Nevada
Nevada Data Privacy Laws: SB 220 & Consumer Rights Guide (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 22 primary sources cited on this page. How we verify our legal content

Nevada does not have a comprehensive data privacy law, but NRS Chapter 603A gives residents layered protections: SB 220 (NRS 603A.300) grants the right to opt out of online data sales, NRS 603A.220 requires breach notification, and SB 370 (NRS 603A.400) mandates consent before collecting consumer health data.
Nevada has built a layered framework of data privacy protections through NRS Chapter 603A. The state does not have a single comprehensive privacy act covering all personal data, but its combination of targeted statutes covers online data sales, data security, breach notification, consumer health information, payment card protection, and insurance data security.
This guide covers every major Nevada data privacy statute currently in effect, the rights these laws give you as a consumer, the obligations they impose on businesses, and the federal laws that apply regardless of state action.
Nevada's approach differs from comprehensive-law states like California, Virginia, and Colorado in an important way: protections are narrower and more targeted, but they apply to businesses of all sizes. The opt-out right under SB 220 carries no revenue threshold and no traffic minimum, so any operator with a commercial website collecting Nevada resident data must honor an opt-out request. The separate online-notice duty in NRS 603A.340 is the one place Nevada exempts small in-state operators.
NRS Chapter 603A: Nevada's Core Data Privacy Framework
All of Nevada's principal data privacy protections are housed in Chapter 603A of the Nevada Revised Statutes, titled "Security and Privacy of Personal Information." The chapter was built up over multiple legislative sessions since 2005, with major additions in 2019, 2021, and 2023.
The chapter covers three broad areas. NRS 603A.010 through 603A.290 address data security and breach notification. NRS 603A.300 through 603A.360 address the online privacy opt-out right. NRS 603A.400 through 603A.550 address consumer health data privacy.
Each area carries its own definitions, obligations, and enforcement mechanisms.
Senate Bill 220: The Right to Opt Out of Data Sales
Nevada's Senate Bill 220 was signed in May 2019 and took effect on October 1, 2019. It made Nevada the first state to enact an online privacy opt-out law.
SB 220 is codified in NRS 603A.300 through 603A.360. It grants Nevada consumers a specific right: the ability to direct online businesses not to sell their personally identifiable information.

Who the Law Covers
SB 220 applies to "operators" under NRS 603A.330: persons who own or operate a commercial internet website or online service, collect and maintain covered information from Nevada residents who use or visit the website or service, and have a sufficient constitutional nexus with Nevada.
This definition is intentionally broad. Any commercial website that collects personal data from Nevada residents and has a constitutional connection to the state must comply. Unlike the CCPA, the opt-out duty in NRS 603A.345 sets no revenue threshold and no minimum data-processing volume.
One narrow exemption does exist, and it reaches only the separate notice requirement. Under NRS 603A.340(2), the notice duty does not apply to an operator who is located in Nevada, whose revenue is derived primarily from a source other than the sale or lease of goods, services or credit on internet websites or online services, and whose website or online service has fewer than 20,000 unique visitors per year. All three conditions must be met, and an operator that meets them still has to honor opt-out requests.
What Counts as Covered Information
"Covered information" under NRS 603A.320 means any personally identifiable information collected through an internet website or online service and maintained in accessible form. This includes name, home address, email address, telephone number, Social Security number, and any other information maintained in combination with an identifier that makes it personally identifiable.
What Counts as a Sale
NRS 603A.333 defines "sale" as the exchange of covered information for monetary consideration by an operator or data broker to another person. The original 2019 text also required that the recipient take the information in order to license or sell it. The 2021 amendments deleted that clause, so an exchange for money now counts regardless of what the recipient does with the data afterward.
The definition still turns on money. Data exchanges for non-monetary benefits, such as analytics partnerships or improved services, fall outside the opt-out right. The statute separately excludes disclosures to a processor acting on the operator's behalf, disclosures to a person with whom the consumer has a direct relationship for a product or service the consumer requested, disclosures consistent with the consumer's reasonable expectations, disclosures to an affiliate, and transfers of covered information as an asset in a merger, acquisition, or bankruptcy.
How to Exercise the Opt-Out Right
Under NRS 603A.345, each operator must establish a designated request address (email, toll-free number, or web page) where consumers can submit verified opt-out requests. Once a valid request is received, the operator must stop selling that consumer's data and respond within 60 days. A 30-day extension is available if the operator notifies the consumer.
Exemptions
Financial institutions subject to the Gramm-Leach-Bliley Act and entities subject to HIPAA are exempt from SB 220's opt-out provisions. Information regulated by the Fair Credit Reporting Act is also carved out.
SB 260: Extending Coverage to Data Brokers
In 2021, Senate Bill 260 extended the opt-out right to data brokers. Before SB 260, the law applied only to operators collecting data through their own consumer-facing websites. SB 260 added a category covering entities that collect, aggregate, or sell consumer data without operating a consumer-facing site.
SB 260 also refined the notice requirements under NRS 603A.340. Operators must make information available, in a manner reasonably calculated to be accessible by consumers, disclosing what covered information they collect and how they use it.
The 2021 amendments broadened the definition of sale in NRS 603A.333 as well, deleting the original requirement that the recipient acquire the covered information in order to license or sell it.
The 2021 amendments preserved the 30-day cure period for first-time violations.
Data Security Requirements Under NRS 603A
Nevada's data security obligations apply to any "data collector" that maintains records containing personal information of Nevada residents.
Reasonable Security Measures
NRS 603A.210 requires every data collector to implement and maintain reasonable security measures to protect records from unauthorized access, acquisition, destruction, use, modification, or disclosure. The statute does not prescribe specific technical standards. Reasonableness is assessed case by case based on the nature, scope, and sensitivity of the data held.
Encryption and PCI Compliance
NRS 603A.215 imposes more specific requirements in two areas.
For businesses that accept payment cards, the law requires compliance with the current Payment Card Industry Data Security Standard (PCI DSS). Nevada was one of the first states to mandate PCI DSS compliance by statute.

For electronic transfers of personal information outside a secure system, data collectors must use encryption technology meeting National Institute of Standards and Technology (NIST) Federal Information Processing Standards (FIPS) or equivalent established standards. Appropriate cryptographic key management is also required.
Destruction of Personal Information
When a data collector no longer needs personal information, Nevada law requires reasonable measures to ensure the destruction of those records, such as shredding physical records or electronically erasing digital data.
Data Breach Notification: NRS 603A.220
Nevada's breach notification requirements in NRS 603A.220 apply to any data collector that owns or licenses computerized data containing personal information.
What Triggers Notification
A "breach of the security of the system data" is the unauthorized acquisition of computerized data that materially compromises the security, confidentiality, or integrity of personal information. Not every unauthorized access triggers the obligation. The compromise must be significant enough to meaningfully affect the data's security or integrity.
Personal Information for Breach Purposes
For breach notification, NRS 603A.040 defines personal information as a natural person's first name or first initial and last name combined with any of the following unencrypted data elements: Social Security number; driver's license, driver authorization card, or identification card number; account, credit card, or debit card number combined with a required security code; or medical or health insurance identification number.
Notification Timeline and Methods
Nevada does not impose a specific day count. NRS 603A.220 requires disclosure "in the most expedient time possible and without unreasonable delay." Two exceptions allow delay: legitimate law enforcement needs, and measures necessary to determine the breach scope and restore system integrity.
Notification may be written, electronic (with prior consumer consent), or substitute notice when direct notice is impractical because the affected population exceeds 500,000 or the cost exceeds $250,000. Substitute notice requires email where available, prominent website posting, and notification to major statewide media.
Penalties for Notification Failures
A violation of the breach notification provisions constitutes a deceptive trade practice under NRS 598.0903-598.0999, exposing violators to civil penalties and injunctive relief. Separately, NRS 603A.270 gives a data collector that already provided the required notification its own remedy: it may sue the party that unlawfully obtained or benefited from the breached data, recovering reasonable costs of notification, attorney fees, and punitive damages from that wrongdoer.
Consumer Health Data Privacy: SB 370
Nevada's Senate Bill 370, passed in 2023 and effective March 31, 2024, added NRS 603A.400 through 603A.550. This law creates one of the strongest consumer health data frameworks in the country, modeled closely on Washington's My Health My Data Act.

Who Must Comply
SB 370 applies to "regulated entities": any entity that conducts business in Nevada or produces or provides products or services targeted to Nevada residents, and collects, processes, shares, or sells consumer health data. The law reaches health apps, fitness trackers, fertility monitors, mental health platforms, and any business handling health-related consumer data outside HIPAA's scope.
What Qualifies as Consumer Health Data
NRS 603A.430 defines consumer health data broadly as information linked or reasonably capable of being linked to a consumer that identifies that consumer's past, present, or future health status. Covered categories include health conditions and diagnoses, social or psychological interventions, surgeries and procedures, medication acquisition and usage, bodily functions and vital signs, reproductive or sexual health care information, gender-affirming care information, and biometric or genetic data related to health.
Consent and Authorization Requirements
SB 370 generally prohibits collecting and sharing consumer health data without the consumer's affirmative, voluntary consent. The sale of consumer health data requires written authorization from the consumer, a higher standard than simple consent. Businesses cannot collect health data first and wait for consumers to object. Permission must come before collection begins.
Geofencing Restrictions
SB 370 prohibits implementing a geofence within 1,750 feet of any medical facility, facility for the dependent, or other entity providing in-person healthcare services or products for the purpose of identifying or tracking consumers seeking care, collecting their health data, or sending them health-related notifications or advertisements.
This provision directly addresses concerns about location-based tracking near reproductive health clinics.
Privacy Policy Requirements
Regulated entities must develop, maintain, and post a consumer health data privacy policy disclosing the categories of consumer health data collected and the sources, the categories shared and the recipients, and how data will be used and processed.
Consumer Rights Under SB 370
Consumers may request confirmation of whether a regulated entity is collecting, sharing, or selling their consumer health data. If collection is occurring, consumers may request a list of all third parties who received their data. Regulated entities must respond within 45 days of authenticating the request.
Data Security for Health Data
Regulated entities must limit employee and processor access to consumer health data and establish, implement, and maintain security policies protecting its confidentiality and integrity.
Nevada Insurance Data Security Act
Nevada's Insurance Data Security Act, codified in NRS Chapter 679C, requires insurance licensees to develop, implement, and maintain a comprehensive written information security program based on the licensee's risk assessment. The law is modeled on the National Association of Insurance Commissioners (NAIC) Insurance Data Security Model Law.
Covered licensees must also establish and maintain a cybersecurity incident response plan. Upon discovering a cybersecurity event that affects 250 or more Nevada residents, the licensee must notify the Nevada Division of Insurance within 72 hours. Notification to affected consumers follows in the most expedient time possible. The Insurance Commissioner can examine and investigate licensees for compliance and may impose administrative penalties for violations.
Pending Legislation: Nevada Consumer Privacy Act
During the 2023 and 2025 legislative sessions, Nevada considered but did not pass a comprehensive consumer privacy bill. As of May 2026, no comprehensive Nevada Consumer Privacy Act has been enacted. Legislation modeled on the Virginia Consumer Data Protection Act framework has been introduced and failed.
Nevada residents seeking broader access, correction, and deletion rights must rely on California's CCPA where applicable (for businesses also covered by CCPA), federal law, or contractual rights.
Watch the Nevada Legislature's bill search for updates on any reintroduced privacy legislation.
Nevada and the CCPA: Key Differences
Nevada's SB 220 and California's CCPA are frequently compared because both address the sale of consumer data. The differences are significant.
Scope of coverage: the CCPA applies to all personal information regardless of collection channel. SB 220 covers only personally identifiable information collected through an internet website or online service. Offline data collection is outside SB 220's reach.
Business size thresholds: the CCPA applies only to businesses meeting specific revenue or data-volume thresholds. Nevada's opt-out right applies to all operators regardless of size. The only size-based carve-out in the chapter is the narrow small-operator exemption from the notice duty in NRS 603A.340(2).
Consumer rights: the CCPA grants consumers rights to access, delete, and opt out of data sales. SB 220 provides only the opt-out right.
Definition of sale: California defines sale to include exchanges for monetary or other valuable consideration. Nevada limits the definition to monetary consideration only.
Enforcement: the CCPA allows fines of $2,500 per unintentional violation and $7,500 per intentional violation. Nevada's SB 220 provisions carry civil penalties up to $5,000 per violation.
Private right of action: the CCPA includes a limited private right of action for data breaches. SB 220 does not create any private right of action.
Federal Privacy Laws and Nevada
Several federal statutes operate alongside Nevada's state-level protections. These laws generally do not preempt Nevada's requirements unless state law directly conflicts with federal provisions.
TAKE IT DOWN Act (Pub. L. 119-12). Congress signed this law on May 19, 2025. It immediately criminalized the nonconsensual publication of intimate images, including AI-generated deepfake imagery. Online platforms had one year to establish notice-and-removal processes. The FTC began enforcing platform compliance obligations on May 19, 2026. A covered platform must remove content subject to a valid takedown request, along with known identical copies, within 48 hours.
HIPAA. The Health Insurance Portability and Accountability Act governs health information held by covered entities and their business associates. HIPAA does not cover many entities that fall under Nevada's SB 370, which is why SB 370 was necessary.
GLBA. The Gramm-Leach-Bliley Act requires financial institutions to explain their information-sharing practices and safeguard sensitive data. Financial institutions and their affiliates are exempt from SB 220's opt-out provisions.
COPPA. The Children's Online Privacy Protection Act restricts the online collection of personal information from children under 13. COPPA operates independently of Nevada's data privacy laws.
FCRA. The Fair Credit Reporting Act regulates the collection, dissemination, and use of consumer credit information. Information regulated by the FCRA is carved out from SB 220's coverage.
FTC Act Section 5. The Federal Trade Commission can pursue unfair or deceptive acts or practices in data security and privacy. The FTC has authority regardless of whether a state law enforcement action is pending.
APRA. The American Privacy Rights Act, a bipartisan federal comprehensive privacy bill, was introduced in April 2024 but did not pass before the 118th Congress expired in January 2025. As of May 2026, no equivalent bill has been enacted in the 119th Congress. Nevada residents should not expect federal comprehensive privacy legislation in the near term.
Enforcement and Penalties
Nevada's enforcement framework varies by statute section.
SB 220 Enforcement (NRS 603A.300-.360)
The Nevada Attorney General has exclusive enforcement authority over the online privacy opt-out provisions. Civil penalties up to $5,000 per violation may be imposed by a district court. There is no private right of action. First-time violators receive a 30-day cure period.
Breach Notification Enforcement (NRS 603A.010-.290)
Violations constitute deceptive trade practices under NRS Chapter 598. The Attorney General and district attorneys can pursue injunctions, civil penalties, and consumer restitution.
SB 370 Enforcement (NRS 603A.400-.550)
The consumer health data provisions are enforceable solely by the Attorney General. SB 370 does not create a private right of action.
Notable Enforcement Actions
The Nevada Attorney General's office has participated in major multistate data breach enforcement actions. In 2019, the office joined 49 other attorneys general in a $600 million settlement with Equifax over the 2017 data breach affecting 147 million Americans. In 2022, the office joined a $1.25 million settlement with Carnival Cruise Line over a 2019 data breach.
No formal public AG enforcement actions under SB 370 have been announced as of May 2026.
Compliance Checklist for Businesses
Businesses operating in Nevada or handling data from Nevada residents should address all of the following.
SB 220 compliance: Establish a designated request address where consumers can submit opt-out requests. Respond to verified requests within 60 days. Post a notice disclosing what covered information you collect and how you use it, unless you meet all three conditions of the NRS 603A.340(2) exemption for small Nevada-based operators. Stop selling covered information about any consumer who submits a valid opt-out request.
Data security compliance: Implement and maintain reasonable security measures. If you accept payment cards, comply with the current PCI DSS. Use NIST-compliant encryption for electronic transfers. Maintain proper key management. Use reasonable destruction methods for records no longer needed.
Breach notification compliance: Develop and test an incident response plan. Notify affected Nevada residents in the most expedient time possible after discovering a breach. Notify data owners if you maintain personal information you do not own. Use approved notification methods.

Consumer health data compliance (if applicable): Obtain affirmative consent before collecting or sharing consumer health data. Obtain written authorization before selling consumer health data. Post a consumer health data privacy policy. Respond to consumer requests within 45 days. Do not implement geofences within 1,750 feet of healthcare facilities. Limit employee access and maintain security policies.
Insurance data security compliance (if applicable): If you hold a Nevada insurance license, implement a written information security program, maintain a cybersecurity incident response plan, and notify the Division of Insurance within 72 hours of a cybersecurity event affecting 250 or more Nevada residents.
How Nevada Residents Exercise Their Rights
To opt out of data sales under SB 220, locate the operator's designated request address, which may be labeled "Do Not Sell My Personal Information" or similar language. Submit a verified request. The operator must respond within 60 days.
To request confirmation or deletion of consumer health data under SB 370, contact the regulated entity directly. It must respond within 45 days of authenticating your request.
To report a business you believe has violated Nevada's data privacy laws, file a complaint with the Nevada Attorney General's Bureau of Consumer Protection. For potential TAKE IT DOWN Act violations by platforms, file a report with the FTC.
Nevada's recording laws also intersect with data privacy for audio and video surveillance. Nevada is a hybrid consent state: one-party consent for in-person conversations under NRS 200.650, but all-party consent for phone calls, video calls, and text messages under NRS 200.620, per Lane v. Allstate.
More Nevada Laws
Frequently Asked Questions
Does Nevada have a comprehensive data privacy law like the CCPA?
Nevada does not have a single comprehensive consumer privacy law as of May 2026. Instead, the state uses a layered approach through NRS Chapter 603A, which includes SB 220 for an online data-sale opt-out right, general data security and breach notification requirements, and SB 370 for consumer health data. Unlike the CCPA, Nevada's laws do not grant consumers broad rights to access or delete all personal data held by businesses.
How do I opt out of a company selling my personal data in Nevada?
Under NRS 603A.345, you can submit a verified request to any operator that collects your personally identifiable information through its website or online service. The operator must provide a designated request address, which may be an email address, a toll-free phone number, or a page on its website. Once the operator receives your request, it has 60 days to respond and must stop selling your data. There is no cost to submit a request.
What should I do if my personal data is breached by a Nevada business?
If you receive a breach notification, immediately change passwords for compromised accounts and monitor your financial statements and credit reports. You can place a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, TransUnion) at no cost. If you believe a business failed to notify you as required, file a complaint with the Nevada Attorney General's Bureau of Consumer Protection at ag.nv.gov.
Does Nevada's health data privacy law apply to my fitness tracker or health app?
Yes. SB 370 applies to any regulated entity that collects consumer health data, even if the entity is not a traditional healthcare provider covered by HIPAA. If a fitness tracker, mental health app, or wellness platform collects data about your health conditions, medications, vital signs, or reproductive health and does business in Nevada or targets Nevada residents, it must comply with SB 370's consent and privacy requirements.
Can I sue a company in Nevada for violating my data privacy rights?
Nevada's SB 220 and SB 370 do not create a private right of action. Only the Nevada Attorney General can enforce those provisions. Data breach notification violations are treated as deceptive trade practices under NRS Chapter 598, which may support civil actions by the AG or district attorneys. If you believe your rights have been violated, file a complaint with the Nevada Attorney General.
What is the Nevada Insurance Data Security Act and who does it cover?
The Nevada Insurance Data Security Act (NRS Chapter 679C) applies to entities that hold an insurance license issued by Nevada, including insurers, agents, brokers, and other licensees. It requires covered entities to develop and maintain a written information security program, establish a cybersecurity incident response plan, and notify the Nevada Division of Insurance within 72 hours of a cybersecurity event affecting 250 or more Nevada residents.
What does the TAKE IT DOWN Act mean for Nevada residents?
The TAKE IT DOWN Act (Pub. L. 119-12), signed May 19, 2025, is a federal law that immediately criminalized the nonconsensual sharing of intimate images, including AI-generated deepfakes. Beginning May 19, 2026, covered online platforms must remove such images within 48 hours of a valid takedown request, and the FTC enforces that obligation. Nevada residents can submit takedown requests directly to platforms and report noncompliance to the FTC at reportfraud.ftc.gov.
Does Nevada recognize Global Privacy Control or a Universal Opt-Out Mechanism?
No. Nevada's SB 220 does not require operators to recognize Global Privacy Control (GPC) signals or any other Universal Opt-Out Mechanism. To exercise Nevada's opt-out right, consumers must submit a verified request through the operator's designated request address. This contrasts with Colorado, Connecticut, and Oregon, which require businesses to honor GPC browser signals as a valid opt-out.
Updates
Corrected the definition of sale to the current NRS 603A.333 text after the 2021 amendments removed the license-or-resell requirement, and qualified the statement that SB 220 has no size threshold by adding the NRS 603A.340(2) notice exemption for small Nevada-based operators with fewer than 20,000 annual visitors.
Corrected the SB 370 consumer health data statute range (NRS 603A.400-.550, not -.920) in four places, fixed the sale-definition citation (NRS 603A.333, not .335), clarified that NRS 603A.270 lets a compliant business sue the party that stole its data rather than penalizing the business for a notification failure, and corrected the closing summary of Nevada's recording law to reflect its hybrid one-party (in-person) / all-party (phone, video, text) consent rules.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
May 2026 refresh: added Nevada Insurance Data Security Act (NRS Chapter 679C) section; added TAKE IT DOWN Act (Pub. L. 119-12, signed May 19, 2025) to federal overlay with FTC platform enforcement effective May 19, 2026; added APRA 2024-2025 status note (did not pass, not reintroduced); added pending legislation section noting no comprehensive Nevada Consumer Privacy Act as of May 2026; added NRS 200.620 wiretap cross-link; added GPC/UOOM FAQ noting Nevada does not honor browser opt-out signals; added Insurance Data Security Act FAQ; expanded FAQ from 5 to 8 questions; corrected SourcesList prop from sources= to citations=; verified the 2026 Cyber Task Force AG press release citation is live and accurate, and kept it; images updated to correct media_library JSONB format; word count approx. 3,850.
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Nevada Revised Statutes, Chapter 603A: SECURITY AND PRIVACY OF PERSONAL INFORMATION
§ 603A.345Submission of verified request to operator not to sell covered information collected by operator; response to verified request.In force
1. Each operator shall establish a designated request address through which a consumer may submit a verified request pursuant to this section. 2. A consumer may, at any time, submit a verified request through a designated request address to an operator directing the operator not to make any sale of any covered information the operator has collected or will collect about the consumer. 3. An operator that has received a verified request submitted by a consumer pursuant to subsection 2 shall not make any sale of any covered information the operator has collected or will collect about that consumer. 4. An operator shall respond to a verified request submitted by a consumer pursuant to subsection 2 within 60 days after receipt thereof. An operator may extend by not more than 30 days the period prescribed by this subsection if the operator determines that such an extension is reasonably necessary. An operator who extends the period prescribed by this subsection shall notify the consumer of such an extension.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at leg.state.nv.us
Explore the law
This article also draws on these acts and chapters (opening at their first section): Nevada Revised Statutes, Chapter 598: DECEPTIVE TRADE PRACTICES § 598.091 (“Collective mark” defined.) · Nevada Revised Statutes, Chapter 603A: SECURITY AND PRIVACY OF PERSONAL INFORMATION § 603A.010 (Definitions.)
Related law for further reading — not part of this article’s citations.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- NRS Chapter 603A - Security and Privacy of Personal Information(leg.state.nv.us).gov
- Nevada Senate Bill 220 (2019) - Enrolled Text(leg.state.nv.us).gov
- Nevada Senate Bill 260 (2021) - Enrolled Text(leg.state.nv.us).gov
- Nevada Senate Bill 370 (2023) - Enrolled Text(leg.state.nv.us).gov
- Nevada Attorney General - Senate Bill 220 Information(ag.nv.gov).gov
- Nevada Attorney General - Notice Regarding Data Breaches(ag.nv.gov).gov
- NRS 603A Compliance Checklist - Nevada Attorney General(ag.nv.gov).gov
- Nevada Attorney General - Equifax Data Breach Settlement(ag.nv.gov).gov
- Nevada Attorney General - Carnival Cruise Line Data Breach Settlement(ag.nv.gov).gov
- Nevada Attorney General - Cyber Task Force Announcement(ag.nv.gov).gov
- HIPAA - U.S. Department of Health and Human Services(hhs.gov).gov
- Gramm-Leach-Bliley Act - Federal Trade Commission(ftc.gov).gov
- COPPA Rule - Federal Trade Commission(ftc.gov).gov
- Fair Credit Reporting Act - Federal Trade Commission(ftc.gov).gov
- National Institute of Standards and Technology (NIST)(nist.gov).gov
- NRS Chapter 598 - Deceptive Trade Practices(leg.state.nv.us).gov
- Preemption and Privacy Law - Congressional Research Service(congress.gov).gov
- NRS Chapter 679C - Insurance Data Security(leg.state.nv.us).gov
- Nevada AG File a Complaint - Bureau of Consumer Protection(ag.nv.gov).gov
- TAKE IT DOWN Act - FTC Legal Library(ftc.gov).gov
- Nevada Legislature Bill Search - 83rd Session (2025)(leg.state.nv.us).gov
- FTC Report Fraud Portal(reportfraud.ftc.gov).gov
- NRS 603A.333 - Sale defined (2025 Nevada Revised Statutes)(law.justia.com)
- NRS 603A.340 - Notice regarding covered information collected by operator: contents; exception (2025 Nevada Revised Statutes)(law.justia.com)