USA - Delaware: Revenue-Based Applicability
Delaware Jurisdiction: Revenue-Based Applicability in the Delaware Personal Data Privacy Act
The Delaware Personal Data Privacy Act (PDPA) uses a revenue-based applicability criterion to determine the law's scope, targeting businesses that derive a significant portion of their income from the sale of personal data.
Text of Relevant Provisions
Delaware PDPA Para.12D-103(a)(2):
"(a) This chapter applies to persons that conduct business in the State or persons that produce products or services that are targeted to residents of the State and that during the preceding calendar year did any of the following: (2) Controlled or processed the personal data of not less than 10,000 consumers and derived more than 20 percent of their gross revenue from the sale of personal data."
Analysis of Provisions
- Delaware PDPA Para.12D-103(a)(2) introduces a revenue-based threshold, applying the law to any entity that controls or processes the personal data of at least 10,000 consumers and generates more than 20% of its gross revenue from selling that data. This provision targets businesses whose financial model heavily relies on data monetization.
- By setting the threshold at 20%, Delaware lawmakers ensure that the PDPA applies to businesses where a significant portion of their revenue is directly tied to the sale of personal data, indicating a heightened level of data processing activity and risk. The relatively low consumer threshold of 10,000 individuals also captures smaller businesses that might have a substantial impact on consumer privacy despite their size.
Implications
- Businesses in Delaware that meet these criteria must comply with the PDPA's requirements, including obligations related to data subject rights, data security, and transparency. For example, a small marketing firm that derives over 20% of its income from selling data of 10,000 Delaware residents would be required to adhere to the PDPA.
- This revenue-based criterion necessitates that companies assess their revenue streams and data processing practices. Failure to comply with the PDPA, if applicable, could lead to significant legal and financial repercussions. The focus on revenue derived from data sales underscores the importance of transparency and accountability in data monetization practices.
Jurisdiction Overview
🏛️ Government and Public Agency Exemption🎯 Exemption for Specific Purposes of Processing🏡 Personal and Domestic Use Exemption💼 Doing Business in Jurisdiction⛑️ Nonprofit Organization Exemption👷🏿 Employment and Agency Relationship Exemption💵 Revenue-Based Applicability👴🏿 Benefit administration data🧮 Number of Data Subjects⚖️ Sectoral Exceptions Regulated by Other Laws