Key point: Plaintiffs in Virginia have focused on a rarely tested state privacy statute with statutory damages that imposes notice-and-consent obligations on retailers that share or sell in-store customer data.

Most retailers have spent the last several years building their privacy compliance programs around the major comprehensive state privacy laws, such as Virginia’s Consumer Data Protection Act (CDPA), California’s Consumer Privacy Act (CCPA), and their counterparts in a dozen other states. A recent lawsuit filed in the Eastern District of Virginia is a reminder that older, narrower statutes can carry just as much litigation risk, and that the plaintiffs’ bar is actively looking for the next viable theory.

The statute at issue is the Virginia Personal Information Privacy Act (VPIPA). It has been on the books for decades. Until recently, however, it had produced exactly one lawsuit. That may be changing.

Key Point: A multistate coalition of 42 state AGs reached a landmark $150 million settlement with 23andMe over a 2023 data breach affecting 6.9 million customers, marking the largest AG multistate settlement involving consumer genetic data to date. This resolution signals heightened regulatory scrutiny of genetic data security practices and establishes a precedent for state enforcement authority in bankruptcy proceedings.

Key points: Troutman Pepper Locke’s Regulatory Investigations, Strategy + Enforcement (RISE) and Privacy + Cyber + AI practice groups worked with the firm’s innovation team using AI to collect and curate five years of data concerning state AG activities and actions related to privacy, security, and AI. This Regulatory

On June 26, 2026, Florida Attorney General (AG) James Uthmeier and Roku, Inc. announced a negotiated resolution of Florida’s enforcement action filed under the Florida Digital Bill of Rights (FDBR). Under the agreement, Roku will enhance its child protection features by giving parents greater control over their children’s streaming experience.

On June 30, 2026, New Jersey enacted legislation A5328 (P.L.2026, c.25), which will expose a broad swath of U.S. companies to data broker registration fees ranging from $5,000 to $1.5 million annually. The new legislation is not limited to data brokers in the conventional sense. It applies generally to any company that sells or licenses personal data of New Jersey residents, including those with direct customer relationships. Much of the law takes effect immediately, so companies should begin reviewing the requirements now to comply.

Key point: Amendments to California Senate Bill (SB) 690 would foreclose private rights of action for pen register and trap and trace law and apply to cases brought within previous two years.

The Privacy and Consumer Protection Committee of the California State Assembly heard testimony on support and opposition to SB 690 late Wednesday, July 1.

We have now had a bit of time to work with clients on the new Colorado Automated Decision-Making Technology in Consequential Decisions Bill (SB 26-189) (ADMT law” — replacing the CO AI Act). The sausage making and behind-the-scenes political machinations were interesting to watch unfold. Ultimately, the ADMT law succeeds in narrowing or eliminating many of the more onerous requirements of the CO AI Act, including disparate impact risk assessment requirements, notification obligations to the Attorney General upon discovery of algorithmic discrimination (within 90 days), and the AI framework-compliance affirmative defense.

Key point: Louisiana becomes the 22nd state — and third this year — to enact a consumer data privacy law, adopting a law similar to Texas’ law.

On May 29, 2026, Louisiana Governor Jeff Landry signed the Louisiana Data Privacy Act (SB 386) into law. Louisiana is the 22nd state to pass a broad consumer data privacy law. It is the third state — following Oklahoma and Alabama — to pass a law this year.

The new law largely tracks Texas’ law but with some notable differences we identify below.