Delaware Gov. Matt Meyer recently signed into law House Bill 380, which amends the Delaware Personal Data Privacy Act (DPDPA) that was enacted in 2023. The amendments, some of which are described below, will go into effect on Jan. 1, 2027.
APPLICABILITY THRESHOLDS LOWERED
Originally, the Act applied to persons conducting business in Delaware or producing products or services targeting residents who:
- Controlled or processed the personal data of not less than 35,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or
- Controlled or processed the personal data of not less than 10,000 consumers and derived more than 20 percent of their gross revenue from the sale of personal data.
The amendments reduce the number of consumers in paragraph one to 10,000, and the number of consumers in paragraph two to 5,000. Additionally, the Act will now apply to “third parties who acquire personal data from a controller.”
ENTITY-LEVEL GLBA EXEMPTION REMOVED
The Act originally provided an exemption for financial institutions or affiliates subject to the Gramm-Leach-Bliley Act (GLBA), and separately exempted data subject to the GLBA. The amendments remove the entity-level GLBA exemption and create a new exemption for banks, credit unions, and savings associations. The data-level GLBA exemption remains unchanged.
New exemptions are created for various insurance-related entities and agents, broker-dealers, and investment advisor representatives.
SENSITIVE DATA DEFINITION EXPANDED
“Sensitive data” is expanded to include national origin, health treatment or status, neural data, financial account information “that, alone or in combination with any required access or security code, password, or credential, would allow access to a consumer’s financial account,” and government-issued identification numbers.
CONSUMER RIGHTS EXPANDED
The current Act allows a consumer to obtain a list of categories of third parties to which a controller disclosed the consumer’s personal data. The amendments allow the consumer to receive a list of the third parties themselves to which the consumer’s personal data was disclosed unless: 1) the data is pseudonymized; 2) the controller cannot compile the list, in which case the controller must disclose all third parties with which it disclosed personal data; or 3) the listing would reveal a trade secret.
CONTRACTUAL REQUIREMENTS FOR THIRD PARTIES CREATED
The Act requires a contract between a controller and a processor to contain specific provisions. The amendments address the contracts between controllers and third parties and require that such contracts:
- Specify that the personal data is sold or disclosed by the controller only for limited and specified purposes;
- Obligate the third party to comply with the Act and provide the same level of privacy protection as the controller;
- Grant the controller rights to ensure the third party uses the personal data in a manner consistent with the controller’s obligations;
- Require the third party to notify the controller if it determines it can no longer meet its obligations under the law; and
- Grant the controller the right to take steps to stop and remediate unauthorized use of personal data.
NEW REQUIREMENTS FOR AUTOMATED DECISIONS CREATING LEGAL OR SIMILARLY SIGNIFICANT EFFECTS
Current law requires controllers to conduct data protection assessments under certain circumstances. The amendments require that a controller also conduct an impact assessment if “engaging in profiling in furtherance of automated decisions that produce legal or similarly significant effects concerning a consumer.”
Additionally, if a controller discloses a report to a third party for use “in connection with any decision that produces legal or similarly significant effects,” there must be a contract requiring the third party to:
- Provide notice to a resident of any adverse action that is based on the report;
- Provide a description of the personal data relied upon in making the adverse action;
- Include a statement that the resident may obtain certain decision-related information from the controller; and
- Include a statement that the resident may request that the third party perform a human review of the adverse action.
IMPRESSION
The amendments, not all of which are summarized above, will greatly increase the number of entities subject to the Act, and create additional compliance challenges for those already subject to it.
Photo: vasanth/stock.adobe.com

