Delaware’s consumer privacy law will apply to many more businesses on January 1, 2027, after lawmakers lowered its general coverage threshold from 35,000 consumers to 10,000. House Bill 380 also reduces the threshold for businesses deriving more than 20% of revenue from data sales from 10,000 consumers to 5,000, according to the enacted bill text.

Gov. Matt Meyer signed HB 380 and a companion privacy measure on September 2. The administration said the package gives residents new protections when personal data is used in automated decisions involving loans, housing or employment. Its announcement also highlighted new safeguards for national origin, citizenship, immigration status and gender identity.

The lower thresholds are only one part of the expansion. HB 380 expressly brings third parties that acquire personal data from a controller within the law and establishes duties for those recipients. A third party without the required contract may not continue processing the data; recipients must follow contract terms and supply information needed for risk assessments and due diligence. Two independent legal analyses, from Troutman and Squire Patton, identified those third-party obligations as a notable feature of Delaware’s approach.

More data becomes sensitive

The law broadens “sensitive data” to cover neural data, financial-account credentials, certain government identification numbers and inferences used to identify protected traits or conditions. Those traits include national or ethnic origin, health status, pregnancy, transgender or nonbinary status, citizenship and immigration status. Controllers generally must obtain consent before processing sensitive data, and a sale of that data requires clear notice, express consent and a five-year record of the consent, according to the legal analysis.

Automated decision systems receive separate attention. The law expands the right to opt out of profiling used in decisions with legal or similarly significant effects, even when profiling is only one component rather than the sole basis. When a company supplies a report used for such a decision, contracts must require notice of an adverse action and identify the data relied upon. Where technically feasible, residents must have an opportunity for human review. The bill defines significant decisions broadly enough to include lending, housing, insurance, education, employment, healthcare and access to essential goods or services.

Businesses crossing the new thresholds will also face a lower trigger for data-protection assessments: 50,000 consumers rather than 100,000, excluding payment-only processing. Companies using profiling for significant automated decisions must document intended uses, foreseeable harms, performance limits, safeguards and post-deployment monitoring. The attorney general may obtain those assessments during an investigation, while the documents remain confidential rather than public records.

The result is a meaningful compliance change for firms that were too small to fall under the earlier 35,000-consumer threshold, as well as financial-sector affiliates that relied on a broader exemption. The statute does not prohibit automated decision-making or data commerce. Instead, it widens who must comply and adds consent, contracting, transparency and assessment requirements before covered data can be used in higher-risk ways.