State Attorneys General enforce most US privacy statutes, often in coordinated multistate actions that reach further than any single office could. This hub covers sweeps, cure notices, and settlements.

Biometric Privacy

Two Cases: The Whole Enforcement Record Under Texas's Biometric Statute

August 31, 2026

Texas has regulated the commercial capture of biometric identifiers since 2009, and for more than a decade nobody enforced the statute. The record now consists of two Attorney General actions, against Meta and against Google, and the settlement documents are more informative than the headline figures.

Read more →
Biometric Privacy

Biometric Privacy Statutes Outside Illinois, and Who Gets to Enforce Them

August 24, 2026

Illinois is not the only state with a biometric privacy statute — it is the only one where a private plaintiff can bring the claim. Texas, Washington and Colorado each regulate the capture and retention of biometric identifiers, and each reserves enforcement to a state official. This guide reads the three statutes against each other and traces what that enforcement design produces in practice.

Read more →
Data Brokers

Data Broker Registration: The Four State Registries and What They Require

August 24, 2026

Data broker registration is the one privacy obligation that starts with a public filing rather than a consumer request. Four states — California, Vermont, Texas and Oregon — operate registries, and each defines the regulated entity differently enough that a company can be a broker in one and not the next. This guide reads the four statutes against each other.

Read more →

Related pages