Delaware Privacy Law (DPDPA): Compliance Guide
The Delaware Personal Data Privacy Act, effective January 1, 2025, has the lowest applicability thresholds in the country — 35,000 consumers, or just 10,000 when a fifth of revenue comes from selling personal data. A business too small for almost every other state law can still be covered in Delaware. Since January 1, 2026 it also requires honoring universal opt-out mechanisms, putting the second-smallest state firmly in the twelve-state GPC club.
- Effective
- January 1, 2025
- GPC / universal opt-out
- Required since January 1, 2026
- Required link text
- “Your Privacy Choices”
Last reviewed July 19, 2026 · Delaware Personal Data Privacy Act (DPDPA)
Applicability
Who must comply with the DPDPA
The Delaware Personal Data Privacy Act applies to businesses that meet the following criteria:
- Controls or processes the personal data of 35,000 or more Delaware consumers, or
- Controls or processes the personal data of 10,000 or more Delaware consumers and derives 20% or more of gross revenue from the sale of personal data
Consumer rights
What Delaware consumers can demand
- Right to access personal data
- Right to correct inaccuracies
- Right to delete personal data
- Right to data portability
- Right to opt out of targeted advertising, profiling, and the sale of personal data
Opt-out mechanics
Delaware opt-out & GPC requirements
Like every US state privacy law, the DPDPA uses an opt-out model: you do not need a GDPR-style cookie banner, but you must provide a clear and conspicuous opt-out link. The accepted text for Delaware is “Your Privacy Choices”.
Global Privacy Control: Required since January 1, 2026
Delaware requires covered businesses to honor universal opt-out mechanisms such as Global Privacy Control. The obligation took effect January 1, 2026 — exactly one year after the law itself.
Enforcement
DPDPA penalties & enforcement
- Enforced by the Delaware Attorney General
Cure period: Our reference lists no specific cure period for Delaware; enforcement runs through the Delaware Attorney General.
State quirks
What makes Delaware different
Delaware's headline is reach. Its 35,000/10,000 thresholds are the lowest in the nation, and its definition of personal data is broader than most states', so processing that is out of scope elsewhere may be covered here. Its universal opt-out duty was phased in deliberately — January 1, 2026, one year after the law took effect — which caught businesses that assumed the 2025 effective date was the only deadline that mattered.
Lowest thresholds in the country
Coverage starts at 35,000 consumers — or just 10,000 when 20% or more of revenue comes from selling personal data.
Broad definition of personal data
Delaware defines personal data more broadly than most states, pulling more processing activities into scope.
Universal opt-out from 2026
Universal opt-out mechanisms must be honored starting January 1, 2026 — one year after the law's own effective date.
Enhanced consumer insight
Consumers get stronger visibility into how their data is used than the baseline state framework provides.
Automation
How ConsentKit handles Delaware
- ConsentKit's widget is served from Cloudflare's edge and receives the visitor's US state server-side, so Delaware visitors are identified before any consent UI renders — no client-side geo-lookup delay.
- Delaware visitors see a persistent “Your Privacy Choices” link — the exact statutory text — available to new and returning visitors alike.
- Because Delaware requires universal opt-out signals, ConsentKit automatically honors Global Privacy Control for Delaware visitors: when the browser broadcasts GPC, the widget applies the opt-out and denies analytics and marketing categories with no click required.
- Every opt-out is recorded server-side with a timestamp and jurisdiction metadata, reviewable and exportable (CSV) from the dashboard — the audit trail regulators ask for.
- Google Consent Mode v2 stays in sync: analytics and advertising tags update the moment a Delaware visitor makes a choice.
Delaware's low thresholds catch smaller sites; ConsentKit's free tier (one site, 10,000 pageviews a month) covers the consent mechanics without an enterprise budget.
FAQ
Delaware DPDPA FAQ
Does the DPDPA apply to small businesses?
More often than other state laws do. Delaware's thresholds are the lowest in the country: 35,000 consumers, or just 10,000 consumers when 20% or more of gross revenue comes from selling personal data. A niche business with a modest Delaware audience can be covered here while falling under every other state's radar.
Is Global Privacy Control required in Delaware?
Yes, since January 1, 2026 — exactly one year after the law itself took effect. Covered businesses must honor universal opt-out mechanisms such as Global Privacy Control for Delaware visitors.
What rights do Delaware consumers have?
Delaware consumers can access, correct, delete, and obtain a portable copy of their personal data, and can opt out of targeted advertising, profiling, and the sale of their personal data.
What makes Delaware's definition of personal data different?
Delaware uses a broader definition of personal data than most states, which pulls more processing activities into scope. Combined with the lowest coverage thresholds in the country, it means businesses should not assume they are too small or their data too thin for the law to apply.
This guide is for informational purposes and is not legal advice. Work with qualified counsel to confirm your obligations under the DPDPA.
Comply with Delaware's DPDPA — and the other 19 state laws
ConsentKit detects each visitor's state at the Cloudflare edge, renders the exact opt-out link their law requires, honors GPC automatically where mandated, and records every choice for your audit trail.