DPDPA
Delaware Personal Data Privacy Act
Virginia-style law with low thresholds and coverage of many nonprofits.
The law in brief
The Delaware Personal Data Privacy Act (DPDPA) is Delaware's comprehensive consumer privacy law. It has been in effect since 1 January 2025. Like the other state laws built on the same model, it gives Delaware residents rights over their personal data and puts duties on the businesses that decide how that data is used (controllers) and on the vendors that handle it for them (processors).
Virginia-style law with low thresholds and coverage of many nonprofits.
Who it applies to
- Businesses that process personal data of the state's residents above the law's thresholds. Thresholds, exemptions and sensitive-data rules differ by state.
- The thresholds usually turn on how many Delaware residents' personal data a business handles in a year, and whether it earns revenue from selling personal data. Check the statute for the exact figures.
- Like most state privacy laws, it exempts some organizations and data, commonly including data already covered by HIPAA or the Gramm-Leach-Bliley Act, and data about people acting in an employment or commercial capacity.
What it requires
A clear privacy notice
Publish a privacy notice describing the categories of personal data you process, why, what you share and with whom, how consumers can use their rights, and how to appeal.
Collect only what you need
Limit collection to what is adequate, relevant and reasonably necessary for the purposes you disclosed, and secure it with reasonable safeguards.
Sensitive data
Get the consumer's opt-in consent before processing sensitive data, such as health information, biometric or genetic data, precise geolocation, and data about a known child (for whom parental consent is needed).
Contracts with processors
Bind each processor by contract to your instructions, confidentiality, deletion or return at the end of the service, and help with audits and assessments.
Honor opt-outs
Stop targeted advertising, sales and, where covered, qualifying profiling for consumers who opt out, and check whether the law requires you to honor universal opt-out signals such as Global Privacy Control.
Data protection assessments
Document an assessment before processing that presents a heightened risk, such as targeted advertising, selling personal data, processing sensitive data, and certain profiling.
People's rights
Delaware residents can generally ask a business to confirm and access their personal data, correct it, delete it and get a copy in a portable format, and can opt out of targeted advertising, the sale of their data, and profiling that produces legal or similarly significant effects. Businesses generally have 45 days to respond, extendable once. Residents can usually appeal a refusal.
Enforcement and penalties
Enforced by the Delaware Attorney General. Violations carry civil penalties set by the statute.
What to do first
- Check the thresholds against your Delaware consumer numbers and any data sales.
- Map the personal and sensitive data you hold about Delaware residents.
- Update your privacy notice and add the opt-out routes the law requires.
- Set up requests and appeals within the response deadlines.
- Put DPDPA-ready terms in processor contracts.
- Build one program for all state laws, then add Delaware's departures.
Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.
Recent developments
-
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
The law creates new notice, disclosure, and remediation obligations for employers using AI in hiring, promotion, and termination decisions. On May 14, 2026, Colorado Governor signed SB 26-189, repealing and replacing the 2024 Artificial Intelligence Act. The new law, effective January 1, 2027, targets automated decision‑making technology (ADMT) that materially influences consequential employment decisions. It requires deployers to notify individuals before use, disclose decisions within 30 days of an adverse outcome, and provide rights to correction, appeal, and human review.
Effective: 1 January 2027. SB 26-189.
Source: Covington Inside Privacy. DPDPA in the regulations library.
-
Senator Mark Kelly introduces Senior Chatbot Protection Act
The bill aims to protect seniors' privacy and autonomy as AI chatbots become more prevalent in their daily lives. Future of Privacy Forum notes the bipartisan Senior Chatbot Protection Act was introduced to establish baseline consumer protections and transparency for AI chatbots used by older adults. The statement welcomes the effort to create clear guardrails for responsible AgeTech.
Source: Future of Privacy Forum. DPDPA in the regulations library.
Sources
- All of the comprehensive privacy laws that take effect in 2026 MultiState · Law firm or analyst
- US state privacy laws comparison (24 enacted laws, effective dates) Recording Law · Law firm or analyst