A quiet threshold got crossed this month. Twenty state comprehensive privacy laws are now in effect in the United States, and as of July 2026, nine of those states’ cure periods have expired.
A cure period is the grace mechanism written into most of these statutes: a regulator who finds a violation must first notify the business and give it a window — typically 30 or 60 days — to fix the problem before any penalty attaches. In practice it functioned as a free pass. You could run a non-compliant operation indefinitely, and the worst realistic outcome of getting caught was a letter telling you to stop.
Those nine states no longer work that way. A first violation now means enforcement, not a warning.
Connecticut went further
Connecticut’s amended Data Privacy Act took effect July 1, 2026 — with no added cure period, meaning the new requirements were immediately enforceable on day one. The amendment is one of the more substantive state privacy updates of the year:
- More businesses in scope. The applicability thresholds were broadened, pulling in companies that previously fell below the line.
- Public disclosure required when personal data is used to train LLMs. This is the notable one. Connecticut is now requiring companies to say, publicly, when they feed personal data into large language model training. Not consent — disclosure — but disclosure is what makes the rest possible.
- Neural data classified as sensitive. So are government IDs and financial credentials.
The neural data provision reflects a genuine and growing category. Consumer neurotechnology — EEG headbands for sleep and focus, brain-computer interface peripherals, neural wearables — has moved from research curiosity to shipped product, and the data these devices generate has essentially no regulatory history. Colorado moved first on this in 2024; Connecticut’s addition is part of a pattern of states legislating ahead of a harm rather than after one, which is rare enough to note.
The FTC’s location data ban came with an asterisk
In May 2026, the FTC settled with data broker Kochava, banning the sale of sensitive location data without consent. That was reported widely, and correctly, as a landmark: the first substantial federal constraint on the commercial location data trade.
The final order is weaker than the headline. Compared to the earlier proposed terms, it:
- Narrows the list of protected “sensitive locations.” Hospitals, shelters, and places of worship remain covered. The list is shorter than it was.
- Drops the ban on merely using sensitive location data, as distinct from selling it. A broker can therefore still derive inferences, build audience segments, and enrich profiles internally — it just can’t sell the underlying location records without consent.
- Removes the requirement that retention timeframes be tied to a business purpose. Retention limits that float free of any stated justification are limits in name.
The use-versus-sale distinction is the one that matters most. The commercial surveillance industry’s core product is not raw coordinates — it’s the inference built from them. A rule that constrains the sale of the input while permitting unrestricted use of it to produce the output leaves the business model substantially intact.
And then the Court unbolted the FTC
On the same docket that produced the geofence warrant ruling, the Supreme Court decided Trump v. Slaughter, 6-3: presidents may remove FTC commissioners at will, ending decades of protection for the agency’s independence.
The structural implication is significant and largely independent of who holds office. The FTC has been the closest thing the US has to a federal privacy regulator — not by statute, but by using its Section 5 authority over “unfair or deceptive” practices to reach data brokers, ad tech, health data, and children’s privacy. That work depends on multi-year investigations and consent decrees enforced across administrations.
An agency whose commissioners serve at the pleasure of the president is an agency whose enforcement priorities can be reset every four years. Long-horizon privacy enforcement is exactly the kind of work that doesn’t survive that.
Which redirects pressure back to the states — where, conveniently, the cure periods just expired.
What this actually means for ordinary people
The practical upshot is that your data rights got meaningfully stronger this month, in a way that most people won’t notice unless they use them.
Depending on where you live, you likely have some combination of:
- The right to know what personal data a company holds about you
- The right to delete it
- The right to correct inaccuracies
- The right to opt out of sale, sharing, and targeted advertising
- The right to opt out of profiling that produces legal or similarly significant effects
- Restrictions on sensitive data — precise geolocation, health, biometrics, and in Connecticut, neural data
The change isn’t the rights. It’s that ignoring them now costs money on the first offense in nine states, and that California has stood up an audits division that examines companies proactively rather than waiting for complaints.
How to use this
-
Find out what your state actually gives you. Twenty states, twenty slightly different statutes. The IAPP maintains a state law tracker; your state AG’s office usually has a consumer privacy page.
-
Use the universal opt-out. California, Colorado, Connecticut, Texas, and others require businesses to honor browser-level opt-out signals. Install Global Privacy Control — it’s built into Firefox and Brave, available as an extension elsewhere — and you send a legally binding opt-out to every site you visit, automatically. This is by a wide margin the highest-leverage privacy action available to a US consumer, and it takes two minutes.
-
File deletion requests with data brokers. California’s DROP (Delete Request and Opt-out Platform) lets residents submit a single request that registered data brokers must honor. Other states are watching how it performs.
-
Escalate when ignored. If a company blows past the statutory response deadline or returns something useless, file a complaint with your state AG or, in California, with CalPrivacy. With cure periods gone, that complaint can now produce a penalty rather than a nudge.
-
Check the sensitive categories. If you use a neurotech device, a fertility tracker, a mental health app, or anything handling biometrics, look at whether your state treats that data as sensitive — the protections are usually stronger and the opt-in requirements stricter.
The pattern
American privacy law has spent a decade in a strange equilibrium: expansive rights on paper, near-zero enforcement in practice, and a business ecosystem that priced compliance accordingly. Cure periods were the formal expression of that equilibrium — a statutory guarantee that the first time you got caught, nothing happened.
That’s ending, unevenly and state by state, at exactly the moment the federal regulator’s independence got structurally weakened. The net direction is a privacy regime that is more aggressive but more fragmented: real enforcement risk in California, Connecticut, Colorado and Texas; considerably less in states with no comprehensive law at all.
For companies, that means the compliance floor is now set by the strictest state you operate in. For individuals, it means your protections increasingly depend on your ZIP code — and that the rights you do have are only worth what you’re willing to exercise.
Sources:
- Privacy Dispatch July 2026: The FTC Bans Location Data Sales (With a Catch), Grace Periods Expire, and SCOTUS Weighs In — DataGrail
- Top Privacy and AI Developments of 2026: Midyear Report — Holland & Knight
- U.S. Data Privacy Laws and Regulations in 2026 — Smarsh
- Data privacy laws: what to expect for 2026 — Ketch



