Effective January 1, 2025

Delaware Personal Data Privacy Act (DPDPA)

A practical compliance guide for website owners. Learn what Delaware's privacy law requires and how to implement it on your site.

Who Must Comply

Conducts business in Delaware or targets Delaware residents AND controls/processes personal data of 35K+ consumers (excl. payment transactions), OR controls/processes data of 10K+ consumers and derives 20%+ of gross revenue from selling personal data

Consent model: Opt-outGPC RequiredSensitive data: Opt-in required

What Your Website Must Do

RequirementStatus
Cookie consent bannerRecommended
Do Not Sell linkRequired
Do Not Share linkRequired
Honor GPC browser signalsRequired
Universal opt-out mechanismRequired
Sensitive data opt-in consentRequired

Checked against the DPDPA on August 29, 2026. Read the source This is a summary, not legal advice.

Required Links & Notices

The DPDPA requires the following links or notices to be visible on your website:

  • 1Do Not Sell or Share My Personal Data
  • 2Privacy Policy

Enforcement & Penalties

Enforcement Body
Delaware Attorney General + Department of Justice
Maximum Penalty
$10,000 per violation. 60-day cure period (sunset December 2025).

Key Things to Know

The Delaware Personal Data Privacy Act (DPDPA) has applied in Delaware since January 1, 2025.

Who it covers: Conducts business in Delaware or targets Delaware residents AND controls/processes personal data of 35K+ consumers (excl. payment transactions), OR controls/processes data of 10K+ consumers and derives 20%+ of gross revenue from selling personal data.

Do Not Sell and opt-out rights: residents may opt out of the sale of their personal data and opt out of targeted advertising. DPDPA expects the choice to be reachable from your site under the heading “Do Not Sell or Share My Personal Data”, and you may not degrade the service of someone who exercises it.

Global Privacy Control: DPDPA requires you to honour a universal opt-out mechanism sent by the visitor’s browser. A GPC signal has to be treated as the opt-out itself — not as a request to show someone a banner — and it applies to that browser without any further action from the person.

Cookie banner: DPDPA is an opt-out law, so it does not require the opt-in banner the GDPR does. What it does require is that the tracking you run for advertising can be switched off on request, which in practice means a preference control that actually blocks tags rather than a notice that only records a click. Sensitive data is the exception: that needs consent before you process it.

Enforcement: $10,000 per violation. 60-day cure period (sunset December 2025). Enforced by the Delaware Attorney General + Department of Justice.

How to Configure LegalBanner for DPDPA

  1. 1

    Create your site

    Sign up for free and add your website domain in the dashboard.

  2. 2

    Set consent mode to "Opt-out"

    In Settings, select the consent mode that matches Delaware's requirements.

  3. 3

    Install the snippet

    Add the one-line script tag to your website. The banner, opt-out links, and GPC support are automatic.

  4. 4

    Generate your Privacy Policy

    Use the built-in policy wizard to generate a DPDPA-compliant privacy policy.

Set up DPDPA compliance in 5 minutes

LegalBanner handles Delaware privacy requirements automatically — cookie banner, opt-out links, and GPC support included.

Frequently Asked Questions

When did the Delaware DPDPA take effect?

The DPDPA took effect January 1, 2025.

What are the thresholds for the Delaware law?

35,000+ consumers (excluding payment transactions) or 10,000+ consumers with 20%+ revenue from data sales. These are among the lowest thresholds nationally.

Does Delaware cover data 'sharing' in addition to 'selling'?

Yes. Delaware covers both sale and sharing of personal data, similar to California. This broader scope means more data practices are covered.

Does Delaware require honoring GPC signals?

The DPDPA does not currently require honoring GPC signals, but implementing GPC support is recommended.

What are the penalties for DPDPA violations?

Up to $10,000 per violation. The 60-day cure period sunsets in December 2025, after which the AG can take direct enforcement action.

Disclaimer: This page provides practical implementation guidance only. It does not constitute legal advice. The information is current as of the most recent review date but privacy laws change frequently. Consult a qualified attorney for legal advice specific to your situation. LegalBanner provides compliance tools, not legal counsel.