Privacy Law Library

Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006

Nebraska Data Breach Notification and Data Security Act

Breach notification · Data security · Biometric

Nebraska's breach law requires businesses and government entities that own or license computerized personal information to investigate a breach promptly and, if misuse has occurred or is reasonably likely, to notify affected residents and the Attorney General. Since 2018 it also requires reasonable security procedures, including for disposal, and contracts requiring vendors to safeguard the data. Notice to the Attorney General and the username/email-and-password element were added by LB835, effective July 21, 2016.

Where
Nebraska
Citation
Neb. Rev. Stat. 87-801 to 87-808
Status
In force
In force since
2006-07-14
Last amended
2018-07-19
Enforced by
Nebraska Attorney General
People can sue
No
Penalties
The Attorney General may issue subpoenas and recover direct economic damages for each injured Nebraska resident for notice violations (87-806(1)). A violation of the security requirement in 87-808 is an unfair or deceptive practice under the Consumer Protection Act (59-1602) but gives no private cause of action (87-806(2)).
Applies to
  • Individuals and commercial entities (including governments, agencies, and nonprofits) that conduct business in Nebraska and own or license computerized data containing personal information of Nebraska residents (87-802(2), 87-803(1))
  • Entities that maintain such data for an owner or licensee (87-803(3))
  • Personal information: name plus SSN, driver's license or state ID number, financial account or card number with access code, unique electronic ID or routing code with access code, or unique biometric data; or a username or email address with password or security question and answer (87-802(5))

What a privacy notice must say

  • Notice may be written, telephonic, or electronic (E-SIGN compliant); substitute notice (email, website posting, statewide media) is allowed if cost exceeds $75,000, more than 100,000 residents are affected, or contact information is insufficient, with a separate option for entities with 10 or fewer employees.Neb. Rev. Stat. 87-802(4)

Security duties

  • Implement and maintain reasonable security procedures and practices appropriate to the information and the business, including safeguards when disposing of personal information.Neb. Rev. Stat. 87-808(1) · From 2018-07-19
  • Require by contract that nonaffiliated third-party service providers receiving personal information maintain reasonable security procedures (contracts entered or renewed on or after July 19, 2018).Neb. Rev. Stat. 87-808(2) · From 2018-07-19

Breach duties

  • On becoming aware of a breach, conduct a good-faith, reasonable, and prompt investigation of the likelihood that personal information has been or will be misused.Neb. Rev. Stat. 87-803(1)
  • Notify affected Nebraska residents as soon as possible and without unreasonable delay if misuse has occurred or is reasonably likely to occur.Neb. Rev. Stat. 87-803(1) · Only if: Risk-of-harm trigger: unauthorized use occurred or is reasonably likely
  • Notify the Attorney General no later than the time residents are notified. The Attorney General's Consumer Protection Division provides a notification form that asks for the manner of notice, a sample notice letter, and any reason for delay.Neb. Rev. Stat. 87-803(2)
  • An entity maintaining data it does not own or license must notify and cooperate with the owner or licensee, including sharing relevant breach information.Neb. Rev. Stat. 87-803(3)
  • Notice may be delayed while a law enforcement agency determines it would impede a criminal investigation.Neb. Rev. Stat. 87-803(4)

Other duties

  • Entities that follow their own consistent notice procedures, or procedures required by their primary state or federal regulator, are deemed compliant if they notify residents and the Attorney General; compliance with GLBA or HIPAA rules satisfies the security duties.Neb. Rev. Stat. 87-804; 87-808(3)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: The Attorney General's breach form cites 'Neb. Rev. Stat. 87-303(2)', an apparent typo for 87-803(2).

Research reference, not legal advice.