Disclaimer: Kash, John, and Michele all made a point of saying this up front, so I’m doing the same. Everything they shared reflects their own personal views, not the official position of their offices or Attorneys General.
This past Wednesday, I hosted a fireside chat with three state privacy regulators. Kash Chand out of the New Jersey Attorney General’s office, John Eakins from Delaware, and Michele Lucan from Connecticut. It wasn’t a presentation or fancy slides. It was a solid hour of a true round table discussion sharing what each of the regulators are seeing firsthand and what their state expects companies to be doing. Oftentimes, we hear that regulators collaborate and work together. It was SO apparent that this group really is on speed dial with each other, and just like privacy pros build community to learn from each other, regulators do that too.
We were reminded by a personal story Kash shared that:
Regulators are just people who use the same apps we do, and get frustrated by the same broken opt-out buttons.
It’s like when a kid sees a teacher at the grocery store or Target – wait, teachers are real people too? Yup, same situation here: regulators use the same websites and apps as the consumers they are trying to protect because they are consumers.
I took a lot of notes. There was too much here for one newsletter topic, honestly, so this week I’m going long, and it’s hard to cram it all in here. Five things kept surfacing, and I think every one of them belongs in your operational checklist, not just your policy binder.

Privacy offices are growing
New Jersey has the biggest team of the three. Kash described his Data Privacy and Cybersecurity section as “a rather big team,” with 12 attorneys, one part-time attorney, and two paralegals.
Connecticut has grown steadily but stayed leaner. Michele said she started with “just two of us on the privacy team” and they’re now up to 6 attorneys, plus a legal investigator and a paralegal, with the team “no doubt continuing to grow.” She also noted Connecticut doesn’t have a technologist yet, but will be “looking for one soon.”
Delaware is smaller still. John called it “a small team, as a small state, probably not surprising that we have a smaller team than Kash,” though one thing sets Delaware apart: a team member who works as a technologist with a PhD in computer science.
Nobody’s asking for perfect
Michele said this almost verbatim: none of them are looking for perfection. What they want is evidence that a company took the law seriously and made a documented, good-faith effort to comply.
When Connecticut sends an inquiry, they’re not just asking about the one issue that triggered it. They’re asking for your privacy program, your notices, your internal policies, and your data protection assessments. John made the point even sharper: they want to see decisions documented when they were actually made, not reconstructed after the fact once a letter shows up. Kash put it plainly too. They want to understand why you chose one path over another, and whether you’ve gone back and re-evaluated that choice as your data practices changed.
I’ve said this is like in school, where showing your work on how you solved the math problem is important – not just the answer. It’s quite possible that a regulator might not agree; however, understanding the thought process and documentation is factored into the analysis.

Here’s the part I didn’t expect: both Kash and Michele talked about how much worse it gets when a company seems evasive. Kash described seeing less cooperative responses lately with companies being less transparent about what actually happened on their systems, which just drags the investigation out and makes it more contentious. Michele agreed. Vague, one-sentence answers don’t protect companies, they just slow everything down and make the office dig harder. Neither office is going to walk away from a matter without a clear picture of what happened, so stonewalling doesn’t avoid that outcome.
Kash shared a story that one time outside counsel asked him why he even cared about a case, since he wouldn’t be there in three years when it was resolved. His answer is that these offices are built to outlast any one person on either side of the table, so playing a long game against them isn’t really a strategy. And Kash is still there seven years later.
None of that requires a flawless program. It requires a paper trail. If your privacy decisions live in someone’s memory instead of somewhere written down, that’s the gap to close first, and it’s usually the cheapest one to fix.
Opt-Outs: The freedom to choose, change, and choose again
Kash reminded companies that consumers need to be able to change their decisions. He shared that he once personally made an opt-in choice on his phone and found reversing it to be far more complicated than agreeing to provide his data. He also flagged a pattern he’s seeing: some companies, after you opt out, show you a banner warning that you won’t get “the best version” of the site. He said that starts to look like a dark pattern too, because it breaks the symmetry between opting in and opting out. Michele reminded companies that if you’re going to have a cookie banner, it needs to be symmetrical. One step to opt-in? Then it can’t be multiple steps to opt-out.
I continue to see this ALL the time! We recently went through a batch of consumer apps and websites, and they had no way to change your choice once you made it. You picked one, and that was it. Gone. In last week’s newsletter, we highlighted our most common cookie consent challenges.
John and Michele both flagged the same failure mode from the other direction: companies build an opt-out mechanism, flip it on, and consider the job done. But a mechanism that exists isn’t the same as a mechanism that works.
Connecticut ran a joint sweep with California and Colorado last fall, specifically testing whether universal opt-out signals (which sidebar led to an entire discussion on what we’re calling this now – the general agreement was “OOPS” now) were actually being honored across a company’s systems. The investigation revealed some companies honored the signal while others did not.
Regulators reminded us they have technical tools to test these opt-outs.

Selling data doesn’t end your responsibility for it
This one might be the biggest shift happening right now. For years, a lot of companies treated data sharing agreements as something you only needed for EU data. Regulators had strong opinions on why companies need to have data sharing agreements in place. For example, Delaware’s newest amendments spell out exactly when you need a contract and due diligence for those transfers.
New Jersey took it further with its data broker registry law, which was talked about briefly (that could be an entire webinar on its own). Companies that collect data and then sell or share it with unrelated third parties now have to register and disclose what opt-outs they honor and how.
Michele reminded us that privacy rights belong to the person, not the device or the platform. They’re not something that resets every time your data moves somewhere new. If your company shares data across an ad tech ecosystem or a network of partners, the expectation is that a person’s choice follows them through that whole environment, not just the part of it you built yourself.
If you don’t have a clean map right now of who you share data with and what’s in those contracts, fix that before someone asks you for it on a deadline.
A stale privacy notice is a warning light, not a paperwork issue
There were a lot of comments here too about privacy notices.
John pointed to a red flag he sees constantly: opening a privacy notice and finding “last updated March 2024,” which is a huge hint that there are other issues.
Every state privacy law requires the notice to actually inform people what their rights are, and regulators are seeing things constantly: companies listing the wrong states, and companies hedging with language like “you may have certain rights.”
John was pretty direct that hedging doesn’t cut it. Saying a consumer “may” have a right doesn’t actually tell a Delaware resident whether they have one. In his words, that’s almost its own dark pattern: you’re making someone go research their own state’s law just to find out if the rights you’re describing even apply to them. He’d rather every Delawarean knew the law existed, but they don’t, so the notice is the one place that’s supposed to make it clear.
He also pushed on something a lot of companies don’t think about: it’s not just your website. Mobile apps and other connected devices carry the same obligations. If you’re dropping an SDK into your app, you need to know exactly where that data goes, because that’s an area his office is actively looking at, right alongside websites.
Michele backed this up from the Connecticut side. Privacy notices, she said, are low-hanging fruit for her office. She’s still seeing notices that don’t mention Connecticut’s law at all, or only reference California’s, three years into CTDPA enforcement. Her words were that this is inexcusable at this point. And if the public-facing notice is that far off, she assumes there’s more wrong underneath it, because if a company can’t get the one document meant for consumers right, the internal work is unlikely to be in better shape.
Regulators say it plainly: these are the easy-to-spot issues that send them looking for the harder, more technical violations underneath.

Sensitive data, profiling, and kids are where all three offices are leaning in hardest
We didn’t originally plan to spend much time here, but it came up enough that it deserves its own section.
Michele walked through where Connecticut’s law has gotten stronger. Residents now have the right to opt out of profiling, and profiling was just redefined more broadly. It used to mean solely automated decision-making. Now it covers any automated processing that produces a legal or similarly significant effect, which is an expanded right. Residents can also contest the results of a profiling decision, and businesses have to run impact assessments on any profiling activity. If you handle Connecticut residents’ data and haven’t looked at your profiling practices against this, that’s worth doing now.
Kash talked about New Jersey’s approach, which is aggressive. The data broker registry law effectively prohibits sharing sensitive data for profiling purposes. His office is co-leading litigation against Meta with California, Colorado, and Kentucky, and has separately sued TikTok and Discord. A lot of this is aimed at protecting the 13 to 17 age group, which COPPA doesn’t cover. New Jersey now requires opt-in consent to use that age group’s data for profiling or targeted advertising. New Jersey also just passed a law addressing surveillance pricing, looking at how profiling of both kids and adults can affect something as basic as what someone pays for groceries.
John described Delaware’s amendments as moving in the same direction. They ban the sale of sensitive data outright. Delaware was also the first state, back in 2023, to extend its age protections to include 16- and 17-year-olds specifically, not just kids under 13. The newer amendments expand what counts as sensitive data too, covering nearly all health-related data, and for the first time writing directly into statute that an inference used to place someone into a sensitive category counts as sensitive data itself. Colorado already does this by regulation, but John said most people in his line of work already treated inferences this way. The amendment is really just making that explicit.
Reminder: the age ranges are not the same state to state.
New Jersey said 13 to 17. Other states say 13 to 16. Either companies have to take a conservative approach to treat all teens the same at the strictest requirements possible or check state by state and build operations to accommodate the differences.
Resources
If you want a deeper resource here, Michele pointed people toward Connecticut’s own advisories on this. The Attorney General’s office keeps a page with the CTDPA enforcement reports, FAQs, and guidance specifically on privacy notices and honoring Global Privacy Control. It’s worth a look even if you’re not a Connecticut-only company, since a lot of what they’re flagging shows up across every state law modeled the same way.

Here’s where it all lands
Every one of these comes back to the same idea: trust and compliance aren’t two separate goals. A notice people can actually read, an opt-out that holds up when you test it, a vendor relationship you can explain in plain terms. It’s not just about avoiding an enforcement letter. It’s what makes people trust you with their data in the first place.
Before we even got into any of this, I opened the session with a poll, asking what your organization’s biggest privacy challenge is right now?

Thirty-five percent of you picked turning requirements into operational processes – more than any other answer. Keeping up with changing regulations came in second, and prioritizing with limited resources came in third.
That result doesn’t surprise me at all. We love helping companies operationalize their privacy programs. It’s what we do all day, every day. And it’s exactly why everything in this newsletter is written the way it is.
Companies need to create programs that support the requirements states expect – like documented decisions, not stale notices, and sometimes opt-in consent for teens’ data. Operationalizing all of these requirements calls for repeatable processes.
This is what we’re doing all day for our clients – operationalizing privacy. We’ve taken our approach and created more than two dozen downloadable guides and templates built to help companies cover topics like privacy notices, cookie governance, data inventories, training, program management, and more. You can grab whatever piece you need here.
And if you need more than just the guides, we will walk alongside you to help with full- service implementations. Schedule a consultation, and we’ll walk through where your program actually stands and what it needs next.
We’ll have the full recording in the coming week. Follow Red Clover Advisors to catch it.
Jodi
💡 When you’re ready, here’s how we can help:
⚙ Privacy Advisory & Implementation: We help companies navigate privacy requirements with confidence. Our advisory support covers strategy, operations, and real-world implementation.
⚙ Fractional Privacy Services: We provide fractional privacy leadership tailored to your needs and pace. From program development to day-to-day support, we help you build and sustain a strong privacy program.