Law / United States / Alaska

Alaska

United States law applies in Alaska Alaska is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Alaska, described on this page below, applies here too.

6 of 7 named instruments researched to a stage, across three of the six areas of law we track: 4 in force and 2 enacted but not yet in force. As of 16 September 2026.

  1. AI law none researched
  2. Privacy law 2
  3. Scraping law 3
  4. Cybersecurity law 1
  5. Age gating law none researched
  6. News aggregation law none researched

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law2 instruments, 2 enacted but not yet in force

Research summary (205 words)

Alaska has no comprehensive consumer-privacy statute. Article I, Section 22 of the Alaska Constitution recognizes an explicit right of privacy, but the provision's own text directs the legislature to implement it, and Alaska courts have read it as binding government action rather than private conduct, so a private business is not directly bound by it.

The Alaska Personal Information Protection Act (PIPA), AS 45.48.010 to 45.48.090, is the state's operative private-sector privacy statute, a breach notification duty whose personal information definition covers only a name combined with a Social Security number, a driver's license or state ID number, or a financial account number and access code, with no biometric, genetic, or health category of any kind.

A PIPA violation by a non-governmental information collector is deemed an unfair or deceptive act or practice under Alaska's general Unfair Trade Practices and Consumer Protection Act, which arms a private plaintiff with an action for actual economic damages (capped at $500 under one of the two cross-referenced remedy provisions) in addition to a state civil penalty of up to $500 per unnotified resident, capped at $50,000 total.

A comprehensive Consumer Data Privacy Act, HB 367, remains in committee as of this writing and has not passed either chamber.

Breach notification

Alaska Personal Information Protection Act, breach notification duty

Alaska Stat. Secs. 45.48.010-45.48.070official Alaska Statutes text, Alaska State Legislature

Commencement not set. Binds public and private bodies.

What this law does

A covered person (a person doing business, a governmental agency, or a person with more than 10 employees) that owns or licenses personal information on an Alaska resident must, after discovering or being notified of a breach of the security of the information system containing it, disclose the breach to each affected resident in the most expeditious time possible and without unreasonable delay.

Disclosure is not required if, after an appropriate investigation and written notice to the Alaska Attorney General, the covered person determines there is no reasonable likelihood of harm, a determination that must be documented and kept for five years.

Personal information covers only a name combined with a Social Security number, driver's license or state ID number, or a financial account, credit card, or debit card number with any needed access code; biometric, genetic, and health data are absent from the definition entirely, so a breach of biometric data alone triggers no notice duty under this Act.

What it requires

Enforcement supervision

Alaska Personal Information Protection Act, violations and enforcement

Alaska Stat. Sec. 45.48.080official Alaska Statutes text, Alaska State Legislature

Commencement not set. Binds public and private bodies.

What this law does

A governmental agency that violates the breach notification duty is liable to the state for a civil penalty of up to $500 per unnotified resident (capped at $50,000) and may be enjoined, enforced by the Department of Administration.

A non-governmental information collector's violation is instead deemed an unfair or deceptive act or practice under Alaska's Unfair Trade Practices and Consumer Protection Act (AS 45.50.471-45.50.561), which arms a private plaintiff, but this Act caps what that private plaintiff may recover: damages under the Act's general private and class action provision (AS 45.50.531, ordinarily treble damages or $500, whichever is greater) are limited here to actual economic damages not exceeding $500, and damages under the Act's fees-and-costs provision (AS 45.50.537) are limited to actual economic damages.

The non-governmental violator is also liable to the state for the same $500-per-resident, $50,000-total civil penalty as a governmental agency, though not the Act's ordinary civil penalties.

What it requires

Scraping law3 instruments, 3 in force

Research summary (225 words)

Alaska has no dedicated anti-scraping, terms-of-service, or database-right statute; the state's reach over unauthorized data collection runs through its general computer-crime chapter. Criminal use of a computer, AS 11.46.740, is a class C felony reaching a person who exceeds authorized access to a computer system and, as a result, obtains information concerning a person, obtains proprietary information, or obtains information otherwise available to the public only for a fee.

A lower-tier offense, criminal mischief in the fourth degree under AS 11.46.484(a)(3), makes mere unauthorized access to a computer or network a class A misdemeanor with no further act required. Unauthorized use of a computer system is also chargeable as theft of services under AS 11.46.200(a)(3), graded as a felony or misdemeanor under the general theft-degree statutes, AS 11.46.120 to 11.46.150, by the value of the services obtained.

Terms-of-service enforceability, database rights, and text-and-data-mining exceptions are federal-baseline only; Alaska adds nothing state-specific to any of them, and no Alaska statute or regulation assigns robots.txt independent legal weight. Alaska's Personal Information Protection Act reaches personal data a scraper collects; that duty is described in the privacy topic's own document for this jurisdiction rather than restated here.

Alaska's general Unfair Trade Practices and Consumer Protection Act, AS 45.50.471-45.50.561, does not name automated access or data collection in any subsection, so it adds nothing scraping-specific beyond the federal baseline.

Computer misuse

Criminal mischief in the fourth degree, unauthorized computer access

Alaska Stat. Sec. 11.46.484(a)(3)official Alaska Statutes text, Alaska State Legislature

In force. Binds public and private bodies.

What this law does

A person commits criminal mischief in the fourth degree if, having no right to do so or any reasonable ground to believe the person has such a right, the person knowingly accesses a computer, computer system, computer program, computer network, or part of a computer system or network.

Unlike criminal use of a computer under AS 11.46.740, this offense requires no further act after the unauthorized access itself and no showing that the person obtained, damaged, or tampered with anything once inside. Criminal mischief in the fourth degree is a class A misdemeanor.

What it requires

Criminal use of a computer

Alaska Stat. Sec. 11.46.740official Alaska Statutes text, Alaska State Legislature

In force. Binds public and private bodies.

What this law does

A person commits criminal use of a computer if, having no right to do so or any reasonable ground to believe the person has such a right, the person knowingly accesses, causes to be accessed, or exceeds the person's authorized access to a computer, computer system, computer program, or computer network and, as a result, obtains information concerning a person, obtains proprietary information of another person, obtains information that is only available to the public for a fee, introduces false information, or tampers with, disrupts, disables, or destroys a computer, computer system, program, or network.

The offense also reaches installing or using a keystroke logger to record another person's keystrokes without authorization. Criminal use of a computer is a class C felony, a single penalty tier with no lesser degree for a smaller-scale violation.

What it requires

Theft of services, unauthorized use of a computer system

Alaska Stat. Sec. 11.46.200(a)(3)official Alaska Statutes text, Alaska State Legislature

In force. Binds public and private bodies.

What this law does

A person commits theft of services if the person obtains the use of computer time, a computer system, a computer program, a computer network, or any part of a computer system or network, with reckless disregard that the use by that person is unauthorized.

Theft of services obtained through unauthorized computer use is graded under Alaska's general theft-degree statutes by the value of the services obtained: a class B felony at $25,000 or more, a class C felony from $750 up to $25,000, a class A misdemeanor from $250 up to $750, and a class B misdemeanor under $250.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (579 words)

Alaska's private-sector security law is a single disposal-of-records duty rather than a general reasonable-security-procedures statute, a product-security statute, or a general vulnerability or incident-reporting statute.

Article 4 of the Alaska Personal Information Protection Act, AS 45.48.500 to 45.48.590, enacted by section 4 of Chapter 92, SLA 2008 (HB 65) and in effect since July 1, 2009 under that Act's own section 10, requires a business and a governmental agency alike to take all reasonable measures necessary to protect against unauthorized access to or use of records containing personal information when disposing of them, to adopt a written destruction-and-disposal policy, and to complete due diligence before contracting out record destruction to a third party.

This is a standalone security statute rather than a section of a comprehensive data-protection act, so it sits in this topic under the same Test 1 reasoning as Colorado's disposal duty, C.R.S. 6-1-713, even though its trigger is the same personal-information definition the Act's breach-notification duty uses. That breach-notification duty, AS 45.48.010 to 45.48.070, and its enforcement provision, AS 45.48.080, are this jurisdiction's privacy-topic row and are not repeated here.

No enacted Alaska statute was located, after a search of the full personal-information protection chapter and the surrounding titles of the Alaska Statutes, that sets security requirements a connected device or software product must meet before or after it reaches the market, comparable to California's, Oregon's, or the Cyber Resilience Act's product-security requirements; that reading rests on an affirmative search for connected-device, Internet of Things, manufacturer, vulnerability-disclosure, and critical-infrastructure terms across the statutes rather than on silence alone, so it is recorded as a researched absence.

No general private-sector duty to report a vulnerability or a security incident to an Alaska authority was located outside the insurance sector.

Alaska has enacted a sector-specific cyber-resilience regime that reaches a narrow class of digital-service operator: Senate Bill 134 (2024), codified as Article 2 of AS Title 21, Chapter 23, AS 21.23.240 to 21.23.399, adopts the substance of the NAIC Insurance Data Security Model Law, requiring a licensee of the Alaska Division of Insurance to conduct a risk assessment (AS 21.23.250) and develop, implement, and maintain a comprehensive written information security program based on it (AS 21.23.260), and to investigate and, on specified thresholds and within three business days of determination, notify the director of a cybersecurity event (AS 21.23.270, 21.23.280), with provisions phased in across January 1, 2025, January 1, 2026, and January 1, 2027 per the Division of Insurance's own bulletin.

The regime creates no private cause of action (AS 21.23.240(b)) and exempts a licensee with fewer than ten employees and one already subject to Health Insurance Portability and Accountability Act (HIPAA) (AS 21.23.300).

Its bound party, an insurance "licensee," is not a role this profile's activity vocabulary can express, so it is recorded here rather than filed as an instrument, following the same role-inexpressible-deferral treatment already applied this session to other states' NAIC-model insurance regimes; nothing here should be read as covering a software product simply because its developer happens to also hold an Alaska insurance license.

No dedicated regulator or civil penalty schedule enforces the disposal-of-records duty; a knowing violation is liable to the state for a civil penalty not to exceed $3,000 under AS 45.48.550, and, separately, an individual damaged by a violation may bring a civil action under AS 45.48.560 to enjoin further violations and recover actual economic damages, court costs, and full reasonable attorney fees, arming a private plaintiff in a way the insurance data-security regime does not.

Security baseline statutes

Alaska Personal Information Protection Act, disposal of records duty

Alaska Stat. Secs. 45.48.500-45.48.590official Alaska Statutes text, Alaska State Legislature

In force since 1 July 2009. Binds public and private bodies.

What this law does

A business and a governmental agency that disposes of records containing personal information on an Alaska resident must take all reasonable measures necessary to protect against unauthorized access to or use of the records. The business or governmental agency must also adopt written policies and procedures relating to the adequate destruction and proper disposal of those records.

Permitted measures include burning, pulverizing, or shredding paper documents, and destroying or erasing electronic and nonpaper media, so that the personal information cannot practicably be read or reconstructed.

Where a business or governmental agency instead contracts with a third party engaged in the business of record destruction, it must first complete due diligence, ordinarily reviewing an independent audit of the third party's operations, checking references or trade-association certification, or reviewing the third party's own information security policies and procedures.

It is not liable for the disposal once it has relinquished control of the records to that third party or to the individual to whom the records pertain.

A business is exempt if it is subject to and complying with the Gramm-Leach-Bliley Financial Modernization Act, or if the manner of its disposal is subject to and complies with the Fair Credit Reporting Act's disposal rule, 15 U.S.C. 1681w. A business or governmental agency is also exempt to the extent federal law requires a manner of disposal the Alaska duty does not permit. A knowing violation is liable to the state for a civil penalty not to exceed $3,000.

Separately, an individual damaged by a violation may bring a civil action to enjoin further violations and recover actual economic damages, court costs, and full reasonable attorney fees. This duty is distinct from the Act's breach-notification duty, AS 45.48.010 to 45.48.070, which is this jurisdiction's privacy-topic row.

What it requires

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.