Delaware Expands Data Privacy Law With Automated Decision Profiling Opt-Out Right
Delaware has enacted significant changes to its consumer privacy law, including an expanded right for consumers to opt out of profiling used in furtherance of automated decisions involving financial services, housing, employment, healthcare, and other consequential areas.
Governor Matt Meyer signed House Bill 380 (HB 380) into law on September 2, amending the Delaware Personal Data Privacy Act (DPDPA). The changes take effect January 1, 2027.
Among the most notable provisions is a consumer right to opt out of automated decision-making when the resulting decision produces legal or similarly significant effects.
The legislation also lowers the thresholds determining which businesses are subject to the DPDPA, expands the categories of information considered sensitive, and introduces additional requirements involving profiling, third-party data sharing, and data protection assessments.
Automated Decisions Face New Consumer Protections
HB 380 addresses automated decision-making involving areas that can have significant consequences for consumers.
Under the amendments, consumers may opt out of the processing of their personal data for profiling in furtherance of automated decisions that produce legal or similarly significant effects. This can be related to financial or lending services, housing, insurance, education, criminal justice, employment, healthcare, or access to essential goods or services.
The law also establishes requirements when a controller provides a profiling report to a third party for use in making such a decision.
Controllers must enter into contracts requiring the third party to provide affected residents with information when an adverse action occurs. That includes notice of the adverse action, a description of the personal data relied upon, information about obtaining further details from the controller, and an opportunity for human review.
For financial services and other organizations using data-driven decision systems, the changes introduce another state-level consideration around how automated decisions and profiling are managed.
More Businesses Could Fall Under Delaware Privacy Law
HB 380 substantially lowers the DPDPA’s applicability thresholds.
Previously, the law generally applied to businesses controlling or processing personal data belonging to at least 35,000 consumers. The amendment lowers that threshold to 10,000 consumers.
For businesses deriving more than 20% of their gross revenue from selling personal data, the applicable threshold falls from 10,000 to 5,000 consumers.
The legislation also extends requirements to third parties acquiring personal data from a controller regardless of the numerical thresholds, further broadening the law’s potential reach.
Financial Institution Exemption Becomes Narrower
The amendments also change how the law applies to the financial sector.
Previously, financial institutions subject to the Gramm-Leach-Bliley Act (GLBA) benefited from an entity-level exemption. HB 380 replaces that approach with narrower exemptions.
According to the legislation, exemptions remain for specified entities such as banks, credit unions, savings associations, insurers, and certain affiliates principally engaged in financial activities. Certain securities agents, broker-dealers, and investment advisers regulated by Delaware or the Securities and Exchange Commission are also covered by exemptions.
The narrower approach means organizations operating in or alongside financial services may need to determine whether their activities and organizational structure remain within an exemption.
Sensitive Data Definition Expands
Delaware is also expanding the types of personal information subject to heightened protections.
HB 380 adds categories including national origin, citizenship and immigration status, pregnancy and treatment status, transgender or nonbinary status, neural data, financial account credentials, and government-issued identification numbers.
Inferences generated from other personal information can also qualify as sensitive data when they are used to reveal or identify a sensitive category.
The legislation further restricts the sale of sensitive data. Such disclosures generally must be strictly necessary for a product or service requested by the consumer and accompanied by clear notice identifying the sensitive-data categories and third-party recipients.
Consumer consent is also required, with records of that consent subject to a five-year retention requirement.
New Requirements Extend to Third-Party Data Practices
The amendments introduce additional responsibilities involving third parties.
Controllers face new due-diligence and contracting requirements when working with third parties that receive personal data. The changes also narrow the existing employee-data exemption when personal information is processed in connection with profiling and related reports.
Data protection assessments will apply more broadly as well. The threshold triggering assessment requirements is being reduced from 100,000 consumers to 50,000 consumers.
Together, the changes expand the scope of both the organizations and data-processing activities that may require closer privacy review.
Changes Take Effect in January 2027
HB 380 takes effect January 1, 2027, giving affected organizations time to assess the new requirements. Businesses using automated decision-making may need to review opt-out procedures, profiling practices, human-review processes, and third-party contracts.
The lower applicability thresholds and narrower financial-sector exemptions could also bring more organizations under the DPDPA. For receivables, lending, and other data-driven financial services, the amendments add new privacy considerations as automated decision-making becomes more widely used.