Skip to content

Cyber Liability by state

Arkansas data breach notification law and cyber insurance

Direct answer

What is Arkansas's data breach notification law?

Arkansas's breach notification law (Ark. Code sect. 4-110-101 et seq.) requires businesses to notify affected residents in the most expedient time and manner possible and without unreasonable delay after a breach of personal information. Arkansas requires businesses to notify residents of breaches of unencrypted personal information without unreasonable delay, once the business determines harm is reasonably likely.

Reviewed by Cornerstone Staff28 years of financial services state licensing experienceLast verified July 29, 2026

What the statute requires

Arkansas requires businesses to notify residents of breaches of unencrypted personal information without unreasonable delay, once the business determines harm is reasonably likely. Cyber liability coverage typically pays for the forensic analysis, legal review, and notification costs behind that determination.

Consumer notification deadline
In the most expedient time and manner possible and without unreasonable delay
Regulator notice
Notify the Arkansas Attorney General when a breach affects more than 1,000 individuals, at the same time affected individuals are notified or within 45 days of determining a reasonable likelihood of harm, whichever occurs first.
Safe harbor
Notification is not required if the compromised data was encrypted, and disclosure is not required if the business reasonably determines there is no likelihood of harm to consumers.
Enforcement
Violations are enforceable by the Attorney General as deceptive trade practices, which allow civil penalties and injunctive relief.

Statutes and sources

  • Arkansas Personal Information Protection Act

    Ark. Code sect. 4-110-101 et seq.

Regulator: Arkansas Attorney General . Last verified 2026-07-29 from the official source .

Get Arkansas coverage handled

Share a few details and an agent will respond within one business day.