
The Arizona data breach notification law gives a business 45 days to notify affected Arizona residents once it determines that their personal information was breached. The rules sit in A.R.S. 18-551, which defines the key terms, and A.R.S. 18-552, which sets out who must notify, when, how and what happens if they do not.
The deadline is easy to remember. The hard part is the investigation that comes first, because every obligation turns on what you can prove: which systems, which records, which residents and whether the data was encrypted. That is where cyber incident response and forensic scoping decide whether a notice goes out on time and says the right thing.
This guide covers the statute as of October 2026, a step-by-step response timeline and how forensic work answers the questions the law asks.
Key takeaways
- Notify affected Arizona residents within 45 days after you determine a security system breach occurred (A.R.S. 18-552(B)).
- Over 1,000 individuals? Also notify the Attorney General, the director of the Arizona Department of Homeland Security and the three largest nationwide consumer reporting agencies.
- Personal information means a name plus a specified data element, or a username or email plus a password or security answer.
- Properly encrypted or redacted data falls outside the breach definition if the key stayed confidential.
- HIPAA covered entities, business associates and GLBA-regulated institutions are exempt and follow federal rules.
- Knowing and willful violations can bring civil penalties of up to $500,000 per breach, plus restitution.
This article is general information, not legal advice. Confirm how the statute applies to your facts with breach counsel.
Where this guidance comes from. We read the current text of A.R.S. 18-551 and 18-552 on azleg.gov, the session laws that created and amended them, the Arizona Attorney General’s data breach page, form and FAQ, the FTC’s Data Breach Response Guide, the HIPAA Breach Notification Rule, the FTC Safeguards Rule notification requirement and NIST SP 800-61 Rev. 3. The practical advice reflects our team’s field experience responding to incidents and preserving digital evidence.
What the Arizona data breach notification law covers
The current framework was created by House Bill 2154 (Laws 2018, Chapter 177, signed April 11, 2018). House Bill 2146 (Laws 2022, Chapter 81, signed March 29, 2022) added the director of the Arizona Department of Homeland Security as a recipient for larger breaches. The definitions in A.R.S. 18-551 control everything else.
Personal information and specified data elements
Personal information is either a first name or first initial and last name combined with a specified data element, or a username or email address combined with a password or security question and answer that unlocks an online account. Lawfully public government records and widely distributed media are excluded. The specified data elements are:
- Social Security number.
- Driver license or nonoperating identification license number.
- A private key unique to the individual used to authenticate or sign electronic records.
- Financial account or card number plus any required code or password.
- Health insurance identification number.
- Medical or mental health treatment or diagnosis information.
- Passport number.
- Taxpayer identification number or IRS identity protection PIN.
- Biometric data used to authenticate to an online account.
What counts as a security system breach
A breach is an unauthorized acquisition of and unauthorized access that materially compromises the security or confidentiality of unencrypted and unredacted computerized personal information in a database about multiple individuals. Good-faith access by an employee or agent for business purposes is not a breach if the data is not misused or further disclosed.
A security incident is different: an event that creates reasonable suspicion that systems or data may have been compromised. An incident triggers the duty to investigate. Only a confirmed breach triggers notice.
Encryption, redaction and who counts
Encrypt means making data unreadable or unusable without a confidential process or key. Redact means no more than the last four digits are accessible and at least two digits were removed. Only Arizona residents with a principal mailing address in Arizona, as shown in your records at the time of the breach, count as individuals.
Who must comply with the Arizona data breach notification law
The duty applies to any person that conducts business in Arizona and owns, maintains or licenses unencrypted and unredacted computerized personal information. That includes companies, nonprofits and government agencies. The Department of Public Safety, sheriffs, municipal police, prosecution agencies and courts are excluded but must keep their own breach policies.
Owners and licensees send the notices. A vendor that only maintains data for someone else, such as an IT provider or payroll processor, must notify the owner as soon as practicable and share what it knows under A.R.S. 18-552(C). The vendor does not notify consumers unless the contract says so.
When does the 45-day clock start?
When you become aware of a security incident, A.R.S. 18-552(A) requires an investigation to promptly determine whether a breach occurred. The 45 days run from that determination. The statute sets no fixed investigation period, but a slow or undocumented investigation is hard to defend as prompt.
Record the date you learned of the incident and the date you made the breach determination. The Arizona data breach notification law also allows delay if a law enforcement agency advises that notice would impede a criminal investigation; once it no longer would, you have 45 days. Document that request carefully.
Facing a possible breach right now? The scoping work in the first days decides your notice list. Request incident response online and we will help you preserve evidence and document the determination. For active attacks after hours, use the urgent intake form.
Who you must notify under A.R.S. 18-552
Recipients depend on how many Arizona residents need notice and how you deliver it. This matrix reflects the statute as of October 2026.
| Recipient | When required | Deadline | How |
|---|---|---|---|
| Affected Arizona individuals | Any confirmed breach, unless exempt | 45 days after determination | Letter, email, live phone call or substitute notice |
| Arizona Attorney General | More than 1,000 individuals | Same 45 days | AG online form, fillable PDF or a copy of the individual notice |
| Director, Arizona Department of Homeland Security | More than 1,000 individuals | Same 45 days | In writing; the same notice sent to the AG is allowed |
| Three largest nationwide consumer reporting agencies | More than 1,000 individuals | Same 45 days | Notice to each agency |
| Attorney General (substitute notice) | Any breach using substitute notice | With substitute notice | Letter showing why substitute notice qualifies |
Notices to the Attorney General and the Department of Homeland Security, other than substitute notice letters, are confidential under A.R.S. 44-1525. The AG’s form screens filers on the over-1,000 threshold and HIPAA or GLBA status.
What the notice must say and how to send it
A.R.S. 18-552(E) requires at least the approximate date of the breach, a brief description of the personal information involved, the toll-free numbers and addresses of the three largest nationwide consumer reporting agencies, and the toll-free number, address and website of the FTC or another federal identity theft agency. The FTC also recommends explaining what you are doing and what steps people can take, such as credit freezes.
Delivery methods and substitute notice
Notice may go by letter, by email if you have addresses, or by phone if you reach people directly rather than by recording. Substitute notice is allowed if regular notice would cost more than $50,000, more than 100,000 individuals are affected, or contact information is insufficient. It requires a letter to the Attorney General plus a conspicuous website posting for at least 45 days.
When only usernames or emails with passwords or security answers are exposed, subsection (G) allows electronic notice telling people to change those credentials everywhere they reused them, and a forced password reset can satisfy the duty for your own service.
Exemptions: HIPAA, GLBA and other safe harbors
A.R.S. 18-552(N) excludes persons subject to Title V of the Gramm-Leach-Bliley Act and HIPAA covered entities and business associates. They still have federal duties:
- HIPAA requires individual notice no later than 60 calendar days after discovery (45 CFR 164.404(b)). See our guide to HIPAA breach forensic investigation requirements.
- Since May 13, 2024, the FTC Safeguards Rule requires covered financial institutions to report breaches of 500 or more consumers to the FTC within 30 days of discovery.
Three more provisions matter. Following your primary federal regulator’s breach rules is deemed compliance with individual notice. So is following your own written policy if it is consistent with the article, including the 45 days. And no notice is required if you, an independent third-party forensic auditor or law enforcement reasonably determines that substantial economic loss to individuals is not reasonably likely.
Penalties and Attorney General enforcement
A knowing and willful violation is an unlawful practice under the Arizona Consumer Fraud Act, and only the Attorney General may enforce it. Penalties cannot exceed the lesser of $10,000 per affected individual or total economic loss, capped at $500,000 per breach or series of related breaches, plus restitution. The Arizona data breach notification law also preempts city and county breach rules.
Step-by-step Arizona breach response timeline
This is a sample planning timeline. Only the 45-day limits and the vendor duty come from the statute; other timings are working targets.
| Step | Suggested timing | What happens | Legal hook |
|---|---|---|---|
| 1. Recognize the incident | Hour 0 | Log awareness time, activate the plan, engage counsel and insurer | 18-552(A) |
| 2. Contain and preserve | Hours 0 to 72 | Isolate without wiping; capture images, memory and logs | FTC guide |
| 3. Vendor tells owner | As soon as practicable | Service provider reports and shares findings | 18-552(C) |
| 4. Law enforcement | Early | Report the crime; document any delay request | 18-552(D) |
| 5. Forensic scoping | Promptly | Access window, systems, data elements, exfiltration, encryption | 18-552(A) |
| 6. Breach determination | Day D | Written finding, Arizona resident count, any 18-552(J) analysis | Starts 45 days |
| 7. Prepare notices | D to about D+30 | Address list, required content, recipient support | 18-552(E), (F) |
| 8. Notify individuals | By D+45 | Mail, email or call; substitute posting if used | 18-552(B)(1) |
| 9. AG, AZDOHS, credit bureaus | By D+45 if over 1,000 | AG form, same notice to AZDOHS, three agencies | 18-552(B)(2) |
| 10. Close out | After notice | Fix root cause, retain the file, update the plan | NIST SP 800-61r3 |
If ransomware is involved, see our first 24 hours ransomware guide for Arizona and the broader data breach response plan for small businesses.
How forensic investigation determines breach scope
Every duty under the Arizona data breach notification law depends on facts an investigation must establish. The FTC advises considering independent forensic investigators to determine the source and scope of a breach, and taking affected equipment offline without shutting it down until they arrive. A scoping investigation answers these questions:
- Was data accessed and acquired? Endpoint, identity, firewall and cloud audit logs show what the intruder touched and whether data was staged or transferred out.
- What was the time window? A timeline from first malicious activity to containment defines which data was in scope.
- Which data elements were exposed? Mapping affected databases, shares and mailboxes against the A.R.S. 18-551 data elements shows whether personal information was involved.
- Did encryption hold? Encryption at rest does not help if the attacker worked inside a logged-in session or stole the key.
- How many Arizona residents? De-duplicated records matched to mailing addresses decide whether the over-1,000 notices apply.
- Is substantial economic loss likely? Relying on A.R.S. 18-552(J) requires a documented, reasonable investigation behind the conclusion.
Two cautions from field work: mailbox compromises are often under-scoped because sensitive attachments sit in sent items and archives, and restoring from backup before imaging can erase the logs that would have narrowed the notice list. If the incident began with business email compromise or an insider, cyber investigations focused on attribution can run alongside the response. To estimate the financial impact, try our data breach cost calculator.
How Honeybadger helps with Arizona data breach notification
Honeybadger Solutions is a veteran-led firm based in Casa Grande, Arizona, and an Arizona DPS-licensed private investigation agency (License No. 1759795). Our cyber incident response team handles triage, containment, eradication and recovery, then documents forensics and root cause to court-ready standards, with reporting built for leadership, insurers and regulators.
Our digital forensics laboratory acquires computers, servers, mobile devices and cloud accounts, including remotely, with chain of custody and a unified timeline. We work alongside your breach counsel and insurer and supply the facts they need to make the notice decision within 45 days; we do not give legal opinions.
Starting online is fastest. Submit a service request for breach investigation with a short description of what you are seeing, or book a consultation online to set up an incident response retainer before you need one.
Why the online intake is faster than a phone call: it takes about two minutes, and your answers are routed straight to the specialist team that handles your kind of matter, whether that is cyber and forensics, investigations or field security. That team sees the full picture before it replies, so you skip phone tag and get a real answer and next steps sooner. If it cannot wait for business hours, use the urgent intake form, which is read seven days a week.
Frequently asked questions
How long do I have to notify under the Arizona data breach notification law?
45 days after your investigation determines that a security system breach occurred, under A.R.S. 18-552(B). The investigation itself must be prompt. A law enforcement request can delay notice; once the agency says notice will no longer compromise its investigation, you have 45 days to send it.
Do I have to notify the Arizona Attorney General about every breach?
No. The Attorney General, the director of the Arizona Department of Homeland Security and the three largest nationwide consumer reporting agencies must be notified when more than 1,000 individuals need notice. Substitute notice always requires a letter to the Attorney General.
Is encrypted data covered by the Arizona breach law?
The breach definition covers unencrypted and unredacted computerized personal information. If the attacker also obtained the key, or took data from a system where it was already decrypted, that protection may not hold, so key handling needs forensic review.
Does the Arizona law apply to HIPAA-covered entities and banks?
No. A.R.S. 18-552(N) exempts HIPAA covered entities and business associates and persons subject to Title V of the Gramm-Leach-Bliley Act. They follow federal rules instead, such as HIPAA’s 60-day individual notice limit or the FTC Safeguards Rule’s 30-day report. Confirm your status with counsel.
What are the penalties for violating the Arizona breach notification law?
A knowing and willful violation is an unlawful practice under the Arizona Consumer Fraud Act, enforceable only by the Attorney General. Civil penalties are capped at the lesser of $10,000 per affected individual or total economic loss, with a $500,000 maximum per breach or series of related breaches, plus possible restitution.
Can a forensic investigation show that notice is not required?
Possibly. Under A.R.S. 18-552(J), notice is not required if the business, an independent third-party forensic auditor or law enforcement determines after a reasonable investigation that the breach has not caused and is not reasonably likely to cause substantial economic loss to affected individuals. Document that conclusion and have counsel review it.
Sources and further reading
- A.R.S. 18-551, Definitions — Breach, encryption, personal information and data element definitions.
- A.R.S. 18-552, Notification of security system breaches — Deadline, recipients, content, methods, exemptions and penalties.
- Laws 2018, Chapter 177 (HB 2154) — Created A.R.S. 18-551 and 18-552.
- Laws 2022, Chapter 81 (HB 2146) — Added the Arizona Department of Homeland Security as a recipient.
- Arizona Attorney General: Data Breach — State breach reporting overview.
- Arizona Attorney General: Notification Form — Online and PDF filing and exemption screening.
- Arizona Attorney General: Data Breach FAQ — AG summary of duties and penalties.
- FTC: Data Breach Response, A Guide for Business — Forensic investigation and notice recommendations.
- 45 CFR Part 164, Subpart D — HIPAA Breach Notification Rule.
- FTC: Safeguards Rule notification requirement (May 2024) — 500-consumer, 30-day FTC report.
- NIST SP 800-61 Rev. 3 (April 2025) — Incident response guidance aligned with CSF 2.0.
- 15 U.S.C. 1681a — Definition of a nationwide consumer reporting agency.
- FTC: IdentityTheft.gov — FTC identity theft resource for consumers.
Written and reviewed by the Honeybadger Solutions security and investigations team, a veteran-led Arizona firm (Arizona DPS private investigation agency license No. 1759795). Facts checked against the cited sources on October 2, 2026. This article is general information, not legal advice.
Browse by topic
Security guard services  · Private investigations  · Cybersecurity  · Digital forensics  · Financial fraud investigation  · Executive protection  · All articles