EnglishEspañol
Arizona flag

Arizona

Arizona Data Privacy Laws: Breach Rules & Consumer Rights (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 18 primary sources cited on this page. How we verify our legal content

Arizona Data Privacy Laws: Breach Rules & Consumer Rights (2026)

Frequently Asked Questions

Does Arizona have a comprehensive data privacy law like California or Virginia?

No. As of May 2026, Arizona does not have a comprehensive consumer data privacy law. The state relies on its data breach notification statute (A.R.S. § 18-552), the Consumer Fraud Act, sector-specific laws like the Genetic Information Privacy Act, and applicable federal laws including HIPAA and GLBA. SB 1815, introduced in the 57th Legislature's second regular session in February 2026, has not passed. Multiple earlier attempts, including HB 2790 in 2022, also failed to advance.

How quickly must a business notify me of a data breach in Arizona?

Under A.R.S. § 18-552, businesses must notify affected individuals within 45 days after determining that a security system breach has occurred. Notification must be provided in writing, by telephone, or by email. If the breach affects more than 1,000 Arizona residents, the business must also notify the Arizona Attorney General, the Department of Homeland Security, and the three major credit reporting agencies within the same 45-day window.

Can I sue a company for a data breach in Arizona?

Arizona's breach notification statute does not provide a private right of action. Only the Attorney General can bring enforcement actions under A.R.S. § 18-552, seeking civil penalties up to $500,000 plus restitution. However, consumers may have claims under the Arizona Consumer Fraud Act (A.R.S. § 44-1522) if a business made deceptive claims about its data security practices, or through common law negligence and breach of contract theories.

Are healthcare providers and banks exempt from Arizona's data breach notification law?

Yes. Entities subject to HIPAA (healthcare providers, health plans, healthcare clearinghouses) and entities regulated under Title V of the Gramm-Leach-Bliley Act (financial institutions) are exempt from Arizona's state breach notification requirements. These entities must still comply with their respective federal breach notification and data security obligations, which generally meet or exceed the state standard.

What are my rights regarding genetic testing data in Arizona?

Under Arizona's Genetic Information Privacy Act (HB 2069, effective September 2021), consumers who use direct-to-consumer genetic testing services have the right to access their genetic data, delete their account and genetic data, and request destruction of biological samples. Testing companies cannot share genetic data with health insurers, life insurers, long-term care insurers, or employers. Companies must obtain express consent before collecting or using genetic data and cannot disclose it to law enforcement without a valid legal process.

What is the TAKE IT DOWN Act and does it protect Arizona residents?

The TAKE IT DOWN Act (Pub. L. 119-12, signed May 19, 2025) is a federal law that criminalizes the publication of nonconsensual intimate images, including AI-generated deepfakes. The criminal prohibition took effect immediately on signing. Platform removal obligations under Section 3 of the Act, which require covered platforms to remove flagged content within 48 hours of a valid request, became enforceable on May 19, 2026. The FTC enforces platform compliance. Arizona residents can submit removal requests to covered platforms under the federal framework, in addition to pursuing state remedies under A.R.S. § 13-1424 (voyeurism).

How has the Arizona AG enforced data privacy rules?

Arizona AG Mark Brnovich secured an $85 million settlement with Google in October 2022 over deceptive location tracking practices under the Consumer Fraud Act. AG Kris Mayes filed suit against Temu in December 2025 for alleged unauthorized data harvesting and deceptive trade practices. Mayes also joined a 19-state coalition in June 2025 suing the Trump administration over the mass transfer of Medicaid health records to DHS, alleging HIPAA violations. The AG's office actively accepts consumer data breach complaints and breach notifications from businesses.

Does Arizona have a law against computer hacking?

Yes. A.R.S. § 13-2316 (Arizona Computer Crimes Act) prohibits unauthorized access to computer systems with intent to disrupt, alter, damage, delete, or destroy data or programs. Depending on the specific conduct, violations range from a class 6 felony, the tier covering unauthorized access to confidential records and databases, up to a class 2 felony for tampering with critical infrastructure. The statute applies to unauthorized access to databases containing personal information and complements the civil enforcement framework under the breach notification and consumer fraud statutes.

Updates

Corrected the breach-law history to credit the 2018 amendment (HB 2154) with the 45-day notification deadline and the expanded personal-information definition, restated the law enforcement delay and the no-substantial-economic-loss exception to match A.R.S. 18-552, dated the $391.5 million multistate Google settlement to November 2022, and corrected who recovers damages under the Genetic Information Privacy Act.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Corrected the A.R.S. 13-2316 and 13-1424 felony-classification descriptions to match the statutes' actual tiered penalties, and rewrote the 'Reasonable Security Requirements' section, which had misattributed a student-data-operator security duty (A.R.S. 15-1046) to the breach notification statute (A.R.S. 18-552).

Governing law re-checked for recent changes

May 2026 refresh: Added AG Mayes Temu lawsuit (December 2025), Google $85 million settlement specifics (October 2022), TAKE IT DOWN Act federal coverage (signed May 2025, platform obligations effective May 2026), Arizona Computer Crimes Act (A.R.S. § 13-2316), voyeurism statute (A.R.S. § 13-1424), pending SB 1815 (introduced February 2026), Medicaid data transfer lawsuit (June 2025), compliance steps for businesses section, expanded FAQ to 8 items, converted sources to SourcesList component. Word count increased from 2,847 to approximately 4,600.

Reviewed and approved by an editor

Sources and References

  1. A.R.S. § 18-552: Notification of Security System Breaches(azleg.gov).gov
  2. A.R.S. § 18-551: Definitions(azleg.gov).gov
  3. Data Privacy and Data Breach Reporting(azag.gov).gov
  4. Arizona Data-Breach Notification Law FAQ(azag.gov).gov
  5. HB 2146: Data Security Breach Notification Amendments (2022)(azleg.gov).gov
  6. HB 2069: Genetic Information Privacy Act (2021)(azleg.gov).gov
  7. A.R.S. § 44-1522: Consumer Fraud Act(azleg.gov).gov
  8. A.R.S. § 15-1046: Student Data Privacy(azleg.gov).gov
  9. A.R.S. § 20-2104: Insurance Information Practices(azleg.gov).gov
  10. Data Breach Notification Form(azag.gov).gov
  11. A.R.S. § 13-2316: Computer Tampering (Arizona Computer Crimes Act)(azleg.gov).gov
  12. A.R.S. § 13-1424: Voyeurism(azleg.gov).gov
  13. Attorney General Mayes Sues Temu for Stealing Arizonans Data (December 2025)(azag.gov).gov
  14. AG Brnovich: $85 Million Settlement with Google (2022)(azag.gov).gov
  15. AG Mayes Sues Trump Administration Over Medicaid Health Data Transfer (2025)(azag.gov).gov
  16. TAKE IT DOWN Act (Pub. L. 119-12) -- FTC Legal Library(ftc.gov).gov
  17. FTC Begins Enforcing the TAKE IT DOWN Act (May 2026)(ftc.gov).gov
  18. TAKE IT DOWN Act: Congressional Research Service Summary(congress.gov).gov
  19. HB 2154 (Laws 2018, Ch. 177): 45-Day Breach Notification Deadline and Expanded Personal Information Definition(azleg.gov)
  20. A.R.S. § 44-8004: Genetic Information Privacy Act Enforcement and Penalties(azleg.gov)
  21. $391.5 Million Multistate Google Location-Tracking Settlement (November 14, 2022)(ncdoj.gov)
Share: