Delaware Personal Data Privacy Act (6 Del. C. ch. 12D)
Below is what the official text of Delaware Personal Data Privacy Act (6 Del. C. ch. 12D) states about whom it covers, when it applies to a business and since when. Where the pages we read do not say, the row says "not stated".
The wording shown is taken from the official page named in each row. The duties of a business and the contents of a privacy notice are in the paid checklist.
Typical situations, run through the same conditions as the check
- A for-profit US business with 150,000 people in Delaware and $30 million revenue: Applies, or may apply: conditions to check.
- The same business with 8,000 people in Delaware: Not triggered by these answers.
- A US business with no users in Delaware: Not triggered by these answers.
Judged on 2026-10-06. Our law data was last verified on 2026-10-06; a law that took effect after that date is not in it. These situations leave other answers blank or neutral: use the check for your own.
What the official text states
| Question | What the official text states | Source |
|---|---|---|
| What it covers | Chapter 12D binds persons that conduct business in Delaware or produce products or services targeted to Delaware residents and that meet stated thresholds for controlling or processing consumers' personal data.Official wording(a) This chapter applies to persons that conduct business in the State or persons that produce products or services that are targeted to residents of the State and that during the preceding calendar year did any of the following: | delcode.delaware.gov read 2026-10-06 |
| When it applies to a business | Currently (version effective until Jan. 1, 2027) applies to persons conducting business in Delaware or targeting Delaware residents that in the preceding calendar year controlled or processed personal data of at least 35,000 consumers (excluding payment-transaction-only data), or at least 10,000 consumers while deriving more than 20% of gross revenue from the sale of personal data. Conditions to check: The Code shows a second version 'Effective Jan. 1, 2027' with lower thresholds: at least 10,000 consumers, or at least 5,000 consumers with more than 20% of gross revenue from sale, plus third parties that acquire personal data from a controller; the test we run reflects only the version in force until Jan. 1, 2027. Thresholds are measured over the preceding calendar year. Entity exemptions in 12D-103(b) (not covered by our questions): state and local government bodies (but not institutions of higher education), financial institutions subject to GLBA (to be replaced from 2027 by banks, credit unions, insurers, certain investment professionals), a nonprofit dedicated exclusively to preventing and addressing insurance crime, securities/futures associations; many data categories (e.g. HIPAA PHI) are exempt. Only that one narrow nonprofit is exempt, not nonprofits generally. Official wording(1) Controlled or processed the personal data of not less than 35,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction. (2) Controlled or processed the personal data of not less than 10,000 consumers and derived more than 20% of their gross revenue from the sale of personal data. | delcode.delaware.gov read 2026-10-06 |
| In force from | 2025-01-01 Laws of Delaware vol. 84 ch. 197 section 3: if enacted on or before January 1, 2024, takes effect January 1, 2025 (the Act was approved September 11, 2023). The Code shows later amendments effective January 1, 2027 (including lower applicability thresholds). Official wordingIf this Act is enacted before or on January 1, 2024, this Act takes effect on January 1, 2025. | legis.delaware.gov read 2026-10-06 |
| Privacy notice | Included in the paid checklist. See the checklist | — |
| Consent and opt-out | Included in the paid checklist. See the checklist | — |
| Rights of individuals | Included in the paid checklist. See the checklist | — |
| Data protection officer | Not stated on the official pages we read. the text we read does not say whether a data protection officer must be appointed | — |
| Breach notification | Not stated on the official pages we read. separate breach-notification statute not read | — |
| What the privacy notice must contain | Included in the paid checklist. See the checklist | — |
What we do not cover
These areas are outside this site, so nothing on this page says anything about them:
- Privacy laws for particular sectors (for example health care, banking and credit, education)
- Rules specific to children's online privacy
- Cookie and electronic-communications rules (including consent for cookies and marketing messages)
- Employee, job applicant and contractor data
- Rules on sending personal data to other countries
- US state data-breach notification laws (a separate set of state laws)
- US state privacy laws that are not yet in force, and state laws on particular topics (for example biometric or health data)
- Privacy laws of countries that are not listed here
- Planned changes to the laws listed here