EnglishEspañol
Arizona flag

Arizona

Arizona Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 11 primary sources cited on this page. How we verify our legal content

Arizona Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How long does a business have to notify Arizona residents of a data breach?

Arizona law requires notification within 45 days after the business determines that a security system breach has occurred. This 45-day deadline was established by a 2018 amendment to A.R.S. § 18-552, which also expanded the protected categories to include biometric data; the 2022 amendments later added the Department of Homeland Security notification requirement. Law enforcement may request a delay if notification would interfere with a criminal investigation, but the 45-day clock restarts once law enforcement clears the notification.

Does Arizona allow individuals to sue companies for failing to report a data breach?

No. Arizona does not provide a private right of action for breach notification violations. Only the Arizona Attorney General may enforce the law. Consumers who believe a company failed to provide required notification can file a complaint with the AG's office at (602) 542-5025 or through the AG's Consumer Protection Division. The AG can pursue civil penalties of up to $500,000 per breach plus restitution.

What triggers the requirement to notify the Arizona Attorney General about a breach?

The AG notification requirement activates when a breach affects more than 1,000 Arizona residents. At the same threshold, the business must also notify the Director of the Arizona Department of Homeland Security and the three largest nationwide consumer reporting agencies. Both the AG and DHS notifications are treated as confidential under Arizona law.

Is a business required to notify anyone if the breached data was encrypted?

No. Arizona's breach notification law only applies to unencrypted and unredacted computerized personal information. If the compromised data was properly encrypted at the time of the breach, the notification requirements do not apply. Similarly, if sensitive numbers like Social Security numbers were redacted to show only the last four digits, notification is not triggered.

Does Arizona's breach notification law cover biometric data?

Yes. The 2018 amendments to A.R.S. § 18-551 added unique biometric data to the list of protected data elements, but only biometric data generated from a measurement or analysis of human body characteristics to authenticate an individual when the individual accesses an online account. If a breach exposes an individual's name along with biometric data of that kind, the 45-day notification requirement applies.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the breach-notification requirements against the current text of A.R.S. 18-551 and 18-552: the Gramm-Leach-Bliley and HIPAA exemptions apply outright rather than on condition of federal compliance, the biometric data element is limited to authenticating access to an online account, the required consumer notice does not include an FTC identity-theft-information statement, and the breach definition requires a database covering multiple individuals.

Corrected the article's legislative history: Arizona's 45-day breach notification deadline dates to a 2018 amendment, not the 2022 HB 2146 amendment (which added biometric data and Department of Homeland Security notification); clarified that the Department of Public Safety, county sheriff's departments, municipal police departments, prosecution agencies, and courts are excluded from the 45-day deadline and instead must maintain their own security and notification policy with no set deadline; corrected the Blackbaud settlement press release date to 2023; and replaced two dead Arizona Attorney General press-release links (Equifax and Uber settlements) with archived copies of the same official releases.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. A.R.S. § 18-551 (Definitions)(azleg.gov).gov
  2. A.R.S. § 18-552 (Notification requirements)(azleg.gov).gov
  3. HB 2146 - Chapter 81, Laws 2022(azleg.gov).gov
  4. Arizona AG Data Breach FAQ(azag.gov).gov
  5. Arizona AG Data Breach Notification Form(azag.gov).gov
  6. Arizona AG Data Breach Submission Form (PDF)(azag.gov).gov
  7. Equifax $600M Settlement Press Release (archived)(web.archive.org).gov
  8. Uber $148M Settlement Press Release (archived)(web.archive.org).gov
  9. Blackbaud $49.5M Settlement Press Release(azag.gov).gov
  10. FTC Gramm-Leach-Bliley Act(ftc.gov).gov
  11. Arizona Consumer Fraud Act (Title 44)(azleg.gov).gov
Share: