Privacy News

Concord Privacy News: 9/23/26

Washington invented a privacy model, but AI is changing the rules; why privacy can be good for business; Delaware expands its privacy law; big tech faces big resistance.

Concord Team · Published Wed Sep 23 2026

Concord Privacy News: 9/23/26

Washington Invented a Privacy Model. Now AI Is Changing the Rules.

More than 20 states have adopted versions of a privacy framework that originated in Washington state. There’s just one problem: Washington still doesn’t have a comprehensive consumer privacy law of its own.

In a recent report, Washington's Attorney General called on lawmakers to establish stronger limits on how much personal information companies collect and retain. But efforts to pass comprehensive legislation have repeatedly stalled, largely over whether consumers should have the right to sue companies that violate the law.

Meanwhile, the privacy landscape has changed dramatically since Washington’s original proposal was introduced in 2019. Artificial intelligence has made data minimization more important than ever. The more personal information organizations collect and retain, the more data may ultimately be available for secondary uses, including AI development and training.

That raises a fundamental privacy question: How can organizations protect data from uses that didn’t even exist when the data was collected?

The original Washington model emphasized consumer rights such as accessing, correcting, and deleting personal information, along with limits on the use of sensitive data and on automated decision-making. Today, some experts argue that those principles need to be supplemented with stronger requirements around data minimization and purpose limitation.

Washington may eventually get its privacy law. But its bigger opportunity could be to learn from the more than 20 states that followed its lead and to build a framework designed for an AI-driven data ecosystem.

The lesson for organizations is already clear: collecting less data, understanding where it goes, and limiting how it is used are becoming increasingly important parts of a modern privacy program.

More Trust, More Data: Why Privacy Can Be Good for Business

What if stronger privacy protections didn't make customers less willing to share data, but actually more willing?

Recent research highlighted by Harvard Business School suggests exactly that. Researchers Ayelet Israeli and Eva Ascarza analyzed consumer behavior following the implementation of privacy laws in California and Virginia and found that consumers in those states shared 9% more information with a customer engagement platform than consumers elsewhere. They also shared a wider variety of data.

Why? The answer is simple: trust.

The researchers suggest that increased transparency, consent requirements, and privacy protections changed how consumers perceived the risk of sharing their information. Rather than discouraging engagement, those protections appeared to give people greater confidence in the exchange.

For businesses, that's an important shift in perspective. Privacy isn't only about compliance or reducing risk. When done well, it can be a way to build trust that makes customers more willing to engage, share information, and deepen their relationship with a brand.

Trust isn't just good for privacy. It can be good for growth.

Read the full article from Harvard Business School Working Knowledge.

Other Privacy News of Note

Delaware’s Privacy Landscape Just Changed

On September 2, 2026, Delaware signed legislation expanding its consumer privacy and data-breach laws. The updates broaden the scope of the Delaware Personal Data Privacy Act and introduce new considerations around AI, profiling, sensitive data, third-party data recipients, and consumer rights.

For companies operating across multiple states, the bigger takeaway is clear: privacy compliance is becoming an ongoing operational process, not a one-time legal exercise. Read more.

Big Tech Faces Big Resistance

Meta's landmark social media settlement marks the latest milestone in a decade-long unwinding of Big Tech's once-unfettered freedom to operate.

Why it matters: The AI industry is watching closely. Its historic expansion, already fraught with job risks and public anxiety, depends on building thousands of power-hungry data centers in communities where opposition is rising fast. Read more.