REGIONAL COMPLIANCE · PA / NJ / DE / MD

The Mid-Atlantic Recap: E-Waste and Data Destruction Law in Pennsylvania, New Jersey, Delaware, and Maryland

A company with an office in Philadelphia, a warehouse in South Jersey, a branch in Wilmington, and a sales team in Baltimore retires equipment under four different sets of rules — and the differences are not cosmetic. One state bans covered electronics from landfills and makes mid-sized businesses pay for their own recycling. One treats old consumer electronics as universal waste and tells you, in statute, how to destroy customer records. One has no e-waste program at all but lets a consumer sue over careless record destruction. One makes you notify the Attorney General before you notify the people whose data was lost. This recap puts the four rulebooks side by side, as they stand in September 2026, and then explains why the right response is one program, not four.

By Charles Nygard Published 10 min read ↓ PDF one-pager

STRAIGHT ANSWER

Businesses in PA, NJ, DE, and MD face four different rulebooks for retiring IT equipment. Pennsylvania and New Jersey ban covered electronics from disposal; New Jersey, Delaware, and Maryland have data-destruction statutes; all four have breach-notification laws with different regulator-notice rules (Maryland and New Jersey notify the state first). Beneath them sit the FTC Disposal Rule and RCRA. One program built to the strictest requirement — NIST 800-88 destruction, serialized certificates, certified recycling — satisfies all four.

01 / THE FRAMEFour rule sets, four states

Every state regulates retiring IT equipment along the same four axes; the Mid-Atlantic simply answers each one differently. Electronics-disposal law decides whether covered devices may go to a landfill and who pays for recycling. Data-destruction law decides whether a business has a stand-alone statutory duty to destroy records containing personal information before disposal. Breach-notification law decides what happens when an unsanitized device surfaces — who must be told, by when, and in what order. And the universal waste rules decide how the batteries, lamps, and (in one state) electronics that come out of a decommissioned office are handled under the hazardous-waste regime.

Underneath all four sits a federal floor that applies identically in Harrisburg, Trenton, Dover, and Annapolis: the FTC Disposal Rule (16 CFR Part 682) for consumer report information, RCRA for the waste, and the sector overlays — HIPAA, GLBA, FERPA — that attach by industry rather than by state. The Multi-State ITAD Compliance Field Guide covers the fifty-state landscape and the federal floor in depth; this recap zooms in on the four states most of our readers actually operate in, and links to each state's dedicated page for the detail.

The Mid-Atlantic grid — as of September 2026
PennsylvaniaNew JerseyDelawareMaryland
E-waste disposalCovered Device Recycling Act: landfill ban since 2013; free programs only for consumers and businesses under 50 employeesElectronic Waste Management Act: covered devices banned from disposal; manufacturer-funded recyclingNo covered-device program or ban; universal-recycling framework, DNREC guidance, RCRAStatewide Computer Recycling Program (manufacturer-funded); no blanket landfill ban; RCRA applies
Data-destruction statuteNone of general application; FTC Disposal Rule and sector rules governN.J.S.A. 56:8-162 — destroy by shredding, erasing, or making unreadable6 Del. C. Ch. 50C — reasonable steps to destroy; private right of actionCom. Law § 14-3502 — reasonable steps against unauthorized access when destroying
Breach notificationResidents without unreasonable delay; AG when >500 residentsResidents; State Police before customersResidents within 60 days; AG when >500 residentsResidents within 45 days; AG before individuals; CRAs when >1,000
State universal-waste additionsOil-based finishesConsumer electronics; oil-based finishesFederal listFederal list
DetailPennsylvania pageNew Jersey pageDelaware pageMaryland page

02 / PENNSYLVANIAThe landfill ban, the 50-employee line, and the AG at 500

Pennsylvania's Covered Device Recycling Act (Act 108 of 2010) has banned covered devices — desktop and laptop computers, monitors, peripherals, tablets and e-readers with connectivity, and televisions — from municipal waste disposal since January 24, 2013. The statute names generators, haulers, landfills, and transfer stations as parties who can be liable for improper disposal. Its free, manufacturer- and retailer-funded recycling programs are available to consumers and to small businesses with fewer than 50 employees; a business at or above 50, and public entities such as school districts, must arrange and pay for their own covered-device recycling. Cell phones are exempt from the Act.

Pennsylvania has no general business records-destruction statute of the kind New Jersey, Delaware, and Maryland have. Its data duties come from the Breach of Personal Information Notification Act — Act 94 of 2005, substantially amended by Act 151 of 2022 (effective May 2, 2023) and Act 33 of 2024 (effective September 26, 2024). The amendments widened "personal information" to include medical and health-insurance information and a username or email address combined with a password or security question, and added a requirement to notify the Attorney General when more than 500 residents are affected, concurrent with notice to individuals. A lost or unsanitized drive can qualify as the "unauthorized access and acquisition" the Act defines as a breach. On the environmental side, Pennsylvania's universal-waste program (25 Pa. Code Chapter 266b) adopts the federal categories and adds oil-based finishes; it does not list electronics.

03 / NEW JERSEYThe disposal ban, the written destruction standard, and the State Police

New Jersey's Electronic Waste Management Act makes it one of the comprehensive producer-responsibility states: manufacturers fund recycling of covered electronic devices (computers, monitors, portable computers, televisions), and those devices are banned from solid-waste disposal. The free programs are oriented to consumers; the ban applies to everyone. New Jersey is also the one state in the region that lists consumer electronics as a universal waste (N.J.A.C. 7:26A-7, alongside oil-based finishes), which lets qualifying handlers manage them under the streamlined universal-waste standards rather than the full hazardous-waste rules.

On data, New Jersey is the most explicit of the four. N.J.S.A. 56:8-162 requires a business or public entity to "destroy, or arrange for the destruction of" customer records containing personal information that it no longer retains, "by shredding, erasing, or otherwise modifying the personal information in those records to make it unreadable, undecipherable or nonreconstructable through generally available means." The phrase "arrange for the destruction" is why a serialized certificate from a certified provider matters: it is the evidence that the arrangement was carried out. New Jersey's breach statute (N.J.S.A. 56:8-163) then requires notice to affected residents and, distinctively, notice to the Division of State Police before customers are notified; a 2019 amendment (effective September 1, 2019) added online account credentials to the definition of personal information.

04 / DELAWARENo e-waste program, but a private right of action

Delaware has no manufacturer-funded covered-device program and no statewide covered-electronics landfill ban of the Pennsylvania or New Jersey kind. Electronics disposal runs through the state's universal-recycling framework, DNREC guidance, and the federal RCRA rules — which, for a business, still mean that used electronics are evaluated under the commercial hazardous-waste standards and the household exemption does not apply. Delaware follows the federal universal-waste list.

The data side is where Delaware is stricter than its e-waste posture suggests. 6 Del. C. Chapter 50C, in effect since January 1, 2015, requires a commercial entity to take reasonable steps to destroy, or arrange for the destruction of, a consumer's records containing personal identifying information within its custody and control when they are no longer to be retained, by shredding, erasing, or otherwise destroying or modifying the information to make it unreadable. It exempts entities already governed by GLBA, HIPAA, or the Fair Credit Reporting Act, and government — but for everyone else it carries a private right of action: a consumer who suffers actual damages from a reckless or intentional violation may sue. A parallel provision in Title 19 (§ 736) applies the same destruction duty to employers disposing of employee records. Delaware's breach statute (6 Del. C. § 12B-101 et seq.) requires notice to residents within 60 days and to the Attorney General when more than 500 residents are affected, and the Delaware Personal Data Privacy Act, effective January 1, 2025, adds a comprehensive consumer-privacy overlay for covered businesses.

05 / MARYLANDManufacturer-funded recycling and the Attorney General first

Maryland channels electronics recycling through its Statewide Computer Recycling Program, under which manufacturers of covered electronic devices register with the Maryland Department of the Environment and pay fees that fund county collection. There is no single statewide landfill ban on covered electronics, though several counties restrict them; for a business, federal RCRA still governs the hazardous components, and the data laws govern the rest. Maryland follows the federal universal-waste list.

Maryland's Personal Information Protection Act supplies both the destruction duty and the breach rule. Com. Law § 14-3502 requires a business destroying a customer's, employee's, or former employee's records that contain personal information to take reasonable steps to protect against unauthorized access to or use of that information, considering the sensitivity of the records, the nature and size of the business, the costs and benefits of different destruction methods, and available technology — a reasonableness standard that a documented NIST 800-88 process meets comfortably. § 14-3504 then requires notice of a breach to affected individuals within 45 days, notice to the Attorney General before the individuals are notified, and notice to the consumer reporting agencies when more than 1,000 residents are affected. Maryland's definition of personal information reaches health information and biometric data, which puts retired healthcare and access-control equipment squarely in scope.

Two of the four states want to hear from the government before they hear from your customers. Maryland: the Attorney General first. New Jersey: the State Police first. A serialized certificate of destruction is how you never make either call.

06 / ONE PROGRAMBuild to the strictest rule and apply it everywhere

Four rulebooks do not require four programs. Each axis has a strictest answer in the region, and a program built to that answer satisfies the other three states by construction:

  • Disposal: treat every covered electronic device as banned from disposal, as Pennsylvania and New Jersey require. Route all of it to a certified recycler with an audited downstream (R2v3 Appendix A) regardless of which state the pallet is in. That also discharges RCRA's generator responsibility everywhere.
  • Destruction: destroy or sanitize every data-bearing device to NIST SP 800-88 Rev. 2 with a serialized certificate before it leaves your control. That satisfies New Jersey's "unreadable, undecipherable or nonreconstructable" standard, Delaware's reasonable steps, Maryland's reasonableness factors, and the FTC Disposal Rule in one act — and the certificate is the "arrangement" New Jersey and Delaware ask you to be able to show.
  • Breach: a device with a certificate never enters a breach analysis. That is the point of the certificate. It is also the cheapest compliance control in this recap.
  • Universal waste: the lamps and batteries from a decommissioning are universal waste in all four states; label, date, and ship them to a handler or destination facility, and keep the electronics on a separate truck to a certified ITAD provider. The facilities brief has the routing plan.

The Compliance Map lets you click through any state and industry combination; the multi-state guide is the long-form reference; and for organizations in regulated sectors, the bank and credit union brief and the healthcare field guide add the federal overlay. CyberCrunch, headquartered in Greensburg, Pennsylvania, runs one certified program across all four states — the same certificates, chain of custody, and recycling whether the truck is in Scranton or Salisbury.

07 / FAQMid-Atlantic ITAD law FAQ

Can a business in the Mid-Atlantic throw old computers in the dumpster?

In Pennsylvania and New Jersey, no: both ban covered electronic devices (computers, monitors, televisions, and in Pennsylvania peripherals and tablets) from landfill or solid-waste disposal, and Pennsylvania's law reaches generators and haulers as well as landfills. Delaware and Maryland have no equivalent statewide covered-device ban, but business electronics remain subject to federal RCRA hazardous-waste rules, the household exemption does not apply to a business, and the data on the devices is governed by each state's destruction and breach laws. In practice the answer is no in all four states; the reasons differ.

Which Mid-Atlantic states have a data-destruction statute for businesses?

New Jersey (N.J.S.A. 56:8-162, requiring destruction by shredding, erasing, or otherwise making personal information unreadable), Delaware (6 Del. C. Chapter 50C, requiring commercial entities to take reasonable steps to destroy records containing personal identifying information, with a private right of action for reckless or intentional violations), and Maryland (Com. Law 14-3502, requiring reasonable steps against unauthorized access when destroying customer or employee records). Pennsylvania has no general business records-destruction statute of that kind; its obligations arise from its breach-notification law, sector rules, and the federal FTC Disposal Rule, which applies in all four states.

How do the breach-notification rules differ across the four states?

All four require notice to affected residents; the differences are in timing and regulator notice. Pennsylvania requires notice to the Attorney General when more than 500 residents are affected, concurrent with notice to individuals. New Jersey requires notice to the Division of State Police before notifying customers. Delaware requires notice within 60 days and Attorney General notice above 500 residents. Maryland requires notice within 45 days and notice to the Attorney General before notifying individuals, plus consumer reporting agencies above 1,000 residents. A lost or unsanitized device holding residents' personal information is a fact pattern each of these laws reaches.

Are electronics universal waste in any of these states?

Only in New Jersey, which lists consumer electronics (and oil-based finishes) as state universal wastes under N.J.A.C. 7:26A-7, allowing them to be managed under streamlined handler standards rather than full hazardous-waste rules. Pennsylvania adds oil-based finishes but not electronics. Delaware and Maryland follow the federal list (batteries, pesticides, mercury-containing equipment, lamps, aerosol cans). In every state, the batteries and lamps that come out of a decommissioned office are universal waste, and the data-bearing electronics are routed separately to certified IT asset disposition.

What single program satisfies all four states?

Build to the strictest requirement in the region and apply it everywhere: treat every covered electronic device as banned from disposal (Pennsylvania and New Jersey), destroy or sanitize every data-bearing device to NIST SP 800-88 Rev. 2 with a serialized certificate before it leaves your control (which satisfies New Jersey's, Delaware's, and Maryland's destruction statutes and the FTC Disposal Rule, and keeps you out of every breach-notification analysis), recycle through an R2v3-certified provider with an audited downstream, and keep the certificates and chain of custody on file. A program that meets the hardest state's rule meets the other three by construction.

FOUR STATES, ONE STANDARD

One certified program across Pennsylvania, New Jersey, Delaware, and Maryland

CyberCrunch is headquartered in the region and certified to the strictest requirement in it — NAID AAA continuously since 2012, R2v3 with Appendix B, RIOS, and a PA DEP permit. NIST SP 800-88 Rev. 2 destruction, serialized certificates, documented chain of custody, and audited recycling, in every one of the four states and all 50.

This recap is informational only and reflects publicly available sources as of September 2026 — Pennsylvania's Covered Device Recycling Act and Breach of Personal Information Notification Act (as amended by Acts 151 of 2022 and 33 of 2024) and 25 Pa. Code Chapter 266b; New Jersey's Electronic Waste Management Act, N.J.S.A. 56:8-162 and 56:8-163, and N.J.A.C. 7:26A-7; Delaware's 6 Del. C. Chapter 50C, Title 19 § 736, 6 Del. C. § 12B-101 et seq., and Personal Data Privacy Act; Maryland's Statewide Computer Recycling Program and Com. Law §§ 14-3502 and 14-3504; and the federal FTC Disposal Rule and RCRA — described at the pattern level, without penalty figures. It is not legal advice, does not create an attorney-client relationship, and does not address every statute or local ordinance that may apply to your organization. Laws change frequently; confirm current requirements with qualified counsel before acting.