Technology & Privacy, Tax & Budgets
How States Are Taxing Digital Goods, Social Media, and Targeted Advertising
July 30, 2026 | Andrew Jones
September 18, 2026 | Max Rieper
Key Takeaways:
State legislatures have driven much of the debate over data privacy in recent years, enacting a growing patchwork of comprehensive privacy laws and more targeted protections. But lawmakers are not the only state officials shaping privacy policy. Attorneys general and state agencies are increasingly using both privacy laws and broader consumer protection statutes to scrutinize how companies collect, use, and share personal information.
Enforcement activity has picked up in recent years. According to the Future of Privacy Forum, 15 enforcement actions under state comprehensive privacy laws were publicly announced, filed, or settled in 2025, compared with just three public enforcement actions under the new generation of comprehensive privacy laws prior to that year. This year, state regulators are pursuing a growing range of privacy violations.
State privacy laws generally provide heightened protections for certain categories of “sensitive data,” which can include information about a person’s health, finances, precise location, genetics or biometrics, among other categories. Recent enforcement actions show that state regulators are paying particular attention to how companies protect and share these especially sensitive types of information, even when they are acting under laws other than comprehensive state privacy statutes.
This summer, 42 states reached an $18 million settlement with genetic testing company 23andMe over a 2023 breach affecting 6.9 million customers. This month, Connecticut reached a $275,000 settlement with online tax preparation service TaxAct over allegations that it used tracking technologies that transmitted sensitive taxpayer information to Meta and Google. In Utah, Attorney General Derek Brown has filed a suit against Hims & Hers Health, Inc., alleging the company improperly shared customers' private health information with third parties, alongside other consumer-protection allegations. California Attorney General Rob Bonta secured a $12.75 million settlement with GM over allegations it sold location information to data brokers without consent.
Sensitive data
Sensitive data refers to categories of personal information that require heightened protection under privacy laws, such as health information, financial data, precise location, genetic or biometric details. State privacy statutes often impose stricter requirements on the collection, use, and sharing of this information due to the increased risk of harm if it is misused or disclosed.
Privacy statutes are only one tool available to state regulators. Attorneys general are also using longstanding consumer protection laws to challenge data practices they consider deceptive or unfair.
This week, Meta reached an $18 billion settlement with 47 states alleging Facebook and Instagram included features allegedly designed to encourage compulsive use among children, including infinite scroll, auto-play, and push notifications. Part of the suit involved allegations that it also violated children’s privacy law by collecting personal information from users under 13 without parental consent. In March, New Mexico Attorney General Raúl Torrez won a $375 million case against Meta when a jury found they had violated the state’s Unfair Practices Act by misleading consumers about the safety of Facebook and Instagram. This summer, a court ordered Meta to pay an additional $567 million after finding that the platforms constituted a public nuisance that contributed to youth mental health harms, addiction, and sexual exploitation.
Texas Attorney General Ken Paxton has aggressively challenged companies over their data practices. He sued Netflix under the Texas Deceptive Trade Practices Act (DTPA), alleging the company extensively tracked users’ viewing habits, preferences, devices, network information, and other behavioral data, including data from children’s profiles, despite representations about its data collection and sharing practices. He also reached a settlement with LG over allegations that the company used Automated Content Recognition technology in its televisions to collect consumers’ viewing data without informed consent, in violation of the DTPA.
These cases illustrate that platforms may face enforcement risk even in states that have not enacted laws specifically regulating children's online experiences. Attorneys general can use existing consumer protection statutes to challenge practices they consider deceptive or unfair, including representations about platform safety and the use of features designed to encourage compulsive use.
Some states require certain obligations on data controllers and brokers, and have begun ramping up enforcement of those laws. California is the only state with a stand-alone agency dedicated exclusively to privacy enforcement. The California Privacy Protection Agency Board settled with Ford earlier this year over allegations that the company required consumers to verify their identity before they could opt out, causing “unnecessary friction” and constituting a violation of California Consumer Privacy Act regulations.
This month, the agency also began issuing its first fines to data brokers for failing to register under the Delete Act. The growing patchwork of state privacy laws is only part of the enforcement landscape. Even where a comprehensive privacy statute does not apply, attorneys general are increasingly using consumer protection and other existing laws to challenge how companies collect, share, and characterize their use of personal information.
MultiState’s team is actively identifying and tracking Technology and Privacy issues so that businesses and organizations have the information they need to navigate and effectively engage. If your organization would like to further track these or other related issues, please contact us.
What types of sensitive data are state attorneys general targeting in recent privacy enforcement actions?
State regulators are focusing enforcement on health information, financial data, precise location data, genetic information, and biometric data. Recent actions include cases against genetic testing companies for data breaches, tax preparation services for sharing taxpayer information with tech platforms, telehealth companies for improperly disclosing health data, and automakers for selling location data to brokers without consent.
Can state attorneys general enforce privacy violations in states without comprehensive privacy laws?
Yes, attorneys general can use longstanding consumer protection statutes to challenge data practices they consider deceptive or unfair, even without comprehensive privacy laws. Texas, for example, has used its Deceptive Trade Practices Act to sue companies over tracking practices and smart TV data collection, while New Mexico used its Unfair Practices Act to secure a $375 million verdict against Meta for misleading consumers about platform safety.
What privacy violations is California's Privacy Protection Agency currently enforcing?
The California Privacy Protection Agency is enforcing violations related to identity verification requirements that create unnecessary friction in the opt-out process, as demonstrated in its settlement with Ford. The agency is also issuing fines to data brokers for failing to register under the Delete Act, marking its first enforcement actions specifically targeting data broker compliance.
Are state regulators taking action against features designed to encourage compulsive use of social media platforms?
Yes, 47 states reached an $18 billion settlement with Meta over allegations that Facebook and Instagram included features like infinite scroll, auto-play, and push notifications designed to encourage compulsive use among children. The case also included allegations of collecting personal information from users under 13 without parental consent, demonstrating that regulators are addressing both addictive design features and privacy violations together.
How are state attorneys general addressing the collection of children's data on platforms?
State attorneys general are pursuing enforcement through both privacy-specific violations and broader consumer protection claims related to children's data collection. Actions have targeted platforms for collecting personal information from users under 13 without parental consent, tracking data from children's profiles despite privacy representations, and creating public nuisances that contribute to youth mental health harms and exploitation.
July 30, 2026 | Andrew Jones
April 30, 2026 | Max Rieper
April 30, 2026 | Katherine Tschopp