Delaware wrote a strict-tier privacy law for the smallest population yet covered by one, and aimed it wider than most: nonprofits, universities, and hospitals’ non-HIPAA data are all in, thresholds are set where ordinary web traffic reaches them, and minors keep ad-targeting consent rights to age 18. For multistate programs, Delaware’s significance is as a forcing function, its January 2025 arrival, with Iowa, Nebraska, New Hampshire, and New Jersey in the same month, ended the era of state-by-state compliance triage.
| Law | DPDPA, 6 Del. C. ch. 12D |
|---|---|
| Effective | January 1, 2025 (UOOM Jan 1, 2026; cure sunset Dec 31, 2025) |
| Thresholds | 35,000 consumers, or 10,000 + 20% sale revenue |
| Max penalty | $10,000 per violation |
| Regulator | Delaware DOJ |
| Statute | 6 Del. C. ch. 12D |
What Delaware adds to your program
Re-scope the covered-entity list. If your privacy program lives only in the for-profit parent, Delaware (with Oregon and Colorado) pulls affiliated foundations, .edu properties, and healthcare marketing operations into scope. Run the exemption analysis at the data level, not the org-chart level.
Third-party disclosure reporting. Delaware consumers may request the categories, or where feasible specific names, of third parties receiving their data, close enough to Oregon’s register requirement that one recipient-mapping system should serve both.
Under-18 ad gating. Actual-knowledge-or-willful-disregard is a weaker shield than it sounds for services with age signals (birthdate fields, school-adjacent content, teen-skewing analytics). Fold Delaware’s to-18 rule into the children’s privacy matrix alongside Connecticut and Montana.
Otherwise, inherit. Sensitive-data consent, 45-day DSARs with appeals, processor contracts, assessments, and GPC from 2026 are all satisfied by a strict-tier build; see the state comparison and multi-state strategy for the consolidated spec.
Verify the consumer-visible layer, notices, opt-outs, trackers, against Delaware’s requirements with a free scan.