Connecticut, Arkansas, and Utah made their comprehensive privacy laws enforceable on July 1, adding a new wave of state-specific consent and opt-out rules for marketers to track this year

  • Tension: Compliance teams keep treating each new state privacy law as a one-off box to check, while the real shift is structural — the thresholds for who counts as “covered” keep dropping, and businesses that assumed they were exempt are finding out otherwise.
  • Noise: Coverage of these laws typically treats each state in isolation — Connecticut did this, Arkansas did that — which obscures that this is one uncoordinated patchwork expanding on a rolling basis, with no federal law to unify it.
  • Direct Message: Twenty states now run their own privacy regime, and three of them just rewrote the rules again. The question isn’t whether a compliance program covers state privacy law. It’s whether it still covers the version of that law that existed as of July 1.

To learn more about our editorial approach, explore The Direct Message methodology.

Three states changed what counts as lawful handling of personal data on the same day this month, and the changes didn’t move in the same direction. Connecticut widened who has to comply. Arkansas closed a specific loophole around advertising to minors. Utah added a consumer right that most other states already had. None of it was coordinated, and none of it is the last change coming this year.

Connecticut lowers the bar for who counts as covered

Amendments to Connecticut’s Data Privacy Act, passed as SB 1295, took effect July 1 and cut the applicability threshold from 100,000 consumers to 35,000. That alone pulls a meaningful number of smaller businesses into scope for the first time. More significant is the second change sitting next to it: any organization that processes sensitive data or sells personal data now falls under the law regardless of volume, a shift away from the purely threshold-based approach the original CTDPA used.

The amendments also narrow a major carve-out. The prior exemption for entities covered by the Gramm-Leach-Bliley Act applied at the entity level — if a business was a financial institution, its data was largely out of scope. That’s now a data-level exemption, meaning only the specific data covered by GLBA is excluded, not everything the business touches. Connecticut also expanded its definition of sensitive data to include government-issued identifiers, financial account information, Social Security numbers, neural data, and certain biometric or genetic data, and made clear that none of it can be sold without consent.

Two other changes matter specifically for marketing operations: the profiling opt-out no longer applies only to decisions based solely on automated processing, and businesses now have to disclose if personal data is used to train large language models. Companies that assumed an LLM-training disclosure requirement was a hypothetical future problem now have a live one.

Arkansas bans targeted advertising to minors outright

Arkansas’s Children and Teens’ Online Privacy Protection Act, HB 1717, also became enforceable July 1. It applies to for-profit operators of sites, apps, and online services that are either directed at children and teens or have actual knowledge they’re collecting a minor’s personal data — nonprofits, government bodies, and educational institutions are excluded.

The law sets up a two-tiered consent structure for general data processing: parental consent is required for children 12 and under, while users 13 to 16 can provide consent themselves or through a parent. But on advertising specifically, there’s no tiering and no exception. Targeted advertising based on a minor’s personal data is prohibited outright, and data minimization rules restrict both what can be collected from minors and how long it can be retained. Enforcement rests exclusively with the Arkansas Attorney General — the law doesn’t create a private right of action, so the exposure here is regulatory rather than litigation risk.

Utah adds a right to correct and a portability mandate

Utah’s changes are narrower but still meaningful. Amendments to the Utah Consumer Privacy Act, HB 418, add a right to correct inaccurate personal data — a right that already existed in most other comprehensive state laws and that Utah had, until now, left out. The same amendments impose new data portability and interoperability obligations specifically on social media platforms, requiring them to let Utah consumers export their personal data in a machine-readable format. The broader UCPA enforcement structure is unchanged.

July 1 wasn’t the year’s first compliance deadline — it’s the second of at least five

July 1 wasn’t the first deadline of 2026. New comprehensive privacy laws in Indiana, Kentucky, and Rhode Island took effect January 1, bringing the total number of states with comprehensive privacy laws in effect this year to twenty, according to the International Association of Privacy Professionals. The MultiState policy tracker lists January 1, July 1, and August 1 as the three major 2026 effective dates for state privacy obligations, with California’s expanded data broker registration requirements landing on the last of those.

More is already scheduled. New impact assessment obligations for high-risk processing under Connecticut’s amended law begin August 1, alongside California’s Delete Act broker mechanism becoming fully operational. Additional CTDPA amendments follow October 1. Oklahoma’s comprehensive privacy law takes effect January 1, 2027, and Alabama’s follows that May.

What it means for marketing operations specifically

The pattern across all three July 1 changes is the same: each one narrows an exemption, lowers a threshold, or closes a gap that existed the day before. Connecticut’s data-level GLBA exemption means marketing teams at financial institutions can no longer assume blanket exclusion. Its broadened profiling opt-out reaches further into personalization and ad-targeting workflows than the original law did. Arkansas’s flat ban on targeted advertising to minors removes the consent-based workaround that existed for other categories of data processing under the same law. None of these are edge cases — they’re the parts of the law that touch how marketing data actually gets used.

Compliance programs built around last year’s map of state privacy law are compliance programs built around a map that’s already out of date. The next redraw is five weeks away.

Picture of Direct Message News

Direct Message News

Direct Message News is the byline under which DMNews publishes its editorial output. Our team produces content across psychology, politics, culture, digital, analysis, and news, applying the Direct Message methodology of moving beyond surface takes to deliver real clarity. Articles reflect our team's collective editorial process, sourcing, drafting, fact-checking, editing, and review, rather than a single writer's work. DMNews takes editorial responsibility for content under this byline. For more on how we work, see our editorial standards.

MOST RECENT ARTICLES

Marketing automation platforms spent the first half of 2026 compressing the time from insight to campaign launch from days to minutes, and the fight nobody is naming yet is over who owns that layer of intelligence, not who owns the software

Zeta Global tracked what AI shoppers do before they buy — seven in ten still complete the purchase on the brand’s own site, but the data suggests AI has already shaped which brand that would be

Illinois directed its economic development agency to stop processing new data center tax deals starting this July, after lawmakers left Springfield without passing the reforms the governor asked for

Indiana disclosed this year that more than 93 percent of its data center tax exemption went to a single company, with that one recipient’s share increasing by 1,011 percent in a single year

Virginia projected its data center tax exemption would cost $1.5 million a year when it was created in 2008. In fiscal 2025, the state’s own report put the actual cost at $1.9 billion — a gap that has become a reference point in data center tax debates in more than a dozen other states.

AI has not solved marketing’s measurement problem, it has raised the stakes, because boards now expect proof of ROI at the same time as the tools that were supposed to provide it have made attribution harder to defend