US Privacy Law Delaware, USA

Delaware DPDPA: Personal Data Privacy Act Guide

Delaware's Personal Data Privacy Act: 35,000-consumer threshold, narrow exemptions, nonprofit coverage, sensitive-data consent, and DOJ enforcement at $10,000.

Regulation

Delaware Personal Data Privacy Act (HB 154, 2023), 6 Del. C. ch. 12D, effective January 1, 2025

Max Penalty

Up to $10,000 per violation under Delaware's consumer fraud framework

Enforcing Authority

Delaware Department of Justice (Attorney General)

Official Source

attorneygeneral.delaware.gov

Executive Summary

  • The Delaware Personal Data Privacy Act (effective January 1, 2025) sets one of the lowest coverage bars in the country: 35,000+ Delaware consumers' personal data annually, or 10,000+ with over 20% of revenue from selling personal data.
  • Delaware follows the strict Connecticut/Oregon line: nonprofits are covered (with narrow exceptions), there is no entity-level HIPAA exemption, and higher-education institutions are included.
  • The rights set is standard-plus: access, correction, deletion, portability, opt-outs of targeted advertising, sale, and profiling, and an Oregon-style right to a list of specific third-party recipients (categories or specific parties).
  • Sensitive data, whose definition includes status as transgender or nonbinary and pregnancy status within health data, requires opt-in consent; universal opt-out recognition became mandatory January 1, 2026.
  • The DOJ enforces with up to $10,000 per violation; a 60-day cure right applies until December 31, 2025, then becomes discretionary.

Delaware wrote a strict-tier privacy law for the smallest population yet covered by one, and aimed it wider than most: nonprofits, universities, and hospitals’ non-HIPAA data are all in, thresholds are set where ordinary web traffic reaches them, and minors keep ad-targeting consent rights to age 18. For multistate programs, Delaware’s significance is as a forcing function, its January 2025 arrival, with Iowa, Nebraska, New Hampshire, and New Jersey in the same month, ended the era of state-by-state compliance triage.

LawDPDPA, 6 Del. C. ch. 12D
EffectiveJanuary 1, 2025 (UOOM Jan 1, 2026; cure sunset Dec 31, 2025)
Thresholds35,000 consumers, or 10,000 + 20% sale revenue
Max penalty$10,000 per violation
RegulatorDelaware DOJ
Statute6 Del. C. ch. 12D

What Delaware adds to your program

Re-scope the covered-entity list. If your privacy program lives only in the for-profit parent, Delaware (with Oregon and Colorado) pulls affiliated foundations, .edu properties, and healthcare marketing operations into scope. Run the exemption analysis at the data level, not the org-chart level.

Third-party disclosure reporting. Delaware consumers may request the categories, or where feasible specific names, of third parties receiving their data, close enough to Oregon’s register requirement that one recipient-mapping system should serve both.

Under-18 ad gating. Actual-knowledge-or-willful-disregard is a weaker shield than it sounds for services with age signals (birthdate fields, school-adjacent content, teen-skewing analytics). Fold Delaware’s to-18 rule into the children’s privacy matrix alongside Connecticut and Montana.

Otherwise, inherit. Sensitive-data consent, 45-day DSARs with appeals, processor contracts, assessments, and GPC from 2026 are all satisfied by a strict-tier build; see the state comparison and multi-state strategy for the consolidated spec.

Verify the consumer-visible layer, notices, opt-outs, trackers, against Delaware’s requirements with a free scan.

Frequently Asked Questions

Why is Delaware's threshold so low, and who does it catch?

35,000 consumers is about 3.4% of Delaware's population of roughly one million, and the alternative trigger (10,000 consumers plus 20% sale revenue) is the lowest volume figure in any comprehensive state law. National consumer businesses with routine East Coast traffic clear the bar, and the covered-entity net includes nonprofits and universities that most states exempt. Delaware corporate registration, famously common, is irrelevant; what matters is residents' data.

Which exemptions does Delaware narrow?

Like Oregon: HIPAA covered entities are not exempt as entities (only protected health information itself), nonprofits are covered except for narrow categories (such as those serving victims of abuse), and higher education is covered. GLBA financial institutions retain an entity-level exemption. Hospitals, health systems, charities, and universities holding Delaware residents' marketing or operational data are in scope.

What is in Delaware's sensitive-data definition?

The Connecticut list plus explicit additions: racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis (including pregnancy), sexual orientation, status as transgender or nonbinary, citizenship or immigration status, genetic or biometric data, known-child data, and precise geolocation. All require prior opt-in consent under a clear-affirmative-act standard, with inferred attributes included.

What do minors get under the DPDPA?

Consent (from the minor aged 13-17, or a parent under 13 via COPPA) is required before processing for targeted advertising or sale where the controller has actual knowledge or willfully disregards that the consumer is under 18, among the earliest states to extend ad-targeting consent to all minors, not just under-16s. Combined with the low thresholds, teen-facing services should treat Delaware as automatically applicable.

How does enforcement work?

The Delaware DOJ's Fraud and Consumer Protection Division enforces; violations are treated within the consumer-fraud framework carrying civil penalties up to $10,000 per violation plus injunctive relief, with no private right of action. Through December 31, 2025, the DOJ must offer a 60-day cure opportunity where cure is possible; from 2026 cure is discretionary. Expect Delaware to enforce through the multistate consortium rather than solo landmark cases.

Regulatory Crosswalk

Connecticut CTDPAOregon OCDPAColorado CPA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.