Law note · Arizona

Arizona data breach notification law

cite A.R.S. secs. 18-551 to 18-552 stage IMMINENT commencement not set reviewed 2026-08-27

Arizona's breach-notification statute requires a person or entity that owns, maintains, or licenses unencrypted computerized personal information of an Arizona resident to notify the affected individual without unreasonable delay and no later than 45 days after determining a breach of system security occurred.

The duty runs to any 'person' that conducts business in the state, a term A.R.S. sec. 18-551(6) defines to include a government or governmental subdivision or agency alongside a natural person or business entity, with no exclusion for public bodies anywhere in sec. 18-552; this document had previously coded the duty private-only, which understated its reach.

If the breach affects more than 1,000 individuals, the person must also notify the three largest nationwide consumer reporting agencies, the Arizona Attorney General, and the director of the Arizona Department of Homeland Security. Notice may be delayed for an active law enforcement investigation, and no notice is required at all if a reasonable investigation determines there is no substantial risk of economic loss. GLBA- and HIPAA-regulated entities are exempt.

The statute creates no lawful-basis, purpose-limitation, or data-subject-rights framework for ordinary processing; it governs breach response only.

What it asks of an app

  • Notify each affected Arizona resident of a breach of system security involving their personal information without unreasonable delay and no later than 45 days after determining the breach occurred.
  • Notify the Arizona Attorney General, the director of the Arizona Department of Homeland Security, and the three largest nationwide consumer reporting agencies if the breach affects more than 1,000 individuals.
  • Treat a person's unique biometric data generated to authenticate access to an online account as personal information capable of triggering this notification duty. Biometric data collected for a purpose other than online-account authentication is not covered by this statute's biometric element.
  • Expect this statute to be enforced exclusively by the Arizona Attorney General as an unlawful practice under the Arizona Consumer Fraud Act. It creates no private right of action.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach, processes_biometrics, processes_voice

Primary source: official Arizona Revised Statutes text, Arizona State Legislature website

← Back to the example  ·  Lint your app →