{"id":21450,"date":"2026-04-14T09:38:52","date_gmt":"2026-04-14T07:38:52","guid":{"rendered":"https:\/\/www.cookiebot.com\/en\/?p=21450"},"modified":"2026-04-14T15:46:49","modified_gmt":"2026-04-14T13:46:49","slug":"delaware-personal-data-privacy-act-dpdpa","status":"publish","type":"post","link":"https:\/\/www.cookiebot.com\/en\/delaware-personal-data-privacy-act-dpdpa\/","title":{"rendered":"Delaware Personal Data Privacy Act (DPDPA): What Businesses Need to Know"},"content":{"rendered":"\n<p>Delaware's data privacy law came into effect on January 1, 2025, making it the 13th in the U.S. to enact comprehensive consumer privacy legislation. The Delaware Personal Data Privacy Act (DPDPA) gives Delaware residents meaningful rights over how their personal data is collected, used, and shared. The DPDPA also places a corresponding set of obligations on the businesses and organizations that process consumers\u2019 data.&nbsp;<\/p>\n\n\n\n<p>Notably, the DPDPA's compliance thresholds are among the lowest of any comparable U.S. state privacy law, meaning a wider range of organizations fall within its scope. This overview covers who must comply, what the law requires, how enforcement works, and what has changed since the law took effect.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The DPDPA took effect January 1, 2025, making Delaware the 13th U.S. state to enact a comprehensive consumer data privacy law.<\/li>\n\n\n\n<li>Compliance thresholds are the lowest of any comparable U.S. state law: covering controllers processing data on 35,000+ consumers, or 10,000+ consumers while deriving more than 20 percent of gross revenue from personal data sales.<\/li>\n\n\n\n<li>Consumers hold six key rights: access, correction, deletion, portability, disclosure of specific third parties, and opt-out of sale, targeted advertising, and certain profiling.<\/li>\n\n\n\n<li>Sensitive data \u2014 including precise geolocation, biometric data, and data revealing transgender or nonbinary status \u2014 cannot be processed without prior consent.<\/li>\n\n\n\n<li>Controllers must recognize Universal Opt-Out Mechanisms (such as Global Privacy Control) as of January 1, 2026.<\/li>\n\n\n\n<li>Delaware\u2019s Attorney General enforces the law: the DPDPA does not specify a civil penalty amount, but by designating violations as unlawful practices under Delaware's Consumer Fraud Act, willful violations can result in civil penalties up to USD 10,000 per violation; cure period is at the DOJ\u2019s discretion; consumers have no private right of action.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-delaware-s-place-in-the-u-s-privacy-landscape\">Delaware's Place in the U.S. Privacy Landscape<\/h2>\n\n\n\n<p>Delaware joined a growing list of states enacting comprehensive consumer data privacy legislation when Governor John Carney signed <a href=\"https:\/\/legis.delaware.gov\/BillDetail?LegislationId=140388\">House Bill 154<\/a> into law on September 11, 2023. When the DPDPA took effect on January 1, 2025, Delaware became the 13th state to put a comprehensive privacy framework in place.\u00a0<\/p>\n\n\n\n<p>For U.S. businesses operating nationally or internationally, the lack of a single, federal, comprehensive data privacy regulation means potentially managing compliance obligations across multiple jurisdictions simultaneously.&nbsp;<\/p>\n\n\n\n<p>Delaware's law adds one more layer, which, because its compliance thresholds are notably lower than its predecessors, draws in a broader range of organizations than many expect.Delaware's DPDPA is considered one of the more consumer-protective state-level privacy laws in the U.S., though it does not reach the stringency of <a href=\"https:\/\/www.cookiebot.com\/en\/what-is-ccpa\/\">California's CCPA\/CPRA<\/a>. It covers a wider range of business sizes than laws like <a href=\"https:\/\/www.cookiebot.com\/en\/florida-digital-bill-of-rights-fdbr\/\">Florida's Digital Bill of Rights (FDBR)<\/a>, which primarily targets large platforms, and unlike the <a href=\"https:\/\/www.cookiebot.com\/en\/texas-data-privacy-and-security-act-tdpsa\/\">Texas Data Privacy and Security Act (TDPSA)<\/a>, it does not exempt small businesses by revenue.<\/p>\n\n\n<div class=\"cta-block cta-block--size-m cta-block--has-shield cb-ctx--blue\">\n            <img decoding=\"async\"\n            class=\"cta-block__shield\"\n            src=\"\/wp-content\/themes\/cookiebot\/img\/backgrounds\/cta-shield.svg\"\n            alt=\"Cookiebot bg shield\"\n            width=\"930\"\n            height=\"929\"\n            loading=\"lazy\">\n        <div class=\"cta-block__glass\">\n        <div class=\"cta-block__inner\">\n            <div class=\"cta-block__left-column\">\n                                                    <h2 class=\"cta-block__title no-default-margin like-h2\">\n                        Does Delaware's DPDPA apply to your business?                    <\/h2>\n                                                    <div class=\"cta-block__description like-text-md\">\n                        <p>Delaware's DPDPA has no revenue requirement and a low consumer data threshold. That means more businesses are covered than they may realize. Check your obligations \u2014 and other laws that might apply to you.<\/p>\n                    <\/div>\n                                                                                                                <div class=\"cta-block__buttons\">\n                                                    <div class=\"cta-block__buttons__button-wp\">\n                                <a id=\"dcc34763-f5d9-4d2a-85a3-136135ed844d\" class=\"cb-button cb-button-size-l cb-button-contained  no-default-link-decoration cb-button-icon-right cta-block__buttons__button\" href=\"\/en\/regulations-finder\/\" target=\"\">\n<span>Find My Regulations<\/span><\/a>\n                                                            <\/div>\n                                                                        <\/div>\n                                                                                <\/div>\n                    <\/div>\n    <\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-the-delaware-personal-data-privacy-act\">What Is the Delaware Personal Data Privacy Act?<\/h2>\n\n\n\n<p>The DPDPA is a consumer-oriented data protection statute designed to give Delaware residents meaningful control over how their personal data is collected, used, and shared. It establishes a comprehensive set of rights for consumers and a corresponding set of obligations for organizations that process personal data.<\/p>\n\n\n\n<p>The law protects \"consumers\", meaning individuals who are Delaware residents acting in a personal or household capacity, not in a commercial or employment context. It defines data controllers, processors, and the categories of data they handle, and it establishes enforcement authority in the Delaware Attorney General and Department of Justice (DOJ).<\/p>\n\n\n\n<p>The DPDPA follows the opt-out consent model common to most U.S. state privacy laws: businesses can generally collect and process personal data without prior consent, but must give consumers meaningful opportunities to opt out of certain uses, including the sale of personal data, targeted advertising, and profiling. Prior opt-in consent is required only for sensitive data categories and children's data.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-who-must-comply-with-the-dpdpa\">Who Must Comply with the DPDPA?<\/h2>\n\n\n\n<p>The DPDPA applies to any person \u2014 defined as an individual or entity \u2014 that conducts business in Delaware or produces products and services targeted at Delaware residents, and that during the preceding calendar year met at least one of the following thresholds:<\/p>\n\n\n\n<div class=\"cb-article-list-timeline cb-article-list-timeline--empty-header cb-article-list-timeline--no-image cb-ctx--base\" style=\"\" data-manual-enabling=\"false\" style=\"--items-count: 2\">\n        <div class=\"cb-article-list-timeline__list\">\n                    <div class=\"cb-article-list-timeline__item\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p>Controlled or processed the personal data of at least 35,000 consumers (excluding data processed solely to complete a payment transaction), or<\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <div class=\"cb-article-list-timeline__item cb-article-list-timeline__item--last\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p>Controlled or processed the personal data of at least 10,000 consumers and derived more than 20 percent of gross revenue from the sale of personal data.<\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <\/div>\n<\/div>\n\n\n\n<p>The 35,000-consumer figure is among the lowest threshold of any comparable U.S. state privacy law to date. This was a deliberate design choice, given Delaware's population of roughly one million people.&nbsp;<\/p>\n\n\n\n<p>The practical effect is that Delaware's law draws in significantly more small and mid-market businesses relative to the state's population than most comparable laws. Companies that have not historically considered themselves subject to state privacy laws should review these thresholds carefully.<\/p>\n\n\n\n<p>Notably, the DPDPA does not include a revenue-only threshold. A company cannot qualify solely on the basis of annual revenue; it must meet one of the data-volume criteria above.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-dpdpa-exemptions\">DPDPA Exemptions<\/h3>\n\n\n\n<p>Certain entities and categories of data are exempt from the DPDPA's requirements. Exempt entities include:<\/p>\n\n\n\n<div class=\"cb-article-list-timeline cb-article-list-timeline--empty-header cb-article-list-timeline--no-image cb-ctx--base\" style=\"\" data-manual-enabling=\"false\" style=\"--items-count: 7\">\n        <div class=\"cb-article-list-timeline__list\">\n                    <div class=\"cb-article-list-timeline__item\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p>Governmental agencies (regulatory, administrative, legislative, or judicial bodies)<\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <div class=\"cb-article-list-timeline__item\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p>Public health organizations<\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <div class=\"cb-article-list-timeline__item\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p>Financial institutions and their affiliates subject to the Gramm-Leach-Bliley Act (GLBA)<\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <div class=\"cb-article-list-timeline__item\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p>Press, wire, or other information services, and the non-commercial activities of media entities<\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <div class=\"cb-article-list-timeline__item\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p>Nonprofit organizations dedicated exclusively to preventing and addressing insurance crime<\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <div class=\"cb-article-list-timeline__item\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p>Nonprofit organizations that provide services to victims of child abuse, domestic violence, human trafficking, sexual assault, violent felony, or stalking<\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <div class=\"cb-article-list-timeline__item cb-article-list-timeline__item--last\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p>Higher education institutions<\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <\/div>\n<\/div>\n\n\n\n<p>Data exempt from the law's scope includes information already governed by the following federal laws:<\/p>\n\n\n\n<div class=\"cb-article-list-timeline cb-article-list-timeline--empty-header cb-article-list-timeline--no-image cb-ctx--base\" style=\"\" data-manual-enabling=\"false\" style=\"--items-count: 7\">\n        <div class=\"cb-article-list-timeline__list\">\n                    <div class=\"cb-article-list-timeline__item\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p><a href=\"https:\/\/usercentrics.com\/knowledge-hub\/health-insurance-portability-and-accountability-act-hipaa\/\" target=\"_blank\" rel=\"noopener\">Health Insurance Portability and Accountability Act (HIPAA)<\/a><\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <div class=\"cb-article-list-timeline__item\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p><a href=\"\/en\/gramm-leach-bliley-act-glba\/\">Gramm-Leach-Bliley Act (GLBA)<\/a><\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <div class=\"cb-article-list-timeline__item\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p>Fair Credit Reporting Act (FCRA)<\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <div class=\"cb-article-list-timeline__item\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p>Driver's Privacy Protection Act<\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <div class=\"cb-article-list-timeline__item\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p>Family Educational Rights and Privacy Act (FERPA)<\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <div class=\"cb-article-list-timeline__item\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p>Farm Credit Act<\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <div class=\"cb-article-list-timeline__item cb-article-list-timeline__item--last\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p>Airline Deregulation Act<\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <\/div>\n<\/div>\n\n\n\n<p>One important nuance: unlike some state laws, the DPDPA does not offer a blanket entity-level exemption for HIPAA-covered entities. Only the specific protected health information governed by HIPAA is exempt. Organizations that handle both HIPAA-regulated data and other categories of personal data may still fall within the DPDPA's scope for the latter. Legal counsel should review this carefully.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-key-definitions-under-the-dpdpa\">Key Definitions Under the DPDPA<\/h2>\n\n\n\n<p>Understanding the DPDPA's core definitions is essential to assessing compliance obligations accurately.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-personal-data\">Personal Data<\/h3>\n\n\n\n<p>Personal data is defined as any information that is linked or reasonably linkable to an identified or identifiable individual. De-identified data and publicly available information are excluded. Common examples include home addresses, driver's license numbers, passport information, financial account numbers, login credentials, and payment card information.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-sensitive-data\">Sensitive Data<\/h3>\n\n\n\n<p>Sensitive data is a specific, higher-risk subset of personal data that requires prior consumer consent before processing. Under the DPDPA, sensitive data includes information that reveals:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Racial or ethnic origin<\/li>\n\n\n\n<li>Religious beliefs<\/li>\n\n\n\n<li>Mental or physical health condition or diagnosis, including pregnancy<\/li>\n\n\n\n<li>Sex life or sexual orientation, including status as transgender or nonbinary<\/li>\n\n\n\n<li>National origin<\/li>\n\n\n\n<li>Citizenship or immigration status<\/li>\n\n\n\n<li>Genetic or biometric data processed to uniquely identify an individual<\/li>\n\n\n\n<li>Personal data collected from a known child (under 13 years of age)<\/li>\n\n\n\n<li>Precise geolocation data (within a radius of 1,750 feet)<\/li>\n<\/ul>\n\n\n\n<p>Delaware's inclusion of transgender or nonbinary gender status as sensitive data was, at the time of the law's passage, shared only with Oregon among U.S. state privacy statutes, though several more states have since adopted this in their privacy laws.&nbsp;<\/p>\n\n\n\n<p>The DPDPA also provides a specific definition of \"genetic data\", which was first among comprehensive U.S. state privacy laws at the time of enactment.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-consent\">Consent<\/h3>\n\n\n\n<p>The DPDPA aligns with the consent standard established by the EU's <a href=\"https:\/\/www.cookiebot.com\/en\/gdpr\/\">General Data Protection Regulation (GDPR)<\/a>: consent must be a clear affirmative act that is freely given, specific, informed, and unambiguous. A written statement (including electronic) or any other unambiguous affirmative action qualifies.\u00a0<\/p>\n\n\n\n<p>Consent does not include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Acceptance of general or broad terms of use containing data processing descriptions alongside unrelated information<\/li>\n\n\n\n<li>Actions such as hovering, muting, pausing, or closing a piece of content<\/li>\n\n\n\n<li>Agreement obtained through the use of <a href=\"https:\/\/usercentrics.com\/knowledge-hub\/dark-patterns-and-how-they-affect-consent\/\">dark patterns<\/a><\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-controllers-and-processors\">Controllers and Processors<\/h3>\n\n\n\n<p>A <strong>controller<\/strong> is any person or entity that, alone or jointly with others, determines the purpose and means of processing personal data. A <strong>processor<\/strong> is any person or entity that processes personal data on behalf of a controller. The distinction matters because each role carries different (though related) compliance obligations under the law.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-profiling\">Profiling<\/h3>\n\n\n\n<p>The DPDPA defines profiling as any automated processing performed on personal data to evaluate, analyze, or predict aspects of an individual's economic situation, health, demographic characteristics, personal preferences, interests, reliability, behavior, location, or movements.&nbsp;<\/p>\n\n\n\n<p>The inclusion of \"demographic characteristics\" is broader than the profiling definitions in most comparable U.S. state laws, giving Delaware consumers a correspondingly wider right to opt out.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-targeted-advertising\">Targeted Advertising<\/h3>\n\n\n\n<p>Targeted advertising means displaying advertisements selected based on personal data obtained from a consumer's activities over time and across non-affiliated websites or applications. It does not include ads based solely on the context of the current visit, on-site activity, or direct responses to consumer requests, nor does it include processing purely to measure advertising performance.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-sale-of-personal-data\">Sale of Personal Data<\/h3>\n\n\n\n<p>Sale of personal data means the exchange or transfer of personal data for monetary or other valuable consideration to a third party. Excluded from this definition are disclosures to processors acting on the controller's behalf, transfers within affiliated entities, consumer-directed disclosures, publicly available data, and transfers as part of mergers, acquisitions, or bankruptcy proceedings.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-consumer-rights-under-the-dpdpa\">Consumer Rights Under the DPDPA<\/h2>\n\n\n\n<p>Delaware residents have seven rights under the DPDPA. Controllers must provide accessible mechanisms for consumers to exercise each of these rights:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Right to access:<\/strong> Consumers may confirm whether a controller is processing their personal data, and access that data.<\/li>\n\n\n\n<li><strong>Right to disclosure:<\/strong> Consumers may request a list of the specific categories of third parties to which their personal data has been disclosed.<\/li>\n\n\n\n<li><strong>Right to correction:<\/strong> Consumers may request correction of inaccurate or outdated personal data the controller holds that was provided by the consumer.<\/li>\n\n\n\n<li><strong>Right to deletion:<\/strong> Consumers may request deletion of their personal data held by the controller, subject to certain exceptions.<\/li>\n\n\n\n<li><strong>Right to portability:<\/strong> Consumers may obtain a copy of their personal data in a readily usable format.<\/li>\n\n\n\n<li><strong>Right not to be discriminated against:<\/strong> Controllers cannot deny services, charge different prices, or otherwise penalize consumers for exercising their rights.<\/li>\n\n\n\n<li><strong>Right to opt out:<\/strong> Consumers may opt out of the sale of personal data, targeted advertising, and profiling in furtherance of solely automated decisions that produce legal or similarly significant effects.<\/li>\n<\/ul>\n\n\n\n<p>Consumers may make one privacy rights request for free every 12 months. Controllers may deny requests that are manifestly unfounded, excessive, or repetitive, but bear the burden of demonstrating this. Controllers can also deny requests by consumers whose identities cannot be reasonably verified.<\/p>\n\n\n\n<p>Businesses must respond to consumer requests within 45 days, with a possible 45-day extension if reasonably necessary. If a request is denied, controllers must provide a clear appeal process; the controller then has 60 days to respond to any appeal.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-consumer-complaints-and-the-role-of-the-doj\">Consumer Complaints and the Role of the DOJ<\/h3>\n\n\n\n<p>Consumers who have an unresolved dispute with a controller may submit a complaint to the Delaware Department of Justice. Controllers are required to direct consumers to this mechanism in their privacy notices and appeals processes.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-coverage-for-children\">Coverage for Children<\/h3>\n\n\n\n<p>Parents and legal guardians may exercise consumer rights on behalf of children. All personal data of known children is classified as sensitive by default under the DPDPA, meaning prior parental or guardian consent is required before processing.&nbsp;<\/p>\n\n\n\n<p>The DPDPA defers to the federal <a href=\"https:\/\/usercentrics.com\/knowledge-hub\/childrens-online-privacy-protection-act-coppa\/\">Children's Online Privacy Protection Act (COPPA)<\/a> for definitions and protections, including the definition of a \"child\" as any person under 13 years of age.<\/p>\n\n\n<div class=\"cta-block cta-block--size-m cta-block--has-shield cb-ctx--blue\">\n            <img decoding=\"async\"\n            class=\"cta-block__shield\"\n            src=\"\/wp-content\/themes\/cookiebot\/img\/backgrounds\/cta-shield.svg\"\n            alt=\"Cookiebot bg shield\"\n            width=\"930\"\n            height=\"929\"\n            loading=\"lazy\">\n        <div class=\"cta-block__glass\">\n        <div class=\"cta-block__inner\">\n            <div class=\"cta-block__left-column\">\n                                                    <h2 class=\"cta-block__title no-default-margin like-h2\">\n                        Manage personal data collection, consent, and user preferences with Cookiebot                    <\/h2>\n                                                    <div class=\"cta-block__description like-text-md\">\n                        <p>In 5 minutes you can customize your cookie banner for your brand and relevant regulations. Then start your 14-day free trial to see it in action.<\/p>\n                    <\/div>\n                                                                                                                <div class=\"cta-block__buttons\">\n                                                    <div class=\"cta-block__buttons__button-wp\">\n                                <a id=\"abe16e1c-6184-4e5b-9027-0bb06a76a6f0\" class=\"cb-button cb-button-size-l cb-button-contained  no-default-link-decoration cb-button-icon-right cta-block__buttons__button\" href=\"\/en\/cmp-interactive-demo-builder\/\" target=\"\">\n<span>Try It Now<\/span><\/a>\n                                                            <\/div>\n                                                                        <\/div>\n                                                                                <\/div>\n                    <\/div>\n    <\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-business-obligations-under-the-dpdpa\">Business Obligations Under the DPDPA<\/h2>\n\n\n\n<p>The DPDPA creates a set of concrete obligations for controllers and processors. Organizations that fall within the law's scope should make sure that they have addressed each of the following areas.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-privacy-notice-requirements\">Privacy Notice Requirements<\/h3>\n\n\n\n<p>Controllers must publish a privacy notice that is reasonably accessible, clear, and meaningful. The notice must include:<\/p>\n\n\n\n<div class=\"cb-article-list-timeline cb-article-list-timeline--empty-header cb-article-list-timeline--no-image cb-ctx--base\" style=\"\" data-manual-enabling=\"false\" style=\"--items-count: 7\">\n        <div class=\"cb-article-list-timeline__list\">\n                    <div class=\"cb-article-list-timeline__item\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p>Categories of personal data collected and processed<\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <div class=\"cb-article-list-timeline__item\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p>Purposes for processing<\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <div class=\"cb-article-list-timeline__item\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p>Categories of personal data shared with third parties, and the categories of those third parties<\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <div class=\"cb-article-list-timeline__item\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p>How consumers can exercise their rights, including opting out<\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <div class=\"cb-article-list-timeline__item\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p>How consumers can appeal a controller's decision (e.g., if a data access request is denied)<\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <div class=\"cb-article-list-timeline__item\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p>An active email address or other secure, reliable digital contact method for the controller<\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <div class=\"cb-article-list-timeline__item cb-article-list-timeline__item--last\" >\n                <div class=\"cb-article-list-timeline__item-graphics \">\n                    <div class=\"cb-article-list-timeline__item-bullet cb-article-list-timeline__item-bullet--icon\">\n                        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M9.63335 17.838L3.93335 12.138L5.35835 10.713L9.63335 14.988L18.8084 5.81299L20.2334 7.23799L9.63335 17.838Z\" fill=\"black\"\/>\n<\/svg>\n                    <\/div>\n                <\/div>\n\n                <div class=\"cb-article-list-timeline__item-content\">\n                                        <div class=\"cb-article-list-timeline__item-description\">\n                        <p>Clear and conspicuous disclosure if the controller sells personal data or uses it for targeted advertising purposes<\/p>\n                    <\/div>\n                <\/div>\n            <\/div>\n                    <\/div>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-data-minimization-and-purpose-limitation\">Data Minimization and Purpose Limitation<\/h3>\n\n\n\n<p>Controllers may only process personal data for the purposes disclosed to consumers. That processing must be adequate, relevant, and reasonably necessary in relation to those stated purposes. If the purposes for processing change, controllers must provide new notice. Where relevant, they must also obtain fresh consent for the additional purposes.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-data-security\">Data Security<\/h3>\n\n\n\n<p>Controllers must establish and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data they hold.&nbsp;<\/p>\n\n\n\n<p>This obligation extends to protecting the confidentiality, integrity, and accessibility of that data. Processors are similarly obligated, and their security responsibilities must be formalized contractually before processing begins.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-data-protection-assessments\">Data Protection Assessments<\/h3>\n\n\n\n<p>Controllers are required to conduct data protection assessments (DPAs) for processing activities that present a heightened risk of harm, including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Targeted advertising<\/li>\n\n\n\n<li>Processing of sensitive data<\/li>\n\n\n\n<li>Sale of personal data<\/li>\n\n\n\n<li>Profiling where there is a reasonably foreseeable or heightened risk of harm<\/li>\n<\/ul>\n\n\n\n<p>Additionally, controllers that process data belonging to 100,000 or more consumers must conduct regular DPAs. Importantly, this requirement applies only to processing activities created or generated on or after July 1, 2025, but it is not retroactive. The Delaware Attorney General may require a controller to disclose a DPA in the course of any investigation.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-consent-requirements\">Consent Requirements<\/h3>\n\n\n\n<p>Prior consent is not required for most data processing under the DPDPA, but it is mandatory for sensitive data and children's data. Where consent is obtained, consumers must be able to revoke it as easily as they gave it. Upon receiving a revocation, controllers must cease processing within 15 days.<\/p>\n\n\n\n<p>In the event of a data subject request or audit, it is also important for controllers to maintain and have available comprehensive and up-to-date records of users\u2019 consent choices over time.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-nondiscrimination\">Nondiscrimination<\/h3>\n\n\n\n<p>Controllers are prohibited from unlawfully discriminating against consumers who exercise their rights. This includes denying access to a website because a consumer has opted out of data collection.&nbsp;<\/p>\n\n\n\n<p>However, if certain features depend on specific cookies or trackers to function, and a consumer opts out of those, the resulting limitation is not considered discriminatory. Controllers may offer reasonable, proportionate incentives, such as loyalty program benefits, for voluntary data sharing, but such offers cannot be structured to look like payments for consent.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-third-party-contracts-and-processor-obligations\">Third-Party Contracts and Processor Obligations<\/h3>\n\n\n\n<p>A binding contract must be in place between a controller and any processor before data processing begins. That contract must specify:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A duty of confidentiality<\/li>\n\n\n\n<li>Clear instructions for processing, including nature, purpose, type of data, and duration<\/li>\n\n\n\n<li>Rights and obligations of both parties<\/li>\n\n\n\n<li>Requirements for the processor to delete or return data at the end of services, absent superseding legal obligations<\/li>\n\n\n\n<li>The processor's obligation to provide, on request, all information needed to verify compliance<\/li>\n\n\n\n<li>Requirements for any subprocessors to comply with the same obligations<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-universal-opt-out-mechanism-uoom\">Universal Opt-Out Mechanism (UOOM)<\/h3>\n\n\n\n<p>As of January 1, 2026, controllers subject to the DPDPA must recognize universal opt-out signals such as the <a href=\"https:\/\/www.cookiebot.com\/en\/global-privacy-control\/\">Global Privacy Control (GPC)<\/a>. As of 2026, Delaware is one of 12 states requiring GPC or UOOM recognition.\u00a0<\/p>\n\n\n\n<p>GPC enables consumers to set opt-out preferences once \u2014 typically in their browser \u2014 and have those preferences communicated automatically to all compatible websites they visit. This removes the burden on consumers of opting out individually on each site (consumers wouldn\u2019t typically see a consent banner, for example) and places the recognition obligation squarely on controllers.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-dpdpa-enforcement-what-changed-in-2026\">DPDPA Enforcement: What Changed in 2026<\/h2>\n\n\n\n<p>The enforcement landscape for the DPDPA has evolved since the law took effect. Two milestones in particular have shifted how businesses should approach their compliance posture going into 2026 and beyond.<\/p>\n\n\n\n<p>Enforcement authority rests exclusively with the Delaware Attorney General and Department of Justice. Consumers do not have a private right of action under the DPDPA, meaning they cannot sue controllers directly, for example, in the event of a data breach. Instead, complaints are submitted to the DOJ, which investigates and may initiate proceedings.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-the-cure-period-has-sunset\">The Cure Period Has Sunset<\/h3>\n\n\n\n<p>Until December 31, 2025, the DPDPA required the Attorney General to provide a 60-day cure period before initiating enforcement action. This gave controllers time to fix identified violations before incurring penalties.&nbsp;<\/p>\n\n\n\n<p>That mandatory cure period expired as of January 1, 2026. The DOJ has full discretion over whether to offer any opportunity to cure, depending on the nature, scope, and severity of the violation. Organizations that relied on the cure period as a compliance buffer no longer have that safety net.<\/p>\n\n\n\n<p>When determining whether and how to enforce, the DOJ weighs factors including the number and nature of violations, the size and complexity of the organization, the likelihood of harm to the public, whether the violation resulted from human or technical error, and the organization's prior compliance history.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-penalties\">Penalties<\/h3>\n\n\n\n<p>Violations of the DPDPA constitute a per se violation of Delaware's Consumer Fraud Act under <a href=\"https:\/\/delcode.delaware.gov\/title29\/c025\/sc02\/index.html\">Subchapter II of Chapter 25 of Title 29<\/a> of the Delaware Code. The Attorney General may investigate, initiate administrative proceedings, sanction unlawful conduct, and\/or seek remedies including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Civil penalties up to USD 10,000 per violation, pursuant to Delaware's Consumer Fraud Act<\/li>\n\n\n\n<li>Injunctive relief<\/li>\n\n\n\n<li>Restitution<\/li>\n\n\n\n<li>Disgorgement of unlawfully obtained gains<\/li>\n<\/ul>\n\n\n\n<p>There is no cap on the aggregate number of violations that can be charged, meaning that a single non-compliant data processing practice affecting thousands of consumers could, in principle, give rise to thousands of individual violations.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-the-dpdpa-is-different-from-other-u-s-state-privacy-laws\">How the DPDPA Is Different from Other U.S. State Privacy Laws<\/h2>\n\n\n\n<p>While the DPDPA shares many structural features with other comprehensive U.S. state privacy laws, several provisions set it apart in ways that matter for compliance planning.<\/p>\n\n\n\n<p>The 35,000-consumer threshold is one of the lowest of any comparable U.S. law, drawing in a broader population of businesses, including smaller organizations with significant data processing activity.&nbsp;<\/p>\n\n\n\n<p>The revenue threshold is also comparatively accessible: deriving 20 percent of gross revenue from data sales while processing 10,000 consumers' data triggers coverage. Laws in states like California or Colorado require higher revenue percentages or larger consumer volumes.<\/p>\n\n\n\n<p>Delaware's definition of profiling is broader than most, explicitly including \"demographic characteristics\". This gives consumers the right to opt out of a wider range of automated data processing activities.<\/p>\n\n\n\n<p>The right to disclosure \u2014 specifically, the right to receive a list of the categories of third parties to whom a controller has disclosed personal data \u2014 is found in only a handful of other U.S. state privacy laws. Oregon and Minnesota go further, requiring controllers to name specific third parties; Maryland shares Delaware's narrower formulation.<\/p>\n\n\n\n<p>Nonprofits are generally covered from day one, unlike some state laws (such as Oregon's) that granted nonprofits additional transition time. Organizations in the nonprofit sector should not assume an exemption applies without verifying which, if any, of the specific nonprofit carve-outs they meet.<\/p>\n\n\n\n<p>Finally, the DPDPA does not authorize rulemaking, meaning the law's text is the definitive source of obligations. There is no state privacy agency that will issue clarifying regulations over time, as California's CPPA does. This makes precise statutory interpretation and qualified legal counsel particularly important.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-consent-management-and-dpdpa-compliance\">Consent Management and DPDPA Compliance<\/h2>\n\n\n\n<p>The DPDPA's opt-out framework requires businesses to give consumers clear, accessible, and actionable information about how their data is being processed. They must also have a straightforward mechanism to exercise their choices. A consent management platform (CMP) is one of the most practical tools available to help achieve this.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.cookiebot.com\/en\/cookie-consent-solution\/\">Cookiebot by Usercentrics<\/a> scans websites automatically to identify cookies and tracking technologies in use, categorizes them, and surfaces them to users in a transparent consent banner.&nbsp;<\/p>\n\n\n\n<p>For a DPDPA-subject organization, this directly addresses the law's requirement to provide consumers with clear, granular information about the categories of data collected, the specific services involved, and the third parties with whom data is shared.<\/p>\n\n\n\n<p>Cookiebot CMP also supports the management of consent preferences across multiple regulations simultaneously, which is essential for businesses operating in several U.S. states or internationally.&nbsp;<\/p>\n\n\n\n<p>Geotargeting capabilities enable the CMP to present region-specific consent experiences in the user's preferred language, ensuring that both opt-out obligations under Delaware's law and opt-in requirements under frameworks like the GDPR are handled correctly for each visitor.<\/p>\n\n\n\n<p>As of January 1, 2026, the DPDPA requires controllers to recognize the Global Privacy Control signal and other universal opt-out mechanisms. Cookiebot by Usercentrics supports GPC recognition, enabling businesses to honor browser-level opt-out preferences automatically and without requiring consumers to navigate each site individually.<\/p>\n\n\n\n<p>For organizations managing compliance across multiple U.S. states, the patchwork nature of state-level privacy law makes a centralized, adaptable consent infrastructure a practical necessity. See the <a href=\"https:\/\/www.cookiebot.com\/en\/us-data-privacy-laws\/\">Cookiebot guide to U.S. data privacy laws<\/a> for a broader overview of the landscape.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-preparing-for-dpdpa-compliance-a-practical-checklist\">Preparing for DPDPA Compliance: A Practical Checklist<\/h2>\n\n\n\n<p>This section is not legal advice; organizations should consult qualified privacy counsel for a compliance program tailored to their specific operations. That said, the following steps represent the core areas any DPDPA-subject business should address.<\/p>\n\n\n\n<p>The DPDPA's compliance threshold review should be the starting point. If your organization processes data on 35,000 or more Delaware residents, or 10,000 or more with significant revenue from personal data sales, it is in scope. This is a lower bar than many businesses assume.<\/p>\n\n\n\n<p>Once scope is confirmed, organizations should audit their data processing activities:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>What personal data is collected<\/li>\n\n\n\n<li>What the processing purposes are<\/li>\n\n\n\n<li>How long data is retained and how it is deleted\/anonymized<\/li>\n\n\n\n<li>Which third parties receive data&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>Such audits should be conducted regularly as business operations, technologies in use, and regulatory requirements change. The inventory forms the foundation for a compliant privacy notice and for conducting the data protection assessments now required for activities created or generated after July 1, 2025.<\/p>\n\n\n\n<p>Privacy notices should be reviewed against the DPDPA's specific requirements, particularly the obligation to disclose the categories of third parties to whom data has been shared, and to provide a clear contact mechanism (such as a verified email address) for consumer requests. Opt-out links must be clear and conspicuous on the website.<\/p>\n\n\n\n<p>Consumer rights request processes \u2014 covering access, correction, deletion, portability, and opt-out \u2014 should be documented and tested. Response timelines (45 days, extendable by 45 days) and the appeal procedure (60-day response window) must be built into operational workflows.<\/p>\n\n\n\n<p>Data processing agreements with all processors must be reviewed or established. If processors engage subprocessors, the chain of contractual obligations must extend to them as well.<\/p>\n\n\n\n<p>With the mandatory cure period now expired, organizations should treat DPDPA enforcement as fully active. The January 1, 2026 universal opt-out deadline means GPC recognition is now an immediate operational requirement, not a future obligation.<\/p>\n\n\n<div class=\"cta-block cta-block--size-m cta-block--has-shield cb-ctx--blue\">\n            <img decoding=\"async\"\n            class=\"cta-block__shield\"\n            src=\"\/wp-content\/themes\/cookiebot\/img\/backgrounds\/cta-shield.svg\"\n            alt=\"Cookiebot bg shield\"\n            width=\"930\"\n            height=\"929\"\n            loading=\"lazy\">\n        <div class=\"cta-block__glass\">\n        <div class=\"cta-block__inner\">\n            <div class=\"cta-block__left-column\">\n                                                    <h2 class=\"cta-block__title no-default-margin like-h2\">\n                        One state's privacy rules or all of them? They all have specific requirements.                    <\/h2>\n                                                    <div class=\"cta-block__description like-text-md\">\n                        <p>Do you have privacy obligations only in the state where you're headquartered, or need coast-to-coast or global coverage? Find out what relevant laws say about consumer rights and what you need to do.<\/p>\n                    <\/div>\n                                                                                                                <div class=\"cta-block__buttons\">\n                                                    <div class=\"cta-block__buttons__button-wp\">\n                                <a id=\"65803202-0dc9-495f-95e3-e15f6599a657\" class=\"cb-button cb-button-size-l cb-button-contained  no-default-link-decoration cb-button-icon-right cta-block__buttons__button\" href=\"\/en\/regulations-finder\/\" target=\"\">\n<span>Find My Regulations<\/span><\/a>\n                                                            <\/div>\n                                                                        <\/div>\n                                                                                <\/div>\n                    <\/div>\n    <\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The Delaware Personal Data Privacy Act (DPDPA) took effect January 1, 2025, giving Delaware's one million residents broad rights over their personal data. With one of the lowest consumer-volume thresholds among U.S. state privacy laws, it affects a wide range of businesses, including many mid-market companies that may not realize they qualify.<\/p>\n","protected":false},"author":35,"featured_media":21451,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"editor_notices":[],"footnotes":""},"categories":[1],"tags":[],"class_list":["post-21450","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"acf":[],"thumbnail_status":false,"thumbnail_url":"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2026\/04\/Delaware-DPDPA_1200x630_ffffff.png","_links":{"self":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts\/21450","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/users\/35"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/comments?post=21450"}],"version-history":[{"count":0,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts\/21450\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/media\/21451"}],"wp:attachment":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/media?parent=21450"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/categories?post=21450"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/tags?post=21450"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}