On July 1, 2026, amended data privacy laws in Connecticut, Arkansas, and Utah took effect alongside a new Virginia restriction on selling precise geolocation data. Connecticut's lower applicability threshold now pulls in thousands of previously exempt businesses, Arkansas introduced tiered parental consent for minors, and Virginia joined a growing list of states restricting location data sales.
In other words, July 1, 2026, was not a quiet day for U.S. data privacy law. These significant legislative changes take effect simultaneously, adding new obligations for businesses that collect, process, or sell consumer data. For marketing, legal, and IT/compliance teams managing a national or multi-state customer base, the question is straightforward: Does your organization need to act?
Nearly 20 states now have comprehensive data privacy laws on the books. The July 1 changes are just one milestone in an accelerating, ongoing patchwork, and understanding what shifted is the first step to knowing whether your business is affected.
This post covers exactly what changed, why it matters, what your team should consider doing now, and what's coming next on the privacy law calendar through 2027.

What Changed on July 1, 2026?
Here is a breakdown of four of the most significant updates to US data privacy laws this year, all of which took effect on July 1. This information is sourced from analysis published by Ice Miller and Morgan Lewis and is for educational purposes only. It should not be considered legal advice, and organizations should consult qualified legal counsel regarding privacy, compliance, and regulatory matters specific to their business.
Connecticut — CTDPA Amendments
Connecticut's amendments to the Connecticut Data Privacy Act (CTDPA) represent the most far-reaching of the July 1 changes.
| Policy Change | Description |
|---|---|
Lower Applicability Threshold | The consumer volume threshold was reduced from 100,000 to 35,000 consumers, meaning the law now applies to significantly more businesses than it did before. Additionally, any organization that processes sensitive data or sells personal user data now falls within the scope of the law, regardless of user volume. |
Narrower Exemptions | An entity-level exemption that was created by the Gramm-Leach-Bliley Act was replaced with a data-level exemption. This means organizations will likely need to conduct a closer, category-by-category review to determine what data is out of scope. |
Expanded Sensitive Data Definition | The definition of “sensitive data” now includes government-issued identifying information, Social Security numbers, information about financial accounts, neural data, and certain types of biometric and genetic data. Importantly, none of these categories may be sold without explicit consumer consent. |
LLM Training Disclosure Requirement | Organizations must now disclose when personal data is used to train large language models. This is a new obligation that will require privacy notice updates for many companies operating AI-integrated systems. |
Note: Connecticut also rolled out new impact assessment obligations regarding automated data processing and profiling. Those changes took effect on August 1, 2026, and additional CTDPA amendments, including a precise geolocation data sale prohibition, are effective October 1, 2026.
Arkansas — Children and Teens' Online Privacy Protection Act
Arkansas's new law is intended to increase protections for children and teens. It applies to for-profit entities that operate websites, apps, or online services directed at children or teens, or that have actual knowledge they are collecting personal data from minors.
| Policy Change | Description |
|---|---|
Two-Tiered Consent Structure | Parental consent is required to collect data for children aged 12 and under. Users aged 13–16 may provide consent themselves or through a parent. |
Targeted Advertising Prohibition | Using minors' personal data to serve targeted advertising is prohibited outright. |
Data Minimization | Collection and retention of minors' data must align with data minimization principles, and organizations may not collect more than what is necessary for the stated purpose. |
Enforcement | The Arkansas Attorney General holds exclusive enforcement authority. There is no private right of action. Nonprofits, government bodies, and educational institutions are excluded from coverage. |
Utah — UCPA Amendments
Utah's amendments to the Utah Consumer Privacy Act (UCPA) focus on social media.
| Policy Change | Description |
|---|---|
Data Portability and Interoperability | Users gain expanded rights to access and transfer their data across platforms, giving them greater control over their personal information. The broader structure of the UCPA, including its existing enforcement framework, remains unchanged. The UCPA just added the new right to correct inaccurate data effective July 1, 2026. |
Virginia — Geolocation Data Sale Ban
Virginia's amendment prohibiting the sale of precise geolocation data took effect July 1, 2026. Virginia joins Maryland and Oregon in restricting this practice at the state level. Connecticut's similar ban is effective as of October 1, 2026, signaling a clear national trend toward tighter controls on location data. Express consent is now required before collecting, disclosing, or using precise geolocation data.
Why These Changes Matter
Collectively, these data privacy compliance updates reflect three broader trends that compliance teams cannot afford to overlook:
| Trend | Impact |
|---|---|
| More businesses are now in scope. | Connecticut's threshold drop from 100,000 to 35,000 consumers, combined with its volume-agnostic sensitive data trigger, brings organizations into the CTDPA that may never have met the criteria previously. For businesses that process any of the newly expanded sensitive data categories and serve Connecticut residents, the law may now apply regardless of scale. |
| Youth privacy is a growing legislative priority. | Arkansas's law is part of a broader movement. Organizations that market to audiences that include minors, or that operate platforms where minors may register or engage, can expect more states to introduce similar consent tiers and targeted advertising restrictions in the future. |
| Geolocation restrictions are becoming standard, not exceptional. | Virginia now joins Maryland and Oregon with a geolocation sale ban, and Connecticut follows in October. For businesses that share or monetize precise location data as part of their ad tech or CRM stack, these restrictions are converging toward a de facto national standard. Waiting for a federal law is not a viable compliance strategy. |
For a broader framework on how legal, technical, and management functions each contribute to privacy compliance, see Americaneagle.com's post on The Three Pillars of Digital Privacy Protection.
Key Considerations Following the July 1 Changes
Not every business will be affected by the July 1 changes in the same way, if at all. However, the updates highlight several areas that organizations may want to examine more closely. These are particularly relevant if your organization collects sensitive data, engages with minors online, uses personal data in AI systems, or relies on geolocation information as part of your marketing or technology stack.
Here are some areas to consider:
| Consideration | Impact |
|---|---|
Scope Under Connecticut's CTDPA | Even if your organization previously fell below the 100,000-consumer threshold, consider whether the 35,000-consumer threshold or the sensitive data trigger now applies. Volume is no longer the only relevant factor. |
Updates to Privacy Notices | Connecticut's expanded sensitive data categories and its new LLM training disclosure requirement will necessitate privacy policy updates for organizations subject to the CTDPA. Consider reviewing notices against the full list of newly covered data types. |
Consent Flows and Data Collection Practices | If your website, app, or platform could reach minors, Arkansas's two-tiered consent model may apply. It may be beneficial to map your user base and assess whether existing consent mechanisms meet the new requirements. |
Geolocation Data Practices | If your organization sells or shares precise location data, directly or through third-party integrations, Virginia's ban requires immediate review. Connecticut's similar prohibition is effective October 1, 2026. |
Consumer Rights Processes | Expanded profiling opt-out rights and other evolving consumer rights under these amendments require that your team can operationally respond to requests. Consider testing those workflows now. |
What Comes Next in Privacy Law
July 1 is not the last major milestone on the privacy law calendar. Additional state privacy laws, amendments, and enforcement provisions are scheduled to take effect through mid-2027. Here’s a quick look at the continuing expansion of the U.S. privacy regulatory landscape:
| Effective Date | Policy Change |
|---|---|
August 1, 2026 | California's DELETE Act data broker registration and deletion mechanism becomes fully operational. Connecticut's new data protection impact assessment obligations also take effect this day. |
October 1, 2026 | Additional Connecticut CTDPA amendments take effect, including Connecticut's own ban on selling precise geolocation data. |
January 1, 2027 | Oklahoma and Louisiana’s comprehensive consumer privacy law takes effect. |
May 1, 2027 | Alabama's comprehensive consumer privacy law takes effect. |
For organizations operating across state lines, each of these dates represents another potential scope review, notice update, or consent flow adjustment. Building a standing compliance calendar, rather than reacting at each deadline, is increasingly the only smart approach.
Why Work with Americaneagle.com on Data Privacy Compliance?
Many businesses simply do not have the bandwidth to track every state-level policy change, assess their applicability in real time, and implement the required technical and policy changes across their website, third-party integrations, and data flows. That is precisely where Americaneagle.com's compliance auditing experience becomes relevant.
Americaneagle.com has hands-on experience auditing websites and third-party systems for GDPR, CCPA/CPRA, and broader U.S. state privacy compliance; reviewing data collection entry points, cookie and consent configurations, consumer rights workflows, and vendor integrations. Our team's approach addresses the full compliance picture, not just one regulation at a time.
If the July 1 changes have raised questions about your organization's current compliance posture, contact Americaneagle.com to discuss a privacy and compliance audit.
Related FAQs
What state privacy laws took effect on July 1, 2026?
Four state privacy law changes took effect on July 1, 2026: amendments to Connecticut's Connecticut Data Privacy Act (CTDPA) under SB 1295, Arkansas's Children and Teens' Online Privacy Protection Act (HB 1717), amendments to Utah's Consumer Privacy Act (UCPA) under HB 418, and Virginia's new prohibition on selling precise geolocation data.
Does Connecticut's updated privacy law now apply to smaller businesses?
Yes. Connecticut's amendments lowered the consumer threshold from 100,000 to 35,000 consumers. Additionally, any organization that processes sensitive data or sells personal data now falls within the CTDPA's scope regardless of volume.
What does Arkansas's new children's privacy law require?
Arkansas's HB 1717 applies to for-profit operators of websites, apps, and online services directed at minors or with actual knowledge of collecting minors' data. It requires parental consent for children 12 and under, allows users 13–16 to consent themselves or via a parent, prohibits targeted advertising based on minors' personal data, and mandates data minimization. Enforcement rests exclusively with the Arkansas Attorney General—there is no private right of action.
Is my company affected by these changes if I don't operate in Connecticut, Arkansas, or Utah?
Potentially, yes. Virginia's geolocation sale ban applies to businesses that sell precise location data involving Virginia residents regardless of where the business is headquartered. Connecticut's lower threshold and sensitive data trigger may also capture organizations that do not consider themselves "Connecticut businesses" but serve Connecticut consumers online. State privacy laws generally apply based on where consumers are located, not where the business is based.
What other state privacy laws are coming in 2026 and 2027?
Key effective dates include: California's DELETE Act data broker mechanism (August 1, 2026), additional Connecticut CTDPA amendments including a geolocation sale ban (October 1, 2026), Oklahoma and Louisiana's comprehensive privacy law (January 1, 2027), and Alabama's comprehensive privacy law (May 1, 2027).
Do I need to update my cookie consent banner because of these changes?
Possibly. Connecticut's expanded sensitive data categories and its new LLM training disclosure requirement may necessitate updates to your privacy notice and consent flows if your organization is subject to the CTDPA. If your site or app reaches minors, Arkansas's consent requirements may also affect how you collect and document consent.
Disclaimer: This content is for informational purposes only and does not constitute legal advice. All effective dates and provisions referenced below are sourced from law firm publications by Ice Miller and Morgan Lewis, current as of early August 2026. Organizations with specific compliance questions should consult qualified legal counsel.

