See how Syrenis helps simplify compliance, build trust, and gain greater control over customer data. Book a Demo

Blog Article

The 2026 Privacy Playbook: What’s Changed, What’s Next, and What Companies Need to Know

Posted: September 14, 2026

A company sets up a consent management platform, publishes a privacy notice with a rights request link, and files a data inventory. A year later, the link is broken, nobody is checking the request mailbox, and the inventory does not mention the three tools marketing adopted since. 

On paper, the privacy program is complete, but from the outside it has already failed.

That gap between having privacy tools and running an effective privacy program was the thread running through a recent webinar, The 2026 Privacy Playbook, with Jodi Daniels, founder and CEO of Red Clover Advisors, and Morgan Woodbury, VP of Enterprise Sales at Syrenis

Here are the developments they flagged and the tests they suggested, backed by the enforcement record.

What Changed in 2026: Four New State Laws and a Wider Net

After a year with no new comprehensive state privacy laws, 2026 has produced four: Oklahoma, Alabama, Louisiana, and Vermont, bringing the commonly cited total to 23 states with comprehensive privacy laws. Indiana, Kentucky, and Rhode Island also took effect this year.

Daniels singled out two: 

  • Louisiana adds a $25 million revenue threshold, one of the few states besides California to do so, which can pull in businesses that might fall outside purely volume-based thresholds.
  • Alabama does not give nonprofits a blanket exemption. Nonprofits with fewer than 100 employees are exempt only if they do not sell personal data, meaning larger nonprofits may need to assess whether the law applies to them.

The wider net includes sensitive data. Connecticut has added neural data to its sensitive categories, joining Colorado, and several states are amending existing laws to cover children’s data or adding standalone children’s laws that reach teenagers. 

As Daniels put it, these laws cover the teen market, and the age bands differ by state: Some protections extend to age 16, others to 17 or 18.

What’s Next: Deletion at Scale and AI by Sector

More than 500,000 Californians have already registered with the state’s Delete Request and Opt-out Platform (DROP), and brokers have been required to begin processing DROP requests since August 1, accessing the system at least once every 45 days.

Daniels warned companies not to assume the Delete Act is someone else’s problem: The broker definition is wide, and if sales or marketing buys data, the pool available to them will shrink as opt-outs accumulate.

AI regulation is following the same patchwork path. 

Daniels noted that more than 300 AI bills had already been introduced or were moving across the states earlier in 2026, including dozens in California, many targeting specific uses: Chatbots, employment, pricing, real estate, and minors. Automated decision-making is also moving from policy discussion into concrete compliance obligations, with California’s ADMT requirements for significant decisions scheduled to begin January 1, 2027.

Why Operationalizing Privacy is Harder than Understanding It

Most companies can read a new law. The difficulty, in Woodbury’s description, is the translation layer: Working out what a change means across every customer touchpoint, every system, every vendor and their vendors, and every process built before the law existed

The underlying problem is rarely the regulation and usually visibility, because teams cannot say with confidence how data is used and who has access to it.

Daniels’ starting point is ownership. Someone has to own the consent tool, the pixel deployment process, and the question of whether the company holds children’s data at all. Without an owner and a plan, each of those pieces drifts.

Where the False Sense of Readiness Comes From

Daniels notes that website privacy audits almost always turn up something out of line: A rights form that was never configured properly, a notice in the app store that differs from the one in the app and the one on the website, or an inventory that was comprehensive two years ago.

Regulators are finding the same problems from the outside.

  • In February 2026, a major streaming and media company paid $2.75 million, the largest settlement under the California Consumer Privacy Act (CCPA), because opt-outs applied only to the service or device where they were made. 
  • Four months earlier, a live TV streaming service paid $530,000 in part because its privacy choices link led to a cookie preference center that did nothing to stop data sales through other channels. Both companies had the tools. The choices recorded in them were never fully honored.

Both companies had the tools, but the choices recorded in them were never fully honored.

Who Owns Privacy and AI Governance

Woodbury described a pattern she sees more often: An AI governance board that meets monthly, produces polished presentations, and moves nothing forward until it is quietly disbanded. The missing element is a final decision maker and clear ownership of each step.

Her working framework has four layers. 

  1. Executive leadership sets risk appetite. 
  2. The business owner defines the why behind an initiative. 
  3. Privacy and legal challenge whether all that data is needed and set the boundaries within the risk appetite. 
  4. Security and IT make sure those boundaries hold in the actual systems.

Daniels added that where privacy sits matters less than whether it gets a seat and support. She has seen it owned successfully by marketing, security, and legal, with one caveat: Privacy and security are intertwined and remain different disciplines, so a security-owned program still needs dedicated privacy resources. 

Privacy champions embedded in marketing and product teams are how some of the largest global brands make a small privacy operations team work.

What an Effective Risk Assessment Uncovers

A risk assessment starts with the data inventory questions: 

  • What is collected? 
  • How is it used? 
  • Who is it shared with? 
  • In which systems? 

From there it asks what could go wrong, which controls mitigate it, who is responsible, and by when.

Companies fall short in three places: The conversation happens and nothing is documented. Something is documented and no privacy professional reviews it against the laws that apply. Or issues are found and the loop is never closed. 

When a regulator or customer later asks “where’s the proof,” the answer has to be more than a memory of a good meeting.

Three Things to Do This Quarter

  • First, identify your top three risks. For some companies that is marketing and sales, for others product, employee data, analytics, or AI use. Start where your riskiest data or use case lives.
  • Second, test one customer choice end to end. Pick a single flow, follow the consent through every system it touches, and check whether there is an audit trail. Regulators test from the outside, and so do prospective B2B customers, and an external failure is what starts an inquiry.
  • Third, build triggers. A short privacy threshold assessment attached to new projects, new vendors, or a standing monthly check-in with product and marketing decides whether a deeper assessment is needed. 

One caveat from Daniels: Project management offices tend to track spend, and a privacy impact can arrive with a budget of zero.

The full recording, including the audience Q&A on which customer journey to test first, is available to download here.