State Breach Law

Arizona Data Breach Notification Law

A.R.S. § 18-551, § 18-552 • Effective 2006-12-31

Arizona gives you 45 days to notify affected residents after determining a breach occurred. If more than 1,000 Arizona residents are affected, you must also notify the Attorney General. The law also requires proper disposal of personal information when you no longer need it.

Notification deadline: 45 days from determination that breach occurred

Enforcement: Arizona Attorney General

Overview

Arizona requires businesses to notify affected residents within 45 days of determining a breach occurred. The law covers both data breach notification and security requirements for disposing of personal information.

Who Must Be Notified

  • Affected Arizona residents (within 45 days)
  • Arizona Attorney General (if 1,000+ residents affected)
  • Consumer reporting agencies (if 1,000+ residents affected)

Covered Data Types

Social Security number, Driver's license number, Financial account number with access code, Private key for electronic signatures, Passport number, Taxpayer ID number, Tribal ID number, Health insurance ID number, Medical history information, Biometric data, Username with password

Notification Requirements

  • Written, telephonic, or electronic notice within 45 days
  • Include date or estimated date of breach
  • Description of personal information involved
  • Contact information for business
  • Contact information for credit bureaus
  • Notify AG if 1,000+ Arizona residents affected

Is your business exposed?

Exemptions

  • Encrypted data (if key not compromised)
  • Good faith acquisition by employee
  • Entities in compliance with GLBA, HIPAA
  • Redacted data

Penalties

Civil penalties up to $10,000 per breach. AG can seek additional penalties up to $500,000 for intentional violations.

If You Experience a Breach

  1. 1.

    Be prepared to meet 45-day notification deadline

  2. 2.

    Create notification templates meeting AZ requirements

  3. 3.

    Know how to report to AZ Attorney General

    AZ AG Consumer Protection

  4. 4.

    Implement proper disposal procedures for personal information

  5. 5.

    Implement reasonable security measures

  6. 6.

    Train employees on breach detection

Official Source

https://www.azag.gov/consumer

Other State Breach Laws

New York, Texas, Florida

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required