House Bill 380 has reshaped compliance requirements for Delaware businesses. On September 2, 2026, Governor Carney signed amendments lowering the Delaware Personal Data Privacy Act's (DPDPA) applicability threshold from 35,000 to 10,000 consumers. This change, effective January 1, 2027, brings many mid-sized organizations into scope. If you thought Delaware's privacy laws didn't affect you, it's time to reassess.
The amendments go beyond thresholds. They expand sensitive data categories, enforce vendor-management protocols, and tighten breach-notification rules through HB 381. These changes signal Delaware's move towards a more inclusive data-protection framework.
What Changed
Previously, the DPDPA applied to businesses handling personal data of at least 35,000 consumers annually. HB 380 reduces this to 10,000 consumers. For businesses earning over 20% of revenue from selling personal data, the threshold drops from 10,000 to 5,000 consumers.
The amendments also cover third parties acquiring personal data from a controller. "Third party" includes anyone other than the consumer, controller, processor, or an affiliate. This broad definition now includes data brokers, marketing platforms, and analytics vendors.
Sensitive data categories now include national origin, health treatment or status, neural data, certain financial-account information, and government-issued ID numbers. Inferences revealing sensitive characteristics are also covered.
Controllers must now have contracts with third parties receiving personal data. These contracts should specify data purposes, require equivalent privacy protection, and allow the controller to address unauthorized uses. Controllers must conduct due diligence on third parties, including questionnaires and document reviews.
Key Findings
Threshold reduction expands compliance burden. Lowering the threshold to 10,000 consumers means businesses with regional operations or moderate e-commerce volume are now under the DPDPA. You need to track your consumer count continuously, as the law references "the preceding calendar year."
Sensitive data expansion creates new restrictions. Neural data is significant. If your organization uses biometric authentication or emotion-detection tools, you're handling sensitive data under Delaware law. Financial-account information and government-issued IDs also require careful handling.
Third-party coverage closes the data-broker loophole. Extending the DPDPA to third parties ensures data remains regulated even when it leaves the original collector. If you acquire consumer lists or enrich records with third-party data, you're now regulated in Delaware.
Vendor contracts become mandatory. Entering contracts with third parties is now a legal requirement. The contract must specify purposes, require equivalent privacy protections, and grant enforcement rights. This requires purpose-specific language reflecting actual data use.
Due diligence becomes documented. Questionnaires and document reviews are now required for vendor assessment. If you've relied on vendor representations without documentation, you're not meeting Delaware's standard for "reasonable due diligence."
What This Means for Your Team
If your organization processes between 10,000 and 35,000 Delaware consumers annually, you have until January 1, 2027, to establish a DPDPA compliance program. This involves inventorying data flows, drafting consumer-rights workflows, updating privacy notices, and executing vendor contracts.
For those already covered under the original thresholds, focus on the sensitive data expansion and vendor-management obligations. Start contract negotiations with your third-party ecosystem now, as vendors may need months to review and negotiate terms.
The third-party provision creates obligations for businesses acquiring data from controllers. If you're a data broker or analytics platform, assess whether your data sources include Delaware residents and if your activities trigger DPDPA obligations.
Action Items by Priority
Immediate (Q4 2026): Calculate your Delaware consumer count for the preceding year. Use actual records, deduplicate by consumer, and document your methodology. If you're near 10,000, plan accordingly.
Q1 2027: Inventory sensitive data processing. Identify systems handling national origin, health information, neural data, financial credentials, or government IDs. Map data entry, storage, access, and third-party flows to drive consent logic and access controls.
Q1-Q2 2027: Draft and execute third-party contracts. Prioritize vendors handling sensitive or high volumes of personal data. Contracts must specify limited purposes, require equivalent privacy protections, and grant audit rights. Allow time for vendor negotiation.
Q2 2027: Build your due-diligence process. Create a vendor questionnaire covering data security and compliance. Establish a document-review protocol for security policies and data-processing agreements. Assign responsibility for ongoing vendor monitoring.
Q3 2027: Update your privacy notice and consumer-rights workflows. Delaware consumers have rights to access, correct, delete, and opt out of targeted advertising and sale. Your notice must clearly explain these rights, and your process must verify Delaware residency before fulfilling requests. Test workflows with sample requests before January 1, 2027.
Ongoing: Monitor your consumer count quarterly. A seasonal spike or marketing campaign could push you into scope mid-year. Set up alerts for your compliance team when you approach 9,000 Delaware consumers to accelerate readiness.




