, and automated privacy practices and a comprehensive consent management platform like [Cookiebot™ CMP](https://www.cookiebot.com/us/cookie-consent-solution/) are the most reliable way to manage that risk, and getting it right does double duty. It helps to protect you from penalties and lawsuits alike, and it shows visitors you take their data seriously.

## Scale U.S. privacy compliance from one platform

Manage consent across U.S. state privacy laws from one platform. Geotargeting, auto-blocking, honoring opt-out signals, and more. Try it free for 14 days.

[Start Free Trial](https://www.cookiebot.com/us/cookie-consent-solution/)

---

## Footer

### Products
- [Cookiebot™ Consent Solution](https://www.cookiebot.com/us/cookie-consent-solution/)
- [Audience Survey](https://www.cookiebot.com/us/audience-survey-add-on/)
- [Usercentrics for Wix](https://www.cookiebot.com/us/cookiebot-for-wix-by-usercentrics-app/)
- [Usercentrics Cookiebot plugin for WordPress](https://www.cookiebot.com/us/new-wp-cookie-plugin/)
- [Cookiebot CMP for Shopify](https://www.cookiebot.com/us/cookiebot-cmp-for-shopify/)
- [Cookie checker](https://www.cookiebot.com/us/cookie-checker/)
- [Usercentrics products](https://usercentrics.com/us/)
- [Pricing](https://www.cookiebot.com/us/pricing/)

### Regulations
- [DMA (EU)](https://www.cookiebot.com/us/digital-markets-act-dma/)
- [GDPR (EU)](https://www.cookiebot.com/us/gdpr/)
- [CCPA (California)](https://www.cookiebot.com/us/what-is-ccpa/)
- [VCDPA (Virginia)](https://www.cookiebot.com/us/virginia-vcdpa/)
- [LGPD (Brazil)](https://www.cookiebot.com/us/lgpd/)
- [TCF v2.4 (IAB)](https://www.cookiebot.com/us/tcf/)
- [Google Consent Mode (EU)](https://www.cookiebot.com/us/cookiebot-cmp-google-consent-mode/)
- [Microsoft UET Consent Mode](https://www.cookiebot.com/us/microsoft-consent-mode-cmp/)
- [View all regulations](/us/regulations-and-frameworks/#united-states-state&united-states-federal)

### Partners
- [Become an affiliate](https://www.cookiebot.com/us/affiliates/)
- [Affiliate Login](https://app.impact.com/login.user)
- [Become a partner](https://www.cookiebot.com/us/resellers/)
- [Find a partner](https://www.cookiebot.com/us/cookiebot-reseller/)

### Resources
- [Blog](https://www.cookiebot.com/us/blog/)
- [Customer stories](https://www.cookiebot.com/us/customer-stories/)
- [Customer directory](https://www.cookiebot.com/us/cookiebot-customer-directory/)
- [Digital Markets Act Hub](https://www.cookiebot.com/us/digital-markets-act-dma-resources/)
- [Google Consent Mode Hub](https://www.cookiebot.com/us/google-consent-mode-resources/)
- [Google Consent Mode V2 certification](https://courses.usercentrics.com/course/google-consent-mode-v2)
- [Google Consent Audit Fixes](https://www.cookiebot.com/us/google-consent-audit-fixes/)
- [Cookie Banner Cost Calculator](https://www.cookiebot.com/us/cookie-banner-pricing-calculator/)

### Company
- [About us](https://www.cookiebot.com/us/about/)
- [Careers](https://usercentrics.com/career/)
- [Support](https://support.cookiebot.com/hc/en-us/)
- [Developer documentation](https://www.cookiebot.com/us/developer/)

©2026 Cookiebot. All rights reserved. Cookiebot is a trademark of     Usercentrics     A/S. Usercentrics A/S is registered in Denmark. Company reg. no.: 34624607. Do Not Sell or Share My Personal InformationData Subject RequestsManage Your Preferences

[Privacy Policy](https://www.cookiebot.com/us/privacy-policy/) · [Terms of Service](/en/terms-of-service/) · [Cookie Declaration](https://www.cookiebot.com/us/cookie-declaration/) · [Data Processing Agreement](/us/data-processing-agreement/) · [Legal Notice](https://www.cookiebot.com/us/legal-notice/) · [Accessibility Statement](/en/accessibility-statement-wcag-compliance/)