Skip to content

The office of the Washington State Attorney General (“AG”) recently released its inaugural “Data Privacy Report” (the “Report”), providing key insights into what regulators in Washington are focused on and giving businesses a preview of potential future liability risks. In an introductory letter, Attorney General Nick Brown outlined the “gaps” his office hopes to address with a revamped data privacy framework, and the Report lays out a series of policy, enforcement, and education proposals intended to address those concerns.

Areas of Concern

The Report details concerns in four categories: A) “Overcollection” and Secondary Use; B) Consent Requirements and Design Issues; C) Collection and Sale of Sensitive Data; and D) Lack of Consumer Understanding of Data Broker Practices.

“Overcollection” and Secondary Use. Among the chief concerns identified by the AG’s office is that businesses collect more data than necessary for the provision of their services and then use that data in ways attenuated from the purpose for which it was initially collected. The Report suggests that unnecessary data collection and retention increase consumer privacy risks.

Consent Requirements and Design Issues. The Report also describes issues with consumers’ “informed consent,” and what it describes as businesses utilizing a “deceptive design” when constructing their privacy policies and the embedded consumer acceptance buttons. The Report borrows heavily from the European Union’s General Data Protection Regulation’s (“GDPR”) informed consent framework, emphasizing clear and accessible consumer disclosures. The Report also focuses on so-called “deceptive designs” that purportedly make it easier for consumers to accept privacy terms than decline them.

Collection and Sale of Sensitive Data. The Report identifies concerns regarding the collection, storage, and sale of sensitive data, particularly biometric identifiers, such as fingerprints and facial recognition data, and geolocation data. The Report expresses concerns that misuse of this information may facilitate surveillance and other consumer harms.

Lack of Consumer Understanding of Data Broker Practices. The Report states that consumers do not know which brokers possess their information, how the information is used, and who has access to it, suggesting that data brokers should be required to register on a statewide database. Additionally, the Report also advocates for a centralized mechanism through which consumers can request deletion of their information, similar to California’s Delete Request and Opt-out Platform, better known as “DROP,” which California created under its DELETE Act.

Proposed Solutions

In addressing these concerns, the Report proposes changes in three areas: 1) policy, 2) enforcement, and 3) education. The AG urges the Legislature to adopt regulations that closely model the GDPR, and those already present in states like California, Colorado, Oregon, Connecticut, and Virginia.

Policy Approaches. The AG urges the Washington State Legislature to consider and adopt four key policy proposals: 1) establish stronger informed consent requirements; 2) establish minimization requirements and secondary use limitations; 3) institute stronger protections for biometric and precise geolocation data; and 4) require data broker registration, safeguards, and consumer data deletion and opt-out rights.

  1. Stronger Informed Consent Requirements

    As set out above, the Report borrows from the GDPR and uses its language to exhort the Legislature to adopt consent requirements that are “clear, balanced, and easy to navigate.” The Report also recommends restrictions on practices it characterizes as “deceptive designs” and urges adoption of consumer privacy rights that are easier to exercise and enforce.

    For businesses, these proposals warrant attention because similar privacy laws, including the California Consumer Privacy Act, the Connecticut Data Privacy Act, the Oregon Consumer Privacy Act, the Colorado Privacy Act, and the Virginia Consumer Data Protection Act have created substantial compliance obligations and enforcement exposure. Businesses should be proactive and prepared to confront the kind of regulatory scrutiny that has become common under the laws of those states, and is now expanding in Washington state.
  2. Minimization Requirements and Secondary Use Limitations

    The AG also requests that the Legislature adopt regulations that require data collectors to collect only the data that they need for the provision of services requested by the consumer. The Report also recommends limitations on secondary uses of consumer data beyond the purpose for which it was originally collected.

    For businesses that rely on broad data collection, retention, or monetization practices, these proposals could require significant operational changes and threaten existing revenue streams.
  3. Stronger Protections for Biometric and Precise Geolocation Data

    The Report asks the Legislature to adopt additional laws, protecting biometric identifiers and precise geolocation data.

    Biometric data use is on the rise among Americans, and businesses that collect, use, or retain biometric identifiers or precise geolocation data should closely monitor legislative developments, as these categories of information remain a priority for state-level privacy regulators nationwide.
  4. Data Broker Registration, Safeguards, and Consumer Deletion and Opt-Out Requests

    The Report recommends that the Legislature require data brokers to register annually with the state and disclose, in a publicly accessible database, the types of consumer information they collect or sell.

    Washington State’s proposed data broker registry bill, HB 2483, defines a “data broker” is a business that collects, sells, or licenses brokered personal data to another person. Businesses that fall within this definition should begin evaluating whether their existing compliance programs could survive a paradigm like California’s DROP, requiring registration, consumer deletion requests, and opt-out obligations.

Enforcement Approaches. The Report bases its enforcement approach around two core proposals: 1) ensuring privacy laws have clear, practical, and accountable enforcement mechanisms, and 2) ensuring state agencies can adopt privacy principles and have enough capacity.

  1. Clear, Practical, and Accountable Enforcement Mechanisms

    The Report would like any privacy laws adopted by the Legislature to be clear, practical, and accountable.

    For businesses, enforcement is where the practical risk lies. Even businesses with robust, compliant mechanisms may face investigations and enforcement actions. Establishing clear and consistent compliance and audit procedures is key, but so is understanding that isolated violations may arise and being prepared to deal with related enforcement actions.
  2. Supporting Agencies’ Enforcement Adoption and Capacity

    The Report also recommends providing state agencies, such as the Washington Office of Privacy and Data Protection and Washington Technology Solutions, with additional resources, personnel, and inter-agency coordination systems to support privacy enforcement and oversight efforts.

    For businesses, the broader takeaway is that Washington appears poised to invest heavily in privacy oversight and enforcement capacity. As a result, businesses need to be ready for inspection and scrutiny at every turn, and the larger the business, the more scrutiny it can expect.

Educational Approaches. The Report also requests that the Legislature allocate funding for programming intended to “raise the baseline of digital literacy in Washington,” in two ways: 1) free and accessible resources explaining data privacy to Washingtonians, and 2) public-private partnerships that develop educational resources to support small business compliance.

  1. Free and Accessible Data-Privacy Resources for Washingtonians

    The Report requests that the AG’s Tech Policy Team work with consumer advocates to create educational materials written in plain language to explain the Report’s data-privacy concerns.

    For businesses, this can represent an opportunity. While these proposals are concerning from a business perspective, these initiatives may create opportunities to participate in consumer-privacy education efforts and shape public understanding of responsible data practices.
  2. Public-Private Partnerships to Help Small Business Compliance

    The Report recognizes that small businesses may lack the time, staff, and resources to become completely compliant, and so it suggests creating a pathway to help small businesses build systems that allow them to become compliant and “lower the barriers to responsible data management.” The only solution the Report suggests is the AG’s Tech Policy Team partnering with business associations to create “effective and practical resources.”

    Although many of the Report’s proposals appear aimed at large data aggregators and brokers, small businesses should not assume they will escape scrutiny. Small businesses should monitor developments and evaluate their compliance programs before new requirements take effect.

Conclusion

The Report provides the clearest indication yet of the AG’s priorities and the direction state policymakers may take in future privacy legislation. While many of the Report’s recommendations remain proposals, businesses should view them as an early harbinger of potential compliance obligations to come. Companies that collect, use, or monetize consumer data should monitor legislative developments closely and evaluate whether their existing privacy practices would withstand the AG’s proposed privacy paradigm.

Related Capabilities

Related People

Stay up to date

Subscribe

Attorney Advertising ©2026 Vedder

cping