GroundRules
← Search the law
Delaware · Through 2026-08-10 (85 Del. Laws, c. 421, 424) · Newer source version available

5 Del. C. § 3537: Customer data privacy and information security [For application of this section, see 85 Del. Laws, c. 339, § 2].

Read at publisher ↗
Where this section sits in the code
  1. Title 5. Banking
  2. Other Businesses Under Jurisdiction of State Banking Department
  3. CHAPTER 35. Delaware Payment Stablecoins Act [For application of this chapter, see 85 Del. Laws, c. 339, § 2]
  4. Subchapter VII. Risk Management and Governance [For application of this subchapter, see 85 Del. Laws, c. 339, § 2]

(a) A permitted payment stablecoin issuer licensed under § 3511 of this title shall establish, implement, and maintain a written program to protect the nonpublic personal information of its customers from unauthorized access, use, or disclosure. The program must do all of the following:

(1) Include administrative, technical, and physical safeguards appropriate to the size, complexity, and sensitivity of the customer information maintained by the issuer.

(2) Identify and assess internal and external risks to the security, confidentiality, and integrity of customer nonpublic personal information.

(3) Design and implement safeguards to control the risks identified under paragraph (a)(2) of this section.

(4) Include measures to ensure continuity of operations and recover critical functions in the face of disruptions to systems that maintain or process nonpublic personal information.

(b) A permitted payment stablecoin issuer and affiliates of permitted payment stablecoin issuers may not sell, transfer, or disclose a customer’s nonpublic personal information to a nonaffiliated third party except in any of the following circumstances:

(1) With the prior informed consent of the customer.

(2) As necessary to provide a product or service requested by the customer, subject to appropriate safeguards and contractual protections.

(3) As required by applicable federal or state law, including a lawful order.

(c) Except as otherwise provided in § 12D-103 of Title 6, a permitted payment stablecoin issuer is subject to Chapter 12D of Title 6.

(d) A permitted payment stablecoin issuer that discovers or reasonably suspects an unauthorized acquisition of or access to nonpublic personal information of its customers must do all of the following:

(1) Promptly investigate the incident and take reasonable steps to contain and mitigate any harm to affected customers.

(2) Notify the Commissioner through the Commissioner’s designated supervisory office within 72 hours of becoming aware that a breach of nonpublic personal information has occurred or is reasonably likely to have occurred.

(3) Notify affected customers as soon as reasonably practicable following the investigation described in paragraph (d)(1) of this section, in accordance with the form, timing, and content requirements established by the Commissioner by regulation under subsection (e) of this section. If the permitted payment stablecoin issuer is unable to identify which specific customers’ information has been accessed, it shall notify all customers in the group of files or accounts reasonably believed to have been accessed. Customer notice may be delayed if a federal or state law-enforcement agency determines in writing that notification will interfere with a criminal investigation; upon such determination, the issuer shall notify affected customers as soon as the law-enforcement agency advises that notification will no longer interfere with the investigation.

(e) The Commissioner shall promulgate regulations establishing detailed standards under this section, which must be principles-based and substantially similar to standards applicable to federal qualified payment stablecoin issuers under 12 C.F.R. Part 15, as amended. The Commissioner’s regulations must address, at a minimum, all of the following:

(1) Content and format requirements for the written information security program required by subsection (a) of this section.

(2) Standards for determining when a breach has occurred or is reasonably likely to have occurred for purposes of paragraph (d)(2) of this section.

(3) Form, timing, and content of customer notifications under paragraph (d)(3) of this section.

(4) Coordination with the Commissioner’s supervisory office and relevant law-enforcement agencies in the event of a material breach.

Collected 2026-09-05T23:02:05Z. Source file · JSON

Browse this collection