Privacy Rules Are Advancing Through Narrower, Harder Controls
Delaware broadened its consumer-privacy law, Microsoft’s school AI agreement put binding limits on secondary data use, and the European Commission proposed new child-access rules for online services. Each is a concrete move toward more prescriptive controls over how data is collected, used, and governed.
But the day did not produce a unified privacy settlement. The same reporting showed why: networked vehicle surveillance remains contested, while fraudulent requests and poorly held credentials can still expose highly sensitive records without a breach of core systems. Privacy is becoming more operational, but its protections remain uneven.
Delaware enacted HB 380 and HB 381, expanding the businesses covered by its privacy law and tightening rules around sensitive data, profiling, third parties, vendors, and breach procedures. Most of the broader changes take effect January 1, 2027, giving affected organizations time to assess consent records, contracts, automated-decision processes, and incident response.
Microsoft’s legally binding agreement with the American Federation of Teachers remains a consequential near-term model for education AI. From November 1, covered schools receive limits on using student and educator data for AI training, advertising, sales, or unrelated product development, alongside third-party audits and family-facing explanations.
The European Commission’s proposed EU KIDS Act would extend child-access and privacy-by-design obligations across social media, games, video services, and AI chatbots. It is only a proposal, but it puts age assurance at the center of product and privacy design—where the safeguards themselves may create new collection and exclusion risks.
Flock’s expanding license-plate-reader network drew pressure on two fronts: local reporting documented deployment and litigation in Pennsylvania, while Senators Ron Wyden and Adam Schiff sought answers from the company on alleged misuse and access controls. The question is not simply whether cameras are installed, but who can search a durable, networked location database and under what safeguards.
Revolut’s disclosure after a fraudulent government request and Florida’s driver-database access through police credentials stored on a personal device point to the same practical weakness: sensitive data can escape through trusted access channels. Both incidents were contained, but neither has a confirmed full scope.
Key Points
- Privacy governance is advancing through enforceable but narrow levers: state-law amendments, institutional contracts, and product-specific proposals. That continues the recent pattern of operational controls arriving faster than a common, generally applicable framework.
- Age assurance is becoming a core privacy design problem, not just a child-safety feature. The EU proposal couples access limits with protections for profiles, location, devices, and recommendations, while leaving the data consequences of estimating age unresolved.
- Access governance is emerging as the shared stress point across public surveillance and breach response. Flock scrutiny centers on search authorization and auditing; the Revolut and Florida cases center on verification and credential custody. In each case, the sensitive system was not the only risk—the permission to use it was.
Implications
Organizations within Delaware’s expanded reach should begin scoping changes now, especially around sensitive-data consent, vendor controls, profiling and significant decisions, and breach workflows. Precise obligations will depend on implementation and enforcement interpretation.
Education buyers have a more concrete contractual template for AI procurement: limits on secondary use, independent audits, family disclosures, and restrictions on dependency-oriented features. Its wider significance depends on whether comparable commitments spread beyond covered Microsoft contracts.
For platforms serving younger users in Europe, the EU KIDS Act is an early warning rather than a compliance deadline. Legislative progress and the eventual age-assurance model will determine whether the proposal produces workable privacy safeguards or shifts more identity data into verification systems.
Watchpoints
Watch
Implementation guidance and enforcement posture for Delaware HB 380 and HB 381, including how expanded duties around automated decisions and third parties will be interpreted.
Watch
Whether other major AI providers make school-data commitments comparable to Microsoft’s, and how audits operate once the agreement takes effect on November 1.
Watch
The EU KIDS Act’s legislative progress and whether its final age-assurance rules meaningfully limit data collection and exclusion risks.
Watch
Flock’s response to congressional requests, along with outcomes from Pennsylvania litigation and proposed restrictions on license-plate-reader use.
Watch
Confirmed affected populations, notifications, and remediation from the Revolut and Florida incidents.
Fallout
Yesterday’s developments reinforced a practical divide in privacy: legal and contractual controls are becoming more specific, while access to sensitive data remains difficult to govern consistently in practice.
Delaware Privacy Compliance
Delaware’s amendments broaden state privacy-law coverage and add operational duties around sensitive data, automated decisions, vendors, and breach response.
Fresh developments
HB 380 and HB 381 were enacted. Most HB 380 changes are scheduled for January 1, 2027, while the revised breach-notification procedures are described as effective upon signing.
Why we noticed
This is a concrete expansion of state-level compliance work, not a policy debate. It reaches into consent management, contracting, notices, due diligence, and incident handling.
Watch for:
- Interpretive guidance on coverage and sensitive-data requirements.
- Enforcement expectations for profiling, significant decisions, and third-party disclosures.
- How organizations update vendor contracts and breach procedures ahead of 2027.
School AI Data Governance
Microsoft’s agreement with the American Federation of Teachers creates binding privacy and safety terms for AI tools used by covered schools.
Fresh developments
The agreement is set to take effect November 1 and restricts use of student and educator data for AI training, advertising, sales, and unrelated product development. It also requires audits and family-facing explanations.
Why we noticed
The agreement converts broad principles into procurement terms that schools can enforce, offering a practical model where broad statutory protections remain absent.
Watch for:
- How the audit and disclosure commitments are implemented after November 1.
- Whether OpenAI, Anthropic, Google, or other providers adopt comparable terms.
- The agreement’s practical coverage across products and school districts.
Child Access and Age Assurance in Europe
The proposed EU KIDS Act would set child-access limits and privacy-oriented design duties across a wide range of online services.
Fresh developments
The European Commission proposed restrictions for children under 13 and guardian-created accounts for users aged 13 to 15, alongside requirements affecting profiles, location and device access, and recommender systems.
Why we noticed
The proposal makes age assurance a material product-design and privacy question for platforms, while acknowledging that verification can itself increase data collection and exclusion risks.
Watch for:
- The proposal’s legislative path and final scope.
- The eventual age-estimation and verification safeguards.
- Whether final rules limit the collection and retention of identity-related data.
Networked Vehicle Surveillance
Flock’s license-plate-reader network faces renewed scrutiny over searchable location data, access controls, and alleged misuse.
Fresh developments
The Morning Call documented continued deployment across Lehigh Valley communities amid litigation and policy debate. Wyden and Schiff separately requested records from Flock and questioned safeguards, privacy-law compliance, and alleged abuse.
Why we noticed
The dispute has moved beyond camera installation to governance of a networked database: authentication, audit trails, search justifications, retention, and secondary use are the operative privacy questions.
Watch for:
- Flock’s response to the senators’ requests.
- Outcomes from Pennsylvania litigation and legislative proposals.
- Evidence of stronger search auditing, authentication, warrant, or retention controls.
Sensitive-Data Access Controls
Separate incidents at Revolut and in Florida show how social engineering and poor credential custody can expose financial and government identity records.
Fresh developments
Revolut disclosed customer information after a fraudulent government request. Florida said attackers accessed its Driver and Vehicle Information Database using police credentials that had been stored on a personal device.
Why we noticed
Neither case depends on a confirmed compromise of core systems. They show the privacy importance of validating requests and controlling privileged access around high-value data.
Watch for:
- Confirmed affected-customer and record counts.
- Notifications and remediation for affected people.
- Changes to requester-verification and privileged-access practices.
Final Thought
As rules increasingly narrow what organizations may do with data, the harder privacy test is becoming who can obtain it—and whether the controls around that access work when they matter.
