State Privacy Law Changes in July 2026: Connecticut, Utah, New Jersey, and Arkansas
Last updated July 2026 · Obtainer
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
Four US state privacy obligations changed inside a two-week window in July 2026. On July 1, Connecticut cut its applicability threshold from 100,000 consumers to 35,000 and removed it entirely for businesses that sell personal data or process sensitive data, Utah switched on a consumer right to correct inaccurate personal data, and Arkansas turned on a children and teens online privacy law. On July 15, New Jersey's mandatory 30-day cure period sunset, so the Division of Consumer Affairs no longer has to warn a controller before bringing an enforcement action. Two of those four changes pull companies newly into scope, and one removes the only safety net New Jersey had.
What changed in state privacy law in July 2026?
Here is the whole set in one table, with the operational consequence rather than the statutory citation.
| State | Date | What changed | Who it affects |
|---|---|---|---|
| Connecticut (CTDPA) | July 1, 2026 | Threshold cut from 100,000 consumers to 35,000, and removed entirely if you sell personal data or process sensitive data. Sensitive data expanded to include neural data, disability status, transgender or nonbinary status, and financial account credentials. Child protections raised from under 16 to under 18. New duty to disclose whether personal data is used to train large language models. | Mid-market companies that were previously under the Connecticut bar, and anyone training models on customer data |
| Utah (UCPA) | July 1, 2026 | New consumer right to correct inaccurate personal data, added by House Bill 418, with a 45-day response window. Utah was the second-to-last state without one. | Every controller already covered by Utah's $25 million revenue and volume thresholds |
| Arkansas | July 1, 2026 | Children and Teens' Online Privacy Protection Act (HB 1717) takes effect. Bars targeted advertising to minors, requires parental consent under 13 and parental or teen consent for ages 13 to 16, and requires honoring deletion requests. Penalties up to $10,000 per knowing and willful violation, no cure period. | Any online service directed at minors or with actual knowledge it collects minors' data |
| New Jersey (NJDPA) | July 15, 2026 | The 18-month mandatory cure period expired. Notice and a 30-day opportunity to fix a violation are now discretionary, not a right. Penalties remain $10,000 for a first violation and $20,000 for each subsequent one. | Every controller covered by the NJDPA, which has no revenue floor and a 25,000-consumer test that triggers on any data-sale revenue |
Statutes and amendments move, so confirm any single row against the current text before relying on it.
Connecticut's threshold cut is the biggest change
Connecticut lowered its consumer threshold by 65 percent, from 100,000 to 35,000. On a population basis that is a genuinely low bar: Connecticut has roughly 3.6 million residents, so 35,000 is about one percent of the state. A national consumer app, a mid-size ecommerce brand, or a SaaS company with a few thousand business customers and their end users can cross it without ever having thought about Connecticut.
The second half of that change matters more. If you sell personal data or process sensitive data, there is no threshold at all. One record is enough. Combined with the expanded sensitive-data definition, which now reaches neural data, disability status, transgender or nonbinary status, and financial account credentials, that pulls in health apps, fintech products, HR platforms, and anyone running an ad partnership that a regulator would read as a sale.
Connecticut also added a disclosure obligation nobody else has yet: you have to say whether personal data is used to train large language models. That is a privacy notice change, not a request workflow change, but it will show up in access requests, because a consumer who reads that disclosure is more likely to ask what you actually hold. The details of the full amendment are in our Connecticut Data Privacy Act 2026 amendments breakdown, and the state page covers thresholds, rights, and penalties on the Connecticut Data Privacy Act compliance page.
Utah added a right to correct, which is harder than it sounds
House Bill 418 gave Utah consumers the right to correct inaccurate personal data starting July 1, 2026, with the same 45-day response window Utah already used for access and deletion. That leaves Iowa as the only comprehensive state privacy law without a correction right.
Access requests are read-only. You find the data, you report it, you are done. A correction request is a write, and a write has to land everywhere the wrong value went. If a consumer tells you their date of birth is wrong, the fix has to reach your production database, the warehouse copy, the help desk contact record, the email platform, and whatever downstream vendor consumed it last Tuesday. Teams that handle access requests comfortably often discover their correction process ends at the first system and quietly leaves the others wrong. Counting where a single record actually lives is the kind of question you end up asking your database in plain English before you can answer it in a compliance workflow.
We covered the full workflow separately in how to handle a correction request under US state laws, and the state specifics are on the Utah Consumer Privacy Act compliance page.
New Jersey lost its cure period on July 15
The NJDPA took effect January 15, 2025 with an 18-month transition: for that period, the Division of Consumer Affairs had to send written notice and allow 30 days to cure before bringing an enforcement action, whenever a cure was deemed possible. That window ran out on July 15, 2026.
From that date, whether you get a warning is a discretionary call made by the attorney general after they have already reviewed your conduct. Penalties are among the higher ones in the country: up to $10,000 for a first violation and up to $20,000 for each subsequent violation, enforced through the New Jersey Consumer Fraud Act. There is no private right of action.
New Jersey deserves attention beyond the cure change because its applicability test is unusually broad. Most state laws require you to derive 25 or 50 percent of revenue from selling data before the lower 25,000-consumer threshold applies. New Jersey requires only that you derive any revenue, or even a discount on goods or services. Full detail is on the New Jersey Data Privacy Act compliance page, and the wider picture of which states still offer a grace window is in state privacy law cure periods in 2026.
Arkansas turned on a minors law, not a comprehensive one
The Arkansas change is narrower than the other three and is often miscategorized. HB 1717, the Children and Teens' Online Privacy Protection Act, took effect July 1, 2026. It applies to operators of online services directed at children, or operators with actual knowledge they collect personal information from children or teens. Under 13, parental consent is required across the board. For ages 13 to 16, collection for purposes other than targeted advertising is allowed but requires consent from either the teen or a parent. Targeted advertising to minors using their personal data is barred outright.
Operators must give clear notice of data practices, honor deletion requests, and implement reasonable security. The Arkansas attorney general has exclusive enforcement authority, penalties reach $10,000 per knowing and willful violation, and there is no cure period. If any part of your user base is under 18, this is a real obligation even though it is not a general consumer privacy statute.
Frequently asked questions
Which states changed their privacy laws in July 2026?
Four. Connecticut cut its applicability threshold from 100,000 consumers to 35,000 and expanded its sensitive-data definition on July 1. Utah added a right to correct inaccurate personal data on July 1. Arkansas brought its Children and Teens' Online Privacy Protection Act into force on July 1. New Jersey's mandatory 30-day cure period sunset on July 15, making any grace window discretionary.
What is Connecticut's new privacy law threshold?
Since July 1, 2026, the CTDPA applies to a controller that processes the personal data of 35,000 or more Connecticut consumers, down from 100,000. If the controller sells personal data or processes sensitive data, the numeric threshold does not apply at all, so coverage begins at a single record. Penalties are up to $5,000 per violation, counted per affected consumer, and Connecticut has had no cure period since the end of 2024.
Does New Jersey still have a cure period under the NJDPA?
Not as a right. The statutory 30-day notice-and-cure requirement applied only for the first 18 months after the January 15, 2025 effective date, which ended July 15, 2026. The attorney general may still choose to offer an opportunity to cure, but it is discretionary now, so enforcement can begin without any warning. Penalties are $10,000 for a first violation and $20,000 for each subsequent one.
Do I need to change my DSAR process because of these updates?
Probably in two places. First, confirm whether the lower Connecticut threshold now covers you, because coverage is counted on residents and data sales rather than revenue. Second, make sure your request intake can accept and route a correction request, not just access and deletion, since Utah now expects one and nineteen of twenty state laws already did. The 45-day response deadline itself is unchanged everywhere.
How many states have a comprehensive privacy law in effect now?
Twenty states have a comprehensive consumer privacy law in effect in 2026: California, Virginia, Colorado, Connecticut, Utah, Oregon, Texas, Florida, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Tennessee, Maryland, Indiana, Kentucky, and Rhode Island. Arkansas's July 2026 law is a minors-specific statute rather than a comprehensive one. The full state-by-state breakdown covers each in turn.
What to do about it this quarter
Recount your Connecticut residents against 35,000 rather than 100,000, and check whether anything you do would be read as selling data or processing sensitive data, because that removes the threshold entirely. Add a correction path to your request intake if you only handle access and deletion. Treat New Jersey as a no-warning state now. And if you are not sure which laws reach you at all, work through the applicability thresholds state by state before you spend money on tooling.
Obtainer handles the operational half of all of this: it intakes an access, deletion, or correction request, discovers where the person's data lives across your systems, compiles one reviewable manifest, drafts a deadline-safe response, and tracks the 45-day clock. Nothing is disclosed or changed until a person redacts and approves it. Obtainer helps you comply. It is not legal advice, so scope and exemption calls stay with your team.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.