Arizona
Arizona Data Privacy Laws: Breach Rules & Consumer Rights (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 18 primary sources cited on this page. How we verify our legal content

Arizona has no comprehensive consumer data privacy law as of 2026, but businesses must notify affected residents of a breach within 45 days under A.R.S. § 18-552, with civil penalties reaching $500,000 for knowing violations. Sector-specific protections cover genetic data, student records, and insurance information.
Arizona does not have a comprehensive consumer data privacy statute comparable to the California Consumer Privacy Act or the Virginia Consumer Data Protection Act. As of May 2026, the state has introduced SB 1815 in the 57th Legislature's second regular session, but no comprehensive privacy bill has passed.
Arizona residents are not without protection. The state enforces a robust data breach notification law with a hard 45-day deadline, sector-specific privacy statutes covering genetic data, student records, and insurance information, a consumer fraud act that the AG has used to bring major enforcement actions, and federal frameworks that fill key gaps for healthcare and financial data.
This guide covers every Arizona-specific data privacy protection currently in force, the obligations businesses face, and the rights residents can exercise when their personal information is compromised. For recording-consent rules in Arizona, see Arizona Recording Laws.
Arizona Data Breach Notification Law (A.R.S. § 18-552)
The centerpiece of Arizona's data privacy framework is the data breach notification statute at A.R.S. §§ 18-551 and 18-552. Originally enacted in 2006 and significantly strengthened by HB 2154 in 2018, this law sets clear deadlines and penalties for businesses that experience security breaches involving personal information. The 2018 amendments added the mandatory 45-day notification timeline, expanded the definition of personal information, and required notice to the Attorney General and the major consumer reporting agencies for breaches affecting more than 1,000 individuals. A later amendment, HB 2146 in 2022, added the Director of the Arizona Department of Homeland Security to the list of officials who must receive those large-breach notices.

Who Must Comply
The law applies to any person or entity that conducts business in Arizona and owns, maintains, or licenses unencrypted and unredacted computerized personal information. This includes corporations, partnerships, sole proprietors, government agencies, and nonprofit organizations.
The key phrase is "conducts business in Arizona." A company does not need to be headquartered in the state. Any business that collects or processes the personal data of Arizona residents must comply with the notification requirements if a breach occurs.
What Counts as Personal Information
Under A.R.S. § 18-551, personal information means an individual's first name or first initial and last name combined with one or more of the following specified data elements:
- Social Security number
- Driver's license or non-operating identification license number issued under A.R.S. § 28-3166 or § 28-3165
- Financial account number or credit or debit card number combined with any required security code, access code, or password
- Health insurance identification number
- Medical or mental health treatment information
- Taxpayer identification number or identity protection personal identification number issued by the IRS
- Unique biometric data generated from a measurement or analysis of a biological characteristic (fingerprint, retina, iris) used to authenticate an individual accessing an online account
- A private key unique to an individual used to authenticate or sign an electronic record
- Passport number
- A username or email address combined with a password or security question and answer that would permit access to an online account
The statute specifies that personal information does not include publicly available information that is lawfully made available to the general public from federal, state, or local government records.
The 45-Day Notification Timeline
When a person conducting business in Arizona becomes aware of a security incident, they must promptly investigate to determine whether a security system breach has occurred. If the investigation confirms a breach, the person who owns or licenses the data must notify affected individuals within 45 days of that determination.
Notification may be provided in one of three ways:
- Written notice sent to the individual's mailing address
- Telephone notification directly to the affected individual
- Email notice if the individual has previously provided an email address
A substitute notice option is available if the cost of standard notification exceeds $50,000, the affected class exceeds 100,000 individuals, or the entity does not have sufficient contact information. Substitute notice requires sending a letter to the Arizona Attorney General demonstrating the necessity and posting notice conspicuously on the entity's website for at least 45 days.
Large Breach Reporting Requirements
If a breach requires notification of more than 1,000 individuals, the entity must also provide written notice to:
- The three largest nationwide consumer reporting agencies (Equifax, Experian, and TransUnion)
- The Arizona Attorney General
- The Director of the Arizona Department of Homeland Security
The notification to the Attorney General must follow the form prescribed by rule or order of the AG, or the entity may provide a copy of the notification sent to affected individuals. All notifications to the Director of the Department of Homeland Security are treated as confidential.
When Notification Is Not Required
A covered entity is not required to send breach notifications if the entity itself, an independent third-party forensic auditor, or a law enforcement agency determines after a reasonable investigation that the breach has not resulted in and is not reasonably likely to result in substantial economic loss to affected individuals. The statute lets the breached entity make that determination on its own, so long as it conducts a reasonable investigation.
Notification may also be delayed if a law enforcement agency advises the entity that notifying would impede a criminal investigation. Once law enforcement informs the entity that notification no longer compromises the investigation, the entity has 45 days from that point to make the required notifications.
Penalties for Violations
A knowing and willful violation of A.R.S. § 18-552 is classified as an unlawful practice under A.R.S. § 44-1522 of the Arizona Consumer Fraud Act. Only the Arizona Attorney General may enforce these violations.
The AG may seek:
- Civil penalties not to exceed the lesser of $10,000 per affected individual or the total economic loss sustained by affected individuals, with a cap of $500,000 per breach or series of related breaches
- Restitution to affected individuals
- Injunctive relief to prevent ongoing violations
There is no private right of action under the breach notification statute. Individual consumers cannot sue businesses directly for failing to provide timely notification.
HIPAA and GLBA Exemptions
Entities already regulated by certain federal laws are exempt from Arizona's breach notification requirements:
- HIPAA-covered entities: Healthcare providers, health plans, and healthcare clearinghouses subject to the federal Health Insurance Portability and Accountability Act do not need to comply with state law, provided they follow federal breach notification rules
- GLBA-regulated entities: Financial institutions subject to Title V of the Gramm-Leach-Bliley Act are exempt from the Arizona statute
These exemptions exist because federal law already imposes breach notification requirements on these industries that meet or exceed the state standard.
State Preemption
Arizona's breach notification statute explicitly preempts all municipal and county laws, charters, ordinances, and rules relating to security system breach notification. Cities like Phoenix, Tucson, and Mesa cannot impose additional local breach notification requirements.
Reasonable Security Requirements
Arizona does not impose a general statutory duty on businesses to maintain reasonable security procedures. A.R.S. § 18-552 requires notification once a breach is discovered, but it does not itself mandate pre-breach security measures for private businesses. A comparable reasonable-security-procedures standard does exist in Arizona law, but at A.R.S. § 15-1046(C)(1), where it applies to student-data operators, not to businesses generally.
Because no general security duty applies to Arizona businesses, the state does not prescribe specific technical controls or security frameworks they must adopt. The Attorney General's leverage is indirect: a business that misrepresents its security practices, for example in a privacy policy, can face enforcement under the Arizona Consumer Fraud Act if a breach follows.
Businesses that suffer a breach after misrepresenting their security practices can face Consumer Fraud Act enforcement action by the Attorney General, discussed in the next section.
Arizona Consumer Fraud Act and Data Privacy
The Arizona Consumer Fraud Act (A.R.S. § 44-1522) declares it unlawful to employ deception, deceptive or unfair acts, fraud, false pretenses, misrepresentation, or concealment of material facts in connection with the sale or advertisement of merchandise. The AG has used this statute to bring significant data-privacy enforcement actions.
The Consumer Fraud Act gives the Attorney General authority to investigate and prosecute businesses that:
- Make false claims about how they collect, use, or share personal data
- Fail to disclose material data collection practices to consumers
- Misrepresent the security measures protecting consumer information
- Violate their own published privacy policies

Google Location Tracking Settlement (2022)
In October 2022, then-Arizona Attorney General Mark Brnovich secured an $85 million settlement with Google over deceptive location tracking practices. Arizona's lawsuit followed an investigation showing that Google continued to track the location of Android devices even after users disabled the Location History setting, relying on a separate Web and App Activity setting to access location data for targeted advertising. The $85 million settlement was the largest per-capita privacy settlement of its kind at the time, and constituted a standalone Arizona recovery on top of a separate $391.5 million multistate settlement with 40 states announced on November 14, 2022.
Temu Lawsuit (December 2025)
On December 2, 2025, Arizona Attorney General Kris Mayes filed suit against Temu and its parent company PDD Holdings in Maricopa County Superior Court, alleging violations of the Arizona Consumer Fraud Act. The complaint alleges that the Temu app is designed to harvest sensitive user data without users' knowledge or consent, including precise physical location, microphone and camera access, and private activity on other apps installed on the device. The app allegedly uses multiple layers of encryption to evade front-end security review. The lawsuit also alleges deceptive trade practices including false advertising, misappropriated intellectual property, and a pattern of refusing to participate in consumer arbitration. As of May 2026, the litigation is pending.
Arizona Computer Crimes Act (A.R.S. § 13-2316)
Arizona's Computer Crimes Act at A.R.S. § 13-2316 prohibits unauthorized access to computer systems with the intent to disrupt, alter, damage, delete, or destroy data or programs. The statute encompasses computer tampering, unlawful possession of an access device, and unauthorized release of proprietary or confidential computer security information.
Violations range from a class 6 felony up to a class 2 felony depending on the specific conduct: knowingly accessing a computer, system, or data without authorization is a class 6 felony, disrupting, altering, or destroying data is generally a class 4 felony (class 2 if critical infrastructure is involved), and using a computer to defraud or deceive is a class 3 felony. While the statute addresses anti-hacking conduct rather than consumer privacy directly, the provisions most relevant to unauthorized access to personal data held by businesses and government agencies, knowingly obtaining confidential records under A.R.S. § 13-2316(A)(7)-(8), are class 6 felonies, the statute's lowest tier. Prosecutors have used A.R.S. § 13-2316 in cases involving unauthorized access to databases containing personal information.
Voyeurism and Nonconsensual Intimate Images (A.R.S. § 13-1424)
Arizona's voyeurism statute at A.R.S. § 13-1424 prohibits knowingly invading another person's privacy without their knowledge for the purpose of sexual stimulation. The statute covers photographing or filming a person in a private state and separately prohibits disclosing, displaying, distributing, or publishing such images. A violation is generally a class 5 felony, except that disclosing, displaying, distributing, or publishing the image is a class 4 felony if the person depicted is recognizable.
The federal TAKE IT DOWN Act (discussed below) now supplements state voyeurism law by adding criminal penalties for nonconsensual intimate images, including AI-generated deepfakes, and imposing platform removal obligations.
Genetic Information Privacy Act (HB 2069)
Arizona enacted one of the nation's more detailed genetic data privacy laws when HB 2069 took effect on September 29, 2021. The law targets direct-to-consumer genetic testing companies that collect and process DNA, chromosomes, genes, or gene products.
Key Requirements for Testing Companies
Privacy notices. Companies must provide a clear, publicly available privacy notice describing their data collection, consent, use, access, disclosure, transfer, security, retention, and deletion practices. A high-level privacy policy overview must also be available.
Express consent. Companies must obtain the consumer's express consent before collecting, using, or disclosing genetic data. The consent must clearly describe the intended uses and specify who will have access to test results.
Separate consent for research. If the company wants to use genetic data for research, product development, or sharing with third parties, it must obtain separate opt-in consent beyond the initial testing consent.
Data security. Companies must develop, implement, and maintain a comprehensive security program to protect genetic data against unauthorized access, use, or disclosure.
Law enforcement restrictions. Companies cannot disclose genetic data to law enforcement or government agencies without the consumer's express written consent unless they receive a valid legal process such as a warrant or court order.
Consumer Rights Under the Genetic Privacy Act
Arizona residents who use direct-to-consumer genetic testing services have the right to:
- Access their genetic data held by the company
- Delete their account and all associated genetic data
- Request destruction of their biological samples
Prohibited Disclosures
The law specifically prohibits genetic testing companies from disclosing consumer genetic data to:
- Health insurance companies
- Life insurance companies
- Long-term care insurance companies
- Employers of the consumer
Violations can result in a civil penalty of up to $2,500 per violation, actual damages incurred by consumers as a result of the violation, and the costs and reasonable attorney fees incurred by the Attorney General's office.
Student Data Privacy Protections
Arizona has enacted specific protections for student data through A.R.S. § 15-1046 and related statutes.
Biometric Data in Schools
Under Arizona law, schools in school districts and charter schools cannot collect biometric information from a student unless the student's parent or guardian gives written permission. Schools must provide written notice to parents at least 30 days before collecting biometric information.
Student data protected under Arizona law includes first and last name, home address, telephone number, email address, discipline records, grades, test results, evaluations, special education data, medical and health records, Social Security number, biometric information, juvenile dependency records, socioeconomic information, photos, voice recordings, and geographic information.
These protections supplement the federal Family Educational Rights and Privacy Act (FERPA), which gives parents rights to access education records and limits disclosure without consent.
Insurance Data Privacy (A.R.S. § 20-2104)
Arizona requires insurers and insurance producers to provide privacy notices to applicants and policyholders under A.R.S. § 20-2104. Insurance companies must deliver a notice of information practices no later than when they deliver the insurance policy or when they first collect personal information from a source other than the applicant or public records.
For ongoing relationships, the notice must be provided at least annually during the continuation of the policyholder relationship. Insurance privacy notices must comply with Section 503 of the federal Gramm-Leach-Bliley Act or include the specific disclosures required by Arizona statute.
Federal Privacy Laws That Apply in Arizona
Because Arizona lacks a comprehensive privacy law, several federal statutes serve as the primary privacy framework for specific sectors.

TAKE IT DOWN Act (May 2025)
The Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act (TAKE IT DOWN Act), Pub. L. 119-12, was signed by President Trump on May 19, 2025. The criminal prohibition on publishing nonconsensual intimate images (NCII), including AI-generated deepfakes, took effect immediately. Platform obligations under Section 3 of the Act, which require covered platforms to implement a notice-and-removal process for NCII requests and to remove flagged content within 48 hours of a valid request, became enforceable on May 19, 2026, when the FTC began active enforcement. Platforms that fail to reasonably comply face FTC enforcement action, with civil penalties of up to $53,088 per violation.
Arizona residents who are victims of nonconsensual intimate image sharing can now submit removal requests directly to covered platforms under the federal framework, supplementing the state voyeurism statute at A.R.S. § 13-1424.
Health Insurance Portability and Accountability Act (HIPAA)
HIPAA protects the privacy of individually identifiable health information held by covered entities (healthcare providers, health plans, healthcare clearinghouses) and their business associates. Arizona healthcare organizations must comply with HIPAA's Privacy Rule, Security Rule, and Breach Notification Rule.
The importance of HIPAA protections for Arizona residents was underscored in June 2025, when AG Mayes joined a 19-state coalition suing the Trump administration over HHS's mass transfer of Medicaid personal health records to the Department of Homeland Security, alleging violations of HIPAA, the Social Security Act, the Privacy Act, and the Administrative Procedure Act.
Gramm-Leach-Bliley Act (GLBA)
Financial institutions operating in Arizona must comply with GLBA, which requires written data protection policies, employee training on data security, and privacy notices to consumers explaining how their financial information is collected, shared, and protected.
Children's Online Privacy Protection Act (COPPA)
Websites and online services directed at children under 13 that operate in or reach Arizona residents must comply with COPPA's parental consent and data minimization requirements.
Family Educational Rights and Privacy Act (FERPA)
FERPA protects student education records at institutions receiving federal funding. Arizona schools, colleges, and universities must comply with FERPA's requirements for access rights and disclosure limitations.
Fair Credit Reporting Act (FCRA)
The FCRA regulates the collection, dissemination, and use of consumer credit information. Consumer reporting agencies, users of credit reports, and furnishers of credit data in Arizona must comply with FCRA requirements.
FTC Act Section 5
The FTC enforces the prohibition on unfair or deceptive acts or practices under Section 5 of the FTC Act (15 U.S.C. § 45). This provides a federal backstop for data privacy violations not covered by sector-specific statutes, including deceptive privacy policies and inadequate data security practices.
American Privacy Rights Act (APRA)
The American Privacy Rights Act was introduced in Congress in 2024 as a bipartisan comprehensive federal privacy bill. It did not pass. A revised version circulated in 2025 under the label APRA 2.0. As of May 2026, no federal comprehensive consumer data privacy law has been enacted. Until one passes, state-by-state rules remain the primary framework for consumer privacy rights.
Pending Arizona Legislation
Arizona has consistently failed to pass comprehensive consumer privacy legislation. The most recent comprehensive attempt was HB 2790, introduced in February 2022, which did not advance past committee.
In the 57th Legislature's second regular session (2026), SB 1815, titled "Personal data; consumers; controllers; requirements," was introduced on February 10, 2026 and received a second Senate reading. The bill has not passed as of May 2026 and no comprehensive privacy law is currently on a path to enactment this session.
Arizona's House passed HB 2861 (social media protections for minors) during the 57th Legislature's first regular session in 2025. That bill, which would require social media platforms to enable high-level privacy protections by default for minor users, moved to the Senate but its final signed status was not confirmed in available legislative records at the time of this update.
The national trend toward state privacy legislation, combined with active AG enforcement under existing consumer fraud authority, suggests continued legislative activity in future sessions.
How to Report a Data Breach in Arizona
If you are a business or organization that has experienced a data breach affecting Arizona residents:
- Investigate promptly to determine whether a security system breach has occurred
- Notify affected individuals within 45 days of determining a breach occurred, using written notice, telephone, or email
- Notify the Attorney General if more than 1,000 individuals are affected, using the AG notification form
- Notify the Director of the Arizona Department of Homeland Security if more than 1,000 individuals are affected
- Notify the three major credit reporting agencies (Equifax, Experian, TransUnion) if more than 1,000 individuals are affected
If You Are a Consumer Affected by a Breach
Arizona residents who believe their personal information has been compromised can:
- File a consumer complaint with the Arizona Attorney General's Office
- Place a fraud alert or credit freeze with the three major credit reporting agencies
- Monitor financial accounts and credit reports for unauthorized activity
- Report identity theft to the Federal Trade Commission at IdentityTheft.gov
Compliance Steps for Arizona Businesses
Arizona businesses that collect personal information should take these practical steps:

Map your data. Know what personal information you hold, where it lives, and who has access to it. The definition of personal information under A.R.S. § 18-551 is specific; make sure your inventory covers all covered categories.
Align security practices with your public claims. Arizona does not prescribe specific technical controls, but the AG can bring Consumer Fraud Act enforcement against businesses that misrepresent their security practices and then suffer a breach. Aligning with a recognized framework such as the NIST Cybersecurity Framework or CIS Controls provides a defensible baseline and reduces that gap.
Prepare an incident response plan. The 45-day notification clock starts on the day you determine a breach occurred. Without a tested plan, that deadline is difficult to meet. Include legal counsel, forensic investigators, and notification vendors in your plan.
Review your privacy policy. The Consumer Fraud Act reaches businesses that violate their own published privacy policies. Ensure your policy accurately describes your data practices.
Check your vendor contracts. Third-party processors that handle personal information on your behalf can trigger your notification obligations if they suffer a breach. Contracts should require prompt notification and specify their security standards.
Know your federal obligations. If you are a HIPAA covered entity, a GLBA financial institution, or a company marketing to children, federal law governs your privacy and breach obligations. These federal requirements supplement, and in many cases replace, Arizona's state breach notification law.
More Arizona Laws
Frequently Asked Questions
Does Arizona have a comprehensive data privacy law like California or Virginia?
No. As of May 2026, Arizona does not have a comprehensive consumer data privacy law. The state relies on its data breach notification statute (A.R.S. § 18-552), the Consumer Fraud Act, sector-specific laws like the Genetic Information Privacy Act, and applicable federal laws including HIPAA and GLBA. SB 1815, introduced in the 57th Legislature's second regular session in February 2026, has not passed. Multiple earlier attempts, including HB 2790 in 2022, also failed to advance.
How quickly must a business notify me of a data breach in Arizona?
Under A.R.S. § 18-552, businesses must notify affected individuals within 45 days after determining that a security system breach has occurred. Notification must be provided in writing, by telephone, or by email. If the breach affects more than 1,000 Arizona residents, the business must also notify the Arizona Attorney General, the Department of Homeland Security, and the three major credit reporting agencies within the same 45-day window.
Can I sue a company for a data breach in Arizona?
Arizona's breach notification statute does not provide a private right of action. Only the Attorney General can bring enforcement actions under A.R.S. § 18-552, seeking civil penalties up to $500,000 plus restitution. However, consumers may have claims under the Arizona Consumer Fraud Act (A.R.S. § 44-1522) if a business made deceptive claims about its data security practices, or through common law negligence and breach of contract theories.
Are healthcare providers and banks exempt from Arizona's data breach notification law?
Yes. Entities subject to HIPAA (healthcare providers, health plans, healthcare clearinghouses) and entities regulated under Title V of the Gramm-Leach-Bliley Act (financial institutions) are exempt from Arizona's state breach notification requirements. These entities must still comply with their respective federal breach notification and data security obligations, which generally meet or exceed the state standard.
What are my rights regarding genetic testing data in Arizona?
Under Arizona's Genetic Information Privacy Act (HB 2069, effective September 2021), consumers who use direct-to-consumer genetic testing services have the right to access their genetic data, delete their account and genetic data, and request destruction of biological samples. Testing companies cannot share genetic data with health insurers, life insurers, long-term care insurers, or employers. Companies must obtain express consent before collecting or using genetic data and cannot disclose it to law enforcement without a valid legal process.
What is the TAKE IT DOWN Act and does it protect Arizona residents?
The TAKE IT DOWN Act (Pub. L. 119-12, signed May 19, 2025) is a federal law that criminalizes the publication of nonconsensual intimate images, including AI-generated deepfakes. The criminal prohibition took effect immediately on signing. Platform removal obligations under Section 3 of the Act, which require covered platforms to remove flagged content within 48 hours of a valid request, became enforceable on May 19, 2026. The FTC enforces platform compliance. Arizona residents can submit removal requests to covered platforms under the federal framework, in addition to pursuing state remedies under A.R.S. § 13-1424 (voyeurism).
How has the Arizona AG enforced data privacy rules?
Arizona AG Mark Brnovich secured an $85 million settlement with Google in October 2022 over deceptive location tracking practices under the Consumer Fraud Act. AG Kris Mayes filed suit against Temu in December 2025 for alleged unauthorized data harvesting and deceptive trade practices. Mayes also joined a 19-state coalition in June 2025 suing the Trump administration over the mass transfer of Medicaid health records to DHS, alleging HIPAA violations. The AG's office actively accepts consumer data breach complaints and breach notifications from businesses.
Does Arizona have a law against computer hacking?
Yes. A.R.S. § 13-2316 (Arizona Computer Crimes Act) prohibits unauthorized access to computer systems with intent to disrupt, alter, damage, delete, or destroy data or programs. Depending on the specific conduct, violations range from a class 6 felony, the tier covering unauthorized access to confidential records and databases, up to a class 2 felony for tampering with critical infrastructure. The statute applies to unauthorized access to databases containing personal information and complements the civil enforcement framework under the breach notification and consumer fraud statutes.
Updates
Corrected the breach-law history to credit the 2018 amendment (HB 2154) with the 45-day notification deadline and the expanded personal-information definition, restated the law enforcement delay and the no-substantial-economic-loss exception to match A.R.S. 18-552, dated the $391.5 million multistate Google settlement to November 2022, and corrected who recovers damages under the Genetic Information Privacy Act.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected the A.R.S. 13-2316 and 13-1424 felony-classification descriptions to match the statutes' actual tiered penalties, and rewrote the 'Reasonable Security Requirements' section, which had misattributed a student-data-operator security duty (A.R.S. 15-1046) to the breach notification statute (A.R.S. 18-552).
Governing law re-checked for recent changes
May 2026 refresh: Added AG Mayes Temu lawsuit (December 2025), Google $85 million settlement specifics (October 2022), TAKE IT DOWN Act federal coverage (signed May 2025, platform obligations effective May 2026), Arizona Computer Crimes Act (A.R.S. § 13-2316), voyeurism statute (A.R.S. § 13-1424), pending SB 1815 (introduced February 2026), Medicaid data transfer lawsuit (June 2025), compliance steps for businesses section, expanded FAQ to 8 items, converted sources to SourcesList component. Word count increased from 2,847 to approximately 4,600.
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Arizona Revised Statutes, Title 18 (Information Technology), Chapter 5 (NETWORK SECURITY), Article 4 (Data Security Breaches)
§ 18-552Notification of security system breaches; requirements; enforcement; confidentiality; civil penalty; preemption; exceptionsIn forcecited in 3 of our articles
A. If a person that conducts business in this state and that owns, maintains or licenses unencrypted and unredacted computerized personal information becomes aware of a security incident, the person shall conduct an investigation to promptly determine whether there has been a security system breach. B. If the investigation results in a determination that there has been a security system breach, the person that owns or licenses the computerized data, within forty-five days after the determination, shall: 1. Notify the individuals affected pursuant to subsection E of this section and subject to the needs of law enforcement as provided in subsection D of this section. 2. If the breach requires notification of more than one thousand individuals, notify both: (a) The three largest nationwide consumer reporting agencies.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at azleg.gov
Also relied on in: Arizona Biometric Privacy Laws: Collection, Consent & Penalties (2026), Arizona Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 18-551DefinitionsIn forcecited in 3 of our articles
In this article, unless the context otherwise requires: 1. "Breach" or "security system breach": (a) Means an unauthorized acquisition of and unauthorized access that materially compromises the security or confidentiality of unencrypted and unredacted computerized personal information maintained as part of a database of personal information regarding multiple individuals. (b) Does not include a good faith acquisition of personal information by a person's employee or agent for the purposes of the person if the personal information is not used for a purpose unrelated to the person and is not subject to further unauthorized disclosure. 2. "Court" means the supreme court, the court of appeals, the superior court, a court that is inferior to the superior court and a justice court. 3. "Encrypt" means to use a process to transform data into a form that renders the data unreadable or unusable without using a confidential process or key. 4. "Individual" means a resident of this state who has a principal mailing address in this state as reflected in the records of the person conducting business in this state at the time of the breach. 5.
Official text (excerpt) · last checked 2026-08-04 · Read the full text in our law library · Verify at azleg.gov
Arizona Revised Statutes, Title 44 (Trade and Commerce), Chapter 10 (COMPETITION AND COMPETITIVE PRACTICES), Article 7 (Consumer Fraud)
§ 44-1522Unlawful practices; intended interpretation of provisionsIn force
A. The act, use or employment by any person of any deception, deceptive or unfair act or practice, fraud, false pretense, false promise, misrepresentation, or concealment, suppression or omission of any material fact with intent that others rely on such concealment, suppression or omission, in connection with the sale or advertisement of any merchandise whether or not any person has in fact been misled, deceived or damaged thereby, is declared to be an unlawful practice. B. The violation of chapter 9, article 16 or chapter 19, article 1 of this title is declared to be an unlawful practice and subject to enforcement under this article. C. It is the intent of the legislature, in construing subsection A, that the courts may use as a guide interpretations given by the federal trade commission and the federal courts to 15 United States Code sections 45, 52 and 55(a)(1).
Official text (excerpt) · last checked 2026-08-04 · Read the full text in our law library · Verify at azleg.gov
Cited in 157 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Parks v. MacRo-dynamics, Inc. (Court of Appeals of Arizona 1979, 121 Ariz. 517)“…amen of which is fraud, both common law and statutory under A.R.S. Sec. 44-1522, alleges that in advertisements and in…”
- Peery v. Hansen (Court of Appeals of Arizona 1978, 120 Ariz. 266)“…eason of such acts. The unlawful practices are set forth in A.R.S. Sec. 44-1522; “A. The act, use, or employment by a…”
- Haisch v. Allstate Insurance (Court of Appeals of Arizona 2000, 197 Ariz. 606)“…misrepresentation" within the Arizona Consumer Fraud Act, A.R.S. § 44-1522(A); or b. a misrepresentation that wo…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Arizona Revised Statutes, Title 13 (Criminal Code), Chapter 14 (SEXUAL OFFENSES)
§ 13-1424Voyeurism; classificationIn forcecited in 8 of our articles
A. It is unlawful to knowingly invade the privacy of another person without the knowledge of the other person for the purpose of sexual stimulation. B. It is unlawful for a person to disclose, display, distribute or publish a photograph, videotape, film or digital recording that is made in violation of subsection A of this section without the consent or knowledge of the person depicted. C. For the purposes of this section, a person's privacy is invaded if both of the following apply: 1. The person has a reasonable expectation that the person will not be photographed, videotaped, filmed, digitally recorded or otherwise viewed or recorded. 2. The person is photographed, videotaped, filmed, digitally recorded or otherwise viewed, with or without a device, either: (a) While the person is in a state of undress or partial dress. (b) While the person is engaged in sexual intercourse or sexual contact. (c) While the person is urinating or defecating. (d) In a manner that directly or indirectly captures or allows the viewing of the person's genitalia, buttock or female breast, whether clothed or unclothed, that is not otherwise visible to the public. D.
Official text (excerpt) · last checked 2026-08-04 · Read the full text in our law library · Verify at azleg.gov
Cited in 15 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- State v. Blazak (Arizona Supreme Court 1977, 114 Ariz. 199)“…timony and not to the admissibility of the evidence. A.R.S. § 13-1424 permits a peace officer to apply to a m…”
- State v. Grijalva (Arizona Supreme Court 1975, 111 Ariz. 476)“…fense sought to suppress certain evidence taken pursuant to ARS § 13-1424, including photographs of the defendant…”
- Long v. Garrett (Court of Appeals of Arizona 1974, 22 Ariz. App. 397)“…tioner's special action challenges the constitutionality of A.R.S. § 13-1424, both on its face and as construed and…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Arizona Audio Recording Laws: Complete Guide to Consent Rules, Arizona Security Camera Laws: Rules for Homes and Businesses, Arizona Video Recording Laws: Rules for Cameras and Filming
Arizona Revised Statutes, Title 15 (Education), Chapter 9 (SCHOOL DISTRICT BUDGETING AND FINANCIAL ASSISTANCE), Article 8 (Student Accountability Information System)
§ 15-1046Student data privacy; definitionsIn forcecited in 2 of our articles
A. An operator may not knowingly do any of the following: 1. Engage in targeted advertising on the operator's site, service or application or on any other site, service or application if the targeting of the advertising is based on any information, including covered information and persistent unique identifiers, that the operator has acquired because of the use of that operator's site, service or application for school purposes. 2. Use information, including persistent unique identifiers, created or gathered by the operator's site, service or application to amass a profile about a student except in furtherance of school purposes. This paragraph does not apply to the collection and retention of account information that remains under the control of the student, the student's parent or guardian or the public school. 3. Sell or rent a student's information, including covered information.
Official text (excerpt) · last checked 2026-08-04 · Read the full text in our law library · Verify at azleg.gov
Arizona Revised Statutes, Title 13 (Criminal Code), Chapter 23 (ORGANIZED CRIME, FRAUD AND TERRORISM)
§ 13-2316Computer tampering; venue; forfeiture; classificationIn force
A. A person who acts without authority or who exceeds authorization of use commits computer tampering by: 1. Accessing, altering, damaging or destroying any computer, computer system or network, or any part of a computer, computer system or network, with the intent to devise or execute any scheme or artifice to defraud or deceive, or to control property or services by means of false or fraudulent pretenses, representations or promises. 2. Knowingly altering, damaging, deleting or destroying computer programs or data. 3. Knowingly introducing a computer contaminant into any computer, computer system or network. 4. Recklessly disrupting or causing the disruption of computer, computer system or network services or denying or causing the denial of computer or network services to any authorized user of a computer, computer system or network. 5. Recklessly using a computer, computer system or network to engage in a scheme or course of conduct that is directed at another person and that seriously alarms, torments, threatens or terrorizes the person. For the purposes of this paragraph, the conduct must both: (a) Cause a reasonable person to suffer substantial emotional distress.
Official text (excerpt) · last checked 2026-08-04 · Read the full text in our law library · Verify at azleg.gov
Cited in 10 court opinions in our collectionLatest citing opinion in our collection: 2024
Opinions citing this section in our collection:
- State v. Young (Court of Appeals of Arizona 2010, 223 Ariz. 447)“…y a jury on one count of computer tampering, a violation of A.R.S. § 13-2316(A)(7) and a class six undesignated felo…”
- Johnson v. State (Court of Appeals of Arizona 1990, 166 Ariz. 567)“…t issued in aid of an investigation of computer fraud under A.R.S. section 13-2316. The subsequent petition for forfeiture…”
- State v. Gillies (Arizona Supreme Court 1983, 135 Ariz. 500)“…nviction for computer fraud in the first degree pursuant to A.R.S. § 13-2316(A). 2 The court denied app…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Arizona Revised Statutes, Title 20 (Insurance), Chapter 11 (INSURANCE INFORMATION AND PRIVACY PROTECTION), Article 1 (General Provisions)
§ 20-2104Notice of insurance information practicesIn force
A. An insurance institution or insurance producer shall provide a notice of information practices to applicants and policyholders in connection with insurance transactions as prescribed in this section. B. The insurance institution or insurance producer shall provide the notice at the following times: 1. In the case of an application for insurance, not later than when the insurance institution or insurance producer either: (a) Delivers the insurance policy or certificate, if personal information is collected only from the applicant or from public records. (b) First collects personal information from a source other than the applicant or public records. 2. In the case of a policy renewal, at least annually during the continuation of the relationship with the policyholder, except that an insurance institution or insurance producer is not required to provide the notice described in subsection C of this section annually if the insurance institution or insurance producer meets both of the following requirements: (a) Provides personal information in accordance with section 20-2113.
Official text (excerpt) · last checked 2026-08-04 · Read the full text in our law library · Verify at azleg.gov
United States Code Title 15
§ 45Unfair methods of competition unlawful; prevention by CommissionIn forcecited in 14 of our articles
Unfair methods of competition in or affecting commerce, and unfair or deceptive acts or practices in or affecting commerce, are hereby declared unlawful. The Commission is hereby empowered and directed to prevent persons, partnerships, or corporations, except banks, savings and loan institutions described in section 57a(f)(3) of this title, Federal credit unions described in section 57a(f)(4) of this title, common carriers subject to the Acts to regulate commerce, air carriers and foreign air carriers subject to part A of subtitle VII of title 49, and persons, partnerships, or corporations insofar as they are subject to the Packers and Stockyards Act, 1921, as amended [7 U.S.C. 181 et seq.], except as provided in section 406(b) of said Act [7 U.S.C. 227(b) ], from using unfair methods of competition in or affecting commerce and unfair or deceptive acts or practices in or affecting commerce.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 3,207 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):United States v. Philadelphia National Bank (1963) applied the bank exclusion in 15 U.S.C. 45(a)(6) when construing Clayton Act section 7, and Copperweld Corp. v. Independence Tube Corp. (1984) noted that a corporation and its wholly owned subsidiaries remain subject to section 5 of the FTC Act.
Opinions citing this section in our collection:
- Morales v. Trans World Airlines, Inc. (Supreme Court of the United States 1992, 504 U.S. 374)“…etition in commerce.” 38 Stat. 719 , codified as amended, 15 U. S. C. § 45 (a)(1). That type of prohibition is ent…”
- Copperweld Corp. v. Independence Tube Corp. (Supreme Court of the United States 1984, 467 U.S. 752)“…d § 5 of the Federal Trade Commission Act, 38 Stat. 719 , 15 U. S. C. §45 . That these statutes are adequate to c…”
- Bowen v. Massachusetts (Supreme Court of the United States 1988, 487 U.S. 879)“…n required to exhaust before coming into court. See 15 U. S. C. §45 (c) (1940 ed.); 29 U. S. C. § 160 (f)…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: FTC Fines Travel App Hopper $35 Million Over Hidden "Junk Fees", FTC Finalizes Order Against Illuminate Over Student Data Breach (2026), How the FTC's Nationwide Noncompete Ban Was Struck Down, and What It Means for At-Will Workers
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- A.R.S. § 18-552: Notification of Security System Breaches(azleg.gov).gov
- A.R.S. § 18-551: Definitions(azleg.gov).gov
- Data Privacy and Data Breach Reporting(azag.gov).gov
- Arizona Data-Breach Notification Law FAQ(azag.gov).gov
- HB 2146: Data Security Breach Notification Amendments (2022)(azleg.gov).gov
- HB 2069: Genetic Information Privacy Act (2021)(azleg.gov).gov
- A.R.S. § 44-1522: Consumer Fraud Act(azleg.gov).gov
- A.R.S. § 15-1046: Student Data Privacy(azleg.gov).gov
- A.R.S. § 20-2104: Insurance Information Practices(azleg.gov).gov
- Data Breach Notification Form(azag.gov).gov
- A.R.S. § 13-2316: Computer Tampering (Arizona Computer Crimes Act)(azleg.gov).gov
- A.R.S. § 13-1424: Voyeurism(azleg.gov).gov
- Attorney General Mayes Sues Temu for Stealing Arizonans Data (December 2025)(azag.gov).gov
- AG Brnovich: $85 Million Settlement with Google (2022)(azag.gov).gov
- AG Mayes Sues Trump Administration Over Medicaid Health Data Transfer (2025)(azag.gov).gov
- TAKE IT DOWN Act (Pub. L. 119-12) -- FTC Legal Library(ftc.gov).gov
- FTC Begins Enforcing the TAKE IT DOWN Act (May 2026)(ftc.gov).gov
- TAKE IT DOWN Act: Congressional Research Service Summary(congress.gov).gov
- HB 2154 (Laws 2018, Ch. 177): 45-Day Breach Notification Deadline and Expanded Personal Information Definition(azleg.gov)
- A.R.S. § 44-8004: Genetic Information Privacy Act Enforcement and Penalties(azleg.gov)
- $391.5 Million Multistate Google Location-Tracking Settlement (November 14, 2022)(ncdoj.gov)