Law status
Verified comprehensive law
Yes - Delaware Personal Data Privacy Act (DPDPA)
- Official name / citation
- 6 Del. C. Chapter 12D
- Status / effective date
- Identified as the operative comprehensive law in an official AG notice letter
- Principal enforcer
- Delaware Department of Justice / Attorney General
Direct attached-library attribution
0 cases · $0
These totals are assigned solely by the attachment’s state heading. Shared multistate totals are not allocated in full to every state.
The attached library does not enumerate participant-level allocations for every multistate matter; shared settlement totals are presented once at the national level and are not duplicated into state totals.
Official law sources
Other generally applicable PII law
n.a.
Public enforcement context
Tier 1
Marriott International, Inc.
$52 million to the states; Delaware share stated as nearly $400,000 · October 10, 2024
Delaware joined the 50-AG Marriott settlement over a breach affecting 131.5 million guest records.
Legal basis: State consumer protection, personal-information protection and breach-notification laws
Mapped control outcomes
1 personal data inventory/data map; 2 sensitive-data discovery; 3 downstream copy tracking; 8 breach blast-radius analysis; 9 retention/minimization; 10 regulator audit evidence
Kestryl can evidence where regulated personal data actually resides across structured stores and unstructured attachments/images, produce audit rows and evidence packs showing when each location was discovered and reviewed, and apply structured-data remediation modes (mask, vault, strip) to reduce exposure. It does not alter source attachments or documents, and its output is technical evidence supporting controls, not proof of legal compliance.
Educational information, not legal advice. The supplied snapshot is dated August 25, 2026; confirm current law, applicability, exceptions, official status, and reporting decisions with qualified counsel and the relevant authority.