🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-DE · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 12 sources retrieved model claude-sonnet-5 ·

United States – Delaware

US-DE schema gdpri-v2 trajectory: not recordedhybrid regimeoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 35 claims · 12 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
35Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core instrument is fully in force with a clear, functioning regulator and well-documented material/territorial scope; amber-adjacent risk only from the unconfirmed pending amendment tracked separately in enforcement_and_redress.

Primary frameworkDelaware Personal Data Privacy Act (DPDPA), 6 Del. C. § 12D-101 et seq.
Traffic-light rationale — GreenCore instrument is fully in force with a clear, functioning regulator and well-documented material/territorial scope; amber-adjacent risk only from the unconfirmed pending amendment tracked separately in enforcement_and_redress.

Sub-modules (5)

Regulator And AuthorityGreen

Enforcement authority sits with the Delaware DOJ/Attorney General's Consumer Protection Unit; there is no dedicated privacy regulator or rulemaking agency.

Claims (1):

  • The Delaware Personal Data Privacy Act (DPDPA) took effect on January 1, 2025, and is enforced by the Delaware Department of Justice.

Act And InstrumentsGreen

The DPDPA is the sole omnibus instrument; a separate long-standing Delaware breach-notification statute (6 Del. C. §12B) operates alongside it.

Claims (1):

  • The Delaware Personal Data Privacy Act (DPDPA) took effect on January 1, 2025, and is enforced by the Delaware Department of Justice.

Material ScopeGreen

Material scope is defined by consumer-count/revenue thresholds and a broad personal-data definition, with sectoral exemptions.

Claims (2):

  • The DPDPA applies to persons conducting business in or targeting Delaware residents that, in the preceding calendar year, controlled or processed the personal data of 35,000 or more consumers, or 10,000 or more consumers while deriving more than 20% of gross revenue from selling personal data.
  • The DPDPA does not apply to personal data maintained in compliance with the Gramm-Leach-Bliley Act, HIPAA, or the Fair Credit Reporting Act, nor to certain data processed for specified exempt purposes.

Territorial ScopeGreen

The Act reaches any entity, regardless of domicile, that targets Delaware residents or conducts business in the state and meets the threshold; the AG has indicated it will pursue out-of-state controllers meeting the threshold.

Claims (1):

  • The Attorney General has stated it will not hesitate to pursue enforcement against out-of-state third parties doing business in Delaware if they meet the DPDPA's applicability threshold.

Regulator Registration And FilingAmber

No controller registration/filing regime with the Attorney General was identified; compliance is self-assessed against statutory thresholds.

Claims (1):

  • No controller registration or filing obligation with the Delaware Attorney General was located within the DPDPA or AG guidance; compliance appears self-assessed.
Category narrative103 words

Delaware's comprehensive consumer-privacy regime is the Delaware Personal Data Privacy Act (DPDPA), 6 Del. C. § 12D-101 et seq., signed September 11, 2023 and in force since January 1, 2025, enforced exclusively by the Delaware Department of Justice / Attorney General (no dedicated privacy agency). It applies to entities conducting business in or targeting Delaware residents that meet a 35,000-consumer (or 10,000-consumer plus 20%-revenue-from-sale) processing threshold, with express carve-outs for data governed by GLBA, HIPAA and FCRA. A pending amendment (HB 380, introduced April 2026) would lower thresholds and expand obligations effective January 2027; its enactment status is unconfirmed as of this run.

Sources and claims (5)
  1. ConfirmedState of DelawareThe Delaware Personal Data Privacy Act (DPDPA) took effect on January 1, 2025, and is enforced by the Delaware Department of Justice.observed
  2. ConfirmedDataGuidanceThe DPDPA applies to persons conducting business in or targeting Delaware residents that, in the preceding calendar year, controlled or processed the personal data of 35,000 or more consumers, or 10,000 or more consumers while deriving more than 20% of gross revenue from selling personal data.observed
  3. ConfirmedState of DelawareThe DPDPA does not apply to personal data maintained in compliance with the Gramm-Leach-Bliley Act, HIPAA, or the Fair Credit Reporting Act, nor to certain data processed for specified exempt purposes.observed
  4. ConfirmedState of DelawareThe Attorney General has stated it will not hesitate to pursue enforcement against out-of-state third parties doing business in Delaware if they meet the DPDPA's applicability threshold.observed
  5. ProbableState of DelawareNo controller registration or filing obligation with the Delaware Attorney General was located within the DPDPA or AG guidance; compliance appears self-assessed.observed

#

Structurally divergent from GDPR Art. 6 lawful-basis architecture (amber for interoperability), though the consent standard itself is clearly and consistently defined; pseudonymisation/anonymisation safe-harbour detail was not confirmed.

Primary frameworkDelaware Personal Data Privacy Act (DPDPA)
Traffic-light rationale — AmberStructurally divergent from GDPR Art. 6 lawful-basis architecture (amber for interoperability), though the consent standard itself is clearly and consistently defined; pseudonymisation/anonymisation safe-harbour detail was not confirmed.

Sub-modules (4)

Lawful BasesAmber

No enumerated Art. 6-style lawful bases; a notice/purpose-limitation-and-opt-out model governs ordinary processing.

Claims (1):

  • Rather than enumerating GDPR-style lawful bases, the DPDPA relies on a notice-and-purpose-limitation model, requiring affirmative consumer consent only for sensitive-data processing, secondary-purpose processing, and processing following a consumer opt-out.

Special CategoriesGreen

Sensitive data (health, biometric, genetic, ethnicity, religion, sexual orientation, immigration status, children's data) requires prior consumer consent.

Claims (1):

  • Sensitive data under the DPDPA includes data revealing racial/ethnic origin, religious beliefs, health diagnoses, sexual orientation/activity, citizenship/immigration status, and genetic or biometric data used to uniquely identify an individual, requiring consumer consent prior to collection or processing.

Pseudonymisation And AnonymisationRed

Detailed pseudonymisation/anonymisation safe-harbour criteria were not confirmed in the reviewed AG guidance.

Category narrative60 words

The DPDPA does not use a GDPR-style enumerated lawful-basis regime (Art. 6 analogue); instead it operates a notice-and-opt-out model built on purpose limitation and data minimization, layering an affirmative-consent requirement onto sensitive-data processing, secondary-purpose processing, and post-opt-out processing. Sensitive data is broadly defined (race/ethnicity, religion, health, sexual orientation/activity, immigration status, genetic/biometric identifiers, and children's data) and requires consent before collection.

Sources and claims (3)
  1. ConfirmedState of DelawareRather than enumerating GDPR-style lawful bases, the DPDPA relies on a notice-and-purpose-limitation model, requiring affirmative consumer consent only for sensitive-data processing, secondary-purpose processing, and processing following a consumer opt-out.observed
  2. ConfirmedState of DelawareUnder the DPDPA, consent must be affirmative, freely given, specific, informed, and unambiguous; acceptance of broad terms of service, passive interaction with content, or agreement obtained through deceptive webpage design is not valid consent.observed
  3. ConfirmedState of DelawareSensitive data under the DPDPA includes data revealing racial/ethnic origin, religious beliefs, health diagnoses, sexual orientation/activity, citizenship/immigration status, and genetic or biometric data used to uniquely identify an individual, requiring consumer consent prior to collection or processing.observed

#

Rights and response windows are clearly documented and in force.

Primary frameworkDelaware Personal Data Privacy Act (DPDPA)
Traffic-light rationale — GreenRights and response windows are clearly documented and in force.

Sub-modules (5)

Access RightGreen

Consumers may access their personal data free of charge once every 12 months; additional requests may incur an administrative fee.

Claims (1):

  • Delaware consumers may request access to personal data a controller has collected about them free of charge once every 12 months; controllers may charge an administrative fee for additional requests.

Rectification And ErasureGreen

Consumers may correct inaccuracies and delete personal data, including data obtained by controllers from third parties.

Claims (1):

  • Consumers have the right to correct inaccuracies in and delete their personal data, including data a controller collected through third parties.

Restriction And ObjectionGreen

Consumers may opt out of the sale of personal data to third parties and may designate an authorized agent to do so on their behalf.

Claims (1):

  • Consumers may opt out of the sale of personal data to third parties and may designate a third party to exercise the opt-out on their behalf.

Data PortabilityGreen

Portability is included among the enumerated consumer rights alongside access, correction, erasure and opt-out.

Claims (1):

  • Consumer rights under the DPDPA include information access, data rectification, erasure, portability, and opt-out options for targeted advertising and automated profiling.

Deadlines And Response WindowsGreen

Controllers have 45 days to respond to a consumer's appeal of a denied rights request.

Claims (1):

  • A controller has 45 days after receipt of a consumer's appeal of a denied rights request to respond in writing, explaining the actions taken and reasons for refusal.
Category narrative36 words

The DPDPA grants Delaware consumers access, correction, deletion, portability, and opt-out (sale/targeted-advertising/profiling) rights, with a free access request permitted once every 12 months and a 45-day window for controllers to respond to appeals of denied requests.

Sources and claims (5)
  1. ConfirmedState of DelawareDelaware consumers may request access to personal data a controller has collected about them free of charge once every 12 months; controllers may charge an administrative fee for additional requests.observed
  2. ConfirmedState of DelawareConsumers have the right to correct inaccuracies in and delete their personal data, including data a controller collected through third parties.observed
  3. ConfirmedState of DelawareConsumers may opt out of the sale of personal data to third parties and may designate a third party to exercise the opt-out on their behalf.observed
  4. ConfirmedDataGuidanceConsumer rights under the DPDPA include information access, data rectification, erasure, portability, and opt-out options for targeted advertising and automated profiling.observed
  5. ConfirmedState of DelawareA controller has 45 days after receipt of a consumer's appeal of a denied rights request to respond in writing, explaining the actions taken and reasons for refusal.observed

#

Core security/DPIA/breach duties are well documented and in force; DPO and ROPA specifics are gaps.

Primary frameworkDelaware Personal Data Privacy Act (DPDPA); Delaware data breach notification statute, 6 Del. C. §12B
Traffic-light rationale — AmberCore security/DPIA/breach duties are well documented and in force; DPO and ROPA specifics are gaps.

Sub-modules (7)

Accountability And DpiaGreen

DPIAs are required for high-risk processing activities.

Claims (1):

  • Controllers must conduct data protection impact assessments (DPIAs) for high-risk processing activities under the DPDPA.

Dpo RequirementsRed

No DPO-appointment threshold analogous to GDPR Art. 37 was identified.

Claims (1):

  • No dedicated Data Protection Officer appointment threshold analogous to GDPR Art. 37-39 was identified in the DPDPA or AG guidance.

Ropa RequirementsAmber

Controllers/processors document processing relationships contractually; a formal public ROPA filing requirement was not confirmed.

Claims (1):

  • Businesses are directed to inventory personal data collected, identify storage locations, and document access and third-party processor relationships, though no formal public Records-of-Processing-Activities filing requirement was confirmed.

Joint Controller ArrangementsAmber

The Act distinguishes controller/processor roles by decision-making authority; a processor exercising independent decision-making becomes a controller for that processing.

Security MeasuresGreen

Controllers must employ reasonable data security measures proportionate to the sensitivity of the personal data collected.

Claims (1):

  • The DPDPA requires businesses to employ reasonable data security measures proportionate to the nature and sensitivity of the personal data collected, to prevent unauthorized access.

Breach NotificationGreen

Delaware's separate 2018 breach-notification statute requires notice to affected residents and, above 500 residents, to the Attorney General.

Claims (1):

  • Delaware's data breach notification statute, in effect since April 14, 2018, requires notice to affected Delaware residents and, where a breach affects 500 or more residents, additional notice to the Delaware Attorney General.

Retention And DisposalAmber

No DPDPA-specific retention-period or disposal-duty detail beyond general data-minimization principles was confirmed.

Category narrative41 words

Controllers must apply data minimization, security, and DPIA obligations for high-risk processing. A long-standing separate breach-notification statute (since 2018) requires consumer notice and, above a 500-resident threshold, Attorney General notice. No DPO-appointment threshold or standalone public ROPA filing requirement was confirmed.

Sources and claims (5)
  1. ConfirmedDataGuidanceControllers must conduct data protection impact assessments (DPIAs) for high-risk processing activities under the DPDPA.observed
  2. ProbableState of DelawareNo dedicated Data Protection Officer appointment threshold analogous to GDPR Art. 37-39 was identified in the DPDPA or AG guidance.observed
  3. ProbableState of DelawareBusinesses are directed to inventory personal data collected, identify storage locations, and document access and third-party processor relationships, though no formal public Records-of-Processing-Activities filing requirement was confirmed.observed
  4. ConfirmedState of DelawareThe DPDPA requires businesses to employ reasonable data security measures proportionate to the nature and sensitivity of the personal data collected, to prevent unauthorized access.observed
  5. ConfirmedState of DelawareDelaware's data breach notification statute, in effect since April 14, 2018, requires notice to affected Delaware residents and, where a breach affects 500 or more residents, additional notice to the Delaware Attorney General.observed

#

No comprehensive transfer-mechanism regime exists in this state statute; explicit gap consistent with the sectoral/hybrid US pattern.

Traffic-light rationale — RedNo comprehensive transfer-mechanism regime exists in this state statute; explicit gap consistent with the sectoral/hybrid US pattern.

Sub-modules (6)

Transfer MechanismsRed

No dedicated transfer-mechanism provisions were located; general contractual/security duties apply irrespective of data destination.

Claims (1):

  • The DPDPA does not contain an adequacy-decision framework, Standard Contractual Clauses regime, Binding Corporate Rules mechanism, or data-localisation mandate; cross-border transfer is governed only indirectly through the Act's general controller/processor contractual and security obligations.

Adequacy ReceivedRed

Not applicable; US states do not receive adequacy decisions under this framework.

Adequacy GrantedRed

No adequacy-granting mechanism exists under the DPDPA.

Sccs And BcrsRed

No SCC or BCR regime identified under the DPDPA.

Transfer Impact AssessmentRed

No transfer-impact-assessment requirement identified.

Data LocalisationRed

No data-localisation mandate identified under the DPDPA.

Category narrative53 words

The DPDPA, consistent with the general US state-omnibus-privacy pattern, does not contain a GDPR-style cross-border transfer regime. No adequacy-decision mechanism, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate was identified in the Act or AG guidance; cross-border transfer is regulated only indirectly via the Act's general contractual and security obligations on controllers and processors.

Sources and claims (1)
  1. ProbableState of DelawareThe DPDPA does not contain an adequacy-decision framework, Standard Contractual Clauses regime, Binding Corporate Rules mechanism, or data-localisation mandate; cross-border transfer is governed only indirectly through the Act's general controller/processor contractual and security obligations.observed

#

Financial and health carve-outs are clearly documented; several sub-modules (telecoms, credit-scoring, education, insurance) have no DE-specific overlay evidence.

Primary frameworkDelaware Personal Data Privacy Act (DPDPA); federal GLBA/HIPAA/FCRA (deferred-to)
Traffic-light rationale — AmberFinancial and health carve-outs are clearly documented; several sub-modules (telecoms, credit-scoring, education, insurance) have no DE-specific overlay evidence.

Sub-modules (7)

Financial Sector OverlayAmber

Data maintained in compliance with GLBA is exempt from the DPDPA.

Claims (1):

  • The DPDPA does not apply to personal data maintained in compliance with the Gramm-Leach-Bliley Act, HIPAA, or the Fair Credit Reporting Act, as well as personal data processed for certain specified purposes.

Health Sector OverlayAmber

Data maintained in compliance with HIPAA is exempt from the DPDPA.

Claims (1):

  • The DPDPA does not apply to personal data maintained in compliance with the Gramm-Leach-Bliley Act, HIPAA, or the Fair Credit Reporting Act, as well as personal data processed for certain specified purposes.

Telecoms And EprivacyRed

No Delaware-specific telecoms/ePrivacy overlay was identified.

Employment DataAmber

The DPDPA excludes personal data processed in an employment context (e.g., job applications) from its consumer protections.

Claims (1):

  • The DPDPA applies to Delawareans acting in an individual or household context and does not protect an individual acting in an employment context, such as applying for a job.

Credit And ScoringAmber

The Fair Credit Reporting Act exemption covers certain credit-related data; no DE-specific credit-scoring overlay beyond this was identified.

Claims (1):

  • The DPDPA does not apply to personal data maintained in compliance with the Gramm-Leach-Bliley Act, HIPAA, or the Fair Credit Reporting Act, as well as personal data processed for certain specified purposes.

EducationRed

No Delaware-specific education-sector data overlay was identified.

InsuranceRed

No Delaware-specific insurance-sector data overlay was identified.

Category narrative44 words

The DPDPA exempts data governed by GLBA, HIPAA and FCRA and excludes employment-context personal data (e.g., job applicants) from its consumer-rights framework, deferring to those federal sectoral regimes. No Delaware-specific overlays for telecoms/ePrivacy, credit-scoring, education, or insurance were identified beyond these general federal deferrals.

Sources and claims (2)
  1. ConfirmedState of DelawareThe DPDPA does not apply to personal data maintained in compliance with the Gramm-Leach-Bliley Act, HIPAA, or the Fair Credit Reporting Act, as well as personal data processed for certain specified purposes.observed
  2. ConfirmedState of DelawareThe DPDPA applies to Delawareans acting in an individual or household context and does not protect an individual acting in an employment context, such as applying for a job.observed

#

Opt-out signal and dark-pattern provisions are confirmed and in force; clean-room and direct-marketing-specific rules are gaps.

Primary frameworkDelaware Personal Data Privacy Act (DPDPA)
Traffic-light rationale — AmberOpt-out signal and dark-pattern provisions are confirmed and in force; clean-room and direct-marketing-specific rules are gaps.

Sub-modules (6)

Cookies And TrackersAmber

No dedicated cookie-consent statute distinct from the general personal-data consent framework was identified.

Dark PatternsGreen

Consent obtained through deceptive webpage design is expressly excluded as valid consent.

Claims (1):

  • Acceptance of broad terms of service, hovering over or pausing on content, and agreement obtained through deceptive webpage design ('dark patterns') are not considered valid consent under the DPDPA.

Opt Out SignalsGreen

Universal opt-out mechanisms must be honored by controllers as valid consumer opt-out requests as of January 1, 2026.

Claims (1):

  • Beginning January 1, 2026, controllers must recognize universal opt-out mechanisms as valid consumer requests to opt out of personal-data processing across multiple websites at once.

Clean Rooms And DcrRed

No clean-room or data-collaboration-room rules were identified under the DPDPA.

Cross Context AdvertisingGreen

Consumers may opt out of processing for targeted advertising and automated profiling.

Claims (1):

  • Consumer rights under the DPDPA include opt-out options for targeted advertising and automated profiling.

Direct MarketingAmber

No DE-specific direct-marketing consent/suppression regime distinct from the general sale/targeted-advertising opt-out was identified.

Category narrative55 words

Consumers may opt out of the sale of personal data and processing for targeted advertising and profiling. Universal opt-out mechanisms (GPC-style signals) became mandatory for controllers to recognize as of January 1, 2026. Dark-pattern-induced consent is expressly invalid. No dedicated cookie statute, clean-room/data-collaboration rules, or direct-marketing-specific suppression regime beyond the general opt-out right was identified.

Sources and claims (3)
  1. ConfirmedState of DelawareAcceptance of broad terms of service, hovering over or pausing on content, and agreement obtained through deceptive webpage design ('dark patterns') are not considered valid consent under the DPDPA.observed
  2. ConfirmedState of DelawareBeginning January 1, 2026, controllers must recognize universal opt-out mechanisms as valid consumer requests to opt out of personal-data processing across multiple websites at once.observed
  3. ConfirmedDataGuidanceConsumer rights under the DPDPA include opt-out options for targeted advertising and automated profiling.observed

#

Biometric/genetic and minor-profiling protections are confirmed; AI-specific risk assessment and surveillance-carveout detail are gaps.

Primary frameworkDelaware Personal Data Privacy Act (DPDPA)
Traffic-light rationale — AmberBiometric/genetic and minor-profiling protections are confirmed; AI-specific risk assessment and surveillance-carveout detail are gaps.

Sub-modules (6)

Profiling RestrictionsGreen

Consumers may opt out of processing for automated profiling; minors under 18 require opt-in consent for related targeted-advertising/sale processing.

Claims (1):

  • The DPDPA requires controllers to obtain opt-in consent before selling a consumer's personal data or processing personal data for targeted advertising when the consumer is under 18 years old.

Automated Decision Making TransparencyAmber

No explicit ADM-explanation right distinct from the general profiling opt-out was confirmed.

Ai Risk AssessmentsRed

No AI-specific risk-assessment regime (EU AI Act analogue) was identified; DPIA obligations cover high-risk processing generally.

Claims (1):

  • No AI-system-specific risk-assessment regime akin to the EU AI Act or state AI-transparency statutes was identified within the DPDPA; its DPIA obligations address 'high-risk processing' generally rather than AI systems specifically.

Biometric RegimeGreen

Biometric data used to uniquely identify an individual is classified as sensitive data requiring consent.

Claims (1):

  • Genetic and biometric data used to uniquely identify an individual are classified as sensitive data under the DPDPA, requiring consumer consent prior to collection or processing.

Genetic DataGreen

Genetic data used to uniquely identify an individual is classified as sensitive data requiring consent.

Claims (1):

  • Genetic and biometric data used to uniquely identify an individual are classified as sensitive data under the DPDPA, requiring consumer consent prior to collection or processing.

State Surveillance CarveoutsAmber

The Act permits denial of consumer-rights requests where necessary to comply with federal, state, or local law, functioning as a general legal-compliance carve-out rather than a dedicated national-security exemption.

Claims (1):

  • A controller may deny a consumer's rights request where fulfilling it would restrict the controller's ability to comply with federal, state, or local law.
Category narrative52 words

Biometric and genetic data used to uniquely identify an individual are classified as sensitive data requiring consent. Minors under 18 receive opt-in-consent protection against profiling-adjacent targeted advertising and data sale. No AI-specific risk-assessment regime distinct from general high-risk-processing DPIAs, and no dedicated state-surveillance carve-out beyond the Act's general legal-compliance exception, were identified.

Sources and claims (4)
  1. ConfirmedState of DelawareThe DPDPA requires controllers to obtain opt-in consent before selling a consumer's personal data or processing personal data for targeted advertising when the consumer is under 18 years old.observed
  2. ProbableDataGuidanceNo AI-system-specific risk-assessment regime akin to the EU AI Act or state AI-transparency statutes was identified within the DPDPA; its DPIA obligations address 'high-risk processing' generally rather than AI systems specifically.observed
  3. ConfirmedState of DelawareGenetic and biometric data used to uniquely identify an individual are classified as sensitive data under the DPDPA, requiring consumer consent prior to collection or processing.observed
  4. ConfirmedState of DelawareA controller may deny a consumer's rights request where fulfilling it would restrict the controller's ability to comply with federal, state, or local law.observed

#

Minor-specific protections are clearly documented and in force; education-settings and dependent-adults sub-modules are explicit gaps.

Primary frameworkDelaware Personal Data Privacy Act (DPDPA); federal COPPA (referenced)
Traffic-light rationale — GreenMinor-specific protections are clearly documented and in force; education-settings and dependent-adults sub-modules are explicit gaps.

Sub-modules (5)

Age VerificationAmber

No standalone age-verification mandate distinct from the under-18 opt-in-consent trigger was identified.

Minor Profiling BansGreen

Opt-in consent is required before selling or using a under-18 consumer's data for targeted advertising, restricting default profiling-adjacent uses.

Claims (1):

  • In addition to protections afforded adults, Delaware law provides additional protections for children and teens under 18, including a requirement of opt-in consent before selling their personal data or using it for targeted advertising.

Education SettingsRed

No Delaware-specific education-sector/student-data provisions were identified within the DPDPA.

Dependent AdultsRed

No Delaware-specific dependent-adult (elderly/incapacitated) protections were identified within the DPDPA.

Category narrative35 words

Delaware provides children and teens under 18 additional protections beyond adults, including opt-in consent for sale/targeted-advertising processing and parental/guardian exercise of consumer rights, alongside COPPA-referenced parental-consent duties. No DE-specific education-setting or dependent-adult provisions were identified.

Sources and claims (2)
  1. ConfirmedState of DelawareWhere a child's personal data is processed, the child's parent or legal guardian may exercise the DPDPA's consumer rights on the child's behalf, and controllers must follow COPPA parental-consent requirements.observed
  2. ConfirmedState of DelawareIn addition to protections afforded adults, Delaware law provides additional protections for children and teens under 18, including a requirement of opt-in consent before selling their personal data or using it for targeted advertising.observed

#

Enforcement powers and penalties are clear and in force; the pending HB 380 amendment's enactment status is an unresolved material development within the 180-day window, and regulator funding/capacity data is a gap.

Primary frameworkDelaware Personal Data Privacy Act (DPDPA)
Traffic-light rationale — AmberEnforcement powers and penalties are clear and in force; the pending HB 380 amendment's enactment status is an unresolved material development within the 180-day window, and regulator funding/capacity data is a gap.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

Civil penalties up to $10,000 per violation, plus injunctive relief, restitution, and disgorgement, are available to the Attorney General.

Claims (1):

  • Entities or individuals that violate the DPDPA may face civil penalties up to $10,000 per violation, and the Attorney General can additionally seek injunctive relief, restitution, and/or disgorgement.

Enforcement Activity IndexAmber

No specific published enforcement actions/fines under the DPDPA were located as of this run; enforcement began January 1, 2025.

Regulator Funding And CapacityRed

No specific headcount or budget figures for DPDPA enforcement within the Consumer Protection Unit were located.

Claims (1):

  • No specific headcount, budget, or staffing figures for DPDPA enforcement within the Delaware DOJ Consumer Protection Unit were located in reviewed sources.

Collective Redress And Class ActionsAmber

Absent a private right of action, collective redress is limited to Attorney General complaint channels rather than consumer-initiated class actions.

Claims (1):

  • Because the DPDPA lacks a private right of action, consumer complaints are channeled to the Attorney General's office ([email protected]) rather than through consumer-initiated class actions.

Private Right Of ActionAmber

The DPDPA does not include a private cause of action; private citizens cannot sue directly under the Act.

Claims (1):

  • The DPDPA does not include a private cause of action; private citizens are not entitled to file lawsuits or enforce legal rights directly under the Act.

Recent Developments 180DAmber

HB 380, introduced April 16, 2026, would amend the DPDPA (lower thresholds, expanded rights, January 1, 2027 effective date) and was reported to have passed the Legislature by June 2026; gubernatorial signature is unconfirmed.

Claims (1):

  • House Bill No. 380, introduced to the Delaware House on April 16, 2026, would amend the DPDPA by lowering the applicability threshold to 10,000 consumers (or 5,000 with significant data-sale revenue), expand access and profiling opt-out rights, and take effect January 1, 2027; the bill was reported to have passed the Legislature by June 2026, but gubernatorial signature was not confirmed as of this run.
Category narrative90 words

The Attorney General may seek civil penalties up to $10,000 per violation plus injunctive relief, restitution and/or disgorgement. A mandatory 60-day right-to-cure period applied through December 31, 2025, after which cure is discretionary. The DPDPA carries no private right of action, so redress runs solely through AG complaint channels rather than class actions. A pending amendment, HB 380 (introduced April 16, 2026; reported passed by the Legislature by June 2026), would lower thresholds and expand rights effective January 1, 2027, but gubernatorial signature was not confirmed as of this run.

Sources and claims (5)
  1. ConfirmedState of DelawareEntities or individuals that violate the DPDPA may face civil penalties up to $10,000 per violation, and the Attorney General can additionally seek injunctive relief, restitution, and/or disgorgement.observed
  2. UncertainState of DelawareNo specific headcount, budget, or staffing figures for DPDPA enforcement within the Delaware DOJ Consumer Protection Unit were located in reviewed sources.observed
  3. ProbableState of DelawareBecause the DPDPA lacks a private right of action, consumer complaints are channeled to the Attorney General's office ([email protected]) rather than through consumer-initiated class actions.observed
  4. ConfirmedState of DelawareThe DPDPA does not include a private cause of action; private citizens are not entitled to file lawsuits or enforce legal rights directly under the Act.observed
  5. ProbableDataGuidanceHouse Bill No. 380, introduced to the Delaware House on April 16, 2026, would amend the DPDPA by lowering the applicability threshold to 10,000 consumers (or 5,000 with significant data-sale revenue), expand access and profiling opt-out rights, and take effect January 1, 2027; the bill was reported to have passed the Legislature by June 2026, but gubernatorial signature was not confirmed as of this run.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Delaware
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 35 claim(s), 12 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated with T1 (Delaware AG portal/FAQ/letter/breach-notification pages) as primary anchors, supplemented by T3 secondary legal-guidance sources (DataGuidance, IAPP) for legislative-history and cross-state comparison context. Strong T1 coverage: regulator_and_framework, data_subject_rights, controller_processor_duties (security/breach), adtech_and_commercial_privacy, children_and_vulnerable_groups, enforcement_and_redress (penalties/cure/private-right-of-action). Weaker/gap coverage relying on T3 or absent_field_provenance: cross_border_and_adequacy (no regime exists — explicit gap), controller_processor_duties.dpo_requirements/ropa_requirements, algorithmic_biometric_and_surveillance_governance.ai_risk_assessments, sectoral_watch.telecoms/education/insurance, enforcement_and_redress.regulator_funding_and_capacity.

Unresolved questions (5):

  • Has Delaware HB 380 (DPDPA amendment) been signed into law by the Governor, and if so on what date, given DataGuidance reports it passed the Legislature by June 2026?
  • Does the DPDPA or implementing guidance specify any DPO-appointment threshold or independence requirement not surfaced in AG FAQ/business pages?
  • Is there a formal, filed Records-of-Processing-Activities (ROPA) obligation, or only an internal-inventory expectation?
  • Are there any published DPDPA enforcement actions or settlements since the January 1, 2025 effective date?
  • Does Delaware have any state-specific AI-transparency or biometric-privacy statute layered on top of the DPDPA sensitive-data provisions?

Escalate to primary-source review: yes