Nebraska
Nebraska Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 5 primary sources cited on this page. How we verify our legal content

Nebraska's Financial Data Protection and Consumer Notification of Data Security Breach Act, under Neb. Rev. Stat. 87-803, requires businesses to notify affected residents as soon as possible and without unreasonable delay after a breach. The Nebraska Attorney General must receive notice no later than the time notice is provided to individuals.
If your business handles personal information belonging to Nebraska residents, a data breach triggers specific legal obligations under the Nebraska Financial Data Protection and Consumer Notification of Data Security Breach Act. Neb. Rev. Stat. 87-801 et seq. sets out the requirements for determining when a breach has occurred, who must be notified, what information triggers notification, and the consequences of noncompliance. Nebraska's law has evolved significantly since its original enactment, with recent amendments expanding the definition of personal information to include biometric data and login credentials.
This guide covers the full scope of Nebraska's breach notification requirements, including what personal information triggers the law, who must be notified, the notification timeline, the class-action liability shield for cybersecurity events, penalties, and how the state's broader data privacy framework interacts with breach obligations.
Who Must Comply With Nebraska's Breach Notification Law
Nebraska's law applies to any individual or commercial entity that conducts business in Nebraska and owns, licenses, or maintains computerized data that includes personal information about a Nebraska resident. This includes businesses physically located outside Nebraska if they hold data belonging to Nebraska residents.
The law distinguishes between data owners and third-party data maintainers. When a third party that maintains data on behalf of another entity becomes aware of a breach, it must give notice to and cooperate with the data owner or licensee, including by sharing information relevant to the breach. Neb. Rev. Stat. 87-803(3) ties that duty to the point when the maintainer becomes aware of the breach and sets no separate deadline of its own. The data owner then carries the primary responsibility to notify affected consumers and the Attorney General.
Government Entities
Nebraska's breach notification law applies to state and local government entities that maintain personal information about Nebraska residents. Government agencies have the same notification obligations as private businesses.
What Qualifies as a Breach
Under Neb. Rev. Stat. 87-802, a "breach of the security of the system" means the unauthorized acquisition of unencrypted computerized data that compromises the security, confidentiality, or integrity of personal information maintained by the individual or commercial entity.
Good Faith Exception
A good faith acquisition of personal information by an employee or agent of the individual or commercial entity does not constitute a breach, provided the personal information is not used for an unauthorized purpose or subject to further unauthorized disclosure.
Nebraska law also excludes from the definition of breach any acquisition of personal information made pursuant to a search warrant, subpoena, or other court order, or pursuant to a subpoena or order of a state agency.
Encryption Safe Harbor
Nebraska provides a clear safe harbor for encrypted data. A breach does not trigger notification requirements if the personal information was encrypted, and the encryption key or other means to decipher the information was not also acquired. If the encryption key was compromised along with the data, the safe harbor does not apply.
Risk of Harm Analysis
Nebraska law includes a risk assessment component. After discovering a possible breach, the entity must conduct a reasonable and prompt investigation to determine the likelihood that personal information has been or will be used for an unauthorized purpose. Notification is required only if the investigation determines that the use of the information for an unauthorized purpose has occurred or is reasonably likely to occur.
Personal Information That Triggers Notification
Nebraska's definition of personal information is one of the broadest among U.S. states. Under Neb. Rev. Stat. 87-802, personal information means a Nebraska resident's first name or first initial and last name combined with any one or more of the following data elements:
- Social Security number
- Driver's license number or state identification card number
- Account number or credit or debit card number combined with any required security code, access code, or password that would permit access to the account
- Unique electronic identification number or routing code combined with any required security code, access code, or password
- Biometric data (fingerprint, voice print, retina or iris image, or other unique physical representation)
- Username or email address combined with a password or security question and answer that would permit access to an online account
The inclusion of biometric data and username/password combinations places Nebraska among the states with the most comprehensive definitions of protected personal information.

Personal information does not include publicly available information that is lawfully made available to the general public from federal, state, or local government records.
Notification Timeline
Nebraska requires notification "as soon as possible and without unreasonable delay" under Neb. Rev. Stat. 87-803. The state does not impose a specific day count, giving entities flexibility to investigate before notifying.
When Delay Is Permitted
Delay in notification is reasonable if it is necessary to:
- Determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system
- Comply with a request from law enforcement that notification may impede a criminal investigation
When a delay occurs for law enforcement purposes, notification must be made as soon as possible after law enforcement determines disclosure no longer compromises the investigation.
Who Must Be Notified
Affected Individuals
Every Nebraska resident whose unencrypted personal information was or is reasonably believed to have been acquired by an unauthorized person must be notified. Nebraska's statute does not prescribe the content of the notice to residents, but a well-drafted notice conventionally includes:
- A description of the incident in general terms
- The type of personal information that was subject to the breach
- The telephone number, address, and website of the entity providing notice
- The toll-free telephone numbers, addresses, and websites of the major consumer reporting agencies
- The toll-free telephone number, address, and website of the Federal Trade Commission
- A statement advising the individual to remain vigilant by reviewing account statements and monitoring credit reports
Nebraska Attorney General
The Nebraska Attorney General must be notified no later than the time affected individuals are notified, under Neb. Rev. Stat. 87-803(2). The statute fixes that deadline but does not prescribe what the notice to the Attorney General must contain, and no Nebraska rule supplies a required form or format. In practice, entities commonly provide:
- A description of the nature of the breach
- The number of Nebraska residents affected
- The steps the entity has taken in response
- A copy of the notification sent to affected individuals
Consumer Reporting Agencies
Nebraska's breach notification law does not require notice to consumer reporting agencies. The Financial Data Protection and Consumer Notification of Data Security Breach Act imposes only two notification duties: notice to affected Nebraska residents and notice to the Attorney General.
How to Provide Notification
Nebraska permits the following notification methods:
- Written notice sent by mail to the last known address of the individual
- Electronic notice if the entity's primary means of communication with the individual is by electronic means, consistent with the E-SIGN Act (15 U.S.C. 7001)
- Telephone notification
Substitute Notice
Substitute notice is available when:
- The cost of notification would exceed $75,000
- The affected class exceeds 100,000 Nebraska residents
- The entity does not have sufficient contact information
Substitute notice must consist of all of the following:
- Email notice to individuals for whom the entity has an email address
- Conspicuous posting of the notice on the entity's website
- Notification to major statewide media outlets
Small-Business Substitute Notice
Nebraska also provides a separate, easier-to-reach substitute notice path for small entities. An individual or commercial entity with ten employees or fewer that demonstrates the cost of notification will exceed $10,000 may use substitute notice consisting of all of the following:
- Email notice to individuals for whom the entity has an email address
- A paid newspaper advertisement covering at least one-quarter of a page, published at least once a week for three consecutive weeks
- Conspicuous posting of the notice on the entity's website
- Notification to major media outlets in the entity's local geographic area
Because the small-business path triggers at a $10,000 cost threshold rather than $75,000, small Nebraska businesses can qualify for substitute notice far more easily than the general thresholds alone suggest.
Class-Action Liability Shield for Cybersecurity Events
Nebraska does not have a NIST- or ISO-framework-based affirmative defense against tort claims. What it does have is narrower: under Neb. Rev. Stat. 87-1201, enacted by LB241 (2025), a private entity is not liable in a class action resulting from a cybersecurity event unless the event was caused by willful, wanton, or gross negligence on the entity's part.
A "cybersecurity event" is defined as unauthorized access to, or disruption or misuse of, an information system or nonpublic information. The shield applies only to class actions; it does not bar individual lawsuits, and it does not limit the Attorney General's regulatory enforcement authority under the breach notification law or the Consumer Protection Act.

Enforcement and Penalties
Nebraska's breach notification law is enforced by the Nebraska Attorney General. For a violation of the notification-timing statute (Neb. Rev. Stat. 87-803), the Attorney General may issue subpoenas and recover direct economic damages for each affected Nebraska resident injured, under Neb. Rev. Stat. 87-806. The statute sets no dollar cap on this remedy.
A separate requirement, the reasonable-security-procedures duty under Neb. Rev. Stat. 87-808, is treated as a violation of the Consumer Protection Act and carries a civil penalty of up to $2,000 per violation under Neb. Rev. Stat. 59-1614. That penalty applies to a failure to maintain reasonable security procedures, not to a delay in notifying residents.
There is no private right of action for breach notification violations. Only the Attorney General can bring enforcement actions.

Exemptions and Deemed Compliance
Nebraska does not exempt federally regulated entities from its breach notification requirements. Instead, Neb. Rev. Stat. 87-804 lets an entity satisfy the statute by following its own procedures, and only on the condition that the required notices still go out:
- Entities with their own notice procedures. Under 87-804(1), an entity whose information security policy includes notice procedures otherwise consistent with the timing requirements of 87-803 is deemed in compliance if it notifies affected Nebraska residents and the Attorney General in accordance with those procedures.
- Entities regulated by state or federal law. Under 87-804(2), an entity that maintains breach procedures under the laws, rules, regulations, guidances, or guidelines of its primary or functional state or federal regulator, such as a GLBA-regulated financial institution or a HIPAA-covered entity, is deemed in compliance with 87-803 if it notifies affected Nebraska residents and the Attorney General in accordance with those maintained procedures.
The practical consequence is that notice to the Nebraska Attorney General is still owed. A regulated entity that notifies its federal regulator and its customers but skips the Nebraska Attorney General does not qualify for deemed compliance under 87-804.
A separate provision, Neb. Rev. Stat. 87-808(3), addresses the reasonable-security duty rather than notice. An entity satisfies that duty by complying with a state or federal law that provides greater protection to personal information than 87-808 provides, or with the regulations promulgated under Title V of the Gramm-Leach-Bliley Act or HIPAA if it is subject to those acts.
This article provides general legal information about Nebraska data privacy laws and breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in Nebraska for guidance specific to your situation.
More Nebraska Laws
Frequently Asked Questions
How long does a business have to notify Nebraska residents of a data breach?
Nebraska law requires notification 'as soon as possible and without unreasonable delay' but does not set a specific day deadline. A delay is permitted to determine the scope of the breach and restore system integrity, or to comply with a law enforcement request. The entity must also complete a reasonable and prompt investigation to determine whether the information is likely to be used for an unauthorized purpose before notification is required.
Does Nebraska require businesses to notify the Attorney General after a data breach?
Yes. The Nebraska Attorney General must be notified no later than the time affected individuals are notified, under Neb. Rev. Stat. 87-803(2). The statute fixes that deadline but does not prescribe what the notice to the Attorney General must contain, though entities commonly describe the breach, give the number of Nebraska residents affected and the steps taken in response, and enclose a copy of the consumer notice. Nebraska's law does not require notice to consumer reporting agencies; the only two required recipients are affected residents and the Attorney General.
Does Nebraska's breach notification law cover biometric data?
Yes. Nebraska is one of the states that includes biometric data in its definition of personal information. Fingerprints, voice prints, retina or iris images, and other unique physical representations of biometric data are all covered. A breach of biometric data combined with a name triggers the full notification requirements.
Does Nebraska have a cybersecurity liability shield for businesses?
Not the framework-based affirmative defense some other states use. Nebraska's law (Neb. Rev. Stat. 87-1201, enacted by LB241 in 2025) instead shields private entities from class-action liability for a cybersecurity event unless the event was caused by willful, wanton, or gross negligence. It does not apply to individual lawsuits or to Attorney General enforcement.
Can individuals sue for a breach notification violation in Nebraska?
No. Nebraska's breach notification law does not create a private right of action. Only the Nebraska Attorney General can enforce the notification-timing statute (87-803), whose remedy is subpoenas and recovery of direct economic damages for each affected resident with no stated dollar cap. A separate violation of the security-practices requirement (87-808) is treated as a Consumer Protection Act violation and carries a civil penalty of up to $2,000 per violation. Individuals may pursue common law claims such as negligence; Nebraska's class-action liability shield (Neb. Rev. Stat. 87-1201) may limit exposure to class claims arising from a cybersecurity event, but it does not affect individual suits.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the Attorney General notice section to reflect that Neb. Rev. Stat. 87-803 sets the notification deadline but prescribes no required contents, fixed a misquoted timing phrase in the third-party data maintainer duty, and rewrote the exemptions section to explain that federally regulated entities are deemed compliant only if they still notify both affected Nebraska residents and the Attorney General.
Corrected the enforcement and penalties section: Nebraska's Attorney General recovers direct economic damages for notification-timing violations with no stated dollar cap (not a $25,000 Consumer Protection Act penalty, which applies only to a separate security-practices violation and caps at $2,000). Removed an incorrect claim that Nebraska requires notice to consumer reporting agencies, added the small-business substitute-notice path, and tightened the biometric-data and good-faith-exception descriptions to match the statute.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Corrected the breach-notification law's mischaracterized AG-notice timing ('at the same time' to the statute's actual 'not later than' deadline), removed an added 'materially' qualifier from the statutory breach definition, and replaced a fabricated NIST/ISO-framework 'cybersecurity safe harbor' (falsely attributed to Neb. Rev. Stat. 87-806) with Nebraska's real, narrower liability protection: the LB241 (2025) class-action shield at Neb. Rev. Stat. 87-1201.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Nebraska Revised Statutes, Chapter 87: TRADE PRACTICES
§ 87-803Breach of security; investigation; notice to resident; notice to Attorney GeneralIn force
(1) An individual or a commercial entity that conducts business in Nebraska and that owns or licenses computerized data that includes personal information about a resident of Nebraska shall, when it becomes aware of a breach of the security of the system, conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal information has been or will be used for an unauthorized purpose. If the investigation determines that the use of information about a Nebraska resident for an unauthorized purpose has occurred or is reasonably likely to occur, the individual or commercial entity shall give notice to the affected Nebraska resident. Notice shall be made as soon as possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the computerized data system.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at nebraskalegislature.gov
§ 87-802Terms, definedIn forcecited in 2 of our articles
For purposes of the Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006: (1) Breach of the security of the system means the unauthorized acquisition of unencrypted computerized data that compromises the security, confidentiality, or integrity of personal information maintained by an individual or a commercial entity. Good faith acquisition of personal information by an employee or agent of an individual or a commercial entity for the purposes of the individual or the commercial entity is not a breach of the security of the system if the personal information is not used or subject to further unauthorized disclosure.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at nebraskalegislature.gov
Also relied on in: Nebraska Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 87-801Act, how citedIn forcecited in 2 of our articles
Sections 87-801 to 87-808 shall be known and may be cited as the Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at nebraskalegislature.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2019
Opinions citing this section in our collection:
- Prime Foods for Processing and Trading v. Greater Omaha Packing Co., Inc. (District Court, D. Nebraska 2019)“…of Data Security Breach Act of 2006 (Data Protection Act), Neb. Rev. Stat. § 87-801 et seq.,5 and agree those statutes do n…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 87-1201Cybersecurity event; liability of private entityIn force
(1) For purposes of this section: (a) Cybersecurity event means an event resulting in unauthorized access to, or disruption or misuse of, an information system or nonpublic information stored on an information system; (b) Information system means: (i) A discrete set of electronic information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of electronic nonpublic information; or (ii) A specialized system, including an industrial or process control system, a telephone switching and private branch exchange system, and an environmental control system; (c) Nonpublic information means information that is not publicly available and concerns a person that, because of a name, number, personal mark, or other identifier, can be used to identify such person, in combination with the following: (i) A social security number; (ii) A driver's license number or state identification card number; (iii) A financial account number or credit or debit card number; (iv) A security code, access code, or password that would permit access to such person's financial accounts; or (v) Any biometric record; (d) Private entity means a…
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at nebraskalegislature.gov
United States Code Title 15
§ 7001General rule of validityIn forcecited in 18 of our articles
Notwithstanding any statute, regulation, or other rule of law (other than this subchapter and subchapter II), with respect to any transaction in or affecting interstate or foreign commerce— a signature, contract, or other record relating to such transaction may not be denied legal effect, validity, or enforceability solely because it is in electronic form; and a contract relating to such transaction may not be denied legal effect, validity, or enforceability solely because an electronic signature or electronic record was used in its formation. This subchapter does not— limit, alter, or otherwise affect any requirement imposed by a statute, regulation, or rule of law relating to the rights and obligations of persons under such statute, regulation, or rule of law other than a requirement that contracts or other records be written, signed, or in nonelectronic form; or require any person to agree to use or accept electronic records or electronic signatures, other than a governmental agency with respect to a record other than a contract to which it is a party.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 132 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Metropolitan Regional Information Systems v. American Home Realty Network (2012) applied 15 U.S.C. 7001(a) to hold an electronic assignment process satisfied the signed writing requirement of Copyright Act 204(a). Blatt v. Capital One Auto Finance (2017) held 7001(c) disclosures were not required where the record was delivered on paper.
Opinions citing this section in our collection:
- Metropolitan Regional Information Systems, Inc. v. American Home Realty Network, Inc. (District Court, D. Maryland 2012, 904 F. Supp. 2d 530)✓Subscribers assigned photo copyrights to a real estate database by uploading images under online terms of use; the court relied on E-SIGN, 15 U.S.C. section 7001, to hold those electronic assignments met the Copyright Act signed-writing rule, and denied reconsideration.
- Cutrone v. Mortgage Electronic Registration Systems, Inc. (District Court, E.D. New York 2013, 981 F. Supp. 2d 144)✓Homeowners sued MERS in state court over a second mortgage recording tax on an E-Sign mortgage; MERS removed under 15 U.S.C. section 7001, but the court held that statute gives no private right of action and at most a federal defense, which cannot support removal, and remanded.
- Blatt v. Capital One Auto Finance, Inc. (District Court, M.D. Tennessee 2017, 237 F. Supp. 3d 688)“…legal effect ..solely because it is in electronic form[.]” 15 U.S.C. § 7001 (a)(1).. Furthermore, it mandates that…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Mississippi Data Breach Notification Laws: Reporting Rules & Timelines (2026), Mississippi Data Privacy Laws: Breach Notification & Consumer Rights (2026), Montana Data Privacy Laws: MCDPA Consumer Rights Guide (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Neb. Rev. Stat. 87-801 et seq. - Financial Data Protection Act(nebraskalegislature.gov).gov
- Neb. Rev. Stat. 87-802 - Definitions(nebraskalegislature.gov).gov
- Neb. Rev. Stat. 87-803 - Notification Requirements(nebraskalegislature.gov).gov
- Neb. Rev. Stat. 87-1201, Cybersecurity event; liability of private entity(nebraskalegislature.gov).gov
- Nebraska Attorney General(ago.nebraska.gov).gov
- Neb. Rev. Stat. 87-804, Compliance with notice requirements; manner(nebraskalegislature.gov)
- Neb. Rev. Stat. 87-808, Security procedures and practices; disclosure of computerized data; contract provisions; compliance(nebraskalegislature.gov)