Delaware's Personal Data Privacy Act and AI Profiling
9 min read · updated August 11, 2026
Delaware’s Personal Data Privacy Act, 6 Del. C. ch. 12D, took effect on 1 January 2025. It is easy to skip on the grounds that Delaware has under a million residents. That is the wrong reason to skip it: the applicability threshold is the lowest of any US comprehensive privacy statute, and the statute reaches organisations that every other state exempts.
The lowest threshold in the country
The Act applies to persons that conduct business in Delaware or produce products or services targeted to Delaware residents and that, during the preceding calendar year, either controlled or processed the personal data of at least 35,000 consumers — excluding data controlled or processed solely for completing a payment transaction — or controlled or processed the personal data of at least 10,000 consumers and derived more than 20% of gross revenue from the sale of personal data.
Compare 100,000 in Virginia and Oregon. Because Delaware has roughly a million residents, 35,000 consumers is a far larger share of the state’s population than 100,000 is of Virginia’s, and a moderately successful consumer product with national reach will cross it. The revenue-share limb is also lower than the 25% used in Oregon and the 50% used in Virginia.
The other structural difference is that Delaware does not carry a blanket nonprofit exemption. Nonprofit organisations are generally within scope, with carve-outs including certain entities dedicated to preventing or addressing insurance crime and, separately, institutions of higher education. A hospital foundation, an advocacy organisation or a membership body running a scoring or targeting model over Delaware residents is inside a statute it may assume it is outside. The codified chapter is published by the Delaware Code at delcode.delaware.gov.
The “solely automated” qualifier
The consumer rights include a right to opt out of the processing of personal data for the purposes of targeted advertising, the sale of personal data, or profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the consumer.
That middle phrase is Delaware’s distinguishing feature and it is borrowed from Article 22 of the GDPR rather than from the Virginia model. Virginia and Oregon reach profiling in furtherance of decisions that produce such effects, full stop; Delaware reaches it only where the decision is solely automated. Insert a person with genuine authority into the decision and Delaware’s opt-out arguably falls away while the neighbouring states’ rights do not.
“Arguably” is doing work there, and it should. The Delaware Act does not define “solely automated”, and no Delaware court or Attorney General opinion has construed it. The obvious source of interpretive material is the European jurisprudence on Article 22, where the position is that nominal human involvement does not defeat the provision — the reviewer must have real authority and actually exercise it, and a decision rubber-stamped by a person is still solely automated in substance. Delaware regulators are not bound by that, and it is genuinely open whether they will follow it. What would settle it is an enforcement action or an AG interpretation; neither exists at the time of writing. See the solely-automated definition page for how the European reading was arrived at.
The practical consequence for system design is that the compliance question is about your escalation path, not about your model. Whether a person can and does overturn the output, on what information, in what time, is the fact that decides the legal analysis, and it is a fact about queue design and staffing.
The assessment duty catches more than the opt-out
Delaware requires a data protection assessment for processing that presents a heightened risk of harm to a consumer, and the enumerated activities include targeted advertising, the sale of personal data, the processing of sensitive data, and profiling where the profiling presents a reasonably foreseeable risk of unfair or deceptive treatment or disparate impact on consumers, financial, physical or reputational injury, intrusion upon solitude or seclusion that would be offensive to a reasonable person, or other substantial injury.
The important structural point is the mismatch. The assessment trigger is a risk test with no “solely automated” qualifier, so a human-reviewed model that produces no opt-out right can still require a documented assessment. Building a compliance programme around the opt-out alone leaves that duty unaddressed.
The assessments must weigh the benefits to the controller, the consumer, other stakeholders and the public against the risks to consumer rights as mitigated by safeguards. They are confidential and exempt from public disclosure, and the Department of Justice may require their production in connection with an investigation. As elsewhere, an assessment produced under compulsion is being read by an adversary, which is the reason to write it as an honest risk analysis rather than as a defence brief — a document that identifies no risks is not credible and reads badly.
Sensitive data and the third-party list
Processing sensitive data requires consent, and Delaware’s sensitive category is wider than most: alongside the usual racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, sex life, sexual orientation, citizenship or immigration status, genetic and biometric data, precise geolocation and children’s data, it expressly includes data revealing an individual’s status as transgender or nonbinary. For inference systems this matters because sensitivity attaches to what the data reveals, and a model output that reveals one of those categories is sensitive data even when every input was mundane — the same mechanism that drives Washington’s health-inference regime.
Delaware also gives consumers a right that most states do not: the right to obtain a list of the categories of third parties to which the controller has disclosed the consumer’s personal data, or, if the controller does not maintain it in that form, a list of the categories of third parties to which it has disclosed personal data generally. If your model providers and analytics vendors receive personal data, they are third parties for that purpose, and the answer needs to be true.
Dates, cure periods and enforcement
The Act took effect on 1 January 2025. Enforcement is by the Delaware Department of Justice; there is no private right of action. Through the end of 2025 the Department was required to give notice and a sixty-day opportunity to cure before taking action, and that mandatory cure period lapsed at the start of 2026, after which cure is discretionary. A programme designed on the assumption of a guaranteed cure window is designed for a regime that has expired.
Two further dates. Controllers were required to recognise universal opt-out mechanisms — a browser or device signal indicating a consumer’s choice to opt out — from 1 January 2026, so an opt-out implemented only as a web form is now incomplete. And the statute obliges controllers to provide a means to revoke consent that is at least as easy as the means by which it was given, and to cease processing within a specified period of revocation.