Delaware Amends Personal Data Privacy Act: Lower Thresholds, Neural Data, and Third-Party Rules

Governor Matt Meyer has signed House Bill 380 into law, enacting substantial revisions to the Delaware Personal Data Privacy Act (DPDPA). The amendments lower the law's applicability threshold to 10,000 consumers, classify neural data and financial credentials as sensitive information, and impose direct compliance duties on third parties that buy or receive consumer records.
The legislation passed the Delaware General Assembly with bipartisan support and received executive signature on September 2, 2026. The revised statute takes effect on January 1, 2027, the same date the state's baseline privacy framework begins general operation.
HB 380 amends Title 6, Chapter 12D of the Delaware Code. By reducing the consumer volume threshold from 35,000 to 10,000, Delaware now has the lowest population-based applicability threshold among comprehensive state privacy statutes in the United States.
Lower Applicability Thresholds (Section 12D-103)
Under the original DPDPA enacted in 2023, businesses had to control or process the personal data of at least 35,000 Delaware consumers (or 10,000 consumers if deriving more than 20 percent of gross revenue from data sales) to trigger compliance obligations.
HB 380 replaces those numbers under Section 12D-103(a):
- Standard Business Threshold (Section 12D-103(a)(1)): The threshold drops from 35,000 to 10,000 consumers whose personal data was controlled or processed during the preceding calendar year, excluding data processed solely to complete a payment transaction.
- Data Broker and Sales Threshold (Section 12D-103(a)(2)): The threshold drops from 10,000 to 5,000 consumers for entities that derive more than 20 percent of their gross revenue from selling personal data.
- Direct Inclusion of Third Parties (Section 12D-103(a)(3)): The statute explicitly brings third parties that acquire personal data from a controller directly under the scope of the Act.
Expanded Categories of Sensitive Data (Section 12D-102)
The amended statute expands Delaware's definition of sensitive data, requiring controllers to obtain affirmative consumer consent before processing:
- Neural Data (Section 12D-102): Information generated by measuring the electrical, magnetic, or physical activity of an individual's central nervous system.
- Financial Account Credentials (Section 12D-102): A consumer's financial account number, login username, credit card number, or debit card number in combination with any required security code, password, or access credential.
- Government Identification Numbers (Section 12D-102): Social Security numbers, passport numbers, driver's license numbers, and state identification card numbers that are not required by law to be publicly displayed.
- Health and Medical Status (Section 12D-102): Broadens physical or mental health diagnoses to include treatment, health status, pregnancy, and reproductive health records.
Section 12D-106(a)(12) prohibits controllers from selling sensitive personal data unless the disclosure is strictly necessary to provide a product or service affirmatively requested by the consumer, accompanied by clear and conspicuous notice, and supported by affirmative opt-in consent.
Direct Obligations and Due Diligence for Third Parties
HB 380 introduces statutory requirements for data vendors, advertising networks, and processors:
Controller Due Diligence (Section 12D-106(a)(11))
Controllers must conduct documented due diligence of third parties to whom they disclose or sell personal data. At a minimum, this diligence requires administering questionnaires and reviewing vendor compliance documentation. The rigor of the assessment must correspond to the sensitivity of the underlying data.
Third-Party Cooperation (Section 12D-107)
Third parties that acquire consumer data must provide all information necessary to enable the original controller to complete statutory data protection assessments. Under Section 12D-107(e), any third party qualifying under the applicability thresholds must comply directly with every obligation in the chapter.
Profiling and Automated Decision Assessments (Section 12D-108)
Controllers that profile consumers for automated decisions that produce legal or similarly significant effects must complete regular impact assessments under Section 12D-108(a)(2). These assessments must document:
- The specific purpose, intended deployment context, and business benefits of the profiling system.
- An evaluation of foreseeable harms to consumers and the specific technical safeguards taken to mitigate those risks.
- The input data categories and resulting automated outputs.
- Performance metrics, error rates, and known algorithmic limitations.
- Active transparency measures that inform consumers when profiling occurs.
- Post-deployment monitoring procedures and human oversight controls.
Enforcement and Cure Periods (Section 12D-111)
The Delaware Department of Justice retains exclusive enforcement authority over the Act. Violations constitute unlawful practices under Delaware consumer protection statutes (6 Del. C. Section 2513).
Under Section 12D-111(c), the Department of Justice exercises discretion over whether to grant a 60-day cure period for alleged non-compliance, evaluating the controller's past conduct, the sensitivity of the data, and whether the violation was corrected upon discovery.
Key Changes: Original DPDPA vs. Amended HB 380
| Statutory Dimension | Original DPDPA (Enacted 2023) | Amended by HB 380 (Effective Jan 1, 2027) |
|---|---|---|
| Standard Threshold | 35,000 Delaware consumers | 10,000 Delaware consumers |
| Data Sales Threshold | 10,000 consumers and >20% revenue | 5,000 consumers and >20% revenue |
| Third-Party Coverage | Contractual obligations governed by controller agreements | Direct statutory applicability under Section 12D-103(a)(3) |
| Neural Data | Unaddressed | Classified as sensitive data requiring opt-in consent |
| Account Credentials | Regulated under separate data breach notification statutes | Integrated directly into DPDPA sensitive data protections |
| Vendor Due Diligence | Standard vendor contracts required | Mandatory questionnaires and documentation reviews (Section 12D-106(a)(11)) |
| Sensitive Data Sales | Opt-out consent allowed under standard sales rules | Strictly prohibited unless affirmatively requested by consumer (Section 12D-106(a)(12)) |
Official Sources
- Delaware General Assembly Bill Detail (HB 380): legis.delaware.gov/BillDetail/143105
- House Amendment No. 2 to HB 380: legis.delaware.gov/json/BillDetail/GenerateHtmlDocumentEngrossment?engrossmentId=37933&docTypeId=6
- Delaware Personal Data Privacy Act (Title 6, Chapter 12D): delcode.delaware.gov/title6/c012d/index.html