Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Organizations
  • Organizations
    • E-mail Would Get Updated Privacy Protections Under Bicameral Bill
    • Commerce IG Finds Flaws in NIST’s Management of Cyber Vulnerability Database
    • Commerce’s Commitment to Connected Car Ban Questioned Following Volvo Deal
    • Governor Signs Connecticut Bill to Implement New Privacy Protections
    • Luxembourg DPA: Tourist Accommodation Operators May Not Copy ID Documents
    • New York Assembly Committee Advances Proposed Data Protection Act
    • Organizations Should Prioritize Privacy in Chatbot Use, Belgian Regulator Says
    • Privacy Safeguards Required for AI-Powered Employee Stress Monitoring, Garante Says
    • Singapore Cyber Agency Warns of Agentic AI Risks
    • The Week in State Privacy and Cybersecurity Legislation—May 25-29, 2026
  • Articles
  • Articles
  • Organizations
  • Organizations

    Cybersecurity Policy Report, The Week in State Privacy and Cybersecurity Legislation—May 25-29, 2026, (Jun 1, 2026)

    By WK Editorial Staff

    Welcome back to The Week in State Privacy and Cybersecurity Legislation, your weekly update on the latest developments in proposed and amended privacy and data security legislation across the 50 states and the District of Columbia, as well as a summa ...

    By WK Editorial Staff

    Welcome back to The Week in State Privacy and Cybersecurity Legislation, your weekly update on the latest developments in proposed and amended privacy and data security legislation across the 50 states and the District of Columbia, as well as a summary of what’s on the schedule for the coming week. For comprehensive status and summaries of all state privacy and cybersecurity bills in play this year, please consult the State Privacy and Cybersecurity Legislation Tracker, located in the Spotlight Topics panel on the Wolters Kluwer Cybersecurity & Privacy dashboard.

    Last week, Connecticut enacted legislation imposing new regulatory requirements for data brokers and making a variety of amendments to the state’s privacy law, and Vermont edged closer to enacting comprehensive privacy legislation, among other developments.

    RECENT DEVELOPMENTS

    Connecticut privacy updates signed. On May 27, Connecticut Gov. Ned Lamont (D.) signed S.B. 4 (P.A. 64), Reg Sess. (Conn. 2026), a bill that imposes registration and reporting requirements on data brokers, requires brokers to establish an accessible deletion mechanism, and amends the Connecticut Data Privacy Act (CTDPA) to expand consumer rights over personal and genetic data, restricting surveillance pricing, and enhancing transparency and enforcement mechanisms. Among many specific provisions, the law prohibits the sale, sharing, or transfer of precise geolocation data by controllers and processors and requires businesses using facial recognition in public spaces to disclose it at each entrance and provide a process for consumers to request removal of their images. The provisions of the legislation take effect on Oct. 1 (see separate story).

    Comprehensive privacy law awaits gubernatorial review in Vermont. Vermont’s state Senate concurred in the House’s proposed amendments to a bill that would establish a comprehensive privacy and data protection law in the state on May 29. The legislation (S.B. 71, Reg Sess.) would enact the Vermont Data Privacy and Online Surveillance Act, with elements similar to those included in state laws enacted over the past several years, including giving consumers access, correct, deletion, and opt-out rights, and imposing requirements on data controllers and processors (CPR, May 29). As introduced in the 2025 legislative session, the bill included a private right of action under specified conditions, but the version currently being considered by Gov. Phil Scott (R.) does not include this provision. If enacted, the law would take effect on Jan. 1, 2028.

    California bills on children’s safety, privacy advance. Bills that would strengthen children’s privacy protections and provide broader deletion rights for California residents cleared their respective chambers of introduction last week.

    On May 26, the California state Assembly voted to advance A.B. 2246, Reg Sess., which would impose stricter requirements and higher penalties on businesses providing online services likely to be accessed by minors. Specifically, the bill would require businesses to estimate the age of users with reasonable certainty or apply child privacy protections to all users, set high default privacy settings for children, provide clear and age-appropriate privacy information, and offer tools for children and their guardians to exercise privacy rights (CPR, May 27). The bill has been sent to the Senate Rules Committee for assignment.

    Meanwhile, on May 27, the California state Senate approved S.B. 923, Reg Sess., which would expand the right to delete personal information to cover information that a business collects and holds on a consumer from a third-party and require businesses that operate exclusively online to provide consumers with both an e-mail address and an online method, such as a web form or online portal, for residents to access, correct, or delete their personal information (CPR, May 28). The bill has had its first reading in the state Assembly, where it is awaiting committee assignment.

    Biometric tracking disclosure proposal clears New York committee. A bill that would require New York retailers to post clear warnings and provide opt-out information if they tracked customers or collected biometric data was voted unanimously out of the state Assembly Codes Committee on May 28. A.B. 1558, Reg Sess., would require retailers to inform customers in plain language if they are being tracked via cellphones, store-installed cameras, or other electronic devices and provide opt-out information where applicable. If biometric data is being collected, the signage would have to specify the types of data collected, how it is used, and offer opt-out details if available (CPR, May 29). The bill also gained approval today in the Assembly Rules Committee.

    WHAT’S COMING UP

    The Rhode Island state Senate Health & Human Services Committee will review S.B. 3256, Reg Sess., a bill that would create the Public Health Data Privacy and Protection Act to regulate the reporting of information relating to reportable disease data in the possession of the state Department of Health, on June 2.

    On the same day, the Ohio state House Finance Committee will take up H.B. 163, Reg Sess., which would establish the Enhanced Cybersecurity for SNAP Act of 2026, requiring the state to transition to chip-enabled EBT cards for SNAP, adopt updated cybersecurity standards, and provide a fraud reporting mechanism.

    WHAT WE’RE TRACKING

    Last Week:

    Introduced Bills: 3

    Enacted Bills: 2

    Failed Bills: 0

    2026 Total (including carryforward)

    Introduced Bills: 699

    Enacted Bills: 42

    Failed Bills: 36

    MainStory: DataPrivacy DataSecurity DataBreach StateLegislation

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use