Law report No. GLW-1444 · filed October 2, 2026
Regulation & EnforcementReported case
California Eyes Higher Privacy Fines and Age Assurance Rules
California lawmakers are weighing higher privacy fines and age assurance duties as enforcement is set to ramp up in other US states, IAPP reports.
By Sophie Lindqvist2 min read325 words
Holding
- California's legislative agenda includes higher privacy fines and age assurance requirements, IAPP reports.
- Privacy enforcement is expected to ramp up in other US states.
- California historically leads US privacy law via the CCPA and the California Privacy Protection Act.

Privacy enforcement is set to intensify across the United States, with California lawmakers placing higher fines and age assurance requirements on the state's legislative agenda, according to a report by the International Association of Privacy Professionals (IAPP).
The report, published by the IAPP's news desk, indicates that California — the jurisdiction that has long served as the bellwether for American data protection law through the California Consumer Privacy Act (CCPA) and the California Privacy Protection Act — is preparing to sharpen its regulatory toolkit. Two items dominate the agenda: increased monetary penalties for violations and new age assurance obligations, the latter aimed at strengthening protections for minors online.
For practitioners, the significance is twofold. First, any increase in fine levels under the CCPA enforcement regime, administered by the California Privacy Protection Agency and the state attorney general, would raise the financial stakes of non-compliance for businesses handling California consumers' personal information. Second, age assurance requirements would impose fresh technical and legal duties on companies whose services are likely to be accessed by children, likely requiring verified age-estimation or age-verification mechanisms before processing minors' data.
California is not acting alone. The IAPP report signals that enforcement activity is expected to ramp up in other states as well, reflecting a broader pattern: with no comprehensive federal privacy statute in place, state attorneys general and newly created state privacy agencies are increasingly asserting themselves. Companies operating nationally therefore face a growing patchwork of state-level obligations, each with its own thresholds, cure periods and penalty structures.
The practical consequence for legal teams is straightforward. Compliance programmes designed around the lowest common denominator of state requirements will come under strain as enforcement tightens. Counsel advising clients with national footprints should expect heightened scrutiny of data practices involving minors, and should monitor California's legislative calendar closely, since measures adopted there have historically shaped both copycat legislation in other states and the trajectory of privacy practice nationally.
via GN Enforcement (Source)
More from Sophie Lindqvist
Show full bio
News editor covering industry trends and analytics at Global Law Wire.
202 articles
Also before the court
- California Enacts Sweeping Package of Children's Online Safety Laws
- California Regulators Announce Largest CCPA Fine to Date
- California Overhauls AI Transparency Requirements
- Sanctions Compliance Meets Data Privacy: A Structural Tension
- Turkish Parliament Passes Bill Restricting Social Media for Under-15s