Nevada
Nevada Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 5 primary sources cited on this page. How we verify our legal content

Under NRS 603A.220, Nevada requires businesses to notify affected residents of a data breach in the most expedient time possible and without unreasonable delay. The law sets no fixed-day deadline. Notification may be delayed briefly to allow law enforcement needs or breach investigation to be addressed.
If your business handles personal information belonging to Nevada residents, a data breach triggers specific legal obligations under Nevada's Security of Personal Information statute. Nev. Rev. Stat. 603A.010 et seq. sets out who must notify, what triggers the duty, and how quickly you need to act. Nevada was among the early adopters of breach notification legislation, enacting its first version in 2005, and has amended the law multiple times to strengthen data security requirements.
This guide covers the full scope of Nevada's breach notification requirements, including what personal information triggers the law, who must be notified, the timeline, penalties, exemptions, and how the state's broader data privacy framework interacts with breach obligations.
Who Must Comply With Nevada's Breach Notification Law
Nevada's law applies to any data collector that owns or licenses computerized data that includes personal information. Under NRS 603A.030, a "data collector" is defined broadly to include any governmental agency, institution of higher education, corporation, financial institution, or any other type of business entity or association that handles personal information for any purpose.
This means the law covers businesses of all sizes, government agencies, universities, and nonprofits. Out-of-state businesses that handle personal information of Nevada residents are also subject to the law.
When a third party that maintains data on behalf of a data collector becomes aware of a breach, the third party must notify the data collector immediately. The data collector then carries the responsibility to notify affected individuals.
What Qualifies as a Breach
Under NRS 603A.020, a "breach of the security of the system data" means the unauthorized acquisition of computerized data that materially compromises the security, confidentiality, or integrity of personal information maintained by the data collector.
Good Faith Exception
A good faith acquisition of personal information by an employee or agent of the data collector for a legitimate business purpose does not constitute a breach, as long as the personal information is not used for a purpose unrelated to the data collector's business or subject to further unauthorized disclosure.
Encryption Safe Harbor
Nevada provides a safe harbor for encrypted data. If the personal information subject to the breach was encrypted and the encryption key was not acquired by the unauthorized person, notification is not required. This safe harbor applies only when the encryption key remains secure.

Personal Information That Triggers Notification
Under NRS 603A.040, personal information means a natural person's first name or first initial and last name combined with any one or more of the following data elements:
- Social Security number
- Driver's license number, driver authorization card number, or identification card number
- Account number, credit card number, or debit card number combined with any required security code, access code, or password that would permit access to the financial account
- Medical identification number or health insurance identification number
- A user name, unique identifier, or email address combined with a password, access code, or security question and answer that would permit access to an online account
The definition excludes the last four digits of a Social Security number, driver's license number, driver authorization card number, or identification card number when that is the only information disclosed.
What Nevada's Law Does Not Cover
Compared to states with recently updated laws, Nevada's definition of personal information does not include:
- Biometric data (fingerprints, retina scans, voiceprints)
- Passport numbers
- Taxpayer identification numbers (other than SSNs)
Personal information does not include publicly available information that is lawfully made available to the general public from federal, state, or local government records.
Notification Timeline
Nevada requires notification "in the most expedient time possible and without unreasonable delay" under NRS 603A.220. The state does not impose a specific day count, giving entities flexibility to investigate before notifying.
When Delay Is Permitted
Notification may be delayed if:
- A law enforcement agency determines that the notification will impede a criminal investigation. The data collector must notify affected individuals after the law enforcement agency determines that notification no longer compromises the investigation.
- The data collector needs time to determine the scope of the breach and restore the reasonable integrity of the system. However, this must not cause unreasonable delay.
Who Must Be Notified
Affected Individuals
Every Nevada resident whose unencrypted personal information was or is reasonably believed to have been acquired by an unauthorized person must receive notification. Unlike many states, NRS 603A.220 does not prescribe specific content the notice must include. As a best practice, many Nevada notification letters cover:
- The types of personal information that were or are reasonably believed to have been the subject of the breach
- A general description of the breach incident
- Contact information for the data collector
- Advice directing the individual to remain vigilant by reviewing account statements and monitoring free credit reports
No Attorney General Notification Required
Unlike the majority of U.S. states, Nevada does not require businesses to notify the Attorney General or any other state agency when a data breach occurs. This is a notable distinction that simplifies compliance for businesses but reduces the state's visibility into breach activity.
Consumer Reporting Agencies
When a breach affects more than 1,000 Nevada residents, the data collector must notify the consumer reporting agencies without unreasonable delay. The notification must include the timing, distribution, and content of the notification to individuals.
How to Provide Notification
Nevada permits the following notification methods:
- Written notification sent by mail to the last known address of the individual
- Electronic notification, if the notification provided is consistent with the Electronic Signatures in Global and National Commerce Act, 15 U.S.C. 7001 et seq. Nevada attaches no additional precondition to this option. The statute does not require that electronic contact be the primary means of communication with the individual.
Substitute Notice
Substitute notice is available when:
- The cost of providing notification would exceed $250,000
- The affected class exceeds 500,000 people
- The data collector does not have sufficient contact information
Substitute notice must include all of the following:
- Email notification to individuals for whom the data collector has an email address
- Conspicuous posting of the notice on the data collector's website
- Notification to major statewide media outlets
Exemptions and Deemed Compliance
NRS 603A.220 carries its own carve-outs, and two of them do most of the work in practice.
Under NRS 603A.220(5), a data collector is deemed to be in compliance with the notification requirement if it either:
- Maintains its own notification policies and procedures as part of an information security policy for the treatment of personal information that is otherwise consistent with the timing requirements of the section, and notifies subject persons in accordance with those policies after a breach; or
- Is subject to and complies with the privacy and security provisions of the Gramm-Leach-Bliley Act, 15 U.S.C. 6801 et seq. This is the path that governs most banks, credit unions, and other financial institutions, even though they are otherwise "data collectors" under the chapter.
Under NRS 603A.220(7), the section does not apply at all to a person licensed pursuant to chapter 675 of NRS.
Data Security Requirements
Beyond breach notification, Nevada imposes affirmative data security obligations. Under NRS 603A.210, data collectors that maintain personal information must implement and maintain reasonable security measures to protect that information from unauthorized access, acquisition, destruction, use, modification, or disclosure.
Nevada is also notable for its explicit PCI DSS mandate. Under NRS 603A.215(1), any data collector that accepts a payment card in connection with a sale of goods or services must comply with the current version of PCI DSS with respect to those transactions. This is one of the few state statutes that directly incorporates PCI DSS by reference.

The encryption duties in the same statute run to a different group of businesses. NRS 603A.215(2) opens "A data collector doing business in this State to whom subsection 1 does not apply," so it reaches collectors that do not accept payment cards. Those collectors must use encryption when they transfer personal information outside their secure system by electronic, nonvoice transmission other than a facsimile, and when they move a data storage device containing personal information beyond their own controls.
The two subsections are alternative tracks rather than cumulative duties. A card-accepting merchant owes the PCI DSS obligation in subsection 1; a business that does not accept payment cards owes the encryption obligations in subsection 2. Subsection 4 also exempts telecommunication providers acting solely as conduits and certain transmissions over secure private payment channels.
Enforcement and Penalties
Nevada's breach notification law is enforced through the state's general consumer protection framework. Under NRS 603A.260, a violation of NRS 603A.010 to 603A.290 constitutes a deceptive trade practice for the purposes of NRS 598.0903 to 598.0999, which routes enforcement to the Nevada Attorney General under the Deceptive Trade Practices Act. NRS 603A.290 also allows the district attorney of any county, not only the Attorney General, to bring an action for a temporary or permanent injunction against a violation.
Available public enforcement remedies include:
- Injunctive relief to stop ongoing violations, sought by the Attorney General or a district attorney under NRS 603A.290
- Civil penalties as prescribed under the Deceptive Trade Practices Act
- Restitution under NRS 598.0993, which lets the court order money or property acquired by means of the deceptive trade practice restored to a person in interest
Whether a consumer can sue a business directly is unsettled. NRS 603A.200 to 603A.290 contains no express private right of action and no express bar on one. The chapter's only express bar sits in NRS 603A.360(4), which applies to the SB 220 operator provisions in NRS 603A.300 to 603A.360, and the Nevada Legislature did not write a parallel bar into the breach notification sections. Working the other direction, NRS 603A.260 labels a violation a deceptive trade practice, and NRS 41.600(2)(e) gives an action to any victim of consumer fraud, which it defines to include a deceptive trade practice as defined in NRS 598.0915 to 598.0925. Whether that chain carries a breach notification failure into a private suit has not been settled, so treat it as an open question rather than a closed door and get advice from a Nevada attorney.
Separately, NRS 603A.270 creates a civil action that runs the other direction: it lets the data collector that provided notification sue the person who unlawfully obtained or benefited from the stolen personal information, recovering the reasonable costs of notification, attorney's fees and costs, and punitive damages when appropriate. NRS 603A.280 works the same way, letting a court order a person convicted of unlawfully obtaining or benefiting from the information to pay restitution to the data collector for its notification costs. Neither section provides compensation to affected consumers.

How Nevada's Privacy Laws Interact With Breach Notification
Nevada has two separate privacy statutes that interact with breach notification:
SB 220 (NRS 603A.340-360): Nevada's opt-out privacy law, effective October 1, 2019, requires covered operators of internet websites and online services to provide consumers with a mechanism to opt out of the sale of their personal information. While SB 220 does not contain its own breach notification requirements, compliance with its data handling requirements can reduce the scope of data at risk in a breach.
NRS 603A.200-290 (Security of Personal Information): This is the core breach notification and data security statute discussed throughout this article.
Both frameworks are enforced by the Attorney General. There is no overlap in their notification requirements, as SB 220 focuses on data sale practices rather than breach response.
This article provides general legal information about Nevada data privacy laws and breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in Nevada for guidance specific to your situation.
More Nevada Laws
Frequently Asked Questions
How long does a business have to notify Nevada residents of a data breach?
Nevada law requires notification 'in the most expedient time possible and without unreasonable delay' but does not set a specific day deadline. Notification may be delayed if law enforcement determines it would impede a criminal investigation, or if the business needs time to determine the scope of the breach and restore system integrity. Once the reason for the delay no longer exists, notification must happen promptly.
Does Nevada require businesses to notify the Attorney General after a data breach?
No. Nevada is one of the few states that does not require Attorney General notification for data breaches. Businesses must notify affected individuals and, when more than 1,000 Nevada residents are affected, the nationwide consumer reporting agencies. But there is no mandatory state agency notification requirement.
Does encryption protect businesses from Nevada's breach notification requirements?
Yes, Nevada provides an encryption safe harbor. If the compromised personal information was encrypted and the encryption key was not acquired by the unauthorized person, notification is not required. However, if the encryption key was also compromised, the safe harbor does not apply and full notification obligations are triggered.
Does Nevada require PCI DSS compliance?
Yes, for businesses that take cards. Nevada is one of the few states that explicitly requires PCI DSS compliance by statute. Under NRS 603A.215(1), a data collector that accepts a payment card in connection with a sale of goods or services must comply with the current version of the Payment Card Industry Data Security Standard for those transactions. The encryption duties in NRS 603A.215(2) apply to a different group. That subsection reaches a data collector 'to whom subsection 1 does not apply,' meaning businesses that do not accept payment cards, and requires encryption when personal information is transferred outside the secure system of the business or moved on a data storage device beyond the collector's controls. The two subsections are alternative tracks, not a PCI duty plus an encryption add-on.
Can individuals sue for a data breach in Nevada?
It is unsettled. The breach notification sections, NRS 603A.200 to 603A.290, neither create a private right of action nor expressly bar one. The chapter's only express bar is in NRS 603A.360(4) and applies to the separate SB 220 operator provisions. NRS 603A.260 makes a violation a deceptive trade practice, and NRS 41.600 gives an action to a victim of consumer fraud that includes certain deceptive trade practices, so there is an argument for a private claim, but Nevada courts have not settled whether that chain works for a breach notification failure. The chapter's own civil action provision, NRS 603A.270, runs the other way: it lets the data collector sue the person who stole or benefited from the data. Many consumers pursue claims on separate theories such as negligence. Ask a Nevada attorney about your specific situation.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the electronic-notice and encryption rules, fixed a statute citation in the key takeaways, added the Gramm-Leach-Bliley and own-policy compliance paths and the NRS chapter 675 exemption, and reframed the private-lawsuit question as unsettled rather than settled.
Corrected the description of what counts as protected personal information under Nevada law (username/email plus password is covered, not excluded), fixed a citation to a nonexistent statute section describing consumer damages rights, reframed a notification-content checklist as best practice rather than a legal requirement, and corrected the 1,000-resident credit-bureau notification threshold to more than 1,000.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Nevada Revised Statutes, Chapter 603A: SECURITY AND PRIVACY OF PERSONAL INFORMATION
§ 603A.220Disclosure of breach of security of system data; methods of disclosure; applicability.In force
1. Except as otherwise provided in subsection 7, a data collector that owns or licenses computerized data which includes personal information shall disclose any breach of the security of the system data following discovery or notification of the breach to any resident of this State whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. The disclosure must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subsection 3, or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the system data. 2. Any data collector that maintains computerized data which includes personal information that the data collector does not own shall notify the owner or licensee of the information of any breach of the security of the system data immediately following discovery if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at leg.state.nv.us
§ 603A.210Security measures.In force
1. A data collector that maintains records which contain personal information of a resident of this State shall implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification or disclosure. 2. If a data collector is a governmental agency and maintains records which contain personal information of a resident of this State, the data collector shall, to the extent practicable, with respect to the collection, dissemination and maintenance of those records, comply with the current version of the CIS Controls as published by the Center for Internet Security, Inc. or its successor organization, or corresponding standards adopted by the National Institute of Standards and Technology of the United States Department of Commerce.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at leg.state.nv.us
Cited in 6 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- CLARK CTY. SCHOOL DIST. VS. LAS VEGAS REVIEW-JOURNAL (Nevada Supreme Court 2018, 429 P.3d 313)“…ust be protected against disclosure under NRS 603A.210. The list in NRS 239.010(1) also includ…”
- Archambault v. Riverside Resort & Casino, Inc. (District Court, D. Nevada 2025)“…adequate 24 and by violating statutes such as the FTC and NRS 603A.210 requiring data collectors to 25 “impl…”
- Gill v. Caesars Entertainment, Inc. (District Court, D. Nevada 2025)“…reaching 12 several federal and state statutes, including NRS 603A.210(1), which requires 13 that “[a] data…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 603A.215Security measures for data collector that accepts payment card; use of encryption; liability for damages; applicability.In force
1. If a data collector doing business in this State accepts a payment card in connection with a sale of goods or services, the data collector shall comply with the current version of the Payment Card Industry (PCI) Data Security Standard, as adopted by the PCI Security Standards Council or its successor organization, with respect to those transactions, not later than the date for compliance set forth in the Payment Card Industry (PCI) Data Security Standard or by the PCI Security Standards Council or its successor organization.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at leg.state.nv.us
United States Code Title 15
§ 7001General rule of validityIn forcecited in 18 of our articles
Notwithstanding any statute, regulation, or other rule of law (other than this subchapter and subchapter II), with respect to any transaction in or affecting interstate or foreign commerce— a signature, contract, or other record relating to such transaction may not be denied legal effect, validity, or enforceability solely because it is in electronic form; and a contract relating to such transaction may not be denied legal effect, validity, or enforceability solely because an electronic signature or electronic record was used in its formation. This subchapter does not— limit, alter, or otherwise affect any requirement imposed by a statute, regulation, or rule of law relating to the rights and obligations of persons under such statute, regulation, or rule of law other than a requirement that contracts or other records be written, signed, or in nonelectronic form; or require any person to agree to use or accept electronic records or electronic signatures, other than a governmental agency with respect to a record other than a contract to which it is a party.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 132 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Metropolitan Regional Information Systems v. American Home Realty Network (2012) applied 15 U.S.C. 7001(a) to hold an electronic assignment process satisfied the signed writing requirement of Copyright Act 204(a). Blatt v. Capital One Auto Finance (2017) held 7001(c) disclosures were not required where the record was delivered on paper.
Opinions citing this section in our collection:
- Metropolitan Regional Information Systems, Inc. v. American Home Realty Network, Inc. (District Court, D. Maryland 2012, 904 F. Supp. 2d 530)✓Subscribers assigned photo copyrights to a real estate database by uploading images under online terms of use; the court relied on E-SIGN, 15 U.S.C. section 7001, to hold those electronic assignments met the Copyright Act signed-writing rule, and denied reconsideration.
- Cutrone v. Mortgage Electronic Registration Systems, Inc. (District Court, E.D. New York 2013, 981 F. Supp. 2d 144)✓Homeowners sued MERS in state court over a second mortgage recording tax on an E-Sign mortgage; MERS removed under 15 U.S.C. section 7001, but the court held that statute gives no private right of action and at most a federal defense, which cannot support removal, and remanded.
- Blatt v. Capital One Auto Finance, Inc. (District Court, M.D. Tennessee 2017, 237 F. Supp. 3d 688)“…legal effect ..solely because it is in electronic form[.]” 15 U.S.C. § 7001 (a)(1).. Furthermore, it mandates that…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Mississippi Data Breach Notification Laws: Reporting Rules & Timelines (2026), Mississippi Data Privacy Laws: Breach Notification & Consumer Rights (2026), Montana Data Privacy Laws: MCDPA Consumer Rights Guide (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Nev. Rev. Stat. 603A - Security of Personal Information(leg.state.nv.us).gov
- NRS 603A.220 - Notification Requirements(leg.state.nv.us).gov
- NRS 603A.210 - Data Security Requirements(leg.state.nv.us).gov
- NRS 603A.215 - PCI DSS and Encryption(leg.state.nv.us).gov
- Nevada Attorney General(ag.nv.gov).gov
- NRS 603A.260 - Violation constitutes deceptive trade practice(leg.state.nv.us)
- NRS 603A.290 - Injunction (Attorney General or district attorney)(leg.state.nv.us)
- NRS 41.600 - Actions by victims of fraud(leg.state.nv.us)
- NRS Chapter 598 - Deceptive Trade Practices, including NRS 598.0993 relief for injured persons(leg.state.nv.us)