Feature Data Privacy
State Privacy Law Enforcement in 2026: What Texas, California, and the New AG Consortium Mean for Financial Services
Texas filed the first-ever lawsuit under a state comprehensive privacy law in January 2025. California hit Disney with a $2.75 million CCPA fine in February 2026. Eight AGs now share enforcement intelligence through a formal consortium. The 'nobody is actually enforcing this' assumption is over.
Table of Contents
TL;DR
- Texas filed the first-ever enforcement action under a state comprehensive privacy law in January 2025 (against Allstate/Arity for geolocation data collection) and has investigated 200+ companies since June 2024
- California produced its largest-ever CCPA settlement in February 2026 — $2.75 million against Disney/ABC — while GM settled for $12.75 million over connected-car location data in the same month
- Eight state AGs formed a formal Privacy Enforcement Consortium in April 2025, meaning one state’s investigation now generates enforcement intelligence for seven others
- With 19 states having active comprehensive privacy laws and Colorado’s mandatory cure period expired, the window for low-consequence noncompliance is closing
For most of the four years that state comprehensive privacy laws have been on the books, enforcement looked like cure letters. A company got noticed, had 30 to 60 days to fix the identified issue, resolved it quietly, and moved on. Industry observers described a “regulatory adolescence” where the laws existed but real enforcement costs felt theoretical.
That model is breaking. Texas filed a lawsuit. California issued its largest-ever CCPA fine. And eight state attorneys general now share enforcement intelligence through a formal consortium that didn’t exist 18 months ago. The compliance calculus for financial services firms — banks, fintechs, credit unions, payment processors — changed, and a lot of compliance programs haven’t caught up.
Texas: The State That Actually Filed Suit
On January 13, 2025, Texas Attorney General Ken Paxton filed the first-ever enforcement action brought under any state comprehensive privacy law in the United States. The target was Allstate and its subsidiary Arity.
The allegations: Arity embedded software development kits (SDKs) into popular mobile apps — including Life360, GasBuddy, Fuel Rewards, and Routely — without adequate disclosure or consent, collecting precise geolocation data and driving behavior from Texas consumers. That data was allegedly sold to insurance companies, which used it to price auto insurance policies. Consumers using these apps had no meaningful understanding that their driving data was being monetized through a chain ending at their insurance carrier.
The case matters beyond the specific defendants. The SDK-in-app data collection model — where a company’s code lives inside a third-party application and harvests data from users who primarily interact with a different brand — is widespread in financial services. Advertising partnerships, risk scoring vendors, and telematics providers all use variations of this approach. The Allstate/Arity case signals that the Texas AG views undisclosed SDK-driven collection as actionable under TDPSA, not just as a policy concern.
Texas’s privacy enforcement footprint is broader than one lawsuit. Since launching the Data Privacy and Security Initiative in June 2024, the AG has investigated over 200 companies spanning data brokers, car manufacturers, social media platforms, and entities with ties to foreign adversaries. The enforcement context for the Allstate case includes two landmark settlements from prior Texas privacy actions: $1.4 billion from Meta for biometric data collection, and $1.375 billion from Google for location tracking violations. These settlements were under Texas’s biometric and deceptive trade practices laws, not TDPSA specifically — but they establish the AG’s willingness to pursue large-dollar enforcement, and they fund the investigation infrastructure that produces TDPSA actions.
TDPSA penalties cap at $7,500 per violation. The cure period is 30 days — the AG must provide written notice before filing. Unlike Colorado, Texas has not sunset its cure period, so the 30-day cure remains available. But the Allstate filing demonstrates that “cure period available” doesn’t mean “AG won’t sue.”
California: Two Enforcement Arms, Record Fines
California’s enforcement structure is unique and worth understanding clearly, because both enforcement pathways are active.
The California Privacy Protection Agency (CPPA) is an independent agency with authority to issue regulations and enforce CPRA directly. It can impose fines without filing in court. In September 2025, the CPPA issued a $1.35 million penalty against Tractor Supply Company — the largest penalty the CPPA had imposed up to that point — for failing to notify consumers and job applicants of their privacy rights, failing to maintain adequate service provider agreements, and failing to provide effective opt-out mechanisms. Importantly, this was primarily an employee and job-applicant data case, not a consumer financial data case.
The California Attorney General retains concurrent CCPA/CPRA enforcement authority. In February 2026, the AG announced the largest CCPA enforcement settlement to date: $2.75 million from Disney and ABC. The action alleged that Disney failed to fully effectuate consumer opt-out requests for data sale and sharing across Disney+, Hulu, and ESPN+ — specifically that the company linked consumer devices for targeted advertising purposes but failed to link those same devices for opt-out compliance. The practical problem: Disney’s systems could track that Device A and Device B belonged to the same user when serving ads, but claimed it couldn’t link those devices when processing opt-out requests. The AG concluded that’s not a technological limitation; it’s a compliance failure.
Also in February 2026, General Motors settled for $12.75 million over unlawful sale of driving and location data collected through its OnStar connected car service. GM allegedly collected and sold precise geolocation data from California drivers without adequate disclosure or consent. The financial services angle is direct: connected-vehicle data is increasingly used by auto insurance subsidiaries and fintech lenders for underwriting. The GM settlement puts the entire connected-car data ecosystem on notice.
Looking ahead: the California Delete Act begins active enforcement on August 1, 2026. Data brokers that fail to honor consumer deletion requests routed through the state’s centralized deletion mechanism face penalties of $200 per day per request not addressed. For financial services firms that sell consumer data to data brokers — or that operate data brokerage functions themselves — this is a live obligation, not a future one.
The AG Enforcement Consortium: Eight States, One Strategy
On April 16, 2025, eight privacy regulators announced the formation of the Consortium of Privacy Regulators:
- California Attorney General
- California Privacy Protection Agency (CPPA)
- Colorado Attorney General
- Connecticut Attorney General
- Delaware Attorney General
- Indiana Attorney General
- New Jersey Attorney General
- Oregon Attorney General
The Consortium’s stated purpose is to address multijurisdictional privacy issues with greater efficiency and consistency — sharing enforcement intelligence, investigative strategies, and compliance expectations across member jurisdictions.
The practical consequence: a California investigation that surfaces evidence of systematic opt-out failures, SDK-based data collection, or inadequate service provider agreements now generates intelligence that can inform enforcement actions in Colorado, Connecticut, Indiana, New Jersey, Oregon, and Delaware. Companies that treated each state’s enforcement as an isolated risk calculation must now treat Consortium-member states as a single enforcement zone for detection and evidence-sharing purposes.
Colorado’s position within the Consortium is worth specific attention. The mandatory 60-day cure period in the Colorado Privacy Act expired on January 1, 2025 — the AG can now file suit without providing cure notice. Colorado is also moving quickly on amendments: SB 24-041 (effective October 1, 2025) added heightened protections when a controller knows a user is a minor. And SB 25-276, effective August 12, 2026, will classify precise geolocation data as sensitive data under the Colorado Privacy Act — triggering higher consent and opt-out requirements for any Colorado-resident geolocation processing.
The 2026 State Privacy Landscape: What’s Active Now
As of June 2026, 19 states have active comprehensive consumer privacy laws. The two most recently activated laws most relevant for financial services teams:
| State | Law | Effective Date | Notable Features |
|---|---|---|---|
| Minnesota | Consumer Data Privacy Act (MNDPA) | July 31, 2025 | Right to question automated decisions; applies to 100K+ consumer data processors |
| New Jersey | New Jersey Data Privacy Law (NJDPA) | January 15, 2025 | Cure period expiring mid-2026; broad applicability |
| Colorado | Colorado Privacy Act (as amended) | Geolocation = sensitive data: August 12, 2026 | No cure period; AG is Consortium member |
| California | Delete Act enforcement | August 1, 2026 | $200/day per deletion request not addressed |
Minnesota’s MNDPA includes an unusual provision: consumers can question automated decisions made through profiling — not just receive opt-outs, but actively challenge automated outcomes affecting significant decisions. For fintechs using algorithmic credit decisioning, risk scoring, or fraud detection, this creates an obligation that goes beyond standard CCPA/CPRA disclosure requirements.
What This Means for Financial Services Firms
The GLBA safe harbor has limits. The GLBA exemption in most state privacy laws applies to data regulated under GLBA’s safeguards and privacy rules — consumer financial data covered by Regulation P. But GLBA doesn’t cover employee data, marketing data, app behavior data from non-customers, or data collected through third-party SDKs on partner apps. The Allstate/Arity case illustrates precisely the category of data that GLBA doesn’t protect: behavioral data collected through mobile app integrations, not from a financial services relationship.
Tracking pixels and SDKs in financial products. If your fintech or insurance subsidiary embeds third-party tracking SDKs in your mobile app — and most do, for analytics, attribution, and behavioral data — those SDKs may be collecting and transmitting data in ways that trigger state privacy law obligations. The Allstate/Arity enforcement framework applies equally to financial services apps. Audit your app’s third-party SDK inventory against your privacy notice and data processing agreements.
DSAR handling across 19 frameworks. Consumer data subject access requests (DSARs) — the right to know, delete, correct, and opt out — now exist across 19 state frameworks, each with slightly different timelines and scope. A unified DSAR response workflow that handles the most common state requirements (California, Texas, Colorado, Virginia, Connecticut) covers most of your exposure. See the DSAR response workflow for CCPA, GDPR, and state privacy laws for a practical process structure.
Employee biometric data. Fintech onboarding that uses face recognition, fingerprint authentication, or voice biometrics is subject to Illinois BIPA for any Illinois-resident employees or users — and to emerging biometric privacy laws in Texas, Washington, and other states. The BIPA 2024 amendment (single violation per person) reduced class action exposure significantly, but the underlying compliance obligation remains.
Illinois BIPA: Still the Dominant Biometric Privacy Law
The Illinois Biometric Information Privacy Act remains the most consequential biometric privacy statute in the US. BIPA class action settlements in 2025 totaled approximately $136.6 million — a decline from 2024’s $206 million, reflecting the impact of the August 2024 single-violation amendment — but still substantial.
The 2024 amendment did three important things: it capped liability at one violation per person regardless of how many times biometric data was disclosed to the same recipient; it defined “written release” to include electronic signatures; and it clarified that electronic consent satisfies BIPA’s informed consent requirements.
For fintech and financial services firms, the electronic consent clarification is operationally useful — digital onboarding flows that collect face geometry or fingerprint data for authentication can now satisfy BIPA’s consent requirement through an e-sign disclosure, without requiring a paper signature or a separate wet-ink consent process.
The substantive obligations — providing advance notice, obtaining informed consent before collection, having a written policy for retention and destruction, prohibiting sale — remain unchanged. If your authentication system or onboarding product collects biometric identifiers from Illinois residents, BIPA compliance is not optional and the amendment’s changes don’t reduce the underlying obligation.
The Divergence from GDPR: Managing Multiple Frameworks
US state privacy law enforcement is accelerating at exactly the moment companies managing GDPR exposure are already stretched on data privacy compliance resources. The frameworks are similar in concept but differ in structure, enforcement mechanism, and penalty calculation.
GDPR is unified across the EU, enforced by data protection authorities with direct fining power, and calculates penalties as a percentage of global annual revenue — up to €20 million or 4% of worldwide turnover, whichever is higher. US state enforcement is fragmented across 19 AGs and two agencies, with per-violation penalties that can compound across consumer records but don’t have the revenue-based ceiling structure of GDPR.
The Consortium changes the fragmentation calculus. GDPR enforcement produced over €1 billion in fines in 2025 through largely coordinated DPA actions. US state enforcement is building toward a similar coordination model — less formal than GDPR’s one-stop-shop mechanism, but more coordinated than the purely siloed state-AG model that characterized 2022–2024.
For compliance teams managing both frameworks, the practical advice is consistent: build your privacy program around the highest-common-denominator obligations (GDPR’s consent, documentation, and DPIA requirements) and use that as your baseline for US state compliance — then layer in state-specific rights obligations (Texas’s cure notice requirements, Colorado’s sensitive data categories, California’s deletion mechanisms) on top.
So What?
State privacy law enforcement stopped being theoretical in January 2025. Texas filed suit. California issued record fines. Eight AGs formed an enforcement consortium. The compliance teams that were waiting for “real enforcement” before building privacy programs have now seen it.
For financial services firms specifically, the risk profile isn’t primarily about core customer financial data — that’s largely GLBA-covered and excluded from most state privacy laws. The exposure sits in the periphery: mobile app tracking SDKs, behavioral data sold to third parties, employee biometric authentication, connected-car and IoT data in fintech products, and DSAR operations that haven’t kept pace with the 19-state framework.
The Maryland MODPA added sensitive data protections in June 2026. Colorado is adding geolocation as sensitive data in August 2026. The California Delete Act enforcement begins August 1, 2026. The Consortium’s enforcement intelligence sharing means a gap identified by one AG’s investigation can become a notice from another’s office without warning.
The window for low-consequence noncompliance — where cure letters were the worst-case outcome — is closing.
Sources:
- Texas Attorney General: First TDPSA Enforcement Action Against Allstate/Arity (VE Law coverage)
- California AG: Privacy Enforcement Actions
- California Privacy Protection Agency: Tractor Supply Enforcement Action (White & Case coverage)
- State AGs Form Bipartisan Privacy Enforcement Consortium (Greenberg Traurig)
- US State Privacy Law Tracker 2026 — Laws in Effect (Multistate)
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Does the GLBA safe harbor still protect banks and fintechs from state privacy laws?
Our company operates in 12 states. Do we need to comply with each state's privacy law separately?
What are the penalties for violating the Texas TDPSA?
Is California's enforcement threat primarily from the AG or the Privacy Protection Agency (CPPA)?
What is the AG Privacy Enforcement Consortium and which states are members?
Do Illinois BIPA requirements apply to fintech companies?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Keep reading
Related posts.
Data Privacy
Oregon's Privacy Law Has a Feature No Other State Has — and Financial Services Companies Are Probably in Scope
The Oregon Consumer Privacy Act's 30-day cure period ended January 1, 2026. The AG can now sue without notice. More importantly for financial services: the GLBA exemption is narrower than most assume, fintechs have significant exposure on non-NPI data, and Oregon requires something no other state does — a list of the specific named third parties that received consumer data.
Jul 17, 2026
Data Privacy
Connecticut's CTDPA Just Got a Lot Bigger — And Fintechs May Not Know They're Covered
Connecticut's CTDPA expanded on July 1, 2026 — lower thresholds, narrowed GLBA exemption, eliminated cure period, new profiling impact assessments. Here's what fintechs and nonbank lenders need to do now.
Jul 16, 2026
Data Privacy
NYDFS Part 500 in 2026: What 27 Consent Orders and $144M in Fines Tell You About Examiner Priorities
All Part 500 amended requirements are now in effect. NYDFS has 27 consent orders and $144M in fines under its belt. Here's what examiners are finding — and what to do before they show up at your door.
Jul 15, 2026