ImportantSecurity & Privacy
Gartner: US states issued $3.45B in privacy-related fines to companies in 2025, a total larger than the last five years combined, driven by new privacy laws (Derek B. Johnson/CyberScoop)
US states issued $3.45 billion in privacy-related fines to companies in 2025—exceeding the previous five years combined—signaling a dramatic shift in regulatory enforcement driven by new state privacy laws. This represents a critical business risk and compliance challenge that requires IT organizations to prioritize data governance, privacy-by-design architecture, and cross-functional regulatory monitoring to avoid escalating financial and reputational penalties. Technology leaders must immediately reassess their data handling practices and privacy compliance posture, as the regulatory environment has fundamentally changed and non-compliance costs are now exponentially higher.

Derek B. Johnson / CyberScoop: Gartner: US states issued $3.45B in privacy-related fines to companies in 2025, a total larger than the last five years combined, driven by new privacy laws — The increase is being driven by powerful privacy laws in states like California, new interstate partnerships and a renewed focus on the privacy impacts of AI and automation.