Law / United States / Nebraska

Nebraska

United States law applies in Nebraska Nebraska is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Nebraska, described on this page below, applies here too.

15 of 17 named instruments researched to a stage, across five of the six areas of law we track: 12 in force, 2 enacted but not yet in force and 1 repealed, withdrawn or blocked. As of 14 September 2026.

When they take effect13 of 15 carry a date, 2 do not. Earlier is before 2015.
Before 2015: 1 instrument (1 in force) earlier 2015: 0 instruments 2016: 0 instruments 2017: 0 instruments 2018: 1 instrument (1 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 1 instrument (1 in force) 2025: 5 instruments (5 in force) ’25 2026: 4 instruments (3 in force, 1 repealed, withdrawn or blocked) 2027: 1 instrument (1 enacted but not yet in force) ’27 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 3
  2. Privacy law 5
  3. Scraping law 2
  4. Cybersecurity law 1
  5. Age gating law 4
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law3 instruments, 2 in force, 1 enacted but not yet in force

Research summary (217 words)

Nebraska diverges from the federal AI-transparency baseline in three enacted respects: a 2025 amendment folded artificial-intelligence-generated depictions into the state's Child Sexual Abuse Material Prevention Act; a 2025 act, the Ensuring Transparency in Prior Authorization Act, bars a health insurance utilization review agent's artificial intelligence-based algorithm from being the sole basis of a decision to deny, delay, or modify health care services on medical-necessity grounds, effective January 1, 2026; and a 2026 act, not yet operative, will require operators of conversational AI services to disclose AI status to users and protect minor account holders.

A broader, Colorado-style AI risk-management bill (LB 642) and a candidate election-deepfake disclosure bill (LB 615) were both introduced in the 109th Legislature and died with its 2025-2026 biennium closing on April 17, 2026 without a floor vote.

Nebraska's general consumer-protection statutes, the Consumer Protection Act (Neb. Rev. Stat. §§ 59-1601 to 59-1623) and the Uniform Deceptive Trade Practices Act (Neb. Rev. Stat. §§ 87-301 to 87-306), name no automated or AI-specific practice and reach AI-driven conduct only as general unfair-or-deceptive-trade-practice law.

No enacted Nebraska statute regulates AI use by government bodies as such; that would be an absence for this profile in any event, since the profile is scoped to duties on any person, not to a government body's own AI use.

AI prohibited practices

Child Sexual Abuse Material Prevention Act, computer-generated and artificial-intelligence depictions

Neb. Rev. Stat. §§ 28-1801 to 28-1806Nebraska Revised Statutes, official Nebraska Legislature text

In force. Binds public and private bodies.

What this law does

A 2025 amendment (LB 383) revised the Act's definitions so that child sexual abuse material includes an obscene visual depiction of a computer-generated person who is, or would appear to a reasonable person to be, a child, whether or not any real child was used to produce the image. The Act defines computer-generated to include an image created, adapted, or modified using artificial intelligence.

Knowing possession or receipt of such material by a person nineteen or older is a Class IIA felony, by a person under nineteen a Class I misdemeanor rising to a Class IV felony on a second or later conviction, and a Class IC felony for anyone with a prior covered-offense conviction.

Note and primary source

AI risk obligations

Ensuring Transparency in Prior Authorization Act, artificial-intelligence utilization review restriction

Neb. Rev. Stat. §§ 44-5432 to 44-5444Nebraska Revised Statutes, official Nebraska Legislature text

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

LB 77 (2025), the Ensuring Transparency in Prior Authorization Act, bars a utilization review agent's artificial intelligence-based algorithm from being the sole basis of a decision to deny, delay, or modify health care services based, in whole or in part, on medical necessity.

The agent must disclose to the Department of Insurance, to each health care provider in its network, to each enrollee, and on its public website whether artificial intelligence-based algorithms are used or will be used in the utilization review process. The department may audit, itself or through a third-party entity, the agent's automated utilization management system. These provisions became operative on January 1, 2026.

What it requires

AI transparency

Conversational Artificial Intelligence Safety Act (LB 525, §§ 12-18)

2026 Neb. Laws LB 525, §§ 12-18 (109th Legislature, 2nd Session)official Nebraska Legislature slip law text

In force in 281 days, effective 1 July 2027. Binds public and private bodies.

What this law does

Beginning July 1, 2027, an operator of a conversational AI service must clearly and conspicuously disclose AI status to a minor account holder as a persistent disclaimer, and to any user a reasonable person could be misled into believing is human.

Operators must not use unpredictable engagement rewards to increase a minor's use of the service, must take reasonable measures to keep the service from producing sexual content involving or directed at a minor or claiming to be human or to provide professional mental-health care, and must adopt a suicide and self-harm referral protocol; the Attorney General enforces, and the Act creates no private right of action.

What it requires

Privacy law5 instruments, 4 in force, 1 enacted but not yet in force

Research summary (164 words)

The Nebraska Data Privacy Act (NDPA), Neb. Rev. Stat. sections 87-1101 to 87-1130, is Nebraska's comprehensive consumer-privacy regime. A 'Ch. 87 Art. 8' label sometimes given for the Act is unsupported: the official Nebraska Revised Statutes site prints no Article subdivision on the self-citing section, only the chapter and section numbers.

Enacted as part of omnibus Legislative Bill 1074 (108th Legislature), approved by the Governor April 17, 2024, effective January 1, 2025 per consistent secondary reporting. Genetic or biometric data processed to identify a person is one of NDPA's enumerated sensitive-data categories.

Separately, Nebraska's biometric-data definition claws back data generated from a photograph, video, or audio recording the moment it is generated to identify someone, so a recording-derived identifier still reaches the sensitive category. A separate, older statute, Neb. Rev. Stat. section 87-803, governs breach notification. The Attorney General has exclusive enforcement authority, with a mandatory 30-day cure right carrying no sunset date in the text read; there is no private right of action.

Breach notification

Nebraska Financial Data Protection and Consumer Notification of Data Security Breach Act

Neb. Rev. Stat. § 87-803official Nebraska statute text, Neb. Rev. Stat. § 87-803

Commencement not set. Binds public and private bodies.

What this law does

An individual or commercial entity conducting business in Nebraska that owns or licenses computerized data including personal information about a Nebraska resident must, upon becoming aware of a breach of security, conduct a reasonable and prompt investigation and, where notice is required, also notify the Attorney General no later than when notice is provided to the affected resident.

This provision is in force under the current codified text; no dated original commencement is established, so no effective date is recorded here.

What it requires

Comprehensive regime

Nebraska Data Privacy Act (NDPA), general applicability and controller/processor duties

Neb. Rev. Stat. §§ 87-1101, 87-1107 to 87-1114official Nebraska statute text, Neb. Rev. Stat. §§ 87-1101 to 87-1130

In force since 1 January 2025. Binds private bodies.

What this law does

NDPA governs private-sector processing of Nebraska residents' personal data. Enacted as part of omnibus Legislative Bill 1074 (108th Legislature), approved by the Governor April 17, 2024, effective January 1, 2025 per consistent secondary reporting; the enactment date is corroborated by the slip law's own title as reported, rather than independently confirmed against primary text. Controller and processor duties are allocated across sections 87-1107 to 87-1114.

What it requires

Data subject rights

Nebraska Data Privacy Act, consumer rights

Neb. Rev. Stat. § 87-1108official Nebraska statute text, Neb. Rev. Stat. § 87-1108

In force since 1 January 2025. Binds private bodies.

What this law does

NDPA gives a Nebraska consumer rights consistent with the other states researched in this batch, access, correction, deletion, a portable copy, and opt-out of targeted advertising, sale, and qualifying profiling, structure inferred from a cross-reference in the response-timing provision rather than independently pulled verbatim from the rights-granting section itself.

A controller must respond without undue delay and within 45 days after receipt of the request, with one 45-day extension available.

What it requires

Enforcement supervision

Nebraska Data Privacy Act, Attorney General enforcement

Neb. Rev. Stat. §§ 87-1119, 87-1122, 87-1124, 87-1125official Nebraska statute text, Neb. Rev. Stat. §§ 87-1119, 87-1122, 87-1124, 87-1125

In force since 1 January 2025. Binds private bodies.

What this law does

The Nebraska Attorney General has exclusive authority to enforce NDPA. Before bringing an action, the Attorney General must give a controller or processor 30 days' written notice identifying the specific provisions violated; no sunset date for this cure right appears in the text read, unlike Connecticut's and Delaware's time-limited cure windows or Montana's eliminated one. Civil penalties run up to $7,500 per violation, and the Act creates no private right of action.

What it requires

Sensitive categories

Nebraska Data Privacy Act, sensitive data and biometric data definitions

Neb. Rev. Stat. § 87-1102(3), (30)official Nebraska statute text, Neb. Rev. Stat. § 87-1102

In force since 1 January 2025. Binds private bodies.

What this law does

NDPA classifies data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, or citizenship or immigration status, genetic or biometric data processed to uniquely identify an individual, a known child's data, and precise geolocation data as sensitive data.

'Biometric data' means data generated to identify a specific individual through automatic measurement of a biological characteristic, including a fingerprint, voice print, retina image, or iris image, and is structured slightly differently in wording from the Connecticut, Oregon, Montana, and Delaware definitions (opening with the identification purpose rather than excluding then clawing back), but reaches the same operative result: a raw recording is excluded, except when generated to identify a specific individual.

What it requires

Scraping law2 instruments, 2 in force

Research summary (152 words)

Nebraska diverges from federal scraping law in the computer_misuse and personal_data families. Its computer-crime statute is the clearest on the authorization question: Nebraska defines computer security system by statute, requiring either a conspicuous warning banner or a credential or access-code challenge, so a page with neither is, on the statute's own terms, not a computer security system and cannot be penetrated.

The Nebraska Data Privacy Act (NDPA) is also distinctive: applicability turns on federal Small Business Act size standards rather than a fixed consumer-count or revenue threshold, and it exempts the entire nonprofit sector and higher-education institutions outright, a broader categorical exemption than several peer states carry. Copyright, text-and-data-mining, and database rights add nothing beyond the federal position.

ToS enforceability and Nebraska's general consumer-protection and deceptive-trade-practices statutes rest on general law not independently verified against primary text, so neither earns its own instrument here. robots.txt carries no independent legal weight in Nebraska.

Computer misuse

Nebraska Computer Crimes Act, unauthorized access defined against a statutory computer security system

Neb. Rev. Stat. §§ 28-1343, 28-1343.01official text, Nebraska Legislature (nebraskalegislature.gov)

In force since 6 September 1991. Binds public and private bodies.

What this law does

Section 28-1343.01 provides that a person commits the offense of unauthorized computer access if the person intentionally and without authority penetrates a computer security system, with penalty tiers running from a Class II misdemeanor up to a Class IV felony depending on the risk created.

Section 28-1343(5) defines computer security system precisely as a program or device that is intended to protect the confidentiality and secrecy of data and information stored in or accessible through the computer system, and that either displays a conspicuous warning to a user that the user is entering a secure system or requires a person seeking access to knowingly respond by use of an authorized code to gain access.

Read together, a page with no login wall, no access code, and no conspicuous entry warning does not meet Nebraska's own statutory definition of a computer security system, so a plain crawl of such a page cannot, on the text, penetrate one, a materially clearer and more scraper-favorable authorization test than a bare without authorization formulation. No reported Nebraska case has applied this to scraping specifically, but the statutory text itself is the controlling authority.

What it requires

Personal data

Nebraska Data Privacy Act (NDPA), Small Business Act applicability and nonprofit exemption

Neb. Rev. Stat. §§ 87-1101 to 87-1130 (Laws 2024, LB1074)official text, Nebraska Legislature (nebraskalegislature.gov)

In force since 1 January 2025. Binds private bodies.

What this law does

Section 87-1102(28) excludes information lawfully made available through government records, or that a business has a reasonable basis to believe was lawfully made available to the public through widely distributed media, by a consumer, or by someone the consumer disclosed it to, unless the consumer has restricted the information to a specific audience, from the Act's definition of personal data.

Unusually, section 87-1103(1) applies the NDPA not by a consumer-count or revenue threshold but to a person that conducts business in Nebraska or produces a product or service consumed by Nebraska residents, that processes or sells personal data, and that is not a small business as determined under the federal Small Business Act, as such act existed on January 1, 2024, tying Nebraska's coverage to federal size standards that vary by industry rather than a fixed number.

Section 87-1103(2) exempts nonprofit organizations and institutions of higher education outright, beyond the standard state-agency, financial-institution, and Health Insurance Portability and Accountability Act (HIPAA)-covered-entity carve-outs, a broader nonprofit exemption than several peer states carry. Effective January 1, 2025, confirmed on the Nebraska Attorney General's official Data Privacy homepage. Enforcement is by the Nebraska Attorney General; there is no private right of action.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (485 words)

Nebraska's product-security and cyber-resilience posture rests on one enacted standalone statute, Neb. Rev. Stat. section 87-808, the security-procedures half of the Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006 (sections 87-801 to 87-808), added by Laws 2018, LB757, section 7, approved by the Governor February 28, 2018 and effective July 19, 2018.

It requires any individual or commercial entity that conducts business in Nebraska and owns, licenses, or maintains computerized data including a Nebraska resident's personal information to implement and maintain reasonable security procedures and practices appropriate to the nature and sensitivity of that information and to the size and resources of the business, and to flow the same reasonable-security requirement down by contract to a nonaffiliated third-party service provider.

No enacted Nebraska statute sets security requirements a connected device or software product must meet before or after it reaches the market: a connected-device bill of the kind California and Oregon have enacted was not located in Nebraska's current or recent legislative record, so this is a researched absence rather than a gap in coverage.

Nebraska has no general private-sector duty to report an exploited vulnerability or a security incident to an authority; the federal Cyber Incident Reporting for Critical Infrastructure Act would reach Nebraska critical-infrastructure operators once the Cybersecurity and Infrastructure Security Agency's implementing rule takes effect, but that rule had not been finalized as of September 2026.

No Nebraska sector-specific cyber-resilience regime reaching a software or platform provider was located; the state's insurance-sector privacy statute, the Privacy of Insurance Consumer Information Act (Neb. Rev. Stat. sections 44-901 to 44-925), governs an insurer's handling and disclosure of a consumer's personal information rather than a security-program duty, and no Nebraska analogue to the NAIC Insurance Data Security Model Law was found.

Section 87-808 is enforced only by the Attorney General: a violation is deemed a violation of the Consumer Protection Act's unfair-practices section, Neb. Rev. Stat. section 59-1602, carrying a civil penalty of up to $2,000 for each violation under section 59-1614, and section 87-808 expressly creates no private right of action.

A separate 2025 enactment, Neb. Rev. Stat. section 87-1201 (Laws 2025, LB241, section 1), narrows a private entity's exposure for a cybersecurity event rather than creating a duty of its own: it bars class-action liability for a cybersecurity event unless the event was caused by willful, wanton, or gross negligence, and is not filed here as an instrument for the same reason a product-liability directive is not, but is worth a reader's notice alongside the safeguards duty it narrows exposure under.

Nebraska's breach-notification duty, Neb. Rev. Stat. section 87-803, the other half of the same 2006 Act, is already this jurisdiction's privacy row rather than repeated here: it requires notice to an affected Nebraska resident and, regardless of the number affected, to the Attorney General, without the dollar or population thresholds many states attach to that second notice.

Security baseline statutes

Financial Data Protection and Consumer Notification of Data Security Breach Act, security procedures and practices duty

Neb. Rev. Stat. section 87-808 (added by Laws 2018, LB757, section 7)Official statute text, Nebraska Revised Statutes, Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006

In force since 19 July 2018. Binds public and private bodies.

What this law does

An individual or commercial entity that conducts business in Nebraska and owns, licenses, or maintains computerized data including a Nebraska resident's personal information must implement and maintain reasonable security procedures and practices appropriate to the nature and sensitivity of that information and to the nature, size, and resources of the business, including safeguards for disposal of the information.

Where the entity discloses that data to a nonaffiliated third-party service provider, it must require by contract that the provider maintain reasonable security procedures and practices of its own. The Act's own definition of a bound commercial entity reaches a government, governmental subdivision, agency, or instrumentality as well as a private business.

An entity that already complies with a state or federal law giving greater protection, or with the Gramm-Leach-Bliley Act Title V or Health Insurance Portability and Accountability Act (HIPAA) regulations where it is subject to either, is deemed to comply. Only the Attorney General enforces the duty, as a deemed violation of the Consumer Protection Act's unfair-practices section, and the section creates no private right of action.

What it requires

Age gating law4 instruments, 3 in force, 1 repealed, withdrawn or blocked

Research summary (158 words)

Nebraska has enacted laws in three of the four age-gating families. The Online Age Verification Liability Act (LB 1092, 2024) has required age verification for websites where a substantial portion of content is harmful to minors since July 19, 2024, and remains in effect.

The Age-Appropriate Online Design Code Act (LB 504, 2025, broadened by LB 838 in 2026) became operative January 1, 2026 and requires covered online services to give minors user controls, default high privacy settings, and limits on addictive design features and targeted advertising.

The Parental Rights in Social Media Act (LB 383, 2025) would require age verification and parental consent for minors on social media, but a federal court preliminarily enjoined its age verification and parental consent provisions on June 27, 2026, days before their planned July 1, 2026 effective date, on First Amendment grounds; the act's parental monitoring provisions were not enjoined. Nebraska has no app store or device level age verification law.

Adult content age verification (AV)

LB 1092 (2024), Online Age Verification Liability Act

Neb. Rev. Stat. §§ 87-1001 to 87-1005official Nebraska Revised Statutes text

In force since 19 July 2024. Binds private bodies.

What this law does

Creates civil liability for a commercial entity that knowingly or intentionally publishes or distributes material harmful to minors on the internet, where such material makes up a substantial portion (more than one third) of the site's content, without performing reasonable age verification of Nebraska users.

Note and primary source

Age-appropriate design code

LB 504 (2025), Age-Appropriate Online Design Code Act

Neb. Rev. Stat. §§ 87-1301 to 87-1311official chaptered bill text, Nebraska Legislature

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

Requires a covered online service (over $25 million in annual revenue that derives at least half its revenue from selling or sharing personal data) to give minors accessible controls over addictive design features such as infinite scroll and push notifications, default to the highest available privacy and safety settings, limit profiling and targeted advertising to minors, and restrict sharing of precise geolocation data.

Note and primary source

LB 838 (2026), amendments broadening the Age-Appropriate Online Design Code Act

Neb. Rev. Stat. §§ 87-1301 to 87-1311, as amendedofficial chaptered bill text, Nebraska Legislature

In force 67 days, effective 18 July 2026. Binds private bodies.

What this law does

Broadens which businesses count as a covered online service under the Age-Appropriate Online Design Code Act, applying it to a business that derives a majority of its annual revenue from online services and either has more than $25 million in annual revenue or processes the personal data of 50,000 or more consumers, households, or devices. Approved by the Governor on April 14, 2026; the design code sections become operative July 18, 2026, three calendar months after the session's adjournment.

Note and primary source

Social media and minors

LB 383 (2025), Parental Rights in Social Media Act

Neb. Rev. Stat. §§ 86-1701 to 86-1705official Nebraska Revised Statutes text

Enjoined: enforcement paused by a court, effective 1 July 2026. Binds private bodies.

What this law does

Would require social media companies to verify the age of prospective account holders using a reasonable age verification method and to obtain a parent's express, verified consent before a minor may hold an account, with parental tools to view messages, control privacy settings, and limit time on the platform.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.