Last Update: 09/29/2026 at 3:33 PM EST

Morning Briefing: Privacy

Tuesday, September 29, 2026

September 29, 2026

State Privacy Rules Advance While Surveillance Safeguards Lag

Yesterday’s reporting paired concrete state compliance movement with two unresolved debates over police surveillance. California’s broker-deletion system, enforcement action, and Delaware’s coming expansion of privacy duties point to requirements that organizations must build into routine operations.

By contrast, scrutiny of Flock’s vehicle-location network and San Francisco police drones remains centered on proposed limits and oversight. The divide is increasingly clear: some privacy obligations are becoming actionable, while safeguards for expanding public-surveillance tools remain unsettled.

State privacy governance gained practical weight. Privacy and Data Security Insights reported that Delaware HB 380 will broaden coverage and contract requirements from January 2027, while California’s CPPA ordered data broker LocateSmarter LLC to pay $116,490 and change its practices. California’s DROP system also requires registered brokers to keep processing centralized deletion requests, including for newly acquired covered data.

The Senate’s examination of Flock remains the leading U.S. surveillance development. Lawmakers focused on a network of more than 120,000 cameras, searchable vehicle-movement records, access controls, alleged misuse, and inaccurate matches. Warrants, shorter retention, audits, and independent testing were discussed, but no federal requirement resulted.

San Francisco’s police-drone expansion now presents a local governance test. The Electronic Frontier Foundation reported deployments rose from roughly 350 in 2024 to more than 3,500 in the first five months of 2026, while arguing that a policy pending before the Police Commission lacks clear limits on drone-as-first-responder use. The commission is scheduled to consider it October 14.

Key Points

  • State privacy policy is becoming less abstract for covered organizations. Broker deletion workflows, enforcement penalties, expanded statutory scope, and more specific contracting duties all require repeatable operational controls rather than one-time policy updates.
  • The surveillance debate is narrowing toward verifiable guardrails: who may search data, how long it is retained, what access is logged, how systems are tested, and whether deployment boundaries are enforceable. The questions are becoming more concrete even where the rules are not yet settled.

Implications

Organizations handling consumer or brokered data face a more varied state compliance environment. The immediate task is not uniform national compliance, but maintaining processes that can accommodate differing deletion, contracting, and scope requirements as they take effect.

For police agencies and surveillance vendors, oversight risk increasingly turns on whether access, retention, accuracy, and deployment limits can be demonstrated. That pressure may affect procurement and governance even before new federal rules emerge.

Watchpoints

Watch

Whether Flock-related proposals become legislation, agency restrictions, or procurement requirements with enforceable limits on searches, retention, or audits.

Watch

The San Francisco Police Commission’s October 14 action, including whether the final drone policy defines permissible deployments and retention controls.

Watch

Implementation and enforcement follow-through for Delaware HB 380 and California’s data-broker obligations, including evidence of how brokers handle recurring DROP requests.

Fallout

The day showed a widening practical gap between state-led data-governance obligations and still-unresolved controls on police surveillance systems.

State Privacy Compliance

California and Delaware developments are turning privacy obligations into recurring operational work for data brokers and other covered organizations.

Fresh developments

Reporting highlighted Delaware HB 380’s expanded duties beginning January 1, 2027, California’s $116,490 enforcement action against LocateSmarter LLC, and ongoing broker obligations under California’s centralized deletion system.

Why we noticed

The measures combine statutory expansion, enforcement, and a continuing deletion workflow—three distinct ways compliance exposure can become tangible.

Watch for:

  • Delaware implementation guidance and preparation for the 2027 effective date.
  • Further California enforcement and evidence of broker compliance with recurring deletion requests.
  • Whether Texas tracking-related demand-letter disputes produce clearer litigation or response practices.

Police Surveillance Oversight

Large-scale vehicle-location and drone programs face sharper questions about the enforceable limits governing their use.

Fresh developments

The Senate’s Flock hearing kept attention on location-data searches, access controls, retention, and accuracy, while San Francisco’s rapidly expanded drone program awaits Police Commission consideration of its operating policy.

Why we noticed

Both developments show that scrutiny is moving beyond general privacy objections toward specific controls over deployment, data access, retention, and accountability.

Watch for:

  • Whether Flock oversight proposals acquire binding force.
  • The final terms of San Francisco’s drone policy after the October 14 commission meeting.
  • Evidence that agencies adopt auditable controls for searches, access, and retention.

Final Thought

The day’s dividing line is not concern versus inaction: states are converting parts of data governance into recurring obligations, while the limits on large-scale public surveillance are still being argued over.