Delaware Signs HB 380: DPDPA Privacy Overhaul Effective 2027

Independently fact-checkedBy Recording Law Editorial Team27 min read

Independently fact-checked against primary sources (last audited September 5, 2026). · 7 primary sources cited on this page. How we verify our legal content

Delaware Signs HB 380: DPDPA Privacy Overhaul Effective 2027

Frequently Asked Questions

When does Delaware House Bill 380 take effect?

January 1, 2027. Section 2 of the act sets that date, and the General Assembly's bill detail page lists the same effective date. Governor Matt Meyer signed the bill on September 2, 2026, but signing and effectiveness are separate dates here. Until January 1, 2027 the Delaware Personal Data Privacy Act as currently codified at Chapter 12D of Title 6 is the operative law.

What is the new DPDPA applicability threshold?

From January 1, 2027 the chapter applies to a business that conducts business in Delaware or targets products or services to Delaware residents and, in the preceding calendar year, controlled or processed the personal data of at least 10,000 consumers, excluding data processed solely to complete a payment transaction. The current figure is 35,000. A second trigger drops from 10,000 to 5,000 consumers where more than 20 percent of gross revenue comes from selling personal data, and a third trigger is added for third parties who acquire personal data from a controller, with no number attached.

Does the amended DPDPA create a private right of action?

No. Section 12D-111(d) provides that nothing in the chapter shall be construed as providing the basis for, or be subject to, a private right of action, and House Bill 380 does not amend that subsection. Section 12D-111(e), as amended, still provides that violations are enforced solely by the Delaware Department of Justice.

Is neural data protected under Delaware law?

It becomes sensitive data on January 1, 2027. The bill inserts a category covering neural data that is generated by measuring the activity of an individual's central nervous system. As sensitive data, processing it will require the consumer's consent and must also be reasonably necessary and proportionate to the disclosed purposes for processing sensitive data.

Does the amendment cover employee and job applicant data?

Partly. The exclusion for data processed in the course of applying to, being employed by, or acting as an agent or contractor of a business remains, but the amendment appends an exception for personal data processed in connection with profiling and reports under Section 12D-106(f). Ordinary employment administration stays outside the chapter; data feeding profiling or a report used in a decision with legal or similarly significant effects does not.

What does the new adverse action provision require?

Where a controller discloses a report to a third party for use in a decision producing legal or similarly significant effects concerning a Delaware resident, it must contract with that third party to require notice of any adverse action based in whole or in part on the report, a description of the personal data relied on, information about obtaining more from the controller, and a statement that the resident may ask for a human review where technically feasible. On request, the controller must provide within 30 days the personal data it holds, the source of data used in profiling, and every third party that obtained a report about the resident in the previous 24 months. It does not apply to output that is a consumer report furnished in compliance with the federal Fair Credit Reporting Act.

Does House Bill 380 change the profiling opt-out?

Yes. The current opt-out at Section 12D-104(a)(6)c. covers profiling in furtherance of solely-automated decisions that produce legal or similarly significant effects. The bill strikes solely-automated and inserts automated, so from January 1, 2027 the opt-out reaches automated consequential decisions even where a human is involved in the process.

Do banks and financial companies still get an exemption?

The entity exemption narrows. The broad exemption for any financial institution subject to Title V of the Gramm-Leach-Bliley Act is struck and replaced with narrower ones for insurers and insurance-related entities, chartered banks, credit unions and savings associations, and agents, broker-dealers and investment advisers regulated by the Delaware Investor Protection Unit or the Securities and Exchange Commission, plus certain affiliates. The separate data-level exemption for data subject to Title V of Gramm-Leach-Bliley at Section 12D-103(c)(14) is unchanged.

What is House Bill 381 and was it also signed?

Yes. House Bill 381 is a companion measure amending Chapter 12B of Title 6, Delaware's computer security breach chapter. Its bill detail page records it as signed on September 2, 2026, assigned Chapter 464 of Volume 85 of the Laws of Delaware, with an effective date of September 2, 2026, so it took effect on signature. Its official synopsis says it clarifies when businesses must provide notice of a computer security breach to the Attorney General.

Updates

Independently fact-checked against the cited primary sources

Sources and References

  1. Delaware General Assembly, House Bill 380, 153rd General Assembly, bill detail page (status "Signed 9/2/26"; Laws of Delaware Volume:Chapter 85:463; Governor's Advisory Number 57; Effective Date 1/1/27; introduced 4/16/26; primary sponsor Rep. Griffith).(legis.delaware.gov).gov
  2. Delaware General Assembly, House Bill No. 380 as amended by House Amendment No. 2, engrossed text (amending 6 Del. C. §§ 12D-102 through 12D-111; § 12D-103(a)(1) threshold struck from 35,000 and inserted as 10,000; new § 12D-106(f) report and adverse-action duties; Section 2, effective January 1, 2027).(legis.delaware.gov).gov
  3. Delaware General Assembly, House Bill 380 as introduced, full text with synopsis (operative text strikes 35,000 and inserts 10,000; synopsis prose refers to a threshold of 15,000 consumers).(legis.delaware.gov).gov
  4. Delaware Code Online, Title 6, Chapter 12D, Delaware Personal Data Privacy Act, as currently codified (§ 12D-102(30) sensitive data; § 12D-103(a) 35,000 and 10,000 thresholds; § 12D-103(b)(2) and (c)(14) Gramm-Leach-Bliley exemptions; § 12D-104(a)(5) categories of third parties; § 12D-108(a) 100,000 threshold; § 12D-111(b), (d) and (e) enforcement and no private right of action).(delcode.delaware.gov).gov
  5. Office of the Governor of Delaware, "Governor Meyer Signed Historic Data Privacy Legislation, Protecting Delaware Residents and Businesses," September 2, 2026 (two bills signed; "lowest threshold in the nation" at 10,000 consumers; quotes from Governor Meyer, Attorney General Jennings and Rep. Griffith; narrowing of the employee-data exclusion).(news.delaware.gov).gov
  6. Delaware General Assembly, House Bill 381, 153rd General Assembly, bill detail page (status "Signed 9/2/26"; Laws of Delaware 85:464; Effective Date 9/2/26; long title relating to computer security breaches).(legis.delaware.gov).gov
  7. Delaware General Assembly, House Bill 381 full text (amending 6 Del. C. §§ 12B-101, 12B-102(c)(3) and 12B-103(b) on notice of a breach of security to the Attorney General).(legis.delaware.gov).gov
Share: