LawFlash

Delaware Significantly Expands Its Consumer Data Privacy Law

October 06, 2026
8 minute read

Key Takeaways

  • Delaware has amended its comprehensive consumer privacy law, the Delaware Personal Data Privacy Act, less than two years after the act first took effect.
  • HB 380 takes effect on January 1, 2027, giving businesses only a few months to evaluate the amendments and implement necessary changes.
  • Among other changes, HB 380 lowers the act’s applicability threshold, narrows the GLBA exemption, imposes new contractual and due diligence requirements on third parties, expands the act’s definition of “sensitive data,” and amends the rights available to Delaware consumers.
Delaware recently joined several other states in significantly amending its comprehensive consumer privacy law, the Delaware Personal Data Privacy Act (DPDPA). Delaware House Bill 380, which takes effect January 1, 2027, revises the DPDPA’s scope and applicability thresholds, narrows exemptions, imposes new due diligence and contracting obligations relating to third parties, restricts the sale of sensitive data, expands consumer rights, and introduces new requirements related to profiling. 

These changes arrive less than two years after the DPDPA first took effect and will require businesses already subject to the law—as well as businesses newly brought within its scope—to reassess their privacy compliance programs.

Several other states recently amended their comprehensive consumer privacy laws, and four others adopted comprehensive consumer privacy laws. Read more in our LawFlashes New US State Consumer Privacy Laws: What Businesses Should Know and US State Consumer Privacy Law Update: Notable Changes Across Existing Frameworks.

REVISED APPLICABILITY THRESHOLDS

HB 380 lowers the DPDPA’s applicability threshold to apply to businesses that

  • control or process the personal data of 10,000 or more consumers, excluding data processed solely to complete a payment transaction (down from 35,000 consumers); or
  • control or process the personal data of 5,000 or more consumers (down from 10,000 consumers) deriving more than 20% of gross revenue from the sale of personal data.

The law also creates a separate basis for coverage for a third party that acquires personal data from a controller, without a numerical threshold.

NARROWED EXEMPTIONS

The Gramm-Leach-Bliley Act (GLBA) exemption is narrowed under HB 380. While the DPDPA previously contained a broad entity-level exemption for GLBA covered entities, the revised law exempts only specific financial institutions (such as certain banks, insurers, and securities firms) and their affiliates at the entity level.

Entities covered by the GLBA that fall outside of these categories should evaluate whether they remain exempt under the amended statute. The law also introduces additional exemptions for certain categories of health data.

NEW CONTRACTUAL AND DUE DILIGENCE REQUIREMENTS FOR THIRD PARTIES

HB 380 imposes significant new diligence and contracting obligations related to the disclosure of personal data to third parties. Under the amended law, controllers must conduct “reasonable due diligence” of third parties to which they disclose personal data.

Such diligence must, at a minimum, include assessments using questionnaires and a review of relevant documents concerning the third party’s ability to comply with applicable law.

Further, a controller must enter into a contract with a third party to whom it discloses personal data, including “in a sale of personal data for targeted advertising,” which agreement must:

  • Specify that the personal data is disclosed or sold only for limited and specified purposes, including specifying whether the purpose includes use for decisions that produce legal or similarly significant effects;
  • Obligate the third party to comply with and provide the same level of privacy protections as required by the DPDPA;
  • Allow the controller to take reasonable and appropriate steps to ensure the third party complies with their obligations under the DPDPA;
  • Require the third party to notify the controller if it determines it cannot meet its obligations under the DPDPA; and
  • Allow the controller, upon reasonable notice, to take reasonable and appropriate steps to stop and remediate any unauthorized use of personal data. A third party may not process personal data disclosed by a controller or processor without an agreement satisfying the DPDPA’s requirements.

These requirements may warrant a review of existing data-sharing arrangements and vendor and commercial agreements, particularly where companies have historically distinguished between processor relationships and transfers to independent third parties.

HB 380 also incorporates a diligence-based liability standard into the DPDPA. Under the amended law, a controller or processor that discloses personal data to a processor or third party may avoid liability for the recipient’s DPDPA violations where certain statutory conditions are satisfied, including that the disclosing party “undertook reasonable diligence and oversight to ensure compliance with contractual commitments to which the disclosed personal data is subject.”

EXPANDED DEFINITION AND PROTECTION OF SENSITIVE DATA

HB 380 significantly expands the DPDPA’s definition of sensitive data: under the revised law, covered information now includes national origin, certain health-related information, neural data, certain financial account information, and government-issued identification numbers. The definition also includes certain inferences derived from personal data that are used to reveal or identify a sensitive category.

The amendments impose stricter substantive limitations on processing sensitive data. A controller generally may not process sensitive data without the consumer’s consent, and the processing must be “reasonably necessary and proportionate to the disclosed purposes.” Previously, consumer consent alone was sufficient.

HB 380 also imposes specific conditions on the sale of sensitive data. While the sale of sensitive data is not prohibited, the following requirements now apply:

  • Any such sale must be “strictly necessary” to provide or maintain a product or service affirmatively requested by the consumer
  • The controller must provide clear and conspicuous advance notice describing the sensitive data categories, purpose, and third-party recipients
  • The controller must obtain and retain the consumer’s consent; the consent record generally must be retained for five years

EXPANDED CONSUMER RIGHTS

HB 380 follows in the footsteps of other states to amend the rights available to Delaware consumers. As one example, in connection with an access request consumers will have the right to confirm whether a controller has made certain inferences about them or is processing their personal data for profiling that produces legal or similarly significant effects and, where applicable, to obtain the relevant information.

As with the consumer privacy laws in Connecticut, Oregon, and Minnesota, HB 380 permits consumers to request a list of the specific third parties to whom a controller has disclosed their personal data, subject to certain exemptions.

HB 380 also expands Delaware’s opt-out mechanism requirements. Controllers must provide a clear and conspicuous link on their website or application to a webpage or interface that enables consumers to opt out of targeted advertising, sales, or profiling.

By extending Delaware’s opt-out link requirement to cover profiling and requiring the mechanism to be available through applications as well as websites, controllers may need to reassess the opt-out user experience across mobile, connected television, and other applications.

PROFILING AND AUTOMATED DECISION-MAKING

The amendments introduce new obligations for certain uses and disclosures of personal data for use in decisions producing legal or similarly significant effects. If a controller processes the personal data of 50,000 or more Delaware consumers and engages in profiling in furtherance of automated decisions producing legal or similarly significant effects, it must conduct an impact assessment.

The assessment must include the purposes and intended uses of the profiling, reasonably foreseeable heightened risks of harm, categories of personal data processed, performance metrics and known limitations, transparency measures, and post-deployment monitoring and safeguards.

Further, a controller that discloses “reports” for use in connection with any decision that produces a legal or similarly significant effect on a Delaware “resident” is subject to additional compliance obligations. A “report” can include written, oral, or other communications of personal data, including recommendations, summaries, or automated decisions based on personal data or profiling.

A controller must contractually require a third party to provide notice to a Delaware resident of any adverse action based on the report, describe the personal data relied upon in making the decision, inform the resident of their right to obtain information from the controller, and, where technically feasible, provide the resident an opportunity for human review of the adverse action.

If requested by a Delaware resident, a controller must provide within 30 days the personal data maintained on the resident, the source of the data used in profiling, and a list of all third parties that obtained a “report” concerning the resident within the prior 24 months. The resident must also have an opportunity to correct any inaccurate personal data. These obligations do not apply if the report or personal data is a consumer report subject to the Fair Credit Reporting Act. 

Note that these provisions provide rights to “residents,” not just “consumers” under the DPDPA. As a result, certain profiling-related requirements apply in the employment context and implicate employment-related technologies and automated decision-making tools. The governor’s announcement accompanying the bill signing specifically noted the legislation’s relevance to AI resume screening, interview scoring, and reports used for hiring, promotion, discipline, and termination.

DATA MINIMIZATION AND PROCESSING RESTRICTIONS

The amendments strengthen the DPDPA’s data minimization principles, particularly controllers must limit processing of personal data to what is reasonably necessary and proportionate to the purposes disclosed to the consumer.

Except as otherwise permitted, controllers may not process personal data for an additional purpose that is not reasonably necessary and proportionate to the purpose disclosed at collection without obtaining consumer consent.

HOW WE CAN HELP

Morgan Lewis is prepared to guide companies and institutions of all sizes through the challenges they face in this new regulatory environment that begins January 1. We closely follow developments in all 50 states as data privacy legislation is proposed, enacted, and amended.

Our lawyers assist clients in virtually all the major industries around the globe in understanding how these critical changes affect their businesses and how to navigate the changing data privacy landscape.