On September 2, 2026, Delaware Governor Matt Meyer signed House Bill 380, amending the Delaware Personal Data Privacy Act(DPDPA). The changes take effect on January 1, 2027. HB 380 lowers thresholds, expands sensitive-data categories, strengthens consent requirements, and adds new rules for profiling, minors, and third parties.
Key Takeaways
- HB 380 takes effect January 1, 2027 and lowers the DPDPA’s general applicability threshold from 35,000 to 10,000 consumers.
- Processing sensitive data will require consent plus a reasonably necessary and proportionate connection to the disclosed purpose.
- New rules affect targeted advertising, sale of personal data, profiling, minors ages 13 to 18, third-party contracts, DPIAs, and consumer disclosures.
- Readiness depends on evidence, including consent records, named third-party data, processing purposes, profiling assessments, and anti-bias testing documentation.
More Organizations and Third Parties Fall Within Scope
HB 380 lowers the general applicability threshold from 35,000 to 10,000 consumers. The sale-based threshold drops from 10,000 to 5,000 consumers where at least 20% of gross revenue comes from personal data sales.
Third parties that acquire personal data from a controller subject to the DPDPA are now subject to the DPDPA's provisions.
The amendments also extend obligations to third parties acquiring personal data and narrow the GLBA entity-level exemption to specified financial institutions and affiliates.
Organizations previously outside the DPDPA should reassess whether they fall within scope.
Sensitive Data Consent Becomes More Specific
HB 380 expands the definition of sensitive data to include pregnancy status, transgender or nonbinary status, citizenship or immigration status, neural data, financial account login credentials, specified government-issued identification numbers, and sensitive inferences.
Controllers must obtain consent before processing sensitive data, and the processing must be reasonably necessary and proportionate to the purpose disclosed to the consumer.
For example, if a service collects sensitive information for account security, then reuses it for personalization, the later use needs assessment against the disclosed purpose and the necessity and proportionality standard.
Selling Sensitive Data Adds Notice, Consent, and Five-Year Evidence
HB 380 creates a separate regime for selling sensitive data. Before a sale, the disclosure must be strictly necessary to provide or maintain a product or service affirmatively requested by the consumer.
The controller must provide clear and conspicuous notice identifying the sensitive-data categories, disclosure purpose, and third parties receiving it, then obtain consent.
The consent record must be retained for five years and provided with relevant Data Protection Impact Assessment (DPIA) documentation.
Consent programs therefore need to distinguish consent to process sensitive data from consent to sell it, connect the choice to named recipients and purpose, and preserve proof after the interaction.
Teen Privacy Requires a Separate Consent Path
HB 380 adds specific protection for consumers ages 13 through 18. Where a controller has actual knowledge, or willfully disregards, that a consumer falls within this age range, consent is required before using personal data for targeted advertising, sale, or profiling that supports automated decisions producing legal or similarly significant effects.
For example, if a known 16-year-old declines targeted advertising, recording that choice in the interface addresses only the first step. Advertising and data-sharing workflows also need to honor the restriction.
Profiling Governance Moves Toward Ongoing Evidence
For covered profiling tied to automated decisions producing legal or similarly significant effects, controllers processing at least 50,000 consumers annually, down from 100,000 consumers, must regularly document a DPIA
The assessment must cover intended uses, deployment context, foreseeable harms, data inputs and outputs, performance, limitations, transparency, monitoring, and safeguards.
HB 380 also makes evidence of proactive anti-bias testing in profiling relevant to claims and defenses. The quality, efficacy, recency, scope, results, and organizational response matter. The absence of any proactive anti-bias testing is also considered relevant.
Third-Party Relationships Need More Precision
HB 380 introduces contractual and due-diligence requirements where controllers disclose personal data to third parties, including for sale or targeted advertising.
Contracts must specify limited purposes, require DPDPA-level protection, preserve controller oversight and remediation rights, and require notification by the third party when the third party no longer meets its obligations. Controllers also face reasonable due-diligence duties before entering a relationship with third parties that is scaled to data sensitivity.
Processor contracts face a related change: each processing purpose must be described with specificity and particularity, rather than with generic references to the contract itself
Consumers Gain Greater Visibility Into Named Third Parties
HB 380 gives consumers a right to obtain a named list of third parties to which the controller disclosed their personal data, subject to limited exceptions.
A privacy rights workflow therefore needs current disclosure records and enough data lineage to identify relevant recipients or, where compiling the list requires unreasonable effort, provide the entire list of named third parties
This raises an operational issue that reaches across consent, vendor governance, and privacy rights. If a consumer’s data flows to multiple advertising or analytics partners, teams need enough visibility to identify the relevant recipients when the request arrives.
What Organizations Should Prioritize Before January 1, 2027
Start by reassessing scope under the lower thresholds and the expanded definition of sensitive data. Map sensitive data processing, targeted advertising, sale, teen data, and profiling to the consent and preference experiences that govern them. Check whether records preserve the purpose, data category, recipient, timestamp, and five-year evidence required for consent to sensitive data sales.
Next, connect third-party inventories with contracts and consumer-rights workflows. Profiling programs should identify systems meeting the DPIA threshold and where anti-bias testing, monitoring, and remediation evidence sits.
These changes span consent, privacy operations, third-party governance, and AI governance. Connected controls help keep choices, processing, and evidence aligned.
For a step-by-step readiness exercise across these requirements, download the Delaware DPDPA Readiness Checklist: Preparing for HB 380.
Explore OneTrust Consent & Preferences to review how consent and preference signals are managed across digital experiences.
Explore OneTrust Privacy Automation to see how privacy teams connect processing inventories, assessments, rights workflows, and compliance evidence.
Key Questions About the 2027 DPDPA Amendments