Law note · Alaska
Alaska Personal Information Protection Act, breach notification duty
A covered person (a person doing business, a governmental agency, or a person with more than 10 employees) that owns or licenses personal information on an Alaska resident must, after discovering or being notified of a breach of the security of the information system containing it, disclose the breach to each affected resident in the most expeditious time possible and without unreasonable delay.
Disclosure is not required if, after an appropriate investigation and written notice to the Alaska Attorney General, the covered person determines there is no reasonable likelihood of harm, a determination that must be documented and kept for five years.
Personal information covers only a name combined with a Social Security number, driver's license or state ID number, or a financial account, credit card, or debit card number with any needed access code; biometric, genetic, and health data are absent from the definition entirely, so a breach of biometric data alone triggers no notice duty under this Act.
What it asks of an app
- Disclose a breach of the security of an information system containing an Alaska resident's personal information to each affected resident in the most expeditious time possible and without unreasonable delay.
- Document and retain for five years any determination, made after investigation and written notice to the Alaska Attorney General, that a breach is unlikely to cause resident harm and so does not require disclosure.
- Do not rely on this statute to cover a breach of biometric, genetic, or health data alone. Alaska's personal information definition does not include any of those categories.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach
Primary source: official Alaska Statutes text, Alaska State Legislature