Enforcement Outlook | Consumer Protection Trends, Priorities, and Compliance Risks | McDermott

VIRTUAL

Key Takeaways | Enforcement Outlook | Consumer Protection Trends, Priorities, and Compliance Risks

July 22, 2026

Event details

July 22, 2026

1:00 pm (ET)

Webinar

This event is in the past. See recordings and other materials from this event below.

Consumer protection enforcement remains a significant risk for businesses in 2026, but the enforcement landscape has shifted considerably. While federal regulators have refocused their attention, including on traditional fraud, deceptive marketing, pricing transparency, subscription programs, and other forms of measurable consumer harm, companies must also contend with growing scrutiny from state Attorneys General (AG) and an increasingly active plaintiffs’ bar. As enforcement priorities continue to evolve, awareness of trends and developments are critical for organizations to reassess their compliance strategies and address emerging risks across advertising, privacy, artificial intelligence, consumer finance, and e-commerce.

Members of McDermott Will & Schulte’s cross-practice team discussed how consumer protection enforcement has evolved, and will evolve, during the Trump administration and where businesses face the greatest exposure.

Key takeaways included:

Consumer protection enforcement has shifted, not disappeared

Under current leadership, the Federal Trade Commission (FTC) continues to pursue traditional consumer protection cases involving identifiable deception, fraud, and consumer injury. Rather than developing expansive theories of unfairness, the FTC is increasingly applying longstanding deception principles across industries. Priority areas include pricing transparency, algorithmic pricing, subscriptions and negative options, marketing practices, children’s privacy, artificial intelligence (AI) deceptive marketing, and misleading health claims.

The Consumer Financial Protection Bureau is operating amid leadership, staffing, and funding uncertainty that have curtailed its enforcement and supervisory activity. However, the agency has not abandoned its statutory mandate, and continues to address traditional fraud, scams targeting vulnerable populations, and cases involving tangible, measurable consumer harm.

Businesses should not interpret reduced federal activity as permission to relax existing compliance programs. The underlying statutes remain enforceable, and conduct occurring during a period of reduced scrutiny may still be examined by future agency leadership, state regulators, or private plaintiffs.

State AGs are setting the bar

State AGs are using traditional Unfair or Deceptive Acts or Practice statutes, existing and new state privacy laws, industry-specific requirements and, in some cases, federal consumer financial protection authority to investigate conduct across industries. For example, California is increasingly acting as a national enforcement leader, with the AG expanding activity across consumer protection, privacy, and antitrust while federal enforcement recedes.

Coordination among states is also becoming more institutionalized. Multistate coalitions, information-sharing agreements, and specialized regulatory groups allow an investigation initiated by one office to expand rapidly. Companies should respond to every regulator inquiry with a potential multistate audience in mind.

For national businesses, the practical standard may be established by the strictest state requirement or by the injunctive provisions of a major multistate settlement, not by the federal minimum. A single point of contact, a unified response protocol, and a consistent factual narrative are critical.

Pricing, subscriptions, and dark patterns are enforcement magnets

Pricing transparency remains a bipartisan, cross-industry priority. Regulators are challenging drip pricing, hidden mandatory charges, misleading advertised prices, and fees described as taxes or regulatory pass-throughs when they are actually used for cost recovery or profit.

Subscription practices present similar challenges. Companies should ensure recurring obligations are clearly disclosed, consent is properly obtained, and cancellation is just as easy as enrollment.

Dark patterns are also being challenged under both consumer protection and privacy law. Companies should review consent, opt-out, and cancellation flows for equal prominence, comparable steps, and unnecessary friction.

Privacy and AI claims are being treated as consumer protection issues

Privacy enforcement has not slowed. Regulators are focused on whether companies’ actual practices match their public representations.

Privacy policies, cookie banners, settings, and statements such as, “we do not sell your data,” are increasingly treated as advertising claims.

Common enforcement themes include:

  • Misleading or outdated privacy representations
  • Failure to honor access, deletion, and opt-out requests
  • Tracking technologies and vendor data sharing
  • Excessive data collection and retention
  • Sensitive data, including geolocation, biometrics, and minors’ data
  • Data-broker registration and deletion obligations

Companies should test whether consumer choices work throughout the full technology stack, not merely whether a link or webform exists.

Children’s privacy and age assurance are becoming central priorities

Children’s privacy is one of the areas where enforcement activity remains particularly strong. Federal Children’s Online Privacy Protection Act requirements now operate alongside a growing number of state laws addressing teen data, age assurance, parental consent, addictive design, targeted advertising, and AI products accessible to minors.

The compliance discussion is shifting from whether companies may verify age to whether they have implemented a reasonable age-assurance approach. At the same time, age-verification tools must be designed carefully so that the verification process does not create new privacy risks.

Businesses offering services that are directed to, or foreseeably used by, children and teenagers should evaluate:

  • Whether age-assurance tools are reasonably accurate
  • Whether data collected for age verification is minimized and promptly deleted
  • Whether parental consent mechanisms operate as represented
  • Whether youth accounts use protective default settings
  • Whether recommendation systems, notifications and engagement features create foreseeable risks for minors

Private lawsuits may be the bigger risk

Consumer class action activity continues to rise even as some federal agencies narrow their enforcement posture. Plaintiffs are pursuing claims under the Telephone Consumer Protection Act, Fair Credit Reporting Act, Fair Debt Collection Practices Act, and state wiretapping and consumer protection statutes.

Plaintiffs’ firms are using regulatory guidance and enforcement actions as litigation roadmaps, particularly in matters involving privacy disclosures, tracking technologies, subscription practices, pricing transparency, dark patterns, and AI marketing.

Companies should expect plaintiffs to seek the same internal materials regulators request, including product testing, substantiation records, consumer disclosures, pricing data, cancellation metrics, vendor oversight, and remediation records.

Bottom line: Prove it works.

The most successful compliance programs will focus on demonstrable consumer harm, clear disclosures, and operational accountability. Companies should be able to answer:

  • How prices and mandatory fees are presented
  • How marketing and AI claims are reviewed and substantiated
  • How consumers provide and withdraw consent
  • How subscriptions are enrolled, renewed, and cancelled
  • How privacy choices are transmitted across the technology stack
  • How vendors and embedded technologies are monitored
  • How complaints are escalated and remediated
  • How compliance decisions, testing, and corrective actions are recorded

This documentation is particularly important in multistate matters. Companies should develop a consistent, practice-based narrative explaining how the relevant system operates, how it was tested, and what remediation occurred. Inconsistent explanations across jurisdictions can turn a manageable inquiry into a broader credibility problem.

To view the webinar presentation materials, click here.


McDermott Will & Schulte’s Enforcement Outlook webinar series is designed to keep you up to date on the enforcement trends that might impact your organization’s compliance strategy. For more materials related to past episodes, visit our Enforcement Outlook Series hub.

Speakers