Comprehensive Privacy Law
Delaware Personal Data Privacy Act
Delaware · Jan 1, 2025 (HB 380 amendments effective Jan 1, 2027)
Lower thresholds than most states: applies at 35,000+ Delaware consumers, or 10,000+ if 20%+ of revenue comes from selling personal data. Nonprofit exemption only covers insurance-fraud-prevention organizations — most nonprofits are covered. No entity-level HIPAA exemption — only specific health data (PHI, public-health/research data) is exempt, so HIPAA-covered entities/business associates remain subject to the DPDPA for other personal data they process. No higher-education exemption — the law's government-entity exemption expressly excludes institutions of higher education. HB 380 is now law — signed Sep 2, 2026, effective Jan 1, 2027 — and the thresholds shown here are only the ones in force until then. On Jan 1, 2027 the general threshold drops to 10,000 consumers and the sale-based threshold to 5,000 consumers with 20%+ of gross revenue from data sales, which the Governor's office describes as the lowest in the country, and a third trigger with no volume test at all reaches any third party that acquires personal data from a controller. The same amendment makes the GLBA carve-out a data-level exemption for all GLBA-regulated data while limiting entity-level exemptions to banks and insurers (and affiliates principally engaged in financial activities), expands sensitive data to include neural data, financial account credentials, government ID numbers and inferred sensitive characteristics, adds an opt-out of profiling used in significant automated decisions, narrows the employee-data exclusion for those decisions, and adds third-party contracting and due-diligence duties.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual revenue, data volume, and data types.