delaware

As we flagged last month in our mid-year U.S. privacy roundup, the Delaware legislature recently passed House Bill 380 (“HB 380”), which amends the Delaware Personal Data Privacy Act (the “Act”) in ways that impose significant new, and in many ways complex and novel, requirements on controllers, processors and third parties.  On September 2, 2026, Delaware Governor Matt Meyer signed House Bill 380 into law and thus amended what was already a fairly strict state consumer privacy law. These amendments significantly lower the volume-based thresholds for applicability, create new obligations for providers of “reports” used to make certain types of decisions and businesses that use that data, add new requirements for consumer rights, impose restrictions on profiling job applicants, employees and independent contractors, and require contracts with and obligations from third parties that receive personal data (e.g., sales), among many other changes. These amendments will become effective on January 1, 2027.

Businesses that are subject to the Act (of which there will be many more as a result of HB 380) should carefully review the amended Act to determine their new obligations, including the significant amendments discussed below.  Financial institutions in particular should determine whether they must now comply with the Act, as the broad exemption for financial institutions subject to Title V of the Gramm-Leach-Bliley Act (the “GLBA”) has been replaced by a narrower exemption for only certain types of financial institutions and certain of their affiliates (see discussion below).

Continue Reading Amendments to Delaware’s Consumer Privacy Law Deepen the Morass of State Privacy Regulation