A buried provision in Delaware's new privacy law dramatically expands which auto service shops must comply with strict data-handling rules.
Most Delaware auto service owners assume privacy regulations only apply to big companies. That assumption just changed—and many shops don't know it yet.
Delaware's HB380, An Act To Amend Title 6 Of The Delaware Code Relating To Personal Data Privacy, contains a provision that will reshape compliance obligations for auto services across the state. The key change: the threshold for triggering full privacy compliance has been cut from 35,000 consumers to just 10,000.
Starting January 1, 2027, if your auto service business collects or processes personal data from 10,000 or more Delaware consumers—a number many mid-sized shops easily reach—you will be subject to the full suite of Delaware Personal Data Protection Act (DPDPA) obligations under § 12D-103(a)(1), Section 1.
That means you'll need to:
Provide privacy notices to customers explaining what data you collect and how you use it.
Respond to consumer rights requests when customers ask to access, delete, or correct their personal information.
Conduct data protection assessments to evaluate privacy and security risks in your operations.
Maintain processor contracts with any vendors or third parties who handle customer data on your behalf.
Perform third-party due diligence to ensure service providers meet privacy standards.
Face potential enforcement by the Delaware Attorney General if you fail to comply.
Notably, there is no small-business exemption in the law. A shop with 10,000 customer records must meet the same requirements as a much larger operation.
For auto services, hitting 10,000 consumers is realistic. If you've been in business for several years, serve a regional customer base, or maintain detailed service records, you likely already meet or will soon meet that number. The old 35,000-consumer threshold left many shops untouched. The new 10,000 threshold brings compliance obligations to a much wider segment of the industry.
You have roughly two years before the law takes effect. That's time to:
Assess how many Delaware consumers your shop has in its records or database.
Review what personal data you currently collect and store (names, phone numbers, email addresses, payment information, vehicle details, service history).
Identify any third-party vendors or software providers who access that data.
Begin planning how you'll document your data practices and respond to consumer requests.
Consider consulting with legal counsel familiar with Delaware privacy law to understand your specific obligations.
The effective date is January 1, 2027. Waiting until late 2026 to prepare is a risk.
For a detailed, business-specific guide to HB380's requirements, contact your local Delaware auto service association or legal advisor.