Last updated: 2026-10-02
On September 2, 2026, Governor Matt Meyer signed Delaware House Bill 380, which amends the Delaware Personal Data Privacy Act (DPDPA, Chapter 12D of Title 6), the comprehensive Delaware privacy law first enacted in 2023. The amendments take effect on January 1, 2027. From that date the DPDPA applies to a business that controlled or processed the personal data of at least 10,000 Delaware consumers in the preceding calendar year, and a controller may sell sensitive data only when the sale is "strictly necessary" to a product or service the consumer requested, after notice and with consent.
HB 380 is Chapter 463 of Volume 85 of the Laws of Delaware; Rep. Krista Griffith is the primary sponsor. The governor signed HB 381 the same day; it amends the security breach chapter (Chapter 12B) on notice to the Attorney General, effective September 2, 2026.
From the governor's signing release: "Your data should belong to you, not the highest bidder, and privacy shouldn't be a privilege – it's a right that everyone in Delaware should have."
Is the HB 380 threshold 10,000 or 15,000 consumers?
The enacted text sets 10,000. Amended § 12D-103(a)(1) covers persons that "Controlled or processed the personal data of not less than 10,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction." The threshold until December 31, 2026 is 35,000.
The original synopsis on the HB 380 bill page states "not less than 15,000 consumers". The bill text, as introduced and as amended by House Amendment No. 2, states 10,000, and the Delaware Code prints 10,000 in the section marked "Effective Jan. 1, 2027". The governor's release also gives 10,000.
The revenue test, for a business that "derived more than 20% of their gross revenue from the sale of personal data", drops from 10,000 to 5,000 consumers. A new subdivision (3) adds "Third parties who acquire personal data from a controller."
The release calls 10,000 "the lowest threshold in the nation". Connecticut, covered in the post on its precise geolocation sale ban, sets 35,000 consumers under Public Act 25-113, section 6 and also covers any person that controls or processes "consumers' sensitive data" or offers "consumers' personal data for sale", at any consumer count. A national ranking needs every state's statute; this post compares Connecticut only.
What changes for sensitive data under HB 380?
The definition of sensitive data adds inferences. Amended § 12D-102 covers personal data that includes the listed categories "and includes inferences made based on personal data, alone or in combination with other data, that are used to reveal or identify any of the following". An inferred pregnancy or an inferred immigration status, used to identify that status, is sensitive data from 2027.
The category list also changes. "National" origin joins racial and ethnic origin, health covers "condition, diagnosis, treatment, or status (including pregnancy)", and transgender or nonbinary covers "treatment or status". Three items are new: "Neural data", financial account numbers and log-in information that "would allow access to a consumer's financial account", and government-issued identification numbers such as Social Security, passport, state ID and driver's license numbers.
The release lists "citizenship and immigration status" and "status as transgender or nonbinary" among the added categories. But the current § 12D-102(30)a already lists "status as transgender or nonbinary, citizenship status, or immigration status" and "pregnancy". The enacted text extends those categories with treatment and inferences.
Processing sensitive data requires more than consent from 2027. Amended § 12D-106(a)(4) permits it only when "The consumer consents to the processing of sensitive data" and "The processing of sensitive data is reasonably necessary and proportionate to the disclosed purposes for processing sensitive data."
When may a controller sell sensitive data in Delaware?
From January 1, 2027, new § 12D-106(a)(12) bars disclosing sensitive data in a sale "unless all of the following apply":
- "The disclosure of sensitive data is strictly necessary to provide or maintain a product or service affirmatively requested by the consumer to whom the sensitive data pertains."
- The controller gives "a clear and conspicuous notice" before the sale naming "the specific categories of sensitive data", the purpose and the third parties.
- "The controller obtains the consumer's consent."
- The controller keeps a record of that consent "for a period of 5 years".
What does HB 380 require of third parties and ad partners?
New § 12D-106(a)(10) requires "binding contractual agreements with third parties to whom personal data is disclosed, including in a sale of personal data or for targeted advertising". Each agreement needs five terms, among them limited and specified purposes and the third party's duty "to provide the same level of privacy protection as is required by this chapter." New § 12D-106(a)(11) requires due diligence that "at a minimum" assesses the third party "through the use of questionnaires and review of relevant documents".
New § 12D-107A, "Duties of third parties", provides: "A third party that receives personal data from a controller or processor and does not have a contract as required by this chapter may not further process personal data disclosed to the third party." The safe harbor in § 12D-110(d) for a controller whose recipient violates the chapter now also requires that the controller "undertook reasonable diligence and oversight". The post on the DROP processing duty covers the separate duties California's Delete Act sets for data brokers.
| Provision | DPDPA until December 31, 2026 | DPDPA from January 1, 2027 (HB 380) |
|---|---|---|
| Applicability, any business | 35,000 consumers | 10,000 consumers |
| Applicability, revenue from sale over 20% | 10,000 consumers | 5,000 consumers |
| Third parties that acquire data from a controller | (no subdivision) | covered, § 12D-103(a)(3) |
| Sensitive data | listed categories | listed categories plus inferences "used to reveal or identify" them; neural data, financial log-ins, government ID numbers |
| Processing sensitive data | consent | consent, and "reasonably necessary and proportionate" |
| Selling sensitive data | consent | strictly necessary to a requested product or service, notice, consent, 5-year consent record |
| Contracts with third parties | processor contracts (§ 12D-107) | third-party contracts for sales and targeted advertising, plus due diligence |
| Opt-out link | "Internet website" | "Internet website or application" |
| Profiling opt-out | "solely-automated" decisions | "automated" decisions |
| Data protection assessments | 100,000 consumers | 50,000 consumers |
| Employee data exclusion | covers data used "within the context of that role" | same, except profiling and reports under § 12D-106(f) |
Sources: the current Delaware Code chapter 12D and the HB 380 engrossed text. The release ties the employee data change to "the bill package"; the change is in HB 380's amendment to § 12D-103(c)(11)a.
Who enforces the DPDPA, and what are the penalties?
The Department of Justice enforces the DPDPA alone, and § 12D-111(d) excludes a private right of action. HB 380 leaves the cure rules in place: from January 1 to December 31, 2025, the Department had to issue a notice of violation with 60 days to cure where it found a cure possible. Since January 1, 2026 the Department "may" weigh seven factors, among them "The number of violations" and "The substantial likelihood of injury to the public", in deciding whether to offer a cure.
Under § 12D-111(e), a violation is "an unlawful practice under § 2513 of this title and a violation of subchapter II of Chapter 25", the Consumer Fraud Act. Under § 2522(b) of that subchapter, where a court finds that a person "has wilfully violated this subchapter", the person, on the Attorney General's petition, "shall forfeit and pay to the State a civil penalty of not more than $10,000 for each violation." Chapter 12D itself names no amount; the $10,000 figure is in the Consumer Fraud Act subchapter that § 12D-111(e) names.
What does an app's traffic show under the sensitive data rules?
A traffic capture records what an app sent to each partner host, field by field. Under the inference rule, relevant fields include interest and audience segment values that name a health condition, pregnancy, national origin or immigration status, and the device identifiers sent with them. A binary scan lists which of those partners' SDKs the app contains.
The capture shows that a value was sent and to which host. Four facts need evidence from outside it:
- whether the transfer was a "sale", which turns on consideration between the app publisher and the recipient;
- whether the recipient has the contract § 12D-106(a)(10) requires;
- whether the user is a Delaware resident;
- whether a segment value is an inference "used to reveal or identify" a category, which turns on how the value was derived and how it is used.
When I scan an app, the report lists the SDKs found in the binary, the permissions the app declares, the consent flow, and the network traffic recorded on test devices: which values were sent to which host, and whether each request was sent before or after the consent prompt. Every static finding cites its file and line; every traffic finding cites its capture. SDK presence in a binary shows the code is there; only a capture shows a value was sent. What a scan checks and the limits of a scan are on the methodology page.
I run these investigations for lawyers and for researchers working with lawyers, on one app or on a list of apps in bulk. Sign up for a CanITrustThat account to run your own research, let us run an investigation for you, or browse the scanned apps.