# Delaware — US state consumer data privacy laws: applicability thresholds by state For Delaware, law name and abbreviation is Delaware Personal Data Privacy Act (DPDPA); effective date is January 1, 2025; consumer volume threshold is Controlled or processed the personal data of not less than 35,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; revenue-from-data-sales threshold is Controlled or processed the personal data of not less than 10,000 consumers and derived more than 20% of their gross revenue from the sale of personal data; threshold combination logic is OR — during the preceding calendar year did any of the following, recorded from its source on 2026-08-12. - **State:** Delaware _(our reading, not quoted from the source)_ - **Law name and abbreviation:** Delaware Personal Data Privacy Act (DPDPA) - **Effective date:** January 1, 2025 - **Consumer volume threshold:** Controlled or processed the personal data of not less than 35,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction _(verified: appears in the quote below)_ - **Revenue-from-data-sales threshold:** Controlled or processed the personal data of not less than 10,000 consumers and derived more than 20% of their gross revenue from the sale of personal data _(verified: appears in the quote below)_ - **Threshold combination logic:** OR — during the preceding calendar year did any of the following _(verified: appears in the quote below)_ - **Key exemptions:** State and political subdivision bodies (excluding institutions of higher education); GLBA-regulated financial institutions; national securities associations; nonprofit organizations dedicated to preventing insurance crime - **Enforcement mechanism:** Attorney General (Department of Justice); 60-day cure period (expires December 31, 2025); no private right of action - **Statute citation:** Del. Code Ann. tit. 6, ch. 12D - **Notes:** Delaware has relatively low thresholds: 35,000 consumers (excl. payment data) or 10,000 consumers with 20% revenue from data sales. Unlike many states, Delaware does not broadly exempt all nonprofits — only nonprofits dedicated to preventing insurance crime are exempt. Institutions of higher education are NOT exempt. ## What the source says > This chapter applies to persons that conduct business in the State or persons that produce products or services that are targeted to residents of the State and that during the preceding calendar year did any of the following: (1) Controlled or processed the personal data of not less than 35,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction. (2) Controlled or processed the personal data of not less than 10,000 consumers and derived more than 20% of their gross revenue from the sale of personal data. ## Source - https://delcode.delaware.gov/title6/c012d/index.html Last verified: 2026-08-12. Review by: 2026-11-10. Part of [US state consumer data privacy laws: applicability thresholds by state](https://referencesource.org/state-data-privacy-applicability-thresholds/).