EnglishEspañol
Alaska flag

Alaska

Alaska Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 14 primary sources cited on this page. How we verify our legal content

Alaska Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How long does a company have to notify me of a data breach in Alaska?

Alaska does not set a specific deadline in days. The law requires notification 'in the most expeditious time possible and without unreasonable delay' after the entity discovers the breach and determines its scope. This flexible standard is enforced by the Attorney General against businesses and by the Department of Administration against government agencies, either of which can act on unreasonable delays. Some states set deadlines of 30 to 60 days, but Alaska's standard is fact-specific.

Can I sue a company for failing to notify me of a data breach in Alaska?

Yes. Alaska is one of approximately 12 states that provides a private right of action for breach notification violations. Under AS 45.48.080, you can file a civil lawsuit to recover actual economic damages up to $500 per person, plus court costs and attorney's fees. This right exists independently of any enforcement action by the Attorney General.

Does Alaska's breach notification law cover medical records or biometric data?

No. Alaska's definition of protected personal information is limited to a person's name combined with a Social Security number, driver's license or state ID number, or financial account number with access codes. The law does not cover medical records, health insurance information, biometric identifiers, email credentials, or taxpayer identification numbers. For biometric data protections, see the Alaska Biometric Privacy Laws page.

Do I have to notify the Alaska Attorney General about every data breach?

Not in every case. Attorney General notification is only required when a covered entity investigates a breach and determines there is no reasonable likelihood of harm, and therefore decides not to notify consumers. In that situation, the entity must provide written notice to the AG explaining its determination and retain documentation for five years. If you are notifying consumers, there is no separate AG notification requirement.

Does encryption protect my business from Alaska's breach notification requirements?

Yes, if the encryption was effective. Alaska's law includes an encryption safe harbor. If the personal information was encrypted at the time of the breach and the encryption key was not compromised or acquired by the unauthorized party, notification is not required. The same applies to data that was properly redacted. This gives businesses a strong incentive to encrypt personal data at rest and in transit.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Clarified that the Alaska Attorney General enforces breach notification against businesses while the Department of Administration enforces against state and local government agencies, noted that agencies of the judicial branch are excluded from the law's definition of a governmental agency, and updated the SB 134 source link.

Corrected a misquote of Alaska's breach-notification timing standard (the statute says "expeditious," not "expedient"), added the statute's third covered-entity category (any person with more than 10 employees), clarified that a financial-account password or PIN can independently qualify as protected personal information, and replaced two dead source links (the 2019 Equifax settlement citation and the E-SIGN Act citation) with live official sources.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Corrected two errors: the individual civil-action remedy under AS 45.48.080 recovers damages only (the injunction remedy is reserved for governmental-agency enforcement, not a private business), and the breach-notification table's 'full or partial SSN' entry was fixed to reflect that a redacted/partial SSN does not trigger notification, matching the statute's redaction exclusion and the page's own encryption/redaction safe-harbor section.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Alaska Personal Information Protection Act (AS 45.48.010-090)(akleg.gov).gov
  2. AS 45.48.090 - Definitions(akleg.gov).gov
  3. AS 45.48.030 - Methods of Disclosure(akleg.gov).gov
  4. AS 45.48.020 - Delay of Disclosure(akleg.gov).gov
  5. AS 45.48.080 - Violations(akleg.gov).gov
  6. AS 45.48.060 - Waivers(akleg.gov).gov
  7. Alaska Unfair Trade Practices Act (AS 45.50.471-561)(akleg.gov).gov
  8. E-SIGN Act (15 U.S.C. 7001)(govinfo.gov).gov
  9. Gramm-Leach-Bliley Act(ftc.gov).gov
  10. AG Settlement with Blackbaud (2023)(law.alaska.gov).gov
  11. AG Settlement with Marriott (2024)(law.alaska.gov).gov
  12. FTC: Equifax Data Breach Settlement (2019)(ftc.gov).gov
  13. Alaska AG Consumer Protection Complaint Form(law.alaska.gov).gov
  14. Alaska SB 134 Insurance Data Security(commerce.alaska.gov).gov
  15. Alaska SB 134 (2024) - Insurance Data Security, AS 21.23(akleg.gov)
  16. Enrolled SB 134 (Laws of Alaska 2024) - full text and staggered effective dates(akleg.gov)
Share: