Key point: Delaware’s HB 380, signed into law on September 2, 2026, significantly expands the scope of the Delaware Personal Data Privacy Act (DPDPA), narrows the GLBA exemption for financial institutions, introduces direct obligations on third parties, and strengthens protections around sensitive data, profiling, and automated decision-making. The amendment takes effect January 1, 2027.

On September 2, 2026, Delaware Governor Matt Meyer signed House Bill 380 (HB 380) into law, amending the Delaware Personal Data Privacy Act (DPDPA). The new law represents the most significant revision to the DPDPA since its initial enactment in September 2023. The amendment

  1. Substantially lowers the law’s applicability thresholds;
  2. Narrows the Gramm-Leach-Bliley Act (GLBA) exemption;
  3. Imposes direct obligations on third-party data recipients;
  4. Expands the definition of sensitive data; and
  5. Introduces new requirements around profiling and automated decision-making.

Businesses that previously fell outside the DPDPA’s scope, including those that relied on the financial institution exemption, should closely examine DPDPA applicability and obligations ahead of the January 1, 2027, effective date.

Link to Applicability Expanded Applicability Expanded

One of the most consequential changes under HB 380 is the significant lowering of the DPDPA’s applicability thresholds. Previously, the DPDPA applied to controllers that processed the personal data of at least 35,000 consumers annually, or at least 10,000 consumers if more than 20% of gross revenue was derived from the sale of personal data. HB 380 reduces the general threshold to 10,000 consumers and the revenue-based sales threshold to 5,000.

Notably, HB 380 also adds an entirely new applicability trigger, as any third party that acquires personal data from a controller is now independently subject to the DPDPA, without any minimum numeric volume threshold. This is a unique feature among state privacy laws, which broadens the universe of entities covered by the DPDPA. “Third party” is defined as any person other than the relevant consumer, the controller, the processor, or an affiliate of the processor or the controller, with an exception for certain entities otherwise excluded from the statute, such as government entities. Businesses that receive personal data from controllers subject to the DPDPA should assess whether this new trigger applies to them, regardless of how many Delaware residents’ data they handle.

The threshold that triggers obligations to conduct mandatory data protection assessments is also reduced, from 100,000 consumers to 50,000 consumers.

Link to GLBA Exemption Narrowed GLBA Exemption Narrowed

The existing DPDPA contains a broad entity-level exemption for any financial institution, or affiliate of a financial institution, subject to Title V of the GLBA. HB 380 replaces this broad exemption with three more targeted entity-level exceptions, each tied to a specific type of financial activity.

  • First, insurers, insurance companies, insurance producers, surplus lines brokers, third-party administrators, health carriers, health services corporations, insurance-support organizations, and insurance agents, along with their affiliates and subsidiaries, retain an exemption under HB 380, but only to the extent they are principally engaged in financial activities as described in 12 U.S.C. Section 1843(k).
  • Second, a separate exemption applies to federally and state-chartered banks, credit unions, and savings associations, again conditioned on their affiliates and subsidiaries being principally engaged in financial activities under the same provision.
  • Third, a new exemption covers agents, broker-dealers, investment advisers, and investment adviser representatives regulated by the Delaware Investor Protection Unit or the Securities and Exchange Commission.

The entity-level GLBA exemption also no longer extends automatically to all affiliates and subsidiaries of a covered financial institution. Instead, each affiliate or subsidiary must be “principally engaged in financial activities” under 12 U.S.C. Section 1843(k).

It is important to note that the data-level exemption for data subject to the GLBA remains and has not been amended by HB 380.

Link to Other Exemptions Modified Other Exemptions Modified

The definition of publicly available information is narrowed to exclude biometric data collected without the consumer’s consent, even where that data was otherwise made available through widely distributed media.

HB 380 narrows the employee data exemption, and data processed in connection with profiling and reports in the employment context is now subject to the DPDCA.

Link to Sensitive Data Protections Expanded Sensitive Data Protections Expanded

HB 380 meaningfully expands the categories of sensitive data covered under the DPDPA to cover:

  • Inferences drawn from personal data, alone or in combination with other data, that are used to reveal or identify sensitive characteristics such as racial or ethnic origin, religious beliefs, health conditions, sexual orientation, immigration status, and related categories. Controllers can no longer argue that inferred sensitive characteristics fall outside the law’s sensitive data protections simply because the underlying data was not sensitive on its face;
  • Neural data generated by measuring central nervous system activity;
  • Financial account credentials such as account numbers, log-in information, and credit or debit card numbers that would allow access to a consumer’s financial account; and
  • Government-issued identification numbers such as Social Security numbers, passport numbers, and driver’s license numbers that applicable law does not require to be publicly displayed.

Where sensitive data is sold to a third party, the controller must provide clear and conspicuous pre-sale notice, obtain express consent, and maintain a record of that consent for five years.

Link to Controller Duties Expanded Controller Duties Expanded

HB 380 introduces modifies existing and creates new affirmative obligations on controllers that go beyond notice and consent.

HB 380 expands the existing law’s data minimization obligations to include not only the collection of personal data, but will now require that any processing of personal data be reasonably necessary and proportional to the purposes for which such data is processed. Furthermore, such purposes must be disclosed to the consumer at the time of collection — controllers would be prohibited from processing personal data for any additional purposes even if later disclosed to the consumer after the time of collection.

Controllers that disclose personal data to third parties, including for purposes of a sale or for targeted advertising, must now enter binding contractual agreements with those third parties. Those contracts must specify the limited purposes for which data is disclosed, including whether the purpose includes decisions with legal or similarly significant effects; obligate the third party to comply with the DPDPA and to provide equivalent privacy protections; grant the controller audit and remediation rights; and require the third party to notify the controller if it can no longer meet its obligations.

Additionally, controllers must conduct reasonable due diligence on third parties to whom they disclose personal data. At a minimum, this requires questionnaires and review of relevant documents, with additional scrutiny required in proportion to the sensitivity of the data shared. This due diligence obligation applies to both disclosures for targeted advertising and sales of personal data.

HB 380 also limits an existing exclusion from the definition of a sale of personal data. Previously, disclosure to a third party for purposes of providing a consumer-requested product or service was excluded from the definition of a sale. Under HB 380, that exclusion remains, except where the disclosure involves sensitive data for monetary or other valuable consideration. In that case, the disclosure must comply with the sensitive data sale requirements under Section 12D-106(a)(12), including pre-sale notice, consent, and the five-year record-keeping obligation.

HB 380 also modifies the existing contract requirements between controllers and processors by specifying that such contracts will now be required to require processors to cooperate with reasonable assessments by controllers when conducting due diligence, and the contracts must identify each limited and specific purpose for which the processor is processing personal data, which cannot be described in generic terms, such as referencing the entire contract generally.

Link to Profiling and Automated Decisioning Obligations Expanded Profiling and Automated Decisioning Obligations Expanded

HB 380 introduces an entirely new framework governing “reports,” defined as any written, oral, or other communication of personal data by a controller or processor, including recommendations, summaries, or automated decisions based on personal data or profiling. This broad definition captures the outputs of algorithmic and artificial intelligence-driven decision-making systems that may go beyond other states’ requirements for automated decision-making technologies.

Where a controller discloses a report to a third party for use in connection with a decision that produces legal or similarly significant effects concerning a Delaware resident, the controller must:

  • Require, by contract, that the third party provide notice to the resident of any adverse action based on that report;
  • Describe the personal data relied upon;
  • Inform the resident of their right to obtain information from the controller; and
  • Where technically feasible, afford the resident an opportunity for human review of the adverse action.

Separately, the controller must, upon request from a resident, provide within 30 days the personal data maintained about the resident, the source of the data used in profiling, and a list of all third parties who obtained a report concerning the resident within the prior 24 months. The resident must also be given an opportunity to correct any inaccurate personal data. Notably, these report-related obligations do not apply where the report or personal data constitutes a consumer report subject to the Fair Credit Reporting Act.

These provisions work alongside the existing opt-out right for profiling in furtherance of solely automated decisions that produce legal or similarly significant effects, which is preserved and clarified under HB 380. Controllers engaging in automated profiling should review their current practices and contracting against these new requirements.

Furthermore, the new law clarifies that the clear and conspicuous link to opt out of profiling should appear not only on a controller’s website, but also in any applications, such as mobile apps.

Link to Consumer Privacy Rights Modified Consumer Privacy Rights Modified

HB 380 modifies the consumer’s right to access personal data relating to third party disclosures by requiring controllers to respond with a list of third parties to which the controller has disclosed the consumer’s personal information, not just the categories of third parties as required under the existing DPDPA. If a list of specific third parties cannot be determined with reasonable effort, the controller is required to provide a list of all third parties to which the controller discloses personal data, not just those to which the consumer’s personal data has been disclosed.

HB 380 also clarifies that in response to a right to access request, the controller must not disclose the specific data elements (Social Security numbers, driver’s license numbers, financial account numbers, health information, passwords and security questions, and biometric data). Instead, the controller may only inform the consumer with sufficient particularity that such personal data is being processed by the controller.

HB 380 also expands the right to opt out of profiling that is being used in furtherance of automated decisions that produce legal or similarly significant effects concerning a consumer. The existing law provided this right to only those circumstances in which the profiling was in furtherance of “solely” automated decisions. The removal of the word “solely” extends this right to other decisions in which the profiling may have been only part of the automated decision.

Link to Protections for Minors Expanded Protections for Minors Expanded

Under HB 380, controllers are prohibited from processing the sensitive personal data of children under 13 years old without parental consent. Controllers must obtain the consent of minors aged 13 to 18 before processing any of their personal data for profiling.

Link to Third Party Obligations Created Third Party Obligations Created

A new provision, Section 12D-107A, imposes direct obligations on third parties that receive personal data from a controller or processor. Specifically, a third party that lacks the required contractual agreement with the controller or processor may not further process the personal data it receives. Third parties must (i) comply with the terms of any required contract, (ii) provide information sufficient for the controller to conduct data protection assessments, and (iii) cooperate with due diligence inquiries. In addition, third parties that independently meet the applicability thresholds must comply with all provisions of the law.

Link to Data Protection Assessment Requirements Enhanced Data Protection Assessment Requirements Enhanced

HB 380 expands the data protection assessment obligations in two important respects.

First, the threshold triggering the need for a controller to conduct such assessments has been lowered from 100,000 to 50,000 consumers.

Second, where a controller engages in profiling in furtherance of automated decisions with legal or similarly significant effects, a separate impact assessment is now required. That impact assessment must address:

  • The purpose and intended use cases of the profiling;
  • A risk analysis identifying known or foreseeable harms and the steps taken to mitigate them;
  • A description of the categories of personal data used as inputs and outputs;
  • An overview of data used to customize profiling, metrics used to evaluate performance and limitations, transparency measures; and
  • A description of post-deployment monitoring and user safeguards.

Link to Other Notable Changes Other Notable Changes

Several additional changes in HB 380 are worth flagging.

The law’s existing prohibition on discriminating against consumers for exercising their rights remains in place, and HB 380 adds a new anti-bias provision specific to profiling, making evidence of proactive bias testing relevant to any claims that a controller’s profiling violated state or federal anti-discrimination laws.

HB 380 clarifies that the privacy notice provided to consumers must be reasonably particular to the product or service offered to the consumer. This may require controllers to develop separate privacy notices for different products or services rather than relying on general privacy disclosures.

Photo of Kim Phan Kim Phan

Kim is a partner in the firm’s Privacy + Cyber Practice Group, where she is a privacy and data security attorney, who also assists companies with data breach prevention and response, including establishing effective security programs prior to a data breach and the

Kim is a partner in the firm’s Privacy + Cyber Practice Group, where she is a privacy and data security attorney, who also assists companies with data breach prevention and response, including establishing effective security programs prior to a data breach and the assessment of breach response obligations following a breach.

Photo of Brianna Dally Brianna Dally

Brianna provides comprehensive advice to clients across various industries on privacy and cybersecurity issues. Her work ranges from implementing information security and incident response programs to addressing complex compliance questions. Brianna has experience advising on compliance with regulations such as the New York…

Brianna provides comprehensive advice to clients across various industries on privacy and cybersecurity issues. Her work ranges from implementing information security and incident response programs to addressing complex compliance questions. Brianna has experience advising on compliance with regulations such as the New York Department of Financial Services (NYDFS) Cybersecurity Regulation and other insurance data security laws modeled on the NAIC Insurance Data Security Model Law.