Mandated Timeframe
Within 60 days
Violations
Penalties and/or civil relief may apply
Breach Reporting |
Consumer Notifications |
|---|---|
Vendor Management |
Vendor Contract Required |
Minimal |
Basic |
Comprehensive |
Extensive |
|---|
Breach Reporting Requirements
Consumer Notification Requirements
Vendor Notification of Breach
Vendor Specific Obligations
Vendor Mandated Contracts
Protection/Security
Employee Training
Vendor Protection/Security Program
Personal Information Protection
Data Disposal of Personal Information
Mandated Timeframe
Within 60 days.
Violations
Penalties and/or civil relief may apply
BreachReporting |
Consumer Notifications |
|---|---|
Vendor Management |
VendorContract Required |
Minimal |
Basic |
Comprehensive |
Extensive |
|---|
Breach Reporting Requirements
Consumer Notification Requirements
Vendor Notification of Breach
Vendor Specific Obligations
Vendor Mandated Contracts
Protection/Security
Employee Training
Vendor Protection/Security Program
Personal Information Protection
Data Disposal of Personal Information
Mandated Timeframe
Within 60 days.
Violations
Penalties and/or civil relief may apply
BreachReporting |
Consumer Notifications |
|---|---|
Vendor Management |
VendorContract Required |
Minimal |
Basic |
Comprehensive |
Extensive |
|---|
Breach Reporting Requirements
Consumer Notification Requirements
Vendor Notification of Breach
Vendor Specific Obligations
Vendor Mandated Contracts
Protection/Security
Employee Training
Vendor Protection/Security Program
Personal Information Protection
Data Disposal of Personal Information
Organizations must implement and maintain reasonable procedures and practices to protect personal information collected and maintained. Organizations and Vendors conducting business in Delaware must have in place measures to destroy or arrange for the destruction of consumer’s personal identifying records so that the records are made unreadable or indecipherable.
A breach of security involving computerized personal information affecting over 500 residents must be reported to the Attorney General no later than the time of consumer notifications. If a breach of security includes Social Security numbers, credit monitoring services must be provided by the breached Organization for a period of 1 year at no cost to affected consumers. Organizations will be responsible to complete any required regulatory reporting and consumer notification.
Delaware residents affected by a breach of security must be notified of the breach within 60 days unless it is determined after an appropriate investigation that harm to the individual(s) is unlikely. If a breach affects residents of other jurisdictions, those individuals must be notified based on the breach notification laws of the jurisdiction where they reside.
Posting of a Privacy Policy containing specific information is required of any operator of a commercial internet website, online or cloud computing service, application or mobile application that collects personal information of Delaware residents. Education-sector vendors must be contracted and abide by contractual requirements for the protection of educational records. Delaware’s Insurance Data Security Law includes requirements for insurance licensees to protect personal information and investigate and respond to breaches of security. Licensees have until July 31, 2021, to comply with the vendor’s management requirements. Entities regulated by the Insurance Commissioner have a breach notification deadline of 3 business days.
Vendors must notify Organizations immediately after the determination of a breach or suspected breach. Vendors must cooperate with Organizations by providing necessary information about a breach incident.
The Attorney General may bring an action to address violations relating to a security breach and may seek relief appropriate to ensure compliance or recover monetary damages, or both. Civil actions may be brought for violations relating to data disposal laws.
Delaware
Right to inspect personal files / safe destruction of records containing personal identifying information
Safe destruction of records containing personal identifying information
| Cookie | Duration | Description |
|---|---|---|
| cookielawinfo-checbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |

