Alaska
Alaska Data Privacy Laws: Constitutional Privacy & Breach Rules (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 19 primary sources cited on this page. How we verify our legal content

Alaska has no comprehensive consumer data privacy law, but Article I, Section 22 of the Alaska Constitution explicitly guarantees a right to privacy. The Alaska Personal Information Protection Act (AS 45.48) requires businesses to notify residents after a breach, while separate statutes protect genetic information and Social Security numbers (Alaska has no biometric-data statute).
Alaska takes a distinctive approach to data privacy. Rather than enacting a single comprehensive consumer privacy statute like California or Texas, the state relies on a combination of its constitutional privacy guarantee, targeted data protection statutes, active Attorney General enforcement, and federal law to safeguard personal information.
This guide covers every major Alaska data privacy protection in force as of May 2026, from the constitutional right to privacy through breach notification rules, genetic safeguards (and the absence of a biometric-data law), the new federal TAKE IT DOWN Act, and the pending comprehensive privacy bill.
Alaska's Constitutional Right to Privacy
Alaska is one of a small number of states that explicitly recognizes a right to privacy in its state constitution. Article I, Section 22 of the Alaska Constitution states:
"The right of the people to privacy is recognized and shall not be infringed. The legislature shall implement this section."
This provision was added by amendment in 1972, making Alaska an early adopter of explicit constitutional privacy protections. The language is notably broad compared to other states that have similar provisions.
How Courts Interpret Alaska's Privacy Right
Alaska courts have developed a framework for analyzing privacy claims under Section 22. The right is not absolute. A person asserting a privacy claim must demonstrate a subjective expectation of privacy that society recognizes as reasonable.
Courts apply a balancing test that weighs the individual's privacy interest against competing government or public interests. This analysis considers the nature of the information at stake, the circumstances of the disclosure, and whether less intrusive alternatives exist.
The constitutional privacy right primarily limits government action. It restricts how state and local agencies collect, store, and share personal data about Alaska residents. Private entities are not directly bound by Section 22, but the legislature has enacted several statutes that extend data privacy protections to the private sector.
Article I, Section 14: Search and Seizure Protections
Alaska's constitution also protects privacy through Article I, Section 14, which mirrors the Fourth Amendment but has been interpreted more broadly by Alaska courts. This section protects against unreasonable searches and seizures of persons, houses, property, papers, and effects.
Together, Sections 14 and 22 create a stronger baseline of privacy protection in Alaska than exists under federal law alone.
Alaska Personal Information Protection Act (AS 45.48)
The Alaska Personal Information Protection Act, codified at AS 45.48.010 through AS 45.48.090, is Alaska's primary data breach notification statute. Enacted in 2008 as House Bill 65 (ch. 92, SLA 2008), it requires businesses and government agencies to notify Alaska residents when their personal information has been compromised.
What Counts as Personal Information
Under the statute, "personal information" means an individual's first name or initial combined with their last name, plus one or more of the following data elements:
- Social Security number
- Driver's license number or state identification card number
- Account number, credit card number, or debit card number, combined with any required security code, access code, or password that would permit access to the account
- Passwords, personal identification numbers (PINs), or other access codes for financial accounts
The definition covers information in any format, whether electronic or paper. Information that has been encrypted or redacted is excluded from the definition, provided the encryption key has not been compromised.
Who Must Comply
The breach notification requirements apply to any person conducting business in Alaska or any entity with more than 10 employees that owns, licenses, or maintains personal information about Alaska residents.
This broad scope means that businesses headquartered outside Alaska must still comply if they hold personal data belonging to Alaska residents.
Notification Timing and Methods
When a breach occurs, the entity must notify affected Alaska residents "in the most expeditious time possible and without unreasonable delay." The statute does not set a specific deadline in days, but it does allow time for the entity to determine the scope of the breach and restore the integrity of its systems.
Notification can be provided through:
- Written notice sent to the resident
- Electronic notice, if that is the primary method of communication with the resident or if it complies with federal E-SIGN Act requirements
- Substitute notice, available when the cost of notification exceeds $150,000, the affected group exceeds 300,000 residents, or the entity lacks sufficient contact information
Substitute notice requires email notification where possible, conspicuous posting on the entity's website, and notification through major statewide media.
Attorney General Notification
An entity may determine that notification is not required after conducting an appropriate investigation, but only if it concludes there is no reasonable likelihood that harm has resulted or will result from the breach. The entity must provide written notification to the Alaska Attorney General of this determination.
Large Breach Reporting
If a breach affects more than 1,000 Alaska residents, the entity must also notify all nationwide consumer credit reporting agencies without unreasonable delay. This requirement mirrors provisions in many other state breach notification laws.
Law Enforcement Delay
Notification may be delayed if a law enforcement agency determines that the notice would impede a criminal investigation. Once law enforcement clears the notice, the entity must proceed with notification.
Penalties for Noncompliance
Violations of the breach notification law carry significant consequences:
Government agencies that fail to comply face civil penalties of up to $500 for each resident who was not properly notified. The total penalty for a single breach is capped at $50,000. The Department of Administration enforces these penalties through administrative procedures.
Non-government entities face the same $500 per person penalty, capped at $50,000. A violation also constitutes an unfair or deceptive trade practice under Alaska consumer protection law, which opens the door to additional enforcement by the Attorney General.
Individual lawsuits are permitted. A person harmed by a breach can bring a civil action to recover actual economic damages up to $500, plus court costs and attorney's fees.
Social Security Number Protections (AS 45.48.400-430)
Alaska has enacted specific protections for Social Security numbers that go beyond the general breach notification requirements.
Under AS 45.48.400(a), a person may not:
- Intentionally communicate or otherwise make an individual's Social Security number available to the general public
- Print an individual's Social Security number on a card required for the individual to access the person's products or services
- Require an individual to transmit a Social Security number over the internet, unless the internet connection is secure or the number is encrypted
- Require an individual to use a Social Security number to access a website, unless a password, a unique personal identification number, or another authentication device is also required
- Print an individual's Social Security number on material mailed to the individual, unless local, state, or federal law expressly authorizes it, or the number appears on an application or other form (including a document sent as part of an application or enrollment process) sent to establish, amend, or terminate an account, contract, or policy, or to confirm the accuracy of the number
Read the third and fourth items carefully, because they are conditional rather than flat bans. Alaska does not prohibit an SSN from being transmitted or used online. It prohibits requiring that when the security or authentication safeguard is missing. The mailing exception carries its own limit as well: an SSN that may lawfully be mailed still cannot be printed on a postcard or other mailer that does not require an envelope, or in a way that makes the number visible on the envelope or without the envelope being opened.
The prohibitions do not apply to a person engaging in the business of government that is authorized by law to make the number available, or where doing so is required for the performance of duties or responsibilities provided by law.
AS 45.48.410 further restricts when entities can request and collect Social Security numbers, while AS 45.48.430 limits the disclosure of SSNs except in specifically enumerated circumstances.
Under AS 45.48.480, a person who knowingly violates AS 45.48.400 through AS 45.48.430 is liable to the state for a civil penalty not to exceed $3,000. An individual may separately bring a civil action to recover actual economic damages, court costs, and full reasonable attorney fees.
Records Disposal Requirements (AS 45.48.500-590)
AS 45.48.500(a) requires businesses and government agencies to take all reasonable measures necessary to protect against unauthorized access to or use of records containing personal information when disposing of those records.
AS 45.48.510 lists three measures that may be taken to comply:
- Paper records: Burning, pulverizing, or shredding documents so that personal information cannot be read or reconstructed
- Electronic media: Destroying or erasing electronic media so that personal information cannot be read or reconstructed
- Third-party contractors: Entering into a written contract with a record destruction company after conducting due diligence
AS 45.48.520 describes the due diligence expected before hiring a third party, which ordinarily includes performing one or more of the following: reviewing an independent audit of the contractor's operations, obtaining information from several references or other reliable sources while requiring certification by a recognized trade association or similar organization, or reviewing and evaluating the contractor's information security policies and procedures.
Under AS 45.48.500(b), a business or agency that has otherwise complied with these provisions in selecting a record-destruction contractor is not liable for the disposal once it has relinquished control of the records.
Under AS 45.48.550, an individual, business, or governmental agency that knowingly violates the disposal provisions is liable to the state for a civil penalty not to exceed $3,000. AS 45.48.560 separately allows a damaged individual to sue to enjoin further violations and to recover actual economic damages, court costs, and full reasonable attorney fees.
No Biometric Data Privacy Law (Yet)
Alaska has no statute regulating the collection, use, retention, or sale of biometric information such as fingerprints, retinal scans, voiceprints, or facial recognition data. AS Title 18, Chapter 13 is titled "Genetic Privacy," not biometric information, and its text ends at Sec. 18.13.100 with no provisions on biometric identifiers. No other Alaska chapter fills the gap.
Lawmakers have tried three times to pass a biometric privacy law, and all three attempts died in committee. HB 96 ("Collection of Biometric Information," 29th Legislature) stalled in the House State Affairs Committee as of February 2015. SB 98 ("Biometric Information for ID," 27th Legislature) and HB 72 ("Collection of Biometric Information," 30th Legislature) both stalled in the House Judiciary Committee without a floor vote.
Because no state statute is in force, Alaska residents currently have no state-law right to notice, consent, or a private right of action specific to biometric data collection. The general consumer-protection and constitutional privacy provisions described elsewhere on this page may still apply depending on the circumstances.

Genetic Privacy (AS 18.13.010-100)
Alaska's Genetic Privacy Act, codified at AS 18.13.010 through AS 18.13.100, provides robust protections for genetic information.
The statute strictly limits genetic testing and controls access to, retention of, and disclosure of genetic data. The core requirement is informed and written consent from the individual before any genetic testing can occur.
Alaska law recognizes that both the genetic information itself and the physical DNA samples collected are the property of the individual. This ownership principle means that entities holding genetic data cannot treat it as their own asset.
Violations of Alaska's genetic privacy protections can result in both civil and criminal penalties, making this one of the more strongly enforced privacy provisions in the state.
23andMe Genetic Data Settlement (2025)
The strength of Alaska's genetic privacy law was demonstrated in July 2025, when Attorney General Taylor announced a settlement with TTAM Research Institute, the nonprofit that acquired most of 23andMe's assets in bankruptcy.
Under the settlement, Alaskans received stronger protections than residents of other states. TTAM may only access the information or DNA samples of Alaskans who affirmatively consented to third-party sharing or biobanking. Alaskans who did not opt in to those consents will not have their data shared unless they affirmatively choose to allow it. TTAM agreed to allow all customers to request permanent deletion of their data and samples at any time.
Credit Report and Security Freeze (AS 45.48.100-290)
Alaska law gives consumers the right to place a security freeze on their credit reports and credit scores. A security freeze prevents a consumer credit reporting agency from releasing your credit information without your express authorization.
Consumers can request a security freeze by mail, telephone, fax, internet, or other electronic means if the credit reporting agency supports those methods. The agency must place the freeze within five business days of receiving the request.
Do not pay to freeze your credit. Federal law requires the three nationwide credit bureaus (Equifax, Experian, and TransUnion) to place and remove a security freeze free of charge, and 15 U.S.C. 1681t(b)(1)(J) preempts state law relating to security freezes. AS 45.48.160(b)-(c) still prints a $5 charge for placing a freeze and a $2 charge for each access request, and AS 45.48.160(e) exempts identity theft victims who provide a law enforcement complaint, but those state fee provisions are superseded as to the nationwide bureaus.
Several types of access remain available even when a freeze is in place, including review or collection of existing financial obligations, court-ordered access, child support enforcement by state or municipal agencies, fraud investigations, and prescreening permitted under the federal Fair Credit Reporting Act.
Consumers have a private right of action against any entity that violates the security freeze provisions.
Insurance Data Security (AS 21.23)
In 2024, Alaska enacted SB 134, establishing comprehensive data security requirements for the insurance industry under AS 21.23.240 through AS 21.23.399. The law applies to all licensees and admitted insurers regulated by the Alaska Division of Insurance and follows the National Association of Insurance Commissioners (NAIC) Insurance Data Security Model Law framework.
SB 134 takes effect on a staggered schedule:
- January 1, 2025: General data security standards and cybersecurity event notification requirements
- January 1, 2026: Risk assessment requirements (AS 21.23.250)
- January 1, 2027: Advanced information security program provisions (AS 21.23.260(c)(7) and (8))
Insurance licensees must implement an information security program that identifies reasonably foreseeable internal and external threats, assesses the likelihood and potential damage of those threats, and evaluates the sufficiency of current safeguards. Cybersecurity events must be reported to the Director of the Division of Insurance using an electronic form.
Identity Theft Protections
Alaska's Personal Information Protection Act includes several provisions aimed at identity theft prevention and recovery:
- Police reports: Victims of identity theft have the right to file a police report (AS 45.48.680)
- Credit card truncation: Businesses must truncate credit card numbers on receipts to prevent theft of full account numbers
- Consumer credit monitoring: Additional protections exist for consumers who have been victims of identity theft
- Court petition: Victims can petition the court for a determination of factual innocence to help clear fraudulent records

Enforcement: Alaska Attorney General Actions
The Alaska Attorney General has been active in enforcing data privacy protections through multistate settlements and consumer advisories.
Blackbaud Settlement (2023)
Alaska joined a $49.5 million multistate settlement with Blackbaud Inc. over a 2020 ransomware attack that exposed sensitive data belonging to customers of nonprofits, schools, healthcare providers, and religious institutions. The breach compromised Social Security numbers, driver's licenses, financial records, and protected health information. Alaska received $358,925 from the settlement. Blackbaud was required to overhaul its data security and breach notification practices.
Marriott Settlement (2024)
Alaska participated in a $52 million multistate settlement with Marriott International over the Starwood guest reservation database breach. Intruders had access to 131.5 million guest records from 2014 through 2018 without detection. Alaska received $376,629. Marriott must now implement zero-trust security principles, data minimization, network segmentation, and undergo independent security assessments every two years for 20 years.
Change Healthcare Advisory (2024)
Attorney General Taylor issued consumer advisories following the February 2024 Change Healthcare cyberattack, one of the largest healthcare data breaches in US history. The AG shared resources for free credit monitoring and identity theft protection services available to affected Alaskans.
23andMe Genetic Data Settlement (2025)
In July 2025, AG Taylor secured enhanced protections for Alaskans in the 23andMe bankruptcy sale to TTAM Research Institute. The settlement went beyond what other states obtained: only Alaskans who had affirmatively consented to data sharing or biobanking would have their information transferred. All others retained the right to immediate deletion.
NCII Deepfake Coalition (2025)
In August 2025, AG Taylor joined a bipartisan coalition of attorneys general urging tech companies to stop the spread of deepfake nonconsensual intimate imagery (NCII). The action preceded federal enforcement of the TAKE IT DOWN Act's platform obligations, which take effect May 19, 2026.
No Comprehensive Consumer Privacy Law (Yet)
Alaska does not currently have a comprehensive consumer data privacy law comparable to the California Consumer Privacy Act (CCPA) or the Texas Data Privacy and Security Act (TDPSA).
Prior Legislation: HB 159 / SB 116 (32nd Legislature, 2021)
Governor Dunleavy introduced the Consumer Data Privacy Act in 2021 through HB 159 and SB 116. The proposed law would have granted Alaskans four new rights: the right to know when businesses collect personal information, the right to disclose what data businesses hold, the right to delete personal information, and the right to opt out of the sale of personal information. The bill stalled in committee during the 32nd Legislature.
Current Legislation: HB 367 (34th Legislature, 2025-2026)
A successor bill, HB 367, was introduced in the 34th Legislature and referred to committee on February 23, 2026. Sponsored by Representative Andy Story, the bill would establish the Consumer Data Privacy Act, require businesses to notify consumers before collecting their personal data, create data broker registration requirements, and impose a 100,000-consumer threshold for covered entities.
On May 8, 2026, the House Judiciary Committee moved CSHB 367(JUD) out of committee with amendments, including a "duty of loyalty" provision modeled on recent Utah law; the committee report, filed May 12, was signed by all five members, three "do pass" and two "do pass with amendment," with no member recorded in opposition. As of May 2026, the bill has been referred to the House Finance Committee. No comprehensive law has been enacted as of the date of this publication.
Federal Laws That Apply in Alaska
Because Alaska lacks a comprehensive state privacy law, several federal statutes fill important gaps.
TAKE IT DOWN Act (2025)
The TAKE IT DOWN Act, Pub. L. 119-12, was signed into law on May 19, 2025. The law creates federal criminal liability for knowingly publishing nonconsensual intimate imagery (NCII), including AI-generated deepfakes. Penalties reach up to two years in prison for crimes against adult victims and three years for crimes against minors.
Platforms must remove reported NCII within 48 hours of a verified request and take reasonable steps to prevent reposting. The platform compliance obligations took effect May 19, 2026, and are enforced by the Federal Trade Commission. For Alaska residents, this federal law fills a significant gap because the state has no dedicated NCII statute of its own.
HIPAA
The Health Insurance Portability and Accountability Act governs the privacy of health information held by covered entities and business associates. HIPAA applies throughout Alaska to health plans, healthcare providers, and their business associates.
GLBA
The Gramm-Leach-Bliley Act requires financial institutions to explain their information-sharing practices and protect sensitive data. It applies to Alaska banks, credit unions, and other financial services firms.
COPPA
The Children's Online Privacy Protection Act restricts the collection of personal information from children under 13 by online services. The FTC actively enforces COPPA against operators who knowingly collect children's data without parental consent.
FCRA and FACTA
The Fair Credit Reporting Act regulates the collection, dissemination, and use of consumer credit information. The Fair and Accurate Credit Transactions Act of 2003 added identity theft provisions and the free annual credit report entitlement. Both apply to consumer reporting agencies operating in Alaska.
FTC Act Section 5
The Federal Trade Commission Act prohibits unfair or deceptive trade practices. The FTC has used Section 5 authority to pursue companies that fail to maintain reasonable data security, making it the primary federal privacy enforcement tool for companies not covered by a sector-specific statute.
APRA (Did Not Pass)
The American Privacy Rights Act, a bipartisan federal comprehensive privacy bill, was proposed in the 118th Congress but expired in January 2025 without enactment. No successor bill had been reintroduced as of May 2026. Alaska residents cannot rely on a federal comprehensive privacy law at this time.
Employee Data Privacy in Alaska
Alaska provides several protections for employee personal data.
Personnel file access. Under AS 23.10.430, employers must permit current and former employees to inspect and copy their personnel files during regular business hours under reasonable rules.
Anti-discrimination protections. AS 18.80.220 prohibits employers from inquiring into sex, disability, marital status, pregnancy, parenthood, age, race, religion, color, or national origin in connection with employment, unless based on a bona fide occupational qualification.
Constitutional privacy. Because Article I, Section 22 restricts government action, public-sector employees in Alaska have stronger workplace privacy protections than private-sector workers. Government employers must satisfy the constitutional balancing test before conducting surveillance or accessing employee data.
Recording laws. Alaska is a one-party consent state for recording conversations under AS 42.20.310(a)(1), which makes it unlawful to use an eavesdropping device to hear or record an oral conversation without the consent of a party to the conversation. This affects workplace monitoring. Employers should be aware that audio recording of employees without at least one party's consent may violate state wiretapping law.
More Alaska Laws
Frequently Asked Questions
Does Alaska have a comprehensive data privacy law like California or Texas?
No. Alaska does not have a comprehensive consumer data privacy law. HB 367, the Consumer Data Privacy Act introduced in the 34th Legislature, passed the House Judiciary Committee on May 8, 2026, and was referred to House Finance, but has not been enacted as of May 2026. Alaska residents are protected by the state's data breach notification law (AS 45.48), constitutional privacy rights under Article I Section 22, a targeted SSN statute (AS 45.48.400-430) but no biometric-data statute, and federal laws including HIPAA, the FCRA, and the TAKE IT DOWN Act.
What must a business do after a data breach involving Alaska residents?
Under AS 45.48.010, the business must notify affected Alaska residents in the most expeditious time possible and without unreasonable delay. If more than 1,000 residents are affected, the business must also notify nationwide consumer credit reporting agencies. The business may skip notification only if it determines there is no reasonable likelihood of harm and provides written notice of that determination to the Alaska Attorney General.
What penalties does Alaska impose for data breach notification failures?
Both government agencies and private businesses face civil penalties of up to $500 per resident who was not notified, with a total cap of $50,000 per breach. For private businesses, violations also constitute unfair trade practices. Affected individuals can sue for actual economic damages up to $500 plus attorney's fees and court costs.
How does Alaska protect biometric data like fingerprints and facial recognition?
Alaska has no biometric-information privacy statute. AS Title 18, Chapter 13 covers genetic privacy only and ends at Sec. 18.13.100; it does not regulate fingerprints, retinal scans, or facial recognition data, and no other Alaska statute does either. Three attempts to pass a biometric privacy law, HB 96 (2015), SB 98, and HB 72, have all died in committee, so Alaska residents currently have no state-specific right to notice, consent, or a private right of action over biometric data collection.
What makes Alaska's constitutional privacy right different from other states?
Alaska is one of about 11 states with an explicit right to privacy in its constitution. Article I, Section 22 was added in 1972 and states that the right of privacy shall not be infringed. Alaska courts interpret this provision more broadly than federal constitutional protections. It primarily limits government collection and use of personal data, and requires courts to apply a balancing test between privacy interests and competing public interests.
What is the TAKE IT DOWN Act and how does it protect Alaskans?
The TAKE IT DOWN Act (Pub. L. 119-12) was signed May 19, 2025. It makes it a federal crime to publish nonconsensual intimate imagery, including AI-generated deepfakes, without the subject's consent. Penalties reach up to two years in prison. Online platforms must remove reported content within 48 hours. Platform enforcement obligations took effect May 19, 2026. This law fills a gap for Alaska, which has no dedicated state NCII statute.
Can Alaskans freeze their credit reports?
Yes, and it is free. Federal law at 15 U.S.C. 1681c-1(i) requires the three nationwide bureaus, Equifax, Experian, and TransUnion, to place and remove a security freeze free of charge, and 15 U.S.C. 1681t(b)(1)(J) preempts state law relating to security freezes. The $5 placement charge and $2 access charge still printed in AS 45.48.160 are therefore superseded as to those bureaus. Alaska's own freeze statute, AS 45.48.100 through AS 45.48.290, still gives residents the right to request a freeze from a consumer credit reporting agency, which must place it within five business days of receiving the request and proper identification.
Updates
Corrected the Alaska Personal Information Protection Act's enactment year to 2008, replaced the wrong one-party-consent citation (AS 42.20.300) with the eavesdropping provision AS 42.20.310(a)(1), rewrote the AS 45.48.400 Social Security number rules to reflect the statute's conditional internet and mailing provisions instead of a flat ban, reattributed the record-disposal measures to AS 45.48.510 and AS 45.48.520 and corrected the $3,000 civil penalty wording, and replaced Alaska's superseded $5 and $2 security freeze fees with the federal rule that freezes are free at the three nationwide credit bureaus.
This page previously cited a nonexistent Alaska biometric-privacy statute (AS 18.13.200-270); Alaska Title 18 Chapter 13 covers genetic privacy only, and the state has no biometric-information privacy law after three failed bills (HB 96, SB 98, HB 72), so we rewrote the KeyTakeaways bullet, article section, FAQ answer, and citation that described one. We also added the $5 security-freeze placement fee alongside the existing $2 lift fee, and corrected a mischaracterized HB 367 committee vote as a unanimous procedural advancement rather than a contested 3-2 vote.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
May 2026 refresh: Added HB 367 (34th Legislature, passed House Judiciary Committee May 8, 2026, now in House Finance); added TAKE IT DOWN Act (Pub. L. 119-12, signed May 19, 2025, platform obligations effective May 19, 2026); added 23andMe genetic data settlement (July 2025) and AG NCII [deepfake](/us-laws/deepfake-laws) coalition action (August 2025); corrected a biometric statute citation (note: that citation was itself erroneous and was removed in August 2026; Alaska has no biometric-privacy statute); replaced Justia Genetic Privacy link with akleg.gov; added AS 42.20.300 wiretap citation to employee recording section (note: that citation was also wrong and was corrected to AS 42.20.310(a)(1), the eavesdropping provision, in August 2026); updated KeyTakeaways and FAQ to reflect current law; APRA status corrected (expired Jan 2025, not reintroduced); title and meta unchanged (strong existing CTR signals).
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Alaska Statutes, Title 45. Trade and Commerce, Chapter 48. Personal Information Protection Act
§ 45.48.010Disclosure of breach of securityIn forcecited in 2 of our articles
(a) If a covered person owns or licenses personal information in any form that includes personal information on a state resident, and a breach of the security of the information system that contains personal information occurs, the covered person shall, after discovering or being notified of the breach, disclose the breach to each state resident whose personal information was subject to the breach. (b) An information collector shall make the disclosure required by (a) of this section in the most expeditious time possible and without unreasonable delay, except as provided in AS 45.48.020 and as necessary to determine the scope of the breach and restore the reasonable integrity of the information system. (c) Notwithstanding (a) of this section, disclosure is not required if, after an appropriate investigation and after written notification to the attorney general of this state, the covered person determines that there is not a reasonable likelihood that harm to the consumers whose personal information has been acquired has resulted or will result from the breach. The determination shall be documented in writing, and the documentation shall be maintained for five years.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at akleg.gov
Also relied on in: Alaska Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Alaska Statutes, Title 42. Public Utilities and Carriers and Energy Programs, Chapter 20. Telegraph and Telephone Systems and Cable Lines; Eavesdropping
§ 42.20.300Unauthorized publication or use of communicationsIn force
(a) Except for a party to a private conversation, a person who receives or assists in receiving, or who transmits or assists in transmitting, a private communication may not divulge or publish the existence, contents, substance, purport, effect, or meaning of the communication, except through authorized channels of transmission or reception (1) to the addressee or the agent or attorney of the addressee; (2) to a person employed or authorized to forward a communication to its destination; (3) to proper accounting or distributing officers of the various communicating centers over which the communication may be passed; (4) to the master of a ship under whom the person is serving; (5) to another on demand of lawful authority; or (6) in response to a subpoena issued or order entered by a court of competent jurisdiction. (b) Except as provided in AS 12.37, a person not authorized by a party to the communication may not intentionally intercept a private communication or divulge or publish the existence, contents, substance, purport, effect, or meaning of the intercepted communication to any person.
Official text (excerpt) · last checked 2026-07-31 · Read the full text in our law library · Verify at akleg.gov
Cited in 2 court opinions in our collectionLatest citing opinion in our collection: 1999
Opinions citing this section in our collection:
- Bachlet v. State (Court of Appeals of Alaska 1997, 941 P.2d 200)“…to the general statutory prohibition on eavesdropping under AS 42.20.300(b).[ 7 ] In this case, Phillip Carter…”
- Boehner, John A. v. McDermott, James A. (Court of Appeals for the D.C. Circuit 1999, 191 F.3d 463)“…C. § 2511 . See Ala. Code §§ 13A-ll-31,13A-ll-35 (1994); Alaska Stat. §§ 42.20.300 to 42.20.330 (Michie 1989 & Supp.1995)…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Alaska Constitution Article I, Sections 14 and 22 - Lieutenant Governor of Alaska(ltgov.alaska.gov).gov
- Alaska Personal Information Protection Act (AS 45.48) - Alaska State Legislature(akleg.gov).gov
- Alaska Statutes Title 45 Chapter 48 - Alaska State Legislature(akleg.gov).gov
- Alaska Statutes Title 18 Chapter 13 - Genetic Privacy (AS 18.13); Alaska has no biometric-information privacy statute(akleg.gov).gov
- Alaska Wiretapping Statute AS 42.20.300 - One-Party Consent Recording(akleg.gov).gov
- Alaska Division of Insurance Cyber Security - SB 134 (AS 21.23)(commerce.alaska.gov).gov
- Alaska AG Settlement with Blackbaud Inc. - $49.5M Multistate Settlement(law.alaska.gov).gov
- Alaska AG Settlement with Marriott International - $52M Multistate Settlement(law.alaska.gov).gov
- Change Healthcare Cyberattack Consumer Resources - Alaska Department of Law(law.alaska.gov).gov
- Alaska AG Settlement on 23andMe Bankruptcy - Genetic Data Protections (July 2025)(law.alaska.gov).gov
- Alaska AG Joins Coalition on Deepfake NCII (August 2025)(law.alaska.gov).gov
- HB 367 Consumer Data Privacy Act - 34th Legislature (2025-2026)(akleg.gov).gov
- HB 159 Consumer Data Privacy Act - 32nd Legislature (2021)(akleg.gov).gov
- TAKE IT DOWN Act Becomes Law - Orrick Analysis (May 2025)(orrick.com)
- Alaska Department of Administration Privacy Statement(doa.alaska.gov).gov
- Alaska Statutes AS 45.48.400-45.48.480 - Social Security Number Protection and Penalties(akleg.gov).gov
- Alaska Statutes AS 45.48.500-45.48.590 - Disposal of Records(akleg.gov).gov
- Alaska Statutes AS 45.48.100-45.48.290 - Credit Report and Credit Score Security Freeze(akleg.gov).gov
- Alaska Statutes AS 42.20.310 - Eavesdropping (one-party consent to record an oral conversation)(akleg.gov).gov
- Alaska HB 65, 25th Legislature - Personal Information & Consumer Credit, signed into law 6/13/2008, ch. 92 SLA 08(akleg.gov).gov
- 15 U.S.C. 1681c-1(i) - Security freezes must be placed and removed free of charge by nationwide consumer reporting agencies(law.cornell.edu)
- 15 U.S.C. 1681t(b)(1)(J) - Federal preemption of state law relating to security freezes(law.cornell.edu)