On July 1, 2026, a new wave of state privacy obligations took effect in Connecticut, Arkansas, and Utah, expanding the compliance landscape for companies that handle personal data…


On July 1, 2026, a new wave of state privacy obligations took effect in Connecticut, Arkansas, and Utah, expanding the compliance landscape for companies that handle personal data of residents in these jurisdictions. Businesses that collect, process, or share consumer information should promptly reassess their privacy programs, contracts, and data-handling practices to align with the updated requirements.

Arkansas has taken a notable step with HB 1717, which became the first law in the United States to extend children's online privacy protections to teens up to age 16. Under the statute, businesses are prohibited from using minors' data for targeted advertising. Companies whose products or services are directed to, or reasonably likely to be accessed by, users in this expanded age group should review their data-collection practices, age-assurance mechanisms, advertising technology stacks, and disclosures to ensure that the personal data of covered minors is not processed for targeted marketing purposes.

Utah's HB 418 introduces two significant developments. First, Utah residents now have the right to correct inaccurate personal data held by covered businesses, requiring organizations to implement or refine intake and verification workflows to respond to correction requests. Second, social-media services must enable machine-readable data portability, allowing users to transfer their data in a usable, interoperable format. Companies offering social-media functionality should evaluate their technical infrastructure, export tools, and user interfaces to confirm they can accommodate portability requests as required.

In Connecticut, the state's comprehensive privacy statute has been broadened by lowering the applicability thresholds, pulling additional businesses into its compliance scope. Organizations that previously fell below the prior thresholds should reassess whether they now qualify as covered entities and, if so, promptly implement the required consumer-rights processes, privacy notices, data protection assessments, and vendor agreements.

Collectively, these developments signal a continued trend toward more granular, sector-specific, and youth-focused privacy regulation at the state level. Businesses should coordinate legal, compliance, and engineering teams to update policies, notices, and operational controls without delay.

This article is provided for general informational purposes only and does not constitute legal advice. Clients should consult qualified counsel for guidance tailored to their specific circumstances.