US privacy enforcement in 2026 continues to follow a familiar shape: California drives a large share of operational US risk for consumer-facing brands, GDPR remains the primary EU baseline for eCommerce with EU customers, and litigation-driven US privacy risk still includes CIPA demand-letter volume alongside public regulatory actions.
This recap filters developments through an eCommerce and consent-management lens — retail media buyers, DTC operators, and teams responsible for pixels, tags, chat widgets, and DSARs. Items that matter mainly to banks, hospitals, or public-sector entities are largely omitted.
Series note: this is the first installment in PieEye’s quarterly enforcement series. Each issue highlights patterns that map to tools in a typical stack — not every headline from every sector.
CIPA: Q3 2026 activity relevant to eCommerce
Structural pattern (most important): CIPA exposure for most online retailers is still volume-driven — demand letters and dispute programs that rarely produce a clean “headline” settlement statistic. The aggregate risk is often in pre-litigation economics and operational distraction, not a single public decision.
Frasco v. Flo Health (August 2025) remains a useful precedent for health-adjacent beauty and wellness brands: plaintiffs continue to argue that certain tracking integrations create elevated risk where product context can imply sensitive adjacency. If your catalog straddles “wellness,” treat disclosures and consent timing as high priority.
Session replay remains a frequent category in tracking-focused claims alongside advertising pixels — the exact docket mix in any quarter varies by firm strategy [VERIFY: monitor PACER/firm reporting for your industry].
Statutory damages: CIPA Section 637.2 provides a private right of action with statutory damages of $5,000 per violation (or three times actual damages, whichever is greater) — a structural driver of demand-letter economics.
Internal resources: what a CIPA demand letter means and your response protocol · what the Frasco v. Flo Health verdict means for health-adjacent eCommerce.
CPPA: Q3 2026 highlights
Public California Privacy Protection Agency (CPPA) activity earlier in 2026 illustrates the agency’s willingness to pursue opt-out mechanics, notice quality, and preference-signal issues — not only “data breach” cases.
-
March 3, 2026: the CPPA announced a $1.10 million settlement with PlayOn Sports / GoFan alleging, among other items, failures related to targeted advertising opt-out, honoring opt-out preference signals, inadequate privacy notices, and conditioning service on acceptance of tracking — issues that map directly to common eCommerce stack misconfigurations.
Source: California AG/CPPA public announcement materials summarized by major law firms (e.g., WilmerHale, White & Case) [VERIFY: read the official CPPA decision and consent terms for your records]. -
January 2026: the CPPA publicized enforcement settlements involving data brokers (e.g., Datamasters and S&P Global matters described in agency announcements) — more relevant to data-broker business models, but a reminder that registry and sale/sharing obligations are active enforcement paths [VERIFY].
GPC + automation: the DROP compliance signal system remains central to how California regulators can identify notice and opt-out gaps without waiting for individual complaints. For eCommerce, the practical lesson is unchanged: treat Global Privacy Control as a real-time constraint on sale/sharing flows.
Internal resource: how the CalPrivacy DROP system works and what it can detect.
Related playbook: universal opt-out and GPC for eCommerce in 2026.
GDPR: Q3 2026 themes for online retail
EU enforcement continues to cluster around:
- Cookie/adtech consent quality (invalid “consent” banners, pre-checked boxes, continued firing after rejection).
- International transfers and SCC/TIA documentation — still active post-Schrems II.
- DSAR throughput — missed deadlines and incomplete responses.
The EU’s broader Digital Omnibus / simplification agenda moved through legislative stages in 2026 [VERIFY: confirm the exact stage as of your publication date with primary EU sources] — it does not remove core GDPR duties today.
VPPA: Salazar v. Paramount — status update
The Supreme Court granted certiorari in Salazar v. Paramount Global on January 26, 2026 (Docket No. 25-459) [VERIFY: confirm on the Supreme Court docket]. The Court is positioned to address who qualifies as a “consumer” under the Video Privacy Protection Act (VPPA) — a circuit split with practical consequences for brands embedding video and subscription flows.
What is at stake for eCommerce: if you use video heavily in commerce experiences, VPPA litigation risk can track subscription relationships and pixel placement strategies. Outcomes may narrow or widen exposure depending on how the Court defines the statutory consumer relationship.
Internal resource: the VPPA circuit split and what Salazar may resolve.
Three compliance actions signaled this quarter
1. GPC audit (this week)
Verify your CMP honors GPC for covered sale/sharing processing. Test with a GPC-enabled browser profile — advertising tags should not fire when the signal opts out.
2. Session replay contract review (this month)
If you use replay tools, align vendor contracts with counsel’s Graham v. Noom playbook and keep replay consent-gated.
3. DSAR backlog check (this month)
Confirm no requests are approaching GDPR 30-day or CPRA 45-day deadlines due to manual routing.
Internal resource: how to audit your full AdTech stack for CIPA and GDPR exposure in one place.
About this series
This quarterly series publishes at the start of each new quarter. Each issue focuses on enforcement, guidance, and litigation trends that matter to eCommerce teams and consent infrastructure. Subscribe to the PieEye newsletter to receive updates.
This article is for informational purposes and does not constitute legal advice. Citations to agency actions should be verified against primary government sources before reliance.
