Delaware Signs HB 380: DPDPA Privacy Overhaul Effective 2027
Independently fact-checked against primary sources (last audited September 5, 2026). · 7 primary sources cited on this page. How we verify our legal content

Delaware Signs HB 380: DPDPA Privacy Overhaul Effective 2027
Delaware Governor Matt Meyer signed House Bill 380 on September 2, 2026, rewriting the Delaware Personal Data Privacy Act. The law cuts the coverage threshold from 35,000 consumers to 10,000, expands sensitive data to include neural data, and takes effect January 1, 2027.
Information last verified on September 5, 2026.
Status: House Bill 380 of the 153rd General Assembly, as amended by House Amendment No. 2, was signed on September 2, 2026 and assigned Chapter 463 of Volume 85 of the Laws of Delaware. Its effective date is January 1, 2027. Until that date, the Delaware Personal Data Privacy Act as currently codified at Chapter 12D of Title 6 of the Delaware Code remains the operative law, unchanged.
Jurisdiction: This article describes Delaware law only. House Bill 380 amends the Delaware Personal Data Privacy Act at Chapter 12D of Title 6 of the Delaware Code. It is not the California Consumer Privacy Act, and it does not change the privacy statute of any other state or any federal privacy law.
What Happened
On September 2, 2026, Governor Matt Meyer signed House Bill 380, an act to amend Title 6 of the Delaware Code relating to personal data privacy. The Delaware General Assembly's bill detail page records the status line as signed on September 2, 2026, assigns the act to Volume 85, Chapter 463 of the Laws of Delaware, gives it Governor's Advisory Number 57, and lists an effective date of January 1, 2027 with no sunset date.
The bill was introduced on April 16, 2026 by Representative Krista Griffith, with Senator Marie Pinkney among the additional sponsors and a long list of House and Senate co-sponsors. The version that became law is the engrossed text, described on its face as House Bill No. 380 as amended by House Amendment No. 2. The General Assembly's fiscal note field reads "Not Required."
Governor Meyer signed a second privacy measure the same day. House Bill 381 amends Chapter 12B of Title 6, Delaware's computer security breach chapter, and is recorded on its own bill detail page as signed on September 2, 2026, assigned Chapter 464 of Volume 85, with an effective date of September 2, 2026. That bill took effect immediately on signature; House Bill 380 did not.
The Governor's office announced the two bills together, describing them as creating "the broadest data protections in the country." The announcement states that the package sets "the lowest threshold in the nation," under which a company handling the data of 10,000 consumers falls within the law. That comparative claim is the Governor's office's characterization; this article does not independently rank Delaware's threshold against every other state comprehensive privacy statute.
What the Law Actually Says
The Delaware Personal Data Privacy Act, enacted in 2023 as 84 Del. Laws c. 197, currently reaches a business that conducts business in Delaware or targets products or services to Delaware residents and, in the preceding calendar year, controlled or processed the personal data of at least 35,000 consumers, or of at least 10,000 consumers while deriving more than 20 percent of gross revenue from selling personal data. That remains the law through December 31, 2026. Our plain-language explainer of how the DPDPA works right now describes the statute as currently codified, not the version that arrives on January 1, 2027.
Everything below is the text that survives in the engrossed bill, meaning existing language the bill leaves alone plus language it inserts. Where the bill deletes language, that is said explicitly.
Definitions in Section 12D-102
Sensitive data gets a new opening clause and three new categories. It will read "personal data that includes any of the following, and includes inferences made based on personal data, alone or in combination with other data, that are used to reveal or identify any of the following." That inference clause is new: a conclusion drawn about a person becomes sensitive when it is used to reveal or identify a listed attribute, not just the underlying data.
The first listed category is rewritten. It currently reads "Data revealing racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis (including pregnancy), sex life, sexual orientation, status as transgender or nonbinary, citizenship status, or immigration status." On January 1, 2027 it reads "Data that reveals or identifies racial, national, or ethnic origin, religious beliefs, mental or physical health condition, diagnosis, treatment, or status (including pregnancy), sex life, sexual orientation, treatment or status as transgender or nonbinary, citizenship status, or immigration status." National origin is added, treatment and status join health condition and diagnosis, and treatment status is added alongside status as transgender or nonbinary. Citizenship and immigration status were already in the 2023 statute and are carried forward, not newly added.
Three categories are inserted outright: neural data "that is generated by measuring the activity of an individual's central nervous system"; financial account numbers, account log-in information, and card numbers that, alone or in combination with any required access or security code, password, or credential, would allow access to a financial account; and government-issued identification numbers, including Social Security, passport, state identification card, and driver's license numbers, that applicable law does not require to be publicly displayed. Genetic and biometric data, personal data of a known child, and precise geolocation data stay sensitive as they are now.
Three definitions are entirely new. Adverse action means "any denial, cancellation, unfavorable change, increase in charge, exclusion of benefit, or other action adverse to the interests of a consumer or resident in connection with a decision that produces legal or similarly significant effects." Report means "any written, oral, or other communication of any personal data by a controller or processor, including recommendations, summaries, or automated decisions based on personal data or profiling," broad enough to reach a spoken communication or a bare score. Resident means "any natural person residing in the State," a wider term than consumer, which excludes individuals acting in a commercial or employment context.
The definition of decisions that produce legal or similarly significant effects is trimmed in three places. The defined term itself currently reads "decisions that produce legal or similarly significant effects concerning the consumer," and the bill drops "concerning the consumer." The body currently covers "decisions made by the controller that result in the provision or denial by the controller of" a listed benefit, and the bill strikes both instances of "by the controller." What survives is "decisions that result in the provision or denial of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunities, health-care services, or access to essential goods or services." The concept no longer depends on the controller being the decision-maker.
Publicly available information narrows: its second prong will end "and that does not include biometric data that can be associated with a specific consumer that was collected without the consumer's consent." Because personal data expressly excludes publicly available information, that will close the route by which a faceprint or voiceprint built from publicly posted material could sit outside the statute entirely. How Delaware currently handles biometric information is useful pre-amendment background.
The sale of personal data definition adds a qualifier to its product-or-service carve-out: disclosing sensitive data for monetary or other valuable consideration to a third party "must comply with § 12D-106(a)(2) of this title," the purpose-limitation provision, which as amended forbids processing for any additional purpose that is not reasonably necessary and proportionate to the purposes disclosed at the time of collection unless the controller obtains consent. Third party is redefined to exclude entities on the Section 12D-103(b) exemption list.
Consumer rights in Section 12D-104
Access expands to cover "any inferences about the consumer derived from such personal data" and whether the consumer's data is being processed for profiling to make a decision with legal or similarly significant effects. The trade secret limit on access is unchanged.
The third-party disclosure right changes in kind. Delaware currently grants a right to a list of the categories of third parties that received a consumer's data. The bill strikes "the categories of," making it a right to the third parties themselves, subject to three written exceptions: pseudonymous data; a controller that cannot compile the list with reasonable effort, which must then disclose all third parties to which it discloses personal data; and a listing that would reveal a trade secret.
The profiling opt-out drops one consequential word. It currently covers "Profiling in furtherance of solely-automated decisions that produce legal or similarly significant effects concerning the consumer." The bill strikes "solely-automated" and inserts "automated," so a human step in the workflow no longer places a decision outside the opt-out.
A new paragraph runs the other way. Section 12D-104(c)(6) bars a controller from returning, in response to an access request, a Social Security number, a driver's license or state identification card or other government-issued identification number, a financial account number, a health insurance or medical identification number, an account password, a security question or its answer, or biometric data. The controller may only state, with sufficient particularity, that it processes such data. Our summary of the rights Delaware residents can exercise today reflects the pre-amendment version.
Controller duties in Section 12D-106
Minimization moves from collection to processing, and from "adequate, relevant, and reasonably necessary" to "reasonably necessary and proportional."
Under the amendment, sensitive data takes two things rather than one. Today a controller must not process it "without obtaining the consumer's consent." The amended paragraph requires both that the consumer consents and that the processing be "reasonably necessary and proportionate to the disclosed purposes for processing sensitive data." Consent alone stops being sufficient.
Children's protection broadens from sensitive data concerning a known child to all personal data: a controller may not process a consumer's personal data where it has actual knowledge or wilfully disregards that the consumer is a child, without parental or guardian consent and compliance with Section 1204C of Title 6. The separate provision for consumers at least 13 and under 18 expands from targeted advertising and sale to every purpose listed in Section 12D-104(a)(6), pulling in profiling for automated decisions.
The anti-discrimination duty adds profiling alongside processing, plus an unusual evidentiary sentence: evidence or lack of evidence concerning proactive anti-bias testing, including its quality, efficacy, recency and scope, its results, and the response to those results, "are relevant to any claim for a violation of the laws of this State and any available defense to such claims."
Three new duties govern data leaving the controller. Binding contracts become mandatory with third parties receiving personal data, including in a sale or for targeted advertising, specifying limited purposes and whether those cover consequential decisions, obligating the third party to provide the same level of privacy protection, and giving the controller rights to verify use and to stop unauthorized use. Documented due diligence of those recipients is required, involving "at a minimum, assessing the third party through the use of questionnaires and review of relevant documents." And sensitive data may not be disclosed in a sale unless the disclosure is strictly necessary to provide or maintain a product or service the consumer affirmatively requested, the controller gives clear and conspicuous notice before the sale identifying the categories, purpose and recipients, the consumer consents, and the controller keeps that consent record for five years.
Privacy notices must be "reasonably particular to the product or service offered to the consumer," identify the controller, and describe the rights in Section 12D-104(a). The opt-out link requirement extends from a website to a website "or application," and covers every purpose in Section 12D-104(a)(6) rather than only targeted advertising and sale.
The report and adverse-action regime at 12D-106(f)
This is the longest new block in the bill. A controller that discloses to any third party a report for use in a decision producing legal or similarly significant effects concerning a resident must contract with that third party to require it to give the resident notice of any adverse action based in whole or in part on information in the report, a description of the personal data relied on, a statement that further information is available from the controller with its contact details, and a statement that the resident may ask the third party, where technically feasible, to perform a human review of the adverse action, unless review is not in the resident's best interest, including where delay might risk the resident's life or safety.
Separately, on a resident's request, the controller must within 30 days provide the personal data it maintains about that resident at the time of the request, the source of the personal data used in profiling, and identification of all third parties that obtained a report concerning the resident within the previous 24 months. It must also give the resident an opportunity to correct incorrect personal data.
Subsection (g) then carves all of that out where the report or personal data "consists of a score, a model, an algorithm, or similar output that is a consumer report, or would be a consumer report if furnished to a third party," and is furnished or disclosed in compliance with the federal Fair Credit Reporting Act, 15 U.S.C. Section 1681 et seq.
Third parties and assessments
A brand new Section 12D-107A puts duties directly on third parties: one that receives personal data without a contract required by the chapter may not further process it, must comply with the terms of any required contract, and must supply the information needed for the controller's data protection and due-diligence assessments. A third party subject to the chapter under Section 12D-103(a)(1) or (2) must comply with all provisions of the chapter. Processor contracts, in parallel, must identify each limited and specific purpose for processing "with specificity and particularity" rather than in generic terms.
Assessment duties reach further down. The trigger at Section 12D-108(a) falls from 100,000 consumers to 50,000, and the words "controls or" are struck so the count turns on processing. A new paragraph adds a separate impact assessment wherever a controller profiles in furtherance of automated decisions producing legal or similarly significant effects, documenting the purpose and deployment context, any heightened risk of harm and the mitigation taken, the input categories and outputs, the metrics and known limitations, transparency measures, and post-deployment monitoring. The Attorney General's power to demand an assessment expands to reach one "conducted for the purpose of complying with another applicable law or regulation."
Enforcement is unchanged in substance
House Bill 380 touches Section 12D-111 only lightly. It removes a duplicated "may" in subsection (c) and corrects a cross-reference in subsection (e) so a violation is a violation of "subchapter II of Chapter 25 of this title." The surviving subsection (e) still provides that a violation is an unlawful practice under Section 2513 of Title 6 and "shall be enforced solely by the Department of Justice."
Subsection (d) is not amended at all. It continues to provide that nothing in the chapter "shall be construed as providing the basis for, or be subject to, a private right of action." There is no private right of action under the DPDPA before January 1, 2027 and none after it.
Nor does the bill reopen a cure period. The mandatory 60-day notice-and-cure window in Section 12D-111(b) ran from January 1, 2025 through December 31, 2025 and has closed. Since January 1, 2026, subsection (c) has left a cure opportunity to the Department of Justice's discretion, weighed against factors including the number of violations, the size and complexity of the business, and the likelihood of injury to the public. House Bill 380 leaves that framework in place.
Who Is Newly Covered
The coverage change is the part of this bill most likely to matter to a business that has never looked at Delaware law before.
From January 1, 2027, Section 12D-103(a)(1) reads: "Controlled or processed the personal data of not less than 10,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction." The paired trigger at (a)(2) drops from 10,000 to 5,000 consumers where the business derives more than 20 percent of gross revenue from selling personal data. Delaware's population is small, so the arithmetic runs the other way from a large state: a modest national customer base can put 10,000 Delaware residents on the books.
One caveat worth noting for anyone reading the official record. The bill's synopsis, which describes the measure as introduced, refers to a threshold of "not less than 15,000 consumers." That figure appears nowhere in the operative statutory text of either the introduced or the engrossed version, both of which strike 35,000 and insert 10,000. The synopsis is explanatory material and is not the enacted law. The Governor's announcement likewise uses 10,000.
A third trigger is added with no number attached at all: new paragraph (a)(3) extends the chapter to "Third parties who acquire personal data from a controller." Read alongside Section 12D-107A, which sets out third-party duties and then provides that a third party subject under Section 12D-103(a)(1) or (2) must comply with all provisions of the chapter, the structure suggests a tiered outcome, with a recipient that clears a numeric threshold fully covered and one swept in only by (a)(3) carrying the Section 12D-107A duties. That is a reading of the text as written, and the kind of provision counsel will parse closely before January 1, 2027.
The entity exemptions in subsection (b) narrow considerably. Today the statute exempts "any financial institution or affiliate of a financial institution" as defined in 15 U.S.C. Section 6809 to the extent it is subject to Title V of the Gramm-Leach-Bliley Act. That broad exemption is struck and replaced with three targeted ones: insurers and insurance-related entities, from insurance producers and surplus lines brokers to third-party administrators of self-insurance and insurance-support organizations, plus affiliates principally engaged in financial activities as described in 12 U.S.C. Section 1843(k); federal or state chartered banks, credit unions and savings associations and their similarly situated affiliates; and agents, broker-dealers, investment advisers and investment adviser representatives as defined under Section 73-203 of Title 6 who are regulated by the Delaware Investor Protection Unit or the Securities and Exchange Commission.
Entity-level shelter for financial companies therefore narrows to chartered institutions, insurers, and registered securities professionals, and a non-bank financial company that relied on the general Gramm-Leach-Bliley entity exemption loses it. The data-level exemptions are a separate matter and survive untouched: Section 12D-103(c)(14) still exempts data subject to Title V of Gramm-Leach-Bliley, and (c)(7) still exempts activity regulated under the federal Fair Credit Reporting Act. A company that loses the entity exemption may still find much of its regulated data exempt while its marketing and web data is not.
Employment and applicant data is the other newly exposed category. Section 12D-103(c)(11)a. currently excludes data processed in the course of an individual applying to, being employed by, or acting as an agent or contractor of a business, within the context of that role. The amendment appends "except for personal data processed in connection with profiling and reports under § 12D-106(f) of this title." HR data stays outside the statute for ordinary employment administration and comes back inside it when it feeds profiling or a report used in a decision with legal or similarly significant effects. The Governor's announcement frames this as reaching resume screeners, interview scoring tools, and reports that determine hiring, promotion, discipline and termination.
Four new data-level exemptions are added at the same time, all in the health space: information created for and maintained by a device manufacturer as defined at 21 C.F.R. 820.3(o) when used for treatment, payment, or health care operations under HIPAA; information created for purposes of the Federal Health Care Quality Improvement Act of 1986; information derived from protected health information or human-subjects data and deidentified under 45 C.F.R. Section 164.514; and information in a Limited Data Set under 45 C.F.R. Section 164.514(e). The entity exemption list still contains no general exemption for nonprofit organizations, which remain covered when they meet a numeric threshold, as under current law.
Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
The threshold cut will get the headlines, but the structurally interesting change in House Bill 380 is the shift in who the statute is written about.
Delaware's DPDPA, like the state comprehensive privacy laws it was modeled on, is built around the consumer, a term that expressly excludes a person acting in a commercial or employment context. House Bill 380 introduces a second subject, the resident, defined as any natural person residing in the state, and then hangs its most operationally demanding new machinery on that term. The adverse-action notice, the description of data relied on, the human-review request, the 30-day disclosure of data sources and of every third party that received a report in the previous two years: all of that in Section 12D-106(f) runs to residents, not to consumers. Paired with the narrowed employment carve-out, the text creates a path by which a job applicant, who is not a consumer for most of the chapter, can nonetheless be a resident entitled to know why an automated screening decision went against them.
The same drafting logic shows up in the definition of decisions that produce legal or similarly significant effects. Striking both instances of "by the controller" detaches the concept from the entity that made the call. Combined with the new and deliberately broad definition of report, which covers recommendations, summaries, and automated decisions in written, oral, or other form, the chapter now regulates a controller that supplies the inputs to a consequential decision it does not itself make. That is a different regulatory target from a website operator deciding what ads to show.
The architecture of Sections 12D-106(f) and (g) is worth noticing on its own terms. The obligations, adverse-action notice, a statement of the data relied on, access to the underlying file, and a right to correct, track the shape of the Fair Credit Reporting Act. Subsection (g) then carves out anything that already is, or would be, a consumer report furnished in compliance with the FCRA. Read together, the two subsections describe a gap-filling regime: FCRA-style duties for the scoring, screening, and recommendation products that sit next to the federal consumer-reporting system without falling inside it.
Two smaller amendments carry outsized operational weight. Deleting "solely-automated" from the profiling opt-out removes what has been a reliable compliance answer under several state privacy laws, namely that a human somewhere in the workflow places a decision outside the opt-out. And converting the third-party disclosure right from categories to named recipients turns a boilerplate paragraph into a data-lineage requirement, which is presumably why the drafters wrote in a reasonable-effort escape hatch that still requires disclosing the full set of recipients.
The evidentiary sentence added to the anti-discrimination duty is unusual statutory drafting. Rather than mandating bias testing, the text makes evidence or lack of evidence of proactive anti-bias testing relevant both to a claim and to any available defense. It creates an incentive without creating a requirement, and it makes the absence of testing something a factfinder may weigh.
The enforcement picture is worth restating plainly, because the volume of new duties invites the opposite assumption. None of this is privately enforceable, the Department of Justice remains the sole enforcer, and the mandatory cure period expired at the end of 2025 without being revived. The scope of the statute grows substantially on January 1, 2027; the enforcement channel does not move at all. Anyone comparing that setup against other jurisdictions can start from our side-by-side look at state privacy statutes, bearing in mind that it, too, describes Delaware as the law stands today.
How This Affects You
For Delaware residents. Nothing changes on your side until January 1, 2027. Through the end of 2026, the rights available to you are the ones in the current chapter: confirmation and access, correction, deletion, a portable copy, a list of the categories of third parties that received your data, and opt-outs from targeted advertising, sale, and profiling in furtherance of solely-automated consequential decisions. From January 1, 2027, the statute as amended adds access to inferences drawn about you, a list of named third parties rather than categories, an opt-out that reaches automated consequential decisions even where a person is involved, and, where a business sends a report about you to someone else for a consequential decision, notice of an adverse action and an ability to request human review. The statute directs complaints to the Delaware Department of Justice; a controller that denies an appeal must provide a mechanism to contact that office.
For businesses. The amended chapter sets out obligations for controllers, processors, and third parties alike. Assessment duties attach at 50,000 consumers processed rather than 100,000. The chapter requires binding contracts with third parties receiving personal data, documented due diligence of those third parties, an impact assessment for profiling that drives automated consequential decisions, purpose-specific processor contracts, consent plus a necessity-and-proportionality test before processing sensitive data, and a strict-necessity test plus advance notice, consent and a five-year consent record before any sale of sensitive data. Businesses that relied on the general Gramm-Leach-Bliley entity exemption, and those that treat applicant and employee data as wholly outside the chapter, are the two groups whose analysis changes most. A checklist of what the DPDPA requires today is a reasonable starting point, but read it as the pre-amendment baseline, not as the January 1, 2027 requirements.
This article describes what the statute says. It does not tell any particular reader or organization what to do about it, and whether and how any of these provisions apply to a specific business is a question for its own counsel.
Not legal advice. This article is general legal information about Delaware House Bill 380 and the Delaware Personal Data Privacy Act. It is not legal advice, it does not create an attorney-client relationship, and it is not a substitute for advice from a licensed Delaware attorney about your own situation. Statutory text can be amended and cross-references can change; verify the current text of Chapter 12D of Title 6 before relying on it.
Related articles
- Delaware data privacy laws
- What the DPDPA is and how it works
- Consumer rights under the DPDPA
- A compliance checklist for the current statute
- Biometric information under Delaware law
- How state privacy laws compare
Last updated: 2026-09-05. Details verified as of 2026-09-05.
Frequently Asked Questions
When does Delaware House Bill 380 take effect?
January 1, 2027. Section 2 of the act sets that date, and the General Assembly's bill detail page lists the same effective date. Governor Matt Meyer signed the bill on September 2, 2026, but signing and effectiveness are separate dates here. Until January 1, 2027 the Delaware Personal Data Privacy Act as currently codified at Chapter 12D of Title 6 is the operative law.
What is the new DPDPA applicability threshold?
From January 1, 2027 the chapter applies to a business that conducts business in Delaware or targets products or services to Delaware residents and, in the preceding calendar year, controlled or processed the personal data of at least 10,000 consumers, excluding data processed solely to complete a payment transaction. The current figure is 35,000. A second trigger drops from 10,000 to 5,000 consumers where more than 20 percent of gross revenue comes from selling personal data, and a third trigger is added for third parties who acquire personal data from a controller, with no number attached.
Does the amended DPDPA create a private right of action?
No. Section 12D-111(d) provides that nothing in the chapter shall be construed as providing the basis for, or be subject to, a private right of action, and House Bill 380 does not amend that subsection. Section 12D-111(e), as amended, still provides that violations are enforced solely by the Delaware Department of Justice.
Is neural data protected under Delaware law?
It becomes sensitive data on January 1, 2027. The bill inserts a category covering neural data that is generated by measuring the activity of an individual's central nervous system. As sensitive data, processing it will require the consumer's consent and must also be reasonably necessary and proportionate to the disclosed purposes for processing sensitive data.
Does the amendment cover employee and job applicant data?
Partly. The exclusion for data processed in the course of applying to, being employed by, or acting as an agent or contractor of a business remains, but the amendment appends an exception for personal data processed in connection with profiling and reports under Section 12D-106(f). Ordinary employment administration stays outside the chapter; data feeding profiling or a report used in a decision with legal or similarly significant effects does not.
What does the new adverse action provision require?
Where a controller discloses a report to a third party for use in a decision producing legal or similarly significant effects concerning a Delaware resident, it must contract with that third party to require notice of any adverse action based in whole or in part on the report, a description of the personal data relied on, information about obtaining more from the controller, and a statement that the resident may ask for a human review where technically feasible. On request, the controller must provide within 30 days the personal data it holds, the source of data used in profiling, and every third party that obtained a report about the resident in the previous 24 months. It does not apply to output that is a consumer report furnished in compliance with the federal Fair Credit Reporting Act.
Does House Bill 380 change the profiling opt-out?
Yes. The current opt-out at Section 12D-104(a)(6)c. covers profiling in furtherance of solely-automated decisions that produce legal or similarly significant effects. The bill strikes solely-automated and inserts automated, so from January 1, 2027 the opt-out reaches automated consequential decisions even where a human is involved in the process.
Do banks and financial companies still get an exemption?
The entity exemption narrows. The broad exemption for any financial institution subject to Title V of the Gramm-Leach-Bliley Act is struck and replaced with narrower ones for insurers and insurance-related entities, chartered banks, credit unions and savings associations, and agents, broker-dealers and investment advisers regulated by the Delaware Investor Protection Unit or the Securities and Exchange Commission, plus certain affiliates. The separate data-level exemption for data subject to Title V of Gramm-Leach-Bliley at Section 12D-103(c)(14) is unchanged.
What is House Bill 381 and was it also signed?
Yes. House Bill 381 is a companion measure amending Chapter 12B of Title 6, Delaware's computer security breach chapter. Its bill detail page records it as signed on September 2, 2026, assigned Chapter 464 of Volume 85 of the Laws of Delaware, with an effective date of September 2, 2026, so it took effect on signature. Its official synopsis says it clarifies when businesses must provide notice of a computer security breach to the Attorney General.
Updates
Independently fact-checked against the cited primary sources
Sources and References
- Delaware General Assembly, House Bill 380, 153rd General Assembly, bill detail page (status "Signed 9/2/26"; Laws of Delaware Volume:Chapter 85:463; Governor's Advisory Number 57; Effective Date 1/1/27; introduced 4/16/26; primary sponsor Rep. Griffith).(legis.delaware.gov).gov
- Delaware General Assembly, House Bill No. 380 as amended by House Amendment No. 2, engrossed text (amending 6 Del. C. §§ 12D-102 through 12D-111; § 12D-103(a)(1) threshold struck from 35,000 and inserted as 10,000; new § 12D-106(f) report and adverse-action duties; Section 2, effective January 1, 2027).(legis.delaware.gov).gov
- Delaware General Assembly, House Bill 380 as introduced, full text with synopsis (operative text strikes 35,000 and inserts 10,000; synopsis prose refers to a threshold of 15,000 consumers).(legis.delaware.gov).gov
- Delaware Code Online, Title 6, Chapter 12D, Delaware Personal Data Privacy Act, as currently codified (§ 12D-102(30) sensitive data; § 12D-103(a) 35,000 and 10,000 thresholds; § 12D-103(b)(2) and (c)(14) Gramm-Leach-Bliley exemptions; § 12D-104(a)(5) categories of third parties; § 12D-108(a) 100,000 threshold; § 12D-111(b), (d) and (e) enforcement and no private right of action).(delcode.delaware.gov).gov
- Office of the Governor of Delaware, "Governor Meyer Signed Historic Data Privacy Legislation, Protecting Delaware Residents and Businesses," September 2, 2026 (two bills signed; "lowest threshold in the nation" at 10,000 consumers; quotes from Governor Meyer, Attorney General Jennings and Rep. Griffith; narrowing of the employee-data exclusion).(news.delaware.gov).gov
- Delaware General Assembly, House Bill 381, 153rd General Assembly, bill detail page (status "Signed 9/2/26"; Laws of Delaware 85:464; Effective Date 9/2/26; long title relating to computer security breaches).(legis.delaware.gov).gov
- Delaware General Assembly, House Bill 381 full text (amending 6 Del. C. §§ 12B-101, 12B-102(c)(3) and 12B-103(b) on notice of a breach of security to the Attorney General).(legis.delaware.gov).gov