For almost 250 years, our federal system has allowed each state to “serve as a laboratory; and try novel social and economic experiments without risk to the rest of the country.” Nowhere have states more clearly operated in this role in recent years than in the area of protecting the privacy of consumers’ data. Forty-seven states and the District of Columbia have their own data breach notification laws. While these laws have similarities, together they require companies that have experienced a data breach to comply with multiple different, and sometimes contradictory, standards, if those companies do business across state lines. This article provides an overview of the current State Attorneys General privacy enforcement landscape.