Delaware Online Privacy and Protection Act (proposed)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
DOPPA: Digital Book Service User Privacy
A book service provider must not knowingly disclose, and must not be compelled to disclose, personal information regarding a user's use of the book service to any person, except under specified circumstances (such as user consent, a court order, or a law-enforcement request meeting defined conditions).
- Controls restricting disclosure of book-service user information to the permitted circumstances
- Procedure for handling court orders/law-enforcement requests
- Disclosing reader/book-service data outside the permitted circumstances
DOPPA: Enforcement
A violation of the Act is enforceable as an unlawful or deceptive trade practice, with enforcement by the Delaware Attorney General / Consumer Protection Unit.
- Compliance evidence (privacy policy, marketing controls, book-service controls) available for regulator inquiry
- No readiness to evidence DOPPA compliance if the Attorney General inquires
DOPPA: Online Marketing and Advertising to Minors
An operator of an internet service directed to minors, or with actual knowledge that a minor is using it, must not market or advertise specified age-restricted products and services to minors (including alcohol, tobacco/e-cigarettes, firearms, dietary supplements, tanning, lottery and other listed categories).
- Controls preventing advertising of the listed restricted categories to minors on minor-directed services
- Age-screening where actual knowledge of minor users exists
- Serving restricted-product ads on minor-directed services
- No control over restricted-category advertising to known minors
An operator must not knowingly use, disclose, compile, or allow a third party to use, disclose or compile a minor's personal information for the purpose of marketing or advertising the restricted categories of products or services.
- Controls preventing use/disclosure of a minor's personal information for restricted-product marketing
- Contractual restrictions on third parties
- Using or sharing a minor's data for restricted-category marketing
DOPPA: Privacy Policy for Commercial Online Services
The privacy policy must identify the categories of personally identifiable information collected and the categories of third parties with whom it may be shared, describe the process for an individual to review and request changes to their information, describe how the operator notifies users of material changes, and state the effective date.
- Privacy policy containing all required content elements
- Process for users to review and request changes
- Privacy policy missing required content (categories, third parties, review process, effective date)
The privacy policy must disclose how the operator responds to do not track signals or similar mechanisms, and whether third parties may collect personally identifiable information about a consumer's online activities over time and across different sites when using the operator's service.
- Do Not Track response disclosure in the privacy policy
- Disclosure of third-party cross-site tracking
- No Do Not Track disclosure
- No disclosure of third-party cross-site tracking
An operator that collects personally identifiable information about Delaware residents through a commercial internet service must make its privacy policy conspicuously available (e.g., via a link containing the word privacy on the homepage or first significant page).
- A conspicuously posted privacy policy meeting the placement requirements
- No conspicuous privacy-policy link
- Privacy policy not reasonably accessible
DOPPA: Scope and Definitions
The Delaware Online Privacy and Protection Act applies to operators of commercial internet websites, online or cloud computing services, online applications and mobile applications, and to book service providers; it defines operator, minor, personal information, do not track and book service.
- Determination of whether the entity is a DOPPA operator or book service provider
- Identification of services directed to or knowingly used by Delaware residents/minors
- Assuming DOPPA does not apply without scoping operator/book-service status
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Delaware Online Privacy and Protection Act (proposed) framework page.