EnglishEspañol
Nevada flag

Nevada

Nevada Data Privacy Laws: SB 220 & Consumer Rights Guide (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 22 primary sources cited on this page. How we verify our legal content

Nevada Data Privacy Laws: SB 220 & Consumer Rights Guide (2026)

Frequently Asked Questions

Does Nevada have a comprehensive data privacy law like the CCPA?

Nevada does not have a single comprehensive consumer privacy law as of May 2026. Instead, the state uses a layered approach through NRS Chapter 603A, which includes SB 220 for an online data-sale opt-out right, general data security and breach notification requirements, and SB 370 for consumer health data. Unlike the CCPA, Nevada's laws do not grant consumers broad rights to access or delete all personal data held by businesses.

How do I opt out of a company selling my personal data in Nevada?

Under NRS 603A.345, you can submit a verified request to any operator that collects your personally identifiable information through its website or online service. The operator must provide a designated request address, which may be an email address, a toll-free phone number, or a page on its website. Once the operator receives your request, it has 60 days to respond and must stop selling your data. There is no cost to submit a request.

What should I do if my personal data is breached by a Nevada business?

If you receive a breach notification, immediately change passwords for compromised accounts and monitor your financial statements and credit reports. You can place a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, TransUnion) at no cost. If you believe a business failed to notify you as required, file a complaint with the Nevada Attorney General's Bureau of Consumer Protection at ag.nv.gov.

Does Nevada's health data privacy law apply to my fitness tracker or health app?

Yes. SB 370 applies to any regulated entity that collects consumer health data, even if the entity is not a traditional healthcare provider covered by HIPAA. If a fitness tracker, mental health app, or wellness platform collects data about your health conditions, medications, vital signs, or reproductive health and does business in Nevada or targets Nevada residents, it must comply with SB 370's consent and privacy requirements.

Can I sue a company in Nevada for violating my data privacy rights?

Nevada's SB 220 and SB 370 do not create a private right of action. Only the Nevada Attorney General can enforce those provisions. Data breach notification violations are treated as deceptive trade practices under NRS Chapter 598, which may support civil actions by the AG or district attorneys. If you believe your rights have been violated, file a complaint with the Nevada Attorney General.

What is the Nevada Insurance Data Security Act and who does it cover?

The Nevada Insurance Data Security Act (NRS Chapter 679C) applies to entities that hold an insurance license issued by Nevada, including insurers, agents, brokers, and other licensees. It requires covered entities to develop and maintain a written information security program, establish a cybersecurity incident response plan, and notify the Nevada Division of Insurance within 72 hours of a cybersecurity event affecting 250 or more Nevada residents.

What does the TAKE IT DOWN Act mean for Nevada residents?

The TAKE IT DOWN Act (Pub. L. 119-12), signed May 19, 2025, is a federal law that immediately criminalized the nonconsensual sharing of intimate images, including AI-generated deepfakes. Beginning May 19, 2026, covered online platforms must remove such images within 48 hours of a valid takedown request, and the FTC enforces that obligation. Nevada residents can submit takedown requests directly to platforms and report noncompliance to the FTC at reportfraud.ftc.gov.

Does Nevada recognize Global Privacy Control or a Universal Opt-Out Mechanism?

No. Nevada's SB 220 does not require operators to recognize Global Privacy Control (GPC) signals or any other Universal Opt-Out Mechanism. To exercise Nevada's opt-out right, consumers must submit a verified request through the operator's designated request address. This contrasts with Colorado, Connecticut, and Oregon, which require businesses to honor GPC browser signals as a valid opt-out.

Updates

Corrected the definition of sale to the current NRS 603A.333 text after the 2021 amendments removed the license-or-resell requirement, and qualified the statement that SB 220 has no size threshold by adding the NRS 603A.340(2) notice exemption for small Nevada-based operators with fewer than 20,000 annual visitors.

Corrected the SB 370 consumer health data statute range (NRS 603A.400-.550, not -.920) in four places, fixed the sale-definition citation (NRS 603A.333, not .335), clarified that NRS 603A.270 lets a compliant business sue the party that stole its data rather than penalizing the business for a notification failure, and corrected the closing summary of Nevada's recording law to reflect its hybrid one-party (in-person) / all-party (phone, video, text) consent rules.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

May 2026 refresh: added Nevada Insurance Data Security Act (NRS Chapter 679C) section; added TAKE IT DOWN Act (Pub. L. 119-12, signed May 19, 2025) to federal overlay with FTC platform enforcement effective May 19, 2026; added APRA 2024-2025 status note (did not pass, not reintroduced); added pending legislation section noting no comprehensive Nevada Consumer Privacy Act as of May 2026; added NRS 200.620 wiretap cross-link; added GPC/UOOM FAQ noting Nevada does not honor browser opt-out signals; added Insurance Data Security Act FAQ; expanded FAQ from 5 to 8 questions; corrected SourcesList prop from sources= to citations=; verified the 2026 Cyber Task Force AG press release citation is live and accurate, and kept it; images updated to correct media_library JSONB format; word count approx. 3,850.

Reviewed and approved by an editor

Sources and References

  1. NRS Chapter 603A - Security and Privacy of Personal Information(leg.state.nv.us).gov
  2. Nevada Senate Bill 220 (2019) - Enrolled Text(leg.state.nv.us).gov
  3. Nevada Senate Bill 260 (2021) - Enrolled Text(leg.state.nv.us).gov
  4. Nevada Senate Bill 370 (2023) - Enrolled Text(leg.state.nv.us).gov
  5. Nevada Attorney General - Senate Bill 220 Information(ag.nv.gov).gov
  6. Nevada Attorney General - Notice Regarding Data Breaches(ag.nv.gov).gov
  7. NRS 603A Compliance Checklist - Nevada Attorney General(ag.nv.gov).gov
  8. Nevada Attorney General - Equifax Data Breach Settlement(ag.nv.gov).gov
  9. Nevada Attorney General - Carnival Cruise Line Data Breach Settlement(ag.nv.gov).gov
  10. Nevada Attorney General - Cyber Task Force Announcement(ag.nv.gov).gov
  11. HIPAA - U.S. Department of Health and Human Services(hhs.gov).gov
  12. Gramm-Leach-Bliley Act - Federal Trade Commission(ftc.gov).gov
  13. COPPA Rule - Federal Trade Commission(ftc.gov).gov
  14. Fair Credit Reporting Act - Federal Trade Commission(ftc.gov).gov
  15. National Institute of Standards and Technology (NIST)(nist.gov).gov
  16. NRS Chapter 598 - Deceptive Trade Practices(leg.state.nv.us).gov
  17. Preemption and Privacy Law - Congressional Research Service(congress.gov).gov
  18. NRS Chapter 679C - Insurance Data Security(leg.state.nv.us).gov
  19. Nevada AG File a Complaint - Bureau of Consumer Protection(ag.nv.gov).gov
  20. TAKE IT DOWN Act - FTC Legal Library(ftc.gov).gov
  21. Nevada Legislature Bill Search - 83rd Session (2025)(leg.state.nv.us).gov
  22. FTC Report Fraud Portal(reportfraud.ftc.gov).gov
  23. NRS 603A.333 - Sale defined (2025 Nevada Revised Statutes)(law.justia.com)
  24. NRS 603A.340 - Notice regarding covered information collected by operator: contents; exception (2025 Nevada Revised Statutes)(law.justia.com)
Share: