Law note · Nevada

Security breach of personal information, notification

cite NRS 603A.220 stage IMMINENT commencement not set reviewed 2026-08-27

A data collector that owns or licenses computerized data including personal information must disclose a breach of security to an affected Nevada resident in the most expedient time possible and without unreasonable delay, with no fixed numeric deadline, unlike every other statute in this batch. Consumer-reporting-agency notice is required once more than 1,000 persons are notified at one time; no requirement to notify the Nevada Attorney General appears in the text read.

"Personal information" for breach purposes never includes biometric data, so a biometric-only breach does not trigger this duty. A separate section grants a data collector its own civil action against whoever caused the breach, which is not a consumer's private right of action.

But NRS 603A.260 deems any violation of NRS 603A.010 to 603A.290, which includes this breach duty, a deceptive trade practice under NRS 598.0903 to 598.0999, and NRS 598.0977 gives an elderly or disabled Nevada resident harmed by a deceptive trade practice a standalone civil action for actual and punitive damages and attorney's fees; that route is not excepted for this chapter the way it is for NRS 603A.550's consumer health data chapter.

So a general Nevada resident still has no private right of action for a breach-notification violation, but an elderly or disabled resident does, indirectly, through this deeming-plus-UDAP chain. The section's own history note ("Added to NRS by 2005, 2504; A 2023, 3481") gives no printed effective date, so none is recorded here.

What it asks of an app

  • Disclose a security breach of personal information to an affected Nevada resident in the most expedient time possible and without unreasonable delay. Nevada sets no fixed numeric deadline.
  • Notify each nationwide consumer reporting agency if you notify more than 1,000 persons of the breach at one time.
  • Do not rely on this statute alone to cover a breach of biometric data with no accompanying identifier. Biometric data alone is not within this statute's definition of personal information.
  • Expect an elderly or disabled Nevada resident harmed by a breach-notification violation to have an indirect civil action for damages through NRS 603A.260's deceptive-trade-practice deeming and NRS 598.0977, even though a general Nevada resident does not.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach

Primary source: official Nevada statute text, NRS chapter 603A, Nevada Legislature website

← Back to the example  ·  Lint your app →