Skip to main content
Explainer · Reviewed September 2026

What Is the Delaware Personal Data Privacy Act?

DPDPA applies to controllers that conduct business in Delaware or target Delaware residents and meet its 35,000-consumer or 10,000-consumer-plus-more-than-20%-sale-revenue threshold, subject to statutory exceptions. It can apply to nonprofit organizations, requires a 45-day response framework, and requires recognition of qualifying universal opt-out mechanisms beginning January 1, 2026. The Delaware DOJ has exclusive enforcement authority, with civil penalties up to $10,000 per violation; the mandatory cure rule ended after December 31, 2025, and any later cure opportunity is discretionary.

Rahul Kandoriya
Written byRahul Kandoriya·Founder, OfflistMe·Last updated September 7, 2026

At a glance

Full name
Delaware Personal Data Privacy Act
Short code
DPDPA
Effective date
January 1, 2025
Response reference
45 days in this snapshot
Cure period
None recorded in this snapshot
Private right of action
No
Enforcement
Delaware Department of Justice. Consumer Protection Unit
Penalty reference
Up to $10,000 per violation under the Delaware Consumer Fraud Act

Who DPDPA applies to

A business is covered if it meets the applicability thresholds set out in Del. Code tit. 6, §§ 12D-101–12D-111. The thresholds listed below are the research record for this law. Whether one or more applies depends on the current statute, its exceptions, and the business's facts; do not assume a universal threshold structure.

  • Conducts business in Delaware or targets Delaware residents and, during the preceding calendar year, controls or processes the personal data of at least 35,000 Delaware consumers, excluding data processed solely for payment transactions
  • Conducts business in Delaware or targets Delaware residents and, during the preceding calendar year, controls or processes the personal data of at least 10,000 Delaware consumers and derives more than 20% of gross revenue from the sale of personal data

Consumer rights under DPDPA

Delete, access, correct, port, opt-out

Nonprofit coverage subject to statutory exclusions

Universal opt-out recognition from January 1, 2026

Notable features (vs. CCPA)

DPDPA can apply to nonprofit organizations subject to statutory exclusions. It requires recognition of qualifying universal opt-out mechanisms beginning January 1, 2026, requires consent for sensitive-data processing, and requires opt-in consent before sale or targeted advertising involving consumers under 18. The statute also addresses de-identified and pseudonymous data without requiring re-identification.

Enforcement and penalty reference

Enforcing agency: Delaware Department of Justice. Consumer Protection Unit

Penalty reference: Up to $10,000 per violation under the Delaware Consumer Fraud Act

Cure period: The mandatory 60-day notice-and-cure rule applied through December 31, 2025. Beginning January 1, 2026, the Delaware Department of Justice may consider statutory factors when deciding whether to offer an opportunity to cure; do not assume that a cure is available.

Private right of action: DPDPA has no private right of action. Enforcement is exclusive to the Delaware Attorney General. Consumer Protection Unit.

Where to file a complaint: Delaware Department of Justice. Consumer Protection

How to exercise your DPDPA rights

  1. 1

    Identify the business that holds your data. OfflistMe can help you review a provider route across 1,034 US/global workflow profiles in the 1,052-record research universe; it does not decide whether a law applies to a specific request.

  2. 2

    Submit a request to the business's designated contact using the provider's current verification instructions. Include only the information reasonably needed to match your record and check the applicable Delaware residency, scope, exemption, and verification rules before sending.

  3. 3

    This research snapshot records a 45-day reference window for the modeled request. Confirm the current statute, request type, controller scope, extension rule, and verification date before treating it as a deadline.

  4. 4

    If the provider does not respond or disputes the request, preserve the request and response record, review the applicable exceptions, and consider the Delaware Department of Justice. Consumer Protection complaint route at https://attorneygeneral.delaware.gov/fraud/cpu/fraud_complaint. A complaint route does not itself guarantee deletion or a particular enforcement result.

Generate requests in under 60 seconds

Generate a DPDPA privacy request, $9 one-time

Review the provider route, applicable law, and information you intend to send before dispatch. You remain in control of the request and any evidence kept.

FAQ

Why does Delaware state law matter if I don't live in Delaware?+

Some businesses, including some data brokers, are incorporated in Delaware, but incorporation alone does not establish that the DPDPA covers a particular consumer request or that the Delaware AG can pursue every out-of-state conduct. Check the controller, processing, consumer, and statutory-scope facts before relying on Delaware as an enforcement route.

Official sources & citations

Compare with sibling state laws

DPDPA is one of 18 comprehensive US state privacy laws. Its closest peers by effective date, useful when tracking how this law influenced or was influenced by neighboring legislation:

Related concepts & guides