On June 30, 2026, New Jersey enacted legislation A5328 (P.L.2026, c.25), which will expose a broad swath of U.S. companies to data broker registration fees ranging from $5,000 to $1.5 million annually. The new legislation is not limited to data brokers in the conventional sense. It applies generally to any company that sells or licenses personal data of New Jersey residents, including those with direct customer relationships. Much of the law takes effect immediately, so companies should begin reviewing the requirements now to comply.

Key point: Amendments to California Senate Bill (SB) 690 would foreclose private rights of action for pen register and trap and trace law and apply to cases brought within previous two years.

The Privacy and Consumer Protection Committee of the California State Assembly heard testimony on support and opposition to SB 690 late Wednesday, July 1.

In the prior Part 4 of this series, we explained how CCPA cybersecurity audits are likely to surface in CalPrivacy and California Attorney General enforcement actions, and how that regime impacts governance and executive responsibility.

We have now had a bit of time to work with clients on the new Colorado Automated Decision-Making Technology in Consequential Decisions Bill (SB 26-189) (ADMT law” — replacing the CO AI Act). The sausage making and behind-the-scenes political machinations were interesting to watch unfold. Ultimately, the ADMT law succeeds in narrowing or eliminating many of the more onerous requirements of the CO AI Act, including disparate impact risk assessment requirements, notification obligations to the Attorney General upon discovery of algorithmic discrimination (within 90 days), and the AI framework-compliance affirmative defense.

Key point: Two courts in 2026 have allowed CCPA claims to proceed based on adtech use without addressing whether adtech discloses “personal information” under the CCPA

According to plaintiffs’ interpretation of a May 2026 decision from the Northern District of California, if your company uses Google Analytics, Meta Pixel, or other third-party tracking technology on its website, you may be exposed to not only wiretapping or trap-and-trace claims under the California Invasion of Privacy Act (CIPA) or federal law, but also claims under the California Consumer Privacy Act (CCPA) even if you never experience a data breach.

Key point: In response to an open records request submitted by Troutman Pepper Locke, the New Jersey Attorney General’s office provided copies of all cure letters sent pursuant to New Jersey’s consumer data privacy law and resolved by the recipient.

As shown by recent enforcement actions in California, including its most recent $12.5 million fine, the risk for companies that are out of compliance with state consumer data privacy laws has never been higher. As more state laws go into effect and cure periods sunset, the risk will only grow. One state where the enforcement risk may be higher is New Jersey.

Key Point: With the June 3, 2026, compliance deadline fast approaching, small firms subject to amended Regulation S‑P under the Gramm-Leach-Bliley Act (GLBA) should be in the final stages of updating their privacy and safeguards programs. In January 2026, the Securities and Exchange Commission (SEC) held an outreach event to help small firms comply with the amendments to Regulation S-P. This webinar was geared toward small firms in advance of the June 3, 2026, compliance deadline. The SEC highlighted new Regulation S-P compliance obligations, SEC exam team approaches moving forward, and held an examination workshop, which included an incident response tabletop discussion, review of a sample document request list, and a mock examination session.

On April 22, the U.S. House of Representatives Financial Services Committee and the Energy and Commerce Committee jointly unveiled a paired privacy package that, taken together, would substantially recast the federal obligations for the treatment of consumer data. The “Guidelines for Use, Access, and Responsible Disclosure of Financial Data Act” (the GUARD Financial Data Act) would update and enhance Title V of the Gramm‑Leach‑Bliley Act (GLBA) for financial institutions. The “Securing and Establishing Consumer Uniform Rights and Enforcement over Data Act” (the SECURE Data Act) would create a national, cross‑sector privacy framework that would have applicability and features similar to the current patchwork of state comprehensive privacy laws, with strong entity-level and data-level exemptions for financial institutions and financial data subject to GLBA (and for HIPAA-covered entities and business associates, certain nonprofits, and institutions of higher education).

In this episode of The Consumer Finance Podcast, Chris Willis is joined by Troutman Pepper Locke Partners Stefanie Jackman and Brent Hoard to take a close look at the world of medical debt collection. The discussion covers how HIPAA applies to medical debt, what it really means to be a “business associate,” and common privacy challenges that can turn routine collection efforts into regulatory headaches. They also focus on key federal and state debt collection regimes, including the FDCPA, the No Surprises Act, and increasingly complex credit reporting requirements. The group provides insight on collection strategies for health care providers and third-party collectors that are both compliant and workable in practice. For anyone handling medical-related receivables, this episode serves as a practical guide to safeguarding patient information, maintaining tax-exempt status, and enhancing collections while staying within regulatory boundaries.