Brass scales of justice on a wooden desk with law books in the background
Photo via Unsplash

TL;DR: US states issued $3.45 billion in privacy fines against companies in 2025, nearly double the $1.83 billion from 2024, and more than the previous five years combined. California’s leading the charge with record CCPA enforcement. Ten states have formed a consortium to coordinate investigations. And regulators are now turning their attention to how companies use your data to train AI. If your favorite app has been ignoring your opt-out requests, the bill is finally coming due.

The Numbers Don’t Lie

Gartner dropped the data on April 28: US states fined companies $3.45 billion for privacy violations in 2025 [1]. That’s not a typo. Three point four five billion dollars. For context, that’s more than the EU’s GDPR fines for the same period (€3.01 billion across 833 cases) [2].

The jump is staggering. In 2024, state privacy fines totaled $1.83 billion. In 2025, they nearly doubled. The total exceeds what states collected across the entire previous five-year period combined [1].

For years, tech companies treated US state privacy laws as suggestion boxes. Pass a law, wait for enforcement, find out the regulators have no teeth. That calculation just got very expensive.

California Is Done Warning You

The California Privacy Protection Agency (the dedicated regulator created by the CCPA) spent 2024 sending letters and doing outreach. In 2025, it started writing checks. Big ones.

The poster child: Disney. In February 2026, California Attorney General Rob Bonta announced a $2.75 million settlement, the largest CCPA enforcement action in history, after investigators found Disney’s streaming services weren’t actually honoring opt-out requests [3].

The details are infuriating. When Disney customers used the web form to opt out of data sales, it only stopped Disney’s own advertising platforms. Third-party tracking pixels embedded in the service kept right on sharing data. When customers used Global Privacy Control (the browser-level opt-out signal) Disney applied it only to the specific device, even when the customer was logged into their account [3].

Translation: Disney built an opt-out that didn’t actually opt you out. California noticed.

Disney isn’t alone. The CPPA went after Ford and PlayOn Sports in 2025 [1]. The agency is targeting companies across tech, automotive, consumer products, and apparel, not just the usual Big Tech suspects [1].

“Unfortunately what happens when so much time passes between the legislation and starting enforcement regularly, is a lot of organizations let their privacy program atrophy,” said Nader Henein, VP analyst at Gartner [1]. Companies got comfortable. That comfort period is over.

Ten States Are Hunting Together Now

Here’s the part that should make corporate legal departments sweat: states aren’t working alone anymore.

In April 2025, eight states formed the Consortium of Privacy Regulators. By October, Minnesota and New Hampshire had joined, bringing the total to ten. The current roster: the California Privacy Protection Agency plus Attorneys General from California, Colorado, Connecticut, Delaware, Indiana, Minnesota, New Hampshire, New Jersey, and Oregon [4].

What they’re doing: sharing investigative resources, coordinating enforcement actions, and targeting companies that violate privacy laws across state lines. A company that buries opt-out settings in California is probably doing the same thing in Colorado and Connecticut. Now one investigation can trigger enforcement in multiple states simultaneously.

Twenty-two states currently have consumer privacy laws on the books, covering more than half the US population [2]. Another 24 states have introduced similar legislation. Gartner expects most of them to pass within five years [2]. The enforcement infrastructure is scaling to match.

AI Is the Next Target

The $3.45 billion was mostly about traditional privacy violations: companies ignoring opt-out requests, failing to honor deletion rights, sharing data without consent. The next wave is about AI.

Regulators are already focused on how companies use personal data to train AI models and how automated systems make inferences about people [1]. State legislatures are responding to what Gartner calls constituent “AI anxiety,” writing new amendments that specifically target automated decision-making technologies [2].

If you’ve ever wondered whether that chatbot your insurance company uses to deny claims was trained on your data, regulators are starting to ask the same question. With subpoena power.

The US Is Catching Up to Europe

For years, GDPR was the privacy enforcement gold standard. European regulators handed out billions in fines while US states watched from the sidelines. That gap is closing fast.

The EU issued €3.01 billion in GDPR fines across 833 cases in 2025 [2]. The US hit $3.45 billion. Depending on the exchange rate, American states are now either matching or exceeding European enforcement in raw dollar terms.

The pattern mirrors what happened with data breach disclosure laws. California passed the first breach notification law in 2003. Alabama was the last state to follow in 2018. Now every state has one. Privacy enforcement is on the same trajectory: it just moves faster because the template already exists [2].

What This Means for You

Two things.

First, your opt-out rights are real. Companies spent years building dark patterns to discourage you from exercising them. Now there’s a financial consequence for companies that don’t honor those requests. Use them. Install Global Privacy Control in your browser. Submit deletion requests. File complaints with your state’s AG or privacy regulator when companies drag their feet.

Second, the federal government isn’t coming to save you. Every attempt at a national privacy law has stalled in Congress, partly because industry lobbyists push for federal preemption: a national law that would override stronger state protections. Tom Kemp, Executive Director of the California Privacy Protection Agency, warned directly: “Preemption would strip away important existing state privacy provisions that protect tens of millions of Americans now” [1].

The states are the privacy cops. And they just proved they’re willing to use the badge.

Bottom Line

$3.45 billion is a record. Gartner says the trend will accelerate through 2028 [1]. More states are passing privacy laws. More regulators are coordinating enforcement. And the companies that treated privacy compliance as optional are about to find out what “mandatory” looks like.

The era of privacy laws without teeth is ending. About time.

References

  1. CyberScoop: “U.S. companies hit with record fines for privacy in 2025” (April 28, 2026)
  2. Help Net Security: “US state privacy fines reached $3.425 billion in 2025” (April 28, 2026)
  3. California Attorney General: “California Won’t Let It Go: Attorney General Bonta Announces $2.75 Million Settlement with Disney” (February 2026)
  4. California Privacy Protection Agency: “Minnesota and New Hampshire Join Bipartisan Consortium” (October 2025)