Updating the Delaware Personal Data Privacy Act: The “First State” Becomes the Latest to Get a Privacy Refresh
Delaware has become the latest state to update its comprehensive privacy law after Governor Meyer signed HB 380 on September 2, amending the Delaware Personal Data Privacy Act (DPDPA). More than half of the 23 states with comprehensive privacy laws have now amended their laws. The bill makes significant revisions to the DPDPA, including—
- An expanded definition of sensitive data;
- Lowered applicability thresholds;
- New contractual and novel due diligence requirements for disclosing personal data to third parties;
- Additional contractual requirements and rights for disclosing “reports” to third parties used in profiling decisions made about “residents,” rather than “consumers,” and extending to employee data;
- Adding and modifying consumer rights; and more.
These changes will take effect January 1, 2027.
Definitions & Scope
Changes to key definitions track trends in other states. For example, HB 380 narrows the definition of “publicly available information” to exclude biometric data that was collected without the consumer’s consent. “Sensitive data” is similarly broadened to explicitly include “inferences” that reveal sensitive data categories. This bill also adds new categories of sensitive data, including national origin, medical treatment or status (in addition to diagnosis), treatment as transgender or nonbinary (in addition to “status” as such), neural data, financial account information, and government-issued identification numbers. (§ 12D-102)
This bill also lowers the law’s applicability threshold and tightens entity-level exemptions, consistent with other legislative trends from recent years. The law will now apply to any person that, in the past calendar year, controlled or processed the personal data of at least (1) 10,000 Delaware consumers (excluding data processed solely for completing payment transactions) or (2) 5,000 Delaware consumers if the person derived more than 20% of their gross revenue from the sale of personal data. These figures are down from 35,000 and 10,000 in the original law. This bill also expands the law’s scope to include “[t]hird parties who acquire personal data from a controller.” (§§ 12D-103(a), 12D-107A)
Finally, consistent with yet another legislative trend, this bill removes the law’s GLBA-entity level exemption and replaces it with several tailored exemptions for the insurance, banking, and investment industries. The bill also adds new health-related data-level exemptions, including for information in a limited data set subject to protection under 45 CFR § 164.514(e). (§ 12D-103(b)-(c))
Due Diligence for Data Sales
This bill includes new contractual requirements for disclosing personal data to third parties. The contract must specify that the personal data is disclosed only for limited and specified purposes; obligate the third party to comply with the DPDPA’s requirements; grant the controller rights to take “reasonable and appropriate steps to ensure that the third party uses the personal data . . . in a manner consistent with the controller’s obligations under [the DPDPA]”; require the third party to notify the controller if it determines that it can no longer meet its obligations under the DPDPA; and grant the controller the right, upon notice, “to take reasonable and appropriate steps to stop and remediate unauthorized use of personal data.” (§ 12D-106(a)(10))
The controller is required to conduct reasonable due diligence of third party recipients of personal data to assess the recipient’s policies and technical and organizational measures undertaken to comply with the DPDPA. This due diligence must include the use of questionnaires and review of relevant documents, and additional reasonable measures should be taken as commensurate with the sensitivity of the data disclosed. A controller is further prohibited from selling sensitive data unless the disclosure of that data is strictly necessary to provide or maintain a product or service affirmatively requested by the consumer, the controller provides clear and conspicuous notice prior to the sale, the consumer consents to the disclosure, and the controller maintains a record of consent for 5 years. These new consent records must be provided alongside data protection assessments pursuant to the AG’s investigatory powers. (§ 12D-106(a)(11)-(12))
These requirements are similar to the CCPA’s required contracts for the sale of personal information. (See Cal. Civ. Code § 1798.100, subd. (d); CCPA Rules § 7053) Delaware’s requirements may be slightly broader, however, as they apply to the “disclosure” of personal data, “including in a sale of personal data or for targeted advertising.” The more significant difference is Delaware’s novel due diligence requirements, which are not typically seen in other laws.
These new requirements also apply when the disclosure of personal data to a third party is necessary for providing a product or service requested by a consumer (which would otherwise be exempt from the definition of “sale”). (§ 12D-102)
Profiling, Reports, and Adverse Actions
In recent years, various states have introduced heightened protections and rights for consumers with respect to profiling in furtherance of decisions that produce legal or similarly significant effects concerning a consumer (“significant decisions”). Minnesota’s law, for example, includes a broad right to contest adverse profiling decisions. Connecticut’s and Vermont’s laws have a slightly narrowed version that limits aspects of the right to only decisions concerning housing.
Delaware has taken a different approach. Under the amended DPDPA, a controller will have new obligations prior to and after disclosing a report to any third party for use in connection with any significant decision concerning a resident. Key definitions:
- “‘Adverse action’ means any denial, cancellation, unfavorable change, increase in charge, exclusion of benefit, or other action adverse to the interests of a consumer or resident in connection with a decision that produces legal or similarly significant effects.”
- “‘Decisions that produce legal or similarly significant effects’ means decisions that result in the provision or denial of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunities, health-care services, or access to essential goods or services.”
- “‘Report’ means any written, oral, or other communication of any personal data by a controller or processor, including recommendations, summaries, or automated decisions based on personal data or profiling.”
- “‘Resident’ means any natural person residing in the State.” (§ 12D-102)
Prior to disclosing a report to a third party for use in connection with a significant decision concerning a resident, the controller must enter into a contractual agreement with the third party that imposes a number of obligations. Under this required contract, a third party must provide notice to a resident of any adverse action based in whole or in part on any information in the report; provide a description of personal data relied upon in making the adverse action; include a statement that the resident has a right to obtain certain information from the controller, with the controller’s contact information; and include a statement that the resident has a right to request the third party perform a human review of the adverse action, provided that the review must be “technically feasible” and the third party does not have to offer the review if doing so is “not in the best interest of the resident” (e.g., where delay poses a risk to the resident’s life or safety). The required contract between a controller and third party for disclosing a report is “in addition to” the bill’s other new contractual requirement for disclosing personal data to a third party. (§ 12D-106(f)(1))
Apart from entering that contract with a third party prior to disclosing a report, a controller must comply with special access and correction rights for consumers. For the access request, a controller has 30 days to provide a resident with the personal data maintained by the controller concerning the resident, the source of personal data used in profiling, and identification of all third parties who obtained a report concerning the resident in the past 24 months. The controller must also provide the resident with an opportunity to correct any incorrect personal data, although there is no timeline specified for this right. (§ 12D-106(f)(2), (3))
These new requirements apply more broadly than the rest of the law, extending to employment contexts. HB 380 narrowed the law’s data-level exemption for data processed or maintained in “the course of an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party,” providing that the exception now does not apply for personal data processed in connection with profiling and reports under these new requirements. While the definition of “consumer” exempts individuals acting in an employment context, these new controller duties apply to the disclosure of a report for use in connection with significant decisions concerning a “resident,” defined broadly as “a natural person residing in [Delaware].” (§§ 12D-102 & 12D-103(c)(11)(a))
Although these requirements are similar in kind to those under the Fair Credit Reporting Act (FCRA), HB 380 preserves the DPDPA’s existing FCRA exemption and clarifies that nothing in this new subsection applies to a controller or third party when the report or personal data consists of an output such as a score, model, or algorithm that is a consumer report—or would be a consumer report if furnished to a third party—and is furnished or disclosed in compliance with the FCRA. (§ 12D-106(g))
New & Modified Consumer Rights
This bill modifies the DPDPA’s consumer rights in several ways, all of which are similar to changes other states have previously made to their respective laws:
- The right to access now explicitly includes inferences about the consumer that are derived from personal data and information about whether the consumer’s personal data is being processed for profiling to make a significant decision. The right to access is also narrowed to prohibit a controller from disclosing certain types of information to a consumer—SSNs, government-issued ID numbers, financial account numbers, health insurance and medical ID numbers, account passwords, security questions or answers, and biometric data. Rather, a controller must inform the consumer “with sufficient particularity” that the controller processes any of these types of data.
- The right to know third-party recipients of one’s personal data is modified by HB 380. A consumer now has the right to obtain a list of third parties to which the controller disclosed the consumer’s personal data, not merely the categories of such third parties. However, the right no longer applies to pseudonymous data; does not require a controller to list a third party if doing so would reveal a trade secret; and the controller can provide a list of all third-party recipients of personal data rather than a list tailored to the consumer if compiling an individualized list cannot be done with “reasonable effort.”
- The right to opt out of profiling is expanded to apply to profiling in furtherance of “automated decisions” that produce legal or similarly significant effects, rather than “solely automated decisions.” (§ 12D-104)
Additional Changes
This bill makes a number of additional changes to the law, including—
- Requiring a controller to limit the processing of personal data to what is “reasonably necessary and proportional” in relation to the purposes for which the data is processed, as disclosed to the consumer;
- For sensitive data, adding a dual requirement that processing must be pursuant to consent and must be reasonably necessary and proportionate to the disclosed processing purposes;
- Adding bias-testing language to the prohibition on processing or profiling in violation of antidiscrimination law;
- Expanding the teenager opt-in requirement to include profiling in addition to targeted advertising and the sale of personal data;
- Adding a link for consumers to exercise their data rights to applications, not just websites;
- Adding more specificity to the required controller-processor contract;
- Modifying data protection assessment requirements (which only apply to controllers that process the data of at least 50,000 consumers) and adding new impact assessments for profiling that must be conducted “on a regular basis”;
- Requiring that a controller or processor undertake reasonable diligence and oversight to ensure compliance with contractual commitments if that entity wants to benefit from the safe harbor from liability for violations of the DPDPA by a processor or third-party controller that received personal data from the entity; and more.
Many of these changes are similar to those Connecticut made to the CTDPA in 2025.