Delaware has significantly expanded its comprehensive consumer privacy law, lowering the number of consumers a business must reach before the law applies and adding new requirements for sensitive information, profiling, third-party data sharing and automated decision-making.
Gov. Matt Meyer signed House Bill 380 into law on September 2, 2026. The amendments to the Delaware Personal Data Privacy Act take effect January 1, 2027.
For many companies, the most immediate change is the new applicability threshold.
Delaware’s existing law generally covers businesses that process personal data belonging to at least 35,000 consumers, excluding data processed solely to complete payment transactions, or businesses processing at least 10,000 consumers’ data while deriving more than 20% of gross revenue from selling personal data.
Beginning in 2027, those numbers fall sharply.
The amended law will apply to businesses conducting business in Delaware or targeting products or services to Delaware residents that, during the previous calendar year:
- control or process personal data of at least 10,000 consumers, excluding data processed solely to complete payment transactions; or
- control or process personal data of at least 5,000 consumers and derive more than 20% of gross revenue from selling personal data.
The new law also expressly reaches certain third parties that acquire personal data from controllers.
For a state with roughly one million residents, a 10,000-person threshold is low. Delaware officials called it the lowest applicability threshold among comprehensive state privacy laws when Meyer signed the legislation.
But HB 380 is not simply a threshold adjustment.
It changes what Delaware considers sensitive data, expands what consumers can ask companies to disclose, places new restrictions on sensitive-data sales and brings consequential automated decision-making much more clearly into the state’s privacy regime.
Delaware Drops Its Privacy Threshold From 35,000 Consumers to 10,000
This is the provision that will cause some companies to revisit whether they are covered at all.
A company that processes information relating to 20,000 Delaware consumers could currently fall below the general 35,000-consumer threshold, assuming the revenue-based alternative does not apply.
Starting January 1, that same company may be squarely within the law.
The revenue-based threshold also changes.
Instead of needing to process at least 10,000 consumers’ data and derive more than 20% of revenue from data sales, the consumer count falls to just 5,000.
Businesses that previously performed a state-law applicability analysis and concluded that Delaware did not apply should therefore run the calculation again before 2027.
That is particularly important for companies operating nationally.
A business does not need a physical office in Wilmington or Dover to fall within the DPDPA. The law applies to businesses conducting business in the state as well as those producing products or services targeted to Delaware residents.
Delaware Broadens the Definition of Sensitive Data
HB 380 also substantially expands what Delaware treats as sensitive personal information.
The amended definition includes categories such as:
- racial, national or ethnic origin;
- religious beliefs;
- health conditions, diagnosis, treatment or status, including pregnancy;
- sex life and sexual orientation;
- transgender or nonbinary status;
- citizenship and immigration status;
- neural data;
- certain financial account and payment credentials; and
- government-issued identification numbers, including Social Security numbers, passport numbers, driver’s license numbers and state identification numbers.
Perhaps more importantly, Delaware is not limiting the definition to information consumers explicitly provide.
The new language includes inferences created from other personal information when those inferences are used to reveal or identify a sensitive characteristic.
That provision matters for modern advertising, analytics and AI systems.
A company does not necessarily need a field in its database labeled “pregnant,” “religion” or “immigration status” to create sensitive information.
It may infer a sensitive characteristic from browsing activity, purchases, location history, searches, app behavior or combinations of other information.
Under the amended Delaware law, the inference itself can become sensitive data when it is used to reveal or identify the protected characteristic.
Consent Alone Is Not Enough for Sensitive Data
Delaware is also tightening the rules around processing sensitive information.
Controllers must generally obtain consumer consent before processing sensitive data.
HB 380 adds an additional requirement: the processing must also be reasonably necessary and proportionate to the disclosed purpose.
That distinction is important.
Obtaining a checkbox does not necessarily authorize unlimited collection.
A company should still be prepared to explain why it needs the sensitive information and whether the amount and type of information being collected are proportionate to the purpose communicated to the consumer.
The amendments also strengthen consent withdrawal.
Businesses must provide an effective way to revoke consent that is at least as easy as the mechanism used to provide it. Once consent is withdrawn, processing covered by that consent must stop as soon as practicable and no later than 15 days after receipt of the request.
That turns consent into an ongoing operational requirement rather than a one-time record collected during signup.
Selling Sensitive Data Gets Much Harder
HB 380 contains particularly strong restrictions on selling sensitive personal information.
A controller generally cannot disclose sensitive data as part of a sale unless several conditions are satisfied.
The sale must be strictly necessary to provide or maintain a product or service affirmatively requested by the consumer.
The business must give clear and conspicuous notice before the sale, identify the specific categories of sensitive information involved, explain the purpose and identify the third parties receiving the information.
The consumer must consent.
And the controller must maintain evidence of that consent for five years.
That five-year record requirement deserves attention.
Companies relying on consent to sell sensitive information will need more than a user-interface setting showing the consumer’s current preference.
They need historical evidence.
Who consented?
What did the notice say when consent was given?
Which categories of data were covered?
Which third parties were identified?
When did the consent occur?
Was it later withdrawn?
For companies using consent management technology, the quality and durability of consent logs become part of the compliance analysis.
Delaware Is Moving Further Into AI and Profiling
One of HB 380’s most important changes involves automated decisions.
The existing Delaware law gives consumers the right to opt out of profiling used in furtherance of “solely automated” decisions producing legal or similarly significant effects.
HB 380 removes the word “solely.”
Beginning in 2027, the opt-out can apply more broadly to profiling used in automated decisions that produce legal or similarly significant effects.
The law identifies consequential areas including:
financial and lending services;
housing;
insurance;
education enrollment or opportunities;
criminal justice;
employment;
healthcare;
and access to essential goods and services.
This is not just an advertising provision.
It potentially reaches systems used to evaluate whether someone gets a loan, apartment, job, insurance coverage, educational opportunity or healthcare service.
That puts Delaware directly into the growing state-level regulatory discussion around AI-assisted decision systems.
Consumers Can Ask Whether Their Data Is Being Used for Profiling
HB 380 also expands Delaware’s access right.
Consumers will be able to request confirmation not only that a controller possesses their personal data, but also access to inferences derived from that information.
They can also ask whether a controller or processor is using their personal data for profiling connected with a decision that produces a legal or similarly significant effect.
This will make data subject access requests considerably more complicated for companies using predictive models.
A traditional access request might require finding a person’s:
name;
email address;
account information;
purchase history;
support tickets;
and website activity.
Now the business may also need to determine what it has inferred about that person and whether those inferences entered a consequential profiling system.
Privacy teams cannot answer that question reliably unless they understand the company’s AI and analytics architecture.
New Rights When Data Is Used in Important Decisions
HB 380 goes further when controllers disclose reports to third parties for decisions producing legal or similarly significant effects.
Under the new provisions, contractual protections must require the recipient to provide notice when an adverse action is based, at least partly, on information in the report.
That notice must include a description of the personal information relied upon.
Consumers may also be told that they can request human review of an adverse decision where technically feasible, subject to certain exceptions.
And upon request, the originating controller may have to provide information including:
the personal data it maintains concerning the resident;
the source of information used in profiling;
and identification of third parties that obtained a report about the resident during the previous 24 months.
The consumer must also have an opportunity to correct inaccurate information.
There is an exception where the report or output qualifies as a consumer report and is furnished in compliance with the federal Fair Credit Reporting Act.
Still, the broader concept is significant.
Delaware is effectively giving consumers more visibility into the data supply chain behind important automated and data-driven decisions.
Businesses Will Have New Obligations When Sharing Data With Third Parties
HB 380 also takes aim at a familiar privacy problem: a company collecting data and then assuming that its responsibility ends when the information is handed to someone else.
The amended law requires controllers to enter into binding contractual agreements with third parties receiving personal information, including information disclosed through sales or targeted advertising.
Those contracts must limit the purposes for which the information can be used and require the recipient to provide privacy protections consistent with Delaware law.
The third party must notify the controller if it can no longer meet its obligations.
The controller must also have the ability to take reasonable steps to stop and remediate unauthorized use.
But Delaware is not stopping at contracts.
HB 380 creates an affirmative due-diligence requirement.
Controllers must conduct reasonable diligence on third parties receiving personal information. At a minimum, the law describes questionnaires and review of relevant third-party documents, with additional measures expected depending on the sensitivity of the information.
That is considerably more demanding than simply inserting privacy language into a vendor agreement.
Third-Party Privacy Due Diligence Becomes a Real Requirement
This provision deserves more attention than it will probably receive initially.
Companies regularly disclose information to advertising technology providers, analytics companies, data enrichment vendors, identity providers, SaaS platforms and other outside businesses.
HB 380 essentially asks the controller to know something about the recipient before handing over the information.
A signed agreement alone may not be enough.
Businesses need a process for evaluating the third party’s privacy program and technical and organizational safeguards.
Depending on the information involved, that might require reviewing:
data-retention practices;
security measures;
subprocessor relationships;
privacy policies;
consumer-rights processes;
data-use restrictions;
and evidence supporting the vendor’s compliance representations.
This moves privacy vendor management closer to the due-diligence model that companies already use in cybersecurity.
Delaware Also Lowers the Assessment Threshold
The amendment lowers another important number.
Under the existing law, certain controllers processing information relating to at least 100,000 consumers must conduct data protection assessments for processing activities that create heightened privacy risks.
HB 380 lowers that figure to 50,000 consumers.
The law also adds more detailed impact-assessment requirements for profiling used in automated decisions producing significant effects.
Those assessments can require documentation of the system’s purpose, use cases, deployment context, foreseeable harms, inputs, outputs, performance metrics, limitations, transparency measures and post-deployment monitoring.
That language looks increasingly similar to what businesses are encountering in AI governance.
A company using automated models for employment, lending, housing or other significant decisions may therefore find that its privacy impact assessment and AI impact assessment are becoming the same project.
Employee Data Is Not Completely Outside the Law Anymore
Delaware’s existing law contains an exclusion for certain information processed in an employment or independent-contractor context.
HB 380 narrows that exclusion.
Personal data used in connection with certain profiling and reports involving consequential decisions can now fall outside the employment-data carveout.
The governor’s office specifically pointed to AI resume screening, interview-scoring systems and tools involved in hiring, promotion, discipline and termination when discussing the legislation.
That gives employers another reason to inventory automated employment technologies.
A company may think of an AI recruiting platform as an HR tool.
Delaware is increasingly treating the data inside that tool as a privacy issue.
Teen Privacy Protections Also Get Stronger
The amendments strengthen protections for teenagers as well.
Controllers that know, or willfully disregard, that a consumer is between 13 and 17 cannot process the individual’s information for certain opt-out purposes, including targeted advertising and data sales, without consent.
This continues a broader trend in U.S. privacy legislation toward treating teenagers differently from adults even after they are old enough to fall outside traditional COPPA protections.
Businesses with large youth audiences should not assume that a standard adult opt-out framework is sufficient.
Privacy Notices Will Need Another Review
HB 380 also changes what controllers must disclose.
Privacy notices need to be reasonably particular to the product or service offered, and the law expands disclosure requirements around consumer rights and processing subject to opt-out rights.
For businesses coming into scope because of the lower threshold, this means January 1 is not simply a date for publishing a Delaware-specific paragraph in an existing privacy policy.
The company may need to coordinate:
its privacy notice;
data inventory;
consent mechanisms;
sensitive-data practices;
consumer rights portal;
profiling systems;
vendor contracts;
vendor assessments;
data protection assessments;
and opt-out architecture.
Those systems need to describe the same underlying data practices.
Delaware Is Becoming More Aggressive Than Its Size Suggests
Delaware was already unusual among state privacy laws because its original applicability threshold of 35,000 consumers was lower than the 100,000-consumer threshold commonly seen in earlier comprehensive state laws.
Now it is dropping that number to 10,000.
That matters for businesses doing national compliance planning.
It is increasingly difficult to build a U.S. privacy program around the assumption that only large companies will meet state-law thresholds.
A company can have a relatively modest Delaware customer base and still become subject to the DPDPA.
And once it does, the substantive obligations are becoming more demanding.
The state is requiring companies to think about inferred sensitive information, third-party due diligence, consent evidence, consequential profiling and automated decisions, not merely privacy notices and opt-out links.
January 1, 2027 Is Close
HB 380 becomes effective January 1, 2027.
That gives businesses only a few months to determine whether their Delaware obligations have changed.
The first question is simple: recalculate the threshold.
Companies that previously fell below 35,000 Delaware consumers should check whether they processed information relating to 10,000 during 2026.
Companies that derive more than 20% of gross revenue from selling personal information need to check against the new 5,000-consumer threshold.
From there, the analysis becomes more operational.
Identify sensitive data and sensitive inferences.
Review whether that information is sold.
Examine automated profiling used in employment, lending, housing, insurance, healthcare and other consequential decisions.
Review third-party contracts.
Determine whether vendor due diligence meets the new standard.
Confirm that consent can be documented and withdrawn.
And make sure consumer rights systems can actually find the information Delaware will now require companies to produce.
Delaware may be one of the smallest states in the country.
Its privacy law is no longer a small compliance obligation.