Skip to content
DWT logo
People Services Insights
About Offices Careers
Search
People
Services
Insights
About
Offices
Careers
Search

Arizona

See the Summary of U.S. State Data Breach Maps

Quick Facts

Breach Based on Harm Threshold: YES
Deadline for Consumer Notice: No later than 45 days
Government Notification Required: YES, if >1,000 residents notified

Ariz. Rev. Stat. Ann. § 18-55 1 to 552

Scope of This Summary:

Notification requirements applicable to persons or entities that conduct business in the state and own, license, or maintain covered info. Some types of businesses may be exempt from some or all of these requirements, and non-commercial entities may be subject to different requirements.

Risk of Harm Threshold

N/A

Breach Defined

Unauthorized acquisition and access that materially compromises the security or confidentiality of covered information maintained as part of a database of personal information regarding multiple individuals, and that causes or is reasonably likely to cause substantial economic loss to a resident, excluding certain good-faith acquisitions by employees or agents.

Encryption Safe Harbor

Statute does not apply to information that is encrypted, redacted, or secured by any other means rendering the element unreadable or unusable.

Form of Covered Information

Electronic Only

Covered Information

  • Personal information means an individual's first name or first initial and last name in combination with one or more of the following specified data elements:
    • Social Security number.
    • The number on a driver's license issued pursuant to § 28-3166 or number on a non-operating identification license issued pursuant to § 28-3165.
    • A private key that is unique to an individual and that is used to authenticate or sign an electronic record.
    • A financial account number or credit or debit card number in combination with any required security code, access code or password that would permit access to the individual's financial account.
    • A health insurance identification number.
    • Information about an individual's medical or mental health treatment or diagnosis by a healthcare professional.
    • Passport number.
    • Taxpayer identification number or an identity protection personal identification number issued by the United States Internal Revenue Service.
    • Unique biometric data generated from a measurement or analysis of human body characteristics to authenticate an individual when the individual accesses an online account.
  • Personal information also means:
    • An individual's username or email address in combination with a password or security question and answer that allows access to an online account.
    • Personal information does not include publicly available information that is lawfully made available to the general public from federal, state, or local government records or widely distributed media.

Consumer Notice Timing

Notice required within 45 days of determination that a breach has occurred.

Consumer Notice Method

By written notice; email notice if the person has email addresses for the individuals who are subject to the notice; or telephonic notice, if telephonic contact is made directly with the affected individuals and is not through a prerecorded message. Substitute notice is available if certain criteria are satisfied.

Consumer Notice Content

  • Notifications to affected individuals must include at least:
    • The approximate date of the breach.
    • A brief description of the personal information included in the breach.
    • The toll-free numbers and addresses for the three largest nationwide Consumer Reporting Agencies.
    • The toll-free number, address, and website address for the Federal Trade Commission or any federal agency that assists consumers with identity theft matters.
  • For a breach of only an individual's username or email address in combination with a password or security question and answer that allows access to an online account, an entity may comply with notification requirements by:
    • Providing the notification in an electronic form that directs the affected individual to promptly change their password and security question or answer as applicable, or to take other steps that are appropriate to protect the online account with the entity and all other online accounts for which the individual uses the same username and email address and password or security question or answer.

Delayed Notice

Notification may be delayed if law enforcement advises that notice will impede a criminal investigation. Notice must be made no later than 45 days after law enforcement informs the covered entity that delay is no longer required.

Government Notice

If notice to more than 1,000 residents is required, the entity shall notify the Attorney General.

Consumer Reporting Agency Notice

If notice to more than 1,000 residents is required, the entity shall notify the three largest nationwide Consumer Reporting Agencies within 45 days.

Exceptions for Other Laws

The statute exempts from compliance the following entities: Any person who is subject to the federal Gramm-Leach-Bliley Act (GLBA); Any person who is subject to the federal Health Insurance Portability and Accountability Act (HIPAA).

Third-Party Notice

If you maintain unencrypted computerized data that includes covered information on behalf of another entity, you must notify it without unreasonable delay following discovery of a breach. Must cooperate by sharing relevant information about breach.

Private Right of Action

The Arizona statute does not provide for a private right of action.

Potential Penalties

Violations may result in civil penalties.

This summary is for informational purposes only. It provides general information and not legal advice or opinions regarding specific facts. Additional requirements or conditions may apply to any or all provisions referenced herein. For more information about the state data breach notification laws or other data security matters, please seek the advice of counsel.

Last revised on June 15, 2023

DWT logo
©1996-2025 Davis Wright Tremaine LLP. ALL RIGHTS RESERVED. Attorney Advertising. Not intended as legal advice. Prior results do not guarantee a similar outcome.
Media Kit Affiliations Legal notices
Privacy policy Employees DWT Collaborate EEO

SUBSCRIBE
©1996-2025 Davis Wright Tremaine LLP. ALL RIGHTS RESERVED. Attorney Advertising. Not intended as legal advice. Prior results do not guarantee a similar outcome.
Close
Close

CAUTION - Before you proceed, please note: By clicking "accept" you agree that our review of the information contained in your e-mail and any attachments will not create an attorney-client relationship, and will not prevent any lawyer in our firm from representing a party in any matter where that information is relevant, even if you submitted the information in good faith to retain us.