Arizona still has no comprehensive consumer data privacy law in 2026. SB 1815, the state's most recent attempt, died in committee on June 14, 2026. Arizona residents rely on a patchwork of statutes: a strict 45-day breach notification law, a Genetic Information Privacy Act, and student biometric protections — but no CCPA-style right to delete, correct, or opt out of data sales.
Arizona's Current Privacy Landscape
As of August 2026, more than 20 U.S. states have enacted comprehensive consumer data privacy laws. Arizona is not among them. Senate Bill 1815 — introduced February 10, 2026 in the 57th Legislature — would have given residents CCPA-style rights, but it stalled after a second reading and was marked dead on June 14, 2026. Until a similar bill passes, Arizonans rely on targeted statutes and federal laws for protection.
Data Breach Notification Law (A.R.S. §§ 18-551 & 18-552)
The cornerstone of Arizona's data privacy framework is its data breach notification statute. Originally enacted in 2006 and strengthened by HB 2146 in 2022, it sets clear requirements for any business that experiences a security incident affecting Arizona residents.
Key Requirements
- 45-day notification deadline — businesses must notify affected Arizona residents within 45 days of discovering a breach
- Attorney General notification — if a breach affects more than 1,000 Arizonans, the business must also notify the Arizona Attorney General and the three major consumer reporting agencies
- Content requirements — breach notices must describe the incident, list the personal information involved, and provide steps consumers can take to protect themselves
- Substitute notice — allowed when the cost would exceed $50,000 or 100,000+ Arizonans are affected
What Counts as Personal Information
Arizona's breach law covers a broader range of data than most states:
- Social Security numbers
- Driver's license or state ID numbers
- Financial account numbers with any required access code
- Health insurance or medical ID numbers
- Biometric data (fingerprints, retina scans, facial geometry)
- Passport numbers
- Taxpayer identification numbers
- Online account credentials that could permit access to the account
What to Do If You Receive a Breach Notice
If an Arizona company notifies you of a data breach, immediately freeze your credit with Equifax, Experian, and TransUnion, change passwords for affected accounts (and any account reusing the same password), monitor your financial statements weekly for 90 days, and enroll in dark-web monitoring to catch resold credentials.
Genetic Information Privacy Act
Arizona enacted the Genetic Information Privacy Act to regulate direct-to-consumer genetic testing companies like 23andMe, AncestryDNA, and MyHeritage. It is one of the stronger privacy protections available to Arizona residents.
The law requires genetic testing companies to obtain layered, purpose-specific consent:
- Express consent before collecting, using, or sharing genetic data
- Separate consent for sharing data with any third party
- Separate consent for using data beyond the original testing purpose
- Separate consent for retaining your biological sample after testing
- Separate consent for marketing based on genetic results
This layered approach — modeled loosely on Illinois's BIPA — gives you meaningful control over one of the most sensitive types of personal data.
Student Data Privacy
Arizona law restricts how public schools and charter schools handle student biometric information:
- Schools cannot collect biometric information from students without written parental or guardian consent
- Schools must provide written notice to parents at least 30 days before collecting biometric data
- Parents may opt their child out at any time; opted-out data must be destroyed within 30 days
What Arizona Still Lacks
Arizona residents do not have broad statutory rights to access, correct, delete, or port their personal data held by private businesses. There is no state-level right to opt out of data sales, no universal opt-out signal recognition (like California's GPC), and no private right of action for privacy violations. These rights are commonly found in comprehensive privacy laws like California's CCPA, Colorado's CPA, and Virginia's VCDPA.
Skip the manual work
PrivacyOn removes your personal information from 100+ data broker sites and keeps it removed — automatically.
Start your free scan★★★★★ 4.8/5 · Trusted by thousands of families
What Happened to SB 1815
SB 1815 would have granted Arizona residents the rights common in modern state privacy laws:
- The right to know what personal data companies collect about them
- The right to delete their personal data
- The right to correct inaccurate data
- The right to a portable copy of their data
- The right to opt out of targeted advertising and the sale of personal data
- Heightened protections for sensitive data (race, health, precise geolocation, biometrics)
The bill received its second Senate reading in February 2026 but never made it out of committee. It was formally marked dead on June 14, 2026. Advocates expect a similar bill to be reintroduced in the 2027 session, but until then, Arizonans must rely on federal statutes (Fair Credit Reporting Act, HIPAA, GLBA) and targeted state laws.
Federal Laws That Fill Some Gaps
In the absence of a state privacy law, Arizona residents can lean on federal protections:
- FCRA — governs credit reporting; gives you the right to freeze credit and dispute inaccurate reports
- HIPAA — restricts how covered healthcare entities share medical information
- GLBA — requires financial institutions to explain data-sharing practices and let you opt out of some sharing
- COPPA — protects the online privacy of children under 13
- FTC Section 5 — the FTC can pursue companies for unfair or deceptive privacy practices
Protecting Yourself Without a Comprehensive Law
The absence of a state privacy law means Arizona residents need to be more proactive than residents of California or Colorado. Here are the highest-impact steps:
- Opt out of data brokers — Spokeo, BeenVerified, Whitepages, MyLife, Radaris, and 100+ other sites publish your name, address, phone number, relatives, and age
- Freeze your credit — free at all three bureaus; the single most effective step to prevent new-account fraud
- Use privacy-focused tools — a reputable VPN, an encrypted messenger, and a password manager
- Monitor for breaches — sign up for dark-web monitoring so you learn about credential leaks the day they appear
- Set up a Voice-over-IP number for shopping, signups, and directory listings
PrivacyOn makes data broker removal automatic for Arizona residents. We continuously monitor 100+ data brokers and people-search sites, submit opt-out requests on your behalf, verify that your information stays removed, and scan the dark web for leaked credentials — providing the kind of ongoing protection that Arizona law does not yet require businesses to give you. Plans start at $8.33/month with family coverage for up to 5 people. Run a free scan to see how many brokers currently list you.
Frequently Asked Questions
Does Arizona have a data privacy law?
Not a comprehensive one. Arizona has targeted statutes covering data breaches, genetic testing, and student biometrics, but no CCPA-style consumer data privacy law. SB 1815, which would have granted access, deletion, and opt-out rights, died in committee on June 14, 2026.
How long does an Arizona business have to notify me of a breach?
Forty-five days from discovery of the breach, under A.R.S. §§ 18-551 and 18-552. Businesses that affect more than 1,000 Arizonans must also notify the Arizona Attorney General and the three major credit bureaus.
Can I sue a company for a privacy violation in Arizona?
Generally no. Arizona's breach notification law does not create a private right of action. Enforcement is handled by the Arizona Attorney General. You may have federal claims (FCRA, HIPAA, TCPA) depending on the type of violation.
Do I have the right to delete my personal information under Arizona law?
Not under state law. Arizona has no statutory right to deletion for data held by private businesses. Some companies (especially large retailers and tech platforms) offer deletion voluntarily. Data brokers must honor opt-out requests submitted through their own portals — services like PrivacyOn automate this for 100+ sites.
Are Arizona employers restricted from tracking employees?
Arizona has no general employee-monitoring statute, but employers must comply with federal wiretap law and cannot access personal accounts protected by passwords. Employers may monitor company-issued devices and workplace networks with proper notice.
Does the CCPA protect Arizona residents?
Only if a business subject to the CCPA processes your data. Some California-based companies apply CCPA rights to all U.S. residents as a matter of policy — check each company's privacy notice. You have no automatic California-style rights based on where the company is headquartered.