Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
cite NRS 603A.220
stage IMMINENT commencement not set
source official Nevada statute text, NRS chapter 603A, Nevada Legislature website
A data collector that owns or licenses computerized data including personal information must disclose a breach of security to an affected Nevada resident in the most expedient time possible and without unreasonable delay, with no fixed numeric deadline, unlike every other statute in this batch. Consumer-reporting-agency notice is required once more than 1,000 persons are notified at one time; no requirement to notify the Nevada Attorney General appears in the text read.
"Personal information" for breach purposes never includes biometric data, so a biometric-only breach does not trigger this duty. A separate section grants a data collector its own civil action against whoever caused the breach, which is not a consumer's private right of action.
But NRS 603A.260 deems any violation of NRS 603A.010 to 603A.290, which includes this breach duty, a deceptive trade practice under NRS 598.0903 to 598.0999, and NRS 598.0977 gives an elderly or disabled Nevada resident harmed by a deceptive trade practice a standalone civil action for actual and punitive damages and attorney's fees; that route is not excepted for this chapter the way it is for NRS 603A.550's consumer health data chapter.
So a general Nevada resident still has no private right of action for a breach-notification violation, but an elderly or disabled resident does, indirectly, through this deeming-plus-UDAP chain. The section's own history note ("Added to NRS by 2005, 2504; A 2023, 3481") gives no printed effective date, so none is recorded here.
What it asks of an app →
Data subject rights
cite NRS 603A.500-515
stage IMMINENT commencement not set
source official Nevada statute text, NRS chapter 603A, Nevada Legislature website
A regulated entity processing consumer health data must give a Nevada consumer the right to access it, obtain a list of third parties it was disclosed to, stop its collection, sharing, or sale, and delete it, sector-scoped to health data rather than a general personal-data right. A controller must respond within 45 days, with one 45-day extension available, and must provide two free responses per consumer per year.
This provision is in force under the current codified text; the underlying research did not establish a dated original commencement this pass, so no effective_date is recorded here.
What it asks of an app →
cite NRS 603A.300-360
stage IMMINENT commencement not set
source official Nevada statute text, NRS chapter 603A, Nevada Legislature website
An operator of a commercial internet website or online service directed at Nevada residents, or a data broker, must post a privacy notice and, on request, may not sell a Nevada consumer's covered information after the consumer directs it not to.
"Covered information" is limited to name, address, email, phone, Social Security number, and similar contact identifiers plus a catch-all for information maintained with an identifier in personally identifiable form; it never reaches biometric or sensitive-category data as a class. A first-time failure to comply may be cured within 30 days without violating the statute.
This provision is in force under the current codified text; the underlying research did not establish a dated original commencement this pass, so no effective_date is recorded here.
What it asks of an app →
Sensitive categories
cite NRS 603A.415, 603A.430
stage IMMINENT commencement not set
source official Nevada statute text, NRS chapter 603A, Nevada Legislature website
Nevada's only enacted biometric-data definition binds a controller only when the biometric data is related to a health condition, diagnosis, treatment, or similar information, making it "consumer health data" under this chapter; it does not operate as a general biometric-privacy statute.
"Biometric data" is defined broadly, including imagery of a fingerprint, palm print, hand print, scar, bodily mark, tattoo, voiceprint, face, retina, iris, or vein pattern, and keystroke or gait patterns or rhythms that contain identifying information, and unlike New Hampshire's, Kentucky's, Rhode Island's, and Vermont's definitions in this wave, it carries no exclusion for a photograph or recording at all, in either direction: imagery of a person's face is itself named as a form of biometric data.
A general-purpose voiceprint or faceprint collected for identification, authentication, or marketing, with no connection to health status, has no Nevada statutory home at all.
What it asks of an app →