Arkansas
Arkansas Data Privacy Laws: Breach Notification & Consumer Rights (2026)

Arkansas does not have a comprehensive consumer data privacy law. Its primary state-level privacy protection is the Personal Information Protection Act (), which requires breach notification and data security, alongside student and youth data protections and active Attorney General enforcement under the state's consumer protection laws.
Arkansas does not have a comprehensive consumer privacy law. Lawmakers considered one in 2025, the Arkansas Digital Responsibility, Safety, and Trust Act (SB258), but it died at sine die adjournment on May 5, 2025, and never took effect. Arkansas residents' protections instead come from the state's breach notification statute, student and youth data protections, and the Attorney General's consumer protection enforcement authority.
This guide covers every significant Arkansas data privacy law currently in effect, what protections you have as a consumer, what obligations businesses must meet, and the penalties for noncompliance.
Does Arkansas Have a Comprehensive Privacy Law?
Arkansas has not enacted a comprehensive consumer data privacy law. Unlike states such as Virginia, Colorado, and Connecticut, Arkansas gives residents no general state-law right to access, correct, delete, or port personal data held by businesses, and imposes no data protection assessment, consent, or processor-contract duties outside specific sectors.

The 2025 Attempt That Failed
In the 2025 legislative session, Arkansas lawmakers introduced Senate Bill 258, the Arkansas Digital Responsibility, Safety, and Trust Act (ADRSTA), which would have created a Virginia-style comprehensive privacy framework with consumer rights to access, correct, delete, and opt out of the sale of personal data. The bill failed a third-reading vote in the Senate on April 8 and again on April 10, 2025, and formally died on the Senate calendar at sine die adjournment on May 5, 2025. It never became law.
No replacement comprehensive privacy bill has passed since. Arkansas remains among the roughly 30 states without a comprehensive consumer privacy statute.
What Actually Protects Arkansas Consumers
In the absence of a comprehensive law, Arkansas residents' data privacy protections come from a narrower set of state and federal statutes covered throughout this guide:
- The Personal Information Protection Act ( et seq.), which requires reasonable data security and breach notification, described in detail below.
- The Student Online Personal Information Protection Act (), which restricts how education technology operators use K-12 student data.
- The Children and Teens' Online Privacy Protection Act (Act 952 of 2025), which extends consent requirements to minors aged 13 through 16 starting July 1, 2026.
- Sector-specific federal laws, including HIPAA, the Gramm-Leach-Bliley Act, COPPA, and the FCRA.
- Attorney General enforcement under the Arkansas Deceptive Trade Practices Act, which the AG has used against companies like TikTok and Temu over data practices even without a dedicated privacy statute.
None of these statutes give Arkansas consumers a general right to access, correct, delete, or opt out of the sale of personal data held by an ordinary business. A consumer seeking those rights against an Arkansas-based company currently has no state-law claim to them.
Arkansas Personal Information Protection Act
The Personal Information Protection Act (PIPA) is the cornerstone of Arkansas's data breach notification and security framework, and it remains Arkansas's only general-purpose privacy statute. Originally enacted in 2005 through Act 1526, the law was significantly amended in 2019 by Act 1030 to expand the definition of personal information and strengthen notification requirements.
What Qualifies as Personal Information
Under Ark. Code 4-110-103, personal information means an individual's first name or first initial and last name in combination with one or more of the following data elements, when either the name or the data element is not encrypted or redacted:
- Social Security number
- Driver's license number or state identification card number
- Account number, credit card number, or debit card number in combination with any required security code, access code, or password that would permit access to a financial account
- Medical information, including any information regarding an individual's medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional
- Health insurance policy number or subscriber identification number, combined with any unique identifier used by a health insurer to identify the individual
- Biometric data, defined as data generated by automatic measurements of an individual's biological characteristics used to uniquely authenticate an individual's identity
The 2019 amendment through Act 1030 added medical information, health insurance information, and biometric data to this definition. Before that amendment, the law covered only Social Security numbers, driver's license numbers, and financial account information.
Data Security Requirements
Under Ark. Code 4-110-104, any person or business that acquires, owns, or licenses personal information about an Arkansas resident must implement and maintain reasonable security procedures and practices appropriate to the nature of the information. These measures must protect personal information from unauthorized access, destruction, use, modification, or disclosure.
The statute does not define what constitutes "reasonable security procedures." This gives businesses flexibility to design security programs that fit their size and the sensitivity of the data they handle, but it also means adequacy is judged on a case-by-case basis if a breach occurs.
Records Destruction Requirements
also requires that any person or business take all reasonable steps to destroy or arrange for the destruction of a customer's records containing personal information that is no longer to be retained. Acceptable destruction methods include shredding, erasing, or otherwise modifying the personal information to make it unreadable or undecipherable through any means.
This applies to both paper and electronic records. The goal is to prevent personal information from being recovered from discarded records.
Data Breach Notification Requirements
The breach notification provisions in Ark. Code 4-110-105 are the most detailed and consequential part of the Personal Information Protection Act.
Who Must Notify
Any person or business that acquires, owns, or licenses computerized data that includes personal information must disclose any breach of the security of the system to any Arkansas resident whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person.
This obligation extends to third parties that maintain data on behalf of another business. If a third-party service provider experiences a breach involving data belonging to another entity's customers, the service provider must notify the data owner, which must then notify affected individuals.
Definition of a Breach
A "breach of the security of the system" means the unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by a person or business. The key word is "acquisition." A breach has not necessarily occurred simply because a system was accessed without authorization. There must be evidence that personal information was actually obtained or is reasonably believed to have been obtained.
Notification Timeline
Notification must be made in the most expedient time and manner possible and without unreasonable delay, consistent with the legitimate needs of law enforcement or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.
Attorney General Notification
If a breach affects the personal information of more than 1,000 individuals, the person or business must also notify the Arkansas Attorney General. This notification must be made at the same time as notice to affected individuals, or within 45 days after the person or business determines there is a reasonable likelihood of harm to customers, whichever occurs first.
The Attorney General notification must be submitted through the Data Breach Reporting Form on the Arkansas Attorney General's website.
Methods of Notification
Notification may be provided through one of the following methods:
- Written notice sent to the postal address in the records of the person or business
- Electronic notice if the person or business has an email address for the affected individual and the notice is consistent with the provisions of the federal Electronic Signatures in Global and National Commerce Act (E-SIGN Act)
- Substitute notice if certain conditions are met
Substitute Notice
Substitute notice is permitted if the person or business demonstrates that the cost of providing direct notice would exceed $250,000, the affected class of persons exceeds 500,000 individuals, or the person or business does not have sufficient contact information to provide notice.
Substitute notice must include all of the following:
- Email notice to all affected individuals for whom the business has an email address
- Conspicuous posting of the notice on the business's website
- Notification through statewide media
Law Enforcement Delay
Notification may be delayed if a law enforcement agency determines that notification would impede a criminal investigation. Once the law enforcement agency determines that notification will not compromise the investigation, the notification must be made.
Penalties for Violating the Personal Information Protection Act
Under Ark. Code 4-110-108, violations of the Personal Information Protection Act are punishable by action of the Attorney General under the Arkansas Deceptive Trade Practices Act (Ark. Code 4-88-101 et seq.).
This means the Attorney General can pursue the full range of remedies available under the DTPA, including:
- Civil penalties of up to $10,000 per violation
- Injunctive relief ordering the business to change its security practices
- Restitution to consumers who suffered ascertainable losses
- Attorney's fees and costs of investigation
Willful and knowing violations of the Personal Information Protection Act constitute a Class A misdemeanor under Arkansas law, which carries potential criminal penalties including fines and up to one year in jail.
Student Online Personal Information Protection Act

The Student Online Personal Information Protection Act, codified at through 6-18-114, protects the data of K-12 students who use educational technology platforms.
Who the Law Covers
The law applies to "operators," defined as owners of websites, online services, online applications, or mobile applications with actual knowledge that the website, service, or application is used for K-12 school purposes. The law does not apply to the Arkansas Division of Elementary and Secondary Education, school districts, or open-enrollment public charter schools.
Prohibited Activities
Operators covered by the Student Online Personal Information Protection Act are prohibited from:
- Targeted advertising based on covered information obtained through the operator's K-12 educational platform
- Compiling profiles about students using covered information, except in furtherance of K-12 school purposes
- Selling covered information about students, unless the transaction is part of a corporate merger, acquisition, or bankruptcy and the successor entity remains bound by the same restrictions
- Disclosing covered information except in limited, specified circumstances
Security and Deletion Requirements
Operators must implement and maintain reasonable security measures appropriate to the nature of the covered information. When a school or school district requests deletion of a student's covered information, the operator must delete the data within a reasonable timeframe.
Third-Party Service Providers
If an operator shares covered information with a service provider, the operator must contractually require the service provider to:
- Use the information only for providing the contracted service
- Refrain from disclosing the information to additional third parties unless expressly permitted
- Implement and maintain reasonable security procedures and practices
Arkansas Children and Teens' Online Privacy Protection Act
In April 2025, Arkansas enacted the Children and Teens' Online Privacy Protection Act through HB 1717, signed into law as Act 952. This law takes effect on July 1, 2026.
Arkansas is the first state to extend COPPA-like protections specifically to teenagers. While the federal Children's Online Privacy Protection Act (COPPA) only covers children under 13, this Arkansas law creates a two-tiered framework covering both children and teens.
Two-Tiered Consent Framework
The Act establishes different consent requirements based on age:
- Children under 13: Operators must obtain verifiable parental consent before collecting personal information, consistent with federal COPPA requirements.
- Teens aged 13 through 16: Either the teen or their parent may consent to the collection, use, and disclosure of personal information, after receiving clear notice of the operator's data practices.
Operator Requirements
Operators covered by the law must:
- Provide clear, prominent notice of their data collection, use, and disclosure practices
- Honor deletion and correction requests from parents or teens
- Implement reasonable security measures to protect collected personal information
- Avoid collecting more personal information than reasonably necessary
Who Is Covered
The Act applies to for-profit websites, online services, applications, and mobile applications directed to children or teens, or that have actual knowledge they are collecting personal information from these age groups. The definition of "operator" covers any person who, for commercial purposes, operates or provides an online service and collects or maintains personal information from users.
Exemptions
The Act exempts nonprofit organizations, interactive gaming platforms that already comply with federal COPPA, Arkansas governmental entities, and public educational entities in Arkansas.
Enforcement
The Arkansas Attorney General has exclusive authority to enforce the Act. There is no private right of action. This means individual consumers cannot sue companies directly for violations, but the Attorney General can pursue enforcement actions on behalf of Arkansas residents.
Attorney General Enforcement
AG Tim Griffin has pursued privacy-adjacent enforcement actions under the Arkansas Deceptive Trade Practices Act and Personal Information Protection Act, without a comprehensive state privacy statute to rely on.
In March 2023, Griffin sued TikTok and parent company ByteDance in Cleburne County Circuit Court, alleging deceptive practices related to the collection and use of Arkansas users' personal information. The lawsuit survived early dismissal motions.
In June 2024, Griffin sued Temu, the Chinese e-commerce platform, calling it "a data-theft business that sells goods online as a means to an end." The complaint alleged violations of the ADTPA and PIPA based on Temu's alleged access to device data including camera, location, contacts, and text messages. As of early 2026, the lawsuit remained active.
These enforcement actions signal that the AG will use the full range of available state statutes, even without a comprehensive privacy statute, to address data privacy violations affecting Arkansas residents.
Federal Privacy Laws That Protect Arkansas Residents
Federal statutes provide significant privacy protections for Arkansas residents across specific sectors.

Health Insurance Portability and Accountability Act (HIPAA)
The HIPAA Privacy Rule establishes national standards for the protection of individually identifiable health information. HIPAA applies to covered entities including health plans, healthcare providers, and healthcare clearinghouses, as well as their business associates.
In 2023, the U.S. Department of Health and Human Services settled a HIPAA enforcement action with Arkansas-based business associate MedEvolve for $350,000 after the company exposed protected health information on an unsecured server.
Gramm-Leach-Bliley Act (GLBA)
The Gramm-Leach-Bliley Act requires financial institutions to explain their information-sharing practices to customers and to safeguard sensitive data. Arkansas residents who do business with banks, credit unions, insurance companies, and securities firms are protected by the GLBA's privacy and data security provisions.
Children's Online Privacy Protection Act (COPPA)
The federal COPPA law requires operators of websites and online services directed at children under 13 to obtain verifiable parental consent before collecting personal information. Beginning July 1, 2026, the Arkansas Children and Teens' Online Privacy Protection Act will extend similar protections to teens aged 13 through 16.
Fair Credit Reporting Act (FCRA)
The FCRA regulates the collection, dissemination, and use of consumer credit information. This law gives Arkansas consumers the right to access their credit reports, dispute inaccurate information, and limit who can access their credit data.
TAKE IT DOWN Act (2025)
Congress enacted the TAKE IT DOWN Act (Pub. L. 119-12) on May 19, 2025. The law prohibits the nonconsensual publication of intimate visual depictions, including AI-generated deepfakes. Covered platforms -- including major social media sites, dating apps, and image-hosting services -- were required to implement a notice-and-removal process by May 19, 2026, with the removal obligation requiring action within 48 hours of a valid request. The FTC began enforcement against non-compliant platforms in May 2026.
How Consumers Exercise Their Rights
Arkansas residents do not have a general state-law right to access, correct, or delete personal data held by most businesses, because Arkansas has no comprehensive privacy law. The rights that do exist are sector-specific.
Under the Children and Teens' Online Privacy Protection Act, once it takes effect July 1, 2026, parents and teens aged 13 through 16 can request deletion and correction of personal data collected by covered operators.
Under HIPAA, patients can request their medical records, ask for corrections, and receive a Notice of Privacy Practices explaining how their health information is used.
Under the FCRA, consumers can request free annual credit reports from each of the three major bureaus and dispute inaccurate entries.
Consumers who believe a business has violated Arkansas data privacy laws can file a complaint with the Consumer Protection Division of the Arkansas Attorney General's office.
This article is for informational purposes only and does not constitute legal advice. Data privacy laws change frequently, and enforcement interpretations evolve over time. Consult a licensed attorney in Arkansas for advice about your specific situation. Last reviewed: May 2026.
More Arkansas Laws
Frequently Asked Questions
Does Arkansas have a comprehensive consumer data privacy law?
No. Arkansas has not enacted a comprehensive consumer data privacy law. A 2025 attempt, the Arkansas Digital Responsibility, Safety, and Trust Act (SB258), died at sine die adjournment on May 5, 2025, and never took effect. Arkansas residents' privacy protections instead come from the Personal Information Protection Act (breach notification and data security), the Student Online Personal Information Protection Act, the Children and Teens' Online Privacy Protection Act, and federal sector laws like HIPAA and COPPA.
What must a business do if it suffers a data breach affecting Arkansas residents?
A business must notify affected Arkansas residents in the most expedient time possible and without unreasonable delay. If the breach affects more than 1,000 individuals, the business must also notify the Arkansas Attorney General within 45 days of determining there is a reasonable likelihood of harm, or at the same time it notifies affected individuals, whichever comes first. The Attorney General notification must be submitted through the official Data Breach Reporting Form on the AG website.
What types of personal information are protected under Arkansas law?
The Personal Information Protection Act covers a person's name combined with their Social Security number, driver's license number, financial account numbers with security codes or passwords, medical information, health insurance policy or subscriber identification numbers with unique identifiers, and biometric data. Arkansas does not have a broader comprehensive privacy law that defines additional categories of sensitive personal information.
What penalties can businesses face for violating Arkansas data privacy laws?
Violations of the Personal Information Protection Act are enforced through the Arkansas Deceptive Trade Practices Act, with civil penalties of up to $10,000 per violation, injunctive relief, and restitution. Willful violations are a Class A misdemeanor. Arkansas has no comprehensive privacy statute, so there is no separate APDPA penalty scheme. The Children and Teens' Online Privacy Protection Act, effective July 1, 2026, is enforced exclusively by the Attorney General with no private right of action.
How does the new Arkansas Children and Teens' Online Privacy Protection Act affect my teenager?
Effective July 1, 2026, the Arkansas Children and Teens' Online Privacy Protection Act (Act 952 of 2025) requires commercial websites and apps directed at teens aged 13 through 16 to obtain consent from either the teen or their parent before collecting personal information. Operators must provide clear notice of their data practices, honor deletion requests, and implement reasonable security measures. The law is enforced exclusively by the Arkansas Attorney General.
Can I sue a company directly for violating my Arkansas data privacy rights?
No. Arkansas has no comprehensive privacy statute, and the Personal Information Protection Act does not create a private right of action either. Only the Arkansas Attorney General can bring enforcement actions under Arkansas's data privacy and consumer protection statutes. If you believe your rights have been violated, file a complaint with the Consumer Protection Division of the Arkansas AG's office at arkansasag.gov.
What is the TAKE IT DOWN Act and how does it protect Arkansas residents?
The TAKE IT DOWN Act, signed into federal law on May 19, 2025, requires covered online platforms to remove nonconsensual intimate images, including AI-generated deepfakes, within 48 hours of a valid request. The platform takedown obligations took effect May 19, 2026, and the FTC enforces compliance. The law applies nationwide, including for Arkansas residents.
Updates
This page previously described a comprehensive Arkansas consumer privacy law, the 'Arkansas Personal Data Protection Act,' that was never enacted. Arkansas has no comprehensive consumer privacy statute; the 2025 bill that would have created one (SB258) died in the Senate at sine die adjournment. The page now describes that failed attempt accurately and focuses on Arkansas's real privacy protections: the Personal Information Protection Act (breach notification), student and teen data laws, and Attorney General enforcement.
Independently fact-checked against current primary sources.
Independently fact-checked against the cited primary sources
Governing law re-checked for recent changes
Governing law re-checked for recent changes
Major refresh: Reviewed Arkansas's privacy law landscape and confirmed the state has not enacted a comprehensive consumer privacy law. The 2025 attempt, the Arkansas Digital Responsibility, Safety, and Trust Act (SB258), died in the Senate at sine die adjournment on May 5, 2025 and did not become law. Updated opening summary, KeyTakeaways, and FAQ to reflect that Arkansas remains without a comprehensive privacy statute. Added Attorney General enforcement actions section covering Temu (June 2024) and TikTok (March 2023) lawsuits. Added TAKE IT DOWN Act (Pub. L. 119-12) federal overlay with updated enforcement status (FTC enforcement began May 2026). Preserved PIPA, breach notification, SOPIPA, and ACTOPPA sections verbatim. Title unchanged. Previous review: March 2026.
Reviewed and approved by an editor
The Law Behind This Article
This article rests on 5 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
Arkansas Code of 1987 Annotated
§ 4-110-101Short title.In forcecited in 2 of our articles
This chapter shall be known and cited as the “Personal Information Protection Act”.
Official text (excerpt) · as of 2020-11-06 · Read the full section at archive.org
Also relied on in: Arkansas Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 4-110-103Definitions.In force
As used in this chapter: (1)(A) “Breach of the security of the system” means unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by a person or business. (B) “Breach of the security of the system” does not…
Official text (excerpt) · as of 2020-11-06 · Read the full section at archive.org
§ 4-110-104Protection of personal information.In force
(a) A person or business shall take all reasonable steps to destroy or arrange for the destruction of a customer's records within its custody or control containing personal information that is no longer to be retained by the person or business by shredding, erasing, or otherwise modifying the…
Official text (excerpt) · as of 2020-11-06 · Read the full section at archive.org
§ 4-110-105Disclosure of security breaches.In force
(a)(1) Any person or business that acquires, owns, or licenses computerized data that includes personal information shall disclose any breach of the security of the system following discovery or notification of the breach of the security of the system to any resident of Arkansas whose unencrypted…
Official text (excerpt) · as of 2020-11-06 · Read the full section at archive.org
§ 6-18-109Student Online Personal Information Protection Act — Definitions.In force
(a) As used in this section: (1) “Covered information” means personally identifiable information or materials regarding a public school student in this state, in any media or format, when the information is: (A) Created or provided by a student or the student's parent or guardian to an operator…
Official text (excerpt) · as of 2020-11-06 · Read the full section at archive.org
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Arkansas Personal Information Protection Act (Ark. Code 4-110-101 et seq.)(law.justia.com)
- Arkansas Attorney General - Data Breach Reporting(arkansasag.gov).gov
- Ark. Code 4-110-103 - Definitions(law.justia.com)
- Ark. Code 4-110-104 - Protection of Personal Information(law.justia.com)
- Ark. Code 4-110-105 - Disclosure of Security Breaches(law.justia.com)
- Act 1030 of 2019 - PIPA Amendments(arkleg.state.ar.us).gov
- Act 1526 of 2005 - Original PIPA(arkleg.state.ar.us).gov
- Student Online Personal Information Protection Act (Ark. Code 6-18-109)(law.justia.com)
- HB 1717 - Children and Teens Online Privacy Protection Act(arkleg.state.ar.us).gov
- Act 952 of 2025 - Full Text(arkleg.state.ar.us).gov
- Arkansas AG - Consumer Protection Division(arkansasag.gov).gov
- NCSL - Security Breach Notification Laws(ncsl.org)
- HHS - HIPAA Privacy Rule Summary(hhs.gov).gov
- HHS - MedEvolve HIPAA Settlement (Arkansas)(hhs.gov).gov
- NCSL - Consumer Privacy 2025 Legislation(ncsl.org)
- Arkansas DESE - Data Privacy Resources(dese.ade.arkansas.gov).gov
- AG Griffin Sues Temu for Data Practices (June 2024)(arkansasag.gov).gov
- AG Griffin - TikTok Lawsuit Ruling (2024)(arkansasag.gov).gov
- FTC - TAKE IT DOWN Act Enforcement Begins (May 2026)(ftc.gov).gov