Law / Nevada

Nevada

age

Nevada has no age gating law on the books in any of the four tracked families: no adult content age verification law, no social media minor access law, no app store age verification law, and no design code.

The Nevada Youth Online Safety Act (SB 63, 2025), an Attorney General backed bill whose final form would have required social media platforms to disable engagement driven features for known minor users and restrict processing of minors' personal data, passed the Senate 13 to 8 on May 27, 2025 and passed the Assembly 26 to 15 with amendments on June 2, 2025, but the Senate never concurred in the Assembly amendment before the Legislature adjourned sine die, so the bill was never enrolled and did not become law; NRS chapter 603, which the bill would have amended, contains no such provisions.

An earlier age appropriate design code bill (AB 320, 2023) also died without a floor vote. The Legislature meets biennially and next convenes in regular session in February 2027.

privacy

Nevada has no comprehensive personal-data-privacy statute. NRS chapter 603A instead layers three sectoral regimes: a general breach-notification duty (NRS 603A.220), an Online Privacy Notice regime that lets a consumer opt out of the sale of narrowly defined covered information to data brokers and website operators (NRS 603A.300-360), and a Consumer Health Data chapter granting access, disclosure-list, cessation, and deletion rights over health-related data (NRS 603A.400-550).

Nevada's only enacted biometric-data definition sits inside the health-data chapter and reaches a voiceprint, faceprint, or other biometric identifier only when it is related to a health condition, diagnosis, or treatment; a general-purpose biometric identifier collected for identification, authentication, or marketing has no Nevada statutory home at all, and the definition carries no exclusion at all for data derived from a photograph, video, or audio recording.

The opt-out chapter expressly denies a private right of action with no deeming route around it; the health-data chapter both deems a violation a deceptive trade practice and expressly denies a private right of action in the same section; the breach chapter grants a data collector its own civil action against whoever caused the breach and is deemed a deceptive trade practice without an express denial, which combines with a narrow elderly-or-disabled civil action statute to give that class, but not the general public, an indirect private right of action.

10 instruments named 4 researched in detail As of 2026-08-27

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

Security breach of personal information, notification

cite NRS 603A.220 stage IMMINENT commencement not set source official Nevada statute text, NRS chapter 603A, Nevada Legislature website

A data collector that owns or licenses computerized data including personal information must disclose a breach of security to an affected Nevada resident in the most expedient time possible and without unreasonable delay, with no fixed numeric deadline, unlike every other statute in this batch. Consumer-reporting-agency notice is required once more than 1,000 persons are notified at one time; no requirement to notify the Nevada Attorney General appears in the text read.

"Personal information" for breach purposes never includes biometric data, so a biometric-only breach does not trigger this duty. A separate section grants a data collector its own civil action against whoever caused the breach, which is not a consumer's private right of action.

But NRS 603A.260 deems any violation of NRS 603A.010 to 603A.290, which includes this breach duty, a deceptive trade practice under NRS 598.0903 to 598.0999, and NRS 598.0977 gives an elderly or disabled Nevada resident harmed by a deceptive trade practice a standalone civil action for actual and punitive damages and attorney's fees; that route is not excepted for this chapter the way it is for NRS 603A.550's consumer health data chapter.

So a general Nevada resident still has no private right of action for a breach-notification violation, but an elderly or disabled resident does, indirectly, through this deeming-plus-UDAP chain. The section's own history note ("Added to NRS by 2005, 2504; A 2023, 3481") gives no printed effective date, so none is recorded here.

What it asks of an app

Data subject rights

Consumer Health Data, access, disclosure, and deletion rights

cite NRS 603A.500-515 stage IMMINENT commencement not set source official Nevada statute text, NRS chapter 603A, Nevada Legislature website

A regulated entity processing consumer health data must give a Nevada consumer the right to access it, obtain a list of third parties it was disclosed to, stop its collection, sharing, or sale, and delete it, sector-scoped to health data rather than a general personal-data right. A controller must respond within 45 days, with one 45-day extension available, and must provide two free responses per consumer per year.

This provision is in force under the current codified text; the underlying research did not establish a dated original commencement this pass, so no effective_date is recorded here.

What it asks of an app

Online Privacy Notice, opt-out of sale

cite NRS 603A.300-360 stage IMMINENT commencement not set source official Nevada statute text, NRS chapter 603A, Nevada Legislature website

An operator of a commercial internet website or online service directed at Nevada residents, or a data broker, must post a privacy notice and, on request, may not sell a Nevada consumer's covered information after the consumer directs it not to.

"Covered information" is limited to name, address, email, phone, Social Security number, and similar contact identifiers plus a catch-all for information maintained with an identifier in personally identifiable form; it never reaches biometric or sensitive-category data as a class. A first-time failure to comply may be cured within 30 days without violating the statute.

This provision is in force under the current codified text; the underlying research did not establish a dated original commencement this pass, so no effective_date is recorded here.

What it asks of an app

Sensitive categories

Consumer Health Data, biometric data definition

cite NRS 603A.415, 603A.430 stage IMMINENT commencement not set source official Nevada statute text, NRS chapter 603A, Nevada Legislature website

Nevada's only enacted biometric-data definition binds a controller only when the biometric data is related to a health condition, diagnosis, treatment, or similar information, making it "consumer health data" under this chapter; it does not operate as a general biometric-privacy statute.

"Biometric data" is defined broadly, including imagery of a fingerprint, palm print, hand print, scar, bodily mark, tattoo, voiceprint, face, retina, iris, or vein pattern, and keystroke or gait patterns or rhythms that contain identifying information, and unlike New Hampshire's, Kentucky's, Rhode Island's, and Vermont's definitions in this wave, it carries no exclusion for a photograph or recording at all, in either direction: imagery of a person's face is itself named as a form of biometric data.

A general-purpose voiceprint or faceprint collected for identification, authentication, or marketing, with no connection to health status, has no Nevada statutory home at all.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.