Washington’s Privacy Gap Has a Map Now
Washington is home to Amazon, Microsoft, and one of the most data-dependent economies in the country. It doesn’t have a generally applicable consumer privacy law. Three attempts at one failed in 2019, 2020, and 2021, and each time the cause it failed was the same fight: the Senate wanted Attorney General-only enforcement, the House wanted a private right of action, and nobody budged.
On August 14, 2026, Attorney General Nick Brown released the first-ever Washington State Data Privacy Report. You can read the AG press release or the full 35-page report. For the first time, there’s a map: what’s broken, what consumers want, and what other states already do that Washington doesn’t. I advise Washington businesses on security and privacy, and most aren’t anti-privacy. They’re uncertain about what’s coming. This report reduces some of that uncertainty.
The Numbers Should Bother You
In 2025, the AGO (Attorney General’s Office) received notices for 209 data breaches affecting more than 8 million Washingtonians. That marks the second straight year breach notices sent (many people receive more than one) outnumbered the state’s residents. More than 80% of those breaches exposed Social Security numbers. According to the AGO’s own Data Breach Report and state open data portal, more than 47 million breach notices have gone out to Washington residents since 2017. Nothing structural has changed to slow that counter.
The AGO’s 2025 Data Privacy Survey adds the consumer side, pulling over 700 responses from 26 counties. Eighty-three percent of respondents said they have little or no control over who accesses their personal information. Ninety-five percent said there is no circumstance in which they’d be comfortable having data collected, shared, or sold without informed consent. Fifty-five percent said they don’t trust any institution, public or private, to keep information secure. Your customers are telling you, in plain language, that they don’t trust anyone holding their data, and that includes you. That’s not a compliance problem. That’s a revenue problem. Distrust shows up as abandoned carts, opt-outs, and customers who churn to a competitor they trust more. Every point of erosion has a dollar value.
| Metric | Statistic | Source |
|---|---|---|
| Breaches in 2025 | 209 | 2026 Data Privacy Report |
| Residents Affected | 8+ million | 2026 Data Privacy Report |
| Breaches Exposing SSNs | 80%+ | 2026 Data Privacy Report |
| Feel Little/No Control Over Data | 83% | 2025 Data Privacy Survey (n=700+) |
| Demand Informed Consent Always | 95% | 2025 Data Privacy Survey (n=700+) |
| Trust No Institution | 55% | 2025 Data Privacy Survey (n=700+) |
Breach figures from the 2026 Data Privacy Report; survey figures from the 2025 Data Privacy Survey (n=700+).
Fragmentation Creates Confusion
The report’s sharpest point is about fragmentation, where the same type of data gets strong protection in one context, and no protection in another. Location data is protected when it’s near a healthcare facility under the My Health My Data Act (Chapter 19.373 RCW, or MHMDA) or when collected through a government ALPR (automated license plate reader) system under the Driver Privacy Act, signed March 30, 2026. Location data collected for commercial advertising? Nothing. Biometric identifiers are covered under RCW 19.375, but photographs, video, audio recordings, and data derived from all of those are explicitly carved out.
For businesses, fragmentation means you can’t build one compliance program and trust it. The same customer record might be regulated three different ways depending on where it was collected and why, and you often don’t know which regime applies until something goes wrong. A consistent framework would reduce compliance complexity, not add to it.
What the Report Recommends
The report makes four substantive policy recommendations to the Legislature, plus a fifth on enforcement (more on that below). Together, they mirror what businesses in California, Colorado, Oregon, and Connecticut already deal with.
Consent and Deceptive Design
Require meaningful, informed consent before collecting or sharing data beyond what’s necessary to deliver a service. Ban deceptive design practices that make “accept all” easy and “reject” buried. The GDPR (General Data Protection Regulation) and CPPA (California Privacy Protection Agency) enforcement advisory references are the template. If your cookie banner makes accepting privacy terms one click and rejecting takes four, you have a problem. Fix it before a regulator or plaintiffs’ attorney does it for you.
Data Minimization
Collect only what you need, retain it only as long as necessary, and restrict secondary uses. The report draws a direct line between overcollection and breach severity. The more you hold, the more you lose. Audit your data collection. If you’re gathering information you don’t use to deliver your core service, you’re carrying exposure you don’t need. Anything you collect but don’t use is pure downside.
Biometric and Geolocation Protections
Strengthen protections for biometric and precise geolocation data with consent requirements, sale restrictions, and retention limits. Virginia’s SB 338 and Oregon’s HB 2008, both banning geolocation data sales, are cited as models. Check your biometric and geolocation retention. Are you keeping movement histories longer than the service requires? Regulators and plaintiffs look there first.
Data Broker Registry
Require data brokers to register with the state, maintain security safeguards, honor deletion and opt-out requests, and participate in a centralized mechanism similar to California’s DROP (Delete Request and Opt-out Platform). Washington’s HB 2483, which would create a broker registry, is already in the Legislature. Map your data-sharing pipeline. Under HB 2483’s proposed definition, a data broker is a business that collects, sells, or licenses brokered personal data to another person. If your business sells or licenses consumer data to third parties, figure out whether you’d fall under that definition before the Legislature decides for you.
The Enforcement Question
Two bills are worth tracking. HB 1671, the People’s Privacy Act, modeled on the framework developed by EPIC (Electronic Privacy Information Center) and Consumer Reports, passed committee in early 2025 and has been sitting in Appropriations since. HB 2483, the narrower data broker registry, is the more likely first pass because it’s scoped tighter and has precedent in five other states.
The enforcement section is where things get politically loaded. Recommendation 5 calls for “clear, practical, and accountable enforcement mechanisms” and lists regulators, consumers, or both as possible enforcement authorities. That’s deliberately non-prescriptive, and it’s the exact fault line that sank three bills.
Here’s what’s different now. The MHMDA already includes a private right of action through the Washington Consumer Protection Act, with treble damages up to $25,000 per violation. Two class actions were filed under it in 2025: one against Amazon in February over software development kit (SDK) based location data collection, and one against Uncle Ike’s, a Seattle cannabis retailer, in November over website tracking pixels transmitting customer data to Google and other third parties. Both are pending. Private rights of action aren’t hypothetical in Washington. They’re live, and the MHMDA proves they’re politically viable.
Monday Morning Checklist
| Action | Why Do It | Risk if Ignored |
|---|---|---|
| Inventory data collection | Reduces breach surface | Minimization violations if a law passes |
| Review consent flows | Meets consent standard | Deceptive design claims; see the 2025 MHMDA class actions |
| Map data-sharing pipeline | Identifies broker status | Registry noncompliance under HB 2483 |
| Check biometric retention | Limits scope of liability | Private right of action exposure under MHMDA precedent |
| Monitor HB 1671 and HB 2483 | Tracks legislative timeline | Scrambling when laws pass, with no runway |
What Happens Next
The report is a signal, not a law. Whether it becomes one depends on the Legislature, and businesses should weigh those risks of future litigation and regulatory enforcement against their own tolerance. Some will accept the risk and move on. But the conditions the report describes are already here: 47 million breach notices, consumers who trust nobody, and targeted laws that protect the same data in one context and leave it wide open in another.
The businesses that read this report and act now keep their options open. The ones that wait are betting nothing changes, and Washington’s history says that bet gets worse every year.