These questions come from privacy operators, DSAR coordinators, and consent managers who've been reaching out over the past few months. You're seeing more enforcement notices, handling more subject rights requests, and wondering if your current setup will withstand scrutiny. Here's what you need to know.
"We're a 40-person company. Are we actually on regulators' radar?"
Yes. The era when only giants like Facebook and Google faced enforcement is over.
Romania has issued €2,000 fines to companies with fewer than 50 employees. While not financially devastating, these fines can impact your reputation during customer, partner, or investor evaluations. The reputational damage often outlasts the financial hit.
California and Texas have both issued multiple enforcements in 2025, targeting more than just big names. State regulators are also sending non-compliance notices that, while not resulting in fines, still disrupt operations. Your team has to stop their work to respond, legal counsel gets involved, and you could spend weeks on remediation.
The shift is clear: enforcement is broader, not just bigger. If you're waiting for enforcement to invest in compliance, you're already behind.
"What exactly are regulators checking first when they investigate?"
They're focusing on the parts of your privacy program that consumers see and interact with: your consent notice, privacy policy, and subject rights portal.
Honda faced penalties for excessive identity verification in their subject rights workflow. Allstate's enforcement under the Texas Data Protection and Security Act began when consumer complaints revealed discrepancies between their data collection and disclosures.
Regulators aren't initially auditing your internal assessment templates or vendor management spreadsheets. They're checking if your public-facing compliance mechanisms work and align with your claims.
Prioritize:
- A consent management platform free from dark patterns
- Privacy policies that accurately reflect your data practices
- A subject rights portal that processes requests smoothly
If you've been building compliance from the inside out, shift your focus. Ensure the public-facing elements are solid first.
"How much identity verification can we require for CCPA requests?"
Less than you might think, especially for opt-out requests.
California mandates that you can't verify identity for requests to opt out of the sale or sharing of personal information, or to limit its use. For these requests, process them without verification.
For other requests, access, deletion, correction, collect only the minimum data needed, often just an email address. If you're asking for driver's licenses, utility bills, or multi-step verification for a basic deletion request, you're overcollecting.
The Honda case shows the risks of not following this standard. If you're subject to CCPA, adopt California's identity verification framework, even if you operate in multiple states. It's the most restrictive standard and will keep you compliant elsewhere.
"Should we test our own subject rights workflow?"
Absolutely. Submit test requests through your portal and track the process.
Does the request reach the right team? How long does it take to respond? What information are you collecting? If you're asking for unnecessary data, you're creating compliance risk.
Consider the impact of processing dozens of requests per month. Does your workflow scale, or will it collapse under volume? If your process relies on manual emails and spreadsheets, you'll struggle as request volume increases.
Your subject rights workflow isn't just a compliance checkbox. It's an operational system that needs to function under real-world conditions. Test it before regulators do.
"We haven't updated our privacy policy in two years. How screwed are we?"
It depends on how much your data practices have changed.
If you've added new vendors, implemented new tracking, or expanded data collection without updating your policy, you're signaling non-compliance. Regulators check if your disclosures match your actual practices.
Start with a data inventory. What are you collecting, from whom, for what purposes, and who are you sharing it with? Compare this to your current policy. Where they diverge, you have a disclosure gap.
Update your policy to reflect current practices, not past intentions. Set a recurring reminder to review it quarterly. Your data practices will change; your policy needs to keep pace.
"Are those wiretap and VPPA lawsuits still happening?"
Yes, but the momentum might be shifting.
Lawsuits under the Video Privacy Protection Act and state wiretap laws like the California Invasion of Privacy Act continue to target website tracking pixels. However, some states, like Massachusetts, are denying that wiretap laws apply to website tracking. California's Senate is advancing Senate Bill 690, which would exempt tracking technologies used for commercial purposes.
The NFL recently filed an amicus brief asking the Supreme Court to hear a VPPA case involving the NBA. Depending on the Court's decision, we might see the end of a major litigation source for businesses with video content.
These cases highlight frustration that outdated laws aren't suitable for modern privacy rights. Until courts or legislatures act, you're still at risk if you're using tracking pixels without Valid Consent.
"What's the single most important thing we should focus on right now?"
Visible compliance indicators.
Regulators start investigations with systems consumers interact with. Your consent mechanism, privacy policy, and subject rights portal must be functional, accurate, and compliant.
If you're trying to build everything at once, assessments, vendor management, privacy-by-design workflows, data inventories, you'll spend months or years before reducing your most visible risk. Start with what regulators see first.
Don't tackle this alone. Privacy laws change constantly, and mistakes create the risk you're trying to avoid. Use platforms that embed compliance guidance into workflows, or work with counsel who understands both the law and operational reality.
Businesses facing enforcement aren't always those with the worst practices. They're often the ones with the most visible gaps.



