Arizona Privacy Law
Arizona has no comprehensive consumer privacy statute, but its breach-notification article is one of the more prescriptive in the country. It requires an investigation to be opened on a mere “security incident” before any breach is confirmed, runs a hard 45-day clock from the determination that a breach occurred, dictates four content elements for the notice, and channels every violation into the Consumer Fraud Act, where the Attorney General is the only permitted enforcer. The article also preempts municipal and county regulation of the subject outright.
Sector-Specific Privacy Laws in Arizona
Arizona Consumer Fraud Act (A.R.S. title 44, ch. 10, art. 7)
Section 44-1522 declares unlawful the use of deception, deceptive or unfair acts, fraud, false pretense, false promise, misrepresentation or concealment in connection with the sale or advertisement of merchandise. Section 44-1531 lets the Attorney General, on petition to a court that finds a wilful violation of § 44-1522, recover on the state’s behalf a civil penalty of not more than $10,000 per violation, and defines a wilful violation as one where the party “knew or should have known that his conduct was of the nature prohibited”. Because § 18-552(L) makes a knowing and wilful breach-notice violation an unlawful practice under § 44-1522, the Consumer Fraud Act is the enforcement vehicle for the breach article as well as for deceptive statements about data handling.
What counts as personal information (A.R.S. § 18-551)
The definition has two independent limbs. The first is a name paired with a “specified data element”, and Arizona’s list of those elements runs to nine: a Social Security number; a driver license or nonoperating identification license number; a private key unique to an individual used to authenticate or sign an electronic record; a financial account or card number with the code permitting access; a health insurance identification number; information about medical or mental health treatment or diagnosis by a health care professional; a passport number; a taxpayer identification number or an IRS identity protection PIN; and unique biometric data generated from measurement or analysis of human body characteristics used to authenticate the individual when accessing an online account. The second limb needs no name at all: a user name or email address combined with a password or security question and answer that allows access to an online account. “Redact” is defined precisely — altering or truncating a number so that no more than the last four digits are accessible and at least two digits have been removed — and “security incident” is defined separately from a breach, as an event creating reasonable suspicion that systems or data may have been compromised or that protective measures may have failed.
Law enforcement and court information security policies (A.R.S. § 18-552(O))
Arizona excludes the Department of Public Safety, county sheriff’s departments, municipal police departments, prosecution agencies and courts from the definition of “person” in § 18-551(6)(b), so the notification duties in § 18-552 do not reach them. In their place, § 18-552(O) imposes a separate obligation: each of those bodies must create and maintain an information security policy that includes notification procedures for a security system breach of its own systems.
Data Breach Notification in Arizona
Section 18-552(A) starts the process earlier than most states: on becoming aware of a “security incident” — an event creating reasonable suspicion that systems or data may have been compromised — a person that owns, maintains or licenses unencrypted and unredacted computerized personal information must conduct an investigation to promptly determine whether a breach occurred. If the investigation finds one, subsection B gives 45 days from that determination to notify affected individuals, and, where notice must reach more than 1,000 individuals, to notify both the three largest nationwide consumer reporting agencies and, in writing, the Attorney General and the director of the Arizona Department of Homeland Security. Subsection E fixes the notice content at four items: the approximate date of the breach, a brief description of the personal information involved, the toll-free numbers and addresses of the three largest nationwide consumer reporting agencies, and the toll-free number, address and website of the Federal Trade Commission or another federal agency that assists with identity theft. Substitute notice under subsection F(4) requires a cost over $50,000 or a class over 100,000 individuals, and consists of a written letter to the Attorney General demonstrating the facts plus a conspicuous website posting for at least 45 days. Subsection G provides a credential-reset route for breaches involving only online-account credentials. Subsection J removes the duty entirely where the person, an independent third-party forensic auditor or a law enforcement agency determines after a reasonable investigation that the breach has not resulted in and is not reasonably likely to result in substantial economic loss. Subsection K makes the notifications filed with the Attorney General and the homeland security director confidential under § 44-1525 and exempt from public-records disclosure, and subsection N excludes entities subject to Gramm-Leach-Bliley title V and HIPAA covered entities and business associates.
Residents must be notified within 45 days after determining that a breach occurred. Notify the Attorney General and the director of the Arizona Department of Homeland Security in writing where the breach requires notice to more than 1,000 individuals. Complaints are taken by the Arizona Attorney General, which enforces the statute.
How Arizona Enforces Its Privacy Laws
Only the Attorney General may enforce, and the penalty is capped per breach. Section 18-552(L) provides that a knowing and wilful violation is an unlawful practice under § 44-1522 and that “only the attorney general may enforce such a violation”, investigating and acting under the Consumer Fraud Act. The penalty formula is layered: the Attorney General may impose a civil penalty not exceeding the lesser of $10,000 per affected individual or the total economic loss sustained by affected individuals, but the maximum from a breach or series of related breaches may not exceed $500,000. The subsection preserves the Attorney General’s ability to recover restitution for affected individuals on top of the penalty.
Statewide preemption of local rules. Section 18-552(M) records a legislative determination that security system breach notification is a matter of statewide concern, states that the power to regulate it is preempted by the state, and provides that the article supersedes and preempts all municipal and county laws, charters, ordinances and rules relating to issues the article regulates.
Recent Enforcement in Arizona
State of Arizona v. Temu — Maricopa County Superior Court, December 2025. The Attorney General announced on December 2, 2025 that her office had sued the online shopping platform Temu in Maricopa County Superior Court under the Arizona Consumer Fraud Act. The office’s account of the complaint alleges that the app “secretly infiltrates users’ devices to access and harvest sensitive information, including the user’s precise physical location, the phone’s microphone and camera, and the user’s private activity on other apps”, collecting data far beyond what a shopping app requires and without users’ knowledge or consent. The office further alleges the app was purposely designed to evade front-end security review through multiple layers of encryption and is able to edit its own code once downloaded to a phone. The complaint also covers counterfeit merchandise, fabricated reviews, unauthorized charges, misappropriated Arizona trademarks and bait-and-switch sign-up schemes.
Blackbaud — $49.5 million multistate settlement, more than $1.8 million to Arizona. The Attorney General announced on October 5, 2023 that Arizona had joined 49 other attorneys general in settling with the software company Blackbaud over its data security practices and its response to a 2020 ransomware event in which unauthorized persons accessed its network and the personal information of millions of consumers. The office states that the company delayed or failed to notify affected individuals and downplayed the breach, and that Arizona’s share of the $49.5 million payment was more than $1.8 million. The injunctive terms bar Blackbaud from misrepresenting its data security and safeguarding practices and require incident and breach response plans, timely breach notification and customer support, reporting of security incidents to company leadership, database encryption, dark web monitoring, network segmentation, patch management, intrusion detection, access controls and penetration testing, together with third-party compliance assessments for seven years.
Pending Privacy Legislation
Senate Bill 1815, introduced by Senator Kuby in the Second Regular Session of the Fifty-seventh Legislature (2026) under the reference title “personal data; consumers; controllers; requirements”, would add a new article 27 to title 44, chapter 9 of the Arizona Revised Statutes regulating consumer data. It is the latest of a series rather than a departure: House Bill 2790 of the Second Regular Session of the Fifty-fifth Legislature (2022), titled “personal data; processing; security standards”, took a different structural route, adding a new article 5 headed “Data and Security Standards” to title 18, chapter 5 — the same chapter that holds the breach-notification article — and was not enacted. House Bill 2729 of the Fifty-fourth Legislature carried the same reference title in 2020. None of them has become law, and A.R.S. title 18, chapter 5 still contains only the breach article.
Federal Privacy Laws That Apply in Arizona
Federal privacy law applies in Arizona by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
Outside those federal sectors, Arizona obligations run through the state’s breach-notification statute and the Arizona Attorney General’s general consumer-protection authority rather than through a privacy statute of its own.
Industry Rules That Reach Arizona Businesses
With no comprehensive state statute, most privacy obligations on a Arizona business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.
Two of those reach Arizona businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Arizona itself has none, and any business holding personal information about Arizona residents is subject to the state’s breach-notification statute described above.
Arizona Privacy Law FAQ
When does the 45-day clock start under Arizona’s breach law?
When must the Arizona Attorney General be told about a breach?
What has to be in an Arizona breach notice?
Can an Arizona business skip notice if the breach caused no harm?
Does Arizona’s breach law cover biometric data and online account credentials?
Can an Arizona consumer sue over a breach-notification failure?
Can an Arizona city or county impose its own breach rules?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- A.R.S. § 18-551 — Definitions statute
- A.R.S. § 18-552 — Notification of security system breaches statute
- A.R.S. § 44-1531 — Violations; civil penalties statute
- Senate Bill 1815 (2026) — Consumer data; controllers; requirements legislation
- House Bill 2790 — Personal data; processing; security standards legislation
- Arizona Attorney General — Data-Breach Notification Law FAQ agency
- Arizona Attorney General — Suit against Temu over data collection and deceptive practices (December 2, 2025) agency
- Arizona Attorney General — $49.5 million settlement with Blackbaud over a data breach agency
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.