Davis Wright Tremaine·PRIVACY / DATA SECURITY

Delaware Amends Data Privacy Act, Expands Scope

Recently enacted amendments to the Delaware Personal Data Privacy Act significantly lower applicability thresholds and impose new requirements for handling sensitive data, profiling, and third-party due diligence, effective January 1, 2027.

Delaware has enacted significant amendments to its Personal Data Privacy Act (DPDPA), expanding its scope and imposing stricter compliance obligations effective January 1, 2027. The changes lower the law's applicability threshold to businesses that control or process the data of just 10,000 Delaware consumers, down from 35,000, and create a new, lower 5,000-consumer threshold for businesses that derive over 20% of revenue from selling personal data.

Sophisticated counsel should note the broadened definition of 'sensitive data,' which now includes inferences and requires explicit consent and purpose limitation for processing. The amendments introduce stringent new rules for profiling, requiring controllers to provide enhanced disclosures and conduct regular impact assessments. The law also mandates new contractual requirements and 'reasonable due diligence' for sharing data with third parties. Additionally, the exemption for entities covered by the Gramm-Leach-Bliley Act has been narrowed from an entity-level to a data-level exemption, potentially bringing more financial services firms into scope. Businesses should reassess their DPDPA exposure and update their privacy compliance programs, including vendor contracts and data protection assessments, ahead of the 2027 effective date.

delawaredpdpastate-privacy-lawconsumer-privacydata-protectionsensitive-dataprofiling
Read the original firm alert → Friday, September 11, 2026

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.