UPDATE: Delaware Amends Personal Data Privacy Act
Lower Applicability Thresholds. The most immediate impact of HB 380 will be to lower the DPDPA's applicability thresholds. As of January 1, 2027, the DPDPA will apply to any person who conducts business in Delaware, or produces products or services targeted to Delaware residents, and during the preceding calendar year controlled or processed the personal data of at least 10,000 Delaware consumers, down from the original threshold of 35,000 (still excluding consumers whose personal data was controlled or processed solely to complete a payment transaction). The threshold for persons that sell personal data of Delaware consumers was lowered from 10,000 to 5,000 if the persons derive more than 20% of their gross revenue from the sale of personal data. Delaware Governor Matt Meyer touted these thresholds as the lowest in the nation.
New Category of Applicability. In addition, the DPDPA will apply to third parties who acquire personal data from a controller.
Revised Exemptions. HB 380 amends the DPDPA's Gramm-Leach-Bliley Act (GLBA) applicability exemptions, adopting an approach similar to laws in Connecticut, Montana, and Oregon, by exempting all data regulated by the GLBA while limiting entity-level exemptions specifically to banks, broker dealers, and insurers and their respective affiliates. There will be new health-related data-level exemptions, including for information in a limited data set de-identified as provided in HIPAA.
Sensitive Data. The amendment broadens "sensitive data" to explicitly include "inferences" based on non-sensitive personal data that reveal sensitive data categories. HB 380 also adds new categories of sensitive data, including: national origin (in addition to existing terms covering racial or ethnic origin, religious beliefs, and mental or physical health conditions); treatment as transgender or nonbinary (in addition to "status" as transgender or binary); neural data; financial account log-in credentials and credit or debit card numbers, that alone or in combination with other data would allow access to the account; and government-issued identification numbers, including SSNs, passport numbers, and driver's license numbers. Controllers must obtain consent before processing sensitive data. Moreover, any processing of sensitive data must also be "reasonably necessary and proportionate to the disclosed purposes for processing sensitive data." While the DPDPA already prohibited processing data of a "known child" without parental consent, it will now require that the controller not process personal data of a consumer when the controller "has actual knowledge or willfully disregards that the consumer is a child." Child in the DPDPA means as defined in COPPA.
Controllers may not sell sensitive data unless the disclosure is "strictly necessary" to provide or maintain a product or service affirmatively requested by the consumer; the controller provides clear and conspicuous notice prior to the sale specifying the categories of sensitive data along with the purpose for disclosure and identity of the recipient; the consumer consents; and the controller maintains a record of consent for five years and provides the record with any data protection assessment. Although disclosures of personal data to third parties for the purpose of providing a product or service affirmatively requested by a consumer are exempt from the definition of "sale," any such disclosures of sensitive data must satisfy the provisions described above.
New Duties for Controllers
Reports used in Connection with Certain Decisions. Controllers that disclose a "report" on Delaware residents (any written, oral, or other communication of any personal data by a controller or processor, including recommendations, summaries, or automated decisions based on personal data or profiling) to be used for making a decision that produces any legal or similarly significant effect concerning a Delaware resident (including individuals acting in an employment context), must enter into a binding agreement with the recipient of the report.
Unless the report is furnished or disclosed pursuant to FCRA, the agreement must require the recipient to (1) provide notice to a resident of any adverse action based in whole or part on the information in the report, (2) describe the personal data relied on to take the adverse action, (3) inform the resident that he or she may obtain the data from the controller (see below), and (4) include a statement that the resident may request human review of the decision, unless certain exceptions apply. The information the controller will be obligated to provide includes the personal data maintained by the controller, the source of the data used in profiling, and identification of all third parties who received the report within the previous 24 months. The controller also must provide an opportunity to correct any incorrect personal data.
"Adverse action" means "any denial, cancellation, unfavorable change, increase in charge, exclusion of benefit, or other action adverse to the interests of a consumer or resident in connection with a decision that produces legal or similarly significant effects." HB 380 slightly amends the definition of "legal or similarly significant effects" to delete "consumer" as it applies to residents, and delete the decisions made by the "controller" as it applies to decisions or the provision or denial of services made by third parties. HB 380 also defines the FCRA reports that are excluded from the above provisions to include disclosure of a "report or personal data [that] consists of a score, a model, an algorithm, or similar output that is a consumer report" disclosed in compliance with FCRA.
Profiling. Controllers will be prohibited from engaging in profiling in violation of laws that prohibit discrimination. It will be important for controllers to develop and retain evidence of anti-bias testing of the tools used for profiling, because regulators will consider evidence—or lack of evidence—concerning proactive anti-bias testing (or similar proactive efforts) to avoid procession in violation of the laws, when considering any claim or enforcement action related to profiling. As when processing personal data for sales or targeted advertising, controllers will be required to provide clear and conspicuous disclosures regarding the processing of personal data for profiling.
Data Minimization. HB 380 amends the existing data minimization requirements to require that the processing—not just the "collection"—of personal data be limited to what is reasonably necessary "and proportional" (rather than "adequate" and "relevant") in relation to the purposes for which such data is processed, as disclosed to the consumer. Personal data must not be processed for "any additional purpose that is not reasonably necessary and proportionate" to the purposes disclosed to the consumer "at the time of collection" unless the controller obtains the consumer's consent.
Consent Required for Certain Processing of Minors' Personal Data. Controllers will be prohibited from processing the personal data of consumers whom it has actual knowledge or willfully disregards are at least 13 but younger than 18 years of age for profiling, targeted advertising, or in connection with the sale of such data.
Reasonable Due Diligence of Third Parties Required. Controllers must observe new contractual and reasonable due diligence requirements for disclosing or selling data to third parties, including for targeted advertising. Before disclosing or selling personal data, controllers must assess and review the third party's "policies and technical and organizational measures" to support and demonstrate compliance with the DPDPA, and include contractual provisions that specify the purpose for the disclosure, require the third party to comply with the DPDPA with respect to the disclosed personal data, require the third party to notify the controller if the third party can no longer comply with the DPDPA, and allow the controller to take steps to ensure the third party complies with the DPDPA. This includes taking steps to stop and remediate unauthorized use of personal data. Reasonable due diligence requires, at a minimum, assessing the third parties through the use of questionnaires and a review of relevant documents.
Privacy Notice Requirements. HB 380 added new requirements for privacy notices, including that they must be "reasonably particular to the product or service offered" and must identify the controller and provide a description of personal data rights.
Contractual Obligations Regarding De-Identified and Pseudonymous Data. Controllers that disclose pseudonymous data or de-identified data must enter into contractual commitments that ensure the proper and limited use of such data.
Data Protection Assessments. Finally, HB 380 will now require controllers that process the data of 50,000 consumers (down from 100,000) to conduct data protection assessments. Controllers that engage in profiling in furtherance of automated decisions that produce legal or similarly significant effects concerning a consumer (not just a resident) must also "conduct and document, on a regular basis, an impact assessment."
The impact assessment must include, to the extent reasonably known by or available to the controller: (1) the purpose, intended use cases, deployment context of, and benefits afforded by, such profiling; (2) whether profiling poses any known or reasonably foreseeable heightened risk of harm to a consumer, and, if so (a) the nature of the heightened risk of harm, and (b) the steps that have been taken to mitigate the heightened risk of harm; (3) a description of the main categories of personal data processed as inputs for the purposes of profiling and the outputs the profiling produces; (4) an overview of the main categories of personal data the controller used to customize profiling, if so used; (5) any metrics used to evaluate the performance and known limitations of profiling; (6) a description of any transparency measures taken concerning the use of profiling, including any measures taken to disclose to consumers that the controller is engaged in profiling while the controller is engaged in profiling; and (7) a description of the post-deployment monitoring and user safeguards provided concerning profiling, including the oversight, use, and learning processes established by the controller to address issues arising from profiling.
New Duties for Processors
The contract between the controller and processor must require the processor to provide information necessary for a controller or the controller's designated assessor to assess the processor for purposes of due diligence, and it must identify each limited and specific purpose for which the processor will process personal data. A description of the processing purpose cannot be provided in generic terms—e.g., to fulfill the purpose of the agreement.
New Duties for Third Parties
HB 380 adopts the approach taken by the California Consumer Privacy Act Regulations in requiring a controller to impose certain contractual obligations on third parties to whom the controller sells or otherwise discloses personal data. Such contracts must include the following terms: (1) specify that personal data is sold or disclosed only for limited and specified purposes, including whether the purpose includes use for decisions that produce legal or similarly significant effects; (2) obligate the third party to comply with the DPDPA and to provide the same level of privacy protection that the Act requires; (3) grant the controller the right to take reasonable and appropriate steps to ensure that the third party uses the personal data in a manner consistent with the controller's obligations under the Act; (4) require the third party to notify the controller if it makes a determination that it can no longer meet its obligations under the Act; and (5) grant the controller the right upon notice to take reasonable and appropriate steps to stop and remediate unauthorized use of personal data.
Consumer Rights
HB 380 amends the consumer's right to confirm and access personal data by "including any inferences about the consumer derived from such personal data and whether a controller or processor is processing a consumer's personal data for the purpose of profiling to make a decision that produces any legal or similarly significant effect concerning the consumer," unless such confirmation or access would require the controller to reveal a trade secret. HB 380 will also require controllers to provide a list (not just categories) of third parties to which the controller disclosed the consumer's personal data, unless it is pseudonymous data, the controller cannot make a list with reasonable effort, or the listing of a third party would disclose a trade secret. In the event the list cannot be made with reasonable effort, then the controller must disclose all third parties to which the controller discloses personal data. Finally, HB 380 expands consumers' right to opt out of profiling in furtherance of automated decisions that produce legal or similarly significant effects to include any automated decisions and not just "solely" automated decisions. The amendment therefore expanded the scope of automated decisions covered to include at least some where humans are involved.
The original post from September 13, 2023, appears below.
Delaware's New Personal Data Privacy Act
Delaware becomes the 13th state to enact a comprehensive consumer data privacy law
By Michael T. Borgia, Benjamin Robbins, and Patrick J. Austin
The Delaware Personal Data Privacy Act (DPDPA or Act) became law on September 11, 2023, making Delaware the 13th state to enact a comprehensive consumer data privacy law, joining California, Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Tennessee, Montana, Florida, Texas, and Oregon. The DPDPA will become effective on January 1, 2025. We highlight key aspects of the DPDPA below.
Application Thresholds
The DPDPA applies to persons who conduct business in Delaware or produce products or services targeted to Delaware residents and who, during the preceding calendar year, either: (1) controlled or processed the personal data of at least 35,000 Delaware residents (excluding personal data controlled or processed solely for the purpose of completing a payment transaction); or (2) controlled or processed the personal data at least 10,000 Delaware residents and derived more than 20% of their gross revenue from the sale of personal data.
- The 35,000-consumer threshold is the lowest among states with enacted consumer data privacy laws (Montana comes in second with a 50,000-consumer threshold), likely to account for Delaware's smaller population.
Notable Provisions
- Applicability to Nonprofits: Following the privacy laws in Colorado and Oregon, the DPDPA broadly applies to nonprofit organizations and the data they collect. Other state privacy laws exempt nonprofits. The DPDPA contains limited exemptions for: (1) nonprofit organizations "dedicated exclusively to preventing and addressing insurance crime," and (2) the personal data of victims and witnesses of sexual and violent crimes "that is collected, processed, or maintained" by nonprofit organizations that provide services to those populations.
- No HIPAA Entity-Level Exemption: Delaware does not provide an exemption for covered entities and business associates subject to the Health Insurance Portability and Accountability Act of 1996 (HIPAA). Rather, the DPDPA contains several more limited exemptions for specific types of health data, including protected health information (PHI) covered by HIPAA.
- Broad GLBA Exemptions: The DPDPA exempts both financial institutions and personal data subject to the Gramm–Leach–Bliley Act (GLBA).
- B2B and Employment Exemption. The DPDPA defines "consumer" to "not include an individual acting in a commercial or employment context…."
- Universal Opt-Out Mechanisms: Delaware requires controllers to recognize universal opt-out mechanisms beginning January 1, 2026.
- Definitions of Profiling, Sensitive Data, and Genetic Data: Like other state privacy laws, the DPDPA provides consumers with the ability to opt out of "profiling" (among other things).[1] However, in a first among such laws, the DPDPA includes "demographic characteristics" in the list of features about an individual that may be derived from profiling. As a result, the DPDPA broadens the concept of profiling—and therefore provides consumers a broader right to opt out of profiling activities. Additionally, the Delaware law includes "status as transgender or nonbinary" in its definition of "sensitive data" and, for the first time in a state privacy law, provides a specific definition of "genetic data"[2] as a category of sensitive data.
- Right to Obtain List of Categories of Third Parties: The DPDPA departs from other state privacy laws in allowing consumers to obtain a list of the categories of third parties to which the controller has disclosed that particular consumer's personal data. Other state privacy laws require controllers to list the categories of third parties to which they disclose consumers' personal information generally. This may be challenging, as businesses regularly shift relationships, and accurately tracking and keeping up to date with all of the disclosure relationships for each consumer may require significant resources.
- Children's Data – Restrictions on Sales and Targeted Advertising: If a controller has actual knowledge, or willfully disregards, that the consumer is at least 13 years old but younger than 18 years old, the controller must not "process the personal data . . . for purposes of targeted advertising, or sell the consumer's personal data without the consumer's consent."
- 60-Day Cure Period with Sunset Provision: The DPDPA provides controllers and processors 60 days to cure violations following receipt of notice of the violations from the Delaware Department of Justice (the state's office of the attorney general) "if the Department of Justice determines that a cure is possible." However, that cure provision sunsets on December 31, 2025. After that date, the Delaware Department of Justice may, at its discretion, provide controllers and processors an opportunity to cure violations when considering the scope and nature of the violations at issue.
- Additional Requirements for Liability Shield: A controller or processor will not be responsible for its processor's (or subprocessor's) or a third party's violation of the DPDPA if (i) at the time of disclosure the controller or processor did not have actual knowledge that the recipient had violated—or would violate—the Act, and (ii) the controller or processor was, and remained, in compliance with its obligations as the discloser. This second prong does not exist in other state privacy laws, which focus only on the compliance of the receiving entity.
Consumer Rights
The DPDPA provides Delaware residents the rights to the following, which mostly are typical across U.S. state privacy laws:
- Confirm whether a controller is processing their personal data and access to their personal data;
- Correct inaccuracies in the consumer's personal data;
- Delete personal data provided by, or obtained about, the consumer;
- Obtain a copy of their personal data processed by the controller in a format that allows the consumer to transmit that data to another controller;
- Opt out of the processing of the personal data for the following purposes:
- Targeted advertising;
- The sale[3] of personal data; and
- Profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the consumer.
The DPDPA also permits consumers to obtain a list of the categories of third parties to which the controller disclosed the specific consumer's personal data. Only Oregon's data privacy law contains a similar right. Other state privacy laws permit consumers only to obtain the categories of third parties to which the controller discloses personal data generally (not specific to the requesting consumer).
Children's Data
If a controller has actual knowledge, or willfully disregards, that the consumer is at least 13 years old but younger than 18 years old, it must not "process the personal data . . . for purposes of targeted advertising, or sell the consumer's personal data without the consumer's consent." Data of consumers whom companies know to be under 13 years old is a category of "sensitive data" and cannot be processed for any purpose without the consent of a parent or guardian. Companies that comply with the consent requirements of the Children's Online Privacy Protection Act (COPPA) are deemed to comply with the DPDPA's parental consent requirements.
Information Security
Like other state privacy laws, the DPDPA requires companies to maintain "reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data appropriate to the volume and nature of the personal data at issue." The law does not enumerate any specific required security safeguards (such as encryption or multifactor authentication).
Exemptions
The DPDPA exempts a variety of entities and types of data, including:
- Any financial institution or affiliate of a financial institution subject to Title V of the GLBA.
- A national securities association registered pursuant to § 15A of the Securities Exchange Act of 1934.
- Registered futures association so designated pursuant to § 17 of the Commodity Exchange Act.
- PHI as defined under HIPAA.
- Patient-identifying information for purposes of 42 U.S.C. § 290dd-2.
- Personal data collected, processed, sold, or disclosed in compliance with the Fair Credit Reporting Act (FCRA), Driver's Privacy Protection Act, the Farm Credit Act, and the Airline Deregulation Act.
- Personal data regulated by the Federal Education Rights and Privacy Act (FERPA).
- Information relating to individual job applicants, agents, independent contractors, and employees of a controller, processor, or third party "to the extent that the data is collected and used within the context of [their] role," including emergency contact and benefits information. Separately, the DPDPA excludes "individual[s] acting in a commercial or employment context" from the definition of "consumer," thereby exempting all data processed from individuals acting in these capacities.
While these exemptions are largely similar to those in other state privacy laws, the DPDPA notably has no broad exemption for HIPAA-covered entities and business associates. Rather, the DPDPA contains several more limited exemptions for specific types of health data, including HIPAA-covered PHI. At least some of the data held by HIPAA-covered entities and business associates is not PHI (for example, data of employees and certain marketing-related data), so those entities will have to conduct detailed assessments of their compliance obligations under the DPDPA based on the nature and status of the personal data they process.
Privacy Notices
Like the other comprehensive state privacy laws, the DPDPA requires controllers to provide consumers with a "reasonably accessible, clear, and meaningful" privacy notice that discloses the categories of personal data processed, the purpose for such processing, how consumers may exercise their rights (e.g., the right to delete), the categories of personal data shared with third parties, the categories of third parties with whom the data is shared, and an active email address or other online means by which consumers may contact the controller. Controllers may not process personal data for purposes that are neither reasonably necessary to, nor compatible with, the disclosed purposes for which the personal data is processed, unless the controllers obtain consumer consent.
Processor Contracts
The DPDPA requires that controllers (persons who "determine[] the purpose and means of processing personal data") and processors (persons who "process personal data on behalf of a controller") enter into contracts requiring processors to:
- Impose a duty of confidentiality on all individuals processing personal data;
- Delete or return personal data at termination of the agreement;
- Demonstrate compliance with the DPDPA upon request;
- Cooperate with the controller's data protection assessments; and
- Use subcontractors that are subject to the same privacy requirements as processors, and permit controllers to object to the use of those subcontractors.
Data Protection Assessments
The DPDPA requires a controller "that controls or processes the data of not less than 100,000 consumers, excluding data controlled or processed solely for the purpose of completing a payment transaction" to complete data protection assessments (called "data protection impact assessments" in some other state privacy laws) "on a regular basis" for the following five processing activities:
- Processing personal data for targeted advertising;
- The sale of personal data;
- The processing of personal data for the purposes of profiling if certain risk factors are met;
- Processing sensitive data; and
- Any processing activities that present a "heightened risk of harm."
Under the DPDPA, a single data protection assessment may address a comparable set of processing operations that include similar activities. In addition, if a controller conducts a data protection assessment for the purpose of complying with another applicable law or regulation, the data protection assessment shall be deemed to satisfy the requirements of Delaware's privacy law, if the data protection assessment is reasonably similar in scope and effect to the data protection assessment that would otherwise be conducted pursuant to Delaware law.
The DPDPA's data protection assessment requirements apply to processing activities "created or generated on or after" six months after the law's effective date (i.e., July 1, 2025) and are not retroactive.
Enforcement
Violations of the DPDPA may be enforced solely by the Delaware Department of Justice (the state's office of attorney general). A violation of the DPDPA is a per se violation of Delaware's Consumer Fraud Act. The DPDPA does not authorize any rulemaking.
No Private Right of Action
The DPDPA states that no provision in the law "shall be construed as providing the basis for, or be subject to, a private right of action for violations of [the DPDPA] or any other law."
Looking Ahead
DPDPA's arrival adds yet another layer of privacy compliance complexity for U.S. businesses. While businesses should be able to utilize their current privacy compliance programs to account for a number of DPDPA's statutory requirements, another new privacy law invariably increases enforcement risk. As a result, proper privacy compliance should be prioritized for businesses in Delaware and elsewhere.
The state privacy laws enacted so far in 2023 are slated to go into effect as follows:
- July 1, 2024 – Oregon
- July 1, 2024 – Florida
- July 1, 2024 – Texas
- October 1, 2024 – Montana
- January 1, 2025 – Iowa
- January 1, 2025 – Delaware
- July 1, 2025 – Tennessee
- January 1, 2026 – Indiana
DWT's Privacy and Security team regularly counsels clients on how their business practices can comply with state privacy laws. We will continue to monitor the rapid development of other state and new federal privacy laws and regulations.
This post has been republished on NYU's Compliance and Enforcement blog.
[1] The DPDPA defines "profiling" as "any form of automated processing performed on personal data to evaluate, analyze, or predict personal aspects related to an identified or identifiable individual's economic situation, health, demographic characteristics, personal preferences, interests, reliability, behavior, location, or movements."
[2] The DPDPA defines "genetic data" as "any data, regardless of its format, that results from the analysis of a biological sample of an individual, or from another source enabling equivalent information to be obtained, and concerns genetic material," and specifically includes DNA, RNA, "genes, chromosomes, alleles, genomes, alterations or modifications to DNA or RNA, single nucleotide polymorphisms (SNPs), uninterpreted data that results from analysis of the biological sample or other source, and any information extrapolated, derived, or inferred therefrom."
[3] The DPDPA provides a familiar set of exemptions from the definition of "sale," including: (1) the disclosure of personal data to a processor that processes the personal data on behalf of the controller where limited to the purpose of such processing; (2) the disclosure of personal data to a third party for purposes of providing a product or service affirmatively requested by the consumer; (3) the disclosure or transfer of personal data to an affiliate of the controller or as part of a merger or similar transaction; and (4) other specified disclosures intended or already made by the consumer.