Delaware Rewrote Its Privacy Law. About 800 Delaware Visitors a Month Could Put You in Scope.
Delaware's HB 380 takes effect January 1, 2027. Here's what to check before the deadline.

Delaware's HB 380 lowers the DPDPA threshold to 10,000 residents and adds vendor due diligence rules. What ecommerce brands should check before Jan. 1, 2027.
Stay current on every state privacy change — without the overhead.
For a few years, state privacy laws followed a fairly predictable pattern. A state would pass one; it would look a lot like the laws that came before it, and businesses could reuse much of the compliance work they'd already done.
Now states are amending existing privacy laws, and those updates don't always follow the same playbook.
Delaware's HB 380 is a good example. It expands the Delaware Personal Data Privacy Act (DPDPA) in several meaningful ways, including some requirements that stand out from what other states are doing. The changes below take effect January 1, 2027.
The threshold drops, bringing more brands into scope
Today, the DPDPA applies if you process the personal data of 35,000 or more Delaware residents in a year. HB 380 cuts that threshold to 10,000.
For an ecommerce site, 10,000 residents a year works out to just over 800 unique Delaware visitors a month. That means brands that haven't paid much attention to Delaware before may need to take another look at whether the law applies to them.
There are two other important details:
- If at least 20% of your revenue comes from selling personal data, the threshold drops to 5,000 residents.
- The law also extends obligations to third parties that acquire personal data from a controller. Receiving Delaware personal data from another business subject to the DPDPA could bring you into scope even if you don't independently meet the usual thresholds.
That third-party provision is unusual. Most state privacy laws determine applicability largely based on the data your own business processes. Delaware extends some obligations further down the data-sharing chain.
Vendor contracts get a checklist, and due diligence becomes mandatory
HB 380 puts more responsibility on businesses when they share personal data with third parties. In this context, that generally means outside entities that receive personal data but don't qualify as compliant data processors.
Before disclosing personal data to a third party, you'll need a written contract that:
- Limits the sale or disclosure to specified purposes
- Obligates the third party to comply with the DPDPA and provide the same level of protection
- Grants you audit rights
- Requires the third party to notify you if it can no longer meet its obligations
- Gives you the right to stop and remediate unauthorized use
These requirements mirror language from the CCPA, so many established vendors may already have similar terms in their agreements. It's still worth checking what your contracts actually say.
The bigger change is the due diligence requirement. Businesses must conduct "reasonable due diligence" of third parties to assess their policies and technical and organizational measures. At a minimum, that includes questionnaires and a review of relevant documents. The level of review depends in part on the sensitivity of the data involved.
This gets more complicated in a typical ecommerce stack. Many brands rely on large third parties such as Google and Meta, and those companies are unlikely to complete a custom questionnaire from every retailer they work with. They may instead direct businesses to their existing privacy and security documentation.
HB 380 doesn't spell out how due diligence should work in every scenario, so businesses will need to determine what a reasonable review looks like and document the steps they take.
If your vendor list has grown faster than your records of what each vendor receives, start there. You can't conduct meaningful due diligence until you know which vendors have access to which data.
The "report" rules are broad, unclear, and include employees
This may be the hardest part of HB 380 to interpret.
If you disclose a report to a third party for use in a decision that produces "legal or similarly significant effects" on someone, HB 380 requires you to:
- Contract with the third party to provide the person with information about how the report was used
- Tell the person what personal data was involved and who received it
- Give the person an opportunity to correct that data
Other states already regulate profiling and automated decision-making. Minnesota gives consumers rights related to automated profiling, while California has ADMT regulations taking effect in 2027. Delaware addresses some similar territory, but HB 380 uses unusually broad language.
The statute defines a "report" as any written, oral, or other communication of personal data by a controller or processor. Read literally, that could reach a wide range of situations, including something as ordinary as a former employer providing a reference.
It's also unclear exactly which business practices lawmakers intended to capture. Credit reports and background checks are exempt from the DPDPA under federal law, while automated hiring tools are often operated by processors, which this particular rule may not cover.
Businesses with Delaware employees or applicants should still pay close attention. The provision includes employees, and employment decisions can produce legal or similarly significant effects. Counsel can help determine how the rule may apply to your hiring and HR practices.
Businesses that use profiling to make significant decisions may also need to conduct profiling impact assessments. That obligation, along with certain data protection assessment requirements, applies only to businesses handling the personal data of at least 50,000 Delaware residents per year.
Sensitive data now requires necessity and consent
State privacy laws generally give added protection to sensitive information such as health data, biometric data, and data revealing race or ethnicity. Many require opt-in consent before businesses process it. Maryland also restricts sensitive-data processing unless it's strictly necessary.
Delaware now brings both concepts together. Under HB 380, you can process sensitive data only when it's necessary for your disclosed purposes and you have the consumer's express consent.
Selling sensitive data is still allowed in some circumstances, but the requirements are substantial. The sale must be strictly necessary to provide a product or service, and businesses need to clearly disclose the data categories, purpose of the sale, and specific third-party recipients. Consumers must consent, and businesses must keep a record of that consent for at least five years.
For many brands, those requirements make selling sensitive data difficult to justify unless it's genuinely necessary.
Ecommerce teams in categories such as wellness, supplements, and personal care should look at this section closely. Purchase history and other customer data can reveal more about a person than teams sometimes realize.
What to do before January 1, 2027
1. Run the threshold math. Check your Delaware traffic and customer counts against the new 10,000-person threshold. If you're seeing more than 800 unique Delaware visitors a month, take a closer look at whether the updated law applies to your business. Also consider whether you receive Delaware personal data from other businesses under the new third-party provision.
2. Update your vendor map and the data they receive. The due diligence requirement assumes you know which third parties receive personal data and what they receive. For many ecommerce teams, that list grows quietly as new tools, apps and partners get added. Get the current picture documented before you start reviewing vendors.
3. Review your third-party contracts. Vendors with agreements already updated for the CCPA may cover some of Delaware's new contractual requirements. Check the actual terms so you know where updates are still needed.
4. Check how you handle sensitive data. Review where your business collects or processes sensitive data and whether you have both a necessity justification and express consent. If you sell that data, look closely at the additional disclosure and record-keeping requirements.
5. Review the report rules if you have Delaware employees. The language is broad enough that businesses with employees or job applicants in Delaware should ask counsel how the provision may affect existing hiring and HR practices.
Delaware reflects a broader privacy trend
HB 380 matters on its own, but it also shows where state privacy compliance is headed. Passing a law is no longer the end of the story. States are revisiting existing rules, expanding requirements, and creating new obligations businesses have to keep up with over time.
Your business is changing at the same time. Vendors get added, tracking setups evolve, customer data moves through new systems, and privacy workflows can gradually fall out of sync with how the business actually operates.
That's the operational problem TrueVault helps ecommerce teams manage. We track regulatory changes like HB 380, help you understand which ones matter for your business, and give you practical ways to keep policies, workflows, and vendor oversight current as things change.
You don't need to become an expert in Delaware statutory drafting. You need to understand what changed, how it may affect your business, and what deserves your attention first.
If you're not sure where HB 380 leaves you, we can help you figure that out.
Privacy work that stays current — without adding more chaos.
TrueVault helps lean ecommerce teams keep privacy workflows current as vendors, tracking tools, and privacy laws keep changing.





