AN ACT TO AMEND TITLE 6 OF THE DELAWARE CODE RELATING TO PERSONAL DATA PRIVACY.
What changed between versions
Lowered the consumer threshold for the law to apply from 35,000 consumers to 10,000 consumers (first prong) and from 10,000 to 5,000 consumers (second prong with 20% revenue from sale of personal data). This dramatically expands which businesses must comply.
Added a third applicability prong covering 'third parties who acquire personal data from a controller,' bringing downstream data recipients within the law's reach.
Lowered the data protection assessment threshold from 100,000 consumers to 50,000 consumers, meaning more businesses must conduct and document risk assessments.
Added an entirely new section (12D-107A) imposing duties on third parties: they cannot further process personal data without a required contract, must comply with contract terms, must provide information for data protection assessments and due diligence, and if independently subject to the chapter must comply with all provisions.
Added anti-discrimination and anti-bias testing provisions requiring controllers not to process personal data or engage in profiling in violation of discrimination laws, with evidence of proactive anti-bias testing being relevant to any claim of violation.
Added requirements that controllers obtain consent before processing personal data for targeted advertising or selling personal data when they know the consumer is between 13 and 18 years old.
Added binding contractual agreement requirements when disclosing personal data to third parties, including specified purposes, compliance obligations, controller oversight rights, notification of inability to comply, and remediation rights. Also added due diligence requirements involving questionnaires and document review.
Changed sensitive data processing from requiring consumer consent as a standalone condition to allowing either consent OR meeting two conditions (consumer consents AND processing is reasonably necessary and proportionate to disclosed purposes).
Added requirements for controllers disclosing reports used in decisions producing legal or similarly significant effects: must provide adverse action notice, description of data relied upon, opportunity for human review, and must provide personal data, profiling sources, and third party list within 30 days of request.
Added restrictions on what data can be disclosed in response to consumer access requests: Social Security numbers, driver's license numbers, financial account numbers, health insurance IDs, passwords, security questions/answers, and biometric data may only be confirmed as processed, not disclosed.
Added a consent revocation mechanism requirement: controllers must provide a way to revoke consent that is at least as easy as the original consent mechanism and must cease processing within 15 days of receiving a revocation request.
Added processor requirements to identify each limited and specific purpose for processing (not generic terms), make available compliance information upon request, and cooperate with due diligence assessments.
Expanded the definition of 'sensitive data' to include inferences made from personal data, neural data (generated by measuring central nervous system activity), financial account numbers with access credentials, and government-issued identification numbers not required to be publicly displayed.
Added new definitions for 'adverse action,' 'decisions that produce legal or similarly significant effects concerning the consumer,' 'report,' and 'resident.'
Modified 'publicly available information' definition to exclude biometric data that can be associated with a specific consumer if collected without the consumer's consent.
Expanded financial institution exemptions to cover all data regulated by GLBA, while limiting entity-level exemptions specifically to banks, credit unions, savings associations, insurers, and their affiliates. Removed several HIPAA-related data exemptions that were in the prior version.
Changed enforcement authority from the Attorney General to the Department of Justice. Added that the cure period for alleged violations begins January 1, 2026.
Set the effective date of the Act at January 1, 2027.