Delaware HB 380: Expanding the DPDPA – Key Changes, Controversy, and Compliance Implications

Table of Contents

Delaware is poised to significantly strengthen its comprehensive privacy law. House Bill 380, which passed both chambers of the General Assembly on June 16, 2026, would amend the Delaware Personal Data Privacy Act (DPDPA) and is currently awaiting action by Governor Matt Meyer. If signed, most provisions would take effect on January 1, 2027.

The bill has drawn sharp reactions. Privacy advocates view it as a necessary modernization that expands protections for Delaware residents. Industry groups, led by NetChoice, have formally urged a veto, arguing that HB 380 creates a restrictive, Delaware-specific regime that diverges from the multi-state consensus and imposes costly new burdens on online businesses.

For companies that process personal data of Delaware residents, understanding the proposed changes is essential risk management. This analysis covers the background of the DPDPA, the key amendments in HB 380, the competing viewpoints, practical compliance implications, and how the bill fits into the broader U.S. state privacy landscape. Privacy officers from some of the largest e-commerce companies have spoken with Captain Compliance and said that they are considering just blocking all Delaware traffic and not accepting orders from Delaware as a result of the privacy law.

The Delaware Personal Data Privacy Act

Delaware enacted its comprehensive consumer privacy law in 2023. The DPDPA took effect on January 1, 2025, placing the state among the growing number of jurisdictions with private-sector data protection statutes. Like most state privacy laws modeled after the Washington Privacy Act framework, the original DPDPA established consumer rights (access, deletion, correction, opt-out of sale and targeted advertising), controller and processor obligations, data protection assessments for high-risk processing, and enforcement by the Delaware Department of Justice.

The original law applied to entities conducting business in Delaware or targeting Delaware residents that controlled or processed the personal data of at least 35,000 consumers, or of 10,000 consumers while deriving more than 20 percent of gross revenue from the sale of personal data. It included relatively standard definitions of sensitive data and provided entity-level exemptions for financial institutions subject to the Gramm-Leach-Bliley Act (GLBA).

HB 380 reflects a broader trend: states that passed privacy laws in the first wave are now revisiting those statutes to close perceived gaps, expand coverage, and respond to evolving technology and enforcement experience. Delaware is following the path taken by several other states that have already amended their laws to lower thresholds, strengthen sensitive-data rules, and tighten third-party accountability.

Breakdown of the Key Amendments in HB 380

HB 380 makes several material changes to the DPDPA:

Lower Applicability Thresholds

The bill substantially reduces the number of consumers that trigger coverage. Under the amended thresholds, the law would apply to entities that control or process the personal data of approximately 10,000 to 15,000 Delaware consumers (sources vary slightly on the precise final number, but the reduction from 35,000 is significant), or a lower number if the entity derives more than 20 percent of revenue from data sales. On a population-percentage basis, the new thresholds more closely align Delaware with states such as Connecticut and New Jersey. The practical effect is that a larger set of mid-sized and national companies with moderate Delaware footprints will fall under the statute.

Expanded Definition of Sensitive Data

Perhaps the most consequential change is the broadening of “sensitive data.” The amended definition adds categories including national origin, treatment for any mental or physical health condition (including reproductive and gender-affirming care), neural data, financial account information, login credentials, payment card information, and government-issued identification numbers. Critically, it also reaches certain inferences drawn from personal data that can be used to reveal or identify sensitive attributes. Privacy advocates support this expansion as reflecting real-world risks; industry groups argue the inference language is unusually broad and could sweep routine analytics and e-commerce data into heightened consent and restriction regimes.

New Contracting and Due Diligence Requirements

HB 380 introduces obligations that go beyond the standard controller-processor contract requirements found in most state laws. Controllers would need binding contracts and formal due diligence before disclosing personal data to third parties — including independent entities acting as their own controllers (for example, ad exchanges or publisher networks). No other state currently extends contracting and diligence mandates this far. Smaller businesses may find it difficult to negotiate customized terms with large platforms, potentially limiting access to advertising tools available to competitors operating under less stringent rules.

Restrictions on the Sale of Sensitive Data

The bill limits the sale of sensitive data unless the disclosure is “strictly necessary” to provide or maintain a product or service affirmatively requested by the consumer. Additional notice, consent, and record-keeping requirements would apply. This “strictly necessary” standard appears in only a limited number of other state laws and sits in tension with broader consent-based frameworks.

Automated Decision-Making and Profiling Rights

HB 380 expands consumer rights and controller obligations around decisions that produce legal or similarly significant effects. By removing or modifying the “solely” automated qualifier in certain provisions and extending opt-out and transparency rights more broadly, the bill increases the compliance burden on systems that personalize experiences, screen transactions, or support employment-related or service decisions — even when a human remains in the loop.

Narrowed GLBA Exemptions and Other Adjustments

Entity-level exemptions for financial institutions are narrowed, limiting full exemptions primarily to banks, credit unions, savings associations, insurers, and their affiliates while preserving data-level GLBA protections. The bill also includes provisions addressing minors’ data and other harmonization measures with laws in peer states.

NetChoice Veto Arguments vs. Privacy Advocate Support

On July 14, 2026, NetChoice sent a formal letter to Governor Meyer urging a veto of HB 380 as amended. The organization argues that the bill abandons the multi-state consensus framework adopted by more than twenty states. Key criticisms include:

  • The expanded sensitive-data definition, particularly the open-ended treatment of inferences, would capture routine business data and require opt-in consent by default.
  • Contracting and due-diligence mandates for disclosures to independent third parties impose costs and practical barriers that no other state requires.
  • Changes to automated-decision rules reduce incentives to keep humans in the loop and treat preliminary processes the same as fully automated consequential decisions.
  • Redefining coverage in ways that pull employee and HR-related data into a consumer privacy statute creates unintended operational burdens.
  • The rapid amendment process limited meaningful engagement with the online businesses most affected.

NetChoice contends these features make Delaware a regulatory outlier, raising compliance costs without a clear corresponding increase in consumer protection beyond existing state and federal safeguards (including the Fair Credit Reporting Act).

Privacy organizations take the opposite view. EPIC and Consumer Reports testified in support of the bill, praising the lower thresholds for expanding coverage, the enhanced sensitive-data protections, limits on the sale of sensitive information, and stronger rights around profiling and consequential decisions. They frame HB 380 as a responsible update that reflects lessons from other states and better addresses modern data practices, including those involving AI and inferences. Advocates also note that the bill was developed with input from the Delaware Department of Justice and continues a pattern of iterative improvement seen across the country.

The debate highlights a recurring tension in state privacy legislation: the desire for strong, evolving consumer protections versus the industry preference for relative uniformity that allows scalable national compliance programs.

How HB 380 Fits into the Multi-State Privacy Patchwork

Delaware’s move is part of a larger pattern. After the first wave of comprehensive state privacy laws, several jurisdictions have returned to amend their statutes — lowering thresholds, expanding sensitive-data categories, tightening third-party rules, and addressing automated decision-making more aggressively. HB 380 places Delaware among the more protective end of the spectrum on sensitive data and third-party accountability, while still operating within the broader “state privacy law” family rather than adopting a pure CCPA-style model.

For multi-state businesses, the practical challenge is not any single law but the cumulative effect of diverging requirements. A Delaware-specific contracting regime, expanded inference rules, and lower thresholds mean that companies cannot rely solely on a “consensus state” compliance program. They must either build Delaware-specific controls or adopt the higher standard across their operations. This dynamic is precisely what industry groups cite when arguing for greater uniformity or federal preemption, and what privacy advocates cite when defending state innovation.

Practical Compliance Implications and Action Items

Whether or not Governor Meyer signs HB 380, companies should prepare for the possibility of expanded obligations effective January 1, 2027. Recommended steps include:

  1. Reassess Applicability — Recalculate whether your organization meets the lowered consumer and revenue thresholds for Delaware residents.
  2. Map Sensitive Data and Inferences — Inventory data flows involving the newly expanded sensitive categories, including any inferences that could reveal health, financial, or other protected attributes.
  3. Review Third-Party Relationships — Identify all disclosures and sales of personal data to independent third parties. Evaluate the feasibility of new contractual and due-diligence requirements.
  4. Update Consent and Notice Mechanisms — Prepare for stricter rules on the sale of sensitive data, including the “strictly necessary” standard and associated notice/consent obligations.
  5. Evaluate Automated Decision Systems — Review profiling and decision-making tools that could produce legal or similarly significant effects for Delaware residents and assess opt-out and transparency readiness.
  6. Assess HR and Employee Data Practices — Determine whether any expanded definitions or coverage language could reach workforce-related processing that was previously outside the consumer privacy regime.
  7. Document and Monitor — Strengthen data protection assessment processes and maintain records that demonstrate good-faith compliance efforts.
  8. Engage Counsel and Monitor the Governor’s Decision — Track the status of HB 380 closely and obtain jurisdiction-specific advice once the final text and effective date are confirmed.

Organizations that already maintain mature CCPA/CPRA or multi-state programs will have a head start, but the Delaware-specific elements — particularly contracting mandates and the breadth of sensitive-data inferences — will require targeted attention.

FAQs: Delaware HB 380 and the Amended DPDPA

Q: Has HB 380 been signed into law?

A: As of late July 2026, the bill has passed the legislature and is awaiting action by Governor Matt Meyer. It is not yet law.

Q: When would the changes take effect?

A: If signed, the amendments are generally set to take effect on January 1, 2027.

Q: Will the lower thresholds bring more companies into scope?

A: Yes. Reducing the consumer threshold from 35,000 significantly expands the number of businesses that must comply, particularly national companies with moderate activity in Delaware.

Q: How does the expanded sensitive-data definition affect everyday analytics?

A: The inclusion of certain inferences could require opt-in consent or heightened restrictions for data that businesses previously treated as non-sensitive. Careful mapping and legal review are recommended.

Q: Are the new contracting requirements unique?

A: Yes. Extending binding contract and due-diligence obligations to disclosures to independent third-party controllers goes beyond the standard processor contract rules in most other state privacy laws.

Delaware Privacy Law Preparation Is the Best Response

Delaware HB 380 represents a meaningful expansion of the state’s privacy framework. Whether the bill is signed, vetoed, or further amended, the debate itself signals continued state-level activity and the ongoing tension between stronger consumer protections and operational uniformity for businesses.

Companies that process Delaware resident data should treat the current moment as a planning opportunity. Mapping data flows against the proposed sensitive-data categories, stress-testing third-party arrangements, and updating governance processes will reduce risk regardless of the final outcome.

At Captain Compliance, we help organizations navigate the evolving multi-state privacy landscape. Our team provides the privacy software tailored to laws like the DPDPA and its proposed amendments.

Is your organization prepared for potential changes under Delaware HB 380? Book a demo below to stay ahead of state privacy developments, enforcement trends, and compliance best practices with Captain Compliance.

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.