This is the regulatory companion to Why Web Tracking Survives and Web Tracking Techniques: A 2026 Field Guide.


The past 18 months produced more durable enforcement precedent than the previous five years combined. Three jurisdictions acted in ways that will shape compliance posture for the next decade: the UK ICO drew a hard line on fingerprinting, California AG Rob Bonta extracted the largest CCPA settlement in state history from Disney and Governor Newsom signed a browser-level opt-out mandate into law, and the EU's AI Act prohibitions took effect. California's CPPA finalized CPRA risk assessment regulations. The Ninth Circuit kept the CIPA session replay litigation wave alive despite a defense win in the district courts.

None of these actions occurred in isolation. Each builds on the others. The ICO's fingerprinting position and the Disney settlement share the same enforcement logic: if a business uses a technique to track users, it must honor opt-out signals at the same technical scope. CPRA risk assessments formalize that logic into a proactive obligation. The CIPA wave reflects a litigation theory that behavioral data capture is wiretapping - a theory courts have not fully resolved.

Privacy engineers and compliance officers face a changed surface in 2026. Automated compliance scans audit cookie declarations and consent banner presence. They do not audit server-side tracking payloads, consent signal propagation to server containers, or CNAME-cloaked endpoints. A site can pass every automated check while transmitting behavioral data to advertising platforms without consent. That gap is where enforcement is focused.

The five actions practitioners need to understand: the ICO's formal fingerprinting position, the CPRA risk assessment requirements, the Disney DTC settlement and its identity symmetry theory, the CIPA session replay litigation landscape, and the Opt Me Out Act. Together they define the compliance floor for web tracking operations in California-adjacent and EU-adjacent businesses.

What changed. The ICO established that fingerprinting is subject to the same PECR consent rules as cookies - there is no legal distinction based on whether a user can easily delete the identifier. The CPPA published mandatory risk assessment regulations covering a broad set of automated processing activities, effective January 1, 2026. The California AG established that opt-out obligations must match the scope of a company's identity resolution - a business that unifies identity for targeting must unify it for opt-out. California extended the Global Privacy Control mandate to browsers with the Opt Me Out Act. The EU AI Act's Article 5 prohibited practices took effect February 2, 2025.

What to do. Audit fingerprinting use for PECR and GDPR lawful basis. If your stack runs server-side tracking or CNAME-cloaked endpoints, ensure consent signals propagate to those layers. Inventory any automated processing that infers personal traits - CPRA risk assessments are mandatory if that processing presents significant risk. If your business uses cross-device identity resolution for targeting, your opt-out suppression must operate at the same scope. Activate session replay SDKs only after explicit consent. Implement GPC signal handling as a first-class opt-out across all properties and devices associated with an authenticated account.