close
close
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Delaware Privacy Law

DE

Delaware (DPDPA)

Last updated

DPDPA Enacted, in effect

Who this affects: This page tracks Delaware’s DPDPA, which governs controllers and processors.

Who it applies to: Persons that do business in Delaware or target its residents, and meet: 35,000+ consumers, or 10,000+ consumers and more than 20% of gross revenue from selling data.

Content on this page is not legal advice This page aggregates publicly cited regulatory facts for informational purposes only. It is not legal advice, and DataGrail is not responsible for decisions made in reliance on it. Consult qualified counsel for your specific compliance obligations.
Jan 1, 2025
Effective ↗
Department of Justice
Enforced by ↗
$10,000
Maximum penalty per violation ↗
None
Private right of action ↗

The law, in plain English

Must · Can’t · Should

DPDPA, distilled to what actually changes your week. Read one column to know your floor, your hard limits, and the further obligations and good practices worth planning for.

Must

  • Respond to rights requests within 45 days; extend 45 more only if reasonably necessary, with notice and reasons in that window. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. DE-12D-104 “A controller shall respond to the consumer without undue delay, but not later than 45 days after receipt of the request. The controller may extend the response period by 45 additional days when reasonably necessary, considering the complexity and number of the consumer’s requests, provided the controller informs the consumer of any such extension within the initial 45-day response period and of the reason for the extension.” Read the statute
  • Since January 1, 2026, honor opt-out preference signals for targeted advertising and sales, even over conflicting settings. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. DE-12D-106 “Not later than January 1, 2026, allowing a consumer to opt out of any processing of the consumer’s personal data for the purposes of targeted advertising, or any sale of such personal data, through an opt-out preference signal sent, with such consumer’s consent, by a platform, technology, or mechanism to the controller indicating such consumer’s intent to opt out of any such processing or sale” Read the statute DE-12D-106 “the controller shall comply with such consumer’s opt-out preference signal but may notify such consumer of such conflict and provide to such consumer the choice to confirm such controller-specific privacy setting or participation in such program” Read the statute
  • Offer an appeal process for refused requests and give the consumer a written decision with reasons within 60 days of an appeal. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. DE-12D-104 “A controller shall establish a process for a consumer to appeal the controller’s refusal to take action on a request within a reasonable period of time after the consumer’s receipt of the decision” Read the statute DE-12D-104 “Not later than 60 days after receipt of an appeal, a controller shall inform the consumer in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions” Read the statute

Can't

  • Process sensitive data without consent, or a known child's sensitive data without first getting parent or guardian consent. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. DE-12D-106 “Not process sensitive data concerning a consumer without obtaining the consumer’s consent, or, in the case of the processing of sensitive data concerning a known child, without first obtaining consent from the child’s parent or lawful guardian and otherwise complying with § 1204C of this title.” Read the statute
  • Sell or target ads with data of a consumer you know, or wilfully disregard, is at least 13 but younger than 18, without consent. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. DE-12D-106 “Not process the personal data of a consumer for purposes of targeted advertising, or sell the consumer’s personal data without the consumer’s consent, under circumstances where a controller has actual knowledge or wilfully disregards that the consumer is at least 13 years of age but younger than 18 years of age” Read the statute
  • Require a new account to exercise rights, or discriminate for exercising them outside voluntary bona fide loyalty programs. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. DE-12D-106 “A controller shall not require a consumer to create a new account in order to exercise consumer rights” Read the statute DE-12D-106 “Not discriminate against a consumer for exercising any of the consumer rights contained in this chapter, including denying goods or services, charging different prices or rates for goods or services, or providing a different level of quality of goods or services to the consumer. (b) Nothing in subsection (a) of this section shall be construed to require a controller to provide a product or service that requires the personal data of a consumer which the controller does not collect or maintain, or prohibit a controller from offering a different price, rate, level, quality, or selection of goods or services to a consumer, including offering goods or services for no fee, if the offering is in connection with a consumer’s voluntary participation in a bona fide loyalty, rewards, premium features, discounts, or club card program” Read the statute

Should

  • Make revoking consent as easy as giving it, and stop processing within 15 days of a revocation, sooner if practicable. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. DE-12D-106 “Provide an effective mechanism for a consumer to revoke the consumer’s consent under this section that is at least as easy as the mechanism by which the consumer provided the consumer’s consent and, upon revocation of such consent, cease to process the data as soon as practicable, but not later than 15 days after the receipt of such request” Read the statute
  • Put every processor under a binding contract setting instructions, purpose, data type, duration, and both parties' rights. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. DE-12D-107 “A contract between a controller and a processor must govern the processor’s data processing procedures with respect to processing performed on behalf of the controller. The contract must be binding and clearly set forth instructions for processing data, the nature and purpose of processing, the type of data subject to processing, the duration of processing and the rights and obligations of both parties.” Read the statute
  • Assess and document heightened-risk processing regularly if you hold 100,000+ consumers' data, not counting payment-only data. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. DE-12D-108 “A controller that controls or processes the data of not less than 100,000 consumers, excluding data controlled or processed solely for the purpose of completing a payment transaction, shall conduct and document, on a regular basis, a data protection assessment for each of the controller’s processing activities that presents a heightened risk of harm to a consumer” Read the statute

These are the highlights we judge most important, not everything DPDPA requires. The comprehensive law section below covers the full detail, fact by fact, with the statutory text behind every one.

The comprehensive law

Delaware Personal Data Privacy Act

DPDPA (HB 154) is Delaware’s comprehensive privacy law. Every fact was extracted from the primary statute by the DataGrail regulation engine and is grounded to the cited source. Scan the facts; the exact statutory text sits one click away on each source link.

Status
Enacted, in effect
Archived excerpt — the text we read Section 3. If this Act is enacted before or on January 1, 2024, this Act takes effect on January 1, 2025. If this Act is enacted after January 1, 2024, this Act takes effect on January 1, 2026. Archived from source — captured 2026-08-17 · snapshot 9ddc3ba4 Verify at the source
Effective
January 1, 2025
Archived excerpt — the text we read Section 3. If this Act is enacted before or on January 1, 2024, this Act takes effect on January 1, 2025. If this Act is enacted after January 1, 2024, this Act takes effect on January 1, 2026. Archived from source — captured 2026-08-17 · snapshot 9ddc3ba4 Verify at the source

Corroborated by Privacy-law tracker Regulator guidance

Signed
September 11, 2023
“Approved September 11, 2023” View the source
Enforced by
Department of Justice
Archived excerpt — the text we read 12D-111. Enforcement. (a) The Department of Justice has enforcement authority over this chapter and may investigate and prosecute violations of this chapter in accordance with the provisions of subchapter II of Chapter 25 of Title 29. (b) During the period beginning on January 1, 2025, and ending on December 31, 2025, the Department of Justice shall, prior to initiating an… Archived from source — captured 2026-07-20 · snapshot 91e2ea0b Verify at the source
Maximum penalty per violation
$10,000
Applies to wilful violations; enforced solely by the Department of Justice. Source for each figure$10,000 · 6 Del. C. § 2522 $25,000 · 29 Del. C. § 2526 Additional $10,000 · 6 Del. C. § 2581 “the person shall forfeit and pay to the State a civil penalty of not more than $10,000 for each violation” View the statute
Right to cure
Mandatory cure lapsed Dec 31, 2025; now discretionary
The mandatory cure ended Dec 31, 2025; since Jan 1, 2026 the DOJ may offer a cure at its discretion. Archived excerpt — the text we read …ssible. If the controller fails to cure such violation within 60 days of receipt of the notice of violation, the Department of Justice may bring an enforcement proceeding pursuant to subsection (a) of this section. (c) Beginning on January 1, 2026, the Department of Justice may, in determining whether to grant a controller or processor the opportunity to cure an alleged violation of any provision of this chapter, may consider all of the following: (1) The number of violations. (2) The size and complexity of the controller or processor. (3) The nature and extent of the controller’s or processor’s processing activities. (4) T… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
Private right of action
No private right of action.
Archived excerpt — the text we read … safety of persons or property. (6) Whether such alleged violation was likely caused by human or technical error. (7) The extent to which the controller or processor has violated this or similar laws in the past. (d) Nothing in this chapter shall be construed as providing the basis for, or be subject to, a private right of action for violations of said sections or any other law. (e) A violation of this chapter shall be deemed an unlawful practice under § 2513 of this title and a violation of subchapter II of this title, and shall be enforced solely by the Department of Justice. 84 Del. Laws, c… Archived from source — captured 2026-07-20 · snapshot 91e2ea0b Verify at the source

Corroborated by Privacy-law tracker Regulator guidance

Universal opt-out signal
Required
Archived excerpt — the text we read …er’s Internet website to an Internet web page that enables a consumer, or an agent of the consumer, to opt out of the targeted advertising or the sale of the consumer’s personal data. 2. Not later than January 1, 2026, allowing a consumer to opt out of any processing of the consumer’s personal data for the purposes of targeted advertising, or any sale of such personal data, through an opt-out preference signal sent, with such consumer’s consent, by a platform, technology, or mechanism to the controller indicating such consumer’s intent to opt out of any such processing or sale. Such platform, technology, or mechanism shall do all of the following: A. Not unfairly disadvantage another controller. B. Not make use of a default setting, but, rather, require the consumer to make an affirmative, … Archived from source — captured 2026-07-20 · snapshot 91e2ea0b Verify at the source

Corroborated by Privacy-law tracker

Who it applies to

Persons that do business in Delaware or target its residents, and meet: 35,000+ consumers, or 10,000+ consumers and more than 20% of gross revenue from selling data

What the law gives consumers

  • Right to access Archived excerpt — the text we read § 12D-104. Consumer personal data rights [Effective until Jan. 1, 2027]. (a) A consumer has the right to do all of the following: (1) Confirm whether a controller is processing the consumer’s personal data and access such personal data, unless such confirmation or access would require the controller to reveal a trade secret. (2) Correct inaccuracies in the consumer’s personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer’s personal data. (3) Delete personal data provided by, o… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Right to correct Archived excerpt — the text we read …f the following: (1) Confirm whether a controller is processing the consumer’s personal data and access such personal data, unless such confirmation or access would require the controller to reveal a trade secret. (2) Correct inaccuracies in the consumer’s personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer’s personal data. (3) Delete personal data provided by, or obtained about, the consumer. (4) Obtain a copy of the consumer’s personal data processed by the controller, in a portable and, to the extent technically feasible, readily-usab… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Right to delete Archived excerpt — the text we read …ontroller to reveal a trade secret. (2) Correct inaccuracies in the consumer’s personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer’s personal data. (3) Delete personal data provided by, or obtained about, the consumer. (4) Obtain a copy of the consumer’s personal data processed by the controller, in a portable and, to the extent technically feasible, readily-usable format that allows the consumer to transmit the data to another contr… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Right to data portability Archived excerpt — the text we read …sumer’s personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer’s personal data. (3) Delete personal data provided by, or obtained about, the consumer. (4) Obtain a copy of the consumer’s personal data processed by the controller, in a portable and, to the extent technically feasible, readily-usable format that allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means, provided such controller shall not be required to reveal any trade secret. (5) Obtain a list of the categories of third parties to which the controller has disclosed the consumer’s personal data. (6) Opt out of the processing of the personal data for purposes of any of the following: a. Tar… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Right to know the categories of third-party recipients Archived excerpt — the text we read …t allows the consumer to transmit the data to another controller without hindrance, where the processing is carried out by automated means, provided such controller shall not be required to reveal any trade secret. (5) Obtain a list of the categories of third parties to which the controller has disclosed the consumer’s personal data. (6) Opt out of the processing of the personal data for purposes of any of the following: a. Targeted advertising. b. The sale of personal data, except as provided in § 12D-106(b) of this title. c. Profiling in furth… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Right to opt out of targeted advertising Archived excerpt — the text we read … automated means, provided such controller shall not be required to reveal any trade secret. (5) Obtain a list of the categories of third parties to which the controller has disclosed the consumer’s personal data. (6) Opt out of the processing of the personal data for purposes of any of the following: a. Targeted advertising. b. The sale of personal data, except as provided in § 12D-106(b) of this title. c. Profiling in furtherance of solely-automated decisions that produce legal or similarly significant effects concerning the consumer. (… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Right to opt out of sale Archived excerpt — the text we read …the categories of third parties to which the controller has disclosed the consumer’s personal data. (6) Opt out of the processing of the personal data for purposes of any of the following: a. Targeted advertising. b. The sale of personal data, except as provided in § 12D-106(b) of this title. c. Profiling in furtherance of solely-automated decisions that produce legal or similarly significant effects concerning the consumer. (b) A consumer may exercise rights under this section by a secure and reliable mea… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Right to opt out of profiling for solely automated significant decisions Archived excerpt — the text we read …r’s personal data. (6) Opt out of the processing of the personal data for purposes of any of the following: a. Targeted advertising. b. The sale of personal data, except as provided in § 12D-106(b) of this title. c. Profiling in furtherance of solely-automated decisions that produce legal or similarly significant effects concerning the consumer. (b) A consumer may exercise rights under this section by a secure and reliable means established by the controller and described to the consumer in the controller’s privacy notice. A consumer may designate an authorize… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Right to appeal Archived excerpt — the text we read … the deletion request and the minimum data necessary for the purpose of ensuring the consumer’s personal data remains deleted from the controller’s records and does not use such retained data for any other purpose. (d) A controller shall establish a process for a consumer to appeal the controller’s refusal to take action on a request within a reasonable period of time after the consumer’s receipt of the decision. The appeal process shall be conspicuously available and similar to the process for submitting requests to initiate action pursuant to this section. Not later than 60 days after receipt of an appeal, a controller shall i… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Sensitive data: opt-in consent required Archived excerpt — the text we read …able administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data appropriate to the volume and nature of the personal data at issue. (4) Not process sensitive data concerning a consumer without obtaining the consumer’s consent, or, in the case of the processing of sensitive data concerning a known child, without first obtaining consent from the child’s parent or lawful guardian and otherwise complying with § 1204C of this title. (5) Not process personal data in violation of the laws of this State and federal laws that prohibit unlawful discrimination. (6) Provide an effective mechanism for a consumer to revoke the consumer’s consent under thi… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Right against discrimination Archived excerpt — the text we read …mer’s personal data without the consumer’s consent, under circumstances where a controller has actual knowledge or wilfully disregards that the consumer is at least 13 years of age but younger than 18 years of age. (8) Not discriminate against a consumer for exercising any of the consumer rights contained in this chapter, including denying goods or services, charging different prices or rates for goods or services, or providing a different level of quality of goods or services to the consumer. (b) Nothing in subsection (a) of this section shall be construed to require a controller to provide a product or service that requires the personal data of a consumer which the controller does not collect or maintain, … Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Not granted: Private right of action Archived excerpt — the text we read … safety of persons or property. (6) Whether such alleged violation was likely caused by human or technical error. (7) The extent to which the controller or processor has violated this or similar laws in the past. (d) Nothing in this chapter shall be construed as providing the basis for, or be subject to, a private right of action for violations of said sections or any other law. (e) A violation of this chapter shall be deemed an unlawful practice under § 2513 of this title and a violation of subchapter II of this title, and shall be enforced solely by the Department of Justice. 84 Del. Laws, c… Archived from source — captured 2026-07-20 · snapshot 91e2ea0b Verify at the source

Who the law governs

  • Controllers Archived excerpt — the text we read …y whose communications or transactions with the controller occur solely within the context of that individual’s role with the company, partnership, sole proprietorship, nonprofit organization, or government agency. (9) “Controller” means a person that, alone or jointly with others, determines the purpose and means of processing personal data. (10) “COPPA” means the Children’s Online Privacy Protection Act of 1998, 15 U.S.C. § 6501, et seq., and the regulations, rules, guidance, and exemptions adopted pursuant to said act, as said act and such regulations, r… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Processors Archived excerpt — the text we read … of operations performed, whether by manual or automated means, on personal data or on sets of personal data, such as the collection, use, storage, disclosure, analysis, deletion, or modification of personal data. (24) “Processor” means a person that processes personal data on behalf of a controller. (25) “Profiling” means any form of automated processing performed on personal data to evaluate, analyze, or predict personal aspects related to an identified or identifiable individual’s economic situation, health, dem… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source

Exemptions

  • State and local government bodies (not institutions of higher education) Archived excerpt — the text we read …d or processed the personal data of not less than 10,000 consumers and derived more than 20% of their gross revenue from the sale of personal data. (b) This chapter does not apply to any of the following entities: (1) Any regulatory, administrative, advisory, executive, appointive, legislative, or judicial body of the State or a political subdivision of the State, including any board, bureau, commission, agency of the State or a political subdivision of the State, but excluding any institution of higher education. (2) Any financial institution or affiliate of a financial institution, all as defined in 15 U.S.C. §  6809, to the extent that the financial institution or affiliate is subject to Title V of the Gramm Leach Bliley Act … Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • GLBA-regulated financial institutions Archived excerpt — the text we read …al body of the State or a political subdivision of the State, including any board, bureau, commission, agency of the State or a political subdivision of the State, but excluding any institution of higher education. (2) Any financial institution or affiliate of a financial institution, all as defined in 15 U.S.C. §  6809, to the extent that the financial institution or affiliate is subject to Title V of the Gramm Leach Bliley Act (15 U.S.C. § 6801, et seq., as amended) and the rules and implementing regulations promulgated thereunder. (3) Any nonprofit organization dedicated exclusively to preventing and addressing insurance crime. (4) A natio… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Nonprofit organizations dedicated to preventing insurance crime Archived excerpt — the text we read … the extent that the financial institution or affiliate is subject to Title V of the Gramm Leach Bliley Act (15 U.S.C. § 6801, et seq., as amended) and the rules and implementing regulations promulgated thereunder. (3) Any nonprofit organization dedicated exclusively to preventing and addressing insurance crime. (4) A national securities association registered pursuant to § 15A of the Securities Exchange Act of 1934 (15 U.S.C. § 78o-3, as amended) and the rules and implementing regulations promulgated thereunder, or a register… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • National securities and futures associations Archived excerpt — the text we read …ley Act (15 U.S.C. § 6801, et seq., as amended) and the rules and implementing regulations promulgated thereunder. (3) Any nonprofit organization dedicated exclusively to preventing and addressing insurance crime. (4) A national securities association registered pursuant to § 15A of the Securities Exchange Act of 1934 (15 U.S.C. § 78o-3, as amended) and the rules and implementing regulations promulgated thereunder, or a registered futures association so designated pursuant to § 17 of the Commodity Exchange Act (7 U.S.C. § 21, as amended) and the rules and implementing regulations promulgated thereunder. (c) This chapter does not apply to the following information and data: (1) Protected health information under HIPAA. (2) Patient-identifying information for purposes of 42 U.S.C. § 290dd-2. (3) Identifiable private … Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • HIPAA protected health information Archived excerpt — the text we read … pursuant to § 17 of the Commodity Exchange Act (7 U.S.C. § 21, as amended) and the rules and implementing regulations promulgated thereunder. (c) This chapter does not apply to the following information and data: (1) Protected health information under HIPAA. (2) Patient-identifying information for purposes of 42 U.S.C. § 290dd-2. (3) Identifiable private information, as defined in 45 C.F.R. § 46.102, to the extent that it is used for purposes of the federal policy for the… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • 42 U.S.C. § 290dd-2 patient-identifying information Archived excerpt — the text we read … (7 U.S.C. § 21, as amended) and the rules and implementing regulations promulgated thereunder. (c) This chapter does not apply to the following information and data: (1) Protected health information under HIPAA. (2) Patient-identifying information for purposes of 42 U.S.C. § 290dd-2. (3) Identifiable private information, as defined in 45 C.F.R. § 46.102, to the extent that it is used for purposes of the federal policy for the protection of human subjects pursuant to 45 C.F.R. Part 46. (4) Identifi… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Human subjects research information under 45 C.F.R. Part 46 Archived excerpt — the text we read …omulgated thereunder. (c) This chapter does not apply to the following information and data: (1) Protected health information under HIPAA. (2) Patient-identifying information for purposes of 42 U.S.C. § 290dd-2. (3) Identifiable private information, as defined in 45 C.F.R. § 46.102, to the extent that it is used for purposes of the federal policy for the protection of human subjects pursuant to 45 C.F.R. Part 46. (4) Identifiable private information to the extent it is collected and used as part of human subjects research pursuant to the ICH E6 Good Clinical Practice Guideline issued by the International Council for Harmonisati… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Human subjects research under ICH E6/FDA rules Archived excerpt — the text we read …290dd-2. (3) Identifiable private information, as defined in 45 C.F.R. § 46.102, to the extent that it is used for purposes of the federal policy for the protection of human subjects pursuant to 45 C.F.R. Part 46. (4) Identifiable private information to the extent it is collected and used as part of human subjects research pursuant to the ICH E6 Good Clinical Practice Guideline issued by the International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use or the protection of human subjects under 21 C.F.R. Parts 50 and 56. (5) Patient safety work product, as defined in 42 C.F.R. § 3.20, that is created and used for purposes of patient safety improvement pursuant to 42 C.F.R. Part 3, established pursuant to 42 U.S.C. §§ 299b-21 to 299b-26… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Patient safety work product Archived excerpt — the text we read …ood Clinical Practice Guideline issued by the International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use or the protection of human subjects under 21 C.F.R. Parts 50 and 56. (5) Patient safety work product, as defined in 42 C.F.R. § 3.20, that is created and used for purposes of patient safety improvement pursuant to 42 C.F.R. Part 3, established pursuant to 42 U.S.C. §§ 299b-21 to 299b-26. (6) Information to the extent it is used for public health, community health, or population health activities and purposes, as authorized by HIPAA, when provided by or to a covered entity or when provided by or to a bu… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Public/community/population health information When provided by or to a HIPAA covered entity or business associate. Archived excerpt — the text we read …atient safety work product, as defined in 42 C.F.R. § 3.20, that is created and used for purposes of patient safety improvement pursuant to 42 C.F.R. Part 3, established pursuant to 42 U.S.C. §§ 299b-21 to 299b-26. (6) Information to the extent it is used for public health, community health, or population health activities and purposes, as authorized by HIPAA, when provided by or to a covered entity or when provided by or to a business associate pursuant to a business associate agreement with a covered entity. (7) The collection, maintenance, disclosure, sale, communication, or use of any personal information bearing on a consumer’s credit worthiness, credit standing, credit capacity, character, general reputation, personal … Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • FCRA-regulated data Archived excerpt — the text we read …ation health activities and purposes, as authorized by HIPAA, when provided by or to a covered entity or when provided by or to a business associate pursuant to a business associate agreement with a covered entity. (7) The collection, maintenance, disclosure, sale, communication, or use of any personal information bearing on a consumer’s credit worthiness, credit standing, credit capacity, character, general reputation, personal characteristics, or mode of living by a consumer reporting agency, furnisher, or user that provides information for use in a consumer report, and by a user of a consumer report, but only to the extent that such activity is regulated by and authorized under the federal Fair Credit Reporting Act (15 U.S.C. § 1681, et seq., as amended). (8) Personal data collected, processed, sold, or disclosed in compliance with the Driver’s Privacy Protection Act of 1994, 18 U.S.C. § 2721, et seq., as amended. (9) Personal data regulated by the Family Educational R… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Driver's Privacy Protection Act data Archived excerpt — the text we read …n a consumer report, and by a user of a consumer report, but only to the extent that such activity is regulated by and authorized under the federal Fair Credit Reporting Act (15 U.S.C. § 1681, et seq., as amended). (8) Personal data collected, processed, sold, or disclosed in compliance with the Driver’s Privacy Protection Act of 1994, 18 U.S.C. § 2721, et seq., as amended. (9) Personal data regulated by the Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g, et seq., as amended. (10) Personal data collected, processed, sold, or disclosed in compliance with the Farm Credit Act,… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • FERPA-regulated data Archived excerpt — the text we read …orting Act (15 U.S.C. § 1681, et seq., as amended). (8) Personal data collected, processed, sold, or disclosed in compliance with the Driver’s Privacy Protection Act of 1994, 18 U.S.C. § 2721, et seq., as amended. (9) Personal data regulated by the Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g, et seq., as amended. (10) Personal data collected, processed, sold, or disclosed in compliance with the Farm Credit Act, 12 U.S.C. § 2001, et seq., as amended. (11) Data processed or maintained in any of the following ways: a. In the cou… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Farm Credit Act data Archived excerpt — the text we read …iance with the Driver’s Privacy Protection Act of 1994, 18 U.S.C. § 2721, et seq., as amended. (9) Personal data regulated by the Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g, et seq., as amended. (10) Personal data collected, processed, sold, or disclosed in compliance with the Farm Credit Act, 12 U.S.C. § 2001, et seq., as amended. (11) Data processed or maintained in any of the following ways: a. In the course of an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party, t… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Employment-context data Archived excerpt — the text we read …s amended. (10) Personal data collected, processed, sold, or disclosed in compliance with the Farm Credit Act, 12 U.S.C. § 2001, et seq., as amended. (11) Data processed or maintained in any of the following ways: a. In the course of an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent that the data is collected and used within the context of that role. b. As the emergency contact information of an individual, used for emergency contact purposes. c. Necessary to retain to administer benefits for another individual relating to the individual who is the subject of the … Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Emergency contact information Archived excerpt — the text we read … an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent that the data is collected and used within the context of that role. b. As the emergency contact information of an individual, used for emergency contact purposes. c. Necessary to retain to administer benefits for another individual relating to the individual who is the subject of the information under paragraph (c)(11)a. of this section and used for the purposes of administering… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Benefits administration data Archived excerpt — the text we read …ntroller, processor, or third party, to the extent that the data is collected and used within the context of that role. b. As the emergency contact information of an individual, used for emergency contact purposes. c. Necessary to retain to administer benefits for another individual relating to the individual who is the subject of the information under paragraph (c)(11)a. of this section and used for the purposes of administering such benefits. (12) Personal data collected, processed, sold, or disclosed in relation to price, route, or service, as such terms are used in the Airline Deregulation Act, 49 U.S.C. § 40101, et seq., as amended, by an air carrier sub… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Airline Deregulation Act preempted data Archived excerpt — the text we read …in to administer benefits for another individual relating to the individual who is the subject of the information under paragraph (c)(11)a. of this section and used for the purposes of administering such benefits. (12) Personal data collected, processed, sold, or disclosed in relation to price, route, or service, as such terms are used in the Airline Deregulation Act, 49 U.S.C. § 40101, et seq., as amended, by an air carrier subject to said act, to the extent any part of this chapter is preempted by the Airline Deregulation Act, 49 U.S.C. § 41713, as amended. (13) Personal data of a victim of or witness to child abuse, domestic violence, human trafficking, sexual assault, violent felony, or stalking that is collected, processed, or maintained by a nonprofit organization tha… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Victims of crime data held by nonprofits Archived excerpt — the text we read … Deregulation Act, 49 U.S.C. § 40101, et seq., as amended, by an air carrier subject to said act, to the extent any part of this chapter is preempted by the Airline Deregulation Act, 49 U.S.C. § 41713, as amended. (13) Personal data of a victim of or witness to child abuse, domestic violence, human trafficking, sexual assault, violent felony, or stalking that is collected, processed, or maintained by a nonprofit organization that provides services to victims of or witnesses to child abuse, domestic violence, human trafficking, sexual assault, violent felony, or stalking. (14) Data subject to Title V of the Gramm Leach Bliley Act (15 U.S.C. § 6801, et. seq., as amended) and the rules and implementing regulations promulgated thereunder. (d) Controllers and processors that comply with th… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • GLBA Title V data Archived excerpt — the text we read … collected, processed, or maintained by a nonprofit organization that provides services to victims of or witnesses to child abuse, domestic violence, human trafficking, sexual assault, violent felony, or stalking. (14) Data subject to Title V of the Gramm Leach Bliley Act (15 U.S.C. § 6801, et. seq., as amended) and the rules and implementing regulations promulgated thereunder. (d) Controllers and processors that comply with the verifiable parental consent requirements of COPPA shall be deemed compliant with any obligation to obtain parental consent set forth in this chapter with respect to a… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Evidentiary privilege (compliance would violate a Delaware evidentiary privilege) Archived excerpt — the text we read …ller, or are otherwise compatible with processing data in furtherance of the provision of a product or service specifically requested by a consumer or the performance of a contract to which the consumer is a party. (c) The obligations imposed on controllers or processors under this chapter shall not apply where compliance by the controller or processor with said sections would violate an evidentiary privilege under the laws of this State. Nothing in this chapter shall be construed to prevent a controller or processor from providing personal data concerning a consumer to a person covered by an evidentiary privilege under the laws of this State as part of… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Purely personal or household activity Archived excerpt — the text we read … adversely affects the rights of any person to freedom of speech or freedom of the press guaranteed in the First Amendment to the United States Constitution or § 5 of Article I of the Delaware Constitution of 1897. (2) Apply to any person’s processing of personal data in the course of such person’s purely personal or household activities. (f) Personal data processed pursuant to this section may be processed to the extent that such processing is reasonably necessary and proportionate to the purposes listed in this section, and is adequate, relevant, and… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • Privileged communications to a person covered by an evidentiary privilege Archived excerpt — the text we read …obligations imposed on controllers or processors under this chapter shall not apply where compliance by the controller or processor with said sections would violate an evidentiary privilege under the laws of this State. Nothing in this chapter shall be construed to prevent a controller or processor from providing personal data concerning a consumer to a person covered by an evidentiary privilege under the laws of this State as part of a privileged communication. (d) A controller or processor that discloses personal data to a processor or third-party controller in compliance with this chapter shall not be deemed to have violated this chapter if the processor or third-party cont… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source
  • First Amendment and Delaware Constitution free speech and press rights Archived excerpt — the text we read …r the independent misconduct of the controller or processor from which such third-party controller or processor receives such personal data. (e) Nothing in this chapter may be construed to do any of the following: (1) Impose any obligation on a controller or processor that adversely affects the rights of any person to freedom of speech or freedom of the press guaranteed in the First Amendment to the United States Constitution or § 5 of Article I of the Delaware Constitution of 1897. (2) Apply to any person’s processing of personal data in the course of such person’s purely personal or household activities. (f) Personal data processed pursuant to this section may be processed to the extent that su… Archived from source — captured 2026-09-29 · snapshot 5f0ab3d7 Verify at the source

Published Sep 30, 2026 from the DataGrail regulation engine; each fact links to its primary source.

Timeline

DPDPA milestones

This state currently has one dated milestone on the books.

Enforcement January 1, 2025

DPDPA took effect

Enforcement began — obligations have been live since this date.

Source: primary citation

Published Sep 30, 2026 from the DataGrail regulation engine; each fact links to its primary source. Reference only, not legal advice.

When staying on top of the law isn't enough, DataGrail automates the work.
DSR automation and regulatory tracking — handled by the platform behind this reference.
How DataGrail helps
Back to the Regulations Hub Reference only — not legal advice. Published Sep 30, 2026