Nevada

Nevada Privacy Law

Nevada has no comprehensive privacy statute and has instead accumulated four distinct regimes inside a single chapter of its revised statutes. NRS 603A.215 writes the Payment Card Industry Data Security Standard into state law and, for anyone not accepting payment cards, imposes a flat encryption mandate on personal information leaving the secure system. NRS 603A.340 gives Nevadans a verified do-not-sell right that predates the CCPA. The 2023 consumer health data provisions at NRS 603A.400 to 603A.550 ban implementing a geofence within 1,750 feet of a health care facility to track consumers or collect health data. And NRS 603A.270 does something no other state breach statute does: it gives the breached business its own cause of action against whoever unlawfully obtained the data, for the cost of sending the notices.

Sector-Specific Privacy Laws in Nevada

Security measures and encryption (NRS 603A.210 and 603A.215)

NRS 603A.210(1) requires a data collector maintaining records containing the personal information of a Nevada resident to implement and maintain reasonable security measures protecting those records from unauthorized access, acquisition, destruction, use, modification or disclosure, and subsection (3) requires any contract disclosing that information to oblige the recipient to do the same. Subsection (2) holds governmental agencies to a named external benchmark — to the extent practicable, the current version of the CIS Controls published by the Center for Internet Security, or corresponding standards adopted by the National Institute of Standards and Technology — and subsection (5) directs the Office of Information Security and Cyber Defense within the Governor’s Technology Office to publish the list of controls that satisfy it. NRS 603A.215 splits the private sector in two. A data collector doing business in Nevada that accepts a payment card must comply with the current version of the Payment Card Industry Data Security Standard as adopted by the PCI Security Standards Council with respect to those transactions. A data collector to whom that does not apply may not transfer personal information through an electronic, nonvoice transmission other than a facsimile outside its secure system unless it uses encryption, and may not move a data storage device containing personal information beyond its logical or physical controls unless it uses encryption. Subsection (3) supplies the incentive: a data collector is not liable for damages for a breach if it is in compliance with the section and the breach was not caused by its own gross negligence or intentional misconduct.

Do-not-sell request to online operators (NRS 603A.300 to 603A.360)

Nevada’s opt-out regime, enacted in 2017 and expanded in 2019 and 2021, is narrower than a comprehensive law and older than most of them. It runs on a verified request submitted to an “operator” directing that covered information not be sold, and it is enforced only by the Attorney General. NRS 603A.360(1) gives the office enforcement authority; subsections (2) and (3) let it institute proceedings against an operator that has violated NRS 603A.340 or 603A.345, or against a data broker that has violated NRS 603A.346, with the district court empowered to issue a temporary or permanent injunction or impose a civil penalty not to exceed $5,000 for each violation. Subsection (4) states that the provisions do not establish a private right of action against an operator, and subsection (5) that they are not exclusive and are in addition to other remedies provided by law. The scheme also contains a statutory grace mechanism: NRS 603A.348 and 603A.349 provide that an operator which has not previously failed to comply may remedy a failure within thirty days of being informed of it, and an operator that does so does not violate the section for the purposes of NRS 603A.360. NRS 603A.350 then defines the unlawful act as knowingly failing to remedy within thirty days after being informed, knowingly failing to comply after having previously failed, or making available a notice containing a knowing and material misrepresentation or omission likely to mislead a reasonable consumer to their detriment.

Security and privacy of consumer health data (NRS 603A.400 to 603A.550)

Senate Bill 370 of 2023 added a consumer health data regime to the same chapter, with its own definitions running from NRS 603A.400 through 603A.485 — among them gender-affirming care, genetic data, precise geolocation, reproductive health care, regulated entity, and separate definitions of “sell” and “share”. NRS 603A.505 sets out what a regulated entity must do on a consumer request; NRS 603A.510 requires a response without undue delay and addresses the entity’s inability to authenticate a request after commercially reasonable efforts, with requests free at least twice each year; NRS 603A.515 covers deletion. NRS 603A.535 governs the sale of consumer health data through a written authorization mechanism rather than ordinary consent: a copy goes to both the consumer who signed it and the purchaser, and both seller and purchaser retain a copy for at least six years after the authorization expires. NRS 603A.540 is the provision with no close analogue outside Washington: a person may not implement a geofence within 1,750 feet of any medical facility, facility for the dependent, or other person or entity providing in-person health care services or products, for the purpose of identifying or tracking consumers seeking those services, collecting consumer health data, or sending notifications, messages or advertisements related to consumer health data or health care. The section defines a geofence as technology using global positioning coordinates, cellular tower connectivity, cellular data, radio frequency identification, wireless internet data or any other location-detection method to establish a virtual boundary with a radius of 1,750 feet or less. NRS 603A.545 bars discriminating against a consumer for exercising or enforcing these rights, and NRS 603A.550 makes a violation a deceptive trade practice while stating that the provisions do not create a private right of action.

Deceptive trade practices (NRS 598.0903 to 598.0999)

Nevada channels its privacy violations into the deceptive trade practices chapter. NRS 603A.260 provides that a violation of NRS 603A.010 to 603A.290 — the security and breach provisions — constitutes a deceptive trade practice for the purposes of NRS 598.0903 to 598.0999, and NRS 603A.550 does the same for the consumer health data provisions. NRS 598.0999 then supplies the consequences, and they are unusual in reaching criminal liability. Subsection (1) sets a civil penalty of not more than $10,000 for each violation of a court order or injunction, payable to the State General Fund, with the issuing court retaining jurisdiction. Subsection (2) allows the Attorney General, the Commissioner, the Director or a district attorney to recover a civil penalty not to exceed $15,000 for each violation where the court finds a person has wilfully engaged in a deceptive trade practice, plus reasonable attorney’s fees and costs. Subsection (3) makes a natural person, firm, or officer or managing agent of a corporation or association who knowingly and wilfully engages in a deceptive trade practice guilty of a category D felony where the offense involves a loss of property or services valued at $1,200 or more but less than $5,000, with the grade escalating above that.

Data Breach Notification in Nevada

NRS 603A.220(1) requires a data collector that owns or licenses computerized data including personal information to disclose a breach of the security of the system data, following discovery or notification, to any Nevada resident whose unencrypted personal information was or is reasonably believed to have been acquired by an unauthorized person, in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement or measures necessary to determine the scope of the breach and restore the reasonable integrity of the system data. NRS 603A.040 defines personal information as a natural person’s first name or first initial and last name combined with an unencrypted Social Security number; driver’s licence number, driver authorization card number or identification card number; account, credit card or debit card number with any required security code, access code or password permitting access to a financial account; a medical identification number or a health insurance identification number; or a user name, unique identifier or e-mail address with a password, access code or security question and answer permitting access to an online account. Subsection (2) excludes the last four digits of a Social Security number, driver’s licence number, driver authorization card number or identification card number, and publicly available information from government records. NRS 603A.100(3) makes any waiver of the security and breach provisions contrary to public policy, void and unenforceable. What the chapter does not contain is a threshold requiring notice to a state agency. Instead NRS 603A.290 lets the Attorney General or a district attorney bring an action for a temporary or permanent injunction where there is reason to believe a person is violating, proposes to violate or has violated the provisions, and NRS 603A.260 makes the violation a deceptive trade practice carrying the NRS 598.0999 penalties.

Residents must be notified in the most expedient time possible and without unreasonable delay. NRS 603A.220 imposes no general Attorney General notice duty; the Attorney General and district attorneys may seek an injunction under NRS 603A.290. Complaints are taken by the Nevada Attorney General, which enforces the statute.

How Nevada Enforces Its Privacy Laws

Injunctions first, deceptive-practice penalties second. NRS 603A.290 gives the Attorney General or a district attorney the power to bring an action for a temporary or permanent injunction where there is reason to believe a person is violating, proposes to violate or has violated NRS 603A.010 to 603A.290. NRS 603A.260 then makes such a violation a deceptive trade practice for the purposes of NRS 598.0903 to 598.0999, which supplies the money: up to $15,000 per violation for a wilful deceptive trade practice under NRS 598.0999(2), plus reasonable attorney’s fees and costs, and up to $10,000 for each violation of a court order or injunction under subsection (1). The do-not-sell provisions carry their own separate schedule at NRS 603A.360, capped at $5,000 per violation for operators and for data brokers alike.

Waiver of the security provisions is void. NRS 603A.100(3) provides that any waiver of the provisions of NRS 603A.010 to 603A.290 is contrary to public policy, void and unenforceable. That reaches contractual terms as well as consumer-facing ones, and it sits alongside NRS 603A.210(3), which requires a contract disclosing a Nevada resident’s personal information to include a provision obliging the recipient to implement and maintain reasonable security measures. Taken together, the security duty cannot be contracted away either by the data collector or by a downstream recipient.

Recent Enforcement in Nevada

Equifax — $600 million multistate settlement, $1,468,342.34 to Nevada. On July 22, 2019 the Attorney General announced, with forty-nine other attorneys general, a settlement with Equifax over the breach affecting 147 million consumers — fifty-six percent of American adults — which the office described as the largest data breach enforcement action in history. The total was $600 million, comprising a Consumer Restitution Fund of up to $425 million, of which $300 million was initially dedicated to consumer redress and expandable by a further $125 million, and $175 million to the states; Nevada’s share was $1,468,342.34. The states alleged that Equifax failed to implement an adequate security program, failed to patch a known critical software vulnerability despite being aware of it, and failed to replace software that monitored the breached network for suspicious activity; the intrusion went undetected for seventy-six days. The settlement provided ten years of extended credit monitoring and required simplified credit freeze and thaw processes, easier dispute procedures for inaccurate credit reports, dedicated staff for identity theft victims, a reorganised data security team, minimised collection of sensitive data, and enhanced security monitoring, logging, testing, network segmentation and access controls.

Pending Privacy Legislation

Nevada has built its privacy framework by successive amendment of one chapter rather than by enacting a comprehensive statute. NRS 603A.300 to 603A.360, the do-not-sell provisions, were added in 2017 and amended in 2019 and 2021, the 2021 amendment adding the data broker provisions at NRS 603A.346 and the statutory thirty-day repair mechanism at NRS 603A.348 and 603A.349. Senate Bill 370 of 2023 added the consumer health data provisions at NRS 603A.400 to 603A.550, including the written-authorization regime for sales at NRS 603A.535 and the 1,750-foot geofence prohibition at NRS 603A.540. NRS 603A.210 was amended in 2019 and again in 2025, the later amendment carrying the CIS Controls benchmark for governmental agencies and the publication duty on the Office of Information Security and Cyber Defense. Nothing enacted has created access, correction or deletion rights of general application; the consumer rights in the chapter attach either to the sale of covered information or to consumer health data specifically.

Federal Privacy Laws That Apply in Nevada

Federal privacy law applies in Nevada by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The state-law counterpart to section 5 is the Deceptive trade practices (NRS 598.0903 to 598.0999), which the Nevada Attorney General enforces against businesses whose stated data practices differ from their actual ones.

Industry Rules That Reach Nevada Businesses

With no comprehensive state statute, most privacy obligations on a Nevada business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.

Two of those reach Nevada businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while Nevada itself has none, and any business holding personal information about Nevada residents is subject to the state’s breach-notification statute described above.

Nevada Privacy Law FAQ

How close to a medical facility may a geofence be placed in Nevada?
No closer than 1,750 feet, where the purpose is one of three the statute names. NRS 603A.540(1) provides that a person may not implement a geofence within 1,750 feet of any medical facility, facility for the dependent, or other person or entity providing in-person health care services or products, for the purpose of identifying or tracking consumers seeking in-person health care services or products, collecting consumer health data, or sending notifications, messages or advertisements to consumers related to their consumer health data or health care. Subsection (2) defines a geofence as technology using global positioning coordinates, cellular tower connectivity, cellular data, radio frequency identification, wireless internet data or any other location-detection method to establish a virtual boundary with a radius of 1,750 feet or less.
Does Nevada require encryption by statute?
Yes, for data collectors that do not accept payment cards. NRS 603A.215(1) requires a data collector accepting a payment card to comply with the current version of the Payment Card Industry Data Security Standard for those transactions. Subsection (2) then provides that a data collector to whom subsection (1) does not apply may not transfer personal information through an electronic, nonvoice transmission other than a facsimile to a person outside its secure system unless it uses encryption, and may not move a data storage device containing personal information beyond its logical or physical controls unless it uses encryption. Subsection (3) provides that a compliant data collector is not liable for damages for a breach unless the breach was caused by its own gross negligence or intentional misconduct.
Can a Nevada business sue the people who breached it?
Yes, and this is the provision that most distinguishes NRS chapter 603A. NRS 603A.270 provides that a data collector which gives the notification required by NRS 603A.220 may commence an action for damages against a person that unlawfully obtained or benefited from personal information obtained from records the data collector maintained, and a prevailing data collector may be awarded damages including the reasonable costs of notification, reasonable attorney’s fees and costs, and punitive damages where appropriate — with notification costs defined to include labor, materials, postage and other costs reasonably related to providing the notification. NRS 603A.280 adds a restitution route: a court may order a person convicted of unlawfully obtaining or benefiting from the information to reimburse the data collector for those same notification costs.
Which agency receives a breach notice in Nevada?
None, as a general matter. NRS 603A.220 sets out the duty to disclose to affected Nevada residents and the methods of disclosure, but the chapter contains no provision requiring a filing with the Attorney General or another state agency at any headcount. What it provides instead is an enforcement route: NRS 603A.290 lets the Attorney General or a district attorney bring an action for a temporary or permanent injunction where there is reason to believe a person is violating, proposes to violate or has violated NRS 603A.010 to 603A.290, and NRS 603A.260 makes such a violation a deceptive trade practice for the purposes of NRS 598.0903 to 598.0999.
What happens the first time an operator fails to honour a do-not-sell request?
Nevada gives a statutory thirty-day repair opportunity rather than leaving it to prosecutorial discretion. NRS 603A.348 provides that an operator which has not previously failed to comply with NRS 603A.340(1) may remedy the failure within thirty days after being informed of it, and that an operator which does so does not violate NRS 603A.340 for the purposes of NRS 603A.360. NRS 603A.349 does the same for failures under NRS 603A.345. NRS 603A.350 then defines the unlawful act as knowingly failing to remedy within that thirty days, knowingly failing to comply after having previously failed, or making available a notice containing a knowing and material misrepresentation or omission likely to mislead a reasonable consumer to their detriment.
Is a medical identification number covered by Nevada’s breach law?
Yes. NRS 603A.040(1)(d) lists “a medical identification number or a health insurance identification number” among the elements that, combined with a name and unencrypted, constitute personal information — a category many state breach statutes omit. Subsection (1)(e) separately covers a user name, unique identifier or e-mail address in combination with a password, access code or security question and answer permitting access to an online account. Subsection (2) excludes the last four digits of a Social Security number, driver’s licence number, driver authorization card number or identification card number, along with publicly available government-record information.
How long must a Nevada health data authorization be retained?
Six years after it expires, by both parties. NRS 603A.535(7) requires a person who sells consumer health data to provide a copy of the written authorization to the consumer who signed it and to the purchaser, and subsection (8) requires the seller and the purchaser each to retain a copy for at least six years after the date on which the authorization expired. The section also voids an authorization that was a condition for the provision of goods or services, that does not comply with the section’s content requirements, that has been revoked, or that has expired.
Can a deceptive trade practice be a crime in Nevada?
Yes, which is unusual among state unfair-practices statutes and matters because both the security provisions at NRS 603A.260 and the consumer health data provisions at NRS 603A.550 route violations into that chapter. NRS 598.0999(3) provides that a natural person, firm, or officer or managing agent of a corporation or association who knowingly and wilfully engages in a deceptive trade practice is guilty of a category D felony where the offense involves a loss of property or services valued at $1,200 or more but less than $5,000, with the grade escalating for larger losses. On the civil side, subsection (2) allows a penalty of up to $15,000 per violation for a wilful deceptive trade practice, and subsection (1) up to $10,000 for each violation of a court order or injunction.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.