Google's $1.375B Texas privacy settlement shown on a 2026 US state privacy law mapTexas just handed Google the largest state privacy settlement in US history, and it's reshaping how every state regulates data in 2026.
US Data Privacy Law 2026: Why 20 States Now Outpace GDPR

Policies

US Data Privacy Law in 2026: Why 20 States Now Outpace GDPR

Google just wrote Texas a check for $1.375 billion. Not the European Union. Not the FTC. Texas. That single number tells you almost everything about where US data privacy law stands in 2026: the states, not Washington and not Brussels, are now writing the rules that actually cost companies money.

For most compliance leads, the mental model is still simple: GDPR is the ceiling, US law is the floor, and everything else is noise. That model broke sometime in the last eighteen months. Twenty states now run comprehensive privacy statutes, each with its own thresholds, its own definitions of sensitive data, and in Texas’s case, no revenue threshold at all. A brand-new category, neural data, exists in law that didn’t exist five years ago. And the grace periods that let companies fix violations quietly before facing a fine are expiring, state by state, right now.

This is the map of what changed, what it costs, and what your compliance team needs to budget for before the next state law lands.

The patchwork by the numbers

Twenty states now have comprehensive consumer privacy laws on the books: California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and Washington. Three of those, Indiana, Kentucky, and Rhode Island, only started counting on January 1, 2026.

The thresholds for who even has to comply vary wildly. That’s the part most compliance checklists get wrong when they treat “state privacy law” as one category.

StateEffectiveApplicability triggerNotable feature
IndianaJan 1, 2026100,000 residents (or 25,000 + 50%+ revenue from data sales)Standard Virginia-model structure
KentuckyJan 1, 2026100,000 residents (or 25,000 + 50%+ revenue from data sales)New standalone Office of Data Privacy
Rhode IslandJan 1, 202635,000 residentsLowest population threshold of the three
Maryland (amended)Jul 1, 2026Existing MODPA thresholdsBars data sales to ICE-linked government entities; geolocation defined at a 1,750-foot radius
Connecticut (amended)Jul 1, 2026Existing CTDPA thresholdsFirst state to legally define “neural data”

Every one of those laws borrows structurally from GDPR (the rights to access, correct, delete, and port your own data), but almost none of them borrow GDPR’s core design choice: opt-in consent before collection starts. Eighteen of the twenty states copied the “Virginia model” instead, which defaults to opt-out. Collect first, let the consumer object later. That single difference is the real gap between the US and EU approaches, and no amount of new state legislation is closing it.

Texas v. Google: the settlement that reset the scale

On October 31, 2025, Google finalized a $1.375 billion settlement with Texas Attorney General Ken Paxton, closing two lawsuits filed in 2022 over geolocation tracking, data collected while users believed Incognito mode was private, and biometric identifiers, voiceprints and facial geometry, gathered without proper consent.

It’s the largest privacy recovery any single US state has secured against Google, well past a prior 40-state coalition settlement of $391 million. Paxton didn’t mince words about why Texas pursued it.

“Big Tech is not above the law.” Ken Paxton, Attorney General, State of Texas

Compare that to the FTC’s typical annual privacy enforcement total, historically in the tens of millions of dollars, and the shift is obvious. One state, acting alone, out-fined the entire federal privacy apparatus with a single case. Our read: state attorneys general have effectively become the primary financial deterrent in US privacy enforcement, and Big Tech is now underwriting billion-dollar settlements as a line-item cost of doing business rather than an existential threat.

Not just Google. Texas secured a separate $1.4 billion settlement with Meta in 2024. Two settlements, two years, $2.775 billion combined, from a single state AG’s office. No other enforcement body in the country, federal or state, has matched that pace.

Cure periods are disappearing

Here’s the part most compliance teams haven’t updated their risk models for. A cure period is the grace window that lets a company fix a privacy violation quietly, without penalty, once an attorney general flags it. Several states built cure periods into their original laws specifically to ease companies into compliance.

Those windows are closing. Delaware’s 60-day cure period ended December 31, 2025. Montana’s expired April 1, 2026. New Jersey’s expired mid-2026. In each of those states, attorneys general can now sue on first violation, no warning shot required.

If your compliance strategy has ever relied on “we’ll fix it if someone flags it,” that strategy no longer exists in three states and counting.

Neural data: the newest legal category

Ask a general counsel from five years ago what “neural data” meant as a legal term, and you’d get a blank look. It didn’t exist as a category. Now it does, and it’s expanding fast.

Colorado moved first, classifying neural data as sensitive personal data under HB 24-1058, effective August 2024. California followed in January 2025. Montana came next. Connecticut’s SB 1295 enters force July 1, 2026, defining neural data specifically as central nervous system activity. At least ten more states, including Virginia, Alabama, New York, Illinois, and Vermont, have neural data bills in draft as of a March 2026 tracking analysis from Morrison Foerster.

What counts as neural data in practice? Anything a wearable, VR or AR headset, or medical device captures about your nervous system activity. If your product touches EEG-adjacent hardware, biometric wearables, or even inferential mood and health data derived from sensor input, you may already be handling sensitive data under four state laws without having mapped that obligation yet.

Stanford Law’s Bo Hyoung Lee, at the Center for Law and the Biosciences, has raised a sharper concern than “too many rules.” Lee’s March 2026 analysis argues that traditional notice-and-consent frameworks are structurally unsuited to neural data specifically, because ordinary consumers can’t reasonably evaluate how a raw brain signal might later be processed into inferences about their mood, intent, or mental state. It’s not that the consent box is missing. It’s that no consent box can meaningfully cover what the data might reveal once it’s decoded.

GDPR turns 10. It’s still not the model US states copied

May 24, 2026 marked ten years since GDPR’s adoption. The regulation remains the heaviest financial hammer in privacy globally: cumulative GDPR fines have passed €7.1 billion since 2018, with over 60% of that total value imposed since January 2023 alone, and 2025 added another €1.2 billion on its own, according to DLA Piper’s annual GDPR Fines and Data Breach Survey.

The EU isn’t standing still either. A “GDPR Omnibus” proposal introduced in November 2025 aims to align GDPR with the AI Act and ePrivacy rules, the first real attempt to write AI considerations directly into what had been technology-neutral EU data law.

But raw fine totals aren’t the same as structural rigor, and this is where the GDPR-as-gold-standard narrative gets oversold. GDPR requires opt-in consent as a baseline. US state law, almost uniformly, does not. More states passing “comprehensive” privacy laws doesn’t mean the US is converging toward GDPR’s model. It means the US is building a more elaborate version of its own opt-out baseline, one state at a time.

The $1 trillion counterargument

Not everyone thinks fifty states writing their own privacy rules is a win for consumers. The Information Technology and Innovation Foundation estimates the patchwork will cost the US economy more than $1 trillion over ten years compared to a single federal law, with small businesses absorbing over $200 billion of that burden on their own.

Jordan Crenshaw, Senior Vice President of the US Chamber of Commerce’s Technology Engagement Center, frames the problem as a growth constraint, not just a legal cost center.

“Policymakers need to establish a single national framework.” Jordan Crenshaw, SVP, Technology Engagement Center, U.S. Chamber of Commerce

That national framework isn’t coming soon. The American Privacy Rights Act, the most credible federal preemption bill in over a decade, collapsed after its civil-rights provisions were stripped in a canceled June 2024 markup, then expired without a floor vote when the 118th Congress ended in January 2025. It hasn’t been reintroduced. Smaller bills sit in committee with no real path forward. Anyone forecasting federal preemption arriving in 2026 isn’t reading the current legislative record.

There’s also a quieter enforcement gap worth naming. Texas’s $1.375 billion headline makes for a great story, but most day-to-day state privacy enforcement looks nothing like that: a $56,600 penalty against a single data broker here, a $530,000 settlement with a streaming service there. Big Tech absorbs the billion-dollar cases. Smaller, mid-size data-driven businesses, the ones without a legal department built for this, are far more likely to slip past under-resourced state AG privacy units that in many states still run on a handful of dedicated staff.

What compliance teams need to do now

A few things change immediately for anyone running a multi-state or multinational operation.

  • Retire the “strictest state” shortcut. The strictest state on one provision, Maryland on sensitive-data sales, isn’t the strictest on another. Texas has no revenue threshold at all. You need jurisdiction-aware compliance, not a single static policy document.
  • Recognize Global Privacy Control. Universal opt-out mechanisms are now effectively mandatory across at least ten states, including California, Colorado, Connecticut, and Texas. Signal-based tooling isn’t optional anymore.
  • Map your ADMT exposure. California’s automated decision-making rules, active since January 1, 2026, require opt-outs and human review wherever a system “substantially replaces” human judgment. That catches recommendation engines, hiring tools, and credit or insurance scoring, features teams rarely think of as privacy-law triggers.
  • Budget for neural data as a new category. If your roadmap includes wearables, VR or AR, or biometric sensors, four states already require opt-in consent for that data, with ten more drafting bills.

California’s own enforcement numbers back up the urgency. CalPrivacy’s Delete Act platform, DROP, launched January 1, 2026 and let residents file one deletion request against every registered data broker at once. Within weeks it had drawn more than 215,000 consumer sign-ups, against 545 registered data brokers, the highest count the state has ever recorded.

“A game-changer for consumer privacy.” Tom Kemp, Executive Director, California Privacy Protection Agency

Kemp told IAPP the early adoption numbers show real pent-up demand for a free, scaled deletion tool, a signal that consumer-side privacy tooling, not just enforcement, is becoming a permanent part of the landscape.

Is a fifty-state patchwork the most efficient way to protect consumer data? Almost certainly not. But it’s the system that exists, and it’s the one your legal and engineering teams have to design around today, not the one Congress might eventually pass.


Frequently Asked Questions

How many U.S. states have data privacy laws in 2026?

Twenty U.S. states have comprehensive consumer privacy laws in effect as of mid-2026, following the addition of Indiana, Kentucky, and Rhode Island on January 1, 2026. No federal equivalent exists, so coverage and consumer rights still vary meaningfully by state.

What new privacy laws take effect in 2026?

Indiana, Kentucky, and Rhode Island’s comprehensive privacy laws took effect January 1, 2026. Connecticut’s neural data rule and other amendments took effect July 1, and New Jersey’s sensitive-data sale ban took effect immediately on June 30, 2026.

Is there a federal data privacy law in the U.S.?

No. The American Privacy Rights Act (APRA), the most advanced federal privacy bill in years, expired without a vote at the end of the 118th Congress in January 2025 and has not been reintroduced as of mid-2026, leaving states as the primary regulators.

How is GDPR different from U.S. state privacy laws?

GDPR requires opt-in consent before most data collection or tracking begins. Most U.S. state laws use an opt-out model instead: businesses can collect and process data by default, and consumers must actively exercise rights to stop sale or sharing of their information.

What is neural data and why is it being regulated?

Neural data is information generated by measuring activity in a person’s nervous system, often via wearables, VR or AR headsets, or medical devices. Colorado, California, Montana, and Connecticut now classify it as sensitive personal data requiring opt-in consent.

What was the largest state privacy settlement in U.S. history?

Texas’s $1.375 billion settlement with Google, finalized October 31, 2025, over geolocation tracking, Incognito mode data collection, and biometric identifiers captured without proper consent, the largest privacy recovery any single state has obtained against Google.


Where this goes next

What you now know that you didn’t before: GDPR set the template, but it no longer sets the ceiling. In enforcement dollars, the US states have pulled ahead, and they’re doing it with a fundamentally different design, opt-out instead of opt-in, that no amount of new legislation is bridging.

Three things worth watching over the next six to eighteen months: whether more states follow Connecticut into regulating neural data before consumer neurotech actually reaches mass adoption, whether cure-period expirations in Delaware, Montana, and New Jersey produce a visible spike in first-strike lawsuits, and whether California’s ADMT rules become the template other states copy for regulating AI-driven decisions inside existing privacy law rather than separate AI statutes.

None of it waits for Congress. Plan accordingly.

Subscribe to The Neural Loop at neuralwired.com/newsletter for the next update before it hits your compliance queue.

Leave a Reply

Your email address will not be published. Required fields are marked *