Delaware Adds New Requirements for Sensitive Data, Third-Party Contracts

Delaware Adds New Requirements for Sensitive Data, Third-Party Contracts

Blog WilmerHale Privacy and Cybersecurity Law

On September 2, 2026, Delaware Governor Matt Myer signed House Bill 380 (“HB 380”) into law, amending the Delaware Personal Data Privacy Act (“DPDPA”) to, among other things, create new restrictions for sensitive data that go into effect on January 1, 2027. Delaware now joins Maryland and New Jersey on the growing list of states that prohibit the “sale” of sensitive data. HB 380 also only permits controllers to process sensitive data if the processing is “reasonably necessary and proportionate” to the controller’s disclosed purposes for processing such data. These new amendments create meaningful obligations for companies that engage in targeted advertising and, arguably, make Delaware the state with the most stringent requirements governing sensitive data.

Furthermore, with HB 380, Delaware joins California as the second state to require contractual provisions for the disclosure of personal information to third parties. HB 380 also adds requirements for contracts between controllers and processors that go beyond the requirements in many other states. Companies should reevaluate their vendor and third-party contracts in light of these amendments.

For companies, this is a growing trend to pay attention to. New privacy laws (and amendments to existing laws) are focused on adding substantive requirements to data processing activities, including through restrictions on how businesses are able to process certain categories of data and broader data minimization requirements. Businesses can no longer rely on the disclosures in their privacy policies to reserve broad rights in relation to how they are permitted to use consumer data. They are increasingly required to analyze the substantive data processing limitations imposed by US state laws.

Notably, not all states are leaning into this trend. On September 27, 2026, California Governor Gavin Newsom vetoed Assembly Bill 1542, which would have similarly prohibited the “sale” of sensitive data. Newsom wrote in his veto message that, while he supported “protecting the sensitive personal information of Californians, a categorical ban on sharing that information is a step too far.” Whether other states follow Delaware’s or California’s lead on this issue remains to be seen.

In this post, we highlight the recent amendments to the DPDPA and summarize HB 380’s key provisions. To stay up to date on the latest state privacy law developments, please subscribe to the WilmerHale Privacy and Cybersecurity Law Blog.

HB 380

HB 380 makes several notable amendments to the DPDPA, including the following:

  • Expanded Definition of Sensitive Data: HB 380 expands the definition of sensitive data to include “inferences made based on personal data, alone or in combination with other data, that are used to reveal or identify” certain categories of sensitive data under the DPDPA. HB 380 also expands the categories of sensitive data under the DPDPA to include data that reveals or identifies a consumer’s national origin, mental or physical health treatment or status (in addition to the pre-existing categories of mental or physical condition or diagnosis), neural data, and certain financial data that would allow access to a consumer’s financial account.
  • Additional Requirements for Processing Sensitive Data: HB 380 amends the DPDPA to prohibit a controller from processing a consumer’s sensitive data unless the consumer consents to their sensitive data being processed and the processing is “reasonably necessary and proportionate” to the controller’s disclosed purposes for processing the sensitive data.
  • Additional Requirements for the Sale of Sensitive Data: HB 380 also amends the DPDPA to prohibit the sale of sensitive data unless (1) the disclosure of sensitive data is “strictly necessary” to provide or maintain a product or service affirmatively requested by the consumer; (2) the controller provides a “clear and conspicuous” notice of the sale of personal data before the sale, including the specific categories of sensitive data to be disclosed, the purpose of the disclosure, and the identity of the third parties to which sensitive data will be disclosed; (3) the controller obtains the consumer’s consent; (4) the controller maintains a record of the consumer’s consent for a period of five years; and (5) the record of consent of Delaware consumers must be provided with any data protection assessment requested by the Delaware attorney general.
  • Additional Processor Contracting Requirements: In addition to the pre-existing obligations, HB 380 requires the contract between controllers and processors to “identify each limited and specific purpose for which the processor is processing personal data. The contract must specify that the controller is disclosing the personal data to the processor only for the limited and specific purposes set forth within the contract. The specific purposes may not be described in generic terms, such as referencing the entire contract generally, but must be described with specificity and particularity.”
  • Additional Third-Party Contracting Requirements: When controllers enter into binding contracts with third parties to which personal data is disclosed, HB 380 requires that these contracts have the following terms and conditions: (1) specifying that the personal data is sold or disclosed by the controller only for limited and specified purposes, including whether the purpose includes use for decisions that produce legal or similarly significant effects; (2) obligating the third party to comply with this chapter and obligating the third party to provide the same level of privacy protection as is required by the law; (3) granting the controller rights to take reasonable and appropriate steps to ensure that the third party uses the personal data transferred by the controller in a manner consistent with the controller’s obligations under the law; (4) requiring the third party to notify the controller if it makes a determination that it can no longer meet its obligations under the law; and (5) granting the controller the right upon notice to take reasonable and appropriate steps to stop and remediate the unauthorized use of personal data.
  • New Obligations for De-identified Data: HB 380 requires controllers that disclose de-identified data to exercise reasonable oversight to monitor compliance, including entering contractual commitments to ensure the proper and limited use of de-identified data and to take appropriate steps to address any breaches related to those contractual commitments.
  • Exemption for Information Derived From PHI: HB 380 amends the DPDPA to include an exemption for information derived from PHI regulated under HIPAA, in addition to the DPDPA’s pre-existing information-level exemption for PHI under HIPAA.

Authors

More from this series

Notice

We appreciate your interest in WilmerHale. While we are pleased to have you contact us, please keep in mind that merely contacting WilmerHale does not create an attorney-client relationship. Such a relationship will not arise until the Firm agrees in writing to represent you in connection with a particular matter. Importantly, unless and until this has occurred, you should not provide us with any confidential information, and we have no duty to keep confidential any information that we may receive from you. Thank you for your understanding.