Delaware Gov. Matt Meyer signed H.B. 380 on September 2, amending the Delaware Personal Data Privacy Act (DPDPA) and turning it into one of the strictest state privacy laws in the country. The amendments take effect January 1, 2027, and they add new third-party contracting and due diligence obligations, tighten rules around sensitive data, and expand who the law covers.

 

What happened

H.B. 380 requires controllers who disclose personal data to third parties, including through a sale of data or for targeted advertising, to sign binding contracts with those third parties. The law also requires controllers to conduct "reasonable due diligence" on third parties before disclosing data to them. Besides the contracting changes, the amendments lower the law's applicability thresholds, narrow the exemption for entities covered by the Gramm-Leach-Bliley Act (GLBA), expand the definition of sensitive data, and add new consumer rights and profiling obligations. The changes take effect January 1, 2027.

 

Going deeper

Required contract terms

Controllers must include specific terms in contracts with third parties that receive personal data:

  • The data may be used only for limited, specified purposes, and the contract must state whether that includes decisions that produce legal or similarly significant effects.
  • The third party must meet the same privacy protections the DPDPA requires.
  • The controller may take reasonable steps to confirm the third party's compliance.
  • The third party must notify the controller if it cannot meet its DPDPA obligations.
  • The controller may take reasonable steps to stop and remediate unauthorized use of the data.

 

Due diligence requirements

Controllers must use questionnaires and review relevant documents to assess a third party's policies and technical safeguards, and they must take "additional reasonable measures" based on how sensitive the disclosed data is.

 

Expanded sensitive data

H.B. 380 adds these categories to the DPDPA's definition of sensitive data:

  • National origin
  • Mental or physical health condition, diagnosis, treatment, or status, including pregnancy
  • Neural data generated by measuring central nervous system activity
  • Financial account numbers, login credentials, or card numbers combined with a password or security code
  • Government-issued identifiers, such as Social Security numbers or driver's license numbers

The amendments also state that inferences drawn from personal data that reveal a sensitive characteristic count as sensitive personal data.

 

Sensitive data processing and sale

Processing sensitive data now requires consumer consent, and the processing must be reasonably necessary and proportionate to its stated purpose. Selling sensitive data requires that the sale be strictly necessary for a product or service the consumer requested, plus clear notice before the sale identifying the data categories, purposes, and specific third parties involved.

 

Lower applicability thresholds

The DPDPA now applies to businesses that control or process personal data of 10,000 or more consumers (down from 35,000), or 5,000 or more consumers combined with deriving more than 20% of revenue from data sales (down from 10,000). The law now also applies to third parties that acquire personal data from a controller, regardless of volume.

 

Narrower GLBA exemption

The law previously exempted any entity covered by the GLBA. It now limits that exemption to insurers, banks, and securities firms directly engaged in GLBA-regulated financial activities, which removes the exemption for fintech companies and payment processors that don't fall into those categories.

 

New consumer rights

Consumers can now request information about inferences a controller has drawn from their data and whether the controller profiles them for legal or similarly significant decisions. Consumers can also request a list of specific third parties who received their data, unless the data is pseudonymous, disclosure would reveal a trade secret, or compiling the list isn't reasonably feasible (in which case the controller must disclose all third-party categories generally).

 

Profiling obligations

Controllers that process personal data of 50,000 or more Delaware consumers and use profiling for automated decisions with legal or similarly significant effects must complete an impact assessment covering foreseeable risk of harm, categories of data processed, profiling outputs, transparency measures, and post-deployment monitoring steps. Third parties that receive "reports" (recommendations, summaries, or automated decisions based on personal data or profiling) for use in decisions with legal or similarly significant effects must notify Delaware residents of any adverse action taken based on the report, and must respond to requests to access or correct the data used. Reports used in employment decisions fall under the law even though the DPDPA otherwise exempts employee and job applicant data.

 

What was said

In a press release from the Office of the Governor, Gov. Matt Meyer said, "Your data should belong to you, not the highest bidder, and privacy shouldn't be a privilege – it's a right that everyone in Delaware should have." He added that Delaware is "putting the broadest data protections in the country on the books, covering more Delawareans than any similar law in America and adding new safeguards for national origin, citizenship, immigration status, and gender identity."

 

In the know

A "controller" is the business that decides how and why personal data gets processed, while a "third party" is an outside entity that receives that data, for example through a sale or for targeted advertising. State privacy laws like the DPDPA generally require controllers to protect data themselves and, to make sure the third parties they share it with do the same. H.B. 380 follows a due-diligence and contracting model similar to the one California's privacy law already uses, which means businesses already complying with California's requirements have a template to build from, but they cannot simply reuse the same agreements without updating them for Delaware's specific terms.

 

Why it matters

This amendment changes how adtech companies, data brokers, and any business that sells or shares personal data with vendors need to operate in Delaware. Businesses that built their vendor contracts around California's requirements can no longer treat Delaware as covered by the same language, they need a Delaware-specific addendum or a broader, jurisdiction-neutral contract framework. The lower applicability thresholds also brings more mid-sized businesses into the law's scope, and the narrowed GLBA exemption means fintech companies and payment processors that previously assumed they were exempt now need to check whether they're covered. Since the law doesn't take effect until January 1, 2027, businesses have time to update contracts and build diligence steps into their onboarding processes before enforcement begins. While the law only applies to organizations that operate in Delaware, it’s important to pay attention to these state changes, as they can influence other states to take on similar measures.

 

FAQs

Does a Delaware privacy law affect businesses located outside Delaware?

Yes, state privacy laws generally apply based on whether a business processes the personal data of that state's residents, not on where the business itself is located.

 

Who enforces state privacy laws like this one?

State attorneys general are the ones responsible for enforcing state privacy laws.

 

How does Delaware's law compare to other state privacy laws, like California's?

It follows a similar overall structure to other state laws but sets some of the lowest applicability thresholds and broadest sensitive-data protections in the country.