惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Jina AI
Jina AI
N
Netflix TechBlog - Medium
P
Proofpoint News Feed
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
D
DataBreaches.Net
人人都是产品经理
人人都是产品经理
aimingoo的专栏
aimingoo的专栏
Stack Overflow Blog
Stack Overflow Blog
Blog — PlanetScale
Blog — PlanetScale
月光博客
月光博客
阮一峰的网络日志
阮一峰的网络日志
I
InfoQ
F
Fortinet All Blogs
J
Java Code Geeks
Last Week in AI
Last Week in AI
美团技术团队
大猫的无限游戏
大猫的无限游戏
有赞技术团队
有赞技术团队
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园_首页
量子位
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Apple Machine Learning Research
Apple Machine Learning Research
小众软件
小众软件

Future of Privacy Forum

FPF at the Singapore Data Festival 2026: Agentic AI, Biometrics, and the Future of Digital Trust in APAC Clean-Up on Aisle Three: New Jersey Becomes Third State to Regulate Data-Driven Pricing This Year - Future of Privacy Forum A New Design Code Takes Root in the Garden State CADA: An (E)U-turn on AI regulation FPF and Leading Companies Release Risk Assessment Framework and Updated Best Practices for AI in Hiring & Employment FPF Statement on the Senior Chatbot Protection Bill - Future of Privacy Forum The AI Act implementation timeline: What changes under the AI Omnibus? FPF Submits Comments to Inform Colorado Automated Decision-Making Technology and Chatbot Rulemaking Processes - Future of Privacy Forum FPF Releases New Issue Brief on U.S. “Data Broker” Regulatory Landscape New Survey: Privacy Concerns Are A Top Barrier to AgeTech Adoption Among Older Adults New Survey: Privacy Concerns Are A Top Barrier to AgeTech Adoption Among Older Adults Navigating Cross-Border Data Transfers in the ASEAN Region: An Analysis of Developments from 2023 to 2026 FPF Submits Comments to Inform California Children’s Social Media Protections Rulemaking Process Mandating “Evidence-Based” Suicide Detection in Chatbots Data Brokers & Beyond: Navigating New Jersey’s Data Broker & “Data Collector” Registration Law - Future of Privacy Forum FPF Hosts Frontiers Workshop on Privacy, AI, and Emerging Infrastructure FPF’s 2026 DC Privacy Forum: Leading Voices in AI, Privacy and Emerging Technology Understanding Data Embassies and Corridors Perseverance Pays Off for Vermont Privacy Efforts Future of Privacy Forum Announces 2026 Career Achievement Award Recipients - Future of Privacy Forum Future of Privacy Forum Releases Comprehensive Report On Algorithmic Personalization in Youth Online Experiences Frontier AI Goes Federal: How the Great American AI Act Compares to State Laws Privacy Becomes You, Bayou State: A Look at the Louisiana Data Privacy Act Comparing Enacted App Store Accountability Acts - Future of Privacy Forum No Silver Bullet, But a Silver Lining? PETs and International Data Transfers Career Choice in the AI Age: What Next for Privacy and Data Professionals? FPF Releases Practitioner Guides on Privacy Enhancing Technologies for Education Stakeholders SB 5 in Five: What to Know About Connecticut’s New AI Law Third Time’s the Charm: Connecticut Enacts Annual Privacy Update - Future of Privacy Forum Colorado Revises Its AI Act: What Changed and Why
Updating the Delaware Personal Data Privacy Act: The “Fir...
https://www.facebook.com/FutureofPrivacy · 2026-09-03 · via Future of Privacy Forum

Delaware has become the latest state to update its comprehensive privacy law after Governor Meyer signed HB 380 on September 2, amending the Delaware Personal Data Privacy Act (DPDPA). More than half of the 23 states with comprehensive privacy laws have now amended their laws. The bill makes significant revisions to the DPDPA, including— 

  • An expanded definition of sensitive data;
  • Lowered applicability thresholds;
  • New contractual and novel due diligence requirements for disclosing personal data to third parties;
  • Additional contractual requirements and rights for disclosing “reports” to third parties used in profiling decisions made about “residents,” rather than “consumers,” and extending to employee data; 
  • Adding and modifying consumer rights; and more. 

These changes will take effect January 1, 2027

Definitions & Scope

Changes to key definitions track trends in other states. For example, HB 380 narrows the definition of “publicly available information” to exclude biometric data that was collected without the consumer’s consent. “Sensitive data” is similarly broadened to explicitly include “inferences” that reveal sensitive data categories. This bill also adds new categories of sensitive data, including national origin, medical treatment or status (in addition to diagnosis), treatment as transgender or nonbinary (in addition to “status” as such), neural data, financial account information, and government-issued identification numbers. (§ 12D-102)

This bill also lowers the law’s applicability threshold and tightens entity-level exemptions, consistent with other legislative trends from recent years. The law will now apply to any person that, in the past calendar year, controlled or processed the personal data of at least (1) 10,000 Delaware consumers (excluding data processed solely for completing payment transactions) or (2) 5,000 Delaware consumers if the person derived more than 20% of their gross revenue from the sale of personal data. These figures are down from 35,000 and 10,000 in the original law. This bill also expands the law’s scope to include “[t]hird parties who acquire personal data from a controller.” (§§ 12D-103(a), 12D-107A)

Finally, consistent with yet another legislative trend, this bill removes the law’s GLBA-entity level exemption and replaces it with several tailored exemptions for the insurance, banking, and investment industries. The bill also adds new health-related data-level exemptions, including for information in a limited data set subject to protection under 45 CFR § 164.514(e). (§ 12D-103(b)-(c))

Due Diligence for Data Sales

This bill includes new contractual requirements for disclosing personal data to third parties. The contract must specify that the personal data is disclosed only for limited and specified purposes; obligate the third party to comply with the DPDPA’s requirements; grant the controller rights to take “reasonable and appropriate steps to ensure that the third party uses the personal data . . . in a manner consistent with the controller’s obligations under [the DPDPA]”; require the third party to notify the controller if it determines that it can no longer meet its obligations under the DPDPA; and grant the controller the right, upon notice, “to take reasonable and appropriate steps to stop and remediate unauthorized use of personal data.” (§ 12D-106(a)(10))

The controller is required to conduct reasonable due diligence of third party recipients of personal data to assess the recipient’s policies and technical and organizational measures undertaken to comply with the DPDPA. This due diligence must include the use of questionnaires and review of relevant documents, and additional reasonable measures should be taken as commensurate with the sensitivity of the data disclosed. A controller is further prohibited from selling sensitive data unless the disclosure of that data is strictly necessary to provide or maintain a product or service affirmatively requested by the consumer, the controller provides clear and conspicuous notice prior to the sale, the consumer consents to the disclosure, and the controller maintains a record of consent for 5 years. These new consent records must be provided alongside data protection assessments pursuant to the AG’s investigatory powers. (§ 12D-106(a)(11)-(12))

These requirements are similar to the CCPA’s required contracts for the sale of personal information. (See Cal. Civ. Code § 1798.100, subd. (d); CCPA Rules § 7053)  Delaware’s requirements may be slightly broader, however, as they apply to the “disclosure” of personal data, “including in a sale of personal data or for targeted advertising.” The more significant difference is Delaware’s novel due diligence requirements, which are not typically seen in other laws. 

These new requirements also apply when the disclosure of personal data to a third party is necessary for providing a product or service requested by a consumer (which would otherwise be exempt from the definition of “sale”). (§ 12D-102)

Profiling, Reports, and Adverse Actions 

In recent years, various states have introduced heightened protections and rights for consumers with respect to profiling in furtherance of decisions that produce legal or similarly significant effects concerning a consumer (“significant decisions”). Minnesota’s law, for example, includes a broad right to contest adverse profiling decisions. Connecticut’s and Vermont’s laws have a slightly narrowed version that limits aspects of the right to only decisions concerning housing. 

Delaware has taken a different approach. Under the amended DPDPA, a controller will have new obligations prior to and after disclosing a report to any third party for use in connection with any significant decision concerning a resident. Key definitions: 

  • “‘Adverse action’ means any denial, cancellation, unfavorable change, increase in charge, exclusion of benefit, or other action adverse to the interests of a consumer or resident in connection with a decision that produces legal or similarly significant effects.”
  • “‘Decisions that produce legal or similarly significant effects’ means decisions that result in the provision or denial of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunities, health-care services, or access to essential goods or services.”
  • “‘Report’ means any written, oral, or other communication of any personal data by a controller or processor, including recommendations, summaries, or automated decisions based on personal data or profiling.”
  • “‘Resident’ means any natural person residing in the State.” (§ 12D-102)

Prior to disclosing a report to a third party for use in connection with a significant decision concerning a resident, the controller must enter into a contractual agreement with the third party that imposes a number of obligations. Under this required contract, a third party must provide notice to a resident of any adverse action based in whole or in part on any information in the report; provide a description of personal data relied upon in making the adverse action; include a statement that the resident has a right to obtain certain information from the controller, with the controller’s contact information; and include a statement that the resident has a right to request the third party perform a human review of the adverse action, provided that the review must be “technically feasible” and the third party does not have to offer the review if doing so is “not in the best interest of the resident” (e.g., where delay poses a risk to the resident’s life or safety). The required contract between a controller and third party for disclosing a report is “in addition to” the bill’s other new contractual requirement for disclosing personal data to a third party. (§ 12D-106(f)(1))

Apart from entering that contract with a third party prior to disclosing a report, a controller must comply with special access and correction rights for consumers. For the access request, a controller has 30 days to provide a resident with the personal data maintained by the controller concerning the resident, the source of personal data used in profiling, and identification of all third parties who obtained a report concerning the resident in the past 24 months. The controller must also provide the resident with an opportunity to correct any incorrect personal data, although there is no timeline specified for this right. (§ 12D-106(f)(2), (3))

These new requirements apply more broadly than the rest of the law, extending to employment contexts. HB 380 narrowed the law’s data-level exemption for data processed or maintained in “the course of an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party,” providing that the exception now does not apply for personal data processed in connection with profiling and reports under these new requirements. While the definition of “consumer” exempts individuals acting in an employment context, these new controller duties apply to the disclosure of a report for use in connection with significant decisions concerning a “resident,” defined broadly as “a natural person residing in [Delaware].” (§§ 12D-102 & 12D-103(c)(11)(a))

Although these requirements are similar in kind to those under the Fair Credit Reporting Act (FCRA), HB 380 preserves the DPDPA’s existing FCRA exemption and clarifies that nothing in this new subsection applies to a controller or third party when the report or personal data consists of an output such as a score, model, or algorithm that is a consumer report—or would be a consumer report if furnished to a third party—and is furnished or disclosed in compliance with the FCRA. (§ 12D-106(g))

New & Modified Consumer Rights

This bill modifies the DPDPA’s consumer rights in several ways, all of which are similar to changes other states have previously made to their respective laws: 

  • The right to access now explicitly includes inferences about the consumer that are derived from personal data and information about whether the consumer’s personal data is being processed for profiling to make a significant decision. The right to access is also narrowed to prohibit a controller from disclosing certain types of information to a consumer—SSNs, government-issued ID numbers, financial account numbers, health insurance and medical ID numbers, account passwords, security questions or answers, and biometric data. Rather, a controller must inform the consumer “with sufficient particularity” that the controller processes any of these types of data. 
  • The right to know third-party recipients of one’s personal data is modified by HB 380. A consumer now has the right to obtain a list of third parties to which the controller disclosed the consumer’s personal data, not merely the categories of such third parties. However, the right no longer applies to pseudonymous data; does not require a controller to list a third party if doing so would reveal a trade secret; and the controller can provide a list of all third-party recipients of personal data rather than a list tailored to the consumer if compiling an individualized list cannot be done with “reasonable effort.”
  •   The right to opt out of profiling is expanded to apply to profiling in furtherance of “automated decisions” that produce legal or similarly significant effects, rather than “solely automated decisions.” (§ 12D-104)

Additional Changes

This bill makes a number of additional changes to the law, including—

  • Requiring a controller to limit the processing of personal data to what is “reasonably necessary and proportional” in relation to the purposes for which the data is processed, as disclosed to the consumer;
  • For sensitive data, adding a dual requirement that processing must be pursuant to consent and must be reasonably necessary and proportionate to the disclosed processing purposes;
  • Adding bias-testing language to the prohibition on processing or profiling in violation of antidiscrimination law; 
  • Expanding the teenager opt-in requirement to include profiling in addition to targeted advertising and the sale of personal data; 
  • Adding a link for consumers to exercise their data rights to applications, not just websites;
  • Adding more specificity to the required controller-processor contract; 
  • Modifying data protection assessment requirements (which only apply to controllers that process the data of at least 50,000 consumers) and adding new impact assessments for profiling that must be conducted “on a regular basis”;
  • Requiring that a controller or processor undertake reasonable diligence and oversight to ensure compliance with contractual commitments if that entity wants to benefit from the safe harbor from liability for violations of the DPDPA by a processor or third-party controller that received personal data from the entity; and more.

Many of these changes are similar to those Connecticut made to the CTDPA in 2025.