In this article

Sign up for our newsletter

Share this article

Delaware’s privacy law just got a significant shake-up. Recent amendments to the law amount to more than a coat of paint, but less than a total overhaul.

The applicability threshold drops to businesses handling data on just 10,000 Delaware residents, which is under 1% of the state's population. The law also features new data minimization requirements, narrower exemptions, changes to how sensitive data is handled, and, notably, new contractual requirements between businesses and third parties receiving consumer data.

This is a little different than state privacy laws’ contract requirements between a controller and a processor–i.e., the vendor doing work on your behalf, like a payroll company or an email platform. Third parties aren’t processors. Think a data broker buying a list outright, or an ad network you pay to run campaigns. Only California's CCPA regulations required that kind of contract before now.

The amendments broadly track how California treats third parties, with one significant addition: a first of its kind due diligence obligation. Companies subject to Delaware’s privacy law need to “at a minimum, [assess] the third party through the use of questionnaires and review of relevant documents of the third party,” and “additional reasonable measures must be undertaken in a manner that is commensurate with the sensitivity of the data disclosed by the controller to the processor or third party.”

If you’re subject to Delaware’s privacy law, the first step is to determine whether you send consumer data to third parties. If so, then take a close look at your contracts and vendor assessment practices–Delaware law just got a little toothier.

Best,
Arlo

Resource Listing - State of US Privacy Enforcement

Highlights From Osano

New From Osano

Release Notes: September

What’s new in Osano this month? Check out our release notes to find out the latest.

Read more

In Case You Missed It…

Engineering Blog: Show, Don't Tell: How We Ship Internal Ideas at Osano

In the first of our new engineering blog series, we cover the new internal platform we built to make sharing AI-assisted tools, prototypes, and proofs of concept easier—especially for non-engineers. Meet Archie.

Read more



Top Privacy Stories of the Week

Delaware Significantly Amends Consumer Data Privacy Law

Delaware just rewrote its two-year-old privacy law to catch up with amendments other states have passed since 2023. HB 380 drops the applicability threshold to 10,000 consumers, expands the definition of sensitive data to include neural data and government IDs, and adds a contract requirement for third parties, a category the bill defines to exclude processors. The changes take effect January 1, 2027.

Read more

Grindr Settles HIV Status Data-Sharing Lawsuit for $35 Million

Grindr has agreed to pay roughly $35 million to settle a UK lawsuit brought by about 12,000 users who allege the app shared their HIV status, PrEP use, and ethnicity with advertisers without consent. The sharing allegedly happened before 2020, when Grindr was owned by Chinese gaming company Kunlun, and echoes a similar finding by Norway's data protection authority in 2021. Grindr disputes the allegations but acknowledged in an SEC filing the "distress and loss of trust" the practices caused among UK users. The company will pay two installments of roughly $17.5 million each, the first due by the end of this year.

Read more

Class Action Accuses Flock Safety of Enabling Police Stalking

A new federal class action accuses Flock Safety of enabling its own law enforcement customers to misuse its license-plate camera network for personal surveillance. The suit, filed in Georgia, cites a Washington Post investigation that found at least 50 officers nationwide charged with or accused of misusing automated license-plate readers, with Flock's system implicated in 46 of those cases, more than half involving officers tracking wives, girlfriends, or ex-partners.

Read more

Your Phone or Computer May Soon Ask How Old You Are

Starting January 1, 2027, Windows, macOS, iOS, and Android will all have to ask how old you are. California's Digital Age Assurance Act, signed last October, sorts users into four brackets (under 13, 13-15, 16-17, and 18+) and lets operating systems pass a non-identifying age signal to app developers. The Electronic Frontier Foundation has criticized the approach as "outsourcing censorship to developers," and smaller or volunteer-run operating systems like many Linux distributions may struggle to build the feature at all.

Read more

CalPrivacy Warns Data Brokers Over Registration Accuracy

CalPrivacy has a new warning for data brokers who already registered under the Delete Act: sloppy paperwork still costs money. The agency's Enforcement Advisory 2026-01 spells out that brokers who submit inaccurate registration information are liable for $200 for every day the error goes uncorrected. It follows a string of fines this year against brokers that missed the registration deadline outright, showing the agency's enforcement reach extends beyond brokers who ignored the rules to those who just got the details wrong.

Read more

Like What You See in the Privacy Insider newsletter?

There's more to explore:

🛠️ The Osano Engineering Blog

Learn what we're building, why, and how! New posts released monthly here.

📱 The Osano Subreddit

Join our official subreddit to stay up to date on the latest news, analysis, guidance, and content from Osano!

📖 The Privacy Insider: How to Embrace Data Privacy and Join the Next Wave of Trusted Brands

The book inspired by this newsletter: Osano CEO, Arlo Gilbert, covers the history of data privacy and how companies can start building a privacy program from the ground up. More details here.

If you’re interested in working at Osano, check out our Careers page! 

Get a demo of Osano today
Share this article