State Breach Law
Arizona Data Breach Notification Law
A.R.S. § 18-551, § 18-552 • Effective 2006-12-31
Arizona gives you 45 days to notify affected residents after determining a breach occurred. If more than 1,000 Arizona residents are affected, you must also notify the Attorney General. The law also requires proper disposal of personal information when you no longer need it.
Notification deadline: 45 days from determination that breach occurred
Enforcement: Arizona Attorney General
Overview
Arizona requires businesses to notify affected residents within 45 days of determining a breach occurred. The law covers both data breach notification and security requirements for disposing of personal information.
Who Must Be Notified
- • Affected Arizona residents (within 45 days)
- • Arizona Attorney General (if 1,000+ residents affected)
- • Consumer reporting agencies (if 1,000+ residents affected)
Covered Data Types
Social Security number, Driver's license number, Financial account number with access code, Private key for electronic signatures, Passport number, Taxpayer ID number, Tribal ID number, Health insurance ID number, Medical history information, Biometric data, Username with password
Notification Requirements
- • Written, telephonic, or electronic notice within 45 days
- • Include date or estimated date of breach
- • Description of personal information involved
- • Contact information for business
- • Contact information for credit bureaus
- • Notify AG if 1,000+ Arizona residents affected
Is your business exposed?
Exemptions
- • Encrypted data (if key not compromised)
- • Good faith acquisition by employee
- • Entities in compliance with GLBA, HIPAA
- • Redacted data
Penalties
Civil penalties up to $10,000 per breach. AG can seek additional penalties up to $500,000 for intentional violations.
If You Experience a Breach
- 1.
Be prepared to meet 45-day notification deadline
- 2.
Create notification templates meeting AZ requirements
- 3.
Know how to report to AZ Attorney General
- 4.
Implement proper disposal procedures for personal information
- 5.
Implement reasonable security measures
- 6.
Train employees on breach detection
Official Source
https://www.azag.gov/consumerIs your business exposed?
Check if your company data is circulating on the dark web
Free scan • No credit card required