Skip to content
Delaware Updates Consumer Privacy and Data-Breach Laws

Delaware Updates Consumer Privacy and Data-Breach Laws

First seen 14 Sep 2026, 02:57 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 15, 2026 at 02:23 UTC
  • Delaware's DPDPA now applies to businesses with as few as 10,000 consumers.
  • New consumer rights include access to actual third-party data recipients.
  • Breach notification law now requires notification to the Delaware Attorney General.

On September 2, 2026, Delaware's Governor signed House Bill (HB) 380 and HB 381, amending the Delaware Personal Data Privacy Act (DPDPA) and the state's computer security breach notification law. HB 380 lowers the applicability threshold for businesses from 35,000 to 10,000 consumers, expanding the law's reach. It also introduces new consumer rights, allowing individuals to obtain lists of actual third parties that have received their personal information. HB 381 updates breach notification requirements, mandating that organizations notify the Delaware Attorney General within 60 days of determining a breach. The amendments take effect on January 1, 2027, for HB 380, while HB 381 is effective immediately. These changes aim to enhance consumer protections and data management practices across various sectors.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-02
Delaware Governor signs HB 380 and HB 381
New laws amend the DPDPA and breach notification requirements to enhance consumer protections.
Mondaq
2026-09-02
Changes to DPDPA take effect
HB 380 amendments will be effective January 1, 2027, lowering the consumer threshold for applicability.
Databreaches
2026-09-02
Breach notification law updated
HB 381 mandates notification to the Delaware Attorney General within 60 days of breach determination.
Databreaches

More articles in this cluster (2)