Truyo recognized in Gartner® Magic Quadrant™ for AI Governance Platforms | Download Report
Dormant Laws Privacy Lawsuits
Privacy Enforcement, U.S. Laws & Regulations

Forget-me-not: How Dormant Laws Are Becoming Plaintiff-Friendly For Drive-by Privacy Lawsuits

Privacy litigation is moving beyond the headline-grabbing laws like CCPA. The recent lawsuit against Home Depot taps into the Virginia Personal Information Privacy Act (VPIPA). The decades-old law had, until recently, seen almost no litigation. The plaintiffs in drive-by privacy lawsuits are now dusting off older, less-tested statutes for their low pleading threshold and potential for significant recoveries. Business now needs to be more aware of dormant laws that include a private right of action, statutory damages, or relatively favorable pleading standards.

Organizations that have invested heavily in complying with modern privacy laws should not brush off older or narrowly focused statutes (like VPIPA, Florida’s Digital Bill of Rights, or other similar regulations) as harmless relics. Let’s take a deeper look at the underlying trend.

Anatomy of an Attractive Privacy Claim

The real question we should be asking in the Home Depot lawsuit is why the plaintiff chose a decades-old statute that had seen almost no litigation. The answer is likely to shed light on an attractive path to privacy class action claims.

  • Less-Tested Laws: A statute with little litigation history has fewer judicial decisions defining its limits, available defenses, or application to modern technologies. That allows plaintiffs to advance broader or more creative interpretations without immediately confronting settled precedent. Businesses also have less certainty about whether a court will dismiss the claim, making early settlement more appealing.
  • Lower Pleading Threshold: The first objective isn’t necessarily to win the case but to survive dismissal. If a complaint only needs plausible allegations to proceed, plaintiffs gain access to discovery, where internal emails, contracts, and data-sharing agreements can become powerful bargaining tools. That alone can increase settlement pressure.
  • A Private Right of Action: A PRA removes the regulator from the equation. Instead of waiting for an enforcement action, plaintiffs’ firms can identify an alleged violation, recruit affected consumers, and initiate litigation on their own timeline. Therefore, dormant statutes with a private right of action are far easier to turn into active class actions.
  • Statutory Damages: When a statute assigns a fixed dollar amount to every violation, thousands of transactions can be aggregated into a claim worth millions. The economics improve dramatically without having to prove that every consumer suffered measurable financial harm.
  • Fee-Shifting: Recoverable attorneys’ fees significantly change the risk-reward calculation. Even if the statutory damages are modest, the prospect of recovering legal fees makes these cases more commercially attractive to pursue and gives plaintiffs additional leverage during settlement discussions.

Preparing for Your Blind Spots

The Virginia case is unlikely to be the last of its kind. Nearly every state has older, narrowly focused statutes that have received little attention in the era of comprehensive privacy laws. As established claims become more difficult to pursue, plaintiffs’ firms naturally look for fresh legal theories with favorable economics. Here’s how businesses should prepare:

  • Beyond the popular laws: CCPA, CPRA, and similar laws deserve attention, but they shouldn’t become blinders. Older state statutes may impose unique obligations that aren’t covered by a one-size-fits-all privacy program. If you operate across multiple states, don’t assume every jurisdiction follows the same privacy framework. Some older statutes still create meaningful legal exposure, even if they rarely make the news.
  • Know your data ecosystem: Build and maintain an inventory of every system that collects, stores, shares, or monetizes personal information, including point-of-sale systems, loyalty programs, retail media networks, analytics platforms, advertising partners, data brokers, and other third parties. You cannot assess your legal exposure under state privacy laws if you don’t know what data is being collected, where it is going, and who has access to it.
  • Validate notices against real-world practices: Older privacy statutes often focus on deceptively simple obligations like providing notice or honoring a consumer’s choice. Don’t assume your existing privacy notice or cookie banner satisfies every state law. Review whether customers are receiving the disclosures required where data is collected and confirm those disclosures accurately reflect how information is actually used and shared.
  • Follow your data continuously. Data-sharing relationships rarely stay static. Marketing campaigns change, vendors are added, retail media programs expand, and business teams adopt new technologies. Regularly review who receives customer information, why it is shared, and whether those practices remain consistent with your legal obligations. Continuous visibility is far more effective than discovering an issue after a lawsuit has already been filed.

Old Laws. New Lawsuits.

As comprehensive privacy laws mature and businesses become better prepared for them, plaintiffs’ firms will continue searching for overlooked statutes that offer favorable litigation economics. Today’s dormant law can quickly become tomorrow’s class action trend. For businesses, the takeaway is to measure privacy risk by what the law allows a plaintiff to do. A statute with a private right of action, statutory damages, fee-shifting provisions, and limited judicial precedent deserves attention, regardless of its age.

Truyo Compliance Advisor and Truyo Privacy help businesses to be prepared at scale for surprises like dormant laws by offering comprehensive features for data privacy compliance. Employing them with Truyo Warranty Certification Program will help businesses build a strong line of defense against drive-by privacy lawsuits.


Author

Dan Clarke
Dan Clarke
President, Truyo
August 6, 2026

Let Truyo Be Your Guide Towards Safer AI Adoption

Connect with us today