Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Data Privacy

State Privacy Law Enforcement in 2026: What Texas, California, and the New AG Consortium Mean for Financial Services

Texas filed the first-ever lawsuit under a state comprehensive privacy law in January 2025. California hit Disney with a $2.75 million CCPA fine in February 2026. Eight AGs now share enforcement intelligence through a formal consortium. The 'nobody is actually enforcing this' assumption is over.

By Rebecca Leung · June 24, 2026 ·
Table of Contents

TL;DR

  • Texas filed the first-ever enforcement action under a state comprehensive privacy law in January 2025 (against Allstate/Arity for geolocation data collection) and has investigated 200+ companies since June 2024
  • California produced its largest-ever CCPA settlement in February 2026 — $2.75 million against Disney/ABC — while GM settled for $12.75 million over connected-car location data in the same month
  • Eight state AGs formed a formal Privacy Enforcement Consortium in April 2025, meaning one state’s investigation now generates enforcement intelligence for seven others
  • With 19 states having active comprehensive privacy laws and Colorado’s mandatory cure period expired, the window for low-consequence noncompliance is closing

For most of the four years that state comprehensive privacy laws have been on the books, enforcement looked like cure letters. A company got noticed, had 30 to 60 days to fix the identified issue, resolved it quietly, and moved on. Industry observers described a “regulatory adolescence” where the laws existed but real enforcement costs felt theoretical.

That model is breaking. Texas filed a lawsuit. California issued its largest-ever CCPA fine. And eight state attorneys general now share enforcement intelligence through a formal consortium that didn’t exist 18 months ago. The compliance calculus for financial services firms — banks, fintechs, credit unions, payment processors — changed, and a lot of compliance programs haven’t caught up.

Texas: The State That Actually Filed Suit

On January 13, 2025, Texas Attorney General Ken Paxton filed the first-ever enforcement action brought under any state comprehensive privacy law in the United States. The target was Allstate and its subsidiary Arity.

The allegations: Arity embedded software development kits (SDKs) into popular mobile apps — including Life360, GasBuddy, Fuel Rewards, and Routely — without adequate disclosure or consent, collecting precise geolocation data and driving behavior from Texas consumers. That data was allegedly sold to insurance companies, which used it to price auto insurance policies. Consumers using these apps had no meaningful understanding that their driving data was being monetized through a chain ending at their insurance carrier.

The case matters beyond the specific defendants. The SDK-in-app data collection model — where a company’s code lives inside a third-party application and harvests data from users who primarily interact with a different brand — is widespread in financial services. Advertising partnerships, risk scoring vendors, and telematics providers all use variations of this approach. The Allstate/Arity case signals that the Texas AG views undisclosed SDK-driven collection as actionable under TDPSA, not just as a policy concern.

Texas’s privacy enforcement footprint is broader than one lawsuit. Since launching the Data Privacy and Security Initiative in June 2024, the AG has investigated over 200 companies spanning data brokers, car manufacturers, social media platforms, and entities with ties to foreign adversaries. The enforcement context for the Allstate case includes two landmark settlements from prior Texas privacy actions: $1.4 billion from Meta for biometric data collection, and $1.375 billion from Google for location tracking violations. These settlements were under Texas’s biometric and deceptive trade practices laws, not TDPSA specifically — but they establish the AG’s willingness to pursue large-dollar enforcement, and they fund the investigation infrastructure that produces TDPSA actions.

TDPSA penalties cap at $7,500 per violation. The cure period is 30 days — the AG must provide written notice before filing. Unlike Colorado, Texas has not sunset its cure period, so the 30-day cure remains available. But the Allstate filing demonstrates that “cure period available” doesn’t mean “AG won’t sue.”

California: Two Enforcement Arms, Record Fines

California’s enforcement structure is unique and worth understanding clearly, because both enforcement pathways are active.

The California Privacy Protection Agency (CPPA) is an independent agency with authority to issue regulations and enforce CPRA directly. It can impose fines without filing in court. In September 2025, the CPPA issued a $1.35 million penalty against Tractor Supply Company — the largest penalty the CPPA had imposed up to that point — for failing to notify consumers and job applicants of their privacy rights, failing to maintain adequate service provider agreements, and failing to provide effective opt-out mechanisms. Importantly, this was primarily an employee and job-applicant data case, not a consumer financial data case.

The California Attorney General retains concurrent CCPA/CPRA enforcement authority. In February 2026, the AG announced the largest CCPA enforcement settlement to date: $2.75 million from Disney and ABC. The action alleged that Disney failed to fully effectuate consumer opt-out requests for data sale and sharing across Disney+, Hulu, and ESPN+ — specifically that the company linked consumer devices for targeted advertising purposes but failed to link those same devices for opt-out compliance. The practical problem: Disney’s systems could track that Device A and Device B belonged to the same user when serving ads, but claimed it couldn’t link those devices when processing opt-out requests. The AG concluded that’s not a technological limitation; it’s a compliance failure.

Also in February 2026, General Motors settled for $12.75 million over unlawful sale of driving and location data collected through its OnStar connected car service. GM allegedly collected and sold precise geolocation data from California drivers without adequate disclosure or consent. The financial services angle is direct: connected-vehicle data is increasingly used by auto insurance subsidiaries and fintech lenders for underwriting. The GM settlement puts the entire connected-car data ecosystem on notice.

Looking ahead: the California Delete Act begins active enforcement on August 1, 2026. Data brokers that fail to honor consumer deletion requests routed through the state’s centralized deletion mechanism face penalties of $200 per day per request not addressed. For financial services firms that sell consumer data to data brokers — or that operate data brokerage functions themselves — this is a live obligation, not a future one.

The AG Enforcement Consortium: Eight States, One Strategy

On April 16, 2025, eight privacy regulators announced the formation of the Consortium of Privacy Regulators:

  • California Attorney General
  • California Privacy Protection Agency (CPPA)
  • Colorado Attorney General
  • Connecticut Attorney General
  • Delaware Attorney General
  • Indiana Attorney General
  • New Jersey Attorney General
  • Oregon Attorney General

The Consortium’s stated purpose is to address multijurisdictional privacy issues with greater efficiency and consistency — sharing enforcement intelligence, investigative strategies, and compliance expectations across member jurisdictions.

The practical consequence: a California investigation that surfaces evidence of systematic opt-out failures, SDK-based data collection, or inadequate service provider agreements now generates intelligence that can inform enforcement actions in Colorado, Connecticut, Indiana, New Jersey, Oregon, and Delaware. Companies that treated each state’s enforcement as an isolated risk calculation must now treat Consortium-member states as a single enforcement zone for detection and evidence-sharing purposes.

Colorado’s position within the Consortium is worth specific attention. The mandatory 60-day cure period in the Colorado Privacy Act expired on January 1, 2025 — the AG can now file suit without providing cure notice. Colorado is also moving quickly on amendments: SB 24-041 (effective October 1, 2025) added heightened protections when a controller knows a user is a minor. And SB 25-276, effective August 12, 2026, will classify precise geolocation data as sensitive data under the Colorado Privacy Act — triggering higher consent and opt-out requirements for any Colorado-resident geolocation processing.

The 2026 State Privacy Landscape: What’s Active Now

As of June 2026, 19 states have active comprehensive consumer privacy laws. The two most recently activated laws most relevant for financial services teams:

StateLawEffective DateNotable Features
MinnesotaConsumer Data Privacy Act (MNDPA)July 31, 2025Right to question automated decisions; applies to 100K+ consumer data processors
New JerseyNew Jersey Data Privacy Law (NJDPA)January 15, 2025Cure period expiring mid-2026; broad applicability
ColoradoColorado Privacy Act (as amended)Geolocation = sensitive data: August 12, 2026No cure period; AG is Consortium member
CaliforniaDelete Act enforcementAugust 1, 2026$200/day per deletion request not addressed

Minnesota’s MNDPA includes an unusual provision: consumers can question automated decisions made through profiling — not just receive opt-outs, but actively challenge automated outcomes affecting significant decisions. For fintechs using algorithmic credit decisioning, risk scoring, or fraud detection, this creates an obligation that goes beyond standard CCPA/CPRA disclosure requirements.

What This Means for Financial Services Firms

The GLBA safe harbor has limits. The GLBA exemption in most state privacy laws applies to data regulated under GLBA’s safeguards and privacy rules — consumer financial data covered by Regulation P. But GLBA doesn’t cover employee data, marketing data, app behavior data from non-customers, or data collected through third-party SDKs on partner apps. The Allstate/Arity case illustrates precisely the category of data that GLBA doesn’t protect: behavioral data collected through mobile app integrations, not from a financial services relationship.

Tracking pixels and SDKs in financial products. If your fintech or insurance subsidiary embeds third-party tracking SDKs in your mobile app — and most do, for analytics, attribution, and behavioral data — those SDKs may be collecting and transmitting data in ways that trigger state privacy law obligations. The Allstate/Arity enforcement framework applies equally to financial services apps. Audit your app’s third-party SDK inventory against your privacy notice and data processing agreements.

DSAR handling across 19 frameworks. Consumer data subject access requests (DSARs) — the right to know, delete, correct, and opt out — now exist across 19 state frameworks, each with slightly different timelines and scope. A unified DSAR response workflow that handles the most common state requirements (California, Texas, Colorado, Virginia, Connecticut) covers most of your exposure. See the DSAR response workflow for CCPA, GDPR, and state privacy laws for a practical process structure.

Employee biometric data. Fintech onboarding that uses face recognition, fingerprint authentication, or voice biometrics is subject to Illinois BIPA for any Illinois-resident employees or users — and to emerging biometric privacy laws in Texas, Washington, and other states. The BIPA 2024 amendment (single violation per person) reduced class action exposure significantly, but the underlying compliance obligation remains.

Illinois BIPA: Still the Dominant Biometric Privacy Law

The Illinois Biometric Information Privacy Act remains the most consequential biometric privacy statute in the US. BIPA class action settlements in 2025 totaled approximately $136.6 million — a decline from 2024’s $206 million, reflecting the impact of the August 2024 single-violation amendment — but still substantial.

The 2024 amendment did three important things: it capped liability at one violation per person regardless of how many times biometric data was disclosed to the same recipient; it defined “written release” to include electronic signatures; and it clarified that electronic consent satisfies BIPA’s informed consent requirements.

For fintech and financial services firms, the electronic consent clarification is operationally useful — digital onboarding flows that collect face geometry or fingerprint data for authentication can now satisfy BIPA’s consent requirement through an e-sign disclosure, without requiring a paper signature or a separate wet-ink consent process.

The substantive obligations — providing advance notice, obtaining informed consent before collection, having a written policy for retention and destruction, prohibiting sale — remain unchanged. If your authentication system or onboarding product collects biometric identifiers from Illinois residents, BIPA compliance is not optional and the amendment’s changes don’t reduce the underlying obligation.

The Divergence from GDPR: Managing Multiple Frameworks

US state privacy law enforcement is accelerating at exactly the moment companies managing GDPR exposure are already stretched on data privacy compliance resources. The frameworks are similar in concept but differ in structure, enforcement mechanism, and penalty calculation.

GDPR is unified across the EU, enforced by data protection authorities with direct fining power, and calculates penalties as a percentage of global annual revenue — up to €20 million or 4% of worldwide turnover, whichever is higher. US state enforcement is fragmented across 19 AGs and two agencies, with per-violation penalties that can compound across consumer records but don’t have the revenue-based ceiling structure of GDPR.

The Consortium changes the fragmentation calculus. GDPR enforcement produced over €1 billion in fines in 2025 through largely coordinated DPA actions. US state enforcement is building toward a similar coordination model — less formal than GDPR’s one-stop-shop mechanism, but more coordinated than the purely siloed state-AG model that characterized 2022–2024.

For compliance teams managing both frameworks, the practical advice is consistent: build your privacy program around the highest-common-denominator obligations (GDPR’s consent, documentation, and DPIA requirements) and use that as your baseline for US state compliance — then layer in state-specific rights obligations (Texas’s cure notice requirements, Colorado’s sensitive data categories, California’s deletion mechanisms) on top.

So What?

State privacy law enforcement stopped being theoretical in January 2025. Texas filed suit. California issued record fines. Eight AGs formed an enforcement consortium. The compliance teams that were waiting for “real enforcement” before building privacy programs have now seen it.

For financial services firms specifically, the risk profile isn’t primarily about core customer financial data — that’s largely GLBA-covered and excluded from most state privacy laws. The exposure sits in the periphery: mobile app tracking SDKs, behavioral data sold to third parties, employee biometric authentication, connected-car and IoT data in fintech products, and DSAR operations that haven’t kept pace with the 19-state framework.

The Maryland MODPA added sensitive data protections in June 2026. Colorado is adding geolocation as sensitive data in August 2026. The California Delete Act enforcement begins August 1, 2026. The Consortium’s enforcement intelligence sharing means a gap identified by one AG’s investigation can become a notice from another’s office without warning.

The window for low-consequence noncompliance — where cure letters were the worst-case outcome — is closing.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Does the GLBA safe harbor still protect banks and fintechs from state privacy laws?
Partially. The GLBA safe harbor preempts state privacy laws that are inconsistent with GLBA, but it doesn't provide blanket immunity. California's CCPA/CPRA specifically excludes data regulated under GLBA from its scope — so if you're a GLBA-covered entity collecting consumer financial data subject to Regulation P, that data is excluded from CCPA. However, GLBA doesn't preempt state laws that address categories not covered by GLBA (employee biometric data, for example) or states where courts have narrowed the preemption scope. The Tractor Supply CPPA action is an example — it covered employee and applicant data, not just financial records.
Our company operates in 12 states. Do we need to comply with each state's privacy law separately?
Yes, unless a given state's law has a GLBA exemption that covers your data processing. As of 2026, 19 states have active comprehensive consumer privacy laws, each with different thresholds, rights, and obligations. The practical approach for financial services firms is to identify which state laws apply based on your customer footprint and data volume thresholds, then build a unified compliance framework that satisfies the most restrictive applicable requirements. The AG Enforcement Consortium means that a California investigation can surface evidence used in enforcement by Colorado, Connecticut, or New Jersey — so treating states as isolated silos is a compliance risk, not just an administrative inconvenience.
What are the penalties for violating the Texas TDPSA?
The Texas Data Privacy and Security Act provides for civil penalties of up to $7,500 per violation. There's a 30-day cure period — the AG must provide notice and allow the company to remedy the violation before filing suit — but that cure period is a grace mechanism, not a guarantee that enforcement won't follow. The Texas AG's filing against Allstate and Arity demonstrates the AG is willing to file suit when cure is not provided. The AG also has broader authority to investigate and enforce under the Texas Deceptive Trade Practices Act, which can carry additional penalties.
Is California's enforcement threat primarily from the AG or the Privacy Protection Agency (CPPA)?
Both. The California Attorney General can bring enforcement actions under CCPA and CPRA, as seen in the Disney/ABC $2.75 million settlement (February 2026) and the GM $12.75 million settlement. The California Privacy Protection Agency (CPPA) separately has its own enforcement authority and can issue fines directly — as it did with Tractor Supply ($1.35 million, September 2025). These are parallel enforcement pathways, not a sequential process. California companies face potential exposure from both offices simultaneously.
What is the AG Privacy Enforcement Consortium and which states are members?
The Consortium of Privacy Regulators was formed on April 16, 2025. Members include the California Attorney General, Colorado Attorney General, Connecticut Attorney General, Delaware Attorney General, Indiana Attorney General, New Jersey Attorney General, Oregon Attorney General, and the California Privacy Protection Agency. The Consortium's purpose is to share enforcement intelligence and investigative strategies across multijurisdictional privacy issues. In practice, this means an investigation opened by California may generate evidence or leads that inform enforcement by other member states — without each state independently discovering the same violations.
Do Illinois BIPA requirements apply to fintech companies?
Yes, if you operate in Illinois or collect biometric data from Illinois residents. BIPA regulates any private entity that collects, stores, uses, sells, or profits from biometric identifiers — including fingerprints, retina or iris scans, voiceprints, and face geometry. Fintech applications that use face recognition for onboarding, biometric authentication for login, or voice verification for account access are directly covered. Illinois amended BIPA in August 2024 to create a single-violation-per-person rule (reducing per-claimant class action exposure), but the law remains active. Electronic consent is now valid under the amendment — which simplifies compliance for digital onboarding flows.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.