Three US states begin privacy law enforcement as cure periods expire

Organizations can now face immediate fines for privacy violations in multiple states, with no grace period to fix problems first.

Illustration: Three US states begin privacy law enforcement as cure periods expire
AI-generated illustration · Sylvaris

New laws, immediate enforcement

On January 1, 2026, comprehensive consumer privacy laws in Indiana, Kentucky, and Rhode Island took effect. All three grant consumers rights to access, delete, correct, and port their data, and require opt-in consent for processing sensitive personal information. Enforcement authority rests exclusively with state attorneys general, with civil penalties ranging from $7,500 to $10,000 per violation.

What makes the 2026 wave different is timing. Delaware's 60-day cure period—a grace window allowing companies to fix violations before facing penalties—ended December 31, 2025. Montana's cure period expires April 1, 2026, and New Jersey's expires mid-2026. For organizations that relied on cure windows as a buffer against fines, that safety net is disappearing.

California tightens the ratchet

Updated California Consumer Privacy Act regulations became operational on January 1, 2026, transforming compliance from a checkbox exercise into ongoing operational discipline. The changes broaden annual cybersecurity audit requirements, mandate risk assessments before high-risk data processing, and expand automated decision-making technology disclosure obligations.

California also accelerated data breach notification timelines dramatically. Senate Bill 446 now requires businesses to notify affected California residents within 30 calendar days of discovering a breach, with attorney general reports due 15 days after consumer notification. The compressed timeline demands robust incident response capabilities and comprehensive data mapping to quickly identify affected individuals.

What changed behind the scenes

The January 2026 shift marks a transition from privacy as disclosure to privacy as infrastructure. Multiple jurisdictions now embed privacy expectations into the architecture of consent, identity, and data portability itself. Organizations must treat privacy as a design problem requiring technical controls, not just paperwork.

Browser-based opt-out signals became legally enforceable under California's AB 566. Web browsers must now include one-step opt-out preference settings that businesses must honor, fundamentally changing how consumers exercise privacy rights. Companies can no longer rely on complex opt-out mechanisms designed to discourage action. With Colorado's AI Act taking effect June 30, 2026 and California's automated decision-making technology compliance obligations triggering January 1, 2027, the strategic window for reactive privacy approaches has closed.

sources
more in Privacy & Regulation
FCC eliminates broadband fee transparency requirements after ISP complaints Internet providers no longer must display all fees upfront in nutrition-label format, reducing price transparency for consumers shopping for broadband service. Ireland delays €1 billion Microsoft procurement following digital sovereignty concerns European governments increasingly scrutinize single-vendor cloud contracts as digital sovereignty concerns prompt reconsideration of dependencies on U.S. technology providers. LG bans residential proxy apps from Smart TV platform Smart TVs have been routing third-party traffic through home networks without clear user consent, creating privacy and security risks.