Is Your Company Ready for the Data Privacy Laws of 2026?
September 2025
September 2025
Data privacy in the United States is becoming increasingly difficult to manage as states continue adopting their own requirements. For businesses operating across multiple jurisdictions, the challenge is no longer limited to protecting information from unauthorized access. Organizations must also understand what personal data they collect, why they collect it, where it is stored, who receives it, and how long it should be retained.
Additional state laws were scheduled to become effective in 2026, including comprehensive consumer privacy laws in Indiana and Kentucky. These laws joined an expanding state-level framework with different applicability thresholds, exemptions, consumer rights, and enforcement provisions. Indiana General Assembly Kentucky Attorney General
This does not mean every organization is covered by every new law. It does mean that businesses can no longer treat privacy as a one-time policy exercise.
One of the most common privacy mistakes is assuming that a law applies—or does not apply—based only on company size. State privacy laws may consider where an organization conducts business, the number of residents whose data it processes, whether it sells personal data, and the percentage of revenue associated with those activities.
Kentucky’s law, for example, applies when specified processing or revenue thresholds are met. It also contains exemptions for certain organizations and categories of information. A small business may fall outside a comprehensive state privacy statute while still being subject to contractual obligations, cybersecurity requirements, breach-notification laws, industry rules, or other privacy protections. Kentucky Legislature
The right starting point is therefore a jurisdiction-specific applicability review rather than a general assumption that every privacy law covers every business.
The original discussion surrounding the 2026 laws often blurred an important distinction between consumer information and workforce information. Many comprehensive state consumer privacy laws exclude individuals acting in an employment context. Kentucky’s statutory definition of “consumer,” for example, does not include a person acting in a commercial or employment context. Kentucky Legislature
That exclusion should not be interpreted to mean that employee information is unregulated. Workforce records may still be governed by employment laws, breach-notification requirements, health-information rules, biometric privacy laws, contractual commitments, and internal confidentiality obligations.
California also requires separate attention. The temporary CCPA exemptions for employment-related information expired on December 31, 2022. Covered businesses must therefore consider how California privacy requirements affect the personal information of employees, applicants, independent contractors, and other individuals in the employment context. California Privacy Protection Agency
Organizations should determine which rules apply to each category of information instead of placing consumer, employee, applicant, contractor, and customer data into a single compliance analysis.
Privacy risk is not confined to sophisticated databases. It frequently develops through routine business practices: collecting information that is never used, retaining former employee records without a defined schedule, sharing spreadsheets too broadly, allowing inactive accounts to remain open, or introducing monitoring technology without reviewing what it captures.
A practical assessment should trace the full information lifecycle:
What personal information is collected?
What business or legal purpose supports the collection?
Where is the information stored?
Who can access or disclose it?
Which vendors process it?
How long is it retained?
How is it corrected, retrieved, or securely destroyed?
This process often reveals that an organization’s greatest privacy weakness is not the absence of technology but the absence of ownership. When no one is responsible for a dataset or process, access expands, retention becomes indefinite, and outdated information remains in circulation.
Privacy readiness requires coordination among leadership, operations, HR, technology, security, legal, and any other function that collects or manages personal information. Responsibilities should be clearly assigned, but privacy cannot be delegated entirely to one department.
Organizations preparing for changing requirements should inventory their data, confirm applicable jurisdictions and thresholds, review privacy notices, assess vendor contracts, establish defensible retention practices, and create a workable process for responding to requests and incidents. Any use of biometric information, workforce monitoring, or AI-supported decision-making deserves additional review because these activities may create obligations beyond comprehensive consumer privacy laws.
No organization can prepare for changing privacy laws by updating a website notice and considering the work complete. Sustainable privacy management depends on accurate data inventories, controlled access, clear retention decisions, responsible vendor oversight, and periodic review as laws and business practices change.
Companies that establish those disciplines are better positioned to respond when a new law applies, a client requests evidence of privacy practices, or an incident exposes weaknesses in the way information is handled.
The most important question is not whether a business can claim to be ready for every privacy law. It is whether the organization understands its information well enough to identify what applies and act responsibly when requirements change.