PRIVACY & DATA SECURITY
Delaware Lowers Privacy Law Threshold and Raises the Bar for Vendor Oversight
Delaware has widened the reach of its privacy law and added new duties for businesses already covered by it. Governor Matt Meyer signed House Bill 380 on September 2, 2026, amending the Delaware Personal Data Privacy Act (DPDPA) effective January 1, 2027. The law now applies to businesses that control or process the personal data of 10,000 or more consumers, down from 35,000, or 5,000 or more consumers if at least 20% of gross revenue comes from selling personal data, down from 10,000.
Sensitive data gets stricter treatment. Even with consent, a controller may process it only when reasonably necessary and proportionate to the purpose disclosed at collection, and may sell it only when strictly necessary to provide the product or service the consumer requested. That “strictly necessary” standard goes beyond the consent model in states with similar restrictions on disclosure of sensitive data such as Colorado, Connecticut, and Virginia.
The amendments also regulate vendor relationships. Controllers must conduct reasonable due diligence on processors and third parties, using questionnaires at a minimum, and those vendors must cooperate. Sales of personal data require a contract with privacy-protective terms, and Delaware bars third parties from processing without one, where California places that duty on businesses. Consumers can also request a list of third parties that received their data, with an exception for pseudonymized data.
BUSINESSES NEED TO KNOW: With the effective date a little over three months away, this is the time to scope the work and assign owners.
- Re-run your applicability analysis. Count Delaware consumers against the new thresholds, including data you process for others. An earlier “not covered” conclusion may no longer hold.
- Test sensitive data uses against your disclosed purpose. Consent alone no longer settles the question. Any sale of sensitive data needs a justification tied to the service the consumer asked for, which will be hard to make for many advertising and data-sharing arrangements.
- Build a documented, risk-tiered vendor diligence program. Contractual promises of compliance alone won’t meet this standard, so verify responses for higher-risk partners and keep the records. If you are the vendor, treat incoming diligence requests as a legal obligation.
- Check your contracts on both sides of the data. CCPA contract workflows can be extended to Delaware, but because third parties are now barred from processing without a contract, confirm your own position as well as your partners’.
- Update consumer request procedures. Prepare for third-party list requests and decide how the pseudonymized data exception applies to your data flows.
Astrana Health’s Social Engineering Attack Puts Human Layer of Data Security Back in Focus
Astrana Health disclosed in an SEC Form 8-K filing that a subsidiary was hit by a series of social engineering attacks. The attackers posed as company personnel and spoofed the corporate main phone number when contacting employees, apparently to talk their way into internal systems. The company says its cybersecurity team detected unusual activity and responded, and that information on its servers was likely accessed or acquired without authorization. It is still investigating whether patient, employee, credentialed provider, financial, or proprietary business information was taken.
Its response included resetting affected credentials, restricting remote access tools, restoring some systems from clean backups, and expanding monitoring and logging. It has also retained outside forensic specialists, notified law enforcement, and begun evaluating its notification obligations. The filing notes that its cyber insurance may not cover all losses. The facts so far suggest the attackers relied on persuasion rather than a technical exploit, which is a useful reminder that a well-defended network can still be opened from the inside by a convincing voice on the phone.
BUSINESSES NEED TO KNOW: The best security stack in the world can’t stop an employee who hands over access voluntarily. The attackers here didn’t break in. They persuaded someone, and a familiar phone number was enough to make the call believable. Caller ID is not proof of identity, and employees at every level should hear that plainly.
Generic annual training on email phishing won’t prepare staff for a live call from someone who sounds like a colleague or help desk technician, and generative AI is making those impersonations easier to produce and harder to spot. Train on the scenarios your people will actually face, such as requests for password resets, remote access, or urgent “executive” demands, and test with realistic simulations. Pair training with process. Require a simple verification step, such as calling back on a number from the internal directory, and limit what any one employee can approve alone. Make reporting a suspicious call quick and blame-free, since early reports can keep an incident from becoming a material one. Document all of it, because regulators and plaintiffs will ask what you had in place before a breach.
Newsom Vetoes Sensitive Data Sales Ban but Signs Expanded CCPA Deletion Rights
California’s governor has taken opposite actions on two bills that would expand the CCPA, rejecting a ban on sensitive data sales while signing a broader right to delete. Governor Gavin Newsom vetoed Assembly Bill 1542, which would have generally barred businesses, service providers, and contractors from selling or sharing precise geolocation, biometric, health, and other sensitive personal information with third parties. He called a categorical ban “a step too far,” citing concern that removing consumers from the decision could have unintended consequences and that enforcement costs were not accounted for in the 2026 Budget Act. The veto leaves California on the CCPA’s existing opt-out and limit-use framework, even as Connecticut, Delaware, New Jersey, Virginia, Maryland, and Oregon have moved to restrict these sales, mostly for precise geolocation data.
Newsom did sign Senate Bill 923, the Expanding Privacy Rights Act, which takes effect January 1, 2027. The CCPA’s right to delete currently reaches only information a business collects directly from the consumer; SB 923 extends it to personal information a business obtained about the consumer from data brokers and other third parties in line with requirements in variety of other states. It also permits businesses to keep a suppression list so deleted data stays deleted, and it requires online-only businesses to offer a webform or similar online method for privacy requests rather than an email address alone.
Note that the governor also signed SB 690 (read more about that here), which limits private lawsuits under CIPA’s pen-register and trap-and-trace provision for website and app tracking
BUSINESSES NEED TO KNOW: The veto of AB 1542 is a reprieve, not a resolution. Businesses can keep selling sensitive data of California residents under the opt-out and limit-use framework, but the policy direction is clear: other states already restrict these sales, and consumer advocates intend to try again. Companies operating nationally should plan their compliance around these stricter states.
SB 923 requires concrete work before its January 1st effective date.
- Map third-party data. Deletion requests will reach data you bought or received from brokers and partners, so you need to know where it lives and be able to find it by consumer.
- Set up a suppression process. Without one, purchased data can reintroduce information a consumer already had deleted.
- Check your intake methods. Online-only businesses that accept requests by email alone will need a webform or similar option.
TCPA & TELESERVICES
FCC Finalizes New TCPA Revocation Rules
The FCC finalized its revised rules governing how consumers revoke consent under the TCPA, addressing practical questions that have complicated opt-out compliance for anyone who calls or texts consumers. The order makes three main changes.
- It narrows the effect of some revocations. A consumer who opts out of one category of informational messages, such as payment reminders, no longer automatically revokes consent for all informational messages from that caller. However, a revocation of prior express written consent for marketing or advertising messages still covers all marketing and advertising messages from the caller.
- Callers can designate one way to revoke consent. Callers may designate a single exclusive way to revoke prior express consent or prior express written consent for use of an automatic telephone dialing system or artificial or prerecorded voices from a list of Commission-provided options, such as an automated key-press option, a standard text keyword reply, or a dedicated website or phone number, provided it is clearly disclosed. Callers that don’t designate a method must honor revocation requests made in any reasonable way.
- Financial institutions gain flexibility for fraud and security alerts. These organizations may now source numbers from reliable sources beyond what the customer provided directly, including an authorized family member on the account.
The rules take effect 30 days after publication in the Federal Register, replacing the previously set January 31, 2027 compliance date, and the FCC will announce the exact date by public notice. The order also comes with a further notice seeking additional comment on several proposed refinements to the revocation process that remain under consideration.
BUSINESSES NEED TO KNOW: These rules change how consent revocation works in practice, and the compliance date is now tied to Federal Register publication, so the runway may be shorter than the previous January 2027 date suggested. Any business that calls or texts consumers, or relies on vendors that do, should expect to revisit its opt-out processes, disclosures, and systems.
The rules may not be settled yet, either. The companion further notice asks whether to shorten the time callers have to honor revocations, require two-way texting so consumers can opt out by replying, mandate a single opt-out method across all messages, and apply revocations across affiliates. Each would raise the operational stakes, and businesses can submit comments once the notice is published.
Read our blog post for more details on the order and the steps you should take now to get ready.
ADVERTISING & MARKETING
FTC Publishes Price Transparency FAQs for Auto Dealers
The FTC published a set of frequently asked questions on price transparency for the auto industry, restating a rule dealers have heard before: the advertised price of a vehicle must be the price any consumer can actually walk in and pay, leaving out only charges the government requires. The FAQs address what an advertised price should include, how to treat document fees, rebates, and discounts, how negotiations and optional items fit in, how to keep pricing consistent across media, and how to advertise vehicles that are still in transit. They also explain how dealers can assist the FTC’s enforcement efforts.
The guidance follows letters the Commission sent to 97 auto dealership groups earlier this year, warning that advertised prices must include all mandatory fees. Together, the letters and the FAQs make clear that the FTC sees auto pricing as a continuing enforcement priority and expects dealers to review their own advertising before the agency does it for them.
BUSINESSES NEED TO KNOW: If a fee is mandatory, it belongs in the number the consumer sees first, not in fine print or at the end of the transaction. Auto businesses should review their advertising against the new guidance, paying particular attention to document fees, conditional rebates, and in-transit inventory, and confirm that online, print, and in-store pricing all match.
For any business: although these FAQs are written for auto dealers, other industries that rely on add-on or “plus fee” pricing should pay attention and read this as another sign of FTC enforcement priorities.
Vivid Seats Defeats a Drip Pricing Suit, but Its Arbitration Clause Doesn’t Survive
A Maryland federal court has dismissed a proposed class action accusing Vivid Seats of drip pricing, though the ruling turned on the plaintiff’s pleading and not on the legality of the practice. The plaintiff alleged that tickets advertised at $225 each ended up costing $616.24 for two after mandatory fees, despite a 2024 Maryland law banning the practice. Judge Matthew Maddox held that she failed to state a Maryland Consumer Protection Act claim because the full price was disclosed at the final step and she chose to complete the purchase anyway. The court could not reasonably infer she would have declined to buy had the fees been shown upfront, and found no identifiable loss. The dismissal is without prejudice, and she has until October 16th to seek leave to amend or notify the court she does not intend to.
The court also rejected Vivid Seats’ effort to compel arbitration. Its terms of use let the company change them at any time, effective immediately and without notice to users, with opt-out available only after changes are posted. The court found that made the company’s promises illusory and the arbitration agreement unenforceable. It also declined the plaintiff’s request to certify a question of law to the Maryland Supreme Court.
BUSINESSES NEED TO KNOW: Don’t read this as a green light for drip pricing. The dismissal rested on what this plaintiff pleaded, it is without prejudice, and the Maryland law banning the practice remains in force. Regulators also don’t face the reliance and injury hurdles a private plaintiff does, which matters given the FTC’s continued focus on price transparency.
- Show the full price early. Disclosure at the last step may help in a private suit, but it won’t satisfy laws that require the total upfront.
- Audit your terms of use. A clause letting you change terms immediately and without notice can undermine an arbitration agreement. If you rely on arbitration, build in advance notice and a meaningful right to reject changes.
- Ask counsel about state exposure. Several states now ban or restrict drip pricing, and standards for private claims vary.
Learn how we can help keep you in compliance and ahead of the regulatory curve. Let’s Talk
Want to receive Regulatory Roundups right to your inbox? Subscribe.