Delaware — Comprehensive Law

Delaware Privacy Law

Delaware wrote its exemptions to catch what other states let go. The government-body exclusion at § 12D-103(b)(1) expressly stops short of institutions of higher education, so universities are inside the statute; the nonprofit exclusion reaches only organizations dedicated exclusively to preventing and addressing insurance crime, so charities generally are inside it too. In the other direction the chapter carves out something no neighbouring statute does: the personal data of victims of and witnesses to child abuse, domestic violence, human trafficking, sexual assault, violent felony or stalking, when held by a nonprofit that serves them. The breach statute at § 12B-102(e) requires a year of free credit monitoring whenever a Social Security number is involved, and a separate 2015 chapter regulates what a digital book service may do with a record of what someone read.

The Delaware Personal Data Privacy Act (DPDPA)

Enacted by 84 Del. Laws, c. 197 and in force since January 1, 2025, chapter 12D of title 6 runs from § 12D-101 to § 12D-111. Section 12D-103(a) sets a two-branch threshold measured over the preceding calendar year and excludes payment-transaction-only data from the count. The entity exemptions in subsection (b) are the narrowest in this group: they cover state and local bodies — but the paragraph expressly excludes institutions of higher education from that exclusion — financial institutions and affiliates to the extent subject to Title V of the Gramm-Leach-Bliley Act, nonprofits dedicated exclusively to preventing and addressing insurance crime, and registered national securities and futures associations. Subsection (c) then exempts categories of data rather than entities, and one of those categories is unusual: paragraph (c)(13) removes the personal data of a victim of or witness to child abuse, domestic violence, human trafficking, sexual assault, violent felony or stalking that is collected, processed or maintained by a nonprofit organization providing services to such victims or witnesses. Section 12D-105 lets a consumer designate an authorized agent by way of a platform, technology or mechanism including an internet link, browser setting, browser extension or global device setting, and lets the Department of Justice publish a list of agents presumptively holding that authority. Section 12D-104(e)(1)a.2 required controllers, not later than January 1, 2026, to honour opt-out preference signals meeting five listed conditions, among them that the mechanism not use a default setting but require an affirmative, freely given and unambiguous choice.

Effective dateJanuary 1, 2025
CitationDel. Code tit. 6, ch. 12D
Enforced byDelaware Department of Justice
Maximum penaltyThe Department of Justice states civil penalties of up to $10,000 per violation; 29 Del. C. § 2522(b) sets that figure for a wilful violation in court and § 2523 sets $5,000 administratively
Private right of actionNo, enforcement by the state only
Right to cure60 days, mandatory to December 31, 2025; discretionary from January 1, 2026 against seven statutory factors

Who Must Comply

The DPDPA reaches a business that conducts business in Delaware or produces products or services targeted to Delaware residents, and during the preceding calendar year, and controlled or processed the personal data of not less than 35,000 consumers, excluding data controlled or processed solely to complete a payment transaction, or controlled or processed the personal data of not less than 10,000 consumers and derived more than 20% of gross revenue from the sale of personal data.

Institutions of higher education are expressly kept inside the statute, the nonprofit exemption runs only to insurance-crime organizations, and the data of victims and witnesses held by victim-services nonprofits is exempted outright.

Consumer Rights Under the DPDPA

Residents of Delaware can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.

Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.

Sector-Specific Privacy Laws in Delaware

Online and Personal Privacy Protection (Del. Code tit. 6, ch. 12C)

Chapter 12C predates the comprehensive law and regulates categories the DPDPA does not reach by name. It governs “book service” providers — defined in § 12C-101(3) as a service whose primary purpose is providing individuals with the ability to rent, purchase, borrow, browse or view books electronically or via the internet — and defines “book service information” in paragraph (4) to include any information that identifies, relates to, describes or is associated with a particular user, a unique identifier or internet protocol address used to identify or associate a user or a book in whole or in partial form, and any information relating to or capable of being associated with a user’s access to or use of a book service or a book. Paragraph (5) exempts a commercial entity selling a variety of consumer products where its book service sales do not exceed two percent of its total annual gross sales of consumer products in the United States. The chapter separately governs services directed to children, defining that term in paragraph (11) as one targeted or intended to reach an audience composed predominantly of children — individuals under eighteen who are Delaware residents — and providing that a service is not so directed solely because it refers or links to another such service through a directory, index, reference, pointer or hypertext link. Paragraph (7) prescribes in detail what makes a privacy policy “conspicuously available”, down to the colour contrast, capitalisation and placement of a privacy icon or text link on the homepage or first significant page.

Consumer protection powers of the Department of Justice (Del. Code tit. 29, ch. 25, subch. II)

Section 12D-111(a) gives the Department of Justice authority over the comprehensive chapter to be exercised “in accordance with the provisions of subchapter II of Chapter 25 of Title 29”, and it is there that the money figures live. Section 2522(b) provides that where a court proceeding finds a wilful violation, the court “shall order the violator to pay to the State a civil penalty of not more than $10,000 for each violation”. Section 2523 supplies an administrative alternative, under which the Director or a hearing officer finding a wilful violation orders a civil penalty of not more than $5,000 for each violation. A further provision allows the Attorney General or the Director to petition a court where a person subject to an order or injunction has wilfully violated it or breached a material term of an agreement forming the basis of a cease and desist order, with an enhanced civil penalty of not more than $25,000 per violation and the possibility of contempt sanctions for any subsequent violation of the court’s order.

Breach notice compliance and regulated entities (Del. Code tit. 6, §§ 12B-103, 12B-104)

Section 12B-103 supplies two deemed-compliance routes. Subsection (a) treats a person maintaining its own notice procedures as part of an information security policy for the treatment of personal information, otherwise consistent with the chapter’s timing requirements, as compliant if it notifies affected Delaware residents in accordance with those policies. Subsection (b) treats a person regulated by state or federal law — naming HIPAA and the Gramm-Leach-Bliley Act — that maintains breach procedures under the laws, rules, regulations, guidance or guidelines established by its primary or functional state or federal regulator as compliant if it notifies affected Delaware residents in accordance with those maintained procedures. Section 12B-104(a) then supplies the enforcement route, allowing the Attorney General, under the Director of Consumer Protection’s powers in title 29 chapter 25, to bring an action in law or equity to address violations, for other appropriate relief to ensure compliance, or to recover direct economic damages resulting from a violation, or both. Subsection (a) states that the chapter’s provisions are not exclusive, and subsection (b) preserves any right a person may have at common law, by statute or otherwise.

Data Breach Notification in Delaware

Chapter 12B of title 6 hangs the duty on a determination and then attaches a remedy to it that most state breach statutes leave to negotiation. Section 12B-102(a) requires notice to any Delaware resident whose personal information was or is reasonably believed to have been breached, unless after an appropriate investigation the person reasonably determines that the breach is unlikely to result in harm to the affected individuals. Subsection (c) sets sixty days from determination as the outer limit, with three exceptions: a shorter federal deadline, a law-enforcement request that notice be delayed, and the case where a person could not through reasonable diligence identify within sixty days that particular residents’ information was included, in which case notice to those residents follows as soon as practicable after the later determination unless substitute notice has been given. Subsection (d) requires notice to the Attorney General, no later than the time notice goes to residents, where the affected number to be notified exceeds 500. Subsection (e) is the provision that distinguishes Delaware: where the breach includes a Social Security number, the person “shall offer” each affected resident credit monitoring services at no cost for a period of one year, provide the information necessary to enrol, and include information on how to place a credit freeze — unless the same harm determination in subsection (a) has been made. Subsection (f) addresses the circular case of a breach involving login credentials for an email account the notifying person furnished: notice may not be given to that address, and may instead be given by another statutory method or by clear and conspicuous online notice delivered when the resident is connected to the account from an address or location the person knows the resident customarily uses. Section 12B-104(a) lets the Attorney General sue for relief or to recover direct economic damages, or both.

Residents must be notified without unreasonable delay and not later than 60 days after determination of the breach. Notify the Attorney General where more than 500 Delaware residents are to be notified. Complaints are taken by the Delaware Department of Justice, which enforces the statute.

How the DPDPA Is Enforced

Seven factors, not six. Section 12D-111(b) required the Department of Justice, during the period beginning January 1, 2025 and ending December 31, 2025, to issue a notice of violation before initiating any action where it determined a cure was possible, with sixty days to cure from receipt. Subsection (c) then supplies the discretionary standard from January 1, 2026, and the list is one item longer than New Hampshire’s otherwise identical provision: the number of violations; the size and complexity of the controller or processor; the nature and extent of its processing activities; the substantial likelihood of injury to the public; the safety of persons or property; whether the alleged violation was likely caused by human or technical error; and — the seventh — “[t]he extent to which the controller or processor has violated this or similar laws in the past.” Subsection (d) forecloses a private right of action for violations of the chapter or any other law.

A published list of authorized agents. Section 12D-105(b) gives the Department of Justice a power over the opt-out ecosystem that most states leave unaddressed. A controller must comply with an opt-out request received from an authorized agent where it can verify, with commercially reasonable effort, the identity of the consumer and the agent’s authority to act. The subsection then provides that the Department of Justice “may publish or reference on its website a list of agents who presumptively shall have such authority unless the controller has established a reasonable basis to conclude that the agent lacks such authority”. Subsection (a) allows the consumer to make the designation by way of a platform, technology or mechanism — including an internet link, browser setting, browser extension or global device setting — and provides that the mechanism itself may function as the agent for conveying the decision.

Recent Enforcement in Delaware

The Personal Data Privacy Portal and the public breach database. The Department of Justice publishes two standing records of its privacy work. The Personal Data Privacy Portal, which Attorney General Kathy Jennings launched in July 2024 ahead of the statute’s effective date, carries separate consumer and business guidance, a frequently-asked-questions page and a privacy complaint form; its FAQ states that violators “may face civil penalties up to $10,000 per violation” and that the office may also seek injunctive relief, restitution and disgorgement. Separately, the Consumer Protection Unit maintains a public Data Security Breach Database recording the breach notices submitted to the Attorney General under 6 Del. C. § 12B-102(d), alongside the form by which those notices are filed. Announcing the DPDPA’s entry into force on January 6, 2025, the Attorney General described the law as giving the office “important tools to enforce consumers’ data privacy and security” and set out the new opt-in requirement for sensitive data including race or ethnic origin, religion, health conditions, sexual orientation, gender identity, precise location and biometric data.

Pending Privacy Legislation

Chapter 12D stands as enacted by 84 Del. Laws, c. 197, and its own timetable has supplied the changes: the mandatory notice-and-cure in § 12D-111(b) ran from January 1 to December 31, 2025, the seven-factor discretionary standard in subsection (c) began January 1, 2026, and the opt-out preference signal duty in § 12D-104(e)(1)a.2 attached not later than January 1, 2026. The breach chapter at 12B was substantially rewritten by 81 Del. Laws, c. 129, which added the sixty-day outer limit, the 500-resident Attorney General threshold and the credit-monitoring requirement to a chapter first enacted by 75 Del. Laws, c. 61; §§ 12B-102, 12B-103 and 12B-104 all carry that amendment note. Chapter 12C remains in force alongside the comprehensive law rather than being folded into it, so the book service and child-directed service provisions continue to operate on their own terms.

Federal Privacy Laws That Apply in Delaware

Federal privacy law applies in Delaware by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The DPDPA sits alongside those rules rather than displacing them: the Delaware Department of Justice enforces the state law, while the federal regulators continue to reach the sectors and activities they cover. The state-law counterpart to section 5 is the Consumer protection powers of the Department of Justice (Del. Code tit. 29, ch. 25, subch. II), which the Delaware Department of Justice enforces against businesses whose stated data practices differ from their actual ones.

Delaware Privacy Law FAQ

Are Delaware universities and nonprofits covered by the DPDPA?
Generally yes, and the drafting is deliberate on both counts. Section 12D-103(b)(1) exempts state and local bodies “but excluding any institution of higher education”, so universities do not travel with the government exemption. The only nonprofit exemption in subsection (b) is at paragraph (3), for “[a]ny nonprofit organization dedicated exclusively to preventing and addressing insurance crime”, so nonprofits generally are not exempt as entities.
Does Delaware require free credit monitoring after a breach?
Where a Social Security number is involved, yes. Section 12B-102(e) provides that if the breach of security includes a Social Security number, the person shall offer each affected resident credit monitoring services at no cost for a period of one year, provide all information necessary to enrol, and include information on how the resident can place a credit freeze on their credit file. The obligation does not apply if, after an appropriate investigation, the person reasonably determines that the breach is unlikely to result in harm to the affected individuals.
Whose data does Delaware exempt that other states do not?
Section 12D-103(c)(13) exempts the personal data of a victim of or witness to child abuse, domestic violence, human trafficking, sexual assault, violent felony or stalking, where that data is collected, processed or maintained by a nonprofit organization that provides services to victims of or witnesses to those offences. It sits among data-level exemptions that otherwise track the familiar federal carve-outs for HIPAA, the Fair Credit Reporting Act, the Driver’s Privacy Protection Act, the Family Educational Rights and Privacy Act, the Farm Credit Act and the Airline Deregulation Act.
How does Delaware’s cure standard differ from New Hampshire’s?
By one factor. Both statutes made a sixty-day cure mandatory through the end of 2025 and discretionary thereafter, and both list criteria the enforcer may weigh. New Hampshire’s RSA 507-H:11, III lists six: the number of violations, the size and complexity of the controller or processor, the nature and extent of its processing activities, the substantial likelihood of injury to the public, the safety of persons or property, and whether the violation was likely caused by human or technical error. Delaware’s § 12D-111(c) lists those same six and adds a seventh, “[t]he extent to which the controller or processor has violated this or similar laws in the past.”
What is a “book service” under Delaware law?
Section 12C-101(3) of title 6 defines it as a service by which an entity, as its primary purpose, provides individuals with the ability to rent, purchase, borrow, browse or view books electronically or via the internet. Paragraph (4) defines the associated “book service information” to include any information identifying, relating to, describing or associated with a particular user; a unique identifier or internet protocol address used to identify or associate a user or a book, in whole or partial form; and any information relating to or capable of being associated with a user’s access to or use of a book service or a book. Paragraph (5) exempts a general consumer-products retailer whose book service sales do not exceed two percent of its total annual United States gross sales.
Can Delaware publish a list of trusted opt-out agents?
Section 12D-105(b) says it may. After requiring a controller to comply with an opt-out request from an authorized agent whose identity and authority it can verify with commercially reasonable effort, the subsection provides that the Department of Justice “may publish or reference on its website a list of agents who presumptively shall have such authority unless the controller has established a reasonable basis to conclude that the agent lacks such authority”.
What penalty attaches to a DPDPA violation in Delaware?
The chapter itself states no figure; § 12D-111(a) routes enforcement through subchapter II of chapter 25 of title 29. The Department of Justice’s Personal Data Privacy Portal states that violators “may face civil penalties up to $10,000 per violation” and that the office may also seek injunctive relief, restitution and disgorgement. In the statute, 29 Del. C. § 2522(b) attaches the $10,000-per-violation figure to a wilful violation found in a court proceeding, § 2523 provides for up to $5,000 per violation in an administrative proceeding, and an enhanced penalty of up to $25,000 per violation applies to wilful violation of an order or injunction.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.