Your Privacy Rights

How State Attorneys General Enforce Privacy Laws

By the RedactZero Team · September 22, 2026 · 9 min read

The short version

In nearly every state, the attorney general is the only party who can enforce the privacy law. You cannot sue under it yourself. Enforcement is real but selective: California, Texas, Connecticut and Oregon have all brought cases, ranging from an $85,000 settlement to $1.4 billion. Many laws give a company 30 to 60 days to "cure" a violation before any penalty, which quietly ends most cases. Your complaint rarely gets your own data deleted, but complaints are how offices decide whom to investigate. This article is general information, not legal advice.

Who enforces privacy law in the United States

There is no single national privacy regulator. The Federal Trade Commission polices deception and unfair practices under a general statute, but the comprehensive privacy laws now in force in 19 states are enforced almost entirely by state attorneys general. In California, a dedicated agency, the California Privacy Protection Agency, shares that job with the attorney general.

In practice, that means when a data broker ignores a deletion request you made under a state law, the office with the power to act is your attorney general's consumer protection division. The FTC can still step in if a company lied, as it did in 2023 when TruthFinder and Instant Checkmate paid $5.8 million over background reports that implied criminal records where only a traffic ticket existed. But the FTC does not enforce state privacy statutes. That distinction decides where your complaint should go.

Why you usually cannot sue, and the attorney general can

The comprehensive state privacy laws were written to be enforced by government, not by individuals. Texas, Virginia, Colorado and Connecticut each say in the statute that the law creates no private right of action. The IAPP's tracker shows California as the only one of the 19 laws with any private lawsuit right, limited to data breaches.

California's exception is narrow. Under Civil Code section 1798.150, you can sue only when unencrypted, unredacted personal information is stolen because a business failed to maintain reasonable security. Statutory damages started at $100 to $750 per consumer per incident, and the agency adjusted them to $107 to $799 from January 1, 2025. You must give 30 days' written notice first, and a company that fixes the problem in that window blocks the statutory damages claim.

Virginia's statute goes further in the other direction, giving its attorney general "exclusive authority" to enforce. The one big outlier is Illinois's biometric law, BIPA, which lets any aggrieved person sue for $1,000 per negligent violation or $5,000 per intentional one. For everything else, the honest picture is in our guide on whether you can sue a data broker: rarely, and only under specific laws.

The cure period: the loophole that blunts most cases

A cure period is a legally required warning shot. Before suing, the attorney general must tell the company what it did wrong and give it a fixed window, usually 30 or 60 days, to fix it. Fix it in time and there is no penalty and no case. Several states have let this requirement expire. Texas and Virginia never will.

StateCure windowStatus
California (CCPA)30 daysMandatory cure expired January 1, 2023; now at the enforcer's discretion
Colorado60 daysExpired January 1, 2025
Connecticut60 daysExpired December 31, 2024; discretionary since
Oregon30 daysExpired January 1, 2026
Texas30 daysPermanent, written into the statute
Virginia30 daysPermanent, written into the statute

Source: the enforcement sections of each state's statute (Cal. Civ. Code 1798.199.45; Colo. SB21-190; Conn. Public Act 22-15; Tex. Bus. and Com. Code 541.154; Va. Code 59.1-584) and the Oregon Department of Justice.

Why this matters to you: under a permanent cure regime, a company can ignore the law until it is caught, fix the specific problem named in the letter, and walk away with no fine. Oregon's Department of Justice reported opening and closing 38 cure-letter matters in its law's first year. Even where the mandatory window has expired, enforcers can still choose to offer one. California's statute tells its agency to weigh factors like lack of intent and voluntary fixes made before the notice arrived.

California's attorney general: the pattern in the settlements

California's attorney general has announced at least five settlements under the CCPA since 2022, and the four below share one theme: companies sold or shared personal data while making opt-outs hard or ignoring them. The amounts run from $375,000 to $1.55 million, small for the companies involved, but each came with binding conduct orders that outlast the cheque.

CompanyDatePenaltyWhat went wrong
SephoraAugust 2022$1.2 millionDid not disclose it was selling data; ignored Global Privacy Control opt-outs; did not cure within 30 days
DoorDashFebruary 2024$375,000Handed customer names, addresses and order histories to a marketing cooperative
HealthlineJuly 2025$1.55 millionSent advertisers article titles that revealed readers' likely diagnoses; kept sharing after opt-outs
Sling TVOctober 2025$530,000Buried the opt-out behind cookie settings and a webform; no opt-in for viewers under 16

Source: California Attorney General press releases dated August 24, 2022; February 21, 2024; July 1, 2025; and October 30, 2025.

Two details are worth noticing. Sephora had a 30-day cure window available and, according to the attorney general, did not use it. And both the Sephora and Sling TV cases came out of "sweeps," where the office picks a sector, online retailers in one case and streaming services in the other, and tests many companies at once. Enforcement tends to arrive by industry, not by individual complaint.

California's second enforcer: the privacy agency

California is the only state with a standalone privacy regulator. The California Privacy Protection Agency can impose administrative fines without going to court, and since January 2024 it has run the state's data broker registry. In 2025 it fined Honda $632,500, clothing retailer Todd Snyder $345,178, and Tractor Supply $1.35 million, the largest in the agency's history.

The Tractor Supply case is the clearest answer to "does complaining do anything." The agency says its investigation began after a single consumer in Placerville, California filed a complaint. The resulting order found a deficient privacy policy, no notice to job applicants, and no working opt-out, including a failure to honour Global Privacy Control signals.

For data brokers, the agency's weapon is the Delete Act. Brokers that miss the registration deadline owe $200 per day. National Public Data was fined $46,000 for registering 230 days late; Background Alert, which marketed itself with "It's scary how much information you can dig up on someone," agreed to shut down through 2028 rather than comply. From August 1, 2026, registered brokers must also process requests from the state's DROP platform, and the same $200-per-day fine applies to every deletion request they fail to honour.

Texas: the largest privacy penalties in the country

Texas has produced the biggest privacy recoveries by any single state. In July 2024, Meta agreed to pay $1.4 billion under the state's biometric law over Facebook's facial recognition tagging, which was on by default. In May 2025, Google agreed to $1.375 billion over location tracking, Incognito mode and biometric data. Neither case used the state's newer comprehensive privacy law.

That law, the Texas Data Privacy and Security Act, got its first test on January 13, 2025, when the attorney general sued Allstate and its subsidiary Arity. The complaint alleges the companies embedded tracking code in apps such as Life360 and GasBuddy, collected driving data from more than 45 million Americans without consent, and sold it to insurers. The office called it the first enforcement action by any state attorney general under a comprehensive privacy law. The case was still a lawsuit, not a settlement, when this was written.

Five months earlier, in August 2024, the same office sued General Motors and OnStar over driving data from more than 1.5 million Texans that was sold to firms producing "driving scores" for insurers. That case ran under the state's deceptive trade practices law instead. The lesson: attorneys general reach for whichever statute has the sharpest teeth, and the privacy law is only one tool. Our Texas privacy act guide covers what the law gives you as a resident.

Connecticut and Oregon: what a smaller office actually does

Most state enforcement is quieter than Texas. Connecticut's first public settlement under its privacy law, with ticket reseller TicketNetwork in July 2025, was $85,000. Oregon's Department of Justice reported 214 consumer complaints and 38 cure-letter matters in its law's first year. The everyday tool is the warning letter, not the lawsuit.

The TicketNetwork timeline shows how slowly the machine turns. The attorney general sent a cure notice on November 9, 2023 over a privacy notice it called largely unreadable, with broken rights mechanisms. The company did not fix it within the 60-day window and, according to the office, repeatedly said it had resolved the problems when it had not. The settlement came 20 months later, with obligations to track and report consumer-rights metrics.

Both offices are seeing your problem. Connecticut's attorney general has told its legislature that it keeps receiving complaints about websites that combine public records into personal "profiles," and has asked lawmakers to narrow the publicly-available-information exemption that shields them. Oregon reported that the majority of its first-year complaints concerned online data brokers, and that deletion was the most commonly denied request. People-search sites are on the radar; the law's exemptions are the obstacle.

States are starting to team up

On April 16, 2025, the California Privacy Protection Agency and the attorneys general of California, Colorado, Connecticut, Delaware, Indiana, New Jersey and Oregon formed a Consortium of Privacy Regulators to share expertise and coordinate investigations. Minnesota and New Hampshire joined on October 8, 2025. A company that fails a cure notice in one state can now expect questions from others.

For data brokers this matters more than for most businesses, because their practices are identical in every state. A privacy notice that Connecticut finds unreadable is unreadable in Oregon too. Coordinated sweeps make it harder for a broker to fix its site for one attorney general's letter and leave everyone else's residents exposed.

What your complaint actually achieves

A complaint to your attorney general will almost never get your own listing deleted. California's attorney general says it cannot act as your personal lawyer, and the privacy agency says it does not represent individual consumers. What a complaint does is add your case to the record that decides who gets a cure notice, a sweep, or a lawsuit.

That record has real weight. One complaint started the Tractor Supply investigation. Oregon counts its complaints by category and publishes them, which is why its office can say data brokers dominate. Connecticut's cure notices went out in sweeps built from the same kind of pattern. Your complaint is a data point, and data points are what these offices act on.

To make yours count, include the date you filed your request, the exact text, any confirmation number, the company's reply or the deadline it missed, and a dated screenshot of your data still live. Then file with your attorney general, and with the California Privacy Protection Agency if you live there. Its online form allows anonymous complaints, but the agency notes it cannot follow up on those. Our guide on where to file a privacy complaint walks through each venue.

What "up to $7,500 per violation" really means

Most state privacy laws cap penalties at $7,500 per violation. Texas and Virginia use that figure; California sets $2,500 per violation and $7,500 for intentional ones or those involving a child under 16, inflation-adjusted to $2,663 and $7,988 since January 1, 2025. Because each affected consumer can count as a violation, theoretical exposure is enormous. Real settlements are far smaller.

Connecticut treats a privacy violation as an unfair trade practice, which its attorney general's guidance puts at up to $5,000 per violation. In every state, the number is a ceiling for negotiation, not a formula. The conduct orders usually matter more than the cheque: Healthline is barred from sharing diagnosis-revealing article titles, DoorDash must report to the attorney general annually on data sharing, and TicketNetwork must track and report how it handles rights requests. Those orders are what change how a company treats the next request you send.

What to do if a data broker ignores you

Do not wait on an enforcer. File the complaint, then work the practical route. Every major people-search site has a free opt-out. California residents can use DROP to reach more than 500 registered brokers at once, and a broker that ignores that request faces its own per-day fine. Everyone else opts out site by site and re-checks every few months.

Start by working out which sites list you. Our broker directory shows what each major broker publishes and how its opt-out works, and the step-by-step opt-out guides are verified and dated. If you are not sure which laws apply to you, our guide to data deletion rights by state lays out the rights and response deadlines in each state with a comprehensive law. RedactZero's free exposure scan lists the brokers likely to hold a profile on you, alongside any breaches tied to your email, and stores nothing you type.

See who lists you before you complain

A complaint is stronger with a screenshot. Run a free exposure scan to see which data brokers likely list you, plus any breaches tied to your email - no account, nothing stored.

Run a free exposure scan

Frequently asked questions

Who enforces state privacy laws?

In almost every state, the attorney general's office is the only body that can enforce the comprehensive privacy law. California adds a second enforcer, the California Privacy Protection Agency, which can issue administrative fines and runs the state's data broker registry. The FTC enforces federal law, not state privacy statutes.

Can I sue a company under my state's privacy law?

Usually not. Texas, Virginia, Colorado and Connecticut all state in the statute that the law creates no private right of action, and the IAPP's tracker shows California as the only one of the 19 comprehensive state laws with any private lawsuit right. Even California's is limited to data breaches caused by poor security. Illinois's biometric law is a separate exception.

What is a cure period in a privacy law?

A cure period is a required warning before enforcement. The attorney general must notify the company of the violation and give it a fixed window, usually 30 or 60 days, to fix it. If the company fixes the problem in time, there is no penalty and no case. Texas and Virginia keep this permanently; California, Colorado, Connecticut and Oregon have let theirs expire.

Will my attorney general get my data deleted if I complain?

Almost never directly. California's attorney general says it cannot act as your personal lawyer, and the California Privacy Protection Agency says it does not represent individual consumers. Complaints are used to spot patterns and choose targets. One consumer complaint from Placerville, California did trigger the investigation that ended in a $1.35 million fine against Tractor Supply.

What is the largest state privacy settlement so far?

Texas holds the record. In July 2024 Meta agreed to pay Texas $1.4 billion under the state's biometric privacy law over Facebook's facial recognition tagging, and in May 2025 Google agreed to $1.375 billion over location tracking, Incognito mode and biometric data. Both were brought by the Texas attorney general alone, not a multistate coalition.

Does the FTC enforce state privacy laws?

No. The Federal Trade Commission enforces federal law, mainly the ban on unfair and deceptive practices and the Fair Credit Reporting Act. It has penalised people-search sites under those laws, including a $5.8 million settlement with TruthFinder and Instant Checkmate in 2023, but a violation of your state's privacy statute is your attorney general's job.

Do attorneys general go after data brokers specifically?

Increasingly, yes. Oregon's Department of Justice reported that the majority of complaints in its privacy law's first year concerned online data brokers. Connecticut's attorney general has told its legislature it keeps receiving complaints about sites that compile public records into personal profiles. California's privacy agency has fined a string of brokers for failing to register.

How do I file a complaint with my state attorney general?

Every state attorney general has a free online consumer complaint form. Gather the date of your request, the exact text you sent, any confirmation number, the company's reply, and a dated screenshot of your data still live. Then file with your attorney general and, if you live in California, also with the California Privacy Protection Agency.

Sources: California Attorney General press releases on the Sephora (2022), DoorDash (2024), Healthline (2025) and Sling TV (2025) settlements; California Privacy Protection Agency announcements on Honda, Todd Snyder, Tractor Supply, National Public Data, Background Alert, the 2025 penalty adjustment, and the Consortium of Privacy Regulators; California Civil Code sections 1798.150, 1798.155, 1798.199.45, 1798.199.90 and 1798.99.82; Texas Attorney General press releases on Meta, Google, General Motors, and Allstate and Arity; Texas Business and Commerce Code chapter 541; Connecticut Attorney General TicketNetwork release, CTDPA enforcement reports, and Public Act 22-15; Colorado SB21-190; Virginia Code 59.1-584; Oregon Department of Justice one-year OCPA enforcement report (August 2025); Illinois BIPA; IAPP US State Privacy Legislation Tracker; FTC press release on TruthFinder and Instant Checkmate (September 2023).