Nebraska
Nebraska Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Nebraska's Financial Data Protection and Consumer Notification of Data Security Breach Act, under Neb. Rev. Stat. 87-803, requires businesses to notify affected residents as soon as possible and without unreasonable delay after a breach. The Nebraska Attorney General must receive notice no later than the time notice is provided to individuals.
If your business handles personal information belonging to Nebraska residents, a data breach triggers specific legal obligations under the Nebraska Financial Data Protection and Consumer Notification of Data Security Breach Act. Neb. Rev. Stat. 87-801 et seq. sets out the requirements for determining when a breach has occurred, who must be notified, what information triggers notification, and the consequences of noncompliance. Nebraska's law has evolved significantly since its original enactment, with recent amendments expanding the definition of personal information to include biometric data and login credentials.
This guide covers the full scope of Nebraska's breach notification requirements, including what personal information triggers the law, who must be notified, the notification timeline, the class-action liability shield for cybersecurity events, penalties, and how the state's broader data privacy framework interacts with breach obligations.
Who Must Comply With Nebraska's Breach Notification Law
Nebraska's law applies to any individual or commercial entity that conducts business in Nebraska and owns, licenses, or maintains computerized data that includes personal information about a Nebraska resident. This includes businesses physically located outside Nebraska if they hold data belonging to Nebraska residents.
The law distinguishes between data owners and third-party data maintainers. When a third party that maintains data on behalf of another entity becomes aware of a breach, it must notify the data owner or licensee "as soon as possible." The data owner then carries the primary responsibility to notify affected consumers and the Attorney General.
Government Entities
Nebraska's breach notification law applies to state and local government entities that maintain personal information about Nebraska residents. Government agencies have the same notification obligations as private businesses.
What Qualifies as a Breach
Under Neb. Rev. Stat. 87-802, a "breach of the security of the system" means the unauthorized acquisition of unencrypted computerized data that compromises the security, confidentiality, or integrity of personal information maintained by the individual or commercial entity.
Good Faith Exception
A good faith acquisition of personal information by an employee or agent of the individual or commercial entity does not constitute a breach, provided the personal information is not used for an unauthorized purpose or subject to further unauthorized disclosure.
Encryption Safe Harbor
Nebraska provides a clear safe harbor for encrypted data. A breach does not trigger notification requirements if the personal information was encrypted, and the encryption key or other means to decipher the information was not also acquired. If the encryption key was compromised along with the data, the safe harbor does not apply.
Risk of Harm Analysis
Nebraska law includes a risk assessment component. After discovering a possible breach, the entity must conduct a reasonable and prompt investigation to determine the likelihood that personal information has been or will be used for an unauthorized purpose. Notification is required only if the investigation determines that the use of the information for an unauthorized purpose has occurred or is reasonably likely to occur.
Personal Information That Triggers Notification
Nebraska's definition of personal information is one of the broadest among U.S. states. Under Neb. Rev. Stat. 87-802, personal information means a Nebraska resident's first name or first initial and last name combined with any one or more of the following data elements:
- Social Security number
- Driver's license number or state identification card number
- Account number or credit or debit card number combined with any required security code, access code, or password that would permit access to the account
- Unique electronic identification number or routing code combined with any required security code, access code, or password
- Biometric data (fingerprint, voice print, retina or iris image, or other unique physical representation or digital representation of biometric data)
- Username or email address combined with a password or security question and answer that would permit access to an online account
The inclusion of biometric data and username/password combinations places Nebraska among the states with the most comprehensive definitions of protected personal information.

Personal information does not include publicly available information that is lawfully made available to the general public from federal, state, or local government records.
Notification Timeline
Nebraska requires notification "as soon as possible and without unreasonable delay" under Neb. Rev. Stat. 87-803. The state does not impose a specific day count, giving entities flexibility to investigate before notifying.
When Delay Is Permitted
Delay in notification is reasonable if it is necessary to:
- Determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system
- Comply with a request from law enforcement that notification may impede a criminal investigation
When a delay occurs for law enforcement purposes, notification must be made as soon as possible after law enforcement determines disclosure no longer compromises the investigation.
Who Must Be Notified
Affected Individuals
Every Nebraska resident whose unencrypted personal information was or is reasonably believed to have been acquired by an unauthorized person must be notified. The notification must include:
- A description of the incident in general terms
- The type of personal information that was subject to the breach
- The telephone number, address, and website of the entity providing notice
- The toll-free telephone numbers, addresses, and websites of the major consumer reporting agencies
- The toll-free telephone number, address, and website of the Federal Trade Commission
- A statement advising the individual to remain vigilant by reviewing account statements and monitoring credit reports
Nebraska Attorney General
The Nebraska Attorney General must be notified no later than the time affected individuals are notified. The AG notification must include:
- A description of the nature of the breach
- The number of Nebraska residents affected
- Steps the entity has taken related to the breach
- A copy of the notification sent to affected individuals
Consumer Reporting Agencies
When a breach affects more than 500 Nebraska residents, the entity must also notify the nationwide consumer reporting agencies without unreasonable delay. This notification must include the timing, distribution, and content of the notices sent to affected individuals.
How to Provide Notification
Nebraska permits the following notification methods:
- Written notice sent by mail to the last known address of the individual
- Electronic notice if the entity's primary means of communication with the individual is by electronic means, consistent with the E-SIGN Act ()
- Telephone notification
Substitute Notice
Substitute notice is available when:
- The cost of notification would exceed $75,000
- The affected class exceeds 100,000 Nebraska residents
- The entity does not have sufficient contact information
Substitute notice must consist of all of the following:
- Email notice to individuals for whom the entity has an email address
- Conspicuous posting of the notice on the entity's website
- Notification to major statewide media outlets
Note that Nebraska's substitute notice thresholds ($75,000 cost and 100,000 affected individuals) are lower than many other states, making it harder to qualify for substitute notice.
Class-Action Liability Shield for Cybersecurity Events
Nebraska does not have a NIST- or ISO-framework-based affirmative defense against tort claims. What it does have is narrower: under Neb. Rev. Stat. 87-1201, enacted by LB241 (2025), a private entity is not liable in a class action resulting from a cybersecurity event unless the event was caused by willful, wanton, or gross negligence on the entity's part.
A "cybersecurity event" is defined as unauthorized access to, or disruption or misuse of, an information system or nonpublic information. The shield applies only to class actions; it does not bar individual lawsuits, and it does not limit the Attorney General's regulatory enforcement authority under the breach notification law or the Consumer Protection Act.

Enforcement and Penalties
Nebraska's breach notification law is enforced by the Nebraska Attorney General under the Consumer Protection Act (Neb. Rev. Stat. 59-1601 et seq.). Violations of the breach notification statute are treated as violations of the Consumer Protection Act.
The Attorney General may seek:
- Injunctive relief to stop ongoing violations
- Civil penalties up to $25,000 per violation
- Restitution for affected consumers
There is no private right of action for breach notification violations. Only the Attorney General can bring enforcement actions.

Exemptions
Certain entities are exempt from Nebraska's breach notification requirements if they comply with equivalent federal notification frameworks:
- GLBA-regulated financial institutions that comply with the Interagency Guidance on Response Programs for Unauthorized Access to Customer Information
- HIPAA-covered entities that comply with HIPAA breach notification requirements
- Entities subject to other federal breach notification laws that provide equivalent or greater protection
These entities must still maintain their federal compliance to benefit from the exemption.
This article provides general legal information about Nebraska data privacy laws and breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in Nebraska for guidance specific to your situation.
More Nebraska Laws
Frequently Asked Questions
How long does a business have to notify Nebraska residents of a data breach?
Nebraska law requires notification 'as soon as possible and without unreasonable delay' but does not set a specific day deadline. A delay is permitted to determine the scope of the breach and restore system integrity, or to comply with a law enforcement request. The entity must also complete a reasonable and prompt investigation to determine whether the information is likely to be used for an unauthorized purpose before notification is required.
Does Nebraska require businesses to notify the Attorney General after a data breach?
Yes. The Nebraska Attorney General must be notified no later than the time affected individuals are notified. The notification must include a description of the breach, the number of Nebraska residents affected, the steps taken in response, and a copy of the notification sent to individuals. Consumer reporting agencies must also be notified when more than 500 Nebraska residents are affected.
Does Nebraska's breach notification law cover biometric data?
Yes. Nebraska is one of the states that includes biometric data in its definition of personal information. Fingerprints, voice prints, retina or iris images, and other unique physical or digital representations of biometric data are all covered. A breach of biometric data combined with a name triggers the full notification requirements.
Does Nebraska have a cybersecurity liability shield for businesses?
Not the framework-based affirmative defense some other states use. Nebraska's law (Neb. Rev. Stat. 87-1201, enacted by LB241 in 2025) instead shields private entities from class-action liability for a cybersecurity event unless the event was caused by willful, wanton, or gross negligence. It does not apply to individual lawsuits or to Attorney General enforcement.
Can individuals sue for a breach notification violation in Nebraska?
No. Nebraska's breach notification law does not create a private right of action. Only the Nebraska Attorney General can enforce the statute under the Consumer Protection Act, with civil penalties up to $25,000 per violation. Individuals may pursue common law claims such as negligence; Nebraska's class-action liability shield (Neb. Rev. Stat. 87-1201) may limit exposure to class claims arising from a cybersecurity event, but it does not affect individual suits.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Governing law re-checked for recent changes
Corrected the breach-notification law's mischaracterized AG-notice timing ('at the same time' to the statute's actual 'not later than' deadline), removed an added 'materially' qualifier from the statutory breach definition, and replaced a fabricated NIST/ISO-framework 'cybersecurity safe harbor' (falsely attributed to Neb. Rev. Stat. 87-806) with Nebraska's real, narrower liability protection: the LB241 (2025) class-action shield at Neb. Rev. Stat. 87-1201.
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 5 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
United States Code Title 15
§ 7001General rule of validityIn forcecited in 17 of our articles
Notwithstanding any statute, regulation, or other rule of law (other than this subchapter and subchapter II), with respect to any transaction in or affecting interstate or foreign commerce— a signature, contract, or other record relating to such transaction may not be denied legal effect, validity, or enforceability solely because it is in electronic form; and a contract relating to such transaction may not be denied legal effect, validity, or enforceability solely because an electronic signature or electronic record was used in its formation. This subchapter does not— limit, alter, or otherwise affect any requirement imposed by a statute, regulation, or rule of law relating to the rights and obligations of persons under such statute, regulation, or rule of law other than a requirement that contracts or other records be written, signed, or in nonelectronic form; or require any person to agree to use or accept electronic records or electronic signatures, other than a governmental agency with respect to a record other than a contract to which it is a party.
Official text (excerpt) · as of 2026-07-28 · Read the full section at uscode.house.gov
Cited in 132 court opinionsMost recently applied by a court: 2026
Leading cases: Metropolitan Regional Information Systems, Inc. v. American Home Realty Network, Inc. (District Court, D. Maryland 2012, 904 F. Supp. 2d 530) · Cutrone v. Mortgage Electronic Registration Systems, Inc. (District Court, E.D. New York 2013, 981 F. Supp. 2d 144) · Blatt v. Capital One Auto Finance, Inc. (District Court, M.D. Tennessee 2017, 237 F. Supp. 3d 688)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Mississippi Data Breach Notification Laws: Reporting Rules & Timelines (2026), Mississippi Data Privacy Laws: Breach Notification & Consumer Rights (2026), Montana Data Privacy Laws: MCDPA Consumer Rights Guide (2026)
Nebraska Revised Statutes, Chapter 87: TRADE PRACTICES
§ 87-1201Cybersecurity event; liability of private entityIn force
(1) For purposes of this section: (a) Cybersecurity event means an event resulting in unauthorized access to, or disruption or misuse of, an information system or nonpublic information stored on an information system; (b) Information system means: (i) A discrete set of electronic information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of electronic nonpublic information; or (ii) A specialized system, including an industrial or process control system, a telephone switching and private branch exchange system, and an environmental control system; (c) Nonpublic information means information that is not publicly available and concerns a person that, because of a name, number, personal mark, or other identifier, can be used to identify such person, in combination with the following: (i) A social security number; (ii) A driver's license number or state identification card number; (iii) A financial account number or credit or debit card number; (iv) A security code, access code, or password that would permit access to such person's financial accounts; or (v) Any biometric record; (d) Private entity means a…
Official text (excerpt) · as of 2026-07-29 · Read the full section at nebraskalegislature.gov
§ 87-801Act, how citedIn forcecited in 2 of our articles
Sections 87-801 to 87-808 shall be known and may be cited as the Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006.
Official text (excerpt) · as of 2026-07-29 · Read the full section at nebraskalegislature.gov
Cited in 1 court opinionsMost recently applied by a court: 2019
Leading cases: Prime Foods for Processing and Trading v. Greater Omaha Packing Co., Inc. (District Court, D. Nebraska 2019)
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Nebraska Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 87-802Terms, definedIn forcecited in 2 of our articles
For purposes of the Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006: (1) Breach of the security of the system means the unauthorized acquisition of unencrypted computerized data that compromises the security, confidentiality, or integrity of personal information maintained by an individual or a commercial entity. Good faith acquisition of personal information by an employee or agent of an individual or a commercial entity for the purposes of the individual or the commercial entity is not a breach of the security of the system if the personal information is not used or subject to further unauthorized disclosure.
Official text (excerpt) · as of 2026-07-29 · Read the full section at nebraskalegislature.gov
§ 87-803Breach of security; investigation; notice to resident; notice to Attorney GeneralIn force
(1) An individual or a commercial entity that conducts business in Nebraska and that owns or licenses computerized data that includes personal information about a resident of Nebraska shall, when it becomes aware of a breach of the security of the system, conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal information has been or will be used for an unauthorized purpose. If the investigation determines that the use of information about a Nebraska resident for an unauthorized purpose has occurred or is reasonably likely to occur, the individual or commercial entity shall give notice to the affected Nebraska resident. Notice shall be made as soon as possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the computerized data system.
Official text (excerpt) · as of 2026-07-29 · Read the full section at nebraskalegislature.gov
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- Neb. Rev. Stat. 87-801 et seq. - Financial Data Protection Act(nebraskalegislature.gov).gov
- Neb. Rev. Stat. 87-802 - Definitions(nebraskalegislature.gov).gov
- Neb. Rev. Stat. 87-803 - Notification Requirements(nebraskalegislature.gov).gov
- Neb. Rev. Stat. 87-1201, Cybersecurity event; liability of private entity(nebraskalegislature.gov).gov
- Nebraska Attorney General(ago.nebraska.gov).gov