Arkansas

Arkansas Privacy Law

Arkansas has the most active privacy litigation posture of any state without a comprehensive privacy statute, and the two facts are connected. The Attorney General has brought first-of-their-kind suits under the Personal Information Protection Act and the Deceptive Trade Practices Act against Temu’s parent companies and against General Motors and OnStar, while every statute the General Assembly has passed to regulate minors’ use of social media — Act 689 of 2023 and Acts 900 and 901 of 2025 — has been enjoined by the same federal judge, with two appeals now consolidated in the Eighth Circuit. The comprehensive bill that would have changed the picture, Senate Bill 258 of 2025, failed on the Senate floor twice and died at sine die adjournment. What remains in force is a 2005 breach statute that counted medical information as personal information two decades before most states did, and a 2017 rewrite of the consumer-fraud statute that made private claims markedly harder to bring.

Sector-Specific Privacy Laws in Arkansas

Personal Information Protection Act (Ark. Code § 4-110-101 et seq.)

Enacted as Act 1526 of 2005, the subchapter states in § 4-110-102 that its purpose is to encourage individuals, businesses and state agencies that acquire, own or license personal information about Arkansas citizens to provide reasonable security for it. Section 4-110-104 carries two affirmative duties that do not depend on any breach: a person or business must take all reasonable steps to destroy or arrange for the destruction of a customer’s records containing personal information that it no longer retains, by shredding, erasing or otherwise rendering the information undecipherable; and a person or business that acquires, owns or licenses personal information about an Arkansas resident must implement and maintain reasonable security procedures and practices appropriate to the nature of the information. The definition of “business” in § 4-110-103(2) expressly includes an entity that destroys records and a state agency. Section 4-110-106 exempts a person or business regulated by a state or federal law providing greater protection and at least as thorough disclosure requirements, and § 4-110-107 makes any waiver of the subchapter contrary to public policy, void and unenforceable. Penalties come from outside the subchapter: a violation is punishable by action of the Attorney General under §§ 4-88-101 through 4-88-115, the Deceptive Trade Practices Act.

Act 1030 of 2019 — biometric data, the Attorney General clock and the five-year file

House Bill 1943, sponsored by Representative Cavenaugh and Senator Rapert and approved April 15, 2019, made three changes that account for most of what is distinctive about Arkansas breach practice today. It added subdivision (7)(E) to § 4-110-103, bringing biometric data into the definition of personal information and defining it as data generated by automatic measurements of an individual’s biological characteristics including fingerprints, a faceprint, a retinal or iris scan, hand geometry, voiceprint analysis, deoxyribonucleic acid, and any other unique biological characteristic used by the owner or licensee to uniquely authenticate identity when the individual accesses a system or account. It rewrote § 4-110-105(b) to require, where a breach affects the personal information of more than one thousand individuals, disclosure to the Attorney General at the same time the breach is disclosed to an affected individual or within forty-five days after the person or business determines that there is a reasonable likelihood of harm to customers, whichever occurs first. And it added § 4-110-105(g), requiring the person or business to retain a copy of the written determination of the breach and its supporting documentation for five years, to produce that file to the Attorney General within thirty days of a written request, and providing that the retained determination and documentation are confidential and not subject to public disclosure.

Deceptive Trade Practices Act (Ark. Code § 4-88-101 et seq.), as amended by Act 986 of 2017

The chapter supplies the enforcement machinery for the Personal Information Protection Act and is the basis of the Attorney General’s consumer-privacy suits. Act 986 of 2017, which became law on April 7, 2017 without the Governor’s signature, narrowed the private side of it considerably. It rewrote § 4-88-113(f) so that the claimant is a person who suffers “an actual financial loss” as a result of “his or her reliance on the use of a practice declared unlawful by this chapter”, and may recover that loss rather than actual damages generally. It added a definition of actual financial loss in § 4-88-102 as an ascertainable amount equal to the difference between the amount paid for goods or services and their actual market value. It added § 4-88-113(f)(1)(B), prohibiting a private class action under the subsection unless the claim is asserted for a violation of Amendment 89 of the Arkansas Constitution, and § 4-88-113(f)(2), requiring a claimant to prove individually that he or she suffered an actual financial loss proximately caused by his or her reliance. It also created § 4-88-116, giving any party in an action under § 4-88-113(f) the right to a jury trial. Attorney’s fees remain discretionary with the court.

Social Media Safety Act (Act 689 of 2023, Ark. Code § 4-88-1101 et seq.)

Act 689 required a social media company to verify the age of an account holder in Arkansas, to obtain the express consent of a parent or legal guardian before allowing a minor to hold an account, and to perform reasonable age verification through a third-party vendor before allowing access to the platform, with liability provisions at § 4-88-1103 including damages resulting from a minor accessing a social media platform. It has never been enforceable. On August 31, 2023 the United States District Court for the Western District of Arkansas preliminarily enjoined it, and on March 31, 2025 Chief Judge Timothy L. Brooks granted NetChoice summary judgment and permanently enjoined the Act in its entirety, holding the definitions of “social media platform” and “social media company” content based and therefore subject to strict scrutiny they did not survive, and holding the Act void for vagueness because it failed to define adequately which online services it regulated. The State’s appeal is pending in the Eighth Circuit as No. 25-1889.

Data Breach Notification in Arkansas

Section 4-110-105(a) requires a person or business that acquires, owns or licenses computerized data including personal information to disclose a breach of the security of the system to any Arkansas resident whose unencrypted personal information was or is reasonably believed to have been acquired by an unauthorized person, in the most expedient time and manner possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Subsection (d) supplies the harm test: notification is not required if, after a reasonable investigation, the person or business determines that there is no reasonable likelihood of harm to customers. The definition of personal information in § 4-110-103(7) has counted medical information since 2005 — defined in subdivision (5) as any individually identifiable information, in electronic or physical form, regarding an individual’s medical history or medical treatment or diagnosis by a health care professional — alongside a Social Security number, a driver’s license or Arkansas identification card number, and a financial account or card number with its access code, and since Act 1030 of 2019 it has also counted biometric data. Substitute notice under § 4-110-105(e)(3) requires the cost of notice to exceed $250,000, the affected class to exceed 500,000, or contact information to be insufficient, and then consists of email notice where an address is held, conspicuous website posting, and notification by statewide media. Subsection (b)(1) puts a person or business holding data it does not own on an immediate duty to tell the owner or licensee.

Residents must be notified in the most expedient time and manner possible and without unreasonable delay; no fixed number of days for individual notice. Disclose to the Attorney General where more than 1,000 individuals are affected, at the same time as individual notice or within 45 days of determining a reasonable likelihood of harm, whichever occurs first. Complaints are taken by the Arkansas Attorney General, which enforces the statute.

How Arkansas Enforces Its Privacy Laws

Breach violations are prosecuted as deceptive trade practices. The Personal Information Protection Act contains no penalty schedule of its own. Its penalties section provides that any violation of the subchapter is punishable by action of the Attorney General under §§ 4-88-101 through 4-88-115, which are the investigative, injunctive and penalty provisions of the Deceptive Trade Practices Act. That is why the Attorney General’s data-privacy complaints are pleaded under both statutes together rather than under the breach statute alone.

The 2017 amendments left the public enforcement route untouched. Act 986 of 2017 rewrote only § 4-88-113(f), the subsection creating the private claim, and added the jury-trial section. The reliance requirement, the actual-financial-loss measure and the class-action prohibition apply by their terms to actions brought under that subsection. The Attorney General’s authority elsewhere in §§ 4-88-101 through 4-88-115 was not amended, so the changes narrow who else can sue rather than what the state can pursue.

Recent Enforcement in Arkansas

State v. PDD Holdings and WhaleCo (Temu) — Cleburne County Circuit Court, June 25, 2024. Attorney General Tim Griffin announced on June 25, 2024 that he had sued Temu’s parent companies, PDD Holdings Inc. and WhaleCo Inc., for violations of both the Arkansas Deceptive Trade Practices Act and the Arkansas Personal Information Protection Act, describing it as a first-of-its-kind state lawsuit against the company. The office’s statement characterises Temu as functionally malware and spyware rather than an online marketplace, alleging that it is purposefully designed to gain unrestricted access to a user’s phone operating system, that it can override data privacy settings on users’ devices, and that it monetizes that unauthorized collection of data. The release notes that Apple suspended Temu from its app store in 2023 and that a congressional investigation was then under way. The complaint, filed in Cleburne County Circuit Court, seeks an order enjoining the deceptive trade practices and the violations of users’ privacy, civil penalties, and all other monetary and equitable relief to which the State is entitled.

State v. General Motors and OnStar — driving data sold to insurers, February 26, 2025. The Attorney General announced on February 26, 2025 that his office had sued General Motors and its subsidiary OnStar over the collection and sale of detailed driving data. The office’s account is that GM and OnStar improperly collected that data and sold it to third parties, which in turn sold it to insurance companies that used it to deny consumers coverage or increase their rates, while OnStar was advertised as offering better driving, safety and vehicle operability. The suit alleges violations of the Arkansas Deceptive Trade Practices Act and unjust enrichment, and seeks monetary relief, injunctive relief, and attorneys’ fees and expenses. Unlike the Temu action it is not pleaded under the Personal Information Protection Act, which reaches breaches of security rather than disclosures the company made deliberately.

Pending Privacy Legislation

The comprehensive bill of the 2025 regular session did not survive it. Senate Bill 258, the Arkansas Digital Responsibility, Safety, and Trust Act, was introduced by Senator Penzo with Senator Meeks on February 19, 2025, heard twice in the Senate Transportation, Technology and Legislative Affairs Committee, amended three times, reported Do Pass as amended on April 2, 2025 and engrossed on April 7. It was then read the third time and failed on April 8, taken up again under suspended rules and read the third time and failed again on April 10, and died on the Senate calendar when the 95th General Assembly adjourned sine die on May 5, 2025. Nothing has replaced it, so Arkansas residents have no statutory rights of access, correction, deletion or opt-out. The state’s recent legislative activity in this area has instead gone to minors and social media, and all of it is currently enjoined: Act 689 of 2023 permanently, and Acts 900 and 901 of 2025 preliminarily, with consolidated appeals pending in the Eighth Circuit.

Federal Privacy Laws That Apply in Arkansas

Federal privacy law applies in Arkansas by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The state-law counterpart to section 5 is the Deceptive Trade Practices Act (Ark. Code § 4-88-101 et seq.), as amended by Act 986 of 2017, which the Arkansas Attorney General enforces against businesses whose stated data practices differ from their actual ones.

Industry Rules That Reach Arkansas Businesses

With no comprehensive state statute, most privacy obligations on a Arkansas business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.

Two of those reach Arkansas businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Arkansas itself has none, and any business holding personal information about Arkansas residents is subject to the state’s breach-notification statute described above.

Arkansas Privacy Law FAQ

When does an Arkansas breach have to be reported to the Attorney General?
Section 4-110-105(b)(2), added by Act 1030 of 2019, applies where a breach affects the personal information of more than one thousand individuals. Disclosure to the Attorney General is due at the same time the breach is disclosed to an affected individual, or within forty-five days after the person or business determines that there is a reasonable likelihood of harm to customers — whichever of those two occurs first.
How long must an Arkansas business keep its record of a breach determination?
Five years. Section 4-110-105(g)(1) requires a person or business to retain a copy of the written determination of a breach of the security of a system and its supporting documentation for five years from the date of determination. If the Attorney General submits a written request, subdivision (g)(2) requires the file to be sent within thirty days of receipt of the request, and subdivision (g)(3) makes the retained determination and documentation confidential and not subject to public disclosure.
Does Arkansas have a comprehensive consumer privacy law?
No. Senate Bill 258 of the 2025 regular session, the Arkansas Digital Responsibility, Safety, and Trust Act, was sponsored by Senators Penzo and Meeks and introduced on February 19, 2025. It was reported Do Pass as amended from the Senate Transportation, Technology and Legislative Affairs Committee, amended and engrossed, then read the third time and failed on the Senate floor on April 8 and again on April 10, 2025, and died on the Senate calendar at sine die adjournment on May 5, 2025.
Is biometric data covered by Arkansas’s breach statute?
Since 2019. Act 1030 added § 4-110-103(7)(E), which lists biometric data as an element of personal information and defines it as data generated by automatic measurements of an individual’s biological characteristics, including without limitation fingerprints, a faceprint, a retinal or iris scan, hand geometry, voiceprint analysis, deoxyribonucleic acid, or any other unique biological characteristic used by the owner or licensee to uniquely authenticate the individual’s identity when the individual accesses a system or account.
Can Arkansas consumers bring a class action under the Deceptive Trade Practices Act?
Not since Act 986 of 2017. Section 4-88-113(f)(1)(B) states that a private class action under the subsection is prohibited unless the claim is being asserted for a violation of Amendment 89 of the Arkansas Constitution. Subdivision (f)(2) reinforces the individual character of the claim by requiring a claimant to prove individually that he or she suffered an actual financial loss proximately caused by his or her reliance on the use of a practice the chapter declares unlawful.
Is Arkansas’s social media age-verification law in effect?
No part of it is. Act 689 of 2023 was permanently enjoined on March 31, 2025 in NetChoice, LLC v. Griffin, No. 5:23-cv-5105 (W.D. Ark.). Acts 900 and 901 of 2025, passed to modify and supplement Act 689, were each preliminarily enjoined by the same court — Act 901 on December 15, 2025 and Act 900 on April 20, 2026, the day before it was to take effect. The appeals from the Act 900 and Act 901 injunctions were consolidated in the Eighth Circuit as Nos. 26-1096 and 26-1962 on May 18, 2026.
What must an Arkansas plaintiff prove to recover under the Deceptive Trade Practices Act?
Section 4-88-113(f), as rewritten by Act 986 of 2017, requires an actual financial loss proximately caused by the plaintiff’s own reliance on a practice the chapter declares unlawful. “Actual financial loss” is defined in § 4-88-102 as an ascertainable amount of money equal to the difference between the amount paid for goods or services and their actual market value. Section 4-88-116 gives any party in such an action the right to a jury trial where the action was pending or filed on or after the effective date of the 2017 act.
Can an Arkansas business contract out of the Personal Information Protection Act?
Section 4-110-107 states that any waiver of a provision of the subchapter is contrary to public policy, void, and unenforceable. Section 4-110-106(b) separately provides that the exemption for entities regulated by more protective state or federal law does not relieve a person or business from a duty to comply with other state and federal requirements regarding the protection and privacy of personal information.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.