Cybersecurity and AI Law Report published an article examining distinctive aspects of the New Jersey and Delaware privacy law amendments, the compliance challenges they pose, and enforcement trends.
Covington Data Privacy partner Elizabeth Canter was quoted on the pace of change toward prescriptive requirements and heightened scrutiny of data practices, which she said was "striking if you consider that the New Jersey and Delaware privacy laws first came into effect in 2025." Libbie added, "The very next calendar year, the legislatures in both states worked to amend the laws. And while some parts of the amendments echo concerns seen in other states, there are aspects of each of the New Jersey and Delaware amendments that impose novel requirements."
On the Delaware amendment's lowering of the threshold for coverage, Libbie noted that this was "the lowest numeric threshold" across state privacy laws, and observed that it may bring into scope companies that previously were exempt, especially regional ones with a footprint in states without comprehensive privacy laws or in those with higher numerical thresholds.
Regarding Delaware's due diligence and contracting obligations for controllers that sell or disclose personal data to third parties, Libbie called this a "novel requirement," noting that California is the only other state that imposes an obligation to have in place a written contract in certain circumstances where a business is selling or sharing PI for cross-context behavioral advertising with a third party, and that Delaware went beyond California by requiring additional written contractual terms when a business discloses PI to a third party that will use the information for certain profiling activities.
On the New Jersey enforcement outlook, Libbie offered that regulators "have previewed that their enforcement and anticipated guidance will consider how to fairly enforce the law, which may suggest that they do not intend to come in with an unexpected view of how the new provisions should be enforced until after they release clarifying guidance."
Among her compliance tips, Libbie warned that companies relying on vendors for services such as handling data subject requests should be careful not to rely too heavily on vendor tools, advising that "there should be some degree of legal scrutiny and thinking through whether the interface is something a reasonable user would understand."