Idaho

Idaho Privacy Law

Idaho has not enacted a comprehensive consumer privacy law, but it is not a state without privacy statutes. Its breach-notification chapter sits inside the Idaho identity-theft code and routes enforcement through whichever regulator already supervises the entity, and in 2026 the Legislature enacted the Stop Harms from Addictive Social Media Act, a chapter that regulates how large platforms estimate the age of Idaho account holders and what interface features they may show to children.

Sector-Specific Privacy Laws in Idaho

Stop Harms from Addictive Social Media Act (Idaho Code ch. 48-21)

House Bill 542 was signed on April 2, 2026 as Session Law Chapter 268 and took effect July 1, 2026, adding a new chapter 21 to title 48. It applies to a “covered social media platform” — defined in Idaho Code § 48-2102(4) as a platform whose group generated at least $1 billion in worldwide advertising revenue in one of the preceding three years. Under § 48-2103, within fourteen days after an account holder reaches twenty-five cumulative hours of use in a six-month period, the platform must estimate that holder’s age, and it may treat the holder as other than a child only if it can conclude with 80 percent confidence that the holder is older than sixteen; the confidence threshold rises to 90 percent at fifty cumulative hours. Section 48-2104 bars presenting “addictive interface features” — the statute names infinite scrolling, profile-based feeds, push notifications, auto-play video, personal reaction metrics and streak-style awards — or profile-based advertising in the feed of a child, and requires accounts for children to default to the most private settings. Section 48-2105 creates a private right of action for a child or parent, with statutory damages of $10,000 for reckless or knowing violations, and provides that a contract for a child’s account opened without verifiable parental consent is void as contrary to public policy, arbitration clauses included.

Idaho Consumer Protection Act (Idaho Code ch. 48-6)

Idaho Code § 48-603 declares a list of unfair methods of competition and unfair or deceptive acts in trade or commerce unlawful. Under § 48-606 the Attorney General may sue for a declaratory judgment, an injunction, restitution, civil penalties of up to $5,000 per violation, and investigative costs and fees; the same section directs the Attorney General, absent a written finding that delay would impair the Act, to notify a target before filing and give it a chance to execute an assurance of voluntary compliance or a consent judgment. Section 48-608 gives a private buyer or lessee who suffers an ascertainable loss the greater of actual damages or $1,000, and adds an enhanced penalty of $15,000 or treble damages where the defendant knew or should have known the conduct targeted an elderly or disabled person and caused one of five enumerated losses. In a class action, the same section caps the class total at the greater of actual damages or $1,000.

Student data — Idaho Code § 33-133

Idaho Code § 33-133 governs student data held in the state’s elementary, secondary and postsecondary longitudinal data systems. It defines personally identifiable student data to include not only a name and address but a student education unique identification number, a biometric record, and indirect identifiers such as date of birth, place of birth and mother’s maiden name, together with any information that alone or in combination would let a reasonable person in the school community identify the student with reasonable certainty. The section applies to state agencies and to cities, counties, districts and other political subdivisions.

Data Breach Notification in Idaho

Idaho Code § 28-51-105 sits in the identity-theft chapter of the commercial-transactions title. It does not require notice on discovery alone: an agency, individual or commercial entity that becomes aware of a breach must first conduct a good-faith, reasonable and prompt investigation into the likelihood that personal information has been or will be misused, and the duty to notify residents attaches only if that investigation finds misuse has occurred or is reasonably likely to occur. Section 28-51-104(2) defines the breach itself as the illegal acquisition of unencrypted computerized data that materially compromises the security, confidentiality or integrity of personal information, and § 28-51-104(5) limits “personal information” to a name combined with a Social Security number, a driver’s license or Idaho identification card number, or a financial account number with the code that would permit access. Substitute notice becomes available under § 28-51-104(4)(d) where notice would cost more than $25,000 or reach more than 50,000 Idaho residents. Idaho routes enforcement through a “primary regulator”: § 28-51-104(6) makes the Department of Finance the regulator for its licensees, the Department of Insurance for its licensees, the relevant federal regulator for federally chartered entities, and the Attorney General for everyone else. Under § 28-51-107 that regulator may sue to compel compliance, and an intentional failure to give notice carries a fine of up to $25,000 per breach.

Residents must be notified as soon as possible, in the most expedient time possible and without unreasonable delay, once an investigation finds misuse has occurred or is reasonably likely. A public agency must notify the Attorney General within 24 hours of discovery; a commercial entity may notify but is not required to. Complaints are taken by the Idaho Attorney General, which enforces the statute.

Recent Enforcement in Idaho

Block, Inc. (Cash App) — $416,856 to Idaho, July 2026. The Attorney General announced on July 21, 2026 that Idaho joined 46 states in a $45 million settlement with Block, Inc. resolving allegations that the company misrepresented Cash App’s safety and did not deliver the fraud protection it promised. The office’s account of the settlement describes a sign-up process requiring minimal identity verification, a promotion that encouraged users to post their account identifiers publicly, and years without phone support, during which scammers posed as Cash App representatives. Idaho’s share is $416,856. The settlement requires Block to maintain live customer support, stop misleading safety claims, end marketing practices known to increase fraud, and investigate and reimburse unauthorized transactions.

23andMe bankruptcy claims — just over $200,000 to Idaho, July 2026. In the same announcement the Attorney General reported that Idaho joined 42 states resolving bankruptcy claims arising from the 2023 breach of 23andMe, which exposed genetic data of 6.9 million customers worldwide including 38,537 Idahoans. Idaho received just over $200,000 from the $18 million allotted to states out of the bankruptcy estate. The office states that the multistate investigation found 23andMe failed to guard against credential-stuffing attacks, did not require multifactor authentication, did not detect a spike in login attempts, and did not fix known vulnerabilities before the data was accessed and offered for sale.

The Attorney General’s published breach log. The Consumer Protection Division publishes the security-breach notices it has received since January 1, 2021 on its Security Breaches page, listing each notifying agency or entity and the date of notification. Because § 28-51-105 obliges only public agencies to report, the list mixes mandatory agency filings with voluntary reports from commercial entities.

Pending Privacy Legislation

House Bill 744 of the 2026 session, titled “Capture or use of biometric identifiers,” was referred to the House Environment, Energy and Technology Committee and had not passed when the session adjourned. The comprehensive-privacy bills that other states have enacted have no Idaho counterpart on the books; the Legislature’s 2026 privacy output was House Bill 542, the Stop Harms from Addictive Social Media Act, which became Session Law Chapter 268.

Federal Privacy Laws That Apply in Idaho

Federal privacy law applies in Idaho by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The state-law counterpart to section 5 is the Idaho Consumer Protection Act (Idaho Code ch. 48-6), which the Idaho Attorney General enforces against businesses whose stated data practices differ from their actual ones.

Industry Rules That Reach Idaho Businesses

With no comprehensive state statute, most privacy obligations on a Idaho business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.

Two of those reach Idaho businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Idaho itself has none, and any business holding personal information about Idaho residents is subject to the state’s breach-notification statute described above.

Idaho Privacy Law FAQ

Does an Idaho business have to tell the Attorney General about a data breach?
Not as a general matter. Idaho Code § 28-51-105(1) requires a public agency to notify the Attorney General’s office within twenty-four hours of discovering a breach of its system. The Attorney General’s Security Breaches page states that a commercial entity that experiences a breach may notify the office but is not required to do so, and gives an address and an email box for entities that choose to report.
What triggers the duty to notify Idaho residents after a breach?
Idaho Code § 28-51-105(1) sets an investigation-first sequence. On becoming aware of a breach the entity must conduct a good-faith, reasonable and prompt investigation into the likelihood that personal information has been or will be misused. Notice to affected Idaho residents is required only if that investigation determines misuse has occurred or is reasonably likely to occur, and it must then be given as soon as possible and without unreasonable delay.
Who enforces Idaho’s breach-notification statute?
It depends on the entity. Idaho Code § 28-51-104(6) defines a “primary regulator”: the Department of Finance for entities it licenses, the Department of Insurance for entities it licenses, the relevant federal regulator for federally chartered or licensed entities, and the Attorney General for all agencies and all other entities. Section 28-51-107 lets that primary regulator bring a civil action to compel compliance and enjoin further violations, and sets a fine of up to $25,000 per breach for an intentional failure to notify.
What does the Stop Harms from Addictive Social Media Act require?
The Act, codified at Idaho Code ch. 48-21 and effective July 1, 2026, applies to platforms whose corporate group made at least $1 billion in worldwide advertising revenue in one of the prior three years. Section 48-2103 requires age estimation once an account holder passes twenty-five cumulative hours of use, and treats the holder as a child unless the platform can conclude with 80 percent confidence that the holder is over sixteen. Section 48-2104 prohibits showing children infinite scrolling, profile-based feeds, push notifications, auto-play video and reaction metrics, requires the most private default settings, and conditions a child’s account on verifiable parental consent.
Can an Idaho parent sue a social media platform under the 2026 Act?
Idaho Code § 48-2105(2) gives a child or parent a private right of action for declaratory or injunctive relief, damages including harm to mental health and emotional distress, court costs and attorney fees, for a negligent, reckless or knowing violation. Where the violation was reckless or knowing, the prevailing claimant recovers the greater of actual damages or $10,000 in statutory damages, and punitive damages are available for a consistent pattern of such conduct. Claims must be brought within three years of when the plaintiff knew or reasonably should have known of the violation. The section also provides a defence for platforms that used reasonable means and efforts to comply.
What can a consumer recover under the Idaho Consumer Protection Act?
Idaho Code § 48-608(1) lets a person who purchased or leased goods or services and suffered an ascertainable loss recover the greater of actual damages or $1,000, with restitution, injunctive relief and, at the court’s discretion, punitive damages for repeated or flagrant violations. In a class action the same subsection caps the class recovery at the greater of actual damages or $1,000 for the class as a whole. Subsection (2) adds an enhanced penalty of $15,000 or treble damages, whichever is greater, where an elderly or disabled person was targeted and suffered one of five listed losses.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.