iQ Cookie State Law Series
Cookie & Privacy Law in Delaware
Educational purposes only — not legal advice. This guide is intended to help you understand Delaware’s data privacy law as it relates to cookie consent and website compliance. Laws change, and your specific situation may vary. Always consult a qualified legal professional before making compliance decisions. iQ Cookie is a technology tool, not a law firm.
The short version
Delaware became the 13th state to pass a comprehensive privacy law, taking effect January 1, 2025. It follows the familiar Virginia/Connecticut model — but with the lowest consumer threshold of any state privacy law on the books. If you thought "35,000 consumers" sounded like a small-business exemption, in Delaware it is the entire bar for coverage.
Delaware does not have a separate cookie law. Cookie compliance flows from the DPDPA itself — its opt-out and sensitive-data rules apply directly to cookies and tracking technology.
Who does it apply to?
The DPDPA covers for-profit and nonprofit entities that conduct business in Delaware or target Delaware residents, and meet at least one of these thresholds:
Controls or processes personal data of 35,000 or more Delaware consumers during a calendar year — the lowest bar of any state law.
Controls or processes data of 10,000 or more consumers AND derives over 20% of gross revenue from selling personal data.
Nonprofits are covered, with a narrow exemption for organizations dedicated to preventing insurance crimes. GLBA and HIPAA-regulated data carry their usual exemptions.
Consumer rights
Delaware residents whose data is covered by the DPDPA have these rights:
Businesses must respond within 45 days, extendable by another 45 if reasonably necessary. There is no private right of action — only the Delaware Department of Justice can enforce.
What makes Delaware different
The lowest threshold of any state privacy law. At 35,000 consumers with no revenue floor at all on that path, Delaware catches small and mid-sized sites that would clear the bar in almost every other state. Website traffic alone can trip this.
No cure period since January 2026. The original 60-day right-to-cure sunset December 31, 2025. The Delaware DOJ now has full discretion to enforce without offering advance notice or a chance to fix violations.
Universal opt-out mechanisms became mandatory January 1, 2026. Controllers must recognize Global Privacy Control and similar signals as valid opt-out requests — this obligation is now fully in force.
Broad opt-in protection for anyone under 18. Delaware sets its minors’ age bar higher than most states’ 13–16 range: opt-in consent is required before selling data or using it for targeted advertising for any known consumer under 18.
Data protection assessments required for higher-risk processing. Controllers must complete a DPA before activities presenting a heightened risk of harm — but the requirement only applies to processing that began at least six months after the law took effect, giving existing programs a grace window.
Sensitive data & children
Processing sensitive data requires opt-in consent before collection begins. Sensitive data includes:
For known children under 13, COPPA-compliant parental consent satisfies the DPDPA. Processing any sensitive data of a known child requires opt-in consent as well. For teens 13–17, opt-in consent is required specifically before selling their data or using it for targeted advertising.
What this means for your cookies
| Cookie type | Requirement | What to do |
|---|---|---|
| Sensitive data cookies (health, geolocation, biometric) | Opt-in required | Gate these behind affirmative consent before they fire. |
| Targeted advertising cookies | Opt-out required | Provide a clear opt-out mechanism for sale and targeted ads. |
| GPC / universal opt-out signal | Required since Jan 2026 | Confirm your consent tool automatically honors the signal — this is now fully enforceable. |
| Any cookies — users under 18 | Opt-in required | No sale or targeted-ad cookies without consent for known minors under 18. |
| Analytics & functional cookies | No specific requirement | Disclose in your privacy policy. Confirm they are not building profiles that count as "sale." |
Enforcement
The Delaware Department of Justice has exclusive enforcement authority, with civil penalties up to $10,000 per violation plus injunctive relief, restitution, and disgorgement of profits. With the cure period now gone, businesses that would previously get a warning letter can face a filed action directly — especially given how easily the 35,000-consumer threshold catches mid-sized sites.
Your action checklist
The law is in effect now, with no cure period — here is what to check today:
Check your threshold carefully. 35,000 Delaware consumers is a low bar — run the numbers even if you assumed you were too small for state privacy law.
Confirm GPC recognition is live. This requirement is no longer upcoming — it has been enforceable since January 1, 2026. Test with a GPC-enabled browser.
Audit sensitive data cookies. Health, geolocation, biometric, and similar categories all require opt-in before collection.
Flag users under 18. Delaware’s minors protection extends further than most states — block sale and targeted-ad cookies for known users under 18 without opt-in.
Update your privacy policy. Cover data categories, purposes, third-party recipients, and how to exercise every consumer right.
Complete data protection assessments where required. Any high-risk processing activity that started more than six months after January 1, 2025 needs a documented DPA on file.
Review vendor contracts. Any processor handling Delaware resident data must be covered by a written agreement specifying processing instructions and confidentiality obligations.
iQ Cookie scans your site for compliance gaps and deploys a lightweight US-built consent banner.
iQ Cookie State Law Series · Guide 6 of 25 · Next: Florida →