DPDPA · Opt-out model

Delaware Privacy Law (DPDPA): Compliance Guide

The Delaware Personal Data Privacy Act, effective January 1, 2025, has the lowest applicability thresholds in the country — 35,000 consumers, or just 10,000 when a fifth of revenue comes from selling personal data. A business too small for almost every other state law can still be covered in Delaware. Since January 1, 2026 it also requires honoring universal opt-out mechanisms, putting the second-smallest state firmly in the twelve-state GPC club.

Effective
January 1, 2025
GPC / universal opt-out
Required since January 1, 2026
Required link text
Your Privacy Choices
Handle DPDPA compliance free

Last reviewed July 19, 2026 · Delaware Personal Data Privacy Act (DPDPA)

Applicability

Who must comply with the DPDPA

The Delaware Personal Data Privacy Act applies to businesses that meet the following criteria:

  • Controls or processes the personal data of 35,000 or more Delaware consumers, or
  • Controls or processes the personal data of 10,000 or more Delaware consumers and derives 20% or more of gross revenue from the sale of personal data

Consumer rights

What Delaware consumers can demand

  • Right to access personal data
  • Right to correct inaccuracies
  • Right to delete personal data
  • Right to data portability
  • Right to opt out of targeted advertising, profiling, and the sale of personal data

Opt-out mechanics

Delaware opt-out & GPC requirements

Like every US state privacy law, the DPDPA uses an opt-out model: you do not need a GDPR-style cookie banner, but you must provide a clear and conspicuous opt-out link. The accepted text for Delaware is Your Privacy Choices.

Global Privacy Control: Required since January 1, 2026

Delaware requires covered businesses to honor universal opt-out mechanisms such as Global Privacy Control. The obligation took effect January 1, 2026 — exactly one year after the law itself.

Enforcement

DPDPA penalties & enforcement

  • Enforced by the Delaware Attorney General

Cure period: Our reference lists no specific cure period for Delaware; enforcement runs through the Delaware Attorney General.

State quirks

What makes Delaware different

Delaware's headline is reach. Its 35,000/10,000 thresholds are the lowest in the nation, and its definition of personal data is broader than most states', so processing that is out of scope elsewhere may be covered here. Its universal opt-out duty was phased in deliberately — January 1, 2026, one year after the law took effect — which caught businesses that assumed the 2025 effective date was the only deadline that mattered.

Lowest thresholds in the country

Coverage starts at 35,000 consumers — or just 10,000 when 20% or more of revenue comes from selling personal data.

Broad definition of personal data

Delaware defines personal data more broadly than most states, pulling more processing activities into scope.

Universal opt-out from 2026

Universal opt-out mechanisms must be honored starting January 1, 2026 — one year after the law's own effective date.

Enhanced consumer insight

Consumers get stronger visibility into how their data is used than the baseline state framework provides.

Automation

How ConsentKit handles Delaware

  • ConsentKit's widget is served from Cloudflare's edge and receives the visitor's US state server-side, so Delaware visitors are identified before any consent UI renders — no client-side geo-lookup delay.
  • Delaware visitors see a persistent Your Privacy Choices link — the exact statutory text — available to new and returning visitors alike.
  • Because Delaware requires universal opt-out signals, ConsentKit automatically honors Global Privacy Control for Delaware visitors: when the browser broadcasts GPC, the widget applies the opt-out and denies analytics and marketing categories with no click required.
  • Every opt-out is recorded server-side with a timestamp and jurisdiction metadata, reviewable and exportable (CSV) from the dashboard — the audit trail regulators ask for.
  • Google Consent Mode v2 stays in sync: analytics and advertising tags update the moment a Delaware visitor makes a choice.

Delaware's low thresholds catch smaller sites; ConsentKit's free tier (one site, 10,000 pageviews a month) covers the consent mechanics without an enterprise budget.

FAQ

Delaware DPDPA FAQ

Does the DPDPA apply to small businesses?

More often than other state laws do. Delaware's thresholds are the lowest in the country: 35,000 consumers, or just 10,000 consumers when 20% or more of gross revenue comes from selling personal data. A niche business with a modest Delaware audience can be covered here while falling under every other state's radar.

Is Global Privacy Control required in Delaware?

Yes, since January 1, 2026 — exactly one year after the law itself took effect. Covered businesses must honor universal opt-out mechanisms such as Global Privacy Control for Delaware visitors.

What rights do Delaware consumers have?

Delaware consumers can access, correct, delete, and obtain a portable copy of their personal data, and can opt out of targeted advertising, profiling, and the sale of their personal data.

What makes Delaware's definition of personal data different?

Delaware uses a broader definition of personal data than most states, which pulls more processing activities into scope. Combined with the lowest coverage thresholds in the country, it means businesses should not assume they are too small or their data too thin for the law to apply.

This guide is for informational purposes and is not legal advice. Work with qualified counsel to confirm your obligations under the DPDPA.

Comply with Delaware's DPDPA — and the other 19 state laws

ConsentKit detects each visitor's state at the Cloudflare edge, renders the exact opt-out link their law requires, honors GPC automatically where mandated, and records every choice for your audit trail.