Alaska
Alaska Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Alaska's Personal Information Protection Act, under Alaska Stat. 45.48.010, requires businesses and government agencies to notify affected residents of a data breach in the most expedient time possible and without unreasonable delay. No fixed day deadline applies; the standard is enforced by the Alaska Attorney General.
Alaska's data breach notification law took effect on July 1, 2009, making it one of the later states to adopt breach notification requirements. What sets Alaska apart from most states is its private right of action provision, which allows individual consumers to take companies to court for failing to provide proper breach notification.
The law is part of Alaska's Personal Information Protection Act, codified at AS 45.48.010 through 45.48.090. It applies to any person or entity that owns, licenses, or maintains personal information about Alaska residents, regardless of where the business is located.
For a broader overview of privacy protections in the state, see the parent guide to Alaska Data Privacy Laws.
Who Must Comply with Alaska's Breach Notification Law
The statute applies broadly to two categories of entities that it calls "covered persons":
- Businesses and organizations that own, license, or maintain personal information about Alaska residents in the course of business
- Government agencies at the state and local level that collect or maintain personal information
Third parties also have obligations. If you maintain personal information on behalf of another entity and discover a breach, you must notify the information owner "immediately" and cooperate by sharing relevant details about the breach. The only exception is that you do not have to share confidential business information or trade secrets.
The law applies regardless of where the business is physically located. If you hold personal information on Alaska residents, you are subject to the notification requirement.
What Triggers a Notification Obligation
A breach of security under AS 45.48.090 means the unauthorized acquisition, or reasonable belief of unauthorized acquisition, of personal information that compromises the security, confidentiality, or integrity of the data.
The word "acquisition" is defined broadly. It includes obtaining data through:
- Digital means (hacking, unauthorized access to a computer system)
- Photocopying or facsimile
- Any other paper-based method
- Devices including computers and radio frequency identification (RFID) readers

What Counts as Personal Information
Alaska defines protected personal information as an individual's name (first name or first initial and last name) combined with one or more of the following data elements, when not encrypted or redacted:
| Data Element | Example |
|---|---|
| Social Security number | Full, unredacted SSN (a redacted or truncated SSN does not trigger notification) |
| Driver's license or state ID number | Alaska DL or ID card number |
| Financial account number | Bank account, credit card, or debit card number with any required security code, access code, PIN, or password |
This definition is narrower than many other states. Alaska's law does not cover biometric identifiers, medical records, health insurance information, email credentials, or taxpayer identification numbers. For information about Alaska's approach to biometric data, see Alaska Biometric Privacy Laws.
The Encryption Safe Harbor
If the personal information was encrypted at the time of the breach and the encryption key was not accessed or acquired by the unauthorized party, notification is not required. The same applies to data that has been redacted.
This safe harbor gives businesses a strong incentive to encrypt personal information at rest and in transit. If you can demonstrate that encryption was intact and keys were not compromised, you avoid the entire notification process.
Notification Timeline and Process
How Quickly You Must Notify
Alaska does not set a hard deadline in days. Instead, the statute requires disclosure "in the most expedient time possible and without unreasonable delay." This flexible standard allows time to:
- Determine the scope of the breach
- Restore the reasonable integrity of the information system
- Comply with any law enforcement delay request
While the law does not specify a number of days, "most expedient time possible" has real teeth. The Alaska Attorney General can take enforcement action if a covered person delays notification beyond what is reasonable under the circumstances.
Methods of Notification
Under AS 45.48.030, notification must be delivered through one of these methods:
Written notice sent directly to the affected individual.
Electronic notice that complies with the federal Electronic Signatures in Global and National Commerce Act (E-SIGN Act, 15 U.S.C. 7001).
Substitute notice is available when:
- The cost of direct notification exceeds $150,000
- The affected class exceeds 300,000 residents
- The entity lacks sufficient contact information
Substitute notice requires all three of the following: email notification (where an address is available), conspicuous posting on the entity's website, and notification to major statewide media outlets.
Consumer Reporting Agency Notification
If a breach affects more than 1,000 Alaska residents, the entity must also notify all nationwide consumer reporting agencies. This notification must include the timing, distribution, and content of the notices sent to consumers. Entities subject to the Gramm-Leach-Bliley Act (GLBA) are exempt from this consumer reporting agency notification requirement.
The Harm Threshold Exception
Alaska's law includes a notable exception. An entity may avoid sending consumer notifications if, after an appropriate investigation, it determines there is "not a reasonable likelihood that harm to the consumers whose personal information has been acquired has resulted or will result."
To use this exception, the entity must:
- Conduct an appropriate investigation
- Provide written notification to the Alaska Attorney General explaining the determination
- Document the determination in writing
- Retain that documentation for five years
This is the only situation where notification to the Attorney General is required under the statute. Alaska does not require routine AG notification for every breach.
Law Enforcement Delay
Under AS 45.48.020, an information collector may delay notification if a law enforcement agency determines that disclosure would interfere with a criminal investigation. The delay lasts only as long as law enforcement determines is necessary.
Penalties and Enforcement
Government Agency Violations
A government agency that violates the notification requirements faces a civil penalty of up to $500 per resident who was not notified, with a total cap of $50,000 per breach.
Non-Government Entity Violations
For private businesses and organizations, a violation of the breach notification law is treated as an unfair or deceptive act or practice under Alaska's Unfair Trade Practices and Consumer Protection Act (AS 45.50.471-561). This means the Attorney General can pursue enforcement using the full range of consumer protection remedies.
However, the statute places specific limits:
- The entity is not subject to the general civil penalties under AS 45.50.551
- Instead, the entity faces a civil penalty of up to $500 per unnotified resident, capped at $50,000 total
- Damages awarded to individuals are limited to actual economic damages not exceeding $500 per person
Private Right of Action
This is where Alaska's law stands out. Under AS 45.48.080, an individual whose personal information was involved in a breach by a non-governmental information collector may bring a civil action to recover actual economic damages suffered as a result of the violation. The injunction remedy in AS 45.48.080(a) applies only to the Department of Administration's enforcement against governmental agencies; it is not available in an individual's private civil action against a business.

Damages are limited to actual economic damages up to $500, plus court costs and attorney's fees. While the per-person cap is modest, the right to sue directly without waiting for the Attorney General to act is significant. Only about 12 states provide this type of private right of action for breach notification violations.
The rights and remedies under this section are in addition to any other rights or remedies available under other laws.
Waivers Are Void
Under AS 45.48.060, any waiver of the protections in AS 45.48.010 through 45.48.090 is void and unenforceable. A business cannot make consumers sign away their breach notification rights through terms of service, contracts, or other agreements.
Alaska AG Enforcement in Action
Alaska has participated in several major multistate data breach enforcement actions:
Blackbaud Settlement (2023): Alaska joined 49 other states in a $49.5 million settlement with Blackbaud Inc. over a 2020 ransomware attack that exposed personal information of millions of consumers. Alaska received $358,925. The AG found that Blackbaud had failed to implement reasonable data security measures and did not provide timely or complete breach notifications.
Marriott Settlement (2024): Alaska joined a $52 million multistate settlement with Marriott International over data breaches in the Starwood guest reservation system that went undetected from 2014 to 2018, exposing records of 131.5 million U.S. customers. Alaska received $376,629. Marriott agreed to implement a comprehensive information security program with zero-trust principles, multi-factor authentication, and independent third-party security audits every two years for 20 years.
Equifax Settlement (2019): Alaska was part of the 50-state, $600 million settlement with Equifax over the 2017 breach that exposed personal data of approximately 147 million Americans.

Interaction with Federal Laws
Alaska's breach notification law operates alongside federal data security regulations:
GLBA (Gramm-Leach-Bliley Act): Financial institutions covered by GLBA are exempt from the consumer reporting agency notification requirement in AS 45.48.040, but must still comply with the core notification obligations to affected individuals.
HIPAA: The statute does not contain a specific HIPAA exemption. Healthcare entities covered by HIPAA must comply with both federal breach notification rules under the HITECH Act and Alaska's state notification requirements, though the narrower definition of personal information in Alaska's law means HIPAA-covered health data alone would not trigger the state statute.
SB 134 Insurance Data Security (2024): Alaska enacted SB 134 establishing data security and breach reporting requirements for insurance licensees under AS 21.23, with provisions taking effect on a staggered schedule from January 1, 2025 through January 1, 2027. This supplements, rather than replaces, the general breach notification requirements.
What to Do if You Experience a Data Breach in Alaska
If you believe your personal information was compromised in a data breach, take these steps:
-
Document what you received. Save any breach notification letters or emails. Note the date you received them and the date the company says the breach occurred.
-
Place a fraud alert or credit freeze. Contact any one of the three major credit bureaus (Equifax, Experian, or TransUnion) to place a fraud alert, which lasts one year. For stronger protection, place a credit freeze with all three bureaus.
-
Monitor your accounts. Watch bank statements, credit card statements, and credit reports closely for unauthorized activity.
-
File a complaint. If a company failed to notify you of a breach or delayed notification unreasonably, you can file a complaint with the Alaska Attorney General's Consumer Protection Unit.
-
Consider legal action. Alaska's private right of action means you can consult with an attorney about filing a civil lawsuit to recover actual economic damages if a company violated the notification requirements.
Sources and References
This article references Alaska statutes and official government publications. For the full text of Alaska's Personal Information Protection Act, visit the Alaska State Legislature website. For consumer protection resources and breach complaint forms, visit the Alaska Department of Law Consumer Protection Unit.
This article provides general legal information about Alaska data breach notification laws. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official Alaska government sources.
More Alaska Laws
Frequently Asked Questions
How long does a company have to notify me of a data breach in Alaska?
Alaska does not set a specific deadline in days. The law requires notification 'in the most expedient time possible and without unreasonable delay' after the entity discovers the breach and determines its scope. This flexible standard is enforced by the Attorney General, who can take action against unreasonable delays. Some states set deadlines of 30 to 60 days, but Alaska's standard is fact-specific.
Can I sue a company for failing to notify me of a data breach in Alaska?
Yes. Alaska is one of approximately 12 states that provides a private right of action for breach notification violations. Under AS 45.48.080, you can file a civil lawsuit to recover actual economic damages up to $500 per person, plus court costs and attorney's fees. This right exists independently of any enforcement action by the Attorney General.
Does Alaska's breach notification law cover medical records or biometric data?
No. Alaska's definition of protected personal information is limited to a person's name combined with a Social Security number, driver's license or state ID number, or financial account number with access codes. The law does not cover medical records, health insurance information, biometric identifiers, email credentials, or taxpayer identification numbers. For biometric data protections, see the Alaska Biometric Privacy Laws page.
Do I have to notify the Alaska Attorney General about every data breach?
Not in every case. Attorney General notification is only required when a covered entity investigates a breach and determines there is no reasonable likelihood of harm, and therefore decides not to notify consumers. In that situation, the entity must provide written notice to the AG explaining its determination and retain documentation for five years. If you are notifying consumers, there is no separate AG notification requirement.
Does encryption protect my business from Alaska's breach notification requirements?
Yes, if the encryption was effective. Alaska's law includes an encryption safe harbor. If the personal information was encrypted at the time of the breach and the encryption key was not compromised or acquired by the unauthorized party, notification is not required. The same applies to data that was properly redacted. This gives businesses a strong incentive to encrypt personal data at rest and in transit.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected two errors: the individual civil-action remedy under AS 45.48.080 recovers damages only (the injunction remedy is reserved for governmental-agency enforcement, not a private business), and the breach-notification table's 'full or partial SSN' entry was fixed to reflect that a redacted/partial SSN does not trigger notification, matching the statute's redaction exclusion and the page's own encryption/redaction safe-harbor section.
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 6 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Alaska Statutes, Title 45. Trade and Commerce, Chapter 48. Personal Information Protection Act
§ 45.48.020Allowable delay in notificationIn force
An information collector may delay disclosing the breach under AS 45.48.010 if an appropriate law enforcement agency determines that disclosing the breach will interfere with a criminal investigation. However, the information collector shall disclose the breach to the state resident in the most expeditious time possible and without unreasonable delay after the law enforcement agency informs the information collector in writing that disclosure of the breach will no longer interfere with the investigation.
Official text (excerpt) · as of 2026-07-31 · Read the full section at akleg.gov
§ 45.48.030Methods of noticeIn force
An information collector shall make the disclosure required by AS 45.48.010 (1) by a written document sent to the most recent address the information collector has for the state resident; (2) by electronic means if the information collector's primary method of communication with the state resident is by electronic means or if making the disclosure by the electronic means is consistent with the provisions regarding electronic records and signatures required for notices legally required to be in writing under 15 U.S.C. 7001 et seq. (Electronic Signatures in Global and National Commerce Act); or (3) if the information collector demonstrates that the cost of providing notice would exceed $150,000, that the affected class of state residents to be notified exceeds 300,000, or that the information collector does not have sufficient contact information to provide notice, by (A) electronic mail if the information collector has an electronic mail address for the state resident; (B) conspicuously posting the disclosure on the Internet website of the information collector if the information collector maintains an Internet website; and (C) providing a notice to major statewide media.
Official text (excerpt) · as of 2026-07-31 · Read the full section at akleg.gov
§ 45.48.060WaiversIn force
A waiver of AS 45.48.010 45.48.090 is void and unenforceable.
Official text (excerpt) · as of 2026-07-31 · Read the full section at akleg.gov
§ 45.48.080ViolationsIn force
(a) If an information collector who is a governmental agency violates AS 45.48.010 45.48.090 with regard to the personal information of a state resident, the information collector (1) is liable to the state for a civil penalty of up to $500 for each state resident who was not notified under AS 45.48.010 45.48.090, but the total civil penalty may not exceed $50,000; and (2) may be enjoined from further violations. (b) If an information collector who is not a governmental agency violates AS 45.48.010 45.48.090 with regard to the personal information of a state resident, the violation is an unfair or deceptive act or practice under AS 45.50.471 45.50.561. However, (1) the information collector is not subject to the civil penalties imposed under AS 45.50.551 but is liable to the state for a civil penalty of up to $500 for each state resident who was not notified under AS 45.48.010 45.48.090, except that the total civil penalty may not exceed $50,000; and (2) damages that may be awarded against the information collector under (A) AS 45.50.531 are limited to actual economic damages that do not exceed $500; and (B) AS 45.50.537 are limited to actual economic damages.
Official text (excerpt) · as of 2026-07-31 · Read the full section at akleg.gov
§ 45.48.090DefinitionsIn force
In AS 45.48.010 45.48.090, (1) breach of the security means unauthorized acquisition, or reasonable belief of unauthorized acquisition, of personal information that compromises the security, confidentiality, or integrity of the personal information maintained by the information collector; in this paragraph, acquisition includes acquisition by (A) photocopying, facsimile, or other paper-based method; (B) a device, including a computer, that can read, write, or store information that is represented in numerical form; or (C) a method not identified by (A) or (B) of this paragraph; (2) covered person means a (A) person doing business; (B) governmental agency; or (C) person with more than 10 employees; (3) governmental agency means a state or local governmental agency, except for an agency of the judicial branch; (4) information collector means a covered person who owns or licenses personal information in any form if the personal information includes personal information on a state resident; (5) information distributor means a person who is an information collector and who owns or licenses personal information to an information recipient; (6) information recipient means a person who is…
Official text (excerpt) · as of 2026-07-31 · Read the full section at akleg.gov
United States Code Title 15
§ 7001General rule of validityIn forcecited in 17 of our articles
Notwithstanding any statute, regulation, or other rule of law (other than this subchapter and subchapter II), with respect to any transaction in or affecting interstate or foreign commerce— a signature, contract, or other record relating to such transaction may not be denied legal effect, validity, or enforceability solely because it is in electronic form; and a contract relating to such transaction may not be denied legal effect, validity, or enforceability solely because an electronic signature or electronic record was used in its formation. This subchapter does not— limit, alter, or otherwise affect any requirement imposed by a statute, regulation, or rule of law relating to the rights and obligations of persons under such statute, regulation, or rule of law other than a requirement that contracts or other records be written, signed, or in nonelectronic form; or require any person to agree to use or accept electronic records or electronic signatures, other than a governmental agency with respect to a record other than a contract to which it is a party.
Official text (excerpt) · as of 2026-07-28 · Read the full section at uscode.house.gov
Also relied on in: Mississippi Data Breach Notification Laws: Reporting Rules & Timelines (2026), Mississippi Data Privacy Laws: Breach Notification & Consumer Rights (2026), Montana Data Privacy Laws: MCDPA Consumer Rights Guide (2026)
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- Alaska Personal Information Protection Act (AS 45.48.010-090)(akleg.gov).gov
- AS 45.48.090 - Definitions(akleg.gov).gov
- AS 45.48.030 - Methods of Disclosure(akleg.gov).gov
- AS 45.48.020 - Delay of Disclosure(akleg.gov).gov
- AS 45.48.080 - Violations(akleg.gov).gov
- AS 45.48.060 - Waivers(akleg.gov).gov
- Alaska Unfair Trade Practices Act (AS 45.50.471-561)(akleg.gov).gov
- E-SIGN Act (15 U.S.C. 7001)(govinfo.gov).gov
- Gramm-Leach-Bliley Act(ftc.gov).gov
- AG Settlement with Blackbaud (2023)(law.alaska.gov).gov
- AG Settlement with Marriott (2024)(law.alaska.gov).gov
- AG Settlement with Equifax (2019)(law.alaska.gov).gov
- Alaska AG Consumer Protection Complaint Form(law.alaska.gov).gov
- Alaska SB 134 Insurance Data Security(commerce.alaska.gov).gov