If you want a single number that describes what happened to American privacy enforcement this year, here it is: the frequency of privacy rights–related insurance claims in the first half of 2026 has doubled relative to 2025.
That is not a survey of sentiment or a projection. It is insurers reporting what is actually crossing their desks. Companies are being sued and investigated over privacy at twice the rate they were a year ago, and the driver is not Washington.
Pennsylvania v. TikTok
Pennsylvania Attorney General Dave Sunday filed suit against TikTok in Allegheny County, alleging the company failed to shield children from age-inappropriate material and from over-use of the app — and, notably, that it misrepresented its safeguards and content in order to obtain an app store age rating suitable for children as young as 13.
That last theory is the interesting one, and it is worth separating from the general wave of social-media-harms litigation.
Most suits against platforms over minors run into Section 230, which bars treating a service as the publisher of third-party content. Pennsylvania’s framing routes around that. The claim is not TikTok published harmful content. The claim is TikTok made false statements to Apple and Google about its own product in order to get a 12+ rating, and parents relied on that rating.
That is a straightforward consumer protection deception theory about the company’s own speech regarding its own product. Section 230 does not protect a company’s representations about itself. This is the same doctrinal move Texas made in its 2024 suit, and the same one that survived a motion to dismiss in Minnesota AG Ellison’s case against TikTok in March 2026.
Whether it wins is a separate question. But it is a well-constructed theory, and multiple AGs converging on it independently is a signal.
Utah and Hims & Hers
Utah joined a federal lawsuit against Hims & Hers over data privacy concerns.
Telehealth is the sector where the gap between what counts as health data and what everyone treats as health data is widest. A direct-to-consumer platform dispensing treatment for hair loss, erectile dysfunction, mental health, and weight management holds information whose disclosure is straightforwardly humiliating, and it holds it in a consumer-app context — with marketing pixels, ad attribution, growth analytics, and an incentive structure built entirely on paid acquisition.
The recurring failure mode across this sector has been advertising infrastructure on pages where a user’s condition is inferable from the URL. It has produced FTC actions against GoodRx, BetterHelp, and Premom, and it keeps happening because the acquisition economics of DTC telehealth demand precise conversion tracking, and precise conversion tracking means telling the ad platform what the user converted on.
Utah is not a state most people associate with aggressive privacy enforcement. That is the point.
Why the states
The structural explanation is short.
There is no federal comprehensive privacy law. The Secure Data Act and its predecessors have not passed and there is no realistic path this Congress.
The FTC’s attention is elsewhere. The Commission’s most prominent privacy-adjacent action this year is a policy statement about AI output accuracy issued under executive direction, with a preemption question embedded in it. Its Kochava order was weakened. The agency that carried American privacy enforcement for two decades has a different agenda.
Twenty states now have comprehensive privacy laws, and almost all of them are enforced exclusively by the state attorney general, with civil penalties in the $7,500 to $10,000 per violation range. Per violation, in a consumer data context, means per consumer — which is how a technical compliance failure becomes a nine-figure exposure.
Cure periods are expiring. Most of these statutes launched with a mandatory right to cure: notify the company, give them 30 or 60 days to fix it, and only then proceed. Those provisions were time-limited by design, and nine states’ cure periods lapsed this year. The training wheels are off.
So you have fifty separately elected officials, most with a direct political incentive to be seen acting against large technology companies, each holding a statute with per-consumer penalties and no cure requirement. The doubling in claim frequency is what that looks like from an insurer’s ledger.
What it means in practice
For companies: the compliance target is now the most aggressive state, not the average one. There is no federal floor to standardise against, and a patchwork enforced by fifty offices with different priorities is precisely the outcome industry warned about while lobbying against a federal law with preemption. That is not irony so much as arithmetic.
For consumers: this is, on balance, good — with a real caveat. State AG enforcement has produced more concrete change in two years than federal action produced in ten. But your protection now depends on where you live and on who won an election there. Twenty states have comprehensive laws. Thirty do not.
For the federal preemption fight: every one of these actions raises the stakes. Industry’s appetite for a federal privacy law is directly proportional to how expensive state enforcement gets, and the version industry will accept is one that preempts. The doubling in claims frequency is the pressure that produces a federal bill — and determines how weak it is.
What you can do
-
Find out whether your state has a comprehensive privacy law. If it does, you have access, deletion, correction, portability, and opt-out rights, and opt-in consent requirements for sensitive data. Most people in covered states have never exercised any of them.
-
File complaints with your state AG, not just with the company. AG offices open investigations based on complaint volume. A single complaint is data; a hundred is a case. This is the highest-leverage thing an individual can do in the current enforcement environment, and almost nobody does it.
-
Send a deletion request and keep the record. If a company ignores it or responds inadequately, that documented failure is exactly what an AG investigation is built from.
-
Be careful with DTC telehealth. Use a browser with tracking protection, do not log in from a session tied to your social accounts, and read what the intake form says about advertising partners. The Hims & Hers suit will not be the last one in this sector.
-
If you are a California resident, use DROP. It went live for brokers on August 1 and it is the strongest consumer privacy mechanism in the country.
The pattern
American privacy enforcement moved from a single federal regulator to fifty state ones, and almost nobody planned it.
It happened because a federal law never passed, the FTC’s priorities changed, and twenty state legislatures filled the vacuum with statutes that hand enforcement to elected officials who benefit politically from using them. The result is inconsistent, geographically arbitrary, and considerably more effective than what it replaced.
The doubling in claims frequency is the sound of that transition completing. Whatever comes next — a federal bill with preemption, most likely — will be negotiated against this baseline, by an industry that now has a concrete number for what state enforcement costs.


