---
title: Data Breach Notification in Delaware - SCA Security
description: What are the data breach notification laws in Delaware? Statute Codes Breach notification in Delaware is covered under a section of state law called Computer Security Breaches. The official designation is Del. Code Ann. tit. 6 § 12B-101 et seq. It includes H.B. 116, which became law June 28, 2005, and was rendered effective June
image: https://blog.scasecurity.com/hubfs/Imported_Blog_Media/Delaware.jpg
---

[727-571-1141 Talk to an Expert](tel:727-571-1141) [info@scasecurity.com Email Us](mailto:info@scasecurity.com) <https://www.facebook.com/Security-Compliance-Associates-170070577097300/?ref=br_rs> <https://twitter.com/scasecurity> <https://www.linkedin.com/company/security-compliance-associates/>

[![sca-logo-r](https://blog.scasecurity.com/hs-fs/hubfs/sca-logo-r.png?length=190&name=sca-logo-r.png)](https://scasecurity.com/)

☰

- [Home](https://scasecurity.com/)
- [Security](https://scasecurity.com/security/) 
    - [Email Phishing & Employee Training](https://scasecurity.com/anti-phishing-training-with-phished-io/)
    - [Vulnerability Assessments](https://scasecurity.com/security/vulnerability-assessments/)
    - [Penetration Testing](https://scasecurity.com/security/penetration-testing/)
    - [Applications](https://scasecurity.com/security/applications/)
    - [Controls](https://scasecurity.com/security/controls/)
    - [Centurion ESO](https://scasecurity.com/executive-security-officer/)
    - [Consulting](https://scasecurity.com/security/consulting/)
- [Risk & Compliance](https://scasecurity.com/compliance/) 
    - [CMMC](https://scasecurity.com/cybersecurity-maturity-model-certification/)
    - [HITRUST](https://scasecurity.com/hitrust/)
    - [Federal](https://scasecurity.com/compliance/federal/)
    - [State](https://scasecurity.com/compliance/state/)
    - [Industry](https://scasecurity.com/compliance/industry/)
    - [Cybersecurity Risk Assessment](https://scasecurity.com/security/risk-assessment/)
    - [NIST Cybersecurity Framework Assessment](https://scasecurity.com/compliance/nist-framework/)
    - [AI Risk Management Services](https://scasecurity.com/ai-risk-management-services/)
- [Governance](https://scasecurity.com/compliance/governance/)
- [Industries](https://scasecurity.com/industries/) 
    - [Financial Services](https://scasecurity.com/industries/financial-services/)
    - [Healthcare](https://scasecurity.com/industries/healthcare/)
    - [Government/Public Sector](https://scasecurity.com/industries/government-public-sector/)
    - [Title/Real Estate](https://scasecurity.com/industries/title-real-estate/)
    - [Technology](https://scasecurity.com/industries/technology/)
    - [Manufacturing](https://scasecurity.com/industries/manufacturing/)
    - [Professional Services](https://scasecurity.com/industries/professional-services/)
    - [Automotive](https://scasecurity.com/automotive/)
    - [Higher Education](https://scasecurity.com/higher-education/)
- News & Resources 
    - [Blog](https://blog.scasecurity.com)
    - [Events](https://scasecurity.com/event/)
    - [Case Studies](https://scasecurity.com/case-studies/)
    - [Recorded Webinars](https://scasecurity.com/recorded-webinars/)
    - [SCA Breach Notification Guide](https://scasecurity.com/breach-notification-guide/)
    - [HIPAA Security Audit Checklist](https://info.scasecurity.com/hipaa-audit-checklist)
    - [Cybersecurity Checklist for Insurance Providers](https://info.scasecurity.com/cybersecurity-checklist-for-insurance-providers)
- Company 
    - [About Us](https://scasecurity.com/about-us/)
    - [Leadership](https://scasecurity.com/leadership/)
    - [Affiliates](https://scasecurity.com/affiliates/)
    - [Career Opportunities](https://scasecurity.com/career-opportunities/)
    - [Testimonials](https://scasecurity.com/testimonials/)
- [Contact Us](https://scasecurity.com/contact-us/)

#### Menu

 Home

 Security ›

 Email Phishing & Employee Training

 Vulnerability Assessments

 Penetration Testing

 Applications

 Controls

 Centurion ESO

 Consulting

 Risk & Compliance ›

 CMMC

 HITRUST

 Federal

 State

 Industry

 Cybersecurity Risk Assessment

 NIST Cybersecurity Framework Assessment

 AI Risk Management Services

 Governance

 Industries ›

 Financial Services

 Healthcare

 Government/Public Sector

 Title/Real Estate

 Technology

 Manufacturing

 Professional Services

 Automotive

 Higher Education

 News & Resources ›

 Blog

 Events

 Case Studies

 Recorded Webinars

 SCA Breach Notification Guide

 HIPAA Security Audit Checklist

 Cybersecurity Checklist for Insurance Providers

 Company ›

 About Us

 Leadership

 Affiliates

 Career Opportunities

 Testimonials

 Contact Us

[727-571-1141 Talk to an Expert](tel:727-571-1141)

[info@scasecurity.com Email Us](mailto:info@scasecurity.com)

<https://www.facebook.com/Security-Compliance-Associates-170070577097300/?ref=br_rs>

<https://twitter.com/scasecurity>

<https://www.linkedin.com/company/security-compliance-associates/>

 December 13, 2019

# Data Breach Notification in Delaware

 By: SCA Editor

![](https://blog.scasecurity.com/hubfs/Imported_Blog_Media/Delaware.jpg)

## What are the data breach notification laws in Delaware?

### Statute Codes

Breach notification in Delaware is covered under a section of state law called Computer [Security](https://scasecurity.com/security/) Breaches. The official designation is Del. Code Ann. tit. 6 § 12B-101 et seq. It includes H.B. 116, which became law June 28, 2005, and was rendered effective June 28, 2005. H.B. 247 is also included, and was made law June 10, 2010, and signed on the same day. Also, Delaware’s Computer Security Breaches law includes House Substitute 1 for HB 180, which was signed on August 17, 2017, and made effective April 14, 2018.

### Legal Requirements and Purpose

Laws pertaining to breach notification in Delaware apply to entities. Entities include individuals, partnerships, corporations, business trusts, LLCs, associations, governments, joint ventures, subdivisions of government, government agency or instrumentality, corporation of a public kind, or basically any operation or individual defined as an entity in the legal or commercial sense. Delaware law additionally applies to entities exterior to the state who may manage PI of state residents. If you’ve got any PI on Delaware residents, breach notification laws apply to you.

Delaware describes a security breach as unauthorized access of computerized PI; specifically: data that involves integrity, security, or confidentiality of that PI. If PI is  
 encrypted, and it is accessed in an unauthorized way, this isn’t a breach unless those who have obtained such encrypted data can decrypt it. If there’s a reason to believe someone can decrypt the encrypted data, breach notification is also required. If you suspect there’s a decryption key out there, you’d better notify the proper parties. However, good-faith acquisition of PI isn’t a breach, provided it’s also used in good faith.

### Breach Reporting Timeframes

It’s required in Delaware that breach notification take place should PI of any Delaware resident be compromised, or if entities can reasonably believe such data may have been compromised. If, after investigation appropriately conducted, it is determined breached data won’t threaten affected parties, notification isn’t required.

If there are more than 500 residents affected, the entity must contact the AG. This contact must happen no later than the notification of affected residents, and ideally sooner. Credit monitoring services must also be provided should a DE resident’s SSN be compromised. You must, under the law, provide credit monitoring services for a year, for free, if an SSN has been compromised or is believed to have been compromised. Also, Delaware law requires entities to give affected individuals all the information they need to enroll in such credit monitoring services and help them understand how to place a credit freeze on their file. Again, if the investigation shows harm won’t come to affected individuals, notification isn’t necessary.

Pertaining to third parties, if an entity who has PI for them when a breach happens must let them know as soon as reasonably possible. If it’s feasible, this notification should be sent out immediately once a breach has been identified. This notification should include cooperation with third parties and sharing of licensee information if such sharing becomes necessary. Such notification can’t be made later than 60 days in Delaware. If there’s a shorter federal law, then that takes precedence. If it can’t be determined within 60 days that PI was compromised in a breach, then the entity must, as soon as it is feasible to provide notice to affected residents. This is unless substitute notice, which will subsequently be defined, has already been given.

Should it be determined that the cost of providing notice exceeds $75,000, or more than 100,000 residents, or there’s no contact information of affected parties, then three substitute notice efforts are required.

### Contact Security Compliance Associates Today

SCA has years of experience helping organizations across the United States to prevent and manage potential data breaches. Contact us today at 727-571-1141 to schedule a no-cost consultation. You can also download our free [Data Breach Response Guide](https://scasecurity.com/data-breach-response-guide/) to learn more about breach notification law in your state.

#### Subscribe

Email\*

Notification Frequency

[Data Breach](https://blog.scasecurity.com/tag/data-breach)

[September 26, 2024 6 Functions of the NIST Cybersecurity Framework](https://blog.scasecurity.com/nist-security-framework) [September 14, 2023 7 Lessons Learned from the Dish TV Ransomware Attack](https://blog.scasecurity.com/7-lessons-learned-from-the-dish-tv-ransomware-attack) [August 27, 2023 Cybersecurity Consulting: Five Considerations for AI and Privacy Issues](https://blog.scasecurity.com/cybersecurity-consulting-five-considerations-for-ai-and-privacy-issues)

### Comments

© 2026 - All rights reserved.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "SCA Editor",
    "url" : "https://blog.scasecurity.com/author/sca-editor"
  },
  "dateModified" : "2025-04-10T15:41:18.253Z",
  "datePublished" : "2019-12-13T05:00:00.000Z",
  "headline" : "Data Breach Notification in Delaware - SCA Security",
  "image" : [ "https://blog.scasecurity.com/hubfs/Imported_Blog_Media/Delaware.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.scasecurity.com/data-breach-notification-in-delaware",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.scasecurity.com/hubfs/sca-logo-r.png"
    },
    "name" : "Security Compliance Associates"
  }
}
```