Delaware Data Breach Notification Law: 60-Day Deadline and Penalties

Delaware’s data breach notification law, codified at Title 6, Chapter 12B of the Delaware Code, requires any business that owns, licenses, or maintains computerized personal information of Delaware residents to notify those residents within 60 days of discovering a breach. When Social Security numbers are involved, the business also has to offer at least one year of free credit monitoring. Breaches affecting more than 500 Delaware residents must be reported to the Delaware Attorney General at the same time the residents are notified.

Who Has to Comply

The statute reaches any person or entity conducting business in Delaware that owns, licenses, or maintains computerized data containing personal information of Delaware residents.1Delaware Department of Justice. Data Security Breaches The language is deliberately broad. It captures Delaware corporations, businesses physically located in the state, and out-of-state companies that simply hold data belonging to Delaware residents. Size is not a factor. A three-person startup and a Fortune 500 company face the same obligations.

What Data Triggers the Law

Notification is only required when a breach involves “personal information” as the statute defines it: a Delaware resident’s first name or first initial plus last name, combined with at least one of the following:

  • Social Security number
  • Driver’s license or government ID number
  • An account number, credit card number, or debit card number paired with any security code, access code, or password needed to access the account
  • Passport number
  • A username or email address paired with a password or security question and answer that would unlock the account
  • Medical history, treatment records, diagnoses by a healthcare professional, or a DNA profile
  • Health insurance policy numbers, subscriber IDs, or other unique identifiers used by a health insurer
  • Biometric data generated from measurements or analysis of body characteristics for authentication
  • Individual taxpayer identification number

Delaware’s definition goes further than the older breach laws that focused only on Social Security and financial account numbers. Online login credentials, biometric data, medical records, and taxpayer IDs are all in scope. Publicly available information lawfully obtained from government records or widely distributed media is excluded, even when it appears alongside a name.2Delaware Code Online. Delaware Code Title 6, Chapter 12B – Computer Security Breaches

Encryption offers a safe harbor, but a conditional one. If the compromised data was encrypted, notification is generally not required. If the encryption key was also compromised or reasonably believed to be compromised, the safe harbor disappears and the breach is treated like any other.2Delaware Code Online. Delaware Code Title 6, Chapter 12B – Computer Security Breaches

When a Breach Requires Notice

The statute defines a breach as the unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information. An employee or agent who accesses personal information in good faith for legitimate business purposes has not caused a breach, provided the data is not used improperly or disclosed further.2Delaware Code Online. Delaware Code Title 6, Chapter 12B – Computer Security Breaches

Not every confirmed breach triggers notification. After discovering one, the business must conduct an appropriate investigation and determine in good faith whether the breach is “unlikely to result in harm” to the affected individuals. A reasonable conclusion of no likely harm means notification is not required.3Justia. Delaware Code Title 6 12B-102 – Disclosure of Breach of Security; Notice The word doing the work here is “reasonably.” The assessment has to be documented and defensible. If the Attorney General later reviews it and finds the analysis cursory, enforcement follows. When in doubt, notifying is the safer path.

The 60-Day Deadline and What Can Delay It

Once the business determines a breach occurred and is likely to cause harm, it must notify affected Delaware residents without unreasonable delay and no later than 60 days after discovering the breach.3Justia. Delaware Code Title 6 12B-102 – Disclosure of Breach of Security; Notice The clock starts on the “determination of the breach,” not the date the breach occurred. A breach that happened in January but was discovered in June starts the 60-day window in June.

Three situations adjust that deadline:

  • If another federal law imposes a shorter timeline, that shorter timeline controls.
  • If a law enforcement agency determines notification would interfere with a criminal investigation, notice can be delayed until the agency clears it.
  • If the business cannot identify within 60 days which specific Delaware residents were affected, it must notify them as soon as practicable after making that determination.

None of these eliminate the obligation. They only shift the timing.3Justia. Delaware Code Title 6 12B-102 – Disclosure of Breach of Security; Notice

What the Notice Must Say and How to Send It

Delaware does not prescribe a mandatory template or a list of required elements for a breach notification letter.1Delaware Department of Justice. Data Security Breaches That does not mean anything works. A vague or confusing notice invites Attorney General scrutiny, and the statute imposes specific content requirements when Social Security numbers are involved (below). As a practical matter, a defensible notice describes what happened, what types of personal information were involved, what the business is doing in response, and what the individual can do to protect themselves, including contact information for the business and the major credit bureaus.

Delaware allows three delivery methods:

  • Written notice mailed to the individual’s last known address.
  • Electronic notice, if it complies with the federal Electronic Signatures in Global and National Commerce Act (E-SIGN Act).
  • Substitute notice, available when direct notice is impractical.

Substitute notice becomes available when the cost of direct notification would exceed $75,000, the number of affected Delaware residents exceeds 100,000, or the business lacks sufficient contact information. It requires all three of: email to every affected resident for whom an address is available, a conspicuous posting on the business’s website, and notification to major statewide media including newspapers, radio, television, and major social media platforms.2Delaware Code Online. Delaware Code Title 6, Chapter 12B – Computer Security Breaches

A business that already has internal breach notification procedures as part of an information security program may follow those procedures instead, provided they meet Delaware’s timing requirements.3Justia. Delaware Code Title 6 12B-102 – Disclosure of Breach of Security; Notice

Free Credit Monitoring When Social Security Numbers Are Involved

When a breach involves Social Security numbers, notification alone is not enough. The business must offer each affected Delaware resident free credit monitoring for at least one year. The notice has to include everything the resident needs to enroll, plus instructions on how to place a credit freeze on their credit file.2Delaware Code Online. Delaware Code Title 6, Chapter 12B – Computer Security Breaches

The harm assessment still applies. If a good-faith investigation concludes no harm is likely, credit monitoring is not required. But arguing “no likely harm” after Social Security numbers were exposed is a steep hill.

Notifying the Attorney General

When a breach affects more than 500 Delaware residents, the business must notify the Delaware Attorney General no later than the time it notifies the affected residents.3Justia. Delaware Code Title 6 12B-102 – Disclosure of Breach of Security; Notice The Attorney General’s Consumer Protection Unit runs a dedicated page for these submissions.1Delaware Department of Justice. Data Security Breaches The 500-resident threshold is lower than many businesses expect, and a mid-size retailer or healthcare provider can cross it easily. Treat AG notification as the default unless you have confirmed the count is below 500.

Penalties for Missing the Deadline

Enforcement runs through the Consumer Protection Unit of the Delaware Attorney General’s office. Under Section 12B-104, the Attorney General may bring an action in law or equity to address violations and to recover direct economic damages resulting from non-compliance.4Justia. Delaware Code Title 6 12B-104 – Violations

A common misconception is that the statute sets a fixed $10,000-per-violation fine. It doesn’t. The statute text authorizes the Attorney General to seek “other relief that may be appropriate to ensure proper compliance” and to recover actual economic damages caused by the violation. That open-ended language gives the office significant flexibility, and exposure scales with the number of affected individuals, the severity of the breach, and how the business handled the response.

The statute also preserves other remedies. A business that violates Chapter 12B may still face liability under other state or federal laws, and individuals keep whatever rights they have at common law or under other statutes.4Justia. Delaware Code Title 6 12B-104 – Violations

HIPAA and GLBA Safe Harbor

Businesses regulated by HIPAA or the Gramm-Leach-Bliley Act get a compliance safe harbor. An organization that maintains breach notification procedures under the rules or guidelines of its primary federal or state regulator is considered in compliance with Chapter 12B, as long as it notifies affected Delaware residents consistent with those procedures.2Delaware Code Online. Delaware Code Title 6, Chapter 12B – Computer Security Breaches

This matters most for healthcare providers and financial institutions. A hospital that follows HIPAA’s Breach Notification Rule does not need to build a separate Delaware-specific process, provided the HIPAA notice reaches affected Delaware residents. HIPAA’s own 60-day individual notification deadline aligns with Delaware’s.5The HIPAA Journal. March 1, 2026: Small Healthcare Data Breach HIPAA Reporting Deadline The safe harbor applies to businesses that actually “maintain procedures” under their federal regulator. Being subject to HIPAA or GLBA is not enough on its own. You need written procedures in place and a record of following them.

What About the Personal Data Privacy Act

Delaware’s Personal Data Privacy Act, effective January 1, 2025, is a separate law. It creates broader rights around data access, correction, deletion, opt-outs for sales and targeted advertising, and heightened protections for children’s data.6Delaware Department of Justice. AG Jennings Announces New Data Privacy Rights Available to Delawareans It does not replace Chapter 12B. After a breach, the notification obligations under Chapter 12B still apply regardless of any Privacy Act duties. The data mapping the Privacy Act encourages is also the groundwork that makes breach notification faster when it’s needed.

Getting Ready Before a Breach Happens

Businesses that handle Delaware breach notifications smoothly have done the work in advance. That means an up-to-date inventory of what personal information you hold and where it lives. A written incident response plan that assigns roles, sets internal escalation timelines shorter than 60 days, and includes pre-drafted notification templates. Awareness of the substitute-notice thresholds. And, if your data includes Social Security numbers, a credit monitoring vendor already lined up rather than sourced during a crisis.

Cyber liability insurance is worth considering for organizations without in-house resources. Policies commonly cover breach notification costs, forensic investigation, legal counsel, mailing, and credit monitoring services, and the premium is generally less than assembling those pieces under pressure after a breach has already been discovered.