Sep 20, 2026 · 7 min read
Delaware HB 380 Drops Privacy Threshold to 10,000 Consumers
Governor Matt Meyer signed House Bill 380 on September 2, 2026, rewriting the Delaware Personal Data Privacy Act with lower applicability thresholds, a narrowed banking exemption, neural data in the sensitive category, and a third party trigger with no numeric threshold at all. Everything lands January 1, 2027.
Delaware has fewer residents than Austin, Texas, and hosts the legal domicile of most of the Fortune 500. That combination makes its privacy law worth reading closely even if you have never sold anything to anyone in Wilmington—and on September 2, 2026, Governor Matt Meyer signed an amendment that pulls thousands more companies inside its perimeter.
House Bill 380 does not tinker. It cuts the applicability threshold by more than two thirds, strips the blanket exemption financial institutions have leaned on, and creates an obligation that applies to third parties regardless of how few Delaware records they touch. The deadline is January 1, 2027.
Key Takeaways
- Delaware Governor Matt Meyer signed House Bill 380 on September 2, 2026, and the amendments to the Delaware Personal Data Privacy Act take effect January 1, 2027.
- The applicability threshold drops from 35,000 Delaware consumers to 10,000, and from 10,000 to 5,000 for companies earning more than 20% of gross revenue from selling personal data.
- Any third party that acquires personal data from a controller is covered with no numeric threshold, a trigger no other state privacy law currently has.
- Sensitive data now includes neural data, national origin, financial account credentials, government issued identification numbers, and inferences used to reveal sensitive characteristics.
- Consumers gain the right to a list of the specific third parties that received their data, not just categories, with controllers required to respond within 30 days.
Who Is Newly in Scope Under HB 380?
Under the amended § 12D-103(a), the Delaware Personal Data Privacy Act reaches any entity that "controlled or processed the personal data of not less than 10,000 consumers," down from 35,000—or 5,000 consumers where the company derives more than 20% of gross revenue from selling personal data. The bill record at the Delaware General Assembly shows HB 380 passed in June 2026 and was signed on September 2.
Put that number against the state. Delaware had 1,051,917 residents as of July 1, 2024, per U.S. Census Bureau QuickFacts. Ten thousand consumers is under 1% of the population. A mid sized ecommerce brand with a national mailing list clears that bar without trying.
The data protection assessment threshold also fell, from 100,000 Delaware residents to 50,000. And the novel piece: the law now attaches to any third party that acquires personal data from a controller, with no volume requirement at all. As McDermott's analysis notes, that trigger is unique to Delaware. The statute leaves the consequence unstated, so here it is: a company with zero direct Delaware customers becomes a regulated third party the moment it buys a list from someone who has them.
Why Banks Lost Their Blanket Exemption
The old DPDPA followed the standard state template and exempted any entity subject to Title V of the Gramm Leach Bliley Act. HB 380 replaces that with three narrow carve outs: federally and state chartered banks, credit unions and savings associations; insurers and related entities principally engaged in financial activities; and agents or broker dealers regulated by Delaware's Investor Protection Unit or the SEC. According to Troutman Pepper's breakdown, the exemption no longer flows automatically to affiliates—each must independently qualify.
Fintechs, lead generators, mortgage servicers and marketing affiliates that have spent three years answering state privacy questionnaires with "GLBA exempt" will need a new answer in Delaware. It is the same direction of travel visible across the wave of state privacy law amendments taking effect in 2026.
What Counts as Sensitive Data Now?
HB 380 widens the sensitive data definition to cover national origin, certain health information, financial account credentials, government issued identification numbers, neural data generated by measuring central nervous system activity, and inferences drawn from personal data that are used to reveal sensitive characteristics. That last category is the one most likely to catch marketing teams off guard: a derived segment can be sensitive data even when every input to it was mundane. Hunton's privacy team puts the neural data addition alongside Colorado's and California's.
Selling sensitive data now requires clear and conspicuous pre sale notice, express consent, and a retained record of that consent for five years.
How Do the New Profiling Rules Work?
The profiling opt out got broader through one small edit: the word "solely" is gone. Consumers could previously object only to decisions made solely by automated means, which let controllers keep a human in the loop as a compliance shield. Delaware now covers profiling in furtherance of automated decisions that produce legal or similarly significant effects, rubber stamp or not.
Several disclosure duties come with it, per the Privacy World analysis:
- Consumers can request a list of the specific third parties that received their personal data, not merely the categories.
- Controllers must respond to access requests within 30 days, including the sources of data used to profile the consumer.
- Consumers can ask which third parties obtained a report about them in the prior 24 months.
- Where a third party takes adverse action based on a report, the consumer must get notice and an opportunity for human review where technically feasible.
- When a consumer revokes consent, processing must stop within 15 days.
Controllers also owe reasonable due diligence on the third parties they disclose data to, plus binding contracts specifying the limited purposes of each disclosure. That is a procurement problem as much as a legal one.
What Does Enforcement Look Like?
Enforcement sits entirely with the Delaware Department of Justice. Under § 12D-111, a violation is deemed an unlawful practice and "shall be enforced solely by the Department of Justice"—there is no private right of action. The mandatory 60 day cure period that ran through December 31, 2025 is gone; since January 1, 2026 the Department decides case by case whether to offer a cure, weighing violation count, entity size, likelihood of harm, and evidence of good faith compliance.
That is the risk shift compliance officers should register. A company pulled into scope on January 1, 2027 arrives in a regime where the safety net has already been withdrawn. Delaware has announced no headline enforcement action yet, roughly where the newest state privacy regimes sit too—early quiet is not tolerance.
What This Means for Your Inbox
State comprehensive privacy laws govern targeted advertising and profiling, and email is one of the busiest inputs to both. When a marketing message records that you opened it, from where, on what device and how many times, that signal lands in the same customer profile that drives targeted advertising. Delaware's expanded profiling opt out and its right to a named list of recipients apply to that profile as squarely as to anything collected on a website.
For a Delaware resident, the practical consequence is a question they can now ask and get answered: which specific companies received my data, and what inferences were drawn from it. Adjacent state efforts, including New Jersey's data broker registration law, are converging on the same idea from a different direction.
What Should Compliance Teams Do Before January 1, 2027?
Four steps, in the order they will hurt least:
- Recount your Delaware records. Anyone who sat comfortably under 35,000 needs a fresh count against 10,000, and against 50,000 for the assessment duty. Third parties receiving data need no count at all—they are in.
- Rebuild the third party inventory as a list, not a taxonomy. Answering "which companies received my data" within 30 days requires per consumer lineage, which most consent platforms do not store today.
- Reopen GLBA exemption claims. Check whether each affiliate independently qualifies. If not, it is a controller in Delaware next January.
- Rescope your sensitive data map. Add neural data, financial credentials, government ID numbers and inference derived segments, then verify you can produce a five year consent record for anything you sell. The IAPP state privacy legislation tracker keeps the rest of the map current.
Delaware moved from the middle of the pack to among the strictest state privacy regimes in the country, in a state whose corporate registry touches nearly every large American company. Small jurisdiction, unusually long reach. Treat January 2027 as real.