Law / United States / Delaware

Delaware

United States law applies in Delaware Delaware is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Delaware, described on this page below, applies here too.

15 of 19 named instruments researched to a stage, across five of the six areas of law we track: 12 in force, 1 enacted but not yet in force and 2 proposed. As of 14 September 2026.

When they take effect8 of 15 carry a date, 7 do not. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 1 instrument (1 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 6 instruments (6 in force) 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 5
  2. Privacy law 5
  3. Scraping law 2
  4. Cybersecurity law 1
  5. Age gating law 2
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law5 instruments, 4 in force, 1 proposed

Research summary (367 words)

Delaware has no comprehensive AI-risk or AI-transparency statute and no enacted chatbot-disclosure duty. Its AI-specific findings sit instead in the criminal code and in medical-licensing law. The child sexual abuse material offenses at Del. Code tit. 11, sec. 1109 and sec. 1111 define "visual depiction" to include a computer-generated image and do not require an actual child, reaching a wholly synthetic, AI-generated depiction on the same terms as a photograph.

House Bill 353 (2024), the Amelia Kramer Act, added a private civil cause of action at Del. Code tit. 10, ch. 78 and a matching criminal offense at tit. 11, sec. 1335(a)(9) for distributing a non-consensual deep fake intimate depiction of an identifiable person.

House Bill 316 (2024) added a parallel disclosure-or-prohibition regime for election deep fakes at Del. Code tit. 15, sec. 5145, structured like Colorado's candidate deep fake statute: distribution is unlawful close to an election unless the deep fake carries a specified on-its-face disclosure.

House Bill 191 (2026) added that a nonhuman entity, including an agent powered by artificial intelligence, may not be licensed as, or use the protected title or abbreviation of, a physician, physician associate, professional nurse, advanced practice registered nurse, or practical nurse, at Del. Code tit. 24, secs. 1720(k)-(l), 1773(d), and 1920(h)-(i).

A general consumer-facing chatbot and AI-agent disclosure duty, House Bill 306, passed the House and has been pending in a Senate committee since May 2026 without a floor vote; it does not yet bind anyone.

The Delaware Artificial Intelligence Commission (House Bill 333, 2024, Del. Code tit. 29, ch. 90C) inventories the state government's own generative AI use and issues recommendations; House Bill 16 (2025) made a further definitional and membership amendment to that Commission statute; and House Joint Resolution 7 directs the Commission to work with the Secretary of State to design an agentic-AI regulatory sandbox.

All three govern only the state government's own use and study of AI and impose no duty on a private developer or deployer, so none is catalogued as an instrument. Delaware's own automated-profiling opt-out right for consumers, at Del. Code tit. 6, sec. 12D-104(6)(c), is a duty attaching to personal data and is researched under the privacy topic rather than here.

AI prohibited practices

Child sexual abuse material offenses, computer-generated depictions

Del. Code Ann. tit. 11, §§ 1100(2), (11), 1109, 1111Delaware Code Online, current codified text of Title 11, Chapter 5, Subchapter V

In force. Binds public and private bodies.

What this law does

Delaware's "visual depiction" definition, which governs dealing in child sexual abuse material (a class B or class D felony under sec. 1109) and possession of it (a class F felony under sec. 1111), expressly includes "any picture, or computer-generated image or picture, or any other image whether made, stored or produced by electronic, digital, mechanical or other means".

Delaware's "child" definition for these offenses separately extends to any individual the defendant intends to appear 14 years of age or younger. Neither offense requires an actual identifiable child, so a wholly AI-generated depiction is reached on the same terms as a photograph.

Possession under sec. 1111(2) separately reaches any visual depiction "created, adapted, modified or edited so as to appear" that a child is engaged in a prohibited sexual act, covering an AI-altered image built from a real photograph.

What it requires

House Bill 191 (2026), medical professional title protection against nonhuman and AI entities

Del. Code Ann. tit. 24, §§ 1720(k)-(l), 1773(d), 1920(h)-(i) (enacted as House Bill 191, 153rd General Assembly, 85 Del. Laws, c. 250)Delaware Code Online

In force. Binds public and private bodies.

What this law does

House Bill 191's progress status on the General Assembly's own bill tracker reads Signed 4/23/26. It amended Title 24 to add that a nonhuman entity, including an agent powered by artificial intelligence, may not be certified to practice medicine under sec. 1720(k). It may not be licensed as a physician associate under sec. 1773(d). It may not be licensed to practice professional nursing, as an advanced practice registered nurse, or as a practical nurse under sec. 1920(h).

The same sections separately bar such a nonhuman entity or AI agent from using the physician titles Doctor, Dr., Physician, surgeon, Medical doctor, MD, Doctor of osteopathy, and DO under sec. 1720(l). They bar it from using the title physician associate or the abbreviation PA under sec. 1773(d).

They bar it from using the nursing titles Advanced Practice Registered Nurse or APRN, Certified Registered Nurse Anesthetist or CRNA, Clinical Nurse Specialist or CNS, Certified Nurse Practitioner or CNP, Certified Nurse Midwife or CNM, Nurse, Registered Nurse or RN, Licensed Practical Nurse or LPN, and Doctor or Dr. under sec. 1920(i).

A person who practices or attempts to practice medicine contrary to Chapter 17, which reaches the sec. 1720(k)-(l) bar, is guilty of a class F felony under sec. 1766(a), fined not less than $1,000 nor more than $5,000 and imprisoned not more than 3 years, or both. A violation of Chapter 17 for which no other penalty is specified is a class B misdemeanor under sec. 1766(c).

Representing a nonhuman entity as a physician associate contrary to Subchapter VI is separately fined not less than $500 nor more than $2,000 or imprisoned not more than 1 year, or both, under sec. 1774B(b). Using a protected nursing title or abbreviation for an entity not licensed under Chapter 19 is fined not more than $1,000, or imprisoned not more than 1 year, or both, under sec. 1925.

What it requires

House Bill 353 (2024), deep fake intimate images (The Amelia Kramer Act)

Del. Code Ann. tit. 10, ch. 78; tit. 11, § 1335(a)(9)Delaware Code Online, current codified text of Title 11, Chapter 5, Subchapter VII, sec. 1335

In force. Binds public and private bodies.

What this law does

House Bill 353, known as the Amelia Kramer Act and signed October 9, 2024, extended Delaware's existing non-consensual intimate-image regime to a "deep fake," defined as synthetic media created or intentionally manipulated with generative adversarial network techniques or other digital technology that appears to a reasonable person to depict a real individual doing or saying something that did not occur.

Under the criminal offense at Title 11, sec. 1335(a)(9), knowingly disseminating a nonconsensual deep fake or intimate visual depiction of an identifiable person is a class A misdemeanor, elevated to a class G felony where an aggravating factor is proven; sec. 1335(a)(9)g. specifically dispenses with any need to prove the depicted person had a reasonable expectation of privacy where the image is a deep fake.

The parallel civil chapter at Title 10, ch. 78 gives a depicted individual a cause of action against a person who knew or acted with reckless disregard in disseminating or threatening to disseminate the deep fake without consent.

What it requires

AI transparency

House Bill 306 (pending), Computer Communication Act

H.B. 306, 153rd General Assembly (introduced March 5, 2026; pending Senate committee)Bill detail and original synopsis, Delaware General Assembly, as introduced

Proposed: draft date not recorded. Before the second chamber, dated 5 May 2026, as of 12 September 2026. Binds private bodies.

What this law does

This measure remains pending in the Senate Banking, Business, Insurance and Technology Committee as of its last committee action on May 5, 2026, with no floor vote scheduled; it does not bind anyone yet.

As introduced, it would amend Title 6 to make it an unlawful and prohibited trade practice for a business to engage in a commercial transaction with a consumer who interacts with computer technology, under circumstances where a reasonable person would believe they are dealing with an actual human being, without first notifying the consumer that they are communicating with a computer.

It would create a private right of action for damages and let the Attorney General seek injunctive relief and a civil penalty of up to $5,000,000 for violations. As introduced, the measure states it takes effect 180 days after enactment into law.

What it requires

House Bill 316 (2024), use of deep fake technology to influence an election

Del. Code Ann. tit. 15, § 5145Delaware Code Online

In force. Binds public and private bodies.

What this law does

House Bill 316 added this Title 15 provision, approved October 9, 2024. It makes it unlawful for a person to distribute, or contract to distribute, a deep fake depicting a candidate or political party within 90 days of an election, without the depicted individual's consent, if the person knows or reasonably should know the item is a deep fake.

Distribution is not a violation if the synthetic media carries a specified on-screen or spoken disclosure that it has been altered or artificially generated, or if it falls within the exceptions for a bona fide newscast, a news website or periodical that flags the media as inaccurate, or satire or parody; a further exception for a paid broadcaster meeting good-faith verification conditions was itself repealed by its own one-year sunset clause and no longer appears in the current code.

A depicted candidate may bring an expedited action for injunctive relief, damages, and attorney's fees in the Court of Chancery. A violation is a class B misdemeanor, elevated to a class A misdemeanor if committed with intent to cause violence or bodily harm, or on a repeat violation within 5 years.

What it requires

Privacy law5 instruments, 4 in force, 1 enacted but not yet in force

Research summary (177 words)

The Delaware Personal Data Privacy Act (DPDPA) is codified at Del. Code Ann. tit. 6, ch. 12D, sections 12D-101 to 12D-111, confirmed against the official Delaware Code; Chapter 12C, sometimes cited for the DPDPA, is a different statute. Enacted as H.B. 154, 152nd General Assembly, effective January 1, 2025. Genetic or biometric data is one of DPDPA's enumerated sensitive-data categories.

Separately, Delaware's biometric-data definition claws back data generated from a recording the moment it is generated to identify someone, so a recording-derived identifier still reaches the sensitive category. A separate chapter, Del. Code Ann. tit. 6, ch. 12B, governs breach notification. The Delaware Department of Justice has enforcement authority, with a mandatory cure period through December 31, 2025 and a discretionary one from January 1, 2026; there is no private right of action.

H.B. 380 (153rd General Assembly), which would extend DPDPA to employment data and lower applicability thresholds, passed the General Assembly in June 2026 but remained unsigned as of the date shown; it is not recorded as an instrument here because its enactment is unconfirmed.

Breach notification

Computer Security Breaches

Del. Code Ann. tit. 6, §§ 12B-101 to 12B-104official Delaware statute text, Title 6 Chapter 12B, Delaware Code

Commencement not set. Binds public and private bodies.

What this law does

Notice of a breach of security must be made without unreasonable delay and no later than 60 days after determination of the breach, except in specified situations. If the number of affected Delaware residents exceeds 500, the person required to provide notice must also notify the Attorney General by the time notice is provided to residents. This provision is in force under the current codified text; no dated original commencement is established, so no effective date is recorded here.

What it requires

Comprehensive regime

Delaware Personal Data Privacy Act (DPDPA), general applicability and controller/processor duties

Del. Code Ann. tit. 6, §§ 12D-101, 12D-104 to 12D-109official Delaware statute text, Title 6 Chapter 12D, Delaware Code

In force since 1 January 2025. Binds private bodies.

What this law does

DPDPA governs private-sector processing of Delaware consumers' personal data. It is codified at Del. Code Ann. tit. 6, ch. 12D; Chapter 12C, sometimes cited for the DPDPA, is a different Delaware statute. Enacted as H.B. 154, 152nd General Assembly, effective January 1, 2025. Controller duties are allocated at sections 12D-104 through 12D-108 and processor duties at section 12D-109.

H.B. 380 (153rd General Assembly), which would extend the Act to employee, applicant, and contractor data used in consequential employment decisions and lower applicability thresholds, passed the General Assembly on June 16, 2026 but its gubernatorial signature status was unconfirmed as of the date shown; it is not recorded as its own instrument pending that confirmation.

What it requires

Data subject rights

Delaware Personal Data Privacy Act, consumer rights

Del. Code Ann. tit. 6, § 12D-104official Delaware statute text, Title 6 Chapter 12D, Delaware Code

In force since 1 January 2025. Binds private bodies.

What this law does

DPDPA gives a Delaware consumer the right to confirm processing, access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and profiling in furtherance of solely-automated decisions with legal or similarly significant effects. A controller must respond without undue delay and no later than 45 days after receipt, with one 45-day extension available.

What it requires

Enforcement supervision

Delaware Personal Data Privacy Act, Department of Justice enforcement

Del. Code Ann. tit. 6, § 12D-111official Delaware statute text, Title 6 Chapter 12D, Delaware Code

In force since 1 January 2025. Binds private bodies.

What this law does

The Delaware Department of Justice has authority to enforce DPDPA; a violation is deemed an unlawful practice under the Delaware Consumer Fraud Act, Del. Code tit. 6, section 2513, and is enforced solely by the Department of Justice. A cure notice was mandatory through December 31, 2025; from January 1, 2026 the Department may consider listed factors in deciding whether to offer a cure. The chapter creates no private right of action.

What it requires

Sensitive categories

Delaware Personal Data Privacy Act, sensitive data and biometric data definitions

Del. Code Ann. tit. 6, § 12D-102(3), (30)official Delaware statute text, Title 6 Chapter 12D, Delaware Code

In force since 1 January 2025. Binds private bodies.

What this law does

DPDPA classifies data revealing racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis (including pregnancy), sex life, sexual orientation, transgender or nonbinary status, citizenship or immigration status, genetic or biometric data, a known child's data, and precise geolocation data as sensitive data.

'Biometric data' means data from automatic measurement of biological characteristics used to identify a person, such as a fingerprint or voiceprint, and the raw recording is excluded, but data generated from it is covered once generated to identify a specific individual, matching the Connecticut, Oregon, Montana, and Nebraska structure.

What it requires

Scraping law2 instruments, 2 in force

Research summary (183 words)

Delaware diverges from federal scraping law in the computer_misuse and personal_data families. Its computer crime statute is worded almost identically to the federal Computer Fraud and Abuse Act (CFAA)'s undefined without authorization standard, but distinctively creates an express private civil right of action, including treble damages for willful conduct, so a scraper defeating a technical access control in Delaware faces private civil exposure beyond prosecutorial risk.

The Delaware Personal Data Privacy Act (DPDPA) excludes publicly available government-record and widely-distributed-media information from the definition of personal data itself, the same structural exemption Connecticut uses, and its applicability thresholds are notably lower than several peer states.

The DPDPA is Title 6, Chapter 12D; Chapter 12C is a different, older law, the Delaware Online and Personal Privacy Protection Act (website privacy policies and children's book-service disclosures). Copyright, text-and-data-mining, and database rights add nothing beyond the federal position.

ToS enforceability and unfair competition (Delaware's Consumer Fraud Act and Deceptive Trade Practices Act) rest on general contract and consumer-protection law with no Delaware case applying either to scraping, so neither earns its own instrument here. robots.txt carries no independent legal weight in Delaware.

Computer misuse

Delaware Computer Crime (unauthorized access, with a private civil right of action)

Del. Code tit. 11, §§ 932, 939, 941official text, Delaware Code Online (delcode.delaware.gov)

In force since 20 July 1984. Binds public and private bodies.

What this law does

Section 932 provides that a person is guilty of the computer crime of unauthorized access to a computer system when, knowing that the person is not authorized to do so, the person accesses or causes to be accessed any computer system without authorization, near-verbatim identical to Connecticut's statute and sharing the same undefined authorization concept the Computer Fraud and Abuse Act (CFAA) carries.

Section 939 grades penalties by dollar value and section 939(h) fixes the value of private personal data at $500 for grading purposes, a lower figure than Connecticut's $1,500.

Distinctively, section 941 creates an express civil right of action for any aggrieved person, recoverable in the Court of Chancery (injunction, restitution, receivership) or at law (actual damages, damages for unjust enrichment, and treble damages where there has been a showing of wilful and malicious conduct), plus attorney's fees to a prevailing plaintiff, with a three-year discovery-based limitations period.

This private right of action is broader than the parallel Connecticut statute, which carries no equivalent civil-remedy section, and it means a scraper defeating a technical access control in Delaware faces private civil exposure, not only prosecutorial risk.

Sections 931-941 were enacted together by 64 Del. Laws c. 438, approved July 20, 1984; the enrolled act's own text of section 932 reads identically in substance to the current codification (only a later gender-neutral pronoun update was made), so the section dates to its original 1984 commencement.

What it requires

Personal data

Delaware Personal Data Privacy Act (DPDPA), publicly available information exemption

Del. Code tit. 6, ch. 12D (84 Del. Laws c. 197)official text, Delaware Code Online (delcode.delaware.gov)

In force since 1 January 2025. Binds private bodies.

What this law does

Section 12D-102(21) defines personal data to mean information linked or reasonably linkable to an identified or identifiable individual and expressly excludes de-identified data or publicly available information.

Publicly available information is defined at section 12D-102(28) as information lawfully made available through federal, state, or local government records, or information a controller has a reasonable basis to believe the consumer has lawfully made available to the general public through widely distributed media.

As in Connecticut, the exclusion operates on the definition of personal data itself, so scraped government-record or public-media personal data is outside the DPDPA's scope by definition rather than by a carve-out from an otherwise-applicable duty.

The Act's applicability threshold is notably lower than several peer states: section 12D-103(a) applies the chapter to persons conducting business in Delaware or targeting Delaware residents who, in the preceding calendar year, controlled or processed the personal data of 35,000 or more consumers (excluding payment-transaction data), or 10,000 or more consumers while deriving more than 20% of gross revenue from personal-data sales.

Chapter 12D's own text at section 12D-101 states this chapter shall be known and may be cited as the Delaware Personal Data Privacy Act; Chapter 12C is instead the Delaware Online and Personal Privacy Protection Act (website privacy policies and children's book-service-provider disclosures). DPDPA's general applicability and controller and processor duties took effect January 1, 2025, the same date the chapter's enforcement notice-and-cure window began running.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (568 words)

Delaware's product-security and baseline-security posture rests on one enacted state statute standing outside a comprehensive regime: Del. Code Ann. tit. 6, section 12B-100, part of the Computer Security Breaches chapter and added by 81 Del. Laws, c. 129, section 1 (approved August 17, 2017, effective April 14, 2018, 240 days after enactment), which requires any person who conducts business in Delaware and owns, licenses, or maintains personal information to implement and maintain reasonable procedures and practices to prevent the unauthorized acquisition, use, modification, disclosure, or destruction of that personal information collected or maintained in the regular course of business.

The chapter's own definition of 'person' at section 12B-101(6) reaches a government or governmental subdivision as well as a private actor, so the duty binds both. No enacted Delaware statute sets security requirements a connected device or software product must meet before or after it reaches the market, and no such bill was located pending before the General Assembly, so this is a researched absence rather than a gap in coverage.

Delaware has no general private-sector duty to report an exploited vulnerability or a security incident, as distinct from a personal-data breach, to a state authority.

The one sector-specific cyber-resilience regime located, the Delaware Insurance Data Security Act, Del. Code Ann. tit. 18, ch. 86 (82 Del. Laws, c. 176, section 1), requires an insurer domiciled in Delaware or a producer whose home state is Delaware, a 'licensee,' to maintain an information security program, adopt a written incident response plan, investigate a cybersecurity event, notify the Insurance Commissioner within 3 business days of determining one occurred, notify affected consumers within 60 days, and certify compliance to the Commissioner annually by February 15.

Because its bound party, an insurance licensee, is a role the LexLint activity vocabulary cannot yet express, it is deferred rather than flagged on a guess (#6740), and no instrument for it is filed here.

Section 12B-104 gives the Attorney General, through the Director of Consumer Protection of the Department of Justice under Title 29, Chapter 25, authority to bring an action in law or equity to address a violation of the chapter and to recover direct economic damages, or both; the chapter's own text neither grants nor expressly disclaims a private right of action for a violation of section 12B-100, and no published enforcement record specific to the safeguards duty, as against the chapter's breach-notice half, was located.

Delaware's breach-notification duty, Del. Code Ann. tit. 6, sections 12B-101 to 12B-104, the other half of the same chapter, is already this jurisdiction's privacy row rather than repeated here; it requires notice to an affected Delaware resident without unreasonable delay and no later than 60 days after determination of a breach, and notice to the Attorney General where more than 500 residents are affected.

The Delaware Personal Data Privacy Act's own security-of-processing duty, Del. Code Ann. tit. 6, section 12D-106(a)(3), requiring a controller to establish, implement, and maintain reasonable administrative, technical, and physical data security practices, is that comprehensive regime's own security clause and stays with this jurisdiction's privacy row rather than being split out here, the same rule the corpus applies to General Data Protection Regulation (GDPR) Article 32.

Delaware's computer crime statute, Del. Code tit. 11, sections 932, 939, 941, is an offense committed against a system by an intruder and belongs to this jurisdiction's scraping row rather than this one; a computer-misuse offense alone is not a security-topic presence.

Security baseline statutes

Computer Security Breaches, protection of personal information

Del. Code Ann. tit. 6, section 12B-100Official statute text, Delaware Code Online, Title 6 Chapter 12B

In force since 14 April 2018. Binds public and private bodies.

What this law does

Any person, including a government entity, who conducts business in Delaware and owns, licenses, or maintains personal information must implement and maintain reasonable procedures and practices to prevent the unauthorized acquisition, use, modification, disclosure, or destruction of that personal information, collected or maintained in the regular course of business.

The duty was added to the Computer Security Breaches chapter by 81 Del. Laws, c. 129, section 1, alongside that chapter's breach-notification amendments; the Act was approved August 17, 2017 and, by its own Section 2, became effective 240 days later, on April 14, 2018.

The Attorney General, through the Director of Consumer Protection of the Department of Justice under Title 29, Chapter 25, may bring an action in law or equity to address a violation of the chapter and to recover direct economic damages resulting from a violation, or both; the chapter states no fixed civil penalty or statutory damages figure for this duty and creates no criminal offense.

What it requires

Age gating law2 instruments, 1 in force, 1 proposed

Research summary (101 words)

Delaware has no adult content age verification law in effect. A 2024 bill that would have required age verification on websites publishing material harmful to minors (HB 265) passed the House but died in the Senate Executive Committee when the 152nd General Assembly adjourned, and no similar bill has been enacted since.

The state's 2024 comprehensive privacy law, the Delaware Personal Data Privacy Act, effective January 1, 2025, requires parental or teen consent before a business processes a minor's data for targeted advertising or sale, but Delaware has not enacted a social media account restriction, app store, or design code law.

Adult content age verification (AV)

HB 265 (2024), age verification for material harmful to minors

House Bill No. 265, 152nd General Assembly (not enacted)official Delaware General Assembly bill history

Proposed: draft date not recorded. Binds private bodies.

What this law does

Would have required a commercial entity that knowingly publishes material harmful to minors online to verify a visitor's age using a government issued ID or comparable method, with civil penalties and liability for a minor's access. Cleared the Delaware House in June 2024 but died in the Senate Executive Committee (last action June 18, 2024) when the 152nd General Assembly adjourned.

Note and primary source

Social media and minors

Delaware Personal Data Privacy Act, consent for minors' data

Del. Code tit. 6, ch. 12D, Secs. 12D-101 to 12D-111official Delaware Code text

In force since 1 January 2025. Binds private bodies.

What this law does

Requires a business to obtain verifiable parental consent before processing the personal data of a known child under 13, and the teen's own consent for a consumer age 13 to 17, before using that data for targeted advertising, sale, or certain profiling.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.