Delaware enacts automated decision opt-out right and broadens data privacy law’s reach
On September 2, the Delaware governor signed into law HB 380, amending the Delaware Personal Data Privacy Act by adding a right to opt out of automated decisions that produce legal or similarly significant effects — defined to include decisions resulting in the provision or denial of financial or lending services, housing, insurance, education, criminal justice, employment, health care, or access to essential goods or services. The law requires controllers that disclose profiling reports to third parties used in such decisions to enter into contracts obligating the third party to provide notice to residents of any adverse action, a description of the personal data relied upon, a statement that the resident may obtain further information from the controller, and an opportunity for human review.
The law lowers the applicability threshold from 35,000 consumers whose personal data a business controls or processes to 10,000 consumers, and from 10,000 consumers to 5,000 in cases where a business derives more than 20 percent of gross revenue from data sales. The law also applies to third parties that acquire personal data from a controller, regardless of any numeric threshold. The law replaces the prior entity-level exemption for financial institutions subject to the GLBA with narrower exemptions limited to banks, credit unions, savings associations, insurers, and their affiliates principally engaged in financial activities, and to securities agents, broker-dealers, and investment advisers regulated by the state or the SEC. The law expands the definition of sensitive data to include national origin, citizenship and immigration status, pregnancy and treatment status, status as transgender or nonbinary, neural data, financial account credentials, and government-issued identification numbers, and treats inferences drawn from personal data as sensitive when used to reveal or identify a sensitive category.
The law further restricts sales of sensitive data, requiring that any such disclosure be strictly necessary to a product or service requested by the consumer, accompanied by clear notice identifying the categories of sensitive data and third-party recipients, and supported by the consumer’s consent and a five-year record-retention obligation. The law also narrows the employee-data exemption to exclude personal data processed in connection with profiling and reports, imposes new third-party due diligence and contracting requirements on controllers, and lowers the data protection assessment threshold from 100,000 to 50,000 consumers. The amendments take effect January 1, 2027.