Core instrument is fully in force with a clear, functioning regulator and well-documented material/territorial scope; amber-adjacent risk only from the unconfirmed pending amendment tracked separately in enforcement_and_redress.
Primary frameworkDelaware Personal Data Privacy Act (DPDPA), 6 Del. C. § 12D-101 et seq.
Traffic-light rationale — GreenCore instrument is fully in force with a clear, functioning regulator and well-documented material/territorial scope; amber-adjacent risk only from the unconfirmed pending amendment tracked separately in enforcement_and_redress.
Sub-modules (5)
Regulator And AuthorityGreen
Enforcement authority sits with the Delaware DOJ/Attorney General's Consumer Protection Unit; there is no dedicated privacy regulator or rulemaking agency.
Claims (1):
The Delaware Personal Data Privacy Act (DPDPA) took effect on January 1, 2025, and is enforced by the Delaware Department of Justice.
Act And InstrumentsGreen
The DPDPA is the sole omnibus instrument; a separate long-standing Delaware breach-notification statute (6 Del. C. §12B) operates alongside it.
Claims (1):
The Delaware Personal Data Privacy Act (DPDPA) took effect on January 1, 2025, and is enforced by the Delaware Department of Justice.
Material ScopeGreen
Material scope is defined by consumer-count/revenue thresholds and a broad personal-data definition, with sectoral exemptions.
Claims (2):
The DPDPA applies to persons conducting business in or targeting Delaware residents that, in the preceding calendar year, controlled or processed the personal data of 35,000 or more consumers, or 10,000 or more consumers while deriving more than 20% of gross revenue from selling personal data.
The DPDPA does not apply to personal data maintained in compliance with the Gramm-Leach-Bliley Act, HIPAA, or the Fair Credit Reporting Act, nor to certain data processed for specified exempt purposes.
Territorial ScopeGreen
The Act reaches any entity, regardless of domicile, that targets Delaware residents or conducts business in the state and meets the threshold; the AG has indicated it will pursue out-of-state controllers meeting the threshold.
Claims (1):
The Attorney General has stated it will not hesitate to pursue enforcement against out-of-state third parties doing business in Delaware if they meet the DPDPA's applicability threshold.
Regulator Registration And FilingAmber
No controller registration/filing regime with the Attorney General was identified; compliance is self-assessed against statutory thresholds.
Claims (1):
No controller registration or filing obligation with the Delaware Attorney General was located within the DPDPA or AG guidance; compliance appears self-assessed.
Category narrative103 words
Delaware's comprehensive consumer-privacy regime is the Delaware Personal Data Privacy Act (DPDPA), 6 Del. C. § 12D-101 et seq., signed September 11, 2023 and in force since January 1, 2025, enforced exclusively by the Delaware Department of Justice / Attorney General (no dedicated privacy agency). It applies to entities conducting business in or targeting Delaware residents that meet a 35,000-consumer (or 10,000-consumer plus 20%-revenue-from-sale) processing threshold, with express carve-outs for data governed by GLBA, HIPAA and FCRA. A pending amendment (HB 380, introduced April 2026) would lower thresholds and expand obligations effective January 2027; its enactment status is unconfirmed as of this run.
Sources and claims (5)
ConfirmedState of Delaware — The Delaware Personal Data Privacy Act (DPDPA) took effect on January 1, 2025, and is enforced by the Delaware Department of Justice.observed
ConfirmedDataGuidance — The DPDPA applies to persons conducting business in or targeting Delaware residents that, in the preceding calendar year, controlled or processed the personal data of 35,000 or more consumers, or 10,000 or more consumers while deriving more than 20% of gross revenue from selling personal data.observed
ConfirmedState of Delaware — The DPDPA does not apply to personal data maintained in compliance with the Gramm-Leach-Bliley Act, HIPAA, or the Fair Credit Reporting Act, nor to certain data processed for specified exempt purposes.observed
ConfirmedState of Delaware — The Attorney General has stated it will not hesitate to pursue enforcement against out-of-state third parties doing business in Delaware if they meet the DPDPA's applicability threshold.observed
ProbableState of Delaware — No controller registration or filing obligation with the Delaware Attorney General was located within the DPDPA or AG guidance; compliance appears self-assessed.observed
Structurally divergent from GDPR Art. 6 lawful-basis architecture (amber for interoperability), though the consent standard itself is clearly and consistently defined; pseudonymisation/anonymisation safe-harbour detail was not confirmed.
Primary frameworkDelaware Personal Data Privacy Act (DPDPA)
Traffic-light rationale — AmberStructurally divergent from GDPR Art. 6 lawful-basis architecture (amber for interoperability), though the consent standard itself is clearly and consistently defined; pseudonymisation/anonymisation safe-harbour detail was not confirmed.
Sub-modules (4)
Lawful BasesAmber
No enumerated Art. 6-style lawful bases; a notice/purpose-limitation-and-opt-out model governs ordinary processing.
Claims (1):
Rather than enumerating GDPR-style lawful bases, the DPDPA relies on a notice-and-purpose-limitation model, requiring affirmative consumer consent only for sensitive-data processing, secondary-purpose processing, and processing following a consumer opt-out.
Consent ThresholdsGreen
Consent must be affirmative, freely given, specific, informed and unambiguous; broad ToS acceptance and dark-pattern-induced agreement are expressly invalid.
Claims (1):
Under the DPDPA, consent must be affirmative, freely given, specific, informed, and unambiguous; acceptance of broad terms of service, passive interaction with content, or agreement obtained through deceptive webpage design is not valid consent.
Special CategoriesGreen
Sensitive data (health, biometric, genetic, ethnicity, religion, sexual orientation, immigration status, children's data) requires prior consumer consent.
Claims (1):
Sensitive data under the DPDPA includes data revealing racial/ethnic origin, religious beliefs, health diagnoses, sexual orientation/activity, citizenship/immigration status, and genetic or biometric data used to uniquely identify an individual, requiring consumer consent prior to collection or processing.
Pseudonymisation And AnonymisationRed
Detailed pseudonymisation/anonymisation safe-harbour criteria were not confirmed in the reviewed AG guidance.
Category narrative60 words
The DPDPA does not use a GDPR-style enumerated lawful-basis regime (Art. 6 analogue); instead it operates a notice-and-opt-out model built on purpose limitation and data minimization, layering an affirmative-consent requirement onto sensitive-data processing, secondary-purpose processing, and post-opt-out processing. Sensitive data is broadly defined (race/ethnicity, religion, health, sexual orientation/activity, immigration status, genetic/biometric identifiers, and children's data) and requires consent before collection.
Sources and claims (3)
ConfirmedState of Delaware — Rather than enumerating GDPR-style lawful bases, the DPDPA relies on a notice-and-purpose-limitation model, requiring affirmative consumer consent only for sensitive-data processing, secondary-purpose processing, and processing following a consumer opt-out.observed
ConfirmedState of Delaware — Under the DPDPA, consent must be affirmative, freely given, specific, informed, and unambiguous; acceptance of broad terms of service, passive interaction with content, or agreement obtained through deceptive webpage design is not valid consent.observed
ConfirmedState of Delaware — Sensitive data under the DPDPA includes data revealing racial/ethnic origin, religious beliefs, health diagnoses, sexual orientation/activity, citizenship/immigration status, and genetic or biometric data used to uniquely identify an individual, requiring consumer consent prior to collection or processing.observed
Traffic-light rationale — GreenRights and response windows are clearly documented and in force.
Sub-modules (5)
Access RightGreen
Consumers may access their personal data free of charge once every 12 months; additional requests may incur an administrative fee.
Claims (1):
Delaware consumers may request access to personal data a controller has collected about them free of charge once every 12 months; controllers may charge an administrative fee for additional requests.
Rectification And ErasureGreen
Consumers may correct inaccuracies and delete personal data, including data obtained by controllers from third parties.
Claims (1):
Consumers have the right to correct inaccuracies in and delete their personal data, including data a controller collected through third parties.
Restriction And ObjectionGreen
Consumers may opt out of the sale of personal data to third parties and may designate an authorized agent to do so on their behalf.
Claims (1):
Consumers may opt out of the sale of personal data to third parties and may designate a third party to exercise the opt-out on their behalf.
Data PortabilityGreen
Portability is included among the enumerated consumer rights alongside access, correction, erasure and opt-out.
Claims (1):
Consumer rights under the DPDPA include information access, data rectification, erasure, portability, and opt-out options for targeted advertising and automated profiling.
Deadlines And Response WindowsGreen
Controllers have 45 days to respond to a consumer's appeal of a denied rights request.
Claims (1):
A controller has 45 days after receipt of a consumer's appeal of a denied rights request to respond in writing, explaining the actions taken and reasons for refusal.
Category narrative36 words
The DPDPA grants Delaware consumers access, correction, deletion, portability, and opt-out (sale/targeted-advertising/profiling) rights, with a free access request permitted once every 12 months and a 45-day window for controllers to respond to appeals of denied requests.
Sources and claims (5)
ConfirmedState of Delaware — Delaware consumers may request access to personal data a controller has collected about them free of charge once every 12 months; controllers may charge an administrative fee for additional requests.observed
ConfirmedState of Delaware — Consumers have the right to correct inaccuracies in and delete their personal data, including data a controller collected through third parties.observed
ConfirmedState of Delaware — Consumers may opt out of the sale of personal data to third parties and may designate a third party to exercise the opt-out on their behalf.observed
ConfirmedDataGuidance — Consumer rights under the DPDPA include information access, data rectification, erasure, portability, and opt-out options for targeted advertising and automated profiling.observed
ConfirmedState of Delaware — A controller has 45 days after receipt of a consumer's appeal of a denied rights request to respond in writing, explaining the actions taken and reasons for refusal.observed
Traffic-light rationale — AmberCore security/DPIA/breach duties are well documented and in force; DPO and ROPA specifics are gaps.
Sub-modules (7)
Accountability And DpiaGreen
DPIAs are required for high-risk processing activities.
Claims (1):
Controllers must conduct data protection impact assessments (DPIAs) for high-risk processing activities under the DPDPA.
Dpo RequirementsRed
No DPO-appointment threshold analogous to GDPR Art. 37 was identified.
Claims (1):
No dedicated Data Protection Officer appointment threshold analogous to GDPR Art. 37-39 was identified in the DPDPA or AG guidance.
Ropa RequirementsAmber
Controllers/processors document processing relationships contractually; a formal public ROPA filing requirement was not confirmed.
Claims (1):
Businesses are directed to inventory personal data collected, identify storage locations, and document access and third-party processor relationships, though no formal public Records-of-Processing-Activities filing requirement was confirmed.
Joint Controller ArrangementsAmber
The Act distinguishes controller/processor roles by decision-making authority; a processor exercising independent decision-making becomes a controller for that processing.
Security MeasuresGreen
Controllers must employ reasonable data security measures proportionate to the sensitivity of the personal data collected.
Claims (1):
The DPDPA requires businesses to employ reasonable data security measures proportionate to the nature and sensitivity of the personal data collected, to prevent unauthorized access.
Breach NotificationGreen
Delaware's separate 2018 breach-notification statute requires notice to affected residents and, above 500 residents, to the Attorney General.
Claims (1):
Delaware's data breach notification statute, in effect since April 14, 2018, requires notice to affected Delaware residents and, where a breach affects 500 or more residents, additional notice to the Delaware Attorney General.
Retention And DisposalAmber
No DPDPA-specific retention-period or disposal-duty detail beyond general data-minimization principles was confirmed.
Category narrative41 words
Controllers must apply data minimization, security, and DPIA obligations for high-risk processing. A long-standing separate breach-notification statute (since 2018) requires consumer notice and, above a 500-resident threshold, Attorney General notice. No DPO-appointment threshold or standalone public ROPA filing requirement was confirmed.
Sources and claims (5)
ConfirmedDataGuidance — Controllers must conduct data protection impact assessments (DPIAs) for high-risk processing activities under the DPDPA.observed
ProbableState of Delaware — No dedicated Data Protection Officer appointment threshold analogous to GDPR Art. 37-39 was identified in the DPDPA or AG guidance.observed
ProbableState of Delaware — Businesses are directed to inventory personal data collected, identify storage locations, and document access and third-party processor relationships, though no formal public Records-of-Processing-Activities filing requirement was confirmed.observed
ConfirmedState of Delaware — The DPDPA requires businesses to employ reasonable data security measures proportionate to the nature and sensitivity of the personal data collected, to prevent unauthorized access.observed
ConfirmedState of Delaware — Delaware's data breach notification statute, in effect since April 14, 2018, requires notice to affected Delaware residents and, where a breach affects 500 or more residents, additional notice to the Delaware Attorney General.observed
Traffic-light rationale — RedNo comprehensive transfer-mechanism regime exists in this state statute; explicit gap consistent with the sectoral/hybrid US pattern.
Sub-modules (6)
Transfer MechanismsRed
No dedicated transfer-mechanism provisions were located; general contractual/security duties apply irrespective of data destination.
Claims (1):
The DPDPA does not contain an adequacy-decision framework, Standard Contractual Clauses regime, Binding Corporate Rules mechanism, or data-localisation mandate; cross-border transfer is governed only indirectly through the Act's general controller/processor contractual and security obligations.
Adequacy ReceivedRed
Not applicable; US states do not receive adequacy decisions under this framework.
Adequacy GrantedRed
No adequacy-granting mechanism exists under the DPDPA.
Sccs And BcrsRed
No SCC or BCR regime identified under the DPDPA.
Transfer Impact AssessmentRed
No transfer-impact-assessment requirement identified.
Data LocalisationRed
No data-localisation mandate identified under the DPDPA.
Category narrative53 words
The DPDPA, consistent with the general US state-omnibus-privacy pattern, does not contain a GDPR-style cross-border transfer regime. No adequacy-decision mechanism, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate was identified in the Act or AG guidance; cross-border transfer is regulated only indirectly via the Act's general contractual and security obligations on controllers and processors.
Sources and claims (1)
ProbableState of Delaware — The DPDPA does not contain an adequacy-decision framework, Standard Contractual Clauses regime, Binding Corporate Rules mechanism, or data-localisation mandate; cross-border transfer is governed only indirectly through the Act's general controller/processor contractual and security obligations.observed
Financial and health carve-outs are clearly documented; several sub-modules (telecoms, credit-scoring, education, insurance) have no DE-specific overlay evidence.
Primary frameworkDelaware Personal Data Privacy Act (DPDPA); federal GLBA/HIPAA/FCRA (deferred-to)
Traffic-light rationale — AmberFinancial and health carve-outs are clearly documented; several sub-modules (telecoms, credit-scoring, education, insurance) have no DE-specific overlay evidence.
Sub-modules (7)
Financial Sector OverlayAmber
Data maintained in compliance with GLBA is exempt from the DPDPA.
Claims (1):
The DPDPA does not apply to personal data maintained in compliance with the Gramm-Leach-Bliley Act, HIPAA, or the Fair Credit Reporting Act, as well as personal data processed for certain specified purposes.
Health Sector OverlayAmber
Data maintained in compliance with HIPAA is exempt from the DPDPA.
Claims (1):
The DPDPA does not apply to personal data maintained in compliance with the Gramm-Leach-Bliley Act, HIPAA, or the Fair Credit Reporting Act, as well as personal data processed for certain specified purposes.
Telecoms And EprivacyRed
No Delaware-specific telecoms/ePrivacy overlay was identified.
Employment DataAmber
The DPDPA excludes personal data processed in an employment context (e.g., job applications) from its consumer protections.
Claims (1):
The DPDPA applies to Delawareans acting in an individual or household context and does not protect an individual acting in an employment context, such as applying for a job.
Credit And ScoringAmber
The Fair Credit Reporting Act exemption covers certain credit-related data; no DE-specific credit-scoring overlay beyond this was identified.
Claims (1):
The DPDPA does not apply to personal data maintained in compliance with the Gramm-Leach-Bliley Act, HIPAA, or the Fair Credit Reporting Act, as well as personal data processed for certain specified purposes.
EducationRed
No Delaware-specific education-sector data overlay was identified.
InsuranceRed
No Delaware-specific insurance-sector data overlay was identified.
Category narrative44 words
The DPDPA exempts data governed by GLBA, HIPAA and FCRA and excludes employment-context personal data (e.g., job applicants) from its consumer-rights framework, deferring to those federal sectoral regimes. No Delaware-specific overlays for telecoms/ePrivacy, credit-scoring, education, or insurance were identified beyond these general federal deferrals.
Sources and claims (2)
ConfirmedState of Delaware — The DPDPA does not apply to personal data maintained in compliance with the Gramm-Leach-Bliley Act, HIPAA, or the Fair Credit Reporting Act, as well as personal data processed for certain specified purposes.observed
ConfirmedState of Delaware — The DPDPA applies to Delawareans acting in an individual or household context and does not protect an individual acting in an employment context, such as applying for a job.observed
Traffic-light rationale — AmberOpt-out signal and dark-pattern provisions are confirmed and in force; clean-room and direct-marketing-specific rules are gaps.
Sub-modules (6)
Cookies And TrackersAmber
No dedicated cookie-consent statute distinct from the general personal-data consent framework was identified.
Dark PatternsGreen
Consent obtained through deceptive webpage design is expressly excluded as valid consent.
Claims (1):
Acceptance of broad terms of service, hovering over or pausing on content, and agreement obtained through deceptive webpage design ('dark patterns') are not considered valid consent under the DPDPA.
Opt Out SignalsGreen
Universal opt-out mechanisms must be honored by controllers as valid consumer opt-out requests as of January 1, 2026.
Claims (1):
Beginning January 1, 2026, controllers must recognize universal opt-out mechanisms as valid consumer requests to opt out of personal-data processing across multiple websites at once.
Clean Rooms And DcrRed
No clean-room or data-collaboration-room rules were identified under the DPDPA.
Cross Context AdvertisingGreen
Consumers may opt out of processing for targeted advertising and automated profiling.
Claims (1):
Consumer rights under the DPDPA include opt-out options for targeted advertising and automated profiling.
Direct MarketingAmber
No DE-specific direct-marketing consent/suppression regime distinct from the general sale/targeted-advertising opt-out was identified.
Category narrative55 words
Consumers may opt out of the sale of personal data and processing for targeted advertising and profiling. Universal opt-out mechanisms (GPC-style signals) became mandatory for controllers to recognize as of January 1, 2026. Dark-pattern-induced consent is expressly invalid. No dedicated cookie statute, clean-room/data-collaboration rules, or direct-marketing-specific suppression regime beyond the general opt-out right was identified.
Sources and claims (3)
ConfirmedState of Delaware — Acceptance of broad terms of service, hovering over or pausing on content, and agreement obtained through deceptive webpage design ('dark patterns') are not considered valid consent under the DPDPA.observed
ConfirmedState of Delaware — Beginning January 1, 2026, controllers must recognize universal opt-out mechanisms as valid consumer requests to opt out of personal-data processing across multiple websites at once.observed
ConfirmedDataGuidance — Consumer rights under the DPDPA include opt-out options for targeted advertising and automated profiling.observed
Traffic-light rationale — AmberBiometric/genetic and minor-profiling protections are confirmed; AI-specific risk assessment and surveillance-carveout detail are gaps.
Sub-modules (6)
Profiling RestrictionsGreen
Consumers may opt out of processing for automated profiling; minors under 18 require opt-in consent for related targeted-advertising/sale processing.
Claims (1):
The DPDPA requires controllers to obtain opt-in consent before selling a consumer's personal data or processing personal data for targeted advertising when the consumer is under 18 years old.
Automated Decision Making TransparencyAmber
No explicit ADM-explanation right distinct from the general profiling opt-out was confirmed.
Ai Risk AssessmentsRed
No AI-specific risk-assessment regime (EU AI Act analogue) was identified; DPIA obligations cover high-risk processing generally.
Claims (1):
No AI-system-specific risk-assessment regime akin to the EU AI Act or state AI-transparency statutes was identified within the DPDPA; its DPIA obligations address 'high-risk processing' generally rather than AI systems specifically.
Biometric RegimeGreen
Biometric data used to uniquely identify an individual is classified as sensitive data requiring consent.
Claims (1):
Genetic and biometric data used to uniquely identify an individual are classified as sensitive data under the DPDPA, requiring consumer consent prior to collection or processing.
Genetic DataGreen
Genetic data used to uniquely identify an individual is classified as sensitive data requiring consent.
Claims (1):
Genetic and biometric data used to uniquely identify an individual are classified as sensitive data under the DPDPA, requiring consumer consent prior to collection or processing.
State Surveillance CarveoutsAmber
The Act permits denial of consumer-rights requests where necessary to comply with federal, state, or local law, functioning as a general legal-compliance carve-out rather than a dedicated national-security exemption.
Claims (1):
A controller may deny a consumer's rights request where fulfilling it would restrict the controller's ability to comply with federal, state, or local law.
Category narrative52 words
Biometric and genetic data used to uniquely identify an individual are classified as sensitive data requiring consent. Minors under 18 receive opt-in-consent protection against profiling-adjacent targeted advertising and data sale. No AI-specific risk-assessment regime distinct from general high-risk-processing DPIAs, and no dedicated state-surveillance carve-out beyond the Act's general legal-compliance exception, were identified.
Sources and claims (4)
ConfirmedState of Delaware — The DPDPA requires controllers to obtain opt-in consent before selling a consumer's personal data or processing personal data for targeted advertising when the consumer is under 18 years old.observed
ProbableDataGuidance — No AI-system-specific risk-assessment regime akin to the EU AI Act or state AI-transparency statutes was identified within the DPDPA; its DPIA obligations address 'high-risk processing' generally rather than AI systems specifically.observed
ConfirmedState of Delaware — Genetic and biometric data used to uniquely identify an individual are classified as sensitive data under the DPDPA, requiring consumer consent prior to collection or processing.observed
ConfirmedState of Delaware — A controller may deny a consumer's rights request where fulfilling it would restrict the controller's ability to comply with federal, state, or local law.observed
Traffic-light rationale — GreenMinor-specific protections are clearly documented and in force; education-settings and dependent-adults sub-modules are explicit gaps.
Sub-modules (5)
Age VerificationAmber
No standalone age-verification mandate distinct from the under-18 opt-in-consent trigger was identified.
Parental ConsentGreen
Parents/guardians may exercise DPDPA consumer rights on a child's behalf, and controllers must additionally follow COPPA parental-consent requirements.
Claims (1):
Where a child's personal data is processed, the child's parent or legal guardian may exercise the DPDPA's consumer rights on the child's behalf, and controllers must follow COPPA parental-consent requirements.
Minor Profiling BansGreen
Opt-in consent is required before selling or using a under-18 consumer's data for targeted advertising, restricting default profiling-adjacent uses.
Claims (1):
In addition to protections afforded adults, Delaware law provides additional protections for children and teens under 18, including a requirement of opt-in consent before selling their personal data or using it for targeted advertising.
Education SettingsRed
No Delaware-specific education-sector/student-data provisions were identified within the DPDPA.
Dependent AdultsRed
No Delaware-specific dependent-adult (elderly/incapacitated) protections were identified within the DPDPA.
Category narrative35 words
Delaware provides children and teens under 18 additional protections beyond adults, including opt-in consent for sale/targeted-advertising processing and parental/guardian exercise of consumer rights, alongside COPPA-referenced parental-consent duties. No DE-specific education-setting or dependent-adult provisions were identified.
Sources and claims (2)
ConfirmedState of Delaware — Where a child's personal data is processed, the child's parent or legal guardian may exercise the DPDPA's consumer rights on the child's behalf, and controllers must follow COPPA parental-consent requirements.observed
ConfirmedState of Delaware — In addition to protections afforded adults, Delaware law provides additional protections for children and teens under 18, including a requirement of opt-in consent before selling their personal data or using it for targeted advertising.observed
Enforcement powers and penalties are clear and in force; the pending HB 380 amendment's enactment status is an unresolved material development within the 180-day window, and regulator funding/capacity data is a gap.
Primary frameworkDelaware Personal Data Privacy Act (DPDPA)
Traffic-light rationale — AmberEnforcement powers and penalties are clear and in force; the pending HB 380 amendment's enactment status is an unresolved material development within the 180-day window, and regulator funding/capacity data is a gap.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
Civil penalties up to $10,000 per violation, plus injunctive relief, restitution, and disgorgement, are available to the Attorney General.
Claims (1):
Entities or individuals that violate the DPDPA may face civil penalties up to $10,000 per violation, and the Attorney General can additionally seek injunctive relief, restitution, and/or disgorgement.
Enforcement Activity IndexAmber
No specific published enforcement actions/fines under the DPDPA were located as of this run; enforcement began January 1, 2025.
Regulator Funding And CapacityRed
No specific headcount or budget figures for DPDPA enforcement within the Consumer Protection Unit were located.
Claims (1):
No specific headcount, budget, or staffing figures for DPDPA enforcement within the Delaware DOJ Consumer Protection Unit were located in reviewed sources.
Collective Redress And Class ActionsAmber
Absent a private right of action, collective redress is limited to Attorney General complaint channels rather than consumer-initiated class actions.
Claims (1):
Because the DPDPA lacks a private right of action, consumer complaints are channeled to the Attorney General's office ([email protected]) rather than through consumer-initiated class actions.
Private Right Of ActionAmber
The DPDPA does not include a private cause of action; private citizens cannot sue directly under the Act.
Claims (1):
The DPDPA does not include a private cause of action; private citizens are not entitled to file lawsuits or enforce legal rights directly under the Act.
Recent Developments 180DAmber
HB 380, introduced April 16, 2026, would amend the DPDPA (lower thresholds, expanded rights, January 1, 2027 effective date) and was reported to have passed the Legislature by June 2026; gubernatorial signature is unconfirmed.
Claims (1):
House Bill No. 380, introduced to the Delaware House on April 16, 2026, would amend the DPDPA by lowering the applicability threshold to 10,000 consumers (or 5,000 with significant data-sale revenue), expand access and profiling opt-out rights, and take effect January 1, 2027; the bill was reported to have passed the Legislature by June 2026, but gubernatorial signature was not confirmed as of this run.
Category narrative90 words
The Attorney General may seek civil penalties up to $10,000 per violation plus injunctive relief, restitution and/or disgorgement. A mandatory 60-day right-to-cure period applied through December 31, 2025, after which cure is discretionary. The DPDPA carries no private right of action, so redress runs solely through AG complaint channels rather than class actions. A pending amendment, HB 380 (introduced April 16, 2026; reported passed by the Legislature by June 2026), would lower thresholds and expand rights effective January 1, 2027, but gubernatorial signature was not confirmed as of this run.
Sources and claims (5)
ConfirmedState of Delaware — Entities or individuals that violate the DPDPA may face civil penalties up to $10,000 per violation, and the Attorney General can additionally seek injunctive relief, restitution, and/or disgorgement.observed
UncertainState of Delaware — No specific headcount, budget, or staffing figures for DPDPA enforcement within the Delaware DOJ Consumer Protection Unit were located in reviewed sources.observed
ProbableState of Delaware — Because the DPDPA lacks a private right of action, consumer complaints are channeled to the Attorney General's office ([email protected]) rather than through consumer-initiated class actions.observed
ConfirmedState of Delaware — The DPDPA does not include a private cause of action; private citizens are not entitled to file lawsuits or enforce legal rights directly under the Act.observed
ProbableDataGuidance — House Bill No. 380, introduced to the Delaware House on April 16, 2026, would amend the DPDPA by lowering the applicability threshold to 10,000 consumers (or 5,000 with significant data-sale revenue), expand access and profiling opt-out rights, and take effect January 1, 2027; the bill was reported to have passed the Legislature by June 2026, but gubernatorial signature was not confirmed as of this run.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for United States – Delaware
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 35 claim(s), 12 source(s) in the cumulative register.
GDPR article map
Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).
All 10 modules populated with T1 (Delaware AG portal/FAQ/letter/breach-notification pages) as primary anchors, supplemented by T3 secondary legal-guidance sources (DataGuidance, IAPP) for legislative-history and cross-state comparison context. Strong T1 coverage: regulator_and_framework, data_subject_rights, controller_processor_duties (security/breach), adtech_and_commercial_privacy, children_and_vulnerable_groups, enforcement_and_redress (penalties/cure/private-right-of-action). Weaker/gap coverage relying on T3 or absent_field_provenance: cross_border_and_adequacy (no regime exists — explicit gap), controller_processor_duties.dpo_requirements/ropa_requirements, algorithmic_biometric_and_surveillance_governance.ai_risk_assessments, sectoral_watch.telecoms/education/insurance, enforcement_and_redress.regulator_funding_and_capacity.
Unresolved questions (5):
Has Delaware HB 380 (DPDPA amendment) been signed into law by the Governor, and if so on what date, given DataGuidance reports it passed the Legislature by June 2026?
Does the DPDPA or implementing guidance specify any DPO-appointment threshold or independence requirement not surfaced in AG FAQ/business pages?
Is there a formal, filed Records-of-Processing-Activities (ROPA) obligation, or only an internal-inventory expectation?
Are there any published DPDPA enforcement actions or settlements since the January 1, 2025 effective date?
Does Delaware have any state-specific AI-transparency or biometric-privacy statute layered on top of the DPDPA sensitive-data provisions?