{
 "jurisdiction_id": "US-AZ",
 "jurisdiction": "United States – Arizona",
 "url": "https://dataprotection.gi/jurisdictions/united-states-arizona/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-06",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 22,
  "sub_modules": 57,
  "source_register": 10
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-arizona/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "A named regulator and concrete instruments exist (breach notification statute, Consumer Fraud Act), but there is no comprehensive framework defining lawful bases, subject rights or controller obligations.",
   "claims": [
    {
     "statement": "The Arizona Attorney General is the primary enforcement authority for data-breach notification and consumer-data-practice violations in Arizona, in the absence of a dedicated data-protection regulator.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/arizona",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Arizona currently has no comprehensive consumer-privacy statute; recent legislative attempts to pass general privacy legislation have not been enacted.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/arizona",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Breach and data-security requirements in Arizona are governed by the state's breach-notification law under §18-552 of the Arizona Revised Statutes, which requires notification to consumers and to the Arizona Attorney General or the Arizona Department of Homeland Security.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/arizona",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "HB 2146, signed by the Arizona Governor on 29 March 2022, amended A.R.S. §18-552 and expanded the definition of personal information subject to breach-notification duties, while also introducing a 45-day notification deadline.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/arizona-bill-amend-breach-notification-requirements",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "For breaches affecting more than 1,000 Arizona residents, HB 2146 requires notification to the three largest nationwide consumer-reporting agencies in addition to the Attorney General and the Arizona Department of Homeland Security.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/arizona-bill-amend-breach-notification-requirements",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "red",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-arizona/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "No omnibus lawful-basis, consent, or special-category regime exists at the state level; only a narrow genetic-testing carve-out was identified.",
   "claims": [
    {
     "statement": "The Arizona Attorney General alleged in litigation against Google that the company continued collecting users' location data via settings such as Web & App Activity even after users disabled Location History, framing this as a deceptive-consent practice under the Arizona Consumer Fraud Act.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/arizona-ag-files-lawsuit-against-google-deceptive",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Arizona is among twelve US states (alongside Alabama, California, Kentucky, Maryland, Montana, Tennessee, Texas, Utah, Virginia, Wyoming and Nebraska) with a statute specifically governing direct-to-consumer genetic-testing companies.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/nebraska",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "red",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-arizona/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "No comprehensive data-subject-rights regime exists in Arizona; this is a legitimate structural gap rather than an omission.",
   "claims": [
    {
     "statement": "Arizona's breach-notification statute imposes a 45-day deadline for notifying affected individuals of a data breach, but this is a breach-response deadline, not a subject-access-request response window, since no general access-request regime exists in Arizona.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/healthcare-data-breaches-included-in-arizonas-new-notification-law/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-arizona/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Breach notification is a real, enforceable duty; the remaining accountability infrastructure (DPIA, DPO, ROPA, retention) is absent at state level.",
   "claims": [
    {
     "statement": "Arizona's breach-notification statute presumes an underlying duty of reasonable data security by penalizing failure to protect personal information that leads to a breach, though it does not itemize specific technical or organisational security measures.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/arizona",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Arizona's amended breach-notification law (via HB 2146) sets a 45-day deadline for notifying affected individuals, expands the definition of covered personal information to include health-care data, and gives the Attorney General enhanced power to prosecute violators.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/healthcare-data-breaches-included-in-arizonas-new-notification-law/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Under A.R.S. §18-552, businesses must notify affected consumers and either the Arizona Attorney General or the Arizona Department of Homeland Security in the event of a data breach, and the Attorney General holds the power to sanction violations and issue penalties.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/arizona",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "red",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-arizona/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "No AZ-specific cross-border transfer, adequacy or localisation framework exists; this is a legitimate gap given the absence of a state omnibus law.",
   "claims": []
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-arizona/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "A narrow genetic-testing overlay exists; broader sectoral coverage (health, finance, education, insurance) is federal and out of scope for this state JID.",
   "claims": [
    {
     "statement": "Arizona healthcare entities, such as a regional medical center and other providers, have reported large-scale ransomware and malware-related patient-data breaches to HHS OCR under federal HIPAA breach-reporting obligations, impacting hundreds of thousands of individuals.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/arizona",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Arizona has enacted a law restricting telephone solicitations to numbers on the National Do-Not-Call registry, subject to specific exceptions.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/arizona",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-arizona/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "No structural cookie/opt-out regime exists, but active AG enforcement under general consumer-fraud authority provides a meaningful, demonstrated deterrent against deceptive ad-tech data practices.",
   "claims": [
    {
     "statement": "The Arizona Attorney General secured an $85 million settlement with Google in 2022 resolving allegations that Google deceptively continued collecting and using consumers' location data for advertising purposes after users had disabled location tracking, brought under the Arizona Consumer Fraud Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/b/arizona-attorney-general-reaches-85m-location-privacy-settlement",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-arizona/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Meaningful legislative activity exists (biometric, AI, surveillance-pricing bills) but none confirmed in force; treat as pending/proposed pending regulator confirmation.",
   "claims": [
    {
     "statement": "Arizona House Bill 2489 would restrict surveillance-based pricing practices by defining and prohibiting such practices and establishing enforcement mechanisms, but has not been confirmed enacted as of this run.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/arizona",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Arizona House Bill 2311 would introduce disclosure, safety, and content restrictions for conversational AI services, with enhanced protections for minors, but its passage into law has not been confirmed in this run.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/arizona",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Arizona Senate Bill 1238 would regulate biometric-data handling by private entities and provide legal recourse for violations; the bill was read in the State Senate but its final enactment status could not be independently confirmed in this run.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/arizona",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-arizona/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Active pending legislative pipeline on minors' data exists, but nothing AZ-specific is confirmed in force; federal COPPA is the operative baseline, and is out of scope for this JID.",
   "claims": [
    {
     "statement": "Arizona House Bill 2920 would mandate age verification, parental consent, and data-sharing duties for app stores and developers handling minors' accounts, but its enactment status has not been independently confirmed in this run.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/arizona",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Arizona House Bill 2861 would enhance privacy protections for minors on social media platforms, and House Bill 2858 similarly seeks to enhance online privacy and safety for minors on social media, but neither has been confirmed enacted in this run.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/arizona",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-arizona/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement powers and recent activity are real and material, but redress avenues remain reactive/consumer-fraud-based rather than a dedicated private right of action under a comprehensive privacy statute.",
   "claims": [
    {
     "statement": "The Arizona Attorney General obtained an $85 million settlement with Google in 2022 for deceptive location-data practices found to violate the Arizona Consumer Fraud Act, with the bulk of proceeds directed to the state general fund and $5 million earmarked for attorney-general education programs.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/attorney-general-journal/attorney-general-consumer-protection-news-october-2022/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Arizona Attorney General has sued Temu alleging unlawful data collection and inadequate privacy disclosures, representing recent state enforcement activity against a commercial data practice.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/arizona",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Pending Arizona Senate Bill 1238 would regulate biometric-data handling by private entities and provide for legal recourse for violations, which would constitute a private right of action if enacted, but enactment has not been confirmed in this run.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdiction/arizona",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  }
 ]
}