Law note · Arkansas

Arkansas Personal Information Protection Act, breach notification and security

cite Ark. Code Ann. secs. 4-110-101 to 4-110-108 stage IMMINENT commencement not set reviewed 2026-08-27

PIPA requires an individual, business, or state agency that acquires, owns, or licenses personal information of an Arkansas resident to implement and maintain reasonable security procedures, dispose of records properly, and notify affected Arkansas residents of a breach of security without unreasonable delay.

If a breach affects more than 1,000 individuals, the person or business must also notify the Attorney General, at the same time as consumer notice or within 45 days of determining a reasonable likelihood of harm, whichever is first.

Biometric data, including faceprint and voiceprint, is one of the data elements that makes information personal information for these purposes, named with no exclusion for data derived from a photograph or recording, but PIPA imposes no separate capture-consent, retention, or destruction duty on biometric data as such.

PIPA violations are enforced by the Attorney General under the Arkansas Deceptive Trade Practices Act; whether that Act's own private-suit provision, section 4-88-113, also arms a private plaintiff for a PIPA violation specifically was not confirmed from primary text in this research pass and is left as an open question rather than a decided finding.

What it asks of an app

  • Implement and maintain reasonable security procedures and practices to protect Arkansas residents' personal information, and dispose of records containing it in a manner that renders the information unreadable or undecipherable.
  • Notify each affected Arkansas resident of a breach of security without unreasonable delay.
  • Notify the Arkansas Attorney General if the breach affects more than 1,000 individuals, at the same time as consumer notice or within 45 days of determining a reasonable likelihood of harm, whichever occurs first.
  • Treat faceprint and voiceprint data as personal information capable of triggering this Act's security and breach duties. PIPA names them directly with no exclusion for data derived from a photograph or recording.
  • Do not assume PIPA violations are shielded from private suit. Whether the Arkansas Deceptive Trade Practices Act's private right of action reaches a PIPA violation has not been confirmed either way; treat it as an open question rather than a cleared risk.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach, processes_biometrics, processes_voice

Primary source: official Arkansas General Assembly session-law text
Act 1526 of 2005 (original enactment, sections 4-110-102 through 4-110-108) and Act 1030 of 2019 (biometric data and Attorney General notification amendments) no free official mirror of the currently consolidated Arkansas Code was reachable

← Back to the example  ·  Lint your app →