Back to the hub

Does Delaware's Personal Data Privacy Act apply to your business?

Delaware's Personal Data Privacy Act applies to businesses that operate in Delaware or target its residents and, in the prior year, controlled or processed personal data of at least 35,000 consumers, or at least 10,000 consumers while deriving more than 20 percent of gross revenue from selling personal data. Nonprofits and universities are not exempt.

Applies to: Businesses that conduct business in Delaware or target Delaware residents and meet either the 35,000-consumer threshold or the 10,000-consumer-plus-data-sales threshold, and that are not otherwise exempt.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

Delaware's Personal Data Privacy Act took effect on January 1, 2025. On paper it looks like the other state privacy laws, but two features make it reach further than most: low thresholds, and the absence of the nonprofit and university carve-outs that other states take for granted. A small organization that assumed it was too minor to worry about state privacy law should check Delaware carefully.

Who the Delaware Personal Data Privacy Act covers

Under 6 Del. C. 12D-103, the chapter applies to a person that conducts business in Delaware, or produces products or services targeted to Delaware residents, and that during the preceding calendar year either controlled or processed the personal data of at least 35,000 consumers, or controlled or processed the personal data of at least 10,000 consumers and derived more than 20 percent of gross revenue from the sale of personal data. Data controlled or processed only to complete a payment transaction is excluded from the 35,000 count. A consumer means a Delaware resident acting in a personal capacity.

Why the 10,000 prong matters

The second trigger is the lowest data-sales threshold in any US state privacy law. At 10,000 consumers and more than 20 percent of gross revenue from selling data, a small ad-supported app or data-driven service can be covered in Delaware while sitting well under the bar in larger states. If any real share of your revenue comes from selling personal data, run the numbers here first.

Who is carved out, and who is not

Section 12D-103(b) exempts Delaware government bodies, GLBA financial institutions and their affiliates, national securities associations, and nonprofits dedicated exclusively to preventing insurance crime. Two common exemptions are missing. There is no general nonprofit exemption, and institutions of higher education are expressly left out of the government carve-out. So a Delaware university or a typical charity that meets the thresholds is covered, which is not the case under Virginia or most other states.

What covered businesses owe

Covered controllers publish a clear privacy notice, honor consumer rights to access, correct, delete, and port data, and let consumers opt out of the sale of personal data, targeted advertising, and profiling that produces significant effects. Delaware recognizes universal opt-out signals and requires opt-in consent before processing sensitive data. Larger controllers, those handling at least 100,000 consumers, must also run data protection assessments. The 35,000 threshold matches the amended Connecticut Data Privacy Act and New Hampshire's Data Privacy Act; the Colorado Privacy Act sets out similar duties. Our privacy thresholds by state table and the US state privacy laws hub show how the numbers line up.

Next step

Delaware catches organizations that other state laws let through, so the safe move is to check rather than assume. The free 2-minute Obligation Scan runs the 12D-103 thresholds against your business and flags the notice, consent, and assessment duties that follow, so you spend your time on the obligations rather than the arithmetic.

Compliance checklist

  • Count the Delaware consumers whose personal data you controlled or processed last year, keeping the 35,000 and 10,000 figures in view; payment-only data does not count.
  • If you are near 10,000, work out whether more than 20 percent of your gross revenue comes from selling personal data, since that is the lowest data-sales trigger of any state.
  • If you are a nonprofit or a university, do not assume you are exempt; under 12D-103 you probably are not.
  • If covered, publish a privacy notice, honor consumer rights, and let consumers opt out of sale, targeted advertising, and profiling, including via a universal opt-out signal.
  • Get consent before processing sensitive data, and run data protection assessments for higher-risk processing.

Sources

Last verified: 2026-07-22

Informational, not legal advice.