Key Point: A multistate coalition of 42 state AGs reached a landmark $150 million settlement with 23andMe over a 2023 data breach affecting 6.9 million customers, marking the largest AG multistate settlement involving consumer genetic data to date. This resolution signals heightened regulatory scrutiny of genetic data security practices and establishes a precedent for state enforcement authority in bankruptcy proceedings.

Key points: Troutman Pepper Locke’s Regulatory Investigations, Strategy + Enforcement (RISE) and Privacy + Cyber + AI practice groups worked with the firm’s innovation team using AI to collect and curate five years of data concerning state AG activities and actions related to privacy, security, and AI. This Regulatory

On June 30, 2026, New Jersey enacted legislation A5328 (P.L.2026, c.25), which will expose a broad swath of U.S. companies to data broker registration fees ranging from $5,000 to $1.5 million annually. The new legislation is not limited to data brokers in the conventional sense. It applies generally to any company that sells or licenses personal data of New Jersey residents, including those with direct customer relationships. Much of the law takes effect immediately, so companies should begin reviewing the requirements now to comply.

In the prior Part 4 of this series, we explained how CCPA cybersecurity audits are likely to surface in CalPrivacy and California Attorney General enforcement actions, and how that regime impacts governance and executive responsibility.

In this episode of The Consumer Finance Podcast, Chris Willis is joined by Troutman Pepper Locke Partners Stefanie Jackman and Brent Hoard to take a close look at the world of medical debt collection. The discussion covers how HIPAA applies to medical debt, what it really means to be a “business associate,” and common privacy challenges that can turn routine collection efforts into regulatory headaches. They also focus on key federal and state debt collection regimes, including the FDCPA, the No Surprises Act, and increasingly complex credit reporting requirements. The group provides insight on collection strategies for health care providers and third-party collectors that are both compliant and workable in practice. For anyone handling medical-related receivables, this episode serves as a practical guide to safeguarding patient information, maintaining tax-exempt status, and enhancing collections while staying within regulatory boundaries.

In Parts 1-3 of this series, we covered the mechanics of the CCPA’s new cybersecurity audit requirement: who is covered, when audits are required, what must be audited, who can perform the audit, how it fits with existing security frameworks, and what needs to be documented.

A federal court in Michigan significantly narrowed Michigan Attorney General (AG) Dana Nessel’s privacy and consumer protection case against Roku, Inc. (Roku) dismissing all non-Children’s Online Privacy Protection Act (COPPA) claims for lack of standing while allowing the state’s privacy claims under COPPA to proceed. The decision highlights COPPA’s utility as a vehicle for state AGs to bring enforcement actions in federal court, while also underscoring the jurisdictional limits on bringing companion state privacy and consumer protection claims in the same forum.

In Part 1 of this series, we outlined the basics of the California Consumer Privacy Act’s (CCPA) new cybersecurity audit requirement: who is covered, when audits are required, and the key obligations to keep in mind. In Part 2, we explored the mechanics and explained what the California Privacy Protection Agency (CalPrivacy) expects the cybersecurity audit to look like in practice, including what must be evaluated, who may conduct the audit, how thorough it must be, and what goes into the audit report.

On March 16, 2026, New York Attorney General (AG) Letitia James rallied in support of the “One Fair Price Package” — a pair of bills aimed at curbing algorithmic and surveillance pricing in New York. Together, the bills would prohibit the use of personalized algorithmic pricing based on consumer data, ban electronic shelf labels in large food and drug retailers, and create robust enforcement mechanisms and private rights of action. The announcement from New York comes shortly after New Jersey Governor Mikie Sherrill backed legislation to ban what she has called “surveillance” pricing, and after California Attorney General Rob Bonta announced an investigative sweep focused on businesses that use consumer data to individualize prices for their goods or services earlier this year.

In Part 1 of this series, we walked through the basics of the California Consumer Privacy Act’s (CCPA) new cybersecurity audit requirement: which businesses are covered, when audits are required, and the high-level obligations to have on your radar.