USPrivacyAtlasState Privacy & Data Security Law Matcher

State Guide

Delaware Privacy & Data Security Laws

Every statute below can apply to a business handling Delaware residents' data, depending on your revenue, the number of Delaware consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

Jan 1, 2025 (HB 380 amendments effective Jan 1, 2027)
Delaware Personal Data Privacy Act
DPDPA

Lower thresholds than most states: applies at 35,000+ Delaware consumers, or 10,000+ if 20%+ of revenue comes from selling personal data. Nonprofit exemption only covers insurance-fraud-prevention organizations — most nonprofits are covered. No entity-level HIPAA exemption — only specific health data (PHI, public-health/research data) is exempt, so HIPAA-covered entities/business associates remain subject to the DPDPA for other personal data they process. No higher-education exemption — the law's government-entity exemption expressly excludes institutions of higher education. HB 380 is now law — signed Sep 2, 2026, effective Jan 1, 2027 — and the thresholds shown here are only the ones in force until then. On Jan 1, 2027 the general threshold drops to 10,000 consumers and the sale-based threshold to 5,000 consumers with 20%+ of gross revenue from data sales, which the Governor's office describes as the lowest in the country, and a third trigger with no volume test at all reaches any third party that acquires personal data from a controller. The same amendment makes the GLBA carve-out a data-level exemption for all GLBA-regulated data while limiting entity-level exemptions to banks and insurers (and affiliates principally engaged in financial activities), expands sensitive data to include neural data, financial account credentials, government ID numbers and inferred sensitive characteristics, adds an opt-out of profiling used in significant automated decisions, narrows the employee-data exclusion for those decisions, and adds third-party contracting and due-diligence duties.

Del. Code tit. 6, § 12D-101 et seq., as amended by 2026 HB 380Read statute →

Data Security & Breach Notification · 1

Varies by state
Delaware data breach notification law
DE Breach Notification

Requires reasonable procedures and practices to protect personal information (§ 12B-100), plus notice to affected residents and — where more than 500 Delaware residents must be notified — to the Attorney General (§ 12B-102(d)). HB 381 (signed and effective Sep 2, 2026) clarified when that AG notice is owed and added a hard outer deadline: notice without unreasonable delay and no later than 60 days after determination of the breach. Applies regardless of company size whenever you hold covered personal information about a resident of this state.

Del. Code tit. 6, §§ 12B-100 to 12B-104, as amended by 2026 HB 381Read statute →