Law / United States / Delaware

Computer Security Breaches, protection of personal information

Del. Code Ann. tit. 6, section 12B-100

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 14 April 2018.

A security baseline statutes rule binding public and private bodies.

As of 14 September 2026.

What it requires

  • This binds any person, including a government entity, that conducts business in Delaware and owns, licenses, or maintains personal information of a Delaware resident.
  • Implement and maintain reasonable procedures and practices to prevent the unauthorized acquisition, use, modification, disclosure, or destruction of that personal information, collected or maintained in the regular course of business.
  • There is no separate compliance runway to build against: the duty has been in force since April 14, 2018, when 81 Del. Laws, c. 129, section 1 took effect 240 days after its August 17, 2017 approval.
  • Expect enforcement only from the Delaware Attorney General, through the Director of Consumer Protection, seeking to address a violation and to recover direct economic damages; the chapter does not itself state whether a private plaintiff may also sue.

If you get it wrong

Criminal exposureNo

Who enforces it

Enforcement body

Del. Code Ann. tit. 6, section 12B-104(a) authorizes the Attorney General, through the enforcement duties and powers of the Director of Consumer Protection of the Department of Justice under Title 29, Chapter 25, to bring an action in law or equity to address a violation of this chapter and to recover direct economic damages resulting from a violation, or both.

What it reaches

Obligation class

Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Any person, including a government entity, who conducts business in Delaware and owns, licenses, or maintains personal information must implement and maintain reasonable procedures and practices to prevent the unauthorized acquisition, use, modification, disclosure, or destruction of that personal information, collected or maintained in the regular course of business.

The duty was added to the Computer Security Breaches chapter by 81 Del. Laws, c. 129, section 1, alongside that chapter's breach-notification amendments; the Act was approved August 17, 2017 and, by its own Section 2, became effective 240 days later, on April 14, 2018.

The Attorney General, through the Director of Consumer Protection of the Department of Justice under Title 29, Chapter 25, may bring an action in law or equity to address a violation of the chapter and to recover direct economic damages resulting from a violation, or both; the chapter states no fixed civil penalty or statutory damages figure for this duty and creates no criminal offense.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Official statute text, Delaware Code Online, Title 6 Chapter 12B

Back to the example  ·  Lint your app