Arkansas
Arkansas Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 5 primary sources cited on this page. How we verify our legal content

Arkansas requires businesses and government agencies to notify residents when a data breach exposes their personal information. The state's Personal Information Protection Act (Ark. Code Ann. 4-110-101 et seq.) sets the rules for who must report, what triggers a notification, and how quickly affected individuals must be told.
The notification duty applies to any person, business, or state agency that acquires, owns, or licenses computerized data containing personal information about Arkansas residents. If a breach occurs and there is a reasonable likelihood of harm, the clock starts ticking.
What the Arkansas Personal Information Protection Act Covers
Arkansas enacted its data breach notification law in 2005 as part of the Personal Information Protection Act (PIPA). The law has been amended several times since then, most significantly through Act 1030 of 2019, which expanded the definition of personal information to include biometric data and other categories.
PIPA serves two main functions. First, it requires any entity handling the personal information of Arkansas residents to implement reasonable security procedures and practices (Ark. Code Ann. 4-110-104). Second, it mandates notification to affected individuals and, in certain cases, the Attorney General when a breach compromises that data.
The breach notification duty is keyed to computerized data, so an incident involving only paper files does not trigger notice under Ark. Code Ann. 4-110-105. Other parts of PIPA reach further: the destruction duty in Ark. Code Ann. 4-110-104(a) lists shredding alongside erasing, and the definition of medical information in Ark. Code Ann. 4-110-103(5) covers information "in electronic or physical form."
How Arkansas Defines Personal Information
Under Ark. Code Ann. 4-110-103, personal information means an individual's first name (or first initial) and last name combined with one or more of the following data elements, when neither the name nor the data element is encrypted or redacted:
- Social Security number
- Driver's license or Arkansas identification card number
- Financial account number, credit card number, or debit card number in combination with any required security code, access code, or password that would permit access to the account
- Medical information, meaning any individually identifiable information, in electronic or physical form, regarding the individual's medical history or medical treatment or diagnosis by a healthcare professional
- Biometric data, meaning data generated by automatic measurements of biological characteristics such as fingerprints, faceprints, retinal or iris scans, hand geometry, voiceprint analysis, DNA, or any other unique biological characteristic used to authenticate an individual's identity
Act 1030 of 2019 added biometric data to this list.
What Triggers a Breach Notification
A "breach of the security of the system" under Arkansas law means the unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by a person or business (Ark. Code Ann. 4-110-103).
Not every security incident triggers notification. The law includes two key carve-outs:
Good-faith exception. If an employee or agent of the business acquires personal information in good faith for legitimate business purposes, and the data is not further used improperly or subject to additional unauthorized disclosure, no notification is required.
Harm threshold. A business is not required to notify affected individuals if, after a reasonable investigation, it determines there is no reasonable likelihood of harm to consumers. This investigation must be documented, and the entity must retain a written record of its determination for five years.
Notification Timeline and Requirements
When to Notify
Arkansas does not set a specific number of days for notification. Instead, the statute requires disclosure "in the most expedient time and manner possible and without unreasonable delay" (Ark. Code Ann. 4-110-105). The timeline accounts for the time needed to determine the scope of the breach and to restore the reasonable integrity of the data system.
Law enforcement may request a delay in notification if immediate disclosure would impede a criminal investigation. The notification must go out as soon as law enforcement determines that disclosure will no longer compromise the investigation.

How to Notify
The statute permits two primary methods of direct notification:
- Written notice sent to the individual's last known mailing address
- Electronic notice consistent with the requirements of the federal Electronic Signatures in Global and National Commerce Act (E-SIGN Act)
Substitute Notice
When direct notification is not feasible, substitute notice is available if any of the following conditions exist:
- The cost of providing notice would exceed $250,000
- The number of affected individuals exceeds 500,000
- The business does not have sufficient contact information for affected individuals
Substitute notice requires all three of the following steps:
- Email notification to available email addresses
- Conspicuous posting on the business's website
- Notification to statewide media
Attorney General Notification
When a breach affects more than 1,000 Arkansas residents, the business must notify the Arkansas Attorney General. This notification must occur at the same time as individual notifications or within 45 days after the business determines there is a reasonable likelihood of harm to customers, whichever comes first.
The AG may also request a copy of the written determination of the breach and all supporting documentation. If the AG makes this request, the business must provide the materials within 30 days.

Encryption Safe Harbor
Arkansas provides a clear encryption safe harbor. If the personal information involved in the breach was encrypted or redacted at the time of the incident, notification is not required under the statute. This applies regardless of the number of records affected or the type of data involved.
The law does not specify particular encryption standards or algorithms. However, the encryption must render the data unreadable or unusable. If an encryption key is also compromised in the breach, the safe harbor likely does not apply, as the data would no longer be effectively protected.
Reasonable Security Requirements
Beyond breach notification, Ark. Code Ann. 4-110-104 requires all businesses and individuals that acquire, own, or license personal information about Arkansas residents to:
- Implement and maintain reasonable security procedures and practices appropriate to the nature of the information
- Protect personal information from unauthorized access, destruction, use, modification, or disclosure
- Properly destroy records containing personal information that are no longer needed, by shredding, erasing, or otherwise making the data unreadable
The statute does not define what constitutes "reasonable" security measures, leaving this to be evaluated based on the circumstances.
Penalties and Enforcement
Civil Enforcement
Violations of the Personal Information Protection Act are enforceable by the Arkansas Attorney General under the Arkansas Deceptive Trade Practices Act (Ark. Code Ann. 4-88-101 et seq.), as specified in Ark. Code Ann. 4-110-108. Knowing and willful violations of the Deceptive Trade Practices Act can also constitute a Class A misdemeanor under Ark. Code Ann. 4-88-103, though enforcement is typically civil. Available remedies include:
- Civil penalties of up to $10,000 per violation
- Injunctive relief to stop ongoing violations
- Restitution for consumers who suffered financial harm
- Recovery of attorney's fees and investigation costs
No Explicit Private Right of Action
The statute does not create an explicit private right of action for individuals affected by a data breach. Consumers cannot sue businesses directly under PIPA for failing to notify them. However, affected individuals may have claims under other legal theories, such as negligence, if they can demonstrate actual harm from the breach.
Recent AG Enforcement Actions
The Arkansas Attorney General's office has become increasingly active in data breach enforcement in recent years.
In 2024, Attorney General Tim Griffin launched an investigation into Change Healthcare (a unit of UnitedHealth Group) after a massive cyberattack compromised medical and personal information. The AG specifically cited the Personal Information Protection Act and the Deceptive Trade Practices Act in the investigation, examining whether Arkansans' medical and personal data were compromised and whether the company complied with state law.
Arkansas also participated in a multistate settlement with Marriott International in October 2024 over data breaches affecting millions of guests. Arkansas received $804,965 as part of that settlement.
Interaction with Federal Laws
Arkansas's breach notification law includes exemptions for entities already subject to more protective federal or state requirements:
- HIPAA-covered entities that comply with the Health Insurance Portability and Accountability Act's breach notification requirements are generally considered in compliance with Arkansas law, provided federal protections are equal to or greater than state requirements.
- Financial institutions regulated under the Gramm-Leach-Bliley Act (GLBA) may satisfy their obligations under federal law, though they should confirm compliance with any additional state-specific requirements.
- Entities with their own notification procedures that maintain an information security policy consistent with the statute's timing requirements are deemed in compliance if they notify affected persons according to their internal policies.
How Arkansas Compares to Neighboring States
Arkansas's "most expedient time" standard contrasts with states that set firm deadlines. Missouri also requires notice to its Attorney General when a breach affects more than 1,000 residents, a threshold similar to Arkansas's own. Mississippi uses a comparable open-ended standard, requiring disclosure "without unreasonable delay" (Miss. Code Ann. 75-24-29(3)). Tennessee is the opposite case: Tenn. Code Ann. 47-18-2107(b) requires disclosure "no later than forty-five (45) days from the discovery or notification of the breach of system security," a fixed deadline Arkansas does not impose. Both states also define personal information more narrowly than Arkansas, covering neither medical information nor biometric data.
Arkansas's inclusion of biometric data and medical information puts it among the more comprehensive state definitions, though it still falls short of states like Illinois, which has a standalone biometric privacy law (BIPA) with a private right of action.
For a broader overview of how Arkansas protects consumer data, see the parent guide on Arkansas Data Privacy Laws.
This article provides general legal information about Arkansas data breach notification requirements under the Personal Information Protection Act. It is not legal advice. If your business has experienced a data breach or you believe your personal information has been compromised, consult an attorney for advice specific to your situation.
More Arkansas Laws
Frequently Asked Questions
How quickly does an Arkansas business have to report a data breach?
Arkansas does not set a specific number of days. The law requires notification in the most expedient time and manner possible and without unreasonable delay (Ark. Code Ann. 4-110-105). The timeline allows for time to investigate the breach scope and restore system integrity.
Does Arkansas require notification to the Attorney General?
Yes, when a breach affects more than 1,000 Arkansas residents. The notification must go to the AG at the same time individual notices are sent, or within 45 days of determining a reasonable likelihood of harm, whichever comes first.
Is notification required if the breached data was encrypted?
No. Arkansas provides an encryption safe harbor. If the personal information was encrypted or redacted at the time of the breach, notification is not required, provided the encryption key was not also compromised.
Can individuals sue a business for a data breach under Arkansas law?
The Personal Information Protection Act does not create an explicit private right of action. Individuals cannot sue directly under this statute. However, affected persons may pursue claims under other legal theories such as negligence if they can demonstrate actual harm.
What qualifies as personal information under Arkansas breach notification law?
Personal information includes a person's name combined with their Social Security number, driver's license number, financial account data with access codes, medical information, or biometric data (added by Act 1030 of 2019).
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the statutory definition of medical information to match Ark. Code Ann. 4-110-103(5), clarified that the computerized-data limit applies to the breach notification duty rather than to all of the Personal Information Protection Act, and fixed the multi-state comparison to show Tennessee's 45-day disclosure deadline.
Removed a fabricated criminal Class A misdemeanor penalty and an unrelated insurance-industry penalty tier that PIPA does not impose, corrected the statutory definition of personal information (removed invented health-insurance-identifier and online-credential categories), fixed a mischaracterized AG press-release quote about Change Healthcare, corrected an inaccurate claim that Missouri does not require Attorney General notification, and replaced six generic statute citation links with pinpoint links to the actual code sections.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Arkansas Code of 1987 Annotated
§ 4-110-105Disclosure of security breaches.In forcecited in 2 of our articles
(a)(1) Any person or business that acquires, owns, or licenses computerized data that includes personal information shall disclose any breach of the security of the system following discovery or notification of the breach of the security of the system to any resident of Arkansas whose unencrypted…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at advance.lexis.com
Also relied on in: Arkansas Data Privacy Laws: Breach Notification & Consumer Rights (2026)
§ 4-110-101Short title.In forcecited in 2 of our articles
This chapter shall be known and cited as the “Personal Information Protection Act”.
Official text (excerpt) · last checked 2020-11-06 · Read the full text in our law library
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Ark. Code Ann. 4-110-101 et seq. (Personal Information Protection Act)(law.justia.com)
- Act 1030 of 2019 (HB1943) - PI Definition Expansion(arkleg.state.ar.us).gov
- Arkansas AG - Data Breach Reporting(arkansasag.gov).gov
- AG Investigation of Change Healthcare Cyberattack(arkansasag.gov).gov
- AG Settlement with Marriott International for Data Breach(arkansasag.gov).gov
- HB1943 Bill Information - Arkansas Legislature(arkleg.state.ar.us).gov
- Act 1526 of 2005 (SB1167) - Arkansas Personal Information Protection Act as enacted(arkleg.state.ar.us)
- Tennessee Public Chapter 91 (2017), amending Tenn. Code Ann. 47-18-2107 (45-day breach disclosure deadline)(publications.tnsosfiles.com)
- Mississippi HB 277 (2021) as enrolled, amending Miss. Code Ann. 75-24-29 (breach disclosure without unreasonable delay)(billstatus.ls.state.ms.us)