Delawareâs privacy law just got a significant shake-up. Recent amendments to the law amount to more than a coat of paint, but less than a total overhaul.
The applicability threshold drops to businesses handling data on just 10,000 Delaware residents, which is under 1% of the state's population. The law also features new data minimization requirements, narrower exemptions, changes to how sensitive data is handled, and, notably, new contractual requirements between businesses and third parties receiving consumer data.
This is a little different than state privacy lawsâ contract requirements between a controller and a processorâi.e., the vendor doing work on your behalf, like a payroll company or an email platform. Third parties arenât processors. Think a data broker buying a list outright, or an ad network you pay to run campaigns. Only California's CCPA regulations required that kind of contract before now.
The amendments broadly track how California treats third parties, with one significant addition: a first of its kind due diligence obligation. Companies subject to Delawareâs privacy law need to âat a minimum, [assess] the third party through the use of questionnaires and review of relevant documents of the third party,â and âadditional reasonable measures must be undertaken in a manner that is commensurate with the sensitivity of the data disclosed by the controller to the processor or third party.â
If youâre subject to Delawareâs privacy law, the first step is to determine whether you send consumer data to third parties. If so, then take a close look at your contracts and vendor assessment practicesâDelaware law just got a little toothier.
Best,
Arlo
New From Osano
Release Notes: September
Whatâs new in Osano this month? Check out our release notes to find out the latest.
In Case You Missed ItâŚ
Engineering Blog: Show, Don't Tell: How We Ship Internal Ideas at Osano
In the first of our new engineering blog series, we cover the new internal platform we built to make sharing AI-assisted tools, prototypes, and proofs of concept easierâespecially for non-engineers. Meet Archie.
Top Privacy Stories of the Week
Delaware Significantly Amends Consumer Data Privacy Law
Delaware just rewrote its two-year-old privacy law to catch up with amendments other states have passed since 2023. HB 380 drops the applicability threshold to 10,000 consumers, expands the definition of sensitive data to include neural data and government IDs, and adds a contract requirement for third parties, a category the bill defines to exclude processors. The changes take effect January 1, 2027.
Grindr Settles HIV Status Data-Sharing Lawsuit for $35 Million
Grindr has agreed to pay roughly $35 million to settle a UK lawsuit brought by about 12,000 users who allege the app shared their HIV status, PrEP use, and ethnicity with advertisers without consent. The sharing allegedly happened before 2020, when Grindr was owned by Chinese gaming company Kunlun, and echoes a similar finding by Norway's data protection authority in 2021. Grindr disputes the allegations but acknowledged in an SEC filing the "distress and loss of trust" the practices caused among UK users. The company will pay two installments of roughly $17.5 million each, the first due by the end of this year.
Class Action Accuses Flock Safety of Enabling Police Stalking
A new federal class action accuses Flock Safety of enabling its own law enforcement customers to misuse its license-plate camera network for personal surveillance. The suit, filed in Georgia, cites a Washington Post investigation that found at least 50 officers nationwide charged with or accused of misusing automated license-plate readers, with Flock's system implicated in 46 of those cases, more than half involving officers tracking wives, girlfriends, or ex-partners.
Your Phone or Computer May Soon Ask How Old You Are
Starting January 1, 2027, Windows, macOS, iOS, and Android will all have to ask how old you are. California's Digital Age Assurance Act, signed last October, sorts users into four brackets (under 13, 13-15, 16-17, and 18+) and lets operating systems pass a non-identifying age signal to app developers. The Electronic Frontier Foundation has criticized the approach as "outsourcing censorship to developers," and smaller or volunteer-run operating systems like many Linux distributions may struggle to build the feature at all.
CalPrivacy Warns Data Brokers Over Registration Accuracy
CalPrivacy has a new warning for data brokers who already registered under the Delete Act: sloppy paperwork still costs money. The agency's Enforcement Advisory 2026-01 spells out that brokers who submit inaccurate registration information are liable for $200 for every day the error goes uncorrected. It follows a string of fines this year against brokers that missed the registration deadline outright, showing the agency's enforcement reach extends beyond brokers who ignored the rules to those who just got the details wrong.
Like What You See in the Privacy Insider newsletter?
There's more to explore:
đ ď¸ The Osano Engineering Blog
Learn what we're building, why, and how! New posts released monthly here.
đą The Osano Subreddit
Join our official subreddit to stay up to date on the latest news, analysis, guidance, and content from Osano!
đ The Privacy Insider: How to Embrace Data Privacy and Join the Next Wave of Trusted Brands
The book inspired by this newsletter: Osano CEO, Arlo Gilbert, covers the history of data privacy and how companies can start building a privacy program from the ground up. More details here.
If youâre interested in working at Osano, check out our Careers page!
Arlo Gilbert
Arlo Gilbert
Arlo Gilbert is the CIO & co-founder of Osano. A native of Austin, Texas, he has been building software companies for more than 25 years in categories including telecom, payments, procurement, and compliance. In 2005 Arlo invented voice commerce, he has testified before congress on technology issues, and is a frequent speaker on data privacy rights.
