iQ Cookie  State Law Series

State 6 of 25 · Delaware

Cookie & Privacy Law in Delaware

Published August 2026
Law in effect
Since January 1, 2025

Educational purposes only — not legal advice. This guide is intended to help you understand Delaware’s data privacy law as it relates to cookie consent and website compliance. Laws change, and your specific situation may vary. Always consult a qualified legal professional before making compliance decisions. iQ Cookie is a technology tool, not a law firm.

LAW
DPDPA
HB 154
SIGNED
Sep 11, 2023
Gov. John Carney
EFFECTIVE
Jan 1, 2025
In effect 18+ months
STATE RANK
#13
To enact a law

The short version

Delaware became the 13th state to pass a comprehensive privacy law, taking effect January 1, 2025. It follows the familiar Virginia/Connecticut model — but with the lowest consumer threshold of any state privacy law on the books. If you thought "35,000 consumers" sounded like a small-business exemption, in Delaware it is the entire bar for coverage.

Delaware does not have a separate cookie law. Cookie compliance flows from the DPDPA itself — its opt-out and sensitive-data rules apply directly to cookies and tracking technology.

Delaware Department of Justice — Official Resource
Delaware Personal Data Privacy Act, HB 154 — Personal Data Privacy Portal

Who does it apply to?

The DPDPA covers for-profit and nonprofit entities that conduct business in Delaware or target Delaware residents, and meet at least one of these thresholds:

THRESHOLD 1

Controls or processes personal data of 35,000 or more Delaware consumers during a calendar year — the lowest bar of any state law.

THRESHOLD 2

Controls or processes data of 10,000 or more consumers AND derives over 20% of gross revenue from selling personal data.

Nonprofits are covered, with a narrow exemption for organizations dedicated to preventing insurance crimes. GLBA and HIPAA-regulated data carry their usual exemptions.

Consumer rights

Delaware residents whose data is covered by the DPDPA have these rights:

Access
Confirm processing and receive a copy of their data
Correct
Fix inaccurate personal data
Delete
Including data sourced from third parties
Portability
Receive data in a usable, portable format
Know recipients
Get a list of third parties data was disclosed to
Opt out
Sale, targeted ads, and significant profiling

Businesses must respond within 45 days, extendable by another 45 if reasonably necessary. There is no private right of action — only the Delaware Department of Justice can enforce.

What makes Delaware different

The lowest threshold of any state privacy law. At 35,000 consumers with no revenue floor at all on that path, Delaware catches small and mid-sized sites that would clear the bar in almost every other state. Website traffic alone can trip this.

No cure period since January 2026. The original 60-day right-to-cure sunset December 31, 2025. The Delaware DOJ now has full discretion to enforce without offering advance notice or a chance to fix violations.

Universal opt-out mechanisms became mandatory January 1, 2026. Controllers must recognize Global Privacy Control and similar signals as valid opt-out requests — this obligation is now fully in force.

Broad opt-in protection for anyone under 18. Delaware sets its minors’ age bar higher than most states’ 13–16 range: opt-in consent is required before selling data or using it for targeted advertising for any known consumer under 18.

Data protection assessments required for higher-risk processing. Controllers must complete a DPA before activities presenting a heightened risk of harm — but the requirement only applies to processing that began at least six months after the law took effect, giving existing programs a grace window.

Sensitive data & children

Processing sensitive data requires opt-in consent before collection begins. Sensitive data includes:

Racial / ethnic origin
Religious beliefs
Mental / physical health conditions
Sexual activity / orientation
Transgender / nonbinary status
Citizenship / immigration status
Genetic data
Biometric data
Precise geolocation
Children’s data (under 13)

For known children under 13, COPPA-compliant parental consent satisfies the DPDPA. Processing any sensitive data of a known child requires opt-in consent as well. For teens 13–17, opt-in consent is required specifically before selling their data or using it for targeted advertising.

What this means for your cookies

Cookie typeRequirementWhat to do
Sensitive data cookies (health, geolocation, biometric)Opt-in requiredGate these behind affirmative consent before they fire.
Targeted advertising cookiesOpt-out requiredProvide a clear opt-out mechanism for sale and targeted ads.
GPC / universal opt-out signalRequired since Jan 2026Confirm your consent tool automatically honors the signal — this is now fully enforceable.
Any cookies — users under 18Opt-in requiredNo sale or targeted-ad cookies without consent for known minors under 18.
Analytics & functional cookiesNo specific requirementDisclose in your privacy policy. Confirm they are not building profiles that count as "sale."

Enforcement

$10,000
Max penalty per violation
None
Cure period sunset Dec 31, 2025
DOJ only
No private right of action

The Delaware Department of Justice has exclusive enforcement authority, with civil penalties up to $10,000 per violation plus injunctive relief, restitution, and disgorgement of profits. With the cure period now gone, businesses that would previously get a warning letter can face a filed action directly — especially given how easily the 35,000-consumer threshold catches mid-sized sites.

Your action checklist

The law is in effect now, with no cure period — here is what to check today:

1

Check your threshold carefully. 35,000 Delaware consumers is a low bar — run the numbers even if you assumed you were too small for state privacy law.

2

Confirm GPC recognition is live. This requirement is no longer upcoming — it has been enforceable since January 1, 2026. Test with a GPC-enabled browser.

3

Audit sensitive data cookies. Health, geolocation, biometric, and similar categories all require opt-in before collection.

4

Flag users under 18. Delaware’s minors protection extends further than most states — block sale and targeted-ad cookies for known users under 18 without opt-in.

5

Update your privacy policy. Cover data categories, purposes, third-party recipients, and how to exercise every consumer right.

6

Complete data protection assessments where required. Any high-risk processing activity that started more than six months after January 1, 2025 needs a documented DPA on file.

7

Review vendor contracts. Any processor handling Delaware resident data must be covered by a written agreement specifying processing instructions and confidentiality obligations.

Not sure where your site stands with Delaware?

iQ Cookie scans your site for compliance gaps and deploys a lightweight US-built consent banner.

iQ Cookie State Law Series  ·  Guide 6 of 25  ·  Next: Florida →