Skip to content

Evidence request lists

Delaware Online Privacy and Protection Act (proposed)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

DOPPA: Digital Book Service User Privacy

DE-DOPPA-1206C
Privacy of book service user information

A book service provider must not knowingly disclose, and must not be compelled to disclose, personal information regarding a user's use of the book service to any person, except under specified circumstances (such as user consent, a court order, or a law-enforcement request meeting defined conditions).

Artefacts an auditor will ask for
  • Controls restricting disclosure of book-service user information to the permitted circumstances
  • Procedure for handling court orders/law-enforcement requests
Where this commonly fails
  • Disclosing reader/book-service data outside the permitted circumstances

DOPPA: Enforcement

DE-DOPPA-1203C
Enforcement

A violation of the Act is enforceable as an unlawful or deceptive trade practice, with enforcement by the Delaware Attorney General / Consumer Protection Unit.

Artefacts an auditor will ask for
  • Compliance evidence (privacy policy, marketing controls, book-service controls) available for regulator inquiry
Where this commonly fails
  • No readiness to evidence DOPPA compliance if the Attorney General inquires

DOPPA: Online Marketing and Advertising to Minors

DE-DOPPA-1204C-MKT
Prohibition on marketing or advertising specified products to minors

An operator of an internet service directed to minors, or with actual knowledge that a minor is using it, must not market or advertise specified age-restricted products and services to minors (including alcohol, tobacco/e-cigarettes, firearms, dietary supplements, tanning, lottery and other listed categories).

Artefacts an auditor will ask for
  • Controls preventing advertising of the listed restricted categories to minors on minor-directed services
  • Age-screening where actual knowledge of minor users exists
Where this commonly fails
  • Serving restricted-product ads on minor-directed services
  • No control over restricted-category advertising to known minors
DE-DOPPA-1204C-PI
Prohibition on using a minor's personal information for restricted marketing

An operator must not knowingly use, disclose, compile, or allow a third party to use, disclose or compile a minor's personal information for the purpose of marketing or advertising the restricted categories of products or services.

Artefacts an auditor will ask for
  • Controls preventing use/disclosure of a minor's personal information for restricted-product marketing
  • Contractual restrictions on third parties
Where this commonly fails
  • Using or sharing a minor's data for restricted-category marketing

DOPPA: Privacy Policy for Commercial Online Services

DE-DOPPA-1205C-CONTENT
Required content of the privacy policy

The privacy policy must identify the categories of personally identifiable information collected and the categories of third parties with whom it may be shared, describe the process for an individual to review and request changes to their information, describe how the operator notifies users of material changes, and state the effective date.

Artefacts an auditor will ask for
  • Privacy policy containing all required content elements
  • Process for users to review and request changes
Where this commonly fails
  • Privacy policy missing required content (categories, third parties, review process, effective date)
DE-DOPPA-1205C-DNT
Do Not Track and cross-site tracking disclosure

The privacy policy must disclose how the operator responds to do not track signals or similar mechanisms, and whether third parties may collect personally identifiable information about a consumer's online activities over time and across different sites when using the operator's service.

Artefacts an auditor will ask for
  • Do Not Track response disclosure in the privacy policy
  • Disclosure of third-party cross-site tracking
Where this commonly fails
  • No Do Not Track disclosure
  • No disclosure of third-party cross-site tracking
DE-DOPPA-1205C-POST
Conspicuous posting of a privacy policy

An operator that collects personally identifiable information about Delaware residents through a commercial internet service must make its privacy policy conspicuously available (e.g., via a link containing the word privacy on the homepage or first significant page).

Artefacts an auditor will ask for
  • A conspicuously posted privacy policy meeting the placement requirements
Where this commonly fails
  • No conspicuous privacy-policy link
  • Privacy policy not reasonably accessible

DOPPA: Scope and Definitions

DE-DOPPA-1201C-1202C
Short title, scope and definitions

The Delaware Online Privacy and Protection Act applies to operators of commercial internet websites, online or cloud computing services, online applications and mobile applications, and to book service providers; it defines operator, minor, personal information, do not track and book service.

Artefacts an auditor will ask for
  • Determination of whether the entity is a DOPPA operator or book service provider
  • Identification of services directed to or knowingly used by Delaware residents/minors
Where this commonly fails
  • Assuming DOPPA does not apply without scoping operator/book-service status
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Delaware Online Privacy and Protection Act (proposed) framework page.