Key point: Less than two years after Delaware’s consumer data privacy law went into effect, Delaware lawmakers have significantly revised the law to update it for changes made by other states while creating new obligations for controllers and third parties.
On September 2, 2026, Delaware Governor Matt Meyer signed HB 380 into law. Effective January 1, 2027, HB 380 significantly revises Delaware’s consumer data privacy law, which went into effect January 1, 2025.
In general, HB 380 updates Delaware’s law to incorporate amendments that other states have adopted since Delaware’s law was passed in 2023. Those amendments include lowering the law’s applicability standard, modifying the Gramm-Leach-Bliley Act (GLBA) exemption, and expanding the definition of sensitive data. The bill also creates new contracting obligations for transfers of personal data to third parties and new profiling obligations, including in the employment context.
The below post summarizes the more notable changes.
Applicability
HB 380 reduces the law’s existing consumer applicability thresholds and adds a new applicability category.
The law now applies to persons that conduct business in Delaware or produce products or services directed to Delaware residents and that, during the preceding calendar year either (1) controlled or processed the personal data of not less than 10,000 consumers (down from 35,000), excluding personal data controlled or processed solely for the purpose of completing a payment transaction or (2) controlled or processed the personal data of not less than 5,000 consumers (down from 10,000) and derived more than 20% of their gross revenue from the sale of personal data. The 10,000-consumer threshold is approximately 0.95% of Delaware’s 1,050,000 population.
The bill also adds a new category of applicability – third parties who acquire personal data from a controller. That provision is likely to significantly expand the law’s applicability since it covers entities buying personal data.
Exemptions
The bill follows Connecticut, Minnesota, Montana, Oregon, and Vermont in narrowing the GLBA-entity level exemption. The bill also adds a handful of health-related data level exemptions.
Stricter Treatment of Sensitive Data
The bill modifies the law’s treatment of sensitive data in third ways. First, it expands the types of information that are considered sensitive data. Second, it strengthens the requirements for processing sensitive data. Finally, it creates new restrictions on the sale of sensitive data.
The bill follows the recent trend of states amending their laws to expand the definition of sensitive data. Delaware’s definition already was broad, but it was amended to include financial information, government-issued identification numbers, neural data, national origin, and more health-related information. It also was expanded to include inferences from personal data that are used to reveal or identify any category of sensitive data.
Controllers also cannot process sensitive data unless the consumer consents and the processing is reasonably necessary and proportionate to the disclosed purposes for processing sensitive data. Previously, consent alone was sufficient.
The bill also provides that controllers cannot sell sensitive data unless five conditions are met: (1) the disclosure “is strictly necessary to provide or maintain a product or service affirmatively requested by the consumer to whom the sensitive data pertains; (2) prior to the sale, the controller provides a clear and conspicuous notice of the sale to the consumer, which notice must include the specific categories of sensitive data to be disclosed, the purpose of the disclosure, and identifies the third parties to which sensitive data will be disclosed; (3) the controller obtains the consumer’s consent; (4) the controller maintains a record of the consumer’s consent for a period of 5 years; and (5) the record of consent must be provided with any data protection assessment produced under the law.
Expanded Consumer Rights
The bill expands consumer rights in two ways.
First, consumers now have a right to access inferences derived from personal data and whether a controller or processor is processing a consumer’s personal data for the purpose of profiling to make a decision that produces any legal or similarly significant effect concerning the consumer.
Second, the bill modifies Delaware’s existing right for consumers to obtain a list of categories of third parties to whom the controller has disclosed the consumer’s personal data. The law removes the reference to categories – such that consumers can now obtain a list of third parties, which is how states like Connecticut, Minnesota, and Oregon do it. As with those other states, a controller can produce a list of all third parties to whom it transfers personal data if it cannot compile a list specific to the consumer with reasonable effort.
Finally, in line with the recent trend, controllers will not be required to produce sensitive information (such as Social Security numbers) in response to an access request.
New Duties and Contractual Requirements for Third Parties
Under the current state consumer data privacy laws, only California requires companies to enter into contracts when transferring personal data to third parties. The other laws only require contracts for controller/processor data transfers. Delaware’s bill addresses that issue by requiring controllers to enter into data processing agreements when transferring personal data to third parties. For the most part, Delaware’s amendment tracks the same requirements found in CCPA Regulation 7053 (Contract Requirements for Third Parties) although the law creates a stronger due diligence requirement. For example, the law specifically requires reasonable diligence of a third party to include the use of questionnaires and review of relevant documents of the third party. In a press release, the bill sponsors call this “a first of its kind due diligence obligation that would require controllers to make sure that any third-party they sell or disclose our data to are properly and securely handling that information.”
Separately, the bill creates a new “duties of third parties” section. That section requires third parties that receive personal data from controllers or processors without a contract to not further process the personal data. It also requires third parties to abide by the terms of the required contract, to provide the necessary information for controllers to conduct data protection impact assessments and due diligence, and to generally comply with the data privacy law.
Data Minimization
The bill modifies the law’s data minimization requirement to now provide that a controller must (1) limit the processing of personal data to what is reasonably necessary and proportional in relation to the purposes for which such data is processed, as disclosed to the consumer and (2) except as otherwise permitted by the law, not process personal data for any additional purpose that is not reasonably necessary and proportionate to the disclosed purpose for which such personal data is processed, as disclosed to the consumer at the time of collection, unless the consumer consents. This new language drew criticism from privacy advocates, arguing it is insufficient to protect consumers.
New Profiling Requirements
Profiling Reports and Consumer Rights
The bill requires controllers disclosing a “report” to third parties used in “connection with any decision that produces legal or similarly significant effects concerning a resident” to comply with certain obligations as discussed below. The bill broadens the law’s definition of legally significant effects to apply to decisions made by any entity (not just controllers) that result in the provision or denial of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunities, health-care services, or access to essential goods or services.
Notably, this section of the bill uses the term “resident” and not consumer. Resident is defined as “any natural person residing in” Delaware. The term is broader than “consumer,” which excludes individuals acting in an employment context.
“Report” is defined broadly to mean “any written, oral, or other communication of any personal data by a controller or processor, including recommendations, summaries, or automated decisions based on personal data or profiling.” As noted, the disclosure of the report must be made from a controller to a third party. Therefore, this would not apply in a controller/processor context.
Controllers disclosing reports must (1) enter into contractual agreements as discussed above; (2) provide notice to a resident of any adverse action that is based in whole or in part on any information contained in the report; (3) provide a description of the personal data relied upon in making the adverse action; (4) include a statement that the resident may obtain the information described below from the controller with appropriate contact information for the controller; and (5) include a statement that the resident may request that the third party, where technically feasible, perform a human review of the adverse action concerning the resident, unless providing the opportunity for review is not in the best interest of the resident, including instances in which any delay might pose a risk to the life or safety of the resident.
The law defines “adverse action” as “any denial, cancellation, unfavorable change, increase in charge, exclusion of benefit, or other action adverse to the interests of a consumer or resident in connection with a decision that produces legal or similarly significant effects.”
In addition to the above requirements, controllers must – upon request from a resident and within 30 days, provide (1) personal data maintained by the controller concerning the resident at the time of the request; (2) the source of the personal data used in profiling; (3) identification of all third parties who obtained a report concerning the resident within the previous 24-months; and (4) an opportunity to correct any incorrect personal data.
This section specifically excludes controllers and third parties when the report or personal data consists of a score, a model, an algorithm, or similar output that is a consumer report, or would be a consumer report if furnished to a third party and is furnished or disclosed in compliance with the FCRA.
Data Protection Impact Assessments
In addition, controllers that engage in profiling in furtherance of automated decisions that produce legal or similarly significant effects concerning a consumer (not resident) must conduct impact assessments. The assessments must include: (1) a statement by the controller disclosing the purpose, intended use cases, deployment context of, and benefits afforded by, such profiling; (2) an analysis of whether profiling poses any known or reasonably foreseeable heightened risk of harm to a consumer, and, if so, a description of (a) the nature of the heightened risk of harm to a consumer and (b) the steps that have been taken to mitigate the heightened risk of harm to a consumer; (3) a description of the main categories of personal data processed as inputs for the purposes of profiling and the outputs the profiling produces; (4) an overview of the main categories of personal data the controller used to customize profiling, if the controller used personal data to customize profiling; (5) any metrics used to evaluate the performance and known limitations of profiling; (6) a description of any transparency measures taken concerning the use of profiling, including any measures taken to disclose to consumers that the controller is engaged in profiling while the controller is engaged in profiling; and (7) a description of the post-deployment monitoring and user safeguards provided concerning profiling, including the oversight, use, and learning processes established by the controller to address issues arising from profiling.
Effective Date
The amendments go into effect January 1, 2027.

