Nebraska Data Privacy Act (NDPA)

· About Nebraska Data Privacy Act (NDPA)

Key Takeaways

  • The Nebraska Data Privacy Act (NDPA) applies to entities that conduct business in Nebraska or produce products or services targeted to Nebraska residents, process personal data, and are not small businesses under the federal Small Business Act unless they sell sensitive data without prior consent.[1][7][13]
  • The NDPA took effect on 1 January 2025, and Nebraska’s codified text remains in force in the Nebraska Revised Statutes at Neb. Rev. Stat. §§ 87-1101 to 87-1130.[1][4][6]
  • Nebraska residents have rights to access, correct, delete, obtain portability, and opt out of targeted advertising, sale of personal data, and certain profiling decisions.[1][2][3]
  • Controllers must conduct data protection assessments for specified high-risk processing activities and provide clear privacy notices, data rights mechanisms, and appeal processes.[1][2][11]
  • The Nebraska Attorney General enforces the law exclusively, there is no private right of action, and civil penalties can reach $7,500 per violation after the cure process.[1][2][6]
  • No 2025–2026 amendment or delay changing the NDPA’s general effective date has been identified in the current codified text and 2026 practitioner summaries; the operative law remains the 2024 enactment effective in 2025.[1][4][6]

What It Is

The Nebraska Data Privacy Act is Nebraska’s comprehensive consumer privacy law, codified at Neb. Rev. Stat. §§ 87-1101 to 87-1130, and it governs the collection, processing, sale, and protection of personal data of Nebraska residents.[1][4] The law is enforced by the Nebraska Attorney General.[2][6]

The legislature enacted the NDPA in 2024 as LB1074, and the statute is identified in the Nebraska Revised Statutes as the “Data Privacy Act.”[1][4][6] The law became effective on 1 January 2025.[2][3][5][6]

The available 2026 materials do not show a later statewide postponement or a replacement amendment that displaced the 2025 effective date for the consumer privacy act.[1][4][6] Practitioners in 2026 continue to describe the law as in force and enforceable as of 2025.[2][3][6]

Who Must Comply

The NDPA applies to a controller or other covered person that does business in Nebraska or produces products or services targeted to Nebraska residents, processes personal data, and is not a small business under the federal Small Business Act, subject to a sensitive-data carveout.[1][7][13]

The law also reaches entities that engage in the sale of personal data.[2][9][13] That means some smaller organizations can still be covered if they sell sensitive data without obtaining prior consent, even if they otherwise qualify as a small business.[13]

The statute excludes certain entities and data contexts, including common statutory exemptions such as government agencies and entities regulated under other privacy regimes, and practitioners also identify nonprofits and financial institutions subject to the Gramm-Leach-Bliley Act as outside the main coverage framework.[2][9] As with other state privacy laws, exemptions are narrower than many organizations assume, so scope should be tested against the statutory definitions rather than business type alone.[1][7]

The law’s reach is not limited to Nebraska-headquartered companies; it is triggered by Nebraska residents and the covered business criteria, so it has extraterritorial practical effect for out-of-state controllers handling Nebraska consumer data.[1][13]

Core Requirements

  1. Provide a compliant privacy notice. Controllers must disclose the categories of personal data processed, the purposes for processing, categories of personal data shared with third parties, categories of third parties, and the consumer rights available under the law.[1][2][11]
  2. Honor consumer rights requests. Covered businesses must provide processes for access, correction, deletion, portability, and opt-out rights for targeted advertising, sale of personal data, and certain profiling-based decisions.[1][2][3]
  3. Respond within statutory timelines. Controllers must establish a process to respond to verified consumer requests within the statutory response period, which practitioner summaries describe as 45 days, with a possible extension where justified.[1][12]
  4. Limit sensitive data processing. The NDPA requires prior consent for processing sensitive data, and the consent standard is central to the law’s handling of health, biometrics, precise geolocation, children’s data, and similar categories.[2][11][13]
  5. Conduct data protection assessments. Controllers must assess processing activities that present heightened risk, including targeted advertising, sale of personal data, profiling, sensitive data processing, and certain forms of data processing that reasonably present foreseeable risk.[1][2][11]
  6. Maintain reasonable security practices. Controllers must implement administrative, technical, and physical safeguards appropriate to the volume and sensitivity of data processed.[1][2][11]
  7. Provide an appeal process. If a controller denies a consumer request, the controller must have an internal appeal mechanism and explain how the consumer may contact the Attorney General if the appeal is denied.[1][2]

Deadlines and Penalties

| milestone | date | what applies | |---|---:|---| | Enactment | 17 April 2024 | LB1074 was signed into law and codified as the NDPA.[4][6] | | Effective date | 1 January 2025 | The full consumer privacy regime became operative.[2][3][5][6] | | Ongoing compliance | 2025 onward | Controllers must continue to honor rights requests, notices, assessments, and safeguards.[1][2][11] |

The Attorney General has exclusive enforcement authority, and the NDPA provides a cure period before a penalty can be sought for certain violations.[1][2] After cure or if a written statement is breached, civil penalties can reach $7,500 per violation.[1][2][6]

The law does not provide a private right of action, so consumers cannot sue directly under the NDPA for statutory damages.[2][3][6] Other sanctions are primarily injunctive and civil-enforcement based through the Attorney General.[1][2]

How to Comply

  1. Map data and scope. Inventory personal data, sensitive data, sales, sharing, processors, and targeted advertising flows, then test threshold and exemption status against the statute.[1][7][13]
  2. Update governance and legal roles. Assign controller, processor, and internal privacy-owner accountability, and document decision points for requests, consent, and vendor oversight.[1][2]
  3. Build rights-request operations. Implement intake, identity verification, response tracking, appeal handling, and auditable workflows for access, deletion, correction, portability, and opt-out requests.[1][2][12]
  4. Refresh notices and consent mechanisms. Rewrite privacy notices for statutory disclosures and deploy consent capture for sensitive data and other uses that require affirmative authorization.[1][2][11]
  5. Run and document assessments. Use a repeatable privacy impact assessment process aligned to ISO 27001 for control discipline, NIST CSF 2.0 for governance and risk management, and ISO 42001 where automated profiling or AI decisioning is involved.[1][11]
  6. Strengthen security controls. Align security safeguards to ISO 27001 or NIST CSF 2.0 so access control, encryption, logging, incident response, and vendor security are demonstrably reasonable for the data processed.[1][11]
  7. Review vendors and contracts. Require processors to follow documented instructions, support rights requests, maintain confidentiality and security, and assist with assessments and audits.[1][2]
  8. Train and test annually. Train legal, privacy, product, and support teams on request handling, consent, and escalation, then test the program against real requests and regulator-ready documentation.[1][2]

Related Regulations

The Colorado Privacy Act overlaps heavily because both laws cover consumer rights, targeted advertising, sensitive data, and assessments, but Nebraska’s statute is narrower in some structural details and enforcement architecture.[1][6]

The Texas Data Privacy and Security Act is similar in its controller-style framework and rights structure, making it a useful comparison point for multistate privacy programs.[14]

The Virginia Consumer Data Protection Act overlaps on core rights and assessments, but Nebraska’s penalties and enforcement posture should be checked separately because each state sets its own cure and penalty rules.[1][6]

The California Consumer Privacy Act / CPRA is broader in scope and more operationally prescriptive, especially on notice and consumer request mechanics, so California controls often exceed Nebraska’s minimums.[1][6]

The Gramm-Leach-Bliley Act can exempt certain financial institutions and data, which can remove some records from NDPA coverage even when the same organization processes other covered consumer data.[2][9]

Does the NDPA apply to companies outside Nebraska?

Yes, if the company does business in Nebraska or targets products or services to Nebraska residents and otherwise meets the statute’s coverage criteria.[1][13] The law is not limited to Nebraska-incorporated businesses. Out-of-state entities should assess Nebraska resident data and sales activity, not just headquarters location.[1][7]

Does the NDPA have a private right of action?

No. Enforcement is by the Nebraska Attorney General, not private plaintiffs.[1][2][6] That said, an AG investigation can still produce civil penalties and injunctive relief.[1][2]

When did the NDPA start applying?

The NDPA became effective on 1 January 2025.[2][3][5][6] The enacted law was signed in 2024, and the current codified statute remains in force in 2026.[1][4][6]

What personal data rights do Nebraska residents have?

Residents can access, correct, delete, obtain a copy of their data, and opt out of certain processing such as targeted advertising, sale of personal data, and some profiling activities.[1][2][3] Controllers must also explain how to appeal a denied request.[1][2]

Are small businesses exempt?

Generally, the statute does not apply to a person that qualifies as a small business under the federal Small Business Act, but the sensitive-data and sale-related carveouts matter.[7][13] A business should not assume exemption without checking whether it sells personal data or processes sensitive data in a way that triggers coverage.[13]

What are the penalties for violating the NDPA?

The statute allows civil penalties of up to $7,500 per violation after the cure process or breach of a written statement to the Attorney General.[1][2][6] The Nebraska Attorney General may also seek injunctive relief and other enforcement remedies available under state law.[1][2]

Sources

Put it into practice

More compliance guides