Alaska Personal Information Protection Act (APIPA)
· About Alaska Personal Information Protection Act (APIPA)
Key Takeaways
- Alaska’s Personal Information Protection Act (APIPA) is the state’s breach-notification and data-safeguards law for covered persons that own or license personal information of Alaska residents, and it is enforced through Alaska’s statutory framework in Title 45, Chapter 48.[5][8]
- Covered persons must give notice to affected Alaska residents after discovering a qualifying breach, using the most expedient time possible and without unreasonable delay, subject to investigation and law-enforcement delay exceptions.[5][8]
- If a breach affects more than 1,000 Alaska residents, the covered person must also notify nationwide consumer reporting agencies without unreasonable delay and provide the timing, distribution, and content of resident notices.[10]
- Notice is generally not required when personal information is encrypted or redacted and the encryption key was not acquired, which is a key statutory safe harbor reflected in current Alaska summaries and statutory text.[7][8]
- The Alaska Legislature has considered broader privacy and data-broker legislation in 2026, but APIPA itself remains the operative breach-notice law; no 2025–2026 enacted replacement was identified in the official materials reviewed.[3][4][9]
- The statute authorizes Attorney General enforcement and civil penalties, so breach-response failures can create both notification exposure and regulatory enforcement risk.[7][8]
What It Is
APIPA is Alaska’s personal information breach-notification statute, codified in AS 45.48, requiring disclosure when a breach of the security of an information system containing personal information on an Alaska resident occurs.[5][8] It applies to entities that own, license, or otherwise maintain personal information and imposes a notice-and-response regime rather than a comprehensive general privacy framework.[5][12]
The operative chapter was enacted in 2008 and then incorporated into Alaska’s laws as the Personal Information Protection Act, with later amendments refining notice mechanics and related obligations.[11][15] Current statutory materials show the notice framework in AS 45.48.010–.090, and the most recent official legislative activity in 2026 focused on separate privacy/data-broker bills rather than repeal of APIPA.[3][4][9]
Exact dates: the underlying law traces to 2008 enactment, with the current codified chapter in force now; no 2025–2026 delay of APIPA’s effective dates was identified in the official materials reviewed.[11][15]
Who Must Comply
APIPA applies to a covered person that owns or licenses personal information on an Alaska resident, and to an information collector in the breach-notice provisions.[5][6][8] Alaska summaries also describe coverage for persons doing business, persons with more than ten employees, government agencies, and other entities that own or license personal information, but the statutory core is broader than any single employee threshold.[7][8]
The statute has extraterritorial reach in the practical sense that it applies when personal information on an Alaska resident is involved, regardless of where the business is located.[5][7][12] If an information recipient holds Alaska resident data and suffers a breach, it must promptly notify the information distributor so the distributor can comply with Alaska’s notice duties.[12]
Exemptions and limitations include the encrypted/redacted safe harbor, and a law-enforcement delay when the Alaska Department of Law determines notice would compromise an investigation.[5][7][8] Alaska’s statute also excludes notice to agencies in certain circumstances where consumer notice is not required because no reasonable likelihood of harm exists, although that point is described in secondary compliance guidance and should be aligned with the statutory text before relying on it operationally.[7][8]
Core Requirements
- Resident notice after breach discovery. A covered person must notify an Alaska resident when a breach of security involving that resident’s personal information occurs, even if the data has not been shown to have been used for a fraudulent purpose.[5][8]
- Notice without unreasonable delay. The disclosure must be made in the most expedient time possible and without unreasonable delay, except as needed to investigate, determine scope, restore integrity, or comply with law-enforcement delay instructions.[5][8]
- Minimum-content notice. The notice must be sent in a manner consistent with Alaska’s statutory requirements and may be written or electronic, depending on the entity’s communication practices and applicable electronic-record rules.[7][8]
- Notice to consumer reporting agencies. If more than 1,000 Alaska residents are notified, the covered person must also notify nationwide consumer reporting agencies of the timing, distribution, and content of the resident notices.[10]
- Coordinate recipient/distributor breaches. When a breach occurs at an information recipient, the recipient must promptly inform the information distributor and cooperate so the distributor can issue legally required notices.[12]
- Maintain reasonable safeguards. APIPA is a breach-notice law, but it also presumes that entities maintain reasonable protections over personal information and restore system integrity promptly after an incident.[5][8]
Deadlines and Penalties
| milestone | date | what applies | |---|---:|---| | Breach discovered | Immediately | Start incident assessment and determine whether Alaska resident personal information was involved.[5][8] | | Resident notice | Without unreasonable delay | Send notice as soon as practicable, subject to investigation and restoration needs.[5][8] | | Law-enforcement delay | As directed | Delay notice if the Alaska Department of Law determines disclosure would compromise an investigation.[5] | | Credit bureau notice | Without unreasonable delay | Notify nationwide consumer reporting agencies if more than 1,000 Alaska residents are notified.[10] |
Maximum fines and sanctions: Alaska summaries of the statute report Attorney General enforcement and civil penalties, and current compliance guidance treats APIPA violations as enforceable under state consumer-protection and breach-notice authority.[7][8] Secondary analyses commonly describe civil penalties up to $500 per violation and possible injunctive relief, but the precise exposure should be confirmed against the current Alaska enforcement provisions and any linked consumer-protection remedies before relying on a penalty cap in a live matter.[7][8]
How to Comply
- Map personal information holdings. Identify where Alaska resident data is stored, processed, transmitted, backed up, and shared, including vendors and affiliates; this is the baseline for APIPA scoping and aligns well with ISO 27001 asset and information-classification controls.
- Build a breach triage playbook. Define decision trees for whether a security event is a reportable breach, whether encryption/redaction safe harbor applies, and whether law-enforcement delay is available; this maps cleanly to NIST CSF 2.0 incident-response functions.
- Pre-draft notice templates. Prepare resident, regulator, and consumer-reporting-agency notices so legal review and factual insertion can happen quickly after discovery.
- Contract for downstream cooperation. Put breach-notice, investigation, and data-sharing obligations into vendor and recipient contracts so an information recipient can satisfy its duty to notify the information distributor promptly.[12]
- Test restoration and containment. Demonstrate the ability to restore system integrity and determine scope quickly; this is both an APIPA timing issue and a core operational control under ISO 27001 and NIST CSF 2.0.
- Use ISO 42001 for AI/data governance where relevant. If personal information is processed by AI systems, incorporate model and dataset governance, logging, and human oversight into the incident and privacy program so breach detection and impact assessment remain reliable.
- Run breach exercises annually. Tabletop drills should cover notification thresholds, the 1,000-resident bureau-notice trigger, and cross-functional signoff between legal, security, privacy, and communications teams.
- Track legal updates. Reassess Alaska legislative activity each session, because the state has active privacy and data-broker proposals that may alter the broader compliance environment even if APIPA itself remains unchanged.[3][4][9]
Related Regulations
- Alaska consumer privacy proposals. 2026 bills such as HB 367 and HB 159 show Alaska’s broader privacy agenda, but they do not displace APIPA’s breach-notice regime unless enacted into new law.[3][4][9]
- Federal FTC Act Section 5. Unfair or deceptive privacy and security practices can create overlapping federal enforcement risk when breach handling or security claims are misleading.
- GLBA. Financial institutions and service providers may need to satisfy GLBA safeguard and incident-response expectations in parallel with Alaska notice duties when Alaska residents are affected.
- HIPAA. Covered entities and business associates may need to follow HIPAA breach rules for protected health information, which can coexist with APIPA if the personal data also fits Alaska’s definition.
- State breach laws in other jurisdictions. Multi-state incidents often trigger a patchwork of resident-notice timing and content requirements, so APIPA must be harmonized with the strictest applicable state rule.
Does APIPA apply to companies outside Alaska?
Yes. The statute reaches entities that own or license personal information on Alaska residents, so an out-of-state company can be covered if it holds Alaska resident data.[5][7][12] The key trigger is the data subject and the breach, not the company’s headquarters.
What counts as personal information under Alaska’s law?
APIPA covers the categories of personal information defined in AS 45.48, including data elements used for identity theft and account access.[5][8] The exact definition should be checked against the current codified text before a breach decision is made.
Is encrypted data exempt from notice?
Often yes. Alaska guidance indicates notice is not required when the personal information is encrypted or redacted and the key was not acquired, which is the statute’s main confidentiality safe harbor.[7][8] That exemption depends on the facts and the security of the key management process.
How fast must breach notices go out?
Notices must be sent in the most expedient time possible and without unreasonable delay, subject to investigation, scope determination, and system-restoration needs.[5][8] If law enforcement says disclosure would compromise an investigation, notice may be delayed.[5]
What happens if more than 1,000 residents are notified?
The covered person must also notify the national consumer reporting agencies that compile consumer files and provide the timing, distribution, and content of the notices to Alaska residents.[10] That trigger is in addition to, not instead of, resident notice.
Has APIPA been replaced by a newer Alaska privacy law?
No enacted replacement was identified in the 2025–2026 official materials reviewed. Alaska did consider broader privacy and data-broker bills in 2026, but APIPA remains the current breach-notice law in force.[3][4][9]
Sources
- Alaska Legislature, AS 45.48.010 and related chapter materials
- Alaska Legislature, HB 367 bill detail and amendment history
- Alaska Legislature, HB 159 bill text
- Justia, Alaska Statutes Title 45, Chapter 48, Article 1
- Justia, Sec. 45.48.040 notification of certain other agencies
- FindLaw, Alaska Statutes § 45.48.070
- Constangy, Alaska data privacy interactive map
- Alaska Legislature PDF, Laws of Alaska chapter text
Put it into practice
- Generate the policy: Privacy policy generator (generatepolicy.com)
- Buy the policy pack: State Privacy Law Checklist (cyberpolicy.shop)
- Build it yourself: 2026 US Privacy Program Workbook (ciso.diy)