databreaches.net 13 Sept 2026, 14:50 UTC

Delaware Tightens Privacy Rules and Breach Reporting Duties

CyberSIXT Evidence Panel Source marked as original reporting

DELAWARE Governor signed House Bill (HB) 380 and HB 381 on 2 September 2026, updating the state’s privacy and data-breach laws. HB 380 amends the Delaware Personal Data Privacy Act (DPDPA), which took effect on 1 January 2025, while HB 381 changes the computer security breach-notification law. The DPDPA amendments will take effect on 1 January 2027 and expand the businesses and data covered, strengthen protections for sensitive data, and introduce new vendor-management and automated decision-making requirements. HB 381 took effect on signing.

HB 381 changes the rules for substitute notice, which may be used when notification costs exceed $75,000, more than 100,000 Delaware residents are affected, or insufficient contact information is available. Organisations must now also notify the Delaware Attorney General when using substitute notice.

Where reasonable diligence does not establish within 60 days that Delaware residents’ personal information was involved, notification must be issued as soon as practicable after that determination; the Attorney General must also be notified within 60 days of the determination.

The legislation also narrows an existing exemption for organisations regulated under laws such as HIPAA or the Gramm-Leach-Bliley Act. Compliance with regulator-established breach procedures now satisfies only Delaware’s 60-day timing requirement, rather than the state’s full breach-notification obligations.

View full article

Article by CyberSIXT