Delaware
Delaware Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 9 primary sources cited on this page. How we verify our legal content

Delaware protects biometric data, including fingerprints, voiceprints, and iris scans, as a category of sensitive personal data under the Delaware Personal Data Privacy Act (DPDPA), which took effect January 1, 2025. The DPDPA requires affirmative opt-in consent before collection and gives the Attorney General exclusive enforcement authority, with no private right of action.
Delaware does not have a standalone biometric privacy law like Illinois' BIPA. Instead, the state protects biometric information through the Delaware Personal Data Privacy Act (DPDPA), a comprehensive data privacy law signed by Governor John Carney on September 11, 2023, and effective January 1, 2025. The DPDPA treats biometric data as a category of "sensitive data" that triggers heightened consent requirements and processing restrictions.
This guide covers how Delaware law defines and regulates biometric data, what obligations businesses face, how enforcement works, and how breach notification rules apply to biometric information.
How Delaware Law Defines Biometric Data
Under Section 12D-102(3) of the DPDPA, biometric data means data generated by automatic measurements of an individual's unique biological characteristics. The statute lists specific examples:
- Fingerprints
- Voiceprints
- Eye retinas
- Irises
- Other unique biological patterns or characteristics
The defining requirement is that these measurements must be used to identify a specific individual.
What Is Excluded
The DPDPA explicitly excludes certain categories from the biometric data definition. Digital or physical photographs, audio recordings, and video recordings do not qualify as biometric data unless someone processes them specifically to identify a particular person.
This distinction matters in practice. A security camera recording in a Delaware workplace is not biometric data by itself. However, if a company runs that footage through facial recognition software to identify employees, the extracted faceprint data becomes biometric data subject to DPDPA requirements.
Biometric Data as Sensitive Data Under the DPDPA
Section 12D-102(30) classifies biometric data alongside other categories of sensitive personal data, including:
- Racial or ethnic origin
- Religious beliefs
- Mental or physical health conditions or diagnoses
- Sexual orientation
- Citizenship or immigration status
- Genetic data
- Precise geolocation data (within a 1,750-foot radius)
- Data concerning known children
This classification is significant because sensitive data receives stronger protections than ordinary personal data under the DPDPA. Controllers face additional obligations before they can collect or use any information in these categories.
Consent Requirements for Biometric Data
The DPDPA's most important biometric protection is its consent mandate. Under Section 12D-106(a)(4), a controller may not process sensitive data, including biometric data, without first obtaining the consumer's consent.
What Counts as Valid Consent
Delaware law sets a high bar for valid consent. Section 12D-102(7) requires a "clear affirmative act" that is:
- Freely given by the consumer without coercion
- Specific to the data processing activity
- Informed with clear notice about what data is collected and why
- Unambiguous in expressing agreement

What Does Not Count as Consent
The DPDPA specifically rejects several common business practices as valid consent:
- Accepting broad terms of service or general use policies
- Hovering over, pausing on, or otherwise interacting with website content
- Agreement obtained through deceptive or manipulative webpage design (dark patterns)
This means a company cannot bury biometric data consent in a lengthy terms of service agreement and claim compliance. Biometric data collection requires a separate, specific consent mechanism.
Special Rules for Children
When processing biometric data of a known child, controllers must obtain consent from the child's parent or lawful guardian. The controller must also comply with Section 1204C of the Delaware Code, which aligns with federal COPPA protections.
Who Must Comply: Applicability Thresholds
The DPDPA does not apply to every business operating in Delaware. Under Section 12D-103, the law covers entities that conduct business in Delaware and meet at least one of these thresholds:
- Controlled or processed the personal data of 35,000 or more consumers during the prior calendar year, OR
- Controlled or processed the personal data of 10,000 or more consumers and derived more than 20% of gross revenue from the sale of personal data
HB 380, passed by the General Assembly on June 16, 2026 and awaiting the Governor's signature, would lower these thresholds to 10,000 or more consumers, or 5,000 or more consumers combined with more than 20% of gross revenue from the sale of personal data, effective January 1, 2027 if signed.
Key Exemptions
Several categories of organizations and data are exempt from the DPDPA:
- Government entities (excluding state institutions of higher education)
- Financial institutions subject to the Gramm-Leach-Bliley Act (GLBA)
- HIPAA-covered entities and protected health information
- Educational records governed by FERPA
- Fair Credit Reporting Act activities
- Nonprofits serving abuse, trafficking, or stalking victims
These exemptions mean that a hospital collecting fingerprints for patient identification is likely covered by HIPAA rather than the DPDPA. A bank using fingerprint authentication would typically fall under GLBA instead.
Controller Obligations for Biometric Data
Beyond the consent requirement, the DPDPA imposes several duties on controllers that handle biometric data.
Data Minimization
Controllers must limit their collection of biometric data to what is "adequate, relevant, and reasonably necessary" for the disclosed purpose. A gym that collects members' fingerprint scans so they can check in at the door cannot also feed those scans into marketing analytics.
Security Requirements
Controllers must establish "reasonable administrative, technical, and physical data security practices" to protect biometric data under Section 12D-106(a)(3). That is a general reasonableness standard. The statute names no specific security framework or benchmark, so a controller has to judge for itself what safeguards are reasonable for the biometric data it holds.
Privacy Notice
Every controller processing biometric data must provide a "reasonably accessible, clear, and meaningful privacy notice" that discloses the categories of personal data processed, the purposes of processing, how consumers can exercise their rights, and what categories of data are shared with third parties.
Easy Revocation
If a consumer gave consent to biometric data processing, the controller must provide a way to revoke that consent. The revocation mechanism must be "at least as easy as" the method used to give consent in the first place.
Non-Discrimination
Controllers cannot discriminate against consumers who exercise their privacy rights. A company cannot deny services or charge higher prices to a customer who refuses to provide fingerprint data, as long as the biometric data is not strictly necessary for the service.
Consumer Rights Over Biometric Data
Delaware residents have several rights under Section 12D-104 that apply to their biometric data:
- Right to confirm and access: Consumers can ask whether a company processes their biometric data and request a copy.
- Right to correct: Consumers can demand correction of inaccurate biometric records.
- Right to delete: Consumers can request deletion of their biometric data.
- Right to portability: Consumers can obtain their biometric data in a portable format.
- Right to know third-party categories: Consumers can obtain a list of the categories of third parties to which the controller disclosed their personal data. Section 12D-104(a)(5) does not require the controller to name the individual recipients.
- Right to opt out: Consumers can opt out of the sale of their biometric data, its use for targeted advertising, or automated profiling.
Controllers must respond to these requests within 45 days, with a possible 45-day extension. The first request in any 12-month period must be processed free of charge.
Consumers can also designate an authorized agent to exercise opt-out rights on their behalf, including through browser settings, privacy-focused extensions, or other technical mechanisms.
Employers and Employee Biometric Data
Every DPDPA duty, including the sensitive data consent rule, runs to a "consumer." Section 12D-102(8) defines a consumer as an individual who is a resident of Delaware, then excludes "an individual acting in a commercial or employment context or as an employee, owner, director, officer, or contractor of a company, partnership, sole proprietorship, nonprofit organization, or government agency whose communications or transactions with the controller occur solely within the context of that individual's role."
Because of that exclusion, biometric data an employer collects from its own workforce falls outside the DPDPA, even when the employer is large enough to meet the applicability thresholds for its customer-facing data. Common workplace uses that sit outside the Act include:
- Fingerprint-based time clocks for tracking attendance
- Facial recognition systems for building access
- Palm scanners or hand geometry readers at secure facilities
- Voice recognition for phone authentication
Delaware also has no standalone biometric statute, so unlike an employer in Illinois or Texas, a Delaware employer faces no state biometric consent or retention mandate for employee scans. Other law can still reach the same conduct: Delaware's breach notification statute in Chapter 12B uses its own definitions and is not limited to consumers, employment contracts and collective bargaining agreements may impose their own terms, and a multi-state employer with workers in Illinois, Texas, or Washington is subject to those states' biometric laws for those workers.

Practical Steps for Employers
None of the following is required by the DPDPA for employee data. They are risk-reduction measures that address breach exposure, other states' biometric laws, and employee relations:
- Audit all systems that collect biometric data from employees, and confirm which workers are covered by another state's biometric law
- Use a standalone biometric notice and consent form, separate from general employment agreements
- Keep biometric records segregated from name-linked personnel files where practical, since the breach notice trigger in Chapter 12B turns on the combination
- Give employees a route to withdraw participation or request deletion
- Review retention practices and delete biometric templates that are no longer needed
Breach Notification for Biometric Data
Delaware's Computer Security Breaches law (Title 6, Chapter 12B) provides a separate layer of protection for biometric data. Section 12B-101(7) lists "unique biometric data generated from measurements or analysis of human body characteristics for authentication purposes" as one of the data elements that can make up "personal information."
The definition requires a combination, not the biometric element alone: it covers a Delaware resident's first name or first initial and last name together with one of the listed elements. Biometric records breached on their own, with nothing linking them to a name, do not by themselves trigger the notice duty in Section 12B-102.
If a breach exposes that combination, the company must:
- Notify affected Delaware residents without unreasonable delay and no later than 60 days after discovering the breach
- Notify the Delaware Attorney General if the breach affects more than 500 Delaware residents
- Investigate whether the breach is likely to result in harm to affected individuals
For more details on Delaware's breach reporting requirements, see our guide to Delaware Data Breach Notification Laws.
Enforcement and Penalties
Attorney General Enforcement
The Delaware Department of Justice has exclusive authority to enforce the DPDPA under Section 12D-111. This means only the Attorney General can bring enforcement actions against companies that violate the law's biometric data provisions.

No Private Right of Action
Unlike Illinois' Biometric Information Privacy Act (BIPA), which allows individuals to sue companies directly, the DPDPA explicitly states that nothing in the chapter "shall be construed as providing the basis for...a private right of action." Delaware residents cannot file lawsuits against companies for mishandling their biometric data under this law.
Penalties
Violations of the DPDPA constitute an "unlawful practice" under Section 2513 of the Delaware Code. Section 12D-111 sets no penalty figure of its own; the dollar amount comes from the consumer fraud subchapter. The Attorney General can pursue:
- Civil penalties of up to $10,000 per violation, which Section 2522(b) authorizes only where a court finds the person "has wilfully violated this subchapter," meaning it "knew or should have known that the conduct was of the nature prohibited"
- Injunctive relief to stop ongoing violations
- Restitution for affected consumers
- Disgorgement of profits gained through violations
Cure Period Changes
The enforcement timeline has shifted since the DPDPA took effect:
- Through December 31, 2025: The Attorney General was required to issue a notice of violation and give controllers 60 days to cure the problem before taking enforcement action.
- Starting January 1, 2026: The mandatory cure period has ended. The Attorney General now has discretion to consider the severity of the violation, the size and complexity of the business, the number of affected consumers, and any prior violations when deciding whether to offer a cure opportunity.
Consumers can submit complaints to the Delaware Department of Justice at privacy@delaware.gov.
Legislative History and Future Outlook
Delaware's path to biometric privacy protection has evolved over several years.
In 2018, the Delaware General Assembly introduced HB 350, a standalone biometric privacy bill modeled after Illinois' BIPA. That bill would have required written retention policies, specific consent before collection, and a ban on selling biometric data. HB 350 died in the House Economic Development/Banking/Insurance/Commerce Committee without receiving a vote.
Rather than revisiting a standalone biometric law, Delaware took a broader approach. The DPDPA, signed into law in September 2023, folded biometric protections into a comprehensive consumer data privacy framework. This approach addresses biometric data as one category of sensitive information rather than creating a separate regulatory scheme.
The Delaware General Assembly's interest in neural data privacy protections has since moved from exploratory to enacted. HB 380, which amends the DPDPA, passed both chambers of the General Assembly on June 16, 2026 and is awaiting the Governor's signature. If signed, HB 380 would add neural data, defined as data generated by measuring the activity of an individual's central nervous system, as a new category of sensitive data under the DPDPA, separate from the existing biometric data definition, effective January 1, 2027.
How Delaware Compares to Other States
Delaware's approach to biometric privacy falls in the middle of the national landscape:
| Feature | Delaware (DPDPA) | Illinois (BIPA) | Texas (CUBI) |
|---|---|---|---|
| Law type | Comprehensive privacy law | Standalone biometric law | Standalone biometric law |
| Private right of action | No | Yes | No |
| Consent required | Yes (sensitive data) | Yes (written release) | Yes (informed consent) |
| Maximum penalty | $10,000/violation, wilful violations only | $1,000-$5,000/violation | $25,000/violation |
| Retention/destruction policy | Not explicitly required | Required (3-year max) | Required |
| Effective date | January 1, 2025 | October 3, 2008 | September 1, 2009 |
Delaware offers solid biometric protections but lacks the private right of action that makes Illinois' BIPA the strongest biometric privacy law in the country. The absence of a standalone biometric statute also means Delaware does not require explicit written retention and destruction policies for biometric data.
For a broader overview of Delaware's privacy framework, see our guide to Delaware Data Privacy Laws.
This article is for informational purposes only and does not constitute legal advice. Biometric privacy law is evolving rapidly, and the information here reflects Delaware law as of early 2026. Consult a qualified attorney licensed in Delaware for guidance on your specific situation.
More Delaware Laws
Frequently Asked Questions
Does Delaware have a standalone biometric privacy law?
No. Delaware does not have a standalone biometric privacy law like Illinois' BIPA. Instead, biometric data is protected as a category of sensitive data under the Delaware Personal Data Privacy Act (DPDPA), which took effect January 1, 2025. A standalone biometric bill (HB 350) was introduced in 2018 but died in committee.
What biometric data does Delaware law protect?
The DPDPA protects data generated by automatic measurements of unique biological characteristics used to identify a specific individual. This includes fingerprints, voiceprints, eye retinas, irises, and other unique biological patterns. Photos, audio recordings, and video recordings are excluded unless they are processed specifically to identify a person.
Can I sue a company in Delaware for misusing my biometric data?
No. The DPDPA explicitly prohibits private lawsuits. Only the Delaware Attorney General can enforce the law. If you believe a company has mishandled your biometric data, you can file a complaint with the Department of Justice at privacy@delaware.gov.
What consent is required before collecting biometric data in Delaware?
Controllers must obtain consent that is affirmative, freely given, specific, informed, and unambiguous before processing biometric data. Broad terms of service acceptance, passive website interactions, and agreements obtained through dark patterns do not qualify as valid consent.
Do employers in Delaware need consent to use fingerprint time clocks?
Not under the DPDPA. The Act's duties run only to a 'consumer,' and Section 12D-102(8) excludes an individual acting in an employment context or as an employee or contractor. So even an employer large enough to meet the applicability thresholds owes its own workforce no DPDPA consent duty for a fingerprint time clock, and Delaware has no standalone biometric statute that supplies one. Employers with workers in Illinois, Texas, or Washington remain subject to those states' biometric laws, and Delaware's breach notification law still applies if employee names and biometric records are exposed together.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the DPDPA sensitive-data consent citation to Section 12D-106(a)(4), removed an unsupported claim that the statute names NIST and ISO/IEC security frameworks, and rewrote the employer guidance to reflect that Section 12D-102(8) excludes employees from the Act, along with clarifications to the $10,000 penalty (wilful violations only), the third-party disclosure right (categories, not recipients), and the breach-notice name-combination requirement.
Updated the neural data section to reflect that HB 380 has passed the Delaware General Assembly and is awaiting the Governor's signature, and added a note that HB 380 would lower the DPDPA's applicability thresholds effective January 1, 2027.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Delaware Code, Title 6 (Commerce and Trade), Chapter 012d (Delaware Personal Data Privacy Act)
§ 12D-106Duties of controllers.In forcecited in 2 of our articles
(a) A controller shall do all of the following: (1) Limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which such data is processed, as disclosed to the consumer. (2) Except as otherwise permitted by this chapter, not process personal data for purposes that are neither reasonably necessary to, nor compatible with, the disclosed purposes for which such personal data is processed, as disclosed to the consumer, unless the controller obtains the consumer’s consent. (3) Establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data appropriate to the volume and nature of the personal data at issue. (4) Not process sensitive data concerning a consumer without obtaining the consumer’s consent, or, in the case of the processing of sensitive data concerning a known child, without first obtaining consent from the child’s parent or lawful guardian and otherwise complying with § 1204C of this title.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at delcode.delaware.gov
Also relied on in: DPDPA Compliance Checklist: Delaware Privacy
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Delaware Personal Data Privacy Act (Title 6, Chapter 12D)(delcode.delaware.gov).gov
- HB 154 Bill Detail - Delaware General Assembly(legis.delaware.gov).gov
- Delaware Personal Data Privacy Portal - Attorney General(attorneygeneral.delaware.gov).gov
- DPDPA Frequently Asked Questions - Delaware DOJ(attorneygeneral.delaware.gov).gov
- Delaware Computer Security Breaches Law (Title 6, Chapter 12B)(delcode.delaware.gov).gov
- HB 350 Biometric Privacy Bill - Delaware General Assembly(legis.delaware.gov).gov
- AG Jennings Announces New Data Privacy Rights - Delaware News(news.delaware.gov).gov
- Neural Data Privacy Issue Brief - Delaware General Assembly(legis.delaware.gov).gov
- Data Security Breaches - Delaware DOJ(attorneygeneral.delaware.gov).gov
- 6 Del. C. Sec. 2522 - Civil penalties and injunctions (Consumer Fraud subchapter)(delcode.delaware.gov)
- HB 380 Bill Detail (153rd General Assembly) - Delaware General Assembly(legis.delaware.gov)