New U.S. data privacy and AI rules are becoming part of everyday marketing decisions, from choosing data providers and building audiences to using artificial intelligence models. For businesses operating across multiple states, the challenge is translating different requirements into a consistent strategy that supports customer acquisition and retention as the rules governing data use evolve.
The report U.S. State Privacy and AI Legislative Insights — Summer 2026, authored by Caroline Hudson, a partner at Loeb & Loeb, outlines the major developments shaping this landscape. Growing scrutiny of data brokers, sensitive personal data, and automated decision-making is expanding business responsibilities across data collection, analysis, and activation.
Understanding these changes helps identify the capabilities marketing teams need: a clearer understanding of their data, the ability to extract value from it, and ways to apply data use requirements to daily operations. Technology can support these needs by connecting customer intelligence with marketing activation.
The U.S. Data Privacy Landscape: Overlapping State Requirements
Consumer privacy in the United States continues to be governed by a patchwork of state privacy laws alongside federal and sector-specific requirements. Marketing teams must navigate frameworks that share some core principles but differ in applicability thresholds, definitions, exemptions, and restrictions.
Major developments include broader data broker regulations, expanded state privacy laws, tighter restrictions on sensitive data, protections for children and teens, and new requirements for certain uses of AI.
This fragmentation has practical consequences. The same data activation workflow may require different assessments depending on the state, the data involved, the parties receiving it, and the purpose of processing. Businesses therefore need processes that accommodate these differences and adapt to future changes.
Data Broker Regulations: Greater Scrutiny of Data Sources and Data Flows
Data broker regulations are expanding the range of businesses subject to specific obligations, introducing new definitions and mechanisms for consumers to exercise their privacy rights.
New Jersey has introduced a category of “data collectors”: businesses that collect information directly from consumers and then sell or license it to a data broker. Collecting data directly does not necessarily place a business outside these requirements when it subsequently commercializes that information. Registration is expected to begin in spring 2027.
In California, the Delete Request and Opt-out Platform, or DROP, allows residents to submit a centralized deletion request to registered data brokers. Starting August 1, 2026, data brokers must access the platform at least once every 45 days to begin processing deletion requests.
Connecticut follows a separate timeline, with data broker provisions taking effect on October 1, 2026, a registration requirement beginning January 1, 2027, and residents able to submit requests through its centralized mechanism starting July 1, 2028.
For marketing teams using purchased data or data enrichment services, these developments make it more important to understand data provenance, provider terms, and changes that may affect how information can be used. Data broker obligations also affect the broader ecosystem that supplies data for targeting, analytics, and customer profile enrichment.
Sensitive Personal Data: Derived Attributes Matter Too
Another significant change is the expansion of sensitive personal data categories and the protections attached to them.
Definitions may include health information, biometric and neural data, certain financial and government identifiers, and other protected categories. In some states, sensitive data provisions apply even to businesses that do not meet the thresholds normally established by comprehensive privacy laws.
For marketing, the treatment of inferences is particularly important. In Maryland, the definition includes sensitive attributes inferred from data, such as information about health, religion, or sex life.
Assessments therefore need to cover the outputs of analytics and AI models. A dataset may contain seemingly ordinary purchases, interactions, or text, while a segment generated from that data may reveal a sensitive characteristic.
The issue extends to what a business infers about a consumer, beyond the information originally collected. A model predicting repeat purchase probability and one attempting to infer a health condition produce attributes with different implications. This distinction becomes central as predictive AI and customer segmentation become part of marketing workflows.
Data Sale and Sharing Restrictions: Consent Does Not Authorize Every Use
Several states are introducing or strengthening prohibitions on the sale of sensitive personal data, precise geolocation data, and information about minors. Some restrictions are absolute: consumer consent does not create an exception allowing the prohibited activity.
Businesses must distinguish between activities permitted under specific conditions and those prohibited by applicable law.
The terms “sale” and “sharing” also require attention. Their statutory meanings can extend beyond transferring data in exchange for money and cover data flows used in the advertising ecosystem.
In California, sharing refers to disclosing personal information for cross-context behavioral advertising, and consumers have the right to opt out of both sale and sharing. The conditions under which data is sent to an advertising partner therefore become part of campaign planning.
Technically transforming an identifier does not necessarily remove these obligations. Hashed data used for matching may remain linkable to an individual and continue to qualify as personal data.
Children’s and Teens’ Privacy: Audience Segmentation Must Account for Age Restrictions
Protections for children and teens continue to evolve through rules that differ by age, activity, and service type.
Requirements include restrictions on data sales, targeted advertising, and certain online features. Some laws also establish age assurance, parental consent, and specific privacy settings.
For marketing teams, this means that meeting a campaign’s commercial targeting criteria does not automatically make a customer eligible for activation. A customer may fit the intended segment while also being subject to an age-related exclusion.
Businesses need to connect their marketing criteria with the information and rules they use to determine which audiences can be reached through each channel.
AI and Automated Decision-Making: The Use Case Determines the Obligations
U.S. AI laws address a range of issues, including transparency, chatbots, synthetic content, frontier models, algorithmic pricing, and automated decision-making.
Businesses using predictive AI need to understand which provisions apply to their use cases. Rules governing deepfakes or companion chatbots address different concerns from those governing automated consumer decisions.
Colorado provides a concrete example. SB26-189 replaces the previous framework with requirements for automated decision-making technology that materially influences consequential decisions in areas such as employment, education, housing, financial services, insurance, and healthcare. Requirements begin January 1, 2027, and include documentation, consumer notices, and rights related to covered decisions.
A prediction used in a retail marketing campaign does not automatically fall within these requirements. The model’s role, the industry, and the effects of the decision help determine the applicable framework.
Clearly defining each AI use case connects the technology to its actual function. Estimating customer lifetime value, selecting campaign recipients, and contributing to a decision about access to a service are distinct activities.
What Changing Privacy Laws Mean for Marketing Operations
These developments make data governance an operational capability. Businesses need to connect data use requirements with the workflows that generate predictions, audiences, and advertising signals.
The first need is a shared data foundation with clear provenance. Data sources, available attributes, and permitted uses become harder to manage when marketing teams rely on exports and datasets spread across different systems.
The second is getting more value from direct customer relationships. Greater scrutiny of data brokers makes it strategically important to understand what purchases, interactions, and customer history can already reveal before adding external data.
The third is incorporating privacy preferences and exclusions into audiences. Eligibility information needs to work alongside commercial targeting criteria so that business rules carry through to campaign execution.
The fourth is designing data activation workflows around specific objectives. For each destination, marketing teams need to select the events, values, and attributes to use, keeping transfers connected to a defined purpose.
These needs call for closer collaboration between marketing and data teams. A shared data foundation and integrated activation tools can make that collaboration easier and reduce the manual work required to move from analysis to campaign execution.
How the Bytek Prediction Platform Supports These Needs
The Bytek Prediction Platform connects data in the warehouse with predictive intelligence and marketing activation. It works within a business’s policies and data governance processes, helping translate them into operational marketing use cases.
Warehouse-Native AI: Working From a Shared Data Foundation
The BPP uses a warehouse-native, zero-copy architecture: predictive processing runs in the data warehouse, using data within the company’s infrastructure.
This approach allows marketing and data teams to work from a common foundation, reducing the need to create an additional operational repository of source data to run predictive models.
The benefit is greater continuity between data preparation, attribute creation, and marketing execution. Datasets selected by the data team can support predictions and segments alongside the information needed to determine eligibility for the intended activities.
In a fragmented regulatory landscape, this structure makes workflows easier to adapt. When inputs or business-defined criteria change, teams can organize their work around the same data foundation, limiting the proliferation of separate dataset versions.
Predictive Intelligence: Getting More From First-Party Data
BPP models, including Action Prediction, Predictive Lifetime Value, AI RFM, and Churn, turn customer history into insights that help teams prioritize acquisition and retention efforts.
For brands, this means moving beyond segmentation based only on the most recent purchase or historical spending. Predicted customer lifetime value accounts for expected future value; Action Prediction estimates the likelihood of a specific action; and churn models help identify customers at risk of leaving.
These insights can support budget prioritization, differentiated customer engagement strategies, and opportunities to re-engage customers.
The benefit is making better use of the data already available. Many marketing decisions can be supported by a deeper interpretation of first-party data, reducing the need to purchase additional personal attributes for every initiative.
Data Enrichment: Creating and Integrating the Attributes Marketing Needs
The BPP offers three complementary ways to enrich customer intelligence: Field Builder, AI Data Enrichment, and Data Enrichment API. Teams can choose how to obtain information based on the available data and the use case, drawing on existing business data first and adding external sources when needed.
Field Builder creates attributes through aggregations, formulas, conditional logic, text operations, and lookups. Teams can calculate order counts over the past 90 days, cumulative margin, days since the last purchase, or engagement tiers. Information spread across multiple records becomes fields that can be used for customer segmentation and activation.
The benefit is generating useful new information from existing first-party data, reducing reliance on external sources when the answer can be derived from customer history. As data provenance and data flows receive greater scrutiny, this allows businesses to enrich segmentation using information whose collection context they already understand.
An objective such as “re-engage high-value customers who have not purchased in two months” can be translated into precise criteria by combining a value prediction with a days-since-last-purchase field. The resulting attributes can be reused in future initiatives.
AI Data Enrichment derives attributes from existing content using a large language model, or LLM, for tasks such as categorization, text extraction, summarization, and sentiment analysis. A brand can, for example, turn written feedback into categories related to delivery, packaging, or customer support. Content that was previously difficult to use becomes structured information that helps identify recurring issues and inform more relevant actions.
When a use case requires additional information, Data Enrichment API connects the data warehouse to external providers and integrates the resulting attributes into the data foundation used by marketing. This enables businesses to add data in response to a specific need, with a targeted selection of sources and required information.
Together, these capabilities allow teams to calculate attributes from existing data, derive them from available content, or add them through a provider. The benefit is richer customer intelligence while limiting new data acquisition to what the marketing objective actually requires.
Audience Manager: Combining Business Priorities With Activation Eligibility
Audience Manager builds audiences by combining available attributes and predictive outputs.
When the underlying data includes business-defined eligibility attributes, those fields can become part of the segmentation criteria alongside customer value, recent behavior, and propensity to act.
A win-back campaign can therefore select customers with high predicted customer lifetime value, no purchase in the past 60 days, and eligibility for the chosen channel. The same data foundation can support a suppression audience for recent purchasers.
The benefit is incorporating rules into the segment definition, reducing the need to manually adjust lists after they have been created. Marketing and data teams can connect available information with more consistent audience activation logic.
Audiences can be activated across supported destinations, connecting customer intelligence with the platforms used to execute campaigns.
Signals Manager: Optimizing Campaigns for Value
Signals Manager supports integrations such as Enhanced Conversions, Conversion Adjustments, and Meta Conversions API, connecting business data with the signals used by advertising platforms.
For marketing teams, the benefit is designing campaign optimization around events and values that better reflect business objectives. Purchases with different values can be treated differently, while predictive insights can contribute to a customer lifetime value strategy through the capabilities supported by each destination.
This allows teams to focus on signal quality: selecting information that is meaningful for optimization and organizing the data flow around the users, events, and attributes defined for the use case.
As data flows receive greater scrutiny, precise signal configuration helps connect each transfer to a concrete marketing objective.
Connecting Data Governance With Marketing Activation
New U.S. privacy and AI laws require businesses to understand their data more clearly and carry data use requirements through to marketing execution. This makes a first-party data strategy built on a shared foundation for analytics, segmentation, and activation increasingly valuable.
The BPP supports this approach by using warehouse data to generate predictions and attributes and connect them with marketing destinations. Business-defined eligibility information can be used alongside commercial criteria, while audiences and signals are built around the objectives of each initiative.
The benefit is a more direct path from data to action: generating intelligence from existing data, reducing reliance on external sources when they are unnecessary, and incorporating business rules into activation workflows. This gives marketing teams an operational foundation for adapting to regulatory changes while continuing to focus on customer acquisition, customer value, and retention.


