TL;DR: On July 1, 2026, three different states rewrite different parts of their privacy laws on the same day. Connecticut's CTDPA amendments drop the applicability threshold from 100,000 to 35,000 consumers, expand what counts as "sensitive data" to include SSNs and driver's license numbers, ban the sale of sensitive data without consent, give consumers new rights to question automated decisions and demand a list of every third party their data was sold to, and extend the under-18 opt-in to age 17. Utah's UCPA amendment adds the right to correct inaccurate personal data, the one core right the original UCPA forgot. Arkansas becomes the first state to enact a "COPPA 2.0" law (HB 1717), extending federal child-data protections to teens aged 13 to 16, banning targeted advertising to minors, and requiring data minimization for any business serving Arkansas children or teens. The amendments were all signed in 2025 and most of them take effect together on July 1, 2026. The full deep dive on Connecticut is in our CTDPA amendments piece; this article is the roundup and covers what Utah and Arkansas are doing in addition.
The Pattern: State Privacy Law Is Converging on the Same Day
Connecticut, Utah, and Arkansas each picked a different piece of the privacy puzzle to fix. The fact that all three amendments land on July 1, 2026 is not a coincidence. It is the rhythm of state privacy law. Bills introduced in early 2025 with one-year effective dates naturally cluster around July 1 of the following year, the standard effective date for state privacy law amendments passed in regular sessions. The pattern is now visible every six months: a January 1 wave for new comprehensive laws, and a July 1 wave for amendments to existing ones.[1]
MultiState's 2026 tracking confirms the cluster. Of the 22 states with comprehensive consumer privacy laws in force as of June 2026, the next big wave of effective dates is exactly this July 1.[1] The Connecticut amendments are the biggest single piece. Utah and Arkansas are smaller fixes, but they both fill gaps that consumer advocates have been pointing at for two years. Read together, the three amendments tell a clear story: state privacy law is no longer just about who is covered. It is about what rights you actually have once the law covers you.
Connecticut: The Big One
Connecticut's Data Privacy Act amendments are the most consequential piece of state privacy legislation taking effect in 2026. They go in five directions at once, and any one of them would be the headline on its own.
Applicability threshold drops from 100,000 to 35,000 consumers. The current CTDPA, in force since January 1, 2023, applies to entities that control or process personal data of at least 100,000 consumers in the preceding calendar year (or 25,000 consumers if at least 25% of revenue came from selling personal data). The amendments lower the first threshold to 35,000 and add two new no-threshold triggers: any entity that processes Connecticut consumers' sensitive data, and any entity that offers Connecticut consumer data for sale, is now in scope regardless of total volume.[2][3] The 100,000-consumer floor was the main reason smaller data brokers and ad-tech firms were able to operate outside Connecticut privacy law. That cover is gone.
Sensitive data expands and selling it now requires opt-in. The expanded sensitive-data definition covers government identifiers (driver's license numbers, passport numbers), financial account-related elements, and Social Security numbers, on top of the existing categories. The amendments layer a new restriction on top: the sale of sensitive data is now expressly prohibited absent consumer consent. SSNs, financial account credentials, and biometric identifiers cannot be sold to data brokers, ad networks, or downstream customers without an explicit opt-in.[2][3]
New rights over automated profiling and data-buyer lists. The amendments give consumers the right to question, be informed of the reasoning behind, review the data used in, and request reevaluation of certain covered automated decisions. A human-in-the-loop review that rubber-stamps an algorithm no longer shields the decision from opt-out. Consumers also gain a new right to a list of every third party to whom the controller has sold the consumer's personal data. The right is the lever consumer advocates have been pushing for since 2020, and Connecticut is the first state to make it a statutory right.[2][3]
Inferences are now explicitly personal data. The amendments close a long-running loophole where controllers argued that a model's prediction about you (creditworthiness, health risk, "interested in X") was not "your data" and therefore not subject to access requests. The amendment says inferences are data. You can ask for them.[2]
The under-18 opt-in extends to age 17. The current CTDPA requires opt-in consent before a controller engages in targeted advertising or sells the personal data of consumers between ages 13 and 16. The amendments extend that protected bracket to age 17. Seventeen-year-olds in Connecticut now join 13- to 16-year-olds in needing affirmative opt-in for targeted ads and data sales.[2]
Read our full Connecticut CTDPA deep dive for the per-section breakdown, comparison to Texas, Oregon, and Colorado, and what to do before July 1.
Utah: The Right to Correct
Utah's amendment to the Utah Consumer Privacy Act is small, narrow, and overdue. The original UCPA, signed by Governor Spencer Cox as S.B. 227 and effective December 31, 2023, did not give consumers the right to correct inaccuracies in their personal data. The right is one of the five core rights in almost every other state privacy law. Iowa is the only other state that left it out at adoption. The July 1, 2026 amendment fixes the gap.[4][5][6]
The new right to correct is "straightforward" per TrueVault's analysis. Consumers can now demand that a controller correct inaccurate personal data, taking into account the nature of the personal data and the purposes for which it is processed.[4] Controllers must respond on the same timeline as other UCPA consumer rights requests. The amendment does not add a universal opt-out mechanism, a profiling opt-out, or a right to limit further use; those gaps remain in the UCPA. The single right to correct is the only change.
For Utah businesses, the burden is light. Most controllers already honor right-to-correct requests under other state laws (California's CCPA, Virginia's VCDPA, Colorado's CPA, Connecticut's CTDPA, Oregon's OCPA) and under sector-specific rules like HIPAA and FCRA. The amendment brings Utah into alignment with the rest. TrueVault's summary: "the amendment should not add much regulatory burden to businesses that are already broadly privacy-compliant."[4]
For Utah residents, the practical change is that a wrong address, a stale employment record, or an inaccurate credit report sitting in a data-broker file is now something a consumer can ask to be fixed with a statutory citation. The same kind of request Utah residents have been sending to California controllers since 2020 will work in-state starting July 1.
Arkansas: COPPA 2.0 for Teens
Arkansas is the headline story of this July 1 wave, and the one with the most national implications. HB 1717, the "Arkansas Children and Teens Online Privacy Protection Act," was signed by Governor Sarah Huckabee Sanders in 2025. It takes effect July 1, 2026. The bill is the first state-level law in the country to put COPPA 2.0 protections for teens into enforceable statute, and the Future of Privacy Forum called Arkansas the leader on the issue when the bill passed.[7][8]
The original Children's Online Privacy Protection Act of 1998 establishes national privacy protections for children under 13. Arkansas HB 1717 goes further in three ways.[7]
1. Expands protections to teens aged 13 to 16. Federal COPPA stops at age 13. Arkansas extends the privacy framework to cover teens, the population that uses social media, gaming platforms, and AI chatbots most intensively and that state lawmakers have had the hardest time regulating. The bill brings teens into the same verifiable-consent regime that COPPA established for younger children.
2. Substantive data minimization. The bill requires data minimization for any business that knows it is serving Arkansas children or teens. Collection has to be limited to what is reasonably necessary for the activity. The bill prohibits targeted advertising to minors using personal data, with a narrow exception for advertising based on data collected in a first-party context. The first-party carve-out is meaningful: a gaming company that serves a teen who has been playing for two years can still use in-game behavior to target ads. A third-party ad network that buys teen data from a data broker cannot.[7][8]
3. New rights for teens over their own data. Teens aged 13 to 16 gain new rights to access, delete, and correct personal information held about them. The framework mirrors what adult consumers have under Arkansas's existing Personal Data Protection Act (the comprehensive state privacy law in force since July 1, 2025) and under Connecticut's CTDPA.[7][9]
Federal preemption is the open question. COPPA includes an express preemption clause that prohibits state laws from imposing requirements that are inconsistent with COPPA. The Arkansas law goes beyond COPPA in two specific ways (extending protections to teens, and adding new substantive limits on the use of children's and teens' data such as targeted-advertising restrictions and strict data minimization requirements). The FPF flagged the preemption question as the most likely legal challenge.[7] If a court finds the Arkansas law inconsistent with COPPA, parts of HB 1717 could be struck. If it stands, expect a wave of state-level COPPA 2.0 bills in 2027 and 2028 modeled on the Arkansas template.
For businesses serving minors nationally, the practical consequence is that Arkansas becomes a de facto national standard. The cost of building a teen-data compliance program for one state is the same as building it for all 50, and the marketing risk of a teen privacy scandal in Arkansas is roughly the same as in California. Most platforms will just adopt the Arkansas framework as the floor.
What the Other 19 State Privacy States Are Doing
Connecticut, Utah, and Arkansas are the three with material amendments effective July 1, 2026. The other 19 state privacy states either amended smaller items with later effective dates or are still working on 2025-2026 session bills. MultiState's February 2026 roundup identified the three states covered here as the focus of the July 1 wave.[1]
States that passed notable privacy legislation in 2025 with later effective dates include Colorado (amendments to its CPA), New Jersey, and Tennessee. California's August 1, 2026 effective date for expanded data-broker registration and consumer health data rules is the next big post-July-1 cluster.[1]
The federal layer is also moving, in the opposite direction. The federal "Securing the Internet of Things" and "American Privacy Rights Act" efforts stalled in 2025. Two 2026 congressional proposals, the Secure Data Act and the Online Privacy Act, are competing versions of a federal preemption bill that would override state laws like the Connecticut, Utah, and Arkansas amendments. Both are unlikely to clear both chambers this year. State amendments like the ones in this article are the privacy law that will actually apply through 2026.[10][11]
What Residents of the Three States Should Do Before July 1
If you live in Connecticut, Utah, or Arkansas, the July 1 amendments give you new rights that you can use right away. A short checklist:
- Connecticut residents: send a "right to know" request to every company that has your data. Under the amended CTDPA, the request can explicitly ask for the list of third parties your data was sold to. The IAPP has a Connecticut-specific template, and most controllers are required to acknowledge within 45 days. Send the request by mid-June so the response lands after July 1, when the new rights are in force. For parents of 17-year-olds, revisit the ad and data settings on Instagram, TikTok, Snapchat, YouTube, and any gaming platform; the age-17 opt-in means the default should change.[2][12]
- Utah residents: if a data broker, employer, or other controller has a factually wrong record about you (a wrong address, a stale employment history, a misattributed credit line), you can now send a right-to-correct request with a Utah statutory citation. Keep the confirmation. If the controller refuses, the Utah Attorney General's office has enforcement authority under the UCPA.[4][5]
- Arkansas residents with teens aged 13-16: check what data your teen's favorite apps collect, who they share it with, and whether the apps have an ad-free or data-minimization setting. Arkansas HB 1717 does not require a parent to file a request; the duty is on the company. But the law is new, and most companies will not change their behavior until they see enforcement. If you are the parent of a teen in Arkansas and a platform is failing to honor the data-minimization duty, you can file a complaint with the Arkansas Attorney General.[7][8][9]
What Businesses Operating in the Three States Should Do Before July 1
The combined effect of the three amendments is that the compliance floor for any consumer-facing business in the United States is rising. The specific actions:
- Recalculate your applicability against all three states. Connecticut's threshold drop is the most consequential: if you are between 35,000 and 100,000 Connecticut consumers, you are newly in scope as of July 1. If you process sensitive data or sell personal data, you are in scope in Connecticut regardless of volume. Map your 2025 traffic and 2026 projections against the new triggers before July 1.[2][3]
- Update your privacy notice to cover the new rights. Connecticut's amendment adds new disclosures, including the right to a list of data buyers. Utah's amendment adds the right to correct. Arkansas HB 1717 adds teen data rights. Most state-privacy-law templates cover the existing rights; the new ones need explicit language.[2][4][7]
- Build a teen-data compliance program if you serve users under 18. Arkansas HB 1717 is the first state-level teen privacy law of its kind, but it will not be the last. The cost of building it once for Arkansas is the same as building it for all 50 states, and the marketing risk of a teen-privacy scandal in any one state is similar. Most platforms will just adopt the Arkansas framework as the floor.[7][8]
- Build a sensitive-data sale opt-in flow. Connecticut's amendment prohibits the sale of sensitive data without opt-in. If you sell any sensitive data (SSNs, financial account numbers, biometric identifiers), you need a documented opt-in. Pause any planned sales of newly-sensitive data categories until the opt-in is in place.[2]
- Train customer service on the new profiling and data-buyer rights. Connecticut's "right to question, be informed of reasoning, review data, and request reevaluation" requires a process, not just a checkbox. A consumer invoking the right against a script-reading agent will get a wrong answer.[2]
The Bottom Line
Three states, three different angles, one date. Connecticut is doing the heavy lifting on consumer rights, applicability, and sensitive-data sale bans. Utah is closing a small but annoying gap. Arkansas is becoming the test case for whether a state can do COPPA 2.0 better than Congress. The pattern across 2024-2026 is convergence: every state privacy law is moving toward broader applicability, stronger sensitive-data rules, more rights over automated decisions, and more protection for minors. Connecticut, Utah, and Arkansas are each pushing one piece of that pattern forward. The next 24 months will show whether the rest of the 22-state patchwork catches up.
References
- MultiState Insider: "All of the Comprehensive Privacy Laws That Take Effect in 2026" (February 4, 2026) - Authoritative state-government-relations roundup of the 2026 effective-date calendar for state consumer privacy laws, including the July 1 cluster (Connecticut, Arkansas, Utah) and the August 1 California data-broker registration expansion.
- Wiley Rein: "Major Changes to Connecticut's Consumer Privacy Law Will Take Effect July 1, 2026" (April 27, 2026) - Primary law-firm alert with the detailed breakdown of the CTDPA amendments, applicability thresholds, sensitive-data expansion, consumer rights additions, and youth data opt-in extension.
- Benesch: "Connecticut Broadens Data Privacy Act Requirements Effective July 1, 2026" - Cross-confirming law-firm alert on the CTDPA amendments with additional analysis on compliance steps and applicability triggers.
- TrueVault: "Utah Adds to Its Privacy Law" (May 18, 2026) - Source for the Utah Consumer Privacy Act right-to-correct amendment, effective July 1, 2026, signed by Governor Spencer Cox in March/April 2025.
- Bass, Berry & Sims: "Slalom Through Sensitive Data: Utah Skis Into Consumer Privacy Protection" - Cross-confirming analysis of the UCPA framework and the right-to-correct amendment taking effect July 1, 2026.
- Baker Donelson: Consumer Data Privacy Law Guide, Utah - State-law reference with the UCPA applicability threshold ($25M revenue + 100,000 Utah consumers) and the right-to-correct amendment effective July 1, 2026.
- Future of Privacy Forum: "Little Rock, Minor Rights: Arkansas Leads with COPPA 2.0-Inspired Law" (April 17, 2025) - Primary source for Arkansas HB 1717, the "Arkansas COPPA 2.0" teen privacy law effective July 1, 2026, covering teens 13-16, data minimization, and teen rights to access/delete/correct.
- Alston & Bird Privacy & Cybersecurity: "Arkansas Enacts Children and Teens Online Privacy Protection Act" - Cross-confirming analysis of HB 1717's teen-data provisions, data minimization, and federal preemption considerations.
- Recording Law: "Arkansas Data Privacy Laws: Breach Notification & Consumer Rights (2026)" - Reference for the Arkansas Personal Data Protection Act (APDPA) signed April 11, 2023, effective July 1, 2025, the comprehensive state privacy law that HB 1717 amends for teen data.
- State of Surveillance: "The Federal Privacy Preemption Fight Is Back" - Coverage of the Secure Data Act and competing federal preemption bills that would override state privacy laws like the Connecticut, Utah, and Arkansas amendments.
- IAPP US State Privacy Legislation Tracker - Authoritative tracker of state privacy law applicability thresholds, sensitive-data definitions, and effective dates for all 22 state privacy laws.
- State of Surveillance: "Connecticut's Privacy Law Overhaul Hits July 1, 2026" - The deep dive on the Connecticut CTDPA amendments, with per-section breakdown and what to do before July 1.