Law / United States / Nevada

Security breach of personal information, notification

NRS 603A.220

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

Commencement not set.

A breach notification rule binding public and private bodies.

As of 2 September 2026.

What it requires

  • Disclose a security breach of personal information to an affected Nevada resident in the most expedient time possible and without unreasonable delay. Nevada sets no fixed numeric deadline.
  • Notify each nationwide consumer reporting agency if you notify more than 1,000 persons of the breach at one time.
  • Do not rely on this statute alone to cover a breach of biometric data with no accompanying identifier. Biometric data alone is not within this statute's definition of personal information.
  • Expect an elderly or disabled Nevada resident harmed by a breach-notification violation to have an indirect civil action for damages through NRS 603A.260's deceptive-trade-practice deeming and NRS 598.0977, even though a general Nevada resident does not.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Via the same NRS 603A.260 deeming chain, a natural person, firm, or corporate officer or managing agent who knowingly and willfully engages in the deemed deceptive trade practice is guilty of a misdemeanor (NRS 598.0999(3)(e)), or of a category B, C or D felony where the offense involves a quantifiable loss of property or services (from a category D felony at $1,200 to under $5,000, up to a category B felony at $100,000 or more, punishable by up to 20 years' imprisonment and a $15,000 fine).

Penalty structure

NRS 603A.260 deems a violation of the breach-notification duty (NRS 603A.220) a deceptive trade practice under NRS 598.0903 to 598.0999. NRS 598.0999(2) then lets the Commissioner, the Director, a district attorney, or the Attorney General recover a civil penalty of up to $15,000 per violation the court finds willful; NRS 598.0999(1) separately allows up to $10,000 per violation of a resulting court order or injunction.

Rule
Per violation only
As of
2 September 2026
Currency
USD
Per violation unit
Violation
Per violation amount
15,000

Who enforces it

Enforcement body

Nevada Attorney General, the Commissioner of Consumer Affairs, the Director of the Department of Business and Industry, or a county district attorney, via NRS 603A.260's deeming of a violation as a deceptive trade practice under NRS 598.0903 to 598.0999; also, for an elderly or disabled Nevada resident, an indirect private civil action under NRS 598.0977.

What it reaches

Obligation class

Breach notice

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A data collector that owns or licenses computerized data including personal information must disclose a breach of security to an affected Nevada resident in the most expedient time possible and without unreasonable delay, with no fixed numeric deadline, unlike every other statute in this batch. Consumer-reporting-agency notice is required once more than 1,000 persons are notified at one time; no requirement to notify the Nevada Attorney General appears in the text read.

"Personal information" for breach purposes never includes biometric data, so a biometric-only breach does not trigger this duty. A separate section grants a data collector its own civil action against whoever caused the breach, which is not a consumer's private right of action.

But NRS 603A.260 deems any violation of NRS 603A.010 to 603A.290, which includes this breach duty, a deceptive trade practice under NRS 598.0903 to 598.0999, and NRS 598.0977 gives an elderly or disabled Nevada resident harmed by a deceptive trade practice a standalone civil action for actual and punitive damages and attorney's fees; that route is not excepted for this chapter the way it is for NRS 603A.550's consumer health data chapter.

So a general Nevada resident still has no private right of action for a breach-notification violation, but an elderly or disabled resident does, indirectly, through this deeming-plus-UDAP chain. The section's own history note ("Added to NRS by 2005, 2504; A 2023, 3481") gives no printed effective date, so none is recorded here.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach

Read the law

official Nevada statute text, NRS chapter 603A, Nevada Legislature website

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app