Delaware's Personal Data Privacy Act pulls a business into scope once it processes the personal data of 35,000 or more Delaware consumers in a calendar year, the lowest primary threshold of any comprehensive state privacy law that took effect in 2024 or 2025, well below the 100,000-consumer bar Oregon's Consumer Privacy Act uses. Both laws took effect within six months of each other, both are enforced exclusively by a state Attorney General, and both now sit inside the same multistate enforcement network. Where they genuinely diverge is scope and penalty size, not enforcement philosophy.

Delaware DPDPA: the lowest consumer threshold of any 2024-2025 state privacy law DPDPA Delaware, USA, since 2025 35,000 consumers processedto trigger coverage $10,000 per willful violation,Consumer Fraud Act no private right of action,AG enforcement only, cure period sunset Dec 2025

What consumer threshold triggers Oregon's and Delaware's privacy laws?

Oregon's OCPA applies to a business conducting business in Oregon or targeting Oregon residents that controls or processes the personal data of 100,000 or more Oregon consumers in a calendar year, or, as an alternate path, 25,000 or more consumers combined with deriving 25% or more of gross annual revenue from selling personal data. Delaware's DPDPA sets a lower bar: 35,000 or more Delaware consumers, or 10,000 consumers combined with more than 20% of gross revenue from data sales.

Figure 1: Delaware already sits at the lower threshold tier that Connecticut is moving to on July 1, 2026. Source: Delaware DPDPA applicability section, Oregon OCPA applicability section, Recording Law US State Privacy Laws Comparison Chart (2026).

A business that clears Oregon's threshold almost certainly clears Delaware's too, but the reverse is not true: a company processing 50,000 consumer records nationally could owe Delaware compliance while sitting entirely outside Oregon's law, simply because Delaware's population-adjusted reach is broader relative to the size of its market.

How does the two-path threshold test actually work?

Both laws share the same two-path structure: a business is in scope if it clears a straight consumer-count test, or if it clears a lower consumer-count floor while also deriving a set share of revenue from selling personal data. The revenue-linked path exists to catch smaller data brokers that process fewer records but monetize them heavily.

Figure 2: Delaware's revenue-linked path activates at a smaller consumer floor and a lower revenue share than Oregon's. Source: DPDPA and OCPA applicability sections as compiled by Recording Law's US State Privacy Laws Comparison Chart (2026).

A site already checking its Oregon exposure can generate a privacy policy that maps state-by-state applicability rather than treating each new state law as a separate compliance project, since the underlying disclosures, sale opt-outs, and sensitive-data handling largely overlap across both laws.

Oregon's sensitive-data category is also unusually broad: it explicitly includes status as transgender or nonbinary, a category most other state laws, including Delaware's, do not single out by name. A business meeting Oregon's threshold should not assume its Delaware-compliant sensitive-data disclosures automatically cover Oregon's list.

How steep are the civil penalties?

Delaware's Consumer Fraud Act treats a DPDPA violation as a per se violation, capping civil penalties at $10,000 per willful violation. Oregon caps its penalties lower, at $7,500 per violation, enforced exclusively by the Oregon Department of Justice with no separate statutory ceiling tied to revenue.

Figure 3: Delaware's per-violation ceiling is the highest among this group of Virginia-model state laws. Source: Delaware Consumer Fraud Act enforcement provisions, Oregon OCPA enforcement provisions, Recording Law US State Privacy Laws Comparison Chart (2026).

Neither state's penalty scales with company revenue the way GDPR's percentage-of-turnover cap does. Both cap out at a flat per-violation dollar figure, so exposure grows with the number of consumers affected by a violation rather than with company size.

When did each law take effect, and how does that compare to their peers?

Oregon's OCPA took effect July 1, 2024, for most controllers, with a delayed July 1, 2025 compliance date for nonprofit organizations. Delaware's DPDPA followed January 1, 2025, alongside seven other state laws that all started within the same twelve months.

Figure 4: Delaware was one of eight states that started enforcement in 2025, the busiest single year for new state privacy law effective dates so far. Source: IAPP US State Privacy Legislation Tracker; see PrivacyTerms.io's full US state privacy law tracker for every state's effective date.

The eighteen-month gap between Oregon's and Delaware's effective dates gave Delaware's drafters a working model to react to. Delaware's lower 35,000-consumer threshold was a deliberate departure from the 100,000-consumer figure Oregon and most of the 2023 cohort had already settled on, not an oversight.

Do Oregon and Delaware treat cure periods and enforcement coordination the same way?

Both states originally offered a mandatory cure period before a fine could be assessed: Oregon gave businesses 30 days, Delaware gave 60 days. Both rights have since sunset. Oregon's mandatory cure period ended January 1, 2026; Delaware's ended December 31, 2025. In both states, the Attorney General may still grant a cure opportunity, but neither has to.

Figure 5: Delaware paired its broader consumer-count reach with a longer original cure window than Oregon offered. Source: OCPA and DPDPA cure-period provisions as compiled above.

Both states also share the same enforcement network. Oregon and Delaware are both named among the 11 member states of the Consortium of Privacy Regulators as of August 2026, a coordination group that has grown from eight founding member organizations in April 2025, according to the Vermont Attorney General's office, which joined as the twelfth member organization on August 4, 2026. Neither Oregon's nor Delaware's Attorney General has announced a publicly disclosed civil penalty under its respective law as of this post's most recent refresh, matching the pattern seen in most 2023 to 2025 cohort states: enforcement so far has run through cure notices and warning letters rather than court-ordered fines. Connecticut's experience is the clearest evidence this changes with time: its Attorney General's office logged its first CTDPA settlement three years after the law took effect, and Connecticut's own consumer threshold is dropping to Delaware's 35,000 figure starting July 2026.

How do Oregon and Delaware compare feature by feature?

FeatureOregon (OCPA)Delaware (DPDPA)
Consumer threshold100,000, or 25,000 + 25% revenue from data sales35,000, or 10,000 + 20% revenue from data sales
Effective dateJuly 1, 2024 (nonprofits: July 1, 2025)January 1, 2025
Civil penalty cap$7,500 per violation$10,000 per violation
Cure period30 days, AG discretion after January 1, 202660 days, AG discretion after December 31, 2025
Private right of actionNoNo
Nonprofit exemptionNo (delayed compliance only)Yes, exempted outright

Source: Oregon OCPA and Delaware DPDPA applicability and enforcement sections, Recording Law US State Privacy Laws Comparison Chart (2026).

The nonprofit row is the sharpest practical difference. A Delaware nonprofit processing 40,000 consumer records sits outside the DPDPA entirely, while an Oregon nonprofit doing the same volume of business needed to reach OCPA compliance by July 2025, a full year after most for-profit Oregon businesses. Businesses that already track the Utah, Iowa, and Indiana threshold comparison will recognize the same pattern here: the consumer-count number rarely tells the whole applicability story on its own.

The Bottom Line

Delaware's 35,000-consumer threshold and Oregon's 100,000-consumer threshold sit at opposite ends of the range this generation of state privacy laws has settled into, and that gap matters more in practice than either state's penalty cap or cure-period length. A mid-size business with a large Delaware customer list can be squarely inside DPDPA's scope while remaining outside OCPA's, even while running an identical Oregon operation with fewer processed records. Neither state has announced a publicly disclosed fine yet, both now sit inside the same 11-state coordination network, and both lost their guaranteed cure period within the past 14 months, so the practical compliance gap between "watching" and "being investigated" has narrowed in both states at the same time.

Frequently Asked Questions

What is Delaware's consumer threshold under the DPDPA? 35,000 Delaware consumers processed in a calendar year, or 10,000 consumers combined with deriving more than 20 percent of gross revenue from selling personal data. That 35,000-consumer figure is the lowest primary threshold of any state privacy law that took effect in 2024 or 2025.

What is Oregon's consumer threshold under the OCPA? 100,000 Oregon consumers processed in a calendar year, or 25,000 consumers combined with deriving 25 percent or more of gross revenue from selling personal data, nearly three times Delaware's primary 35,000-consumer bar.

What is the maximum civil penalty under each law? Delaware caps civil penalties at $10,000 per willful violation under its Consumer Fraud Act. Oregon caps penalties at $7,500 per violation, $2,500 lower than Delaware's ceiling, enforced exclusively by the Oregon Department of Justice.

Are nonprofits covered by Oregon's or Delaware's privacy law? Oregon's OCPA covers nonprofits, though their compliance deadline was delayed a full year to July 1, 2025. Delaware's DPDPA exempts nonprofit organizations outright, along with institutions of higher education, so a nonprofit in Delaware processing 35,000 or more consumer records still falls outside the law.

Where the Numbers Come From

  1. IAPP. "US State Privacy Legislation Tracker." Source for Oregon's July 1, 2024 and Delaware's January 1, 2025 effective dates, and the 20-state comprehensive privacy law count as of 2026.
  2. Recording Law. (2026). "US State Privacy Laws Comparison Chart." Source for the consumer-count thresholds, revenue-share alternate paths, civil penalty caps, and cure-period figures for Oregon, Delaware, Virginia, and Utah used throughout this post.
  3. Oregon State Legislature. "SB 619 (2023 Regular Session), Oregon Consumer Privacy Act." Enrolled bill text setting the 100,000/25,000-consumer thresholds, the $7,500 per-violation penalty cap, and the nonprofit compliance delay to July 1, 2025.
  4. Office of the Vermont Attorney General. (2026). "Vermont Joins Bipartisan Coalition of Privacy Regulators to Strengthen Data Privacy Efforts." Confirms Oregon and Delaware among the 11 member states of the Consortium of Privacy Regulators as of August 4, 2026.
  5. Measured Collective. State privacy law enforcement tracking. Source for the absence of a publicly disclosed civil penalty under either OCPA or DPDPA as of this post's most recent refresh.

Note: All figures verified as of August 2026. Oregon's and Delaware's specific statutory thresholds, penalty caps, and cure-period sunset dates are drawn from secondary compliance-tracking sources rather than a direct line-by-line read of each state's current codified statute text; readers relying on this post for compliance decisions should confirm against Oregon Revised Statutes Chapter 646A and Delaware Code Title 6 directly before acting. These figures are refreshed at least twice a year as each state's Attorney General publishes new guidance.