Law / United States / Hawaii

Hawaii

United States law applies in Hawaii Hawaii is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Hawaii, described on this page below, applies here too.

All 9 named instruments researched to a stage, across four of the six areas of law we track: 5 in force, 3 enacted but not yet in force and 1 repealed, withdrawn or blocked. As of 15 September 2026.

  1. AI law 4
  2. Privacy law 3
  3. Scraping law 1
  4. Cybersecurity law 1
  5. Age gating law none researched
  6. News aggregation law none researched

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law4 instruments, 3 in force, 1 repealed, withdrawn or blocked

Research summary (229 words)

Hawaii's 2024 election-deepfake disclosure law, Haw. Rev. Stat. §§ 11-303 and 11-304 (Act 191), was permanently enjoined statewide by the U.S. District Court for the District of Hawaii on January 30, 2026 in Babylon Bee, LLC v. Lopez, so it does not currently bind anyone even though its text remains on the books.

A 2026 law, Act 248 (S.B. 3001, CD1), adds a new section to Haw. Rev. Stat. chapter 481B requiring an AI companion operator to disclose that a user is interacting with artificial intelligence and to meet added safety, content, and reporting duties for minor users, effective July 14, 2026; two earlier 2025-2026 bills covering similar ground, HB 1782 and HB 639, died without passage and their substance was largely folded into Act 248.

Separately from AI-transparency duties, two existing Penal Code provisions were amended to reach AI-generated and computer-manipulated imagery and bind any person: the promoting-child-abuse statute (Haw. Rev. Stat. §§ 707-750 to 707-752) defines "child pornography" to include a computer-generated image, and the violation-of-privacy statute (Haw. Rev. Stat. § 711-1110.9(1)(c)) reaches a deepfake or composite image giving a real person's likeness a nude or sexual depiction they did not actually appear in.

No Hawaii statute requiring disclosure of AI training data, imposing high-risk AI system conformity duties, or honoring a text-and-data-mining opt-out was identified; those questions are governed by federal law and the scraping profile.

AI prohibited practices

Promoting Child Abuse, computer-generated child pornography

Haw. Rev. Stat. §§ 707-750 to 707-752official codified text, Hawaii Revised Statutes, www.capitol.hawaii.gov (Haw. Rev. Stat. § 707-750, carrying the section's commentary)

In force. Binds public and private bodies.

What this law does

Hawaii's promoting-child-abuse statute defines "child pornography" to include any pornographic visual representation, including a "computer or computer-generated image or picture," where either the production used a real minor or the image "has been created, adapted, or modified to appear that an identifiable minor is engaging in sexual conduct," reaching an AI-generated or AI-altered depiction with no real minor involved at all.

Producing such material is promoting child abuse in the first degree (class A felony); disseminating it, or possessing thirty or more qualifying images, is the second degree (class B felony); simple possession is the third degree (class C felony). This computer-generated language was added by 2002 Session Laws Act 200 to address, in the legislature's words, "the problem of utilizing computer technology in committing crimes against children."

What it requires

Violation of Privacy in the First Degree, deepfake and composite intimate images

Haw. Rev. Stat. § 711-1110.9(1)(c)official codified text, Hawaii Revised Statutes, www.capitol.hawaii.gov (Haw. Rev. Stat. § 711-1110.9, carrying the section's commentary)

In force. Binds public and private bodies.

What this law does

Subsection (1)(c), added by 2021 Session Laws Act 59, makes it violation of privacy in the first degree to intentionally create, disclose, or threaten to disclose an image or video of a "composite fictitious person" depicted nude or in sexual conduct that includes a real, identifiable person's recognizable physical characteristics, so the image appears to depict that known person, with intent to substantially harm the depicted person or as an act of revenge or retribution; this reaches a deepfake or AI-generated composite image regardless of whether any genuine nude or sexual image of the depicted person ever existed.

The offense is a class C felony. A provider of an "electronic communication service" or "remote computing service" is not liable for an image or video another person discloses through that service.

What it requires

AI transparency

Artificial Intelligence Disclosure and Safety Act (2026 Haw. Sess. Laws Act 248, S.B. 3001 CD1)

Haw. Rev. Stat. ch. 481B, part I (new section) (2026 Haw. Sess. Laws Act 248)enrolled CD1 bill text, S.B. 3001 (2026 Haw. Sess. Laws Act 248), Hawaii State Legislature

In force 71 days, effective 14 July 2026. Binds private bodies.

What this law does

Requires an operator of an AI companion (a system using artificial intelligence, generative artificial intelligence, or emotional-recognition algorithms designed to simulate a sustained human-like relationship) to clearly and conspicuously disclose that it is not human whenever a reasonable person could otherwise mistake it for one, and adds a recurring, more frequent disclosure duty, content restrictions, and parental controls where the operator knows or reasonably believes the user is a minor.

An operator must adopt an evidence-based protocol for responding to a user's suicidal-ideation or self-harm prompts by referring the user to crisis-intervention services, and beginning January 1, 2028 must file an annual, de-identified report on crisis referrals with the Department of Health's Behavioral Health Administration.

A violation is an unfair or deceptive trade practice under Haw. Rev. Stat. § 480-2, enforceable by the Department of the Attorney General and the Office of Consumer Protection; the section expressly creates no private right of action, and expressly imposes no liability on the developer of an AI model for a third party's violation using that model. Not yet assigned a permanent section number on the state code site as of the date shown; the bill designates it a new section of chapter 481B, part I.

What it requires

Election Deepfake Disclosure Law (2024 Haw. Sess. Laws Act 191, S.B. 2687)

Haw. Rev. Stat. §§ 11-303, 11-304 (2024 Haw. Sess. Laws Act 191)official codified text, Hawaii Revised Statutes, www.capitol.hawaii.gov

Enjoined: enforcement paused by a court, effective 3 July 2024. Binds public and private bodies.

What this law does

Section 11-303 prohibited recklessly distributing, or agreeing with another person to distribute, "materially deceptive media" (an AI-generated, computer-generated, or otherwise digitally altered video, image, or audio depicting a real, identifiable person saying or doing something they did not say or do, that a reasonable viewer would believe genuine) between the first working day of February of an even-numbered year and the following general election, unless the media carried a conspicuous disclaimer in the form the section specifies; section 11-304 gave a depicted individual, a candidate, the attorney general, the campaign spending commission, and certain other parties a civil action for damages or injunctive relief.

On January 30, 2026, the U.S. District Court for the District of Hawaii granted summary judgment to the plaintiffs in Babylon Bee, LLC v. Lopez and permanently enjoined the state defendants from enforcing Act 191, holding it an unconstitutional content-based speech restriction; the statutory text has not been repealed, but the injunction means the law does not currently bind anyone.

What it requires

Privacy law3 instruments, 3 enacted but not yet in force

Research summary (202 words)

Hawaii has no comprehensive consumer-privacy statute. Article I, Section 6 of the Hawaii Constitution recognizes an explicit right of privacy subject to a compelling state interest standard, the strictest tier of judicial scrutiny, but it binds government action rather than private conduct, so a private business is not directly bound by it.

The Security Breach of Personal Information Act, HRS ch. 487N, is Hawaii's operative private-sector privacy statute, a breach notification duty whose personal information definition covers only a name combined with a Social Security number, driver's license or state ID number, or a financial account number with an access code, excludes information lawfully made public through government records, and has no biometric, genetic, or health category.

A violation is a strong basis for private recovery: HRS Sec. 487N-3 makes a violating business liable to the injured party for actual damages plus attorneys' fees, on top of a state civil penalty, and Hawaii's general Uniform Deceptive Trade Practices Act separately gives any person likely to be damaged by a deceptive trade practice a right to an injunction without needing to prove monetary damage.

A comprehensive Hawaii Consumer Privacy Protection Act, HB 2463 (2026), has been introduced but has not advanced past introduction.

Breach notification

Hawaii Security Breach of Personal Information Act, notice of security breach

Haw. Rev. Stat. Secs. 487N-1, 487N-2official Hawaii Revised Statutes text, Hawaii State Legislature

Commencement not set. Binds public and private bodies.

What this law does

A business that owns or licenses personal information of Hawaii residents, a business conducting business in Hawaii that owns or licenses such information, and a government agency that collects personal information for government purposes must each provide notice, without unreasonable delay, to a person affected by a security breach.

Notice must be clear and conspicuous, describe the incident and the type of personal information exposed, describe remedial steps taken, give a contact number, and advise the recipient to monitor credit reports; substitute notice is available above a $100,000 cost or 200,000-person threshold. Above a 1,000-person notice threshold, the business must also notify the State of Hawaii's Office of Consumer Protection and nationwide consumer reporting agencies.

Hawaii's personal information definition covers only a name combined with a Social Security number, driver's license or state ID number, or a financial account number with an access code or password, excludes information lawfully made public through federal, state, or local government records, and has no biometric, genetic, or health category, so a breach of biometric data alone triggers no notice duty.

What it requires

Enforcement supervision

Hawaii Security Breach of Personal Information Act, penalties and civil action

Haw. Rev. Stat. Sec. 487N-3official Hawaii Revised Statutes text, Hawaii State Legislature

Commencement not set. Binds private bodies.

What this law does

A business that violates any provision of the Security Breach of Personal Information Act is subject to a penalty of not more than $2,500 per violation, brought by the Attorney General or the executive director of the Office of Consumer Protection. Separately and additionally, a violating business is liable to the injured party for actual damages sustained as a result of the violation, and the court may award reasonable attorneys' fees to the prevailing party.

No action under either route may be brought against a government agency, so the private right of action and the state enforcement action both reach only private businesses despite the notice duty itself extending to government agencies.

What it requires

Hawaii Uniform Deceptive Trade Practices Act, private injunctive relief

Haw. Rev. Stat. Sec. 481A-4official Hawaii Revised Statutes text, Hawaii State Legislature

Commencement not set. Binds private bodies.

What this law does

A person likely to be damaged by a deceptive trade practice of another may bring an action for an injunction, without needing to prove monetary damage, loss of profits, or intent to deceive.

This is a second, independent private-action route into Hawaii's data-privacy landscape, broader than the Security Breach of Personal Information Act's own private right of action in the conduct it reaches (any deceptive trade practice, not only a chapter 487N breach) but narrower in remedy, since it reaches only injunctive relief rather than damages, and it carries discretionary fee-shifting against a groundless or knowingly deceptive claim.

What it requires

Scraping law1 instrument, 1 in force

Research summary (158 words)

Hawaii adds a general computer-crime statute to the federal baseline but no scraping-specific terms-of-service, database-right, personal-data, or robots.txt rule.

Part IX of the Penal Code (Haw. Rev. Stat. §§ 708-890 to 708-895.7) defines unauthorized access by reference to the permission of the computer's owner or rightful user, a Computer Fraud and Abuse Act (CFAA)-style authorization test, and grades unauthorized computer access, computer fraud, and computer damage into first, second, and third degree offenses carrying class A, B, and C felony penalties depending on financial gain, the value of information obtained, or whether the access furthers another crime.

No reported Hawaii appellate decision applies this statute to automated collection of public web pages, so how the authorization test would read against an unauthenticated, no-login scrape is untested. Terms-of-service enforceability, database rights, text-and-data-mining, and personal-data protection for scraped information rest on federal law and ordinary Hawaii contract and tort doctrine, on which the statute is silent; robots.txt carries no independent legal weight under Hawaii law.

Computer misuse

Hawaii Computer Crime Law, Part IX (unauthorized computer access, computer fraud, computer damage)

Haw. Rev. Stat. §§ 708-890 to 708-895.7official codified text, Hawaii Revised Statutes, www.capitol.hawaii.gov (Haw. Rev. Stat. § 708-895.7, carrying the Part's commentary)

In force. Binds public and private bodies.

What this law does

A person commits unauthorized computer access in the first, second, or third degree by knowingly accessing a computer, computer system, or computer network without authorization, with the first degree requiring an aggravating fact (commercial or private financial gain, furtherance of another crime, information worth more than $20,000, or information a statute or court rule protects from disclosure) and each lower degree dropping that requirement; the same Part separately grades computer fraud (access with intent to commit theft, sections 708-891 to 708-891.6) and computer damage (sections 708-892 to 708-892.6) into parallel first-through-third-degree tiers.

Section 708-890 defines "without authorization" as without the permission of, or in excess of the permission granted by, the computer's owner, lessor, or rightful user, the same permission-based test the federal Computer Fraud and Abuse Act uses. Section 708-893 separately makes using a computer to further certain listed offenses, including harassment, stalking, and violation of privacy, an offense one class or grade higher than the underlying crime.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (603 words)

Hawaii's private-sector security law is a records-disposal duty rather than a product-security or general reasonable-security regime.

Haw. Rev. Stat. ch. 487R, the Destruction of Personal Information Records chapter, effective January 1, 2007 (Act 136 of the 2006 Regular Session, SB2292 SD2 HD1 CD1, approved May 25, 2006), requires any business or government agency that conducts business in Hawaii, or that maintains or otherwise possesses a Hawaii resident's personal information, to take reasonable measures to protect against unauthorized access to or use of that personal information in connection with or after its disposal, satisfied by burning, pulverizing, recycling or shredding paper records and destroying or erasing electronic and other nonpaper media so the information cannot practicably be read or reconstructed, or by exercising due diligence over a contracted records-destruction vendor; a financial institution subject to the Gramm-Leach-Bliley Act, a Health Insurance Portability and Accountability Act (HIPAA)-compliant health plan or health care provider, and a Fair Credit Reporting Act-compliant consumer reporting agency are exempt.

A violating business is subject to a civil penalty of not more than $2,500 per violation, brought by the attorney general or the executive director of the office of consumer protection, and is separately liable to the injured party for actual damages and, at the court's discretion, reasonable attorneys' fees; no action under the chapter may be brought against a government agency, and the chapter carries no criminal exposure.

No enacted Hawaii statute is confirmed in the primary text consulted here to set security requirements a connected device or software product must meet before or after it reaches the market: a bill closely modeled on California's and Oregon's connected-device statutes, the Security of Connected Devices Act (identical companion bills HB739 and SB1002, 2021 Regular Session), was deferred by the House committee on Energy & Environmental Protection and Consumer Protection on February 5, 2021, carried over to the 2022 Regular Session on December 10, 2021, and never enacted in either chamber, so this is a researched absence rather than a gap in coverage.

Hawaii has no general private-sector duty to report a security incident or an exploited vulnerability to an authority.

The one sector-specific cyber-resilience regime this jurisdiction runs is the Insurance Data Security Law, Haw. Rev. Stat. secs. 431:3B-101 to 431:3B-306 (Act 112 of the 2021 Regular Session, approved June 28, 2021, effective July 1, 2021, adopting the National Association of Insurance Commissioners' Insurance Data Security Model Law), which requires every insurance licensee to develop, implement and maintain a comprehensive written information security program commensurate with its size and the sensitivity of the nonpublic information it holds, and requires notice to the insurance commissioner as promptly as possible, and in no event later than three business days, from a determination that a cybersecurity event affecting 250 or more consumers has occurred; a licensee with fewer than ten employees is exempt from the program duty, a licensee compliant with HIPAA's own information security program is deemed compliant, and a violation draws the insurance code's general enforcement provision, a fine of $100 to $10,000 per violation or imprisonment of not more than one year, in addition to license suspension, revocation or a monetary penalty and restitution under Haw. Rev. Stat. sec. 431:2-203.

Because the Insurance Data Security Law's bound party is an insurance licensee, a role no activity this profile can flag on expresses, it is recorded here in prose rather than filed as its own instrument, so that no false reach is published for a developer whose app is not an insurance licensee. The Security Breach of Personal Information Act, Haw. Rev. Stat. ch. 487N, is this jurisdiction's privacy-topic row for breach notification and is not repeated here.

Security baseline statutes

Destruction of Personal Information Records

Haw. Rev. Stat. Secs. 487R-1 to 487R-3official Hawaii Revised Statutes text, Hawaii State Legislature

In force since 1 January 2007. Binds public and private bodies.

What this law does

Haw. Rev. Stat. ch. 487R, effective January 1, 2007 (Act 136, 2006 Regular Session, SB2292 SD2 HD1 CD1), requires any business or government agency that conducts business in Hawaii, or that maintains or otherwise possesses a Hawaii resident's personal information, to take reasonable measures to protect against unauthorized access to or use of that personal information in connection with or after its disposal.

The duty is satisfied by burning, pulverizing, recycling or shredding paper records and destroying or erasing electronic and other nonpaper media so the information cannot practicably be read or reconstructed, or by exercising due diligence over a contracted records-destruction vendor. A financial institution subject to the Gramm-Leach-Bliley Act, a Health Insurance Portability and Accountability Act (HIPAA)-compliant health plan or health care provider, and a Fair Credit Reporting Act-compliant consumer reporting agency are exempt.

A violating business is subject to a civil penalty of not more than $2,500 per violation, brought by the attorney general or the executive director of the office of consumer protection, and is separately liable to the injured party for actual damages and, at the court's discretion, reasonable attorneys' fees. No action under the chapter may be brought against a government agency, which instead must report a material breach of disposed records to the legislature under section 487R-4.

What it requires

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.