Law / United States / Nevada

Security measures for data collectors maintaining personal information

NRS 603A.210

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

Commencement not set.

A security baseline statutes rule binding public and private bodies.

As of 14 September 2026.

What it requires

  • This binds any data collector, a term defined to include a governmental agency, institution of higher education, corporation, financial institution, retail operator, or other business entity or association, that maintains records containing the personal information of a Nevada resident.
  • Implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification, or disclosure.
  • If you are a governmental agency, additionally comply, to the extent practicable, with the current version of the CIS Controls published by the Center for Internet Security or the corresponding National Institute of Standards and Technology standards, with respect to the collection, dissemination, and maintenance of those records.
  • Require, by contract, any person to whom you disclose a Nevada resident's personal information to implement and maintain the same reasonable security measures.
  • Compliance with a state or federal law that requires greater protection for the same records is deemed compliance with this section.
  • Expect an elderly or disabled Nevada resident harmed by a violation of this section to have an indirect civil action for damages through NRS 603A.260's deceptive-trade-practice deeming and NRS 598.0977, even though a general Nevada resident does not.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Via NRS 603A.260's deeming of a violation of NRS 603A.010 to 603A.290, inclusive (which includes this section), as a deceptive trade practice under NRS 598.0903 to 598.0999, a natural person, firm, or corporate officer or managing agent who knowingly and willfully engages in the deemed practice is guilty of a misdemeanor, or of a category D, C, or B felony where the offense involves a quantifiable loss of property or services, up to a category B felony at $100,000 or more, punishable by 1 to 20 years' imprisonment and a fine of up to $15,000.

Penalty structure

NRS 603A.260 deems a violation of this section a deceptive trade practice under NRS 598.0903 to 598.0999. NRS 598.0999(2) then lets the Commissioner, the Director, a district attorney, or the Attorney General recover a civil penalty of up to $15,000 per violation the court finds willful.

Rule
Per violation only
As of
14 September 2026
Currency
USD
Per violation unit
Violation
Per violation amount
15,000

Who enforces it

Enforcement body

Nevada Attorney General, the Commissioner of the Consumer Affairs Unit, the Director of the Department of Business and Industry, or a county district attorney, via NRS 603A.260's deeming of a violation as a deceptive trade practice under NRS 598.0903 to 598.0999; also, for an elderly or disabled Nevada resident, an indirect private civil action under NRS 598.0977.

What it reaches

Obligation class

Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A data collector that maintains records containing the personal information of a Nevada resident must implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification, or disclosure.

A data collector that is a governmental agency must, to the extent practicable, additionally comply with the current CIS Controls published by the Center for Internet Security or corresponding National Institute of Standards and Technology standards for the collection, dissemination, and maintenance of those records. A contract disclosing a Nevada resident's personal information must require the recipient to implement and maintain the same reasonable-security duty.

Compliance with a state or federal law requiring greater protection for the same records is deemed compliance with this section.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Official statute text, Nevada Revised Statutes chapter 603A, Nevada Legislature website

Back to the example  ·  Lint your app