The Delaware Personal Data Privacy Law now sits at the centre of consumer data compliance across the First State. Enforcement powers activated on 1 January 2025, and the cure period officially expired on 31 December 2025.
This guide breaks down every requirement, right, and obligation your business must understand today under Delaware law. It covers thresholds, consumer rights, enforcement powers, universal opt-out obligations, and practical compliance steps you can begin implementing this quarter.
The Delaware Personal Data Privacy Law is a comprehensive state privacy statute that gives consumers control over how businesses collect and use personal data.
Formally titled House Bill 154, the Act amends Title 6 of the Delaware Code and creates Chapter 12D. Representative Krista Griffith sponsored the bill, and Governor John Carney signed it into law on 11 September 2023.
The statute took effect on 1 January 2025, granting Delaware residents new privacy rights immediately. Attorney General Kathy Jennings and the Delaware Department of Justice hold exclusive enforcement authority over every controller and processor operating within the state.
Delaware hosts most Fortune 500 headquarters through its corporate registry, which magnified regulatory pressure to protect resident consumers. Legislators wanted a modern framework aligned with Connecticut, Colorado, and Virginia rules while addressing profiling risks unique to modern advertising.
The Delaware Personal Data Privacy Law applies to organisations conducting business in Delaware or targeting its residents once specific processing thresholds are met.
A business falls under the Act if it processes personal data of at least 35,000 Delaware consumers annually. It also applies to those handling 10,000 consumers while earning over 20% of gross revenue from selling personal data.
Unlike Virginia or Connecticut, Delaware extends coverage to non-profits and institutions of higher education. Narrow carve-outs exist for specific national securities associations, HIPAA-covered entities, financial institutions under Gramm-Leach-Bliley, and certain research bodies handling non-commercial data.
Even entities below the threshold must respect certain provisions if they knowingly sell sensitive data belonging to Delaware consumers. Small operators processing tightly limited data volumes often escape most obligations but should still track annual consumer counts.
The statute grants Delaware residents six clear privacy rights that mirror leading US frameworks while adding stronger protections around profiling and demographic data.
Consumers can confirm whether a controller processes their personal data and request access to that information. Businesses must reply within 45 days of receiving a verified request and may extend by another 45 days when reasonably necessary.
Delaware residents can correct inaccurate personal data and request deletion of information collected about them. Controllers must honour these requests unless a documented statutory exception applies, and they must confirm the outcome to the consumer promptly.
Consumers can request a portable copy of the personal data they previously provided, delivered in a readily usable format. This right supports account switching, price comparison, and independent audit of the personal information a business holds.
Residents can opt out of targeted advertising, the sale of personal data, and profiling that produces legally significant effects. Understanding the distinction between opt-in vs opt-out consent helps businesses build clean interfaces that actually respect user intent.
Delaware goes further than most states by allowing consumers to obtain categories of third parties receiving their personal data. This transparency requirement forces controllers to maintain accurate vendor inventories and disclosure logs at all times.
When a controller refuses to act on a request, consumers can appeal within a reasonable timeframe. Controllers must respond within 60 days and, if denied again, provide a mechanism to contact the Delaware Attorney General.
Controllers and processors carry specific duties around transparency, security, purpose limitation, contracting, and risk assessments once they fall within the statute’s scope.
Controllers must publish a clear privacy notice covering categories of data collected, purposes, retention, sharing practices, and consumer rights. The notice must also explain how consumers can exercise rights and appeal any refusals from the controller.
Processing sensitive data requires prior opt-in consent from the Delaware resident, mirroring GDPR-style principles. Sensitive personal information includes health, biometric, precise geolocation, immigration status, sexual orientation, race, religion, and any data revealing minors under thirteen.
The Act requires documented Data Protection Assessments before processing that presents heightened consumer risk. Covered activities include targeted advertising, selling personal data, profiling that carries reasonably foreseeable risks, and any handling of sensitive categories of data.
From 1 January 2026, controllers must honour universal opt-out mechanisms such as Global Privacy Control signals. Selecting one of the best consent management platforms simplifies detection, records, and downstream signalling to advertising and analytics vendors.
Every processor must operate under a written contract that limits processing, requires confidentiality, and sets deletion or return obligations. Contracts should also mandate cooperation with audits and prompt notification of any suspected personal data breach.
Delaware’s existing breach notification law under Title 6 Chapter 12B remains fully in force alongside the Privacy Act. Controllers must still notify affected residents and the Attorney General when a security breach exposes personal information without unreasonable delay.
Comparing the Delaware statute with parallel regimes helps businesses map compliance across multiple states without duplicating work or overlooking specific Delaware requirements.
| Feature | Delaware DPDPA | Virginia VCDPA | Connecticut CTDPA | Maryland MODPA |
|---|---|---|---|---|
| Consumer threshold | 35,000 | 100,000 | 100,000 | 35,000 |
| Sale-based threshold | 10,000 + 20% revenue | 25,000 + 50% revenue | 25,000 + 25% revenue | 10,000 + 20% revenue |
| Non-profits covered | Yes | No | Yes | Yes |
| Sensitive data | Opt-in | Opt-in | Opt-in | Opt-in |
| Universal opt-out | Yes (from 2026) | No mandate | Yes | Yes |
| Cure period | Expired 12/2025 | Discretionary | Expired 12/2024 | Discretionary |
| Max penalty | $10,000 per violation | $7,500 per violation | $5,000 per violation | $10,000 per violation |
Delaware’s low sale-based threshold captures far more data brokers and adtech firms than Virginia’s law does. Its extension to non-profits and universities also brings hospital fundraising teams, alumni offices, and community advocacy groups directly into scope.
Both Delaware and its neighbouring states enforce opt-in consent for sensitive data, mandate data protection assessments, and give consumers a documented appeal path. Overlapping requirements simplify multi-state compliance if teams design one shared rights-management workflow.
Businesses operating nationwide should map the Delaware Personal Data Privacy Law alongside every parallel statute early. Studying the Maryland Online Data Privacy Act alongside Delaware highlights shared thresholds and helps unify DSAR workflows across the two states.
The Delaware Department of Justice enforces the statute exclusively and holds broad discretion over investigations, cure opportunities, and financial penalties for violations.
Only the Attorney General may bring an enforcement action, since the statute does not create a private right for individuals. Investigations often begin with consumer complaints filed through the state Personal Data Privacy Portal and internal referrals.
Each violation may attract a civil penalty of up to $10,000 under Delaware’s Consumer Fraud Act framework. Penalties can stack quickly across affected consumers, making even modest compliance gaps financially painful for medium and large organisations.
During 2025, the Act guaranteed a 60-day cure window before enforcement could proceed against a controller. That mandatory grace period expired on 31 December 2025, and cure decisions now rest fully at the Attorney General’s discretion.
From 2026, the Attorney General weighs violation count, entity size, complexity, likelihood of consumer harm, and evidence of good faith. Documented compliance programmes and remediation history now carry real weight during any enforcement decision made against businesses.
Ignoring universal opt-out signals now creates instant risk since the January 2026 recognition mandate is live. Missing Global Privacy Control detection means every unrecognised opt-out request compounds violation exposure across each impacted Delaware consumer session.
Treating profiling as marketing-only misses Delaware’s broader definition, which explicitly captures demographic characteristics and inferred consumer traits. Controllers must review every algorithm producing consumer scores or segments to determine whether opt-out and assessment obligations apply.
Skipping data protection assessments when handling sensitive personal information invites enforcement scrutiny even without an actual security breach. Written assessments must be produced on request and cover risks, mitigations, and the balancing of consumer interests.
Overlooking non-profit and higher education coverage leaves entire departments exposed since Delaware’s Act deliberately breaks from Virginia’s carve-out exclusions. University alumni offices, foundations, and student marketing operations all need documented programmes and consumer-facing rights processes.
Failing to update processor contracts before enforcement escalates leaves controllers legally responsible when a vendor mishandles Delaware personal data. Every existing agreement should be reviewed and amended to reflect the Act’s specific processor requirements this quarter.
Assuming the expired cure period still guarantees a safety net leaves organisations dangerously exposed to fast-tracked enforcement actions. Since 1 January 2026, the Attorney General may bypass any negotiation and move straight to civil penalties.
Working through a structured checklist keeps every Delaware compliance requirement visible, assignable, and measurable across legal, security, marketing, and engineering teams.
Begin with a full inventory of every Delaware consumer touchpoint, including web forms, cookies, mobile apps, and offline capture. Document processing purposes, storage locations, retention periods, sharing relationships, and any sensitive category involved for each system.
Refresh public privacy notices to cover Delaware-specific rights, categories of third parties, and the appeal process consumers must follow. Similar disclosure planning under the Tennessee Information Protection Act helps larger businesses standardise notices across regional variants.
Deploy a consent banner and preference centre that captures opt-in for sensitive processing and opt-out for advertising or profiling. Wire the system to detect Global Privacy Control signals and store the response as an auditable event.
Prepare written assessments before launching any targeted advertising, profiling, sensitive data processing, or data-sale programme in Delaware. Assessments should capture context, risks, safeguards, and the balancing test weighing consumer interests against actual business benefits pursued.
Audit every processor agreement to confirm data-flow limits, deletion duties, breach notification timelines, and audit cooperation obligations. Flag any vendor without an updated data processing addendum and require remediation before continuing personal data transfers or sharing.
Deliver targeted training to marketing, product, sales, HR, and support teams handling Delaware consumer data day to day. Run quarterly compliance reviews that check DSAR metrics, opt-out signals, breach drills, and updates to any regulatory guidance issued.
Combine the Delaware Personal Data Privacy Law with the state’s separate breach notification requirements into a single incident response playbook. Predefined communications, forensic contacts, and Attorney General notification templates cut critical hours during any live incident significantly.
Create a verified DSAR intake process, an internal routing SLA, and a documented appeal path for refused requests. The Minnesota Consumer Data Privacy Act follows a similar 45-day model, so building one workflow can cover both states.
The Delaware Personal Data Privacy Law now sets a firm compliance baseline for any business touching consumer data across the First State. The mandatory cure period has ended, universal opt-out obligations are live, and the Attorney General retains full discretion. Building a documented programme today protects revenue, reputation, and long-term consumer trust.
Seers AI helps you meet every Delaware Personal Data Privacy Law requirement through automated consent, DSAR workflows, universal opt-out detection, and complete audit trails. Deploy a compliant privacy banner, honour Global Privacy Control signals, and document every consumer request without complex engineering effort.
START FREE TODAYYes, the statute applies to any organisation conducting business in Delaware or producing products and services targeting Delaware residents. Physical presence in the state is not required. What matters is whether the entity meets one of the consumer processing thresholds and provides goods or services to identifiable Delaware residents through websites, mobile applications, offline channels, or partner arrangements each calendar year.
The statute excludes personal data processed in an employment context and information collected during business-to-business communications. Employee background checks, HR records, and workplace monitoring generally fall outside its immediate scope. Contact data collected from a business representative during a commercial transaction is also excluded. Employers should still comply with any other applicable federal and state workplace privacy statutes currently in force today.
Missing the statutory deadline exposes the controller to enforcement action from the Delaware Department of Justice. Consumers can escalate directly to the Attorney General through the state Personal Data Privacy Portal, which triggers an investigation. Controllers should track every request through internal ticketing, document reasons for any extensions, and maintain written responses that clearly explain the outcome to each consumer promptly.
The Act treats data belonging to consumers between thirteen and seventeen years old as sensitive whenever used for targeted advertising, sale, or profiling. Controllers must obtain opt-in consent from the teenager before processing personal information for those purposes. Data from children under thirteen falls under COPPA, which continues to apply alongside Delaware’s Privacy Act, with the strictest applicable standard prevailing.
A unified notice can meet Delaware’s transparency obligations if it clearly includes state-specific rights, contact channels, appeal instructions, and full controller identity information. Many businesses now build a modular privacy centre with dedicated state supplements for Delaware, Maryland, Minnesota, Tennessee, and California. This approach reduces duplication while satisfying each jurisdiction’s disclosure content requirements without overloading readers with irrelevant regional information.
The Act does not mandate the formal appointment of a data protection officer for controllers or processors operating in Delaware. However, controllers must document data protection assessments, maintain compliance records, and manage consumer requests within tight statutory timeframes. Assigning a named privacy lead, whether internal or through an external adviser, remains the most reliable way to meet those ongoing evidentiary obligations.
Since 1 January 2026, controllers must automatically detect and honour recognised universal opt-out signals from browsers and connected devices. Global Privacy Control is currently the most widely deployed standard across major browsers. Businesses need server-side logic that identifies the signal, applies the opt-out to sale, targeted advertising, and profiling activity, and records the timestamp for audit or Attorney General review purposes.
The official statutory text lives in Title 6, Chapter 12D of the Delaware Code, available at delcode.delaware.gov for public access. The originating House Bill 154 and its full legislative history remain accessible through the Delaware General Assembly website. The Attorney General’s Personal Data Privacy Portal also publishes compliance guidance, consumer resources, and updates on any new regulatory interpretations released.
Rimsha ZafarRimsha is a Senior Content Writer at Seers AI with over 5 years of experience in advanced technologies and AI-driven tools. Her expertise as a research analyst shapes clear, thoughtful insights into responsible data use, trust, and future-facing technologies.