Delaware data privacy and data broker removal

Delaware gives you the right to access, delete, and control your personal data. Here is how those rights work in practice, and how to get yourself off data brokers.

At a glance
Comprehensive privacy law? Yes — Delaware Personal Data Privacy Act (DPDPA)
In effect since January 1, 2025
Your core rights Access, correct, delete, portability, plus five more
Honors Global Privacy Control? Yes
Data-broker registry? No
Can you sue? (private right of action) No
Enforced by Delaware Department of Justice
Last verified June 2026 Reviewed quarterly

Your rights in Delaware

Delaware residents are protected by the Delaware Personal Data Privacy Act (DPDPA).

Sensitive data gets extra protection. Companies need your explicit consent before collecting or using your most sensitive personal information, including biometric data, precise location, health information, race or ethnicity, and sexual orientation. That is a higher bar than the standard opt-out that applies to other data types.

Does this cover the company that has my data?

Most companies that collect or sell personal data in Delaware are likely covered. The law applies to any business that handles the personal data of at least 35,000 Delaware consumers, or at least 10,000 consumers while drawing more than 20% of its gross revenue from selling personal data.

Delaware set a low threshold and kept its exemptions narrow. It does not exempt nonprofits or higher-education institutions at the entity level, so it reaches more organizations than most state privacy laws.

Where the law stands now. Global Privacy Control recognition has been mandatory since January 1, 2026. The automatic 60-day cure period ended with 2025, so the Department of Justice can now pursue enforcement without first offering a company a chance to fix a violation. Data-protection-assessment obligations have applied since July 1, 2025.

How to remove yourself from data brokers in Delaware

Delaware law gives you the right to request deletion. Exercising it across every site that holds your data takes real effort, though. Here are the most effective steps, in order.

1. Enable Global Privacy Control

Global Privacy Control is a free browser setting that automatically tells every website you visit not to sell or share your data. It takes two minutes to turn on and then works quietly in the background. Since January 1, 2026, Delaware law has required covered businesses to honor it, so this is not just a request; it carries legal weight.

2. Submit direct opt-out requests

You can also file requests directly with each company. Look for the "Do not sell my personal information" link in the website footer; most major brokers have one. You can submit formal access, deletion, or correction requests through each company's privacy policy page.

Under Delaware law, covered companies must respond within the statutory deadline. If they don't, you have grounds to file a complaint with the Delaware Department of Justice.

3. Keep removal going over time

Here is the part nobody tells you: even after you complete every step above, brokers re-ingest your information from public records, data-sharing networks, and commercial databases. Within a few months, your profiles reappear. Staying off is not a one-time task; it is ongoing work that most people cannot keep up by hand.

Delist searches the open internet for where your information shows up, including what AI assistants surface about you, then files removals on your behalf and re-runs a full scan every month so it stays down. The free scan takes under a minute.

Run a free scan

Delaware's data broker rules: what they mean for you

Delaware does not have a dedicated data-broker registry. Most national data brokers are registered in California and honor opt-out requests from residents of any state. Without a Delaware-specific law requiring it, though, you have little recourse if a broker ignores your request. Delist handles this across states and sites in one place.

Other privacy protections in Delaware

Beyond the comprehensive privacy law, Delaware has additional protections that may apply to you:

How to file a privacy complaint in Delaware

File with the Delaware Department of Justice, Consumer Protection Unit: attorneygeneral.delaware.gov/fraud/cpu.

Most state agencies enforce privacy laws in the aggregate; they investigate patterns of violations rather than resolving individual disputes. Filing a complaint still matters: it creates a record that helps trigger enforcement actions.

Frequently asked questions

Does Delaware have a data privacy law?
Yes. Delaware residents are protected by the Delaware Personal Data Privacy Act (DPDPA), which gives you rights to access, delete, and control your personal data.
Can I sue a company for violating my privacy in Delaware?
Generally no. Privacy enforcement in Delaware is handled by the Delaware Department of Justice, not private lawsuits. You cannot sue for most violations.
How do I opt out of data brokers in Delaware?
Enable Global Privacy Control, submit direct opt-out requests to each broker, and consider a removal service to automate the process. Delaware has no broker registry.
Does Delaware require websites to honor Global Privacy Control?
Yes. Delaware law requires covered businesses to treat Global Privacy Control as a valid opt-out request. Enable it in your browser for automatic protection.

Sources

This page is privacy-rights information, not legal advice. Privacy law changes often; confirm the current rules with your state privacy agency or a licensed attorney before acting. Last verified June 22, 2026. We re-check state privacy laws quarterly.

Take back your privacy in Delaware

Delist finds where your information is exposed, files removals on your behalf, and re-runs a full scan every month so it stays down.

Run a free scan