Law / United States / Nevada
Security measures for a data collector accepting payment cards, encryption duty, and conditioned liability shield
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
Commencement not set.
A security baseline statutes rule binding private bodies.
As of 14 September 2026.
What it requires
- If you accept a payment card in connection with a sale of goods or services to a Nevada resident, comply with the current version of the Payment Card Industry (PCI) Data Security Standard adopted by the PCI Security Standards Council, with respect to those transactions, by the compliance date the standard itself sets.
- If you do not accept payment cards, do not transfer a Nevada resident's personal information through an electronic, nonvoice transmission other than a facsimile outside your secure system, and do not move a data storage device containing that personal information beyond your logical or physical controls, unless the data is encrypted using an encryption technology adopted by an established standards-setting body, with appropriate management and safeguards of the cryptographic keys.
- Compliance with this section, combined with a breach not caused by your own gross negligence or intentional misconduct, is a defense to damages for a breach of the security of the system data; a telecommunication provider acting solely to convey the communications of other persons is outside this section entirely.
- Expect an elderly or disabled Nevada resident harmed by a violation of this section to have an indirect civil action for damages through NRS 603A.260's deceptive-trade-practice deeming and NRS 598.0977, even though a general Nevada resident does not.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Via NRS 603A.260's deeming of a violation of NRS 603A.010 to 603A.290, inclusive (which includes this section), as a deceptive trade practice under NRS 598.0903 to 598.0999, a natural person, firm, or corporate officer or managing agent who knowingly and willfully engages in the deemed practice is guilty of a misdemeanor, or of a category D, C, or B felony where the offense involves a quantifiable loss of property or services, up to a category B felony at $100,000 or more, punishable by 1 to 20 years' imprisonment and a fine of up to $15,000.
Penalty structure
NRS 603A.260 deems a violation of this section a deceptive trade practice under NRS 598.0903 to 598.0999. NRS 598.0999(2) then lets the Commissioner, the Director, a district attorney, or the Attorney General recover a civil penalty of up to $15,000 per violation the court finds willful.
- Rule
- Per violation only
- As of
- 14 September 2026
- Currency
- USD
- Per violation unit
- Violation
- Per violation amount
- 15,000
Who enforces it
Enforcement body
Nevada Attorney General, the Commissioner of the Consumer Affairs Unit, the Director of the Department of Business and Industry, or a county district attorney, via NRS 603A.260's deeming of a violation as a deceptive trade practice under NRS 598.0903 to 598.0999; also, for an elderly or disabled Nevada resident, an indirect private civil action under NRS 598.0977.
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A data collector that accepts a payment card in connection with a sale of goods or services must comply with the current Payment Card Industry (PCI) Data Security Standard adopted by the PCI Security Standards Council, with respect to those transactions, not later than the compliance date the standard itself sets.
A data collector to which that duty does not apply must not transfer a Nevada resident's personal information through an electronic, nonvoice transmission other than a facsimile outside its secure system, and must not move a data storage device containing that personal information beyond its logical or physical controls, unless the data collector encrypts the information using a standards-body-adopted encryption technology with appropriate cryptographic key management.
A data collector that complies with this section, and whose breach was not caused by its own gross negligence or intentional misconduct, is not liable for damages for a breach of the security of the system data. The section does not reach a telecommunication provider acting solely to convey the communications of other persons.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
Official statute text, Nevada Revised Statutes chapter 603A, Nevada Legislature website