Obtainer
Use case

Delaware Personal Data Privacy Act (DPDPA) Compliance: 35,000 Consumers, 45 Days, No Cure Period

The Delaware Personal Data Privacy Act has the lowest consumer threshold of any comprehensive state privacy law: 35,000 Delaware residents, and no revenue floor at all. A verified request starts a 45-day clock, the cure period expired on January 1, 2026, and HB 380 would cut the threshold to 15,000 if signed. Obtainer finds where a person's data lives across your systems, compiles one reviewable manifest, drafts the response, and tracks the deadline.

See how it works
Discovery across your systems Human redaction gate Helps you comply, not legal advice
Request Studio
Requester
Compiled the manifest and drafted the response - illustrative sample request
0
records found
0
systems scanned
Data manifest
Response draft

Assembling the cover letter from the template...

You approve what is disclosed before anything ships

Helps you comply, not legal advice

In short

The Delaware Personal Data Privacy Act (DPDPA) took effect January 1, 2025. It applies to a controller that conducts business in Delaware or targets Delaware residents and, in the preceding calendar year, either controlled or processed the personal data of at least 35,000 Delaware consumers, excluding data used solely to complete a payment transaction, or controlled or processed the data of at least 10,000 consumers while deriving more than 20 percent of gross revenue from selling personal data. Delaware sets no revenue floor, and 35,000 is the lowest headcount threshold among the comprehensive state laws, which matters because Delaware's population is small: a consumer app with national reach can cross it without ever thinking about Delaware. The law is also unusual in covering many nonprofits and higher education institutions that other states exempt. Delaware consumers can confirm and access their personal data, correct inaccuracies, delete it, obtain a portable copy, get a list of the categories of third parties the controller has disclosed their data to, and opt out of sale, targeted advertising, and profiling. You generally must respond within 45 days, extendable once by another 45 days with notice, with a 60-day appeal window on denials. Universal opt-out signals such as Global Privacy Control have been mandatory since January 1, 2026. The 60-day right to cure expired on December 31, 2025, so from January 1, 2026 the Delaware Department of Justice decides on its own whether to offer one. Civil penalties reach $10,000 per violation, and the department can also seek injunctive relief, restitution, and disgorgement. Watch HB 380: the General Assembly passed it on June 16, 2026, and if the governor signs it, the threshold drops from 35,000 to 15,000 consumers on January 1, 2027, along with expanded sensitive-data definitions and new third-party due diligence duties. Obtainer handles the operational side: intake, discovery of where the person's data lives, a source-system manifest, a drafted deadline-safe response, and 45-day tracking. Nothing is disclosed or erased automatically; a human reviews, redacts, and approves. Obtainer helps you comply. It is not legal advice, so scope and exemption calls stay with your team. Self-serve from $49/mo.

// THE FIT

Why it fits

Delaware businesses, nonprofits, and higher education institutions, plus any national SaaS, ecommerce, or consumer app that crosses 35,000 Delaware residents, which is a far lower bar than the 100,000-consumer thresholds in most other states.

The lowest threshold in the country, and it may drop again

Thirty-five thousand Delaware consumers with no revenue floor is the easiest comprehensive state privacy law to fall under, and Delaware's small population means the percentage of your user base that trips it is tiny. HB 380 passed the General Assembly on June 16, 2026 and would cut that to 15,000 effective January 1, 2027 if signed. Companies that ruled Delaware out on volume should recount.

No cure period since January 2026

The DPDPA's 60-day right to cure expired on December 31, 2025. Since January 1, 2026 the Delaware Department of Justice can act without offering you a chance to fix the problem first, and penalties reach $10,000 per violation alongside injunctive relief, restitution, and disgorgement. The first missed 45-day deadline is now the violation rather than a warning.

Nonprofits and universities are in scope

Most state privacy laws exempt nonprofits outright. Delaware does not: it covers nonprofits with only narrow carve-outs, and it covers institutions of higher education for a subset of obligations. If you run a university, an association, or a nonprofit that assumed state privacy law did not reach you, Delaware and Oregon are the two that do, and both expect a real request workflow.

// FAQ

Questions

Common questions about this

Who must comply with the Delaware Personal Data Privacy Act?

A controller doing business in Delaware or targeting Delaware residents that, in the preceding calendar year, processed the personal data of at least 35,000 Delaware consumers, excluding payment-transaction-only data, or processed the data of at least 10,000 consumers while deriving more than 20 percent of gross revenue from selling personal data. There is no revenue threshold, and unlike most states, many nonprofits and higher education institutions are covered rather than exempt.

Does Delaware still have a cure period?

No. The DPDPA gave controllers a 60-day right to cure through December 31, 2025. Since January 1, 2026 the Delaware Department of Justice has full discretion over whether to offer an opportunity to cure before enforcing, so it is no longer something you can rely on. Civil penalties reach $10,000 per violation, and the department can also seek injunctive relief, restitution, and disgorgement.

What is Delaware HB 380 and when does it take effect?

HB 380 is an amendment to the DPDPA that the Delaware General Assembly passed on June 16, 2026. If the governor signs it, the changes take effect January 1, 2027. It lowers the applicability threshold from 35,000 to 15,000 consumers, expands sensitive data to include neural data, government identification numbers, and financial account credentials, requires reasonable due diligence on third parties receiving personal data, and narrows the financial institution exemption to banks, insurers, and their affiliates.

How long do I have to respond to a Delaware data subject request?

Forty-five days from receipt of a verified request, extendable once by another 45 days when reasonably necessary if you notify the consumer of the extension and the reason inside the original window. If you deny a request you must explain why and provide an appeal mechanism, and you have 60 days to respond to the appeal. That matches the 45-day standard used by eighteen of the twenty comprehensive state privacy laws, with Iowa at 90 days and Florida capping its extension at 15.

Run a data subject access request end to end

Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.