It was a busy week for the privacy compliance patchwork, with a wave of new state laws in the US, a major multistate settlement over genetic data, and regulators on both sides of the Atlantic sharpening their enforcement posture. Here's what actually matters.
New and Pending Legislation
The US state privacy landscape got noticeably more crowded. On June 16, 2026, Vermont Governor Phil Scott signed the Vermont Data Privacy and Online Surveillance Act (S.71)↗ into law, making Vermont the latest state to enact a comprehensive privacy law — notably, it requires disclosure when personal data is used to train AI or large language models, a first-of-its-kind provision worth flagging for any company doing AI development on user data.
Delaware's General Assembly passed HB 380↗, an amendment to the state's Personal Data Privacy Act, which now awaits the governor's signature and would take effect January 1, 2027.
New York City adopted a "Click to Cancel" rule↗, effective October 1, 2026, governing how businesses must disclose, bill, and let consumers cancel subscriptions — a new operational obligation for anyone selling subscriptions to NYC consumers.
Connecticut's newly signed AI law (SB 5↗) extends consumer-protection obligations to subscription marketing, layering onto the state's existing AI companion and employment-decision provisions.
Not every proposal made it through: Colorado's governor vetoed HB 26-1210↗, a broad bill that would have regulated use of "surveillance data" for individualized and algorithmic pricing and wage-setting — a signal that even privacy-forward states have limits on how far they'll go in regulating algorithmic pricing.
Internationally, France became the first EU member state to approve a children's social media ban↗, a move that could set a precedent other EU states follow on minors' online safety enforcement. And in China, the cybersecurity regulator (TC260) proposed significant amendments↗ to its National Standard on Personal Information Protection (GB/T 35273) — the practical rulebook most China-facing data programs are built around — worth watching closely during the comment period if you process China-sourced personal data.
Enforcement
The California Privacy Protection Agency launched its first-ever sectoral CCPA audit sweep↗, targeting gig-economy platforms — a meaningful shift from complaint-driven enforcement to proactive sector audits that other industries should take as a warning sign.
A 42-state coalition, led by Connecticut's Attorney General, finalized a settlement with 23andMe↗ over its 2023 genetic-data breach, one of the largest multistate resolutions yet involving sensitive biometric and genetic data.
In Europe, the EDPB ruled that the Belgian DPA must address the merits↗ of NOYB's cookie-banner complaint rather than deflect it — a signal that regulators are being pushed to stop punting on cookie-consent enforcement.
Litigation
A federal judge dismissed a Wiretap Act claim against Blue Shield of California↗ over its use of Google Analytics and the Meta Pixel, ruling that the complaint named the wrong party as the "interceptor" — Google and Meta, not the health plan itself. The dismissal came with leave to amend and turned on pleading, not on whether the underlying tracking was harmful, so it's a narrower win for site operators than the headline suggests amid the ongoing wave of session-replay and pixel litigation.
The Takeaway
The throughline this week: states aren't slowing down on comprehensive privacy laws (Vermont, Delaware), narrower local rules are adding operational burden even where broad laws don't reach (NYC's Click to Cancel), and regulators — from the CPPA to the EDPB — are moving from reactive to proactive enforcement. Meanwhile, courts are still working out where liability lands in the pixel/session-replay litigation wave, and this week's ruling turned on a pleading technicality rather than settling the underlying question.
Compiled from PieEye's daily Privacy Reg Watch monitoring of regulators, law firms, and industry sources.