All Blog Posts

Why Your Website's Privacy Risk Looks Different in 2026

Close
Read time
3 mins
Published
Aug 27, 2026
Share

  • More than 20 U.S. states now have their own privacy rules, and one of them can apply to your site even if you don't operate there.
  • Lawsuits over everyday tools, like tracking pixels, chat widgets, session replay, have surged since 2022, and retail sites are the single biggest target.
  • 12 states now require your site to detect and honor automatic opt-out signals like GPC, not just show a cookie banner.
  • In California, that now means showing visible proof the opt-out signal worked, not processing it silently.
  • A pending California bill could narrow one lawsuit theory, but it won't change what your site needs to do today.
  • All of this lands right as Black Friday and Cyber Monday traffic peaks — exactly the wrong time to find a gap.

For years, privacy compliance in the U.S. meant watching one state: California. That's no longer true. Many more states have enacted privacy laws, and regulators are working together on enforcement priorities across state lines. And then there’s the litigation.

Retailers and e-commerce teams now face a wider, faster-moving set of rules, and two very different kinds of enforcement.

It's Not Just California Anymore

More than 20 states have comprehensive privacy laws on the books, and a few more are set to join them over the next year or two.

Each state's law is a little different in who it applies to, what counts as a "sale" of data, how big a company has to be before the law kicks in, opt-out signal handling, and other requirements. 

For a retailer selling nationwide, that means a website has to satisfy the strictest state, not the easiest one. And there is still no federal statute governing the data privacy rules.

The Bigger Risk Might Not Be a Fine

Most privacy conversations focus on regulators. The state attorneys general are issuing fines, with the exception of California, which also has the CPPA. That's real, but it's not the only risk, and often not the fastest-moving one.

The other track is private lawsuits, and it's grown fast. In California, plaintiffs' lawyers have been using the California Invasion of Privacy Act (CIPA) to sue over everyday website tools like tracking pixels, chat widgets, and session-recording software. 

CIPA is a 1967 wiretapping law. Since 2022, filings have climbed from the low hundreds to several thousand, and retail is the most-targeted sector by a wide margin. Many businesses hear about this first through a CIPA demand letter rather than a lawsuit. 

It's not the only law being used this way, either. The VPPA and ECPA, both federal, are seeing similar claims.

The SB 690 bill could eventually narrow one piece of this (the "pen register" theory), but it's still moving through the California legislature and won't touch broader wiretapping claims. If it passes, it could apply to claims going back two years, which is worth knowing if you've gotten a demand letter recently. Either way, it shouldn't change what a retailer does today.

Your Site Has to Respond to Signals It Can't See

A growing number of states require websites to recognize opt-out signals like Global Privacy Control (GPC) or other Universal Opt-Out Mechanisms (UOOM). This is a signal that individuals set up in their browser settings or via a plugin, and it automatically communicates "don't sell or share my data." 

Websites receiving the signal have to stop selling or sharing that visitor's data, and for California visitors, show something like an 'Opt-Out Signal Honored' message so visitors can see it actually worked.

Unlike a cookie banner, GPC doesn't wait for a click. A site either honors the signal or it doesn't. And depending on requirements and setup, the banner may not even be displayed.

That's a shift from posting a privacy policy and a cookie banner to something harder: detecting and responding to a signal you never see the visitor choose. For high-traffic retail sites, it’s a technical and legal requirement. And the marketing team probably has something to say about it as well.

What to Do Before Peak Traffic Hits

None of this is settled, and none of it is slowing down. More states are joining the list, lawsuits are still being filed, and opt-out signal requirements keep expanding. 

For a retailer heading into the highest-traffic, highest-tracking weeks of the year, Black Friday and Cyber Monday are exactly the wrong time to find out a tag or tracker is out of step with what the law now expects. 

There's a bigger shift worth planning for, too. Given the direction all of this is heading, it's worth starting to treat the U.S. more like an opt-in consent market, closer to how the EU already works, rather than the opt-out approach it's had until now. 

Adjusting site and marketing setups with that in mind now, rather than waiting for a CIPA demand letter or a specific law to force it, can help protect the data and campaign performance you're already relying on, not just reduce legal exposure.