Alaska's private-sector security law is a single disposal-of-records duty rather than a general reasonable-security-procedures statute, a product-security statute, or a general vulnerability or incident-reporting statute.
Article 4 of the Alaska Personal Information Protection Act, AS 45.48.500 to 45.48.590, enacted by section 4 of Chapter 92, SLA 2008 (HB 65) and in effect since July 1, 2009 under that Act's own section 10, requires a business and a governmental agency alike to take all reasonable measures necessary to protect against unauthorized access to or use of records containing personal information when disposing of them, to adopt a written destruction-and-disposal policy, and to complete due diligence before contracting out record destruction to a third party.
This is a standalone security statute rather than a section of a comprehensive data-protection act, so it sits in this topic under the same Test 1 reasoning as Colorado's disposal duty, C.R.S. 6-1-713, even though its trigger is the same personal-information definition the Act's breach-notification duty uses. That breach-notification duty, AS 45.48.010 to 45.48.070, and its enforcement provision, AS 45.48.080, are this jurisdiction's privacy-topic row and are not repeated here.
No enacted Alaska statute was located, after a search of the full personal-information protection chapter and the surrounding titles of the Alaska Statutes, that sets security requirements a connected device or software product must meet before or after it reaches the market, comparable to California's, Oregon's, or the Cyber Resilience Act's product-security requirements; that reading rests on an affirmative search for connected-device, Internet of Things, manufacturer, vulnerability-disclosure, and critical-infrastructure terms across the statutes rather than on silence alone, so it is recorded as a researched absence.
No general private-sector duty to report a vulnerability or a security incident to an Alaska authority was located outside the insurance sector.
Alaska has enacted a sector-specific cyber-resilience regime that reaches a narrow class of digital-service operator: Senate Bill 134 (2024), codified as Article 2 of AS Title 21, Chapter 23, AS 21.23.240 to 21.23.399, adopts the substance of the NAIC Insurance Data Security Model Law, requiring a licensee of the Alaska Division of Insurance to conduct a risk assessment (AS 21.23.250) and develop, implement, and maintain a comprehensive written information security program based on it (AS 21.23.260), and to investigate and, on specified thresholds and within three business days of determination, notify the director of a cybersecurity event (AS 21.23.270, 21.23.280), with provisions phased in across January 1, 2025, January 1, 2026, and January 1, 2027 per the Division of Insurance's own bulletin.
The regime creates no private cause of action (AS 21.23.240(b)) and exempts a licensee with fewer than ten employees and one already subject to Health Insurance Portability and Accountability Act (HIPAA) (AS 21.23.300).
Its bound party, an insurance "licensee," is not a role this profile's activity vocabulary can express, so it is recorded here rather than filed as an instrument, following the same role-inexpressible-deferral treatment already applied this session to other states' NAIC-model insurance regimes; nothing here should be read as covering a software product simply because its developer happens to also hold an Alaska insurance license.
No dedicated regulator or civil penalty schedule enforces the disposal-of-records duty; a knowing violation is liable to the state for a civil penalty not to exceed $3,000 under AS 45.48.550, and, separately, an individual damaged by a violation may bring a civil action under AS 45.48.560 to enjoin further violations and recover actual economic damages, court costs, and full reasonable attorney fees, arming a private plaintiff in a way the insurance data-security regime does not.