{
 "jurisdiction_id": "US-DE",
 "jurisdiction": "United States – Delaware",
 "url": "https://dataprotection.gi/jurisdictions/united-states-delaware/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-06",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 35,
  "sub_modules": 57,
  "source_register": 12
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-delaware/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Core instrument is fully in force with a clear, functioning regulator and well-documented material/territorial scope; amber-adjacent risk only from the unconfirmed pending amendment tracked separately in enforcement_and_redress.",
   "claims": [
    {
     "statement": "The Delaware Personal Data Privacy Act (DPDPA) took effect on January 1, 2025, and is enforced by the Delaware Department of Justice.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/business/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The DPDPA applies to persons conducting business in or targeting Delaware residents that, in the preceding calendar year, controlled or processed the personal data of 35,000 or more consumers, or 10,000 or more consumers while deriving more than 20% of gross revenue from selling personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/delaware-dpdpa-faqs",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The DPDPA does not apply to personal data maintained in compliance with the Gramm-Leach-Bliley Act, HIPAA, or the Fair Credit Reporting Act, nor to certain data processed for specified exempt purposes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/frequently-asked-questions/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Attorney General has stated it will not hesitate to pursue enforcement against out-of-state third parties doing business in Delaware if they meet the DPDPA's applicability threshold.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/frequently-asked-questions/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No controller registration or filing obligation with the Delaware Attorney General was located within the DPDPA or AG guidance; compliance appears self-assessed.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/business/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-delaware/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Structurally divergent from GDPR Art. 6 lawful-basis architecture (amber for interoperability), though the consent standard itself is clearly and consistently defined; pseudonymisation/anonymisation safe-harbour detail was not confirmed.",
   "claims": [
    {
     "statement": "Rather than enumerating GDPR-style lawful bases, the DPDPA relies on a notice-and-purpose-limitation model, requiring affirmative consumer consent only for sensitive-data processing, secondary-purpose processing, and processing following a consumer opt-out.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/frequently-asked-questions/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Under the DPDPA, consent must be affirmative, freely given, specific, informed, and unambiguous; acceptance of broad terms of service, passive interaction with content, or agreement obtained through deceptive webpage design is not valid consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/frequently-asked-questions/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Sensitive data under the DPDPA includes data revealing racial/ethnic origin, religious beliefs, health diagnoses, sexual orientation/activity, citizenship/immigration status, and genetic or biometric data used to uniquely identify an individual, requiring consumer consent prior to collection or processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/frequently-asked-questions/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-delaware/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Rights and response windows are clearly documented and in force.",
   "claims": [
    {
     "statement": "Delaware consumers may request access to personal data a controller has collected about them free of charge once every 12 months; controllers may charge an administrative fee for additional requests.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/frequently-asked-questions/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Consumers have the right to correct inaccuracies in and delete their personal data, including data a controller collected through third parties.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/frequently-asked-questions/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Consumers may opt out of the sale of personal data to third parties and may designate a third party to exercise the opt-out on their behalf.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/frequently-asked-questions/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Consumer rights under the DPDPA include information access, data rectification, erasure, portability, and opt-out options for targeted advertising and automated profiling.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/delaware-governor-signs-personal-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "A controller has 45 days after receipt of a consumer's appeal of a denied rights request to respond in writing, explaining the actions taken and reasons for refusal.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/frequently-asked-questions/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-delaware/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Core security/DPIA/breach duties are well documented and in force; DPO and ROPA specifics are gaps.",
   "claims": [
    {
     "statement": "Controllers must conduct data protection impact assessments (DPIAs) for high-risk processing activities under the DPDPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/delaware-dpdpa-faqs",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No dedicated Data Protection Officer appointment threshold analogous to GDPR Art. 37-39 was identified in the DPDPA or AG guidance.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/business/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Businesses are directed to inventory personal data collected, identify storage locations, and document access and third-party processor relationships, though no formal public Records-of-Processing-Activities filing requirement was confirmed.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/business/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The DPDPA requires businesses to employ reasonable data security measures proportionate to the nature and sensitivity of the personal data collected, to prevent unauthorized access.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2024/12/2024_11_25_Notice-Letter-AG-Signature_Redacted.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Delaware's data breach notification statute, in effect since April 14, 2018, requires notice to affected Delaware residents and, where a breach affects 500 or more residents, additional notice to the Delaware Attorney General.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/cpu/securitybreachnotification/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "red",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-delaware/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "No comprehensive transfer-mechanism regime exists in this state statute; explicit gap consistent with the sectoral/hybrid US pattern.",
   "claims": [
    {
     "statement": "The DPDPA does not contain an adequacy-decision framework, Standard Contractual Clauses regime, Binding Corporate Rules mechanism, or data-localisation mandate; cross-border transfer is governed only indirectly through the Act's general controller/processor contractual and security obligations.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/business/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-delaware/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Financial and health carve-outs are clearly documented; several sub-modules (telecoms, credit-scoring, education, insurance) have no DE-specific overlay evidence.",
   "claims": [
    {
     "statement": "The DPDPA does not apply to personal data maintained in compliance with the Gramm-Leach-Bliley Act, HIPAA, or the Fair Credit Reporting Act, as well as personal data processed for certain specified purposes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/frequently-asked-questions/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The DPDPA applies to Delawareans acting in an individual or household context and does not protect an individual acting in an employment context, such as applying for a job.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/frequently-asked-questions/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-delaware/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Opt-out signal and dark-pattern provisions are confirmed and in force; clean-room and direct-marketing-specific rules are gaps.",
   "claims": [
    {
     "statement": "Acceptance of broad terms of service, hovering over or pausing on content, and agreement obtained through deceptive webpage design ('dark patterns') are not considered valid consent under the DPDPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/frequently-asked-questions/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Beginning January 1, 2026, controllers must recognize universal opt-out mechanisms as valid consumer requests to opt out of personal-data processing across multiple websites at once.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/frequently-asked-questions/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Consumer rights under the DPDPA include opt-out options for targeted advertising and automated profiling.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/delaware-governor-signs-personal-data-privacy-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-delaware/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Biometric/genetic and minor-profiling protections are confirmed; AI-specific risk assessment and surveillance-carveout detail are gaps.",
   "claims": [
    {
     "statement": "The DPDPA requires controllers to obtain opt-in consent before selling a consumer's personal data or processing personal data for targeted advertising when the consumer is under 18 years old.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/parents-and-kids/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No AI-system-specific risk-assessment regime akin to the EU AI Act or state AI-transparency statutes was identified within the DPDPA; its DPIA obligations address 'high-risk processing' generally rather than AI systems specifically.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/delaware-dpdpa-faqs",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Genetic and biometric data used to uniquely identify an individual are classified as sensitive data under the DPDPA, requiring consumer consent prior to collection or processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/frequently-asked-questions/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "A controller may deny a consumer's rights request where fulfilling it would restrict the controller's ability to comply with federal, state, or local law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/frequently-asked-questions/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "green",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-delaware/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Minor-specific protections are clearly documented and in force; education-settings and dependent-adults sub-modules are explicit gaps.",
   "claims": [
    {
     "statement": "Where a child's personal data is processed, the child's parent or legal guardian may exercise the DPDPA's consumer rights on the child's behalf, and controllers must follow COPPA parental-consent requirements.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/parents-and-kids/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "In addition to protections afforded adults, Delaware law provides additional protections for children and teens under 18, including a requirement of opt-in consent before selling their personal data or using it for targeted advertising.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/parents-and-kids/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-delaware/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement powers and penalties are clear and in force; the pending HB 380 amendment's enactment status is an unresolved material development within the 180-day window, and regulator funding/capacity data is a gap.",
   "claims": [
    {
     "statement": "Entities or individuals that violate the DPDPA may face civil penalties up to $10,000 per violation, and the Attorney General can additionally seek injunctive relief, restitution, and/or disgorgement.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/frequently-asked-questions/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No specific headcount, budget, or staffing figures for DPDPA enforcement within the Delaware DOJ Consumer Protection Unit were located in reviewed sources.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Because the DPDPA lacks a private right of action, consumer complaints are channeled to the Attorney General's office (privacy@delaware.gov) rather than through consumer-initiated class actions.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/frequently-asked-questions/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The DPDPA does not include a private cause of action; private citizens are not entitled to file lawsuits or enforce legal rights directly under the Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "State of Delaware",
     "source_url": "https://attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/frequently-asked-questions/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "House Bill No. 380, introduced to the Delaware House on April 16, 2026, would amend the DPDPA by lowering the applicability threshold to 10,000 consumers (or 5,000 with significant data-sale revenue), expand access and profiling opt-out rights, and take effect January 1, 2027; the bill was reported to have passed the Legislature by June 2026, but gubernatorial signature was not confirmed as of this run.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/delaware-bill-amending-dpdpa-introduced-house",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  }
 ]
}