Delaware recently enacted two significant changes to its privacy and cybersecurity laws that expand privacy obligations and tighten breach-response requirements. The expansion, HB 380, effective January 1, 2027, updates the Delaware Personal Data Privacy Act (DPDPA) to bring more businesses within its scope while also adding new requirements for sensitive data, third parties, automated decision-making, and profiling. Delaware’s breach notification rules were also updated (HB 381) and are already in effect to include changes to when businesses must notify the Delaware attorney general. So what do companies need to know about these changes, and what impact do they have?
Key Takeaways
- Businesses should reassess whether and how the DPDPA now applies in light of lower coverage thresholds and expanded reach.
- Covered businesses should review how they collect, use, and share sensitive data; confirm that required consent is in place; and strengthen contracts and oversight for vendors and other third parties that receive personal data.
- Covered businesses should also ensure they are meeting the due diligence requirements of those to whom they disclose personal information and have all required contractual agreements and data protection agreements.
- Companies using profiling or automated tools to support decisions that produce legal or similarly significant effects, such as decisions involving employment, housing, lending, insurance, education, or health care (referred to here as “significant decisions”), should evaluate new consumer rights, disclosure and human review requirements, and any applicable assessment obligations.
- Companies should update breach-response procedures to ensure the Delaware attorney general is notified within 60 days after determining that a breach occurred, even if the company’s investigation is still identifying affected residents.
Broader Coverage and Higher Compliance Expectations
The first question for companies is straightforward: Does the DPDPA apply to us now, even if it did not before? Beginning January 1, 2027, the law generally covers businesses that operate in Delaware or target Delaware residents and controlled or processed personal data of at least 10,000 consumers in the prior year (down from the previous 35,000-consumer requirement), excluding data used solely to complete payment transactions. A lower 5,000-consumer threshold applies if more than 20 percent of gross revenue comes from personal-data sales. This law also extends certain requirements to third parties that acquire personal data from controllers covered by the law. Businesses that previously fell below Delaware’s thresholds should reassess whether they are now covered.
For companies already subject to the DPDPA, HB 380 raises the compliance bar. “Sensitive data” now includes certain inferences or predictions about a person, as well as pregnancy status, citizenship or immigration status, neural data, certain financial account credentials, and government-issued ID numbers. Processing sensitive data generally requires consent and must be reasonably necessary and proportionate to the disclosed purpose, while sales of sensitive data face stricter restrictions. Companies that share personal data with third parties will also need binding agreements that limit how the data can be used and require protections consistent with Delaware law, along with reasonable due diligence and oversight.
The updates also add new obligations for companies that use profiling or automated tools to make or support decisions that can significantly affect a consumer, including decisions involving employment, housing, lending, insurance, education, health care, or access to other essential services (referred to here as “significant decisions”). Consumers will have broader rights to understand how profiling and inferences are used in those decisions, and the right to opt out of profiling is no longer limited solely to automated decisions. When reports are used to make or support “significant decisions,” additional requirements may apply, including certain disclosures and, where feasible, the right to request human review. Companies subject to applicable assessment requirements may also need to evaluate how their profiling systems work, the data they use and produce, their limitations and risks, and how they are monitored over time.
Breach Notifications: Earlier Attorney General Notice, Even During an Ongoing Investigation
The updates to breach notification requirements, already in effect, clarify what companies must do when they determine that a data breach occurred but are still identifying who was affected. If, despite reasonable diligence, a company cannot identify all affected Delaware residents within 60 days, it must still notify the Delaware attorney general within 60 days after determining that the breach occurred. Individual residents may be notified later, as soon as practicable after the company determines that their information was involved. The updates also include a substitute-notice requirement narrowing the exceptions available to businesses that provide notifications in Delaware for compliance with other state or federal breach notification rules.
For assistance in assessing these changes’ impact on your business or in updating your compliance program, please contact one of the authors or any member of McCarter & English’s Cybersecurity and Data Privacy team.
