{
 "jurisdiction_id": "US-AR",
 "jurisdiction": "United States – Arkansas",
 "url": "https://dataprotection.gi/jurisdictions/united-states-arkansas/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-06",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 41,
  "sub_modules": 57,
  "source_register": 14
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-arkansas/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "No omnibus statute exists (would be red for material/territorial/registration sub-modules), but a functioning breach-notification/security regime with an active enforcing regulator (AG) exists and is expanding via sectoral bills, justifying amber rather than red at the module level.",
   "claims": [
    {
     "statement": "The Arkansas Attorney General is the state regulator responsible for enforcing the Personal Information Protection Act and the Arkansas Deceptive Trade Practices Act, including data-breach and consumer-privacy-adjacent violations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance/OneTrust",
     "source_url": "https://www.dataguidance.com/jurisdictions/arkansas",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Arkansas has no comprehensive consumer data-protection or privacy statute; the state's principal privacy-relevant law is the Personal Information Protection Act, which addresses data-breach notification and reasonable-security/disposal obligations only.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/privacy-in-arkansas-is-arkansas-ready-for-a-consumer-privacy-law-",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Personal Information Protection Act (Ark. Code Ann. § 4-110-101 et seq.), effective April 4, 2005, requires individuals, businesses, and state agencies that acquire, own, or license personal information of Arkansas residents to implement reasonable security measures and reasonable data-disposal procedures.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance/OneTrust",
     "source_url": "https://www.dataguidance.com/jurisdictions/arkansas",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Arkansas expanded the entities subject to its breach-notification statute to any business that acquires, owns, or licenses personal information of a state resident, giving the law reach over out-of-state entities holding Arkansas residents' data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OPC Canada",
     "source_url": "https://www.priv.gc.ca/en/opc-actions-and-decisions/advice-to-parliament/2007/sub_070222_06/?wbdisable=true",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Arkansas law does not impose a general registration or filing obligation on data controllers or processors.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance/OneTrust",
     "source_url": "https://www.dataguidance.com/jurisdictions/arkansas",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "red",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-arkansas/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Core sub-modules (lawful_bases, special_categories, pseudonymisation) are entirely absent; only a narrow, minors-specific consent overlay exists and part of that overlay has been struck down.",
   "claims": [
    {
     "statement": "Arkansas has no general statutory enumeration of lawful bases for processing personal data equivalent to GDPR Article 6; processing outside sector-specific contexts requires no specific lawful-basis justification under Arkansas law.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/privacy-in-arkansas-is-arkansas-ready-for-a-consumer-privacy-law-",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Arkansas Children and Teens' Online Privacy Protection Act (HB1717), effective July 1, 2026, prohibits covered operators from collecting personal data from minors for targeted-advertising purposes and mandates specific data-management practices.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance/OneTrust",
     "source_url": "https://www.dataguidance.com/jurisdictions/arkansas",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Arkansas Social Media Safety Act (SB396), which would have required age verification and parental consent for minors under 18 to use social media platforms, was enjoined by the U.S. District Court for the Western District of Arkansas and subsequently held unconstitutional on First and Fourteenth Amendment grounds; its consent mechanism is not currently enforceable.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/federal-court-pauses-arkansas-childrens-social-media-law/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Arkansas has no independent statutory scheme creating heightened protections for special/sensitive categories of personal data (health, biometric, genetic, etc.) outside of federal sectoral overlays such as HIPAA and COPPA.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/privacy-in-arkansas-is-arkansas-ready-for-a-consumer-privacy-law-",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Arkansas law provides no statutory definition of, or safe-harbour for, pseudonymised or anonymised data.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance/OneTrust",
     "source_url": "https://www.dataguidance.com/jurisdictions/arkansas",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "red",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-arkansas/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "All consumer-rights sub-modules are absent except a narrow breach-notice timing rule.",
   "claims": [
    {
     "statement": "Arkansas law does not grant consumers a general right of access, rectification, erasure, restriction, objection, or data portability with respect to personal data held by private-sector controllers.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/privacy-in-arkansas-is-arkansas-ready-for-a-consumer-privacy-law-",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "PIPA requires notification of a security breach to affected Arkansas residents and, depending on the number affected, to the Attorney General, functioning as a breach-notice timing obligation rather than a general subject-access-request deadline.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance/OneTrust",
     "source_url": "https://www.dataguidance.com/jurisdictions/arkansas",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-arkansas/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Security, breach-notification and disposal duties are in force and enforced by the AG, but the broader accountability infrastructure (DPIA, DPO, ROPA, joint controllers) found in omnibus regimes is entirely absent.",
   "claims": [
    {
     "statement": "Arkansas law contains no accountability principle or DPIA-trigger obligation comparable to GDPR Articles 5, 25, or 35.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/privacy-in-arkansas-is-arkansas-ready-for-a-consumer-privacy-law-",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Arkansas law imposes no requirement to appoint a data protection officer.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/privacy-in-arkansas-is-arkansas-ready-for-a-consumer-privacy-law-",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Arkansas law imposes no obligation to maintain records of processing activities.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/privacy-in-arkansas-is-arkansas-ready-for-a-consumer-privacy-law-",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Arkansas law contains no statutory framework governing joint-controller relationships or allocation of responsibility between co-controllers.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/privacy-in-arkansas-is-arkansas-ready-for-a-consumer-privacy-law-",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Personal Information Protection Act requires covered persons, businesses, and state agencies to implement and maintain reasonable security procedures and practices to protect personal information from unauthorized access, use, modification, or disclosure.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance/OneTrust",
     "source_url": "https://www.dataguidance.com/jurisdictions/arkansas",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "PIPA requires notification of security breaches involving personal information to affected Arkansas residents and, depending on the number of individuals affected, to the Arkansas Attorney General.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance/OneTrust",
     "source_url": "https://www.dataguidance.com/jurisdictions/arkansas",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "PIPA requires covered entities to implement reasonable procedures for the proper disposal of records containing personal information to prevent unauthorized access to or use of the information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance/OneTrust",
     "source_url": "https://www.dataguidance.com/jurisdictions/arkansas",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "red",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-arkansas/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "No sub-module has any state-level content; all rely on absent_field_provenance.",
   "claims": [
    {
     "statement": "Arkansas has no data-localisation mandate or state-level cross-border data-transfer mechanism (adequacy, SCCs, BCRs, or transfer-impact-assessment requirement) applicable to personal data generally, in the absence of a comprehensive consumer-privacy statute.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/privacy-in-arkansas-is-arkansas-ready-for-a-consumer-privacy-law-",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-arkansas/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Several narrow, real sectoral overlays exist and are enforced, but broad sectors (employment, credit, education) have no state-specific coverage beyond federal baselines.",
   "claims": [
    {
     "statement": "Arkansas Act 557 imposes data-security-program and incident-response-plan requirements on virtual-currency businesses operating in the state, supplementing the general PIPA security baseline for this sector.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance/OneTrust",
     "source_url": "https://www.dataguidance.com/jurisdictions/arkansas",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Health-sector personal information in Arkansas is governed primarily by the federal Health Insurance Portability and Accountability Act, as Arkansas has no independent comprehensive state health-privacy statute displacing HIPAA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Arkansas Consumer Telephone Privacy Act, Ark. Code Ann. § 4-99-401 et seq., sets out telemarketing requirements and establishes a state-wide Do-Not-Call database.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance/OneTrust",
     "source_url": "https://www.dataguidance.com/jurisdictions/arkansas",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No independent Arkansas statute governs employment-data privacy, credit-scoring privacy, or education-data privacy beyond the general breach-notification baseline and applicable federal overlays (FCRA, FERPA).",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/privacy-in-arkansas-is-arkansas-ready-for-a-consumer-privacy-law-",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Arkansas House Bill 1297 regulates the use of artificial intelligence in health-insurance decision-making, mandating transparency and quality-assurance requirements for AI algorithms used by insurers.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance/OneTrust",
     "source_url": "https://www.dataguidance.com/jurisdictions/arkansas",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-arkansas/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "General adtech sub-modules (cookies, dark patterns, opt-out signals, clean rooms) are entirely absent; only narrow minors-advertising and telemarketing suppression rules exist.",
   "claims": [
    {
     "statement": "Arkansas has no general cookie/tracker consent law, dark-pattern prohibition, opt-out-signal recognition mandate, or clean-room regulation.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/privacy-in-arkansas-is-arkansas-ready-for-a-consumer-privacy-law-",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Arkansas Children and Teens' Online Privacy Protection Act (HB1717) prohibits covered operators from engaging in targeted advertising directed at minors, effective July 1, 2026.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance/OneTrust",
     "source_url": "https://www.dataguidance.com/jurisdictions/arkansas",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Arkansas Consumer Telephone Privacy Act establishes a state-wide Do-Not-Call database that functions as a direct-marketing suppression mechanism for telemarketing calls.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance/OneTrust",
     "source_url": "https://www.dataguidance.com/jurisdictions/arkansas",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "red",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-arkansas/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Only one confirmed sectoral ADM-transparency obligation exists; profiling, biometric, genetic, and surveillance-carveout sub-modules are absent or unconfirmed.",
   "claims": [
    {
     "statement": "Arkansas has no general statutory restriction on automated profiling of the general population comparable to GDPR Article 22.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/privacy-in-arkansas-is-arkansas-ready-for-a-consumer-privacy-law-",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Arkansas House Bill 1297 mandates transparency and quality-assurance requirements for AI algorithms used by health insurers in coverage decision-making.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance/OneTrust",
     "source_url": "https://www.dataguidance.com/jurisdictions/arkansas",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Arkansas Senate Bill 258 addresses AI and data protection, focusing on high-risk AI systems and their impact assessments; whether the bill has been enacted into law could not be confirmed from available sources.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance/OneTrust",
     "source_url": "https://www.dataguidance.com/jurisdictions/arkansas",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No dedicated biometric-data or genetic-data statute, and no Arkansas-specific state-surveillance carve-out statute, was identified.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/privacy-in-arkansas-is-arkansas-ready-for-a-consumer-privacy-law-",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-arkansas/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Meaningful minors-specific coverage exists (age verification, prospective ad-targeting ban) but the flagship consent mechanism (Social Media Safety Act) is unenforceable, and education/dependent-adult sub-modules are absent.",
   "claims": [
    {
     "statement": "Arkansas's Protection of Minors from the Distribution of Harmful Material Act requires age-verification methods before allowing access to a website containing a substantial portion of material that is harmful to minors.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance/OneTrust",
     "source_url": "https://www.dataguidance.com/jurisdictions/arkansas",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No Arkansas education-settings-specific data-protection statute beyond the federal Family Educational Rights and Privacy Act was identified.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/privacy-in-arkansas-is-arkansas-ready-for-a-consumer-privacy-law-",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No Arkansas data-protection-specific statute for dependent adults was identified; the state's SAFER AR Act creates a financial-exploitation reporting duty for Adult Protective Services but does not create data-protection rights or obligations.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/attorney-general-journal/consumer-chief-of-the-month-shannon-halijan-deputy-attorney-general-arkansas-attorney-generals-office/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-arkansas/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Active, well-documented AG enforcement exists, but redress avenues for individuals (private right of action, class actions) are unconfirmed/absent, and regulator capacity appears limited relative to its broad portfolio.",
   "claims": [
    {
     "statement": "The Arkansas Attorney General holds the power to sanction violations of the Personal Information Protection Act and issue penalties.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance/OneTrust",
     "source_url": "https://www.dataguidance.com/jurisdictions/arkansas",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Arkansas Attorney General Tim Griffin has pursued active enforcement in 2024-2026 targeting privacy-adjacent deceptive practices, including suits against TikTok/ByteDance, Meta, and Temu based on Arkansans' personal information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/privacy-in-arkansas-is-arkansas-ready-for-a-consumer-privacy-law-",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Consumer Protection Division of the Arkansas Attorney General's Office is described as a small team of lawyers and investigators managing antitrust, tobacco, charities enforcement, privacy, and other deceptive-trade-practices matters.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/attorney-general-journal/kate-donoven-senior-assistant-attorney-general-consumer-protection-division-arkansas-attorney-generals-office/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No Arkansas data-protection-specific collective-redress or class-action mechanism was identified; available enforcement is Attorney-General-driven.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/privacy-in-arkansas-is-arkansas-ready-for-a-consumer-privacy-law-",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Personal Information Protection Act does not grant Arkansas consumers an express private right of action; enforcement authority rests with the Attorney General.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance/OneTrust",
     "source_url": "https://www.dataguidance.com/jurisdictions/arkansas",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Within the recent reporting window, Arkansas courts held the Social Media Safety Act unconstitutional on First and Fourteenth Amendment grounds, and the Children and Teens' Online Privacy Protection Act's July 1, 2026 effective date approached.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance/OneTrust",
     "source_url": "https://www.dataguidance.com/jurisdictions/arkansas",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  }
 ]
}