Arizona
Arizona Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 11 primary sources cited on this page. How we verify our legal content

Arizona requires businesses to notify affected individuals within 45 days of determining a breach occurred under A.R.S. 18-552. When more than 1,000 residents are affected, the law also requires notice to the Arizona Attorney General, the Director of the Arizona Department of Homeland Security, and the three largest nationwide consumer reporting agencies.
If your business handles personal data belonging to Arizona residents, state law requires you to act quickly when a breach occurs. Arizona's data breach notification statute sets a firm 45-day notification deadline and imposes civil penalties for noncompliance.
The law was originally enacted in 2006 with a general "most expedient manner possible" notification standard. A 2018 amendment (signed April 11, 2018) replaced that standard with the current 45-day deadline and expanded the definition of personal information to cover categories such as biometric data. HB 2146 in 2022 further updated the law by adding a requirement to notify the Arizona Department of Homeland Security director for breaches affecting more than 1,000 residents.
For an overview of Arizona's broader privacy framework, see the parent guide to Arizona Data Privacy Laws.
What Counts as a Security System Breach
Under A.R.S. § 18-551, a security system breach means the unauthorized acquisition of and unauthorized access that materially compromises the security or confidentiality of unencrypted and unredacted computerized personal information maintained as part of a database of personal information regarding multiple individuals.
Several elements must line up for a breach to be reportable. The data must be unencrypted and unredacted, the compromise must be material rather than trivial, and the information must have been maintained as part of a database covering multiple individuals.
The statute includes a good faith exception. If an employee or agent of the business acquires personal information for legitimate business purposes, and the data is not used for an unrelated purpose or subjected to further unauthorized disclosure, that access does not count as a breach.
Protected Personal Information
Arizona defines personal information broadly. The law covers an individual's first name or first initial and last name combined with any of the following data elements:
- Social Security number
- Driver's license number or state identification card number
- Private key that is unique to an individual and used to authenticate or sign an electronic record
- Financial account number or credit/debit card number, in combination with any required security code, access code, or password that would permit access to the account
- Health insurance identification number
- Medical or mental health treatment information
- Passport number
- Taxpayer identification number
- Unique biometric data generated from a measurement or analysis of human body characteristics to authenticate an individual when the individual accesses an online account
The law also covers a standalone category: an individual's username or email address combined with a password or security question and answer that allows access to an online account. This category does not require a name to trigger notification.
Publicly available information lawfully made available from federal, state, or local government records is excluded from the definition.
The 45-Day Notification Timeline
When a business that conducts business in Arizona and owns, maintains, or licenses unencrypted computerized personal information becomes aware of a security incident, the business must conduct a reasonable investigation to determine whether a breach has occurred.
Once the investigation confirms a breach, the clock starts. Under A.R.S. § 18-552, the business must notify affected individuals within 45 days after the determination that a breach occurred.

Law enforcement can request a delay if notification would impede a criminal investigation. Once law enforcement clears the notification, the 45-day window applies from the date of that clearance.
Who Must Be Notified
Arizona's notification requirements extend to multiple parties depending on the size of the breach.
Affected Individuals
Every person whose unencrypted personal information was compromised must receive direct notice. The notice must include:
- The approximate date of the breach
- A description of the personal information that was involved
- Contact information for the three largest nationwide consumer reporting agencies
- The toll-free number, address, and website address for the Federal Trade Commission or any federal agency that assists consumers with identity theft matters
Attorney General and Department of Homeland Security
If a breach affects more than 1,000 Arizona residents, the business must also notify the Arizona Attorney General and the Director of the Arizona Department of Homeland Security. These notifications are confidential and exempt from public records disclosure.
The AG's office provides a data breach notification form that businesses must complete when reporting a breach.

Consumer Reporting Agencies
When more than 1,000 individuals must be notified, the business must also notify the three largest nationwide consumer reporting agencies about the timing, distribution, and content of the individual notices.
How Notification Must Be Delivered
Arizona allows several notification methods under A.R.S. § 18-552:
- Written notice sent to the individual's mailing address
- Email notice if the business has email addresses on file
- Telephone notice through direct conversation (not prerecorded messages)
Substitute Notice
A business may use substitute notice if it demonstrates that direct notification would cost more than $50,000, that more than 100,000 individuals need to be notified, or that the business does not have sufficient contact information.
Substitute notice requires two steps:
- A written letter to the Attorney General explaining the facts that justify using substitute notice
- Conspicuous posting of the notice on the business's website for at least 45 days
Encryption Safe Harbor
Arizona's breach notification law only applies to unencrypted and unredacted personal information. If the compromised data was properly encrypted or if data elements like Social Security numbers were redacted (truncated to show only the last four digits), notification is not required.

This safe harbor gives businesses a strong incentive to encrypt personal information at rest and in transit.
Exemptions
A.R.S. § 18-552(N) places two categories of entities outside the article entirely, with no condition attached:
- Persons subject to Title V of the Gramm-Leach-Bliley Act (15 U.S.C. sections 6801 through 6809)
- HIPAA covered entities and business associates as defined under regulations implementing HIPAA, 45 C.F.R. § 160.103 (2013). The same paragraph also reaches a charitable fundraising foundation or nonprofit corporation whose primary purpose is to support a covered entity, but only if that foundation or nonprofit complies with any applicable provision of HIPAA and its implementing regulations
A separate route is deemed compliance rather than exemption. Under subsection H, a business that maintains its own notification procedures as part of an information security policy is deemed to satisfy the individual-notice requirement if those procedures are otherwise consistent with the article, including the 45-day deadline. Under subsection I, a business that follows the breach notification rules or procedures of its primary or functional federal regulator is likewise deemed to be in compliance.
Penalties and Enforcement
Only the Arizona Attorney General may enforce violations of the data breach notification law. A knowing and willful violation is treated as an unlawful practice under the Arizona Consumer Fraud Act (Title 44, Chapter 10, Article 7).
The penalty structure works as follows:
- Per-individual penalty: Up to $10,000 per affected individual, or the total amount of economic loss sustained by affected individuals, whichever is less
- Maximum cap: $500,000 per breach or series of related breaches
- Restitution: The AG may also seek restitution for affected individuals
There is no private right of action. Individual consumers cannot sue businesses directly for failing to provide timely breach notification. Enforcement is exclusively through the AG's office.
Arizona AG Enforcement Track Record
The Arizona Attorney General has actively participated in major multistate data breach settlements. Notable cases include:
- Equifax (2019): Arizona joined 49 other states in securing a $600 million settlement following the 2017 breach that exposed personal data of approximately 147 million Americans
- Uber (2018): The AG secured $148 million in a nationwide settlement after Uber concealed a 2016 data breach affecting 57 million users, with Arizona receiving approximately $2.7 million
- Blackbaud (2023): Attorney General Kris Mayes joined a $49.5 million multistate settlement with the software company over a 2020 ransomware attack
These cases demonstrate that while individual state penalties are capped at $500,000, participation in multistate actions can result in significantly larger outcomes.
Substantial Economic Loss Exception
Arizona includes a notable exception to notification requirements. If the person who experienced the breach, a law enforcement agency, or an independent forensic auditor determines that the breach has not resulted in and is not reasonably likely to result in substantial economic loss to the affected individuals, notification is not required.
This determination must be documented and defensible. The Arizona AG FAQ makes clear that this exception does not eliminate the obligation to investigate every security incident.
Government Entity Requirements
The 2022 amendments require specific government entities, the Department of Public Safety, county sheriff's departments, municipal police departments, prosecution agencies, and courts, to create and maintain an information security policy with breach notification procedures under A.R.S. § 18-552(O).
These entities are expressly excluded from the statute's definition of "person" under A.R.S. § 18-551(6)(b), so they are not bound by the standard 45-day notification deadline that applies to businesses and other government agencies. The statute does not specify a deadline for their own internal notification procedures.
How Arizona Compares to Other States
Arizona's 45-day notification deadline places it among the states with specific statutory timelines, alongside states like Florida (30 days) and Colorado (30 days). Many states still use a less specific "most expedient time possible" standard.
The dual government notification requirement to both the AG and the Department of Homeland Security is relatively unusual among state breach notification laws. Most states that require government notification only mandate AG notification.
Arizona's inclusion of online-account authentication biometrics, passport numbers, and taxpayer identification numbers in its definition of personal information reflects the 2018 modernization of the statute. These categories are not universally covered across all state breach notification laws.
Steps to Take After a Breach in Arizona
If your organization discovers a potential breach involving Arizona residents, follow this sequence:
- Investigate immediately. Determine whether the incident constitutes a security system breach under A.R.S. § 18-551.
- Document the scope. Identify which data elements were compromised and how many Arizona residents were affected.
- Check encryption status. If all compromised data was encrypted or redacted, the safe harbor may apply.
- Assess economic impact. If the breach is not reasonably likely to cause substantial economic loss, document that determination thoroughly.
- Notify within 45 days. If notification is required, provide notice to affected individuals using an approved method.
- Report to the AG and DHS. If more than 1,000 individuals are affected, submit the AG notification form and notify the Director of the Arizona Department of Homeland Security.
- Notify consumer reporting agencies. If more than 1,000 individuals are notified, inform the three largest nationwide consumer reporting agencies.
Sources and References
This article references Arizona statutes and official state government publications. For the full text of the breach notification law, visit the Arizona Legislature website. For guidance on reporting a breach or filing a complaint, visit the Arizona Attorney General's Data Breach page.
This article provides general legal information about Arizona data breach notification laws. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official Arizona government sources.
More Arizona Laws
Frequently Asked Questions
How long does a business have to notify Arizona residents of a data breach?
Arizona law requires notification within 45 days after the business determines that a security system breach has occurred. This 45-day deadline was established by a 2018 amendment to A.R.S. § 18-552, which also expanded the protected categories to include biometric data; the 2022 amendments later added the Department of Homeland Security notification requirement. Law enforcement may request a delay if notification would interfere with a criminal investigation, but the 45-day clock restarts once law enforcement clears the notification.
Does Arizona allow individuals to sue companies for failing to report a data breach?
No. Arizona does not provide a private right of action for breach notification violations. Only the Arizona Attorney General may enforce the law. Consumers who believe a company failed to provide required notification can file a complaint with the AG's office at (602) 542-5025 or through the AG's Consumer Protection Division. The AG can pursue civil penalties of up to $500,000 per breach plus restitution.
What triggers the requirement to notify the Arizona Attorney General about a breach?
The AG notification requirement activates when a breach affects more than 1,000 Arizona residents. At the same threshold, the business must also notify the Director of the Arizona Department of Homeland Security and the three largest nationwide consumer reporting agencies. Both the AG and DHS notifications are treated as confidential under Arizona law.
Is a business required to notify anyone if the breached data was encrypted?
No. Arizona's breach notification law only applies to unencrypted and unredacted computerized personal information. If the compromised data was properly encrypted at the time of the breach, the notification requirements do not apply. Similarly, if sensitive numbers like Social Security numbers were redacted to show only the last four digits, notification is not triggered.
Does Arizona's breach notification law cover biometric data?
Yes. The 2018 amendments to A.R.S. § 18-551 added unique biometric data to the list of protected data elements, but only biometric data generated from a measurement or analysis of human body characteristics to authenticate an individual when the individual accesses an online account. If a breach exposes an individual's name along with biometric data of that kind, the 45-day notification requirement applies.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the breach-notification requirements against the current text of A.R.S. 18-551 and 18-552: the Gramm-Leach-Bliley and HIPAA exemptions apply outright rather than on condition of federal compliance, the biometric data element is limited to authenticating access to an online account, the required consumer notice does not include an FTC identity-theft-information statement, and the breach definition requires a database covering multiple individuals.
Corrected the article's legislative history: Arizona's 45-day breach notification deadline dates to a 2018 amendment, not the 2022 HB 2146 amendment (which added biometric data and Department of Homeland Security notification); clarified that the Department of Public Safety, county sheriff's departments, municipal police departments, prosecution agencies, and courts are excluded from the 45-day deadline and instead must maintain their own security and notification policy with no set deadline; corrected the Blackbaud settlement press release date to 2023; and replaced two dead Arizona Attorney General press-release links (Equifax and Uber settlements) with archived copies of the same official releases.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Arizona Revised Statutes, Title 18 (Information Technology), Chapter 5 (NETWORK SECURITY), Article 4 (Data Security Breaches)
§ 18-552Notification of security system breaches; requirements; enforcement; confidentiality; civil penalty; preemption; exceptionsIn forcecited in 3 of our articles
A. If a person that conducts business in this state and that owns, maintains or licenses unencrypted and unredacted computerized personal information becomes aware of a security incident, the person shall conduct an investigation to promptly determine whether there has been a security system breach. B. If the investigation results in a determination that there has been a security system breach, the person that owns or licenses the computerized data, within forty-five days after the determination, shall: 1. Notify the individuals affected pursuant to subsection E of this section and subject to the needs of law enforcement as provided in subsection D of this section. 2. If the breach requires notification of more than one thousand individuals, notify both: (a) The three largest nationwide consumer reporting agencies.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at azleg.gov
Also relied on in: Arizona Data Privacy Laws: Breach Rules & Consumer Rights (2026), Arizona Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 18-551DefinitionsIn forcecited in 3 of our articles
In this article, unless the context otherwise requires: 1. "Breach" or "security system breach": (a) Means an unauthorized acquisition of and unauthorized access that materially compromises the security or confidentiality of unencrypted and unredacted computerized personal information maintained as part of a database of personal information regarding multiple individuals. (b) Does not include a good faith acquisition of personal information by a person's employee or agent for the purposes of the person if the personal information is not used for a purpose unrelated to the person and is not subject to further unauthorized disclosure. 2. "Court" means the supreme court, the court of appeals, the superior court, a court that is inferior to the superior court and a justice court. 3. "Encrypt" means to use a process to transform data into a form that renders the data unreadable or unusable without using a confidential process or key. 4. "Individual" means a resident of this state who has a principal mailing address in this state as reflected in the records of the person conducting business in this state at the time of the breach. 5.
Official text (excerpt) · last checked 2026-08-04 · Read the full text in our law library · Verify at azleg.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- A.R.S. § 18-551 (Definitions)(azleg.gov).gov
- A.R.S. § 18-552 (Notification requirements)(azleg.gov).gov
- HB 2146 - Chapter 81, Laws 2022(azleg.gov).gov
- Arizona AG Data Breach FAQ(azag.gov).gov
- Arizona AG Data Breach Notification Form(azag.gov).gov
- Arizona AG Data Breach Submission Form (PDF)(azag.gov).gov
- Equifax $600M Settlement Press Release (archived)(web.archive.org).gov
- Uber $148M Settlement Press Release (archived)(web.archive.org).gov
- Blackbaud $49.5M Settlement Press Release(azag.gov).gov
- FTC Gramm-Leach-Bliley Act(ftc.gov).gov
- Arizona Consumer Fraud Act (Title 44)(azleg.gov).gov