Nebraska Privacy Law
Nebraska’s two privacy statutes each ask for something the neighbouring states do not. Under the Data Privacy Act, a controller that wants the benefit of the cure period must give the Attorney General not merely a written statement that the violation is fixed but “supportive documentation to show how such violation was cured”. Under the breach statute, the remedy the Attorney General may recover is not a civil penalty per violation at all — it is direct economic damages for each affected Nebraskan injured, alongside subpoena power. The office has used its consumer-protection and data-security laws in the state courts rather than through multistate settlements: its suit against Change Healthcare, UnitedHealth Group and Optum survived a motion to dismiss in a case the court described as involving the exposure of nearly 900,000 Nebraskans.
The Nebraska Data Privacy Act (NDPA)
The Data Privacy Act occupies thirty sections of chapter 87, from § 87-1101 to § 87-1130, and follows the Texas model in dispensing with numeric thresholds. Section 87-1103 states the applicability test by reference to the federal Small Business Administration definition rather than to a consumer count or a revenue share. Section 87-1118 then keeps a duty on the small businesses the test otherwise excludes: a person described by § 87-1103(1)(c) may not engage in the sale of personal data that is sensitive data without prior consumer consent, and is subject to the § 87-1124 penalty for doing so. Section 87-1108(2) gives controllers forty-five days to respond to a rights request, extendable once by a further forty-five where reasonably necessary given the complexity and number of requests, provided the consumer is told within the initial period and given the reason. Subsection (4) makes responses free up to twice annually and places the burden of demonstrating that a request is manifestly unfounded, excessive or repetitive on the controller. Subsection (6) resolves a problem most statutes leave open: a controller that obtained personal data from a source other than the consumer complies with a deletion request either by retaining a record of the request and the minimum data needed to keep the consumer’s data deleted, using it for nothing else, or by opting the consumer out of all non-exempt processing of that data.
| Effective date | January 1, 2025 |
|---|---|
| Citation | Neb. Rev. Stat. §§ 87-1101 to 87-1130 |
| Enforced by | Nebraska Attorney General |
| Maximum penalty | Up to $7,500 for each violation under Neb. Rev. Stat. § 87-1124(1) |
| Private right of action | No, enforcement by the state only |
| Right to cure | 30 days, with no sunset, but the cure must be documented (Neb. Rev. Stat. § 87-1122) |
Who Must Comply
The NDPA reaches a business that conducts business in Nebraska or produces products or services consumed by Nebraska residents, and processes or engages in the sale of personal data, and is not a small business as determined under the federal Small Business Administration definition — though § 87-1118 still bars a small business from selling sensitive data without consent.
Curing a violation requires supportive documentation showing how it was cured, not merely a statement that it was, and the Act reaches every business that is not a federally defined small business.
Consumer Rights Under the NDPA
Residents of Nebraska can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.
Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.
Sector-Specific Privacy Laws in Nebraska
Age verification for material harmful to minors (Neb. Rev. Stat. §§ 87-1001 to 87-1005)
Immediately preceding the Data Privacy Act in the same chapter, §§ 87-1001 to 87-1005 impose an age-verification regime on commercial entities. Section 87-1001 states how the act is cited and § 87-1002 defines its terms. Section 87-1003 requires a commercial entity to use a reasonable age verification method in the circumstances the section specifies. Section 87-1004 authorises a civil action, and § 87-1005 fixes the applicability of the act. The placement matters for reading the chapter: the sections share chapter 87 with the Uniform Deceptive Trade Practices Act at § 87-301 et seq., the breach act at §§ 87-801 to 87-808, and the Data Privacy Act at §§ 87-1101 to 87-1130, so a single Nebraska chapter carries the state’s deceptive-practices, breach, age-verification and comprehensive privacy regimes together.
Financial data security and disposal (Neb. Rev. Stat. §§ 87-806, 87-808)
Section 87-808 imposes the data-security duty that sits behind the notification obligation, and § 87-806(2) supplies its enforcement route: a violation of § 87-808 “shall be considered a violation of section 59-1602 and be subject to the Consumer Protection Act and any other law which provides for the implementation and enforcement of section 59-1602”, and expressly does not give rise to a private cause of action. That routing is what makes the Consumer Protection Act at § 59-1601 et seq. the operative remedial statute for security failures in Nebraska, as distinct from notification failures, which § 87-806(1) addresses through subpoenas and direct economic damages. Section 87-806 therefore splits the two halves of a breach case into two different remedial regimes.
Uniform Deceptive Trade Practices Act (Neb. Rev. Stat. § 87-301 et seq.)
Nebraska’s deceptive-practices statute occupies the same chapter as its privacy laws and supplies the general prohibition on which the Attorney General’s consumer-protection litigation rests. Section 87-302 enumerates the deceptive trade practices the Act reaches, and the chapter runs on through § 87-303.05 and the sections that follow, which govern remedies and enforcement. In practice the Attorney General has pleaded Nebraska’s consumer protection and data security laws together in privacy litigation rather than relying on any single provision, as in the Lancaster County actions against Change Healthcare and against TikTok.
Data Breach Notification in Nebraska
The Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006 puts an investigation between the breach and the notice. Section 87-803(1) requires an individual or commercial entity conducting business in Nebraska that owns or licenses computerized data including personal information, on becoming aware of a breach, to “conduct in good faith a reasonable and prompt investigation to determine the likelihood that personal information has been or will be used for an unauthorized purpose”, and to notify the affected Nebraska resident only if that investigation finds unauthorized use has occurred or is reasonably likely to occur. Subsection (2) then ties the regulator’s notice to the resident’s: where notice is required, the entity shall “not later than the time when notice is provided to the Nebraska resident” also notify the Attorney General, with no threshold number. Subsection (3) puts a holder of data it does not own or license on a duty to notify and cooperate with the owner, with cooperation including sharing information relevant to the breach but excluding proprietary information. The definition of personal information at § 87-802(5)(a) reaches, alongside a Social Security number, a motor vehicle operator’s license or state identification card number and an account or card number with its access code, two elements many states omit: a unique electronic identification number or routing code with its required security code, and unique biometric data such as a fingerprint, voice print, or retina or iris image. Section 87-806(1) sets the remedy, and it is not a penalty schedule: for purposes of the Act the Attorney General may issue subpoenas and “seek and recover direct economic damages for each affected Nebraska resident injured by a violation of section 87-803”. Section 87-806(2) treats a violation of the data-security section at § 87-808 as a violation of § 59-1602 subject to the Consumer Protection Act, and states that it does not give rise to a private cause of action.
Residents must be notified as soon as possible and without unreasonable delay after the investigation concludes that unauthorized use has occurred or is reasonably likely. The Attorney General is notified no later than the time notice goes to the resident — no headcount threshold. Complaints are taken by the Nebraska Attorney General, which enforces the statute.
How the NDPA Is Enforced
A cure that has to be evidenced. Section 87-1122 requires the Attorney General, before bringing an action under § 87-1124, to notify a controller or processor in writing not later than the thirtieth day before filing, identifying the specific provisions of the Act alleged to have been violated. The action may not be brought if, within the thirty-day period, the controller or processor cures the identified violation and provides the Attorney General two things: a written statement that the violation was cured “and supportive documentation to show how such violation was cured”, and an express written statement that it will not commit any such violation after the cure. The documentation requirement distinguishes Nebraska from Indiana and Kentucky, whose parallel provisions call only for a written statement. Section 87-1124(1) then makes a person who violates the Act after the cure period, or who breaches the written statement given under § 87-1122, liable for a civil penalty not exceeding $7,500 for each violation, with the Attorney General able under subsection (2) to sue in the name of the State to recover the penalty, to restrain or enjoin, or both, and under subsection (3) to recover reasonable attorney’s fees and investigative expenses.
Appeals and the route to the Attorney General. Section 87-1108(3) requires a controller declining to comply with a request to inform the consumer within forty-five days of the justification and to provide instructions for appealing the decision under § 87-1109. That section requires the controller to establish an appeal process available within a reasonable period after the consumer receives the decision, conspicuously available and similar to the process for making the original request, and requires the controller to inform the consumer in writing of any action taken or not taken not later than the sixtieth day after receiving the appeal, with a written explanation of the reasons. Subsection (4) closes the loop: if the controller denies the appeal, it must provide the consumer with the online mechanism described in § 87-1108 through which the consumer may contact the Attorney General to submit a complaint.
Recent Enforcement in Nebraska
State v. Change Healthcare, UnitedHealth Group and Optum — Lancaster County District Court. The Attorney General announced on December 16, 2024 that he had filed suit in Lancaster County District Court against Change Healthcare alleging violations of Nebraska’s consumer protection and data security laws. The office states that the complaint arises from a breach and subsequent operational shutdown that exposed the personal and electronic protected health information of at least hundreds of thousands of Nebraskans, that the stolen data included information reflecting medical diagnoses, and that the shutdown disrupted payment and claim processing for healthcare providers across the state including critical access hospitals in rural areas. The office further alleges that the defendants’ failure to implement proper security measures exacerbated the breach and that the company disregarded its duty to notify Nebraskans. The Lancaster County District Court subsequently denied the defendants’ motion to dismiss; announcing the ruling, the office states that the court found the State had sufficiently alleged all violations of Nebraska’s consumer protection and data privacy laws and underscored that the cyberattack exposed the sensitive personal and medical information of nearly 900,000 Nebraskans. The case has moved into the next phase of litigation.
Pending Privacy Legislation
The Data Privacy Act was enacted in 2024 and took effect January 1, 2025, and chapter 87 has continued to accumulate related sections around it rather than through amendments to the Act itself: the age-verification sections at §§ 87-1001 to 87-1005 immediately precede it, and the 2006 breach act at §§ 87-801 to 87-808 and the Uniform Deceptive Trade Practices Act at § 87-301 et seq. remain in force alongside. Unlike Connecticut, Delaware, Minnesota, Montana, New Hampshire and Oregon, Nebraska set no sunset on its cure period: § 87-1122 carries no expiry date, and no session has supplied one. Nothing in the Act confers rulemaking authority, and its enforcement provisions at §§ 87-1119 to 87-1124 have not been amended since enactment.
Federal Privacy Laws That Apply in Nebraska
Federal privacy law applies in Nebraska by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The NDPA sits alongside those rules rather than displacing them: the Nebraska Attorney General enforces the state law, while the federal regulators continue to reach the sectors and activities they cover. The state-law counterpart to section 5 is the Uniform Deceptive Trade Practices Act (Neb. Rev. Stat. § 87-301 et seq.), which the Nebraska Attorney General enforces against businesses whose stated data practices differ from their actual ones.
Nebraska Privacy Law FAQ
What does a Nebraska controller have to show to cure a violation?
Does Nebraska’s privacy law have a consumer-count threshold?
What can Nebraska’s Attorney General recover for a breach-notice failure?
Must a Nebraska business investigate before notifying?
Is biometric data covered by Nebraska’s breach statute?
How does a Nebraska consumer escalate a denied rights request?
How does a Nebraska controller delete data it did not get from the consumer?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- Neb. Rev. Stat. § 87-1101 — Data Privacy Act, how cited statute
- Neb. Rev. Stat. § 87-1103 — Applicability of act to persons or entities statute
- Neb. Rev. Stat. § 87-1108 — Controller; compliance; procedure statute
- Neb. Rev. Stat. § 87-1109 — Appeal process statute
- Neb. Rev. Stat. § 87-1118 — Sensitive data; sale; consent required statute
- Neb. Rev. Stat. § 87-1122 — Notification of violations; response statute
- Neb. Rev. Stat. § 87-1124 — Violation; penalty; actions authorized statute
- Neb. Rev. Stat. § 87-802 — Breach act definitions statute
- Neb. Rev. Stat. § 87-803 — Breach of security; investigation; notice statute
- Neb. Rev. Stat. § 87-806 — Attorney General; powers; violation statute
- Neb. Rev. Stat. § 87-302 — Uniform Deceptive Trade Practices Act statute
- Nebraska Attorney General — lawsuit against Change Healthcare (Dec. 16, 2024) agency
- Nebraska Attorney General — court allows Change Healthcare case to proceed agency
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.