{
  "type": "practice-guide",
  "canonical": "https://openagreements.org/practice-guides/privacy/us/delaware",
  "links": [
    {
      "rel": "self",
      "href": "https://openagreements.org/practice-guides/privacy/us/delaware.json",
      "type": "application/json"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/delaware",
      "type": "text/html"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/delaware/markdown",
      "type": "text/markdown"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/delaware/json",
      "type": "application/json"
    }
  ],
  "data": {
    "topic": "privacy",
    "state": "delaware",
    "frontmatter": {
      "title": "Delaware Consumer Privacy Law (DPDPA)",
      "description": "The Delaware Personal Data Privacy Act gives Delaware residents rights over their personal data and imposes notice, contracting, and consent duties on controllers above unusually low thresholds — it reaches early-stage startups and most nonprofits, is enforced exclusively by the Delaware Department of Justice, and provides no private right of action.",
      "state": "Delaware",
      "lastReviewed": "2026-06-06",
      "license": "CC BY 4.0",
      "authors": [
        "steven-obiajulu"
      ],
      "summary": {
        "keyLaw": "Del. Code tit. 6 §§ 12D-101 et seq. (Delaware Personal Data Privacy Act)",
        "appliesTo": "Persons doing business in Delaware (or targeting residents) that control or process the data of 35,000+ consumers a year, or 10,000+ while deriving more than 20% of gross revenue from selling data — no revenue floor, and only insurance-crime nonprofits are exempt",
        "privacyPolicyRequired": "Yes — a reasonably accessible, clear, and meaningful notice with statutorily fixed contents",
        "privateRightOfAction": "No — enforcement belongs solely to the Delaware Department of Justice",
        "regulator": "Delaware Department of Justice (exclusive)",
        "bottomLine": "If you control or process the data of 35,000 Delaware residents (or 10,000 plus a fifth of revenue from selling data), the DPDPA requires a privacy notice, opt-in consent to process sensitive data, and processor contracts — enforced by the Department of Justice, whose temporary right-to-cure expired at the end of 2025, with no consumer lawsuits.",
        "lawCoverage": "comprehensive",
        "policyMandate": "statutoryContents",
        "consumersCanSue": "no",
        "sensitiveDataConsent": "optIn",
        "universalOptOutSignal": "required"
      },
      "about": [
        "Delaware Personal Data Privacy Act DPDPA",
        "Delaware privacy policy requirements",
        "Delaware privacy notice contents",
        "DPDPA applicability thresholds",
        "DPDPA sensitive data consent",
        "DPDPA processor contract requirements",
        "Delaware Department of Justice privacy enforcement",
        "DPDPA no private right of action"
      ],
      "translations": [
        {
          "language": "中文",
          "status": "planned"
        },
        {
          "language": "Español",
          "status": "planned"
        },
        {
          "language": "Português",
          "status": "planned"
        },
        {
          "language": "Deutsch",
          "status": "planned"
        }
      ]
    },
    "questions": [
      {
        "slug": "does-dpdpa-apply",
        "label": "Does the Delaware Personal Data Privacy Act apply to your business?",
        "heading": "Does the Delaware Personal Data Privacy Act apply to your business?",
        "answerText": "It turns on how many Delaware residents you reach, not how much money you make. The DPDPA applies to persons that do business in Delaware or target its residents and that, in the prior calendar year, controlled or processed the personal data of at least 35,000 consumers, or at least 10,000 consumers while deriving more than 20% of gross revenue from selling personal data.",
        "sources": [
          {
            "id": "stat-103-apply",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Del. Code tit. 6 § 12D-103",
            "citation": "Del. Code tit. 6 § 12D-103(a).",
            "url": "https://delcode.delaware.gov/title6/c012d/index.html",
            "proposition": "The DPDPA applies to persons doing business in Delaware or targeting its residents that, in the preceding calendar year, controlled or processed the data of at least 35,000 consumers, or at least 10,000 consumers while deriving more than 20% of gross revenue from selling personal data.",
            "verbatimQuote": "This chapter applies to persons that conduct business in the State or persons that produce products or services that are targeted to residents of the State and that during the preceding calendar year did any of the following: (1) Controlled or processed the personal data of not less than 35,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction. (2) Controlled or processed the personal data of not less than 10,000 consumers and derived more than 20% of their gross revenue from the sale of personal data.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/delaware#src-stat-103-apply"
          }
        ]
      },
      {
        "slug": "privacy-policy-contents",
        "label": "What must your Delaware privacy policy contain?",
        "heading": "What must your Delaware privacy policy contain?",
        "answerText": "A controller must provide a reasonably accessible, clear, and meaningful privacy notice that lists the categories of personal data processed, the purpose for processing, how consumers exercise and appeal their rights, the categories of personal data shared with third parties, the categories of those third parties, and a way to contact the controller.",
        "sources": [
          {
            "id": "stat-106-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Del. Code tit. 6 § 12D-106",
            "citation": "Del. Code tit. 6 § 12D-106(c).",
            "url": "https://delcode.delaware.gov/title6/c012d/index.html",
            "proposition": "A controller must provide a reasonably accessible, clear, and meaningful privacy notice that lists the categories of personal data processed, the purpose for processing, how consumers may exercise and appeal their rights, the categories of personal data shared with third parties, the categories of those third parties, and a mechanism the consumer may use to contact the controller.",
            "verbatimQuote": "A controller shall provide consumers with a reasonably accessible, clear, and meaningful privacy notice that includes all of the following: (1) The categories of personal data processed by the controller. (2) The purpose for processing personal data. (3) How consumers may exercise their consumer rights, including how a consumer may appeal a controller’s decision with regard to the consumer’s request. (4) The categories of personal data that the controller shares with third parties, if any. (5) The categories of third parties with which the controller shares personal data, if any. (6) An active electronic mail address or other online mechanism that the consumer may use to contact the controller.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/delaware#src-stat-106-notice"
          }
        ]
      },
      {
        "slug": "vendor-contracts",
        "label": "What must your contracts with processors say?",
        "heading": "What must your contracts with processors say?",
        "answerText": "A binding contract must govern any processor's handling of personal data on the controller's behalf — so a data processing agreement is a statutory requirement, not a best practice — and that contract must set out the processing instructions, the nature and purpose of processing, the type of data, the duration, and the rights and obligations of both parties.",
        "sources": [
          {
            "id": "stat-107-contract",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Del. Code tit. 6 § 12D-107",
            "citation": "Del. Code tit. 6 § 12D-107(b).",
            "url": "https://delcode.delaware.gov/title6/c012d/index.html",
            "proposition": "A binding contract between a controller and a processor must govern the processor's data processing and set forth the processing instructions, nature and purpose, type of data, duration, and the rights and obligations of both parties.",
            "verbatimQuote": "A contract between a controller and a processor must govern the processor’s data processing procedures with respect to processing performed on behalf of the controller. The contract must be binding and clearly set forth instructions for processing data, the nature and purpose of processing, the type of data subject to processing, the duration of processing and the rights and obligations of both parties.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/delaware#src-stat-107-contract"
          }
        ]
      },
      {
        "slug": "sensitive-data",
        "label": "Do you need consent to process sensitive data?",
        "heading": "Do you need consent to process sensitive data?",
        "answerText": "Yes. A controller may not process a consumer's sensitive data without first obtaining consent, and for a known child it must instead obtain a parent's or guardian's consent and otherwise comply with Delaware's children's-data provisions. Sensitive data covers data revealing race or ethnicity, religious beliefs, a mental or physical health condition or diagnosis, sex life, sexual orientation, transgender or nonbinary status, or citizenship or immigration status; genetic or biometric data; the personal data of a known child; and precise geolocation.",
        "sources": [
          {
            "id": "stat-106-consent",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Del. Code tit. 6 § 12D-106",
            "citation": "Del. Code tit. 6 § 12D-106(a)(4).",
            "url": "https://delcode.delaware.gov/title6/c012d/index.html",
            "proposition": "A controller may not process a consumer's sensitive data without consent, and must obtain parental or guardian consent for a known child's sensitive data.",
            "verbatimQuote": "Not process sensitive data concerning a consumer without obtaining the consumer’s consent, or, in the case of the processing of sensitive data concerning a known child, without first obtaining consent from the child’s parent or lawful guardian and otherwise complying with § 1204C of this title.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/delaware#src-stat-106-consent"
          },
          {
            "id": "stat-102-sensitive",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Del. Code tit. 6 § 12D-102",
            "citation": "Del. Code tit. 6 § 12D-102(30).",
            "url": "https://delcode.delaware.gov/title6/c012d/index.html",
            "proposition": "Sensitive data includes data revealing race or ethnicity, religious beliefs, a health condition or diagnosis, sex life, sexual orientation, transgender or nonbinary status, or citizenship or immigration status; genetic or biometric data; the personal data of a known child; and precise geolocation.",
            "verbatimQuote": "“Sensitive data” means personal data that includes any of the following: a. Data revealing racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis (including pregnancy), sex life, sexual orientation, status as transgender or nonbinary, citizenship status, or immigration status. b. Genetic or biometric data. c. Personal data of a known child. d. Precise geolocation data.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/delaware#src-stat-102-sensitive"
          }
        ]
      },
      {
        "slug": "consumer-lawsuit",
        "label": "Can a consumer sue your business under the DPDPA?",
        "heading": "Can a consumer sue your business under the DPDPA?",
        "answerText": "No. The DPDPA gives the Delaware Department of Justice exclusive enforcement authority and expressly forecloses any private right of action. The law's right-to-cure was temporary: through the end of 2025 the Department had to issue a notice and allow 60 days to fix a curable violation, but that mandatory cure period applied only to the period ending December 31, 2025.",
        "sources": [
          {
            "id": "stat-111-enforce",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Del. Code tit. 6 § 12D-111",
            "citation": "Del. Code tit. 6 § 12D-111(d).",
            "url": "https://delcode.delaware.gov/title6/c012d/index.html",
            "proposition": "The Delaware Department of Justice has enforcement authority over the DPDPA, and the chapter provides no private right of action.",
            "verbatimQuote": "Nothing in this chapter shall be construed as providing the basis for, or be subject to, a private right of action for violations of said sections or any other law.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/delaware#src-stat-111-enforce"
          },
          {
            "id": "stat-111-cure",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Del. Code tit. 6 § 12D-111",
            "citation": "Del. Code tit. 6 § 12D-111(b).",
            "url": "https://delcode.delaware.gov/title6/c012d/index.html",
            "proposition": "The mandatory right-to-cure applied only during the period ending December 31, 2025, requiring a notice of violation and 60 days to cure before enforcement.",
            "verbatimQuote": "During the period beginning on January 1, 2025, and ending on December 31, 2025, the Department of Justice shall, prior to initiating any action for a violation of any provision of this chapter, issue a notice of violation to the controller if the Department of Justice determines that a cure is possible. If the controller fails to cure such violation within 60 days of receipt of the notice of violation, the Department of Justice may bring an enforcement proceeding pursuant to subsection (a) of this section.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/delaware#src-stat-111-cure"
          }
        ]
      }
    ]
  }
}
