Arizona's private-sector security-topic footprint is narrow: one enacted state statute imposes a genuine disposal duty on paper records, no enacted state law sets market-entry security requirements for a connected device or software product, no state law creates a general private-sector duty to report a vulnerability or a security incident to an authority, and the one sector regime located binds a role this profile's activity vocabulary cannot express.
A.R.S. section 44-7601 (Title 44, Trade and Commerce, Chapter 33), in effect by at least 2005 (the earliest year for which a copy of this section could be located; the current statute text carries no enactment-date annotation of its own), requires an 'entity,' defined broadly to include a corporation, unincorporated association, sole proprietorship, partnership, trust, and a government, governmental subdivision or agency, to redact or destroy a paper record or document before discarding or disposing of it if the record or document combines an individual's first and last name, or first initial and last name, with a Social Security number, a credit, charge or debit card number, a retirement account number, a savings, checking or securities entitlement account number, or a driver license or nonoperating identification license number; the duty reaches paper records and documents only, states no parallel duty over electronic data, and exempts an entity already regulated under the Gramm-Leach-Bliley Act, Health Insurance Portability and Accountability Act (HIPAA), or the federal Fair Credit Reporting Act.
Arizona's Administrative Code, Title 20, Chapter 6, Article 21 (R20-6-2101 through R20-6-2104, adopted in 2004 under the older NAIC Standards for Safeguarding Customer Information model, distinct from and narrower than the newer NAIC Insurance Data Security Model Law), requires a 'licensee,' an insurance institution, insurance producer, or insurance support organization, to implement a comprehensive written customer information security program with administrative, technical and physical safeguards appropriate to the licensee's size and complexity; because it binds only an insurance licensee, a bound-party class no activity in the LexLint vocabulary expresses, and because it carries no duty to report a cybersecurity event to the Insurance Commissioner or to affected consumers, unlike a jurisdiction that has adopted the newer NAIC model law, it is recorded here rather than flagged on a guess or filed as an instrument.
A.R.S. section 15-1046(C)(1) requires an 'operator' of an internet website, online service, online application or mobile application used primarily for school purposes and marketed for school purposes to implement and maintain reasonable security procedures and practices appropriate to the nature of covered student information; that duty is one subsection of Arizona's comprehensive student-data-privacy statute, whose other subsections restrict targeted advertising, profiling and the sale of student data and impose deletion and privacy-policy-notice duties, so the security clause belongs to the privacy topic in the same way the General Data Protection Regulation's Article 32 and the Texas Data Privacy and Security Act's section 541.101(a)(2) do, and it is not yet researched under either topic as of this visit; it is named here rather than duplicated as a security-topic row.
A.R.S. section 13-2316.02, which makes it a felony to communicate, release or publish proprietary or confidential computer security information about a particular computer, computer system or network without its owner's or operator's authorization, binds any person who releases such information about another's system rather than the system's own operator or manufacturer, so it sits with the state's computer-tampering chapter (A.R.S. section 13-2316 and its offense-by-an-intruder siblings) in the scraping topic's computer_misuse family rather than here.
No enacted Arizona statute was located that sets security requirements a connected device or software product must meet before or after it reaches the market, comparable to California's or Oregon's connected-device statutes or the Cyber Resilience Act, or that creates a general private-sector duty to report an exploited vulnerability or a security incident to a state authority; both are researched absences rather than gaps in coverage.
A.R.S. section 44-7601 is enforced by a county attorney in the county where records were wrongfully discarded or disposed, or by the Attorney General, with a civil penalty per violation arising from one incident that rises with each violation (up to $500 for a first violation, $1,000 for a second, and $5,000 for a third or subsequent violation) and no private right of action; no published enforcement record for it is confirmed in the primary text consulted here.
Arizona's breach-notification duty, A.R.S. section 18-552, is already this jurisdiction's privacy row rather than repeated here.