EnglishEspañol
Delaware flag

Delaware

Delaware Data Privacy Laws: DPDPA Consumer Rights Guide (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 15 primary sources cited on this page. How we verify our legal content

Delaware Data Privacy Laws: DPDPA Consumer Rights Guide (2026)

Frequently Asked Questions

Does the DPDPA apply to small businesses in Delaware?

The DPDPA applies based on data processing volume, not business size or annual revenue alone. If your business controlled or processed the personal data of at least 35,000 Delaware consumers in the prior calendar year, you must comply regardless of company size. The 35,000 threshold excludes data processed solely to complete payment transactions. If you process data of at least 10,000 consumers and derive more than 20% of gross revenue from selling personal data, you must also comply. Many small businesses that do not reach these thresholds will not be covered. HB 380, which drops the primary threshold to 10,000 consumers and the revenue prong to 5,000 consumers, was signed September 2, 2026 and takes effect January 1, 2027.

How does Delaware handle universal opt-out signals like Global Privacy Control?

Beginning January 1, 2026 (now in effect), controllers subject to the DPDPA must recognize and honor universal opt-out preference signals such as Global Privacy Control (GPC). When a consumer uses a browser or extension that sends a GPC signal, the controller must treat it as a valid opt-out request for targeted advertising and data sales. Controllers cannot require additional verification steps or ignore the signal. This aligns Delaware with California, Colorado, Connecticut, and Montana, which also mandate GPC recognition.

What makes Delaware's sensitive data definition different from other states?

Delaware's sensitive data definition is one of the broadest in the country. In addition to standard categories such as racial origin, health data, biometric data, and precise geolocation, the DPDPA specifically includes status as transgender or nonbinary and citizenship or immigration status. Only Oregon includes similar categories. Businesses must obtain opt-in consent before processing data revealing whether a person is transgender, nonbinary, or a non-citizen. HB 380, signed September 2, 2026 and effective January 1, 2027, expands the definition further, adding national origin, neural data, financial account numbers and log-in credentials, and government-issued identification numbers.

Can Delaware residents sue businesses that violate the DPDPA?

No. The DPDPA does not include a private right of action. Only the Delaware Attorney General can enforce the law. Consumers who believe their rights have been violated should file a complaint with the Delaware Department of Justice at privacy@delaware.gov. The Attorney General can seek injunctive relief and restitution, and under 6 Del. C. § 2522(b) a court can impose a civil penalty of up to $10,000 per violation where it finds the violation was wilful. The mandatory 60-day cure period expired December 31, 2025, so the Attorney General now has discretion in deciding whether to extend a cure opportunity before pursuing formal enforcement.

Does the DPDPA apply to nonprofit organizations and universities?

Yes, and this is one of the DPDPA's most distinctive features. Most state privacy laws exempt nonprofits entirely. Delaware's law applies to 501(c)(3), 501(c)(4), 501(c)(6), and 501(c)(12) organizations if they meet the applicability thresholds. Only narrow exemptions exist for nonprofits focused solely on insurance crime prevention and those serving victims of domestic violence, sexual assault, or human trafficking. Institutions of higher education are covered because they fall outside the government entity exemption. Only Colorado and Oregon have similarly broad nonprofit coverage among comprehensive state privacy laws.

What is the Delaware data breach notification deadline?

Under 6 Del. C. § 12B-102, entities must notify affected Delaware residents without unreasonable delay, and no later than 60 days after discovering a qualifying breach. If more than 500 Delaware residents are affected, the entity must also notify the Delaware Attorney General within the same 60-day window. When the breach involves Social Security numbers, the entity must offer affected residents at least one year of free credit monitoring services and provide instructions for placing a credit freeze.

Does my company need to comply with the DPDPA just because it is incorporated in Delaware?

No. Incorporation in Delaware alone does not trigger DPDPA compliance obligations. The jurisdictional hook is market-facing activity: conducting business in Delaware or producing products and services targeted to Delaware residents. A company incorporated in Delaware but with no Delaware consumer base and no Delaware-targeted offerings does not meet the applicability requirement. A company incorporated elsewhere that actively markets to Delaware residents and processes data on 35,000 or more of them does come within scope, a figure that drops to 10,000 on January 1, 2027 under HB 380.

What is the TAKE IT DOWN Act and does it apply in Delaware?

The TAKE IT DOWN Act, Pub. L. 119-12, is a federal law signed May 19, 2025, that applies nationwide including in Delaware. It creates a federal criminal prohibition on knowingly publishing or threatening to publish nonconsensual intimate images (including AI-generated deepfakes) of adults or minors. Criminal penalties reach two years' imprisonment for adult victims and three years for minors. Platforms hosting user-generated content must implement a notice-and-removal process effective May 19, 2026, removing flagged images within 48 hours of a valid notice. The FTC enforces the platform requirements.

Updates

September 2026 update: Governor Matt Meyer signed House Bill 380, as amended by House Amendment No. 2, on September 2, 2026. It is chaptered as 85 Del. Laws ch. 463 and takes effect January 1, 2027. Every section that described HB 380 as pending was corrected. Effective January 1, 2027 the applicability thresholds drop to 10,000 consumers and to 5,000 consumers under the data-sales revenue prong, a third trigger covers third parties who acquire personal data from a controller, the sensitive data definition expands to include national origin, neural data, financial account numbers and log-in credentials and government-issued identification numbers, the blanket Gramm-Leach-Bliley entity exemption is replaced by narrower insurance, bank and broker-dealer exemptions, and the data protection assessment threshold drops to 50,000 consumers. The 35,000-consumer threshold remains the operative law until January 1, 2027.

Corrected four statutory citations (the third-party-list right is 6 Del. C. § 12D-104(a)(5), the COPPA parental-consent safe harbor is § 12D-103(d), the breach-of-security definition is § 12B-101(1), and Chapter 12D ends at § 12D-111) and clarified that the $10,000-per-violation civil penalty under 6 Del. C. § 2522(b) requires a court finding of a wilful violation.

Updated HB 380's status: the bill passed both chambers of the Delaware General Assembly on June 16, 2026, and now awaits the Governor's signature, rather than 'advancing through committee' as previously stated in six places on this page. Also clarified that the DPDPA's broad sensitive-data opt-in requirement applies to a known child under 13, not under 18 (the 13-17 age range is a separate targeted-advertising consent rule).

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

May 2026 refresh: Added TAKE IT DOWN Act (Pub. L. 119-12, signed May 19, 2025; platform obligations effective May 19, 2026). Added HB 380 pending amendment (threshold to 10,000 consumers per the engrossed bill text; an earlier 15,000 figure was corrected August 2026; committee advanced 4-0 on April 21, 2026). Updated Universal Opt-Out section: GPC requirement now in effect as of January 1, 2026. Updated enforcement section: mandatory cure period confirmed expired December 31, 2025; no formal AG enforcement actions filed as of May 2026. Added Delaware Online Privacy and Protection Act (DOPPA, 6 Del. C. ch. 12C) section. Added incorporation-state context section. Corrected Delaware's designation to 13th state (prior version said 12th). Expanded SourcesList from 7 to 14 sources. Added FAQ entries on breach notification, incorporation, and TAKE IT DOWN Act.

Reviewed and approved by an editor

Sources and References

  1. Delaware Personal Data Privacy Act - 6 Del. C. ch. 12D(delcode.delaware.gov).gov
  2. HB 154 Bill Detail - Delaware General Assembly(legis.delaware.gov).gov
  3. Delaware AG Personal Data Privacy Portal(attorneygeneral.delaware.gov).gov
  4. Delaware AG Personal Data Privacy Portal - FAQs(attorneygeneral.delaware.gov).gov
  5. AG Jennings Announces New Data Privacy Rights(news.delaware.gov).gov
  6. AG Jennings Issues Data Privacy Tips - Delaware News(news.delaware.gov).gov
  7. AG Jennings Launches DPDPA Portal - Delaware News(news.delaware.gov).gov
  8. DPDPA Implementation Notice Letter - Delaware AG(attorneygeneral.delaware.gov).gov
  9. Delaware Data Breach Notification Law - 6 Del. C. ch. 12B(delcode.delaware.gov).gov
  10. AG Portal - Security Breach Notification(attorneygeneral.delaware.gov).gov
  11. Delaware Online Privacy and Protection Act - 6 Del. C. ch. 12C(delcode.delaware.gov).gov
  12. HB 380 Bill Detail - Delaware General Assembly(legis.delaware.gov).gov
  13. TAKE IT DOWN Act - S. 146, 119th Congress(congress.gov).gov
  14. FTC COPPA Rule(ftc.gov).gov
  15. Delaware Consumer Fraud Act enforcement and civil penalties - 6 Del. C. § 2522(delcode.delaware.gov)
  16. Delaware General Assembly, House Bill 380 (153rd General Assembly) as amended by House Amendment No. 2, bill detail page: signed 9/2/26, effective date 1/1/27, Volume:Chapter 85:463(legis.delaware.gov).gov
Share: