Keep Calm and Prepare to Gobble On a New Feast of Privacy, Cyber and AI Laws
Privacy, Cyber & AI Decoded Alert | 6 min read
Nov 24, 2025
In this November edition of Hinshaw’s Privacy, Cyber and AI Decoded, in celebration of the U.S. Thanksgiving holiday, we are recommending that our readers Keep Calm as they are faced with a new surge of legal requirements, regulations and enforcement actions, and Gobble On. We are here, except when running in the turkey trot or cooking, to help you assess your Privacy, Cyber and AI risk in response to these changes!
Compliance Dates on the Platter!
As January 2026 privacy, cyber, and AI strategy planning ramps up, we wanted to remind you about some upcoming compliance dates.
- Indiana’s Consumer Data Protection Act is effective on January 1, 2026.
- Kentucky’s Consumer Data Protection Act is effective on January 1, 2026.
- Rhode Island’s Data Transparency and Privacy Protection Act is effective on January 1, 2026.
- Delaware’s and Oregon’s right to cure period expire, as of January 1, 2026. Both states have active privacy enforcement teams.
- California’s CCPA revised regulations are effective January 1, 2026, as are the Delete Act regulations. Please see our October edition of Privacy, Cyber and AI Decoded for more information and below.
- We will highlight more AI state legislation and their effective dates in our December edition.
California’s CPPA Increases its Appetite for Enforcement Against Data Brokers with a Strike Force and the Delete Act.
On November 19, 2025, the CPPA announced it had established a dedicated strike force to enforce California’s data brokers registration and privacy compliance requirements. A data broker is defined as a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship, with certain exceptions.
In October 2025, the CPPA approved regulations to implement the Delete Act (California Senate Bill No. 362). The new regulations, effective January 1, 2026, establish how California consumers can submit deletion requests through the CPPA’s new Delete Request and Opt-out Platform (“DROP”) and how data brokers must process them. DROP will be a state-run website enabling consumers to request the deletion of personal information held by multiple data brokers with a single click. It is already established that data brokers operating under the CCPA have an accurate, compliant privacy policy.
The Delete Act requires, among other things, the following:
- Data brokers must register with the CPPA, provide specific information regarding their privacy practices, and pay a registration fee.
- Beginning August 1, 2026, data brokers must check DROP at least every 45 days, retrieve submitted requests, and delete matching personal information as requested by consumers, process related opt-outs of the sale or sharing of personal information, and request that their service providers delete such personal information and also process the opt-outs, including inferences.
- Beginning January 1, 2028, and every three years thereafter, data brokers will be required to undergo an independent third-party audit to assess their compliance with the Delete Act.
Businesses should assess if they qualify as a data broker under these requirements before January 1, 2026, and—if they have not already—develop a road map for the appropriate compliance measures. Failure to comply may subject a data broker to administrative fines as well as the costs and expenses of enforcement actions.
More Privacy Regulators are invited to the Table!
Two more states, Minnesota and New Hampshire, have joined the Consortium of Privacy Regulators, a bipartisan effort aimed at implementing and enforcing state privacy laws nationwide. The Consortium holds regular meetings and coordinates enforcement. Members now include the California Privacy Protection Agency and state Attorneys General from California, Colorado, Connecticut, Delaware, Indiana, New Hampshire, New Jersey, Minnesota, and Oregon.
Organizations operating in these Consortium states and subject to their privacy laws should understand that there is an increased likelihood for multi-state privacy enforcement actions, potentially raising their privacy risk.
Featured Insights

In The News
Nov 13, 2025
A Profile on Neil Rollnick: After 57 Years in Practice, He Has No Plans to Retire

Press Release
Oct 22, 2025
Hinshaw & Culbertson LLP Launches New Website and Refreshed Brand

Press Release
Sep 26, 2025
Hinshaw Recognized as a “Leader in Litigation” in the BTI Consulting Litigation Outlook 2026 Survey

Privacy, Cyber & AI Decoded Alert
Sep 23, 2025
Fall 2025 Regulatory Roundup: Top U.S. Privacy and AI Developments for Businesses to Track

Press Release
Sep 15, 2025
Hinshaw Achieves 2024–2025 Mansfield Rule Certification Plus Status

In The News
Sep 5, 2025
Jessica Riley Reflects in a Law360 Story on Lessons She Learned as a Junior Lawyer








