Delaware Personal Data Privacy Act Privacy Notice
DELAWARE PERSONAL DATA PRIVACY ACT (DPDPA) PRIVACY NOTICE
Effective Date: [DATE]
Last Updated: [DATE]
NOTICE TO DELAWARE RESIDENTS
This Privacy Notice is provided pursuant to the Delaware Personal Data Privacy Act, codified at Delaware Code Title 6, Chapter 12D, which became effective January 1, 2025.
1. SCOPE AND APPLICABILITY
1.1 Who This Notice Applies To
This Notice applies to Delaware residents acting in an individual or household context ("consumers"). It does not apply to individuals acting in a commercial or employment context.
1.2 Applicability Thresholds
Pursuant to Del. Code Section 12D-103(a), this Notice applies because [COMPANY NAME]:
☐ Controls or processes personal data of at least 35,000 Delaware consumers (excluding data processed solely for payment transactions)
☐ Controls or processes personal data of more than 10,000 Delaware consumers AND derives more than 20% of gross revenue from the sale of personal data
1.3 Unique Inclusion of Nonprofits and Higher Education
Important: Unlike most other state privacy laws, the DPDPA applies to:
☐ Nonprofit organizations
☐ Institutions of higher education
1.4 Exemptions
Pursuant to Del. Code Section 12D-103(b), the following are exempt:
- State and local government bodies
- Financial institutions subject to GLBA
- Covered entities and business associates under HIPAA
- Data regulated by specific federal laws (GLBA, HIPAA, FCRA, FERPA, COPPA, DPPA)
2. DEFINITIONS
Pursuant to Del. Code Section 12D-102:
"Personal Data" means any information that is linked or reasonably linkable to an identified or identifiable individual, excluding de-identified data and publicly available information.
"Sensitive Data" includes personal data revealing:
- Racial or ethnic origin
- Religious beliefs
- Mental or physical health condition, treatment, or diagnosis
- Sex life or sexual orientation
- Citizenship or citizenship status
- Status as transgender or nonbinary
- Genetic or biometric data for identification purposes
- Personal data collected from a known child
- Precise geolocation data
"Sale" means the exchange of personal data for monetary or other valuable consideration.
"Targeted Advertising" means displaying advertisements based on personal data obtained from consumer's activities over time and across nonaffiliated websites or applications.
"Profiling" means any form of automated processing to evaluate, analyze, or predict aspects concerning a natural person.
3. CATEGORIES OF PERSONAL DATA PROCESSED
Pursuant to Del. Code Section 12D-106(a)(1), we process the following categories of personal data:
3.1 General Personal Data
| Category | Examples | Collected | Purpose |
|---|---|---|---|
| Identifiers | Name, email, phone number, account ID | ☐ Yes ☐ No | [PURPOSE] |
| Contact Information | Postal address, email, phone | ☐ Yes ☐ No | [PURPOSE] |
| Demographic Information | Age, gender, language preferences | ☐ Yes ☐ No | [PURPOSE] |
| Commercial Information | Purchase history, transaction records | ☐ Yes ☐ No | [PURPOSE] |
| Internet Activity | Browsing history, search history, interactions | ☐ Yes ☐ No | [PURPOSE] |
| Geolocation Data | General location (non-precise) | ☐ Yes ☐ No | [PURPOSE] |
| Professional Information | Employment, job title | ☐ Yes ☐ No | [PURPOSE] |
| Education Information | Educational background | ☐ Yes ☐ No | [PURPOSE] |
| Inferences | Preferences, characteristics, behaviors | ☐ Yes ☐ No | [PURPOSE] |
3.2 Sensitive Data
Pursuant to Del. Code Section 12D-106(a)(5), we collect sensitive data only with your consent:
| Sensitive Category | Collected | Consent Obtained | Purpose |
|---|---|---|---|
| Racial or ethnic origin | ☐ Yes ☐ No | ☐ Yes | [PURPOSE] |
| Religious beliefs | ☐ Yes ☐ No | ☐ Yes | [PURPOSE] |
| Mental or physical health condition | ☐ Yes ☐ No | ☐ Yes | [PURPOSE] |
| Sex life or sexual orientation | ☐ Yes ☐ No | ☐ Yes | [PURPOSE] |
| Citizenship or citizenship status | ☐ Yes ☐ No | ☐ Yes | [PURPOSE] |
| Transgender or nonbinary status | ☐ Yes ☐ No | ☐ Yes | [PURPOSE] |
| Genetic data | ☐ Yes ☐ No | ☐ Yes | [PURPOSE] |
| Biometric data | ☐ Yes ☐ No | ☐ Yes | [PURPOSE] |
| Data from known child | ☐ Yes ☐ No | ☐ Yes | [PURPOSE] |
| Precise geolocation data | ☐ Yes ☐ No | ☐ Yes | [PURPOSE] |
4. PURPOSES OF PROCESSING
Pursuant to Del. Code Section 12D-106(a)(2), we process personal data for:
☐ Providing and maintaining our services
☐ Processing transactions and orders
☐ Communicating with you about your account
☐ Customer support and inquiries
☐ Security and fraud prevention
☐ Legal compliance
☐ Research and analytics
☐ Marketing and promotional communications
☐ Personalization of services
☐ Targeted advertising (subject to opt-out)
☐ [ADDITIONAL PURPOSES]
5. SALE OF PERSONAL DATA AND TARGETED ADVERTISING
5.1 Sale of Personal Data
Pursuant to Del. Code Section 12D-104(a)(5):
☐ We sell personal data
☐ We do not sell personal data
Categories of Data Sold:
| Category | Third Party Recipients | Purpose |
|---|---|---|
| [CATEGORY] | [RECIPIENTS] | [PURPOSE] |
5.2 Targeted Advertising
Pursuant to Del. Code Section 12D-104(a)(4):
☐ We process personal data for targeted advertising
☐ We do not process personal data for targeted advertising
5.3 Profiling
Pursuant to Del. Code Section 12D-104(a)(6):
☐ We engage in profiling that produces legal or similarly significant effects
☐ We do not engage in such profiling
6. THIRD-PARTY DISCLOSURES
Pursuant to Del. Code Section 12D-106(a)(3-4), we share personal data with:
| Third Party Category | Categories of Data | Purpose |
|---|---|---|
| Service Providers | [CATEGORIES] | Processing on our behalf |
| Business Partners | [CATEGORIES] | [PURPOSE] |
| Advertising Partners | [CATEGORIES] | Targeted advertising |
| Analytics Providers | [CATEGORIES] | Analytics services |
| Payment Processors | [CATEGORIES] | Transaction processing |
| Government Entities | [CATEGORIES] | Legal compliance |
7. YOUR DELAWARE PRIVACY RIGHTS
Pursuant to Del. Code Section 12D-104, Delaware consumers have the following rights:
7.1 Right to Know/Access (Section 12D-104(a)(1))
You have the right to confirm whether we are processing your personal data and to access such data.
7.2 Right to Correct (Section 12D-104(a)(2))
You have the right to correct inaccuracies in your personal data.
7.3 Right to Delete (Section 12D-104(a)(3))
You have the right to delete personal data provided by or obtained about you.
7.4 Right to Data Portability (Section 12D-104(a)(7))
You have the right to obtain a copy of your personal data in a portable and, to the extent technically feasible, readily usable format.
7.5 Right to List of Third Parties (Delaware-Specific)
You have the right to obtain a list of the categories of third parties to whom we have disclosed your personal data.
7.6 Right to Opt Out (Section 12D-104(a)(4-6))
You have the right to opt out of:
- Targeted advertising
- Sale of personal data
- Profiling in furtherance of decisions that produce legal or similarly significant effects
8. EXERCISING YOUR RIGHTS
8.1 How to Submit a Request
Methods to Submit Requests:
☐ Online Portal: [URL]
☐ Email: [PRIVACY EMAIL]
☐ Phone: [PHONE NUMBER]
☐ Mail: [MAILING ADDRESS]
8.2 Identity Verification
We will authenticate your identity before fulfilling your request using commercially reasonable methods.
8.3 Authorized Agents
You may designate an authorized agent to submit requests on your behalf. We may require:
- Written authorization signed by you
- Verification of your identity
- Verification of the agent's authority
8.4 Response Timeline
Pursuant to Del. Code Section 12D-104(b):
- Initial Response: Within 45 days of receipt
- Extension: May extend by an additional 45 days when reasonably necessary
- Notification: We will inform you of any extension and the reason
8.5 No Fee
We provide responses free of charge. We may charge a reasonable fee for manifestly unfounded, excessive, or repetitive requests.
9. UNIVERSAL OPT-OUT MECHANISMS (EFFECTIVE JANUARY 1, 2026)
9.1 Recognition of Opt-Out Preference Signals
Pursuant to Del. Code Section 12D-104, effective January 1, 2026, we recognize and process universal opt-out mechanisms including:
☐ Global Privacy Control (GPC)
☐ Other Universal Opt-Out Mechanisms: [SPECIFY]
9.2 How Universal Opt-Out Requests Are Processed
When we receive a universal opt-out signal, we will:
- Process it as a valid opt-out request for targeted advertising and sale of personal data
- Apply the opt-out to the browser or device from which the signal was sent
- Not require you to verify your identity for opt-out requests
9.3 Opt-Out Link
"Your Privacy Choices" Link: [URL]
10. RIGHT TO APPEAL
10.1 Appeal Process
Pursuant to Del. Code Section 12D-104(c), if we decline your request, you have the right to appeal.
To Submit an Appeal:
☐ Email: [APPEAL EMAIL]
☐ Online Form: [URL]
☐ Mail: [ADDRESS]
10.2 Appeal Response
- We will respond to your appeal within 60 days
- If we deny your appeal, we will provide a method to contact the Delaware Department of Justice
10.3 Contact the Attorney General
Delaware Department of Justice
Consumer Protection Unit
820 N. French Street
Wilmington, DE 19801
Email: [email protected]
Website: attorneygeneral.delaware.gov
11. CURE PERIOD
11.1 Before December 31, 2025
Pursuant to Del. Code Section 12D-111(b), we may receive a 60-day notice and opportunity to cure alleged violations.
11.2 After December 31, 2025
The mandatory 60-day cure period expires December 31, 2025. After this date, granting a cure period is at the discretion of the Delaware Department of Justice.
12. MINOR PROTECTIONS
12.1 Children Under 13
We comply with COPPA and obtain verifiable parental consent before collecting personal data from children under 13.
12.2 Minors 13-17
Pursuant to Del. Code Section 12D-106(a)(6):
For minors between 13 and 17 years of age, we obtain consent before:
☐ Processing personal data for targeted advertising
☐ Selling personal data
12.3 Definition of Minor
A "minor" means an individual under 18 years of age.
13. DATA PROTECTION ASSESSMENTS
13.1 Assessment Requirements (Effective July 1, 2025)
Pursuant to Del. Code Section 12D-108(a), effective July 1, 2025, we conduct data protection assessments for controllers processing data for 100,000 or more consumers if their data activities pose heightened consumer risks.
13.2 Heightened Risk Activities
Data protection assessments are required for:
☐ Processing for targeted advertising
☐ Sale of personal data
☐ Processing for profiling with risk of unfair or deceptive impact, financial/physical injury, or intrusion on privacy
☐ Processing sensitive data
☐ Any processing presenting heightened risk of harm
14. DATA MINIMIZATION AND PURPOSE LIMITATION
14.1 Data Minimization
Pursuant to Del. Code Section 12D-106(a)(3), we limit collection to what is adequate, relevant, and reasonably necessary for the specified purposes.
14.2 Purpose Limitation
Pursuant to Del. Code Section 12D-106(a)(4), we do not process personal data for purposes incompatible with the disclosed purposes without obtaining your consent.
15. DATA SECURITY
Pursuant to Del. Code Section 12D-106(a)(2), we maintain reasonable administrative, technical, and physical data security practices to protect:
- The confidentiality and integrity of personal data
- Against unauthorized access, use, or disclosure
Our security measures include:
☐ Encryption of data in transit and at rest
☐ Access controls and authentication
☐ Regular security assessments
☐ Employee training
☐ Incident response procedures
☐ Vendor security requirements
16. DATA RETENTION
We retain personal data only as long as reasonably necessary for the purposes disclosed:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account Information | [PERIOD] | [BASIS] |
| Transaction Records | [PERIOD] | [BASIS] |
| Marketing Data | [PERIOD] | [BASIS] |
| Communication Records | [PERIOD] | [BASIS] |
17. CONTROLLER AND PROCESSOR RELATIONSHIPS
17.1 Controller Information
[COMPANY NAME] is the controller of personal data processed under this Notice.
Controller Contact:
[ADDRESS]
[EMAIL]
[PHONE]
17.2 Processor Contracts
Pursuant to Del. Code Section 12D-107, our contracts with processors include:
- Clear processing instructions
- Nature and purpose of processing
- Type of data processed
- Duration of processing
- Rights and obligations of both parties
- Confidentiality requirements
- Subprocessor restrictions
- Audit rights
18. ENFORCEMENT
18.1 Attorney General Enforcement
Pursuant to Del. Code Section 12D-111(a), the Delaware Department of Justice has exclusive enforcement authority. Violations may result in civil penalties up to $10,000 per violation.
18.2 No Private Right of Action
The DPDPA does not create a private right of action for consumers.
18.3 Consumer Complaints
Consumers may submit complaints via email to: [email protected]
19. CONTACT INFORMATION
Privacy Inquiries:
Name: [PRIVACY OFFICER NAME]
Title: [TITLE]
Email: [EMAIL]
Phone: [PHONE]
Address: [ADDRESS]
Consumer Rights Requests:
Email: [EMAIL]
Online: [URL]
Phone: [PHONE]
20. CHANGES TO THIS NOTICE
We may update this Notice to reflect changes in our practices or legal requirements. We will notify you of material changes:
☐ By posting an updated Notice on our website
☐ By email notification
☐ By notice within our application
DOCUMENT CONTROL
| Version | Date | Author | Changes |
|---|---|---|---|
| 1.0 | [DATE] | [NAME] | Initial version |
Legal Review: ☐ Completed Date: _________ Reviewer: _________
Next Review Date: _____________
This Notice is provided for informational purposes and compliance with the Delaware Personal Data Privacy Act. It does not constitute legal advice. Consult with qualified legal counsel for specific compliance questions.
About This Template
Compliance documents are what regulated businesses use to prove they follow the rules that apply to their industry, whether that is privacy, anti-money-laundering, consumer protection, or sector-specific requirements. Regulators look for consistent policies, up-to-date records, and clear evidence of employee training. The cost of getting compliance paperwork right is almost always smaller than the cost of an enforcement action, fine, or public disclosure.
Important Notice
This template is provided for informational purposes. It is not legal advice. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.
Last updated: February 2026
Get your Delaware Personal Data Privacy Act Privacy Notice, done and ready to use
Fill it in for your situation, adjust it for your state, and download the finished Word and PDF. Let the AI do it in about 5 minutes, or finish it yourself in the editor. Drafting this from scratch takes hours. Finish yours in about 5 minutes for $49, one time.