Privacy

Delaware Expands Privacy Law with New Third-Party Due Diligence Requirements

Published: Oct. 07, 2026

On September 2, 2026, Governor Matt Meyer signed HB 380, which makes significant changes to the Delaware Personal Data Privacy Act (“DPDPA”). The law expands the DPDPA’s coverage and imposes new requirements concerning third-party disclosures and due diligence, sensitive data, profiling, and data protection assessments. Delaware’s HB 380 takes effect January 1, 2027.

What Does HB 380 Change?

HB 380 broadens the DPDPA’s reach while adding several new compliance obligations that will require covered entities to reassess existing privacy practices and third-party relationships. HB 380 will:

Expand the DPDPA’s coverage

The law amends the DPDPA to lower the existing general applicability threshold from 35,000 to 10,000 consumers and its alternative threshold from 10,000 to 5,000 consumers for entities deriving more than 20% of gross revenue from selling personal data.

Expand the DPDPA’s regulation of third parties

The law amends the DPDPA to create a new applicability prong for third parties that acquire personal data from controllers, without a separate consumer-volume threshold. Previously, receipt of personal data alone did not trigger specific DPDPA obligations for a third party.

Expand third-party contracting requirements

The law expands the DPDPA’s contracting requirements beyond the existing controller-processor framework by requiring controllers to enter into binding agreements with third parties to whom they disclose personal data, including through sales or for targeted advertising. Among other requirements, those agreements must specify the limited and specified purposes for which personal data is sold or disclosed, require the third party to comply with the DPDPA and provide the same level of privacy protection, and give controllers rights to oversee and remediate unauthorized uses of the data.

Create what Delaware lawmakers have described as a “first of its kind” third-party due diligence obligation

Under the law, controllers must assess third-party recipients’ policies and technical and organizational measures that support compliance with the DPDPA. At a minimum, that diligence must include questionnaires and the review of relevant third-party documents, with additional reasonable measures commensurate with the sensitivity of the data disclosed. Third parties, in turn, must provide the information necessary for the controller or its designated assessor to conduct that assessment. A controller or processor that discloses personal data to a processor or third-party controller will not be deemed to have violated the DPDPA based on the recipient’s independent violation only if, among other conditions, it has undertaken reasonable diligence and oversight to ensure compliance with applicable contractual commitments.

Strengthen protections for sensitive data

The amendments expand the existing definition of sensitive data to include neural data, certain government identifiers and financial credentials, and inferences revealing sensitive characteristics. The DPDPA already requires consumer consent to process sensitive data, but HB 380 adds that such processing must also be reasonably necessary and proportionate to the disclosed purposes. HB 380 also substantially restricts sales of sensitive data. Such sales must be strictly necessary to provide or maintain a product or service affirmatively requested by the consumer. Controllers must also provide advance notice identifying the specific categories of sensitive data, purpose of the sale, and third-party recipients; obtain consumer consent; retain that consent for five years; and provide the consent record with applicable data protection assessments.

Expand the DPDPA’s profiling and assessment requirements

The amendments extend the profiling opt-out right beyond “solely automated” decisions to profiling in furtherance of automated decisions that produce legal or similarly significant effects. They also impose new notice, transparency, and correction requirements for certain reports disclosed to third parties for use in such decisions, as well as, in certain circumstances, an opportunity to request human review. HB 380 also lowers the consumer threshold for mandatory data protection assessments of heightened-risk processing from 100,000 to 50,000 consumers. Controllers meeting that threshold that engage in covered profiling must regularly conduct and document detailed impact assessments addressing, among other things, intended uses, foreseeable risks and mitigation measures, performance limitations, transparency, and post-deployment monitoring.

What Should Businesses Be Thinking About?

With HB 380 taking effect January 1, 2027, businesses should evaluate how the amendments affect their privacy programs, data practices, and third-party relationships. In particular, businesses should consider:

  • Whether HB 380 changes the business’s DPDPA coverage analysis. Businesses that previously determined the DPDPA did not apply may need to revisit that conclusion in light of HB 380’s lower consumer thresholds and new third-party applicability prong. Businesses brought within scope for the first time should consider what changes to their existing privacy compliance program may be needed before January 1, 2027.
  • Whether third-party contracting and diligence processes need to be updated. Businesses may want to consider whether existing agreements, onboarding processes, questionnaires, and document-review procedures address HB 380’s new contracting and diligence requirements. This may include evaluating when heightened review is appropriate based on data sensitivity and how remediation should be incorporated into ongoing oversight.
  • Whether sensitive-data practices need to change. Businesses should consider how HB 380’s expanded definition of sensitive data affects existing products and data flows and whether current collection and use practices implicate the law’s consent and necessity-and-proportionality requirements. Businesses that sell sensitive data should also evaluate with counsel whether those arrangements can continue and what notice, consent, and recordkeeping changes may be required.
  • Whether profiling and automated decision-making practices need to be reassessed. Businesses using profiling or automated decision tools should consider whether HB 380 brings additional activities within the DPDPA’s opt-out and impact-assessment requirements and whether existing decision systems, consumer-rights processes, or privacy and AI assessment frameworks need to be updated.
  • Whether privacy notices and consumer-rights processes need to be updated. Businesses should consider whether existing notices and consumer-rights processes adequately address HB 380’s expanded disclosure and opt-out requirements, including relevant inferences, profiling activities, and third-party recipient information.