What happened
Delaware Governor Matt Meyer signed House Bill 381 on September 2, and it took effect immediately, amending the state's data breach notification law. Three changes matter for anyone holding personal information about Delaware residents.
First, an early reporting trigger aimed at the Attorney General. Delaware already requires notice to the Attorney General for breaches requiring notice to more than 500 residents, due no later than when those residents are told, and notice to individuals without unreasonable delay and within 60 days of determining a breach occurred. HB 381 adds a case that sits earlier in the sequence: if, despite reasonable diligence, an organisation cannot identify within those 60 days that a particular resident's personal information was included, it must notify the Attorney General inside the original 60 day window. Regulator notice can now be due before individual notice.
Second, Attorney General notice becomes part of Delaware's substitute notice process. The existing 500 resident threshold for that notice is unchanged.
Third, and the part regulated entities will feel most, the compliance safe harbour for GLBA regulated financial institutions and HIPAA regulated entities is narrowed. Previously, an organisation that followed breach procedures set by its primary or functional regulator and notified affected residents under those procedures was deemed compliant with the chapter as a whole. That deemed compliance is now limited to the section governing the timing of individual notice. GLBA and HIPAA regulated organisations must separately assess Delaware's Attorney General notification duty and the state's credit monitoring requirement for certain breaches involving Social Security numbers.
Federal obligations do not disappear, and they run on their own clocks, including the FTC's breach notification rule for certain nonbank financial institutions, the NCUA's 72 hour cyber incident reporting rule, and federal banking regulators' 36 hour requirement for certain notifiable computer security incidents.
Why this is a GRC story
Most incident response plans treat notification as a step that follows a completed investigation. Delaware's amendment breaks that assumption for one regulator, which means the plan has to carry two parallel tracks: an interim regulatory notice drafted while the facts are still moving, and individual notices written once the affected population is known.
The safe harbour change is the second lesson. Compliance with a federal regulator's process is not a general shield against state law, and a clause that looked like blanket protection can be narrowed by a state legislature in a single bill. Any team that has been relying on the safe harbour to skip a Delaware analysis should confirm that assumption in writing now.
There is also a drafting nuance for legal counsel. Public statements by the bill's sponsors described the Attorney General requirement more broadly than the enacted text, which does not change the 500 resident threshold. Where legislative history and statutory text diverge, document the reading you are relying on and monitor guidance from the Attorney General's office.
What to watch
Watch for guidance from the Delaware Attorney General on how the early notice interacts with the existing threshold, and whether other states copy the model. Delaware's approach mirrors reporting deadlines already used in Texas and Vermont, which suggests the pattern is spreading rather than staying local.
The practical question for an incident response team is blunt. If an investigation is still running on day 55, can you produce a regulator notification by day 60 without knowing who was affected?
Attribution: Analysis based on JD Supra and related public reporting. This article is original commentary, not a repost of the source material.
