#
Core instrument is fully in force with a clear, functioning regulator and well-documented material/territorial scope; amber-adjacent risk only from the unconfirmed pending amendment tracked separately in enforcement_and_redress.
Sub-modules (5)
Regulator And AuthorityGreen
Enforcement authority sits with the Delaware DOJ/Attorney General's Consumer Protection Unit; there is no dedicated privacy regulator or rulemaking agency.
Claims (1):
- The Delaware Personal Data Privacy Act (DPDPA) took effect on January 1, 2025, and is enforced by the Delaware Department of Justice.
Act And InstrumentsGreen
The DPDPA is the sole omnibus instrument; a separate long-standing Delaware breach-notification statute (6 Del. C. §12B) operates alongside it.
Claims (1):
- The Delaware Personal Data Privacy Act (DPDPA) took effect on January 1, 2025, and is enforced by the Delaware Department of Justice.
Material ScopeGreen
Material scope is defined by consumer-count/revenue thresholds and a broad personal-data definition, with sectoral exemptions.
Claims (2):
- The DPDPA applies to persons conducting business in or targeting Delaware residents that, in the preceding calendar year, controlled or processed the personal data of 35,000 or more consumers, or 10,000 or more consumers while deriving more than 20% of gross revenue from selling personal data.
- The DPDPA does not apply to personal data maintained in compliance with the Gramm-Leach-Bliley Act, HIPAA, or the Fair Credit Reporting Act, nor to certain data processed for specified exempt purposes.
Territorial ScopeGreen
The Act reaches any entity, regardless of domicile, that targets Delaware residents or conducts business in the state and meets the threshold; the AG has indicated it will pursue out-of-state controllers meeting the threshold.
Claims (1):
- The Attorney General has stated it will not hesitate to pursue enforcement against out-of-state third parties doing business in Delaware if they meet the DPDPA's applicability threshold.
Regulator Registration And FilingAmber
No controller registration/filing regime with the Attorney General was identified; compliance is self-assessed against statutory thresholds.
Claims (1):
- No controller registration or filing obligation with the Delaware Attorney General was located within the DPDPA or AG guidance; compliance appears self-assessed.
no periodic updates on record for this sub-brief
Sources and claims (5)
- ProbableState of Delaware — The Delaware Personal Data Privacy Act (DPDPA) took effect on January 1, 2025, and is enforced by the Delaware Department of Justice.observed
- ProbableDataGuidance — The DPDPA applies to persons conducting business in or targeting Delaware residents that, in the preceding calendar year, controlled or processed the personal data of 35,000 or more consumers, or 10,000 or more consumers while deriving more than 20% of gross revenue from selling personal data.observed
- ProbableState of Delaware — The DPDPA does not apply to personal data maintained in compliance with the Gramm-Leach-Bliley Act, HIPAA, or the Fair Credit Reporting Act, nor to certain data processed for specified exempt purposes.observed
- ProbableState of Delaware — The Attorney General has stated it will not hesitate to pursue enforcement against out-of-state third parties doing business in Delaware if they meet the DPDPA's applicability threshold.observed
- ProbableState of Delaware — No controller registration or filing obligation with the Delaware Attorney General was located within the DPDPA or AG guidance; compliance appears self-assessed.observed