Orange textured background

US state law

Delaware DPDPA and browser fingerprinting

How the Delaware Personal Data Privacy Act regulates device fingerprinting, why its 35,000-consumer threshold catches businesses that every other US state law misses, and what first-strike enforcement looks like now that the cure period has sunset.

Reviewed

RegionDelaware, USA
RegulatorDelaware Department of Justice - Consumer Protection Unit (Attorney General)
Effective1 January 2025
Max penaltyUp to $10,000 per intentional violation (Del. Code §12D-111)
Status in-force

What DPDPA says about fingerprinting

The Delaware Personal Data Privacy Act was signed into law as House Bill 154 in 2023 and took effect on 1 January 2025. It is codified at Delaware Code Title 6 Chapter 12D, sections 12D-101 through 12D-111. Like the other laws in the Virginia-cluster, the statute does not mention 'fingerprinting', 'browser fingerprint', or 'device identifier' by name. Section 12D-101 defines 'personal data' as 'any information that is linked or reasonably linkable to an identified or identifiable natural person'. A browser or device fingerprint hash - composed of canvas output, font metrics, WebGL renderer strings, audio context fingerprint, installed plugins, time zone, and similar device characteristics - qualifies under that definition the moment the controller uses it to recognise a returning Delaware consumer. The hash does not need to be tied to a name, email, or account number; linkability is satisfied by the fact that the same hash maps back to the same browser across visits.

Delaware borrowed its definitional framework from Virginia's VCDPA and its structural provisions from Oregon's OCPA, but two features make it genuinely distinct from every other law in the cluster. First, its applicability thresholds are the lowest in any US state - meaning companies that are out of scope for every other state law may be inside DPDPA. Second, it extends those obligations to nonprofit organisations, not just commercial entities. Both differences have direct operational consequences for any product that deploys fingerprinting and touches Delaware consumers.

When DPDPA applies to you

Section 12D-103 sets out the applicability test. DPDPA applies to any person that conducts business in Delaware or produces products or services targeted to Delaware residents, and either (a) controls or processes the personal data of at least 35,000 Delaware consumers in a calendar year, or (b) controls or processes the personal data of at least 10,000 Delaware consumers AND derives more than 20% of gross revenue from the sale of personal data.

The 20%-of-revenue leg is the most aggressive revenue-based test in any cluster state. Colorado requires any revenue from sale, but DPDPA replaces a percentage test at a lower consumer count. A mid-size SaaS that processes 15,000 Delaware signups and earns 22% of its revenue from selling fingerprint-derived audience data is inside DPDPA even though it is well below every other state's 100,000-consumer floor.

Consumer under DPDPA means a natural person who is a Delaware resident acting in an individual or household context. The statute excludes employees and contractors acting in a professional capacity and individuals acting as B2B contacts. A fingerprint captured on an internal HR tool used solely by Delaware-resident employees, or on a SaaS where every user is acting on behalf of a business, does not trigger DPDPA obligations.

Nonprofits are the critical exception to the standard exemptions. DPDPA extends its obligations to nonprofit organisations that meet the same thresholds when processing member or donor personal data. A nonprofit with 40,000 Delaware members who are fingerprinted during event registration or online fundraising is inside the law. Oregon's OCPA is the only other US state law with comparable nonprofit coverage.

The opt-out rights that touch fingerprinting

Section 12D-104 gives Delaware consumers five rights: access, correction, deletion, portability, and opt-out. The opt-out right divides into three independent categories, each of which intersects with fingerprinting in distinct ways.

Targeted advertising under §12D-101 means displaying advertisements selected based on personal data obtained from the consumer's activities across non-affiliated websites or applications over time. Using a fingerprint hash to identify a returning visitor and serve ads based on their cross-site behaviour is the direct case. First-party retargeting on your own domain, frequency capping, and contextual advertising are excluded.

Sale of personal data under DPDPA means the exchange of personal data for monetary or other valuable consideration by the controller to a third party. The 'or other valuable consideration' phrasing follows Colorado's CPA rather than Virginia's narrower monetary-only definition, making non-monetary data exchanges more likely to count as sale in Delaware than in Virginia.

Profiling that produces legal or similarly significant effects is the third opt-out hook. DPDPA aligns with the Virginia standard here: profiling that affects credit decisions, employment, insurance pricing, healthcare access, or housing is subject to the opt-out right; profiling used to refine a marketing dashboard is not.

Common fingerprinting purposes under DPDPA

PurposePersonal data under DPDPA?DPA required?Opt-out right applies?
Anti-fraud at login or paymentYesNo (security use, not heightened-risk processing)No
Account-takeover detectionYesNoNo
Bot mitigation on a public formYesNoNo
Cross-site targeted advertisingYesYesYes (targeted advertising opt-out)
Selling fingerprint-derived audience segments (for money)YesYesYes (sale opt-out)
Sharing fingerprint data with ad-tech partner for mutual lift (no direct payment)YesYesYes (likely sale under 'other valuable consideration')
Profiling for credit, insurance, or employment decisionsYesYesYes (profiling with legal or similarly significant effects)
Product analytics on your own serviceYesNoNo
Frequency capping on your own siteYesNo (first-party carve-out)No
Fingerprinting nonprofit members during event registrationYes (nonprofit coverage applies)Yes, if for targeted advertising or saleYes, same as commercial controller

Data Protection Assessments under DPDPA

Section 12D-107 requires a controller to conduct and document a Data Protection Assessment before engaging in four categories of processing: targeted advertising, sale of personal data, processing of sensitive data, and profiling that presents a reasonably foreseeable risk of harm to the consumer. The assessment must identify the purpose, the categories of personal data involved, the controller's legitimate interest in the processing, the potential benefits and risks to consumers, and any safeguards applied to mitigate those risks.

For a fingerprinting deployment powering targeted advertising, an adequate DPDPA assessment names the signal categories collected (canvas, fonts, WebGL, audio, plugins, time zone), the hash construction method, the retention window, the downstream recipients, any de-identification or pseudonymisation steps, and the operational controls that honour both the on-site opt-out and the GPC signal. The assessment is an internal document; it is not published. The AG can require production during an enforcement investigation, and the absence of a required assessment is itself a violation.

A single assessment can cover a category of comparable processing activities - meaning one assessment for your entire targeted-advertising fingerprinting flow is defensible, rather than one per campaign or per consumer segment. Assessments must be retained and updated when the processing changes materially.

Universal Opt-Out Mechanism and the GPC signal

Section 12D-105 requires controllers to honour Universal Opt-Out Mechanisms for targeted advertising and sale processing. GPC recognition became mandatory on 1 January 2026. From that date, a fingerprinting script that fires for targeted advertising or sale purposes before checking for a GPC browser signal from a Delaware consumer is in violation of DPDPA, regardless of whether the consumer ever clicked an on-site opt-out link.

The practical integration requirement: the call to any fingerprinting API used for targeted advertising or sale must be gated behind a check that reads the GPC header and your own preference-centre opt-out flag. Fraud-prevention and product-analytics fingerprinting paths do not require this gate because those purposes are not targeted advertising or sale - but the controller must maintain architectural separation between the regulated and exempt data flows to sustain that distinction under scrutiny.

The cure period is gone

DPDPA originally gave controllers a 60-day right to cure after receiving notice of a violation from the AG. That cure period was the most generous in any US cluster state - twice as long as Virginia's 30-day window and Colorado's original 30-day window. Section 12D-111 terminated the cure right on 31 December 2025. From 1 January 2026, the Delaware DOJ Consumer Protection Unit can proceed to civil penalty assessment on the first identified violation without issuing a cure notice.

The 60-day cure window was clearly intended as an on-ramp for a new law with a January 2025 effective date. The year-end 2025 sunset means the grace period is over. Controllers that have not yet implemented UOOM handling, Data Protection Assessments for regulated purposes, or a privacy notice that discloses fingerprinting are now directly exposed to civil penalties on first discovery.

Enforcement context: the Delaware DOJ Consumer Protection Unit

  • Enforcement of DPDPA sits with the Delaware Department of Justice Consumer Protection Unit, which sits within the Attorney General's office. The unit has existing experience enforcing the Delaware Consumer Fraud Act (6 Del. C. §2511 et seq.), which has been active since the 1970s and gives the unit a track record of investigating deceptive commercial practices at the small-to-mid-size business level.
  • The Delaware Consumer Fraud Act enforcement history is the closest proxy for how the DOJ will approach DPDPA. The unit has historically moved against companies for deceptive disclosures in consumer-facing materials - the same disclosure failures that underpin most DPDPA violations (missing privacy notices, undisclosed fingerprinting, unimplemented opt-out mechanisms).
  • DPDPA's enforcement record is new - the law has only been in force since January 2025 and the cure window ran through December 2025. First-strike enforcement actions under DPDPA are expected to emerge in 2026, and the DOJ has signalled publicly that it views low-threshold applicability as a reason to focus on mid-size digital businesses that have not yet built compliance programmes.
  • Civil penalty exposure under DPDPA is up to $10,000 per intentional violation. That cap is meaningfully higher than Virginia's $7,500 and Utah's $7,500, though lower than Colorado's $20,000. The AG may seek injunctive relief in addition to civil penalties, including orders to stop specific processing activities.

Territorial reach: remote businesses and the Delaware threshold

DPDPA reaches any controller that produces products or services targeted to Delaware residents, regardless of where the controller is incorporated or physically located. A New York-based SaaS, a London-based ad-tech vendor, or a Bangalore-based analytics company all owe DPDPA obligations if they cross the 35,000-consumer or 10,000-with-20%-revenue threshold for their Delaware consumer population.

Delaware's incorporation status does not, by itself, create DPDPA obligations. A company incorporated in Delaware but with no Delaware-resident consumer base does not have DPDPA obligations purely by virtue of being a Delaware entity. The trigger is targeting and serving Delaware residents, not legal domicile.

In practice, the 35,000-consumer threshold means many multi-state products that have quietly assumed they are below every US state law's scope will need to revisit that assumption for Delaware specifically. A B2C subscription service with 400,000 US users distributed proportionally across states will have roughly 12,000-15,000 Delaware users - well above the 10,000-with-20%-revenue leg if any data monetisation is happening.

How Benny the Doorman fits into a DPDPA-aware deployment

Benny is a fingerprinting SDK and hosted API, not a consent management platform or a Universal Opt-Out Mechanism handler. The controller's CMP or preference centre owns the opt-out gating; Benny should be invoked only after that gating signal confirms the processing is permitted for the intended purpose.

Three integration steps for a DPDPA-aware deployment. First, gate any Benny call used for targeted advertising or sale purposes behind a UOOM check (the GPC signal) and your own preference-centre flag. From 1 January 2026, DPDPA's GPC recognition is mandatory, and a fingerprint call that fires without checking GPC is in violation. Second, produce and retain a Data Protection Assessment for each §12D-107 purpose before going live - Benny's documentation lists the per-signal categories, hash construction, retention defaults, and data-flow architecture details that populate the technical sections of an adequate assessment. Third, if the same Benny deployment supports both an exempt purpose (anti-fraud) and a regulated purpose (targeted advertising), architect those as separate data flows with separate retention windows and access scopes. The §12D-105 opt-out must be honoured on the regulated flow without breaking the exempt one, and the separation must be demonstrable if the AG requests documentation.

Nonprofits using Benny to fingerprint members or donors for analytics or personalisation purposes should note that DPDPA's nonprofit coverage means they owe the same DPA, opt-out, and UOOM obligations as commercial controllers on that data. Fraud-prevention fingerprinting for nonprofit payment flows retains its exempt status - but any personalisation or segment-building use of fingerprint data on nonprofit infrastructure requires the same compliance treatment as a commercial deployment.

Frequently asked questions

Is browser fingerprinting illegal under DPDPA?

No. Fingerprinting is not banned under the Delaware Personal Data Privacy Act. It is regulated as personal data when the fingerprint can be linked back to an identified or identifiable Delaware consumer. Lawful use requires honouring the opt-out right for targeted advertising, sale, and covered profiling; completing a Data Protection Assessment before deploying fingerprinting for those purposes; and, from 1 January 2026, respecting the Global Privacy Control signal as a Universal Opt-Out Mechanism.

Is Delaware's DPDPA related to India's DPDP Act?

No. They are entirely unrelated laws that happen to share a similar acronym. Delaware's DPDPA is the Delaware Personal Data Privacy Act, a US state consumer privacy law codified at Del. Code Title 6 Chapter 12D, effective 1 January 2025. India's DPDP Act is the Digital Personal Data Protection Act 2023, a national law enacted by the Parliament of India. The two laws share no legal lineage, no common regulator, no shared definitions, and no cross-border applicability. If your compliance question involves Indian consumers or Indian-law obligations, see the separate India DPDP Act page.

Does DPDPA apply to my business if I'm below every other state law's threshold?

Possibly yes. Delaware's 35,000-consumer threshold is the lowest of any US state privacy law. If you process personal data of 35,000 or more Delaware residents in a year, DPDPA applies regardless of whether you clear Virginia's 100,000-consumer floor, Colorado's 100,000-consumer floor, or any other state's threshold. A mid-size SaaS with 12,000 Delaware users that earns more than 20% of gross revenue from data sales is inside DPDPA even if it falls below every other state's applicability test.

Does DPDPA cover nonprofit organisations?

Yes. DPDPA applies to nonprofit organisations that meet the same applicability thresholds when processing member or donor personal data. A nonprofit with 40,000 Delaware members whose browsing activity is fingerprinted for analytics or personalisation owes the same opt-out, Data Protection Assessment, and UOOM obligations as a commercial controller. Oregon's OCPA is the only other US state law with comparable nonprofit coverage.

The cure period sounded useful - is it still available?

No. DPDPA's 60-day cure period sunset on 31 December 2025. From 1 January 2026, the Delaware Department of Justice Consumer Protection Unit can assess civil penalties on the first identified violation without issuing a cure notice. Any compliance posture that relied on fixing issues after receiving an AG notice needs to be revisited for Delaware deployments.

Do I have to honour the Global Privacy Control under DPDPA?

Yes, from 1 January 2026. DPDPA mandates recognition of Universal Opt-Out Mechanisms for targeted advertising and sale processing, and the Global Privacy Control is the primary recognised UOOM. A fingerprinting deployment that fires for targeted advertising purposes without checking the GPC header on a Delaware browser is in violation of §12D-105, even if the consumer never used your on-site opt-out.

How is DPDPA's sale definition different from VCDPA?

Delaware's sale definition includes 'monetary or other valuable consideration', following Colorado's CPA model rather than Virginia's narrower monetary-only definition. Sharing fingerprint hashes with an ad-tech partner for mutual lift or audience matching, without a direct dollar payment, is more likely to qualify as sale under DPDPA than under VCDPA. If your legal analysis relied on VCDPA's narrow sale definition to avoid sale-opt-out obligations, that analysis does not automatically carry over to Delaware.

What is the maximum penalty for non-compliant fingerprinting under DPDPA?

Up to $10,000 per intentional violation under Del. Code §12D-111. That cap is higher than Virginia's $7,500 per violation and higher than Utah's equivalent cap, though lower than Colorado's $20,000. The AG may also seek injunctive relief. There is no private right of action under DPDPA; enforcement is exclusively through the Delaware Department of Justice Consumer Protection Unit.

Does DPDPA apply to anti-fraud fingerprinting?

Yes, anti-fraud fingerprinting is personal data processing under DPDPA when the fingerprint can be linked to a Delaware consumer. However, the opt-out rights for targeted advertising, sale, and profiling do not apply to anti-fraud use, and a Data Protection Assessment is generally not required for narrowly scoped security processing that does not present a reasonably foreseeable risk of substantial harm. Anti-fraud remains one of the lowest-friction fingerprinting use cases under Delaware law, provided it is architecturally separated from any regulated-purpose flows.

Tooling

Benny the Doorman is built for this compliance posture.

Free, cookieless fingerprinting that defers to your consent management platform, runs on Indian infrastructure, and ships with a DPA addendum sized for the jurisdiction above.

Last reviewed 2026-06-06