On August 4, 2026, the Vermont Attorney General's office puts out a short announcement. Vermont is joining something called the Consortium of Privacy Regulators — a bipartisan group of state privacy enforcers who share investigative work, compare findings, and coordinate strategy across state lines. It is not a dramatic document. It reads like housekeeping.
It is the ninth member. The group launched in April 2025 with the California Privacy Protection Agency and the attorneys general of California, Colorado, Connecticut, Delaware, Indiana, New Jersey, and Oregon. Five months after it formed, four of those regulators ran a joint investigative sweep on the same day, looking at businesses that were ignoring browser-level opt-out signals.
Now hold that next to a second change almost nobody announced. For the first three years of US state privacy law, nearly every statute came with a right to cure — a window, usually thirty days, in which a company that got a regulator's letter could fix the problem and make the matter go away. Connecticut's expired at the end of 2024. Colorado's expired at the start of 2025. Delaware's and Oregon's expired on January 1 of this year. Montana's expired April 1. Tennessee's expired July 15.
I have watched a lot of companies treat that window as their privacy program. Not deliberately — nobody would approve that in writing. It just became the operating reality: build the feature, launch it, and if somebody official ever writes, fix it then.
So what happens to a compliance strategy built on getting a warning, in a year when the warning stopped coming and the people who would have sent it started working together?
What actually changed, and when#
Three separate things moved between January 2025 and August 2026. Individually each is a footnote. Together they change the arithmetic.
The cure periods closed
A right to cure is a statutory second chance. The regulator identifies a violation, sends notice, and the company gets a defined window — thirty days in most states — to fix it. Fix it in time and the matter closes with no penalty. Think of it as a building inspector who has to give you a correction notice before writing a fine.
That was the default when these laws arrived. It is not the default now. Connecticut's sunset on December 31, 2024. Colorado's on January 1, 2025. Delaware's and Oregon's on January 1, 2026. Montana's on April 1, 2026. Tennessee's on July 15, 2026. Minnesota's sunsets later this year.
The pattern is not universal, and the exceptions matter. Indiana and Kentucky, whose comprehensive laws both took effect on January 1, 2026, went deliberately the other way — each wrote in a permanent thirty-day cure period that does not sunset. Indiana pairs it with a ceiling of $7,500 per violation. Several other states keep cure at the regulator's discretion rather than as a right.
So the honest version is narrower than "the grace period is gone." It is this: the grace period is gone in most of the states whose regulators actually bring cases, and it survives in some of the states that so far have not. If your mental model of enforcement was built between 2023 and 2025, it is now calibrated to a set of rules that no longer describes the states most likely to contact you.
The regulators started working together
The Consortium of Privacy Regulators was announced by California's privacy agency on April 16, 2025. The stated purpose is unglamorous: share expertise, share resources, coordinate strategy on potential violations of state privacy laws. Vermont's August 4, 2026 announcement brought it to at least nine.
The thing to understand is what coordination does to the shape of an investigation rather than its severity. On September 9, 2025, California's privacy agency and the attorneys general of California, Colorado, and Connecticut ran a joint sweep targeting businesses that were not honoring Global Privacy Control signals — the browser setting that tells a website "do not sell or share my data," which the law in several states requires you to obey automatically.
One sweep. One day. Four regulators. Same defect.
The old planning assumption was sequential: California would find something first, you would learn from it, and you would remediate everywhere else on your own schedule before anyone noticed. That assumption does not survive four regulators opening the same question on the same morning.
I want to be careful not to oversell this. The consortium is a coordination and information-sharing body, not a joint enforcement authority. Each regulator still acts under its own statute, and there is no consolidated multi-state penalty mechanism. What changed is discovery and timing, not legal power. That is still a meaningful change, because discovery and timing were where most companies had their slack.
The numbers stopped being symbolic
On May 8, 2026, California's Attorney General, several California district attorneys, and the state privacy agency together announced a $12.75 million settlement with General Motors and its connected-vehicle service OnStar. The allegation was that the companies collected and sold vehicle-generated data — including precise location and driving behavior — from hundreds of thousands of California drivers to data brokers, without adequate notice or consent. Alongside the penalty came injunctive terms, including a ban on selling driving data to data brokers. The settlement is subject to court approval.
It is the largest penalty under California's privacy law to date. But the dollar figure is not the part that should change how you think.
This was the first enforcement action built on data minimization and purpose limitation — the principle that you may only collect what you actually need for the purpose you told people about, and may only use it for that purpose. Every prior headline action turned on something visible going wrong: a broken opt-out, a deceptive interface, a breach. Data minimization needs none of those. It asks a question you can answer by reading your own data model: are you collecting more than the stated purpose requires?
The smaller 2026 actions fill in the rest of the picture, and they are more representative of ordinary risk. Disney and ABC settled for $2.75 million in February over gaps in how opt-out worked across their streaming services. PlayOn Sports paid $1.1 million in March over student data and dark patterns. Ford paid $375,703 in March over friction in its opt-out flow. By one running tally, California's privacy penalties now exceed $24.6 million since the first action in August 2022.
Notice what those three have in common. Not deep governance failures — front-end implementation defects. An opt-out that did not fully work. A flow with friction in it. That is the failure mode most companies actually have, and it is one an ordinary engineering team can find and fix.
The part that is genuinely not urgent#
If I stopped here I would be selling you a panic, and the record does not support one.
Most of the heavy new machinery in California's updated rules is not enforceable for years. The regulations covering automated decisionmaking technology, risk assessments, and cybersecurity audits took effect January 1, 2026 — but the substantive deadlines are staggered well past it. Automated decisionmaking compliance is due January 1, 2027. Risk assessments for activities that started before 2026 must be conducted by December 31, 2027, with attestations to the agency by April 1, 2028. Cybersecurity audit certifications are tiered by revenue: April 1, 2028 for businesses over $100 million, April 1, 2029 for $50–100 million, and April 1, 2030 for those under $50 million.
If you are a company under $50 million in revenue, your first cybersecurity audit certification is due in 2030. Anyone selling you an audit program this quarter on the strength of that date is selling you three and a half years of shelf life.
There is a second honest qualifier. Every eight-figure action so far is California, which has a dedicated privacy agency no other state has. Extrapolating California's tempo to all twenty states would overstate what is likely to happen elsewhere in the next year.
And a third: the per-violation ceilings are modest — $2,663 for an unintentional violation, $7,988 for an intentional one or one involving a minor's data. The enormous totals come from multiplying small numbers by large consumer populations. That is a volume problem. If your consumer footprint is small, your exposure arithmetic is different, and pretending otherwise would be dishonest.
So what is live right now, with no future date attached? Two things. The cure sunsets, which are already in force. And one obligation that is not a filing deadline at all.
Data minimization does not require a breach, a complaint, or a failed opt-out. It only requires that you collected more than you needed.
The obligation that is a precondition, not a deadline#
Data protection assessments — structured written evaluations of a processing activity's risk, sometimes called DPIAs — are now required across at least fifteen state laws before you engage in certain high-risk processing. The categories are consistent: targeted advertising, selling data, profiling, and processing sensitive data.
Here is the detail that gets missed. For activities created or generated on or after January 1, 2026, the assessment must be completed before the processing begins.
That is a different kind of rule than everything else in this post. An attestation due in April 2028 is a deadline — you can be late, and lateness is the violation. A precondition cannot be late. If you launched a profiling feature in March 2026 without an assessment, the feature was non-compliant on the day it went live, and doing the assessment now does not retroactively make the launch compliant. It just stops the clock running.
For most companies that is the single most likely place to be quietly out of compliance right now, because assessment-before-launch is a gate that has to exist in the product process, and in most organizations no such gate exists.
How This Impacts Your Organization#
The principle does not change with company size: the rules that used to forgive a first mistake mostly stopped, and the people enforcing them stopped working in isolation. What changes is whether you have a process gate to put this in, how much slack you have when several regulators arrive at once, and whether you are in scope at all.
Large Enterprises (1,000+ employees)
Your legal team already knows the cure periods sunset. That is not the gap. The gap is that the operational teams who would actually receive and act on a regulator's notice still carry a playbook built between 2023 and 2025, when a letter meant thirty days and a remediation ticket. The stale artifact is the runbook, not the statute.
The real risk here is organizational and it is about simultaneity. Your privacy obligations are distributed — web properties under marketing, opt-out plumbing under engineering, data sales relationships under partnerships, retention defaults under whoever built the warehouse. That distribution was survivable when regulators arrived one at a time. It is much less survivable when four of them open the same question on the same morning and each expects a response under its own statute and its own timeline.
Your leverage is that you can put a gate where things already pass. You have a launch review, a privacy review, a data-governance forum — some venue every new processing activity already crosses.
The concrete organizational move: name a single owner for multi-state regulatory response, and give that person the authority to convene across those four functions without escalating. Then have them run one exercise — not a real incident, a tabletop — where three states ask the same question in the same week. You will learn more from the calendar conflicts than from the answers.
Mid-Size Organizations (100–999 employees)
You are the most exposed segment here, and the reason is specific: the cure period was doing more work for you than for anyone else. Without a privacy function, "launch it and fix it if someone writes" was not negligence — it was a rational allocation of scarce attention when the statute genuinely offered a second chance. The statute stopped offering it. The allocation did not change.
The overcorrection to avoid: do not stand up a privacy program to solve this. I have watched companies your size respond to a headline like the GM settlement by scoping a privacy office, buying a governance platform, and commissioning a data inventory that takes two quarters. Meanwhile the actual defects that generated the 2026 enforcement actions — an opt-out that does not fully propagate, a consent flow with friction, an ignored browser signal — are still sitting in production, because none of them were on the platform's roadmap.
Three moves, none of which require a privacy hire:
- Test your own opt-out end to end, as a customer, and follow the data. Not "is there a link" — does the request actually reach every downstream system that holds the record, including your analytics and advertising vendors? This is where Ford and Disney got caught.
- Check whether your site honors Global Privacy Control. That is the exact defect four regulators swept for in September 2025, it is automated, and it is a small engineering fix.
- Put an assessment gate in your launch checklist for anything involving targeted advertising, profiling, data sales, or sensitive data. One page, before launch. It is a precondition, not paperwork you can file later.
Small & Growing Organizations (under 100 employees)
Start with the part most articles will not tell you: you may simply not be covered.
Most state comprehensive privacy laws have applicability thresholds, and most genuinely small companies fall below them. Indiana and Kentucky use Virginia-style thresholds that exempt many smaller organizations. Rhode Island's threshold is lower for businesses driven by data sales. The notable outlier is Texas, which has little to no minimum threshold and therefore catches companies the others miss. And where you are covered in Indiana or Kentucky, that permanent thirty-day cure period is a real cushion that larger-state companies no longer have.
So the first move is not remediation, it is scoping. Find out which laws actually apply to you before spending anything. That is an afternoon with your customer geography and your revenue numbers, and for many companies the honest answer is "two states, and we are under the threshold in one of them."
What I would tell you not to do: do not buy a privacy governance platform, do not commission a data inventory from a consultancy, and do not start a cybersecurity audit program because you read about one. Your certification date, if you ever have one, is 2030.
What is worth doing regardless of scope, because it is nearly free and it is what the sweeps target: make sure your website honors the browser opt-out signal, and make sure that when someone asks you to delete their data, it actually gets deleted everywhere rather than just in the system you thought of first. Both are small. Both are what regulators check when they check anything.
What to do Monday morning#
- Test your own opt-out as a customer, end to end. Submit the request from your own site, then go look in every system that holds that record — your CRM, your analytics, your email platform, your advertising integrations. The 2026 enforcement actions against Ford and Disney were about opt-outs that existed but did not fully work. Free, and it takes an afternoon.
- Check whether you honor Global Privacy Control. Turn the signal on in a browser, visit your own site, and verify the behavior changes. This is the precise defect four regulators swept for jointly in September 2025. It is automated, it is visible from outside your company, and it is a small fix.
- Add an assessment gate to your launch checklist. Any new activity involving targeted advertising, profiling, data sales, or sensitive data needs a written assessment before it starts. This is a precondition, not a deadline — you cannot do it late. One page in the process you already use.
- Ask one question about retention: what are we collecting that we do not need? The GM action was the first built on data minimization, which does not require anything to break. Pick your two largest data stores and ask what the stated purpose was and whether the fields still match it. This is a reading exercise against your own data model.
- Write down which state laws actually apply to you. Customer geography against each state's threshold. This is a meeting, not a technical change, and it should include whoever owns revenue data. Many companies are simultaneously assuming they are in scope when budgeting and out of scope when acting — pick one, and record the reasoning and the date.
- Update the runbook that assumes you get thirty days. If you have an incident or inquiry response document written before 2025, it almost certainly promises a cure window that no longer exists in Connecticut, Colorado, Delaware, Oregon, Montana, or Tennessee. Fix the document while nothing is happening.
- Put the real dates on the calendar, not the scary ones. Automated decisionmaking compliance January 1, 2027. Risk assessments conducted by December 31, 2027, attested by April 1, 2028. Cybersecurity audit certification April 1, 2028, 2029, or 2030 depending on your revenue. Knowing which of those is yours is the difference between planning and worrying.
If you want a place to start#
The new California rules eventually require an annual cybersecurity audit with a written certification, and the preparation work for that is ordinary control-assessment discipline — inventory what you have, assess it against a recognized framework, evidence the gaps. A NIST CSF readiness toolkit produces exactly that artifact, and it produces it in a form that is useful whether or not the audit requirement ever reaches you. If you already run a SOC 2 program, the more useful observation is that you are probably generating most of the evidence that audit will ask for — access control, change management, monitoring — and the work is reuse and mapping rather than a second program. This post is independent of those offerings; the seven actions above cost nothing and stand on their own.
The uncomfortable truth#
So what happens to a compliance strategy built on getting a warning first? It quietly stops being a strategy, and in most cases nobody circulates a memo about it. That is the whole story of the last eighteen months: nothing dramatic was announced, a safety net was withdrawn one state at a time, and the enforcement side got better organized while the compliance side kept running a playbook written for the old arrangement.
I do not think the right response is alarm. Most of the eight-figure numbers involve vehicle telematics, children's data, and data-broker sales, which is not most companies' business. Most of the heavy audit machinery is years out. Plenty of small companies are genuinely out of scope. Anyone using the GM figure to sell you a program this quarter is being imprecise about who that number was actually for.
The right response is narrower and duller. Two things are live right now with no future date attached — the cure periods that already expired, and the requirement to assess high-risk processing before you start it. Both are cheap to address. Neither requires a platform, a hire, or a consultant.
Over the next year I expect the consortium to keep growing and the joint sweeps to keep targeting automated, externally visible signals, because those scale and they do not require a complaint to initiate. Which means the things most likely to get you noticed are also the things easiest to check from your own laptop this week.
That is an unusually fair deal, as regulatory exposure goes. I would take it while it is still on offer.
— Charles Redding, Founder, DLegendDigital
About the author
Charles Redding
Founder of DLegendDigital. 35+ years of enterprise technology leadership across audit, risk management, cybersecurity, and AI. Former CIO, VP of Technology, and Director at organizations ranging from high-growth startups to $4.3B global enterprises.



