Delaware · DPDPA
Delaware privacy law, explained for practice owners
Low threshold, no revenue floor, cure period gone
The short answer
Delaware does not exempt HIPAA covered entities — only the PHI itself. So if your practice touches the personal data of 35,000 Delaware residents in a year, or 10,000 while making more than a fifth of its revenue from selling data, you are a regulated controller for everything on your site that isn't a patient record. Two dates matter: universal opt-out signal recognition became mandatory January 1, 2026, and the 60-day cure period expired at the end of 2025. There is no longer a built-in second chance.
or 10k + 20% revenue
per violation
Dec 31, 2025
The scan loads your site in a real browser and reports which trackers fire before any consent is given. No signup.
Scope
Does DPDPA actually apply to your practice?
Three questions, in order. Most practices can answer the first one and stop — but almost none have answered it in writing.
Being a covered entity does not exempt you
Delaware exempts protected health information, not the practice that holds it. Your patient records are carved out. Your website analytics, advertising identifiers, marketing lists, and prospective-patient data are not.
Do you cross the threshold?
35k consumers or 10k + 20% revenue. Count website visitors — the statute counts personal data, and your site collects it from everyone who loads a page.
If you are near the line, get the number from your analytics rather than estimating from patient volume.
Either way, three things still bind you
HIPAA and the federal analysis of tracking technologies. Other states whose residents visit your one website. And your own published privacy policy, which becomes a consumer-protection problem the moment it stops describing what your site actually does.
No state privacy exemption reaches any of those three.
Reference
Delaware privacy law: the key facts
| Law | Delaware Personal Data Privacy Act (DPDPA) |
|---|---|
| Citation | 6 Del. C. § 12D-101 et seq. |
| Effective | January 1, 2025 Universal opt-out mechanism recognition required from January 1, 2026. The 60-day cure period sunset December 31, 2025. |
| Who enforces it | Department of Justice, Consumer Protection Unit |
| Applicability | Delaware reaches controllers that conduct business in the state or target Delaware residents and, in the prior calendar year, either:
There is no revenue floor. Delaware is also a small state, which cuts the other way from how it sounds: 35,000 residents is a larger share of Delaware than 35,000 is of Texas, but it is still a real number that a single-location practice will not reach on patient volume. Website traffic is the variable that moves it. |
| HIPAA exemption | Data-level only — PHI is exempt, the practice is not Delaware exempts protected health information and other HIPAA-governed data, but it does not exempt HIPAA covered entities as entities. Your practice remains a controller for its non-PHI data. Delaware also declined to exempt nonprofits broadly, which matters for hospital-affiliated and nonprofit clinic structures that assume nonprofit status is a carve-out. Here it largely isn't. |
| Sensitive data | Sensitive data requires opt-in consent, and the category includes data revealing a mental or physical health condition or diagnosis, sex life, sexual orientation, status as transgender or nonbinary, immigration status, and precise geolocation. |
| Definition of “sale” | Broad — monetary or other valuable consideration Delaware's sale definition covers monetary or other valuable consideration, so advertising data sharing can qualify. Consumers also get a distinct opt-out of targeted advertising and of profiling in furtherance of decisions with legal or similarly significant effects. |
| Universal opt-out / GPC | Yes, as of January 1, 2026. Delaware controllers must recognize a universal opt-out mechanism, which in practice means responding correctly to Global Privacy Control. |
| Consumer rights |
|
| Cure period | Expired. Delaware's 60-day right to cure was written with an end date and that date has passed. Through 2025 the Department of Justice was required to give notice and time to fix; from 2026 it is not. |
| Penalties | Violations are enforced under the Delaware Consumer Fraud Act, carrying civil penalties of up to $10,000 per violation, alongside injunctive relief. |
| Private right of action | No private right of action. Enforcement is exclusively with the Delaware Department of Justice. |
What it means for you
The parts that actually change how you operate
Delaware is a data-level state, and that is the whole story
Thirteen of the twenty states with comprehensive privacy laws let a HIPAA covered entity out of the statute entirely. Delaware is one of the seven that do not. The exemption attaches to protected health information, and PHI is a narrow category compared to everything a practice website generates.
Concretely, in Delaware these are all in scope: the IP addresses and device identifiers your analytics collects, the advertising cookies set by your remarketing tags, the browsing behavior of someone reading about a procedure before they are anyone's patient, your newsletter list, your job applicant records.
Nothing about that list is unusual for a practice website. That is the point. In a data-level state, the ordinary operation of a marketing site is the regulated activity.
The nonprofit assumption fails here
Delaware is one of a small group of states — with Maryland, Minnesota, Montana, New Jersey, and Oregon — that declined to write a broad nonprofit exemption into its privacy law. Practices operating under nonprofit or foundation structures, community clinics, and academically affiliated groups routinely assume nonprofit status is a shield. In Delaware it generally is not.
Two deadlines already passed while nobody sent you a letter
Delaware's law is short and its two most consequential dates arrived quietly. Universal opt-out recognition became mandatory on January 1, 2026. The cure period ended twenty-four hours earlier, on December 31, 2025.
Read together, they describe a shift: through 2025 a Delaware inquiry came with a notice and sixty days. From 2026 it comes with neither, and the specific thing a regulator can test first — whether your site honors a Global Privacy Control signal — became mandatory on the same day.
Where the risk lives
Your website is the exposed surface, not your chart system
Practices spend their compliance budget on the EHR, because that is where the patient records are. But the EHR is inside a HIPAA framework with a business associate agreement, access controls, and an audit log. It is the most governed system you own.
Your website is the least governed. Tags accumulate over years, added by successive agencies, and nobody keeps a list. Every one of them is a third party receiving data about someone who came to your site to read about a medical procedure.
That is the gap every state on this list is aimed at, and it is the gap the federal tracking-technology analysis is aimed at too.
What a regulator or a plaintiff can check without asking you anything
- Which third-party scripts load on your consult and treatment pages, and whether any of them fire before a visitor interacts with your banner.
- Whether your site responds to a Global Privacy Control signal.
- Whether the opt-out your privacy policy describes actually exists and actually works.
- Whether your privacy policy's claims match your site's behavior.
All four are testable from outside your building, in a few minutes, with a browser. That asymmetry is the reason website privacy became an enforcement priority: it is the rare compliance question a regulator can answer before opening a file.
The federal floor, stated accurately
HHS Office for Civil Rights issued guidance on tracking technologies in December 2022 and revised it in March 2024. In American Hospital Association v. Becerra (June 2024) a federal court vacated part of that guidance, and HHS withdrew its appeal — so OCR's specific theory that metadata such as an IP address collected on an unauthenticated public page is automatically individually identifiable health information no longer stands.
What survived matters more than what did not. The HIPAA Privacy Rule itself was untouched. Authenticated environments, patient portals, and any context where a specific individual's care can be inferred remain squarely inside the analysis. And a marketing vendor that receives identifiable information about a patient's care still needs a business associate agreement or an authorization.
Anyone telling you the court decision made website trackers a non-issue for healthcare has read the headline and not the opinion.
Consequences
What it costs when it goes wrong in Delaware
Violations are enforced under the Delaware Consumer Fraud Act, carrying civil penalties of up to $10,000 per violation, alongside injunctive relief.
The arithmetic nobody puts in a proposal
Delaware's per-violation ceiling sits at twice the common $5,000 figure and above the $7,500 baseline most states use. Combine that with the low 35,000-consumer threshold and the expired cure period and Delaware is quietly one of the less forgiving states for a mid-sized practice with real web traffic.
You can be under every threshold and still be the one who gets asked
Delaware's Consumer Protection Unit does not need to audit you to find a problem. Anyone can look at your site, enable Global Privacy Control, and watch whether your trackers keep firing. Consumer complaints are the ordinary entry point for state privacy enforcement, and a complaint does not require the complainant to know your revenue.
Which means the question that matters is not “am I big enough to be a target.” It is “if someone looked today, what would they see.”
Do this
Your Delaware action list
In order. Items one and two are the ones that change your answer to everything else.
- Count Delaware consumers including website visitors — there is no revenue floor under the 35,000 threshold.
- Confirm whether your nonprofit or foundation structure actually exempts you here. In Delaware it probably does not.
- Wire universal opt-out signal handling; it has been mandatory since January 1, 2026.
- Get opt-in consent before processing sensitive data, including anything revealing a health condition.
- Be able to produce the categories of third parties you have disclosed personal data to — Delaware gives consumers a right to that list.
- Block non-essential trackers before consent on treatment, consult, and form pages.
- Stop planning around the cure period; it expired December 31, 2025.
- Keep timestamped consent records. Without a cure period, contemporaneous evidence is the remedy.
Questions
Delaware privacy law FAQ
Does the Delaware Personal Data Privacy Act exempt HIPAA covered entities?
No. Delaware provides a data-level exemption for protected health information and other HIPAA-governed data, but the covered entity itself remains subject to the DPDPA for personal data that is not PHI, including website analytics and advertising data.
What are the Delaware DPDPA thresholds?
Controlling or processing the personal data of 35,000 or more Delaware consumers in the prior calendar year, or 10,000 or more while deriving more than 20% of gross revenue from selling personal data. There is no revenue-only threshold.
Is there still a cure period under the Delaware privacy law?
No. The 60-day right to cure was written to sunset and expired on December 31, 2025. The Department of Justice is no longer required to provide notice and an opportunity to fix a violation before acting.
Are nonprofits exempt from Delaware's privacy law?
Generally no. Delaware is one of several states — with Maryland, Minnesota, Montana, New Jersey, and Oregon — that did not include a broad nonprofit exemption.
What is the penalty under the DPDPA?
Violations are enforced under the Delaware Consumer Fraud Act, with civil penalties up to $10,000 per violation plus injunctive relief.
Verify it yourself
Official sources
Every figure on this page comes from the statute or the office that enforces it. Read them directly — and bring them to your own counsel.
Last reviewed July 25, 2026. State privacy law changes on a rolling basis; amendments in Delaware and elsewhere are frequent. If you are making a decision that depends on a specific figure, confirm it against the linked source and your counsel rather than against this page.
Honest about the legal layer
Consential is compliance infrastructure. We build and operate the machinery: blocking non-essential tracking until a visitor agrees, detecting which state framework applies, and writing every choice to an append-only record you can produce later.
We are not a law firm, we do not provide legal advice, and using Consential does not by itself guarantee compliance with any state or federal regulation. This page is a plain-language summary of publicly available law, not an opinion on your practice. The determinations that matter most here — whether you are a HIPAA covered entity, whether a specific data flow is a “sale,” whether a given page needs consent — are legal judgments about your specific facts. Get them from healthcare counsel. We pair with your counsel, not in place of them.
Find out what your site is doing right now
Enter your domain. We load it in a real browser and report every tracker that fires before consent, which cookies get set, and whether a consent layer is present at all — scored, with the evidence named.
Scan your site free No signup. Results in about a minute. The scan reports what we observe; it is not a legal opinion.The rest of the map
Privacy law in the other 19 states
Your website has one configuration for every visitor. If you draw patients across state lines, the strictest state in your traffic sets your standard — not the state you practice in.
Back to state privacy detection · How the consent layer works · Pricing