Arkansas Privacy Law
Arkansas has the most active privacy litigation posture of any state without a comprehensive privacy statute, and the two facts are connected. The Attorney General has brought first-of-their-kind suits under the Personal Information Protection Act and the Deceptive Trade Practices Act against Temu’s parent companies and against General Motors and OnStar, while every statute the General Assembly has passed to regulate minors’ use of social media — Act 689 of 2023 and Acts 900 and 901 of 2025 — has been enjoined by the same federal judge, with two appeals now consolidated in the Eighth Circuit. The comprehensive bill that would have changed the picture, Senate Bill 258 of 2025, failed on the Senate floor twice and died at sine die adjournment. What remains in force is a 2005 breach statute that counted medical information as personal information two decades before most states did, and a 2017 rewrite of the consumer-fraud statute that made private claims markedly harder to bring.
Sector-Specific Privacy Laws in Arkansas
Personal Information Protection Act (Ark. Code § 4-110-101 et seq.)
Enacted as Act 1526 of 2005, the subchapter states in § 4-110-102 that its purpose is to encourage individuals, businesses and state agencies that acquire, own or license personal information about Arkansas citizens to provide reasonable security for it. Section 4-110-104 carries two affirmative duties that do not depend on any breach: a person or business must take all reasonable steps to destroy or arrange for the destruction of a customer’s records containing personal information that it no longer retains, by shredding, erasing or otherwise rendering the information undecipherable; and a person or business that acquires, owns or licenses personal information about an Arkansas resident must implement and maintain reasonable security procedures and practices appropriate to the nature of the information. The definition of “business” in § 4-110-103(2) expressly includes an entity that destroys records and a state agency. Section 4-110-106 exempts a person or business regulated by a state or federal law providing greater protection and at least as thorough disclosure requirements, and § 4-110-107 makes any waiver of the subchapter contrary to public policy, void and unenforceable. Penalties come from outside the subchapter: a violation is punishable by action of the Attorney General under §§ 4-88-101 through 4-88-115, the Deceptive Trade Practices Act.
Act 1030 of 2019 — biometric data, the Attorney General clock and the five-year file
House Bill 1943, sponsored by Representative Cavenaugh and Senator Rapert and approved April 15, 2019, made three changes that account for most of what is distinctive about Arkansas breach practice today. It added subdivision (7)(E) to § 4-110-103, bringing biometric data into the definition of personal information and defining it as data generated by automatic measurements of an individual’s biological characteristics including fingerprints, a faceprint, a retinal or iris scan, hand geometry, voiceprint analysis, deoxyribonucleic acid, and any other unique biological characteristic used by the owner or licensee to uniquely authenticate identity when the individual accesses a system or account. It rewrote § 4-110-105(b) to require, where a breach affects the personal information of more than one thousand individuals, disclosure to the Attorney General at the same time the breach is disclosed to an affected individual or within forty-five days after the person or business determines that there is a reasonable likelihood of harm to customers, whichever occurs first. And it added § 4-110-105(g), requiring the person or business to retain a copy of the written determination of the breach and its supporting documentation for five years, to produce that file to the Attorney General within thirty days of a written request, and providing that the retained determination and documentation are confidential and not subject to public disclosure.
Deceptive Trade Practices Act (Ark. Code § 4-88-101 et seq.), as amended by Act 986 of 2017
The chapter supplies the enforcement machinery for the Personal Information Protection Act and is the basis of the Attorney General’s consumer-privacy suits. Act 986 of 2017, which became law on April 7, 2017 without the Governor’s signature, narrowed the private side of it considerably. It rewrote § 4-88-113(f) so that the claimant is a person who suffers “an actual financial loss” as a result of “his or her reliance on the use of a practice declared unlawful by this chapter”, and may recover that loss rather than actual damages generally. It added a definition of actual financial loss in § 4-88-102 as an ascertainable amount equal to the difference between the amount paid for goods or services and their actual market value. It added § 4-88-113(f)(1)(B), prohibiting a private class action under the subsection unless the claim is asserted for a violation of Amendment 89 of the Arkansas Constitution, and § 4-88-113(f)(2), requiring a claimant to prove individually that he or she suffered an actual financial loss proximately caused by his or her reliance. It also created § 4-88-116, giving any party in an action under § 4-88-113(f) the right to a jury trial. Attorney’s fees remain discretionary with the court.
Social Media Safety Act (Act 689 of 2023, Ark. Code § 4-88-1101 et seq.)
Act 689 required a social media company to verify the age of an account holder in Arkansas, to obtain the express consent of a parent or legal guardian before allowing a minor to hold an account, and to perform reasonable age verification through a third-party vendor before allowing access to the platform, with liability provisions at § 4-88-1103 including damages resulting from a minor accessing a social media platform. It has never been enforceable. On August 31, 2023 the United States District Court for the Western District of Arkansas preliminarily enjoined it, and on March 31, 2025 Chief Judge Timothy L. Brooks granted NetChoice summary judgment and permanently enjoined the Act in its entirety, holding the definitions of “social media platform” and “social media company” content based and therefore subject to strict scrutiny they did not survive, and holding the Act void for vagueness because it failed to define adequately which online services it regulated. The State’s appeal is pending in the Eighth Circuit as No. 25-1889.
Data Breach Notification in Arkansas
Section 4-110-105(a) requires a person or business that acquires, owns or licenses computerized data including personal information to disclose a breach of the security of the system to any Arkansas resident whose unencrypted personal information was or is reasonably believed to have been acquired by an unauthorized person, in the most expedient time and manner possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Subsection (d) supplies the harm test: notification is not required if, after a reasonable investigation, the person or business determines that there is no reasonable likelihood of harm to customers. The definition of personal information in § 4-110-103(7) has counted medical information since 2005 — defined in subdivision (5) as any individually identifiable information, in electronic or physical form, regarding an individual’s medical history or medical treatment or diagnosis by a health care professional — alongside a Social Security number, a driver’s license or Arkansas identification card number, and a financial account or card number with its access code, and since Act 1030 of 2019 it has also counted biometric data. Substitute notice under § 4-110-105(e)(3) requires the cost of notice to exceed $250,000, the affected class to exceed 500,000, or contact information to be insufficient, and then consists of email notice where an address is held, conspicuous website posting, and notification by statewide media. Subsection (b)(1) puts a person or business holding data it does not own on an immediate duty to tell the owner or licensee.
Residents must be notified in the most expedient time and manner possible and without unreasonable delay; no fixed number of days for individual notice. Disclose to the Attorney General where more than 1,000 individuals are affected, at the same time as individual notice or within 45 days of determining a reasonable likelihood of harm, whichever occurs first. Complaints are taken by the Arkansas Attorney General, which enforces the statute.
How Arkansas Enforces Its Privacy Laws
Breach violations are prosecuted as deceptive trade practices. The Personal Information Protection Act contains no penalty schedule of its own. Its penalties section provides that any violation of the subchapter is punishable by action of the Attorney General under §§ 4-88-101 through 4-88-115, which are the investigative, injunctive and penalty provisions of the Deceptive Trade Practices Act. That is why the Attorney General’s data-privacy complaints are pleaded under both statutes together rather than under the breach statute alone.
The 2017 amendments left the public enforcement route untouched. Act 986 of 2017 rewrote only § 4-88-113(f), the subsection creating the private claim, and added the jury-trial section. The reliance requirement, the actual-financial-loss measure and the class-action prohibition apply by their terms to actions brought under that subsection. The Attorney General’s authority elsewhere in §§ 4-88-101 through 4-88-115 was not amended, so the changes narrow who else can sue rather than what the state can pursue.
Recent Enforcement in Arkansas
State v. PDD Holdings and WhaleCo (Temu) — Cleburne County Circuit Court, June 25, 2024. Attorney General Tim Griffin announced on June 25, 2024 that he had sued Temu’s parent companies, PDD Holdings Inc. and WhaleCo Inc., for violations of both the Arkansas Deceptive Trade Practices Act and the Arkansas Personal Information Protection Act, describing it as a first-of-its-kind state lawsuit against the company. The office’s statement characterises Temu as functionally malware and spyware rather than an online marketplace, alleging that it is purposefully designed to gain unrestricted access to a user’s phone operating system, that it can override data privacy settings on users’ devices, and that it monetizes that unauthorized collection of data. The release notes that Apple suspended Temu from its app store in 2023 and that a congressional investigation was then under way. The complaint, filed in Cleburne County Circuit Court, seeks an order enjoining the deceptive trade practices and the violations of users’ privacy, civil penalties, and all other monetary and equitable relief to which the State is entitled.
State v. General Motors and OnStar — driving data sold to insurers, February 26, 2025. The Attorney General announced on February 26, 2025 that his office had sued General Motors and its subsidiary OnStar over the collection and sale of detailed driving data. The office’s account is that GM and OnStar improperly collected that data and sold it to third parties, which in turn sold it to insurance companies that used it to deny consumers coverage or increase their rates, while OnStar was advertised as offering better driving, safety and vehicle operability. The suit alleges violations of the Arkansas Deceptive Trade Practices Act and unjust enrichment, and seeks monetary relief, injunctive relief, and attorneys’ fees and expenses. Unlike the Temu action it is not pleaded under the Personal Information Protection Act, which reaches breaches of security rather than disclosures the company made deliberately.
Pending Privacy Legislation
The comprehensive bill of the 2025 regular session did not survive it. Senate Bill 258, the Arkansas Digital Responsibility, Safety, and Trust Act, was introduced by Senator Penzo with Senator Meeks on February 19, 2025, heard twice in the Senate Transportation, Technology and Legislative Affairs Committee, amended three times, reported Do Pass as amended on April 2, 2025 and engrossed on April 7. It was then read the third time and failed on April 8, taken up again under suspended rules and read the third time and failed again on April 10, and died on the Senate calendar when the 95th General Assembly adjourned sine die on May 5, 2025. Nothing has replaced it, so Arkansas residents have no statutory rights of access, correction, deletion or opt-out. The state’s recent legislative activity in this area has instead gone to minors and social media, and all of it is currently enjoined: Act 689 of 2023 permanently, and Acts 900 and 901 of 2025 preliminarily, with consolidated appeals pending in the Eighth Circuit.
Federal Privacy Laws That Apply in Arkansas
Federal privacy law applies in Arkansas by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The state-law counterpart to section 5 is the Deceptive Trade Practices Act (Ark. Code § 4-88-101 et seq.), as amended by Act 986 of 2017, which the Arkansas Attorney General enforces against businesses whose stated data practices differ from their actual ones.
Industry Rules That Reach Arkansas Businesses
With no comprehensive state statute, most privacy obligations on a Arkansas business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.
Two of those reach Arkansas businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Arkansas itself has none, and any business holding personal information about Arkansas residents is subject to the state’s breach-notification statute described above.
Arkansas Privacy Law FAQ
When does an Arkansas breach have to be reported to the Attorney General?
How long must an Arkansas business keep its record of a breach determination?
Does Arkansas have a comprehensive consumer privacy law?
Is biometric data covered by Arkansas’s breach statute?
Can Arkansas consumers bring a class action under the Deceptive Trade Practices Act?
Is Arkansas’s social media age-verification law in effect?
What must an Arkansas plaintiff prove to recover under the Deceptive Trade Practices Act?
Can an Arkansas business contract out of the Personal Information Protection Act?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- Act 1526 of 2005 — Personal Information Protection Act as enacted statute
- Act 1030 of 2019 — biometric data, Attorney General notice and record retention statute
- Act 986 of 2017 — Deceptive Trade Practices Act damages, class actions and jury trial statute
- Act 689 of 2023 — Social Media Safety Act statute
- Senate Bill 258 (2025) — Arkansas Digital Responsibility, Safety, and Trust Act, status history legislation
- Arkansas Attorney General — suit against Temu’s parent companies agency
- Arkansas Attorney General — suit against General Motors and OnStar agency
- NetChoice, LLC v. Griffin — opinion permanently enjoining Act 689 (W.D. Ark. Mar. 31, 2025) decision
- NetChoice, LLC v. Griffin — docket, W.D. Ark. No. 5:23-cv-05105 docket
- NetChoice v. Griffin — opinion preliminarily enjoining Act 900 (W.D. Ark. Apr. 20, 2026) decision
- NetChoice v. Griffin — docket, W.D. Ark. No. 5:25-cv-05140 docket
- Eighth Circuit consolidated briefing order, Nos. 26-1096 and 26-1962 (May 18, 2026) docket
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.