Idaho Privacy Law
Idaho has not enacted a comprehensive consumer privacy law, but it is not a state without privacy statutes. Its breach-notification chapter sits inside the Idaho identity-theft code and routes enforcement through whichever regulator already supervises the entity, and in 2026 the Legislature enacted the Stop Harms from Addictive Social Media Act, a chapter that regulates how large platforms estimate the age of Idaho account holders and what interface features they may show to children.
Sector-Specific Privacy Laws in Idaho
Stop Harms from Addictive Social Media Act (Idaho Code ch. 48-21)
House Bill 542 was signed on April 2, 2026 as Session Law Chapter 268 and took effect July 1, 2026, adding a new chapter 21 to title 48. It applies to a “covered social media platform” — defined in Idaho Code § 48-2102(4) as a platform whose group generated at least $1 billion in worldwide advertising revenue in one of the preceding three years. Under § 48-2103, within fourteen days after an account holder reaches twenty-five cumulative hours of use in a six-month period, the platform must estimate that holder’s age, and it may treat the holder as other than a child only if it can conclude with 80 percent confidence that the holder is older than sixteen; the confidence threshold rises to 90 percent at fifty cumulative hours. Section 48-2104 bars presenting “addictive interface features” — the statute names infinite scrolling, profile-based feeds, push notifications, auto-play video, personal reaction metrics and streak-style awards — or profile-based advertising in the feed of a child, and requires accounts for children to default to the most private settings. Section 48-2105 creates a private right of action for a child or parent, with statutory damages of $10,000 for reckless or knowing violations, and provides that a contract for a child’s account opened without verifiable parental consent is void as contrary to public policy, arbitration clauses included.
Idaho Consumer Protection Act (Idaho Code ch. 48-6)
Idaho Code § 48-603 declares a list of unfair methods of competition and unfair or deceptive acts in trade or commerce unlawful. Under § 48-606 the Attorney General may sue for a declaratory judgment, an injunction, restitution, civil penalties of up to $5,000 per violation, and investigative costs and fees; the same section directs the Attorney General, absent a written finding that delay would impair the Act, to notify a target before filing and give it a chance to execute an assurance of voluntary compliance or a consent judgment. Section 48-608 gives a private buyer or lessee who suffers an ascertainable loss the greater of actual damages or $1,000, and adds an enhanced penalty of $15,000 or treble damages where the defendant knew or should have known the conduct targeted an elderly or disabled person and caused one of five enumerated losses. In a class action, the same section caps the class total at the greater of actual damages or $1,000.
Student data — Idaho Code § 33-133
Idaho Code § 33-133 governs student data held in the state’s elementary, secondary and postsecondary longitudinal data systems. It defines personally identifiable student data to include not only a name and address but a student education unique identification number, a biometric record, and indirect identifiers such as date of birth, place of birth and mother’s maiden name, together with any information that alone or in combination would let a reasonable person in the school community identify the student with reasonable certainty. The section applies to state agencies and to cities, counties, districts and other political subdivisions.
Data Breach Notification in Idaho
Idaho Code § 28-51-105 sits in the identity-theft chapter of the commercial-transactions title. It does not require notice on discovery alone: an agency, individual or commercial entity that becomes aware of a breach must first conduct a good-faith, reasonable and prompt investigation into the likelihood that personal information has been or will be misused, and the duty to notify residents attaches only if that investigation finds misuse has occurred or is reasonably likely to occur. Section 28-51-104(2) defines the breach itself as the illegal acquisition of unencrypted computerized data that materially compromises the security, confidentiality or integrity of personal information, and § 28-51-104(5) limits “personal information” to a name combined with a Social Security number, a driver’s license or Idaho identification card number, or a financial account number with the code that would permit access. Substitute notice becomes available under § 28-51-104(4)(d) where notice would cost more than $25,000 or reach more than 50,000 Idaho residents. Idaho routes enforcement through a “primary regulator”: § 28-51-104(6) makes the Department of Finance the regulator for its licensees, the Department of Insurance for its licensees, the relevant federal regulator for federally chartered entities, and the Attorney General for everyone else. Under § 28-51-107 that regulator may sue to compel compliance, and an intentional failure to give notice carries a fine of up to $25,000 per breach.
Residents must be notified as soon as possible, in the most expedient time possible and without unreasonable delay, once an investigation finds misuse has occurred or is reasonably likely. A public agency must notify the Attorney General within 24 hours of discovery; a commercial entity may notify but is not required to. Complaints are taken by the Idaho Attorney General, which enforces the statute.
Recent Enforcement in Idaho
Block, Inc. (Cash App) — $416,856 to Idaho, July 2026. The Attorney General announced on July 21, 2026 that Idaho joined 46 states in a $45 million settlement with Block, Inc. resolving allegations that the company misrepresented Cash App’s safety and did not deliver the fraud protection it promised. The office’s account of the settlement describes a sign-up process requiring minimal identity verification, a promotion that encouraged users to post their account identifiers publicly, and years without phone support, during which scammers posed as Cash App representatives. Idaho’s share is $416,856. The settlement requires Block to maintain live customer support, stop misleading safety claims, end marketing practices known to increase fraud, and investigate and reimburse unauthorized transactions.
23andMe bankruptcy claims — just over $200,000 to Idaho, July 2026. In the same announcement the Attorney General reported that Idaho joined 42 states resolving bankruptcy claims arising from the 2023 breach of 23andMe, which exposed genetic data of 6.9 million customers worldwide including 38,537 Idahoans. Idaho received just over $200,000 from the $18 million allotted to states out of the bankruptcy estate. The office states that the multistate investigation found 23andMe failed to guard against credential-stuffing attacks, did not require multifactor authentication, did not detect a spike in login attempts, and did not fix known vulnerabilities before the data was accessed and offered for sale.
The Attorney General’s published breach log. The Consumer Protection Division publishes the security-breach notices it has received since January 1, 2021 on its Security Breaches page, listing each notifying agency or entity and the date of notification. Because § 28-51-105 obliges only public agencies to report, the list mixes mandatory agency filings with voluntary reports from commercial entities.
Pending Privacy Legislation
House Bill 744 of the 2026 session, titled “Capture or use of biometric identifiers,” was referred to the House Environment, Energy and Technology Committee and had not passed when the session adjourned. The comprehensive-privacy bills that other states have enacted have no Idaho counterpart on the books; the Legislature’s 2026 privacy output was House Bill 542, the Stop Harms from Addictive Social Media Act, which became Session Law Chapter 268.
Federal Privacy Laws That Apply in Idaho
Federal privacy law applies in Idaho by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The state-law counterpart to section 5 is the Idaho Consumer Protection Act (Idaho Code ch. 48-6), which the Idaho Attorney General enforces against businesses whose stated data practices differ from their actual ones.
Industry Rules That Reach Idaho Businesses
With no comprehensive state statute, most privacy obligations on a Idaho business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.
Two of those reach Idaho businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Idaho itself has none, and any business holding personal information about Idaho residents is subject to the state’s breach-notification statute described above.
Idaho Privacy Law FAQ
Does an Idaho business have to tell the Attorney General about a data breach?
What triggers the duty to notify Idaho residents after a breach?
Who enforces Idaho’s breach-notification statute?
What does the Stop Harms from Addictive Social Media Act require?
Can an Idaho parent sue a social media platform under the 2026 Act?
What can a consumer recover under the Idaho Consumer Protection Act?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- Idaho Code § 28-51-104 — Definitions statute
- Idaho Code § 28-51-105 — Disclosure of breach of security statute
- Idaho Code § 28-51-107 — Violations statute
- Idaho Code § 48-606 — Proceedings by attorney general statute
- Idaho Code § 48-608 — Actual and punitive damages statute
- Idaho Code § 33-133 — Student data statute
- House Bill 542 (2026) — Stop Harms from Addictive Social Media Act, ch. 268 legislation
- House Bill 744 (2026) — Capture or use of biometric identifiers legislation
- Idaho Attorney General — Security Breaches (notice log) agency
- Idaho Attorney General — $600,000 secured in two consumer data settlements (July 21, 2026) agency
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.