Idaho
Idaho Data Privacy Laws: Breach Notification & Consumer Rights (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 16 primary sources cited on this page. How we verify our legal content

Idaho has no comprehensive consumer data privacy law as of May 2026. The state relies on its breach notification statute, Idaho Code §§ 28-51-104 through 28-51-107, which requires businesses to notify affected residents of a data breach as soon as possible, alongside sector-specific laws and federal protections.
Idaho takes a patchwork approach to data privacy. Unlike California, Colorado, Connecticut, and roughly 20 other states that have enacted comprehensive consumer data privacy statutes, Idaho has no single law giving residents broad rights to access, correct, or delete their personal information held by businesses.
Instead, Idaho residents depend on a combination of the state's data breach notification law, identity theft criminal statutes, student data protections, a genetic testing privacy act, a 2026 children's social media act, a synthetic media prohibition, the Consumer Protection Act, and federal privacy laws that apply to specific industries.
This guide covers every part of Idaho's data privacy framework in force as of May 2026: what protections exist, what your rights are, who enforces the rules, and where the gaps remain. For Idaho's recording consent rules, see Idaho Recording Laws.
Idaho's Data Breach Notification Law
The cornerstone of Idaho's data privacy framework is the Idaho Identity Theft Act, codified at Idaho Code §§ 28-51-104 through 28-51-107. Enacted in 2006, this law requires businesses, government agencies, and individuals that handle computerized personal information to notify affected Idaho residents when a data breach occurs.
The law does not regulate how companies collect or use personal data. It focuses entirely on what happens after a breach.
What Counts as a Data Breach in Idaho?
Under Idaho Code § 28-51-104, a breach is the "illegal acquisition of unencrypted computerized data that materially compromises the security, confidentiality, or integrity of personal information" maintained by an agency, individual, or commercial entity.
The law includes an important carve-out: good faith acquisition of personal information by an employee or agent for legitimate business purposes does not qualify as a breach, as long as the information is not used improperly or shared without authorization.
What Is Personal Information Under Idaho Law?
Idaho Code § 28-51-104 defines personal information as an Idaho resident's first name or first initial and last name combined with one or more of the following data elements:
- Social Security number
- Driver's license number or state identification card number
- Financial account number, credit card number, or debit card number, combined with any required security code, access code, or password that would permit access to the account
The definition excludes information lawfully obtained from publicly available sources or from government records lawfully made available to the general public.
Notification Requirements
The notification rules under Idaho Code § 28-51-105 apply to any entity that conducts business in Idaho and owns or licenses computerized data containing personal information about Idaho residents.
When a breach is discovered, the entity must conduct a good faith, reasonable, and prompt investigation to determine whether personal information has been or is reasonably likely to be misused. If the investigation confirms misuse has occurred or is likely, the entity must notify affected Idaho residents "as soon as possible" without unreasonable delay.
Idaho does not set a specific number of days for notification, unlike Colorado (30 days) or Florida (30 days). The standard is reasonableness.
Public Agency Notification to the Attorney General
Idaho holds public agencies to a stricter standard than private businesses. Under § 28-51-105, any public agency that discovers a breach must notify the Idaho Attorney General within 24 hours.
This is broader than state government. Section 28-51-105(1) opens with "a city, county or state agency," and § 28-51-104 defines "agency" as any "public agency" as defined in Idaho Code § 74-101, which covers a county, city, school district, municipal corporation, district, public health district or political subdivision alongside state agencies. The Attorney General's office states the duty the same way: an Idaho public agency must notify within 24 hours of discovering a breach of its security system. This requirement exists in addition to the agency's obligation to notify affected residents.
Private businesses are not required by Idaho law to report breaches to the Attorney General, though they may do so voluntarily through the AG's Consumer Protection Division.
Methods of Notification
Idaho law permits four methods of notifying affected residents, as defined in § 28-51-104:
| Method | Details |
|---|---|
| Written notice | Sent to the last known address of the affected resident |
| Telephone | Direct contact with the affected resident |
| Electronic notice | Must comply with federal E-SIGN Act requirements |
| Substitute notice | Available when costs exceed $25,000, more than 50,000 residents are affected, or the entity lacks sufficient contact information |
Substitute notice requires all three of the following: email notice to all available email addresses, conspicuous posting on the entity's website, and notification through statewide media outlets.
Third-Party Data Holders
If a business maintains personal information on behalf of another entity (for example, a cloud service provider), § 28-51-105 requires the data holder to notify the data owner immediately after discovering a breach where misuse is likely.
Law Enforcement Delays
Notification may be delayed if a law enforcement agency advises that immediate notice would impede a criminal investigation. Once law enforcement confirms that notification will no longer compromise the investigation, the entity must proceed with notice without unreasonable delay.
Penalties for Violating Idaho's Breach Notification Law
Enforcement falls to the entity's primary regulator. Under Idaho Code § 28-51-107, the primary regulator may initiate a civil action and seek injunctive relief against any entity that fails to provide required notice.
| Violation Type | Penalty |
|---|---|
| Intentional failure to notify | Fine of up to $25,000 per breach |
| Government employee intentional disclosure (Idaho Code § 28-51-105) | Misdemeanor: up to $2,000 fine and/or 1 year in jail |
The $25,000 cap applies per breach of the security system, not per individual affected. A single breach affecting thousands of residents still carries a maximum fine of $25,000.
Idaho does not provide a private right of action under the breach notification law. Enforcement rests with government regulators.
Compliance Safe Harbors
Idaho Code § 28-51-106 provides two safe harbors for compliance:
-
Internal policy compliance. Entities that maintain their own breach notification procedures as part of an information security policy are deemed compliant if their procedures meet the timing requirements of § 28-51-105 and they follow those procedures when a breach occurs.
-
Regulatory compliance. Entities regulated by state or federal agencies that maintain breach notification procedures under their primary regulator's guidelines satisfy Idaho's requirements by following those procedures.
These safe harbors mean that financial institutions following GLBA breach rules and healthcare entities following HIPAA breach rules are typically deemed compliant with Idaho law.
Idaho's Proposed Insurance Data Security Act: A Bill That Did Not Pass

Idaho does not have an insurance-specific data security law. In the 2025 legislative session, lawmakers considered House Bill 117, which would have adopted the National Association of Insurance Commissioners (NAIC) model Insurance Data Security Act. The bill cleared the House Business Committee in March 2025 and was filed for a third reading, but it stalled on the calendar and was sent back to committee on March 20, 2025. It never received a House floor vote, never reached the Senate, and was never signed into law.
Idaho Code Title 41, Chapter 58, a citation sometimes associated with this proposal, is actually the state's Public Adjuster Licensing Act and has nothing to do with data security.
What HB 117 Would Have Required
Had it passed, HB 117 would have required insurance licensees to develop written information security programs, implement administrative, technical, and physical safeguards, conduct prompt investigations of cybersecurity events, and notify the Director of the Idaho Department of Insurance within 10 business days of a significant cybersecurity event. None of these requirements are currently in force.
What Applies to Insurance Licensees Today
Because HB 117 did not become law, Idaho insurance licensees have no state-specific data security statute to follow. They remain subject to the general breach notification requirements under Idaho Code Title 28, Chapter 51 discussed above, along with whatever federal frameworks already apply to their business, such as HIPAA for health-related lines or GLBA for licensees affiliated with financial institutions.
Idaho's Identity Theft Criminal Laws
Idaho's criminal code provides additional personal data protections through identity theft statutes in Idaho Code Title 18, Chapter 31.
Misappropriation of Personal Identifying Information (§ 18-3126)
Idaho Code § 18-3126 makes it unlawful to obtain or record another person's personal identifying information without authorization when the intent is to use that information to fraudulently obtain credit, money, goods, or services.
This is a felony offense. Penalties include up to 5 years in state prison, fines up to $50,000, or both. The statute was originally enacted in 1999 and strengthened through amendments in 2008.
Acquisition by False Authority (§ 18-3126A)
Idaho Code § 18-3126A targets individuals who obtain personal identifying information by falsely representing that they have authority to access it. This covers scenarios such as impersonating an employer, government official, or financial institution to trick someone into providing their data.
This is also a felony with the same penalties: up to 5 years imprisonment and fines up to $50,000.
Idaho's Synthetic Media and Deepfake Law
Idaho enacted House Bill 575 in 2024, criminalizing the disclosure of explicit synthetic media, including AI-generated nonconsensual intimate images (NCII).
What the Law Covers
A person commits the offense of disclosing explicit synthetic media if they knowingly disclose such media and know, or reasonably should know, that an identifiable person depicted in the media did not consent to its disclosure and the disclosure is likely to cause substantial emotional distress.
"Explicit synthetic media" includes AI-generated or digitally manipulated content that depicts an identifiable individual engaged in sexual conduct or that depicts their genitals or intimate parts.
Penalties
| Offense | Penalty |
|---|---|
| First offense (misdemeanor) | Up to 6 months incarceration and up to $1,000 fine |
| Second or subsequent offense within 5 years (felony) | Up to 10 years imprisonment and up to $25,000 fine |
| Threatening to disclose (extortion) | Same penalty scale as above |
Federal Complement: TAKE IT DOWN Act
The federal TAKE IT DOWN Act (Pub. L. 119-12, signed May 19, 2025) adds a layer of protection on top of Idaho's state law. The Act prohibits any person from knowingly publishing nonconsensual intimate visual depictions of adults or any intimate visual depictions of minors, including AI-generated deepfakes.
Critically, the Act requires covered platforms (social media services and similar online platforms) to establish procedures for takedown requests and to remove reported content within 48 hours of receiving a valid request. These platform obligations became effective May 19, 2026, and are enforced by the Federal Trade Commission.
Together, Idaho HB 575 and the TAKE IT DOWN Act create both criminal liability for individual bad actors and a federal takedown mechanism targeting the platforms that host NCII content.
Idaho Consumer Protection Act

The Idaho Consumer Protection Act (Idaho Code § 48-601 et seq.) serves as a general-purpose tool for addressing unfair and deceptive business practices, including those involving personal data.
While the act does not mention data privacy specifically, Idaho Code § 48-603 prohibits "engaging in any act or practice that is otherwise misleading, false, or deceptive" in the conduct of commerce. This catch-all provision gives the Idaho Attorney General authority to pursue companies that engage in deceptive data collection practices, misrepresent their privacy policies, or fail to honor their stated data handling commitments.
Attorney General Raul Labrador's office has significantly increased consumer protection enforcement. In 2025, the office took 49 enforcement actions against businesses violating Idaho's consumer protection laws, up from 17 in 2024 and 8 in 2023. While most of those actions addressed broader deceptive practices, the Consumer Protection Act remains the primary tool for data-related misconduct outside the breach notification law.
The AG's Consumer Protection Division can seek:
- Injunctive relief to stop deceptive practices
- Voluntary compliance agreements
- Civil penalties through district court action
Consumers can file complaints directly with the AG's office. The AG can also accept assurances of voluntary compliance from businesses that commit to correcting their practices.
Student Data Privacy Protections
Idaho Code § 33-133 establishes specific protections for student data in Idaho's public education system. This law was enacted in 2014 to address growing concerns about how schools and educational technology vendors handle student information.

What Student Data Is Protected?
The law defines "personally identifiable data" to include the student's name, names of parents or family members, the student's or family's address, and any direct or indirect identifiers that could identify a specific student.
Prohibited Data Collection
Idaho law explicitly prohibits educational records from containing:
- Juvenile delinquency or criminal records (unless required by law)
- Medical or health records
- Social Security numbers
- Biometric information
- Gun ownership records
- Sexual orientation
- Religious affiliation
Vendor Requirements
Private vendors that access student data must either agree to a complete prohibition on secondary uses of student data (no selling, marketing, or advertising), or provide full disclosure of secondary data uses and obtain parental consent before any use beyond the contracted service.
Penalties
Violations that result in unauthorized release of personally identifiable data carry civil penalties of up to $50,000 per violation. Schools must also notify affected parents and students when unauthorized disclosures occur.
Idaho's Genetic Testing Privacy Act
Genetic information gets its own Idaho statute. The Genetic Testing Privacy Act, Idaho Code Title 39, Chapter 83 (§§ 39-8301 through 39-8305), was enacted in 2006 and amended in 2022.
Restrictions on Employers
Idaho Code § 39-8303 bars an employer, in connection with a hiring, promotion, retention or related decision, from doing any of the following:
- Accessing or otherwise taking into consideration private genetic information about an individual
- Requesting or requiring an individual to consent to a release for the purpose of accessing private genetic information
- Requesting or requiring an individual or a blood relative to submit to a genetic test
- Inquiring into the fact that an individual or a blood relative has taken or refused to take a genetic test
The statute carves out narrow exceptions, including where an individual has placed their own health at issue in a legal proceeding and where the employer has reasonable grounds to believe a health condition creates a genuine safety hazard.
Enforcement and Related Provisions
Section 39-8304 supplies the chapter's enforcement mechanism. The chapter also contains § 39-8305, a prohibition on certain genetic sequencers and genetic analysis technologies.
Stop Harms from Addictive Social Media Act
The Stop Harms from Addictive Social Media Act, Idaho Code Title 48, Chapter 21 (§§ 48-2101 through 48-2106), was added by the 2026 legislature (2026, ch. 268). It is a sectoral children's privacy law rather than a general consumer privacy statute, but it is the most substantial data-handling mandate Idaho has imposed on an industry since the breach notification law.
Age Estimation
Idaho Code § 48-2103 requires a covered social media platform, within 14 days of the first trigger date, to use reasonable means and reasonable efforts, taking into consideration available technology and the data in its possession, to estimate the age of the account holder.
Requirements for Children's Accounts
Under § 48-2104, a covered platform must require applicants to provide a birth date and must obtain verifiable parental consent before creating an account for a child. Information collected to obtain that consent may not be used for any other purpose and must be deleted immediately after the consent attempt, except where the law requires retention.
The section also requires that an account for a child have all privacy settings set by default at the most private levels, and that platforms offer parents a separate password option to monitor time spent, set daily or weekly limits, and restrict access times. Addictive interface features and profile-based paid advertising may not be served to children. A minor may request account termination within 7 days, and a parent within 14 days.
Remedies and Enforcement
Section 48-2105 gives a child or parent a private right of action for declaratory or injunctive relief, damages including harm to mental health and emotional distress, court costs and reasonable attorney's fees. For a reckless or knowing violation, the injured party may recover actual damages established at trial or $10,000 in statutory damages, whichever is greater, and punitive damages are available where the conduct is a consistent pattern of reckless or knowing behavior. A civil action must be brought within 3 years of the date the plaintiff knew, or reasonably should have known, of the violation. The Attorney General may also investigate and prosecute knowing or reckless violations, treating them as violations of Idaho Code § 48-603.
That private right of action is a real departure from the rest of Idaho's privacy framework, which gives residents no way to sue. Section 48-2106 sets out exclusions and prohibits waiver of the chapter's protections. The published statute sections do not carry a stated effective date, so check the 2026 session law before relying on a specific compliance deadline.
Public Records Act Privacy Exemptions
Idaho's Public Records Act (Idaho Code Title 74, Chapter 1) includes privacy-related exemptions under § 74-106 that restrict disclosure of certain personal information held by government agencies.
Exempt records include:
- Personnel records of current or former public employees (except public service history, pay grade, and gross salary)
- Home addresses and phone numbers of retired public employees
- Medical and health records, including prescriptions, psychiatric care, and counseling records
- Reportable disease records maintained by health departments
- Records where disclosure would constitute an "unwarranted invasion of personal privacy"
These exemptions protect individuals from having sensitive personal information disclosed through public records requests, though they apply only to government-held records.
Federal Privacy Laws That Apply in Idaho
Because Idaho lacks a comprehensive state privacy law, federal statutes provide the primary privacy protections for many Idaho residents and businesses.
Health Insurance Portability and Accountability Act (HIPAA)
HIPAA applies to Idaho healthcare providers, health plans, healthcare clearinghouses, and their business associates. It requires physical, technical, and administrative safeguards to protect personal health information (PHI). Idaho healthcare entities must comply with both the HIPAA Privacy Rule and the Security Rule.
Gramm-Leach-Bliley Act (GLBA)
Financial institutions operating in Idaho must comply with GLBA, which requires written information security programs, consumer privacy notices explaining data sharing practices, and opt-out rights for consumers regarding third-party data sharing. Idaho considered but did not enact a state-specific insurance data security law in 2025 (House Bill 117 stalled in the House without passing), so financial institutions that also hold insurance licenses in Idaho are not subject to any additional state insurance data security statute; GLBA and, where applicable, HIPAA remain the controlling frameworks for those licensees.
Children's Online Privacy Protection Act (COPPA)
Any Idaho business that operates a website or online service directed at children under 13, or that knowingly collects personal information from children under 13, must comply with COPPA. Requirements include verified parental consent before data collection and restrictions on how children's data can be used or shared.
Family Educational Rights and Privacy Act (FERPA)
FERPA protects the privacy of student education records at Idaho schools that receive federal funding. It gives parents (and students over 18) the right to access, review, and request corrections to educational records. FERPA works alongside Idaho's own student data protection law (§ 33-133) to create a dual layer of protection.
Fair Credit Reporting Act (FCRA)
The FCRA regulates how consumer reporting agencies in Idaho collect, share, and use credit information. Idaho residents have the right to access their credit reports, dispute inaccurate information, and limit who can access their credit data.
FTC Act Section 5
The Federal Trade Commission enforces Section 5 of the FTC Act against unfair or deceptive data practices. Idaho businesses that misrepresent their privacy policies or fail to implement reasonable data security measures face FTC enforcement regardless of whether Idaho has a specific state law covering the conduct.
A Note on Federal Comprehensive Privacy Legislation
The American Privacy Rights Act (APRA), which would have established a federal baseline for consumer data privacy rights, was introduced in 2024 but expired without passage at the end of the 118th Congress in January 2025. As of May 2026, the bill has not been reintroduced. There is no federal comprehensive consumer data privacy law in force.
How to Report a Data Breach in Idaho

For Businesses and Agencies
Contact the Idaho Attorney General's Consumer Protection Division:
- Email: consumer_protection@ag.idaho.gov
- Mailing address: P.O. Box 83720, Boise, ID 83720-0010
- Phone: 208-334-2400
Public agencies, state and local, must report within 24 hours of discovery. Private businesses may report voluntarily.
For Consumers
If you believe your personal information was compromised in a breach:
- Contact the company or agency that experienced the breach
- File a complaint with the Idaho Attorney General
- Place a fraud alert or credit freeze with the three major credit bureaus
- Monitor your financial accounts and credit reports for suspicious activity
The Attorney General's office maintains a public registry of reported breaches dating back to January 1, 2021.
Idaho vs. Other States: Where Does Idaho Stand?
As of May 2026, more than 20 states have enacted comprehensive consumer data privacy laws. Idaho is not among them. Here is how Idaho compares to neighboring and notable states.
| Feature | Idaho | Montana | Colorado | California |
|---|---|---|---|---|
| Comprehensive privacy law | No | Yes (effective Oct. 2024) | Yes (effective July 2023) | Yes (CCPA/CPRA) |
| Consumer right to access data | No | Yes | Yes | Yes |
| Consumer right to delete data | No | Yes | Yes | Yes |
| Right to opt out of data sales | No | Yes | Yes | Yes |
| Breach notification required | Yes | Yes | Yes | Yes |
| Breach notification deadline | "As soon as possible" | 60 days | 30 days | "Most expedient time possible" |
| AG notification required | Public agencies only (24 hrs) | Yes (if 500+ affected) | Yes (if 500+ affected) | Yes (if 500+ affected) |
| Maximum breach fine | $25,000 per breach | $10,000 per violation | $20,000 per violation | $7,500 per intentional violation |
The gap is significant. Idaho residents have no statutory right to know what personal data a company holds about them, no right to request deletion, and no right to opt out of the sale of their personal information.
Privacy Legislation Outlook
Idaho has not enacted a comprehensive consumer data privacy law through the 2025 legislative session. No comprehensive privacy bill was on an active track in the 2025-2026 session as of May 2026.
The national trend remains clear: the number of states with comprehensive privacy laws has grown from roughly 5 in 2023 to more than 20 by mid-2026. Factors that could accelerate Idaho action include:
- Neighboring state pressure. Montana's comprehensive privacy law took effect in October 2024. As more states in the region adopt privacy laws, Idaho businesses that operate across state lines must comply with those laws regardless of what Idaho requires.
- Federal baseline potential. Although the APRA did not pass in 2024 and has not been reintroduced, renewed federal activity could establish a national floor that all states must meet.
- Sectoral expansion. This is where Idaho actually moves. The 2026 session enacted the Stop Harms from Addictive Social Media Act (Idaho Code §§ 48-2101 to 48-2106), imposing age estimation, verifiable parental consent and default privacy settings on social media platforms and attaching a private right of action to them. Idaho's 2025 attempt to adopt an NAIC-model Insurance Data Security Act (House Bill 117) stalled in the House without passing, but a revived version, or other sectoral laws in healthcare, financial services, or education technology, could follow in a future session.
Until Idaho acts, residents should understand that their primary protections come from the breach notification law, identity theft criminal statutes, the genetic testing privacy act, the children's social media act, the synthetic media prohibition, and whichever federal laws apply to the specific industry handling their data.
This article is for informational purposes only and does not constitute legal advice. Consult a qualified attorney licensed in Idaho for guidance on your specific situation. Laws and regulations may change; verify all information with official state sources.
More Idaho Laws
Frequently Asked Questions
Does Idaho have a comprehensive data privacy law?
No. As of May 2026, Idaho does not have a comprehensive consumer data privacy law. Unlike California, Colorado, Virginia, and neighboring Montana, Idaho has not enacted legislation giving residents broad rights to access, delete, or control how businesses use their personal data. Idaho relies on its data breach notification law (Idaho Code §§ 28-51-104 through 28-51-107), identity theft criminal statutes, and federal privacy laws that apply to specific industries.
What should I do if my personal information is exposed in a data breach in Idaho?
First, contact the company or agency that experienced the breach for details about what information was compromised. Then file a complaint with the Idaho Attorney General's Consumer Protection Division at consumer_protection@ag.idaho.gov or call 208-334-2400. Place a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion). Monitor your bank accounts and credit reports closely for unauthorized activity. Idaho law requires the breached entity to notify you as soon as possible if your personal information was compromised.
How quickly must a company notify me of a data breach in Idaho?
Idaho Code § 28-51-105 requires entities to notify affected residents 'as soon as possible' after determining that personal information has been or is reasonably likely to be misused. The law does not set a specific number of days, unlike Colorado (30 days) or Montana (60 days). Public agencies face a stricter standard and must notify the Idaho Attorney General within 24 hours of discovering a breach. That duty reaches cities, counties, school districts and other political subdivisions, not just state agencies.
What are the penalties for identity theft in Idaho?
Identity theft is a felony in Idaho under Idaho Code § 18-3126. Obtaining or recording someone's personal identifying information without authorization, with intent to fraudulently obtain credit, money, goods, or services, carries penalties of up to 5 years in state prison, fines up to $50,000, or both. Acquiring personal information by falsely claiming authority (§ 18-3126A) carries the same penalties.
Can I sue a company in Idaho for mishandling my personal data?
Idaho's breach notification law does not include a private right of action. You cannot file a lawsuit directly under § 28-51-105 for a company's failure to notify you of a breach. Enforcement is handled by the entity's primary regulator, which can seek fines of up to $25,000 per breach. However, you may have other legal options. You can file a complaint with the Idaho Attorney General under the Consumer Protection Act (Idaho Code § 48-601 et seq.), and in some cases you may be able to pursue common law claims such as negligence if you suffered actual damages from a data breach.
Did Idaho pass an Insurance Data Security Act?
No. House Bill 117 (2025) would have created an Idaho Insurance Data Security Act based on the NAIC model law, but it stalled in the Idaho House and was returned to committee on March 20, 2025 without a floor vote. It never became law, so there is no state insurance-specific data security statute in Idaho. Insurance licensees remain subject to the general breach notification rules under Idaho Code §§ 28-51-104 through 28-51-107, plus HIPAA or GLBA where those already apply.
Is it illegal to share AI-generated intimate images of someone in Idaho without their consent?
Yes. Idaho House Bill 575 (enacted 2024) criminalizes the knowing disclosure of explicit synthetic media, including AI-generated nonconsensual intimate images, when the depicted person did not consent and the disclosure is likely to cause substantial emotional distress. A first offense is a misdemeanor (up to 6 months and $1,000 fine). A second or subsequent offense within 5 years is a felony (up to 10 years and $25,000 fine). Additionally, the federal TAKE IT DOWN Act (effective May 19, 2026) requires online platforms to remove reported nonconsensual intimate images within 48 hours of a valid takedown request.
Updates
Corrected the 24-hour Attorney General breach-notice duty, which applies to all Idaho public agencies including cities, counties and school districts rather than state agencies only, and added coverage of the Genetic Testing Privacy Act (Idaho Code Title 39, Chapter 83) and the 2026 Stop Harms from Addictive Social Media Act (Idaho Code Title 48, Chapter 21).
This page previously described a 2025 Idaho bill (HB 117) to create an insurance-sector data security law as enacted, in-force legislation; that bill stalled in the Idaho House and never became law, and the article has been corrected accordingly, along with a misattributed penalty citation and an incorrect Attorney General phone number.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Governing law re-checked for recent changes
May 2026 refresh: added HB 575 deepfake/NCII synthetic media law (enacted 2024); added federal TAKE IT DOWN Act (signed May 19 2025, platform obligations effective May 19 2026); corrected APRA status (expired Jan 2025, not reintroduced as of May 2026); added AG Labrador 2025 enforcement stats (49 consumer protection actions); added FTC Act Section 5 to federal overlay; added Idaho Recording Laws cross-link; expanded FAQ to 7 questions; expanded SourcesList to 16 sources. Correction (2026-08-14): removed a fabricated claim that Idaho enacted an Insurance Data Security Act (House Bill 117) in 2025; the bill stalled in the House and never became law, and Idaho Code Title 41 Chapter 58 is actually the Public Adjuster Licensing Act. Also corrected the misdemeanor-penalty citation to Idaho Code section 28-51-105 and fixed the AG Consumer Protection Division phone number.
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Idaho Code
§ 28-51-105Disclosure of breach of security of computerized personal information by an agency, individual or a commercial entityIn forcecited in 2 of our articles
28-51-105. Disclosure of breach of security of computerized personal information by an agency, individual or a commercial entity.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at legislature.idaho.gov
Also relied on in: Idaho Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 28-51-104Definitions. For purposes of sections 28-51-104 through 28-51-107, Idaho Code:In forcecited in 3 of our articles
28-51-104. Definitions. For purposes of sections 28-51-104 through 28-51-107, Idaho Code: (1) "Agency" means any "public agency" as defined in section 74-101, Idaho Code.
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at legislature.idaho.gov
Also relied on in: Idaho Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 28-51-106Procedures deemed in compliance with security breach requirementsIn forcecited in 2 of our articles
28-51-106. Procedures deemed in compliance with security breach requirements. (1) An agency, individual or a commercial entity that maintains its own notice procedures as part of an information security policy for the treatment of personal information, and whose procedures are otherwise consistent…
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at legislature.idaho.gov
§ 28-51-107Violations. In any case in which an agency’s, commercial entity’s or individual’s primary regulator has reason to believe that an agency, individual or commercial entity subject to that primary regulator’s jurisdiction under section 28-51-104In forcecited in 3 of our articles
28-51-107. Violations. In any case in which an agency’s, commercial entity’s or individual’s primary regulator has reason to believe that an agency, individual or commercial entity subject to that primary regulator’s jurisdiction under section 28-51-104(6), Idaho Code, has violated section…
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at legislature.idaho.gov
§ 48-603Unfair methods and practices. The following unfair methods of competition and unfair or deceptive acts or practices in the conduct of any trade or commerce are hereby declared to be unlawful, where a person knows, or in the exercise of due care should know, that he has in the past, or is:In force
48-603. Unfair methods and practices. The following unfair methods of competition and unfair or deceptive acts or practices in the conduct of any trade or commerce are hereby declared to be unlawful, where a person knows, or in the exercise of due care should know, that he has in the past, or…
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at legislature.idaho.gov
Cited in 41 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- State v. Daicel Chemical Industries, Ltd. (Idaho Supreme Court 2005, 141 Idaho 102)“…defines what constitutes an unfair method of competition. Idaho Code § 48-603 begins, “The following unfair methods…”
- Fenn v. Noah (Idaho Supreme Court 2006, 142 Idaho 775)“…117 Idaho 399, 401 , 788 P.2d 214, 216 (1990). Idaho Code § 48-603 contains a knowledge element and an en…”
- Estate of Kalinski v. Murphy Law Office PLLC (Idaho Supreme Court 2026)“…neys, that it identified conduct constituting violations of Idaho Code section 48-603(13) and (17), and that the ICPA claim i…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 48-601Short title and purpose. This act shall be known and may be cited as the "Idaho consumer protection act". The purpose of this act is to protect both consumers and businesses against unfair methods of competition and unfair or deceptive acts and practices in the conduct of trade or commerce, and to provide efficient and economical procedures to secure such protection. It is the intention of the legislature that this chapter be remedial and be so construedIn force
48-601. Short title and purpose. This act shall be known and may be cited as the "Idaho consumer protection act". The purpose of this act is to protect both consumers and businesses against unfair methods of competition and unfair or deceptive acts and practices in the conduct of trade or commerce,…
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at legislature.idaho.gov
Cited in 34 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Venable v. Internet Auto Rent & Sales, Inc. (Idaho Supreme Court 2014, 156 Idaho 574)“…as the ‘Idaho consumer protection act.’” See Idaho Code § 48-601, et seq. Further, that w…”
- State ex rel. Lance v. Hobby Horse Ranch Tractor & Equipment Co. (Idaho Supreme Court 1996, 129 Idaho 565)“…6 Hobby Horse had violated Idaho’s Consumer Protection Act, Idaho Code section 48-601 et seq. (1977 and Supp.1996) (CPA) an…”
- State v. HOBBY HORSE RANCH TRAC. & EQUIP. (Idaho Supreme Court 1996, 129 Idaho 565)“…Hobby Horse had violated Idaho's Consumer Protection Act, Idaho Code section 48-601 et seq. (1977 and Supp.1996) (CPA) an…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 18-3126Misappropriation of personal identifying information. It is unlawful for any person to obtain or record personal identifying information of another person without the authorization of that person, with the intent that the information be used to obtain, or attempt to obtain, credit, money, goods or services without the consent of that personIn forcecited in 2 of our articles
18-3126. Misappropriation of personal identifying information. It is unlawful for any person to obtain or record personal identifying information of another person without the authorization of that person, with the intent that the information be used to obtain, or attempt to obtain, credit, money,…
Official text (excerpt) · last checked 2026-09-02 · Read the full text in our law library · Verify at legislature.idaho.gov
Cited in 2 court opinions in our collectionLatest citing opinion in our collection: 2024
Opinions citing this section in our collection:
- State v. Bujak (Idaho Supreme Court 2024, 551 P.3d 771)“…propriation of personal identifying information pursuant to Idaho Code sections 18-3126 and 18-3128. Bujak pleaded guilty to th…”
- State v. Shannon Lynn Madison (Idaho Court of Appeals 2014)“…ed of misappropriation of personal identifying information, Idaho Code §§ 18-3126, 18-3128, and misdemeanor petit theft,…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Idaho Identity Theft Laws: Misappropriation Statute and Penalties
§ 18-3126aAcquisition of personal identifying information by false authority. It is unlawful for any person to falsely assume or pretend to be a member of the armed forces of the United States or an officer or employee acting under authority of the United States or any department, agency or office thereof or of the state of Idaho or any department, agency or office thereof, and in such pretended character, seek, demand, obtain or attempt to obtain personal identifying information of another personIn force
18-3126A. Acquisition of personal identifying information by false authority. It is unlawful for any person to falsely assume or pretend to be a member of the armed forces of the United States or an officer or employee acting under authority of the United States or any department, agency or office…
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at legislature.idaho.gov
§ 33-133definitions — STUDENT DATA — use and limitations — penaltiesIn forcecited in 2 of our articles
33-133. definitions — STUDENT DATA — use and limitations — penalties. (1) As used in this act, the following terms shall have the following meanings: (a) "Agency" means each state board, commission, department, office or institution, educational or otherwise, of the state of Idaho.
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at legislature.idaho.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2020
Opinions citing this section in our collection:
- Ybarra v. Legislature of the State of Idaho & ID Bd of Education (Idaho Supreme Court 2020, 166 Idaho 902)“…Indeed, the Appropriation Bills at issue are ancillary to Idaho Code section 33-133(2)-(3), wherein the Legislature charged…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 74-106Records exempt from disclosure — Personnel records, personal information, health records, professional discipline. The following records are exempt from disclosure:In force
74-106. Records exempt from disclosure — Personnel records, personal information, health records, professional discipline.
Official text (excerpt) · last checked 2026-08-01 · Read the full text in our law library · Verify at legislature.idaho.gov
Cited in 2 court opinions in our collectionLatest citing opinion in our collection: 2020
Opinions citing this section in our collection:
- Strosnider v. City of Nampa (District Court, D. Idaho 2016, 196 F. Supp. 3d 1159)“…f summary judgment. Defendants suggest that according to Idaho Code § 74-106 (1), no documents related to Strosnider…”
- King Hutton v. Blaine County School District 61 (District Court, D. Idaho 2020)“…valuation must follow certain privacy control laws, namely Idaho Code section 74-106. In other words, Defendants argue that…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Idaho Code § 28-51-104: Definitions - Idaho Identity Theft(legislature.idaho.gov).gov
- Idaho Code § 28-51-105: Notification Requirements for Data Breaches(legislature.idaho.gov).gov
- Idaho Code § 28-51-106: Compliance Safe Harbors(legislature.idaho.gov).gov
- Idaho Code § 28-51-107: Penalties for Notification Violations(legislature.idaho.gov).gov
- Idaho Code § 18-3126: Misappropriation of Personal Identifying Information(legislature.idaho.gov).gov
- Idaho Code § 18-3126A: Acquisition by False Authority(legislature.idaho.gov).gov
- Idaho Code § 33-133: Student Data Privacy and Protections(legislature.idaho.gov).gov
- Idaho Consumer Protection Act - Idaho Code § 48-601 et seq.(legislature.idaho.gov).gov
- Idaho Code § 48-603: Unfair Methods and Deceptive Practices(legislature.idaho.gov).gov
- Idaho Public Records Act - Privacy Exemptions (§ 74-106)(legislature.idaho.gov).gov
- House Bill 117 (2025) - Insurance Data Security Act proposal (stalled in House committee, never enacted)(legislature.idaho.gov).gov
- House Bill 575 (2024) - Disclosing Explicit Synthetic Media(legislature.idaho.gov).gov
- TAKE IT DOWN Act - S.146, 119th Congress (signed May 19, 2025)(congress.gov).gov
- Security Breaches - Idaho Office of the Attorney General(ag.idaho.gov).gov
- Consumer Protection Division - Idaho Attorney General(ag.idaho.gov).gov
- AG Labrador: 2025 Year in Review - Defending Consumers(ag.idaho.gov).gov
- Idaho Genetic Testing Privacy Act - Idaho Code Title 39, Chapter 83(legislature.idaho.gov)
- Idaho Code § 39-8303: Restrictions on Employers (genetic information)(legislature.idaho.gov)
- Stop Harms from Addictive Social Media Act - Idaho Code Title 48, Chapter 21 (added 2026, ch. 268)(legislature.idaho.gov)
- Idaho Code § 48-2104: Limitations and Requirements for Social Media Accounts for Children(legislature.idaho.gov)
- Idaho Code § 48-2105: Remedies and Enforcement (private right of action, $10,000 statutory damages)(legislature.idaho.gov)
- Idaho Code § 74-101: Definitions of "local agency" and "public agency"(legislature.idaho.gov)