Washington Attorney General Nick Brown released the state’s first Data Privacy Report last week, urging lawmakers to establish baseline privacy protections and warning that residents have little control over how their personal information is collected, retained, and sold.
The report identifies four recurring concerns in the data economy: overcollection and secondary use of personal information, weak consent requirements and deceptive design, the collection and sale of sensitive data, and limited consumer visibility into data-broker practices.
Brown’s office tied those practices to measurable harm. In 2025, the office received notices of 209 data breaches affecting more than 8 million Washington residents, the second consecutive year breach notices exceeded the state’s population. More than 80% of reported breaches exposed Social Security numbers. The report states that over 47 million breach notices have been sent to Washingtonians since 2017.
A 2025 survey drew more than 700 responses from residents in 26 of the state’s 39 counties. Eighty-three percent said they had little or no control over who could access their personal information, and 95% said no circumstance would make them comfortable having information collected, shared, or sold without informed consent. Only 47% said they had ever given informed consent, while 62% called it difficult to opt out of targeted advertising and 65% said the same about deleting their data from an app or service. Fifty-five percent selected “none of the above” when asked which institutions they trusted to keep their information private.
The report notes that Washington has not enacted a generally applicable consumer privacy law, unlike California, Colorado, Oregon, and Connecticut. Existing state protections are targeted, covering consumer health data, student records, biometric identifiers, data breaches, and automated license plate reader systems.
Brown recommended action across policy, enforcement, and education. On policy, the report urges lawmakers to require informed consent and prohibit deceptive design, mandate data minimization and limits on secondary use, strengthen protections for biometric and precise geolocation data, and require data brokers to register annually with the state. It cites California’s Delete Request and Opt-Out Platform as a model for a centralized deletion system covering registered brokers.
On enforcement, the report calls for mechanisms that are clear, practical, and accountable, and for additional privacy staffing at state agencies. On education, it recommends free public resources and partnerships with business associations to help small businesses meet privacy obligations.
.




