Halfway through 2026, privacy law is winning on paper and losing in practice. Both halves of that sentence are supported by the record, and the gap between them is the most important thing to understand about this year.

The paper case: privacy law has never been stronger

More than 144 countries have data protection laws in force, per IAPP tracking. That is roughly three-quarters of the world’s states, up from a few dozen fifteen years ago.

The GDPR turned ten in May. Adopted 24 May 2016, it remains the template that most of those 144 frameworks borrow from — lawful basis, data subject rights, breach notification, cross-border transfer restrictions, supervisory authorities with fining power.

The Asia-Pacific build-out completed a major phase. New or newly effective frameworks in Vietnam (comprehensive personal data protection law in force 1 January 2026, covered here), India (DPDP moving into enforcement), South Korea, and Malaysia all landed between mid-2025 and early 2026. China’s amended Cybersecurity Law took effect 1 January 2026, its first substantial revision since 2017.

Brazil moved on children specifically. The Digital ECA, a comprehensive children’s online safety law passed at the end of last year, entered enforcement by the national data protection authority this spring.

And in the United States, 23 states now have comprehensive privacy laws, with Indiana, Kentucky, and Rhode Island taking effect 1 January 2026. There is still no federal statute.

If you scored the year by legislative output, it would be one of the best in the history of the field.

The practical case: it is not working

Now score it by what actually happened to people.

Breach volume set records. The Identity Theft Resource Center recorded 471.2 million victim notices in the first six months of 2026 — more than the 297.5 million issued across all of 2025 — across 1,803 tracked compromises. Covered separately here.

Enforcement stayed symbolic where it mattered most. The UK ICO’s response to ACRO Criminal Records Office leaving a public portal unpatched since September 2019, with attackers inside for seven months and criminal offence data and biometrics for up to 10,000 people exposed, was a reprimand. A letter. For a government body holding some of the most sensitive categories the law recognises.

Governments expanded what they buy. ICE moved on $6.7 million for LexisNexis records covering 82 billion data points, with contract terms requiring integration with Palantir and PenLink and bulk facial recognition, and relisted a $100 million-plus investigative analytics requirement contemplating continuous tracking of up to a million individuals. Detail here. None of this is illegal. Purchasing data on the open market is the standing workaround for the warrant requirement, in the US and increasingly elsewhere.

Scanning mandates advanced in Europe. The Council approved a Chat Control framework running to April 2028, while the AI Act’s Annex III high-risk obligations slid toward December 2027 under the omnibus simplification agenda. Analysis here. Read together: the surveillance provisions kept their timeline, the protective provisions got delayed.

Age verification became the universal solvent. The UK Online Safety Act regime, state-level US mandates, and now Brazil’s Digital ECA all require identity or age assurance at scale — which means universal identification infrastructure built for child protection and immediately available for everything else. And the technical premise is already shaky: AI-generated fake IDs are defeating document checks at around $15 for thirty minutes’ work, with volume up roughly 90% year over year.

Facial recognition moved into ordinary public space. British Transport Police deployed live facial recognition inside Victoria Underground station on 11 August, running NEC NeoFace M40 against a watchlist and rotating between stations until November. Detail here.

Why the two ledgers do not touch

Four structural reasons the law keeps expanding while the outcome keeps degrading.

First, most of these frameworks regulate commercial processing and exempt the state. Nearly every comprehensive privacy law carries broad national security and law enforcement carve-outs. The largest and least accountable processing in 2026 is being done by governments, frequently by buying from the same commercial brokers the laws do regulate — which converts a prohibition on state collection into a procurement line item.

Second, enforcement capacity did not scale with scope. Supervisory authorities are chronically under-resourced relative to jurisdiction. Adding your country to the 144 does not add investigators. The result is enforcement that lands on mid-sized firms with poor documentation while the largest processors litigate for years.

Third, consent-based frameworks were designed for a world of discrete transactions. They translate badly to ambient collection: ALPR networks, bid-stream location leakage, biometric capture in transit stations, model training on scraped corpora. There is no consent moment at which a person walking past a camera can exercise a right.

Fourth, the compute and data infrastructure grew faster than the rules. Roughly 800 data centers are under construction in the United States alone, and the federal policy posture treats subnational regulation as friction to be preempted. Capacity is a fact; law is a claim about facts. Right now capacity is compounding and law is not.

What the pessimists get wrong

Three corrections, because “privacy is dead” is both wrong and demobilising.

The laws do work, in the specific places they bite. California’s DROP deletion mechanism went live this year and actually removes people from broker databases at scale, which is a concrete, measurable improvement in ordinary lives. Washington published its first Data Privacy Report with real numbers because a statute required it. State AG enforcement produced genuine settlements and behavioural change. These are not nothing.

The technical baseline improved markedly. End-to-end encryption is the default in mainstream messaging. Passkeys are displacing passwords. Browser-level tracking protection is standard. Capable models now run locally, removing the necessity of cloud disclosure for a large class of tasks. Someone who cares in 2026 has far better tools than someone who cared in 2016.

And the public turned. Data center opposition groups more than doubled to 833 across 49 states. Fifty-plus cities cancelled Flock ALPR contracts. Washington found 83% of surveyed residents feel they have little or no control over their information — which is a grim finding and also a political resource, because 83% is a constituency.

What it means in practice

The mid-year picture is not that privacy law failed. It is that privacy law was built to govern companies collecting data through transactions, and the dominant threat in 2026 is governments acquiring data through purchase and mandate, running on infrastructure whose siting, power, water, and ownership are themselves undisclosed.

A hundred and forty-four national frameworks do not reach that. Twenty-three state statutes do not reach it, and are the specific target of a federal preemption effort with no replacement standard behind it. The rules multiplied on one side of a line while the activity migrated to the other side.

The fights that will matter for the rest of 2026 are therefore not about passing another comprehensive framework. They are about closing the government-purchase loophole, funding the authorities that already exist, and forcing disclosure onto the infrastructure layer.

What you can do

  1. Use the rights you already have. If you are in a state with a deletion or opt-out regime, exercise it — DROP-style mechanisms work, and usage volume is what regulators cite when arguing for budget.
  2. Support closing the purchase loophole. Legislation barring government agencies from buying data they would need a warrant to compel is the single highest-leverage privacy reform available in the US, and it has repeatedly attracted bipartisan sponsorship.
  3. Oppose preemption without substitution. Ask the substitution question every time: which federal standard replaces the state law being preempted, and on what date does it take effect?
  4. Treat age verification proposals as identity infrastructure proposals. Whatever they are called, they build a system that links a legal identity to online activity. Ask what else that system can be queried for, by whom, and with what retention.
  5. Improve your own baseline, because it genuinely helps now. End-to-end encrypted messaging, passkeys, a hardened browser, local inference for sensitive work, and one deletion sweep per year through the broker registries. None of it solves the structural problem. All of it materially reduces your exposure while the structural problem is being fought over.