Cybersecurity Policy Report, Two Privacy Bills Advance in Delaware House, (May 26, 2026)
The Delaware state House has passed two bills aimed at protecting consumer privacy, including a bill to amend the Delaware Personal Data Privacy Act to expand consumer rights, lower applicability thresholds, strengthen protections for sensitive data, and require stricter contracts and due diligence for data sharing.
“At a time when algorithms sometimes know more about us than even our closest friends and family, it is more important than ever to ensure that consumers’ sensitive personal data is protected and cannot be misused by bad actors,” said bill sponsor Rep. Krista Griffith (D.).
The House voted 30-9 to pass HB 380, which would lower the applicability threshold, making the law apply to entities that process the personal data of at least 10,000 consumers (down from 35,000) or 5,000 consumers if more than 20% of gross revenue is derived from selling personal data and includes third parties acquiring personal data.
The bill would also expand definitions of sensitive data to include neural data, financial account information, and government-issued IDs and clarify that biometric data collected without consent was not considered publicly available information.
The bill also would impose additional terms on contractual agreements and due diligence when controllers disclose or sell personal data to third parties. According to the bill, these contracts must specify the purposes of data use, require third parties to comply with the privacy law, and grant controllers oversight rights. Bill sponsor Sen. Marie Pinkney (D.) said this “first of its kind due diligence obligation” would require controllers to make sure that any third-party to which they sell or disclose personal data are properly and securely handling that information.
“Algorithms play a huge role in Delawareans’ day-to-day lives, and it’s our responsibility to strengthen our data privacy laws to better protect our neighbors in this new age,” Sen. Pinkney said in a statement.
In addition, the bill would prohibit the processing of personal data of a consumer when the controller has actual knowledge that the consumer is a child. HB 380 has an effective date of Jan. 1, 2027.
The House also passed HB 381 which would expand the state’s data breach law to better inform the Department of Justice’s Fraud and Consumer Protection Division of security breaches. Under HB 381, businesses would also be required to provide notice to the attorney general’s office within 60 days of the determination of a breach. Currently, the attorney general’s office is only informed when a security breach affects more than 500 Delaware residents.
“As technology advances and personal data becomes more valuable, we need to raise the guardrails that protect Delawareans. HB 380 and 381 modernize Delaware’s data privacy protections to keep pace with AI, require your consent if a company wants to sell your sensitive data, and help ensure that your data stays yours. I’m grateful to Rep. Griffith for her strong leadership,” Attorney General Kathy Jennings (D.) said in a statement.
The bills (H.B. 380 and H.B. 381, Reg Sess.) now head to the Senate for consideration.
“Together, HB 380 and HB 381 will help to ensure that Delawareans can continue to participate in an increasingly digital world, with the comfort of knowing that we have some of the strongest data privacy protections in the country,” Rep. Griffith added.
News: StateLegislation DataPrivacy DataBreach