The start of a new calendar year often prompts thoughts about what is and is not possible to accomplish during the coming year, especially when it comes to matters of importance, such as personal health and business initiatives. But one item that may not be on people’s radar is what we would term “privacy health.” There are good reasons to consider an annual checkup regarding an organization’s privacy policies and practices. Laws are changing quickly and certain states require annual analysis. For example, for companies doing business in California, the California Consumer Privacy Act (CCPA) obligates a business to update its online privacy policy or policies “at least once every 12 months.”[1] To comply with the CCPA, a business also needs to identify the categories of personal information it has collected about consumers in the preceding 12 months and what it has sold, shared or disclosed for a business purpose from those categories. Many organizations have either deployed or refined existing deployments of generative artificial intelligence tools in 2025 and it is important that their privacy policies reflect how consumers’ personal information is being used as part of these initiatives. Similarly, a number of new state privacy laws have come into effect. Since January 1, 2025, seven more states’ new consumer privacy laws have come into effect. New State Consumer Privacy Laws in Effect Since January 1, 2025 State Effective Date Indiana January 1, 2026 Kentucky January 1, 2026 Maryland October 1, 2025 Minnesota July 31, 2025 New Jersey January 15, 2025 Rhode Island January 1, 2026 Tennessee July 1, 2025 In addition, Connecticut [2] and Montana [3] dramatically lowered the thresholds triggering their state consumer privacy laws (as well as changing other provisions of their frameworks), which will capture a new set of businesses that were too small to meet the old criteria. The Maryland Online Data Privacy Act is particularly worth noting because its data minimization approach is less permissive than the CCPA when it comes to how companies can use the data they collect, especially when it comes to the sale of sensitive personal data. Maryland’s law limits the collection of personal data to “what is reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumer.” Controllers are also prevented from collecting, processing or sharing sensitive data about a consumer unless it is “strictly necessary to provide or maintain a specific product or service requested by the consumer to whom the personal data pertains.”[4] There are also additional regulations implementing the CCPA that became effective as of January 1, 2026. These new regulations require certain businesses to conduct risk assessments and complete annual cybersecurity audits, and to implement consumers’ rights to access and opt out of use of automated decision-making tools. Data brokers must now be prepared to work with the delete request and opt-out platform (DROP) created as part of the 2023 California Delete Act. Finally, as we previously discussed, the California Privacy Protection Agency (CPPA) settled several enforcement actions in 2025 that provide significant insight into how the agency will interpret and enforce the CCPA. These enforcement actions reflect an agency focused on not only examining the design and operation of a company’s website, but the accompanying structure of its consumer privacy program as well. Companies should be taking action to learn from and implement the lessons from these settlements to avoid placing themselves in the CPPA’s crosshairs. In short, a regular and disciplined approach to data management and privacy practices is essential in today’s business world. If all of this seems overwhelming, we are available to help. We regularly counsel clients on privacy policies and hygiene and actively monitor state and federal developments in the privacy space. Learn more about Stradley Ronon’s cybersecurity, data protection and privacy practice. [1] Cal. Civ. Code § 1798.130(a)(5). [2] In Connecticut, Senate Bill 1295 (the bulk of the changes go into effect July 1, 2026) amended the Connecticut Data Privacy Act to apply to: (1) businesses that control or process the data of 35,000 (formerly 100,000) or more Connecticut consumers; (2) any business that offers consumers’ personal data for sale in trade or commerce (formerly 25,000 Connecticut consumers or 25% of gross revenue derived from the sale of personal data); or (3) (as a new category) entities that control or process consumers’ sensitive data unless that data is used solely for the purpose of completing a payment transaction. [3] In Montana, Senate Bill 297 (which went into effect October 1, 2025) amended the Montana Consumer Data Privacy Act to apply to: (1) businesses that control or process the data of 25,000 Montana consumers (formerly 50,000); or (2) that control or process the data of at least 15,000 Montana consumers (previously 25,000) and derive over 25% of their gross revenue from selling that data. The law also made changes to other provisions of the act. [4] These particular provisions will only apply to processing activities that take place on or after April 1, 2026.