Law / United States / Arizona

Arizona data breach notification law

A.R.S. secs. 18-551 to 18-552

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

Commencement not set.

A breach notification rule binding public and private bodies.

As of 27 August 2026.

What it requires

  • Notify each affected Arizona resident of a breach of system security involving their personal information without unreasonable delay and no later than 45 days after determining the breach occurred.
  • Notify the Arizona Attorney General, the director of the Arizona Department of Homeland Security, and the three largest nationwide consumer reporting agencies if the breach affects more than 1,000 individuals.
  • Treat a person's unique biometric data generated to authenticate access to an online account as personal information capable of triggering this notification duty. Biometric data collected for a purpose other than online-account authentication is not covered by this statute's biometric element.
  • Expect this statute to be enforced exclusively by the Arizona Attorney General as an unlawful practice under the Arizona Consumer Fraud Act. It creates no private right of action.

If you get it wrong

Private right of actionNo

What it reaches

Excludes recording-derived identifiersNo

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Arizona's breach-notification statute requires a person or entity that owns, maintains, or licenses unencrypted computerized personal information of an Arizona resident to notify the affected individual without unreasonable delay and no later than 45 days after determining a breach of system security occurred.

The duty runs to any 'person' that conducts business in the state, a term A.R.S. sec. 18-551(6) defines to include a government or governmental subdivision or agency alongside a natural person or business entity, with no exclusion for public bodies anywhere in sec. 18-552, so the duty is not private-sector-only.

If the breach affects more than 1,000 individuals, the person must also notify the three largest nationwide consumer reporting agencies, the Arizona Attorney General, and the director of the Arizona Department of Homeland Security. Notice may be delayed for an active law enforcement investigation, and no notice is required at all if a reasonable investigation determines there is no substantial risk of economic loss. Gramm-Leach-Bliley Act (GLBA)- and Health Insurance Portability and Accountability Act (HIPAA)-regulated entities are exempt.

The statute creates no lawful-basis, purpose-limitation, or data-subject-rights framework for ordinary processing; it governs breach response only.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • processes_biometrics
  • processes_voice

Read the law

official Arizona Revised Statutes text, Arizona State Legislature website

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app