Public-domain · open source
OpenJurist

Personal Information Protection Act

Arkansas · Business and Commercial Law · §§ 4-110-101 to 4-110-108 · 8 sections

Overview

This act governs how businesses and government agencies handle personal information about individuals, covering data-security breaches, security freezes on credit information, the use of Social Security numbers, and the disposal of records containing personal data. It requires notice to affected individuals — and in certain cases to other agencies — after a breach of security, lets a person place, confirm, and remove a freeze restricting access to their credit information, and limits when Social Security numbers may be requested, collected, disclosed, sold, or otherwise transferred, subject to exceptions for employees, agents, and specified employment purposes. Entities holding personal records must adopt protective policies and procedures and exercise due diligence in destroying those records, with noncompliance enforceable through civil penalties and court action.

Editorial summary generated from the text of this act. It is not part of the statute — read the sections below for the operative language.

In the courts

Sections of this act have been cited in 4 court decisions.

Most-cited authority: 353 FSUPP3D 1070 - Bellwether Cmty. Credit Union v. Chipotle Mexican Grill, Inc.

Sections covered

Enacted in other states

Alaska, Illinois

All Arkansas named statutes →

Download

Copy

Embed on your site

Hover to preview · click to copy the code

Search Wikipedia →