Delaware · verified official-source register

Delaware Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Delaware case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

23andMe

Date
2026-07-14
Amount
$150 million in allowed claims for states; recovery limited to $18 million; Delaware will receive $159,654; separate $46.75 million class-action settlement for affected U.S. consumers
Legal basis
Delaware Personal Data Privacy Act

Why the action was brought

23andMe’s 2023 credential-stuffing breach compromised genetic data of 6.9 million customers worldwide, including 16,479 Delawareans; some genetic ancestry information was exposed and subsets were published for sale on the dark web. Investigators alleged unreasonable security practices, including inadequate safeguards, rate limiting, logging, monitoring, investigation of unusual logins, vulnerability remediation, and design testing.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Marriott International, Inc.

Date
2024-10-10
Amount
$52 million payment to states; Delaware will receive nearly $400 thousand
Legal basis
State consumer protection laws, personal information protection laws, and, where applicable, breach notification laws

Why the action was brought

Marriott’s guest reservation database was compromised from July 2014 through September 2018, with intruders undetected and 131.5 million records breached. Records included contact information, birth dates, reservation details, hotel-stay preferences, limited unencrypted passport numbers, and unexpired payment-card information. Attorneys General alleged Marriott failed to implement reasonable security and remediate deficiencies.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Blackbaud

Date
2023-10-12
Amount
$49.5 million; Delaware will receive $380,662
Legal basis
state consumer protection laws, breach notification laws, and HIPAA

Why the action was brought

Blackbaud customers’ constituent data included contact and demographic information, Social Security numbers, driver’s license numbers, financial, employment and wealth information, donation history, and protected health information. Blackbaud allegedly failed to implement reasonable security and remediate known gaps, enabling unauthorized network access, then provided untimely, incomplete, or inaccurate breach information, significantly delaying or preventing consumer notification.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.