














Delaware has become the latest state to update its comprehensive privacy law after Governor Meyer signed HB 380 on September 2, amending the Delaware Personal Data Privacy Act (DPDPA). More than half of the 23 states with comprehensive privacy laws have now amended their laws. The bill makes significant revisions to the DPDPA, including—
These changes will take effect January 1, 2027.
Changes to key definitions track trends in other states. For example, HB 380 narrows the definition of “publicly available information” to exclude biometric data that was collected without the consumer’s consent. “Sensitive data” is similarly broadened to explicitly include “inferences” that reveal sensitive data categories. This bill also adds new categories of sensitive data, including national origin, medical treatment or status (in addition to diagnosis), treatment as transgender or nonbinary (in addition to “status” as such), neural data, financial account information, and government-issued identification numbers. (§ 12D-102)
This bill also lowers the law’s applicability threshold and tightens entity-level exemptions, consistent with other legislative trends from recent years. The law will now apply to any person that, in the past calendar year, controlled or processed the personal data of at least (1) 10,000 Delaware consumers (excluding data processed solely for completing payment transactions) or (2) 5,000 Delaware consumers if the person derived more than 20% of their gross revenue from the sale of personal data. These figures are down from 35,000 and 10,000 in the original law. This bill also expands the law’s scope to include “[t]hird parties who acquire personal data from a controller.” (§§ 12D-103(a), 12D-107A)
Finally, consistent with yet another legislative trend, this bill removes the law’s GLBA-entity level exemption and replaces it with several tailored exemptions for the insurance, banking, and investment industries. The bill also adds new health-related data-level exemptions, including for information in a limited data set subject to protection under 45 CFR § 164.514(e). (§ 12D-103(b)-(c))
This bill includes new contractual requirements for disclosing personal data to third parties. The contract must specify that the personal data is disclosed only for limited and specified purposes; obligate the third party to comply with the DPDPA’s requirements; grant the controller rights to take “reasonable and appropriate steps to ensure that the third party uses the personal data . . . in a manner consistent with the controller’s obligations under [the DPDPA]”; require the third party to notify the controller if it determines that it can no longer meet its obligations under the DPDPA; and grant the controller the right, upon notice, “to take reasonable and appropriate steps to stop and remediate unauthorized use of personal data.” (§ 12D-106(a)(10))
The controller is required to conduct reasonable due diligence of third party recipients of personal data to assess the recipient’s policies and technical and organizational measures undertaken to comply with the DPDPA. This due diligence must include the use of questionnaires and review of relevant documents, and additional reasonable measures should be taken as commensurate with the sensitivity of the data disclosed. A controller is further prohibited from selling sensitive data unless the disclosure of that data is strictly necessary to provide or maintain a product or service affirmatively requested by the consumer, the controller provides clear and conspicuous notice prior to the sale, the consumer consents to the disclosure, and the controller maintains a record of consent for 5 years. These new consent records must be provided alongside data protection assessments pursuant to the AG’s investigatory powers. (§ 12D-106(a)(11)-(12))
These requirements are similar to the CCPA’s required contracts for the sale of personal information. (See Cal. Civ. Code § 1798.100, subd. (d); CCPA Rules § 7053) Delaware’s requirements may be slightly broader, however, as they apply to the “disclosure” of personal data, “including in a sale of personal data or for targeted advertising.” The more significant difference is Delaware’s novel due diligence requirements, which are not typically seen in other laws.
These new requirements also apply when the disclosure of personal data to a third party is necessary for providing a product or service requested by a consumer (which would otherwise be exempt from the definition of “sale”). (§ 12D-102)
In recent years, various states have introduced heightened protections and rights for consumers with respect to profiling in furtherance of decisions that produce legal or similarly significant effects concerning a consumer (“significant decisions”). Minnesota’s law, for example, includes a broad right to contest adverse profiling decisions. Connecticut’s and Vermont’s laws have a slightly narrowed version that limits aspects of the right to only decisions concerning housing.
Delaware has taken a different approach. Under the amended DPDPA, a controller will have new obligations prior to and after disclosing a report to any third party for use in connection with any significant decision concerning a resident. Key definitions:
Prior to disclosing a report to a third party for use in connection with a significant decision concerning a resident, the controller must enter into a contractual agreement with the third party that imposes a number of obligations. Under this required contract, a third party must provide notice to a resident of any adverse action based in whole or in part on any information in the report; provide a description of personal data relied upon in making the adverse action; include a statement that the resident has a right to obtain certain information from the controller, with the controller’s contact information; and include a statement that the resident has a right to request the third party perform a human review of the adverse action, provided that the review must be “technically feasible” and the third party does not have to offer the review if doing so is “not in the best interest of the resident” (e.g., where delay poses a risk to the resident’s life or safety). The required contract between a controller and third party for disclosing a report is “in addition to” the bill’s other new contractual requirement for disclosing personal data to a third party. (§ 12D-106(f)(1))
Apart from entering that contract with a third party prior to disclosing a report, a controller must comply with special access and correction rights for consumers. For the access request, a controller has 30 days to provide a resident with the personal data maintained by the controller concerning the resident, the source of personal data used in profiling, and identification of all third parties who obtained a report concerning the resident in the past 24 months. The controller must also provide the resident with an opportunity to correct any incorrect personal data, although there is no timeline specified for this right. (§ 12D-106(f)(2), (3))
These new requirements apply more broadly than the rest of the law, extending to employment contexts. HB 380 narrowed the law’s data-level exemption for data processed or maintained in “the course of an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party,” providing that the exception now does not apply for personal data processed in connection with profiling and reports under these new requirements. While the definition of “consumer” exempts individuals acting in an employment context, these new controller duties apply to the disclosure of a report for use in connection with significant decisions concerning a “resident,” defined broadly as “a natural person residing in [Delaware].” (§§ 12D-102 & 12D-103(c)(11)(a))
Although these requirements are similar in kind to those under the Fair Credit Reporting Act (FCRA), HB 380 preserves the DPDPA’s existing FCRA exemption and clarifies that nothing in this new subsection applies to a controller or third party when the report or personal data consists of an output such as a score, model, or algorithm that is a consumer report—or would be a consumer report if furnished to a third party—and is furnished or disclosed in compliance with the FCRA. (§ 12D-106(g))
This bill modifies the DPDPA’s consumer rights in several ways, all of which are similar to changes other states have previously made to their respective laws:
This bill makes a number of additional changes to the law, including—
Many of these changes are similar to those Connecticut made to the CTDPA in 2025.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。