EnglishEspañol
Delaware flag

Delaware

DPDPA Compliance Checklist: Delaware Privacy

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 8 primary sources cited on this page. How we verify our legal content

DPDPA Compliance Checklist: Delaware Privacy

Frequently Asked Questions

Does my business have to comply with the DPDPA?

Under section 12D-103, you must comply if you conduct business in Delaware or target Delaware residents and, in the prior calendar year, controlled or processed the personal data of at least 35,000 consumers (excluding payment-only data), or of at least 10,000 consumers while deriving more than 20 percent of gross revenue from selling personal data. There is no dollar-revenue floor, so the threshold reaches many mid-size and smaller businesses.

Does the DPDPA apply to nonprofits and colleges?

Generally yes. Under section 12D-103, the only nonprofit exemption is for a nonprofit dedicated exclusively to preventing and addressing insurance crime, and institutions of higher education are expressly excluded from the government-body exemption, meaning colleges are covered. Most nonprofits and all colleges that meet the thresholds must comply.

What does a DPDPA privacy notice need to include?

Under section 12D-106, the notice must disclose the categories of personal data processed, the purposes of processing, how consumers exercise their rights and appeal, the categories of data shared with third parties, and the categories of those third parties. If you sell data or run targeted advertising, you must clearly disclose that and explain how to opt out.

When do I need to honor a universal opt-out signal in Delaware?

As of January 1, 2026. Under section 12D-106(e), a controller that processes data for targeted advertising or sells personal data must recognize a universal opt-out preference signal such as Global Privacy Control sent by a consumer's browser or device. You should test that your systems detect, apply, and persist the signal.

When do I need a data protection assessment under the DPDPA?

Under section 12D-108, a controller that controls or processes the personal data of at least 100,000 consumers must conduct and document a data protection assessment for higher-risk processing, including targeted advertising, the sale of personal data, certain profiling, and the processing of sensitive data. The Delaware DOJ can require disclosure of a relevant assessment during an investigation.

Is there still a right to cure under the DPDPA?

Not as a guarantee. Under section 12D-111, the Delaware DOJ was required to give a 60-day cure opportunity during 2025 where a cure was possible, but that mandatory right to cure sunset on December 31, 2025. Beginning January 1, 2026, any cure opportunity is discretionary and weighed against statutory factors, so businesses should not count on a grace period.

What are the penalties for violating the DPDPA?

The Delaware Department of Justice enforces the DPDPA under section 12D-111, and a wilful violation is treated as an unlawful practice that can carry civil penalties of up to $10,000 per violation under section 2522(b). Non-wilful violations can still draw injunctive relief, restitution, or disgorgement. There is no private right of action under section 12D-111(d), so only the Department of Justice can bring an enforcement action.

What contracts do I need with my data processors?

Under section 12D-107, every processor relationship must be governed by a contract that sets out the processing instructions, confidentiality obligations, deletion or return of data at the end of services, cooperation with assessments and audits, and flow-down of the same duties to subcontractors. Vendor agreements that predate the DPDPA should be reviewed and updated to include these terms.

Updates

Corrected the rights-request section to state that Delaware law requires a controller to respond free of charge once per consumer in any 12-month period, not twice per year, and noted the fee exception for manifestly unfounded, excessive, or repetitive requests.

Added a note that Delaware HB 380 (passed both chambers, awaiting the Governor's signature) would lower the DPDPA's applicability thresholds effective January 1, 2027, and clarified that the $10,000-per-violation civil penalty applies only to wilful violations.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Del. Code tit. 6, ch. 12D: Delaware Personal Data Privacy Act (Full Chapter)(delcode.delaware.gov).gov
  2. Del. Code tit. 6, § 12D-103: Applicability and Exemptions(delcode.delaware.gov).gov
  3. Del. Code tit. 6, § 12D-104: Personal Data Rights of Consumers(delcode.delaware.gov).gov
  4. Del. Code tit. 6, § 12D-106: Responsibilities of Controllers(delcode.delaware.gov).gov
  5. Del. Code tit. 6, § 12D-107: Duties of Processors(delcode.delaware.gov).gov
  6. Del. Code tit. 6, § 12D-108: Data Protection Assessments(delcode.delaware.gov).gov
  7. Del. Code tit. 6, § 12D-111: Enforcement by the Department of Justice(delcode.delaware.gov).gov
  8. Delaware DOJ: Personal Data Privacy Act Frequently Asked Questions(attorneygeneral.delaware.gov).gov
Share: