EnglishEspañol
Arkansas flag

Arkansas

Arkansas Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 5 primary sources cited on this page. How we verify our legal content

Arkansas Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly does an Arkansas business have to report a data breach?

Arkansas does not set a specific number of days. The law requires notification in the most expedient time and manner possible and without unreasonable delay (Ark. Code Ann. 4-110-105). The timeline allows for time to investigate the breach scope and restore system integrity.

Does Arkansas require notification to the Attorney General?

Yes, when a breach affects more than 1,000 Arkansas residents. The notification must go to the AG at the same time individual notices are sent, or within 45 days of determining a reasonable likelihood of harm, whichever comes first.

Is notification required if the breached data was encrypted?

No. Arkansas provides an encryption safe harbor. If the personal information was encrypted or redacted at the time of the breach, notification is not required, provided the encryption key was not also compromised.

Can individuals sue a business for a data breach under Arkansas law?

The Personal Information Protection Act does not create an explicit private right of action. Individuals cannot sue directly under this statute. However, affected persons may pursue claims under other legal theories such as negligence if they can demonstrate actual harm.

What qualifies as personal information under Arkansas breach notification law?

Personal information includes a person's name combined with their Social Security number, driver's license number, financial account data with access codes, medical information, or biometric data (added by Act 1030 of 2019).

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the statutory definition of medical information to match Ark. Code Ann. 4-110-103(5), clarified that the computerized-data limit applies to the breach notification duty rather than to all of the Personal Information Protection Act, and fixed the multi-state comparison to show Tennessee's 45-day disclosure deadline.

Removed a fabricated criminal Class A misdemeanor penalty and an unrelated insurance-industry penalty tier that PIPA does not impose, corrected the statutory definition of personal information (removed invented health-insurance-identifier and online-credential categories), fixed a mischaracterized AG press-release quote about Change Healthcare, corrected an inaccurate claim that Missouri does not require Attorney General notification, and replaced six generic statute citation links with pinpoint links to the actual code sections.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Ark. Code Ann. 4-110-101 et seq. (Personal Information Protection Act)(law.justia.com)
  2. Act 1030 of 2019 (HB1943) - PI Definition Expansion(arkleg.state.ar.us).gov
  3. Arkansas AG - Data Breach Reporting(arkansasag.gov).gov
  4. AG Investigation of Change Healthcare Cyberattack(arkansasag.gov).gov
  5. AG Settlement with Marriott International for Data Breach(arkansasag.gov).gov
  6. HB1943 Bill Information - Arkansas Legislature(arkleg.state.ar.us).gov
  7. Act 1526 of 2005 (SB1167) - Arkansas Personal Information Protection Act as enacted(arkleg.state.ar.us)
  8. Tennessee Public Chapter 91 (2017), amending Tenn. Code Ann. 47-18-2107 (45-day breach disclosure deadline)(publications.tnsosfiles.com)
  9. Mississippi HB 277 (2021) as enrolled, amending Miss. Code Ann. 75-24-29 (breach disclosure without unreasonable delay)(billstatus.ls.state.ms.us)
Share: