Companies that collect, process, or share consumer data across multiple states face a materially expanded compliance landscape as of July 1, 2026. A wave of new state privacy statutes and amendments took effect on that date, and businesses operating on a multistate basis should move promptly to review internal policies, contractual arrangements, and consumer-facing disclosures to align with the updated requirements.
Among the most significant developments, Arkansas's new comprehensive privacy statute is now in force. Its arrival adds another jurisdiction to the growing patchwork of state privacy regimes, and organizations that previously scoped their compliance programs around a smaller number of states should assess whether Arkansas residents' data is within the reach of the new law and, if so, update their data inventories, consumer rights response workflows, and vendor agreements accordingly.
Utah has also expanded its privacy framework by introducing a new right to correct inaccurate personal data. Businesses subject to Utah's regime should confirm that their intake and verification procedures can accommodate correction requests within applicable timelines, and that customer service and privacy teams are trained to identify and process these requests consistently with the amended statute.
Connecticut's amendments to the Connecticut Data Privacy Act (CTDPA) introduce particularly notable changes. The definition of sensitive data has been expanded to include neural data and government-issued identification numbers, categories that will require heightened handling, disclosure, and safeguarding practices. Companies collecting these data types should evaluate whether their existing classification schemes and privacy notices accurately reflect the broadened scope.
The CTDPA amendments also prohibit the sale of sensitive data without consumer consent. Businesses that monetize data, engage in targeted advertising, or share information with third parties for commercial purposes should carefully review their data flows and update consent mechanisms so that any sale of sensitive data is preceded by a valid, affirmative opt-in from the consumer.
Taken together, these developments underscore the continuing fragmentation and intensification of state-level privacy regulation. Organizations should prioritize gap assessments, refreshed employee training, and updates to public-facing privacy notices in the near term.
This article is provided for general informational purposes only and does not constitute legal advice. Clients should seek tailored guidance regarding their specific circumstances.