Law / United States /
Nevada
Security breach of personal information, notification
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
Commencement not set.
A breach notification rule binding public and private bodies.
As of 2 September 2026.
What it requires
- Disclose a security breach of personal information to an affected Nevada resident in the most expedient time possible and without unreasonable delay. Nevada sets no fixed numeric deadline.
- Notify each nationwide consumer reporting agency if you notify more than 1,000 persons of the breach at one time.
- Do not rely on this statute alone to cover a breach of biometric data with no accompanying identifier. Biometric data alone is not within this statute's definition of personal information.
- Expect an elderly or disabled Nevada resident harmed by a breach-notification violation to have an indirect civil action for damages through NRS 603A.260's deceptive-trade-practice deeming and NRS 598.0977, even though a general Nevada resident does not.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Via the same NRS 603A.260 deeming chain, a natural person, firm, or corporate officer or managing agent who knowingly and willfully engages in the deemed deceptive trade practice is guilty of a misdemeanor (NRS 598.0999(3)(e)), or of a category B, C or D felony where the offense involves a quantifiable loss of property or services (from a category D felony at $1,200 to under $5,000, up to a category B felony at $100,000 or more, punishable by up to 20 years' imprisonment and a $15,000 fine).
Penalty structure
NRS 603A.260 deems a violation of the breach-notification duty (NRS 603A.220) a deceptive trade practice under NRS 598.0903 to 598.0999. NRS 598.0999(2) then lets the Commissioner, the Director, a district attorney, or the Attorney General recover a civil penalty of up to $15,000 per violation the court finds willful; NRS 598.0999(1) separately allows up to $10,000 per violation of a resulting court order or injunction.
- Rule
- Per violation only
- As of
- 2 September 2026
- Currency
- USD
- Per violation unit
- Violation
- Per violation amount
- 15,000
Who enforces it
Enforcement body
Nevada Attorney General, the Commissioner of Consumer Affairs, the Director of the Department of Business and Industry, or a county district attorney, via NRS 603A.260's deeming of a violation as a deceptive trade practice under NRS 598.0903 to 598.0999; also, for an elderly or disabled Nevada resident, an indirect private civil action under NRS 598.0977.
What it reaches
Obligation class
Breach notice
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A data collector that owns or licenses computerized data including personal information must disclose a breach of security to an affected Nevada resident in the most expedient time possible and without unreasonable delay, with no fixed numeric deadline, unlike every other statute in this batch. Consumer-reporting-agency notice is required once more than 1,000 persons are notified at one time; no requirement to notify the Nevada Attorney General appears in the text read.
"Personal information" for breach purposes never includes biometric data, so a biometric-only breach does not trigger this duty. A separate section grants a data collector its own civil action against whoever caused the breach, which is not a consumer's private right of action.
But NRS 603A.260 deems any violation of NRS 603A.010 to 603A.290, which includes this breach duty, a deceptive trade practice under NRS 598.0903 to 598.0999, and NRS 598.0977 gives an elderly or disabled Nevada resident harmed by a deceptive trade practice a standalone civil action for actual and punitive damages and attorney's fees; that route is not excepted for this chapter the way it is for NRS 603A.550's consumer health data chapter.
So a general Nevada resident still has no private right of action for a breach-notification violation, but an elderly or disabled resident does, indirectly, through this deeming-plus-UDAP chain. The section's own history note ("Added to NRS by 2005, 2504; A 2023, 3481") gives no printed effective date, so none is recorded here.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
official Nevada statute text, NRS chapter 603A, Nevada Legislature website
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.