On January 1, 2026, consumer data protection laws took effect in Indiana, Kentucky and Rhode Island, joining a patchwork that now covers a large share of US states. On January 8 — eight days later — per the Kentucky Attorney General's office, the state announced its first enforcement action under the new Kentucky Consumer Data Protection Act. The message to marketers: the era of assuming new state privacy laws come with a polite grace period is over.
What the new laws require
The Kentucky law applies to businesses processing personal data of 100,000 or more Kentucky consumers annually, or 25,000 consumers where revenue comes from selling data. Indiana's law follows the same broad architecture. For marketing operations, the obligations that bite are familiar from other states but now locally enforceable:
- honor opt-outs of targeted advertising and data sales, including Global Privacy Control signals
- provide privacy notices and data processing agreements with vendors
- run data protection assessments for targeted advertising and profiling where required
- respond to consumer rights requests — access, correction, deletion — on statutory clocks
Why the Kentucky enforcement matters
Most state privacy statutes give attorneys general exclusive enforcement power, and most AG offices spent 2023-2025 issuing cure notices rather than complaints. Kentucky moving within a week of its law's effective date signals a different posture: the office had been preparing, and businesses that read "effective January 1" as "start working on it January 1" were already exposed.
For teams running national campaigns, the operational reality is that state privacy compliance is no longer a California project. Opt-out signals, vendor contracts and consent flows built for CCPA-era requirements roughly cover the new states — but only if they were actually built, not planned.
The eight-day timing also resets expectations for every law still in the pipeline. State privacy statutes now in force or pending broadly share the same architecture — thresholds, opt-out duties, universal opt-out mechanisms, assessment requirements — which cuts both ways. The good news is that one well-built compliance program covers most of them. The bad news is that partial compliance misses everywhere at once: a GPC gap is a gap in every state with the same requirement, and each new AG has an incentive to be seen enforcing their own statute. The patchwork is legally fragmented and operationally identical, which is precisely what makes it dangerous to ignore.
Related stories: Meta Starts Rolling Out 'Less Personalised Ads' in the EU — What It Changes for Advertisers · TruHeight Becomes the FTC's First Case Under the Fake Reviews Rule.
The marketing-specific trap
The provisions marketers most often miss are the unglamorous ones: GPC signals honored by the tag manager but not the CRM, data processing agreements missing with an ad-tech vendor acquired mid-year, or a lead-scoring model that counts as profiling requiring an assessment. Enforcement complaints tend to start exactly there — not in the ad account, but in the plumbing behind it.
Consider the shape of a typical failure. A visitor sends a Global Privacy Control signal. The consent management platform sees it and suppresses ad cookies. But the marketing automation platform ingests the same visitor's form fill, the CRM syncs it, the email program continues, and a data broker enrichment append touches the record downstream. From the consumer's perspective, they opted out of targeted processing and got more of it. From the AG's perspective, that is a clean, documentable violation — and every system in the chain generated the evidence. Opt-out handling is a data-flow problem, not a checkbox, and it is exactly the kind of problem that looks done on a dashboard while failing in production.
Vendor sprawl makes it worse. Marketing stacks acquire tools faster than legal acquires DPAs, and the tools that matter are often the small ones — a chat widget, a session-replay script, an enrichment API — rather than the named platforms everyone already contracted. A quarterly reconciliation of live tags against signed agreements is unglamorous and closes most of that gap.
How an AG actually finds you
Enforcement rarely begins with sophisticated surveillance; it begins with a complaint. A consumer who cannot exercise a deletion right, a vendor relationship gone sour, a competitor's letter — these are the standard ignition points, and they all route through the same office. What follows is document-heavy: the AG asks for the privacy notice, the DPAs, the opt-out logs, the assessments. Companies that can produce them quickly usually resolve matters at the inquiry stage. Companies that cannot produce them convert an inquiry into an action.
The assessments deserve a specific mention because they are the newest duty and the least built. Data protection assessments for targeted advertising and profiling do not need to be works of scholarship — they need to exist, to be dated, to identify the processing, and to weigh the benefits against the risks to consumers. Teams that wrote them for California's regime can often adapt; teams that never wrote any have a backlog that starts looking like negligence the moment an AG asks.
What to do
Map which new state laws touch your data footprint, verify GPC handling end to end, and audit vendor DPAs against the states now in force. The Kentucky action shows the countdown starts at the effective date, not at your project plan.
One closing note for planners: treat privacy as infrastructure rather than campaigns. Campaigns ship and end; the opt-out flow, the rights-request process and the vendor register run forever, and each new state law raises the cost of having built them badly. Eight days was enough time to make an example. It is also, conveniently, enough time to run an audit — if you start before the next effective date instead of after it.
For more context, read FTC Sends Warning Letters to 10 Companies: The Fake Reviews Grace Period Is Over.
For more context, read meta dma compliance.
For more context, read eu ai act article 50.
