Alaska

Alaska Privacy Law

Alaska has not enacted a comprehensive consumer privacy law, but chapter 48 of title 45 — the Alaska Personal Information Protection Act, enacted as House Bill 65 and chapter 92 SLA 08 — is a single statute covering breach disclosure, credit-report security freezes, limits on the use of Social Security numbers, disposal of records containing personal information, and a court procedure for declaring an identity-theft victim factually innocent. Its breach provisions invert the usual pattern: the Attorney General hears from a company that has decided not to notify.

Sector-Specific Privacy Laws in Alaska

Use of Social Security numbers — AS 45.48.400–.480

AS 45.48.400 bars a person from intentionally communicating or otherwise making available to the general public an individual’s Social Security number, printing it on a card required to access products or services, requiring its transmission over the internet unless the connection is secure or the number is encrypted, requiring its use to access a website unless a password, unique personal identification number or other authentication device is also required, or printing it on material mailed to the individual outside the exceptions listed. AS 45.48.480(a) makes a knowing violation of AS 45.48.400–.430 subject to a civil penalty of up to $3,000 payable to the state, and subsection (b) lets an individual sue for actual economic damages, court costs and full reasonable attorney fees.

Disposal of records — AS 45.48.500–.590

AS 45.48.500(a) requires a business and a governmental agency, when disposing of records that contain personal information, to take all reasonable measures necessary to protect against unauthorized access to or use of the records. Subsections (b) and (c) remove liability once control of the records has been relinquished to a third party engaged in record destruction that was selected in compliance with the article, or to the individual to whom the records pertain. AS 45.48.550 sets a civil penalty of up to $3,000 for a knowing violation, and AS 45.48.560 gives an individual damaged by a violation an action to enjoin further violations and to recover actual economic damages, court costs and full reasonable attorney fees.

Factual declaration of innocence — AS 45.48.600–.640

AS 45.48.600(a) lets a victim of identity theft petition the superior court for a determination that the victim is factually innocent of a crime, where the perpetrator was arrested for, cited for or convicted of the crime using the victim’s identity, a criminal complaint was filed against the perpetrator, and the victim’s identity was mistakenly associated with a record of conviction. Subsection (b) permits the department to petition, or the court to act on its own motion. AS 45.48.610 allows the determination to be made on declarations, affidavits, police reports or other material, relevant and reliable information.

Data Breach Notification in Alaska

AS 45.48.010(a) requires a covered person who owns or licenses personal information about a state resident to disclose a breach of the information system to each resident whose information was subject to it. The distinctive provision is subsection (c): disclosure is not required if, after an appropriate investigation and after written notification to the attorney general, the covered person determines there is not a reasonable likelihood that harm to consumers has resulted or will result. That determination must be documented in writing, the documentation retained for five years, and the statute provides that the notification to the Attorney General is not a public record open to inspection. AS 45.48.030(3) sets the substitute-notice thresholds higher than most states: a notice cost exceeding $150,000 or an affected class exceeding 300,000 state residents. AS 45.48.040(a) requires notice to the nationwide consumer credit reporting agencies where more than 1,000 state residents are notified, and subsection (c) exempts collectors subject to the Gramm-Leach-Bliley Act from that requirement. AS 45.48.060 makes a waiver of the breach provisions void and unenforceable. On penalties, AS 45.48.080(a) makes a governmental agency liable for up to $500 for each resident not notified, capped at $50,000 in total; subsection (b) treats a violation by a non-governmental collector as an unfair or deceptive act under AS 45.50.471–.561 while applying the same $500-per-resident and $50,000 caps and limiting damages under AS 45.50.531 to actual economic damages not exceeding $500.

Residents must be notified in the most expeditious time possible and without unreasonable delay, subject to law-enforcement delay and the scope of the breach. Written notice to the Attorney General is required where the covered person decides not to disclose after concluding harm is not reasonably likely; the 1,000-person threshold triggers notice to nationwide consumer credit reporting agencies. Complaints are taken by the Alaska Attorney General, which enforces the statute.

Recent Enforcement in Alaska

23andMe bankruptcy settlement — $165,447 to Alaska, July 2026. The Department of Law announced on July 14, 2026 that Acting Attorney General Cori Mills joined 42 attorneys general in a settlement with the bankruptcy trustee for 23andMe over the 2023 breach that compromised genetic data of 6.9 million customers worldwide, including 19,541 Alaskans. The settlement includes $150 million in allowed claims for states; because the bankruptcy estate is finite, recovery is limited to $18 million paid immediately and allocated in part by the number of affected customers, of which Alaska received $165,447. The release states the multistate investigation found 23andMe failed to employ safeguards against credential-stuffing attacks including password blocklists and multifactor authentication, failed to implement rate limiting or intrusion prevention, failed to implement logging and monitoring, failed to investigate a massive spike in login attempts, failed to remediate known vulnerabilities, and failed to review and test design features. The Department adds that alongside general consumer-protection and privacy laws, Alaskans are protected by the state’s genetic privacy law, which it describes as making it illegal to transfer genetic data without the informed written consent of the person whose genes the data reflects.

Block, Inc. (Cash App) multistate settlement, July 2026. The Department of Law announced on July 8, 2026 that Acting Attorney General Mills joined the $45 million multistate settlement with Block, Inc. over deceptive practices on Cash App. The Alaska announcement sits alongside the parallel releases issued by the other participating states in the same coalition.

Pending Privacy Legislation

No comprehensive consumer-privacy statute has been enacted in Alaska. The Personal Information Protection Act remains the governing scheme: House Bill 65 of the 25th Legislature became chapter 92 SLA 08 on June 13, 2008, and section 10 of that Act set the general effective date at July 1, 2009. Its title describes the full scope — breaches of security involving personal information, credit report and credit score security freezes, protection of Social Security numbers, care and disposal of records, identity theft, credit and debit cards, and disclosure of the names and addresses of permanent fund dividend applicants.

Federal Privacy Laws That Apply in Alaska

Federal privacy law applies in Alaska by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

Outside those federal sectors, Alaska obligations run through the state’s breach-notification statute and the Alaska Attorney General’s general consumer-protection authority rather than through a privacy statute of its own.

Industry Rules That Reach Alaska Businesses

With no comprehensive state statute, most privacy obligations on a Alaska business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.

Two of those reach Alaska businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Alaska itself has none, and any business holding personal information about Alaska residents is subject to the state’s breach-notification statute described above.

Alaska Privacy Law FAQ

When does an Alaska business have to notify the Attorney General about a breach?
When it decides not to notify consumers. AS 45.48.010(c) provides that disclosure to residents is not required if, after an appropriate investigation and after written notification to the attorney general of this state, the covered person determines there is not a reasonable likelihood that harm to the consumers whose personal information has been acquired has resulted or will result from the breach. That is the reverse of the pattern in most states, where the Attorney General hears about the breaches that are notified.
Is the Alaska Attorney General’s breach notification a public record?
No. The last sentence of AS 45.48.010(c) provides that “the notification required by this subsection may not be considered a public record open to inspection by the public.” The same subsection requires the underlying determination to be documented in writing and the documentation maintained for five years.
What is the maximum penalty for failing to give breach notice in Alaska?
AS 45.48.080 sets a civil penalty of up to $500 for each state resident who was not notified, with a total that may not exceed $50,000. That cap applies both to governmental agencies under subsection (a) and, under subsection (b)(1), to non-governmental information collectors, which are otherwise treated as having committed an unfair or deceptive act under AS 45.50.471–.561 but are expressly removed from the civil penalties in AS 45.50.551.
Can an Alaskan recover damages for a breach?
AS 45.48.080(b)(2) limits what is available. Damages awarded against an information collector under AS 45.50.531 are limited to actual economic damages that do not exceed $500, and damages under AS 45.50.537 are limited to actual economic damages. Separate rights exist elsewhere in the chapter: AS 45.48.480(b) and AS 45.48.560 each allow actual economic damages, court costs and full reasonable attorney fees for the Social Security number and record-disposal articles respectively.
When may an Alaska business use substitute notice?
AS 45.48.030(3) permits it where the information collector demonstrates that the cost of providing notice would exceed $150,000, that the affected class of state residents to be notified exceeds 300,000, or that it does not have sufficient contact information. Substitute notice then consists of all three of email notice where an address is held, conspicuous posting on the collector’s website if it maintains one, and notice to major statewide media.
Can an Alaska contract waive the Personal Information Protection Act?
AS 45.48.060 states in a single sentence that “a waiver of AS 45.48.010 - 45.48.090 is void and unenforceable.” That covers the breach-disclosure article. The Act also contains a separate procedure at AS 45.48.600 by which an identity-theft victim may petition the superior court for a determination of factual innocence.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.