EnglishEspañol
Delaware flag

Delaware

What Is the DPDPA? Delaware Data Privacy Act

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 8 primary sources cited on this page. How we verify our legal content

What Is the DPDPA? Delaware Data Privacy Act

Frequently Asked Questions

What is the DPDPA?

The DPDPA, or Delaware Personal Data Privacy Act, is Delaware's comprehensive consumer data privacy law codified at Del. Code tit. 6, ch. 12D (sections 12D-101 to 12D-111). It was enacted as House Bill 154 of the 152nd General Assembly, signed September 11, 2023, and took effect January 1, 2025. It gives Delaware residents rights over their personal data and requires covered businesses to be transparent about how they collect, use, and disclose it.

When did the DPDPA take effect?

The DPDPA took effect on January 1, 2025. A separate requirement to recognize a universal opt-out preference signal, such as Global Privacy Control, took effect January 1, 2026 under section 12D-106(e). The 60-day right to cure available to businesses during 2025 sunset on December 31, 2025.

What are the DPDPA's coverage thresholds?

Under section 12D-103, the DPDPA covers any person doing business in Delaware or targeting Delaware residents that, in the prior calendar year, controlled or processed the personal data of at least 35,000 consumers (excluding data used solely to complete a payment transaction), or of at least 10,000 consumers while deriving more than 20 percent of gross revenue from selling personal data. There is no dollar-revenue floor, and the 35,000-consumer threshold is among the lowest in the country. HB 380, passed by the General Assembly on June 16, 2026 and awaiting the Governor's signature, would lower these thresholds to 10,000 consumers, or 5,000 consumers plus 20 percent revenue from data sales, effective January 1, 2027 if signed.

Does the DPDPA apply to nonprofits?

Yes, generally. Delaware is unusual in covering most nonprofit organizations, where many other states exempt nonprofits entirely. Under section 12D-103, the only full entity-level nonprofit exemption is for a nonprofit dedicated exclusively to preventing and addressing insurance crime, though a narrower data-level exemption also covers victim-services nonprofits handling specific victim or witness data. The Delaware Department of Justice has confirmed the law applies to both for-profit and nonprofit businesses, so a nonprofit that meets the thresholds is generally covered.

Does the DPDPA apply to colleges and universities?

Yes. Section 12D-103 exempts Delaware state and local government bodies but expressly excludes institutions of higher education from that exemption. As a result, Delaware colleges and universities are covered by the DPDPA if they meet the applicability thresholds, even though general government bodies are not.

What counts as sensitive data under the DPDPA?

Under section 12D-102(30), sensitive data includes data revealing racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis including pregnancy, sex life, sexual orientation, status as transgender or nonbinary, citizenship status, and immigration status. It also includes genetic or biometric data, the personal data of a known child, and precise geolocation data. Processing sensitive data requires opt-in consent under section 12D-106(a)(4).

How is the DPDPA different from the CCPA?

Key differences: Delaware has no dollar-revenue threshold and a low 35,000-consumer trigger while California's CCPA uses a $26.625 million revenue floor (CPI-adjusted from $25 million as of January 1, 2025) among its triggers; Delaware generally covers nonprofits and colleges while California generally exempts nonprofits; Delaware requires opt-in consent for sensitive data while California uses an opt-out right to limit; and California has a limited private right of action for certain breaches while Delaware has none.

Who enforces the DPDPA?

The Delaware Department of Justice has exclusive enforcement authority under section 12D-111. There is no private right of action under section 12D-111(d). A violation is treated as an unlawful practice, and a wilful violation can carry civil penalties of up to $10,000 per violation under section 2522(b). The 60-day right to cure available during 2025 sunset on December 31, 2025, so a guaranteed cure window no longer exists as of 2026.

Updates

Added notes that Delaware HB 380 (passed both chambers, awaiting the Governor's signature) would lower the DPDPA's applicability thresholds effective January 1, 2027; qualified the nonprofit exemption claim to note a narrower victim-services carve-out; updated the CCPA revenue threshold to the current CPI-adjusted $26.625 million figure; and clarified that the $10,000 civil penalty applies to wilful violations.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Del. Code tit. 6, ch. 12D: Delaware Personal Data Privacy Act (Full Chapter)(delcode.delaware.gov).gov
  2. Del. Code tit. 6, § 12D-103: Applicability and Exemptions(delcode.delaware.gov).gov
  3. Del. Code tit. 6, § 12D-102: Definitions (Sensitive Data)(delcode.delaware.gov).gov
  4. Del. Code tit. 6, § 12D-106: Responsibilities of Controllers(delcode.delaware.gov).gov
  5. Del. Code tit. 6, § 12D-111: Enforcement by the Department of Justice(delcode.delaware.gov).gov
  6. Delaware HB 154 (152nd General Assembly): Personal Data Privacy Act(legis.delaware.gov).gov
  7. Delaware Department of Justice: Personal Data Privacy Portal(attorneygeneral.delaware.gov).gov
  8. Delaware DOJ: Personal Data Privacy Act Frequently Asked Questions(attorneygeneral.delaware.gov).gov
Share: