In August 2026, Washington’s Attorney General’s Office published its first-ever Data Privacy Report. The document looks at how companies collect and reuse personal data, what residents say they want, and where state law still has holes.
You do not need a law degree to get the main message. People want a real say before someone collects, shares, or sells their information. Clicking “I agree” on a wall of legal text does not count.
If you run a Shopify store in the USA, this report is a useful checklist for how you ask for consent on your site, even if you never sell to Washington state alone.
Key Takeaways
- On August 14, 2026, Washington Attorney General Nick Brown released the state’s first Data Privacy Report.
- The report’s #1 policy ask is simple: meaningful, informed consent, and a ban on deceptive design that pushes people to say “yes.”
- A 2025 AGO survey found 95% of respondents would never be comfortable sharing personal data without informed consent, yet many still feel they have little control.
- For online stores, that means clear banners, balanced choices, plain language, and easy ways to change your mind, the same bar Consentmo is built to support on Shopify.
What the report is really about
The Attorney General’s office points to four problems that show up again and again in the data economy:
- Overcollection and secondary use – gathering more data than you need for the purchase or account, then using it for something else (for example, sharing a signup email with a marketing partner for ads).
- Weak consent and deceptive design – confusing notices, buried terms, and interfaces that steer people toward “accept all.”
- Sensitive data – biometrics and precise location that can follow someone for years if they leak.
- Data brokers – companies that buy and sell personal data with little visibility for the people in those files.
Those practices do not stay abstract. In 2025, the office received notices for 209 breaches affecting more than 8 million Washingtonians. Over 80% of those breaches exposed Social Security numbers. More data sitting in more systems means more damage when something goes wrong.
The report also stresses that residents want control. In the 2025 AGO Data Privacy Survey (700+ responses across 26 counties):
- 83% said they had little or no control over who can access their personal information.
- 95% said there is no situation where they would be comfortable providing personal information without informed consent.
- Only 47% said they had ever given informed consent as the office defines it; another 25% were unsure.
- 62% found it hard or very hard to opt out of targeted ads.
- 65% found it hard or very hard to ask an app or service to delete their data.

Trust is low too. Many respondents trusted none of the listed institutions to keep their data private and secure.
That is the backdrop for recommendation #1: fix consent.
What “informed consent” means
The report is clear: consent is not “they clicked a button” or “they opened the privacy policy.”
Informed consent needs:
- Clear information about what you collect and why
- Plain language people can actually understand
- A voluntary choice (no pressure or tricks)
- A real chance to say no
Here is a good example of a correctly set banner from a US brand using Consentmo, Vera Wang online store:

Deceptive design works against that standard. Common examples the report calls out:
- Making Accept all big and bright while Reject is hard to find or needs extra clicks
- Bundling unrelated uses into one “agree”
- Misleading button labels
- Making it harder to reverse a privacy choice than it was to accept tracking
Other states already push toward fairer choices. California expects privacy-friendly options to be as easy as less protective ones. Connecticut and Oregon expect withdrawing consent to be at least as easy as giving it. Colorado requires recognition of qualifying universal opt-out signals. Washington’s AG wants the Legislature to move in the same direction: clear consent, easy decline, and an explicit ban on deceptive design.
Why this matters for Shopify merchants
When your store loads marketing pixels, analytics, or personalization scripts before someone chooses, you risk:
- Losing trust from people who already feel they have no control
- Collecting more than you need for the order
- Making opt-out and deletion feel like a maze (exactly what the survey said is hard today)
Consent done well is also good store ops:
- Shoppers see what cookies and trackers do before they run
- You keep a record of what they chose
- You can honor “change my mind” without a support ticket marathon
- You reduce the pile of data that would hurt you in a breach
That is where Consentmo fits. It helps Shopify merchants show clear cookie banners, block non-essential scripts until the shopper chooses, support region-aware rules (including U.S. states), and give people a path to manage privacy requests, so consent stays a real choice, not a dark pattern.
Practical consent checklist (aligned with the report)
Use this as a store-level version of the AG’s top recommendation:
If you sell across the U.S. and EU/UK, one static banner is rarely enough. Rules and shopper expectations differ by region. Consentmo’s geotargeting and banner layouts help you match the message to the visitor without building a custom legal stack yourself.
What else the report asks for
Consent is the headline, but the full package matters for long-term planning:
- Data minimization – only collect, use, and keep what you need for the product or service the person asked for; limit secondary use.
- Stronger rules for biometrics and precise location – clear consent first; tight limits on sale and retention.
- Data broker registration – public registry, security duties, deletion and opt-out, ideally one place to send requests. 5-6. Stronger enforcement and agency capacity so rights are not paper-only. 7-8. Education for residents and small businesses so privacy is easier to understand and implement.
Washington already has targeted laws (breach notice, student data, biometrics, My Health My Data, and more). The AG’s point is that those pieces do not yet form one clear baseline for consent, minimization, and secondary use across the board. Stores that already run fair consent and lean data practices will be better prepared if a broader state framework arrives.
How Consentmo helps you act on the “consent first” message
You do not need to wait for a new Washington statute to raise the bar:
- Cookie consent banners that can present balanced choices instead of “accept or struggle”
- Script and tracker control so marketing tools respect the shopper’s decision
- Region-aware setup for U.S. states and international rules
- Privacy Center / request flows so deletion and preference changes are not buried
- Consent records and scans so your cookie story stays honest as your stack changes
Install or review your setup on the Shopify App Store: Consentmo – GDPR/CCPA Cookie Banner.
Bottom line for store owners
Washington’s first Data Privacy Report puts a simple idea in the center of policy: people should understand the ask, and they should be free to say no.
Survey numbers back that up. Almost everyone wants informed consent. Far fewer feel they have ever given it. Many struggle to opt out or delete.
For merchants, the response is practical. Make the choice obvious. Skip the tricks. Collect less. Make “stop tracking me” as easy as “okay.” Tools like Consentmo exist so that standard is normal on Shopify, not a special project.
If you want to go deeper on related store setup, see our guides on configuring cookie consent by U.S. state and what a cookie policy should cover.
This article summarizes themes from the Washington State Attorney General’s Data Privacy Report (2026) for educational purposes. It is not legal advice. Check the official AGO materials and your counsel for obligations that apply to your business.



