Delaware
Delaware Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 6 primary sources cited on this page. How we verify our legal content

Delaware requires businesses to notify affected residents of a data breach within 60 days of determining a breach occurred, under Del. Code tit. 6, 12B-102. The 60-day clock starts when the business has sufficient evidence a breach took place, not at the moment of the breach itself.
When a business suffers a data breach that exposes Delaware residents' personal information, state law imposes strict notification obligations. Delaware's Computer Security Breaches statute, Del. Code tit. 6, Ch. 12B, requires prompt notification to affected individuals, and in larger breaches, to the Attorney General. Originally enacted in 2005, the law received a major overhaul through HB 180 (81 Del. Laws, c. 129) in 2017, which tightened deadlines, expanded the definition of personal information, and added the AG notification requirement.
This guide covers who must comply, what triggers notification, the timeline and content requirements, enforcement, and how the 2025 Delaware Personal Data Privacy Act (DPDPA) interacts with breach obligations.
Who Must Comply With Delaware's Breach Notification Law
The law applies to any person that conducts business in Delaware and owns, licenses, or maintains computerized data containing personal information of Delaware residents. "Person" is defined broadly under Section 12B-101(6) and includes individuals, corporations, LLCs, partnerships, trusts, joint ventures, government agencies, and any other legal or commercial entity.
Delaware uses two distinct compliance tiers. Data owners and licensees carry the direct notification duty. Third-party data maintainers (such as cloud hosting providers or payment processors) must notify and cooperate with the data owner immediately after discovering a breach, sharing all information relevant to the incident.
Entities with Separate Compliance Frameworks
Section 12B-103 provides that a person regulated by state or federal law, including entities governed by HIPAA or the Gramm-Leach-Bliley Act, that maintains breach procedures set by its primary or functional regulator is deemed in compliance if it notifies affected Delaware residents in accordance with those procedures.
House Bill 381, signed and effective September 2, 2026 (85 Del. Laws ch. 464), narrowed that safe harbor. It now deems a regulated person in compliance with Section 12B-102(c), the 60-day notification timing rule, rather than with the entire chapter. Following a regulator's procedures no longer stands in for the rest of Chapter 12B, including the Attorney General notice duty and the credit monitoring requirement for Social Security number breaches.
Similarly, any business that maintains its own breach notification procedures as part of an information security policy can comply by following those internal procedures, as long as the timing aligns with Delaware's 60-day deadline.
What Qualifies as a Breach of Security

Under Section 12B-101(1), a breach of security is the unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information.
The statute includes a good faith exception. If an employee or agent acquires personal information as part of their legitimate job duties, that does not constitute a breach, provided the data is not used for an unauthorized purpose or disclosed further without authorization.
The Encryption Safe Harbor
Delaware provides a clear safe harbor for encrypted data. A breach does not trigger notification obligations if the compromised personal information was encrypted, unless the unauthorized party also acquired (or is reasonably believed to have acquired) the encryption key.
This means businesses that encrypt personal information at rest and in transit can avoid notification requirements, but only if the encryption keys remain secure. If both the encrypted data and the key are compromised, the full notification obligations apply.
Personal Information That Triggers Notification
Delaware has one of the more comprehensive definitions of personal information among state breach notification laws. Under Section 12B-101(7), personal information means a Delaware resident's first name or first initial and last name combined with any one or more of the following:
- Social Security number
- Driver's license number or state/federal identification card number
- Financial account number, credit card number, or debit card number, combined with any required security code, access code, or password that would permit account access
- Passport number
- Username or email address, combined with a password or security question and answer that would permit access to an online account
- Medical history, medical treatment by a healthcare professional, diagnosis of a mental or physical condition, or DNA profile
- Health insurance policy number, subscriber identification number, or other unique health insurer identifier
- Unique biometric data generated from measurements or analysis of human body characteristics for authentication purposes
- Individual taxpayer identification number
Personal information does not include publicly available information lawfully obtained from federal, state, or local government records or widely distributed media.
DPDPA Expands Biometric Protections
The Delaware Personal Data Privacy Act, effective January 1, 2025, classifies biometric data as sensitive personal data under Section 12D-102(30). This means businesses must obtain affirmative consent before collecting biometric data, and a breach involving such data triggers both notification under Chapter 12B and potential enforcement under the DPDPA. For more on how Delaware regulates biometric data, see our guide to Delaware biometric privacy law.
Notification Timeline and Requirements

The 60-Day Deadline
Delaware imposes a firm 60-day notification deadline. Under Section 12B-102(c), notice must be provided without unreasonable delay and no later than 60 days after the business determines a breach has occurred.
The clock starts at the "determination of the breach," which Section 12B-101(2) defines as the point when the data holder has sufficient evidence to conclude a breach took place. The investigation period before that determination does not count against the 60 days.
Section 12B-102(a) itself carries a risk-of-harm exception that applies to the entire notification duty, not just the credit monitoring requirement described below. If, after an appropriate investigation, the business reasonably determines the breach is unlikely to result in harm to the affected residents, notification of that breach is not required at all.
Exceptions to the 60-Day Rule
Three situations can modify the timeline:
-
Federal law requires a shorter deadline. If another applicable federal regulation mandates faster notification, the business must meet that stricter deadline.
-
Law enforcement delay. A law enforcement agency can request a delay if notification would impede a criminal investigation. The business must notify affected individuals as soon as law enforcement confirms the notification will no longer compromise the investigation.
-
Extended identification period. If a business cannot identify all affected Delaware residents within 60 days despite reasonable diligence, it must notify those individuals as soon as practicable after it determines their personal information was involved. House Bill 381, effective September 2, 2026, added an express Attorney General duty to this exception: the business must also give notice of the breach to the Attorney General within 60 days after determining the breach occurred, unless it provides substitute notice under Section 12B-101(5)d. within that same 60 days.
Methods of Notification
Section 12B-101(5) allows four notification methods:
- Written notice sent to the affected individual
- Telephonic notice delivered directly
- Electronic notice, if consistent with federal E-SIGN Act requirements or if email is the primary communication channel with the individual
- Substitute notice, available when notification costs exceed $75,000, more than 100,000 Delaware residents are affected, or the business lacks sufficient contact information
Substitute notice requires all four of the following: email notification (if addresses are available), conspicuous posting on the company's website, notice to major statewide media outlets including newspapers, radio, television, and the company's major social media platforms, and notice of the breach to the Attorney General. That fourth component was added to Section 12B-101(5)d. by House Bill 381, signed and effective September 2, 2026.
Special Rule for Email Credential Breaches
When a breach involves login credentials for an email account provided by the breached entity, the business cannot send the notification to that compromised email address. Instead, it must use another approved method or deliver a clear, conspicuous notice when the resident logs into the account from a recognized IP address or location.
Attorney General Notification
Under Section 12B-102(d), when a breach affects more than 500 Delaware residents, the business must notify the Delaware Attorney General no later than the time individual notifications are sent. The AG notification goes to the Fraud and Consumer Protection Division, which maintains a public page tracking reported breaches.
What House Bill 381 Changed on September 2, 2026
House Bill 381 was signed into law on September 2, 2026 and took effect that same day as 85 Del. Laws ch. 464. It expanded when the Attorney General has to be told about a breach in two ways. Notice to the Attorney General is now a required fourth component of substitute notice under Section 12B-101(5)d. And under Section 12B-102(c)(3), a business that cannot identify all affected residents within 60 days must still notify the Attorney General within 60 days after determining the breach occurred, unless it has provided substitute notice within that window.
The more than 500 resident threshold in Section 12B-102(d) is unchanged by House Bill 381. The version of Chapter 12B published on the Delaware Code website may not yet show these amendments, so check the enacted bill text for the current language.
Credit Monitoring for SSN Breaches
When a breach involves Social Security numbers, Section 12B-102(e) requires the breached entity to offer free credit monitoring services for one year to each resident whose Social Security number was breached or is reasonably believed to have been breached. In a mixed breach where only some residents had their Social Security numbers exposed, this duty runs to that subset, not to everyone who receives a breach notice. The business must also provide instructions on how to place a credit freeze. This obligation does not apply if an appropriate investigation determines the breach is unlikely to cause harm.
Data Security Obligation
Beyond notification, Section 12B-100 imposes a standalone duty on any person conducting business in Delaware to implement and maintain reasonable procedures and practices to prevent the unauthorized acquisition, use, modification, disclosure, or destruction of personal information. This security requirement applies independently of any breach event.
Enforcement and Penalties

Attorney General Enforcement
The Delaware Attorney General enforces Chapter 12B through the Consumer Protection Division under Section 12B-104. The AG can bring an action in law or equity to address violations and recover direct economic damages resulting from noncompliance.
No Private Right of Action
Delaware's breach notification law does not create a private right of action. Individual consumers cannot sue businesses directly for failing to comply with the notification requirements. However, Section 12B-104(b) preserves any existing rights individuals may have under common law, other statutes, or other legal theories.
DPDPA Enforcement Overlap
The DPDPA, effective January 1, 2025, gives the Attorney General additional enforcement authority over data privacy violations. If a breach results from inadequate data protection practices, the AG could pursue enforcement under both Chapter 12B (breach notification) and Chapter 12D (privacy violations), with DPDPA penalties reaching up to $10,000 per violation.
How Delaware Compares to Neighboring States
Delaware's 60-day notification deadline places it in the middle of the pack nationally. Some states, like Florida, impose 30-day deadlines. Others have no specific deadline and require only that notice occur in a "reasonable" time.
Delaware stands out for its broad definition of personal information, which includes nine categories of protected data. The credit monitoring requirement for SSN breaches also goes beyond what many states mandate.
For a broader view of how Delaware handles data privacy, see our Delaware Data Privacy Laws overview.
This article provides general legal information about Delaware data breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in Delaware for guidance specific to your situation.
More Delaware Laws
Frequently Asked Questions
How quickly must a business notify Delaware residents of a data breach?
Delaware law requires notification within 60 days after the business determines a breach occurred. The clock starts when the business has sufficient evidence to conclude a breach took place, not when the breach itself happened. Law enforcement can request a delay if notification would interfere with a criminal investigation.
Does Delaware require notification to the Attorney General?
Yes. When a breach affects more than 500 Delaware residents, the business must notify the Delaware Attorney General's Fraud and Consumer Protection Division no later than the time individual notices are sent. House Bill 381, effective September 2, 2026, added two more Attorney General notice points: notice to the Attorney General is now a required component of substitute notice, and a business that cannot identify all affected residents within 60 days must notify the Attorney General within 60 days after determining the breach occurred unless it has already given substitute notice.
Is encrypted data exempt from Delaware's breach notification law?
Encrypted data qualifies for a safe harbor, meaning notification is not required if the compromised data was encrypted. However, if the encryption key was also acquired or is reasonably believed to have been acquired during the breach, the safe harbor does not apply and full notification is required.
Can individuals sue for a breach notification violation in Delaware?
No. Delaware's breach notification law does not create a private right of action. Only the Attorney General can enforce the statute. However, individuals may still have claims under common law theories like negligence or other applicable statutes.
How does Delaware's DPDPA affect data breach obligations?
The Delaware Personal Data Privacy Act, effective January 1, 2025, adds a comprehensive data privacy framework that operates alongside the breach notification law. It classifies biometric data as sensitive personal data requiring explicit consent before collection, and gives the Attorney General additional enforcement tools with penalties up to $10,000 per violation for privacy violations related to a breach.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Updated for House Bill 381, signed and effective September 2, 2026 (85 Del. Laws ch. 464): notice to the Attorney General is now a fourth required component of substitute notice, Section 12B-102(c)(3) carries an express 60-day Attorney General notice duty when affected residents cannot be identified in time, and the regulator compliance safe harbor in Section 12B-103(b) now covers only Section 12B-102(c) rather than all of Chapter 12B.
Clarified that Delaware’s free one-year credit monitoring offer is owed to residents whose Social Security numbers were exposed, not to every resident notified of the breach.
Corrected the Delaware Attorney General notification threshold from '500 or more' to 'more than 500' Delaware residents per the statute's exact wording, and clarified that the risk-of-harm exception applies to the entire breach notification duty, not just the credit monitoring requirement.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Delaware Code, Title 6 (Commerce and Trade), Chapter 012b (COMPUTER SECURITY BREACHES)
§ 12B-102Disclosure of breach of security; notice.In force
(a) Any person who conducts business in this State and who owns or licenses computerized data that includes personal information shall provide notice of any breach of security following determination of the breach of security to any resident of this State whose personal information was breached or is reasonably believed to have been breached, unless, after an appropriate investigation, the person reasonably determines that the breach of security is unlikely to result in harm to the individuals whose personal information has been breached. (b) A person that maintains computerized data that includes personal information that the person does not own or license shall give notice to and cooperate with the owner or licensee of the information of any breach of security immediately following determination of the breach of security. For purposes of this subsection, “cooperation” includes sharing with the owner or licensee information relevant to the breach.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at delcode.delaware.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Del. Code tit. 6, Ch. 12B - Computer Security Breaches(delcode.delaware.gov).gov
- Del. Code tit. 6, Ch. 12D - Delaware Personal Data Privacy Act(delcode.delaware.gov).gov
- Delaware AG - Data Security Breaches(attorneygeneral.delaware.gov).gov
- 81 Del. Laws, c. 129 (HB 180, 2017 Amendment)(legis.delaware.gov).gov
- 81 Del. Laws, c. 425(legis.delaware.gov).gov
- Delaware HB 381 (153rd Gen. Assembly), signed September 2, 2026, 85 Del. Laws ch. 464(legis.delaware.gov).gov