State Privacy Rules Reach More Businesses
Coverage from Privacy and Data Security Insights, Mondaq, and others

Delaware, California, and Texas each announced privacy-related changes or guidance affecting organizations.
Delaware is expanding the reach and requirements of its privacy law, California ordered data broker LocateSmarter to pay a penalty and change its practices, and Texas warned businesses about demand letters alleging that website tracking tools violate CIPA. Together, the developments highlight differing state-level pressures on data handling, vendor contracts, data-broker practices, and online tracking.
If you read one thing
It is the only available candidate and gives a broad overview of the separate Delaware, California, and Texas privacy developments.
Delaware is widening privacy-law coverage and obligations
Delaware’s amendments lower applicability and assessment thresholds, broaden sensitive-data coverage, and require more detailed controller–third-party contracts. Most changes take effect January 1, 2027.
California has put data brokers under active enforcement
California ordered LocateSmarter to pay $116,490 and change its practices in the agency’s first data-broker enforcement under the CCPA. The action signals that low opt-out request volume alone does not eliminate enforcement exposure.
Website tracking tools are prompting CIPA demand-letter warnings
Texas’s attorney general warned businesses and nonprofits about demand letters alleging that common tools such as cookies, pixels, and analytics violate CIPA. The alert cautioned that some letters may overstate exposure, while recommending legal review rather than dismissing claims outright.
$116,490 USD
payment required from LocateSmarter LLC
“On August 11, 2026, the California Privacy Protection Agency (CPPA) announced an order against data broker LocateSmarter LLC. The order requires a $116,490 payment and changes to the broker’s practices. According to the CPPA, this is its first enforcement action against a data broker under the CCPA and its first action arising under both the CCPA and California’s Delete Act.”
100,000 consumers
data-protection-assessment threshold before amendment
“The amendments broaden the definition of sensitive data, including national origin, neural data, certain financial account and access information, government-issued identification numbers, and broader health-related information. They also lower the threshold for data protection assessments from 100,000 to 50,000 consumers.”
10,000 consumers
general applicability threshold after amendment
“The amendments lower the general applicability threshold from 35,000 to 10,000 Delaware consumers whose personal data a business controls or processes. The law also applies to businesses that control or process the personal data of at least 5,000 Delaware consumers and derive more than 20% of gross revenue from selling personal data.”
20% percent
gross revenue from selling personal data
“The amendments lower the general applicability threshold from 35,000 to 10,000 Delaware consumers whose personal data a business controls or processes. The law also applies to businesses that control or process the personal data of at least 5,000 Delaware consumers and derive more than 20% of gross revenue from selling personal data.”
5,000 consumers
alternative applicability threshold
“The amendments lower the general applicability threshold from 35,000 to 10,000 Delaware consumers whose personal data a business controls or processes. The law also applies to businesses that control or process the personal data of at least 5,000 Delaware consumers and derive more than 20% of gross revenue from selling personal data.”
No new topic members were supplied, so there is no new evidence of a material change since the prior state.
Previously
Delaware, California, and Texas each announced privacy-related changes or guidance affecting organizations. Delaware is expanding the reach and requirements of its privacy law, California ordered data broker LocateSmarter to pay a penalty and change its practices, and Texas warned businesses about demand letters alleging that website tracking tools violate CIPA. Together, the developments highlight differing state-level pressures on data handling, vendor contracts, data-broker practices, and online tracking.
