- Tension: Compliance teams keep treating each new state privacy law as a one-off box to check, while the real shift is structural — the thresholds for who counts as “covered” keep dropping, and businesses that assumed they were exempt are finding out otherwise.
- Noise: Coverage of these laws typically treats each state in isolation — Connecticut did this, Arkansas did that — which obscures that this is one uncoordinated patchwork expanding on a rolling basis, with no federal law to unify it.
- Direct Message: Twenty states now run their own privacy regime, and three of them just rewrote the rules again. The question isn’t whether a compliance program covers state privacy law. It’s whether it still covers the version of that law that existed as of July 1.
To learn more about our editorial approach, explore The Direct Message methodology.
Three states changed what counts as lawful handling of personal data on the same day this month, and the changes didn’t move in the same direction. Connecticut widened who has to comply. Arkansas closed a specific loophole around advertising to minors. Utah added a consumer right that most other states already had. None of it was coordinated, and none of it is the last change coming this year.
Connecticut lowers the bar for who counts as covered
Amendments to Connecticut’s Data Privacy Act, passed as SB 1295, took effect July 1 and cut the applicability threshold from 100,000 consumers to 35,000. That alone pulls a meaningful number of smaller businesses into scope for the first time. More significant is the second change sitting next to it: any organization that processes sensitive data or sells personal data now falls under the law regardless of volume, a shift away from the purely threshold-based approach the original CTDPA used.
The amendments also narrow a major carve-out. The prior exemption for entities covered by the Gramm-Leach-Bliley Act applied at the entity level — if a business was a financial institution, its data was largely out of scope. That’s now a data-level exemption, meaning only the specific data covered by GLBA is excluded, not everything the business touches. Connecticut also expanded its definition of sensitive data to include government-issued identifiers, financial account information, Social Security numbers, neural data, and certain biometric or genetic data, and made clear that none of it can be sold without consent.
Two other changes matter specifically for marketing operations: the profiling opt-out no longer applies only to decisions based solely on automated processing, and businesses now have to disclose if personal data is used to train large language models. Companies that assumed an LLM-training disclosure requirement was a hypothetical future problem now have a live one.
Arkansas bans targeted advertising to minors outright
Arkansas’s Children and Teens’ Online Privacy Protection Act, HB 1717, also became enforceable July 1. It applies to for-profit operators of sites, apps, and online services that are either directed at children and teens or have actual knowledge they’re collecting a minor’s personal data — nonprofits, government bodies, and educational institutions are excluded.
The law sets up a two-tiered consent structure for general data processing: parental consent is required for children 12 and under, while users 13 to 16 can provide consent themselves or through a parent. But on advertising specifically, there’s no tiering and no exception. Targeted advertising based on a minor’s personal data is prohibited outright, and data minimization rules restrict both what can be collected from minors and how long it can be retained. Enforcement rests exclusively with the Arkansas Attorney General — the law doesn’t create a private right of action, so the exposure here is regulatory rather than litigation risk.
Utah adds a right to correct and a portability mandate
Utah’s changes are narrower but still meaningful. Amendments to the Utah Consumer Privacy Act, HB 418, add a right to correct inaccurate personal data — a right that already existed in most other comprehensive state laws and that Utah had, until now, left out. The same amendments impose new data portability and interoperability obligations specifically on social media platforms, requiring them to let Utah consumers export their personal data in a machine-readable format. The broader UCPA enforcement structure is unchanged.
July 1 wasn’t the year’s first compliance deadline — it’s the second of at least five
July 1 wasn’t the first deadline of 2026. New comprehensive privacy laws in Indiana, Kentucky, and Rhode Island took effect January 1, bringing the total number of states with comprehensive privacy laws in effect this year to twenty, according to the International Association of Privacy Professionals. The MultiState policy tracker lists January 1, July 1, and August 1 as the three major 2026 effective dates for state privacy obligations, with California’s expanded data broker registration requirements landing on the last of those.
More is already scheduled. New impact assessment obligations for high-risk processing under Connecticut’s amended law begin August 1, alongside California’s Delete Act broker mechanism becoming fully operational. Additional CTDPA amendments follow October 1. Oklahoma’s comprehensive privacy law takes effect January 1, 2027, and Alabama’s follows that May.
What it means for marketing operations specifically
The pattern across all three July 1 changes is the same: each one narrows an exemption, lowers a threshold, or closes a gap that existed the day before. Connecticut’s data-level GLBA exemption means marketing teams at financial institutions can no longer assume blanket exclusion. Its broadened profiling opt-out reaches further into personalization and ad-targeting workflows than the original law did. Arkansas’s flat ban on targeted advertising to minors removes the consent-based workaround that existed for other categories of data processing under the same law. None of these are edge cases — they’re the parts of the law that touch how marketing data actually gets used.
Compliance programs built around last year’s map of state privacy law are compliance programs built around a map that’s already out of date. The next redraw is five weeks away.