Privacy Law Library

Delaware Personal Data Privacy Act

DPDPA

Comprehensive privacy · Children · Health · Genetic · Biometric · Location · Artificial intelligence

Delaware's comprehensive consumer privacy law gives residents rights to access, correct, delete, and port their personal data, to get a list of third parties that received it, and to opt out of targeted advertising, sale, and significant-decision profiling. It has low applicability thresholds, requires opt-in consent for sensitive data and for targeted advertising or sale of data about known 13-17-year-olds, and requires honoring universal opt-out signals from 2026-01-01. HB 380 (signed 2026-09-02, effective 2027-01-01) lowers thresholds further and adds third-party contract and diligence duties, adverse-action notices for profiling reports, automated-decision impact assessments, a broader sensitive-data definition (including neural data and financial credentials), and narrows the employee-data exclusion for profiling.

Where
Delaware
Citation
6 Del. C. §§ 12D-101 to 12D-111 (Title 6, Chapter 12D)
Status
In force
In force since
2025-01-01
Last amended
2027-01-01
Enforced by
Delaware Department of Justice (Attorney General), exclusively (12D-111(a), (e))
People can sue
No
Penalties
Violations are unlawful practices under the Consumer Fraud Act (6 Del. C. § 2513), enforced solely by the Department of Justice (12D-111(e)); a court may impose a civil penalty of up to $10,000 per wilful violation (6 Del. C. § 2522(b)). The mandatory 60-day cure period ended 2025-12-31; since 2026-01-01 cure is discretionary (12D-111(b)-(c)).
Applies to
  • Through 2026-12-31: persons conducting business in Delaware or targeting Delaware residents that in the preceding calendar year controlled or processed personal data of at least 35,000 consumers (excluding payment-only data), or of at least 10,000 consumers while deriving over 20% of gross revenue from selling personal data (12D-103(a))
  • From 2027-01-01 (HB 380, 85 Del. Laws c. 463): thresholds drop to 10,000 consumers, or 5,000 consumers plus over 20% of revenue from sales, and third parties that acquire personal data from a controller are also covered (12D-103(a)(1)-(3))
  • No general nonprofit or higher-education exemption; state and local government bodies are exempt but public institutions of higher education are covered (12D-103(b)(1))
  • Exempt through 2026: GLBA-regulated financial institutions and affiliates; from 2027 the entity exemption narrows to insurers, banks, credit unions, and registered securities professionals, while GLBA data stays exempt (12D-103(b), (c)(14))
  • Exempt data includes HIPAA PHI, FCRA-regulated activity, DPPA, FERPA, and employment-context data (12D-103(c))

What a privacy notice must say

  • Controllers that give third parties reports used for significant decisions must contractually require adverse-action notices, a description of the data relied on, and an offer of human review, and must give residents their data, its sources, and recipients within 30 days on request.6 Del. C. § 12D-106(f) [eff. Jan. 1, 2027] · Only if: Does not apply to FCRA-compliant consumer reports (12D-106(g)) · From 2027-01-01
  • Post a clear privacy notice listing categories of data processed, purposes, how to exercise and appeal rights, categories of data shared and third-party recipients, and a contact email or online mechanism; disclose any sale or targeted advertising and how to opt out.6 Del. C. § 12D-106(c)-(d)

Rights it gives people

  • Consumers may confirm processing and access, correct, delete, obtain a portable copy, get a list of categories of third parties that received their data, and opt out of targeted advertising, sale, and solely automated significant-decision profiling.6 Del. C. § 12D-104(a)
  • Access expands to inferences and whether data is used for significant-decision profiling; the third-party disclosure right becomes a list of specific third parties; the profiling opt-out covers automated (not only solely automated) decisions.6 Del. C. § 12D-104(a)(1), (5), (6)c. [eff. Jan. 1, 2027] · From 2027-01-01

Practices it requires

  • Sensitive data expands to include inferences, national origin, health treatment or status, neural data, financial account credentials, and government ID numbers; sensitive data may be processed only with consent and when reasonably necessary and proportionate, and all data of a known child needs parental consent.6 Del. C. § 12D-102(33); § 12D-106(a)(4)-(5) [eff. Jan. 1, 2027] · From 2027-01-01
  • Do not process a consumer's data for targeted advertising or sell it without consent where the controller knows or wilfully disregards that the consumer is 13 to 17 years old.6 Del. C. § 12D-106(a)(7)
  • Honor opt-out preference signals (universal opt-out mechanisms) for targeted advertising and sale, and provide a clear website opt-out link.6 Del. C. § 12D-106(e)(1)a.; § 12D-105 · From 2026-01-01
  • Respond to requests within 45 days (extendable once by 45 days), free once per 12 months, and offer an appeal answered within 60 days that points the consumer to a Department of Justice complaint mechanism if denied.6 Del. C. § 12D-104(c)-(d)
  • Obtain consent before processing sensitive data (including health, genetic, biometric, precise geolocation, and known-child data; parental consent and COPPA compliance for children).6 Del. C. § 12D-106(a)(4); § 12D-102(30)
  • Enter binding contracts with and perform due diligence on third parties that receive personal data; sensitive data may be sold only when strictly necessary for a requested product, after specific notice and consent, with consent records kept 5 years.6 Del. C. § 12D-106(a)(10)-(12); § 12D-107A [eff. Jan. 1, 2027] · From 2027-01-01

Security duties

  • Maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the data; limit collection to what is adequate, relevant, and reasonably necessary.6 Del. C. § 12D-106(a)(1), (3)

Other duties

  • Controllers that profile in furtherance of automated significant decisions must document impact assessments covering purpose, risks and mitigations, data inputs and outputs, performance metrics, transparency, and post-deployment monitoring.6 Del. C. § 12D-108(a)(2) [eff. Jan. 1, 2027] · Only if: Controller meets the 50,000-consumer assessment threshold · From 2027-01-01
  • Controllers processing data of 100,000+ consumers (50,000+ from 2027) must conduct and document data protection assessments for targeted advertising, sale, risky profiling, and sensitive data processing, and produce them to the Attorney General on request.6 Del. C. § 12D-108(a), (c) · Only if: Controller meets the assessment volume threshold

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: HB 380's synopsis describes a 15,000-consumer threshold, but the codified text effective 2027-01-01 reads 10,000 consumers (and 5,000 for data sellers); the entry follows the codified text. | Effective date of the HB 380 amendments taken from the Delaware Code section headers ('Effective Jan. 1, 2027'); the session-law effective-date clause itself was not read.

Research reference, not legal advice.