HB380 revises Delaware’s Personal Data Privacy Act (DPDPA) in Title 6 to expand and refine the state’s consumer privacy framework. The bill lowers the law’s applicability thresholds, so more businesses that process Delaware residents’ personal data would be covered, and it updates several definitions, including “sensitive data,” “publicly available information,” “report,” “resident,” and “third party.” It also broadens the scope of protected data and decisions involving profiling or automated decisions that produce legal or similarly significant effects, such as decisions affecting housing, employment, insurance, education, health care, and access to essential goods or services.
The bill strengthens consumer rights and business obligations. It expands access and portability rights, adds clearer opt-out rights for targeted advertising and certain profiling, and limits disclosure of highly sensitive identifiers in response to access requests. For businesses, it requires data minimization, consent for sensitive data processing, stronger privacy notices, mechanisms to revoke consent, and restrictions on processing children’s and teens’ data. It also adds new requirements for contracts and due diligence when personal data is disclosed to processors or third parties, including obligations tied to sales of data, targeted advertising, and reports used for significant decisions. Larger controllers must conduct regular data protection assessments, and the Attorney General may review those assessments in investigations.
HB380 also narrows and restructures exemptions, especially for financial and insurance entities. The bill appears designed to align Delaware’s law more closely with privacy statutes in other states by adjusting GLBA-related exemptions, clarifying when banks, insurers, and related entities are excluded, and preserving certain evidentiary privilege protections. The bill’s effective date is January 1, 2027, giving covered entities time to prepare for the new compliance requirements.
The overall sentiment reflected in the bill materials is supportive and reform-oriented. The synopsis describes the measure as a harmonization effort intended to bring Delaware’s privacy law into closer alignment with comparable laws in other states, suggesting a policy goal of modernization rather than a wholesale rewrite. The broad list of sponsors from both chambers also indicates substantial legislative backing.
There is no recorded committee transcript or vote history in the provided materials, so no direct opposition is documented here. Based on the text, the most likely points of contention are the lowered coverage thresholds, the expanded obligations on businesses that sell or share data, the new due diligence and contract requirements for third-party disclosures, and the narrower exemptions for financial and insurance-related entities. Businesses subject to data sales, targeted advertising, profiling, or large-scale data processing would be the parties most affected by those changes.
HB380 would amend Chapter 12D of Title 6, Delaware’s Personal Data Privacy Act, by expanding the law’s reach to more businesses, tightening obligations on controllers and processors, and adding new duties for third parties receiving personal data. It would also revise consumer rights, data protection assessment requirements, and disclosure rules for sensitive data, while modifying exemptions for financial institutions, insurers, and related entities. The bill would take effect January 1, 2027, and violations would continue to be treated as unlawful practices enforceable solely by the Department of Justice.
The bill appears broadly favorable and bipartisan in tone, with many sponsors listed from both the House and Senate and a synopsis framing the measure as a technical and policy alignment update to Delaware’s existing privacy law. No committee debate or vote record is provided, so there is no direct evidence of opposition or amendment controversy in the supplied materials. The overall posture suggests support for stronger consumer privacy protections and modernization of the state’s data privacy regime.
The main likely points of contention are the bill’s lower applicability thresholds, which would bring more businesses under the DPDPA, and its expanded compliance obligations for data sales, targeted advertising, profiling, and third-party disclosures. Financial institutions, insurers, and related entities may also object to the way the bill narrows or restructures exemptions tied to GLBA and other financial privacy regimes. In addition, the new contract, due diligence, and data protection assessment requirements could be burdensome for controllers and processors that handle large volumes of consumer data or use automated decision-making.