Delaware is small. Its privacy law increasingly is not.
On September 2, 2026, Gov. Matt Meyer signed House Bill 380, a substantial rewrite of portions of the Delaware Personal Data Privacy Act. The amendments take effect January 1, 2027 and do considerably more than make a few technical corrections.
Delaware lowered the number of consumers a company can handle before the law applies. It expanded the definition of sensitive data. It imposed more explicit requirements on companies sharing information with vendors and other third parties. It strengthened rules around automated decision-making and profiling. It also moved vendor due diligence from something a mature privacy program probably should do into something covered organizations may actually need to document.
For companies operating nationally, Delaware is also another example of why treating the growing collection of state privacy laws as interchangeable is becoming increasingly difficult.
The broad structure may look familiar. The details are starting to diverge.
The Biggest Immediate Change: Delaware Lowered the Threshold
The first question for any privacy law is whether it applies to you.
Beginning January 1, 2027, Delaware’s answer will capture considerably more businesses.
Under the amended law, the Delaware Personal Data Privacy Act generally applies to businesses conducting business in Delaware or targeting products or services to Delaware residents that, during the preceding calendar year, controlled or processed personal data of at least 10,000 consumers.
The prior threshold was 35,000.
There is also a second threshold for companies more dependent on the sale of personal data. The law applies when a company controls or processes personal data of at least 5,000 consumers and derives more than 20% of its gross revenue from selling personal data.
That threshold previously started at 10,000 consumers.
Personal data processed solely to complete a payment transaction does not count toward the primary consumer threshold.
Even with that exclusion, dropping the main threshold from 35,000 to 10,000 consumers is not a cosmetic change. It pulls a new group of smaller and midsize companies into a comprehensive state privacy statute.
A website does not need millions of visitors to encounter 10,000 Delaware consumers. An ecommerce company, SaaS provider, publisher, mobile application or online service operating nationally can get there surprisingly quickly.
Companies that concluded the Delaware law did not apply to them when the original statute was enacted should therefore run the calculation again. A 2024 applicability analysis may produce the wrong answer for 2027.
Sensitive Data Gets a Much Broader Definition
HB 380 also expands what Delaware considers sensitive data.
Some categories will already be familiar to privacy teams: racial or ethnic origin, religious beliefs, health information, sexual orientation and similar information traditionally treated as particularly sensitive.
Delaware is now more explicit and more expansive.
The amended definition includes information revealing or identifying national origin, pregnancy and related treatment or status, transgender or nonbinary status, citizenship status and immigration status.
It also reaches neural data generated by measuring activity in an individual’s central nervous system.
Financial information receives additional treatment as well. Financial account numbers, login information and credit or debit card information capable of providing access to an account can qualify as sensitive data.
Government identification numbers are included too, including Social Security numbers, passport numbers, state identification numbers and driver’s license numbers when the law does not require them to be publicly displayed.
But one of the more interesting parts of the amendment concerns information a company never directly asked the consumer to provide.
An Inference Can Be Sensitive Even When the Source Data Wasn’t
Delaware’s definition expressly reaches inferences made from personal data, alone or combined with other information, when those inferences are used to reveal or identify a sensitive characteristic.
This matters in a world of increasingly sophisticated analytics and artificial intelligence.
Imagine that a retailer never asks whether a customer is pregnant. Instead, its analytics system identifies a combination of purchases and predicts pregnancy.
Or an advertising system combines language preferences, browsing behavior and location information to infer immigration status or national origin.
Or a platform uses seemingly ordinary behavioral signals to infer a medical condition.
The company cannot necessarily escape sensitive-data rules simply by saying, “The consumer never gave us that information.”
If the company’s system generated the sensitive conclusion itself, the inference can be the sensitive data.
This distinction will become more important as machine-learning models derive characteristics from datasets that look fairly ordinary when individual data points are examined separately.
Privacy programs therefore need to ask a different question. It is no longer enough to inventory the sensitive information entering a system. Companies also need to understand what sensitive information their systems create.
Consent Alone Is No Longer the Whole Answer
Delaware already required consent for processing sensitive data. HB 380 adds another limitation.
The processing must also be reasonably necessary and proportionate to the purpose disclosed to the consumer.
That means obtaining a consent click does not automatically create an unlimited license to use sensitive information.
If a consumer provides sensitive information for Purpose A, a business should not assume the same consent permits Purpose B, C and D merely because the data is already sitting in its systems.
The law increasingly connects consent with purpose limitation.
This is an important distinction for organizations that have historically treated consent as a broad authorization rather than permission tied to a particular processing activity.
Selling Sensitive Data Gets an Even Higher Barrier
The rules become considerably stricter when sensitive data is sold.
Under HB 380, a controller may not disclose sensitive data as part of a sale of personal data unless several conditions are satisfied.
Most importantly, the disclosure must be strictly necessary to provide or maintain a product or service affirmatively requested by the consumer.
The controller must also provide clear and conspicuous notice before the sale. That notice must identify the specific categories of sensitive information being disclosed, explain the purpose of the disclosure and identify the third parties receiving it.
The consumer must consent.
And Delaware adds something operationally important: the controller must maintain a record of that consent for five years.
This turns consent from a front-end interface issue into an evidence problem.
It is not enough for a company to say that its website displayed a banner or that a consumer “must have consented.”
A mature compliance system needs to be able to show when consent occurred, what the consumer was told, what categories of processing were authorized and what preference applied at a particular point in time.
That is particularly relevant to digital advertising environments where data may travel through several companies in fractions of a second.
Delaware Is Making Vendor Due Diligence a Real Compliance Function
One of HB 380’s most practical changes may be its treatment of third-party diligence.
Controllers must conduct reasonable due diligence of third parties receiving personal data. That includes disclosures connected with targeted advertising and the sale of personal data.
Delaware does not leave “due diligence” completely undefined.
At a minimum, the process includes questionnaires and review of relevant documents. Additional measures must be proportionate to the sensitivity of the information being disclosed.
That matters because vendor diligence is often one of the weaker parts of operational privacy programs.
A company may spend considerable time reviewing its own privacy policy and consent banner while thousands or millions of data events are being sent to analytics providers, advertising networks, customer-support tools, session-replay technologies, data platforms and other outside systems.
HB 380 puts more pressure on the organization initiating those disclosures to understand who is receiving the data and whether that company can actually comply with its privacy obligations.
A checkbox reading “vendor is GDPR compliant” is unlikely to tell the whole story.
The Vendors Have Responsibilities Too
The amendment does not place the entire burden on the controller.
Processors must provide information necessary for controllers to assess them and demonstrate compliance. Third parties similarly have duties to provide information needed for diligence and data protection assessments.
There is also a strong incentive to get the paperwork completed.
Under the amended law, a third party receiving personal data without a contract required by the statute may not further process that information.
That is a meaningful operational rule.
In many organizations, the technology gets deployed first and the privacy contract catches up later. Delaware is pushing in the opposite direction: understand the data relationship and establish the necessary contractual controls before relying on the downstream processing.
Contracts Need to Describe What Is Actually Happening
HB 380 adds detailed contracting requirements when controllers disclose personal information to third parties, including disclosures for targeted advertising or the sale of personal data.
The agreement needs to identify the limited and specified purposes for which the information is being disclosed. It must require the third party to comply with Delaware’s privacy requirements and provide an appropriate level of protection.
Controllers must also retain rights to take reasonable steps to verify that information is being used consistently with their obligations and to stop or remediate unauthorized uses.
Processor contracts receive similar scrutiny.
The law says processing purposes must be described with specificity and particularity rather than through generic language referencing the contract as a whole.
Anyone who has read a data processing agreement containing a sentence such as “processor may process personal data as necessary to provide the services” can see where this is headed.
The agreement should increasingly match the actual data flow.
Consumers Can Ask Who Received Their Data
Delaware is also expanding consumer access rights.
A consumer can obtain a list of third parties to which a controller disclosed the consumer’s personal data, subject to several exceptions.
One notable exception applies to pseudonymous data. There is also an accommodation where producing the list would not be possible with reasonable effort, in which case broader third-party disclosure information may be provided.
Still, the direction is clear.
Privacy programs need better visibility into data destinations.
A company cannot reliably tell a consumer where information went if the company itself does not know.
That connects consumer rights directly to data mapping, tag management, vendor inventories and technical monitoring.
Automated Decisions Become a Much Bigger Part of the Law
HB 380 deserves attention outside traditional privacy departments because of what it does with profiling and automated decision-making.
The law addresses automated decisions producing legal or similarly significant effects involving areas such as financial services, lending, housing, insurance, education, criminal justice, employment opportunities, health care and access to essential goods or services.
Consumers have rights relating to whether their personal information is being processed for profiling used in these decisions. They can also opt out of qualifying profiling.
The amendments go further where a controller provides a report to a third party for use in a significant decision.
If adverse action is based in whole or in part on information in that report, the system must support notices describing the data relied upon and informing the affected person about available rights.
In certain situations, a resident may request human review where technically feasible.
Residents may also seek information about the source of personal data used in profiling and identify third parties that obtained certain reports concerning them during the preceding 24 months.
This starts to look less like the classic American cookie-and-advertising privacy law and more like a broader governance framework for data-driven decisions.
Employment AI Should Be on the Compliance Team’s Radar
Another subtle but consequential amendment concerns employee information.
The Delaware law contains an exemption for certain information processed in the context of employment, applications, agency relationships and independent contracting.
HB 380 narrows that protection for personal data processed in connection with certain profiling and reports involving significant decisions.
That is important because employers increasingly use automated tools for recruiting, resume review, candidate screening, interview analysis, performance assessment and other employment decisions.
A company that previously saw “employee data exemption” and stopped its analysis should look again.
Artificial intelligence is gradually eroding the old organizational boundary between privacy compliance and employment technology.
Delaware Wants Impact Assessments for Higher-Risk AI
The amendments also expand assessment requirements.
For controllers meeting the applicable threshold, data protection assessments are required for processing activities presenting heightened risks, including targeted advertising, sale of personal data, sensitive-data processing and certain profiling.
HB 380 lowers a relevant assessment threshold from 100,000 consumers to 50,000 consumers.
For profiling used in automated decisions producing legal or similarly significant effects, the assessment becomes fairly detailed.
Companies may need to document the intended use of the system, foreseeable risks, mitigation measures, categories of input and output data, performance metrics, known limitations, transparency measures and post-deployment monitoring.
That last category is important.
AI governance cannot end when a model is approved for launch.
A system can change. Input data can change. Users can deploy it differently from its intended purpose. Performance can vary among populations. An initially reasonable tool can produce unexpected results after deployment.
Delaware’s framework recognizes that governance needs a life after launch.
Consent Revocation Has a Deadline
HB 380 also makes consent withdrawal more concrete.
A mechanism for revoking consent must be at least as easy as the method used to provide consent. After receiving the revocation, the controller must stop the applicable processing as soon as practicable and no later than 15 days.
That creates another reason for organizations to connect consumer-facing preference systems to the technology actually processing the data.
A privacy preference stored in a database does little good if advertising tags, downstream systems or marketing platforms continue operating as though nothing changed.
The interface and the data architecture have to agree.
What Companies Should Be Doing Before January 1, 2027
Delaware has not left companies with a multi-year runway. Organizations potentially within scope should use the remaining months of 2026 to examine several areas:
- Recalculate whether the company crosses Delaware’s new 10,000-consumer or 5,000-consumer thresholds.
- Update data inventories to account for Delaware’s expanded definition of sensitive data, including sensitive inferences.
- Review where sensitive information is sold or disclosed and whether those transfers satisfy the new necessity, notice and consent requirements.
- Confirm that consent records can actually be retained and retrieved as evidence.
- Inventory third parties receiving Delaware consumers’ personal information.
- Review vendor diligence questionnaires and determine where additional evidence should be requested.
- Update processor and third-party agreements so they describe actual processing purposes and data flows.
- Make sure consumer access workflows can identify relevant third parties receiving personal information.
- Identify automated systems involved in employment, lending, housing, insurance, health care and other significant decisions.
- Review whether existing data protection and AI impact assessments meet Delaware’s expanded requirements.
- Test whether consent revocation and opt-out signals actually change downstream processing.
This Is Another Step Away From the Idea of One Generic U.S. Privacy Program
The American state privacy landscape originally looked as though it might settle into a fairly predictable template.
Give consumers access and deletion rights. Allow them to opt out of targeted advertising and data sales. Require contracts with processors. Protect sensitive data. Publish a privacy notice.
Those common elements still exist.
But the differences between states are becoming more operationally important.
Delaware now has unusually low applicability thresholds, detailed third-party diligence obligations, specific sensitive-data sale restrictions, expanded treatment of inferences, stronger rules around consequential automated decisions and more explicit expectations for vendor contracts.
That means national compliance increasingly requires a system capable of adapting to jurisdiction-specific rules rather than a static privacy policy written to the lowest common denominator.
The Real Lesson From HB 380: Know Where the Data Goes
There is a common thread running through many of Delaware’s changes.
The state wants companies to know what data they collect, why they use it, what they infer from it, who receives it and what those recipients are allowed to do next.
That sounds simple until someone tries to map a modern website.
A single page can include analytics platforms, advertising tags, pixels, customer-support software, embedded media, authentication systems, fraud detection, session analytics and other technologies communicating with outside domains.
Some data transfers are obvious. Others happen deep inside scripts, tag managers, APIs or server-side infrastructure.
Contracts cannot accurately describe those relationships if the company does not know they exist. Vendor diligence cannot assess them. Consumer access requests cannot disclose them. Consent cannot meaningfully control them.
This is where technical privacy controls matter.
Organizations need an accurate inventory of the technologies operating on their digital properties, a consent system capable of controlling technologies according to applicable rules, records showing the choices consumers made, and processes for updating privacy notices and downstream data practices as those technologies change.
A privacy program written entirely on paper will have a difficult time satisfying rules that increasingly depend on what software actually does.
Delaware’s Privacy Law Is No Longer Easy to Ignore
Delaware’s original privacy law was already part of the growing American state privacy framework. HB 380 makes it much harder for businesses to treat Delaware as a secondary jurisdiction.
The 10,000-consumer threshold alone changes the applicability analysis for a significant number of companies.
But the more interesting story is what Delaware has built around that threshold.
The state is connecting consumer privacy rights with vendor oversight, sensitive-data controls, contractual evidence, automated decision-making and technical accountability.
For privacy teams, the January 1, 2027 deadline should not simply trigger another privacy-policy update.
It should trigger a review of the systems underneath the policy.
Because under Delaware’s amended privacy law, knowing that data was collected is only the beginning.
Companies increasingly need to know where it went, why it went there, what happened to it, what was inferred from it and whether they can prove that the rules followed the data.