Eight state regulators, including the California Privacy Protection Agency and attorneys general from seven states, formed the bipartisan Consortium of Privacy Regulators to collaborate on the implementation and enforcement of their privacy laws. The group aims to share expertise, resources, and coordinate investigations to protect consumer privacy across jurisdictions.
This announcement does not involve a specific enforcement action, but it signals increased coordination among state regulators, which may lead to more consistent and aggressive enforcement across jurisdictions. In-house legal teams should review their data processing and sharing agreements to ensure compliance with all applicable state privacy laws, particularly regarding consumer rights (access, delete, opt-out), and consider including provisions that address multi-state regulatory requirements. Vendor agreements should be audited for clauses on data use, consent mechanisms, and breach notification that align with the common features of state laws highlighted by the consortium.
Entity
Consortium of Privacy Regulators (California, Colorado, Connecticut, Delaware, Indiana, New Jersey, Oregon)
Industry
Other"The Consortium of Privacy Regulators is a bipartisan effort that includes state Attorneys General and the California Privacy Protection Agency."
"the California Consumer Privacy Act"
"Eight state regulators are collaborating on the implementation and enforcement of their privacy laws with the shared goal of protecting consumers."
The California Privacy Protection Agency announced that over 300,000 Californians have signed up for the Delete Request and Opt-out Platform (DROP) since its launch five months ago. The Data Broker Registry now includes 581 registered data brokers, the highest number since the registry was established in 2020. Beginning August 1, 2026, all data brokers will be required to access DROP and process deletion requests.
The California Privacy Protection Agency launched a statewide roadshow to promote its Delete Request and Opt-out Platform (DROP), which allows California residents to request deletion of their personal information from all registered data brokers in a single request. The roadshow aims to increase awareness of data privacy rights and the DROP tool, which data brokers are legally required to process starting August 1, 2026.
$376K
The California Privacy Protection Agency settled with Ford Motor Company for $375,703 after finding that Ford violated the CCPA by requiring email verification for opt-out requests, creating unnecessary friction. Ford must implement easier opt-out methods, conduct a website audit, and comply with global privacy controls.
$1.1M
The California Privacy Protection Agency settled with PlayOn Sports for $1.10 million over CCPA violations, including failing to provide adequate opt-out mechanisms and improperly tracking users, particularly students. The company must implement proper opt-out methods, improve disclosures, and comply with children's data consent requirements.
The California Privacy Protection Agency (CalPrivacy) announced the appointment of Sabrina Boyson Ross as its first Chief Privacy Auditor and the formation of a new Audits Division. The division will conduct regulatory examinations of businesses to determine compliance with the California Consumer Privacy Act, and its findings may lead to enforcement referrals.
$45K
Datamasters, a data broker, failed to register with the California Data Broker Registry as required by the Delete Act. The company sold sensitive personal information including health conditions, age, race, and political views. As a result, it must pay a $45,000 fine and cease all sales of Californians' personal information.