HB 380 Delaware House · 153rd General Assembly (2025-2026)

AN ACT TO AMEND TITLE 6 OF THE DELAWARE CODE RELATING TO PERSONAL DATA PRIVACY.

Summary
This Act amends the Delaware Personal Data Privacy Act (DPDPA), Chapter 12D of Title 6, originally enacted in 2023, to more closely align the DPDPA with similar consumer data protection laws enacted in other states. This Act amends the applicability threshold of the DPDPA to entities who process the personal data of not less than 15,000 consumers, which on a population percentage basis closely aligns to thresholds in Connecticut and New Jersey. This Act amends Gramm-Leach-Bliley Act (GLBA) applicability exemptions, adopting approaches to financial data in similar laws in Connecticut, Montana, and Oregon, by exempting all data regulated by GLBA while limiting entity-level exemptions specifically to banks and insurers and their respective affiliates. This Act introduces contracting and due diligence requirements where businesses sell or disclose personal data to third parties and also harmonizes several DPDPA business requirements and consumer rights with personal data privacy laws in other states. This Act also makes technical changes to existing law to conform to the standards of the Delaware Legislative Drafting Manual.
Bill status passed both 4 of 5 stages cleared
Introduction
Apr 2026
Committee Review
Jun 2026
House Passage
May 2026
Senate Passage
Jun 2026
Governor
Introduced Apr 16, 2026 Last action Jun 16, 2026
Maddy AI version diff · 1 comparison

What changed between versions

HA 2 to HB 380 Bill Text · 18 edits
MAJOR
HB 380 transitions from House Amendment No. 2 to final bill text, substantially overhauling Delaware's Personal Data Privacy Act. The most significant changes include lowering the consumer threshold for applicability from 35,000 to 10,000 consumers, halving the data protection assessment threshold from 100,000 to 50,000, adding an entirely new section imposing duties on third parties, expanding sensitive data definitions to include neural data and financial account numbers, and shifting enforcement from the Attorney General to the Department of Justice. The bill also adds anti-bias testing provisions, minor protection requirements for ages 13-18, and contractual/due diligence obligations when disclosing personal data to third parties.
SCOPE

Lowered the consumer threshold for the law to apply from 35,000 consumers to 10,000 consumers (first prong) and from 10,000 to 5,000 consumers (second prong with 20% revenue from sale of personal data). This dramatically expands which businesses must comply.

Added a third applicability prong covering 'third parties who acquire personal data from a controller,' bringing downstream data recipients within the law's reach.

Lowered the data protection assessment threshold from 100,000 consumers to 50,000 consumers, meaning more businesses must conduct and document risk assessments.

REQUIREMENT

Added an entirely new section (12D-107A) imposing duties on third parties: they cannot further process personal data without a required contract, must comply with contract terms, must provide information for data protection assessments and due diligence, and if independently subject to the chapter must comply with all provisions.

Added anti-discrimination and anti-bias testing provisions requiring controllers not to process personal data or engage in profiling in violation of discrimination laws, with evidence of proactive anti-bias testing being relevant to any claim of violation.

Added requirements that controllers obtain consent before processing personal data for targeted advertising or selling personal data when they know the consumer is between 13 and 18 years old.

Added binding contractual agreement requirements when disclosing personal data to third parties, including specified purposes, compliance obligations, controller oversight rights, notification of inability to comply, and remediation rights. Also added due diligence requirements involving questionnaires and document review.

Changed sensitive data processing from requiring consumer consent as a standalone condition to allowing either consent OR meeting two conditions (consumer consents AND processing is reasonably necessary and proportionate to disclosed purposes).

Added requirements for controllers disclosing reports used in decisions producing legal or similarly significant effects: must provide adverse action notice, description of data relied upon, opportunity for human review, and must provide personal data, profiling sources, and third party list within 30 days of request.

Added restrictions on what data can be disclosed in response to consumer access requests: Social Security numbers, driver's license numbers, financial account numbers, health insurance IDs, passwords, security questions/answers, and biometric data may only be confirmed as processed, not disclosed.

Added a consent revocation mechanism requirement: controllers must provide a way to revoke consent that is at least as easy as the original consent mechanism and must cease processing within 15 days of receiving a revocation request.

Added processor requirements to identify each limited and specific purpose for processing (not generic terms), make available compliance information upon request, and cooperate with due diligence assessments.

DEFINITION

Expanded the definition of 'sensitive data' to include inferences made from personal data, neural data (generated by measuring central nervous system activity), financial account numbers with access credentials, and government-issued identification numbers not required to be publicly displayed.

Added new definitions for 'adverse action,' 'decisions that produce legal or similarly significant effects concerning the consumer,' 'report,' and 'resident.'

Modified 'publicly available information' definition to exclude biometric data that can be associated with a specific consumer if collected without the consumer's consent.

ELIGIBILITY

Expanded financial institution exemptions to cover all data regulated by GLBA, while limiting entity-level exemptions specifically to banks, credit unions, savings associations, insurers, and their affiliates. Removed several HIPAA-related data exemptions that were in the prior version.

ENFORCEMENT

Changed enforcement authority from the Attorney General to the Department of Justice. Added that the cure period for alleged violations begins January 1, 2026.

TIMELINE

Set the effective date of the Act at January 1, 2027.

Floor votes · House May 21, 2026

How they voted

This bill passed the Senate by voice vote (no roll call recorded).
Full legislative history

Actions timeline

Total actions
10
Key actions
5
Committee
2
Amendments
4
Jun 16, 2026
Upper · Passed
Passed By Senate. Votes: 15 YES 6 NO
upper
Jun 10, 2026
Upper · Passed
Reported Out of Committee (Banking, Business, Insurance & Technology) in Senate with 5 On Its Merits
upper
May 21, 2026
Introduced
Assigned to Banking, Business, Insurance & Technology Committee in Senate
upper
May 21, 2026
Lower · Passed
Passed By House. Votes: 30 YES 9 NO 2 ABSENT
lower
May 21, 2026
Lower · Passed
Amendment HA 2 to HB 380 - Passed In House by Voice Vote
lower
May 21, 2026
Introduced
Amendment HA 1 to HB 380 - Stricken in House
lower
May 21, 2026
Introduced
Amendment HA 2 to HB 380 - Introduced and Placed With Bill
lower
May 14, 2026
Introduced
Amendment HA 1 to HB 380 - Introduced and Placed With Bill
lower
Apr 21, 2026
Lower · Passed
Reported Out of Committee (Technology & Telecommunications) in House with 5 On Its Merits
lower
Apr 16, 2026
Introduced
Introduced and Assigned to Technology & Telecommunications Committee in House
lower
27 primary · 0 co-sponsors

Sponsors