close
close
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Data Privacy News

Privacy Dispatch July 2026: The FTC Bans Location Data Sales (With a Catch), Grace Periods Expire, and SCOTUS Weighs In

Kendall Lovett - July 21, 2026

As new rulings, settlements, and regulations stack up each month, our monthly privacy dispatch cuts through the noise to highlight exactly what privacy, legal, and security teams need to know.

Grace periods are disappearing

20 state privacy laws are in effect today, and many of these laws included a cure period that allowed businesses to correct mistakes without fear of fines. As of July 2026, nine of those states’ cure periods are over. A first violation now means enforcement, not a warning.

This is also true for the latest wave of privacy law amendments. For example, Connecticut’s amended Data Privacy Act took effect July 1 with no added cure period, meaning the new requirements are immediately enforceable. 

The amendment brings more businesses in scope, requires public disclosure when using personal data to train LLMs, and classifies neural data, government IDs, and financial credentials as sensitive data. This is important, as the CTDPA requires additional protective measures related to sensitive data, including:

  • Explicit consent is required before processing any sensitive data
  • Any processing of sensitive data must be “reasonably necessary” to its purpose, even when consent has been given
  • Selling sensitive data requires separate, explicit consent, distinct from the consent to collect it

States are adding new laws for data brokerage, children’s privacy, and social media 

The days of only needing to worry about a single comprehensive privacy law for each state appear to be over.

New Jersey joined five other states in passing a new data broker law independent from its primary privacy law. Meanwhile, standalone legislation in other states is advancing on topics like children’s privacy, surveillance pricing, and social media.

 

The Takeaway

Now is a great time to recheck your compliance program against states’ amended compliance thresholds and new carve-out legislation for sensitive data, AI usage, and data brokerage. DataGrail Live Data Map can tell you in hours, not months, whether your sensitive data processing or your AI training disclosures put you in scope. 

Two new Supreme Court rulings impacting data privacy 

The Supreme Court handed down two privacy-impacting rulings this term: the first limits law enforcement’s access to location data, the second weakens the independence of the agency that watches out for consumers.

In Chatrie v. United States, the Court ruled 6-3 that police need a warrant before demanding location data on everyone near a crime scene from apps and cell towers—a tactic known as a geofence warrant. That’s good news for privacy, and it builds on an earlier ruling that already limited how much location data the government can get without one.

In Trump v. Slaughter, the Court voted 6-3 to let the president remove FTC commissioners at will, ending decades of protections that kept the agency’s leadership independent from politics. That matters because the FTC is one of the most active enforcers of privacy law in the country, and its priorities can now shift more easily with each administration.

 

The Takeaway

If the FTC’s strategy can shift with each presidential administration, its recent rulings aren’t necessarily indicative of what FTC enforcement could look like next year or even five years from now. Privacy teams have to build for the strictest plausible reading of their obligations, rather than current posture. At minimum, you should actively monitor risks across your tech stack so that as new enforcement themes come into focus, you can act quickly.

FTC’s Kochava settlement bans sale of sensitive location data, but weakens guardrails

Speaking of the FTC – In May, the FTC finalized a settlement with data broker Kochava and its subsidiary, Collective Data Solutions, banning the sale of sensitive location data without consumer consent while also shrinking the list of “sensitive locations”. The case, which began in 2022, is the latest in a string of FTC actions against data brokers for selling precise location data tied to hospitals, shelters, and places of worship.

According to a recent analysis from former FTC officials, the order is narrower than past settlements against similar data brokers. It reduces the list of protected “sensitive locations,” drops a prior ban on merely using sensitive location data (as opposed to selling it), and no longer requires that retention timeframes be tied to a business purpose.

 

The Takeaway

Even a win for privacy enforcement can leave room for data to be used, not just sold, in ways that create risk. If your vendors or internal teams handle location data or other sensitive categories, don’t assume a narrow legal definition covers every use case worth monitoring. Use our Vendor Risk Assessment Claude skill to evaluate whether the third parties touching your sensitive data are handling it the way your program actually requires, not just the way the law technically permits.

States go beyond COPPA on children’s privacy protections

Florida settled its lawsuit against Roku over children’s data collection under the state’s Digital Bill of Rights. Roku will spend an estimated $25 million over the next year to add parental controls and child-protection features, with no fine and no finding of wrongdoing. 

Arkansas’ Children and Teens’ Online Privacy Protection Act took effect July 1, and enforcement of Nebraska’s Age-Appropriate Design Code began the same day, both extending protections for minors beyond what the federal COPPA (Children’s Online Privacy Protection Act) requires. Texas is separately urging the Supreme Court to keep its app store age-verification law in effect while litigation continues, and G7 data protection authorities used a late-June meeting in Paris to adopt a joint declaration on privacy-preserving age assurance.

 

The Takeaway

States are building design-code and age-verification obligations that sit entirely outside the COPPA checklist most privacy programs already maintain. Meanwhile, app store-level age verification could shift responsibility for age assurance away from individual companies—depending on how the Texas case resolves. 

If your product touches minors’ data in any way, don’t wait to find out the hard way whether you’re compliant. Responsible data discovery can uncover systems containing data from known minors so you can revisit consent flows and data minimization strategies. 

CIPA-style wiretapping and video privacy claims keep testing new ground

Plaintiff lawsuits continue to try and stretch decades-old wiretapping and video privacy statutes to modern tools like chat widgets, session replay software, and embedded video.

In the latest example, a federal judge dismissed—for now—a case against Blue Shield of California over tools like Google Analytics and Meta Pixel running on its website. The claim argued that tracking people’s health-related browsing activity counts as illegal wiretapping. The judge agreed this could create real privacy harm, but ruled Blue Shield can’t be sued for simply having the tools installed. Under the current law, only the company that actually intercepts the data, Google and Meta in this case, can be held liable in that way. 

 

The Takeaway

Attempts to apply wiretapping and video privacy statutes to modern use cases are only increasing and, so far, each ruling or settlement just seems to create more questions than it answers.

Don’t wait for a final ruling to find out where your own tracking tools stand. Confirm your consent opt-outs work as intended, especially on pages where browsing behavior could imply something sensitive. Be aware enough of your compliance posture to know whether you would settle or fight a claim before one arrives. If you’re not sure whether your consent experience is up to snuff, dig into best practices. And if you don’t have a consent banner at all or your consent banner isn’t working, explore DataGrail Consent

Looking ahead

Expect privacy laws to get increasingly specific on sensitive data and children’s privacy, and potential fines to rise in these areas. FTC enforcement patterns may fluctuate, but even in the unlikely case of an enforcement decline, the difference will be made up in-kind through the continuing rise of expensive civil suits under CIPA and VPPA. 

Privacy programs built for continuous visibility, not periodic catch-up, are going to make the difference in the world of rapidly-expanding privacy requirements and declining grace periods. 

DataGrail gives privacy teams exactly that: a clear, up-to-date picture of where sensitive data lives and how it moves, across every system in your environment. Request a demo to see what is possible before the next enforcement wave hits.

Contact Us image

Let’s get started

Ready to level up your privacy program?

We're here to help.