Law / United States / Nebraska
Financial Data Protection and Consumer Notification of Data Security Breach Act, security procedures and practices duty
Neb. Rev. Stat. section 87-808 (added by Laws 2018, LB757, section 7)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 19 July 2018.
A security baseline statutes rule binding public and private bodies.
As of 14 September 2026.
What it requires
- This binds any individual or commercial entity, including a government, governmental subdivision, agency, or instrumentality, that conducts business in Nebraska and owns, licenses, or maintains computerized data including a Nebraska resident's personal information.
- Implement and maintain reasonable security procedures and practices appropriate to the nature and sensitivity of the personal information held and to the nature, size, and resources of the business and its operations, including safeguards that protect the information when it is disposed of.
- Where personal information is disclosed to a nonaffiliated third-party service provider, require by contract that the provider implement and maintain reasonable security procedures and practices of its own, appropriate to the nature of the information disclosed and reasonably designed to protect it from unauthorized access, acquisition, destruction, use, modification, or disclosure.
- A business already subject to and compliant with the Gramm-Leach-Bliley Act Title V regulations or HIPAA and HITECH regulations, or with a state or federal law providing greater protection, is deemed to comply.
- There is no private right of action; only the Attorney General may enforce this section, as a deemed violation of Neb. Rev. Stat. section 59-1602, seeking a civil penalty of up to $2,000 per violation under section 59-1614.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Penalty structure
A violation of Neb. Rev. Stat. section 87-808 is deemed a violation of section 59-1602 under section 87-806(2); section 59-1614 sets the civil penalty for a section 59-1602 violation at not more than $2,000 for each violation, recoverable only by the Attorney General. Neither 87-808 nor the chain through 59-1602/59-1614 states an aggregate cap.
- Rule
- Per violation only
- As of
- 14 September 2026
- Currency
- USD
- Per violation unit
- Violation
- Per violation amount
- 2,000
Who enforces it
Enforcement body
Neb. Rev. Stat. section 87-808 names no dedicated regulator of its own; a violation is deemed a violation of the Consumer Protection Act's unfair-practices section, Neb. Rev. Stat. section 59-1602, and only the Attorney General may bring a civil action to recover the penalty under section 59-1614.
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
An individual or commercial entity that conducts business in Nebraska and owns, licenses, or maintains computerized data including a Nebraska resident's personal information must implement and maintain reasonable security procedures and practices appropriate to the nature and sensitivity of that information and to the nature, size, and resources of the business, including safeguards for disposal of the information.
Where the entity discloses that data to a nonaffiliated third-party service provider, it must require by contract that the provider maintain reasonable security procedures and practices of its own. The Act's own definition of a bound commercial entity reaches a government, governmental subdivision, agency, or instrumentality as well as a private business.
An entity that already complies with a state or federal law giving greater protection, or with the Gramm-Leach-Bliley Act Title V or HIPAA regulations where it is subject to either, is deemed to comply. Only the Attorney General enforces the duty, as a deemed violation of the Consumer Protection Act's unfair-practices section, and the section creates no private right of action.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product