EnglishEspañol
Arkansas flag

Arkansas

Arkansas Data Privacy Laws: Breach Notification & Consumer Rights (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 9, 2026. · 12 primary sources cited on this page. How we verify our legal content

Arkansas Data Privacy Laws: Breach Notification & Consumer Rights (2026)

Frequently Asked Questions

Does Arkansas have a comprehensive consumer data privacy law?

No. Arkansas has not enacted a comprehensive consumer data privacy law. A 2025 attempt, the Arkansas Digital Responsibility, Safety, and Trust Act (SB258), died at sine die adjournment on May 5, 2025, and never took effect. Arkansas residents' privacy protections instead come from the Personal Information Protection Act (breach notification and data security), the Student Online Personal Information Protection Act, the Children and Teens' Online Privacy Protection Act, and federal sector laws like HIPAA and COPPA.

What must a business do if it suffers a data breach affecting Arkansas residents?

A business must notify affected Arkansas residents in the most expedient time possible and without unreasonable delay. If the breach affects more than 1,000 individuals, the business must also notify the Arkansas Attorney General within 45 days of determining there is a reasonable likelihood of harm, or at the same time it notifies affected individuals, whichever comes first. The Attorney General notification must be submitted through the official Data Breach Reporting Form on the AG website.

What types of personal information are protected under Arkansas law?

The Personal Information Protection Act covers a person's name combined with their Social Security number, driver's license number, financial account numbers with security codes or passwords, medical information, health insurance policy or subscriber identification numbers with unique identifiers, and biometric data. Arkansas does not have a broader comprehensive privacy law that defines additional categories of sensitive personal information.

What penalties can businesses face for violating Arkansas data privacy laws?

Violations of the Personal Information Protection Act are enforced through the Arkansas Deceptive Trade Practices Act, with civil penalties of up to $10,000 per violation, injunctive relief, and restitution. Willful violations are a Class A misdemeanor. Arkansas has no comprehensive privacy statute, so there is no separate APDPA penalty scheme. The Children and Teens' Online Privacy Protection Act, in force since July 1, 2026, is enforced exclusively by the Attorney General with no private right of action.

How does the new Arkansas Children and Teens' Online Privacy Protection Act affect my teenager?

Since July 1, 2026, the Arkansas Children and Teens' Online Privacy Protection Act (Act 952 of 2025) has required commercial websites and apps directed at teens aged 13 through 16 to obtain consent from either the teen or their parent before collecting personal information. Operators must provide clear notice of their data practices, honor deletion requests, and implement reasonable security measures. The law is enforced exclusively by the Arkansas Attorney General.

Can I sue a company directly for violating my Arkansas data privacy rights?

No. Arkansas has no comprehensive privacy statute, and the Personal Information Protection Act does not create a private right of action either. Only the Arkansas Attorney General can bring enforcement actions under Arkansas's data privacy and consumer protection statutes. If you believe your rights have been violated, file a complaint with the Consumer Protection Division of the Arkansas AG's office at arkansasag.gov.

What is the TAKE IT DOWN Act and how does it protect Arkansas residents?

The TAKE IT DOWN Act, signed into federal law on May 19, 2025, requires covered online platforms to remove nonconsensual intimate images, including AI-generated deepfakes, within 48 hours of a valid request. The platform takedown obligations took effect May 19, 2026, and the FTC enforces compliance. The law applies nationwide, including for Arkansas residents.

Updates

Corrected the Personal Information Protection Act summary so it no longer suggests breach notice to affected Arkansas residents waits for 1,000 victims or carries a 45-day clock (those limits apply only to Attorney General notice), fixed the Student Online Personal Information Protection Act's codification to Ark. Code 6-18-109 and narrowed its scope to Arkansas public school students, and updated the Children and Teens' Online Privacy Protection Act to reflect that it has been in force since July 1, 2026.

This page previously described a comprehensive Arkansas consumer privacy law, the 'Arkansas Personal Data Protection Act,' that was never enacted. Arkansas has no comprehensive consumer privacy statute; the 2025 bill that would have created one (SB258) died in the Senate at sine die adjournment. The page now describes that failed attempt accurately and focuses on Arkansas's real privacy protections: the Personal Information Protection Act (breach notification), student and teen data laws, and Attorney General enforcement.

Independently fact-checked against the cited primary sources

Governing law re-checked for recent changes

Governing law re-checked for recent changes

Major refresh: Reviewed Arkansas's privacy law landscape and confirmed the state has not enacted a comprehensive consumer privacy law. The 2025 attempt, the Arkansas Digital Responsibility, Safety, and Trust Act (SB258), died in the Senate at sine die adjournment on May 5, 2025 and did not become law. Updated opening summary, KeyTakeaways, and FAQ to reflect that Arkansas remains without a comprehensive privacy statute. Added Attorney General enforcement actions section covering Temu (June 2024) and TikTok (March 2023) lawsuits. Added TAKE IT DOWN Act (Pub. L. 119-12) federal overlay with updated enforcement status (FTC enforcement began May 2026). Preserved PIPA, breach notification, SOPIPA, and ACTOPPA sections verbatim. Title unchanged. Previous review: March 2026.

Reviewed and approved by an editor

Sources and References

  1. Arkansas Personal Information Protection Act (Ark. Code 4-110-101 et seq.)(law.justia.com)
  2. Arkansas Attorney General - Data Breach Reporting(arkansasag.gov).gov
  3. Ark. Code 4-110-103 - Definitions(law.justia.com)
  4. Ark. Code 4-110-104 - Protection of Personal Information(law.justia.com)
  5. Ark. Code 4-110-105 - Disclosure of Security Breaches(law.justia.com)
  6. Act 1030 of 2019 - PIPA Amendments(arkleg.state.ar.us).gov
  7. Act 1526 of 2005 - Original PIPA(arkleg.state.ar.us).gov
  8. Student Online Personal Information Protection Act (Ark. Code 6-18-109)(law.justia.com)
  9. HB 1717 - Children and Teens Online Privacy Protection Act(arkleg.state.ar.us).gov
  10. Act 952 of 2025 - Full Text(arkleg.state.ar.us).gov
  11. Arkansas AG - Consumer Protection Division(arkansasag.gov).gov
  12. NCSL - Security Breach Notification Laws(ncsl.org)
  13. HHS - HIPAA Privacy Rule Summary(hhs.gov).gov
  14. HHS - MedEvolve HIPAA Settlement (Arkansas)(hhs.gov).gov
  15. NCSL - Consumer Privacy 2025 Legislation(ncsl.org)
  16. Arkansas DESE - Data Privacy Resources(dese.ade.arkansas.gov).gov
  17. AG Griffin Sues Temu for Data Practices (June 2024)(arkansasag.gov).gov
  18. AG Griffin - TikTok Lawsuit Ruling (2024)(arkansasag.gov).gov
  19. FTC - TAKE IT DOWN Act Enforcement Begins (May 2026)(ftc.gov).gov
  20. Act 1196 of 2015 - Student Online Personal Information Protection Act (adds Ark. Code 6-18-109)(arkleg.state.ar.us)
Share: