Delaware Personal Data Privacy Act (DPDPA)

· About Delaware Personal Data Privacy Act (DPDPA)

Key Takeaways

  • The Delaware Personal Data Privacy Act (DPDPA) applies to covered persons that do business in Delaware or target Delaware residents and meet the law’s consumer-data thresholds; it has been in force since 1 January 2025. [13][15]
  • Controllers must honor consumer privacy rights, provide a compliant privacy notice, limit processing to specified purposes, and implement reasonable security practices; violations are enforceable by the Delaware Department of Justice under the state consumer-protection framework. [13][15]
  • Delaware’s 2026 amendment bill, HB 380, passed the General Assembly and was awaiting gubernatorial action in the materials reviewed; if enacted, it would reduce applicability thresholds and add duties for third-party disclosures, profiling, and sensitive data, with an effective date of 1 January 2027. [1][2][4]
  • The law’s universal opt-out mechanism requirement took effect on 1 January 2026, meaning controllers had to recognize browser or device-based opt-out signals from that date. [14]
  • The current statutory penalty cap is tied to Delaware’s consumer fraud enforcement authority, with civil penalties of up to $10,000 per violation and injunctive relief available; each unlawful processing incident can count separately. [13][15]

What It Is

The DPDPA is Delaware’s comprehensive consumer privacy law in Title 6, Chapter 12D, designed to regulate how covered businesses collect, process, sell, and share personal data of Delaware residents. [15] The law is enforced by the Delaware Department of Justice / Attorney General through the state’s consumer-protection enforcement structure. [13][15]

The enacted act became effective on 1 January 2025. [13][15] A later requirement for controllers to recognize universal opt-out mechanisms became effective on 1 January 2026. [14]

The current law remains in force, and the 2026 legislation labeled HB 380 would amend the statute if signed. The materials reviewed indicate that HB 380 would take effect on 1 January 2027 if enacted. [1][2][4]

Who Must Comply

The current DPDPA applies to a person that conducts business in Delaware or produces products or services targeted to Delaware residents and, during the preceding calendar year, controlled or processed personal data of at least 35,000 consumers or controlled or processed personal data of at least 10,000 consumers while deriving more than 20% of gross revenue from the sale of personal data. [15]

The 2026 HB 380 amendment would lower those thresholds to 10,000 consumers and 5,000 consumers plus more than 20% revenue from sale of personal data, and would also extend applicability to certain third parties that acquire personal data from a controller. [1][2][5][12]

The law is extraterritorial in the practical sense common to state privacy statutes: it reaches entities outside Delaware if they target Delaware residents and meet the threshold criteria. [15] The reviewed materials do not identify a broad entity-level exemption comparable to some sectoral laws; instead, HB 380 would narrow the GLBA-related carveout and expand specific obligations, so regulated entities should treat exemptions as limited and text-specific. [6][12]

Core Requirements

  1. Provide a privacy notice. Controllers must give consumers a notice describing the categories of personal data processed, the purposes, how consumers can exercise their rights, categories of data shared, and how the controller responds to consumer requests. [15]
  2. Honor consumer rights. Covered businesses must support rights to access, correction, deletion, portability, and opt-out of targeted advertising, sale of personal data, and certain profiling decisions. [15]
  3. Recognize universal opt-out signals. By 1 January 2026, controllers had to honor eligible browser or device signals that communicate a consumer’s opt-out preference. [14]
  4. Limit processing to disclosed purposes. Controllers may not process personal data beyond what is reasonably necessary and proportionate to the disclosed purposes, consistent with the statutory privacy framework. [15]
  5. Use reasonable security measures. Controllers must maintain administrative, technical, and physical safeguards appropriate to the volume and sensitivity of the data they process. [13][15]
  6. Prepare for 2026 amendment duties if HB 380 is enacted. The amendment would add stronger due-diligence and contractual controls for third-party disclosures, broader sensitive-data rules, and additional consumer rights tied to profiling and third-party recipients. [1][2][8][9]

Deadlines and Penalties

| milestone | date | what applies | |---|---:|---| | DPDPA effective date | 1 January 2025 | Core consumer privacy obligations begin. [13][15] | | Universal opt-out recognition | 1 January 2026 | Controllers must honor universal opt-out mechanisms. [14] | | HB 380 possible effective date | 1 January 2027 | If signed, broader scope and new obligations would apply. [1][2][4] |

The current penalty framework ties to Delaware’s consumer-fraud enforcement authority, which authorizes civil penalties of up to $10,000 per violation and equitable relief including injunctions. [13][15] The law also exposes violators to investigatory and enforcement action by the Delaware Department of Justice, and the practical risk rises quickly because each affected consumer transaction or retention event may be treated as a separate violation. [13][15]

How to Comply

  1. Map data and document purposes. Build a data inventory that links categories of personal data to specific processing purposes, retention periods, and sharing relationships.
  2. Classify Delaware applicability. Test whether the business meets the current 35,000/10,000 thresholds or, if HB 380 becomes law, the lower 10,000/5,000 thresholds and third-party criteria. [1][2][15]
  3. Refresh notices and rights intake. Align privacy notices, request workflows, identity verification, appeal handling, and response deadlines with the DPDPA.
  4. Implement universal opt-out support. Configure consent and preference systems to detect and honor recognized opt-out signals across web and app environments by default. [14]
  5. Strengthen vendor governance. Add contractual controls, audit rights, and data-use restrictions for processors and third parties; this maps well to ISO 27001 supplier controls and NIST CSF 2.0 governance and supply-chain outcomes.
  6. Run privacy risk reviews for high-risk processing. Where profiling, targeted advertising, or sensitive data is involved, adopt structured assessments; if HB 380 is enacted, this should be formalized in privacy impact assessment procedures aligned with ISO 42001 and NIST privacy/risk processes. [1][2][8]
  7. Test incident and complaint handling. Integrate consumer-rights failures into complaint triage, incident response, and legal escalation so enforcement exposure is visible early.
  8. Keep a change log for 2026 amendments. Track whether HB 380 is signed, its final text, and any implementing guidance before the 1 January 2027 date. [1][2][4]

Related Regulations

  • Virginia Consumer Data Protection Act (VCDPA): Delaware tracks Virginia’s privacy-law model closely, but Delaware’s 2026 amendment package would be more aggressive on third-party disclosures and sensitive-data categories.
  • Connecticut Data Privacy Act (CTDPA): Connecticut and Delaware both use consumer thresholds and opt-out rights, but Delaware’s pending changes would tighten applicability and profiling rules differently.
  • Colorado Privacy Act (CPA): Colorado’s approach to universal opt-out signals and privacy assessments is a useful operational benchmark for Delaware compliance design.
  • California Consumer Privacy Act (CCPA/CPRA): California is broader on data rights and vendor contracting, and Delaware’s HB 380 would move closer to that style of obligation in some respects.
  • Delaware Breach Notification Law: The privacy act regulates lawful processing, while the breach law governs notice after unauthorized access or disclosure; they operate in parallel.

FAQ

Does the Delaware privacy law apply to companies outside Delaware?

Yes, if the company does business in Delaware or targets Delaware residents and meets the statutory threshold. The law is not limited to Delaware-incorporated companies. That extraterritorial reach is one of the main reasons multistate businesses need a state-by-state applicability test. [15]

When did the DPDPA become enforceable?

The enacted law took effect on 1 January 2025. Separate universal opt-out obligations became effective on 1 January 2026. [13][14][15]

What changes would HB 380 make if it is signed?

HB 380 would lower the applicability threshold, expand the definition of sensitive data, add new consumer rights and third-party disclosure controls, and impose stronger due-diligence and contract requirements. The reviewed materials indicate a prospective effective date of 1 January 2027 if enacted. [1][2][4][8][9]

Does Delaware require privacy impact assessments today?

The current DPDPA materials reviewed do not show a general, across-the-board privacy impact assessment requirement in the enacted text. However, HB 380 would add assessment-style obligations for certain processing activities, so compliance teams should treat PIAs as a likely future requirement if the amendment is signed. [1][2][8]

What are the fines for violating the DPDPA?

The available Delaware enforcement framework authorizes civil penalties of up to $10,000 per violation, along with injunctive relief and other equitable remedies. The statute is enforced by the Delaware Department of Justice, which can escalate matters quickly when multiple consumers are affected. [13][15]

Does Delaware allow universal opt-out signals?

Yes. Controllers must recognize universal opt-out mechanisms, and that requirement became effective on 1 January 2026. Businesses operating cookie and consent tooling in Delaware should already be configured to honor those signals. [14]

Sources

Put it into practice

More compliance guides