Womble Perspectives

Delaware Becomes 12th US State to Enact Comprehensive Data Privacy Law

Womble Bond Dickinson

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 3:40

Today's episode is a quick rundown of the Delaware Personal Data Privacy Act and some of the requirements listed therein.

Read the full article

About the authors
Tara N. Cho, CIPP/US, CIPP/E
Theodore F. Claypoole
Katie Hyman, CIPP/E, CIPP/US, CIPM
Nadia G. Aram
Taylor Ey, CIPP/US, CIPP/E
Christine Xiao, CIPP/US
Tyler Connor, CIPP/US
Ting Zheng, CIPP/US

Welcome to Womble Perspectives, where we explore a wide range of topics, from the latest legal updates to industry trends to the business of law. Our team of lawyers, professionals and occasional outside guests will take you through the most pressing issues facing businesses today and provide practical and actionable advice to help you navigate the ever changing legal landscape.

With a focus on innovation, collaboration and client service. We are committed to delivering exceptional value to our clients and to the communities we serve. And now our latest episode.

Welcome back and thank you for joining us for Womble Perspectives. Today’s episode is a quick rundown of some of the requirements in Delaware’s new data privacy law.

 Delaware is the twelfth state to enact a comprehensive data privacy law, and The Delaware Personal Data Privacy Act (DPDPA) takes effect on January 1, 2025. 

 Delaware’s Act generally followed the Connecticut model, but has some unique terms. A non-exhaustive list of some of Delaware’s requirements follows.

 The DPDPA has a lower threshold for application and no categorical exemption for all nonprofits. The Act applies to organizations that control or process personal data of 35,000 or more Delaware residents in a given year, or organizations that control or process personal data of 10,000 or more Delaware residents and derive more than 20% of their gross revenue from the sale of personal data. Like states other than California, the DPDPA will only apply to personal data processed for a personal or household purpose. That is, not in the employment context or in a commercial context. Nonprofits are not categorically exempt from the DPDPA unless dedicated exclusively to preventing and addressing insurance crime.

 The Act also has A broader definition of sensitive personal data. Sensitive data under the DPDPA includes “status as transgender or nonbinary” and “mental or physical health condition or diagnosis including pregnancy.”

 In addition, The law provides Protection for teens. Entities subject to the DPDPA cannot, without consent, sell or process for targeted advertising purposes the data of consumers that the entity knows, or willfully disregards, that the individual is between the ages of 13 to 18.

 Next up: Additional data access rights. The DPDPA gives Delaware residents the specific right to “obtain a list of the categories of third parties to whom the controller has disclosed the consumer’s personal data.” This is similar to one part of California’s right to know about categories of information.

 The act also includes a Right to cure with sunset. The DPDPA provides a 60-day cure period for violations, which sunsets on December 31, 2025.

 Finally, we come to No private right of action. The DPDPA contains no private right of action; it will be exclusively enforced by the Delaware Department of Justice.

 That’s it for today’s episode. Thank you for joining us for a quick rundown of some of the requirements of the Delaware Personal Data Privacy Act.

Thank you for listening to Womble Perspectives. If you want to learn more about the topics discussed in this episode, please visit The Show Notes, where you can find links to related resources mentioned today. The Show Notes also have more information about our attorneys who provided today's insights, including ways to reach out to them.

Don't forget to subscribe via your podcast player of choice so that you never miss an episode. Thank you again for listening.