Delaware Lowers Privacy Law Thresholds to Expand Business Oversight
Amendments to the Personal Data Privacy Act will bring more companies under regulatory scrutiny starting in 2027.
Delaware is expanding the reach of its consumer privacy framework through new legislative amendments that lower the threshold for business compliance. Passed by the Delaware General Assembly on June 16, 2026, these changes ensure a broader range of companies must adhere to strict data handling standards.
House Bill (HB) 380 amends the Delaware Personal Data Privacy Act (DPDPA), which was enacted in 2023 and went into effect on January 1, 2025. The primary shift introduced by HB 380 is a significant reduction in applicability thresholds. While the DPDPA originally applied to entities handling the data of 35,000 or more consumers, the new legislation reduces this threshold to 15,000 consumers, according to Clym.
The Shift in Compliance
This legislative move reflects a growing trend among U.S. states to tighten privacy controls and bring smaller-to-mid-sized enterprises under regulatory oversight. By lowering the consumer count required to trigger the law, Delaware is increasing the number of businesses that must implement formal data privacy programs, provide transparency regarding data collection, and honor consumer rights requests.
Why It Matters
For the industry, this means companies previously exempt from the DPDPA due to their size must now audit their data pipelines and legal frameworks. The reduction in the threshold suggests that Delaware regulators view a larger volume of smaller data controllers as posing a meaningful risk to consumer privacy. Businesses that fail to prepare for these expanded requirements risk regulatory penalties as the state moves toward a more inclusive enforcement model.
What's Next
The amendments introduced by HB 380 are scheduled to take effect on January 1, 2027. This provides affected businesses with a grace period to align their operations with the updated law. While the core updates to the DPDPA are set, industry observers are continuing to monitor the broader landscape of Delaware's data breach and privacy updates to determine the full scope of the state's evolving regulatory posture. This shift signals a transition toward a more aggressive privacy posture, mirroring national trends where state-level protections are becoming the primary guardrail for consumer data in the absence of a comprehensive federal privacy law.