Arizona Revised Statutes (A.R.S.) Title 44, Chapter 32
· About Arizona Revised Statutes (A.R.S.) Title 44, Chapter 32
Key Takeaways
- Arizona’s breach-notification law applies to businesses, nonprofits, and government agencies that own, license, or maintain computerized personal information of Arizona residents, and it generally requires notice when a breach is likely to cause substantial economic loss.[5][6]
- Notice to affected individuals is due within 45 days after determining that a breach occurred, unless a law-enforcement delay is requested to avoid interfering with a criminal investigation.[5][9]
- If more than 1,000 Arizona residents are notified, the organization must also notify the Arizona Attorney General, the Arizona Department of Homeland Security, and the three largest nationwide consumer reporting agencies.[5][13]
- Arizona expanded the definition of “personal information” in 2018 to include items such as online account credentials, biometric data in certain combinations, and additional identity-linked data elements.[6]
- Knowing or willful violations can trigger civil penalties of up to $500,000 per breach, enforced by the Arizona Attorney General.[6]
- As of 2026, the core statute remains in force without any confirmed 2025–2026 amendment changing these obligations or delaying implementation. The current official statute text still reflects the 45-day notice rule and the >1,000-person reporting threshold.[3][5]
What It Is
Arizona’s data-breach notification law is codified in A.R.S. § 18-552, which sits within Title 44, Chapter 32 and governs notification after unauthorized acquisition of computerized personal information.[5][12] It applies to persons and entities that own or license computerized data containing personal information about Arizona residents, and it is enforced primarily through the Arizona Attorney General with additional notice obligations to the Arizona Department of Homeland Security in larger incidents.[5][6]
The modern framework was enacted in 2018, when Arizona replaced its older “without unreasonable delay” standard with a firm 45-day notification deadline and broadened the covered data elements.[6][9] The statute took effect after enactment in 2018, and later amendments added the state homeland-security notice channel for larger breaches; the current official text still shows that framework in place in 2026.[5][13]
Who Must Comply
The law reaches any person, business, nonprofit, or government agency that owns, licenses, or maintains computerized data that includes personal information about an Arizona resident.[5][6] The obligation is not limited to Arizona-based organizations; if an entity holds covered data relating to Arizona residents, the statute can apply regardless of where the organization is located.[5]
The law is triggered by a breach of the security system involving unencrypted computerized data containing personal information, and notice is required when the breach has resulted in or is reasonably likely to result in substantial economic loss to affected individuals.[5][9] A breach involving fewer than 1,000 individuals still requires individual notice if the threshold for notice is met, but the additional regulator and credit-bureau notices apply only above that 1,000-person level.[5]
Arizona’s statute does not create broad sector-specific exemptions for financial institutions or healthcare entities in the text reviewed; instead, those entities generally must comply unless another law specifically displaces the state requirement for the incident at issue.[5][14] A law-enforcement delay is available, but only when an investigating agency advises that notice would impede a criminal investigation.[5]
Core Requirements
- Investigate promptly. When an organization becomes aware of an incident involving unauthorized acquisition and access to unencrypted computerized data, it must conduct a reasonable investigation to determine whether a security-system breach occurred.[5]
- Notify affected individuals within 45 days. If a breach is confirmed, the organization must notify the affected individuals within 45 days after determining that a breach occurred, subject to any law-enforcement delay.[5][9]
- Include required content in the notice. The notice must describe the approximate date of the breach, the types of personal information involved, and the consumer-facing contact details required by the statute, including information for the nationwide consumer reporting agencies and the FTC where applicable.[5][6]
- Escalate to regulators and credit bureaus for larger incidents. If the breach requires notice to more than 1,000 individuals, the organization must also notify the Arizona Attorney General, the Arizona Department of Homeland Security, and the three largest nationwide consumer reporting agencies.[5][13]
- Use permitted delivery methods. Arizona permits notice by the methods specified in the statute and accompanying state guidance, including mail or email in the Attorney General’s breach-notification process.[4][6]
- Delay only for law-enforcement needs. Notice may be postponed only if a law-enforcement agency determines that immediate disclosure would interfere with a criminal investigation.[5]
Deadlines and Penalties
| milestone | date | what applies | |---|---:|---| | breach determination | day 0 | The 45-day clock starts when the organization determines a covered breach occurred.[5] | | individual notice deadline | within 45 days | Affected individuals must be notified within 45 days, subject to law-enforcement delay.[5][9] | | regulator and credit-bureau notice | within 45 days | For breaches affecting more than 1,000 individuals, notice must also go to the AG, ADHS, and the three largest nationwide consumer reporting agencies.[5][13] | | law-enforcement delay | no fixed date | Notice may be delayed only if law enforcement says disclosure would impede an investigation.[5] |
The statute authorizes civil penalties of up to $500,000 per breach for knowing or willful violations.[6] Enforcement authority sits with the Arizona Attorney General, and the statutory structure also supports investigation and compliance review for reportable breaches.[6]
How to Comply
- Map covered data and owners. Identify where personal information of Arizona residents is stored, who owns or licenses it, and which service providers can access it.
- Classify the data against Arizona’s definition. Compare your data inventory with Arizona’s expanded personal-information categories, including account credentials and other protected identifiers where applicable.[6]
- Build a breach triage workflow. Use incident-response procedures aligned to NIST CSF 2.0 for detect, respond, and recover functions, with a specific decision point for whether the incident is a covered “security system breach.”
- Set a 45-day legal notification clock. Create an intake process that records the determination date and automatically routes the matter to privacy, security, legal, and executive reviewers.
- Use an ISO 27001-style control environment. Maintain access control, logging, encryption, vendor oversight, and incident management controls consistent with ISO 27001 so that detections, investigations, and evidence preservation are reliable.
- Prepare breach-notice templates. Pre-draft individual notices, AG notices, and consumer-reporting-agency notices so the required content can be finalized quickly after legal review.
- Test disclosure and escalation paths. Run tabletop exercises for incidents affecting more than 1,000 people, including regulator notification, credit-bureau notification, and any law-enforcement delay request.
- Add AI governance where automated tools are used. If AI systems assist with detection, classification, or communications, align governance with ISO 42001 so human review, accountability, and recordkeeping remain defensible.
Related Regulations
- California Civil Code § 1798.82 overlaps because it also requires breach notice to residents, but California’s content, timing, and threshold rules differ in important ways.
- New York SHIELD Act overlaps because it imposes data-security and breach-notice expectations on covered entities handling New York residents’ information.
- HIPAA Breach Notification Rule can conflict or overlap for healthcare entities, because HIPAA may govern patient-data breaches while Arizona still matters for non-preempted obligations.
- FTC Act Section 5 overlaps because deficient security practices can create separate federal unfairness or deception exposure even when state notice is timely.
- State consumer-protection laws can add enforcement risk if breach handling, communications, or remediation statements are misleading.
FAQ
Does Arizona’s breach-notification law apply to companies outside Arizona?
Yes, if the company owns, licenses, or maintains computerized personal information of Arizona residents.[5][6] The statute is residency-based for the affected individuals, not headquarters-based for the organization.[5]
Is there still a 45-day deadline in Arizona?
Yes. The current statute requires notice to affected individuals within 45 days after determining a breach occurred, unless law enforcement requests a delay.[5][9] That deadline is one of the key 2018 changes from the older “without unreasonable delay” language.[6]
Does the law require notice to the Arizona Attorney General?
Yes, but only when the breach requires notice to more than 1,000 individuals.[5][13] In that situation, the organization must also notify the Arizona Department of Homeland Security and the three largest nationwide consumer reporting agencies.[5]
What counts as personal information under Arizona law?
Arizona’s definition includes a person’s name in combination with specified sensitive data elements, and the 2018 amendment broadened it to cover items such as online account credentials and certain biometric or identity-linked data combinations.[6] The exact statutory text should be checked for the current list before sending notice.[5][6]
What are the penalties for ignoring the statute?
Arizona authorizes civil penalties of up to $500,000 per breach for knowing or willful violations.[6] The Attorney General can also investigate compliance and the incident history can create additional litigation and reputational exposure.[6]
Sources
- Arizona Revised Statutes, Title 44 (official statute repository)
- A.R.S. § 18-552, Notification of security system breaches
- Arizona Attorney General, Data Privacy & Data Breach Reporting
- Arizona Attorney General, Notification of Data Breach form
- Arizona Attorney General, Arizona’s Data-Breach Notification Law FAQ
- Arizona Attorney General press release on the 2018 breach-law amendments
- Hunton privacy and cybersecurity analysis of the Arizona amendments
- Foley & Lardner LLP state data-breach chart
Put it into practice
- Generate the policy: Privacy policy generator (generatepolicy.com)
- Buy the policy pack: State Privacy Law Checklist (cyberpolicy.shop)
- Build it yourself: 2026 US Privacy Program Workbook (ciso.diy)